Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Windows 7 computer with virus.


  • This topic is locked This topic is locked
34 replies to this topic

#1 epic pie

epic pie

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:01:17 AM

Posted 14 July 2011 - 04:47 PM

So I was on my Windows 7 computer one today, and I saw some e-mails I didn't send in my account. I checked what they were, and the were this: " http://paulisnotdead.com/modules/Search/myblog.html", and this: "http://fjordseaways.com/modules/Search/myblog.html." I scaned the computer with Malwarebyte's, and nothing came up. So I did a hijackthis scan and here is my log;

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:45:41 PM, on 7/14/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Users\family\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Users\family\Desktop\benjamins\Desktops.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Microsoft\BingBar\BingBar.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
C:\Program Files (x86)\Microsoft\BingBar\BingApp.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10s_ActiveX.exe
C:\Program Files (x86)\Windows Live\Companion\companionuser.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Hijackthis\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [SansaDispatch] C:\Users\family\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKCU\..\Run: [Sysinternals Desktops] C:\Users\family\Desktop\benjamins\Desktops.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\family\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: ActivClient Agent.lnk = C:\Program Files\ActivIdentity\ActivClient\acsagent.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware player\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware player\vsocklib.dll
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - https://s3.amazonaws.com/content.systemrequirementslab.com/global/bin/srldetect_cyri_4.1.72.0_x.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://l.yimg.com/jh/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ActivIdentity Shared Store Service (ac.sharedstore) - ActivIdentity - C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RosettaStoneDaemon - Rosetta Stone Ltd. - C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-ufad.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12098 bytes


Please help someone. Thanks.

BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 10,134 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:17 AM

Posted 29 July 2011 - 05:45 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you!

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

First, I need to know if you still need help! To tell me this, please click on http://www.bleepingcomputer.com/logreply/409557 and follow the instructions there. If you do not still need help, this is all you need to do. If you do need help please continue below.

***************************************************

If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS and GMER log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from one of the following links if you no longer have it available. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE


We also need a new log from the GMER anti-rootkit Scanner.

Please note that if you are running a 64-bit version of Windows you will not be able to run GMER and you may skip this step.

Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice


Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log


As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 epic pie

epic pie
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:01:17 AM

Posted 31 July 2011 - 02:33 PM

Here is my DDS log that the help bot asked for:

AV: AVG Anti-Virus Business Edition *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Business Edition *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ZoneAlarm Firewall *Enabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Program Files (x86)\AVG\AVG9\avgchsva.exe
C:\Program Files (x86)\AVG\AVG9\avgrsa.exe
C:\Windows\system32\lsm.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrva.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
C:\Users\family\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Users\family\Desktop\benjamins\Desktops.exe
C:\Program Files\ActivIdentity\ActivClient\acsagent.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
C:\Windows\SysWOW64\vmnat.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\SysWOW64\vmnetdhcp.exe
C:\Program Files (x86)\AVG\AVG9\avgemc.exe
C:\Program Files (x86)\AVG\AVG9\avgam.exe
C:\Program Files (x86)\AVG\AVG9\avgnsa.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrva.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10u_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Microsoft\BingBar\BingBar.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\Microsoft\BingBar\BingApp.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [SansaDispatch] C:\Users\family\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
uRun: [Sysinternals Desktops] C:\Users\family\Desktop\benjamins\Desktops.exe
uRun: [Google Update] "C:\Users\family\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
mRun: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ACTIVC~1.LNK - C:\Program Files (x86)\ActivIdentity\ActivClient\acsagent.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
LSP: C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll
Trusted Zone: navy.mil\webmail.east.nmci
Trusted Zone: navy.mil\wwwa.nko
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxps://s3.amazonaws.com/content.systemrequirementslab.com/global/bin/srldetect_cyri_4.1.72.0_x.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://l.yimg.com/jh/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 24.197.97.132 24.197.97.136
TCP: Interfaces\{4F15847B-30FF-4C27-BB1F-CE7642F723EA} : DhcpNameServer = 24.197.97.132 24.197.97.136
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO-X64: HP Print Enhancer - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
BHO-X64: HP Smart BHO Class - No File
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
mRun-x64: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
mRun-x64: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
mRun-x64: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun-x64: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\family\AppData\Roaming\Mozilla\Firefox\Profiles\vqgvqqcf.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\NOS\bin\np_gp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\family\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: C:\Users\family\AppData\Local\Microsoft\Internet Explorer\Downloaded Program Files\npsoe.dll
FF - plugin: C:\Users\family\AppData\Local\Roblox\Versions\version-18c3ec3fed324b69\NPRobloxProxy.dll
FF - plugin: C:\Users\family\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AvgRkx64;avgrkx64.sys;C:\Windows\system32\Drivers\avgrkx64.sys --> C:\Windows\system32\Drivers\avgrkx64.sys [?]
R1 AvgLdx64;AVG AVI Loader Driver x64;C:\Windows\system32\Drivers\avgldx64.sys --> C:\Windows\system32\Drivers\avgldx64.sys [?]
R1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;C:\Windows\system32\Drivers\avgmfx64.sys --> C:\Windows\system32\Drivers\avgmfx64.sys [?]
R1 AvgTdiA;AVG Network Redirector x64;C:\Windows\system32\Drivers\avgtdia.sys --> C:\Windows\system32\Drivers\avgtdia.sys [?]
R2 ac.sharedstore;ActivIdentity Shared Store Service;C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-6-3 277032]
R2 avg9emc;AVG E-mail Scanner;C:\Program Files (x86)\AVG\AVG9\avgemc.exe [2010-6-22 921952]
R2 avg9wd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe [2010-6-22 308136]
R2 RosettaStoneDaemon;RosettaStoneDaemon;C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe [2009-9-3 444224]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [2011-3-25 539248]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 wacmoumonitor;Wacom Mode Helper;C:\Windows\system32\DRIVERS\wacmoumonitor.sys --> C:\Windows\system32\DRIVERS\wacmoumonitor.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-2-4 135664]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-3-15 183560]
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-2-4 135664]
S3 nosGetPlusHelper;getPlus® Helper 3004;C:\Windows\System32\svchost.exe -k nosGetPlusHelper [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-07-22 20:40:27 -------- d-----w- C:\Users\family\.thumbnails
2011-07-21 12:28:02 2106216 ----a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-07-21 12:28:02 1998168 ----a-w- C:\Program Files (x86)\Mozilla Firefox\d3dx9_43.dll
2011-07-14 21:03:53 388096 ----a-r- C:\Users\family\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-07-14 01:55:45 -------- d-----w- C:\e550b36287cdb534486a45144022
.
==================== Find3M ====================
.
2011-07-15 12:26:25 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-06 23:52:42 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-06 23:52:42 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-06-13 13:48:43 466456 ----a-w- C:\Windows\System32\wrap_oal.dll
2011-06-13 13:48:43 444952 ----a-w- C:\Windows\SysWow64\wrap_oal.dll
2011-06-13 13:48:43 122904 ----a-w- C:\Windows\System32\OpenAL32.dll
2011-06-13 13:48:43 109080 ----a-w- C:\Windows\SysWow64\OpenAL32.dll
2011-06-11 03:07:25 3137536 ----a-w- C:\Windows\System32\win32k.sys
2011-06-03 06:57:45 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-06-03 06:57:45 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-06-03 06:57:45 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-06-03 06:57:44 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-06-03 06:57:38 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-06-03 06:56:38 421888 ----a-w- C:\Windows\System32\KernelBase.dll
2011-06-03 06:53:33 338944 ----a-w- C:\Windows\System32\conhost.exe
2011-06-03 06:00:53 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-06-03 05:57:52 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-06-03 05:57:33 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-06-03 05:56:12 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-06-03 05:56:11 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-06-03 03:53:31 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-06-03 03:53:31 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-06-03 03:48:32 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-06-03 03:48:31 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-06-03 03:48:31 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-06-03 03:48:31 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-05-28 03:30:09 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-05-28 02:53:58 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-05-24 13:10:46 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-05-24 13:10:46 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-05-24 11:42:55 404480 ----a-w- C:\Windows\System32\umpnpmgr.dll
2011-05-24 10:40:05 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
2011-05-24 10:40:05 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll
2011-05-24 10:39:38 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll
2011-05-24 10:37:54 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe
2011-05-05 13:32:54 317520 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
2011-05-04 08:52:22 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-05-04 05:25:03 2315776 ----a-w- C:\Windows\System32\tquery.dll
2011-05-04 05:22:25 778752 ----a-w- C:\Windows\System32\mssvp.dll
2011-05-04 05:22:25 2223616 ----a-w- C:\Windows\System32\mssrch.dll
2011-05-04 05:22:24 75264 ----a-w- C:\Windows\System32\msscntrs.dll
2011-05-04 05:22:24 491520 ----a-w- C:\Windows\System32\mssph.dll
2011-05-04 05:22:24 288256 ----a-w- C:\Windows\System32\mssphtb.dll
2011-05-04 05:19:28 591872 ----a-w- C:\Windows\System32\SearchIndexer.exe
2011-05-04 05:19:28 249856 ----a-w- C:\Windows\System32\SearchProtocolHost.exe
2011-05-04 05:19:28 113664 ----a-w- C:\Windows\System32\SearchFilterHost.exe
2011-05-04 04:34:43 1549312 ----a-w- C:\Windows\SysWow64\tquery.dll
2011-05-04 04:32:02 666624 ----a-w- C:\Windows\SysWow64\mssvp.dll
2011-05-04 04:32:01 337408 ----a-w- C:\Windows\SysWow64\mssph.dll
2011-05-04 04:32:01 197120 ----a-w- C:\Windows\SysWow64\mssphtb.dll
2011-05-04 04:32:01 1401344 ----a-w- C:\Windows\SysWow64\mssrch.dll
2011-05-04 04:32:00 59392 ----a-w- C:\Windows\SysWow64\msscntrs.dll
2011-05-04 04:28:31 86528 ----a-w- C:\Windows\SysWow64\SearchFilterHost.exe
2011-05-04 04:28:31 427520 ----a-w- C:\Windows\SysWow64\SearchIndexer.exe
2011-05-04 04:28:31 164352 ----a-w- C:\Windows\SysWow64\SearchProtocolHost.exe
2011-05-03 05:29:29 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-05-03 04:30:02 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
.
============= FINISH: 15:31:06.11 ===============


I can not run GMER as I am using 64 bit Windows 7.

#4 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 11,971 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bement, ILL
  • Local time:01:17 AM

Posted 31 July 2011 - 03:22 PM

Hello epic pie,
  • Welcome to Bleeping Computer.
  • My name is fireman4it and I will be helping you with your Malware problem.

    Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean".
  • In the upper right hand corner of the topic you will see a button called Watch Topic.I suggest you click it and select Immediate E-Mail notification and click on Proceed. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

  • Finally, please reply using the ADD REPLY button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply, unless they do not fit into the post.



1.
We need to disable your Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.
  • Open Windows Defender.
  • Click on Tools, General Settings.
  • Scroll down and uncheck Turn on real-time protection (recommended).
  • After you uncheck this, click on the Save button and close Windows Defender.
After all of the fixes are complete it is very important that you enable Real-time Protection again.


2.
Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!
Be sure to download TDSSKiller.exe (v2.5.6.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.
  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.5.6.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.

3.
Install Recovery Console and Run ComboFix

This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.

Download Combofix from any of the links below, and save it to your desktop.

Link 1
Link 2
  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Close any open windows, including this one.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • If you did not have it installed, you will see the prompt below. Choose YES.
  • Posted Image
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Note:The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you
should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    Posted Image
  • Click on Yes, to continue scanning for malware.
  • When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
Leave your computer alone while ComboFix is running.
ComboFix will restart your computer if malware is found; allow it to do so.


Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.


Things to include in your next reply::
TDSSKiller log
Combofix.txt
How is your machine running now?

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


un03.png

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#5 epic pie

epic pie
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:01:17 AM

Posted 02 August 2011 - 09:40 AM

1. Done
2.here is the log:2011/08/02 08:34:41.0260 4280 TDSS rootkit removing tool 2.5.13.0 Jul 29 2011 17:24:11
2011/08/02 08:34:42.0321 4280 ================================================================================
2011/08/02 08:34:42.0321 4280 SystemInfo:
2011/08/02 08:34:42.0321 4280
2011/08/02 08:34:42.0321 4280 OS Version: 6.1.7601 ServicePack: 1.0
2011/08/02 08:34:42.0321 4280 Product type: Workstation
2011/08/02 08:34:42.0336 4280 ComputerName: FAMILY-PC
2011/08/02 08:34:42.0336 4280 UserName: family
2011/08/02 08:34:42.0336 4280 Windows directory: C:\Windows
2011/08/02 08:34:42.0336 4280 System windows directory: C:\Windows
2011/08/02 08:34:42.0336 4280 Running under WOW64
2011/08/02 08:34:42.0336 4280 Processor architecture: Intel x64
2011/08/02 08:34:42.0336 4280 Number of processors: 2
2011/08/02 08:34:42.0336 4280 Page size: 0x1000
2011/08/02 08:34:42.0336 4280 Boot type: Normal boot
2011/08/02 08:34:42.0336 4280 ================================================================================
2011/08/02 08:34:43.0319 4280 Initialize success
2011/08/02 08:35:26.0921 5772 ================================================================================
2011/08/02 08:35:26.0921 5772 Scan started
2011/08/02 08:35:26.0921 5772 Mode: Manual;
2011/08/02 08:35:26.0921 5772 ================================================================================
2011/08/02 08:35:28.0918 5772 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
2011/08/02 08:35:28.0965 5772 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
2011/08/02 08:35:29.0012 5772 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
2011/08/02 08:35:29.0074 5772 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/08/02 08:35:29.0105 5772 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
2011/08/02 08:35:29.0121 5772 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
2011/08/02 08:35:29.0183 5772 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
2011/08/02 08:35:29.0230 5772 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
2011/08/02 08:35:29.0246 5772 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
2011/08/02 08:35:29.0277 5772 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
2011/08/02 08:35:29.0292 5772 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
2011/08/02 08:35:29.0308 5772 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
2011/08/02 08:35:29.0339 5772 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
2011/08/02 08:35:29.0355 5772 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/08/02 08:35:29.0386 5772 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
2011/08/02 08:35:29.0433 5772 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
2011/08/02 08:35:29.0480 5772 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
2011/08/02 08:35:29.0511 5772 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
2011/08/02 08:35:29.0542 5772 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/08/02 08:35:29.0558 5772 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
2011/08/02 08:35:29.0636 5772 AvgLdx64 (b447db072bf939db9e07bef2adf4ecbd) C:\Windows\System32\Drivers\avgldx64.sys
2011/08/02 08:35:29.0698 5772 AvgMfx64 (405baabbb48f9176e220020b1a77c47b) C:\Windows\System32\Drivers\avgmfx64.sys
2011/08/02 08:35:29.0776 5772 AvgRkx64 (5e7f0f9cbe0f7823371a4d51df29f7ff) C:\Windows\system32\Drivers\avgrkx64.sys
2011/08/02 08:35:29.0838 5772 AvgTdiA (8aa68c0ba2b84fd7eb3e1f10bbfc825b) C:\Windows\System32\Drivers\avgtdia.sys
2011/08/02 08:35:29.0885 5772 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
2011/08/02 08:35:29.0916 5772 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
2011/08/02 08:35:29.0963 5772 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
2011/08/02 08:35:29.0979 5772 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/08/02 08:35:30.0026 5772 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
2011/08/02 08:35:30.0041 5772 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/08/02 08:35:30.0057 5772 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/08/02 08:35:30.0088 5772 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
2011/08/02 08:35:30.0119 5772 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/08/02 08:35:30.0135 5772 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/08/02 08:35:30.0150 5772 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/08/02 08:35:30.0166 5772 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/08/02 08:35:30.0197 5772 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/08/02 08:35:30.0244 5772 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
2011/08/02 08:35:30.0291 5772 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
2011/08/02 08:35:30.0338 5772 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
2011/08/02 08:35:30.0384 5772 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/08/02 08:35:30.0431 5772 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
2011/08/02 08:35:30.0478 5772 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
2011/08/02 08:35:30.0509 5772 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
2011/08/02 08:35:30.0556 5772 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
2011/08/02 08:35:30.0587 5772 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/08/02 08:35:30.0650 5772 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
2011/08/02 08:35:30.0681 5772 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
2011/08/02 08:35:30.0712 5772 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
2011/08/02 08:35:30.0759 5772 Dot4 (b42ed0320c6e41102fde0005154849bb) C:\Windows\system32\DRIVERS\Dot4.sys
2011/08/02 08:35:30.0806 5772 Dot4Print (e9f5969233c5d89f3c35e3a66a52a361) C:\Windows\system32\drivers\Dot4Prt.sys
2011/08/02 08:35:30.0837 5772 dot4usb (fd05a02b0370bc3000f402e543ca5814) C:\Windows\system32\DRIVERS\dot4usb.sys
2011/08/02 08:35:30.0884 5772 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
2011/08/02 08:35:30.0930 5772 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
2011/08/02 08:35:31.0008 5772 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
2011/08/02 08:35:31.0086 5772 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
2011/08/02 08:35:31.0133 5772 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
2011/08/02 08:35:31.0180 5772 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
2011/08/02 08:35:31.0211 5772 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
2011/08/02 08:35:31.0242 5772 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
2011/08/02 08:35:31.0274 5772 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
2011/08/02 08:35:31.0289 5772 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
2011/08/02 08:35:31.0320 5772 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/08/02 08:35:31.0367 5772 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
2011/08/02 08:35:31.0398 5772 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
2011/08/02 08:35:31.0461 5772 fssfltr (6c06701bf1db05405804d7eb610991ce) C:\Windows\system32\DRIVERS\fssfltr.sys
2011/08/02 08:35:31.0476 5772 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
2011/08/02 08:35:31.0539 5772 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
2011/08/02 08:35:31.0570 5772 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/08/02 08:35:31.0632 5772 hcmon (d5fa01185a7d5a65724fd87b34e53f5b) C:\Windows\system32\drivers\hcmon.sys
2011/08/02 08:35:31.0648 5772 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
2011/08/02 08:35:31.0710 5772 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
2011/08/02 08:35:31.0742 5772 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
2011/08/02 08:35:31.0757 5772 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/08/02 08:35:31.0788 5772 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
2011/08/02 08:35:31.0804 5772 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
2011/08/02 08:35:31.0835 5772 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\drivers\hidusb.sys
2011/08/02 08:35:31.0898 5772 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
2011/08/02 08:35:31.0944 5772 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
2011/08/02 08:35:32.0007 5772 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
2011/08/02 08:35:32.0038 5772 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
2011/08/02 08:35:32.0085 5772 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
2011/08/02 08:35:32.0272 5772 igfx (c6238c6abd6ac99f5d152da4e9439a3d) C:\Windows\system32\DRIVERS\igdkmd64.sys
2011/08/02 08:35:32.0506 5772 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
2011/08/02 08:35:32.0537 5772 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
2011/08/02 08:35:32.0584 5772 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
2011/08/02 08:35:32.0615 5772 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/08/02 08:35:32.0662 5772 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
2011/08/02 08:35:32.0709 5772 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
2011/08/02 08:35:32.0724 5772 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
2011/08/02 08:35:32.0756 5772 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
2011/08/02 08:35:32.0771 5772 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
2011/08/02 08:35:32.0802 5772 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
2011/08/02 08:35:32.0834 5772 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
2011/08/02 08:35:32.0880 5772 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
2011/08/02 08:35:32.0912 5772 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
2011/08/02 08:35:32.0943 5772 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
2011/08/02 08:35:32.0990 5772 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
2011/08/02 08:35:33.0036 5772 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/08/02 08:35:33.0068 5772 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/08/02 08:35:33.0083 5772 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/08/02 08:35:33.0099 5772 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/08/02 08:35:33.0114 5772 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
2011/08/02 08:35:33.0146 5772 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
2011/08/02 08:35:33.0161 5772 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/08/02 08:35:33.0192 5772 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
2011/08/02 08:35:33.0224 5772 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
2011/08/02 08:35:33.0270 5772 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
2011/08/02 08:35:33.0286 5772 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
2011/08/02 08:35:33.0317 5772 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
2011/08/02 08:35:33.0348 5772 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
2011/08/02 08:35:33.0380 5772 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
2011/08/02 08:35:33.0442 5772 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
2011/08/02 08:35:33.0489 5772 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/08/02 08:35:33.0504 5772 mrxsmb10 (2086d463bd371d8a37d153897430916d) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/08/02 08:35:33.0536 5772 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/08/02 08:35:33.0551 5772 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
2011/08/02 08:35:33.0598 5772 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
2011/08/02 08:35:33.0614 5772 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
2011/08/02 08:35:33.0660 5772 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
2011/08/02 08:35:33.0692 5772 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
2011/08/02 08:35:33.0723 5772 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
2011/08/02 08:35:33.0754 5772 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/08/02 08:35:33.0770 5772 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
2011/08/02 08:35:33.0816 5772 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
2011/08/02 08:35:33.0832 5772 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
2011/08/02 08:35:33.0848 5772 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
2011/08/02 08:35:33.0863 5772 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/08/02 08:35:33.0894 5772 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
2011/08/02 08:35:33.0941 5772 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
2011/08/02 08:35:34.0004 5772 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
2011/08/02 08:35:34.0035 5772 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/08/02 08:35:34.0066 5772 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/08/02 08:35:34.0097 5772 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/08/02 08:35:34.0144 5772 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/08/02 08:35:34.0191 5772 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
2011/08/02 08:35:34.0238 5772 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
2011/08/02 08:35:34.0269 5772 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
2011/08/02 08:35:34.0331 5772 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/08/02 08:35:34.0378 5772 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
2011/08/02 08:35:34.0394 5772 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
2011/08/02 08:35:34.0472 5772 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
2011/08/02 08:35:34.0503 5772 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
2011/08/02 08:35:34.0550 5772 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
2011/08/02 08:35:34.0581 5772 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
2011/08/02 08:35:34.0596 5772 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
2011/08/02 08:35:34.0659 5772 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
2011/08/02 08:35:34.0706 5772 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
2011/08/02 08:35:34.0737 5772 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
2011/08/02 08:35:34.0768 5772 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
2011/08/02 08:35:34.0799 5772 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
2011/08/02 08:35:34.0830 5772 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/08/02 08:35:34.0862 5772 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
2011/08/02 08:35:34.0893 5772 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
2011/08/02 08:35:35.0002 5772 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
2011/08/02 08:35:35.0049 5772 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
2011/08/02 08:35:35.0096 5772 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
2011/08/02 08:35:35.0142 5772 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
2011/08/02 08:35:35.0189 5772 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/08/02 08:35:35.0220 5772 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
2011/08/02 08:35:35.0252 5772 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
2011/08/02 08:35:35.0267 5772 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/08/02 08:35:35.0314 5772 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/08/02 08:35:35.0345 5772 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/08/02 08:35:35.0376 5772 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
2011/08/02 08:35:35.0423 5772 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
2011/08/02 08:35:35.0454 5772 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/08/02 08:35:35.0470 5772 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/08/02 08:35:35.0501 5772 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
2011/08/02 08:35:35.0517 5772 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
2011/08/02 08:35:35.0564 5772 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
2011/08/02 08:35:35.0626 5772 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
2011/08/02 08:35:35.0688 5772 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
2011/08/02 08:35:35.0720 5772 RTL8167 (abcb5a38a0d85bdf69b7877e1ad1eed5) C:\Windows\system32\DRIVERS\Rt64win7.sys
2011/08/02 08:35:35.0766 5772 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
2011/08/02 08:35:35.0813 5772 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
2011/08/02 08:35:35.0907 5772 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2011/08/02 08:35:35.0938 5772 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
2011/08/02 08:35:35.0969 5772 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
2011/08/02 08:35:35.0985 5772 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
2011/08/02 08:35:36.0047 5772 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
2011/08/02 08:35:36.0078 5772 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
2011/08/02 08:35:36.0110 5772 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
2011/08/02 08:35:36.0125 5772 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/08/02 08:35:36.0156 5772 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/08/02 08:35:36.0172 5772 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/08/02 08:35:36.0203 5772 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
2011/08/02 08:35:36.0234 5772 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
2011/08/02 08:35:36.0312 5772 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
2011/08/02 08:35:36.0359 5772 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
2011/08/02 08:35:36.0390 5772 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
2011/08/02 08:35:36.0437 5772 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
2011/08/02 08:35:36.0468 5772 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
2011/08/02 08:35:36.0562 5772 Tcpip (92ce29d95ac9dd2d0ee9061d551ba250) C:\Windows\system32\drivers\tcpip.sys
2011/08/02 08:35:36.0624 5772 TCPIP6 (92ce29d95ac9dd2d0ee9061d551ba250) C:\Windows\system32\DRIVERS\tcpip.sys
2011/08/02 08:35:36.0687 5772 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
2011/08/02 08:35:36.0718 5772 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
2011/08/02 08:35:36.0734 5772 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
2011/08/02 08:35:36.0780 5772 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
2011/08/02 08:35:36.0796 5772 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
2011/08/02 08:35:36.0874 5772 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/08/02 08:35:36.0905 5772 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
2011/08/02 08:35:36.0983 5772 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
2011/08/02 08:35:36.0999 5772 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
2011/08/02 08:35:37.0046 5772 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
2011/08/02 08:35:37.0124 5772 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
2011/08/02 08:35:37.0155 5772 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
2011/08/02 08:35:37.0186 5772 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
2011/08/02 08:35:37.0217 5772 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/08/02 08:35:37.0264 5772 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
2011/08/02 08:35:37.0295 5772 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
2011/08/02 08:35:37.0342 5772 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
2011/08/02 08:35:37.0373 5772 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
2011/08/02 08:35:37.0404 5772 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
2011/08/02 08:35:37.0451 5772 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
2011/08/02 08:35:37.0467 5772 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\drivers\USBSTOR.SYS
2011/08/02 08:35:37.0498 5772 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/08/02 08:35:37.0560 5772 VBoxNetAdp (47499fe912f0b4e7664f8498f2906f0e) C:\Windows\system32\DRIVERS\VBoxNetAdp.sys
2011/08/02 08:35:37.0592 5772 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
2011/08/02 08:35:37.0623 5772 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/08/02 08:35:37.0638 5772 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
2011/08/02 08:35:37.0685 5772 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
2011/08/02 08:35:37.0716 5772 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
2011/08/02 08:35:37.0763 5772 vmci (4c8a14dbd410b510a88f77cb645f2c2a) C:\Windows\system32\drivers\vmci.sys
2011/08/02 08:35:37.0810 5772 vmkbd (ffc30caeeb2fc5fee8568cff74edeaed) C:\Windows\system32\drivers\VMkbd.sys
2011/08/02 08:35:37.0857 5772 VMnetAdapter (9d54f1339e78c95bf3d9939ebcb66378) C:\Windows\system32\DRIVERS\vmnetadapter.sys
2011/08/02 08:35:37.0888 5772 VMnetBridge (fb54ef3aa613d2832fd3812e7cb2fc75) C:\Windows\system32\DRIVERS\vmnetbridge.sys
2011/08/02 08:35:37.0919 5772 VMnetuserif (d0b809f6a9fb437c2b880c3ca8c10780) C:\Windows\system32\drivers\vmnetuserif.sys
2011/08/02 08:35:37.0950 5772 VMparport (55e1dc39d985f2b33ebc23cd7fba582e) C:\Windows\system32\drivers\VMparport.sys
2011/08/02 08:35:38.0013 5772 vmx86 (541a6d6536710fd0602ec3aa24a81756) C:\Windows\system32\drivers\vmx86.sys
2011/08/02 08:35:38.0044 5772 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
2011/08/02 08:35:38.0075 5772 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
2011/08/02 08:35:38.0106 5772 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
2011/08/02 08:35:38.0169 5772 Vsdatant (48bfa6276bcc0535f5f8898107ed489a) C:\Windows\system32\DRIVERS\vsdatant.sys
2011/08/02 08:35:38.0231 5772 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/08/02 08:35:38.0294 5772 vstor2-ws60 (e61c910e2ddf4797c1b1f9239636e894) C:\Program Files (x86)\VMware\VMware Player\vstor2-ws60.sys
2011/08/02 08:35:38.0309 5772 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
2011/08/02 08:35:38.0372 5772 wacmoumonitor (37e4600e2cdad3c1a3613a25b97d457c) C:\Windows\system32\DRIVERS\wacmoumonitor.sys
2011/08/02 08:35:38.0387 5772 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
2011/08/02 08:35:38.0418 5772 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
2011/08/02 08:35:38.0450 5772 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
2011/08/02 08:35:38.0496 5772 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
2011/08/02 08:35:38.0528 5772 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
2011/08/02 08:35:38.0606 5772 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/08/02 08:35:38.0606 5772 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
2011/08/02 08:35:38.0684 5772 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\drivers\WinUSB.sys
2011/08/02 08:35:38.0730 5772 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
2011/08/02 08:35:38.0793 5772 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
2011/08/02 08:35:38.0840 5772 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
2011/08/02 08:35:38.0871 5772 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\drivers\WUDFRd.sys
2011/08/02 08:35:38.0949 5772 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
2011/08/02 08:35:38.0949 5772 MBR (0x1B8) (65e858a8a0293be11a920b0bc99d695e) \Device\Harddisk1\DR1
2011/08/02 08:35:38.0996 5772 Boot (0x1200) (b29c0435f7b01ca9bb012eb63ff8e84e) \Device\Harddisk0\DR0\Partition0
2011/08/02 08:35:39.0011 5772 Boot (0x1200) (84646ae56d7d27c790c059b59f96cd0d) \Device\Harddisk0\DR0\Partition1
2011/08/02 08:35:39.0011 5772 Boot (0x1200) (fdbff74b571ba562a8f2a4ddb6ed3715) \Device\Harddisk1\DR1\Partition0
2011/08/02 08:35:39.0027 5772 ================================================================================
2011/08/02 08:35:39.0027 5772 Scan finished
2011/08/02 08:35:39.0027 5772 ================================================================================
2011/08/02 08:35:39.0042 4828 Detected object count: 0
2011/08/02 08:35:39.0042 4828 Actual detected object count: 0
2011/08/02 08:35:53.0036 3772 Deinitialize success

3.Here this log is:ComboFix 11-08-02.02 - family 08/02/2011 8:46.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2012.1026 [GMT -4:00]
Running from: c:\users\family\Desktop\ComboFix.exe
AV: AVG Anti-Virus Business Edition *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
FW: ZoneAlarm Firewall *Enabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
SP: AVG Anti-Virus Business Edition *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\SIS Setup
c:\program files (x86)\SIS Setup\CHANNEL.txt
c:\program files (x86)\SIS Setup\OFFER1ACTION.txt
c:\program files (x86)\SIS Setup\OFFER2ACTION.txt
c:\program files (x86)\SIS Setup\OFFER3ACTION.txt
c:\program files (x86)\SIS Setup\OFFER4ACTION.txt
c:\program files (x86)\SIS Setup\OFFER5ACTION.txt
c:\program files (x86)\SIS Setup\OFFER6ACTION.txt
c:\program files (x86)\SIS Setup\OFFER7ACTION.txt
c:\program files (x86)\SIS Setup\SIS.EXE
c:\program files (x86)\SIS Setup\trafficplace-us-2-silent-runtime.zugo
c:\program files (x86)\SIS Setup\trafficplace-us-2-silent.exe
c:\program files (x86)\SIS Setup\TYACTION.txt
c:\program files (x86)\SIS Setup\TYURL.txt
c:\program files (x86)\SIS Setup\YTD Stand Alone.exe
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\security\Database\tmp.edb
.
.
((((((((((((((((((((((((( Files Created from 2011-07-02 to 2011-08-02 )))))))))))))))))))))))))))))))
.
.
2011-08-02 12:51 . 2011-08-02 12:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-22 20:40 . 2011-07-22 20:40 -------- d-----w- c:\users\family\AppData\Roaming\gtk-2.0
2011-07-22 20:40 . 2011-07-22 20:40 -------- d-----w- c:\users\family\.thumbnails
2011-07-21 12:28 . 2010-01-01 08:00 2106216 ----a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-07-21 12:28 . 2010-01-01 08:00 1998168 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll
2011-07-15 12:23 . 2011-07-15 12:23 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-14 21:03 . 2011-07-14 21:03 388096 ----a-r- c:\users\family\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-07-14 01:55 . 2011-07-16 13:59 -------- d-----w- C:\e550b36287cdb534486a45144022
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-15 12:26 . 2011-05-20 11:17 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-06 23:52 . 2010-04-04 00:11 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-06 23:52 . 2010-04-04 00:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-13 13:48 . 2011-06-13 13:48 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2011-06-13 13:48 . 2010-03-12 21:19 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2011-06-13 13:48 . 2010-03-12 21:19 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2011-06-13 13:48 . 2010-03-12 21:19 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2011-06-03 05:57 . 2011-07-13 12:07 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-28 03:30 . 2011-06-16 12:44 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-05-28 02:53 . 2011-06-16 12:44 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-05-24 13:10 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-05-24 13:10 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-05-24 11:42 . 2011-06-29 14:33 404480 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-05-24 10:40 . 2011-06-29 14:33 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-05-24 10:40 . 2011-06-29 14:33 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-05-24 10:39 . 2011-06-29 14:33 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-05-24 10:37 . 2011-06-29 14:33 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
2011-05-05 13:32 . 2010-02-04 10:29 317520 ----a-w- c:\windows\system32\drivers\avgtdia.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SansaDispatch"="c:\users\family\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe" [2011-02-26 79872]
"Sysinternals Desktops"="c:\users\family\Desktop\benjamins\Desktops.exe" [2010-01-18 116088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVG9_TRAY"="c:\progra~2\AVG\AVG9\avgtray.exe" [2011-03-15 2071904]
"ZoneAlarm Client"="c:\program files (x86)\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
ActivClient Agent.lnk - c:\program files\ActivIdentity\ActivClient\acsagent.exe [2009-6-3 164904]
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-04 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-03-16 183560]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-04 135664]
R3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe [2009-07-14 27136]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 AvgRkx64;avgrkx64.sys;c:\windows\System32\Drivers\avgrkx64.sys [x]
S1 AvgLdx64;AVG AVI Loader Driver x64;c:\windows\System32\Drivers\avgldx64.sys [x]
S1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;c:\windows\System32\Drivers\avgmfx64.sys [x]
S1 AvgTdiA;AVG Network Redirector x64;c:\windows\System32\Drivers\avgtdia.sys [x]
S2 ac.sharedstore;ActivIdentity Shared Store Service;c:\program files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-06-03 277032]
S2 avg9emc;AVG E-mail Scanner;c:\program files (x86)\AVG\AVG9\avgemc.exe [2010-07-21 921952]
S2 avg9wd;AVG WatchDog;c:\program files (x86)\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]
S2 RosettaStoneDaemon;RosettaStoneDaemon;c:\program files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe [2009-09-03 444224]
S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [x]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [2011-03-26 539248]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 32829823
*Deregistered* - 32829823
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-04 13:55]
.
2011-08-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-04 13:55]
.
2011-08-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3798263754-334116708-512108424-1000Core.job
- c:\users\family\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-22 11:37]
.
2011-08-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3798263754-334116708-512108424-1000UA.job
- c:\users\family\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-22 11:37]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"acevents"="c:\program files\ActivIdentity\ActivClient\acevents.exe" [2009-06-03 196648]
"accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2009-06-03 483880]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 162328]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 417304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\avgrssta.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.yahoo.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
LSP: c:\program files (x86)\VMware\VMware Player\vsocklib.dll
Trusted Zone: navy.mil\webmail.east.nmci
Trusted Zone: navy.mil\wwwa.nko
TCP: DhcpNameServer = 24.178.162.3 97.81.22.195 24.159.64.23
FF - ProfilePath - c:\users\family\AppData\Roaming\Mozilla\Firefox\Profiles\vqgvqqcf.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-(Default) - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10u_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10u_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-08-02 08:54:02
ComboFix-quarantined-files.txt 2011-08-02 12:54
.
Pre-Run: 413,719,089,152 bytes free
Post-Run: 413,302,788,096 bytes free
.
- - End Of File - - A4AB84F03B22B4FF86B54B209E033586

The machine seems to be running as usual...

#6 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 11,971 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bement, ILL
  • Local time:01:17 AM

Posted 02 August 2011 - 03:55 PM

Hello,


IMPORTANT NOTE: One or more of the identified infections is a backdoor Trojan. Backdoor Trojans, Botnets, and IRCBots are very dangerous because they compromise system integrity by making changes that allow it to be used by the attacker for malicious purposes. They can disable your anti-virus and security tools to prevent detection and removal. Remote attackers use backdoors as a means of accessing and taking control of a computer that bypasses security mechanisms. This type of exploit allows them to steal sensitive information like passwords, personal and financial data which is then sent back to the hacker. Read Danger: Remote Access Trojans.

You should disconnect the computer from the Internet and from any networked computers until it is cleaned. If your computer was used for online banking, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for banking, email, eBay, paypal and any online activities which require a username and password. You should consider them to be compromised and change passwords from a clean computer, not the infected one. If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified immediately of the possible security breach. Failure to notify your financial institution and local law enforcement can result in refusal to reimburse funds lost due to fraud or similar criminal activity. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again.

Although the infection has been identified and may be removed, your machine has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume the computer is secure even if the malware appears to have been removed. In some instances an infection may have caused so much damage to your system that it cannot be successfully cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them. Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read:[quote]Whenever a system has been compromised by a backdoor payload, it is impossible to know if or how much the backdoor has been used to affect your system...There are only a few ways to return a compromised system to a confident security configuration. These include:
• Reimaging the system
• Restoring the entire system using a full system backup from before the backdoor infection
• Reformatting and reinstalling the system[/quote]Backdoors and What They Mean to You

This is what Jesper M. Johansson at Microsoft TechNet has to say: Help: I Got Hacked. Now What Do I Do?.[quote]The only way to clean a compromised system is to flatten and rebuild. That’s right. If you have a system that has been completely compromised, the only thing you can do is to flatten the system (reformat the system disk) and rebuild it from scratch (reinstall Windows and your applications).

Because your computer was compromised please read:

1.
Please download Malwarebytes' Anti-Malware (v1.50) and save it to your desktop.
Download Link 1
Download Link 2Malwarebytes' may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.

  • Make sure you are connected to the Internet and double-click on mbam-setup.exe to install the application.
    For instructions with screenshots, please refer to this Guide.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • Malwarebytes will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • Under the Scanner tab, make sure the "Perform Quick Scan" option is selected.
  • Click on the Scan button.
  • When finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box, then click the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked and then click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows the database version and your operating system.
  • Exit Malwarebytes' when done.
Note: If Malwarebytes' encounters a file that is difficult to remove, you will be asked to reboot your computer so it can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally will prevent Malwarebytes' from removing all the malware.

2.
Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

Please download DrWeb-CureIt and save it to your desktop. DO NOT perform a scan yet.

Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with Dr.Web CureIt as follows:
  • Double-click on launch.exe to open the program and click Start. (There is no need to update if you just downloaded the most current version
  • Read the Virus check by DrWeb scanner prompt and click Ok where asked to Start scan now? Allow the setup.exe to load if asked by any of your security programs.
  • The Express scan will automatically begin.
    (This is a short scan of files currently running in memory, boot sectors, and targeted folders).
  • If prompted to dowload the Full version Free Trial, ignore and click the X to close the window.
  • If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All.
  • When complete, click Select All, then choose Cure > Move incurable.
    (This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
  • Now put a check next to Complete scan to scan all local disks and removable media.
  • In the top menu, click Settings > Change settings, and UNcheck "Heuristic analysis" under the "Scanning" tab, then click Ok.
  • Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
  • When the scan is complete, a message will be displayed at the bottom indicating if any viruses were found.
  • Click "Yes to all" if asked to cure or move the file(s) and select "Move incurable".
  • In the top menu, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)

Things to include in your next reply::
MBAM log
Dr Web log
HIJackThis log
How is your machine running now?

Edited by fireman4it, 02 August 2011 - 03:55 PM.

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


un03.png

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#7 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 11,971 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bement, ILL
  • Local time:01:17 AM

Posted 04 August 2011 - 04:40 PM

Hello.

Are you still there?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 3-5 days the topic will need to be closed.

Thanks for understanding :)

With Regards,
fireman4it

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


un03.png

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#8 epic pie

epic pie
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:01:17 AM

Posted 05 August 2011 - 07:45 AM

Sorry, I had the flu, and was unable to get to a computer.
1.DrWebCureIt log is to big to paste, so can I attach it?


2.Here is the Mbam log:Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7377

Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514

8/5/2011 8:43:13 AM
mbam-log-2011-08-05 (08-43-13).txt

Scan type: Quick scan
Objects scanned: 176901
Time elapsed: 3 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


#9 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 11,971 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bement, ILL
  • Local time:01:17 AM

Posted 05 August 2011 - 05:29 PM

1.DrWebCureIt log is to big to paste, so can I attach it?


Sure or use multiple posts. Also please post a new HiJackThis log And how the machine is running now?

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


un03.png

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#10 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 11,971 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bement, ILL
  • Local time:01:17 AM

Posted 07 August 2011 - 11:41 AM

Hello.

Are you still there?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 3-5 days the topic will need to be closed.

Thanks for understanding :)

With Regards,
fireman4it

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


un03.png

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#11 epic pie

epic pie
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:01:17 AM

Posted 07 August 2011 - 12:32 PM

HijackThis:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:31:15 PM, on 8/7/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Users\family\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Users\family\Desktop\benjamins\Desktops.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\Microsoft\BingBar\BingBar.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
C:\Program Files (x86)\Microsoft\BingBar\BingApp.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Hijackthis\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\SysWOW64\DllHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [SansaDispatch] C:\Users\family\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKCU\..\Run: [Sysinternals Desktops] C:\Users\family\Desktop\benjamins\Desktops.exe
O4 - Global Startup: ActivClient Agent.lnk = C:\Program Files\ActivIdentity\ActivClient\acsagent.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware player\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware player\vsocklib.dll
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - https://s3.amazonaws.com/content.systemrequirementslab.com/global/bin/srldetect_cyri_4.1.72.0_x.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://l.yimg.com/jh/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ActivIdentity Shared Store Service (ac.sharedstore) - ActivIdentity - C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RosettaStoneDaemon - Rosetta Stone Ltd. - C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-ufad.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11466 bytes


#12 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 11,971 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bement, ILL
  • Local time:01:17 AM

Posted 07 August 2011 - 02:00 PM

Hello,

Can you please post the Dr.Web log in multiple posts so I can see it. Also How is your machine running now?

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


un03.png

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#13 epic pie

epic pie
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:01:17 AM

Posted 07 August 2011 - 03:35 PM

Working on it, and btw, the computer is work as it did last step.

#14 epic pie

epic pie
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:01:17 AM

Posted 08 August 2011 - 09:54 AM

=============================================================================
Dr.Web Scanner for Windows v6.00.11 (6.00.11.07112)
© Doctor Web, Ltd., 1992-2011
Log generated on: 2011-08-04, 14:09:44 [FAMILY-PC][family]
Command line: "C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\b9bc5_xp.exe" /lng /ini:setup_xp.ini /fast
Operating system: Windows Seven Premium x64/WOW (Build 7601), Service Pack 1
=============================================================================
Dr.Web Shield doesn't load
Engine version: 5.00 (5.00.2.03300)
Engine API version: 2.02
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\36d66478 - 2800 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\cec6ff13 - 8841 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\324e479d - 20563 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\08f47963 - 29147 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\1d24f266 - 20771 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\9ae457d3 - 41547 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\a6958e3d - 35434 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\48cb872c - 41517 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\ab1f9bec - 25512 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\b31b4017 - 28999 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\b79c783f - 36564 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\886459fb - 30676 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\00b77410 - 25157 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\c571f89b - 21479 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\1f8d8d8a - 23541 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\9f50cf6f - 24447 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\6f66d3c8 - 21471 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\c938a23a - 17824 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\6a6a0ced - 18737 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\4f2ba1b7 - 8998 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\2fde472e - 9352 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\60ea9269 - 4901 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\ba7f2c12 - 7472 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\19bbca26 - 13720 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\aeea8b73 - 12944 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\10da103d - 17300 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\2dbeb7dc - 17443 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\c1917293 - 18483 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\7037abbc - 14834 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\355c6673 - 14185 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\b4199252 - 13370 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\13e7bdbf - 7482 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\a073073e - 11624 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\3259feeb - 10523 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\98fa53a7 - 10122 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\df3355eb - 10453 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\055edc42 - 10778 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\99a65aad - 9822 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\5d93c28f - 14045 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\e26e1d6f - 7028 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\680d8fdc - 8674 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\0163a54d - 8626 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\3eb5950c - 8231 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\dfb7fad2 - 10397 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\44a9e90d - 11234 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\1ee9ecde - 10356 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\b0b2d7e1 - 11383 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\671c8a60 - 8957 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\44cbb305 - 11015 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\42b05744 - 11168 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\00170a4d - 7798 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\1b3a44ad - 7873 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\325f1d07 - 6904 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\86bf5696 - 6503 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\8c8438bb - 9823 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\9ae2bda3 - 7572 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\9514f3a3 - 6996 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\0e8ea6b1 - 16360 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\a7bcea58 - 29168 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\4df50c54 - 34202 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\50b5c16a - 28292 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\1d9bbbb3 - 27164 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\7dc9d9ad - 25131 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\311201bb - 31464 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\d70408ae - 18281 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\f26b6740 - 18009 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\44ccff70 - 24685 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\70919f69 - 13651 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\44aed4e9 - 16025 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\1e3fb0f8 - 15644 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\471f73fa - 23265 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\db02d8a9 - 23135 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\db60674f - 20510 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\0d610270 - 25475 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\cb5acecd - 16298 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\5383e93b - 19357 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\8b6bdd30 - 18381 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\84586f95 - 19562 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\b6fe3cea - 27102 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\6cd39fc8 - 21223 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\873cb618 - 24847 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\91dce0fa - 23251 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\552eab72 - 14982 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\449ae6ca - 16778 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\30765e0f - 18725 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\e7921aec - 18429 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\4d3f4edc - 6220 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\2fa093e9 - 142240 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\8a67ab6c - 66726 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\d2e9edf1 - 24512 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\d262cbf5 - 82762 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\d8069987 - 508543 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\8054337f - 851 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\8cf3ef09 - 1843 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\d7681f87 - 1694 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\ff051a16 - 1578 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\7b12ccef - 1959 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\76d903c6 - 2033 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\941ab547 - 1812 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\7d2e56a7 - 1738 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\ca70c263 - 1885 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\34f19a2e - 2091 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\0caaaf3a - 1569 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\7fc8cca5 - 1834 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\bece2fc6 - 708 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\a24ecd96 - 2208 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\a69dbdae - 2483 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\878e7e2d - 1603 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\958a73c4 - 1919 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\47f74a2e - 1819 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\efd76057 - 2229 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\bcce049b - 1833 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\aa110f38 - 1614 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\b5b02712 - 2297 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\acb78ca8 - 2110 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\aa224f3c - 2007 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\9aea5083 - 2370 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\5f93883f - 2241 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\effe8bf2 - 2596 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\d9ecb6e9 - 2024 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\991987ec - 1609 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\207cab1f - 1471 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\8a4185a9 - 1445 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\908cd336 - 1895 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\d3691dc3 - 2312 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\496cdf22 - 3006 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\d089871a - 2146 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\4644d980 - 1714 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\748543ec - 2095 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\197434f1 - 2715 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\a3d94cfc - 2545 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\4f2ea469 - 2801 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\52d04880 - 6197 virus records
[Virus database] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\f31ba509 - 28348 virus records
Total virus records: 2447062
[Self-checking] C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\b9bc5_xp.exe
Key file: C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\setup.key
License key number: 0013622856
Registered to: An unauthorized User
License key activates on: 2011-03-10
License key expires on: 2012-03-11
Process in memory: C:\Windows\System32\smss.exe:244 - OK
Process in memory: C:\Windows\System32\csrss.exe:316 - OK
Process in memory: C:\Windows\System32\csrss.exe:352 - OK
Process in memory: C:\Windows\System32\wininit.exe:360 - OK
Process in memory: C:\Windows\System32\winlogon.exe:388 - OK
Process in memory: C:\Windows\System32\services.exe:448 - OK
Process in memory: C:\Windows\System32\lsass.exe:456 - OK
Process in memory: C:\Windows\System32\lsm.exe:464 - OK
Process in memory: C:\Windows\System32\svchost.exe:564 - OK
Process in memory: C:\Windows\System32\svchost.exe:640 - OK
Process in memory: C:\Windows\System32\svchost.exe:728 - OK
Process in memory: C:\Windows\System32\svchost.exe:764 - OK
Process in memory: C:\Windows\System32\svchost.exe:816 - OK
Process in memory: C:\Windows\System32\svchost.exe:872 - OK
Process in memory: C:\Windows\System32\wisptis.exe:988 - OK
Process in memory: C:\Windows\System32\wisptis.exe:348 - OK
Process in memory: C:\Windows\explorer.exe:656 - OK
Process in memory: C:\Windows\System32\ctfmon.exe:1036 - OK
Process in memory: C:\Users\family\Desktop\drweb-cureit.exe:1320 - OK
Process in memory: C:\Windows\System32\wisptis.exe:1384 - OK
Process in memory: C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\416c13.exe:1444 - OK
Process in memory: C:\Windows\SysWOW64\ctfmon.exe:1452 - OK
Process in memory: C:\Users\family\AppData\Local\Temp\461C1F07-5A5AB364-45B5BC37-3AB124BC\b9bc5_xp.exe:1488 - OK
[Memory scanning] No viruses found
Master Boot Record HDD1 - OK
Master Boot Record HDD2 - OK
Active OS/2 or NT Boot Sector HDD1 Partition0 - OK
OS/2 or NT Boot Sector HDD1 Partition1 - OK
FAT16 (>32Mb,I13ext) Boot Sector HDD2 Partition0 - OK

[Scan path] C:\Windows\system32
C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 - OK
C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 - OK
C:\Windows\system32\aaclient.dll - OK
C:\Windows\system32\accessibilitycpl.dll - OK
C:\Windows\system32\ACCTRES.dll - OK
C:\Windows\system32\acledit.dll - OK
C:\Windows\system32\aclui.dll - OK
C:\Windows\system32\acppage.dll - OK
C:\Windows\system32\acproxy.dll - OK
C:\Windows\system32\ActionCenter.dll - OK
C:\Windows\system32\ActionCenterCPL.dll - OK
C:\Windows\system32\ActionQueue.dll - OK
C:\Windows\system32\activeds.dll - OK
C:\Windows\system32\activeds.tlb - OK
C:\Windows\system32\actxprxy.dll - OK
C:\Windows\system32\AdapterTroubleshooter.exe - OK
C:\Windows\system32\admparse.dll - OK
C:\Windows\system32\adprovider.dll - OK
C:\Windows\system32\adsldp.dll - OK
C:\Windows\system32\adsldpc.dll - OK
C:\Windows\system32\adsmsext.dll - OK
C:\Windows\system32\adsnt.dll - OK
C:\Windows\system32\adtschema.dll - OK
C:\Windows\system32\advapi32.dll - OK
C:\Windows\system32\advpack.dll - OK
C:\Windows\system32\aecache.dll - OK
C:\Windows\system32\aeevts.dll - OK
C:\Windows\system32\aeinv.dll - OK
C:\Windows\system32\aelupsvc.dll - OK
C:\Windows\system32\aepdu.dll - OK
C:\Windows\system32\aepic.dll - OK
C:\Windows\system32\aitagent.exe - OK
C:\Windows\system32\alg.exe - OK
C:\Windows\system32\AltTab.dll - OK
C:\Windows\system32\amcompat.tlb - OK
C:\Windows\system32\amstream.dll - OK
C:\Windows\system32\amxread.dll - OK
C:\Windows\system32\apds.dll - OK
C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-ums-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-security-lsalookup-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-security-sddl-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-service-core-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-service-management-l1-1-0.dll - OK
C:\Windows\system32\api-ms-win-service-management-l2-1-0.dll - OK
C:\Windows\system32\api-ms-win-service-winsvc-l1-1-0.dll - OK
C:\Windows\system32\apilogen.dll - OK
C:\Windows\system32\apircl.dll - OK
C:\Windows\system32\apisetschema.dll - OK
C:\Windows\system32\apphelp.dll - OK
C:\Windows\system32\Apphlpdm.dll - OK
C:\Windows\system32\appidapi.dll - OK
C:\Windows\system32\appidcertstorecheck.exe - OK
C:\Windows\system32\appidpolicyconverter.exe - OK
C:\Windows\system32\appidsvc.dll - OK
C:\Windows\system32\appinfo.dll - OK
C:\Windows\system32\appwiz.cpl - OK
C:\Windows\system32\apss.dll - OK
C:\Windows\system32\ARP.EXE - OK
C:\Windows\system32\asferror.dll - OK
C:\Windows\system32\asycfilt.dll - OK
C:\Windows\system32\at.exe - OK
C:\Windows\system32\AtBroker.exe - OK
C:\Windows\system32\atl.dll - OK
C:\Windows\system32\atmfd.dll - OK
C:\Windows\system32\atmlib.dll - OK
C:\Windows\system32\attrib.exe - OK
C:\Windows\system32\audiodg.exe - OK
C:\Windows\system32\AudioEng.dll - OK
C:\Windows\system32\AUDIOKSE.dll - OK
C:\Windows\system32\AudioSes.dll - OK
C:\Windows\system32\audiosrv.dll - OK
C:\Windows\system32\auditcse.dll - OK
C:\Windows\system32\auditpol.exe - OK
C:\Windows\system32\authfwcfg.dll - OK
C:\Windows\system32\AuthFWGP.dll - OK
C:\Windows\system32\AuthFWSnapin.dll - OK
C:\Windows\system32\AuthFWWizFwk.dll - OK
C:\Windows\system32\authui.dll packed by ZLIB
>C:\Windows\system32\authui.dll - archive BINARYRES
>>C:\Windows\system32\authui.dll/data001 - OK
>>C:\Windows\system32\authui.dll/data002 - OK
>>C:\Windows\system32\authui.dll/data003 - OK
>>C:\Windows\system32\authui.dll/data004 - OK
>C:\Windows\system32\authui.dll - OK
C:\Windows\system32\authz.dll - OK
C:\Windows\system32\autochk.exe - OK
C:\Windows\system32\autoconv.exe - OK
C:\Windows\system32\autofmt.exe - OK
C:\Windows\system32\autoplay.dll - OK
C:\Windows\system32\AuxiliaryDisplayApi.dll - OK
C:\Windows\system32\AuxiliaryDisplayClassInstaller.dll - OK
C:\Windows\system32\AuxiliaryDisplayCpl.dll - OK
C:\Windows\system32\AuxiliaryDisplayDriverLib.dll - OK
C:\Windows\system32\AuxiliaryDisplayServices.dll - OK
C:\Windows\system32\avgrssta.dll - OK
C:\Windows\system32\avicap32.dll - OK
C:\Windows\system32\avifil32.dll - OK
C:\Windows\system32\avrt.dll - OK
C:\Windows\system32\AxInstSv.dll - OK
C:\Windows\system32\AxInstUI.exe - OK
C:\Windows\system32\azman.msc - OK
C:\Windows\system32\azroles.dll - OK
C:\Windows\system32\azroleui.dll - OK
C:\Windows\system32\AzSqlExt.dll - OK
C:\Windows\system32\basecsp.dll - OK
C:\Windows\system32\basesrv.dll - OK
C:\Windows\system32\batmeter.dll - OK
C:\Windows\system32\batt.dll - OK
C:\Windows\system32\bcdboot.exe - OK
C:\Windows\system32\bcdedit.exe - OK
C:\Windows\system32\bcdprov.dll - OK
C:\Windows\system32\bcdsrv.dll - OK
C:\Windows\system32\bcrypt.dll - OK
C:\Windows\system32\bcryptprimitives.dll - OK
C:\Windows\system32\bdaplgin.ax - OK
C:\Windows\system32\bderepair.dll - OK
C:\Windows\system32\bdesvc.dll - OK
C:\Windows\system32\bdeui.dll - OK
C:\Windows\system32\BdeUISrv.exe - OK
C:\Windows\system32\BdeUnlockWizard.exe - OK
C:\Windows\system32\BFE.DLL - OK
C:\Windows\system32\bidispl.dll - OK
C:\Windows\system32\biocpl.dll - OK
C:\Windows\system32\BioCredProv.dll - OK
C:\Windows\system32\bitsadmin.exe - OK
C:\Windows\system32\bitsigd.dll - OK
C:\Windows\system32\bitsperf.dll - OK
C:\Windows\system32\bitsprx2.dll - OK
C:\Windows\system32\bitsprx3.dll - OK
C:\Windows\system32\bitsprx4.dll - OK
C:\Windows\system32\bitsprx5.dll - OK
C:\Windows\system32\bitsprx6.dll - OK
C:\Windows\system32\blackbox.dll - OK
C:\Windows\system32\BlbEvents.dll - OK
C:\Windows\system32\blbres.dll - OK
C:\Windows\system32\blb_ps.dll - OK
C:\Windows\system32\boot.sdi - OK
C:\Windows\system32\bootcfg.exe - OK
C:\Windows\system32\bootres.dll - OK
C:\Windows\system32\bootstr.dll - OK
C:\Windows\system32\BOOTVID.DLL - OK
C:\Windows\system32\bopomofo.uce - OK
C:\Windows\system32\brcoinst.dll packed by PESTUB
>C:\Windows\system32\brcoinst.dll - OK
C:\Windows\system32\brdgcfg.dll - OK
C:\Windows\system32\bridgeres.dll - OK
C:\Windows\system32\bridgeunattend.exe - OK
C:\Windows\system32\browcli.dll - OK
C:\Windows\system32\browser.dll - OK
C:\Windows\system32\browseui.dll - OK
C:\Windows\system32\bthci.dll - OK
C:\Windows\system32\BthMtpContextHandler.dll - OK
C:\Windows\system32\bthpanapi.dll - OK
C:\Windows\system32\BthpanContextHandler.dll - OK
C:\Windows\system32\bthprops.cpl - OK
C:\Windows\system32\bthserv.dll - OK
C:\Windows\system32\bthudtask.exe - OK
C:\Windows\system32\btpanui.dll - OK
C:\Windows\system32\Bubbles.scr - OK
C:\Windows\system32\BWContextHandler.dll - OK
C:\Windows\system32\BWUnpairElevated.dll - OK
C:\Windows\system32\cabinet.dll - OK
C:\Windows\system32\cabview.dll - OK
C:\Windows\system32\cacls.exe - OK
C:\Windows\system32\calc.exe packed by ZLIB
>C:\Windows\system32\calc.exe - archive BINARYRES
>>C:\Windows\system32\calc.exe/data001 - OK
>>C:\Windows\system32\calc.exe/data002 - OK
>>C:\Windows\system32\calc.exe/data003 - OK
>>C:\Windows\system32\calc.exe/data004 - OK
>>C:\Windows\system32\calc.exe/data005 - OK
>>C:\Windows\system32\calc.exe/data006 - OK
>C:\Windows\system32\calc.exe - OK
C:\Windows\system32\capiprovider.dll - OK
C:\Windows\system32\capisp.dll - OK
C:\Windows\system32\CardGames.dll - OK
C:\Windows\system32\catsrv.dll - OK
C:\Windows\system32\catsrvps.dll - OK
C:\Windows\system32\catsrvut.dll - OK
C:\Windows\system32\cca.dll - OK
C:\Windows\system32\cdd.dll - OK
C:\Windows\system32\cdosys.dll - archive BINARYRES
>C:\Windows\system32\cdosys.dll/data001 - OK
C:\Windows\system32\cdosys.dll - OK
C:\Windows\system32\cero.rs packed by ZLIB
>C:\Windows\system32\cero.rs - archive BINARYRES
>>C:\Windows\system32\cero.rs/data001 - OK
>C:\Windows\system32\cero.rs - OK
C:\Windows\system32\certcli.dll - OK
C:\Windows\system32\certCredProvider.dll - OK
C:\Windows\system32\certenc.dll - OK
C:\Windows\system32\CertEnroll.dll - OK
C:\Windows\system32\CertEnrollCtrl.exe - OK
C:\Windows\system32\CertEnrollUI.dll - OK
C:\Windows\system32\certmgr.dll - OK
C:\Windows\system32\certmgr.msc - OK
C:\Windows\system32\CertPolEng.dll - OK
C:\Windows\system32\certprop.dll - OK
C:\Windows\system32\certreq.exe - OK
C:\Windows\system32\certutil.exe - OK
C:\Windows\system32\cewmdm.dll - OK
C:\Windows\system32\cfgbkend.dll - OK
C:\Windows\system32\cfgmgr32.dll - OK
C:\Windows\system32\chajei.ime - OK
C:\Windows\system32\charmap.exe - OK
C:\Windows\system32\chcp.com - OK
C:\Windows\system32\chkdsk.exe - OK
C:\Windows\system32\chkntfs.exe - OK
C:\Windows\system32\chkwudrv.dll - OK
C:\Windows\system32\choice.exe - OK
C:\Windows\system32\chsbrkr.dll - OK
C:\Windows\system32\chtbrkr.dll - OK
C:\Windows\system32\CHxReadingStringIME.dll - OK
C:\Windows\system32\ci.dll - OK
C:\Windows\system32\cic.dll - OK
C:\Windows\system32\cintlgnt.ime - OK
C:\Windows\system32\cipher.exe - OK
C:\Windows\system32\CIRCoInst.dll - OK
C:\Windows\system32\clb.dll - OK
C:\Windows\system32\clbcatq.dll - OK
C:\Windows\system32\cleanmgr.exe - OK
C:\Windows\system32\clfs.sys - OK
C:\Windows\system32\clfsw32.dll - OK
C:\Windows\system32\cliconfg.dll - OK
C:\Windows\system32\cliconfg.exe - OK
C:\Windows\system32\cliconfg.rll - OK
C:\Windows\system32\clip.exe - OK
C:\Windows\system32\clusapi.dll - OK
C:\Windows\system32\cmcfg32.dll - OK
C:\Windows\system32\cmd.exe - OK
C:\Windows\system32\cmdial32.dll - OK
C:\Windows\system32\cmdkey.exe - OK
C:\Windows\system32\cmdl32.exe - OK
C:\Windows\system32\cmicryptinstall.dll - OK
C:\Windows\system32\cmifw.dll - OK
C:\Windows\system32\cmipnpinstall.dll - OK
C:\Windows\system32\cmlua.dll - OK
C:\Windows\system32\cmmon32.exe - OK
C:\Windows\system32\cmncliM.dll - OK
C:\Windows\system32\cmpbk32.dll - OK
C:\Windows\system32\cmstp.exe - OK
C:\Windows\system32\cmstplua.dll - OK
C:\Windows\system32\cmutil.dll - OK
C:\Windows\system32\cngaudit.dll - OK
C:\Windows\system32\cngprovider.dll - OK
C:\Windows\system32\cnvfat.dll - OK
C:\Windows\system32\cofire.exe - OK
C:\Windows\system32\cofiredm.dll - OK
C:\Windows\system32\colbact.dll - OK
C:\Windows\system32\collab.cpl - OK
C:\Windows\system32\COLORCNV.DLL - OK
C:\Windows\system32\colorcpl.exe - OK
C:\Windows\system32\colorui.dll - OK
C:\Windows\system32\comcat.dll - OK
C:\Windows\system32\comctl32.dll - OK
C:\Windows\system32\comdlg32.dll - OK
C:\Windows\system32\comexp.msc - OK
C:\Windows\system32\comp.exe - OK
C:\Windows\system32\compact.exe - OK
C:\Windows\system32\compmgmt.msc - OK
C:\Windows\system32\CompMgmtLauncher.exe - OK
C:\Windows\system32\compstui.dll - OK
C:\Windows\system32\ComputerDefaults.exe - OK
C:\Windows\system32\comrepl.dll - OK
C:\Windows\system32\comres.dll - OK
C:\Windows\system32\comsnap.dll - OK
C:\Windows\system32\comsvcs.dll - OK
C:\Windows\system32\comuid.dll - OK
C:\Windows\system32\conhost.exe - OK
C:\Windows\system32\connect.dll - OK
C:\Windows\system32\consent.exe - OK
C:\Windows\system32\console.dll - OK
C:\Windows\system32\control.exe - OK
C:\Windows\system32\convert.exe - OK
C:\Windows\system32\corpol.dll - OK
C:\Windows\system32\correngine.dll - OK
C:\Windows\system32\CPFilters.dll - OK
C:\Windows\system32\credssp.dll - OK
C:\Windows\system32\credui.dll - OK
C:\Windows\system32\credwiz.exe - OK
C:\Windows\system32\crypt32.dll - OK
C:\Windows\system32\cryptbase.dll - OK
C:\Windows\system32\cryptdlg.dll - OK
C:\Windows\system32\cryptdll.dll - OK
C:\Windows\system32\cryptext.dll - OK
C:\Windows\system32\cryptnet.dll - OK
C:\Windows\system32\cryptsp.dll - OK
C:\Windows\system32\cryptsvc.dll - OK
C:\Windows\system32\cryptui.dll - OK
C:\Windows\system32\cryptxml.dll - OK
C:\Windows\system32\cscapi.dll - OK
C:\Windows\system32\cscdll.dll - OK
C:\Windows\system32\cscript.exe - OK
C:\Windows\system32\csrr.rs - OK
C:\Windows\system32\csrsrv.dll - OK
C:\Windows\system32\csrss.exe - OK
C:\Windows\system32\ctfmon.exe - OK
C:\Windows\system32\cttune.exe - OK
C:\Windows\system32\cttunesvr.exe - OK
C:\Windows\system32\C_037.NLS - OK
C:\Windows\system32\C_10000.NLS - OK
C:\Windows\system32\C_10001.NLS - OK
C:\Windows\system32\C_10002.NLS - OK
C:\Windows\system32\C_10003.NLS - OK
C:\Windows\system32\C_10004.NLS - OK
C:\Windows\system32\C_10005.NLS - OK
C:\Windows\system32\C_10006.NLS - OK
C:\Windows\system32\C_10007.NLS - OK
C:\Windows\system32\C_10008.NLS - OK
C:\Windows\system32\C_10010.NLS - OK
C:\Windows\system32\C_10017.NLS - OK
C:\Windows\system32\C_10021.NLS - OK
C:\Windows\system32\C_10029.NLS - OK
C:\Windows\system32\C_10079.NLS - OK
C:\Windows\system32\C_10081.NLS - OK
C:\Windows\system32\C_10082.NLS - OK
C:\Windows\system32\C_1026.NLS - OK
C:\Windows\system32\C_1047.NLS - OK
C:\Windows\system32\C_1140.NLS - OK
C:\Windows\system32\C_1141.NLS - OK
C:\Windows\system32\C_1142.NLS - OK
C:\Windows\system32\C_1143.NLS - OK
C:\Windows\system32\C_1144.NLS - OK
C:\Windows\system32\C_1145.NLS - OK
C:\Windows\system32\C_1146.NLS - OK
C:\Windows\system32\C_1147.NLS - OK
C:\Windows\system32\C_1148.NLS - OK
C:\Windows\system32\C_1149.NLS - OK
C:\Windows\system32\C_1250.NLS - OK
C:\Windows\system32\C_1251.NLS - OK
C:\Windows\system32\C_1252.NLS - OK
C:\Windows\system32\C_1253.NLS - OK
C:\Windows\system32\C_1254.NLS - OK
C:\Windows\system32\C_1255.NLS - OK
C:\Windows\system32\C_1256.NLS - OK
C:\Windows\system32\C_1257.NLS - OK
C:\Windows\system32\C_1258.NLS - OK
C:\Windows\system32\C_1361.NLS - OK
C:\Windows\system32\C_20000.NLS - OK
C:\Windows\system32\C_20001.NLS - OK
C:\Windows\system32\C_20002.NLS - OK
C:\Windows\system32\C_20003.NLS - OK
C:\Windows\system32\C_20004.NLS - OK
C:\Windows\system32\C_20005.NLS - OK
C:\Windows\system32\C_20105.NLS - OK
C:\Windows\system32\C_20106.NLS - OK
C:\Windows\system32\C_20107.NLS - OK
C:\Windows\system32\C_20108.NLS - OK
C:\Windows\system32\C_20127.NLS - OK
C:\Windows\system32\C_20261.NLS - OK
C:\Windows\system32\C_20269.NLS - OK
C:\Windows\system32\C_20273.NLS - OK
C:\Windows\system32\C_20277.NLS - OK
C:\Windows\system32\C_20278.NLS - OK
C:\Windows\system32\C_20280.NLS - OK
C:\Windows\system32\C_20284.NLS - OK
C:\Windows\system32\C_20285.NLS - OK
C:\Windows\system32\C_20290.NLS - OK
C:\Windows\system32\C_20297.NLS - OK
C:\Windows\system32\C_20420.NLS - OK
C:\Windows\system32\C_20423.NLS - OK
C:\Windows\system32\C_20424.NLS - OK
C:\Windows\system32\C_20833.NLS - OK
C:\Windows\system32\C_20838.NLS - OK
C:\Windows\system32\C_20866.NLS - OK
C:\Windows\system32\C_20871.NLS - OK
C:\Windows\system32\C_20880.NLS - OK
C:\Windows\system32\C_20905.NLS - OK
C:\Windows\system32\C_20924.NLS - OK
C:\Windows\system32\C_20932.NLS - OK
C:\Windows\system32\C_20936.NLS - OK
C:\Windows\system32\C_20949.NLS - OK
C:\Windows\system32\C_21025.NLS - OK
C:\Windows\system32\C_21027.NLS - OK
C:\Windows\system32\C_21866.NLS - OK
C:\Windows\system32\C_28591.NLS - OK
C:\Windows\system32\C_28592.NLS - OK
C:\Windows\system32\C_28593.NLS - OK
C:\Windows\system32\C_28594.NLS - OK
C:\Windows\system32\C_28595.NLS - OK
C:\Windows\system32\C_28596.NLS - OK
C:\Windows\system32\C_28597.NLS - OK
C:\Windows\system32\C_28598.NLS - OK
C:\Windows\system32\C_28599.NLS - OK
C:\Windows\system32\c_28603.nls - OK
C:\Windows\system32\C_28605.NLS - OK
C:\Windows\system32\C_437.NLS - OK
C:\Windows\system32\C_500.NLS - OK
C:\Windows\system32\C_708.NLS - OK
C:\Windows\system32\C_720.NLS - OK
C:\Windows\system32\C_737.NLS - OK
C:\Windows\system32\C_775.NLS - OK
C:\Windows\system32\C_850.NLS - OK
C:\Windows\system32\C_852.NLS - OK
C:\Windows\system32\C_855.NLS - OK
C:\Windows\system32\C_857.NLS - OK
C:\Windows\system32\C_858.NLS - OK
C:\Windows\system32\C_860.NLS - OK
C:\Windows\system32\C_861.NLS - OK
C:\Windows\system32\C_862.NLS - OK
C:\Windows\system32\C_863.NLS - OK
C:\Windows\system32\C_864.NLS - OK
C:\Windows\system32\C_865.NLS - OK
C:\Windows\system32\C_866.NLS - OK
C:\Windows\system32\C_869.NLS - OK
C:\Windows\system32\C_870.NLS - OK
C:\Windows\system32\C_874.NLS - OK
C:\Windows\system32\C_875.NLS - OK
C:\Windows\system32\C_932.NLS - OK
C:\Windows\system32\C_936.NLS - OK
C:\Windows\system32\C_949.NLS - OK
C:\Windows\system32\C_950.NLS - OK
C:\Windows\system32\C_G18030.DLL - OK
C:\Windows\system32\C_IS2022.DLL - OK
C:\Windows\system32\C_ISCII.DLL - OK
C:\Windows\system32\d2d1.dll - OK
C:\Windows\system32\d3d10.dll - OK
C:\Windows\system32\d3d10core.dll - OK
C:\Windows\system32\d3d10level9.dll - OK
C:\Windows\system32\d3d10warp.dll - OK
C:\Windows\system32\d3d10_1.dll - OK
C:\Windows\system32\d3d10_1core.dll - OK
C:\Windows\system32\d3d11.dll - OK
C:\Windows\system32\d3d8thk.dll - OK
C:\Windows\system32\d3d9.dll - OK
C:\Windows\system32\d3dx10_42.dll - OK
C:\Windows\system32\d3dx9_24.dll - OK
C:\Windows\system32\d3dx9_25.dll - OK
C:\Windows\system32\d3dx9_26.dll - OK
C:\Windows\system32\d3dx9_27.dll - OK
C:\Windows\system32\d3dx9_28.dll - OK
C:\Windows\system32\d3dx9_29.dll - OK
C:\Windows\system32\d3dx9_30.dll - OK
C:\Windows\system32\d3dx9_32.dll - OK
C:\Windows\system32\dataclen.dll - OK
C:\Windows\system32\davclnt.dll - OK
C:\Windows\system32\davhlpr.dll - OK
C:\Windows\system32\dbgeng.dll - OK
C:\Windows\system32\dbghelp.dll - OK
C:\Windows\system32\dbnetlib.dll - OK
C:\Windows\system32\dbnmpntw.dll - OK
C:\Windows\system32\dccw.exe - OK
C:\Windows\system32\dciman32.dll - OK
C:\Windows\system32\dcomcnfg.exe - OK
C:\Windows\system32\DDACLSys.dll - OK
C:\Windows\system32\ddodiag.exe - OK
C:\Windows\system32\DDOIProxy.dll - OK
C:\Windows\system32\DDORes.dll - OK
C:\Windows\system32\ddraw.dll - OK
C:\Windows\system32\ddrawex.dll - OK
C:\Windows\system32\defaultlocationcpl.dll - OK
C:\Windows\system32\Defrag.exe - OK
C:\Windows\system32\defragproxy.dll - OK
C:\Windows\system32\defragsvc.dll - OK
C:\Windows\system32\desk.cpl - OK
C:\Windows\system32\deskadp.dll - OK
C:\Windows\system32\deskmon.dll - OK
C:\Windows\system32\deskperf.dll - OK
C:\Windows\system32\desktop.ini - OK
C:\Windows\system32\devenum.dll - OK
C:\Windows\system32\DeviceCenter.dll - OK
C:\Windows\system32\DeviceDisplayObjectProvider.exe - OK
C:\Windows\system32\DeviceDisplayStatusManager.dll - OK
C:\Windows\system32\DeviceEject.exe - OK
C:\Windows\system32\DeviceMetadataParsers.dll - OK
C:\Windows\system32\DevicePairing.dll - OK
C:\Windows\system32\DevicePairingFolder.dll - OK
C:\Windows\system32\DevicePairingHandler.dll - OK
C:\Windows\system32\DevicePairingProxy.dll - OK
C:\Windows\system32\DevicePairingWizard.exe - OK
C:\Windows\system32\DeviceProperties.exe - OK
C:\Windows\system32\DeviceUxRes.dll - OK
C:\Windows\system32\devmgmt.msc - OK
C:\Windows\system32\devmgr.dll - OK
C:\Windows\system32\devobj.dll - OK
C:\Windows\system32\devrtl.dll - OK
C:\Windows\system32\dfdts.dll - OK
C:\Windows\system32\DFDWiz.exe - OK
C:\Windows\system32\dfrgui.exe packed by ZLIB
>C:\Windows\system32\dfrgui.exe - archive BINARYRES
>>C:\Windows\system32\dfrgui.exe/data001 - OK
>>C:\Windows\system32\dfrgui.exe/data002 - OK
>C:\Windows\system32\dfrgui.exe - OK
C:\Windows\system32\dfscli.dll - OK
C:\Windows\system32\dfshim.dll - OK
C:\Windows\system32\DfsShlEx.dll - OK
C:\Windows\system32\dhcpcmonitor.dll - OK
C:\Windows\system32\dhcpcore.dll - OK
C:\Windows\system32\dhcpcore6.dll - OK
C:\Windows\system32\dhcpcsvc.dll - OK
C:\Windows\system32\dhcpcsvc6.dll - OK
C:\Windows\system32\DHCPQEC.DLL - OK
C:\Windows\system32\dhcpsapi.dll - OK
C:\Windows\system32\DiagCpl.dll - OK
C:\Windows\system32\diagperf.dll - OK
C:\Windows\system32\dialer.exe - OK
C:\Windows\system32\diantz.exe - OK
C:\Windows\system32\difx64.exe - OK
C:\Windows\system32\difxapi.dll - OK
C:\Windows\system32\dimsjob.dll - OK
C:\Windows\system32\dimsroam.dll - OK
C:\Windows\system32\dinotify.exe - OK
C:\Windows\system32\dinput.dll - OK
C:\Windows\system32\dinput8.dll - OK
C:\Windows\system32\diskcomp.com - OK
C:\Windows\system32\diskcopy.com - OK
C:\Windows\system32\diskcopy.dll - OK
C:\Windows\system32\diskmgmt.msc - OK
C:\Windows\system32\diskpart.exe - OK
C:\Windows\system32\diskperf.exe - OK
C:\Windows\system32\diskraid.exe - OK
C:\Windows\system32\Dism.exe - OK
C:\Windows\system32\dispci.dll - OK
C:\Windows\system32\dispdiag.exe - OK
C:\Windows\system32\dispex.dll - OK
C:\Windows\system32\Display.dll - OK
C:\Windows\system32\DisplaySwitch.exe - OK
C:\Windows\system32\djoin.exe - OK
C:\Windows\system32\dllhost.exe - OK
C:\Windows\system32\dllhst3g.exe - OK
C:\Windows\system32\dmdlgs.dll - OK
C:\Windows\system32\dmdskmgr.dll - OK
C:\Windows\system32\dmdskres.dll - OK
C:\Windows\system32\dmdskres2.dll - OK
C:\Windows\system32\dmintf.dll - OK
C:\Windows\system32\dmloader.dll - OK
C:\Windows\system32\dmocx.dll - OK
C:\Windows\system32\dmrc.dll - OK
C:\Windows\system32\dmsynth.dll - OK
C:\Windows\system32\dmusic.dll - OK
C:\Windows\system32\dmutil.dll - OK
C:\Windows\system32\dmvdsitf.dll - OK
C:\Windows\system32\dmview.ocx - OK
C:\Windows\system32\dnsapi.dll - OK
C:\Windows\system32\dnscacheugc.exe - OK
C:\Windows\system32\dnscmmc.dll - OK
C:\Windows\system32\dnsext.dll - OK
C:\Windows\system32\dnshc.dll - OK
C:\Windows\system32\dnsrslvr.dll - OK
C:\Windows\system32\docprop.dll - OK
C:\Windows\system32\DocumentPerformanceEvents.dll - OK
C:\Windows\system32\doskey.exe - OK
C:\Windows\system32\dot3api.dll - OK
C:\Windows\system32\dot3cfg.dll - OK
C:\Windows\system32\dot3dlg.dll - OK
C:\Windows\system32\dot3gpclnt.dll - OK
C:\Windows\system32\dot3gpui.dll - OK
C:\Windows\system32\dot3hc.dll - OK
C:\Windows\system32\dot3msm.dll - OK
C:\Windows\system32\dot3svc.dll - OK
C:\Windows\system32\dot3ui.dll - OK
C:\Windows\system32\dpapimig.exe - OK
C:\Windows\system32\dpapiprovider.dll - OK
C:\Windows\system32\DpiScaling.exe - OK
C:\Windows\system32\dpnaddr.dll - OK
C:\Windows\system32\dpnathlp.dll - OK
C:\Windows\system32\dpnet.dll - OK
C:\Windows\system32\dpnhpast.dll - OK
C:\Windows\system32\dpnhupnp.dll - OK
C:\Windows\system32\dpnlobby.dll - OK
C:\Windows\system32\dpnsvr.exe - OK
C:\Windows\system32\dps.dll - OK
C:\Windows\system32\dpx.dll - OK
C:\Windows\system32\driverquery.exe - OK
C:\Windows\system32\drmmgrtn.dll - OK
C:\Windows\system32\drmv2clt.dll - archive BINARYRES
>C:\Windows\system32\drmv2clt.dll/data001 - archive HTML
>>C:\Windows\system32\drmv2clt.dll/data001/JavaScript.0 - OK
>C:\Windows\system32\drmv2clt.dll/data001 - OK
C:\Windows\system32\drmv2clt.dll - OK
C:\Windows\system32\drprov.dll - OK
C:\Windows\system32\drt.dll - OK
C:\Windows\system32\drtprov.dll - OK
C:\Windows\system32\drttransport.dll - OK
C:\Windows\system32\drvinst.exe - OK
C:\Windows\system32\drvstore.dll packed by BINARYRES
>C:\Windows\system32\drvstore.dll packed by MS COMPRESS
>>C:\Windows\system32\drvstore.dll - OK
C:\Windows\system32\ds32gt.dll - OK
C:\Windows\system32\dsauth.dll - OK
C:\Windows\system32\dsdmo.dll - OK
C:\Windows\system32\DShowRdpFilter.dll - OK
C:\Windows\system32\dskquota.dll - OK
C:\Windows\system32\dskquoui.dll - OK
C:\Windows\system32\dsound.dll - OK
C:\Windows\system32\dsprop.dll - OK
C:\Windows\system32\dsquery.dll - OK
C:\Windows\system32\dsrole.dll - OK
C:\Windows\system32\dssec.dat - OK
C:\Windows\system32\dssec.dll - OK
C:\Windows\system32\dssenh.dll - OK
C:\Windows\system32\dsuiext.dll - OK
C:\Windows\system32\dswave.dll - OK
C:\Windows\system32\dtsh.dll - OK
C:\Windows\system32\dui70.dll - OK
C:\Windows\system32\duser.dll - OK
C:\Windows\system32\dvdplay.exe - OK
C:\Windows\system32\dvdupgrd.exe - OK
C:\Windows\system32\dwm.exe - OK
C:\Windows\system32\dwmapi.dll - OK
C:\Windows\system32\dwmcore.dll - OK
C:\Windows\system32\dwmredir.dll - OK
C:\Windows\system32\DWrite.dll - OK
C:\Windows\system32\DWWIN.EXE - OK
C:\Windows\system32\dxdiag.exe - OK
C:\Windows\system32\dxdiagn.dll - OK
C:\Windows\system32\dxgi.dll - OK
C:\Windows\system32\dxmasf.dll - OK
C:\Windows\system32\DXP.dll - OK
C:\Windows\system32\dxpps.dll - OK
C:\Windows\system32\Dxpserver.exe - OK
C:\Windows\system32\DXPTaskRingtone.dll - OK
C:\Windows\system32\DxpTaskSync.dll - OK
C:\Windows\system32\dxtmsft.dll - OK
C:\Windows\system32\dxtrans.dll - OK
C:\Windows\system32\dxva2.dll - OK
C:\Windows\system32\Eap3Host.exe - OK
C:\Windows\system32\eapp3hst.dll - OK
C:\Windows\system32\eappcfg.dll - OK
C:\Windows\system32\eappgnui.dll - OK
C:\Windows\system32\eapphost.dll - OK
C:\Windows\system32\eappprxy.dll - OK
C:\Windows\system32\EAPQEC.DLL - OK
C:\Windows\system32\eapsvc.dll - OK
C:\Windows\system32\efsadu.dll - OK
C:\Windows\system32\efscore.dll - OK
C:\Windows\system32\efslsaext.dll - OK
C:\Windows\system32\efssvc.dll - OK
C:\Windows\system32\efsui.exe - OK
C:\Windows\system32\efsutil.dll - OK
C:\Windows\system32\EhStorAPI.dll - OK
C:\Windows\system32\EhStorAuthn.exe - OK
C:\Windows\system32\EhStorPwdMgr.dll - OK
C:\Windows\system32\EhStorShell.dll - OK
C:\Windows\system32\els.dll - OK
C:\Windows\system32\ELSCore.dll - OK
C:\Windows\system32\elslad.dll - OK
C:\Windows\system32\elsTrans.dll - OK
C:\Windows\system32\encapi.dll - OK
C:\Windows\system32\EncDec.dll - OK
C:\Windows\system32\EncDump.dll - OK
C:\Windows\system32\energy.dll - OK
C:\Windows\system32\eqossnap.dll - OK
C:\Windows\system32\es.dll - OK
C:\Windows\system32\esent.dll - OK
C:\Windows\system32\esentprf.dll - OK
C:\Windows\system32\esentutl.exe - OK
C:\Windows\system32\esrb.rs packed by ZLIB
>C:\Windows\system32\esrb.rs - archive BINARYRES
>>C:\Windows\system32\esrb.rs/data001 - OK
>C:\Windows\system32\esrb.rs - OK
C:\Windows\system32\eudcedit.exe - OK
C:\Windows\system32\eventcls.dll - OK
C:\Windows\system32\eventcreate.exe - OK
C:\Windows\system32\EventViewer_EventDetails.xsl - archive HTML
>C:\Windows\system32\EventViewer_EventDetails.xsl/Script.0 - OK
C:\Windows\system32\EventViewer_EventDetails.xsl - OK
C:\Windows\system32\eventvwr.exe - OK
C:\Windows\system32\eventvwr.msc - OK
C:\Windows\system32\evr.dll - OK
C:\Windows\system32\expand.exe packed by BINARYRES
>C:\Windows\system32\expand.exe packed by MS COMPRESS
>>C:\Windows\system32\expand.exe - OK
C:\Windows\system32\ExplorerFrame.dll - OK
C:\Windows\system32\extrac32.exe - OK
C:\Windows\system32\f3ahvoas.dll - OK
C:\Windows\system32\Faultrep.dll - OK
C:\Windows\system32\fc.exe - OK
C:\Windows\system32\fdBth.dll - OK
C:\Windows\system32\fdBthProxy.dll - OK
C:\Windows\system32\fde.dll - OK
C:\Windows\system32\fdeploy.dll - OK
C:\Windows\system32\fdPHost.dll - OK
C:\Windows\system32\fdPnp.dll - OK
C:\Windows\system32\fdprint.dll - OK
C:\Windows\system32\fdProxy.dll - OK
C:\Windows\system32\FDResPub.dll - OK
C:\Windows\system32\fdSSDP.dll - OK
C:\Windows\system32\fdWCN.dll - OK
C:\Windows\system32\fdWNet.dll - OK
C:\Windows\system32\fdWSD.dll - OK
C:\Windows\system32\feclient.dll - OK
C:\Windows\system32\filemgmt.dll - OK
C:\Windows\system32\find.exe - OK
C:\Windows\system32\findnetprinters.dll - OK
C:\Windows\system32\findstr.exe - OK
C:\Windows\system32\finger.exe - OK
C:\Windows\system32\Firewall.cpl - OK
C:\Windows\system32\FirewallAPI.dll - OK
C:\Windows\system32\FirewallControlPanel.dll - OK
C:\Windows\system32\fixmapi.exe - OK
C:\Windows\system32\fltLib.dll - OK
C:\Windows\system32\fltMC.exe - OK
C:\Windows\system32\fmifs.dll - OK
C:\Windows\system32\fms.dll - OK
C:\Windows\system32\FNTCACHE.DAT - OK
C:\Windows\system32\FntCache.dll - OK
C:\Windows\system32\fontext.dll packed by BINARYRES
>C:\Windows\system32\fontext.dll packed by MS COMPRESS
>>C:\Windows\system32\fontext.dll - OK
C:\Windows\system32\fontsub.dll - OK
C:\Windows\system32\fontview.exe - OK
C:\Windows\system32\forfiles.exe - OK
C:\Windows\system32\format.com - OK
C:\Windows\system32\fphc.dll - OK
C:\Windows\system32\framebuf.dll - OK
C:\Windows\system32\framedyn.dll - OK
C:\Windows\system32\framedynos.dll - OK
C:\Windows\system32\fsmgmt.msc - OK
C:\Windows\system32\fsutil.exe - OK
C:\Windows\system32\fthsvc.dll - OK
C:\Windows\system32\ftp.exe - OK
C:\Windows\system32\fundisc.dll - OK
C:\Windows\system32\fveapi.dll - OK
C:\Windows\system32\fveapibase.dll - OK
C:\Windows\system32\fvecerts.dll - OK
C:\Windows\system32\fvenotify.exe - OK
C:\Windows\system32\fveprompt.exe - OK
C:\Windows\system32\fveRecover.dll - OK
C:\Windows\system32\fveui.dll - OK
C:\Windows\system32\fwcfg.dll - OK
C:\Windows\system32\FWPUCLNT.DLL - OK
C:\Windows\system32\FwRemoteSvr.dll - OK
C:\Windows\system32\FXSAPI.dll - OK
C:\Windows\system32\FXSCOM.dll - OK
C:\Windows\system32\FXSCOMEX.dll - OK
C:\Windows\system32\FXSCOMPOSE.dll - OK
C:\Windows\system32\FXSCOMPOSERES.dll - OK
C:\Windows\system32\FXSCOVER.exe - OK
C:\Windows\system32\FXSEVENT.dll - OK
C:\Windows\system32\FXSMON.dll - OK
C:\Windows\system32\FXSRESM.dll - OK
C:\Windows\system32\FXSROUTE.dll - OK
C:\Windows\system32\FXSST.dll - OK
C:\Windows\system32\FXSSVC.exe - OK
C:\Windows\system32\FXST30.dll - OK
C:\Windows\system32\FXSTIFF.dll - OK
C:\Windows\system32\FXSUNATD.exe - OK
C:\Windows\system32\FXSUTILITY.dll - OK
C:\Windows\system32\g711codc.ax - OK
C:\Windows\system32\gacinstall.dll - OK
C:\Windows\system32\gameux.dll - OK
C:\Windows\system32\GameUXLegacyGDFs.dll - OK
C:\Windows\system32\gatherNetworkInfo.vbs - OK
C:\Windows\system32\gb2312.uce - OK
C:\Windows\system32\gcdef.dll - OK
C:\Windows\system32\gdi32.dll - OK
C:\Windows\system32\getmac.exe - OK
C:\Windows\system32\GettingStarted.exe - OK
C:\Windows\system32\getuname.dll - OK
C:\Windows\system32\Gfxres.ar-SA.resources - OK
C:\Windows\system32\Gfxres.cs-CZ.resources - OK
C:\Windows\system32\Gfxres.da-DK.resources - OK
C:\Windows\system32\Gfxres.de-DE.resources - OK
C:\Windows\system32\Gfxres.el-GR.resources - OK
C:\Windows\system32\Gfxres.en-US.resources - OK
C:\Windows\system32\Gfxres.es-ES.resources - OK
C:\Windows\system32\Gfxres.fi-FI.resources - OK
C:\Windows\system32\Gfxres.fr-FR.resources - OK
C:\Windows\system32\Gfxres.he-IL.resources - OK
C:\Windows\system32\Gfxres.hu-HU.resources - OK
C:\Windows\system32\Gfxres.it-IT.resources - OK
C:\Windows\system32\Gfxres.ja-JP.resources - OK
C:\Windows\system32\Gfxres.ko-KR.resources - OK
C:\Windows\system32\Gfxres.nb-NO.resources - OK
C:\Windows\system32\Gfxres.nl-NL.resources - OK
C:\Windows\system32\Gfxres.pl-PL.resources - OK
C:\Windows\system32\Gfxres.pt-BR.resources - OK
C:\Windows\system32\Gfxres.pt-PT.resources - OK
C:\Windows\system32\Gfxres.ru-RU.resources - OK
C:\Windows\system32\Gfxres.sk-SK.resources - OK
C:\Windows\system32\Gfxres.sl-SI.resources - OK
C:\Windows\system32\Gfxres.sv-SE.resources - OK
C:\Windows\system32\Gfxres.th-TH.resources - OK
C:\Windows\system32\Gfxres.tr-TR.resources - OK
C:\Windows\system32\Gfxres.zh-CN.resources - OK
C:\Windows\system32\Gfxres.zh-TW.resources - OK
C:\Windows\system32\gfxSrvc.dll - OK
C:\Windows\system32\GfxUI.exe - OK
C:\Windows\system32\GfxUI.exe.config - OK
C:\Windows\system32\glmf32.dll - OK
C:\Windows\system32\glu32.dll - OK
C:\Windows\system32\gpapi.dll - OK
C:\Windows\system32\gpedit.dll - OK
C:\Windows\system32\gpprnext.dll - OK
C:\Windows\system32\gpresult.exe - OK
C:\Windows\system32\gpsvc.dll - OK
C:\Windows\system32\gptext.dll - OK
C:\Windows\system32\gpupdate.exe - OK
C:\Windows\system32\grb.rs packed by ZLIB
>C:\Windows\system32\grb.rs - archive BINARYRES
>>C:\Windows\system32\grb.rs/data001 - OK
>>C:\Windows\system32\grb.rs/data002 - OK
>>C:\Windows\system32\grb.rs/data003 - OK
>>C:\Windows\system32\grb.rs/data004 - OK
>C:\Windows\system32\grb.rs - OK
C:\Windows\system32\Groupinghc.dll - OK
C:\Windows\system32\grpconv.exe - OK
C:\Windows\system32\hal.dll - OK
C:\Windows\system32\hbaapi.dll - OK
C:\Windows\system32\hccutils.dll - OK
C:\Windows\system32\hcproviders.dll - OK
C:\Windows\system32\hdwwiz.cpl - OK
C:\Windows\system32\hdwwiz.exe - OK
C:\Windows\system32\help.exe - OK
C:\Windows\system32\HelpPaneProxy.dll - OK
C:\Windows\system32\hgcpl.dll - OK
C:\Windows\system32\hgprint.dll - OK
C:\Windows\system32\hhctrl.ocx - OK
C:\Windows\system32\hhsetup.dll - OK
C:\Windows\system32\hid.dll - OK
C:\Windows\system32\hidphone.tsp - OK
C:\Windows\system32\hidserv.dll - OK
C:\Windows\system32\hkcmd.exe - OK
C:\Windows\system32\hlink.dll - OK
C:\Windows\system32\hnetcfg.dll - OK
C:\Windows\system32\hnetmon.dll - OK
C:\Windows\system32\HOSTNAME.EXE - OK
C:\Windows\system32\hotplug.dll - OK
C:\Windows\system32\HotStartUserAgent.dll - OK
C:\Windows\system32\hpbmiapi.dll - OK
C:\Windows\system32\hpboid.dll - OK
C:\Windows\system32\hpboidps.dll - OK
C:\Windows\system32\hpbpro.dll - OK
C:\Windows\system32\hpbprops.dll - OK
C:\Windows\system32\hplbdchn.dll - OK
C:\Windows\system32\hpotscl1.dll - OK
C:\Windows\system32\hpovst01.dll - OK
C:\Windows\system32\hpowiav1.dll - OK
C:\Windows\system32\HPZidr12.dll - OK
C:\Windows\system32\hpzids40.dll - OK
C:\Windows\system32\HPZinw12.dll - OK
C:\Windows\system32\HPZipm12.dll - OK
C:\Windows\system32\HPZipr12.dll - OK
C:\Windows\system32\hpzipt12.dll - OK
C:\Windows\system32\hpzisn12.dll - OK
C:\Windows\system32\HPZLLWN7.DLL - OK
C:\Windows\system32\html.iec - OK
C:\Windows\system32\httpapi.dll - OK
C:\Windows\system32\htui.dll - OK
C:\Windows\system32\hwrcomp.exe - OK
C:\Windows\system32\hwrreg.exe - OK
C:\Windows\system32\ias.dll - OK
C:\Windows\system32\iasacct.dll - OK
C:\Windows\system32\iasads.dll - OK
C:\Windows\system32\iasdatastore.dll - OK
C:\Windows\system32\iashlpr.dll - OK
C:\Windows\system32\IasMigPlugin.dll - archive BINARYRES
>C:\Windows\system32\IasMigPlugin.dll/data001 - OK
C:\Windows\system32\IasMigPlugin.dll - OK
C:\Windows\system32\iasnap.dll - OK
C:\Windows\system32\iaspolcy.dll - OK
C:\Windows\system32\iasrad.dll - OK
C:\Windows\system32\iasrecst.dll - OK
C:\Windows\system32\iassam.dll - OK
C:\Windows\system32\iassdo.dll - OK
C:\Windows\system32\iassvcs.dll - OK
C:\Windows\system32\icaapi.dll - OK
C:\Windows\system32\icacls.exe - OK
C:\Windows\system32\icardagt.exe - OK
C:\Windows\system32\icardie.dll - OK
C:\Windows\system32\icardres.dll - OK
C:\Windows\system32\icfupgd.dll - OK
C:\Windows\system32\icm32.dll - OK
C:\Windows\system32\icmp.dll - OK
C:\Windows\system32\icmui.dll - OK
C:\Windows\system32\IconCodecService.dll - OK
C:\Windows\system32\icrav03.rat - OK
C:\Windows\system32\icsigd.dll - OK
C:\Windows\system32\icsunattend.exe - OK
C:\Windows\system32\ideograf.uce - OK
C:\Windows\system32\IdListen.dll - OK
C:\Windows\system32\idndl.dll - OK
C:\Windows\system32\IDStore.dll - OK
C:\Windows\system32\ie4uinit.exe - OK
C:\Windows\system32\ieakeng.dll - OK
C:\Windows\system32\ieaksie.dll - OK
C:\Windows\system32\ieakui.dll - OK
C:\Windows\system32\ieapfltr.dat - OK
C:\Windows\system32\ieapfltr.dll - OK
C:\Windows\system32\iedkcs32.dll - OK
C:\Windows\system32\ieframe.dll - OK
C:\Windows\system32\iepeers.dll - OK
C:\Windows\system32\iernonce.dll - OK
C:\Windows\system32\iertutil.dll - OK
C:\Windows\system32\iesetup.dll - OK
C:\Windows\system32\iesysprep.dll - OK
C:\Windows\system32\ieui.dll - OK
C:\Windows\system32\ieuinit.inf - OK
C:\Windows\system32\ieUnatt.exe - OK
C:\Windows\system32\iexpress.exe - OK
C:\Windows\system32\ifmon.dll - OK
C:\Windows\system32\ifsutil.dll - OK
C:\Windows\system32\ifsutilx.dll - OK
C:\Windows\system32\ig4dev64.dll - OK
C:\Windows\system32\ig4icd64.dll - OK
C:\Windows\system32\igcompkrng500.bin - OK
C:\Windows\system32\igd10umd64.dll - OK
C:\Windows\system32\igdDiag.dll - OK
C:\Windows\system32\igdumd64.dll - OK
C:\Windows\system32\igfcg500.bin - OK
C:\Windows\system32\igfcg500m.bin - OK
C:\Windows\system32\igfxcfg.exe - OK
C:\Windows\system32\igfxCoIn_v1872.dll - OK
C:\Windows\system32\igfxCoIn_v2082.dll - OK
C:\Windows\system32\igfxCoIn_v2202.dll - OK
C:\Windows\system32\igfxCoIn_v2302.dll - OK
C:\Windows\system32\igfxcpl.cpl - OK
C:\Windows\system32\igfxdev.dll - OK
C:\Windows\system32\IGFXDEVLib.dll - OK
C:\Windows\system32\igfxdo.dll - OK
C:\Windows\system32\igfxexps.dll - OK
C:\Windows\system32\igfxext.exe - OK
C:\Windows\system32\igfxpers.exe - OK
C:\Windows\system32\igfxpph.dll - OK
C:\Windows\system32\igfxrara.lrc - OK
C:\Windows\system32\igfxrchs.lrc - OK
C:\Windows\system32\igfxrcht.lrc - OK
C:\Windows\system32\igfxrcsy.lrc - OK
C:\Windows\system32\igfxrdan.lrc - OK
C:\Windows\system32\igfxrdeu.lrc - OK
C:\Windows\system32\igfxrell.lrc - OK
C:\Windows\system32\igfxrenu.lrc - OK
C:\Windows\system32\igfxresn.lrc - OK
C:\Windows\system32\igfxresp.lrc - OK
C:\Windows\system32\igfxress.dll - OK
C:\Windows\system32\igfxrfin.lrc - OK
C:\Windows\system32\igfxrfra.lrc - OK
C:\Windows\system32\igfxrheb.lrc - OK
C:\Windows\system32\igfxrhun.lrc - OK
C:\Windows\system32\igfxrita.lrc - OK
C:\Windows\system32\igfxrjpn.lrc - OK
C:\Windows\system32\igfxrkor.lrc - OK
C:\Windows\system32\igfxrnld.lrc - OK
C:\Windows\system32\igfxrnor.lrc - OK
C:\Windows\system32\igfxrplk.lrc - OK
C:\Windows\system32\igfxrptb.lrc - OK
C:\Windows\system32\igfxrptg.lrc - OK
C:\Windows\system32\igfxrrus.lrc - OK
C:\Windows\system32\igfxrsky.lrc - OK
C:\Windows\system32\igfxrslv.lrc - OK
C:\Windows\system32\igfxrsve.lrc - OK
C:\Windows\system32\igfxrtha.lrc - OK
C:\Windows\system32\igfxrtrk.lrc - OK
C:\Windows\system32\igfxsrvc.dll - OK
C:\Windows\system32\igfxsrvc.exe - OK
C:\Windows\system32\igfxTMM.dll - OK
C:\Windows\system32\igfxtray.exe - OK
C:\Windows\system32\igkrng500.bin - OK
C:\Windows\system32\iglhcp64.dll - OK
C:\Windows\system32\iglhsip64.dll - OK
C:\Windows\system32\iglhxa64.cpa - OK
C:\Windows\system32\iglhxa64.vp - OK
C:\Windows\system32\iglhxc64.vp - OK
C:\Windows\system32\iglhxg64.vp - OK
C:\Windows\system32\iglhxo64.vp - OK
C:\Windows\system32\iglhxs64.vp - OK
C:\Windows\system32\IKEEXT.DLL - OK
C:\Windows\system32\imaadp32.acm - OK
C:\Windows\system32\imagehlp.dll - OK
C:\Windows\system32\imageres.dll - OK
C:\Windows\system32\imagesp1.dll - OK
C:\Windows\system32\imapi.dll - OK
C:\Windows\system32\imapi2.dll - OK
C:\Windows\system32\imapi2fs.dll - OK
C:\Windows\system32\imgutil.dll - OK
C:\Windows\system32\IMJP10.IME - OK
C:\Windows\system32\IMJP10K.DLL - OK
C:\Windows\system32\imkr80.ime - OK
C:\Windows\system32\imm32.dll - OK
C:\Windows\system32\inetcomm.dll - OK
C:\Windows\system32\inetcpl.cpl - OK
C:\Windows\system32\inetmib1.dll - OK
C:\Windows\system32\inetpp.dll - OK
C:\Windows\system32\inetppui.dll - OK
C:\Windows\system32\INETRES.dll - OK
C:\Windows\system32\InfDefaultInstall.exe - OK
C:\Windows\system32\infocardapi.dll - OK
C:\Windows\system32\infocardcpl.cpl - OK
C:\Windows\system32\InkEd.dll - OK
C:\Windows\system32\input.dll - OK
C:\Windows\system32\inseng.dll - OK
C:\Windows\system32\intl.cpl - OK
C:\Windows\system32\iologmsg.dll - OK
C:\Windows\system32\IPBusEnum.dll - OK
C:\Windows\system32\IPBusEnumProxy.dll - OK
C:\Windows\system32\ipconfig.exe - OK
C:\Windows\system32\IPHLPAPI.DLL - OK
C:\Windows\system32\iphlpsvc.dll - OK
C:\Windows\system32\ipnathlp.dll - OK
C:\Windows\system32\iprtprio.dll - OK
C:\Windows\system32\iprtrmgr.dll - OK
C:\Windows\system32\ipsecsnp.dll - OK
C:\Windows\system32\IPSECSVC.DLL - OK
C:\Windows\system32\ipsmsnap.dll - OK
C:\Windows\system32\irclass.dll - OK
C:\Windows\system32\irftp.exe - OK
C:\Windows\system32\irmon.dll - OK
C:\Windows\system32\irprops.cpl - OK
C:\Windows\system32\iscsicli.exe - OK
C:\Windows\system32\iscsicpl.dll - OK
C:\Windows\system32\iscsicpl.exe - OK
C:\Windows\system32\iscsidsc.dll - OK
C:\Windows\system32\iscsied.dll - OK
C:\Windows\system32\iscsiexe.dll - OK
C:\Windows\system32\iscsilog.dll - OK
C:\Windows\system32\iscsium.dll - OK
C:\Windows\system32\iscsiwmi.dll - OK
C:\Windows\system32\isoburn.exe - OK
C:\Windows\system32\itircl.dll - OK
C:\Windows\system32\itss.dll - OK
C:\Windows\system32\iTVData.dll - OK
C:\Windows\system32\iyuv_32.dll - OK
C:\Windows\system32\jnwmon.dll - OK
C:\Windows\system32\joy.cpl - OK
C:\Windows\system32\jscript.dll - OK
C:\Windows\system32\jsproxy.dll - OK
C:\Windows\system32\kanji_1.uce - OK
C:\Windows\system32\kanji_2.uce - OK
C:\Windows\system32\kbd101.dll - OK
C:\Windows\system32\kbd101a.dll - OK
C:\Windows\system32\kbd101b.dll - OK
C:\Windows\system32\kbd101c.dll - OK
C:\Windows\system32\kbd103.dll - OK
C:\Windows\system32\kbd106.dll - OK
C:\Windows\system32\kbd106n.dll - OK
C:\Windows\system32\KBDA1.DLL - OK
C:\Windows\system32\KBDA2.DLL - OK
C:\Windows\system32\KBDA3.DLL - OK
C:\Windows\system32\KBDAL.DLL - OK
C:\Windows\system32\KBDARME.DLL - OK
C:\Windows\system32\KBDARMW.DLL - OK
C:\Windows\system32\kbdax2.dll - OK
C:\Windows\system32\KBDAZE.DLL - OK
C:\Windows\system32\KBDAZEL.DLL - OK
C:\Windows\system32\KBDBASH.DLL - OK
C:\Windows\system32\KBDBE.DLL - OK
C:\Windows\system32\KBDBENE.DLL - OK
C:\Windows\system32\KBDBGPH.DLL - OK
C:\Windows\system32\KBDBGPH1.DLL - OK
C:\Windows\system32\KBDBHC.DLL - OK
C:\Windows\system32\KBDBLR.DLL - OK
C:\Windows\system32\KBDBR.DLL - OK
C:\Windows\system32\KBDBU.DLL - OK
C:\Windows\system32\KBDBULG.DLL - OK
C:\Windows\system32\KBDCA.DLL - OK
C:\Windows\system32\KBDCAN.DLL - OK
C:\Windows\system32\KBDCR.DLL - OK
C:\Windows\system32\KBDCZ.DLL - OK
C:\Windows\system32\KBDCZ1.DLL - OK
C:\Windows\system32\KBDCZ2.DLL - OK
C:\Windows\system32\KBDDA.DLL - OK
C:\Windows\system32\KBDDIV1.DLL - OK
C:\Windows\system32\KBDDIV2.DLL - OK
C:\Windows\system32\KBDDV.DLL - OK
C:\Windows\system32\KBDES.DLL - OK
C:\Windows\system32\KBDEST.DLL - OK
C:\Windows\system32\KBDFA.DLL - OK
C:\Windows\system32\KBDFC.DLL - OK
C:\Windows\system32\KBDFI.DLL - OK
C:\Windows\system32\KBDFI1.DLL - OK
C:\Windows\system32\KBDFO.DLL - OK
C:\Windows\system32\KBDFR.DLL - OK
C:\Windows\system32\KBDGAE.DLL - OK
C:\Windows\system32\KBDGEO.DLL - OK
C:\Windows\system32\kbdgeoer.dll - OK
C:\Windows\system32\kbdgeoqw.dll - OK
C:\Windows\system32\KBDGKL.DLL - OK
C:\Windows\system32\KBDGR.DLL - OK
C:\Windows\system32\KBDGR1.DLL - OK
C:\Windows\system32\KBDGRLND.DLL - OK
C:\Windows\system32\KBDHAU.DLL - OK
C:\Windows\system32\KBDHE.DLL - OK
C:\Windows\system32\KBDHE220.DLL - OK
C:\Windows\system32\KBDHE319.DLL - OK
C:\Windows\system32\KBDHEB.DLL - OK
C:\Windows\system32\KBDHELA2.DLL - OK
C:\Windows\system32\KBDHELA3.DLL - OK
C:\Windows\system32\KBDHEPT.DLL - OK
C:\Windows\system32\KBDHU.DLL - OK
C:\Windows\system32\KBDHU1.DLL - OK
C:\Windows\system32\kbdibm02.dll - OK
C:\Windows\system32\KBDIBO.DLL - OK
C:\Windows\system32\KBDIC.DLL - OK
C:\Windows\system32\KBDINASA.DLL - OK
C:\Windows\system32\KBDINBE1.DLL - OK
C:\Windows\system32\KBDINBE2.DLL - OK
C:\Windows\system32\KBDINBEN.DLL - OK
C:\Windows\system32\KBDINDEV.DLL - OK
C:\Windows\system32\KBDINGUJ.DLL - OK
C:\Windows\system32\KBDINHIN.DLL - OK
C:\Windows\system32\KBDINKAN.DLL - OK
C:\Windows\system32\KBDINMAL.DLL - OK
C:\Windows\system32\KBDINMAR.DLL - OK
C:\Windows\system32\KBDINORI.DLL - OK
C:\Windows\system32\KBDINPUN.DLL - OK
C:\Windows\system32\KBDINTAM.DLL - OK
C:\Windows\system32\KBDINTEL.DLL - OK
C:\Windows\system32\KBDINUK2.DLL - OK
C:\Windows\system32\KBDIR.DLL - OK
C:\Windows\system32\KBDIT.DLL - OK
C:\Windows\system32\KBDIT142.DLL - OK
C:\Windows\system32\KBDIULAT.DLL - OK
C:\Windows\system32\KBDJPN.DLL - OK
C:\Windows\system32\KBDKAZ.DLL - OK
C:\Windows\system32\KBDKHMR.DLL - OK
C:\Windows\system32\KBDKOR.DLL - OK
C:\Windows\system32\KBDKYR.DLL - OK
C:\Windows\system32\KBDLA.DLL - OK
C:\Windows\system32\KBDLAO.DLL - OK
C:\Windows\system32\kbdlk41a.dll - OK
C:\Windows\system32\KBDLT.DLL - OK
C:\Windows\system32\KBDLT1.DLL - OK
C:\Windows\system32\KBDLT2.DLL - OK
C:\Windows\system32\KBDLV.DLL - OK
C:\Windows\system32\KBDLV1.DLL - OK
C:\Windows\system32\KBDMAC.DLL - OK
C:\Windows\system32\KBDMACST.DLL - OK
C:\Windows\system32\KBDMAORI.DLL - OK
C:\Windows\system32\KBDMLT47.DLL - OK
C:\Windows\system32\KBDMLT48.DLL - OK
C:\Windows\system32\KBDMON.DLL - OK
C:\Windows\system32\KBDMONMO.DLL - OK
C:\Windows\system32\KBDNE.DLL - OK
C:\Windows\system32\kbdnec.dll - OK
C:\Windows\system32\kbdnec95.dll - OK
C:\Windows\system32\kbdnecat.dll - OK
C:\Windows\system32\kbdnecnt.dll - OK
C:\Windows\system32\KBDNEPR.DLL - OK
C:\Windows\system32\KBDNO.DLL - OK
C:\Windows\system32\KBDNO1.DLL - OK
C:\Windows\system32\KBDNSO.DLL - OK
C:\Windows\system32\KBDPASH.DLL - OK
C:\Windows\system32\KBDPL.DLL - OK
C:\Windows\system32\KBDPL1.DLL - OK
C:\Windows\system32\KBDPO.DLL - OK
C:\Windows\system32\KBDRO.DLL - OK
C:\Windows\system32\KBDROPR.DLL - OK
C:\Windows\system32\KBDROST.DLL - OK
C:\Windows\system32\KBDRU.DLL - OK
C:\Windows\system32\KBDRU1.DLL - OK
C:\Windows\system32\KBDSF.DLL - OK
C:\Windows\system32\KBDSG.DLL - OK
C:\Windows\system32\KBDSL.DLL - OK
C:\Windows\system32\KBDSL1.DLL - OK
C:\Windows\system32\KBDSMSFI.DLL - OK
C:\Windows\system32\KBDSMSNO.DLL - OK
C:\Windows\system32\KBDSN1.DLL - OK
C:\Windows\system32\KBDSOREX.DLL - OK
C:\Windows\system32\KBDSORS1.DLL - OK
C:\Windows\system32\KBDSORST.DLL - OK
C:\Windows\system32\KBDSP.DLL - OK
C:\Windows\system32\KBDSW.DLL - OK
C:\Windows\system32\KBDSW09.DLL - OK
C:\Windows\system32\KBDSYR1.DLL - OK
C:\Windows\system32\KBDSYR2.DLL - OK
C:\Windows\system32\KBDTAJIK.DLL - OK
C:\Windows\system32\KBDTAT.DLL - OK
C:\Windows\system32\KBDTH0.DLL - OK
C:\Windows\system32\KBDTH1.DLL - OK
C:\Windows\system32\KBDTH2.DLL - OK
C:\Windows\system32\KBDTH3.DLL - OK
C:\Windows\system32\KBDTIPRC.DLL - OK
C:\Windows\system32\KBDTUF.DLL - OK
C:\Windows\system32\KBDTUQ.DLL - OK
C:\Windows\system32\KBDTURME.DLL - OK
C:\Windows\system32\KBDUGHR.DLL - OK
C:\Windows\system32\KBDUGHR1.DLL - OK
C:\Windows\system32\KBDUK.DLL - OK
C:\Windows\system32\KBDUKX.DLL - OK
C:\Windows\system32\KBDUR.DLL - OK
C:\Windows\system32\KBDUR1.DLL - OK
C:\Windows\system32\KBDURDU.DLL - OK
C:\Windows\system32\KBDUS.DLL - OK
C:\Windows\system32\KBDUSA.DLL - OK
C:\Windows\system32\KBDUSL.DLL - OK
C:\Windows\system32\KBDUSR.DLL - OK
C:\Windows\system32\KBDUSX.DLL - OK
C:\Windows\system32\KBDUZB.DLL - OK
C:\Windows\system32\KBDVNTC.DLL - OK
C:\Windows\system32\KBDWOL.DLL - OK
C:\Windows\system32\KBDYAK.DLL - OK
C:\Windows\system32\KBDYBA.DLL - OK
C:\Windows\system32\KBDYCC.DLL - OK
C:\Windows\system32\KBDYCL.DLL - OK
C:\Windows\system32\kd1394.dll - OK
C:\Windows\system32\kdcom.dll - OK
C:\Windows\system32\kdusb.dll - OK
C:\Windows\system32\kerberos.dll - OK
C:\Windows\system32\kernel32.dll packed by BINARYRES
>C:\Windows\system32\kernel32.dll packed by MS COMPRESS
>>C:\Windows\system32\kernel32.dll - OK
C:\Windows\system32\KernelBase.dll - OK
C:\Windows\system32\kernelceip.dll - OK
C:\Windows\system32\keyiso.dll - OK
C:\Windows\system32\keymgr.dll - OK
C:\Windows\system32\klist.exe - OK
C:\Windows\system32\kmddsp.tsp - OK
C:\Windows\system32\KMSVC.DLL - OK
C:\Windows\system32\korean.uce - OK
C:\Windows\system32\korwbrkr.dll - OK
C:\Windows\system32\korwbrkr.lex - OK
C:\Windows\system32\ksetup.exe - OK
C:\Windows\system32\ksproxy.ax - OK
C:\Windows\system32\kstvtune.ax - OK
C:\Windows\system32\ksuser.dll - OK
C:\Windows\system32\Kswdmcap.ax - OK
C:\Windows\system32\ksxbar.ax - OK
C:\Windows\system32\ktmutil.exe - OK
C:\Windows\system32\ktmw32.dll - OK
C:\Windows\system32\l2gpstore.dll - OK
C:\Windows\system32\l2nacp.dll - OK
C:\Windows\system32\L2SecHC.dll - OK
C:\Windows\system32\l3codeca.acm - OK
C:\Windows\system32\l3codecp.acm - OK
C:\Windows\system32\label.exe - OK
C:\Windows\system32\LangCleanupSysprepAction.dll - OK
C:\Windows\system32\LAPRXY.DLL - OK
C:\Windows\system32\lcphrase.tbl - OK
C:\Windows\system32\lcptr.tbl - OK
C:\Windows\system32\license.rtf - OK
C:\Windows\system32\licmgr10.dll - OK
C:\Windows\system32\linkinfo.dll - OK
C:\Windows\system32\ListSvc.dll - OK
C:\Windows\system32\LIVESSP.DLL - OK
C:\Windows\system32\lltdapi.dll - OK
C:\Windows\system32\lltdres.dll - OK
C:\Windows\system32\lltdsvc.dll - OK
C:\Windows\system32\lmhsvc.dll - OK
C:\Windows\system32\loadperf.dll - OK
C:\Windows\system32\locale.nls - OK
C:\Windows\system32\localsec.dll - OK
C:\Windows\system32\localspl.dll - OK
C:\Windows\system32\localui.dll - OK
C:\Windows\system32\LocationApi.dll - OK
C:\Windows\system32\LocationNotifications.exe - OK
C:\Windows\system32\locationnotificationsview.xml - OK
C:\Windows\system32\Locator.exe - OK
C:\Windows\system32\lodctr.exe - OK
C:\Windows\system32\logagent.exe - OK
C:\Windows\system32\loghours.dll - OK
C:\Windows\system32\logman.exe - OK
C:\Windows\system32\logoncli.dll - OK
C:\Windows\system32\LogonUI.exe - OK
C:\Windows\system32\lpk.dll - OK
C:\Windows\system32\lpksetup.exe - OK
C:\Windows\system32\lpksetupproxyserv.dll - OK
C:\Windows\system32\lpremove.exe - OK
C:\Windows\system32\lsasrv.dll - OK
C:\Windows\system32\lsass.exe - OK
C:\Windows\system32\lsm.exe - OK
C:\Windows\system32\lsmproxy.dll - OK
C:\Windows\system32\luainstall.dll - OK
C:\Windows\system32\lusrmgr.msc - OK
C:\Windows\system32\lz32.dll - OK
C:\Windows\system32\l_intl.nls - OK
C:\Windows\system32\Magnification.dll - OK
C:\Windows\system32\Magnify.exe packed by ZLIB
>C:\Windows\system32\Magnify.exe - archive BINARYRES
>>C:\Windows\system32\Magnify.exe/data001 - OK
>>C:\Windows\system32\Magnify.exe/data002 - OK
>>C:\Windows\system32\Magnify.exe/data003 - OK
>>C:\Windows\system32\Magnify.exe/data004 - OK
>>C:\Windows\system32\Magnify.exe/data005 - OK
>C:\Windows\system32\Magnify.exe - OK
C:\Windows\system32\main.cpl - OK
C:\Windows\system32\makecab.exe - OK
C:\Windows\system32\manage-bde.exe - OK
C:\Windows\system32\manage-bde.wsf - archive HTML
>C:\Windows\system32\manage-bde.wsf/VBScript.0 - OK
C:\Windows\system32\manage-bde.wsf - OK
C:\Windows\system32\mapi32.dll - OK
C:\Windows\system32\mapistub.dll - OK
C:\Windows\system32\mblctr.exe - OK
C:\Windows\system32\mcbuilder.exe - OK
C:\Windows\system32\MCEWMDRMNDBootstrap.dll - OK
C:\Windows\system32\mciavi32.dll - OK
C:\Windows\system32\mcicda.dll - OK
C:\Windows\system32\mciqtz32.dll - OK
C:\Windows\system32\mciseq.dll - OK
C:\Windows\system32\mciwave.dll - OK
C:\Windows\system32\mcmde.dll packed by PESTUB
>C:\Windows\system32\mcmde.dll - OK
C:\Windows\system32\mcsrchPH.dll - OK
C:\Windows\system32\mctadmin.exe - OK
C:\Windows\system32\mctres.dll - OK
C:\Windows\system32\mcupdate_AuthenticAMD.dll - OK
C:\Windows\system32\mcupdate_GenuineIntel.dll - OK
C:\Windows\system32\Mcx2Svc.dll - OK
C:\Windows\system32\McxDriv.dll - OK
C:\Windows\system32\mdminst.dll - OK
C:\Windows\system32\MdRes.exe - OK
C:\Windows\system32\MdSched.exe - OK
C:\Windows\system32\MediaMetadataHandler.dll - OK
C:\Windows\system32\memdiag.dll - OK
C:\Windows\system32\mf.dll - OK
C:\Windows\system32\mf3216.dll - OK
C:\Windows\system32\mfAACEnc.dll - OK
C:\Windows\system32\mfc42.dll - OK
C:\Windows\system32\mfc42u.dll - OK
C:\Windows\system32\mfcsubs.dll - OK
C:\Windows\system32\mfds.dll - OK
C:\Windows\system32\mfdvdec.dll - OK
C:\Windows\system32\mferror.dll - OK
C:\Windows\system32\mfh264enc.dll - OK
C:\Windows\system32\mfmjpegdec.dll - OK
C:\Windows\system32\mfplat.dll - OK
C:\Windows\system32\MFPlay.dll - OK
C:\Windows\system32\mfpmp.exe - OK
C:\Windows\system32\mfps.dll - OK
C:\Windows\system32\mfreadwrite.dll - OK
C:\Windows\system32\mfvdsp.dll - OK
C:\Windows\system32\MFWMAAEC.DLL - OK
C:\Windows\system32\mgmtapi.dll - OK
C:\Windows\system32\microsoft-windows-hal-events.dll - OK
C:\Windows\system32\microsoft-windows-kernel-power-events.dll - OK
C:\Windows\system32\microsoft-windows-kernel-processor-power-events.dll - OK
C:\Windows\system32\midimap.dll - OK
C:\Windows\system32\MigAutoPlay.exe - OK
C:\Windows\system32\migisol.dll - OK
C:\Windows\system32\miguiresource.dll - OK
C:\Windows\system32\migwiz.lnk - OK
C:\Windows\system32\mimefilt.dll - OK
C:\Windows\system32\mlang.dat - OK
C:\Windows\system32\mlang.dll - OK
C:\Windows\system32\mmc.exe - OK
C:\Windows\system32\mmcbase.dll - OK
C:\Windows\system32\mmci.dll - OK
C:\Windows\system32\mmcico.dll - OK
C:\Windows\system32\mmcndmgr.dll - OK
C:\Windows\system32\mmcshext.dll - OK
C:\Windows\system32\mmcss.dll - OK
C:\Windows\system32\MMDevAPI.dll - OK
C:\Windows\system32\mmres.dll - OK
C:\Windows\system32\mmsys.cpl - OK
C:\Windows\system32\mobsync.exe - OK
C:\Windows\system32\mode.com - OK
C:\Windows\system32\modemui.dll - OK
C:\Windows\system32\montr_ci.dll - OK
C:\Windows\system32\more.com - OK
C:\Windows\system32\moricons.dll - OK
C:\Windows\system32\mouclass.sys - OK

#15 epic pie

epic pie
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:01:17 AM

Posted 08 August 2011 - 09:55 AM

C:\Windows\system32\mouhid.sys - OK
C:\Windows\system32\mountvol.exe - OK
C:\Windows\system32\MP3DMOD.DLL - OK
C:\Windows\system32\MP43DECD.DLL - OK
C:\Windows\system32\MP4SDECD.DLL - OK
C:\Windows\system32\Mpeg2Data.ax - OK
C:\Windows\system32\mpg2splt.ax - OK
C:\Windows\system32\MPG4DECD.DLL - OK
C:\Windows\system32\mpnotify.exe - OK
C:\Windows\system32\mpr.dll - OK
C:\Windows\system32\mprapi.dll - OK
C:\Windows\system32\mprddm.dll - OK
C:\Windows\system32\mprdim.dll - OK
C:\Windows\system32\mprmsg.dll - OK
C:\Windows\system32\MpSigStub.exe - OK
C:\Windows\system32\MPSSVC.dll - OK
C:\Windows\system32\MRINFO.EXE - OK
C:\Windows\system32\MRT.exe - archive BINARYRES
>C:\Windows\system32\MRT.exe/data001 - archive BINARYRES
>>C:\Windows\system32\MRT.exe/data001/data001 - OK
>>C:\Windows\system32\MRT.exe/data001/data002 - OK
>C:\Windows\system32\MRT.exe/data001 - OK
>C:\Windows\system32\MRT.exe/data002 - OK
C:\Windows\system32\MRT.exe - OK
C:\Windows\system32\msaatext.dll - OK
C:\Windows\system32\MSAC3ENC.DLL - OK
C:\Windows\system32\msacm32.dll - OK
C:\Windows\system32\msacm32.drv - OK
C:\Windows\system32\msadp32.acm - OK
C:\Windows\system32\msafd.dll - OK
C:\Windows\system32\msasn1.dll - OK
C:\Windows\system32\msaudite.dll - OK
C:\Windows\system32\mscandui.dll - OK
C:\Windows\system32\mscat32.dll - OK
C:\Windows\system32\msclmd.dll - OK
C:\Windows\system32\mscms.dll - OK
C:\Windows\system32\msconfig.exe - OK
C:\Windows\system32\mscoree.dll - OK
C:\Windows\system32\mscorier.dll - OK
C:\Windows\system32\mscories.dll - OK
C:\Windows\system32\msctf.dll - OK
C:\Windows\system32\msctfime.ime - OK
C:\Windows\system32\MsCtfMonitor.dll - OK
C:\Windows\system32\msctfp.dll - OK
C:\Windows\system32\msctfui.dll - OK
C:\Windows\system32\msdadiag.dll - OK
C:\Windows\system32\msdart.dll - OK
C:\Windows\system32\msdatsrc.tlb - OK
C:\Windows\system32\msdelta.dll - OK
C:\Windows\system32\msdmo.dll - OK
C:\Windows\system32\msdri.dll - OK
C:\Windows\system32\msdrm.dll - OK
C:\Windows\system32\msdt.exe - OK
C:\Windows\system32\msdtc.exe - OK
C:\Windows\system32\msdtckrm.dll - OK
C:\Windows\system32\msdtclog.dll - OK
C:\Windows\system32\msdtcprx.dll - OK
C:\Windows\system32\msdtctm.dll - OK
C:\Windows\system32\msdtcuiu.dll - OK
C:\Windows\system32\msdtcVSp1res.dll - OK
C:\Windows\system32\MSDvbNP.ax - OK
C:\Windows\system32\msdxm.ocx - OK
C:\Windows\system32\msdxm.tlb - OK
C:\Windows\system32\msfeeds.dll - OK
C:\Windows\system32\msfeedsbs.dll - OK
C:\Windows\system32\msfeedssync.exe - OK
C:\Windows\system32\msftedit.dll - OK
C:\Windows\system32\msg711.acm - OK
C:\Windows\system32\msgsm32.acm - OK
C:\Windows\system32\mshta.exe - OK
C:\Windows\system32\mshtml.dll - archive BINARYRES
>C:\Windows\system32\mshtml.dll/data001 - OK
C:\Windows\system32\mshtml.dll - OK
C:\Windows\system32\mshtml.tlb - OK
C:\Windows\system32\mshtmled.dll - OK
C:\Windows\system32\mshtmler.dll - OK
C:\Windows\system32\msi.dll - OK
C:\Windows\system32\MsiCofire.dll - OK
C:\Windows\system32\msidcrl30.dll - OK
C:\Windows\system32\msident.dll - OK
C:\Windows\system32\msidle.dll - OK
C:\Windows\system32\msidntld.dll - OK
C:\Windows\system32\msieftp.dll - OK
C:\Windows\system32\msiexec.exe - OK
C:\Windows\system32\msihnd.dll - OK
C:\Windows\system32\msiltcfg.dll - OK
C:\Windows\system32\msimg32.dll - OK
C:\Windows\system32\msimsg.dll - OK
C:\Windows\system32\msimtf.dll - OK
C:\Windows\system32\msinfo32.exe - OK
C:\Windows\system32\msisip.dll - OK
C:\Windows\system32\msls31.dll - OK
C:\Windows\system32\msmmsp.dll - OK
C:\Windows\system32\msmpeg2adec.dll - OK
C:\Windows\system32\MSMPEG2ENC.DLL - OK
C:\Windows\system32\msmpeg2vdec.dll - OK
C:\Windows\system32\msnetobj.dll - OK
C:\Windows\system32\MSNP.ax - OK
C:\Windows\system32\msobjs.dll - OK
C:\Windows\system32\msoeacct.dll - OK
C:\Windows\system32\msoert2.dll - OK
C:\Windows\system32\mspaint.exe - OK
C:\Windows\system32\mspatcha.dll - OK
C:\Windows\system32\mspbda.dll - OK
C:\Windows\system32\MsPbdaCoInst.dll - OK
C:\Windows\system32\msports.dll - OK
C:\Windows\system32\msprivs.dll - OK
C:\Windows\system32\msra.exe - OK
C:\Windows\system32\msrahc.dll - OK
C:\Windows\system32\MsraLegacy.tlb - OK
C:\Windows\system32\msrating.dll - OK
C:\Windows\system32\msrdc.dll - OK
C:\Windows\system32\MsRdpWebAccess.dll - OK
C:\Windows\system32\msrle32.dll - OK
C:\Windows\system32\msscntrs.dll - OK
C:\Windows\system32\msscp.dll - OK
C:\Windows\system32\mssha.dll - OK
C:\Windows\system32\msshavmsg.dll - OK
C:\Windows\system32\msshooks.dll - OK
C:\Windows\system32\mssign32.dll - OK
C:\Windows\system32\mssip32.dll - OK
C:\Windows\system32\mssitlb.dll - OK
C:\Windows\system32\mssph.dll - OK
C:\Windows\system32\mssphtb.dll - OK
C:\Windows\system32\mssprxy.dll - OK
C:\Windows\system32\mssrch.dll - OK
C:\Windows\system32\mssvp.dll - OK
C:\Windows\system32\msswch.dll - OK
C:\Windows\system32\mstask.dll - OK
C:\Windows\system32\mstime.dll - OK
C:\Windows\system32\mstsc.exe - OK
C:\Windows\system32\mstscax.dll - OK
C:\Windows\system32\msutb.dll - OK
C:\Windows\system32\msv1_0.dll - OK
C:\Windows\system32\msvcirt.dll - OK
C:\Windows\system32\msvcp60.dll - OK
C:\Windows\system32\msvcr100_clr0400.dll - OK
C:\Windows\system32\msvcrt.dll - OK
C:\Windows\system32\msvfw32.dll - OK
C:\Windows\system32\msvidc32.dll - OK
C:\Windows\system32\MSVidCtl.dll - OK
C:\Windows\system32\mswmdm.dll - OK
C:\Windows\system32\mswsock.dll - OK
C:\Windows\system32\msxml3.dll - OK
C:\Windows\system32\msxml3r.dll - OK
C:\Windows\system32\msxml6.dll - OK
C:\Windows\system32\msxml6r.dll - OK
C:\Windows\system32\msyuv.dll - OK
C:\Windows\system32\mtstocom.exe - OK
C:\Windows\system32\mtxclu.dll - OK
C:\Windows\system32\mtxdm.dll - OK
C:\Windows\system32\mtxex.dll - OK
C:\Windows\system32\mtxoci.dll - OK
C:\Windows\system32\muifontsetup.dll - OK
C:\Windows\system32\MUILanguageCleanup.dll - OK
C:\Windows\system32\MuiUnattend.exe - OK
C:\Windows\system32\MultiDigiMon.exe - OK
C:\Windows\system32\mycomput.dll - OK
C:\Windows\system32\mydocs.dll - OK
C:\Windows\system32\Mystify.scr - OK
C:\Windows\system32\NAPCLCFG.MSC - OK
C:\Windows\system32\NAPCRYPT.DLL - OK
C:\Windows\system32\napdsnap.dll - OK
C:\Windows\system32\NAPHLPR.DLL - OK
C:\Windows\system32\NapiNSP.dll - OK
C:\Windows\system32\napipsec.dll - OK
C:\Windows\system32\NAPMONTR.DLL - OK
C:\Windows\system32\NAPSTAT.EXE - OK
C:\Windows\system32\Narrator.exe - OK
C:\Windows\system32\NativeHooks.dll - OK
C:\Windows\system32\NaturalLanguage6.dll - OK
C:\Windows\system32\nbtstat.exe - OK
C:\Windows\system32\NcdProp.dll - OK
C:\Windows\system32\nci.dll - OK
C:\Windows\system32\ncobjapi.dll - OK
C:\Windows\system32\ncpa.cpl - OK
C:\Windows\system32\ncrypt.dll - OK
C:\Windows\system32\ncryptui.dll - OK
C:\Windows\system32\ncsi.dll - OK
C:\Windows\system32\ndadmin.exe - OK
C:\Windows\system32\nddeapi.dll - OK
C:\Windows\system32\ndfapi.dll - OK
C:\Windows\system32\ndfetw.dll - OK
C:\Windows\system32\NdfEventView.xml - OK
C:\Windows\system32\ndfhcdiscovery.dll - OK
C:\Windows\system32\ndiscapCfg.dll - OK
C:\Windows\system32\ndishc.dll - OK
C:\Windows\system32\ndproxystub.dll - OK
C:\Windows\system32\ndptsp.tsp - OK
C:\Windows\system32\negoexts.dll - OK
C:\Windows\system32\net.exe - OK
C:\Windows\system32\net1.exe - OK
C:\Windows\system32\netapi32.dll - OK
C:\Windows\system32\netbios.dll - OK
C:\Windows\system32\netbtugc.exe - OK
C:\Windows\system32\netcenter.dll - OK
C:\Windows\system32\netcfg.exe - OK
C:\Windows\system32\netcfgx.dll - OK
C:\Windows\system32\netcorehc.dll - OK
C:\Windows\system32\netdiagfx.dll - OK
C:\Windows\system32\netevent.dll - OK
C:\Windows\system32\netfxperf.dll - OK
C:\Windows\system32\neth.dll - OK
C:\Windows\system32\netid.dll - OK
C:\Windows\system32\netiohlp.dll - OK
C:\Windows\system32\netiougc.exe - OK
C:\Windows\system32\netjoin.dll - OK
C:\Windows\system32\netlogon.dll - OK
C:\Windows\system32\netman.dll - OK
C:\Windows\system32\netmsg.dll - OK
C:\Windows\system32\netplwiz.dll - OK
C:\Windows\system32\Netplwiz.exe - OK
C:\Windows\system32\netprof.dll - OK
C:\Windows\system32\netprofm.dll - OK
C:\Windows\system32\netsh.exe - OK
C:\Windows\system32\netshell.dll - OK
C:\Windows\system32\NETSTAT.EXE - OK
C:\Windows\system32\nettrace.dll - OK
C:\Windows\system32\NetTrace.PLA.Diagnostics.xml - OK
C:\Windows\system32\netutils.dll - OK
C:\Windows\system32\networkexplorer.dll - OK
C:\Windows\system32\networkitemfactory.dll - OK
C:\Windows\system32\networkmap.dll - OK
C:\Windows\system32\newdev.dll - OK
C:\Windows\system32\newdev.exe - OK
C:\Windows\system32\nlaapi.dll - OK
C:\Windows\system32\nlahc.dll - OK
C:\Windows\system32\nlasvc.dll - OK
C:\Windows\system32\nlhtml.dll - OK
C:\Windows\system32\nlmgp.dll - OK
C:\Windows\system32\nlmsprep.dll - OK
C:\Windows\system32\nlsbres.dll - OK
C:\Windows\system32\NlsData0000.dll - OK
C:\Windows\system32\NlsData0001.dll - OK
C:\Windows\system32\NlsData0002.dll - OK
C:\Windows\system32\NlsData0003.dll - OK
C:\Windows\system32\NlsData0007.dll - OK
C:\Windows\system32\NlsData0009.dll - OK
C:\Windows\system32\NlsData000a.dll - OK
C:\Windows\system32\NlsData000c.dll - OK
C:\Windows\system32\NlsData000d.dll - OK
C:\Windows\system32\NlsData000f.dll - OK
C:\Windows\system32\NlsData0010.dll - OK
C:\Windows\system32\NlsData0011.dll - OK
C:\Windows\system32\NlsData0013.dll - OK
C:\Windows\system32\NlsData0018.dll - OK
C:\Windows\system32\NlsData0019.dll - OK
C:\Windows\system32\NlsData001a.dll - OK
C:\Windows\system32\NlsData001b.dll - OK
C:\Windows\system32\NlsData001d.dll - OK
C:\Windows\system32\NlsData0020.dll - OK
C:\Windows\system32\NlsData0021.dll - OK
C:\Windows\system32\NlsData0022.dll - OK
C:\Windows\system32\NlsData0024.dll - OK
C:\Windows\system32\NlsData0026.dll - OK
C:\Windows\system32\NlsData0027.dll - OK
C:\Windows\system32\NlsData002a.dll - OK
C:\Windows\system32\NlsData0039.dll - OK
C:\Windows\system32\NlsData003e.dll - OK
C:\Windows\system32\NlsData0045.dll - OK
C:\Windows\system32\NlsData0046.dll - OK
C:\Windows\system32\NlsData0047.dll - OK
C:\Windows\system32\NlsData0049.dll - OK
C:\Windows\system32\NlsData004a.dll - OK
C:\Windows\system32\NlsData004b.dll - OK
C:\Windows\system32\NlsData004c.dll - OK
C:\Windows\system32\NlsData004e.dll - OK
C:\Windows\system32\NlsData0414.dll - OK
C:\Windows\system32\NlsData0416.dll - OK
C:\Windows\system32\NlsData0816.dll - OK
C:\Windows\system32\NlsData081a.dll - OK
C:\Windows\system32\NlsData0c1a.dll - OK
C:\Windows\system32\Nlsdl.dll - OK
C:\Windows\system32\NlsLexicons0001.dll - OK
C:\Windows\system32\NlsLexicons0002.dll - OK
C:\Windows\system32\NlsLexicons0003.dll - OK
C:\Windows\system32\NlsLexicons0007.dll - OK
C:\Windows\system32\NlsLexicons0009.dll - OK
C:\Windows\system32\NlsLexicons000a.dll - OK
C:\Windows\system32\NlsLexicons000c.dll - OK
C:\Windows\system32\NlsLexicons000d.dll - OK
C:\Windows\system32\NlsLexicons000f.dll - OK
C:\Windows\system32\NlsLexicons0010.dll - OK
C:\Windows\system32\NlsLexicons0011.dll - OK
C:\Windows\system32\NlsLexicons0013.dll - OK
C:\Windows\system32\NlsLexicons0018.dll - OK
C:\Windows\system32\NlsLexicons0019.dll - OK
C:\Windows\system32\NlsLexicons001a.dll - OK
C:\Windows\system32\NlsLexicons001b.dll - OK
C:\Windows\system32\NlsLexicons001d.dll - OK
C:\Windows\system32\NlsLexicons0020.dll - OK
C:\Windows\system32\NlsLexicons0021.dll - OK
C:\Windows\system32\NlsLexicons0022.dll - OK
C:\Windows\system32\NlsLexicons0024.dll - OK
C:\Windows\system32\NlsLexicons0026.dll - OK
C:\Windows\system32\NlsLexicons0027.dll - OK
C:\Windows\system32\NlsLexicons002a.dll - OK
C:\Windows\system32\NlsLexicons0039.dll - OK
C:\Windows\system32\NlsLexicons003e.dll - OK
C:\Windows\system32\NlsLexicons0045.dll - OK
C:\Windows\system32\NlsLexicons0046.dll - OK
C:\Windows\system32\NlsLexicons0047.dll - OK
C:\Windows\system32\NlsLexicons0049.dll - OK
C:\Windows\system32\NlsLexicons004a.dll - OK
C:\Windows\system32\NlsLexicons004b.dll - OK
C:\Windows\system32\NlsLexicons004c.dll - OK
C:\Windows\system32\NlsLexicons004e.dll - OK
C:\Windows\system32\NlsLexicons0414.dll - OK
C:\Windows\system32\NlsLexicons0416.dll - OK
C:\Windows\system32\NlsLexicons0816.dll - OK
C:\Windows\system32\NlsLexicons081a.dll - OK
C:\Windows\system32\NlsLexicons0c1a.dll - OK
C:\Windows\system32\NlsModels0011.dll - OK
C:\Windows\system32\nltest.exe - OK
C:\Windows\system32\NOISE.CHS - OK
C:\Windows\system32\NOISE.CHT - OK
C:\Windows\system32\NOISE.DAT - OK
C:\Windows\system32\noise.jpn - OK
C:\Windows\system32\noise.kor - OK
C:\Windows\system32\NOISE.THA - OK
C:\Windows\system32\normaliz.dll - OK
C:\Windows\system32\normidna.nls - OK
C:\Windows\system32\normnfc.nls - OK
C:\Windows\system32\normnfd.nls - OK
C:\Windows\system32\normnfkc.nls - OK
C:\Windows\system32\normnfkd.nls - OK
C:\Windows\system32\notepad.exe - OK
C:\Windows\system32\npmproxy.dll - OK
C:\Windows\system32\nrpsrv.dll - OK
C:\Windows\system32\nshhttp.dll - OK
C:\Windows\system32\nshipsec.dll - OK
C:\Windows\system32\nshwfp.dll - OK
C:\Windows\system32\nsi.dll - OK
C:\Windows\system32\nsisvc.dll - OK
C:\Windows\system32\nslookup.exe - OK
C:\Windows\system32\ntdll.dll - OK
C:\Windows\system32\ntdsapi.dll - OK
C:\Windows\system32\ntlanman.dll - OK
C:\Windows\system32\ntlanui2.dll - OK
C:\Windows\system32\ntmarta.dll - OK
C:\Windows\system32\ntoskrnl.exe - OK
C:\Windows\system32\ntprint.dll - OK
C:\Windows\system32\ntprint.exe - OK
C:\Windows\system32\ntshrui.dll - OK
C:\Windows\system32\ntvdm64.dll - OK
C:\Windows\system32\objsel.dll - OK
C:\Windows\system32\occache.dll - OK
C:\Windows\system32\ocsetapi.dll - OK
C:\Windows\system32\ocsetup.exe - OK
C:\Windows\system32\odbc32.dll - OK
C:\Windows\system32\odbc32gt.dll - OK
C:\Windows\system32\odbcad32.exe - OK
C:\Windows\system32\odbcbcp.dll - OK
C:\Windows\system32\odbcconf.dll - OK
C:\Windows\system32\odbcconf.exe - OK
C:\Windows\system32\odbcconf.rsp - OK
C:\Windows\system32\odbccp32.dll - OK
C:\Windows\system32\odbccr32.dll - OK
C:\Windows\system32\odbccu32.dll - OK
C:\Windows\system32\odbcint.dll - OK
C:\Windows\system32\odbctrac.dll - OK
C:\Windows\system32\offfilt.dll - OK
C:\Windows\system32\oflc.rs packed by ZLIB
>C:\Windows\system32\oflc.rs - archive BINARYRES
>>C:\Windows\system32\oflc.rs/data001 - OK
>C:\Windows\system32\oflc.rs - OK
C:\Windows\system32\ogldrv.dll - OK
C:\Windows\system32\ole32.dll - archive BINARYRES
>C:\Windows\system32\ole32.dll/data001 - OK
>C:\Windows\system32\ole32.dll/data002 - OK
C:\Windows\system32\ole32.dll - OK
C:\Windows\system32\oleacc.dll - OK
C:\Windows\system32\oleacchooks.dll - OK
C:\Windows\system32\oleaccrc.dll - OK
C:\Windows\system32\oleaut32.dll - OK
C:\Windows\system32\oledlg.dll - OK
C:\Windows\system32\oleprn.dll - OK
C:\Windows\system32\oleres.dll - OK
C:\Windows\system32\onex.dll - OK
C:\Windows\system32\onexui.dll - OK
C:\Windows\system32\OnLineIDCpl.dll - OK
C:\Windows\system32\onlinesetup.cmd - OK
C:\Windows\system32\OobeFldr.dll - OK
C:\Windows\system32\OpcServices.dll - OK
C:\Windows\system32\OpenAL32.dll - OK
C:\Windows\system32\openfiles.exe - OK
C:\Windows\system32\opengl32.dll - OK
C:\Windows\system32\OptionalFeatures.exe - OK
C:\Windows\system32\osbaseln.dll - OK
C:\Windows\system32\osk.exe - OK
C:\Windows\system32\osuninst.dll - OK
C:\Windows\system32\P2P.dll - OK
C:\Windows\system32\p2pcollab.dll - OK
C:\Windows\system32\P2PGraph.dll - OK
C:\Windows\system32\p2phost.exe - OK
C:\Windows\system32\p2pnetsh.dll - OK
C:\Windows\system32\p2psvc.dll - OK
C:\Windows\system32\packager.dll - OK
C:\Windows\system32\panmap.dll - OK
C:\Windows\system32\PATHPING.EXE - OK
C:\Windows\system32\pautoenr.dll - OK
C:\Windows\system32\pcadm.dll - OK
C:\Windows\system32\pcaevts.dll - OK
C:\Windows\system32\pcalua.exe - OK
C:\Windows\system32\pcasvc.dll - OK
C:\Windows\system32\pcaui.dll - OK
C:\Windows\system32\pcaui.exe - OK
C:\Windows\system32\pcawrk.exe - OK
C:\Windows\system32\pcl.sep - OK
C:\Windows\system32\pcwrun.exe - OK
C:\Windows\system32\pcwum.dll - OK
C:\Windows\system32\pcwutl.dll - OK
C:\Windows\system32\pdh.dll - OK
C:\Windows\system32\pdhui.dll - OK
C:\Windows\system32\pegi-fi.rs packed by ZLIB
>C:\Windows\system32\pegi-fi.rs - archive BINARYRES
>>C:\Windows\system32\pegi-fi.rs/data001 - OK
>>C:\Windows\system32\pegi-fi.rs/data002 - OK
>>C:\Windows\system32\pegi-fi.rs/data003 - OK
>>C:\Windows\system32\pegi-fi.rs/data004 - OK
>>C:\Windows\system32\pegi-fi.rs/data005 - OK
>>C:\Windows\system32\pegi-fi.rs/data006 - OK
>C:\Windows\system32\pegi-fi.rs - OK
C:\Windows\system32\pegi-pt.rs packed by ZLIB
>C:\Windows\system32\pegi-pt.rs - archive BINARYRES
>>C:\Windows\system32\pegi-pt.rs/data001 - OK
>>C:\Windows\system32\pegi-pt.rs/data002 - OK
>>C:\Windows\system32\pegi-pt.rs/data003 - OK
>>C:\Windows\system32\pegi-pt.rs/data004 - OK
>>C:\Windows\system32\pegi-pt.rs/data005 - OK
>>C:\Windows\system32\pegi-pt.rs/data006 - OK
>C:\Windows\system32\pegi-pt.rs - OK
C:\Windows\system32\pegi.rs packed by ZLIB
>C:\Windows\system32\pegi.rs - archive BINARYRES
>>C:\Windows\system32\pegi.rs/data001 - OK
>C:\Windows\system32\pegi.rs - OK
C:\Windows\system32\pegibbfc.rs packed by ZLIB
>C:\Windows\system32\pegibbfc.rs - archive BINARYRES
>>C:\Windows\system32\pegibbfc.rs/data001 - OK
>>C:\Windows\system32\pegibbfc.rs/data002 - OK
>>C:\Windows\system32\pegibbfc.rs/data003 - OK
>>C:\Windows\system32\pegibbfc.rs/data004 - OK
>>C:\Windows\system32\pegibbfc.rs/data005 - OK
>>C:\Windows\system32\pegibbfc.rs/data006 - OK
>>C:\Windows\system32\pegibbfc.rs/data007 - OK
>C:\Windows\system32\pegibbfc.rs - OK
C:\Windows\system32\perfc009.dat - OK
C:\Windows\system32\PerfCenterCPL.dll - OK
C:\Windows\system32\PerfCenterCpl.ico - OK
C:\Windows\system32\perfctrs.dll - OK
C:\Windows\system32\perfd009.dat - OK
C:\Windows\system32\perfdisk.dll - OK
C:\Windows\system32\perfh009.dat - OK
C:\Windows\system32\perfi009.dat - OK
C:\Windows\system32\perfmon.exe - OK
C:\Windows\system32\perfmon.msc - OK
C:\Windows\system32\perfnet.dll - OK
C:\Windows\system32\perfos.dll - OK
C:\Windows\system32\perfproc.dll - OK
C:\Windows\system32\PerfStringBackup.INI - OK
C:\Windows\system32\perftrack.dll - OK
C:\Windows\system32\perfts.dll - OK
C:\Windows\system32\phon.ime - OK
C:\Windows\system32\PhotoMetadataHandler.dll - OK
C:\Windows\system32\PhotoScreensaver.scr packed by ZLIB
>C:\Windows\system32\PhotoScreensaver.scr - archive BINARYRES
>>C:\Windows\system32\PhotoScreensaver.scr/data001 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data002 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data003 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data004 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data005 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data006 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data007 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data008 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data009 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data010 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data011 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data012 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data013 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data014 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data015 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data016 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data017 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data018 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data019 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data020 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data021 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data022 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data023 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data024 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data025 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data026 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data027 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data028 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data029 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data030 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data031 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data032 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data033 - OK
>>C:\Windows\system32\PhotoScreensaver.scr/data034 - OK
>C:\Windows\system32\PhotoScreensaver.scr - OK
C:\Windows\system32\photowiz.dll - OK
C:\Windows\system32\pid.dll - OK
C:\Windows\system32\pidgenx.dll - OK
C:\Windows\system32\pifmgr.dll - OK
C:\Windows\system32\PING.EXE - OK
C:\Windows\system32\pintlgnt.ime - OK
C:\Windows\system32\PkgMgr.exe - OK
C:\Windows\system32\pku2u.dll - OK
C:\Windows\system32\pla.dll - OK
C:\Windows\system32\plasrv.exe - OK
C:\Windows\system32\PlaySndSrv.dll - OK
C:\Windows\system32\pngfilt.dll - OK
C:\Windows\system32\pnidui.dll - OK
C:\Windows\system32\pnpsetup.dll - OK
C:\Windows\system32\pnpts.dll - OK
C:\Windows\system32\pnpui.dll - OK
C:\Windows\system32\PnPUnattend.exe - OK
C:\Windows\system32\PnPutil.exe - OK
C:\Windows\system32\PNPXAssoc.dll - OK
C:\Windows\system32\PNPXAssocPrx.dll - OK
C:\Windows\system32\pnrpauto.dll - OK
C:\Windows\system32\Pnrphc.dll - OK
C:\Windows\system32\pnrpnsp.dll - OK
C:\Windows\system32\pnrpsvc.dll - OK
C:\Windows\system32\polstore.dll - OK
C:\Windows\system32\poqexec.exe - OK
C:\Windows\system32\PortableDeviceApi.dll - OK
C:\Windows\system32\PortableDeviceClassExtension.dll - OK
C:\Windows\system32\PortableDeviceConnectApi.dll - OK
C:\Windows\system32\PortableDeviceStatus.dll - OK
C:\Windows\system32\PortableDeviceSyncProvider.dll - OK
C:\Windows\system32\PortableDeviceTypes.dll - OK
C:\Windows\system32\PortableDeviceWiaCompat.dll - OK
C:\Windows\system32\PortableDeviceWMDRM.dll - OK
C:\Windows\system32\pots.dll - OK
C:\Windows\system32\powercfg.cpl - OK
C:\Windows\system32\powercfg.exe - OK
C:\Windows\system32\powercpl.dll - OK
C:\Windows\system32\powrprof.dll - OK
C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll - OK
C:\Windows\system32\PresentationHost.exe - OK
C:\Windows\system32\PresentationHostProxy.dll - OK
C:\Windows\system32\PresentationNative_v0300.dll - OK
C:\Windows\system32\prevhost.exe - OK
C:\Windows\system32\prflbmsg.dll - OK
C:\Windows\system32\print.exe - OK
C:\Windows\system32\printfilterpipelineprxy.dll - OK
C:\Windows\system32\printfilterpipelinesvc.exe - OK
C:\Windows\system32\PrintIsolationHost.exe - OK
C:\Windows\system32\PrintIsolationProxy.dll - OK
C:\Windows\system32\printui.dll - OK
C:\Windows\system32\printui.exe - OK
C:\Windows\system32\prncache.dll - OK
C:\Windows\system32\prnfldr.dll - OK
C:\Windows\system32\prnntfy.dll - OK
C:\Windows\system32\prntvpt.dll - OK
C:\Windows\system32\procinst.dll - OK
C:\Windows\system32\profapi.dll - OK
C:\Windows\system32\profprov.dll - OK
C:\Windows\system32\profsvc.dll - OK
C:\Windows\system32\propsys.dll - OK
C:\Windows\system32\proquota.exe - OK
C:\Windows\system32\provsvc.dll - OK
C:\Windows\system32\provthrd.dll - OK
C:\Windows\system32\psapi.dll - OK
C:\Windows\system32\psbase.dll - OK
C:\Windows\system32\pscript.sep - OK
C:\Windows\system32\PSHED.DLL - OK
C:\Windows\system32\psisdecd.dll - OK
C:\Windows\system32\psisrndr.ax - OK
C:\Windows\system32\psr.exe - OK
C:\Windows\system32\pstorec.dll - OK
C:\Windows\system32\pstorsvc.dll - OK
C:\Windows\system32\puiapi.dll - OK
C:\Windows\system32\puiobj.dll - OK
C:\Windows\system32\pwrshplugin.dll - OK
C:\Windows\system32\QAGENT.DLL - OK
C:\Windows\system32\QAGENTRT.DLL - OK
C:\Windows\system32\qasf.dll - OK
C:\Windows\system32\qcap.dll - OK
C:\Windows\system32\QCLIPROV.DLL - OK
C:\Windows\system32\qdv.dll - OK
C:\Windows\system32\qdvd.dll - OK
C:\Windows\system32\qedit.dll - OK
C:\Windows\system32\qedwipes.dll - OK
C:\Windows\system32\qintlgnt.ime - OK
C:\Windows\system32\qmgr.dll - OK
C:\Windows\system32\qmgrprxy.dll - OK
C:\Windows\system32\QSHVHOST.DLL - OK
C:\Windows\system32\QSVRMGMT.DLL - OK
C:\Windows\system32\quartz.dll - OK
C:\Windows\system32\Query.dll - OK
C:\Windows\system32\quick.ime - OK
C:\Windows\system32\QUTIL.DLL - OK
C:\Windows\system32\qwave.dll - OK
C:\Windows\system32\RacEngn.dll - OK
C:\Windows\system32\racpldlg.dll packed by ZLIB
>C:\Windows\system32\racpldlg.dll - archive BINARYRES
>>C:\Windows\system32\racpldlg.dll/data001 - OK
>>C:\Windows\system32\racpldlg.dll/data002 - OK
>>C:\Windows\system32\racpldlg.dll/data003 - OK
>>C:\Windows\system32\racpldlg.dll/data004 - OK
>C:\Windows\system32\racpldlg.dll - OK
C:\Windows\system32\RacRules.xml - OK
C:\Windows\system32\radardt.dll - OK
C:\Windows\system32\radarrs.dll - OK
C:\Windows\system32\rasadhlp.dll - OK
C:\Windows\system32\rasapi32.dll - OK
C:\Windows\system32\rasauto.dll - OK
C:\Windows\system32\rasautou.exe - OK
C:\Windows\system32\rascfg.dll - OK
C:\Windows\system32\raschap.dll - OK
C:\Windows\system32\rasctrnm.h - OK
C:\Windows\system32\rasctrs.dll - OK
C:\Windows\system32\rasdiag.dll - OK
C:\Windows\system32\rasdial.exe - OK
C:\Windows\system32\rasdlg.dll - OK
C:\Windows\system32\raserver.exe - OK
C:\Windows\system32\rasgcw.dll - OK
C:\Windows\system32\rasman.dll - OK
C:\Windows\system32\rasmans.dll - OK
C:\Windows\system32\rasmbmgr.dll - OK
C:\Windows\system32\RASMM.dll - OK
C:\Windows\system32\rasmontr.dll - OK
C:\Windows\system32\rasmxs.dll - OK
C:\Windows\system32\rasphone.exe - OK
C:\Windows\system32\rasplap.dll - OK
C:\Windows\system32\rasppp.dll - OK
C:\Windows\system32\rasser.dll - OK
C:\Windows\system32\rastapi.dll - OK
C:\Windows\system32\rastls.dll - OK
C:\Windows\system32\rdpcfgex.dll - OK
C:\Windows\system32\rdpcore.dll - OK
C:\Windows\system32\rdpcorekmts.dll - OK
C:\Windows\system32\rdpd3d.dll - OK
C:\Windows\system32\rdpdd.dll - OK
C:\Windows\system32\RDPENCDD.dll - OK
C:\Windows\system32\rdpencom.dll - OK
C:\Windows\system32\RDPREFDD.dll - OK
C:\Windows\system32\rdprefdrvapi.dll - OK
C:\Windows\system32\rdpwsx.dll - OK
C:\Windows\system32\rdrleakdiag.exe - OK
C:\Windows\system32\ReAgent.dll - OK
C:\Windows\system32\ReAgentc.exe - OK
C:\Windows\system32\recdisc.exe - OK
C:\Windows\system32\recover.exe - OK
C:\Windows\system32\recovery.dll - OK
C:\Windows\system32\reg.exe - OK
C:\Windows\system32\regapi.dll - OK
C:\Windows\system32\RegCtrl.dll - OK
C:\Windows\system32\regedt32.exe - OK
C:\Windows\system32\regidle.dll - OK
C:\Windows\system32\regini.exe - OK
C:\Windows\system32\RegisterIEPKEYs.exe - OK
C:\Windows\system32\regsvc.dll - OK
C:\Windows\system32\regsvr32.exe - OK
C:\Windows\system32\rekeywiz.exe - OK
C:\Windows\system32\relog.exe - OK
C:\Windows\system32\RelPost.exe - OK
C:\Windows\system32\remotepg.dll - OK
C:\Windows\system32\remotesp.tsp - OK
C:\Windows\system32\rendezvousSession.tlb - OK
C:\Windows\system32\repair-bde.exe - OK
C:\Windows\system32\replace.exe - OK
C:\Windows\system32\RESAMPLEDMO.DLL - OK
C:\Windows\system32\resmon.exe - OK
C:\Windows\system32\RestartManager.mof - OK
C:\Windows\system32\RestartManagerUninstall.mof - OK
C:\Windows\system32\resutils.dll - OK
C:\Windows\system32\rgb9rast.dll - OK
C:\Windows\system32\Ribbons.scr - OK
C:\Windows\system32\riched20.dll - OK
C:\Windows\system32\riched32.dll - OK
C:\Windows\system32\RMActivate.exe - OK
C:\Windows\system32\RMActivate_isv.exe - OK
C:\Windows\system32\RMActivate_ssp.exe - archive BINARYRES
>C:\Windows\system32\RMActivate_ssp.exe/data001 packed by ZLIB
>>C:\Windows\system32\RMActivate_ssp.exe/data001 - archive BINARYRES
>>C:\Windows\system32\RMActivate_ssp.exe/data001 - OK
C:\Windows\system32\RMActivate_ssp.exe - OK
C:\Windows\system32\RMActivate_ssp_isv.exe - OK
C:\Windows\system32\RmClient.exe - OK
C:\Windows\system32\rnr20.dll - OK
C:\Windows\system32\Robocopy.exe - OK
C:\Windows\system32\ROUTE.EXE - OK
C:\Windows\system32\RpcDiag.dll - OK
C:\Windows\system32\RpcEpMap.dll - OK
C:\Windows\system32\rpchttp.dll - OK
C:\Windows\system32\RPCNDFP.dll - OK
C:\Windows\system32\RpcNs4.dll - OK
C:\Windows\system32\rpcnsh.dll - OK
C:\Windows\system32\RpcPing.exe - OK
C:\Windows\system32\rpcrt4.dll - OK
C:\Windows\system32\RpcRtRemote.dll - OK
C:\Windows\system32\rpcss.dll - OK
C:\Windows\system32\rrinstaller.exe - OK
C:\Windows\system32\rsaenh.dll - OK
C:\Windows\system32\rshx32.dll - OK
C:\Windows\system32\RstrtMgr.dll - OK
C:\Windows\system32\rstrui.exe - OK
C:\Windows\system32\rtffilt.dll - OK
C:\Windows\system32\rtm.dll - OK
C:\Windows\system32\rtutils.dll - OK
C:\Windows\system32\runas.exe - OK
C:\Windows\system32\rundll32.exe - OK
C:\Windows\system32\RunLegacyCPLElevated.exe - OK
C:\Windows\system32\runonce.exe - OK
C:\Windows\system32\samcli.dll - OK
C:\Windows\system32\samlib.dll - OK
C:\Windows\system32\SampleRes.dll - OK
C:\Windows\system32\samsrv.dll - OK
C:\Windows\system32\sas.dll - OK
C:\Windows\system32\sbe.dll - OK
C:\Windows\system32\sbeio.dll - OK
C:\Windows\system32\sberes.dll - OK
C:\Windows\system32\sbunattend.exe - OK
C:\Windows\system32\sc.exe - OK
C:\Windows\system32\scansetting.dll - OK
C:\Windows\system32\SCardDlg.dll - OK
C:\Windows\system32\SCardSvr.dll - OK
C:\Windows\system32\ScavengeSpace.xml - OK
C:\Windows\system32\scavengeui.dll - OK
C:\Windows\system32\sccls.dll - OK
C:\Windows\system32\scecli.dll - OK
C:\Windows\system32\scesrv.dll - OK
C:\Windows\system32\scext.dll - OK
C:\Windows\system32\schannel.dll - OK
C:\Windows\system32\schedcli.dll - OK
C:\Windows\system32\schedsvc.dll - OK
C:\Windows\system32\schtasks.exe - OK
C:\Windows\system32\scksp.dll - OK
C:\Windows\system32\scripto.dll - archive BINARYRES
>C:\Windows\system32\scripto.dll/data001 - OK
C:\Windows\system32\scripto.dll - OK
C:\Windows\system32\scrnsave.scr - OK
C:\Windows\system32\scrobj.dll - OK
C:\Windows\system32\scrrun.dll - OK
C:\Windows\system32\sdautoplay.dll - OK
C:\Windows\system32\sdbinst.exe - OK
C:\Windows\system32\sdchange.exe - OK
C:\Windows\system32\sdclt.exe - OK
C:\Windows\system32\sdcpl.dll - OK
C:\Windows\system32\sdengin2.dll - OK
C:\Windows\system32\sdhcinst.dll - OK
C:\Windows\system32\sdiageng.dll - OK
C:\Windows\system32\sdiagnhost.exe - OK
C:\Windows\system32\sdiagprv.dll - OK
C:\Windows\system32\sdiagschd.dll - OK
C:\Windows\system32\sdohlp.dll - OK
C:\Windows\system32\sdrsvc.dll - OK
C:\Windows\system32\sdshext.dll - OK
C:\Windows\system32\SearchFilterHost.exe - OK
C:\Windows\system32\SearchFolder.dll - OK
C:\Windows\system32\SearchIndexer.exe - OK
C:\Windows\system32\SearchProtocolHost.exe - OK
C:\Windows\system32\SecEdit.exe - OK
C:\Windows\system32\sechost.dll - OK
C:\Windows\system32\secinit.exe - OK
C:\Windows\system32\seclogon.dll - OK
C:\Windows\system32\secproc.dll - OK
C:\Windows\system32\secproc_isv.dll - OK
C:\Windows\system32\secproc_ssp.dll - OK
C:\Windows\system32\secproc_ssp_isv.dll - OK
C:\Windows\system32\secur32.dll - OK
C:\Windows\system32\security.dll - OK
C:\Windows\system32\sendmail.dll - OK
C:\Windows\system32\Sens.dll - OK
C:\Windows\system32\SensApi.dll - OK
C:\Windows\system32\SensorsApi.dll - OK
C:\Windows\system32\SensorsClassExtension.dll - OK
C:\Windows\system32\SensorsCpl.dll - OK
C:\Windows\system32\sensrsvc.dll - OK
C:\Windows\system32\serialui.dll - OK
C:\Windows\system32\services.exe - OK
C:\Windows\system32\services.msc - OK
C:\Windows\system32\serwvdrv.dll - OK
C:\Windows\system32\SessEnv.dll - OK
C:\Windows\system32\setbcdlocale.dll - OK
C:\Windows\system32\sethc.exe - OK
C:\Windows\system32\SetIEInstalledDate.exe - OK
C:\Windows\system32\setspn.exe - OK
C:\Windows\system32\setupapi.dll packed by BINARYRES
>C:\Windows\system32\setupapi.dll packed by MS COMPRESS
>>C:\Windows\system32\setupapi.dll - OK
C:\Windows\system32\setupcl.exe - OK
C:\Windows\system32\setupcln.dll - OK
C:\Windows\system32\setupetw.dll - OK
C:\Windows\system32\setupugc.exe - OK
C:\Windows\system32\setx.exe - OK
C:\Windows\system32\sfc.dll - OK
C:\Windows\system32\sfc.exe - OK
C:\Windows\system32\sfc_os.dll - OK
C:\Windows\system32\shacct.dll - OK
C:\Windows\system32\sharemediacpl.dll - OK
C:\Windows\system32\shdocvw.dll - OK
C:\Windows\system32\shell32.dll - archive BINARYRES
>C:\Windows\system32\shell32.dll/data001 - OK
C:\Windows\system32\shell32.dll - OK
C:\Windows\system32\shellstyle.dll - OK
C:\Windows\system32\shfolder.dll - OK
C:\Windows\system32\shgina.dll - OK
C:\Windows\system32\ShiftJIS.uce - OK
C:\Windows\system32\shimeng.dll - OK
C:\Windows\system32\shimgvw.dll - OK
C:\Windows\system32\shlwapi.dll - OK
C:\Windows\system32\shpafact.dll - OK
C:\Windows\system32\shrpubw.exe - OK
C:\Windows\system32\shsetup.dll - OK
C:\Windows\system32\shsvcs.dll - OK
C:\Windows\system32\shunimpl.dll - OK
C:\Windows\system32\shutdown.exe - OK
C:\Windows\system32\shwebsvc.dll - OK
C:\Windows\system32\signdrv.dll - OK
C:\Windows\system32\sigverif.exe - OK
C:\Windows\system32\simpdata.tlb - OK
C:\Windows\system32\sisbkup.dll - OK
C:\Windows\system32\slc.dll - OK
C:\Windows\system32\slcext.dll - OK
C:\Windows\system32\slmgr.vbs - OK
C:\Windows\system32\slui.exe - OK
C:\Windows\system32\slwga.dll - OK
C:\Windows\system32\SmartcardCredentialProvider.dll - OK
C:\Windows\system32\SMBHelperClass.dll - OK
C:\Windows\system32\SmiEngine.dll - OK
C:\Windows\system32\smss.exe - OK
C:\Windows\system32\SndVol.exe - OK
C:\Windows\system32\SndVolSSO.dll - OK
C:\Windows\system32\SnippingTool.exe - OK
C:\Windows\system32\snmpapi.dll - OK
C:\Windows\system32\snmptrap.exe - OK
C:\Windows\system32\SNTSearch.dll - OK
C:\Windows\system32\softkbd.dll - OK
C:\Windows\system32\softpub.dll - OK
C:\Windows\system32\sort.exe - OK
C:\Windows\system32\SortServer2003Compat.dll - OK
C:\Windows\system32\SortWindows6Compat.dll - OK
C:\Windows\system32\SoundRecorder.exe - OK
C:\Windows\system32\spbcd.dll - OK
C:\Windows\system32\spcinstrumentation.man - OK
C:\Windows\system32\spcmsg.dll - OK
C:\Windows\system32\sperror.dll - OK
C:\Windows\system32\spfileq.dll packed by BINARYRES
>C:\Windows\system32\spfileq.dll packed by MS COMPRESS
>>C:\Windows\system32\spfileq.dll - OK
C:\Windows\system32\SPInf.dll - OK
C:\Windows\system32\spinstall.exe - OK
C:\Windows\system32\spnet.dll - OK
C:\Windows\system32\spoolss.dll - OK
C:\Windows\system32\spoolsv.exe - OK
C:\Windows\system32\spopk.dll - OK
C:\Windows\system32\spp.dll - OK
C:\Windows\system32\sppc.dll - OK
C:\Windows\system32\sppcc.dll - OK
C:\Windows\system32\sppcext.dll - OK
C:\Windows\system32\sppcomapi.dll - OK
C:\Windows\system32\sppcommdlg.dll - OK
C:\Windows\system32\sppinst.dll - OK
C:\Windows\system32\sppnp.dll - OK
C:\Windows\system32\sppobjs.dll - OK
C:\Windows\system32\sppsvc.exe - OK
C:\Windows\system32\sppuinotify.dll - OK
C:\Windows\system32\sppwinob.dll - OK
C:\Windows\system32\sppwmi.dll - OK
C:\Windows\system32\spreview.exe - OK
C:\Windows\system32\spwinsat.dll - OK
C:\Windows\system32\spwizeng.dll - OK
C:\Windows\system32\spwizimg.dll - OK
C:\Windows\system32\spwizres.dll - OK
C:\Windows\system32\spwizui.dll - OK
C:\Windows\system32\spwmp.dll - OK
C:\Windows\system32\sqlceoledb30.dll - OK
C:\Windows\system32\sqlceqp30.dll - OK
C:\Windows\system32\sqlcese30.dll - OK
C:\Windows\system32\sqlsrv32.dll - OK
C:\Windows\system32\sqlsrv32.rll - OK
C:\Windows\system32\sqmapi.dll - OK
C:\Windows\system32\srchadmin.dll - OK
C:\Windows\system32\srclient.dll - OK
C:\Windows\system32\srcore.dll - OK
C:\Windows\system32\srdelayed.exe - OK
C:\Windows\system32\srhelper.dll - OK
C:\Windows\system32\srrstr.dll - OK
C:\Windows\system32\srvcli.dll - OK
C:\Windows\system32\srvsvc.dll - OK
C:\Windows\system32\srwmi.dll - OK
C:\Windows\system32\sscore.dll - OK
C:\Windows\system32\ssdpapi.dll - OK
C:\Windows\system32\ssdpsrv.dll - OK
C:\Windows\system32\sspicli.dll - OK
C:\Windows\system32\sspisrv.dll - OK
C:\Windows\system32\SSShim.dll - OK
C:\Windows\system32\ssText3d.scr - OK
C:\Windows\system32\sstpsvc.dll - OK
C:\Windows\system32\stclient.dll - OK
C:\Windows\system32\stdole2.tlb - OK
C:\Windows\system32\stdole32.tlb - OK
C:\Windows\system32\sti.dll - OK
C:\Windows\system32\StikyNot.exe - OK
C:\Windows\system32\sti_ci.dll - OK
C:\Windows\system32\stobject.dll - OK
C:\Windows\system32\StorageContextHandler.dll - OK
C:\Windows\system32\Storprop.dll - OK
C:\Windows\system32\streamci.dll - OK
C:\Windows\system32\StructuredQuery.dll - OK
C:\Windows\system32\SubRange.uce - OK
C:\Windows\system32\subst.exe - OK
C:\Windows\system32\sud.dll - OK
C:\Windows\system32\svchost.exe - OK
C:\Windows\system32\swprv.dll - OK
C:\Windows\system32\sxproxy.dll - OK
C:\Windows\system32\sxs.dll - OK
C:\Windows\system32\sxshared.dll - OK
C:\Windows\system32\sxssrv.dll - OK
C:\Windows\system32\sxsstore.dll - OK
C:\Windows\system32\sxstrace.exe - OK
C:\Windows\system32\SyncCenter.dll - OK
C:\Windows\system32\synceng.dll - OK
C:\Windows\system32\SyncHost.exe - OK
C:\Windows\system32\SyncHostps.dll - OK
C:\Windows\system32\SyncInfrastructure.dll - OK
C:\Windows\system32\SyncInfrastructureps.dll - OK
C:\Windows\system32\Syncreg.dll - OK
C:\Windows\system32\syncui.dll - OK
C:\Windows\system32\sysclass.dll - OK
C:\Windows\system32\sysdm.cpl - OK
C:\Windows\system32\SysFxUI.dll - OK
C:\Windows\system32\syskey.exe - OK
C:\Windows\system32\sysmain.dll - OK
C:\Windows\system32\sysmon.ocx - OK
C:\Windows\system32\sysntfy.dll - OK
C:\Windows\system32\sysprepMCE.dll - OK
C:\Windows\system32\sysprint.sep - OK
C:\Windows\system32\sysprtj.sep - OK
C:\Windows\system32\syssetup.dll - OK
C:\Windows\system32\systemcpl.dll - OK
C:\Windows\system32\systeminfo.exe - OK
C:\Windows\system32\SystemPropertiesAdvanced.exe - OK
C:\Windows\system32\SystemPropertiesComputerName.exe - OK
C:\Windows\system32\SystemPropertiesDataExecutionPrevention.exe - OK
C:\Windows\system32\SystemPropertiesHardware.exe - OK
C:\Windows\system32\SystemPropertiesPerformance.exe - OK
C:\Windows\system32\SystemPropertiesProtection.exe - OK
C:\Windows\system32\SystemPropertiesRemote.exe - OK
C:\Windows\system32\systemsf.ebd - OK
C:\Windows\system32\systray.exe - OK
C:\Windows\system32\t2embed.dll - OK
C:\Windows\system32\Tabbtn.dll - OK
C:\Windows\system32\TabbtnEx.dll - OK
C:\Windows\system32\tabcal.exe - OK
C:\Windows\system32\TabletPC.cpl - OK
C:\Windows\system32\TabSvc.dll - OK
C:\Windows\system32\takeown.exe - OK
C:\Windows\system32\tapi3.dll - OK
C:\Windows\system32\tapi32.dll - OK
C:\Windows\system32\tapilua.dll - OK
C:\Windows\system32\TapiMigPlugin.dll - OK
C:\Windows\system32\tapiperf.dll - OK
C:\Windows\system32\tapisrv.dll - OK
C:\Windows\system32\TapiSysprep.dll - OK
C:\Windows\system32\tapiui.dll - OK
C:\Windows\system32\TapiUnattend.exe - OK
C:\Windows\system32\taskbarcpl.dll - OK
C:\Windows\system32\taskcomp.dll - OK
C:\Windows\system32\taskeng.exe - OK
C:\Windows\system32\taskhost.exe - OK
C:\Windows\system32\taskkill.exe - OK
C:\Windows\system32\tasklist.exe - OK
C:\Windows\system32\taskmgr.exe - OK
C:\Windows\system32\taskschd.dll - OK
C:\Windows\system32\taskschd.msc - OK
C:\Windows\system32\TaskSchdPS.dll - OK
C:\Windows\system32\tbs.dll - OK
C:\Windows\system32\tbssvc.dll - OK
C:\Windows\system32\tcmsetup.exe - OK
C:\Windows\system32\tcpbidi.xml - OK
C:\Windows\system32\tcpipcfg.dll - OK
C:\Windows\system32\tcpmib.dll - OK
C:\Windows\system32\tcpmon.dll - OK
C:\Windows\system32\tcpmon.ini - OK
C:\Windows\system32\tcpmonui.dll - OK
C:\Windows\system32\TCPSVCS.EXE - OK
C:\Windows\system32\tdc.ocx - OK
C:\Windows\system32\tdh.dll - OK
C:\Windows\system32\telephon.cpl - OK
C:\Windows\system32\termmgr.dll - OK
C:\Windows\system32\termsrv.dll - OK
C:\Windows\system32\thawbrkr.dll - OK
C:\Windows\system32\themecpl.dll - OK
C:\Windows\system32\themeservice.dll - OK
C:\Windows\system32\themeui.dll - OK
C:\Windows\system32\thumbcache.dll - OK
C:\Windows\system32\ticrf.rat - OK
C:\Windows\system32\timedate.cpl packed by ZLIB
>C:\Windows\system32\timedate.cpl - archive BINARYRES
>>C:\Windows\system32\timedate.cpl/data001 - OK
>>C:\Windows\system32\timedate.cpl/data002 - OK
>>C:\Windows\system32\timedate.cpl/data003 - OK
>>C:\Windows\system32\timedate.cpl/data004 - OK
>>C:\Windows\system32\timedate.cpl/data005 - OK
>>C:\Windows\system32\timedate.cpl/data006 - OK
>C:\Windows\system32\timedate.cpl - OK
C:\Windows\system32\TimeDateMUICallback.dll - OK
C:\Windows\system32\timeout.exe - OK
C:\Windows\system32\tintlgnt.ime - OK
C:\Windows\system32\tlscsp.dll - OK
C:\Windows\system32\tpm.msc - OK
C:\Windows\system32\tpmcompc.dll - OK
C:\Windows\system32\TpmInit.exe - OK
C:\Windows\system32\tquery.dll - OK
C:\Windows\system32\tracerpt.exe - OK
C:\Windows\system32\TRACERT.EXE - OK
C:\Windows\system32\traffic.dll - OK
C:\Windows\system32\TRAPI.dll - OK
C:\Windows\system32\tree.com - OK
C:\Windows\system32\trkwks.dll - OK
C:\Windows\system32\tsbyuv.dll - OK
C:\Windows\system32\TSChannel.dll - OK
C:\Windows\system32\tsddd.dll - OK
C:\Windows\system32\tsgqec.dll - OK
C:\Windows\system32\tsmf.dll - OK
C:\Windows\system32\TSpkg.dll - OK
C:\Windows\system32\TSTheme.exe - OK
C:\Windows\system32\TsUsbGDCoInstaller.dll - OK
C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe - OK
C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll - OK
C:\Windows\system32\TSWbPrxy.exe - OK
C:\Windows\system32\TSWorkspace.dll - OK
C:\Windows\system32\TsWpfWrp.exe - OK
C:\Windows\system32\tvratings.dll - OK
C:\Windows\system32\twext.dll - OK
C:\Windows\system32\txflog.dll - OK
C:\Windows\system32\txfw32.dll - OK
C:\Windows\system32\typeperf.exe - OK
C:\Windows\system32\tzres.dll - OK
C:\Windows\system32\tzutil.exe - OK
C:\Windows\system32\ubpm.dll - OK
C:\Windows\system32\ucmhc.dll - OK
C:\Windows\system32\ucsvc.exe - OK
C:\Windows\system32\udhisapi.dll - OK
C:\Windows\system32\uDWM.dll - OK
C:\Windows\system32\uexfat.dll - OK
C:\Windows\system32\ufat.dll - OK
C:\Windows\system32\UI0Detect.exe - OK
C:\Windows\system32\UIAnimation.dll - OK
C:\Windows\system32\UIAutomationCore.dll - OK
C:\Windows\system32\uicom.dll - OK
C:\Windows\system32\UIHub.dll - OK
C:\Windows\system32\UIRibbon.dll - OK
C:\Windows\system32\UIRibbonRes.dll - OK
C:\Windows\system32\ulib.dll - OK
C:\Windows\system32\umb.dll - OK
C:\Windows\system32\umdmxfrm.dll - OK
C:\Windows\system32\umpnpmgr.dll - OK
C:\Windows\system32\umpo.dll - OK
C:\Windows\system32\umstartup.etl - OK
C:\Windows\system32\umstartup000.etl - OK
C:\Windows\system32\unattend.dll - OK
C:\Windows\system32\unimdm.tsp - OK
C:\Windows\system32\unimdmat.dll - OK
C:\Windows\system32\uniplat.dll - OK
C:\Windows\system32\unlodctr.exe - OK
C:\Windows\system32\unregmp2.exe - OK
C:\Windows\system32\untfs.dll - OK
C:\Windows\system32\upnp.dll - OK
C:\Windows\system32\upnpcont.exe - OK
C:\Windows\system32\upnphost.dll - OK
C:\Windows\system32\ureg.dll - OK
C:\Windows\system32\url.dll - OK
C:\Windows\system32\urlmon.dll - archive BINARYRES
>C:\Windows\system32\urlmon.dll/data001 - OK
C:\Windows\system32\urlmon.dll - OK
C:\Windows\system32\usbceip.dll - OK
C:\Windows\system32\usbmon.dll - OK
C:\Windows\system32\usbperf.dll - OK
C:\Windows\system32\usbui.dll - OK
C:\Windows\system32\user32.dll - OK
C:\Windows\system32\UserAccountControlSettings.dll - OK
C:\Windows\system32\UserAccountControlSettings.exe - OK
C:\Windows\system32\usercpl.dll - OK
C:\Windows\system32\userenv.dll - OK
C:\Windows\system32\userinit.exe - OK
C:\Windows\system32\usk.rs packed by ZLIB
>C:\Windows\system32\usk.rs - archive BINARYRES
>>C:\Windows\system32\usk.rs/data001 - OK
>C:\Windows\system32\usk.rs - OK
C:\Windows\system32\usp10.dll - OK
C:\Windows\system32\utildll.dll - OK
C:\Windows\system32\Utilman.exe - OK
C:\Windows\system32\uudf.dll - OK
C:\Windows\system32\UXInit.dll - OK
C:\Windows\system32\uxlib.dll - OK
C:\Windows\system32\uxlibres.dll - OK
C:\Windows\system32\uxsms.dll - OK
C:\Windows\system32\uxtheme.dll - OK
C:\Windows\system32\VAN.dll - OK
C:\Windows\system32\Vault.dll - OK
C:\Windows\system32\vaultcli.dll - OK
C:\Windows\system32\VaultCmd.exe - OK
C:\Windows\system32\VaultCredProvider.dll - OK
C:\Windows\system32\vaultsvc.dll - OK
C:\Windows\system32\VaultSysUi.exe - OK
C:\Windows\system32\VBICodec.ax - OK
C:\Windows\system32\vbisurf.ax - OK
C:\Windows\system32\VBoxNetFltNotify.dll - OK
C:\Windows\system32\vbscript.dll - OK
C:\Windows\system32\vds.exe - OK
C:\Windows\system32\vdsbas.dll - OK
C:\Windows\system32\vdsdyn.dll - OK
C:\Windows\system32\vdsldr.exe - OK
C:\Windows\system32\vdsutil.dll - OK
C:\Windows\system32\vdsvd.dll - OK
C:\Windows\system32\vds_ps.dll - OK
C:\Windows\system32\verclsid.exe - OK
C:\Windows\system32\verifier.dll - OK
C:\Windows\system32\verifier.exe - OK
C:\Windows\system32\version.dll - OK
C:\Windows\system32\vfwwdm32.dll - OK
C:\Windows\system32\vga.dll - OK
C:\Windows\system32\vidcap.ax - OK
C:\Windows\system32\VIDRESZR.DLL - OK
C:\Windows\system32\virtdisk.dll - OK
C:\Windows\system32\vmnetbridge.dll - OK
C:\Windows\system32\vnetinst.dll - OK
C:\Windows\system32\vnetlib64.dll - OK
C:\Windows\system32\vpnike.dll - OK
C:\Windows\system32\vpnikeapi.dll - OK
C:\Windows\system32\vssadmin.exe - OK
C:\Windows\system32\vssapi.dll - OK
C:\Windows\system32\vsstrace.dll - OK
C:\Windows\system32\VSSVC.exe - OK
C:\Windows\system32\vss_ps.dll - OK
C:\Windows\system32\w32time.dll - OK
C:\Windows\system32\w32tm.exe - OK
C:\Windows\system32\w32topl.dll - OK
C:\Windows\system32\WABSyncProvider.dll - OK
C:\Windows\system32\wacomwucoinst3.dll - OK
C:\Windows\system32\waitfor.exe - OK
C:\Windows\system32\WavDest.dll - OK
C:\Windows\system32\wavemsp.dll - OK
C:\Windows\system32\wbadmin.exe - OK
C:\Windows\system32\wbemcomn.dll - OK
C:\Windows\system32\wbengine.exe - OK
C:\Windows\system32\wbiosrvc.dll - OK
C:\Windows\system32\WcnApi.dll - OK
C:\Windows\system32\wcncsvc.dll - OK
C:\Windows\system32\WcnEapAuthProxy.dll - OK
C:\Windows\system32\WcnEapPeerProxy.dll - OK
C:\Windows\system32\WcnNetsh.dll - OK
C:\Windows\system32\wcnwiz.dll - OK
C:\Windows\system32\WcsPlugInService.dll - OK
C:\Windows\system32\wdc.dll - OK
C:\Windows\system32\wdi.dll - OK
C:\Windows\system32\wdiasqmmodule.dll - OK
C:\Windows\system32\wdigest.dll - OK
C:\Windows\system32\wdmaud.drv - OK
C:\Windows\system32\wdscore.dll - OK
C:\Windows\system32\WdsUnattendTemplate.xml - OK
C:\Windows\system32\WEB.rs - OK
C:\Windows\system32\webcheck.dll - OK
C:\Windows\system32\WebClnt.dll - OK
C:\Windows\system32\webio.dll - OK
C:\Windows\system32\webservices.dll - OK
C:\Windows\system32\wecapi.dll - OK
C:\Windows\system32\wecsvc.dll - OK
C:\Windows\system32\wecutil.exe - OK
C:\Windows\system32\wer.dll - OK
C:\Windows\system32\werconcpl.dll - OK
C:\Windows\system32\wercplsupport.dll - OK
C:\Windows\system32\werdiagcontroller.dll - OK
C:\Windows\system32\WerFault.exe - OK
C:\Windows\system32\WerFaultSecure.exe - OK
C:\Windows\system32\wermgr.exe - OK
C:\Windows\system32\wersvc.dll - OK
C:\Windows\system32\werui.dll - OK
C:\Windows\system32\wevtapi.dll - OK
C:\Windows\system32\wevtfwd.dll - OK
C:\Windows\system32\wevtsvc.dll - OK
C:\Windows\system32\wevtutil.exe - OK
C:\Windows\system32\wextract.exe - OK
C:\Windows\system32\WF.msc - OK
C:\Windows\system32\wfapigp.dll - OK
C:\Windows\system32\WfHC.dll - OK
C:\Windows\system32\WFS.exe - OK
C:\Windows\system32\WFSR.dll - OK
C:\Windows\system32\whealogr.dll - OK
C:\Windows\system32\where.exe - OK
C:\Windows\system32\whhelper.dll - OK
C:\Windows\system32\whoami.exe - OK
C:\Windows\system32\wiaacmgr.exe - OK
C:\Windows\system32\wiaaut.dll - OK
C:\Windows\system32\wiadefui.dll - OK
C:\Windows\system32\wiadss.dll - OK
C:\Windows\system32\WiaExtensionHost64.dll - OK
C:\Windows\system32\wiarpc.dll - OK
C:\Windows\system32\wiascanprofiles.dll - OK
C:\Windows\system32\wiaservc.dll - OK
C:\Windows\system32\wiashext.dll - OK
C:\Windows\system32\wiatrace.dll - OK
C:\Windows\system32\wiavideo.dll - OK
C:\Windows\system32\wiawow64.exe - OK
C:\Windows\system32\wimgapi.dll - OK
C:\Windows\system32\wimserv.exe - OK
C:\Windows\system32\win32k.sys - OK
C:\Windows\system32\win32spl.dll - OK
C:\Windows\system32\winbio.dll - OK
C:\Windows\system32\winbrand.dll - OK
C:\Windows\system32\wincredprovider.dll - OK
C:\Windows\system32\WindowsAnytimeUpgrade.exe - OK
C:\Windows\system32\WindowsAnytimeUpgradeResults.exe - OK
C:\Windows\system32\WindowsAnytimeUpgradeui.exe - OK
C:\Windows\system32\WindowsCodecs.dll - OK
C:\Windows\system32\WindowsCodecsExt.dll - OK
C:\Windows\system32\winethc.dll - OK
C:\Windows\system32\WinFax.dll - OK
C:\Windows\system32\winhttp.dll - OK
C:\Windows\system32\wininet.dll - archive BINARYRES
>C:\Windows\system32\wininet.dll/data001 - OK
C:\Windows\system32\wininet.dll - OK
C:\Windows\system32\wininit.exe - OK
C:\Windows\system32\winipsec.dll - OK
C:\Windows\system32\winload.efi - OK
C:\Windows\system32\winload.exe - OK
C:\Windows\system32\winlogon.exe - OK
C:\Windows\system32\winmm.dll - OK
C:\Windows\system32\winnsi.dll - OK
C:\Windows\system32\winresume.efi - OK
C:\Windows\system32\winresume.exe - OK
C:\Windows\system32\winrm.cmd - OK
C:\Windows\system32\winrm.vbs - OK
C:\Windows\system32\winrnr.dll - OK
C:\Windows\system32\winrs.exe - OK
C:\Windows\system32\winrscmd.dll - OK
C:\Windows\system32\winrshost.exe - OK
C:\Windows\system32\winrsmgr.dll - OK
C:\Windows\system32\winrssrv.dll - OK
C:\Windows\system32\WinSAT.exe - OK
C:\Windows\system32\WinSATAPI.dll packed by ZLIB
>C:\Windows\system32\WinSATAPI.dll - archive BINARYRES
>>C:\Windows\system32\WinSATAPI.dll/data001 - OK
>>C:\Windows\system32\WinSATAPI.dll/data002 - OK
>C:\Windows\system32\WinSATAPI.dll - OK
C:\Windows\system32\WinSCard.dll - OK
C:\Windows\system32\winshfhc.dll - OK
C:\Windows\system32\winsockhc.dll - OK
C:\Windows\system32\winspool.drv - OK
C:\Windows\system32\WINSRPC.DLL - OK
C:\Windows\system32\winsrv.dll - OK
C:\Windows\system32\winsta.dll - OK
C:\Windows\system32\WinSync.dll - OK
C:\Windows\system32\WinSyncMetastore.dll - OK
C:\Windows\system32\WinSyncProviders.dll - OK
C:\Windows\system32\wintrust.dll - OK
C:\Windows\system32\winusb.dll - OK
C:\Windows\system32\winver.exe - OK
C:\Windows\system32\wisptis.exe - OK
C:\Windows\system32\wkscli.dll - OK
C:\Windows\system32\wksprt.exe - OK
C:\Windows\system32\wksprtPS.dll - OK
C:\Windows\system32\wkssvc.dll - OK
C:\Windows\system32\wlanapi.dll - OK
C:\Windows\system32\wlancfg.dll - OK
C:\Windows\system32\WLanConn.dll - OK
C:\Windows\system32\wlandlg.dll - OK
C:\Windows\system32\wlanext.exe - OK
C:\Windows\system32\wlangpui.dll - OK
C:\Windows\system32\WLanHC.dll - OK
C:\Windows\system32\wlanhlp.dll - OK
C:\Windows\system32\wlaninst.dll - OK
C:\Windows\system32\WlanMM.dll - OK
C:\Windows\system32\wlanmsm.dll - OK
C:\Windows\system32\wlanpref.dll - OK
C:\Windows\system32\wlansec.dll - OK
C:\Windows\system32\wlansvc.dll - OK
C:\Windows\system32\wlanui.dll - OK
C:\Windows\system32\wlanutil.dll - OK
C:\Windows\system32\Wldap32.dll - OK
C:\Windows\system32\wlgpclnt.dll - OK
C:\Windows\system32\wlrmdr.exe - OK
C:\Windows\system32\WlS0WndH.dll - OK
C:\Windows\system32\WMADMOD.DLL - OK
C:\Windows\system32\WMADMOE.DLL - OK
C:\Windows\system32\WMALFXGFXDSP.dll - OK
C:\Windows\system32\WMASF.DLL - OK
C:\Windows\system32\wmcodecdspps.dll - OK
C:\Windows\system32\wmdmlog.dll - OK
C:\Windows\system32\wmdmps.dll - OK
C:\Windows\system32\wmdrmdev.dll - OK
C:\Windows\system32\wmdrmnet.dll - OK
C:\Windows\system32\wmdrmsdk.dll - OK
C:\Windows\system32\wmerror.dll - OK
C:\Windows\system32\wmi.dll - OK
C:\Windows\system32\wmicmiplugin.dll - OK
C:\Windows\system32\wmidx.dll - OK
C:\Windows\system32\WmiMgmt.msc - OK
C:\Windows\system32\wmiprop.dll - OK
C:\Windows\system32\WMNetMgr.dll - OK
C:\Windows\system32\wmp.dll - OK
C:\Windows\system32\wmpcm.dll - OK
C:\Windows\system32\WmpDui.dll - OK
C:\Windows\system32\wmpdxm.dll - OK
C:\Windows\system32\wmpeffects.dll - OK
C:\Windows\system32\WMPEncEn.dll - OK
C:\Windows\system32\WMPhoto.dll - OK
C:\Windows\system32\wmploc.DLL - OK
C:\Windows\system32\wmpmde.dll packed by PESTUB
>C:\Windows\system32\wmpmde.dll - OK
C:\Windows\system32\wmpps.dll - OK
C:\Windows\system32\wmpshell.dll - OK
C:\Windows\system32\wmpsrcwp.dll - OK
C:\Windows\system32\wmsgapi.dll - OK
C:\Windows\system32\WMSPDMOD.DLL - OK
C:\Windows\system32\WMSPDMOE.DLL - OK
C:\Windows\system32\WMVCORE.DLL - OK
C:\Windows\system32\WMVDECOD.DLL - OK
C:\Windows\system32\wmvdspa.dll - OK
C:\Windows\system32\WMVENCOD.DLL - OK
C:\Windows\system32\WMVSDECD.DLL - OK
C:\Windows\system32\WMVSENCD.DLL - OK
C:\Windows\system32\WMVXENCD.DLL - OK
C:\Windows\system32\wow64.dll - OK
C:\Windows\system32\wow64cpu.dll - OK
C:\Windows\system32\wow64win.dll - OK
C:\Windows\system32\wowreg32.exe - OK
C:\Windows\system32\Wpc.dll - OK
C:\Windows\system32\wpcao.dll - OK
C:\Windows\system32\wpccpl.dll - OK
C:\Windows\system32\wpcmig.dll - OK
C:\Windows\system32\wpcsvc.dll - OK
C:\Windows\system32\wpcumi.dll - OK
C:\Windows\system32\wpdbusenum.dll - OK
C:\Windows\system32\WpdMtp.dll - OK
C:\Windows\system32\WpdMtpUS.dll - OK
C:\Windows\system32\wpdshext.dll - OK
C:\Windows\system32\WPDShextAutoplay.exe - OK
C:\Windows\system32\WPDShServiceObj.dll - OK
C:\Windows\system32\WPDSp.dll - OK
C:\Windows\system32\wpdwcn.dll - OK
C:\Windows\system32\wpd_ci.dll - OK
C:\Windows\system32\wpnpinst.exe - OK
C:\Windows\system32\wrap_oal.dll - OK
C:\Windows\system32\write.exe - OK
C:\Windows\system32\ws2help.dll - OK
C:\Windows\system32\ws2_32.dll - OK
C:\Windows\system32\wscapi.dll - OK
C:\Windows\system32\wscinterop.dll - OK
C:\Windows\system32\wscisvif.dll - OK
C:\Windows\system32\wscmisetup.dll - OK
C:\Windows\system32\wscproxystub.dll - OK
C:\Windows\system32\wscript.exe - OK
C:\Windows\system32\wscsvc.dll - OK
C:\Windows\system32\wscui.cpl packed by ZLIB
>C:\Windows\system32\wscui.cpl - archive BINARYRES
>>C:\Windows\system32\wscui.cpl/data001 - OK
>>C:\Windows\system32\wscui.cpl/data002 - OK
>>C:\Windows\system32\wscui.cpl/data003 - OK
>>C:\Windows\system32\wscui.cpl/data004 - OK
>>C:\Windows\system32\wscui.cpl/data005 - OK
>>C:\Windows\system32\wscui.cpl/data006 - OK
>>C:\Windows\system32\wscui.cpl/data007 - OK
>>C:\Windows\system32\wscui.cpl/data008 - OK
>>C:\Windows\system32\wscui.cpl/data009 - OK
>>C:\Windows\system32\wscui.cpl/data010 - OK
>>C:\Windows\system32\wscui.cpl/data011 - OK
>>C:\Windows\system32\wscui.cpl/data012 - OK
>>C:\Windows\system32\wscui.cpl/data013 - OK
>>C:\Windows\system32\wscui.cpl/data014 - OK
>>C:\Windows\system32\wscui.cpl/data015 - OK
>C:\Windows\system32\wscui.cpl - OK
C:\Windows\system32\WSDApi.dll - OK
C:\Windows\system32\wsdchngr.dll - OK
C:\Windows\system32\WSDMon.dll - OK
C:\Windows\system32\WSDPrintProxy.DLL - OK
C:\Windows\system32\WSDScanProxy.dll - OK
C:\Windows\system32\wsecedit.dll - OK
C:\Windows\system32\wsepno.dll - OK
C:\Windows\system32\wshbth.dll - OK
C:\Windows\system32\wshcon.dll - OK
C:\Windows\system32\wshelper.dll - OK
C:\Windows\system32\wshext.dll - OK
C:\Windows\system32\wship6.dll - OK
C:\Windows\system32\wshirda.dll - OK
C:\Windows\system32\wshnetbs.dll - OK
C:\Windows\system32\wshom.ocx - OK
C:\Windows\system32\wshqos.dll - OK
C:\Windows\system32\wshrm.dll - OK
C:\Windows\system32\WSHTCPIP.DLL - OK
C:\Windows\system32\wsmanconfig_schema.xml - OK
C:\Windows\system32\WSManHTTPConfig.exe - OK
C:\Windows\system32\WSManMigrationPlugin.dll - OK
C:\Windows\system32\WsmAuto.dll - OK
C:\Windows\system32\wsmplpxy.dll - OK
C:\Windows\system32\wsmprovhost.exe - OK
C:\Windows\system32\WsmPty.xsl - OK
C:\Windows\system32\WsmRes.dll - OK
C:\Windows\system32\WsmSvc.dll - OK
C:\Windows\system32\WsmTxt.xsl - OK
C:\Windows\system32\WsmWmiPl.dll - OK
C:\Windows\system32\wsnmp32.dll - OK
C:\Windows\system32\wsock32.dll - OK
C:\Windows\system32\wsqmcons.exe - OK
C:\Windows\system32\WSTPager.ax - OK
C:\Windows\system32\wtsapi32.dll - OK
C:\Windows\system32\wuapi.dll - OK
C:\Windows\system32\wuapp.exe - OK
C:\Windows\system32\wuauclt.exe - OK
C:\Windows\system32\wuaueng.dll - OK
C:\Windows\system32\wucltux.dll - OK
C:\Windows\system32\WUDFCoinstaller.dll - OK
C:\Windows\system32\WUDFHost.exe - OK
C:\Windows\system32\WUDFPlatform.dll - OK
C:\Windows\system32\WUDFSvc.dll - OK
C:\Windows\system32\WUDFx.dll - OK
C:\Windows\system32\wudriver.dll - OK
C:\Windows\system32\wups.dll - OK
C:\Windows\system32\wups2.dll - OK
C:\Windows\system32\wusa.exe - OK
C:\Windows\system32\wuwebv.dll - OK
C:\Windows\system32\wvc.dll - OK
C:\Windows\system32\Wwanadvui.dll - OK
C:\Windows\system32\WWanAPI.dll - OK
C:\Windows\system32\wwancfg.dll - OK
C:\Windows\system32\wwanconn.dll - OK
C:\Windows\system32\WWanHC.dll - OK
C:\Windows\system32\wwaninst.dll - OK
C:\Windows\system32\wwanmm.dll - OK
C:\Windows\system32\Wwanpref.dll - OK
C:\Windows\system32\wwanprotdim.dll - OK
C:\Windows\system32\wwansvc.dll - OK
C:\Windows\system32\wwapi.dll - OK
C:\Windows\system32\wzcdlg.dll - OK
C:\Windows\system32\x3daudio1_0.dll - OK
C:\Windows\system32\xactengine2_0.dll - OK
C:\Windows\system32\xactengine2_1.dll - OK
C:\Windows\system32\xactengine2_2.dll - OK
C:\Windows\system32\xactengine2_3.dll - OK
C:\Windows\system32\xcopy.exe - OK
C:\Windows\system32\xinput1_1.dll - OK
C:\Windows\system32\xinput1_2.dll - OK
C:\Windows\system32\XInput9_1_0.dll - OK
C:\Windows\system32\xmlfilter.dll - OK
C:\Windows\system32\xmllite.dll - OK
C:\Windows\system32\xmlprovi.dll - OK
C:\Windows\system32\xolehlp.dll - OK
C:\Windows\system32\XpsFilt.dll - OK
C:\Windows\system32\XpsGdiConverter.dll - OK
C:\Windows\system32\XpsPrint.dll - OK
C:\Windows\system32\XpsRasterService.dll - OK
C:\Windows\system32\xpsrchvw.exe - OK
C:\Windows\system32\xpsrchvw.xml - OK
C:\Windows\system32\xpsservices.dll - OK
C:\Windows\system32\XPSSHHDR.dll - OK
C:\Windows\system32\xpssvcs.dll - OK
C:\Windows\system32\xwizard.dtd - OK
C:\Windows\system32\xwizard.exe - OK
C:\Windows\system32\xwizards.dll - OK
C:\Windows\system32\xwreg.dll - OK
C:\Windows\system32\xwtpdui.dll - OK
C:\Windows\system32\xwtpw32.dll - OK
C:\Windows\system32\zgmprxy.dll - OK
C:\Windows\system32\zipfldr.dll - OK
C:\Windows\system32\AdvancedInstallers\cmiadapter.dll - OK
C:\Windows\system32\AdvancedInstallers\cmitrust.dll - OK
C:\Windows\system32\AdvancedInstallers\cmiv2.dll - OK
C:\Windows\system32\AdvancedInstallers\CntrtextInstaller.DLL - OK
C:\Windows\system32\AdvancedInstallers\locdrv.dll - OK
C:\Windows\system32\AdvancedInstallers\OEMHelpIns.dll - OK
C:\Windows\system32\ar-SA\cdosys.dll.mui - OK
C:\Windows\system32\ar-SA\comctl32.dll.mui - OK
C:\Windows\system32\ar-SA\comdlg32.dll.mui - OK
C:\Windows\system32\ar-SA\fms.dll.mui - OK
C:\Windows\system32\ar-SA\mlang.dll.mui - OK
C:\Windows\system32\ar-SA\msimsg.dll.mui - OK
C:\Windows\system32\ar-SA\msprivs.dll.mui - OK
C:\Windows\system32\bg-BG\comctl32.dll.mui - OK
C:\Windows\system32\bg-BG\comdlg32.dll.mui - OK
C:\Windows\system32\bg-BG\fms.dll.mui - OK
C:\Windows\system32\bg-BG\mlang.dll.mui - OK
C:\Windows\system32\bg-BG\msimsg.dll.mui - OK
C:\Windows\system32\Boot\winload.efi - OK
C:\Windows\system32\Boot\winload.exe - OK
C:\Windows\system32\Boot\winresume.efi - OK
C:\Windows\system32\Boot\winresume.exe - OK
C:\Windows\system32\Boot\en-US\winload.efi.mui - OK
C:\Windows\system32\Boot\en-US\winload.exe.mui - OK
C:\Windows\system32\Boot\en-US\winresume.efi.mui - OK
C:\Windows\system32\Boot\en-US\winresume.exe.mui - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Hyper-V-Common-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Hyper-V-Common-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Hyper-V-Guest-Integration-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Hyper-V-Guest-Integration-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Media-Foundation-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Media-Foundation-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Media-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Media-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Anytime-Upgrade-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Anytime-Upgrade-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Anytime-Upgrade-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Anytime-Upgrade-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Anytime-Upgrade-Results-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Anytime-Upgrade-Results-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Anytime-Upgrade-Results-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Anytime-Upgrade-Results-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Backup-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Backup-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Backup-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Backup-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-BLB-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-BLB-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-BLB-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-BLB-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Branding-HomePremium-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Branding-HomePremium-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Branding-HomePremium-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Branding-HomePremium-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Branding-Professional-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Branding-Professional-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Branding-Professional-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Branding-Professional-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Branding-Ultimate-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Branding-Ultimate-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Branding-Ultimate-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Branding-Ultimate-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-BusinessScanning-Feature-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-BusinessScanning-Feature-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-BusinessScanning-Feature-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-BusinessScanning-Feature-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Drivers-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Drivers-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-LanguagePack-Package-wrapper~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Wired-Network-Drivers-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Wired-Network-Drivers-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Wired-Network-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Wired-Network-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ClipsInTheLibrary-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ClipsInTheLibrary-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ClipsInTheLibrary-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ClipsInTheLibrary-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-CodecPack-Basic-Encoder-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-CodecPack-Basic-Encoder-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-CodecPack-Basic-Package-wrapper~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-CodecPack-Basic-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-CodecPack-Basic-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-CodecPack-Basic-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-CodecPack-Basic-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Common-Drivers-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Common-Drivers-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Common-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Common-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Common-Modem-Drivers-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Common-Modem-Drivers-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Common-Modem-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Common-Modem-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-DesktopWindowManager-uDWM-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-DesktopWindowManager-uDWM-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Disk-Diagnosis-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Disk-Diagnosis-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Disk-Diagnosis-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Disk-Diagnosis-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Editions-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Editions-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Gadget-Platform-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Gadget-Platform-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Gadget-Platform-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Gadget-Platform-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GPUPipeline-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GPUPipeline-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GPUPipeline-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GPUPipeline-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientExtensions-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientExtensions-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientExtensions-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientExtensions-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-CoreClientUAHP-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-CoreClientUAHP-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-CoreClientUAHP-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-CoreClientUAHP-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-CoreClientUAPS-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-CoreClientUAPS-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-CoreClientUAPS-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-CoreClientUAPS-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-CoreClientUAUE-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-CoreClientUAUE-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-CoreClientUAUE-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-CoreClientUAUE-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-Customization-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-Customization-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-Customization-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Help-Customization-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-HomePremiumEdition-wrapper~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-HomePremiumEdition~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-HomePremiumEdition~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ICM-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ICM-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ICM-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ICM-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IE-Troubleshooters-Package-wrapper~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IE-Troubleshooters-Package-wrapper~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IE-Troubleshooters-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IE-Troubleshooters-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IE-Troubleshooters-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IE-Troubleshooters-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IIS-WebServer-AddOn-2-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IIS-WebServer-AddOn-2-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IIS-WebServer-AddOn-2-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IIS-WebServer-AddOn-2-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IIS-WebServer-AddOn-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IIS-WebServer-AddOn-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IIS-WebServer-AddOn-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IIS-WebServer-AddOn-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IIS-WebServer-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IIS-WebServer-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IIS-WebServer-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IIS-WebServer-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Indexing-Service-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Indexing-Service-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Indexing-Service-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Indexing-Service-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Optional-Package-wrapper~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Optional-Package-wrapper~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~en-US~8.0.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~en-US~8.0.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~~8.0.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~~8.0.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Package~31bf3856ad364e35~amd64~en-US~8.0.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Package~31bf3856ad364e35~amd64~en-US~8.0.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Package~31bf3856ad364e35~amd64~~8.0.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Package~31bf3856ad364e35~amd64~~8.0.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Killbits-Package~31bf3856ad364e35~amd64~~8.0.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Killbits-Package~31bf3856ad364e35~amd64~~8.0.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Links-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Links-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Links-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Links-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-LocalPack-AU-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-LocalPack-CA-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-LocalPack-GB-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-LocalPack-US-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-LocalPack-ZA-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Media-Format-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Media-Format-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Media-Format-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Media-Format-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MediaCenter-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MediaCenter-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MediaCenter-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MediaCenter-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MediaPlayback-OC-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MediaPlayback-OC-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MediaPlayback-OC-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MediaPlayback-OC-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MediaPlayer-DVDRegistration-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MediaPlayer-DVDRegistration-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-Basic-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-Basic-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-Basic-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-Basic-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-Premium-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-Premium-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-Premium-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-Premium-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-Sensors-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-Sensors-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-Sensors-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-Sensors-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-SideShow-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-SideShow-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-SideShow-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-SideShow-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MSMQ-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MSMQ-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MSMQ-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MSMQ-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-NetFx3-OC-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-NetFx3-OC-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-NetFx3-OC-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-NetFx3-OC-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-NetworkDiagnostics-DirectAccessEntry-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-NetworkDiagnostics-DirectAccessEntry-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-NFS-ClientSKU-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-NFS-ClientSKU-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-NFS-ClientSKU-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-NFS-ClientSKU-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OfflineFiles-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OfflineFiles-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OfflineFiles-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OfflineFiles-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OpticalMediaDisc-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OpticalMediaDisc-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OpticalMediaDisc-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OpticalMediaDisc-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ParentalControls-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ParentalControls-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ParentalControls-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ParentalControls-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PeerDist-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PeerDist-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PeerDist-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PeerDist-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PeerToPeer-Full-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PeerToPeer-Full-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PeerToPeer-Full-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PeerToPeer-Full-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Personalization-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Personalization-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PhotoBasicPackage~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PhotoBasicPackage~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PhotoBasicPackage~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PhotoBasicPackage~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PhotoPremiumPackage~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PhotoPremiumPackage~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PhotoPremiumPackage~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-PhotoPremiumPackage~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printer-Drivers-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printer-Drivers-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printer-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printer-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-Foundation-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-Foundation-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-LocalPrinting-Home-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-LocalPrinting-Home-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-PremiumTools-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-PremiumTools-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-PremiumTools-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-PremiumTools-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ProfessionalEdition-wrapper~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RasRip-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RasRip-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RasRip-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RasRip-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RDC-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RDC-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RDC-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RDC-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RecDisc-SDP-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RecDisc-SDP-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RecDisc-SDP-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RecDisc-SDP-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RemoteAssistance-Package-Client~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RemoteAssistance-Package-Client~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RemoteAssistance-Package-Client~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RemoteAssistance-Package-Client~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RemoteFX-RemoteClient-Setup-LanguagePack~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RemoteFX-RemoteClient-Setup-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RemoteFX-VM-Setup-LanguagePack~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RemoteFX-VM-Setup-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SampleContent-Music-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SampleContent-Music-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SampleContent-Ringtones-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SampleContent-Ringtones-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SearchEngine-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SearchEngine-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SearchEngine-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SearchEngine-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Basic-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Basic-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Basic-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Basic-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Security-SPP-Component-SKU-HomePremium-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Security-SPP-Component-SKU-HomePremium-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Security-SPP-Component-SKU-Professional-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Security-SPP-Component-SKU-Professional-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Security-SPP-Component-SKU-Ultimate-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Security-SPP-Component-SKU-Ultimate-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Security-WindowsActivationTechnologies-Package~31bf3856ad364e35~amd64~~7.1.7600.16395.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ServicingBaseline-Ultimate-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ServicingBaseline-Ultimate-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ShareMedia-ControlPanel-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ShareMedia-ControlPanel-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ShareMedia-ControlPanel-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ShareMedia-ControlPanel-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-HomeGroup-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-HomeGroup-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-HomeGroup-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-HomeGroup-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-InboxGames-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-InboxGames-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-InboxGames-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-InboxGames-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-MultiplayerInboxGames-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-MultiplayerInboxGames-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-MultiplayerInboxGames-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-MultiplayerInboxGames-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-PremiumInboxGames-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-PremiumInboxGames-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-PremiumInboxGames-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-PremiumInboxGames-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-SoundThemes-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Shell-SoundThemes-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Sidebar-Killbits-SDP-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Sidebar-Killbits-SDP-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SimpleTCP-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SimpleTCP-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SimpleTCP-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SimpleTCP-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SnippingTool-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SnippingTool-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SnippingTool-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SnippingTool-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SNMP-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SNMP-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SNMP-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SNMP-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-StickyNotes-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-StickyNotes-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-StickyNotes-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-StickyNotes-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-StorageService-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-StorageService-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-StorageService-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-StorageService-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SUA-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SUA-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SUA-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SUA-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SystemRestore-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SystemRestore-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SystemRestore-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SystemRestore-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TabletPC-OC-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TabletPC-OC-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TabletPC-OC-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TabletPC-OC-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Telnet-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Telnet-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Telnet-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Telnet-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Telnet-Server-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Telnet-Server-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Telnet-Server-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Telnet-Server-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TFTP-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TFTP-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TFTP-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TFTP-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Tuner-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Tuner-Drivers-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-UltimateEdition-wrapper~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-UltimateEdition~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-UltimateEdition~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-VirtualPC-Licensing-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-VirtualPC-Licensing-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-VirtualPC-USB-RPM-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-VirtualPC-USB-RPM-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-VirtualPC-USB-RPM-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-VirtualPC-USB-RPM-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-VirtualXP-Licensing-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-VirtualXP-Licensing-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WindowsMediaPlayer-Troubleshooters-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WindowsMediaPlayer-Troubleshooters-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WindowsMediaPlayer-Troubleshooters-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WindowsMediaPlayer-Troubleshooters-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WinOcr-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WinOcr-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WinOcr-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WinOcr-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WMI-SNMP-Provider-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WMI-SNMP-Provider-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WMI-SNMP-Provider-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WMI-SNMP-Provider-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WMPNetworkSharingService-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WMPNetworkSharingService-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WMPNetworkSharingService-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WMPNetworkSharingService-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Xps-Foundation-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Xps-Foundation-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Xps-Foundation-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Xps-Foundation-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Networking-MPSSVC-Rules-BusinessEdition-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Networking-MPSSVC-Rules-BusinessEdition-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Networking-MPSSVC-Rules-HomePremiumEdition-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Networking-MPSSVC-Rules-HomePremiumEdition-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Networking-MPSSVC-Rules-UltimateEdition-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Networking-MPSSVC-Rules-UltimateEdition-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntexe.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntph.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntprint.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem1.CAT - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem11.CAT - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem12.CAT - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem13.CAT - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem14.CAT - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem15.CAT - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem2.CAT - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem3.CAT - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem4.CAT - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem5.CAT - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem6.CAT - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem7.CAT - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem9.CAT - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_104_for_KB982018~31bf3856ad364e35~amd64~~6.1.3.2.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_105_for_KB982018~31bf3856ad364e35~amd64~~6.1.3.2.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_10_for_KB2497640~31bf3856ad364e35~amd64~~6.1.1.2.cat - OK
C:\Windows\system32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_10_for_KB2507938~31bf3856ad364e35~amd64~~6.1.1.4.cat - OK




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users