ADVERTISEMENT

FRST.txt

Infekcja powodująca tworzenie się skrótów na pendrive'ach

Witam Mam taki sam problem, pozwolę sobie więc podpiąć po ten temat. W załącznikach pliki z FRST i USBfix. Z góry dziękuję za pomoc. Post wydzieliłem do nowego tematu. W przyszłości proszę nie doczepiać się do cudzych wątków i przed napisaniem tematu zapoznać się z regulaminem forum i wewnętrznymi zasadami działu: http://www.elektroda.pl/rtvforum/faq.php http://www.elektroda.pl/rtvforum/topic1159685.html http://www.elektroda.pl/rtvforum/topic1044160.html


Download file - link to post

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-04-2015
Ran by Joanna (administrator) on JOANNA-MSI on 21-04-2015 16:07:14
Running from C:\Users\Joanna\Downloads
Loaded Profiles: Joanna (Available profiles: Joanna & Gość)
Platform: Windows 7 Ultimate (X64) OS Language: Polski (Polska)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Foxit Software Inc.) C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(SlimWare Utilities, Inc.) C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\AMD Quick Stream\AMDQuickStream.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
() C:\Windows\SysWOW64\C2MP\TrayMenu.exe
(Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] = & gt; C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13667032 2000-01-01] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] = & gt; C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AMD AVT] = & gt; C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\...\Run: [SwitchBoard] = & gt; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] = & gt; C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKU\S-1-5-21-3344880123-386020015-1530945299-1000\...\Run: [AppEx Accelerator UI] = & gt; C:\Program Files\AMD Quick Stream\AMDQuickStream.exe [482528 2014-03-31] ()
HKU\S-1-5-21-3344880123-386020015-1530945299-1000\...\Run: [DAEMON Tools Lite] = & gt; C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3344880123-386020015-1530945299-1000\...\Run: [ALLUpdate] = & gt; C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [2765256 2014-11-03] (ALLPlayer Group Ltd.)
HKU\S-1-5-21-3344880123-386020015-1530945299-1000\...\Run: [AdobeBridge] = & gt; [X]
HKU\S-1-5-21-3344880123-386020015-1530945299-1000\...\Run: [GoogleDriveSync] = & gt; C:\Program Files (x86)\Google\Drive\googledrivesync.exe [26232152 2015-02-19] (Google)
HKU\S-1-5-21-3344880123-386020015-1530945299-1000\...\Run: [Napisy24.pl] = & gt; C:\Program Files (x86)\Napisy24\Napisy24.exe [4737992 2015-03-09] (Napisy24.pl)
HKU\S-1-5-21-3344880123-386020015-1530945299-1000\...\Run: [Napisy24Update] = & gt; C:\Program Files (x86)\Napisy24\Napisy24Update.exe [2790344 2015-03-12] (Napisy24.pl)
HKU\S-1-5-21-3344880123-386020015-1530945299-1000\...\Run: [CCleaner Monitoring] = & gt; C:\Program Files\CCleaner\CCleaner64.exe [7451928 2015-03-13] (Piriform Ltd)
HKU\S-1-5-21-3344880123-386020015-1530945299-1000\...\CurrentVersion\Windows: [Load] C:\ProgramData\msbfcsyjd.exe & lt; ===== ATTENTION
HKU\S-1-5-21-3344880123-386020015-1530945299-1000\...\MountPoints2: {b6678592-c05b-11e4-810b-6c626d340e1d} - F:\LG_PC_Programs.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk [2014-06-27]
ShortcutTarget: CodecPackTrayMenu.lnk - & gt; C:\Windows\SysWOW64\C2MP\TrayMenu.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk [2014-06-27]
ShortcutTarget: CodecPackUpdateChecker.lnk - & gt; C:\Windows\SysWOW64\C2MP\UpdateChecker.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3344880123-386020015-1530945299-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT - & gt; DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - & gt; DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - & gt; DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: SteadyVideoBHO Class - & gt; {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - & gt; C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices)
BHO-x32: No Name - & gt; {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - & gt; No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Tcpip\Parameters: [DhcpNameServer] 62.179.1.62 62.179.1.63

FireFox:
========
FF Plugin: @videolan.org/vlc,version=2.1.4 - & gt; C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-28] (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect - & gt; C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2013-03-21] (Adobe Systems)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - & gt; C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - & gt; C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - & gt; C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-02-13] (Google, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - & gt; C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll [2014-02-13] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - & gt; C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - & gt; C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - & gt; C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2013-03-21] (Adobe Systems)
FF HKU\S-1-5-21-3344880123-386020015-1530945299-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Joanna\AppData\Roaming\IDM\idmmzcc3

Chrome:
=======
CHR Profile: C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-09]
CHR Extension: (Google Docs) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-22]
CHR Extension: (Google Drive) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-22]
CHR Extension: (YouTube) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-22]
CHR Extension: (Google Search) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-22]
CHR Extension: (Google Sheets) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-09]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-12-09]
CHR Extension: (Google Wallet) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-22]
CHR Extension: (Gmail) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-22]
CHR HKU\S-1-5-21-3344880123-386020015-1530945299-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 FoxitCloudUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [243880 2015-01-16] (Foxit Software Inc.)
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [336824 2010-11-30] (arvato digital services llc)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2000-01-01] (Realtek Semiconductor)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 APXACC; C:\Windows\System32\DRIVERS\appexDrv.sys [225504 2014-03-28] (AppEx Networks Corporation)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-06-22] (Disc Soft Ltd)
R0 rtcrfilt64; C:\Windows\System32\DRIVERS\rtcrfilt64.sys [19600 2000-01-01] (Realtek Semiconductor Corp.)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2015-04-21] ()

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-21 16:07 - 2015-04-21 16:07 - 00011873 _____ () C:\Users\Joanna\Downloads\FRST.txt
2015-04-21 16:06 - 2015-04-21 16:07 - 00000000 ____D () C:\FRST
2015-04-21 16:06 - 2015-04-21 16:06 - 04314312 _____ (El Desaparecido - SosVirus.net - UsbFix.net) C:\Users\Joanna\Downloads\UsbFix_7.926.3.exe
2015-04-21 15:58 - 2015-04-21 15:58 - 02099712 _____ (Farbar) C:\Users\Joanna\Downloads\FRST64.exe
2015-04-21 15:21 - 2015-04-21 15:21 - 00000056 _____ () C:\Windows\setupact.log
2015-04-21 15:21 - 2015-04-21 15:21 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-21 15:18 - 2015-04-21 15:19 - 00000000 ____D () C:\AdwCleaner
2015-04-21 15:16 - 2015-04-21 15:17 - 02217984 _____ () C:\Users\Joanna\Downloads\adwcleaner_4.201.exe
2015-04-21 15:13 - 2015-04-21 15:13 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-21 14:29 - 2015-04-21 14:29 - 00002796 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-04-21 14:29 - 2015-04-21 14:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-04-21 14:29 - 2015-04-21 14:29 - 00000000 ____D () C:\Program Files\CCleaner
2015-04-21 14:23 - 2015-04-21 14:24 - 05344528 _____ (Piriform Ltd) C:\Users\Joanna\Downloads\ccsetup504.exe
2015-04-21 14:04 - 2015-04-21 14:04 - 00000000 ____D () C:\Windows\system32\appmgmt
2015-04-21 13:57 - 2015-04-21 13:57 - 00000000 ____D () C:\Users\Joanna\Desktop\Nowy folder
2015-04-20 19:01 - 2015-04-20 19:05 - 00007680 _____ () C:\Users\Joanna\Desktop\Wydatki kwiecień.xls
2015-04-18 15:45 - 2015-04-18 15:45 - 00000000 ____D () C:\Users\Joanna\Downloads\Zbiór zadań maturalnych poziom rozszerzony OMEGA
2015-03-31 22:58 - 2015-03-31 22:59 - 112932256 _____ () C:\Users\Joanna\Downloads\Dissection (1995) - Storm Of The Light's Bane.rar
2015-03-31 21:54 - 2015-03-31 21:55 - 84917983 _____ () C:\Users\Joanna\Downloads\Dissection - The Somberlain (1993).zip

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-21 16:04 - 2009-07-14 06:45 - 00010016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-21 16:04 - 2009-07-14 06:45 - 00010016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-21 15:49 - 2009-07-14 19:55 - 00697912 _____ () C:\Windows\system32\perfh015.dat
2015-04-21 15:49 - 2009-07-14 19:55 - 00134990 _____ () C:\Windows\system32\perfc015.dat
2015-04-21 15:49 - 2009-07-14 07:13 - 01549696 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-21 15:38 - 2014-06-22 14:07 - 00001048 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-21 15:24 - 2014-07-17 16:03 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-21 15:24 - 2014-06-22 13:00 - 01549910 _____ () C:\Windows\WindowsUpdate.log
2015-04-21 15:22 - 2014-12-09 16:28 - 00000000 ___RD () C:\Users\Joanna\Dysk Google
2015-04-21 15:21 - 2014-06-22 14:07 - 00001044 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-21 15:21 - 2014-06-22 13:20 - 00016152 _____ () C:\Windows\system32\Drivers\SWDUMon.sys
2015-04-21 15:21 - 2014-06-22 13:20 - 00002840 _____ () C:\Windows\System32\Tasks\SlimDrivers Startup
2015-04-21 15:21 - 2014-06-22 13:20 - 00000412 _____ () C:\Windows\Tasks\SlimDrivers Startup.job
2015-04-21 15:21 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-21 15:13 - 2014-07-17 16:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-21 15:13 - 2014-07-17 16:03 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-04-21 14:55 - 2014-06-23 13:06 - 00000000 ____D () C:\Windows\Minidump
2015-04-21 14:34 - 2014-06-23 14:44 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\uTorrent
2015-04-21 14:34 - 2014-06-22 14:38 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\DAEMON Tools Lite
2015-04-21 14:34 - 2014-06-22 13:55 - 00000000 ____D () C:\Windows\Panther
2015-04-19 15:25 - 2014-06-22 15:23 - 00000000 ____D () C:\Users\Joanna\AppData\Local\Adobe
2015-04-15 23:28 - 2009-07-14 07:08 - 00032604 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-07 01:21 - 2014-12-14 21:29 - 00000000 ____D () C:\ProgramData\Napisy24
2015-04-01 17:39 - 2014-12-14 21:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Napisy24
2015-04-01 17:39 - 2014-12-14 21:29 - 00000000 ____D () C:\Program Files (x86)\Napisy24

==================== Files in the root of some directories =======

2009-07-14 01:31 - 2009-07-14 03:14 - 72871936 ___SH (soldieroperatehere.de) C:\ProgramData\msbfcsyjd.exe

Files to move or delete:
====================
C:\ProgramData\msbfcsyjd.exe


Some content of TEMP:
====================
C:\Users\Joanna\AppData\Local\Temp\cdo1397158362.dll
C:\Users\Joanna\AppData\Local\Temp\Quarantine.exe
C:\Users\Joanna\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe = & gt; File is digitally signed
C:\Windows\System32\wininit.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\wininit.exe = & gt; File is digitally signed
C:\Windows\explorer.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\explorer.exe = & gt; File is digitally signed
C:\Windows\System32\svchost.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\svchost.exe = & gt; File is digitally signed
C:\Windows\System32\services.exe = & gt; File is digitally signed
C:\Windows\System32\User32.dll = & gt; File is digitally signed
C:\Windows\SysWOW64\User32.dll = & gt; File is digitally signed
C:\Windows\System32\userinit.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\userinit.exe = & gt; File is digitally signed
C:\Windows\System32\rpcss.dll = & gt; File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys = & gt; File is digitally signed


LastRegBack: 2015-04-16 13:05

==================== End Of Log ============================