• Registrarse
  • Iniciar sesión


  • Página 3 de 4 PrimeroPrimero 1234 ÚltimoÚltimo
    Resultados 21 al 30 de 34

    ¿Cómo desinstalar Delta Search, (navegador intruso) (Solucionado)

    Resumen del tema: ¿Cómo desinstalar Delta Search, (navegador intruso) (Solucionado) - Dr.Web Scanner SE for Windows v8.2.0.05230 (c) Doctor Web, Ltd., 1992-2013 Scan session started 2013/05/27 07:35:43 Module location : C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ ============================================================================= OPTION [Automatic Apply Actions] NO OPTION [Turn Off Computer After Scan] NO OPTION [Use ...

      
    1. #21
      Usuario Avatar de wasamandrapa
      Registrado
      ene 2010
      Ubicación
      Talca-Chile
      Mensajes
      112

      Re: ¿Cómo desinstalar Delta Search, (navegador intruso)

      Dr.Web Scanner SE for Windows v8.2.0.05230
      (c) Doctor Web, Ltd., 1992-2013
      Scan session started 2013/05/27 07:35:43
      Module location : C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\
      =============================================================================
      OPTION [Automatic Apply Actions] NO
      OPTION [Turn Off Computer After Scan] NO
      OPTION [Use Sound Alerts] NO
      OPTION [Block Network] NO
      OPTION [Protect Process] NO
      OPTION [Protect Raw Disk] NO
      Using language: "Spanish (Español)"
      Available instances: 2
      Instances used: 2
      Platform: Windows 7 Professional x86 (Build 7601), Service Pack 1
      API Version: 2.2
      Scanning Engine version: 8.1.0.4260
      Virus Finding Engine version: 7.0.4.9250
      Total 116 virus bases are loaded from C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0
      qqv07z3d 7.0 5746f1223fabdfb4d740e011e22c388098fcb912 2013/05/27 04:50:28 1088 records - OK
      jwygdoyg 7.0 215c2d42a54f5188e8159bfd122292450d16f29b 2011/07/25 10:20:03 2 records - OK
      a6xev3ds 7.0 9832ea6a702f5de892ed11034c92df19d51f20f9 2013/05/26 23:17:02 1 record - OK
      jt22o7k6 7.0 f562371c5115143824efde38c9567c34ccbe5d1a 2013/05/26 23:16:19 33200 records - OK
      2krj5wgj 7.0 eccb30ec8ed44456f9b88fe96d9fe0de40e4fa51 2013/05/19 23:11:05 46384 records - OK
      9cmk3q4f 7.0 9b481fbfbe1f564a84f21552da1d30d24e7b01db 2013/05/12 23:07:01 34270 records - OK
      l5af8za3 7.0 1bf754dd720727b5d6803e081c16ff7f4ba7b40b 2013/05/05 23:08:46 41611 records - OK
      h2v03oo7 7.0 4e883c92513c2d991968fb3e4f27910a63d9a2df 2013/04/28 23:06:36 36105 records - OK
      m2k7r173 7.0 b047d178295ecde53c3cf1c34e4361004569fa33 2013/04/21 23:07:26 31319 records - OK
      9qggnv2w 7.0 9207e55a924e4aa989dfde4d8d219cf5cc200ce2 2013/04/14 23:07:56 28216 records - OK
      pbvrbf6t 7.0 78855cfb9fbc063889c5405a577fe73188f08789 2013/04/07 23:05:35 23589 records - OK
      39to7js6 7.0 cec6d34c79d50608520e81b90a23d91f39df0b27 2013/03/31 23:07:37 26946 records - OK
      b28v5kvt 7.0 fd3c78d78ea4dae4e252a7f7d76db22e1a679be9 2013/03/24 23:05:37 34778 records - OK
      3hmdvj4a 7.0 268e71b1123ab5e60fd2f38d269fe5f3d22b3697 2013/03/17 23:06:19 11271 records - OK
      fc4sw74b 7.0 d196879775b0dc0ee8286f2e4def9adedb5b88df 2013/03/10 23:05:36 12046 records - OK
      7qunskty 7.0 0db61d4e3235481da8493523538ced712db362c2 2013/03/04 00:05:18 21747 records - OK
      e9kj23qp 7.0 65f99faf227b51883c9f1c854a3f76806b60affb 2013/02/25 00:06:28 11540 records - OK
      04vrd0z6 7.0 17bd7383b9c4b214c5c9029171db8ae1455984a0 2013/02/18 00:06:38 15568 records - OK
      m5q9691d 7.0 cbe8774953ae403e49370d552b522a5839aa9fdb 2013/02/11 00:06:00 18805 records - OK
      bk2po1gu 7.0 fb6865c02a3680338e4ee0603579107227313b2b 2013/02/04 00:06:01 32488 records - OK
      eo4klb12 7.0 95fcd2e24cd9b2ec2610656ffa70b8bf46e86a8b 2013/01/28 00:04:52 15470 records - OK
      0mbq1ig6 7.0 3d710b3dd4580a7eca8c74d2c886d48f5b8b5172 2013/01/21 00:06:27 30093 records - OK
      8ejcd59y 7.0 bddde0b5426b7e5bebd61e1239ca529c87ae6e36 2013/01/14 00:04:41 16158 records - OK
      5svw6p99 7.0 bc40bd9330301e8d7796f489d03357fb711b3121 2013/01/07 00:04:45 19597 records - OK
      ow8s3j2o 7.0 805b6089c867549c75f843eac96b759c3f8d101f 2012/12/31 00:05:41 18184 records - OK
      dlxi4s15 7.0 c12a817c1f95bb9fd8238ef0d5f68868a8d95686 2012/12/24 00:05:33 30183 records - OK
      ngguiubc 7.0 33def496782eb5b7b1cc93fdb036a1b62fa6a2fd 2012/12/17 00:06:21 25519 records - OK
      tm3pfh2n 7.0 422abae03c588822f412aa9aae50578a1d61737e 2012/12/10 00:05:04 20358 records - OK
      dmhowgqq 7.0 a4f0d0ecad4fb6e0afdb1925f4e0b7863b9d03fa 2012/12/03 00:06:19 20133 records - OK
      v2cmf7qz 7.0 86daa918ee3de1e4c1e5dea6f9b5f63544cf8814 2012/11/26 00:05:22 27311 records - OK
      km7f1vfq 7.0 6556881c748e1f894eb9c7943ebae67017e1aec2 2012/11/19 00:06:09 29434 records - OK
      hstukj21 7.0 559141ef34f9e6226bb58560e9b52e4cc5165150 2012/11/12 00:06:22 26900 records - OK
      5270yojn 7.0 cc55013e63ff89319ec772e34d77056c7108cd3b 2012/11/05 00:05:22 25164 records - OK
      rdupqm2p 7.0 f477dc247d9b562bb64fd4f46a7dcbdf7124eb60 2012/10/29 00:06:37 30226 records - OK
      pecz1mkz 7.0 abaf5f7fda7308fcf7573b193bbf2116723e9802 2012/10/22 00:04:37 16441 records - OK
      3h5h1ctf 7.0 5adc85528fb49e201d4bc61eca580d6839cc4a4c 2012/10/15 00:05:04 26289 records - OK
      hkioy8ry 7.0 da8cf3fbd81206bb3d8103347a439f920a74bbe2 2012/10/07 23:05:51 27278 records - OK
      de7zi59j 7.0 5988744d3cb357f1a013427d466e2d79ab5f8907 2012/09/30 23:05:11 17444 records - OK
      198iocul 7.0 d4a0dabf4a4df0f79805c6ccdc025f796765e786 2012/09/23 23:06:30 21205 records - OK
      wl5xh8rf 7.0 82ed005784d9e258213070a0cd8bfceff345018d 2012/09/16 23:05:43 11686 records - OK
      5xj1h6gj 7.0 a95ae63004b8d857c2db055f4e47c15bfc97f626 2012/09/09 23:04:34 12677 records - OK
      6kjmzmks 7.0 c39bf233d25242ae9ed8cf204b9b788c8f45ab79 2012/09/02 23:05:28 10118 records - OK
      qfpjrbni 7.0 d37b5484b009947b7cdd3837dafe8148615401c2 2012/08/26 23:05:26 12602 records - OK
      g3t1mm5h 7.0 41bf1347794ab7060dec7aaecc1d1d95cf6fecb5 2012/08/19 23:04:05 18298 records - OK
      74sfott4 7.0 1a997511e5892aaeb69b3db70e06676af36382e3 2012/08/12 23:05:19 17126 records - OK
      3gleev4p 7.0 f7226c59914e3683e538e668c3b664af3232654d 2012/08/05 23:03:53 20539 records - OK
      6p75yh4d 7.0 4035c8d3b617bf935a317a8c57efaa8e835a61f4 2012/07/29 23:05:26 19330 records - OK
      anecg52z 7.0 09b55bc000f184ed426f1d8b9665669346fe5e71 2012/07/22 23:05:34 19692 records - OK
      mdvvx34h 7.0 f746c097f298e94faa9db94e6f64ef9fd4a7b010 2012/07/15 23:05:43 14727 records - OK
      0qezghi3 7.0 792a6a25a17e764390440cd4c2c6ca5a97ab162f 2012/07/08 23:04:33 19485 records - OK
      2h31w7tz 7.0 ca9905c39e3d93428a4db65a192debe9fbd7acf7 2012/07/01 23:04:55 22898 records - OK
      qpc9p4yh 7.0 dc29c610b866c66ba5327e7830452b2460149a35 2012/06/24 23:05:17 20551 records - OK
      rb1rhw58 7.0 c28739bea153508d12942ac9a61abd475d0a0404 2012/06/17 23:03:35 9661 records - OK
      z4m6l1hq 7.0 e5b5835a7c512120c5348e31483a4caa2a845d28 2012/06/10 23:04:32 23632 records - OK
      n8eo5xmz 7.0 61853ce89026ef0ebbd80174f1b7dd5d25bbc63a 2012/06/03 23:04:41 12423 records - OK
      feo4lscy 7.0 4e6c9897e153b47ca97b7da48ceed23e555a7761 2012/05/27 23:04:26 15493 records - OK
      c0ao11ij 7.0 35f4c105cecd8ec1fd01714abebf30f8f3efb96e 2012/05/20 23:03:29 13065 records - OK
      27kfdovx 7.0 3522aa84677411aa7d67796bb05ea3ab62f02a71 2012/05/13 23:04:24 16238 records - OK
      2sie5t3v 7.0 7597333540eda537bd42c0a17d4a6526ad247a2e 2012/05/06 23:04:33 11570 records - OK
      s4amdyz2 7.0 867814380363bc6ad605acf4b96e02c54dbd60f7 2012/04/29 23:03:28 15478 records - OK
      hp1nvn6t 7.0 3c04f402d91a19039cb9c223c435dc4ea1bb3da4 2012/04/22 23:05:05 11881 records - OK
      y4l7l69l 7.0 8d0220a2a50b367e61a51d3b29c2659cde41bb7f 2012/04/15 23:03:29 13578 records - OK
      djvmr3ar 7.0 b79dc6f5832ad390108d1880694ec538e8b34bb0 2012/04/08 23:05:02 14292 records - OK
      3seupcue 7.0 8ff7cc095c43c2154275b7a54a89bf365e8daf4a 2012/04/01 23:03:24 14084 records - OK
      hmzi87im 7.0 9502a428b32be4ad08556134e271c9ba03195398 2012/03/25 23:04:43 19126 records - OK
      nuh694t4 7.0 28c2fabbc645aff41baac12b911a8499ea163536 2012/03/18 23:03:23 14920 records - OK
      baaggis1 7.0 86de597ff06e58206f94263f2eef33cb41b2530c 2012/03/11 23:03:25 19017 records - OK
      m2amr9q3 7.0 5bd1d666e7c9ca70c34e591dc6c55314ce4b11af 2012/03/05 00:04:32 19691 records - OK
      esw8dvu3 7.0 15a9d10c451d2fcf124700f29f557d9bf338e671 2012/02/27 00:03:21 23605 records - OK
      svt3werg 7.0 5647d941e5358105ca6558dce78873f06c48d5dc 2012/02/20 00:03:45 19067 records - OK
      1754s54y 7.0 c9b2600cb665ce34e0ccd0f19e0a88cd44437f51 2012/02/13 00:04:49 19019 records - OK
      pei7rfd6 7.0 9df2e129e78a9d9ab491186da1329c1dd1190e17 2012/02/06 00:05:25 28028 records - OK
      4prqqww7 7.0 b69b9504a51b8777b8e95a4680dc8ac1d8d8c25d 2012/01/30 00:08:41 29444 records - OK
      r707azzt 7.0 3d7431bdee1a22d6329e017f348db7760f2645ac 2012/01/23 05:22:13 19353 records - OK
      si4h3atn 7.0 e04570f78fb00d758abdf77c534a460980e102c0 2012/01/16 00:12:31 20747 records - OK
      14no3ist 7.0 2de2479b112c4416e2375343f57ca789b042aecc 2012/01/09 00:04:30 28052 records - OK
      9109md3w 7.0 c4bd9612ff1f71d8bd23b4f1bc114eed1ae2ee6b 2012/01/02 00:04:40 12183 records - OK
      f5ow833m 7.0 28b1d218ade8f05fdc8550c7456ac3b74f705208 2011/12/26 00:03:33 19984 records - OK
      08s1ddo6 7.0 539e41e8f3d97a6f347600c7cef903d9f34e0518 2011/12/19 00:08:45 22627 records - OK
      yq5ygl1v 7.0 f8e81968965f555bce0d02fc9933fee840b97aaf 2011/12/12 17:20:22 49580 records - OK
      r9t4ylfz 7.0 14751e0f442bba3efc08ee12d82a2815c61cfeb6 2011/12/04 05:00:00 45195 records - OK
      vdzss8c4 7.0 1a1e6cb9b3096a2cbba2c31d05e11914c0357d52 2011/12/04 04:00:00 165532 records - OK
      7eoqgoo8 7.0 0f948a7d416c556bfc8a8be2c2c39f998fee6d9e 2011/12/04 03:00:00 170820 records - OK
      02wv45gn 7.0 9357c3cc73a4a374346a678f197daa22496c7ae5 2011/12/04 02:00:00 171279 records - OK
      em6fnyzo 7.0 ae56b06b3d6f1e13c5f10cce4ed68f2cccbf3298 2011/12/04 01:00:00 170253 records - OK
      6abnlkxx 7.0 fdaab5c1079d02c94f20d07c39d638cad79d8771 2011/12/04 00:00:00 170291 records - OK
      u6wgfwzu 7.0 b59d8841e65d7670b2aae7f2b65734269f6c4fe3 2011/12/03 23:00:00 170501 records - OK
      vhivjf8d 7.0 3946b1d195434cf7a70d144da71c87559475c58f 2011/12/03 22:00:00 353582 records - OK
      101ax0uc 7.0 8df4695f74ea5949551df6044720694e204b13d7 2011/12/03 21:00:00 852776 records - OK
      l8o32scg 7.0 20d4fe6ae58a6d4da8462d9317ef9e2b2efcdb46 2013/05/27 04:50:54 985 records - OK
      lf2t226v 7.0 0cb77ee7a3e6545553585eb6df267a86d4fecbe4 2013/04/21 23:14:29 1680 records - OK
      rvalqzak 7.0 6cb68b8fab821702ef054f864ff44917414e50fa 2013/02/04 00:13:43 2078 records - OK
      6rup29pr 7.0 cfbe9cf43615f7856e4c35f0fc02e2baf12e39e7 2012/12/17 00:14:14 1725 records - OK
      1l7xi7ft 7.0 047694e79b1a8d295f27ea9c6565062404f84a57 2012/11/12 00:12:52 2050 records - OK
      mwpxlmxz 7.0 f3413603f4ee1c88018a78c1f6faf2abeb8fa8c1 2012/09/23 23:13:14 1456 records - OK
      xlhwqwy1 7.0 8871f579eeb7e5e7b70c6dd898afd27391d7daf4 2012/06/24 23:12:36 1421 records - OK
      9kqrh9r8 7.0 3ee43130fe7fec4b367a791892a444d0a791b29b 2012/03/25 23:12:30 1385 records - OK
      yevxl1qu 7.0 fddc5d687537580c7166dbf117d591593bc62261 2012/01/23 01:56:09 1653 records - OK
      b8ukk5w9 7.0 51a7bab21ba4e765264467fc9984b1a9ed571616 2013/05/27 04:50:46 332 records - OK
      7rx7ag1k 7.0 45cdfad530697916adbfea43a8763a4ab0c95beb 2013/05/19 23:24:48 1426 records - OK
      pnzj4c8c 7.0 bd9fd948b79e07c8676018e17a43ee81f5335e36 2013/04/21 23:24:10 1641 records - OK
      irozcznv 7.0 c7f70566b9bae9fd3f5a8d0b56d961f890a55508 2013/03/17 23:23:44 1742 records - OK
      8fc7o9ph 7.0 8893c0d254eb40c78b5c78ea17fbc3be60ea6304 2013/01/21 00:24:33 2016 records - OK
      9by9rrm2 7.0 cdf3a9d2dcab57f90c378d9eefacbfd358a42699 2012/12/10 00:23:23 1620 records - OK
      kqikgkir 7.0 c0726ba000e840272f0810b89051e6daa8799084 2012/11/05 00:23:16 1658 records - OK
      7l3yfyrh 7.0 216611859de0125bf130d6324d43c9115cb05def 2012/10/07 23:23:20 1465 records - OK
      g0121ot0 7.0 264c14ad60c4423ec292f5f8b182e4448504dfa9 2012/09/09 23:23:14 1588 records - OK
      xnxsga4t 7.0 33197bfe9efefa9db33725d240757103c625b601 2012/07/22 23:22:36 1702 records - OK
      7bfnwtqw 7.0 74d8e114edb84b95bc09d5a2a36191d15a61e2cb 2012/06/10 23:22:36 1659 records - OK
      1whbnut4 7.0 79ca8239f310688d2b9c314fa3d738a34985cce3 2012/04/29 23:22:34 1670 records - OK
      z3qecv3r 7.0 aac27e986e3731e5260cb76f5b14558e36660dec 2012/03/11 23:22:28 1729 records - OK
      fqk26iqg 7.0 fa5c96b8be693a20c2a295e3545419e6f117fdc4 2012/01/30 00:23:00 1523 records - OK
      5i2pd8lz 7.0 e9b21e0a3578ef2e2067f4876309671ddc78f65f 2011/12/19 00:22:29 1805 records - OK
      y9usy8ct 7.0 8f7a8f6f55130f6becc5331ab38dc2108746b8aa 2011/12/03 20:00:00 26456 records - OK
      psto3cgf 7.0 e6d52b11d2f7d405ccd31347da3b6fde69825168 2011/12/03 19:00:00 74279 records - OK
      c1x36p5l 7.0 e20ffde4bbc58e0585b0b3b2f324bc91272c2360 2011/12/03 18:00:00 1 record - OK
      Total records count: 4068902
      Anti-rootkit module version ( ver: 8.3.201305150, api: 5.01/5.01 )

      Using C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\k3eoszuq.key as Dr.Web (R) Key file
      This Dr.Web (R) Key is for 1 computer (A User)
      -----------------------------------------------------------------------------
      Start scanning
      -----------------------------------------------------------------------------
      Command line used:-rpcep:\pipe\1286D902B -rpcpr:np /protmode

      Object(s) to scan:
      - Scan processes in memory
      - Scan boot sectors
      - Scanning for rootkits
      - C:\AdwCleaner[S1].txt
      - C:\AT-Cuarentena
      - C:\AT-Destroyer.txt
      - C:\autoexec.bat
      - C:\bootmgr
      - C:\BOOTSECT.BAK
      - C:\config.sys
      - C:\hiberfil.sys
      - C:\JILUC
      - C:\pagefile.sys
      - C:\Serial.cmd
      - C:\Serial.txt
      - C:\SetSearchAndHomepageInBrowserLog.txt
      - C:\win7.ld
      - C:\WPI_Log_2012.09.05_17.58.21.txt
      - C:\WPI_Log_2012.09.06_17.58.31.txt
      - C:\Windows\system32\
      - C:\Users\Casa\Documents\
      - C:\Windows\TEMP\
      - C:\Users\Casa\AppData\Local\Temp\

      Computer\Motherboard\SYSTEM BIOS - Ok
      c:\windows\system32\ntkrnlpa.exe - Ok
      c:\windows\system32\halmacpi.dll - Ok
      c:\windows\system32\kdcom.dll - Ok
      c:\windows\system32\mcupdate_genuineintel.dll - Ok
      c:\windows\system32\pshed.dll - Ok
      c:\windows\system32\bootvid.dll - Ok
      c:\windows\system32\clfs.sys - Ok
      c:\windows\system32\ci.dll - Ok
      c:\windows\system32\drivers\wdf01000.sys - Ok
      c:\windows\system32\drivers\wdfldr.sys - Ok
      c:\windows\system32\drivers\acpi.sys - Ok
      >c:\windows\system32\drivers\wmilib.sys - packed by FLY-CODE
      c:\windows\system32\drivers\wmilib.sys - Ok
      c:\windows\system32\drivers\msisadrv.sys - Ok
      c:\windows\system32\drivers\pci.sys - Ok
      c:\windows\system32\drivers\vdrvroot.sys - Ok
      c:\windows\system32\drivers\partmgr.sys - Ok
      c:\windows\system32\drivers\volmgr.sys - Ok
      c:\windows\system32\drivers\volmgrx.sys - Ok
      >c:\windows\system32\drivers\intelide.sys - packed by FLY-CODE
      c:\windows\system32\drivers\intelide.sys - Ok
      >c:\windows\system32\drivers\pciidex.sys - packed by FLY-CODE
      c:\windows\system32\drivers\pciidex.sys - Ok
      c:\windows\system32\drivers\mountmgr.sys - Ok
      c:\windows\system32\drivers\vmbus.sys - Ok
      >c:\windows\system32\drivers\winhv.sys - packed by FLY-CODE
      c:\windows\system32\drivers\winhv.sys - Ok
      c:\windows\system32\drivers\atapi.sys - Ok
      >c:\windows\system32\drivers\ataport.sys - packed by FLY-CODE
      c:\windows\system32\drivers\ataport.sys - Ok
      c:\windows\system32\drivers\amdxata.sys - Ok
      c:\windows\system32\drivers\fltmgr.sys - Ok
      c:\windows\system32\drivers\fileinfo.sys - Ok
      c:\windows\system32\drivers\ntfs.sys - Ok
      c:\windows\system32\drivers\msrpc.sys - Ok
      c:\windows\system32\drivers\ksecdd.sys - Ok
      c:\windows\system32\drivers\cng.sys - Ok
      c:\windows\system32\drivers\pcw.sys - Ok
      c:\windows\system32\drivers\aswkbd.sys - Ok
      c:\windows\system32\drivers\fs_rec.sys - Ok
      c:\windows\system32\drivers\ndis.sys - Ok
      >c:\windows\system32\drivers\netio.sys - packed by FLY-CODE
      c:\windows\system32\drivers\netio.sys - Ok
      >c:\windows\system32\drivers\ksecpkg.sys - packed by FLY-CODE
      c:\windows\system32\drivers\ksecpkg.sys - Ok
      c:\windows\system32\drivers\tcpip.sys - Ok
      c:\windows\system32\drivers\fwpkclnt.sys - Ok
      c:\windows\system32\drivers\vmstorfl.sys - Ok
      c:\windows\system32\drivers\volsnap.sys - Ok
      c:\windows\system32\drivers\spldr.sys - Ok
      c:\windows\system32\drivers\rdyboost.sys - Ok
      c:\windows\system32\drivers\mup.sys - Ok
      c:\windows\system32\drivers\hwpolicy.sys - Ok
      c:\windows\system32\drivers\fvevol.sys - Ok
      c:\windows\system32\drivers\disk.sys - Ok
      >c:\windows\system32\drivers\classpnp.sys - packed by FLY-CODE
      c:\windows\system32\drivers\classpnp.sys - Ok
      c:\windows\system32\drivers\aswvmm.sys - Ok
      c:\windows\system32\drivers\aswrvrt.sys - Ok
      c:\windows\system32\drivers\cdrom.sys - Ok
      c:\windows\system32\drivers\aswsnx.sys - Ok
      >c:\windows\system32\drivers\null.sys - packed by FLY-CODE
      c:\windows\system32\drivers\null.sys - Ok
      c:\windows\system32\drivers\beep.sys - Ok
      c:\windows\system32\drivers\vga.sys - Ok
      >c:\windows\system32\drivers\videoprt.sys - packed by FLY-CODE
      c:\windows\system32\drivers\videoprt.sys - Ok
      >c:\windows\system32\drivers\watchdog.sys - packed by FLY-CODE
      c:\windows\system32\drivers\watchdog.sys - Ok
      >c:\windows\system32\drivers\rdpcdd.sys - packed by FLY-CODE
      >>c:\windows\system32\drivers\rdpcdd.sys - packed by FLY-CODE
      c:\windows\system32\drivers\rdpcdd.sys - Ok
      >c:\windows\system32\drivers\rdpencdd.sys - packed by FLY-CODE
      >>c:\windows\system32\drivers\rdpencdd.sys - packed by FLY-CODE
      c:\windows\system32\drivers\rdpencdd.sys - Ok
      >c:\windows\system32\drivers\rdprefmp.sys - packed by FLY-CODE
      >>c:\windows\system32\drivers\rdprefmp.sys - packed by FLY-CODE
      c:\windows\system32\drivers\rdprefmp.sys - Ok
      c:\windows\system32\drivers\msfs.sys - Ok
      c:\windows\system32\drivers\npfs.sys - Ok
      c:\windows\system32\drivers\tdx.sys - Ok
      >c:\windows\system32\drivers\tdi.sys - packed by FLY-CODE
      c:\windows\system32\drivers\tdi.sys - Ok
      c:\windows\system32\drivers\aswtdi.sys - Ok
      c:\windows\system32\drivers\afd.sys - Ok
      c:\windows\system32\drivers\aswrdr2.sys - Ok
      c:\windows\system32\drivers\netbt.sys - Ok
      c:\windows\system32\drivers\wfplwf.sys - Ok
      >c:\windows\system32\drivers\pacer.sys - packed by FLY-CODE
      c:\windows\system32\drivers\pacer.sys - Ok
      c:\windows\system32\drivers\netbios.sys - Ok
      c:\windows\system32\drivers\wanarp.sys - Ok
      c:\windows\system32\drivers\termdd.sys - Ok
      c:\windows\system32\drivers\rdbss.sys - Ok
      c:\windows\system32\drivers\nsiproxy.sys - Ok
      c:\windows\system32\drivers\mssmbios.sys - Ok
      c:\windows\system32\drivers\discache.sys - Ok
      c:\windows\system32\drivers\csc.sys - Ok
      c:\windows\system32\drivers\dfsc.sys - Ok
      c:\windows\system32\drivers\blbdrive.sys - Ok
      c:\windows\system32\drivers\aswsp.sys - Ok
      >c:\windows\system32\drivers\tunnel.sys - packed by FLY-CODE
      >>c:\windows\system32\drivers\tunnel.sys - packed by FLY-CODE
      c:\windows\system32\drivers\tunnel.sys - Ok
      c:\windows\system32\drivers\intelppm.sys - Ok
      c:\windows\system32\drivers\igdkmd32.sys - Ok
      c:\windows\system32\drivers\dxgkrnl.sys - Ok
      >c:\windows\system32\drivers\dxgmms1.sys - packed by FLY-CODE
      c:\windows\system32\drivers\dxgmms1.sys - Ok
      c:\windows\system32\drivers\hdaudbus.sys - Ok
      c:\windows\system32\drivers\rt86win7.sys - Ok
      c:\windows\system32\drivers\usbuhci.sys - Ok
      c:\windows\system32\drivers\usbport.sys - Ok
      c:\windows\system32\drivers\usbehci.sys - Ok
      c:\windows\system32\drivers\vstbs23.sys - Ok
      c:\windows\system32\drivers\ks.sys - Ok
      >c:\windows\system32\drivers\vstdpv3.sys - packed by FLY-CODE
      c:\windows\system32\drivers\vstdpv3.sys - Ok
      c:\windows\system32\drivers\vstcnxt3.sys - Ok
      c:\windows\system32\drivers\modem.sys - Ok
      c:\windows\system32\drivers\i8042prt.sys - Ok
      c:\windows\system32\drivers\kbdclass.sys - Ok
      c:\windows\system32\drivers\mouclass.sys - Ok
      >c:\windows\system32\drivers\compositebus.sys - packed by FLY-CODE
      >>c:\windows\system32\drivers\compositebus.sys - packed by FLY-CODE
      c:\windows\system32\drivers\compositebus.sys - Ok
      c:\windows\system32\drivers\camsuitevac.sys - Ok
      c:\windows\system32\drivers\portcls.sys - Ok
      >c:\windows\system32\drivers\drmk.sys - packed by FLY-CODE
      c:\windows\system32\drivers\drmk.sys - Ok
      c:\windows\system32\drivers\agilevpn.sys - Ok
      c:\windows\system32\drivers\rasl2tp.sys - Ok
      c:\windows\system32\drivers\ndistapi.sys - Ok
      c:\windows\system32\drivers\ndiswan.sys - Ok
      c:\windows\system32\drivers\raspppoe.sys - Ok
      c:\windows\system32\drivers\raspptp.sys - Ok
      c:\windows\system32\drivers\rassstp.sys - Ok
      c:\windows\system32\drivers\rdpbus.sys - Ok
      c:\windows\system32\drivers\swenum.sys - Ok
      >c:\windows\system32\drivers\umbus.sys - packed by FLY-CODE
      >>c:\windows\system32\drivers\umbus.sys - packed by FLY-CODE
      c:\windows\system32\drivers\umbus.sys - Ok
      c:\windows\system32\drivers\usbhub.sys - Ok
      c:\windows\system32\drivers\ndproxy.sys - Ok
      c:\windows\system32\drivers\hdaudio.sys - Ok
      c:\windows\system32\win32k.sys - Ok
      >c:\windows\system32\drivers\dxapi.sys - packed by FLY-CODE
      c:\windows\system32\drivers\dxapi.sys - Ok
      c:\windows\system32\drivers\crashdmp.sys - Ok
      c:\windows\system32\drivers\dump_dumpata.sys - file not found
      c:\windows\system32\drivers\dump_atapi.sys - file not found
      c:\windows\system32\drivers\dump_dumpfve.sys - file not found
      >c:\windows\system32\drivers\monitor.sys - packed by FLY-CODE
      >>c:\windows\system32\drivers\monitor.sys - packed by FLY-CODE
      c:\windows\system32\drivers\monitor.sys - Ok
      c:\windows\system32\tsddd.dll - Ok
      >c:\windows\system32\cdd.dll - packed by FLY-CODE
      c:\windows\system32\cdd.dll - Ok
      c:\windows\system32\drivers\usbccgp.sys - Ok
      c:\windows\system32\drivers\usbd.sys - Ok
      c:\windows\system32\drivers\luafv.sys - Ok
      c:\windows\system32\drivers\aswmonflt.sys - Ok
      c:\windows\system32\drivers\aswfsblk.sys - Ok
      c:\windows\system32\drivers\lltdio.sys - Ok
      >c:\windows\system32\drivers\rspndr.sys - packed by FLY-CODE
      c:\windows\system32\drivers\rspndr.sys - Ok
      >c:\windows\system32\drivers\http.sys is BINARYRES container
      c:\windows\system32\drivers\http.sys - container
      c:\windows\system32\drivers\bowser.sys - Ok
      c:\windows\system32\drivers\mpsdrv.sys - Ok
      c:\windows\system32\drivers\mrxdav.sys - Ok
      c:\windows\system32\drivers\mrxsmb.sys - Ok
      c:\windows\system32\drivers\mrxsmb10.sys - Ok
      c:\windows\system32\drivers\mrxsmb20.sys - Ok
      >c:\windows\system32\drivers\peauth.sys - packed by FLY-CODE
      >>c:\windows\system32\drivers\peauth.sys - packed by FLY-CODE
      c:\

    2. #22
      Usuario Avatar de wasamandrapa
      Registrado
      ene 2010
      Ubicación
      Talca-Chile
      Mensajes
      112

      Re: ¿Cómo desinstalar Delta Search, (navegador intruso)

      c:\windows\system32\drivers\secdrv.sys - Ok
      c:\windows\system32\drivers\srvnet.sys - Ok
      >c:\windows\system32\drivers\tcpipreg.sys - packed by FLY-CODE
      c:\windows\system32\drivers\tcpipreg.sys - Ok
      c:\windows\system32\drivers\srv2.sys - Ok
      c:\windows\system32\drivers\srv.sys - Ok
      c:\users\casa\appdata\local\temp\128e3e947.sys - file not found
      c:\users\casa\appdata\local\temp\12c769589.sys - file not found
      c:\windows\system32\ntdll.dll - Ok
      c:\windows\system32\smss.exe - Ok
      c:\windows\system32\apisetschema.dll - Ok
      c:\windows\system32\autochk.exe - Ok
      >c:\windows\system32\nsi.dll - packed by FLY-CODE
      c:\windows\system32\nsi.dll - Ok
      c:\windows\system32\msvcrt.dll - Ok
      c:\windows\system32\psapi.dll - Ok
      >c:\windows\system32\ole32.dll is BINARYRES container
      c:\windows\system32\ole32.dll - container
      c:\windows\system32\setupapi.dll - Ok
      c:\windows\system32\imm32.dll - Ok
      c:\windows\system32\shlwapi.dll - Ok
      c:\windows\system32\msctf.dll - Ok
      c:\windows\system32\lpk.dll - Ok
      c:\windows\system32\iertutil.dll - Ok
      c:\windows\system32\normaliz.dll - Ok
      c:\windows\system32\comdlg32.dll - Ok
      c:\windows\system32\ws2_32.dll - Ok
      c:\windows\system32\user32.dll - Ok
      c:\windows\system32\sechost.dll - Ok
      c:\windows\system32\wldap32.dll - Ok
      c:\windows\system32\clbcatq.dll - Ok
      c:\windows\system32\shell32.dll - Ok
      c:\windows\system32\difxapi.dll - Ok
      c:\windows\system32\kernel32.dll - Ok
      c:\windows\system32\usp10.dll - Ok
      c:\windows\system32\imagehlp.dll - Ok
      c:\windows\system32\rpcrt4.dll - Ok
      c:\windows\system32\oleaut32.dll - Ok
      c:\windows\system32\advapi32.dll - Ok
      c:\windows\system32\wininet.dll - Ok
      c:\windows\system32\gdi32.dll - Ok
      c:\windows\system32\urlmon.dll - Ok
      c:\windows\system32\cfgmgr32.dll - Ok
      c:\windows\system32\kernelbase.dll - Ok
      c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll - Ok
      c:\windows\system32\devobj.dll - Ok
      c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll - Ok
      c:\windows\system32\comctl32.dll - Ok
      >c:\windows\system32\wintrust.dll - packed by FLY-CODE
      c:\windows\system32\wintrust.dll - Ok
      c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll - Ok
      c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll - Ok
      c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll - Ok
      c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll - Ok
      c:\windows\system32\crypt32.dll - Ok
      c:\windows\system32\msasn1.dll - Ok
      System Process - file not found
      >c:\users\casa\appdata\local\temp\526c69e0-19e4f050-231db8c0-b16da3d0\lc908y97.exe is BINARYRES container
      c:\users\casa\appdata\local\temp\526c69e0-19e4f050-231db8c0-b16da3d0\lc908y97.exe - container
      c:\windows\system32\csrss.exe - Ok
      c:\windows\system32\wininit.exe - Ok
      c:\windows\system32\winlogon.exe - Ok
      c:\windows\system32\services.exe - Ok
      c:\windows\system32\lsass.exe - Ok
      c:\windows\system32\lsm.exe - Ok
      c:\windows\system32\svchost.exe - Ok
      c:\windows\system32\macromed\flash\flashplayerplugin_11_7_700_202.exe - Ok
      c:\program files\common files\adobe\arm\1.0\armsvc.exe - Ok
      c:\windows\system32\audiodg.exe - Ok
      c:\program files\alwil software\avast5\avastsvc.exe - Ok
      c:\program files\malwarebytes' anti-malware\mbamscheduler.exe - Ok
      c:\windows\system32\dwm.exe - Ok
      c:\windows\system32\spoolsv.exe - Ok
      c:\windows\system32\taskhost.exe - Ok
      c:\windows\explorer.exe - Ok
      c:\program files\windows media player\wmpnetwk.exe - Ok
      c:\windows\system32\hkcmd.exe - Ok
      c:\windows\system32\igfxpers.exe - Ok
      c:\program files\alwil software\avast5\avastui.exe - Ok
      c:\users\casa\appdata\local\temp\526c69e0-19e4f050-231db8c0-b16da3d0\tkmmrj2n.exe - Ok
      c:\program files\common files\microsoft shared\windows live\wlidsvc.exe - Ok
      c:\windows\system32\igfxsrvc.exe - Ok
      c:\program files\common files\microsoft shared\windows live\wlidsvcm.exe - Ok
      c:\windows\system32\searchindexer.exe - Ok
      c:\users\casa\appdata\local\temp\526c69e0-19e4f050-231db8c0-b16da3d0\sfp6jo3m.exe - Ok
      c:\windows\system32\ctfmon.exe - Ok
      c:\windows\system32\searchprotocolhost.exe - Ok
      c:\program files\mozilla firefox\plugin-container.exe - Ok
      >c:\users\casa\downloads\hsxct6t2.exe is BINARYRES container
      >>c:\users\casa\downloads\hsxct6t2.exe\data001 - packed by BINARYRES
      >>c:\users\casa\downloads\hsxct6t2.exe\data002 - packed by BINARYRES
      c:\users\casa\downloads\hsxct6t2.exe - container
      c:\users\casa\downloads\hsxct6t2.exe:Zone.Identifier - Ok
      c:\program files\mozilla firefox\firefox.exe - Ok
      c:\windows\system32\searchfilterhost.exe - Ok
      c:\program files\alwil software\avast5\snxhk.dll - Ok
      c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll - Ok
      c:\windows\system32\npmproxy.dll - Ok
      c:\windows\system32\rasadhlp.dll - Ok
      c:\program files\common files\microsoft shared\windows live\wlidnsp.dll - Ok
      c:\windows\system32\netprofm.dll - Ok
      c:\windows\system32\wbem\wbemsvc.dll - Ok
      c:\windows\system32\ntdsapi.dll - Ok
      c:\windows\system32\wbem\fastprox.dll - Ok
      c:\windows\system32\wbemcomn.dll - Ok
      c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll - Ok
      c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll - Ok
      c:\windows\system32\iconcodecservice.dll - Ok
      c:\windows\system32\explorerframe.dll - Ok
      c:\windows\system32\mpr.dll - Ok
      c:\windows\system32\winmm.dll - Ok
      c:\windows\system32\dhcpcsvc.dll - Ok
      c:\windows\system32\dhcpcsvc6.dll - Ok
      c:\windows\system32\fwpuclnt.dll - Ok
      c:\windows\system32\wbem\wbemprox.dll - Ok
      >c:\windows\system32\winnsi.dll - packed by FLY-CODE
      c:\windows\system32\winnsi.dll - Ok
      c:\windows\system32\iphlpapi.dll - Ok
      c:\windows\system32\nlaapi.dll - Ok
      >c:\windows\system32\msimg32.dll - packed by FLY-CODE
      c:\windows\system32\msimg32.dll - Ok
      c:\windows\system32\oleacc.dll - Ok
      c:\windows\system32\windowscodecs.dll - Ok
      c:\windows\system32\dwmapi.dll - Ok
      c:\windows\system32\duser.dll - Ok
      c:\windows\system32\dui70.dll - Ok
      c:\windows\system32\uxtheme.dll - Ok
      c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - Ok
      c:\windows\system32\version.dll - Ok
      c:\windows\system32\wshtcpip.dll - Ok
      c:\windows\system32\credssp.dll - Ok
      c:\windows\system32\bcryptprimitives.dll - Ok
      c:\windows\system32\rsaenh.dll - Ok
      c:\windows\system32\dnsapi.dll - Ok
      c:\windows\system32\msv1_0.dll - Ok
      c:\windows\system32\wship6.dll - Ok
      c:\windows\system32\mswsock.dll - Ok
      c:\windows\system32\cryptsp.dll - Ok
      c:\windows\system32\bcrypt.dll - Ok
      c:\windows\system32\cryptdll.dll - Ok
      >c:\windows\system32\secur32.dll - packed by FLY-CODE
      c:\windows\system32\secur32.dll - Ok
      c:\windows\system32\sspicli.dll - Ok
      c:\windows\system32\apphelp.dll - Ok
      c:\windows\system32\cryptbase.dll - Ok
      c:\windows\system32\rpcrtremote.dll - Ok
      c:\windows\system32\profapi.dll - Ok
      c:\windows\system32\sxs.dll - Ok
      c:\windows\system32\sxssrv.dll - Ok
      c:\windows\system32\winsrv.dll - Ok
      c:\windows\system32\basesrv.dll - Ok
      c:\windows\system32\csrsrv.dll - Ok
      c:\windows\system32\uxinit.dll - Ok
      c:\windows\system32\slc.dll - Ok
      c:\windows\system32\wkscli.dll - Ok
      >c:\windows\system32\netutils.dll - packed by FLY-CODE
      c:\windows\system32\netutils.dll - Ok
      c:\windows\system32\netjoin.dll - Ok
      c:\windows\system32\winsta.dll - Ok
      c:\windows\system32\wtsapi32.dll - Ok
      c:\windows\system32\ubpm.dll - Ok
      c:\windows\system32\authz.dll - Ok
      c:\windows\system32\srvcli.dll - Ok
      c:\windows\system32\scesrv.dll - Ok
      c:\windows\system32\scext.dll - Ok
      c:\windows\system32\certpoleng.dll - Ok
      c:\windows\system32\dssenh.dll - Ok
      c:\windows\system32\cryptnet.dll - Ok
      c:\windows\system32\gpapi.dll - Ok
      c:\windows\system32\userenv.dll - Ok
      c:\windows\system32\scecli.dll - Ok
      c:\windows\system32\livessp.dll - Ok
      c:\windows\system32\pku2u.dll - Ok
      c:\windows\system32\tspkg.dll - Ok
      c:\windows\system32\efslsaext.dll - Ok
      c:\windows\system32\wdigest.dll - Ok
      c:\windows\system32\schannel.dll - Ok
      c:\windows\system32\logoncli.dll - Ok
      c:\windows\system32\netlogon.dll - Ok
      c:\windows\system32\kerberos.dll - Ok
      c:\windows\system32\negoexts.dll - Ok
      c:\windows\system32\msprivs.dll - Ok
      c:\windows\system32\ncrypt.dll - Ok
      c:\windows\system32\cngaudit.dll - Ok
      c:\windows\system32\wevtapi.dll - Ok
      c:\windows\system32\samsrv.dll - Ok
      c:\windows\system32\lsasrv.dll - Ok
      >c:\windows\system32\sspisrv.dll - packed by FLY-CODE
      c:\windows\system32\sspisrv.dll - Ok
      c:\windows\system32\pcwum.dll - Ok
      c:\windows\system32\wmsgapi.dll - Ok
      c:\windows\system32\sysntfy.dll - Ok
      c:\windows\system32\wbem\wmiutils.dll - Ok
      c:\windows\system32\wbem\wmidcprv.dll - Ok
      c:\windows\system32\ntmarta.dll - Ok
      c:\windows\system32\rpcss.dll - Ok
      c:\windows\system32\umpo.dll - Ok
      c:\windows\system32\spinf.dll - Ok
      c:\windows\system32\umpnpmgr.dll - Ok
      c:\windows\system32\devrtl.dll - Ok
      >c:\windows\system32\macromed\flash\npswf32_11_7_700_202.dll - packed by BINARYRES
      >>c:\windows\system32\macromed\flash\npswf32_11_7_700_202.dll is WISE container
      c:\windows\system32\macromed\flash\npswf32_11_7_700_202.dll - container
      c:\windows\system32\mscms.dll - Ok
      c:\windows\system32\mlang.dll - Ok
      c:\windows\system32\dsound.dll - Ok
      c:\windows\system32\powrprof.dll - Ok
      c:\windows\system32\avrt.dll - Ok
      c:\windows\system32\winspool.drv - Ok
      c:\windows\system32\audioses.dll - Ok
      c:\windows\system32\mmdevapi.dll - Ok
      c:\windows\system32\propsys.dll - Ok
      c:\windows\system32\firewallapi.dll - Ok
      c:\windows\system32\rpcepmap.dll - Ok
      c:\windows\system32\wuapi.dll - Ok
      c:\windows\system32\cabinet.dll - Ok
      c:\windows\system32\wscsvc.dll - Ok
      c:\windows\system32\dbghelp.dll - Ok
      c:\program files\internet explorer\ieproxy.dll - Ok
      c:\windows\system32\p2pcollab.dll - Ok
      c:\windows\system32\p2p.dll - Ok
      c:\windows\system32\winrnr.dll - Ok
      c:\windows\system32\pnrpnsp.dll - Ok
      c:\windows\system32\napinsp.dll - Ok
      c:\windows\system32\tquery.dll - Ok
      c:\windows\system32\msxml6.dll - Ok
      c:\windows\system32\wbem\winmgmtr.dll - Ok
      c:\windows\system32\actxprxy.dll - Ok
      c:\windows\system32\provsvc.dll - Ok
      >c:\windows\system32\mfplat.dll - packed by FLY-CODE
      c:\windows\system32\mfplat.dll - Ok
      c:\windows\system32\wmalfxgfxdsp.dll - Ok
      c:\windows\system32\fundisc.dll - Ok
      c:\windows\system32\dhcpcore6.dll - Ok
      c:\windows\system32\dhcpcore.dll - Ok
      c:\windows\system32\nrpsrv.dll - Ok
      c:\windows\system32\lmhsvc.dll - Ok
      c:\windows\system32\atl.dll - Ok
      c:\windows\system32\audiosrv.dll - Ok
      c:\windows\system32\fdproxy.dll - Ok
      c:\windows\system32\wevtsvc.dll - Ok
      c:\windows\system32\hgprint.dll - Ok
      c:\windows\system32\idlisten.dll - Ok
      c:\windows\system32\listsvc.dll - Ok
      c:\windows\system32\sfc_os.dll - Ok
      c:\windows\system32\portabledeviceconnectapi.dll - Ok
      c:\windows\system32\sfc.dll - Ok
      c:\windows\system32\aepic.dll - Ok
      c:\windows\system32\rasman.dll - Ok
      c:\windows\system32\rasapi32.dll - Ok
      c:\windows\system32\mprapi.dll - Ok
      c:\windows\system32\rasdlg.dll - Ok
      c:\windows\system32\netman.dll - Ok
      c:\windows\system32\hnetcfg.dll - Ok
      c:\windows\system32\netcfgx.dll - Ok
      c:\windows\system32\rtutils.dll - Ok
      c:\windows\system32\trkwks.dll - Ok
      c:\windows\system32\sysmain.dll - Ok
      c:\windows\system32\pcasvc.dll - Ok
      c:\windows\system32\cscobj.dll - Ok
      c:\windows\system32\portabledeviceapi.dll - Ok
      c:\windows\system32\netshell.dll - Ok
      c:\windows\system32\uxsms.dll - Ok
      c:\windows\system32\dsrole.dll - Ok
      c:\windows\system32\mstask.dll - Ok
      c:\windows\system32\taskschd.dll - Ok
      c:\windows\system32\peerdist.dll - Ok
      c:\windows\system32\cscsvc.dll - Ok
      c:\windows\system32\samcli.dll - Ok
      c:\windows\system32\netapi32.dll - Ok
      c:\windows\system32\xmllite.dll - Ok
      c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll - Ok
      c:\windows\system32\fdwsd.dll - Ok
      c:\windows\system32\fdphost.dll - Ok
      c:\windows\system32\fdssdp.dll - Ok
      c:\windows\system32\perftrack.dll - Ok
      c:\windows\system32\wdi.dll - Ok
      c:\windows\system32\webservices.dll - Ok
      c:\windows\system32\wsdapi.dll - Ok
      c:\windows\system32\davhlpr.dll - Ok
      c:\windows\system32\wer.dll - Ok
      c:\windows\system32\webio.dll - Ok
      c:\windows\system32\winhttp.dll - Ok
      c:\windows\system32\ssdpapi.dll - Ok
      c:\windows\system32\webclnt.dll - Ok
      c:\windows\system32\nsisvc.dll - Ok
      c:\windows\system32\es.dll - Ok
      c:\windows\system32\fntcache.dll - Ok
      c:\windows\system32\advpack.dll - Ok
      c:\windows\system32\wuaueng.dll - Ok
      >c:\windows\system32\mspatcha.dll - packed by FLY-CODE
      c:\windows\system32\mspatcha.dll - Ok
      c:\windows\system32\qmgr.dll - Ok
      c:\windows\system32\bitsigd.dll - Ok
      c:\windows\system32\bitsperf.dll - Ok
      c:\windows\system32\wbem\ncprov.dll - Ok
      c:\windows\system32\nci.dll - Ok
      c:\windows\system32\wbem\wbemess.dll - Ok
      c:\windows\system32\resutils.dll - Ok
      c:\windows\system32\clusapi.dll - Ok
      c:\windows\system32\ncobjapi.dll - Ok
      c:\windows\system32\wbem\wmiprvsd.dll - Ok
      c:\windows\system32\sscore.dll - Ok
      c:\windows\system32\browser.dll - Ok
      c:\windows\system32\srvsvc.dll - Ok
      c:\windows\system32\wbem\repdrvfs.dll - Ok
      c:\windows\system32\wbem\esscli.dll - Ok
      c:\windows\system32\wbem\wbemcore.dll - Ok
      c:\windows\system32\wdscore.dll - Ok
      c:\windows\system32\sqmapi.dll - Ok
      c:\windows\system32\msxml3.dll - Ok
      c:\windows\system32\iphlpsvc.dll - Ok
      c:\windows\system32\wbem\wmisvc.dll - Ok
      c:\windows\system32\tschannel.dll - Ok
      c:\windows\system32\msi.dll - Ok
      c:\windows\system32\taskcomp.dll - Ok
      c:\windows\system32\wiarpc.dll - Ok
      c:\windows\system32\fvecerts.dll - Ok
      c:\windows\system32\fveapi.dll - Ok
      c:\windows\system32\ktmw32.dll - Ok
      >c:\windows\system32\tbs.dll - packed by FLY-CODE
      c:\windows\system32\tbs.dll - Ok
      c:\windows\system32\appinfo.dll - Ok
      c:\windows\system32\schedsvc.dll - Ok
      c:\windows\system32\shsvcs.dll - Ok
      c:\windows\system32\esent.dll - Ok
      c:\windows\system32\vssapi.dll - Ok
      c:\windows\system32\sens.dll - Ok
      c:\windows\system32\themeservice.dll - Ok
      c:\windows\system32\profsvc.dll - Ok
      c:\windows\system32\gpsvc.dll - Ok
      c:\windows\system32\mmcss.dll - Ok
      c:\windows\system32\vsstrace.dll - Ok
      c:\windows\system32\samlib.dll - Ok
      c:\windows\system32\ksuser.dll - Ok
      c:\windows\system32\audiokse.dll - Ok
      c:\windows\system32\audioeng.dll - Ok
      c:\windows\system32\sensapi.dll - Ok
      c:\windows\system32\ncsi.dll - Ok
      c:\windows\system32\nlasvc.dll - Ok
      c:\windows\system32\cryptsvc.dll - Ok
      c:\windows\system32\wkssvc.dll - Ok
      c:\windows\system32\dnsext.dll - Ok
      c:\windows\system32\dnsrslvr.dll - Ok
      >c:\program files\alwil software\avast5\defs\13052700\algo.dll is BINARYRES container
      >>c:\program files\alwil software\avast5\defs\13052700\algo.dll\data001 - packed by XOREXE
      >>>c:\program files\alwil software\avast5\defs\13052700\algo.dll\data001 - packed by FLY-CODE
      c:\program files\alwil software\avast5\defs\13052700\algo.dll - container
      c:\program files\alwil software\avast5\defs\13052700\aswfidb.dll - Ok
      >c:\program files\alwil software\avast5\defs\13052700\aswengin.dll is BINARYRES container
      >>c:\program files\alwil software\avast5\defs\13052700\aswengin.dll\data001 is LZMA container
      >>c:\program files\alwil software\avast5\defs\13052700\aswengin.dll\data002 - packed by MS COMPRESS
      c:\program files\alwil software\avast5\defs\13052700\aswengin.dll - container
      c:\program files\alwil software\avast5\defs\13052700\aswrep.dll - Ok
      >c:\program files\alwil software\avast5\defs\13052700\aswcmnbs.dll is BINARYRES container
      c:\program files\alwil software\avast5\defs\13052700\aswcmnbs.dll - container
      c:\windows\system32\qmgrprxy.dll - Ok
      >c:\program files\alwil software\avast5\ashwsftr.dll is BINARYRES container
      c:\program files\alwil software\avast5\ashwsftr.dll - container
      c:\windows\system32\security.dll - Ok
      c:\program files\alwil software\avast5\aswpatchmgt.dll - Ok
      c:\program files\alwil software\avast5\ashwebsv.dll - Ok
      c:\program files\alwil software\avast5\ashmaisv.dll - Ok
      c:\program files\alwil software\avast5\ahresws.dll - Ok
      c:\program files\alwil software\avast5\defs\13052700\aswscan.dll - Ok
      >c:\program files\alwil software\avast5\defs\13052700\aswcmnos.dll is BINARYRES container
      >>c:\program files\alwil software\avast5\defs\13052700\aswcmnos.dll\data001 - packed by XOREXE
      >>>c:\program files\alwil software\avast5\defs\13052700\aswcmnos.dll\data001 - packed by BINARYRES
      c:\program files\alwil software\avast5\defs\13052700\aswcmnos.dll - container
      c:\program files\alwil software\avast5\defs\13052700\aswcmnis.dll - Ok
      c:\program files\alwil software\avast5\ahresstd.dll - Ok
      c:\program files\alwil software\avast5\ahresspm.dll - Ok
      c:\program files\alwil software\avast5\ahresp2p.dll - Ok
      c:\program files\alwil software\avast5\ahresns.dll - Ok
      c:\program files\alwil software\avast5\ahresmes.dll - Ok
      c:\program files\alwil software\avast5\ahresmai.dll - Ok
      >c:\program files\alwil software\avast5\ahresjs.dll - packed by FLY-CODE
      c:\program files\alwil software\avast5\ahresjs.dll - Ok
      c:\program files\alwil software\avast5\ahresbhv.dll - Ok
      c:\windows\system32\fltlib.dll - Ok
      c:\program files\alwil software\avast5\defs\13052700\swhealthex.dll - Ok
      c:\program files\alwil software\avast5\defs\13052700\arpot.dll - Ok
      c:\windows\system32\wlanutil.dll - Ok
      c:\program files\alwil software\avast5\libeay32.dll - Ok
      c:\program files\alwil software\avast5\ssleay32.dll - Ok
      c:\windows\system32\wlanapi.dll - Ok
      c:\windows\system32\wscproxystub.dll - Ok
      c:\windows\system32\wscapi.dll - Ok
      c:\windows\system32\wscisvif.dll - Ok
      c:\program files\alwil software\avast5\aswstrm.dll - Ok
      c:\program files\alwil software\avast5\aswdld.dll - Ok
      c:\program files\alwil software\avast5\aswidle.dll - Ok
      c:\program files\alwil software\avast5\avastip.dll - Ok
      >c:\program files\alwil software\avast5\aavm4h.dll - packed by BINARYRES
      c:\program files\alwil software\avast5\aavm4h.dll - Ok
      c:\program files\alwil software\avast5\aavmrpch.dll - Ok
      c:\program files\alwil software\avast5\aswproperty.dll - Ok
      c:\program files\alwil software\avast5\aswsqlt.dll - Ok
      c:\program files\alwil software\avast5\aswlog.dll - Ok
      c:\program files\alwil software\avast5\ashtaskex.dll - Ok
      c:\program files\alwil software\avast5\ashtask.dll - Ok
      c:\program files\alwil software\avast5\aswaux.dll - Ok
      >c:\program files\alwil software\avast5\ashserv.dll is BINARYRES container
      c:\program files\alwil software\avast5\ashserv.dll - container
      c:\program files\alwil software\avast5\3082\base.dll - Ok
      >c:\program files\alwil software\avast5\dbghelp.dll - packed by PESTUB
      c:\program files\alwil software\avast5\dbghelp.dll - Ok
      c:\program files\alwil software\avast5\aswengldr.dll - Ok
      c:\windows\system32\wsock32.dll - Ok
      c:\program files\alwil software\avast5\ashbase.dll - Ok
      c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll - Ok
      c:\program files\alwil software\avast5\aswcmnis.dll - Ok
      >c:\program files\alwil software\avast5\aswcmnos.dll is BINARYRES container
      >>c:\program files\alwil software\avast5\aswcmnos.dll\data001 - packed by XOREXE
      >>>c:\program files\alwil software\avast5\aswcmnos.dll\data001 - packed by BINARYRES
      c:\program files\alwil software\avast5\aswcmnos.dll - container
      >c:\program files\alwil software\avast5\aswcmnbs.dll is BINARYRES container
      c:\program files\alwil software\avast5\aswcmnbs.dll - container
      c:\windows\system32\wshqos.dll - Ok
      c:\program files\malwarebytes' anti-malware\mbamnet.dll - Ok
      c:\program files\malwarebytes' anti-malware\mbam.dll - Ok
      c:\windows\system32\igdumd32.dll - Ok
      c:\windows\system32\d3d10level9.dll - Ok
      c:\windows\system32\d3d11.dll - Ok
      c:\windows\system32\udwm.dll - Ok
      c:\windows\system32\dxgi.dll - Ok
      c:\windows\system32\d3d10_1core.dll - Ok
      c:\windows\system32\d3d10_1.dll - Ok
      c:\windows\system32\dwmcore.dll - Ok
      c:\windows\system32\dwmredir.dll - Ok
      c:\windows\system32\browcli.dll - Ok
      c:\windows\system32\inetpp.dll - Ok
      c:\windows\system32\win32spl.dll - Ok
      c:\windows\system32\spool\prtprocs\w32x86\winprint.dll - Ok
      c:\windows\system32\fdpnp.dll - Ok
      c:\windows\system32\wsdmon.dll - Ok
      c:\windows\system32\wls0wndh.dll - Ok
      c:\windows\system32\usbmon.dll - Ok
      c:\windows\system32\wsnmp32.dll - Ok
      c:\windows\system32\snmpapi.dll - Ok
      c:\windows\system32\tcpmon.dll - Ok
      c:\windows\system32\fxsmon.dll - Ok
      >c:\windows\system32\ep0slm01.dll - packed by PESTUB
      c:\windows\system32\ep0slm01.dll - Ok
      c:\windows\system32\printisolationproxy.dll - Ok
      c:\windows\system32\spoolss.dll - Ok
      c:\windows\system32\localspl.dll - Ok
      c:\windows\system32\umb.dll - Ok
      c:\windows\system32\cscapi.dll - Ok
      c:\windows\system32\dimsjob.dll - Ok
      c:\program files\internet explorer\sqmapi.dll - Ok
      c:\windows\system32\wpc.dll - Ok
      c:\windows\system32\playsndsrv.dll - Ok
      c:\windows\system32\hotstartuseragent.dll - Ok
      c:\windows\system32\msutb.dll - Ok
      c:\windows\system32\wdmaud.drv - Ok
      c:\windows\system32\msctfmonitor.dll - Ok
      c:\windows\system32\wpcumi.dll - Ok
      c:\windows\system32\taskschdps.dll - Ok
      c:\windows\system32\midimap.dll - Ok
      c:\windows\system32\msacm32.dll - Ok
      c:\windows\system32\msacm32.drv - Ok
      c:\program files\glary utilities\contexthandler.dll - Ok
      c:\program files\glary utilities\vcl70.bpl - Ok
      c:\program files\glary utilities\rtl70.bpl - Ok
      c:\windows\system32\thumbcache.dll - Ok
      c:\windows\system32\structuredquery.dll - Ok
      c:\windows\system32\werconcpl.dll - Ok
      >c:\windows\system32\wscui.cpl is ZLIB container
      c:\windows\system32\wscui.cpl - container
      c:\windows\system32\framedynos.dll - Ok
      c:\windows\system32\hcproviders.dll - Ok
      c:\windows\system32\uianimation.dll - Ok
      c:\windows\system32\imapi2.dll - Ok
      c:\windows\system32\hgcpl.dll - Ok
      c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll - Ok
      c:\windows\system32\ieframe.dll - Ok
      c:\windows\system32\bthprops.cpl - Ok
      c:\windows\system32\qagent.dll - Ok
      c:\windows\system32\wwanapi.dll - Ok
      c:\windows\system32\wwapi.dll - Ok
      c:\windows\system32\synccenter.dll - Ok
      c:\windows\system32\msftedit.dll - Ok
      c:\windows\system32\wercplsupport.dll - Ok
      c:\windows\system32\wscinterop.dll - Ok
      c:\windows\system32\networkexplorer.dll - Ok
      c:\program files\common files\microsoft shared\ink\tiptsf.dll - Ok
      c:\windows\system32\msls31.dll - Ok
      c:\windows\system32\mssprxy.dll - Ok
      c:\windows\system32\gameux.dll - Ok
      c:\windows\system32\shdocvw.dll - Ok
      >c:\windows\system32\timedate.cpl is ZLIB container
      c:\windows\system32\timedate.cpl - container
      c:\program files\microsoft office\office14\3082\grooveintlresource.dll - Ok
      c:\program files\common files\microsoft shared\office14\cultures\office.odf - Ok
      c:\program files\microsoft office\office14\grooveex.dll - Ok
      c:\windows\system32\msiltcfg.dll - Ok
      c:\windows\system32\linkinfo.dll - Ok
      c:\windows\system32\ntshrui.dll - Ok
      c:\windows\system32\cscdll.dll - Ok
      c:\windows\system32\cscui.dll - Ok
      c:\windows\winsxs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.6161_none_51cd0a7abbe4e19b\atl90.dll - Ok
      c:\windows\system32\syncui.dll - Ok
      c:\program files\defraggler\defragglershell.dll - Ok
      c:\program files\winrar\rarext.dll - Ok
      c:\windows\system32\ehstorshell.dll - Ok
      c:\program files\alwil software\avast5\ashshell.dll - Ok
      c:\windows\system32\synceng.dll - Ok
      c:\program files\malwarebytes' anti-malware\mbamext.dll - Ok
      c:\windows\system32\twext.dll - Ok
      c:\windows\system32\oledlg.dll - Ok
      c:\windows\system32\fxsresm.dll - Ok
      c:\windows\system32\fxsst.dll - Ok
      c:\windows\system32\fxsapi.dll - Ok
      c:\windows\system32\actioncenter.dll - Ok
      c:\windows\system32\srchadmin.dll - Ok
      c:\windows\system32\qutil.dll - Ok
      c:\windows\system32\pnidui.dll - Ok
      c:\windows\system32\portabledevicetypes.dll - Ok
      c:\windows\system32\wpdshserviceobj.dll - Ok
      c:\windows\system32\dxp.dll - Ok
      c:\windows\system32\alttab.dll - Ok
      c:\windows\ehome\ehsso.dll - Ok
      c:\windows\system32\syncreg.dll - Ok
      c:\windows\system32\prnfldr.dll - Ok
      c:\windows\system32\batmeter.dll - Ok
      c:\windows\system32\stobject.dll - Ok
      c:\windows\system32\hid.dll - Ok
      c:\windows\system32\sndvolsso.dll - Ok
      c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll - Ok
      c:\windows\system32\acppage.dll - Ok
      >c:\windows\system32\cryptui.dll - packed by FLY-CODE
      c:\windows\system32\cryptui.dll - Ok
      >c:\windows\system32\authui.dll is ZLIB container
      c:\windows\system32\authui.dll - container
      c:\windows\system32\wdiasqmmodule.dll - Ok
      c:\windows\system32\radardt.dll - Ok
      c:\windows\system32\bfe.dll - Ok
      c:\windows\system32\diagperf.dll - Ok
      c:\windows\system32\dps.dll - Ok
      c:\windows\system32\wfapigp.dll - Ok
      c:\windows\system32\mpssvc.dll - Ok
      >c:\windows\system32\wiatrace.dll - packed by FLY-CODE
      c:\windows\system32\wiatrace.dll - Ok
      c:\windows\system32\wiaservc.dll - Ok
      c:\windows\system32\wmploc.dll - Ok
      c:\windows\system32\wmp.dll - Ok
      c:\windows\system32\msmpeg2enc.dll - Ok
      c:\windows\system32\blackbox.dll - Ok
      c:\windows\system32\wmpmde.dll - Ok
      >c:\windows\system32\drmv2clt.dll is BINARYRES container
      >>c:\windows\system32\drmv2clt.dll\data001 is JS-HTML container
      c:\windows\system32\drmv2clt.dll - container
      c:\windows\system32\wmdrmdev.dll - Ok
      c:\windows\system32\devenum.dll - Ok
      c:\windows\system32\wmpps.dll - Ok
      c:\windows\system32\davclnt.dll - Ok
      c:\windows\system32\ntlanman.dll - Ok
      c:\windows\system32\upnphost.dll - Ok
      c:\windows\system32\msdmo.dll - Ok
      >c:\windows\system32\winsatapi.dll is ZLIB container
      c:\windows\system32\winsatapi.dll - container
      c:\windows\system32\httpapi.dll - Ok
      c:\windows\system32\drprov.dll - Ok
      c:\windows\system32\upnp.dll - Ok
      c:\windows\system32\igfxsrvc.dll - Ok
      c:\windows\system32\igfxresp.lrc - Ok
      c:\windows\system32\hccutils.dll - Ok
      c:\windows\system32\ac3acm.acm - Ok
      c:\windows\system32\url.dll - Ok
      c:\windows\system32\lameacm.acm - Ok
      >c:\program files\alwil software\avast5\commonres.dll - packed by BINARYRES
      >>c:\program files\alwil software\avast5\commonres.dll is BINARYRES container
      >>>c:\program files\alwil software\avast5\commonres.dll\data003 - packed by FLY-CODE
      >>>>c:\program files\alwil software\avast5\commonres.dll\data003 is NSIS container
      >>>>>c:\program files\alwil software\avast5\commonres.dll\data003\GoogleUpdateSetup_latest.exe is LZMA container
      >>>c:\program files\alwil software\avast5\commonres.dll\data004 - packed by FLY-CODE
      >>>>c:\program files\alwil software\avast5\commonres.dll\data004 is NSIS container
      >>>>>c:\program files\alwil software\avast5\commonres.dll\data004\GoogleUpdateSetup_latest.exe is LZMA container
      >>>c:\program files\alwil software\avast5\commonres.dll\data006 - packed by FLY-CODE
      >>>>c:\program files\alwil software\avast5\commonres.dll\data006 is NSIS container
      >>>>>c:\program files\alwil software\avast5\commonres.dll\data006\GoogleUpdateSetup_latest.exe is LZMA container
      c:\program files\alwil software\avast5\commonres.dll - container
      c:\program files\alwil software\avast5\3082\uilangres.dll - Ok
      c:\program files\alwil software\avast5\aswdata.dll - Ok
      c:\program files\alwil software\avast5\defs\13052700\uiext.dll - Ok
      c:\windows\system32\sirenacm.dll - Ok
      c:\windows\system32\l3codeca.acm - Ok
      c:\windows\system32\msadp32.acm - Ok
      c:\windows\system32\msgsm32.acm - Ok
      c:\windows\system32\msg711.acm - Ok
      >c:\windows\system32\imaadp32.acm - packed by FLY-CODE
      c:\windows\system32\imaadp32.acm - Ok
      c:\program files\alwil software\avast5\aswara.dll - Ok
      >c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll is ZLIB container
      c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll - container
      c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_49768ef57548175e\mfc90esn.dll - Ok
      c:\program files\alwil software\avast5\aswutil.dll - Ok
      >c:\users\casa\appdata\local\temp\526c69e0-19e4f050-231db8c0-b16da3d0\kgncpxdj.dll is BINARYRES container
      >>c:\users\casa\appdata\local\temp\526c69e0-19e4f050-231db8c0-b16da3d0\kgncpxdj.dll\data003 - packed by BINARYRES
      >>c:\users\casa\appdata\local\temp\526c69e0-19e4f050-231db8c0-b16da3d0\kgncpxdj.dll\data004 - packed by BINARYRES
      c:\users\casa\appdata\local\temp\526c69e0-19e4f050-231db8c0-b16da3d0\kgncpxdj.dll - container
      c:\windows\system32\pdh.dll - Ok
      c:\windows\system32\winscard.dll - Ok
      c:\program files\common files\microsoft shared\windows live\sqmapi.dll - Ok
      c:\windows\system32\igfxdev.dll - Ok
      c:\windows\system32\elslad.dll - Ok
      c:\windows\system32\naturallanguage6.dll - Ok
      c:\windows\system32\elscore.dll - Ok
      c:\windows\system32\mssrch.dll - Ok
      c:\windows\system32\msidle.dll - Ok
      c:\windows\system32\ipsecsvc.dll - Ok
      c:\windows\system32\fwremotesvr.dll - Ok
      c:\windows\system32\ssdpsrv.dll - Ok
      c:\windows\system32\udhisapi.dll - Ok
      c:\windows\system32\fdrespub.dll - Ok
      >c:\programdata\microsoft\windows defender\definition updates\{39ce68cd-432e-4379-b723-c7e1c206fe5e}\mpengine.dll is BINARYRES container
      c:\programdata\microsoft\windows defender\definition updates\{39ce68cd-432e-4379-b723-c7e1c206fe5e}\mpengine.dll - container
      c:\windows\system32\tdh.dll - Ok
      c:\program files\windows defender\mpclient.dll - Ok
      c:\program files\windows defender\mpsvc.dll - Ok
      c:\program files\windows defender\mprtp.dll - Ok
      c:\program files\mozilla firefox\xul.dll - Ok
      c:\windows\system32\icm32.dll - Ok
      c:\program files\mozilla firefox\gkmedias.dll - Ok
      c:\program files\mozilla firefox\mozjs.dll - Ok
      c:\program files\mozilla firefox\mozsqlite3.dll - Ok
      c:\program files\mozilla firefox\ssl3.dll - Ok
      c:\program files\mozilla firefox\msvcp100.dll - Ok
      c:\program files\mozilla firefox\msvcr100.dll - Ok
      c:\program files\mozilla firefox\nss3.dll - Ok
      c:\program files\mozilla firefox\smime3.dll - Ok
      c:\program files\mozilla firefox\mozalloc.dll - Ok
      c:\program files\mozilla firefox\nssutil3.dll - Ok
      c:\program files\mozilla firefox\plds4.dll - Ok
      c:\program files\mozilla firefox\nspr4.dll - Ok
      c:\program files\mozilla firefox\plc4.dll - Ok
      c:\program files\mozilla firefox\mozglue.dll - Ok
      c:\windows\system32\mf.dll - Ok
      c:\windows\system32\ehstorapi.dll - Ok
      c:\windows\system32\searchfolder.dll - Ok
      c:\program files\mozilla firefox\nssckbi.dll - Ok
      c:\program files\mozilla firefox\freebl3.dll - Ok
      c:\windows\system32\d3d9.dll - Ok
      c:\windows\system32\dwrite.dll - Ok
      c:\program files\mozilla firefox\nssdbm3.dll - Ok
      c:\program files\mozilla firefox\softokn3.dll - Ok
      c:\program files\mozilla firefox\browser\components\browsercomps.dll - Ok
      c:\windows\system32\t2embed.dll - Ok
      c:\windows\system32\feclient.dll - Ok
      c:\windows\system32\mfreadwrite.dll - Ok
      c:\program files\mozilla firefox\xpcom.dll - Ok
      c:\program files\alwil software\avast5\aswjsflt.dll - Ok
      c:\windows\system32\d3d8thk.dll - Ok
      c:\program files\windows defender\mpoav.dll - Ok
      c:\windows\system32\p2pgraph.dll - Ok
      c:\windows\system32\p2psvc.dll - Ok
      c:\windows\system32\pnrpsvc.dll - Ok
      c:\program files\windows defender\mpcmdrun.exe - Ok
      c:\windows\system32\wermgr.exe - Ok
      c:\windows\system32\sc.exe - Ok
      c:\windows\system32\raserver.exe - Ok
      c:\windows\system32\powercfg.exe - Ok
      c:\windows\system32\gathernetworkinfo.vbs - Ok
      c:\windows\system32\lpremove.exe - Ok
      c:\windows\ehome\ehprivjob.exe - Ok
      c:\windows\system32\defrag.exe - Ok
      c:\windows\system32\bthudtask.exe - Ok
      c:\windows\system32\aitagent.exe - Ok
      c:\windows\system32\appidpolicyconverter.exe - Ok
      c:\users\jajaja\appdata\roaming\microsoft\windows\start menu\programs\startup\desktop.ini - Ok
      c:\users\casa\appdata\roaming\microsoft\windows\start menu\programs\startup\desktop.ini - Ok
      c:\programdata\microsoft\windows\start menu\programs\startup\desktop.ini - Ok
      c:\windows\system32\dshowrdpfilter.dll - Ok
      c:\windows\system32\wwanadvui.dll - Ok
      c:\windows\system32\dfdwiz.exe - Ok
      c:\windows\system32\wabsyncprovider.dll - Ok
      c:\windows\system32\shwebsvc.dll - Ok
      c:\windows\system32\oobefldr.dll - Ok
      c:\windows\system32\stikynot.exe - Ok
      >c:\program files\common files\microsoft shared\ink\tabskb.dll is ZLIB container
      c:\program files\common files\microsoft shared\ink\tabskb.dll - container
      c:\windows\system32\sdiageng.dll - Ok
      >c:\windows\system32\oobe\msoobeui.dll is ZLIB container
      c:\windows\system32\oobe\msoobeui.dll - container
      c:\windows\system32\deviceuxres.dll - Ok
      c:\windows\system32\apds.dll - Ok
      c:\windows\system32\spool\tools\printbrmengine.exe - Ok
      c:\windows\system32\wlanpref.dll - Ok
      c:\windows\system32\documentperformanceevents.dll - Ok
      c:\windows\system32\magnification.dll - Ok
      c:\windows\system32\intl.cpl - Ok
      >c:\windows\system32\drivers\storport.sys - packed by FLY-CODE
      c:\windows\system32\drivers\storport.sys - Ok
      c:\program files\common files\microsoft shared\ink\mshwlatin.dll - Ok
      c:\windows\system32\connect.dll - Ok
      c:\windows\system32\wmphoto.dll - Ok
      c:\program files\common files\microsoft shared\ink\mraut.dll - Ok
      c:\windows\system32\apilogen.dll - Ok
      c:\windows\system32\mfplay.dll - Ok
      c:\windows\system32\wisptis.exe - Ok
      c:\windows\system32\powercpl.dll - Ok
      c:\windows\system32\mssha.dll - Ok
      c:\windows\system32\taskmgr.exe - Ok
      c:\windows\system32\msmpeg2vdec.dll - Ok
      c:\windows\system32\werfault.exe - Ok
      c:\windows\system32\onex.dll - Ok
      c:\windows\system32\ocsetup.exe - Ok
      c:\program files\common files\microsoft shared\ink\inputpersonalization.exe - Ok
      c:\windows\system32\wsmres.dll - Ok
      c:\windows\system32\setupetw.dll - Ok
      c:\windows\system32\msdt.exe - Ok
      c:\windows\system32\wsqmcons.exe - Ok
      c:\windows\system32\windowspowershell\v1.0\psevents.dll - Ok
      c:\windows\system32\powercfg.cpl - Ok
      c:\windows\system32\d3d10core.dll - Ok
      c:\windows\system32\actioncentercpl.dll - Ok
      c:\windows\system32\sdiagprv.dll - Ok
      c:\windows\system32\mblctr.exe - Ok
      c:\windows\system32\portabledevicestatus.dll - Ok
      c:\windows\system32\uiribbon.dll - Ok
      c:\windows\system32\l2nacp.dll - Ok
      >c:\program files\common files\microsoft shared\ink\mip.exe is ZLIB container
      c:\program files\common files\microsoft shared\ink\mip.exe - container
      c:\windows\system32\uiautomationcore.dll - Ok
      c:\windows\system32\napipsec.dll - Ok
      c:\windows\system32\p2phost.exe - Ok
      c:\windows\system32\mp4sdecd.dll - Ok
      c:\program files\internet explorer\iedvtool.dll - Ok
      c:\program files\windows media player\wmpnssui.dll - Ok
      c:\windows\system32\mcxdriv.dll - Ok
      c:\windows\system32\setupcl.exe - Ok
      c:\windows\system32\oobe\windeploy.exe - Ok
      c:\windows\system32\oobe\oobeldr.exe - Ok
      c:\windows\system32\sysprep\sysprep.exe - Ok
      c:\windows\system32\oobe\cmisetup.dll - Ok
      c:\windows\system32\oobe\audit.exe - Ok
      c:\windows\system32\setupugc.exe - Ok
      c:\windows\system32\dxpserver.exe - Ok
      c:\windows\system32\adsldpc.dll - Ok
      c:\windows\system32\display.dll - Ok
      c:\windows\system32\netcenter.dll - Ok
      c:\windows\system32\wevtfwd.dll - Ok
      c:\windows\system32\efssvc.dll - Ok
      c:\program files\windows media player\wmpdmccore.dll - Ok
      c:\windows\system32\sud.dll - Ok
      c:\windows\system32\eqossnap.dll - Ok
      c:\windows\system32\themecpl.dll - Ok
      c:\program files\windows media player\wmpmediasharing.dll - Ok
      c:\windows\system32\osbaseln.dll - Ok
      c:\windows\system32\rdrleakdiag.exe - Ok
      c:\windows\system32\credui.dll - Ok
      c:\windows\system32\jscript9.dll - Ok
      c:\program files\windows nt\accessories\wordpad.exe - Ok
      c:\windows\system32\firewallcontrolpanel.dll - Ok
      c:\windows\system32\elshyph.dll - Ok
      c:\windows\system32\pcaevts.dll - Ok
      c:\windows\system32\racengn.dll - Ok
      c:\windows\system32\drt.dll - Ok
      c:\windows\system32\sdiagschd.dll - Ok
      >c:\program files\windows media player\wmpdmc.exe is ZLIB container
      c:\program files\windows media player\wmpdmc.exe - container
      c:\windows\system32\tsmf.dll - Ok
      c:\windows\system32\dxptaskringtone.dll - Ok
      c:\windows\system32\appidapi.dll - Ok
      c:\windows\system32\wbem\ntevt.dll - Ok
      c:\windows\system32\dccw.exe - Ok
      c:\windows\system32\usercpl.dll - Ok
      c:\windows\system32\drivers\vwififlt.sys - Ok
      c:\program files\common files\microsoft shared\ink\rtscom.dll - Ok
      c:\windows\system32\tzutil.exe - Ok
      c:\windows\system32\rpchttp.dll - Ok
      c:\windows\system32\dxptasksync.dll - Ok
      c:\windows\system32\wlanconn.dll - Ok
      c:\windows\system32\zipfldr.dll - Ok
      c:\windows\system32\mspaint.exe - Ok
      c:\windows\system32\oleres.dll - Ok
      c:\windows\system32\energy.dll - Ok
      c:\windows\system32\wdfres.dll - Ok
      c:\windows\system32\diagcpl.dll - Ok
      c:\windows\system32\oleaccrc.dll - Ok
      c:\windows\system32\displayswitch.exe - Ok
      c:\windows\system32\portabledevicesyncprovider.dll - Ok
      c:\windows\system32\msdtcvsp1res.dll - Ok
      c:\windows\system32\prflbmsg.dll - Ok
      >c:\windows\system32\speech\speechux\speechux.dll is ZLIB container
      c:\windows\system32\speech\speechux\speechux.dll - container
      c:\windows\system32\comres.dll - Ok
      c:\windows\system32\actionqueue.dll - Ok
      c:\program files\windows media player\setup_wm.exe - Ok
      c:\windows\system32\cttune.exe - Ok
      c:\windows\system32\syncinfrastructure.dll - Ok
      c:\windows\system32\wusa.exe - Ok
      c:\windows\system32\taskbarcpl.dll - Ok
      c:\windows\system32\wdc.dll - Ok
      c:\windows\system32\wpd_ci.dll - Ok
      c:\windows\system32\sharemediacpl.dll - Ok
      c:\windows\system32\van.dll - Ok
      c:\program files\windows media player\wmpsideshowgadget.exe - Ok
      c:\program files\windows media player\wmpnscfg.exe - Ok
      c:\windows\system32\peerdistsh.dll - Ok
      c:\windows\system32\wwancfg.dll - Ok
      c:\windows\system32\wlancfg.dll - Ok
      c:\windows\system32\p2pnetsh.dll - Ok
      c:\windows\system32\wcnnetsh.dll - Ok
      c:\windows\system32\nettrace.dll - Ok
      c:\windows\system32\nshipsec.dll - Ok
      c:\windows\system32\napmontr.dll - Ok
      c:\windows\system32\dot3cfg.dll - Ok
      c:\windows\system32\rpcnsh.dll - Ok
      >c:\windows\system32\hnetmon.dll - packed by FLY-CODE
      c:\windows\system32\hnetmon.dll - Ok
      c:\windows\system32\whhelper.dll - Ok
      c:\windows\system32\netiohlp.dll - Ok
      c:\windows\system32\ifmon.dll - Ok
      c:\windows\system32\authfwcfg.dll - Ok
      c:\windows\system32\fwcfg.dll - Ok
      c:\windows\system32\nshhttp.dll - Ok
      c:\windows\system32\wshelper.dll - Ok
      >c:\windows\system32\dhcpcmonitor.dll - packed by FLY-CODE
      c:\windows\system32\dhcpcmonitor.dll - Ok
      c:\windows\system32\nshwfp.dll - Ok
      c:\windows\system32\rasmontr.dll - Ok
      c:\windows\system32\rasplap.dll - Ok
      c:\program files\common files\microsoft shared\windows live\wlidcredprov.dll - Ok
      c:\windows\system32\certcredprovider.dll - Ok
      c:\windows\system32\biocredprov.dll - Ok
      c:\windows\system32\smartcardcredentialprovider.dll - Ok
      c:\windows\system32\vaultcredprovider.dll - Ok
      c:\windows\system32\chkwudrv.dll - Ok
      >c:\program files\defraggler\defraggler.exe is BINARYRES container
      c:\program files\defraggler\defraggler.exe - container
      c:\windows\system32\cleanmgr.exe - Ok
      c:\windows\system32\sdclt.exe - Ok
      >c:\windows\system32\calc.exe is ZLIB container
      c:\windows\system32\calc.exe - container
      c:\windows\system32\rdpwsx.dll - Ok
      c:\windows\system32\rdpclip.exe - Ok
      c:\windows\system32\rdpcfgex.dll - Ok
      c:\windows\system32\rdpendp.dll - Ok
      c:\windows\system32\osk.exe - Ok
      c:\windows\system32\narrator.exe - Ok
      >c:\windows\system32\magnify.exe is ZLIB container
      c:\windows\system32\magnify.exe - container
      c:\windows\system32\wfs.exe - Ok
      c:\windows\system32\msicofire.dll - Ok
      c:\windows\system32\pnpts.dll - Ok
      c:\windows\system32\apphlpdm.dll - Ok
      c:\windows\system32\radarrs.dll - Ok
      c:\windows\system32\pcadm.dll - Ok
      >c:\windows\system32\ncryptui.dll - packed by FLY-CODE
      c:\windows\system32\ncryptui.dll - Ok
      c:\windows\system32\msobjs.dll - Ok
      c:\windows\system32\adtschema.dll - Ok
      c:\windows\system32\msaudite.dll - Ok
      c:\windows\system32\iassvcs.dll - Ok
      c:\program files\windows defender\mpevmsg.dll - Ok
      c:\windows\system32\vdsvd.dll - Ok
      c:\windows\system32\vdsdyn.dll - Ok
      c:\windows\system32\vdsbas.dll - Ok
      c:\windows\system32\ntprint.dll - Ok
      c:\windows\system32\netmsg.dll - Ok
      c:\windows\system32\whealogr.dll - Ok
      c:\windows\system32\wbem\win32_tpm.dll - Ok
      c:\windows\system32\reagent.dll - Ok
      c:\windows\system32\oobe\winsetup.dll - Ok
      c:\windows\servicing\cbsmsg.dll - Ok
      c:\windows\system32\eventproviders\spcmsg.dll - Ok
      c:\windows\system32\recovery.dll - Ok
      c:\windows\system32\pots.dll - Ok
      c:\windows\system32\mdsched.exe - Ok
      c:\windows\system32\relpost.exe - Ok
      c:\windows\system32\lpksetup.exe - Ok
      c:\windows\system32\microsoft-windows-kernel-processor-power-events.dll - Ok
      c:\windows\system32\microsoft-windows-kernel-power-events.dll - Ok
      c:\windows\system32\microsoft-windows-hal-events.dll - Ok
      c:\windows\system32\fms.dll - Ok
      c:\windows\system32\fthsvc.dll - Ok
      c:\windows\system32\ehstorauthn.exe - Ok
      c:\windows\system32\wudfplatform.dll - Ok
      c:\windows\system32\dfdts.dll - Ok
      c:\windows\system32\netdiagfx.dll - Ok
      c:\windows\system32\cofiredm.dll - Ok
      c:\windows\system32\iscsilog.dll - Ok
      c:\windows\system32\rtm.dll - Ok
      c:\windows\system32\dispci.dll - Ok
      c:\windows\system32\dhcpqec.dll - Ok
      c:\windows\system32\netevent.dll - Ok
      c:\windows\system32\iologmsg.dll - Ok
      c:\windows\system32\wshext.dll - Ok
      c:\windows\microsoft.net\framework\v4.0.30319\eventlogmessages.dll - Ok
      c:\windows\system32\wsepno.dll - Ok
      c:\windows\system32\sdengin2.dll - Ok
      c:\windows\system32\wat\watux.exe - Ok
      c:\program files\common files\microsoft shared\dw\dw20.exe - Ok
      c:\windows\system32\msvbvm60.dll - Ok
      >c:\windows\system32\usbperf.dll - packed by FLY-CODE
      c:\windows\system32\usbperf.dll - Ok
      c:\windows\system32\srcore.dll - Ok
      c:\windows\system32\sxproxy.dll - Ok
      c:\windows\system32\appmgr.dll - Ok
      c:\windows\system32\mprmsg.dll - Ok
      c:\program files\microsoft office\office14\3082\mapir.dll - Ok
      c:\windows\system32\msimsg.dll - Ok
      c:\windows\system32\xwizards.dll - Ok
      c:\windows\system32\winsat.exe - Ok
      c:\windows\system32\mciavi32.dll - Ok
      c:\windows\system32\mstscax.dll - Ok
      c:\windows\system32\rstrtmgr.dll - Ok
      c:\windows\system32\msra.exe - Ok
      c:\windows\system32\tsworkspace.dll - Ok
      c:\windows\system32\perfctrs.dll - Ok
      c:\windows\system32\loadperf.dll - Ok
      c:\windows\system32\efscore.dll - Ok
      c:\windows\system32\ksproxy.ax - Ok
      c:\windows\system32\quartz.dll - Ok
      c:\windows\system32\certcli.dll - Ok
      c:\windows\system32\dimsroam.dll - Ok
      c:\windows\system32\certenroll.dll - Ok
      c:\windows\system32\pautoenr.dll - Ok
      c:\windows\system32\blbevents.dll - Ok
      c:\windows\system32\aeevts.dll - Ok
      c:\windows\system32\locationnotifications.exe - Ok
      c:\program files\dvd maker\dvdmaker.exe - Ok
      c:\windows\system32\ulib.dll - Ok
      c:\windows\microsoft.net\framework\v2.0.50727\eventlogmessages.dll - Ok
      c:\program files\common files\microsoft shared\office14\mssoap30.dll - Ok
      c:\windows\microsoft.net\framework\v4.0.30319\servicemodelevents.dll - Ok
      c:\windows\microsoft.net\framework\v3.0\windows communication foundation\servicemodelevents.dll - Ok
      c:\windows\system32\fxsevent.dll - Ok
      c:\program files\common files\microsoft shared\ink\ipseventlogmsg.dll - Ok
      c:\windows\system32\icardres.dll - Ok
      c:\windows\microsoft.net\framework\v2.0.50727\aspnet_rc.dll - Ok
      c:\windows\microsoft.net\framework\v1.1.4322\aspnet_rc.dll - Ok
      c:\program files\microsoft office\office14\urlredir.dll - Ok
      c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll - Ok
      c:\program files\common files\adobe\acrobat\activex\pdfshell.dll - Ok
      c:\program files\alwil software\avast5\aswwebrepie.dll - Ok
      c:\windows\system32\webcheck.dll - Ok
      c:\program files\microsoft office\office14\olkfstub.dll - Ok
      c:\program files\microsoft office\office14\mlshext.dll - Ok
      c:\program files\common files\microsoft shared\office14\msoshext.dll - Ok
      c:\program files\microsoft office\office14\msohevi.dll - Ok
      c:\program files\common files\microsoft shared\help\hxds.dll - Ok
      c:\windows\system32\inetcomm.dll - Ok
      c:\program files\windows live\messenger\msgrapp.dll - Ok
      c:\windows\system32\itss.dll - Ok
      c:\windows\system32\msvidctl.dll - Ok
      c:\windows\system32\mshtml.dll - Ok
      c:\program files\common files\microsoft shared\office14\msoxmlmf.dll - Ok
      c:\windows\system32\mscoree.dll - Ok
      c:\windows\system32\wwansvc.dll - Ok
      c:\windows\system32\wudfsvc.dll - Ok
      c:\windows\system32\drivers\wudfrd.sys - Ok
      c:\windows\system32\drivers\wudfpf.sys - Ok
      c:\windows\system32\drivers\ws2ifsl.sys - Ok
      c:\windows\system32\wpdbusenum.dll - Ok
      c:\windows\system32\wpcsvc.dll - Ok
      c:\windows\system32\wbem\wmiapsrv.exe - Ok
      c:\windows\system32\wbem\wmiaprpl.dll - Ok
      c:\windows\system32\drivers\wmiacpi.sys - Ok
      c:\windows\system32\wlansvc.dll - Ok
      c:\windows\system32\drivers\winusb.sys - Ok
      c:\windows\system32\winsock.dll - Ok
      c:\windows\system32\wsmsvc.dll - Ok
      >c:\windows\system32\drivers\wimmount.sys - packed by FLY-CODE
      >>c:\windows\system32\drivers\wimmount.sys - packed by FLY-CODE
      c:\windows\system32\drivers\wimmount.sys - Ok
      c:\windows\system32\wersvc.dll - Ok
      c:\windows\system32\wecsvc.dll - Ok
      c:\windows\system32\drivers\wd.sys - Ok
      c:\windows\system32\wcspluginservice.dll - Ok
      c:\windows\system32\wcncsvc.dll - Ok
      c:\windows\system32\wbiosrvc.dll - Ok
      c:\windows\system32\wbengine.exe - Ok
      >c:\windows\system32\wat\watadminsvc.exe - packed by FLY-CODE
      >>c:\windows\system32\wat\watadminsvc.exe - packed by PECRYPT
      c:\windows\system32\wat\watadminsvc.exe - Ok
      c:\windows\system32\drivers\wacompen.sys - Ok
      c:\windows\system32\w32time.dll - Ok
      c:\windows\system32\drivers\vwifibus.sys - Ok
      c:\windows\system32\vssvc.exe - Ok
      c:\windows\system32\drivers\vsmraid.sys - Ok
      c:\windows\system32\drivers\vmbushid.sys - Ok
      c:\windows\system32\drivers\viaide.sys - Ok
      c:\windows\system32\drivers\viac7.sys - Ok
      c:\windows\system32\drivers\viaagp.sys - Ok
      c:\windows\system32\drivers\vhdmp.sys - Ok
      c:\windows\system32\drivers\vgapnp.sys - Ok
      c:\windows\system32\vds.exe - Ok
      c:\windows\system32\drivers\usbvideo.sys - Ok
      c:\windows\system32\drivers\usbstor.sys - Ok
      c:\windows\system32\drivers\usbscan.sys - Ok
      c:\windows\system32\drivers\usbprint.sys - Ok
      c:\windows\system32\drivers\usbohci.sys - Ok
      c:\windows\system32\drivers\usbcir.sys - Ok
      c:\windows\system32\umrdp.dll - Ok
      >c:\windows\system32\drivers\umpass.sys - packed by FLY-CODE
      c:\windows\system32\drivers\umpass.sys - Ok
      c:\windows\system32\drivers\uliagpkx.sys - Ok
      c:\windows\system32\ui0detect.exe - Ok
      c:\windows\system32\drivers\udfs.sys - Ok
      c:\windows\system32\drivers\uagp35.sys - Ok
      c:\windows\system32\drivers\tsusbflt.sys - Ok
      c:\windows\system32\drivers\tssecsrv.sys - Ok
      c:\windows\servicing\trustedinstaller.exe - Ok
      c:\windows\system32\termsrv.dll - Ok
      c:\windows\system32\drivers\tdtcp.sys - Ok
      c:\windows\system32\drivers\tdpipe.sys - Ok
      c:\windows\system32\tbssvc.dll - Ok
      c:\windows\system32\tapisrv.dll - Ok
      c:\windows\system32\tabsvc.dll - Ok
      c:\windows\system32\swprv.dll - Ok
      c:\windows\system32\drivers\storvsc.sys - Ok
      c:\windows\system32\storsvc.dll - Ok
      c:\windows\system32\drivers\stexstor.sys - Ok
      c:\windows\system32\sstpsvc.dll - Ok
      c:\windows\system32\sppuinotify.dll - Ok
      >c:\windows\system32\sppsvc.exe - packed by FLY-CODE
      c:\windows\system32\sppsvc.exe - Ok
      >c:\windows\system32\snmptrap.exe - packed by FLY-CODE
      c:\windows\system32\snmptrap.exe - Ok
      c:\windows\system32\drivers\smb.sys - Ok
      c:\windows\system32\drivers\sisraid4.sys - Ok
      c:\windows\system32\drivers\sisraid2.sys - Ok
      c:\windows\system32\drivers\sisagp.sys - Ok
      c:\windows\system32\ipnathlp.dll - Ok
      c:\windows\system32\drivers\sfloppy.sys - Ok
      c:\windows\system32\drivers\sffp_sd.sys - Ok
      c:\windows\system32\drivers\sffp_mmc.sys - Ok
      c:\windows\system32\drivers\sffdisk.sys - Ok
      c:\windows\system32\sessenv.dll - Ok
      c:\windows\system32\drivers\sermouse.sys - Ok
      c:\windows\system32\drivers\serial.sys - Ok
      c:\windows\system32\drivers\serenum.sys - Ok
      c:\windows\system32\sensrsvc.dll - Ok
      c:\windows\system32\seclogon.dll - Ok
      c:\windows\system32\sdrsvc.dll - Ok
      >c:\windows\system32\drivers\scfilter.sys - packed by FLY-CODE
      c:\windows\system32\drivers\scfilter.sys - Ok
      c:\windows\system32\scardsvr.dll - Ok
      c:\windows\system32\drivers\sbp2port.sys - Ok
      c:\windows\system32\drivers\vms3cap.sys - Ok
      c:\windows\system32\locator.exe - Ok
      c:\windows\system32\regsvc.dll - Ok
      c:\windows\system32\mprdim.dll - Ok
      c:\windows\system32\drivers\rdpwd.sys - Ok
      c:\windows\system32\drivers\rdpdr.sys - Ok
      c:\windows\system32\rdpdd.dll - Ok
      c:\windows\system32\rasmans.dll - Ok
      c:\windows\system32\rasauto.dll - Ok
      c:\windows\system32\drivers\rasacd.sys - Ok
      c:\windows\system32\drivers\qwavedrv.sys - Ok
      c:\windows\system32\qwave.dll - Ok
      c:\windows\system32\drivers\ql40xx.sys - Ok
      c:\windows\system32\drivers\ql2300.sys - Ok
      c:\windows\system32\drivers\processr.sys - Ok
      c:\windows\system32\pnrpauto.dll - Ok
      c:\windows\system32\pla.dll - Ok
      c:\windows\system32\perfproc.dll - Ok
      c:\windows\system32\perfos.dll - Ok
      c:\windows\system32\perfnet.dll - Ok
      c:\windows\system32\perfdisk.dll - Ok
      c:\windows\system32\peerdistsvc.dll - Ok
      c:\windows\system32\drivers\pcmcia.sys - Ok
      >c:\windows\system32\drivers\pciide.sys - packed by FLY-CODE
      c:\windows\system32\drivers\pciide.sys - Ok
      c:\windows\system32\drivers\parvdm.sys - Ok
      c:\windows\system32\drivers\parport.sys - Ok
      >c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe - packed by FLY-CODE
      c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe - Ok
      c:\program files\common files\microsoft shared\source engine\ose.exe - Ok
      c:\windows\system32\drivers\ohci1394.sys - Ok
      c:\windows\system32\drivers\nv_agp.sys - Ok
      c:\windows\system32\drivers\nvstor.sys - Ok
      c:\windows\system32\drivers\nvraid.sys - Ok
      c:\windows\system32\drivers\nfrd960.sys - Ok
      c:\windows\microsoft.net\framework\v3.0\windows communication foundation\smsvchost.exe - Ok
      c:\windows\system32\drivers\ndisuio.sys - Ok
      c:\windows\system32\drivers\ndiscap.sys - Ok
      c:\windows\system32\drivers\nwifi.sys - Ok
      c:\windows\system32\qagentrt.dll - Ok
      >c:\windows\system32\drivers\mtconfig.sys - packed by FLY-CODE
      >>c:\windows\system32\drivers\mtconfig.sys - packed by FLY-CODE
      c:\windows\system32\drivers\mtconfig.sys - Ok
      c:\windows\system32\drivers\mstee.sys - Ok
      c:\windows\system32\msscntrs.dll - Ok
      c:\windows\system32\drivers\mspqm.sys - Ok
      c:\windows\system32\drivers\mspclock.sys - Ok
      c:\windows\system32\drivers\mskssrv.sys - Ok
      c:\windows\system32\msiexec.exe - Ok
      c:\windows\system32\iscsiexe.dll - Ok
      c:\windows\system32\drivers\mshidkmdf.sys - Ok
      >c:\windows\system32\drivers\bridge.sys - packed by FLY-CODE
      c:\windows\system32\drivers\bridge.sys - Ok
      c:\windows\system32\msdtc.exe - Ok
      c:\windows\system32\drivers\msdsm.sys - Ok
      c:\windows\system32\drivers\msahci.sys - Ok
      c:\windows\system32\drivers\mpio.sys - Ok
      c:\program files\mozilla maintenance service\maintenanceservice.exe - Ok
      c:\windows\system32\drivers\mouhid.sys - Ok
      c:\program files\microsoft office\office14\groove.exe - Ok
      c:\windows\system32\drivers\megasr.sys - Ok
      c:\windows\system32\drivers\megasas.sys - Ok
      c:\windows\system32\mcx2svc.dll - Ok
      c:\windows\system32\drivers\lsi_scsi.sys - Ok
      c:\windows\system32\drivers\lsi_sas2.sys - Ok
      c:\windows\system32\drivers\lsi_sas.sys - Ok
      c:\windows\system32\drivers\lsi_fc.sys - Ok
      c:\windows\system32\lltdsvc.dll - Ok
      c:\windows\system32\msdtckrm.dll - Ok
      c:\windows\system32\drivers\kbdhid.sys - Ok
      c:\windows\system32\drivers\msiscsi.sys - Ok
      c:\windows\system32\drivers\isapnp.sys - Ok
      c:\windows\system32\drivers\irenum.sys - Ok
      c:\windows\system32\drivers\ipnat.sys - Ok
      c:\windows\system32\drivers\ipmidrv.sys - Ok
      c:\windows\system32\drivers\ipfltdrv.sys - Ok
      c:\windows\system32\ipbusenum.dll - Ok
      c:\windows\system32\ikeext.dll - Ok
      c:\windows\system32\drivers\iirsp.sys - Ok
      c:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe - Ok
      c:\windows\system32\drivers\iastorv.sys - Ok
      c:\windows\system32\drivers\hpsamd.sys - Ok
      c:\windows\system32\kmsvc.dll - Ok
      c:\windows\system32\drivers\hidusb.sys - Ok

    3. #23
      Colaborador Avatar de Mudo13
      Registrado
      abr 2012
      Ubicación
      Ceuta. España.
      Mensajes
      2.260

      Re: ¿Cómo desinstalar Delta Search, (navegador intruso)

      Buenas.

      wasamandrapa, me alegro que el pc esté mejor, de nada, aunque últimamente tengo poco tiempo, es un placer venir aquí y ayudar en la medida que pudo.

      La herramienta revo elimina todos los rastros pero si, es suficiente desinstalar SpyHunter con CCleaner.

      Si, muy buen "alumno" porque explica doto muy bien y trae los reportes, aunque creo que el de Dr.web no esta completo.

      Puede comentar/enumerar con detalles los problemas que quedan por resolver?

      El problema inicial, está solucionado, no? #1

      Saludos!
      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    4. #24
      Usuario Avatar de wasamandrapa
      Registrado
      ene 2010
      Ubicación
      Talca-Chile
      Mensajes
      112

      Re: ¿Cómo desinstalar Delta Search, (navegador intruso)

      Saludos efusivos Mudo13, Un abrazo a la distancia...........y los huerfanos de conocimiento en esta materia lo agradecemos, estamos en deuda, son un ejemplo de que un mundo mejor es pósible .
      - Ciertamente el reporte esta incompleto, me declaro inepto para enviarlo en partes..........he tratado, y seguire.
      Pero el escaner lo realice con exito y elimine una amenaza detectada.
      - Efetivamente el problema inicial y materia de este tema, esta resuelto.
      Quedaría pendiente eliminar los spywares que detectó Argente Utilities-(producto del Spy Hunter).Hoy lo pase por tercera vez, y volvio a señalarlos.
      Aún tengo problemas, cuando realizo algún cambio de ventana, o ingreso a una página nueva........Mozilla Firefox (no responde) , ocasionalmente aparecen ventanas señalando q´tal o cual plug-in esta ocupado, y opciones a elegir........
      Por supuesto, te agradecere me señales que eliminar y que continuar usando.me refiero a todo aquello que descargue.
      Si consideras que debo iniciar un nuevo tema (debido a que mi problema esta resuelto)por mi esta bien, y, por cierto muy agradecido .......bastante....Caso contrario estoy a tu disposición......
      Tu servidor............
      Un abrazo cordial.
      Última edición por wasamandrapa fecha: 27/05/13 a las 19:42:33 Razón: error de dedo

    5. #25
      Usuario Avatar de fc_cat
      Registrado
      abr 2008
      Ubicación
      España
      Mensajes
      47

      Re: ¿Cómo desinstalar Delta Search, (navegador intruso)

      Solo por curiosidad, a mi me paso lo mismo y mande un mail a los de delta y esta fue lo que me contestaron (lo solucione y quite todo lo de delta) la 1ª vez fallo, pero en su 2ª respuesta funciono:

      2013/5/2 Su buscador me aparece cada vez que abro una nueva pestañasin mi permiso, ¿como lo quito? y no esta como ventana de inicio

      Estimado usuario,
      Gracias por contactar con nosotros.

      Con el fin de eliminar el Delta Búsqueda Por favor, siga los siguientes pasos:

      1. Ir al menú Inicio> Panel de control Select> Desinstalar un programa.
      2. Búsqueda de Delta en la lista. Haga clic en Desinstalar en la parte superior de la ventana.
      Si ve también "gestor de navegador" o "Browser-protector" por favor desinstalarlo.

      Eliminar de:
      Google Chrome:

      1. Abre Google Chrome, haga clic en el icono de "llave" (podría ser un icono de 3 rayas) por el lado derecho de la barra de direcciones, haga clic en Configuración:
      2. En "El arranque", elija la opción "Abrir una página específica o un conjunto de páginas."
      3. Haga clic en "Ajustar páginas" y borrar la página de Delta de la lista haciendo clic en el pequeño icono "x" fuera de esta.

      Para cambiar el motor de búsqueda de Google Chrome:

      1. Abre Google Chrome, haga clic en el icono de "llave" por el lado derecho de la barra de direcciones;
      2. Haga clic en Configuración> En "Buscar", haga clic en "Gestionar los motores de búsqueda ...":
      Si ve Delta búsqueda como predeterminado, haga clic en una opción diferente (Google, Bing, etc), lo convierten en default
      3. Retire Delta haciendo clic en el pequeño 'x'

      También puedes ver si cualquier extensión Delta se instala en Google Chrome:
      1. Abre Google Chrome, haga clic en el icono de "llave" en la parte derecha de la barra de direcciones:
      2. Ir a Herramientas> Extensiones.
      3. Retire cualquier extensión Delta (Traductor, barra de herramientas) en la lista, haga clic en el pequeño icono de papelera que aparece al apuntar el cursor sobre él.

      Eliminar de:
      Internet Explorer:

      1. Abra Internet Explorer. Vaya a Herramientas >> Administrar complementos.
      2. Seleccione Barras de herramientas y extensiones. Desinstalar todo lo relacionado con Delta Ltd. de la lista: Delta barra de herramientas, barra de herramientas de ayuda Delta, Delta IE plugin, DeltaToolbar.com, etc
      3. Seleccionar proveedores de búsqueda. En primer lugar, elegir el motor de búsqueda Bing y hacer que su proveedor de búsquedas predeterminado (establecido por defecto). A continuación, seleccione Buscar en la web (Delta) y haga clic en el botón para desinstalarlo quitar (en la esquina inferior derecha de la ventana).
      4. Ir a las herramientas? Opciones de Internet. Seleccione la pestaña General y haga clic en el botón predeterminado uso o introduzca su propia página web, por ejemplo, gooog.com lugar de search.Delta.com. Haga clic en Aceptar para guardar los cambios.

      Eliminar de:
      Mozilla Firefox:

      1. Abra Mozilla Firefox. Vaya a Herramientas >> Add-ons.
      2. Seleccione Extensiones. Desinstalar la siguiente extensión: Delta 1.1.9 para quitar la barra de herramientas de Delta.
      3. Haga clic en el icono de la lupa pequeña en la esquina superior derecha. Selecciona Administrar motores de búsqueda de la lista.
      4. Seleccione Buscar en el web (Delta) y haga clic en el botón Quitar. Haga clic en Aceptar para guardar los cambios.
      5. Ir a Herramientas >> Opciones. En la ficha General restablecer la página de inicio.

      Si necesita más ayuda, no dude en ponerse en contacto con nosotros de nuevo, por favor.
      Saludos cordiales,
      Delta Search Departamento de Servicio



      2013/5/2

      Su buscador me aparece cada vez que abro una nueva pestañasin mi permiso, ¿como lo quito? y no esta como ventana de inicio

      2º mail:

      2013/5/27 He echo lo que me han dicho y siguo con problemas, cada vez que en el explorer le doy a nueva pestaña o nueva ventana me aparece su buscador, por mas que he mirado no encuentro nada instalado de delta, pero sigue apareciendome. Solo me pasa en el explorer, tengo de web de inicio google, según arranco el explorer sin problema, pero en el momento que le doy a nuevo pestaña o ventana vuelve la web de delta.

      Estimado Usuario:

      Gracias por contactar con nosotros.

      Estaremos encantados de ayudarle con cualquier problema técnico que pueda haber tenido, pero necesitaremos más detalles específicos.

      ¿Dónde es exactamente lo que tiene Delta Búsqueda?
      En el navegador (Explorer, Mozilla, Chrome)?
      Es como una página web, motor de búsqueda, una nueva pestaña o barra de herramientas?


      También puede intentar lo siguiente:
      Con el fin de eliminar el Delta búsqueda de:

      Chrome:
      En caso de haber seguido las instrucciones y al abrir una nueva pestaña, Delta búsqueda aparece todavía, por favor haga lo siguiente:
      1. Haga clic en Personalizar y controlar Google Chrome (icono de llave) y seleccione los ajustes.
      2. Haz clic en los motores de búsqueda Gestión ... botón.
      3. Seleccione Google de la lista y hacer que su motor de búsqueda predeterminado.
      4. Seleccione Buscar en la Web (Delta) de la lista eliminar haciendo clic en el signo "X".
      5. En el arranque> marca la opción "Abrir una página específica" o conjunto de páginas> haga clic páginas juego> pon tu página de inicio, si ves a Delta en la lista, haga clic en el signo "X".

      Con el fin de eliminar el Delta búsqueda de:

      Firefox:
      En caso de que se abre una nueva pestaña y Delta búsqueda sigue apareciendo, haga lo siguiente:
      1. Por favor, vaya al panel de control> Agregar o quitar programas> Si ve también "gestor de navegador" o "B-protector" favor desinstalarlo.
      2. Escribe en la barra de direcciones "about: config" y pulse "enter". Confirmar el mensaje. Busque "Delta". Haga clic en las entradas y haga clic en "Restaurar".

      Tenga en cuenta para restablecer sólo las entradas que contengan "browser.newtab" o
      "Browser.search"

      Con el fin de eliminar el Delta búsqueda de:

      Internet Explorer:
      En caso de que se abre una nueva pestaña y Delta búsqueda sigue apareciendo, haga lo siguiente:
      Abra su navegador de Internet Explorer, haga clic en "Herramientas", luego "Opciones de Internet" y en la sección "Tabs", haga clic en "Configuración". Se abrirá una nueva ventana, en la opción "Cuando se abre una nueva pestaña, abra" en el menú desplegable, elija por favor "Su primera página". A continuación, haga clic en Aceptar, en Aplicar y Aceptar.

      Si necesita más ayuda, no dude en ponerse en contacto con nosotros de nuevo, por favor.
      Saludos cordiales,
      Delta Search Departamento de Servicio

      Y aqui me funciono.

    6. #26
      Usuario Avatar de wasamandrapa
      Registrado
      ene 2010
      Ubicación
      Talca-Chile
      Mensajes
      112

      Re: ¿Cómo desinstalar Delta Search, (navegador intruso)

      Saludos fc_cat:Gracias por tu visita y participación, cierto es que nos vemos expuestos a....... casi que nos violen. y lo peor es que no sabemos ¿quién?...Este sistema de libre mercado da pie a que se cometan todo tipo de excesos en provecho de quienes tienen el poder del dinero, y, en detrimento de quienes los sustentamos........algo he leído sobre el hardware y sofware libre, sin ataduras y descontaminado de los que tienen el poder...(dinero).pero que son inescrupulosos...lo son............
      Agradecido por tu comentario, y me alegro que pudieses resolver tu problema....Delta Search.
      Adios.

    7. #27
      Colaborador Avatar de Mudo13
      Registrado
      abr 2012
      Ubicación
      Ceuta. España.
      Mensajes
      2.260

      Re: ¿Cómo desinstalar Delta Search, (navegador intruso)

      Buenas.

      Intente una vez mas copiar aunque sea el último trozo del reporte, una copia del reporte se guarda en %USERPROFILE%\Doctor Web (a los moderadores les gusta examinar los reportes).

      Los rastros de SpyHunter lo encuentra al pasar Argente Utilities, no? cuando acaba de analizar le da a "Eliminar spywares seleccionado"? Recuerde que los spywares tiene que estar seleccionados y después clic en "Eliminar Spyware seleccionados".

      Compruebe si tiene la última versión de Firefox, dentro del navegador presione la tecla alt / Ayuda / acerca de firefox / y se actualizará.

      vamos a intentar poner Firefox "como de fabrica" pero antes haga estos pasos,

      Revise las extensiones por si hay alguna sospechosa que se haya descargado sin su permiso.

      Para ver las extensiones en Firerox : alt / herramientas / Complementos / Extensiones /. Compruebe las extensiones.

      Actualice los plugins.

      Dentro de firefox presione la tecla alt / herramientas / complementos / plugins / clic donde pone "clic aquí para ver si sus plugins están actualizados" y siga los pasos que se indica. Le dejo este enlace para que sea mas fácil.

      Ahora si podemos intentar poner "de brabrica" Firefox:

      Con el navegador firefox cerrado. Es importante que estén cerrada todas las ventanas del navegador.


      - Haga clic en el menú Inicio y selecciona Ejecutar

      - Escriba el siguiente comando: firefox -safe-mode

      - En la ventana que se abre Clic en "Reiniciar Firefox" y a continuación clic en "Restablecer Firefox" espere a que el proceso termine y compruebe los resultados.

      Se conservarán los Marcadores/favoritos, pero haga una copia por si "las moscas".





      Puede desinstalar las herramientas, AT-Destroyer by @Infospyware, Malwarebytes' Anti-Malware, Rkill, ESET Online Scanner, Adwcleaner, Ccleaner, glary utilities, Argente Utilities, Argente - Registry Cleaner, defraggler, Malwarebytes Anti-Rootkit (Beta) y Dr.Web CureIt!

      Antes de desinstalar le comento que Ccleaner y Malwarebytes' Anti-Malware lo puede dejar instalado.

      Para desisntalar AT-Destroyer by @Infospyware y Adwcleaner es el mismo procedimiento Ejecute los programas y clic en "desinstalar".

      Para desinstalar Malwarebytes' Anti-Malware siga éste enlace y busque la herramienta de desinstalación.

      Rkill, Dr.Web CureIt y Malwarebytes Anti-Rootkit (Beta) no se instalan en el pc, elimínelos normalmente.

      Los que quedan por mencionar eliminelos desde el "panel de control".





      Seguiremos en este tema, porque los problemas de navegadores pueden ser causado por los adwares.

      Comente si todavía salen rastros de Spyhunter, como va Firefox y las dudas.

      PD/ gracias al compañero por el aporte.

      Saludos!
      Última edición por Mudo13 fecha: 28/05/13 a las 10:00:45
      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    8. #28
      Usuario Avatar de wasamandrapa
      Registrado
      ene 2010
      Ubicación
      Talca-Chile
      Mensajes
      112

      Re: ¿Cómo desinstalar Delta Search, (navegador intruso)

      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\6p75yh4d - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\6rup29pr - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\74sfott4 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\7bfnwtqw - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\7eoqgoo8 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\7l3yfyrh - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\7qunskty - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\7rx7ag1k - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\8ejcd59y - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\8fc7o9ph - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\9109md3w - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\9by9rrm2 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\9cmk3q4f - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\9kqrh9r8 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\9qggnv2w - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\a6xev3ds - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\anecg52z - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\b28v5kvt - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\b8ukk5w9 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\baaggis1 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\bk2po1gu - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\c0ao11ij - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\c1x36p5l - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\de7zi59j - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\djvmr3ar - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\dlxi4s15 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\dmhowgqq - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\e9kj23qp - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\em6fnyzo - Ok
      >C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm is CHM container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\cureit70_en_popup_text.js is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_additionaloptions.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_cli_parameters.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_cli_switches.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_customscan.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_detectionmethods.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_enfmode.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_intro.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_legal.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_quarantine.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_quickscan.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_quickstart.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_scan_set_1.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_scan_set_2.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_scan_set_3.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_scan_set_4.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_scan_settings.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_setneutrules.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_snip_scan_1.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_statistics.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_sysreq.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_techsupport.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_testing.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\dw_update.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm\helpman_topicinit.js is JS-HTML container
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\en.chm - container
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\eo4klb12 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\esw8dvu3 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\f5ow833m - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\fc4sw74b - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\feo4lscy - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\fqk26iqg - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\g0121ot0 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\g3t1mm5h - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\h2v03oo7 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\hkioy8ry - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\hmzi87im - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\hp1nvn6t - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\hstukj21 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\irozcznv - Ok
      >C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm is CHM container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\cureit70_ja_popup_html.js is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_additionaloptions.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_cli_parameters.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_cli_switches.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_customscan.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_detectionmethods.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_enfmode.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_intro.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_legal.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_quarantine.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_quickscan.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_quickstart.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_scan_set_1.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_scan_set_2.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_scan_set_3.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_scan_set_4.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_scan_settings.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_setneutrules.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_snip_scan_1.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_statistics.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_sysreq.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_techsupport.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_testing.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\dw_update.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm\helpman_topicinit.js is JS-HTML container
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ja.chm - container
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\jt22o7k6 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\jwygdoyg - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\k3eoszuq.key - Ok
      >C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\kgncpxdj.dll is BINARYRES container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\kgncpxdj.dll\data003 - packed by BINARYRES
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\kgncpxdj.dll\data004 - packed by BINARYRES
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\kgncpxdj.dll - container
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\km7f1vfq - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\kqikgkir - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\l5af8za3 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\l8o32scg - Ok
      >C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\lc908y97.exe is BINARYRES container
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\lc908y97.exe - container
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\lf2t226v - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\lm42kjgt.dll - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\m2amr9q3 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\m2k7r173 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\m5q9691d - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\mdvvx34h - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\mwpxlmxz - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\n8eo5xmz - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ngguiubc - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\nuh694t4 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ow8s3j2o - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\pbvrbf6t - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\pecz1mkz - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\pei7rfd6 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\pnzj4c8c - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\psto3cgf - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\qfpjrbni - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\qpc9p4yh - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\qqv07z3d - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\r707azzt - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\r9t4ylfz - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\rb1rhw58 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\rdupqm2p - Ok
      >C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ru.chm is CHM container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ru.chm\cureit70_popup_text.js is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ru.chm\dw_cli_switches.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ru.chm\dw_quickstart.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ru.chm\dw_scan_set_2.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ru.chm\dw_scan_set_3.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ru.chm\dw_testing.htm is JS-HTML container
      >>C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ru.chm\helpman_topicinit.js is JS-HTML container
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\ru.chm - container
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\rvalqzak - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\s4amdyz2 - Ok
      >>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream000 is CAB archive
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream000 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\sfp6jo3m.exe - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\si4h3atn - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream001 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\svt3werg - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream002 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream003 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream004 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\tkmmrj2n.exe - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream005 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream006 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\tm3pfh2n - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\u6wgfwzu - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\v2cmf7qz - Ok
      >>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream007 - packed by BINARYRES
      >>>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream007 is WISE container
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\vdzss8c4 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\vhivjf8d - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\wl5xh8rf - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\xlhwqwy1 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\xnxsga4t - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream007\data001 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream007\data002 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\y4l7l69l - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream007\data003 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream007\data004 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream007\data005 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream007 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\y9usy8ct - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream008 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\yevxl1qu - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\yq5ygl1v - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\z3qecv3r - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\z4m6l1hq - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream009 - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\License.rtf - Ok
      >>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream010 - packed by BINARYRES
      >>>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream010 is WISE container
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream010\data001 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream010\data002 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream010\data003 - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\mbam.dll - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream010\data004 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream010\data005 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream010 - Ok
      >>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream011 - packed by BINARYRES
      >>>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream011 is WISE container
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream011\data001 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream011\data002 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream011\data003 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream011\data004 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream011\data005 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream011 - Ok
      >>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream012 - packed by BINARYRES
      >>>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream012 is WISE container
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream012\data001 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream012\data002 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream012\data003 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream012\data004 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream012\data005 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream012 - Ok
      >C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\mbamcore.dll is BINARYRES container
      >>C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\mbamcore.dll\data002 - packed by BINARYRES
      >>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream013 - packed by BINARYRES
      >>C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\mbamcore.dll\data003 - packed by BINARYRES
      >>>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream013 is WISE container
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream013\data001 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream013\data002 - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\mbamcore.dll - container
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream013\data003 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream013\data004 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream013\data005 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream013 - Ok
      >>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream014 - packed by BINARYRES
      >>>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream014 is WISE container
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream014\data001 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream014\data002 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream014\data003 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream014\data004 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream014\data005 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream014 - Ok
      >>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream015 - packed by BINARYRES
      >>>>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream015 is WISE container
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream015\data001 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream015\data002 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream015\data003 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream015\data004 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream015\data005 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001\stream015 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001 - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe - Ok
      C:\Users\Casa\AppData\Local\Temp\SHSetup.exe - container
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\mbar-log-2013-05-26 (20-15-03).txt - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\mbamnet.dll - Ok
      >C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\mbar.exe is BINARYRES container
      >>C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\mbar.exe\data004 is ZLIB container
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\mbar.exe - container
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\msvcp100.dll - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\msvcr100.dll - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\QtCore4.dll - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\ReadMe.rtf - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\system-log.txt - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\Data\actions.ref - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\Data\rules.ref - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\Data\swissarmy.ref - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\Data\Configuration\build.conf - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\Data\Configuration\config.conf - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\Data\Configuration\database.conf - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\Data\Configuration\local.conf - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\Data\Configuration\manifest.conf - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\Languages\English.lng - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\Plugins\fixdamage.exe - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\imageformats\qico4.dll - Ok
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\imageformats\qicod4.dll - Ok
      C:\Users\Casa\AppData\Local\Temp\_ir_tmpfnt_1\Arial_1.TFT - Ok
      C:\Users\Casa\AppData\Local\Temp\_ir_tmpfnt_2\Arial_1.TFT - Ok
      C:\Users\Casa\AppData\Local\Temp\acro_rd_dir\fla152F.tmp - read error
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\License.rtf - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\mbam.dll - Ok
      >C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\QtGui4.dll is ZLIB container
      C:\Users\Casa\AppData\Local\Temp\Rar$EX51.045\mbar\QtGui4.dll - container
      >C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\mbamcore.dll is BINARYRES container
      >>C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\mbamcore.dll\data002 - packed by BINARYRES
      >>C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\mbamcore.dll\data003 - packed by BINARYRES
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\mbamcore.dll - container
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\mbamnet.dll - Ok
      >C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\mbar.exe is BINARYRES container
      >>C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\mbar.exe\data004 is ZLIB container
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\mbar.exe - container
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\msvcp100.dll - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\msvcr100.dll - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\QtCore4.dll - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\ReadMe.rtf - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\Data\actions.ref - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\Data\rules.ref - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\Data\swissarmy.ref - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\Data\Configuration\build.conf - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\Data\Configuration\config.conf - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\Data\Configuration\database.conf - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\Data\Configuration\local.conf - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\Data\Configuration\manifest.conf - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\Languages\English.lng - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\Plugins\fixdamage.exe - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\imageformats\qico4.dll - Ok
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\imageformats\qicod4.dll - Ok
      >C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\QtGui4.dll is ZLIB container
      C:\Users\Casa\AppData\Local\Temp\mbar-1.06.0.1003\mbar\QtGui4.dll - container

      Total 3582353874 bytes in 16736 files scanned (18005 objects)
      Total 16699 files (17965 objects) are clean
      Total 1 file are suspicious
      Total 35 files are raised error condition
      Scan time is 01:47:04.015

      -----------------------------------------------------------------------------
      Start curing
      -----------------------------------------------------------------------------
      C:\Windows\system32\drivers\etc\hosts - cured, reboot required

      Total 3582353874 bytes in 16736 files scanned (18005 objects)
      Total 16699 files (17965 objects) are clean
      Total 1 file are suspicious
      Total 1 file are neutralized
      Total 35 files are raised error condition
      Scan time is 01:47:04.015

      Mis excusas por aprovechar la opción, ésta es la última parte...........te envio la penultima a continuación...
      Saludos.

    9. #29
      Usuario Avatar de wasamandrapa
      Registrado
      ene 2010
      Ubicación
      Talca-Chile
      Mensajes
      112

      Re: ¿Cómo desinstalar Delta Search, (navegador intruso)

      C:\Windows\system32\wbem\AutoRecover\1D17F2812D61D6A27510A5356CBCB2C6.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\14C5A2A3C41254184B007011E5565E5B.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\1FD16EA55AB471DAD65A8AE31A92BFE1.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\2B8B1A8B0ACD3EE28B421D3918DC1F29.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\33A13765948753719F44CA6F7E586909.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\5774C77265BE4C55B5C6C9718979E015.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\5AE917280E947651A324A3BB4D162227.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\6F8564A71977AE6B940705DCC4847A8D.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\844A429FB6680A32838047A6271F8CD9.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\93BE9B2D6163316A39F5D9F7DCF57A26.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\75054C3771DF289038069A9BB1C1FB6E.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\BA42233C2B9592211C49858860047F3F.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\97823DC673AD0F92AB9B83F4C177678B.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\BBF206490BAA431B592F9A13534F43F6.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\BF7B61BA8D8284B7D0DA637AB41F6C96.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\D04911ACFCA47446EFCB01393D3C3F8B.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\D361F8B496FD6DAF7BEEF497E09C0DC1.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\DFB9AD54AC2D3B8122567AAD3BF3EB7F.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\E9D8A460B2C986DD5FF19F299F4A27EC.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\F1326650D965B0087F10C6AA6C049D46.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\EDB534A0AD75CF6CD3441C25046B8E9A.mof - Ok
      C:\Windows\system32\wbem\AutoRecover\F5E2A66F8CD81F282CEFFB9E8125CC6F.mof - Ok
      C:\Windows\system32\wbem\Performance\WmiApRpl.h - Ok
      C:\Windows\system32\wbem\en-US\msfeeds.mfl - Ok
      C:\Windows\system32\wbem\Performance\WmiApRpl.ini - Ok
      C:\Windows\system32\wbem\en-US\msfeedsbs.mfl - Ok
      C:\Windows\system32\wbem\es-ES\aaclient.mfl - Ok
      C:\Windows\system32\wbem\es-ES\auxiliarydisplaycpl.mfl - Ok
      C:\Windows\system32\wbem\es-ES\cimwin32.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\cimdmtf.mfl - Ok
      C:\Windows\system32\wbem\es-ES\cli.mfl - Ok
      C:\Windows\system32\wbem\es-ES\cimwin32.mfl - Ok
      C:\Windows\system32\wbem\es-ES\cliegaliases.mfl - Ok
      C:\Windows\system32\wbem\es-ES\csv.xsl - Ok
      C:\Windows\system32\wbem\es-ES\dsprov.mfl - Ok
      C:\Windows\system32\wbem\es-ES\filetrace.mfl - Ok
      C:\Windows\system32\wbem\es-ES\hform.xsl - Ok
      C:\Windows\system32\wbem\es-ES\htable.xsl - Ok
      C:\Windows\system32\wbem\es-ES\interop.mfl - Ok
      C:\Windows\system32\wbem\es-ES\irmon.mfl - Ok
      C:\Windows\system32\wbem\es-ES\hbaapi.mfl - Ok
      C:\Windows\system32\wbem\es-ES\iscsidsc.mfl - Ok
      C:\Windows\system32\wbem\es-ES\KrnlProv.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\iscsiprf.mfl - Ok
      C:\Windows\system32\wbem\es-ES\krnlprov.mfl - Ok
      C:\Windows\system32\wbem\es-ES\l2gpstore.mfl - Ok
      C:\Windows\system32\wbem\es-ES\Microsoft-Windows-OfflineFiles.mfl - Ok
      C:\Windows\system32\wbem\es-ES\MMFUtil.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\mof.xsl - Ok
      C:\Windows\system32\wbem\es-ES\mofcomp.exe.mui - Ok
      C:\Windows\system32\wbem\es-ES\msfeeds.mfl - Ok
      C:\Windows\system32\wbem\es-ES\mofd.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\msfeedsbs.mfl - Ok
      C:\Windows\system32\wbem\es-ES\mstsc.mfl - Ok
      C:\Windows\system32\wbem\es-ES\mstscax.mfl - Ok
      C:\Windows\system32\wbem\es-ES\NCProv.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\msi.mfl - Ok
      C:\Windows\system32\wbem\es-ES\ncprov.mfl - Ok
      C:\Windows\system32\wbem\es-ES\ntevt.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\ntevt.mfl - Ok
      C:\Windows\system32\wbem\es-ES\OfflineFilesWmiProvider_Uninstall.mfl - Ok
      C:\Windows\system32\wbem\es-ES\p2p-collab.mfl - Ok
      C:\Windows\system32\wbem\es-ES\p2p-mesh.mfl - Ok
      C:\Windows\system32\wbem\es-ES\p2p-pnrp.mfl - Ok
      C:\Windows\system32\wbem\es-ES\OfflineFilesWmiProvider.mfl - Ok
      C:\Windows\system32\wbem\es-ES\PolicMan.mfl - Ok
      C:\Windows\system32\wbem\es-ES\polproc.mfl - Ok
      C:\Windows\system32\wbem\es-ES\polprou.mfl - Ok
      C:\Windows\system32\wbem\es-ES\powermeterprovider.mfl - Ok
      C:\Windows\system32\wbem\es-ES\polprocl.mfl - Ok
      C:\Windows\system32\wbem\es-ES\powerpolicyprovider.mfl - Ok
      C:\Windows\system32\wbem\es-ES\profileassociationprovider.mfl - Ok
      C:\Windows\system32\wbem\es-ES\RacWmiProv.mfl - Ok
      C:\Windows\system32\wbem\es-ES\rdpcore.mfl - Ok
      C:\Windows\system32\wbem\es-ES\rdpencom.mfl - Ok
      C:\Windows\system32\wbem\es-ES\regevent.mfl - Ok
      C:\Windows\system32\wbem\es-ES\scrcons.exe.mui - Ok
      C:\Windows\system32\wbem\es-ES\rsop.mfl - Ok
      C:\Windows\system32\wbem\es-ES\ScrCons.mfl - Ok
      C:\Windows\system32\wbem\es-ES\sensorscpl.mfl - Ok
      C:\Windows\system32\wbem\es-ES\secrcw32.mfl - Ok
      C:\Windows\system32\wbem\es-ES\ServDeps.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\ServiceModel35.mfl - Ok
      C:\Windows\system32\wbem\es-ES\smtpcons.mfl - Ok
      C:\Windows\system32\wbem\es-ES\ServiceModel.mfl - Ok
      C:\Windows\system32\wbem\es-ES\sppwmi.mfl - Ok
      C:\Windows\system32\wbem\es-ES\subscrpt.mfl - Ok
      C:\Windows\system32\wbem\es-ES\sr.mfl - Ok
      C:\Windows\system32\wbem\es-ES\system.mfl - Ok
      C:\Windows\system32\wbem\es-ES\tscfgwmi.mfl - Ok
      C:\Windows\system32\wbem\es-ES\UserProfileWmiProvider.mfl - Ok
      C:\Windows\system32\wbem\es-ES\vdswmi.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\vds.mfl - Ok
      C:\Windows\system32\wbem\es-ES\vsswmi.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\vss.mfl - Ok
      C:\Windows\system32\wbem\es-ES\WbemCons.mfl - Ok
      C:\Windows\system32\wbem\es-ES\wbemcntl.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\wbemcore.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\wcncsvc.mfl - Ok
      C:\Windows\system32\wbem\es-ES\wbemtest.exe.mui - Ok
      C:\Windows\system32\wbem\es-ES\wfs.mfl - Ok
      C:\Windows\system32\wbem\es-ES\WgxInstalledGame.mfl - Ok
      C:\Windows\system32\wbem\es-ES\whqlprov.mfl - Ok
      C:\Windows\system32\wbem\es-ES\win32_printer.mfl - Ok
      C:\Windows\system32\wbem\es-ES\win32_tpm.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\wininit.mfl - Ok
      C:\Windows\system32\wbem\es-ES\winlogon.mfl - Ok
      C:\Windows\system32\wbem\es-ES\WinMgmt.exe.mui - Ok
      C:\Windows\system32\wbem\es-ES\WinMgmtR.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\wmi.mfl - Ok
      C:\Windows\system32\wbem\es-ES\WmiApRes.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\WmiApRpl.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\WmiApSrv.exe.mui - Ok
      C:\Windows\system32\wbem\es-ES\wmipcima.mfl - Ok
      C:\Windows\system32\wbem\es-ES\wmipdfs.mfl - Ok
      C:\Windows\system32\wbem\es-ES\wmipdskq.mfl - Ok
      C:\Windows\system32\wbem\es-ES\WMIC.exe.mui - Ok
      C:\Windows\system32\wbem\es-ES\WmiPerfClass.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\WmiPerfInst.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\WMIPICMP.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\wmipicmp.mfl - Ok
      C:\Windows\system32\wbem\es-ES\wmipiprt.mfl - Ok
      C:\Windows\system32\wbem\es-ES\wmipsess.mfl - Ok
      C:\Windows\system32\wbem\es-ES\wmipjobj.mfl - Ok
      C:\Windows\system32\wbem\es-ES\WMIsvc.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\wmitimep.mfl - Ok
      C:\Windows\system32\wbem\es-ES\wmpnetwk.mfl - Ok
      C:\Windows\system32\wbem\es-ES\wscenter.mfl - Ok
      C:\Windows\system32\wbem\es-ES\wmiutils.dll.mui - Ok
      C:\Windows\system32\wbem\es-ES\xml.xsl - Ok
      C:\Windows\system32\wbem\es-ES\WUDFx.mfl - Ok
      C:\Windows\system32\wbem\es-ES\xwizards.mfl - Ok
      C:\Windows\system32\wbem\repository\MAPPING1.MAP - Ok
      C:\Windows\system32\wbem\repository\INDEX.BTR - Ok
      C:\Windows\system32\wbem\repository\MAPPING2.MAP - Ok
      C:\Windows\system32\wbem\repository\MAPPING3.MAP - Ok
      C:\Windows\system32\wbem\xml\cim20.dtd - Ok
      C:\Windows\system32\wbem\xml\wmi20.dtd - Ok
      C:\Windows\system32\wbem\repository\OBJECTS.DATA - Ok
      C:\Windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin - Ok
      C:\Windows\system32\wbem\xml\wmi2xml.dll - Ok
      C:\Windows\system32\wdi\ERCQueuedResolutions.dat - Ok
      C:\Windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin - Ok
      C:\Windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin - Ok
      C:\Windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin - Ok
      C:\Windows\system32\wdi\{95c162b7-5b71-44f8-82e4-abfd3108f40f}.bin - Ok
      C:\Windows\system32\wdi\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}.bin - Ok
      C:\Windows\system32\wdi\{88d4896f-f553-446a-9c75-9dec124ff8b7}.bin - Ok
      C:\Windows\system32\wdi\{b171ab1c-60e9-4301-a338-beab1c70b3e9}.bin - Ok
      C:\Windows\system32\wdi\LogFiles\BootCKCL.etl - Ok
      C:\Windows\system32\wdi\LogFiles\ShutdownCKCL.etl - Ok
      C:\Windows\system32\wdi\LogFiles\WdiContextLog.etl.001 - Ok
      C:\Windows\system32\wdi\LogFiles\WdiContextLog.etl.002 - Ok
      C:\Windows\system32\wdi\perftrack\AltTab.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\AppInfoEvents.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\authui.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\comdlg32.ptxml - Ok
      C:\Windows\system32\wdi\LogFiles\WdiContextLog.etl.003 - Ok
      C:\Windows\system32\wdi\perftrack\Core-Fundamentals-ClientPerformance-Perftrack.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\DeviceUx.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\DiagCpl.Events.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\DhcpClientDll.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\Display.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\DisplaySwitch.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\DriverFrameworks-UserMode.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\DXP-DeviceExperience.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\ErrorReportingConsole.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\ETWInstrumentation.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\HealthCenterCPLInstrumentation.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\HealthCenterInstrumentation.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\Help-DataLayer.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\LDDMCore.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\Microsoft-Windows-Documents-Events.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\Microsoft-Windows-IE-HTMLRendering.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\Microsoft-Windows-NCSI.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\Microsoft-Windows-TabletPC-InputPanel-Events.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\ieframe.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\Microsoft-Windows-VAN.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\Microsoft-Windows-WLANConnectionFlow.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\msdt.events.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\NetworkConnectionsFolder.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\NetworkDiagnosticsFramework.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\NetworkProfile.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\NlaSvc.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\powercpl.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\prod_Audio-AudioCore.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\prod_WMPPlayer.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\profsvc.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\provsvc.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\Services.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\Sidebar.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\Spux.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\StobjectInstrumentation.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\taskmgr.events.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\themecpl.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\timedate.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\UIAutomationCore.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\userplugplayetw.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\ShellCoreInstrumentation.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\wdc.events.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\VolumeControl.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\WinINet.ETW.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\WinlogonEvents.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\WpdCoreInstrumentation.ptxml - Ok
      C:\Windows\system32\wdi\perftrack\Wlansvc.ptxml - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{13da2f02-9ef9-4e61-955f-b23be7413f25}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{1af64d63-13e1-4cc9-8df1-ace7cf0d4e94}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{27ad9784-f762-4cac-957a-1b6e69053062}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{2df9a583-3545-4a61-bb56-3d4529dc870b}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{2f02db6c-61c1-4219-886a-9798c525c1b6}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{2fae5cb2-485f-40f3-82b2-9f700a82f93a}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{328281de-b314-41eb-988f-0d4a0c7d340a}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{414c7eb5-14c2-4f1f-bce1-89ba4852c70e}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{5771e3eb-7de0-4289-b7a1-0953acfbe1e6}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{674e6d12-3c2b-415b-abc8-ea2bef917850}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{7247a5d5-5fa3-46a0-b784-856ac27b8793}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{76650c9b-6bb2-4516-8cda-b6f7004ca840}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{7acd1e34-75b9-49ee-a19c-880531bd66ed}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{8981aeae-0283-40ee-a8b8-2b1df3fc69a5}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{89f5c4bc-fdf3-4e14-b410-2737ab2c58f8}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{8ab1dd96-e82a-4519-8099-e2b781a2664d}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{a75ece80-3e2c-4bba-a012-5e3fbca99b8c}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{a85be0d7-9471-4877-bf21-407ec778a905}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{aad511ed-5c06-411a-a547-e19bd5f660bf}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{ab63e365-533b-425c-adbb-a3da08a78266}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{acf470b9-47bf-4ba3-bffe-afa0eef1f53a}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{ad7455ec-dd28-4f20-ab19-f974388a155f}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{cbe6faa3-0035-4bbb-8f12-06a01a44eb26}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{cfc59028-aeaf-4f28-8931-d96f253b4cfa}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{f5394e89-7e13-420d-9206-4497f1c366d8}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{f7cdcb22-c583-42fc-b2ed-0b51ed37dbe5}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3779655943-3478750023-229337645-1000_UserData.bin - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3779655943-3478750023-229337645-1005_UserData.bin - Ok
      C:\Windows\system32\wdi\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{fda859e5-d58a-4aea-a353-7047c82de7c3}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{02860ce2-24f1-4148-8563-b7347f36bf25}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{0723fba4-690b-4ebb-9f90-aa6223ec1a26}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{08ed985e-47e7-436f-b73e-b983cca0275a}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{0b263c5e-1781-4942-9738-28cc6704017b}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{0bee00d2-4d99-4b86-8502-32236f68a282}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{0fb8c0c5-19d4-446e-9335-b0bf475dc604}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{1112dee5-590f-43e5-84ad-436f10eeba6f}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{1ab68412-b228-47e5-90fe-4c914e6c214c}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{1e479a4b-e85f-4c2c-8ae3-4ef9fc0999e5}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{1ee402a2-0e69-44dc-8c66-98e1c3dd50ce}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{21b9072b-1667-48fc-90fb-4c25f306aa54}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{237e7f6a-f8ed-4875-aa55-c254430acf47}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{2492f3ea-f310-4282-9589-9d99ce0b20aa}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{28c2dd2e-8ad8-48ff-8cd5-a7ce9795f8f2}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{2aa12705-b4c0-452a-9ced-22d4a4d9ed95}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{2bf3b612-e3b3-40db-a629-f5e7cb305c51}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{3542a6b0-9c44-48f6-9765-d34567fff6a5}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{35bf888a-a7f2-4ae5-b57c-30a4f4bb9794}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{3ad0e3b6-3b57-471c-99c3-af36c9f88b84}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{3d1e8e2f-421f-49a0-8d28-85f2130bb2c0}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{3e9c10d9-033f-4710-bf7b-287cd2e8c492}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{3f9588c9-632d-4e1e-8d02-fa3d24d13c16}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{40326038-2c84-426d-94fb-203b484e2fe8}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{42f184db-c74e-4811-a09b-d51f9a96b4b3}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{47f1a086-2c4d-411f-99b1-ea1e1685d108}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{50d1ceb2-35b4-4ad9-80e6-214dd4222780}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{527f0703-0714-47bb-87a7-46011499dcc8}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{5284a36a-dd04-44cf-ba8a-8dd4d383d8be}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{532a0bda-d386-492a-a724-a36fb3e230ea}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{5341a8f7-cd83-4b3a-99d3-d78cff0540d5}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{53e60adc-552f-4ae7-bc51-b3c59c9a2b3d}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{57e8e688-aab5-43f9-80e6-8a9403a57408}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{5e774d9d-e667-4368-a92a-db93768249e1}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{5f81c0dc-1c26-4268-a5d5-b071ad16165a}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{60356eae-a47e-4ff1-b375-c06539b07353}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{647444f8-b14c-4eee-85d4-f29ca8e6f130}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{64ae09e0-5c07-4d87-9384-4556e5e2593f}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{67690c11-6754-45d6-a571-4905880c5645}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{68693e59-ac55-4aff-9021-99929fc1795c}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{697bf952-cdb1-4b9c-bbb6-7b1bfaafebf9}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{69a11080-0978-41b2-bd81-86f3f2aca5bf}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{69e313e1-b942-4190-a366-c130abb0f1f1}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{712b524e-afd1-40db-80be-3c33c402f62c}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{7344a894-f52c-4e81-be01-4b779a64728c}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{79ff2958-1143-4e76-82dd-9ee328308c5b}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{7c0b12c5-4661-4f9c-9445-62095529c5c6}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{7c2b145d-12e3-4657-a43f-ca576e22a462}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{83ac9368-5269-4417-9a9b-76635364564c}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{883b34a7-0a85-4ad1-9747-acc364c52807}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{88a0ca51-aa9e-4367-ba1e-a742e24cca2e}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{8d8aac1d-95de-4387-bcb2-2477e71b08db}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{8f7ab2f8-bdcd-4d01-8139-9e12c9e68e03}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{9fb20bc3-224a-426f-b309-19028d61ebfb}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{a5dde066-8f77-405d-bf28-2505bd93f356}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{a6f20456-ed64-4b5c-883a-0906c16aa422}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{a7225c88-09e4-425a-b01f-b581ba2fc8ac}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{aace93e2-45c9-48f4-a28d-960eb0eebc78}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{abb2cb24-eff2-4d3f-a67a-0bc909311e9a}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{ad95086f-648e-4776-a73b-cda9c2bf2381}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{b20444cb-45f4-4a61-bf5b-15034744dda8}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{b2999134-5934-4035-ba4f-2ad92486c0e9}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{b3f5a81e-5c7c-4706-8da4-5f62cf9565b3}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{b52655e7-e73d-4046-afca-83f8c19105e6}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{b58deff5-568a-45a0-b4ba-155d144a3f73}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{b8c17f75-a75e-4cb7-b2a7-ef46be461efc}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{b8eabd44-6b62-48dd-a6e6-f82f09b6f956}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{bbc9119d-c303-4783-809a-b61f85ad9e6a}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{c2225f62-0a96-4b9d-84b5-d2e3c50f20bc}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{c934367f-aa8b-4367-923a-9d59fadd12db}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{c97eb52b-dfdf-4afa-bc5d-fcc1fffa38e5}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{cc353966-71b4-4b20-9103-b7f3b70dd971}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{d26ae214-5946-40ed-99b5-54d93b3b113b}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{d4979aca-91d4-4298-8947-ced4ced8525b}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{d7c51a5c-4108-4a4d-8596-3eb1a2c5e2c1}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{dca103e3-5d2e-4bb3-aeda-e50a628d4da7}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{dda57531-6142-4122-9d14-d4ed3ab2ee40}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{df34d58d-196e-4f2e-ba6e-8e7fee595ef9}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{e034909e-faf8-4959-bffd-ef95e80d91b0}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{e0a8c363-589f-4c45-aac6-e1d199649b4d}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{e4546e27-b997-4475-83fd-d39e82593772}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{e7bd57cc-f523-4d3f-ba48-a424de94e69d}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{e8a63a50-0997-4a11-8489-226a53f9d961}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{e8e19365-ce84-4968-be26-6dac7ae2f41e}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{eadf2634-add4-4e88-adbc-6ef7ec663c46}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{ec31b19c-966a-4e53-99fb-95ff43f1cddc}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{eeb8c79c-e2da-4099-abce-63bbfd81f6a3}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{ef5c6c78-20d3-4a14-805c-027933ba1156}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{f17ce835-de3b-4b3b-8185-e3d353414263}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{f7e6569f-6c32-41c3-afb8-2461ee76ec26}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{f854ca7a-d40e-4a8a-9e3f-d148103cd194}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{f8d88290-e26f-4ca0-8c9d-2d22e7bf3263}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{fa865825-bc94-4f03-9849-100f7c0475df}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{fb18ae56-4e92-4db0-ae48-90eca7c33bd5}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{fc5ac986-6876-47d7-b3a8-49c28fc8956c}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{fe315bce-5444-4a24-a848-f137f0d5abd2}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{12e4b156-acd7-48aa-8164-db3a3d0260f6}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{13aceb35-9266-4977-8b4b-7b81bfa98956}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{2654c79f-badc-4094-b73a-24def931ff79}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{266b11a3-7947-44ef-b78f-4cf1bc89ddf9}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{2a3689ea-ea05-4ed5-9e18-7040d1ea88e7}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{2e81d4d3-4278-4408-bb2a-10592e342868}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{39eca051-c35b-41f8-a3c4-ff4ded3a8320}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{3beb2097-e409-46f0-b78e-3165f27dbee0}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{42303835-cbc7-4d9c-8aa2-71ce9a804356}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{43788fa0-3916-4ed9-bbcd-4dd313b3a158}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{49298729-6c87-47cd-b0ac-ba06cf8c084f}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{4e62f6fe-d34e-4620-ab1a-7104e37fe568}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{50d5e818-0d23-4e64-a292-3e0e4d981e47}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{521fa183-8439-49e5-ab89-a6377291e6c7}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{6ace6118-6132-4a9d-8fdd-e95e21aa35aa}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{6fe1ec6c-8ae8-482d-8bed-540a545213c8}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{7139a726-d347-49cb-9475-04505907ce28}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{78168fea-dc42-4683-b7a1-2d2b626e2726}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{89a240ea-0cf3-4fe7-96da-83fda7d1f68d}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{9b4463d1-5045-48c2-ac91-4e7c0ae1b540}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{a8c964aa-470c-43a4-b113-e06ffc1e0515}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{abd80b6b-7d7d-4e38-b08e-3c91a80ae954}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{adfec3e7-4150-45e5-94b9-ba5ffb962bd0}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{beebada9-c923-45a5-9408-2cf108fa4427}\snapshot.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{d2453ffd-f611-4748-b583-651a34d689d7}\snapshot.etl - Ok
      C:\Windows\system32\wfp\wfpdiag.etl - Ok
      C:\Windows\system32\wdi\{ffc42108-4920-4acf-a4fc-8abdcc68ada4}\{dc1054de-0987-4d0c-ba0d-0fb24490fd90}\snapshot.etl - Ok
      C:\Windows\system32\winevt\Logs\Doctor Web.evtx - Ok
      C:\Windows\system32\winevt\Logs\Application.evtx - Ok
      C:\Windows\system32\winevt\Logs\HardwareEvents.evtx - Ok
      C:\Windows\system32\winevt\Logs\Internet Explorer.evtx - Ok
      C:\Windows\system32\winevt\Logs\Key Management Service.evtx - Ok
      C:\Windows\system32\winevt\Logs\Media Center.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Application-Experience%4Problem-Steps-Recorder.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Troubleshooter.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Inventory.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Audio%4CaptureMonitor.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Telemetry.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Audio%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Backup.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-BranchCacheSMB%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-DateTimeControlPanel%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Diagnosis-Scripted%4Admin.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Diagnosis-Scheduled%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Diagnosis-Scripted%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Fault-Tolerant-Heap%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Help%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-HomeGroup Provider Service%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Known Folders API Service.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-MUI%4Admin.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-NCSI%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4WHC.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-NetworkLocationWizard%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-NlaSvc%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-ParentalControls%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-OfflineFiles%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-PrintService%4Admin.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Recovery%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\microsoft-windows-RemoteDesktopServices-RemoteDesktopSessionManager%4Admin.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-TerminalServices-ClientUSBDevices%4Admin.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-TerminalServices-ClientUSBDevices%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-TerminalServices-RDPClient%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-UAC%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-WER-Diag%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-WindowsBackup%4ActionCenter.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-WindowsSystemAssessmentTool%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-Winlogon%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-WPD-ClassInstaller%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\Microsoft-Windows-WPD-MTPClassDriver%4Operational.evtx - Ok
      C:\Windows\system32\winevt\Logs\OAlerts.evtx - Ok
      C:\Windows\system32\winevt\Logs\Security.evtx - Ok
      C:\Windows\system32\winevt\Logs\Setup.evtx - Ok
      C:\Windows\system32\winevt\Logs\Windows PowerShell.evtx - Ok
      C:\Windows\system32\winevt\Logs\System.evtx - Ok
      C:\Windows\system32\winrm\0C0A\winrm.ini - Ok
      C:\Windows\system32\zh-CN\cdosys.dll.mui - Ok
      C:\Windows\system32\zh-CN\comctl32.dll.mui - Ok
      C:\Windows\system32\zh-CN\comdlg32.dll.mui - Ok
      C:\Windows\system32\zh-CN\DWrite.dll.mui - Ok
      C:\Windows\system32\zh-CN\fms.dll.mui - Ok
      C:\Windows\system32\zh-CN\FntCache.dll.mui - Ok
      C:\Windows\system32\zh-CN\d2d1.dll.mui - Ok
      C:\Windows\system32\zh-CN\mlang.dll.mui - Ok
      C:\Windows\system32\zh-CN\msprivs.dll.mui - Ok
      C:\Windows\system32\zh-CN\WMPhoto.dll.mui - Ok
      C:\Windows\system32\zh-CN\msimsg.dll.mui - Ok
      C:\Windows\system32\zh-HK\comctl32.dll.mui - Ok
      C:\Windows\system32\zh-HK\comdlg32.dll.mui - Ok
      C:\Windows\system32\zh-HK\DWrite.dll.mui - Ok
      C:\Windows\system32\zh-HK\fms.dll.mui - Ok
      C:\Windows\system32\zh-HK\FntCache.dll.mui - Ok
      C:\Windows\system32\zh-HK\mlang.dll.mui - Ok
      C:\Windows\system32\zh-HK\WMPhoto.dll.mui - Ok
      C:\Windows\system32\zh-HK\d2d1.dll.mui - Ok
      C:\Windows\system32\zh-TW\cdosys.dll.mui - Ok
      C:\Windows\system32\zh-TW\comctl32.dll.mui - Ok
      C:\Windows\system32\zh-TW\comdlg32.dll.mui - Ok
      C:\Windows\system32\zh-TW\DWrite.dll.mui - Ok
      C:\Windows\system32\zh-TW\fms.dll.mui - Ok
      C:\Windows\system32\zh-TW\FntCache.dll.mui - Ok
      C:\Windows\system32\zh-TW\d2d1.dll.mui - Ok
      C:\Windows\system32\zh-TW\mlang.dll.mui - Ok
      C:\Windows\system32\zh-TW\msprivs.dll.mui - Ok
      C:\Windows\system32\zh-TW\msimsg.dll.mui - Ok
      C:\Windows\system32\zh-TW\WMPhoto.dll.mui - Ok
      C:\Users\Casa\Documents\Actor.doc - Ok
      C:\Users\Casa\Documents\cc_20121128_203826.reg - Ok
      >C:\Users\Casa\Documents\Actor.docx is ZIP archive
      C:\Users\Casa\Documents\Actor.docx - Ok
      C:\Users\Casa\Documents\Actor.docx - archive
      C:\Users\Casa\Documents\cc_20121230_035803.reg - Ok
      C:\Users\Casa\Documents\cc_20130128_073559.reg - Ok
      C:\Users\Casa\Documents\cc_20130223_181936.reg - Ok
      C:\Users\Casa\Documents\cc_20130319_151704.reg - Ok
      C:\Users\Casa\Documents\cc_20130501_061113.reg - Ok
      C:\Users\Casa\Documents\cc_20130501_190150.reg - Ok
      C:\Users\Casa\Documents\cc_20130505_134430.reg - Ok
      C:\Users\Casa\Documents\cc_20130512_171630.reg - Ok
      C:\Users\Casa\Documents\cc_20130525_163845.reg - Ok
      C:\Users\Casa\Documents\cc_20130526_103255.reg - Ok
      C:\Users\Casa\Documents\Default.rdp - Ok
      C:\Users\Casa\Documents\desktop.ini - Ok
      >C:\Users\Casa\Documents\Doc1.docx is ZIP archive
      C:\Users\Casa\Documents\Doc1.docx - Ok
      C:\Users\Casa\Documents\Doc1.docx - archive
      >C:\Users\Casa\Documents\Componer la música.docx is ZIP archive
      C:\Users\Casa\Documents\Componer la música.docx - Ok
      C:\Users\Casa\Documents\Componer la música.docx - archive
      >C:\Users\Casa\Documents\Ensallo para FISICA.docx is ZIP archive
      C:\Users\Casa\Documents\Ensallo para FISICA.docx - Ok
      C:\Users\Casa\Documents\Ensallo para FISICA.docx - archive
      >C:\Users\Casa\Documents\Herpes genital ppt.pptx is ZIP archive
      C:\Users\Casa\Documents\Herpes genital ppt.pptx - Ok
      C:\Users\Casa\Documents\Herpes genital ppt.pptx - archive
      C:\Users\Casa\Documents\Log.txt - Ok
      >C:\Users\Casa\Documents\MANUEL BLANCO ENCALADA.docx is ZIP archive
      C:\Users\Casa\Documents\MANUEL BLANCO ENCALADA.docx - Ok
      C:\Users\Casa\Documents\MANUEL BLANCO ENCALADA.docx - archive
      >C:\Users\Casa\Documents\Obras musicales.pptx is ZIP archive
      C:\Users\Casa\Documents\Obras musicales.pptx - Ok
      C:\Users\Casa\Documents\Obras musicales.pptx - archive
      C:\Users\Casa\Documents\PCSU_Update.exe - Ok
      >C:\Users\Casa\Documents\Trabajo de investigación de física.docx is ZIP archive
      C:\Users\Casa\Documents\Trabajo de investigación de física.docx - Ok
      C:\Users\Casa\Documents\Trabajo de investigación de física.docx - archive
      C:\Users\Casa\Documents\UDF1.nru - Ok
      C:\Users\Casa\Documents\Fax\Drafts\desktop.ini - Ok
      C:\Users\Casa\Documents\Fax\Inbox\desktop.ini - Ok
      C:\Users\Casa\Documents\Fax\Inbox\WelcomeFax.tif - Ok
      C:\Users\Casa\Documents\Mi música - directory
      C:\Users\Casa\Documents\Mis imágenes - directory
      C:\Users\Casa\Documents\Mis vídeos - directory
      C:\Users\Casa\Documents\Scanned Documents\desktop.ini - Ok
      C:\Users\Casa\Documents\Scanned Documents\Digitalización de bienvenida.jpg - Ok
      C:\Users\Casa\Documents\Scanned Documents\Digitalización de bienvenida.jpg:3or4kl4x13tuuug3Byamue2s4b - Ok
      C:\Users\Casa\Documents\Scanned Documents\Digitalización de bienvenida.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} - Ok
      C:\Windows\TEMP\coinlog.log - Ok
      C:\Windows\TEMP\FAPA22C.tmp - Ok
      C:\Windows\TEMP\FAPCD1F.tmp - Ok
      C:\Windows\TEMP\TMP00000007924CCD9E10AE89CF - Ok
      C:\Windows\TEMP\_avast_\Webshlock.txt - Ok
      C:\Users\Casa\AppData\Local\Temp\AdobeARM.log - Ok
      C:\Users\Casa\AppData\Local\Temp\chrome_installer.log - Ok
      C:\Users\Casa\AppData\Local\Temp\FXSAPIDebugLogFile.txt - Ok
      C:\Users\Casa\AppData\Local\Temp\hosts.bk - Ok
      >C:\Users\Casa\Documents\Obras musicales.ppt is POWERPOINT container
      C:\Users\Casa\Documents\Obras musicales.ppt - container
      C:\Users\Casa\AppData\Local\Temp\system.ini.bk - Ok
      >C:\Users\Casa\AppData\Local\Temp\SHSetup.exe is BINARYRES container
      >>C:\Users\Casa\AppData\Local\Temp\SHSetup.exe\data001 is OLE container
      C:\Users\Casa\AppData\Local\Temp\VXOM02hD.exe.part - Ok
      C:\Users\Casa\AppData\Local\Temp\win.ini.bk - Ok
      C:\Users\Casa\AppData\Local\Temp\wmplog01.sqm - Ok
      C:\Users\Casa\AppData\Local\Temp\wmplog02.sqm - Ok
      C:\Users\Casa\AppData\Local\Temp\wmplog03.sqm - Ok
      C:\Users\Casa\AppData\Local\Temp\wmplog04.sqm - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\02wv45gn - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\04vrd0z6 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\08s1ddo6 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\0mbq1ig6 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\0qezghi3 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\101ax0uc - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\14no3ist - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\1754s54y - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\198iocul - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\1l7xi7ft - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\1whbnut4 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\27kfdovx - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\2h31w7tz - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\2krj5wgj - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\2sie5t3v - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\39to7js6 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\3gleev4p - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\3h5h1ctf - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\3hmdvj4a - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\3seupcue - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\4prqqww7 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\5270yojn - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\5i2pd8lz - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\5svw6p99 - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\5xj1h6gj - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\6abnlkxx - Ok
      C:\Users\Casa\AppData\Local\Temp\526C69E0-19E4F050-231DB8C0-B16DA3D0\6kjmzmks - Ok

    10. #30
      Colaborador Avatar de Mudo13
      Registrado
      abr 2012
      Ubicación
      Ceuta. España.
      Mensajes
      2.260

      Re: ¿Cómo desinstalar Delta Search, (navegador intruso)

      Buenas.

      Vale, esta vez esta mejor el reporte.

      Comente si realizaste lo que le recomendé en el post #27recuerde en comentar como va ahora todo y las dudas.

      Saludos!
      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.