Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected - Cannot Access Windows 10 Settings After Restarts


  • This topic is locked This topic is locked
30 replies to this topic

#1 Torvald

Torvald

  • Members
  • 366 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Antonio, TX USA
  • Local time:05:19 AM

Posted 25 November 2017 - 10:09 PM

A couple of days ago, I decided to update our three Windows 10 home computers to the Fall Creator's Update.  Two home computers updated okay, but had some minor glitches where I had to reinstall some programs to get them to work properly.  My own computer refused multiple upgrade attempts, but I finally succeeded by using a file downloaded from Microsoft to do a Repair Upgrade.  It also had some minor problems, and I was gradually reinstalling some programs on it too.

In the middle of this, I choose to visit some old bookmarked websites using Firefox v57 to look up info on some older computer games.  While doing so, some of the old bookmarked websites were found to be no longer working - no problem, but while accessing some other game websites, I got a screen giving me visual and audio warnings that my computer was infected and to quickly click on some hyperlinks in order to save it.  Wisely, i did not click on anything and either backed out of those websites or closed my Firefox browser.

I thought I was okay, but decided to run a Windows defender scan just to be sure, and that is when I noticed I was probably infected.  I could no longer access Windows Settings, so could not run Windows Defender.  Also, the right-click function quit working on icons in my taskbar.  After a little research, i noticed that if I completely shut down my computer and physically turned off the power, then turned it back on, my computer seemed to work okay.  However, if I instead just did a computer restart, the above problems would reoccur.  I also noticed some strangely named folders had appeared on my C: drive, containing strangely named files, and that whenever i restarted my computer, one of those strange folders would rename & redate itself, and then replace all of the strange files with brand new strange files (various types of files, txt, rtf, doc, xls, etc.).  it would not do this when I fully shut down my computer, but only when I restarted my computer.

Here are the scans I have run so far, but none of them detected anything:  Emisoft Antimalware, SuperAntispyware, Malwarebytes Antirootkit, Malwarebytes Antimalware, Zemana Antimalware (and Windows Defender after a full shutdown).  Also ran Trend Micro online virus scan. It said it detected three infections, but after scanning for seven hours was only 28% complete, so i quit the scan and I don't think it actually cleaned anything.

This infection has me very worried, and I do not dare access any of my online financial websites right now, so would really appreciate help in fixing this infection.

 

Am having trouble transmitting the FRST.txt info (keep getting a timed out message) so am sending this first part by itslef, then will try sending bits and pieces of the FRST.txt and Addition.txt files.


Google is my friend. Make Google your friend too.


BC AdBot (Login to Remove)

 


#2 Torvald

Torvald
  • Topic Starter

  • Members
  • 366 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Antonio, TX USA
  • Local time:05:19 AM

Posted 25 November 2017 - 10:12 PM

Here is the first part of my FRST.txt file:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24-11-2017 01
Ran by Jeff (administrator) on JEFF-PC (25-11-2017 19:56:40)
Running from C:\Users\Jeff\Downloads
Loaded Profiles: Jeff (Available Profiles: Jeff & DefaultAppPool)
Platform: Windows 10 Home Version 1709 16299.64 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Cybereason) C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFreeServiceHost.exe
(CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Ransomware\MB3Service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Samsung Electronics Co., Ltd.) C:\Windows\System32\RAPID\SamsungRapidSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Ransomware\mbarw.exe
(Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Cybereason) C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFree.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
() C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Samsung Electronics Co. Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe
(Valve Corporation) C:\Games\Steam.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Fred's Software) C:\Program Files (x86)\PrintKey2000\Printkey2000.exe
(Zemana Ltd.) C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe
(Valve Corporation) C:\Games\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Games\bin\cef\cef.win7\steamwebhelper.exe
() C:\Program Files (x86)\EaseUS\EaseUS Partition Master 12.5\bin\TrayPopupE\TrayTipAgentE.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13675736 1999-12-31] (Realtek Semiconductor)
HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
HKLM\...\Run: [SamsungRapidApp] => C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe [123800 2016-11-18] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2017-08-13] (IvoSoft)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [ZALFree] => C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe [8980016 2015-11-05] (Zemana Ltd.)
HKLM-x32\...\Run: [EaseUS EPM Tray Agent] => C:\Program Files (x86)\EaseUS\EaseUS Partition Master 12.5\bin\TrayPopupE\TrayTipAgentE.exe [255072 2014-11-18] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2480592 2017-11-14] (Malwarebytes Corporation)
HKLM-x32\...\Run: [P17RunE] => RunDll32 P17RunE.dll,RunDLLEntry
HKLM Group Policy restriction on software: *.avi*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: lsassw86s.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.jse <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.com <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.exe <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.com <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.pif <==== ATTENTION
HKLM Group Policy restriction on software: cipher.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.exe <==== ATTENTION
HKLM Group Policy restriction on software: ** <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.scr <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: lsassvrtdbks.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: scsvserv.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %programfiles(x86)%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.com <==== ATTENTION
HKLM Group Policy restriction on software: syskey.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.com <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: vssadmin.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.exe <==== ATTENTION
HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3098952 2017-11-02] (Electronic Arts)
HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10024624 2017-11-08] (Piriform Ltd)
HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\Run: [Steam] => C:\Games\steam.exe [3102496 2017-10-30] (Valve Corporation)
HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Mystify.scr [150016 2017-09-29] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Kodak software updater.lnk [2012-12-23]
ShortcutTarget: Kodak software updater.lnk -> C:\Program Files (x86)\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Printkey2000.lnk [2012-12-23]
ShortcutTarget: Printkey2000.lnk -> C:\Program Files (x86)\PrintKey2000\Printkey2000.exe (Fred's Software)
GroupPolicy: Restriction - Chrome <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{adb3695c-c3de-4eb6-aa4b-ec5c3a65a0be}: [DhcpNameServer] 209.18.47.61 209.18.47.62

Internet Explorer:
==================
HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001 -> DefaultScope {E37D4B52-2941-495E-8F75-98949E5D2039} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001 -> {E37D4B52-2941-495E-8F75-98949E5D2039} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (IvoSoft)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2017-08-13] (IvoSoft)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (IvoSoft)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-10-20] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-20] (Oracle Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2017-08-13] (IvoSoft)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (IvoSoft)
Toolbar: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2016-01-04] (Belarc, Inc.)

Edge:
======
Edge Extension: (Adblock Plus) -> 10_EyeoGmbHAdblockPlus_d55gg7py3s0m0 => C:\Program Files\WindowsApps\EyeoGmbH.AdblockPlus_0.9.9.0_neutral__d55gg7py3s0m0 [2016-12-08]

FireFox:
========
FF DefaultProfile: k5mqm78o.default
FF ProfilePath: C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\k5mqm78o.default [2017-11-25]
FF Homepage: Mozilla\Firefox\Profiles\k5mqm78o.default -> hxxp://www.google.com/
FF Extension: (uBlock Origin) - C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\k5mqm78o.default\Extensions\uBlock0@raymondhill.net.xpi [2017-11-08]
FF Extension: (NoScript) - C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\k5mqm78o.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2017-11-23]
FF Extension: (Adblock Plus) - C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\k5mqm78o.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-11-08]
FF Extension: (Disable Media WMF NV12 format) - C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\k5mqm78o.default\features\{15a765b6-f9de-4fb8-9ed2-270a3f902e81}\disable-media-wmf-nv12@mozilla.org.xpi [2017-11-25] [Lagacy]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_187.dll [2017-11-14] ()
FF Plugin: @java.com/JavaPlugin,version=10.11.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_187.dll [2017-11-14] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-10-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-10-20] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-11-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4089348763-2620558389-2721033571-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Jeff\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-03-21] (Citrix Online)

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default [2017-11-24]
CHR Extension: (Slides) - C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-11-23]
CHR Extension: (Docs) - C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-23]
CHR Extension: (Google Drive) - C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-17]
CHR Extension: (YouTube) - C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-02]
CHR Extension: (Adblock Plus) - C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-11-23]
CHR Extension: (uBlock Origin) - C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-11-23]
CHR Extension: (Google Search) - C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-20]
CHR Extension: (Sheets) - C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-11-23]
CHR Extension: (Google Docs Offline) - C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-11-23]
CHR Extension: (Ad.Block Plus) - C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohcgafpfnflodmlefikfpfjobidehggm [2016-03-17]
CHR Extension: (uBlock Origin Extra) - C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgdnlhfefecpicbbihgmbmffkjpaplco [2017-11-23]
CHR Extension: (Gmail) - C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-20]
CHR Extension: (Chrome Media Router) - C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-11-23]


Google is my friend. Make Google your friend too.


#3 Torvald

Torvald
  • Topic Starter

  • Members
  • 366 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Antonio, TX USA
  • Local time:05:19 AM

Posted 25 November 2017 - 10:13 PM

Here is more of my FRST.txt file:

 

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-30] (SUPERAntiSpyware.com)
R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [9173552 2017-11-13] (Emsisoft Ltd)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2013-12-09] (Creative Labs) [File not signed]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2012-12-23] (Creative Labs) [File not signed]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [307200 2008-11-18] (Creative Technology Ltd) [File not signed]
R2 CybereasonRansomFree; C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFreeServiceHost.exe [13824 2017-10-08] (Cybereason) [File not signed]
R2 EaseUS Agent; C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [40128 2017-06-19] (CHENGDU YIWO Tech Development Co., Ltd)
R2 hmpalertsvc; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1876816 2015-03-04] (SurfRight B.V.)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [3894760 2017-06-26] (Paramount Software UK Ltd)
R2 MB3Service; C:\Program Files\Malwarebytes\Anti-Ransomware\mb3service.exe [6054352 2017-07-25] (Malwarebytes)
R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [155088 2017-11-14] (Malwarebytes Corporation)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519104 2017-11-15] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519104 2017-11-15] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-11-14] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [460736 2017-11-15] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2123104 2017-11-02] (Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3002728 2017-11-02] (Electronic Arts)
S3 PAExec; C:\WINDOWS\PAExec.exe [189112 2017-05-11] (Power Admin LLC)
R2 SamsungRapidSvc; C:\WINDOWS\System32\RAPID\SamsungRapidSvc.exe [29080 2016-11-18] (Samsung Electronics Co., Ltd.)
S2 SupportSoft RemoteAssist; C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe [386424 2010-02-24] (SupportSoft, Inc.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10942704 2017-11-03] (TeamViewer GmbH)
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [294168 2017-10-03] (Reason Software Company Inc.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation)
R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [33448 2016-12-07] ()
S3 epmntdrv; C:\WINDOWS\SysWOW64\epmntdrv.sys [21496 2016-01-14] ()
R1 epp; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp.sys [124552 2016-11-23] (Emsisoft Ltd)
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [77432 2017-11-14] ()
S3 EUBAKUP0; C:\WINDOWS\system32\drivers\EUBAKUP0.sys [65192 2016-11-28] (CHENGDU YIWO Tech Development Co., Ltd)
R0 EUBKMON; C:\WINDOWS\System32\drivers\EUBKMON.sys [52392 2016-11-28] ()
S3 EUBKMON0; C:\WINDOWS\system32\drivers\EUBKMON0.sys [52392 2016-11-28] ()
R1 EUDSKACS; C:\Windows\system32\drivers\eudskacs.sys [18472 2015-12-10] (CHENGDU YIWO Tech Development Co., Ltd) [File not signed]
R1 EUFDDISK; C:\Windows\system32\drivers\EuFdDisk.sys [192552 2015-12-10] (CHENGDU YIWO Tech Development Co., Ltd) [File not signed]
S3 EUFDDISK0; C:\WINDOWS\system32\drivers\EUFDDISK0.sys [196776 2016-11-28] (CHENGDU YIWO Tech Development Co., Ltd)
S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [10848 2016-07-11] () [File not signed]
S3 EuGdiDrv; C:\WINDOWS\SysWOW64\EuGdiDrv.sys [10208 2016-07-11] () [File not signed]
S3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [46960 2016-08-07] ()
R2 hmpalert; C:\WINDOWS\System32\drivers\hmpalert.sys [93144 2015-03-07] ()
R3 keycrypt; C:\WINDOWS\System32\DRIVERS\KeyCrypt64.sys [143904 2015-11-05] (Zemana Ltd.)
R3 MB3SwissArmy; C:\WINDOWS\system32\drivers\MB3SwissArmy.sys [253888 2017-11-25] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [107960 2017-11-25] (Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2017-11-23] (Malwarebytes)
S1 MpKsld6a3221a; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7EC8C604-A793-47CE-9B2D-CD0C6C7463C4}\MpKsld6a3221a.sys [58120 2017-11-25] () [File not signed]
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_c791f781cd94491f\nvlddmkm.sys [16989296 2017-11-15] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-11-15] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [50624 2017-10-10] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-11-15] (NVIDIA Corporation)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2017-09-29] (Realtek )
R0 SamsungRapidDiskFltr; C:\WINDOWS\System32\DRIVERS\SamsungRapidDiskFltr.sys [272792 2016-11-18] (Samsung Electronics Co., Ltd.)
R0 SamsungRapidFSFltr; C:\WINDOWS\System32\DRIVERS\SamsungRapidFSFltr.sys [111512 2016-11-18] (Samsung Electronics Co., Ltd.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Corporation)
R1 ZAM; C:\WINDOWS\System32\drivers\zam64.sys [203680 2016-09-05] (Zemana Ltd.)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2016-09-05] (Zemana Ltd.)
U3 idsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-25 19:56 - 2017-11-25 19:57 - 000049912 _____ C:\Users\Jeff\Downloads\FRST.txt
2017-11-25 19:52 - 2017-11-25 19:52 - 002393088 _____ (Farbar) C:\Users\Jeff\Downloads\FRST64.exe
2017-11-25 19:45 - 2017-11-25 19:45 - 000000000 __SHD C:\Users\Jeff\Desktop\0K, this directory is for Ransomware detection (just leave it here)
2017-11-25 19:45 - 2017-11-25 19:45 - 000000000 ___HD C:\Users\Jeff\Documents\Ysetup70
2017-11-25 19:45 - 2017-11-25 19:45 - 000000000 ___HD C:\Users\Jeff\Documents\Ajconfiguration157
2017-11-25 19:44 - 2017-11-25 19:44 - 000510163 ____N C:\Users\Ai8rznar\editorialoccurs.xlsx
2017-11-25 19:44 - 2017-11-25 19:44 - 000508657 ____N C:\Users\Wpmbfzs\anne-january-indicate.xlsx
2017-11-25 19:44 - 2017-11-25 19:44 - 000229452 ____N C:\Users\Ai8rznar\handwriting zero.mdb
2017-11-25 19:44 - 2017-11-25 19:44 - 000200483 ____N C:\Users\Wpmbfzs\building.violate.mdb
2017-11-25 19:44 - 2017-11-25 19:44 - 000075278 ____N C:\Users\Wpmbfzs\sour hat juice incompatible.xls
2017-11-25 19:44 - 2017-11-25 19:44 - 000060659 ____N C:\Users\Ai8rznar\lack.fold.exposure.sock.xls
2017-11-25 19:44 - 2017-11-25 19:44 - 000055314 ____N C:\Users\Wpmbfzs\kickpursue.pem
2017-11-25 19:44 - 2017-11-25 19:44 - 000050967 ____N C:\Users\Ai8rznar\coloredignoreresults.pem
2017-11-25 19:44 - 2017-11-25 19:44 - 000030856 ____N C:\Users\Ai8rznar\smell_occupied.txt
2017-11-25 19:44 - 2017-11-25 19:44 - 000020735 ____N C:\Users\Ai8rznar\obligations legislation london.sql
2017-11-25 19:44 - 2017-11-25 19:44 - 000018062 ____N C:\Users\Wpmbfzs\excite_meanwhile_precipitate_voters.txt
2017-11-25 19:44 - 2017-11-25 19:44 - 000013606 ____N C:\Users\Wpmbfzs\coach fled.sql
2017-11-25 19:44 - 2017-11-25 19:44 - 000000000 ___HD C:\Users\Wpmbfzs
2017-11-25 19:44 - 2017-11-25 19:44 - 000000000 ___HD C:\Users\Ai8rznar
2017-11-25 19:44 - 2017-11-25 19:44 - 000000000 ____D C:\Ysettingsettings37
2017-11-25 19:44 - 2017-11-25 19:44 - 000000000 ____D C:\948aselect12
2017-11-25 07:47 - 2017-11-25 07:47 - 000000010 _____ C:\Users\Jeff\AppData\Local\sponge.last.runtime.cache
2017-11-25 07:41 - 2017-11-25 07:41 - 000000000 ____D C:\Users\Jeff\AppData\Local\Trend Micro
2017-11-25 07:41 - 2017-11-25 07:41 - 000000000 ____D C:\ProgramData\Trend Micro
2017-11-25 07:40 - 2017-11-25 07:40 - 000000000 ____D C:\WINDOWS\Trend Micro
2017-11-25 07:33 - 2017-11-25 07:33 - 000000036 _____ C:\Users\Jeff\AppData\Local\housecall.guid.cache
2017-11-25 07:33 - 2017-10-17 10:40 - 000334488 _____ (Trend Micro Inc.) C:\WINDOWS\system32\Drivers\tmcomm.sys
2017-11-25 07:32 - 2017-11-25 07:32 - 002527376 _____ (Trend Micro Inc.) C:\Users\Jeff\Downloads\HousecallLauncher64.exe
2017-11-25 01:51 - 2017-11-25 01:51 - 112129296 _____ (Microsoft Corporation) C:\Users\Jeff\Downloads\mpam-fe.exe
2017-11-25 01:33 - 2017-11-25 19:44 - 000107960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-11-24 19:28 - 2017-11-24 19:28 - 000000207 _____ C:\WINDOWS\tweaking.com-regbackup-JEFF-PC-Windows-10-Home-(64-bit).dat
2017-11-24 17:30 - 2017-11-24 17:30 - 000002185 _____ C:\Users\Jeff\Desktop\Windows Repair (All in One) - Shortcut.lnk
2017-11-24 17:28 - 2017-11-24 17:28 - 000003764 _____ C:\WINDOWS\System32\Tasks\Tweaking.com - Windows Repair Tray Icon
2017-11-24 17:27 - 2017-11-24 17:28 - 000194058 _____ C:\WINDOWS\Tweaking.com - Windows Repair Setup Log.txt
2017-11-24 16:36 - 2017-11-25 19:46 - 000000000 ____D C:\Users\Jeff\AppData\Local\ClassicShell
2017-11-24 16:35 - 2017-11-24 16:35 - 000000000 ____D C:\Users\Jeff\AppData\Roaming\ClassicShell
2017-11-24 16:32 - 2017-11-24 16:32 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\7D3C55CE.sys
2017-11-24 16:05 - 2017-11-24 16:05 - 000000000 ____D C:\ProgramData\ClassicShell
2017-11-24 16:04 - 2017-11-24 16:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2017-11-24 16:04 - 2017-11-24 16:04 - 000000000 ____D C:\Program Files\Classic Shell
2017-11-24 09:07 - 2017-11-25 01:32 - 115081216 _____ C:\WINDOWS\system32\config\SOFTWARE
2017-11-24 08:58 - 2017-11-24 09:06 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
2017-11-23 21:20 - 2017-11-23 21:20 - 000406582 _____ C:\Users\Jeff\Downloads\startmenu.diagcab
2017-11-23 11:55 - 2017-11-23 11:55 - 000000000 ____D C:\Users\Jeff\AppData\Local\ESET
2017-11-23 11:53 - 2017-11-23 11:53 - 006968952 _____ (ESET spol. s r.o.) C:\Users\Jeff\Downloads\esetonlinescanner_enu.exe
2017-11-23 11:16 - 2017-11-23 11:17 - 007187816 _____ (IvoSoft) C:\Users\Jeff\Downloads\ClassicShellSetup_4_3_1.exe
2017-11-23 07:31 - 2017-11-23 07:31 - 000000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2017-11-22 18:57 - 2017-11-22 17:30 - 000000000 ____D C:\Windows.old
2017-11-22 17:32 - 2017-11-22 17:32 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2017-11-22 17:31 - 2017-11-22 17:31 - 000000000 ___HD C:\Users\Jeff\MicrosoftEdgeBackups
2017-11-22 17:30 - 2017-11-22 17:30 - 000000020 ___SH C:\Users\Jeff\ntuser.ini
2017-11-22 17:30 - 2017-11-22 17:30 - 000000000 ___RD C:\Users\Jeff\3D Objects
2017-11-22 17:28 - 2017-11-22 17:28 - 000011433 _____ C:\WINDOWS\diagwrn.xml
2017-11-22 17:28 - 2017-11-22 17:28 - 000011433 _____ C:\WINDOWS\diagerr.xml
2017-11-22 17:17 - 2017-11-25 19:44 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-11-22 17:17 - 2017-11-25 18:06 - 000004150 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4B60F531-410F-4FC3-815F-D087D65A486C}
2017-11-22 17:17 - 2017-11-24 20:29 - 000003638 _____ C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask
2017-11-22 17:17 - 2017-11-22 18:06 - 000003938 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2017-11-22 17:17 - 2017-11-22 17:35 - 000003360 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4089348763-2620558389-2721033571-1001
2017-11-22 17:17 - 2017-11-22 17:17 - 000003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-11-22 17:17 - 2017-11-22 17:17 - 000003398 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-11-22 17:17 - 2017-11-22 17:17 - 000003344 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-11-22 17:17 - 2017-11-22 17:17 - 000003322 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-11-22 17:17 - 2017-11-22 17:17 - 000003176 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-11-22 17:17 - 2017-11-22 17:17 - 000003120 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-11-22 17:17 - 2017-11-22 17:17 - 000002984 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-11-22 17:17 - 2017-11-22 17:17 - 000002956 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-11-22 17:17 - 2017-11-22 17:17 - 000002956 _____ C:\WINDOWS\System32\Tasks\Cybereason RansomFree Keepalive
2017-11-22 17:17 - 2017-11-22 17:17 - 000002914 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-11-22 17:17 - 2017-11-22 17:17 - 000002838 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-11-22 17:17 - 2017-11-22 17:17 - 000002786 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-11-22 17:17 - 2017-11-22 17:17 - 000002744 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-11-22 17:17 - 2017-11-22 17:17 - 000002534 _____ C:\WINDOWS\System32\Tasks\SamsungMagician
2017-11-22 17:17 - 2017-11-22 17:17 - 000002372 _____ C:\WINDOWS\System32\Tasks\{99BF69A3-88A7-4DEE-8FC8-8E2866017869}
2017-11-22 17:17 - 2017-11-22 17:17 - 000002248 _____ C:\WINDOWS\System32\Tasks\Cybereason RansomFree Autostart
2017-11-22 17:17 - 2017-11-22 17:17 - 000002236 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2017-11-22 17:17 - 2017-11-22 17:17 - 000000000 ____D C:\WINDOWS\System32\Tasks\WPD
2017-11-22 17:17 - 2017-11-22 17:17 - 000000000 ____D C:\WINDOWS\System32\Tasks\S-1-5-21-4089348763-2620558389-2721033571-1001
2017-11-22 17:17 - 2017-11-22 17:17 - 000000000 ____D C:\WINDOWS\System32\Tasks\Apple
2017-11-22 17:10 - 2017-11-22 17:10 - 000000000 ____D C:\ProgramData\USOShared
2017-11-22 17:09 - 2017-11-22 17:09 - 000001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-11-22 17:07 - 2017-11-25 19:46 - 000000000 ____D C:\Users\Jeff
2017-11-22 17:07 - 2017-11-24 20:36 - 000000000 ____D C:\Users\Jeff\AppData\Local\Packages
2017-11-22 17:07 - 2017-11-23 07:31 - 000000000 ____D C:\Users\DefaultAppPool
2017-11-22 17:02 - 2017-11-25 19:50 - 000887324 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-11-22 17:01 - 2017-09-29 07:41 - 002241024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-11-22 17:00 - 2017-11-25 19:44 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-11-22 17:00 - 2017-11-25 01:32 - 000405504 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-11-22 16:23 - 2017-11-22 16:23 - 000000000 ___DL C:\Users\Vacr
2017-11-22 16:23 - 2017-11-22 16:23 - 000000000 ___DL C:\Users\Public\Recorded TV (1)
2017-11-22 16:23 - 2017-11-22 16:23 - 000000000 ___DL C:\Users\Ajg3tqv
2017-11-22 16:22 - 2017-11-22 16:22 - 000000000 ____D C:\Program Files\Common Files\SpeechEngines
2017-11-22 16:21 - 2017-11-22 18:57 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2017-11-22 16:15 - 2017-11-22 16:21 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2017-11-22 16:05 - 2017-11-22 16:05 - 013655552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2017-11-22 16:05 - 2017-11-22 16:05 - 012687360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 025246208 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 023658496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 021753344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 019339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 018914304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 017083904 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 008590744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-11-22 16:04 - 2017-11-22 16:04 - 008099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 007831248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 006791472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 006035968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 006015200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 005906264 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 005615968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 004742144 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 004648528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 004487968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 003679232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 003670016 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 003478016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 003313968 _____ C:\WINDOWS\system32\Windows.Mirage.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 002972672 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 002905600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 002869248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 002864640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 002862080 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 002781696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 002717392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 002633216 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 002573208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 002474584 _____ C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 002467840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 002465848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 002400664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 002392576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 002269080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 002106368 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 001970520 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001954048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001856000 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001806336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001667584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001664000 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001634288 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001615720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001587200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001559552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001554216 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001528904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001507736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001485824 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001470976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001463856 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001454568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001436432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001426152 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001377080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001323840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001322496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001280000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001261864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001246432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001200024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-11-22 16:04 - 2017-11-22 16:04 - 001170008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001167360 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 001053592 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-11-22 16:04 - 2017-11-22 16:04 - 001015008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000982016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000975872 _____ C:\WINDOWS\system32\FaceProcessor.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2017-11-22 16:04 - 2017-11-22 16:04 - 000925184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000839928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Perception.Stub.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000812032 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000778936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-11-22 16:04 - 2017-11-22 16:04 - 000768512 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPKsp.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000739696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000726016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000710920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000685056 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000677280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000665600 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000665088 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000654848 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000649304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-11-22 16:04 - 2017-11-22 16:04 - 000640512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswstr10.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000618496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000612760 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000610712 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000603920 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2017-11-22 16:04 - 2017-11-22 16:04 - 000599040 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000597160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000591872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPKsp.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000566272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000559512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000555416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2017-11-22 16:04 - 2017-11-22 16:04 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000541184 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000506256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcSpecfc.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000479912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000478208 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000465408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000464416 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000442880 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000436120 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000428952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000422912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000418712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000374032 _____ (Microsoft Corporation) C:\WINDOWS\system32\vac.exe
2017-11-22 16:04 - 2017-11-22 16:04 - 000373656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000362176 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe
2017-11-22 16:04 - 2017-11-22 16:04 - 000354200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000353688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicRuntimes.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcLayers.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000285080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000269696 _____ C:\WINDOWS\system32\FaceProcessorCore.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000246168 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000232344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000187288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000184984 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000147864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000139672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\luafv.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000123520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmCx.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000097792 _____ C:\WINDOWS\system32\runexehelper.exe
2017-11-22 16:04 - 2017-11-22 16:04 - 000095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CapabilityAccessManagerClient.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000060824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\urscx01000.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsi.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcSpecfc.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdrleakdiag.exe
2017-11-22 16:04 - 2017-11-22 16:04 - 000045464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdrleakdiag.exe
2017-11-22 16:04 - 2017-11-22 16:04 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-11-22 16:04 - 2017-11-22 16:04 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspisrv.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcVSp1res.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcVSp1res.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjint40.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-11-22 16:04 - 2017-11-22 16:04 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-11-22 15:51 - 2017-11-22 15:51 - 000000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2017-11-22 15:51 - 2017-11-22 15:51 - 000000000 ____D C:\WINDOWS\system32\msmq
2017-11-22 15:51 - 2017-11-22 15:51 - 000000000 ____D C:\WINDOWS\system32\BestPractices
2017-11-22 15:51 - 2017-11-22 15:51 - 000000000 ____D C:\Program Files\Reference Assemblies
2017-11-22 15:51 - 2017-11-22 15:51 - 000000000 ____D C:\Program Files\MSBuild
2017-11-22 15:51 - 2017-11-22 15:51 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-11-22 15:51 - 2017-11-22 15:51 - 000000000 ____D C:\Program Files (x86)\MSBuild
2017-11-22 15:51 - 2017-11-22 15:51 - 000000000 ____D C:\inetpub
2017-11-22 15:47 - 2017-09-22 18:19 - 000778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2017-11-22 15:47 - 2017-09-22 18:19 - 000103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-11-22 15:47 - 2017-09-22 18:19 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2017-11-22 15:46 - 2017-09-28 15:50 - 001166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2017-11-22 15:46 - 2017-09-28 15:50 - 000124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2017-11-22 15:46 - 2017-09-28 15:50 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2017-11-22 15:45 - 2017-09-28 21:31 - 000095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\DxToolsReportGenerator.dll
2017-11-22 15:45 - 2017-09-28 20:54 - 000095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DxToolsReportGenerator.dll
2017-11-22 15:45 - 2017-09-28 19:15 - 017928704 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCaptureReplay.dll
2017-11-22 15:45 - 2017-09-28 19:07 - 000398336 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\DXCpl.exe
2017-11-22 15:45 - 2017-09-28 19:05 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsProxyStub.dll
2017-11-22 15:45 - 2017-09-28 19:05 - 000076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARPDebug.dll
2017-11-22 15:45 - 2017-09-28 19:03 - 005784576 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe
2017-11-22 15:45 - 2017-09-28 19:01 - 004907008 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsRemoteEngine.exe
2017-11-22 15:45 - 2017-09-28 19:01 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXGIDebug.dll
2017-11-22 15:45 - 2017-09-28 18:58 - 001312256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11_3SDKLayers.dll
2017-11-22 15:45 - 2017-09-28 18:58 - 000538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1debug3.dll
2017-11-22 15:45 - 2017-09-28 18:56 - 002771968 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12SDKLayers.dll
2017-11-22 15:45 - 2017-09-28 18:55 - 001992192 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsOfflineAnalysis.dll
2017-11-22 15:45 - 2017-09-28 18:55 - 001178112 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCap.exe
2017-11-22 15:45 - 2017-09-28 18:55 - 000284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsExperiment.dll
2017-11-22 15:45 - 2017-09-28 18:55 - 000161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsCapture.dll
2017-11-22 15:45 - 2017-09-28 18:54 - 000188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsMonitor.dll
2017-11-22 15:45 - 2017-09-28 18:54 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsReporting.dll
2017-11-22 15:45 - 2017-09-28 18:51 - 000349696 _____ (Microsoft Corporation) C:\WINDOWS\system32\perf_gputiming.dll
2017-11-22 15:45 - 2017-09-28 18:50 - 014014976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCaptureReplay.dll
2017-11-22 15:45 - 2017-09-28 18:46 - 000375296 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\SysWOW64\DXCpl.exe
2017-11-22 15:45 - 2017-09-28 18:44 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARPDebug.dll
2017-11-22 15:45 - 2017-09-28 18:44 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsProxyStub.dll
2017-11-22 15:45 - 2017-09-28 18:41 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXGIDebug.dll
2017-11-22 15:45 - 2017-09-28 18:40 - 003657216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsRemoteEngine.exe
2017-11-22 15:45 - 2017-09-28 18:40 - 001064448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11_3SDKLayers.dll
2017-11-22 15:45 - 2017-09-28 18:38 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1debug3.dll
2017-11-22 15:45 - 2017-09-28 18:37 - 004550144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsDesktopEngine.exe
2017-11-22 15:45 - 2017-09-28 18:35 - 002216960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12SDKLayers.dll
2017-11-22 15:45 - 2017-09-28 18:35 - 001496064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsOfflineAnalysis.dll
2017-11-22 15:45 - 2017-09-28 18:35 - 000921088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCap.exe
2017-11-22 15:45 - 2017-09-28 18:34 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsExperiment.dll
2017-11-22 15:45 - 2017-09-28 18:34 - 000142336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsMonitor.dll
2017-11-22 15:45 - 2017-09-28 18:34 - 000121856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsCapture.dll
2017-11-22 15:45 - 2017-09-28 18:34 - 000118784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsReporting.dll
2017-11-22 15:45 - 2017-09-28 18:31 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perf_gputiming.dll
2017-11-22 15:31 - 2017-11-22 15:31 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2017-11-22 15:08 - 2017-11-22 18:47 - 000000000 ___DC C:\WINDOWS\Panther
2017-11-22 14:57 - 2017-11-23 21:27 - 000000000 ____D C:\ESD
2017-11-22 14:56 - 2017-11-22 14:56 - 000000000 ___HD C:\$Windows.~WS
2017-11-22 14:40 - 2017-11-22 14:40 - 000000000 ___HD C:\Users\Jeff\Documents\Akconfig44
2017-11-21 17:56 - 2017-11-24 17:38 - 000000000 ___HD C:\Users\Ukpu1
2017-11-21 17:56 - 2017-11-24 17:37 - 000000000 ___HD C:\Users\Akplzi0
2017-11-21 17:56 - 2017-11-23 11:01 - 000000000 ____D C:\948blogs187
2017-11-21 17:56 - 2017-11-22 09:15 - 000000000 ___HD C:\Users\Jeff\Documents\Xprogram109
2017-11-21 17:56 - 2017-11-22 09:15 - 000000000 ___HD C:\Users\Jeff\Documents\Aldates129
2017-11-21 17:56 - 2017-11-22 09:15 - 000000000 ____D C:\Xcached215
2017-11-21 17:53 - 2017-11-15 19:41 - 000057792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys
2017-11-21 17:50 - 2017-11-22 18:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2017-11-21 17:50 - 2017-11-21 17:50 - 000000000 ____D C:\Program Files\7-Zip
2017-11-21 13:44 - 2017-11-21 17:56 - 000000000 ___HD C:\Users\Jeff\Documents\Amstorage110
2017-11-16 19:29 - 2017-11-16 19:29 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2017-11-16 19:29 - 2017-09-13 17:20 - 000798008 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2017-11-16 19:29 - 2017-09-13 17:20 - 000490296 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2017-11-16 19:29 - 2017-09-13 17:19 - 000927544 _____ C:\WINDOWS\system32\vulkan-1.dll
2017-11-16 19:29 - 2017-09-13 17:19 - 000591160 _____ C:\WINDOWS\system32\vulkaninfo.exe
2017-11-16 19:23 - 2017-11-14 16:48 - 040237504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 036239480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 035156600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 029272000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 023264864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 019038976 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 013865256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 013255032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 011780376 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 010883928 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 004484864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 004201592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 003817584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 003614328 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 001989056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438831.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 001673664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438831.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 001615472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 001321264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 001135280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 001099712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 001038680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 001031288 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 000980928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 000932288 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 000885496 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 000794576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 000739448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 000634224 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 000615544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 000598648 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 000505976 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 000225208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2017-11-16 19:23 - 2017-11-14 16:48 - 000048442 _____ C:\WINDOWS\system32\nvinfo.pb
2017-11-16 19:23 - 2017-11-14 16:48 - 000045496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2017-11-16 19:23 - 2017-11-14 16:48 - 000000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2017-11-16 19:23 - 2017-11-14 16:48 - 000000669 _____ C:\WINDOWS\system32\nv-vk64.json
2017-11-15 20:16 - 2017-11-16 19:58 - 000000000 ___HD C:\Users\Jeff\Documents\Anorganized103
2017-11-14 19:05 - 2017-11-14 19:05 - 000000000 ___HD C:\Users\Jeff\Documents\Aoconfiguration110
2017-11-14 17:35 - 2017-11-14 19:04 - 000000000 ___HD C:\Users\Jeff\Documents\Apwrap64
2017-11-12 06:12 - 2017-11-12 06:12 - 000000000 ___HD C:\Users\Jeff\Documents\Aqvalues125
2017-11-06 17:44 - 2017-11-06 19:52 - 000000000 ___HD C:\Users\Jeff\Documents\Arpackage21
2017-11-05 17:27 - 2017-11-05 17:27 - 005114221 _____ C:\Users\Jeff\Downloads\ML15125A004.pdf
2017-11-05 17:20 - 2017-11-05 17:20 - 000061378 _____ C:\Users\Jeff\Downloads\ML15124A777.pdf
2017-11-04 19:07 - 2017-11-04 20:41 - 000000000 ___HD C:\Users\Jeff\Documents\Asstore185
2017-11-04 11:47 - 2017-11-04 11:47 - 001990593 _____ C:\Users\Jeff\Downloads\document.pdf
2017-11-03 10:43 - 2017-11-08 10:21 - 000001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 13.lnk
2017-11-03 10:43 - 2017-11-08 10:21 - 000001028 _____ C:\Users\Public\Desktop\TeamViewer 13.lnk
2017-11-03 05:18 - 2017-11-03 18:09 - 000000000 ___HD C:\Users\Jeff\Documents\Atdate15
2017-11-02 05:24 - 2017-10-10 19:05 - 000050624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2017-10-30 19:01 - 2017-10-27 11:50 - 001989056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438813.dll
2017-10-30 19:01 - 2017-10-27 11:50 - 001673848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438813.dll
2017-10-29 15:25 - 2017-11-05 11:09 - 000001198 _____ C:\Users\Jeff\Desktop\adwcleaner 7.0.4.0.lnk
2017-10-28 07:55 - 2017-10-28 07:55 - 000000000 ____D C:\Users\Jeff\AppData\Local\NVIDIA
2017-10-28 07:54 - 2017-11-22 17:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-10-28 07:54 - 2017-11-21 17:54 - 000001489 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2017-10-28 07:54 - 2017-11-21 17:54 - 000000000 ____D C:\Users\Jeff\AppData\Local\NVIDIA Corporation
2017-10-28 07:54 - 2017-11-15 19:41 - 002404800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2017-10-28 07:54 - 2017-11-15 19:41 - 002070976 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2017-10-28 07:54 - 2017-11-15 19:41 - 001309120 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvRtmpStreamer64.dll
2017-10-28 07:54 - 2017-11-15 19:41 - 000186304 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2017-10-28 07:54 - 2017-11-15 19:41 - 000152512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2017-10-28 07:54 - 2017-10-12 15:38 - 001755072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2017-10-28 07:54 - 2017-10-12 15:38 - 001317312 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2017-10-28 07:53 - 2017-11-14 14:15 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-10-28 07:53 - 2017-11-14 13:56 - 005960640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-10-28 07:53 - 2017-11-14 13:56 - 002587584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2017-10-28 07:53 - 2017-11-14 13:56 - 001766336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-10-28 07:53 - 2017-11-14 13:56 - 000607352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2017-10-28 07:53 - 2017-11-14 13:56 - 000449472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-10-28 07:53 - 2017-11-14 13:56 - 000123000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-10-28 07:53 - 2017-11-14 13:56 - 000082040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-10-28 07:53 - 2017-11-10 00:09 - 007855841 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-10-28 07:49 - 2017-10-12 15:38 - 001988032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438800.dll
2017-10-28 07:49 - 2017-10-12 15:38 - 001606592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438800.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-25 19:56 - 2016-03-28 17:48 - 000091859 _____ C:\WINDOWS\ZAM.krnl.trace
2017-11-25 19:56 - 2016-03-28 17:48 - 000063947 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2017-11-25 19:56 - 2015-03-24 20:04 - 000000000 ____D C:\FRST
2017-11-25 19:54 - 2015-03-07 16:45 - 000000000 ____D C:\WINDOWS\CryptoGuard
2017-11-25 19:51 - 2016-11-18 19:04 - 000000000 ____D C:\Users\Jeff\AppData\LocalLow\Mozilla
2017-11-25 19:50 - 2017-10-19 18:18 - 000000000 ____D C:\Program Files\Emsisoft Anti-Malware
2017-11-25 19:49 - 2014-10-03 20:25 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2017-11-25 19:48 - 2017-05-11 09:33 - 000000000 ____D C:\ProgramData\NVIDIA
2017-11-25 19:48 - 2015-04-18 10:16 - 000000000 ____D C:\Games
2017-11-25 19:44 - 2017-08-02 17:26 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MB3SwissArmy.sys
2017-11-25 19:30 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2017-11-25 17:17 - 2016-03-14 18:37 - 000000000 ____D C:\easeus_tb_cloud
2017-11-25 01:32 - 2017-09-29 02:45 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2017-11-24 21:06 - 2017-09-29 07:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-11-24 20:45 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-11-24 20:39 - 2017-09-29 07:46 - 000000000 ___HD C:\Program Files\WindowsApps
2017-11-24 20:36 - 2017-09-29 07:46 - 000000000 ___RD C:\WINDOWS\PrintDialog
2017-11-24 19:56 - 2017-04-26 18:34 - 001287040 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2017-11-24 17:38 - 2014-07-04 11:57 - 000000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
2017-11-24 17:37 - 2016-04-06 13:19 - 000000000 ____D C:\Users\TEMP
2017-11-24 17:28 - 2015-11-26 09:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2017-11-24 17:28 - 2015-11-26 09:00 - 000000000 ____D C:\Program Files (x86)\Tweaking.com
2017-11-24 16:48 - 2009-07-13 20:34 - 000002132 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_379
2017-11-24 16:30 - 2014-02-12 19:26 - 000000000 ____D C:\AdwCleaner
2017-11-23 21:31 - 2015-05-16 09:52 - 000000000 ____D C:\Users\Jeff\AppData\Local\ElevatedDiagnostics
2017-11-23 21:27 - 2017-09-29 07:44 - 000000000 ____D C:\WINDOWS\INF
2017-11-23 20:30 - 2014-07-04 11:45 - 000192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-11-23 11:43 - 2015-09-12 11:44 - 000000000 ____D C:\mbar
2017-11-23 11:43 - 2014-08-19 19:40 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-11-23 11:03 - 2014-07-04 11:45 - 000109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2017-11-23 07:39 - 2014-11-02 17:54 - 000000000 ____D C:\Users\Jeff\AppData\LocalLow\Adblock Plus for IE
2017-11-23 04:01 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\appcompat
2017-11-22 18:59 - 2017-09-29 07:46 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-11-22 18:57 - 2017-10-20 19:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2017-11-22 18:57 - 2017-10-20 19:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-11-22 18:57 - 2017-10-19 18:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cybereason RansomFree
2017-11-22 18:57 - 2017-10-19 18:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2017-11-22 18:57 - 2017-09-29 07:49 - 000000000 ____D C:\WINDOWS\Setup
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 __SHD C:\Program Files\Windows Sidebar
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\system32\spool
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\system32\oobe
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\system32\IME
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\schemas
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\Help
2017-11-22 18:57 - 2017-09-29 07:46 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2017-11-22 18:57 - 2017-09-04 19:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2017-11-22 18:57 - 2017-08-21 18:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2017-11-22 18:57 - 2017-08-20 06:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 12.5
2017-11-22 18:57 - 2017-08-02 17:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-11-22 18:57 - 2017-06-04 09:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ChrisPC Win Experience Index
2017-11-22 18:57 - 2017-04-26 18:33 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-11-22 18:57 - 2017-04-16 13:05 - 000000000 ____D C:\Program Files\UNP
2017-11-22 18:57 - 2017-03-18 15:03 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2017-11-22 18:57 - 2017-03-16 13:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Westwood Online
2017-11-22 18:57 - 2017-03-16 13:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Command and Conquer Renegade
2017-11-22 18:57 - 2017-03-04 10:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Todo Backup 10.5
2017-11-22 18:57 - 2017-02-10 19:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Node.js
2017-11-22 18:57 - 2017-01-28 07:17 - 000000000 ____D C:\WINDOWS\system32\RAPID
2017-11-22 18:57 - 2017-01-28 07:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician
2017-11-22 18:57 - 2016-12-23 15:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TurboTax 2016
2017-11-22 18:57 - 2016-10-02 05:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vox Populi
2017-11-22 18:57 - 2016-08-10 17:23 - 000000000 ____D C:\WINDOWS\system32\MpEngineStore
2017-11-22 18:57 - 2016-08-07 14:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2017-11-22 18:57 - 2016-08-06 16:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2017-11-22 18:57 - 2016-05-25 18:29 - 000000000 ____D C:\WINDOWS\SysWOW64\1033
2017-11-22 18:57 - 2016-03-29 20:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DiskCheckup
2017-11-22 18:57 - 2016-03-28 20:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foolish IT
2017-11-22 18:57 - 2016-03-28 17:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiLogger Free
2017-11-22 18:57 - 2016-03-20 06:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2017-11-22 18:57 - 2016-02-14 15:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unchecky
2017-11-22 18:57 - 2016-02-13 07:03 - 000000000 ____D C:\WINDOWS\ShellNew
2017-11-22 18:57 - 2016-01-29 12:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Community Patch Project
2017-11-22 18:57 - 2015-03-19 19:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2017-11-22 18:57 - 2015-03-07 16:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro.Alert
2017-11-22 18:57 - 2015-01-24 14:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Age of Wonders
2017-11-22 18:57 - 2014-12-22 15:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2017-11-22 18:57 - 2014-10-31 19:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uninstall Java Runtime and Options
2017-11-22 18:57 - 2014-10-17 17:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-11-22 18:57 - 2014-07-04 11:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit
2017-11-22 18:57 - 2014-07-04 11:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2017-11-22 18:57 - 2014-05-17 15:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2017-11-22 18:57 - 2014-03-19 19:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Scan
2017-11-22 18:57 - 2013-11-11 20:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft DirectX SDK (June 2010)
2017-11-22 18:57 - 2013-07-15 19:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JMicron Technology Corp
2017-11-22 18:57 - 2013-07-10 19:14 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-11-22 18:57 - 2013-03-26 19:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\D-Fend Reloaded
2017-11-22 18:57 - 2013-03-26 19:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DOSBox-0.74
2017-11-22 18:57 - 2013-01-24 20:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2017-11-22 18:57 - 2012-12-23 14:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Expression
2017-11-22 18:57 - 2012-12-23 13:08 - 000000000 ____D C:\WINDOWS\SysWOW64\color
2017-11-22 18:57 - 2012-12-23 13:08 - 000000000 ____D C:\WINDOWS\SysWOW64\BWKDLogs
2017-11-22 18:57 - 2012-12-23 12:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2017-11-22 18:57 - 2012-12-23 12:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintKey2000
2017-11-22 18:57 - 2012-12-23 11:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
2017-11-22 18:57 - 2012-12-23 10:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2017-11-22 18:57 - 2012-12-23 10:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
2017-11-22 18:57 - 2011-11-18 21:16 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2017-11-22 18:57 - 2009-07-13 23:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-11-22 18:57 - 2009-07-13 23:32 - 000000000 ____D C:\Program Files\Microsoft Games
2017-11-22 18:45 - 2012-12-23 15:09 - 000001358 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2017-11-22 18:07 - 2015-01-06 18:53 - 000000000 ____D C:\Users\Jeff\AppData\Roaming\Notepad++
2017-11-22 18:07 - 2014-10-03 22:00 - 000000000 ____D C:\Users\Jeff\AppData\Roaming\TeamViewer
2017-11-22 18:06 - 2012-12-23 10:59 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-11-22 18:01 - 2012-12-23 09:06 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-11-22 18:01 - 2012-12-23 09:06 - 000000000 ___HD C:\Program Files (x86)\Creative Installation Information
2017-11-22 18:01 - 2012-12-23 09:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
2017-11-22 18:01 - 2012-12-23 09:06 - 000000000 ____D C:\Program Files\Creative
2017-11-22 18:00 - 2012-12-23 09:06 - 000000000 ____D C:\Program Files (x86)\Creative
2017-11-22 17:58 - 2015-07-17 19:31 - 000000258 __RSH C:\ProgramData\ntuser.pol
2017-11-22 17:35 - 2016-03-16 16:14 - 000002401 _____ C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-11-22 17:35 - 2016-03-16 16:14 - 000000000 ___RD C:\Users\Jeff\OneDrive
2017-11-22 17:30 - 2016-03-16 16:07 - 000000000 ____D C:\Users\Jeff\AppData\Local\TileDataLayer
2017-11-22 17:30 - 2016-02-13 07:20 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-11-22 17:28 - 2017-09-29 02:45 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2017-11-22 17:17 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\Registration
2017-11-22 17:17 - 2012-12-23 17:31 - 000032220 _____ C:\WINDOWS\system32\emptyregdb.dat
2017-11-22 17:16 - 2017-09-29 07:46 - 000000000 __RSD C:\WINDOWS\media
2017-11-22 17:14 - 2015-03-21 15:30 - 000002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-11-22 17:14 - 2015-03-21 15:30 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-11-22 17:10 - 2017-09-29 07:46 - 000000000 ____D C:\ProgramData\USOPrivate
2017-11-22 17:10 - 2016-08-07 14:40 - 000000000 ____D C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2017-11-22 17:10 - 2016-03-17 07:33 - 000000000 ____D C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2017-11-22 17:10 - 2016-03-17 07:33 - 000000000 ____D C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2017-11-22 17:10 - 2013-11-09 09:07 - 000000000 ____D C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2017-11-22 17:09 - 2017-09-29 07:46 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-11-22 17:08 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2017-11-22 17:08 - 2013-05-11 15:36 - 000000000 ____D C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slitherine
2017-11-22 17:02 - 2017-09-29 02:45 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2017-11-22 17:02 - 2017-05-11 09:33 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2017-11-22 17:02 - 2013-01-14 21:23 - 000000000 ____D C:\Temp
2017-11-22 17:01 - 2017-04-26 18:33 - 000000159 ___RH C:\WINDOWS\ctfile.rfc
2017-11-22 17:01 - 2017-04-26 18:33 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2017-11-22 17:01 - 2017-04-26 18:33 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2017-11-22 16:52 - 2017-09-29 07:46 - 000000000 __RHD C:\Users\Public\Libraries
2017-11-22 16:23 - 2017-08-20 05:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Samsung
2017-11-22 16:23 - 2017-08-05 05:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macrium
2017-11-22 16:23 - 2016-04-06 13:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2017-11-22 16:23 - 2016-03-29 20:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital Corporation
2017-11-22 16:23 - 2016-03-19 05:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan 1.0.3.0
2017-11-22 16:23 - 2015-10-31 12:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Black Isle
2017-11-22 16:23 - 2014-03-19 19:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson
2017-11-22 16:23 - 2013-12-25 15:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2017-11-22 16:23 - 2013-05-11 15:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Slitherine
2017-11-22 16:23 - 2012-12-23 13:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak
2017-11-22 16:22 - 2017-04-26 18:33 - 000000000 ____D C:\Program Files\Realtek
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\tk-TM
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\sw-KE
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\si-LK
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\prs-AF
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\mn-MN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\ky-KG
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-BD
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\tk-TM
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\te-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\ta-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\sw-KE
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\si-LK
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\prs-AF
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\or-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\mn-MN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\ky-KG
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\km-KH
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\is-IS
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\id-ID
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\bn-BD
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\be-BY
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\as-IN
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\am-ET
2017-11-22 16:07 - 2017-09-29 08:42 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2017-11-22 16:07 - 2017-09-29 07:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-11-22 16:07 - 2017-09-29 07:46 - 000000000 ___SD C:\WINDOWS\system32\F12
2017-11-22 16:07 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\TextInput
2017-11-22 16:07 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-11-22 16:07 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-11-22 16:07 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\system32\appraiser
2017-11-22 16:07 - 2017-09-29 02:45 - 000000000 ____D C:\WINDOWS\system32\Dism
2017-11-22 15:51 - 2017-09-29 07:46 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2017-11-22 15:50 - 2017-09-29 07:43 - 000613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2017-11-22 15:50 - 2017-09-29 07:43 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2017-11-22 15:50 - 2017-09-29 07:43 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2017-11-22 15:50 - 2017-09-29 07:43 - 000204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2017-11-22 15:50 - 2017-09-29 07:43 - 000172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2017-11-22 15:50 - 2017-09-29 07:43 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2017-11-22 15:50 - 2017-09-29 07:43 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2017-11-22 15:50 - 2017-09-29 07:43 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2017-11-22 15:50 - 2017-09-29 07:43 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2017-11-22 15:50 - 2017-09-29 07:43 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2017-11-22 15:50 - 2017-09-29 07:43 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2017-11-22 15:50 - 2017-09-29 07:43 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2017-11-22 15:50 - 2017-09-29 07:43 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2017-11-22 15:50 - 2017-09-29 07:43 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2017-11-22 15:50 - 2017-09-29 07:43 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2017-11-22 15:50 - 2017-09-29 07:43 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll
2017-11-22 15:50 - 2017-09-29 07:43 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2017-11-22 15:50 - 2017-09-29 07:43 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngkeyhelper.dll
2017-11-22 15:50 - 2017-09-29 07:43 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2017-11-22 15:50 - 2017-09-29 07:43 - 000009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2017-11-22 15:50 - 2017-09-29 07:42 - 000054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2017-11-22 15:50 - 2017-09-29 07:42 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2017-11-22 15:50 - 2017-09-29 07:42 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2017-11-22 15:50 - 2017-09-29 07:42 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 001381888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000464896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2017-11-22 15:50 - 2017-09-29 07:41 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2017-11-22 15:50 - 2017-09-29 07:41 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2017-11-22 15:50 - 2017-09-29 07:41 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2017-11-22 15:50 - 2017-09-29 07:41 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2017-11-22 15:50 - 2017-09-29 07:41 - 000046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2017-11-22 15:50 - 2017-09-29 07:41 - 000026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe
2017-11-22 15:50 - 2017-09-29 07:41 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2017-11-22 15:50 - 2017-09-29 07:41 - 000024576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe
2017-11-22 15:50 - 2017-09-29 07:41 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe
2017-11-22 15:50 - 2017-09-29 07:41 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2017-11-22 15:50 - 2017-09-29 07:41 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll
2017-11-22 15:50 - 2017-09-29 07:41 - 000005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll
2017-11-22 13:57 - 2015-03-26 21:01 - 000000000 ____D C:\WINDOWS\softwaredistribution.bak
2017-11-22 08:21 - 2013-01-24 20:44 - 000000000 ____D C:\Users\Jeff\AppData\Roaming\FileZilla
2017-11-21 08:08 - 2015-05-15 17:13 - 000000000 ____D C:\BWS
2017-11-20 18:52 - 2017-10-10 18:51 - 127017032 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2017-11-20 18:52 - 2014-07-15 21:56 - 127017032 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-11-20 18:28 - 2010-11-20 21:27 - 000545440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-11-19 16:44 - 2009-11-15 16:40 - 000000000 ____D C:\Users\Jeff\Documents\Building a Computer
2017-11-17 20:37 - 2012-12-23 10:28 - 000000000 ____D C:\ProgramData\TEMP
2017-11-17 20:37 - 2012-12-23 10:28 - 000000000 ____D C:\Program Files (x86)\SpywareBlaster
2017-11-16 19:58 - 2017-06-18 06:11 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-11-16 19:58 - 2015-04-21 18:18 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-11-16 19:57 - 2012-12-23 10:51 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-11-16 19:48 - 2015-04-21 18:18 - 000001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-11-16 19:48 - 2015-04-21 18:18 - 000000000 ____D C:\Users\Jeff\AppData\Roaming\Mozilla
2017-11-16 13:48 - 2014-12-22 15:03 - 000000000 ____D C:\Program Files (x86)\Origin
2017-11-16 12:48 - 2014-07-04 11:57 - 000000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Exploit
2017-11-15 18:53 - 2017-04-06 19:19 - 000001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat
2017-11-10 19:27 - 2016-12-15 06:50 - 000000000 ____D C:\Users\Jeff\AppData\Local\FileZilla
2017-11-10 19:27 - 2013-01-24 20:44 - 000000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2017-11-08 22:37 - 2017-09-07 17:16 - 000077440 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-11-05 17:43 - 2014-12-22 15:03 - 000000000 ____D C:\ProgramData\Origin
2017-11-05 15:45 - 2009-11-15 16:50 - 000000000 ____D C:\Users\Jeff\Documents\Retirement
2017-11-05 14:17 - 2009-11-15 16:43 - 000000000 ____D C:\Users\Jeff\Documents\Lynn
2017-11-05 13:32 - 2014-12-22 15:05 - 000000000 ____D C:\Users\Jeff\AppData\Roaming\Origin
2017-11-05 11:05 - 2013-07-17 19:13 - 000001220 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
2017-11-05 11:05 - 2013-07-17 19:13 - 000001178 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2017-11-05 11:05 - 2013-01-19 15:08 - 000000000 ____D C:\Program Files (x86)\CDBurnerXP
2017-11-04 19:20 - 2016-08-07 14:35 - 000000599 _____ C:\Users\Public\Desktop\Steam.lnk
2017-11-03 19:25 - 2017-09-29 07:49 - 000835568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-11-03 19:25 - 2017-09-29 07:49 - 000177648 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-11-03 10:44 - 2015-02-14 14:27 - 000000000 ____D C:\Users\Jeff\AppData\Local\TeamViewer

==================== Files in the root of some directories =======

2017-11-25 07:33 - 2017-11-25 07:33 - 000000036 _____ () C:\Users\Jeff\AppData\Local\housecall.guid.cache
2016-06-03 20:48 - 2016-06-03 20:48 - 000000017 _____ () C:\Users\Jeff\AppData\Local\resmon.resmoncfg
2017-11-25 07:47 - 2017-11-25 07:47 - 000000010 _____ () C:\Users\Jeff\AppData\Local\sponge.last.runtime.cache

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-11-22 17:00

==================== End of FRST.txt ============================


Google is my friend. Make Google your friend too.


#4 Torvald

Torvald
  • Topic Starter

  • Members
  • 366 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Antonio, TX USA
  • Local time:05:19 AM

Posted 25 November 2017 - 10:14 PM

Here is the first part of my Additions.txt file:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-11-2017 01
Ran by Jeff (25-11-2017 19:57:51)
Running from C:\Users\Jeff\Downloads
Windows 10 Home Version 1709 16299.64 (X64) (2017-11-22 23:30:00)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-4089348763-2620558389-2721033571-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4089348763-2620558389-2721033571-503 - Limited - Disabled)
Guest (S-1-5-21-4089348763-2620558389-2721033571-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4089348763-2620558389-2721033571-1009 - Limited - Enabled)
Jeff (S-1-5-21-4089348763-2620558389-2721033571-1001 - Administrator - Enabled) => C:\Users\Jeff
WDAGUtilityAccount (S-1-5-21-4089348763-2620558389-2721033571-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov)
Adblock Plus for IE (32-bit and 64-bit) (HKLM\...\{0F347A49-E36C-4639-8D2E-003AD408B8B2}) (Version: 1.5 - Eyeo GmbH)
Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.187 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.23) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.23 - Adobe Systems Incorporated)
Age of Wonders (HKLM-x32\...\Age of Wonders) (Version:  - )
AntiLogger Free version 1.8.2.320 (HKLM-x32\...\{A80DB23D-0618-405B-89D9-28F99814E287}_is1) (Version: 1.8.2.320 - Zemana Ltd.)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Baldur's Gate (HKLM-x32\...\Baldur's Gate) (Version:  - )
Baldur's Gate™ II - Throne of Bhaal ™ (HKLM-x32\...\{B8C3B479-1716-11D5-968A-0050BA84F5F7}) (Version:  - )
Belarc Advisor 8.5c (HKLM-x32\...\Belarc Advisor) (Version: 8.5.3.0 - Belarc Inc.)
CardRd81 (HKLM-x32\...\{54C8FE84-89C4-40E8-976C-439EB0729BD6}) (Version: 4.00.0000.0004 - EASTMAN KODAK Company) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.37 - Piriform)
CCScore (HKLM-x32\...\{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}) (Version: 5.00.0000.0011 - EASTMAN KODAK Company) Hidden
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.8.6795 - CDBurnerXP)
ChrisPC Win Experience Index 4.80 (HKLM-x32\...\{1116089C-14B5-1A23-8113-6124567ABCDE}_is1) (Version:  - Chris P.C. srl)
Citrix Online Launcher (HKLM-x32\...\{1EFF9E6C-76E1-43F9-81FB-BC8C037B0902}) (Version: 1.0.258 - Citrix)
Classic Shell (HKLM\...\{CABCE573-0A86-42FA-A52A-C7EA61D5BE08}) (Version: 4.3.1 - IvoSoft)
Command & Conquer™ Renegade (HKLM-x32\...\{97B5E8B9-D5E6-49C4-8CDA-7E096BE2601A}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CR2 (HKLM-x32\...\{432C3720-37BF-4BD7-8E49-F38E090246D0}) (Version: 4.00.0000.0003 - EASTMAN KODAK Company) Hidden
Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.45 - Creative Technology Limited)
Creative Audio Control Panel (HKLM-x32\...\AudioCS) (Version: 2.56 - Creative Technology Limited)
Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.26 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version:  - )
Creative WaveStudio 7 (HKLM-x32\...\WaveStudio 7) (Version: 7.14 - Creative Technology Limited)
CryptoPrevent (HKLM-x32\...\{5C5B24E7-4694-4049-A222-CCE7D3FAC63F}_is1) (Version:  - Foolish IT LLC)
CrystalDiskInfo 6.3.0 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 6.3.0 - Crystal Dew World)
Cybereason RansomFree 2.4.1.0 (HKLM-x32\...\{88BF86F8-A656-4397-B4CE-9C5956E82B1A}) (Version: 2.4.1.0 - Cybereason Inc.)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Data Lifeguard Diagnostic for Windows 1.28 (HKLM-x32\...\{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1) (Version:  - Western Digital Corporation)
Defraggler (HKLM\...\Defraggler) (Version: 2.21 - Piriform)
D-Fend Reloaded 1.3.3 (deinstall) (HKLM-x32\...\D-Fend Reloaded) (Version: 1.4.4 - Alexander Herzog)
DiskCheckup v3.2 (HKLM-x32\...\DiskCheckup_is1) (Version: 3.2.1000 - PassMark Software)
EaseUS Partition Master 12.5 (HKLM-x32\...\EaseUS Partition Master_is1) (Version:  - EaseUS)
EaseUS Todo Backup Free 10.5 (HKLM-x32\...\EaseUS Todo Backup_is1) (Version: 10.5 - CHENGDU YIWO Tech Development Co., Ltd)
Emsisoft Anti-Malware (HKLM\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 2017.4 - Emsisoft Ltd.)
EPSON Perfection V500P User's Guide (HKLM-x32\...\Silent Package Run-Time Sample) (Version:  - )
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
ESSBrwr (HKLM-x32\...\{643EAE81-920C-4931-9F0B-4B343B225CA6}) (Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
ESSCDBK (HKLM-x32\...\{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}) (Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
ESScore (HKLM-x32\...\{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}) (Version: 5.00.0000.0037 - EASTMAN KODAK Company) Hidden
ESSCT (HKLM-x32\...\{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}) (Version: 5.00.0000.0003 - EASTMAN KODAK Company) Hidden
ESSgui (HKLM-x32\...\{91517631-A9F3-4B7C-B482-43E0068FD55A}) (Version: 5.00.0000.0013 - EASTMAN KODAK Company) Hidden
ESShelp (HKLM-x32\...\{87843A41-7808-4F2E-B13F-25C1E67CF2FD}) (Version: 5.00.0000.0005 - EASTMAN KODAK Company) Hidden
ESSini (HKLM-x32\...\{8E92D746-CD9F-4B90-9668-42B74C14F765}) (Version: 5.00.0000.0010 - EASTMAN KODAK Company) Hidden
ESSPCD (HKLM-x32\...\{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}) (Version: 5.00.0000.0007 - EASTMAN KODAK Company) Hidden
ESSPDock (HKLM-x32\...\{FCDB1C92-03C6-4C76-8625-371224256091}) (Version: 5.00.0000.0020 - EASTMAN KODAK Company) Hidden
ESSSONIC (HKLM-x32\...\{4F677FC7-7AA8-412B-A957-F13CBE1C7331}) (Version: 5.00.0000.0002 - EASTMAN KODAK Company) Hidden
ESSTOOLS (HKLM-x32\...\{8A502E38-29C9-49FA-BCFA-D727CA062589}) (Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
ESSTUTOR (HKLM-x32\...\{CA60320D-6A16-49C8-A34F-84EEF4799567}) (Version: 5.00.0000.0002 - EASTMAN KODAK Company) Hidden
ESSvpaht (HKLM-x32\...\{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
ESSvpot (HKLM-x32\...\{48C82F7A-F100-4DAB-A310-8E18BF2159E1}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
FileZilla Client 3.29.0 (HKLM-x32\...\FileZilla Client) (Version: 3.29.0 - Tim Kosse)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 62.0.3202.94 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
GSmartControl (HKLM-x32\...\GSmartControl) (Version: 0.8.7 - Alexander Shaduri)
HellBlazers Maps Pack v7.2 (HKLM-x32\...\{23A6446B-F12A-427D-9EC9-7CB2B4C5B5B8}) (Version: 7.2 - HellBlazer)
HitmanPro.Alert (HKLM\...\HitmanPro.Alert) (Version: 2.6.5.77 - SurfRight B.V.)
HLPIndex (HKLM-x32\...\{38441BE7-79B0-42B8-8297-833704F949FE}) (Version: 5.00.0000.0002 - EASTMAN KODAK Company) Hidden
HLPPDOCK (HKLM-x32\...\{154508C0-07C5-4659-A7A0-E49968750D21}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
HLPRFO (HKLM-x32\...\{AADAC983-FDE9-42FA-8FD9-7BB324155593}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
Internet Explorer (Enable DEP) (HKLM\...\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb) (Version:  - )
Java 8 Update 151 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180151F0}) (Version: 8.0.1510.12 - Oracle Corporation)
Java Runtime and Options (HKLM\...\Java_Runtime_and_Options) (Version: 1.0 - Java Runtime)
JMicron JMB36X Driver (HKLM-x32\...\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}) (Version: 1.17.65.11 - JMicron Technology Corp.)
Junk Mail filter update (HKLM-x32\...\{0BE9E708-5DC0-4963-9CFD-0AA519090E79}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Kodak EasyShare software (HKLM-x32\...\{D32470A1-B10C-4059-BA53-CF0486F68EBC}) (Version:  - Eastman Kodak Company)
KSU (HKLM-x32\...\{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}) (Version: 632.62.0002.0001 - EASTMAN KODAK Company) Hidden
Macrium Reflect Free Edition (HKLM\...\{6085136C-5E0B-4516-BA48-2B909062778A}) (Version: 6.3.1835 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free Edition (HKLM\...\MacriumReflect) (Version: 6.3 - Paramount Software (UK) Ltd.)
Malwarebytes Anti-Exploit version 1.11.1.40 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.11.1.40 - Malwarebytes)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Malwarebytes Anti-Ransomware version 0.9.18.797 (HKLM\...\{bebf7481-07c5-42f5-941e-2e9f78a76d56}_is1) (Version: 0.9.18.797 - Malwarebytes)
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Age of Empires II (HKLM-x32\...\Age of Empires 2.0) (Version:  - )
Microsoft Age of Empires II: The Conquerors Expansion (HKLM-x32\...\Age of Empires II: The Conquerors Expansion 1.0) (Version:  - )
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft DirectX SDK (June 2010) (HKLM-x32\...\Microsoft DirectX SDK (June 2010)) (Version: 9.29.1962.0 - Microsoft Corporation)
Microsoft Expression Encoder 4 Screen Capture Codec (HKLM-x32\...\{BF127B80-CFD5-4379-9752-E8AF1A5D0141}) (Version: 4.0.1639.0 - Microsoft Corporation)
Microsoft Expression Web 4 (HKLM-x32\...\Web_4.0.1303.0) (Version: 4.0.1303.0 - Microsoft Corporation)
Microsoft Expression Web 4 Service Pack 2 (HKLM-x32\...\{F5993FCC-DF5D-4879-B70D-AA1F379C5C6B}) (Version:  - Microsoft Corporation)
Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Small Business 2007 (HKLM-x32\...\SMALLBUSINESSR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\OneDriveSetup.exe) (Version: 17.3.7076.1026 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{77F1F8AD-51B8-4490-AEEC-BF480073E0FC}) (Version: 10.50.1750.9 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\...\{877B76B2-F83F-4F5A-B28D-3F398641ADB6}) (Version: 10.50.1750.9 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Runtime - 10.0.40219 (HKLM\...\{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Service Pack 1 (HKLM-x32\...\Microsoft Visual Studio 2010 Service Pack 1) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Shell (Isolated) - ENU (HKLM-x32\...\{D64B6984-242F-32BC-B008-752806E5FC44}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Works 6-9 Converter (HKLM-x32\...\{95140000-0137-0409-0000-0000000FF1CE}) (Version: 14.0.6120.5002 - Microsoft Corporation)
Mozilla Firefox 57.0 (x64 en-US) (HKLM\...\Mozilla Firefox 57.0 (x64 en-US)) (Version: 57.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 57.0.0.6525 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Node.js (HKLM\...\{6BA2207A-7E42-434C-8DD4-A2FFC1D9EA68}) (Version: 7.5.0 - Node.js Foundation)
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.5.1 - Notepad++ Team)
Notifier (HKLM-x32\...\{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.11.0.73 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.11.0.73 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Origin (HKLM-x32\...\Origin) (Version: 10.5.6.6235 - Electronic Arts, Inc.)
OTtBP (HKLM-x32\...\{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}) (Version: 5.00.0000.0003 - EASTMAN KODAK Company) Hidden
OTtBPSDK (HKLM-x32\...\{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}) (Version: 4.00.0000.0000 - EASTMAN KODAK Company) Hidden
Panzer Corps (HKLM-x32\...\Panzer Corps) (Version: 1.26 - Slitherine)
Panzer Corps Afrika Korps (HKLM-x32\...\Panzer Corps Afrika Korps1.10) (Version: 1.10 - Slitherine)
Panzer Corps Allied Corps (HKLM-x32\...\Panzer Corps Allied Corps1.20) (Version: 1.20 - Slitherine)
Panzer Corps Grand Campaign MegaPack 39-45 (HKLM-x32\...\Panzer Corps Grand Campaign MegaPack 39-451.14) (Version: 1.14 - Slitherine)
PrintKey2000 (HKLM-x32\...\PrintKey2000) (Version:  - )
RAPID Mode (HKLM\...\{4B94C023-022A-4271-A1D6-744ABE74D220}) (Version: 1.0.0.97 - Samsung Electronics Co., Ltd.) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.86.508.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7324 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
Revo Uninstaller 2.0.4 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.4 - VS Revo Group, Ltd.)
Samsung Data Migration (HKLM-x32\...\{3B304604-0BF5-488E-AB95-F2F2E31206F3}) (Version: 3.1 - Samsung)
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 5.0.0.790 - Samsung Electronics)
SFR (HKLM-x32\...\{DB02F716-6275-42E9-B8D2-83BA2BF5100B}) (Version: 5.00.0000.0005 - Eastman Kodak Company) Hidden
SHASTA (HKLM-x32\...\{605A4E39-613C-4A12-B56F-DEFBE6757237}) (Version: 5.00.0000.0003 - EASTMAN KODAK Company) Hidden
Sid Meier's Civilization V (HKLM-x32\...\steam app 8930) (Version:  - 2K Games, Inc.)
SKIN0001 (HKLM-x32\...\{FDF9943A-3D5C-46B3-9679-586BD237DDEE}) (Version: 5.00.0000.0007 - EASTMAN KODAK Company) Hidden
SKINXSDK (HKLM-x32\...\{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}) (Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
Speccy (HKLM\...\Speccy) (Version: 1.31 - Piriform)
SpywareBlaster 5.5 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.5.0 - BrightFort LLC)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1250 - SUPERAntiSpyware.com)
System Requirements Lab (HKLM-x32\...\{A92D0DBB-834A-4CAD-A434-F2232C692516}) (Version: 6.1.4.0 - Husdawg, LLC)
TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.0.3711 Beta - TeamViewer)
TurboTax 2016 (HKLM-x32\...\TurboTax 2016) (Version: 2016.0 - Intuit, Inc)
TWC Customer Controls (HKLM-x32\...\{A2E5F2AA-2996-41EA-BCCD-9FD0476A5326}) (Version: 11 - SupportSoft)
Tweaking.com - Registry Compressor (HKLM-x32\...\Tweaking.com - Registry Compressor) (Version: 1.1.0 - Tweaking.com)
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 4.0.10 - Tweaking.com)
Unchecky v1.1 (HKLM-x32\...\Unchecky) (Version: 1.1 - Reason Software Company Inc.)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
VPRINTOL (HKLM-x32\...\{999D43F4-9709-4887-9B1A-83EBB15A8370}) (Version: 5.00.0000.0002 - EASTMAN KODAK Company) Hidden
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
WestwoodOnline (HKLM-x32\...\{BBCD6D56-8A26-4DDE-9482-DBC9C7B7341D}) (Version: 1.0.0.0 - WestwoodOnline)
Windows 7 Games for Windows 8 and 10 (HKLM-x32\...\MicrosoftGamesForWin8) (Version: 1.1.0.10 - )
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WIRELESS (HKLM-x32\...\{F9593CFB-D836-49BC-BFF1-0E669A411D9F}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
Zemana AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.74.0.150 - Zemana Ltd.)
Zip Motion Block Video codec (Remove Only) (HKLM-x32\...\ZMBV) (Version:  - DOSBox Team)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (IvoSoft)
ContextMenuHandlers1: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2017-06-15] ()
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2017-08-28] ()
ContextMenuHandlers1: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2015-10-12] (Paramount Software UK Ltd)
ContextMenuHandlers1: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2017-06-23] (CHENGDU YIWO Tech Development Co.,Ltd)
ContextMenuHandlers2-x32: [Emsisoft Shell Extension] -> {AB77609F-2178-4E6F-9C4B-44AC179D937A} => C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2contmenu.dll [2015-10-21] (Emsisoft Ltd)
ContextMenuHandlers2-x32: [Emsisoft Shell Extension x64] -> {E3F21FC7-6D65-48E7-B62B-E9ED8200C764} => C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\A2CONTMENU64.DLL [2015-10-21] (Emsisoft Ltd)
ContextMenuHandlers2-x32: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2015-10-12] (Paramount Software UK Ltd)
ContextMenuHandlers2-x32: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2017-06-23] (CHENGDU YIWO Tech Development Co.,Ltd)
ContextMenuHandlers3-x32: [Emsisoft Shell Extension] -> {AB77609F-2178-4E6F-9C4B-44AC179D937A} => C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2contmenu.dll [2015-10-21] (Emsisoft Ltd)
ContextMenuHandlers3-x32: [Emsisoft Shell Extension x64] -> {E3F21FC7-6D65-48E7-B62B-E9ED8200C764} => C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\A2CONTMENU64.DLL [2015-10-21] (Emsisoft Ltd)
ContextMenuHandlers3-x32: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers4: [EncryptionMenu] -> {A470F8CF-A1E8-4f65-8335-227475AA5C46} =>  -> No File
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd)
ContextMenuHandlers4: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2017-06-23] (CHENGDU YIWO Tech Development Co.,Ltd)
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} =>  -> No File
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-11-14] (NVIDIA Corporation)
ContextMenuHandlers6: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2017-06-15] ()
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
ContextMenuHandlers6-x32: [Emsisoft Shell Extension] -> {AB77609F-2178-4E6F-9C4B-44AC179D937A} => C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2contmenu.dll [2015-10-21] (Emsisoft Ltd)
ContextMenuHandlers6-x32: [Emsisoft Shell Extension x64] -> {E3F21FC7-6D65-48E7-B62B-E9ED8200C764} => C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\A2CONTMENU64.DLL [2015-10-21] (Emsisoft Ltd)
ContextMenuHandlers6-x32: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
ContextMenuHandlers6-x32: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6-x32: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd)
ContextMenuHandlers6-x32: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\WINDOWS\system32\StartMenuHelper64.dll [2017-08-13] (IvoSoft)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {13868895-EC5F-4418-88DE-0B79B0692157} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {1869F3F8-7096-4DC5-A52C-DB74725730F7} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-11-15] (NVIDIA Corporation)
Task: {186E6665-E43E-4DBD-81C1-6DCE34854403} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-11-15] (NVIDIA Corporation)
Task: {1D2B73CD-A4C1-4596-BEF9-4EDF6C954915} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {2345C61C-6FD9-4FD9-885E-32F79C451775} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {239BE7E1-4508-4E7D-AC6F-A8CF2DA5A0A2} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {288787EF-6C92-445F-A147-394C46E3D04D} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2C326DB5-DA25-4EA7-98B1-9622FA0F8B68} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {3028D9D1-04EE-4A15-ABE0-CC307370C878} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-11-08] (Piriform Ltd)
Task: {352D30F9-D337-4588-AE83-784A26B5579B} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {36ABD900-F84D-46EF-B18F-4FF511022FAE} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {408AE6AE-6CE2-4FBF-BD13-834691EA07F4} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {41D4817D-2EE8-498E-91CE-F2843CD3B4F0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {506D0062-8910-4D44-8C15-92B8200B9791} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {55C6781C-BCE4-4236-9699-95736DDE722B} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-11-15] (NVIDIA Corporation)
Task: {58C5FB62-EE02-40B7-98A8-05A7845F83B0} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [2016-11-23] (Samsung Electronics Co. Ltd.)
Task: {5CD6A330-E949-4979-A594-7C9D5C876F71} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-11-14] (Adobe Systems Incorporated)
Task: {5D1F8F1B-9723-4175-92A0-DABA462CE062} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {6253823F-AFCB-43B1-AC8B-FD7825F3DD32} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {63D13114-6E19-4080-868A-CAA7A78928F1} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {68EC3B3E-C95B-4D6E-AC59-9A0FC3C5BD06} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6EB3D806-F3D3-460B-9C3D-9E2D9C66DF46} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {7436E3B8-7B5C-4243-B965-C6B3FB236D7D} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {77C481C3-DC58-48B8-8897-D4ED631C880A} - System32\Tasks\Cybereason RansomFree Autostart => C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFree.exe [2017-10-08] (Cybereason)
Task: {79771241-CC31-4EEC-9E11-982F02315C07} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {7C55CE6A-BE8C-41A9-9D8C-3E428327965A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {81A935FC-33D0-4AF7-A5E3-F245727D4404} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-11-15] (NVIDIA Corporation)
Task: {820B1FEB-ACB4-4CCE-A7BD-9BC82CFB8999} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {8B36F6D2-EA48-4367-B17B-6023478E3004} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-11-15] (NVIDIA Corporation)
Task: {8EF9A698-72EB-4312-BFBC-BB7BACB106D4} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {906C8F90-F1D2-46C0-B6DB-814E9B15AA48} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2017-05-02] (Tweaking.com)
Task: {935A0576-765D-4C4F-9056-DC85A113EB6B} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {96A3D389-545F-4572-8540-2AC57478D5ED} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2017-11-08] (Piriform Ltd)
Task: {99DFB1D8-DE1B-4876-A402-C73DC57EDB99} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {A329FE7E-8EF7-4E53-A7E5-DD51D4CF6F94} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-21] (Google Inc.)
Task: {A4EBDDA5-822F-4C42-B880-929F27EBE00B} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {A53D9971-18DD-4A2A-9115-67D03BF96914} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {A8FDDA88-2131-4914-B7B0-A495A1E843FE} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {ABBEB99F-5BD7-4F51-8A30-FD31ECCE9DBB} - System32\Tasks\Cybereason RansomFree Keepalive => C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFree.exe [2017-10-08] (Cybereason)
Task: {B22E3C00-30C6-4A3D-AC74-CF235B811B3A} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {B33A4869-9677-49CE-81EB-5A058CC6AFA0} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {B5260580-6A06-42AA-AB3D-B6C6440612B9} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {B70146CB-87EA-4D36-93E7-FC87C4B576A0} - System32\Tasks\S-1-5-21-4089348763-2620558389-2721033571-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2017-09-29] (Microsoft Corporation)
Task: {B80A1356-574B-421D-9D86-28C12B2CEF8A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-21] (Google Inc.)
Task: {B862864D-29B3-4F3C-A09A-D7E4F783EAA8} - System32\Tasks\{99BF69A3-88A7-4DEE-8FC8-8E2866017869} => C:\Windows\system32\pcalua.exe -a C:\Users\Jeff\Downloads\Intel_RST_MB\Intel_RST_MB\iata_cd.exe -d C:\Users\Jeff\Downloads\Intel_RST_MB\Intel_RST_MB
Task: {B9F08710-4E39-4CE5-9382-336711A9601C} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {BC14581D-84B6-4FE6-888F-A57A14A23A22} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-11-15] (NVIDIA Corporation)
Task: {BD5C1BA2-F828-4AF2-BAC2-E0DBCA8B6911} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-11-15] (NVIDIA Corporation)
Task: {C025019C-2F28-42BF-BF4D-6E99EF77406C} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {C8811EE7-77DA-4858-BAFC-83084440203F} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-11-15] (NVIDIA Corporation)
Task: {C9E6077F-36D4-4630-9172-D8DCBFFB6338} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)
Task: {CC1BCBBF-204A-43A3-8468-5A7C8E4491C2} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {DBF4FA15-8F81-4F0F-B35D-938451EBDA5A} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DFD74129-A271-4AE2-B3D8-B55DC6E4ED00} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
Task: {E761A50A-23DB-4B8C-9D65-CA8EF048C982} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {EA287189-A333-460E-99DA-B685AED7F580} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {F10141D6-724C-4552-99B9-9313B46C4D84} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {F27C6283-AD1A-4B18-B6B8-1047392A09B2} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {F4302394-816E-4E5D-8EC3-32A39B387F6A} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


Google is my friend. Make Google your friend too.


#5 Torvald

Torvald
  • Topic Starter

  • Members
  • 366 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Antonio, TX USA
  • Local time:05:19 AM

Posted 25 November 2017 - 10:16 PM

Here is the rest of my additions.txt file:

 

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


ShortcutWithArgument: C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Ad.Block Plus.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=ohcgafpfnflodmlefikfpfjobidehggm

==================== Loaded Modules (Whitelisted) ==============

2017-10-28 07:54 - 2017-11-15 19:41 - 001267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-09-29 07:41 - 2017-09-29 07:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2017-10-28 07:53 - 2017-11-14 13:56 - 000133752 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-11-06 13:32 - 2017-11-06 13:32 - 000076456 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2017-09-29 07:42 - 2017-09-29 08:43 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-09-29 07:42 - 2017-09-29 08:43 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-08-05 05:24 - 2017-06-19 02:07 - 000259776 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
2017-08-20 06:04 - 2014-11-18 13:44 - 000255072 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 12.5\bin\TrayPopupE\TrayTipAgentE.exe
2017-08-28 18:43 - 2017-08-28 18:43 - 000230064 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2016-03-28 17:48 - 2017-06-15 18:49 - 000155504 _____ () C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll
2017-11-06 13:31 - 2017-11-06 13:31 - 000073384 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
2017-08-05 05:24 - 2017-02-21 16:19 - 000083136 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CodeLog.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000019648 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CompressFile.dll
2017-03-04 10:19 - 2016-12-06 02:44 - 000090816 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBGetRemoteNetInfo.dll
2017-03-04 10:19 - 2016-03-07 18:08 - 001291264 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\libxml2.dll
2017-03-04 10:19 - 2004-10-05 03:08 - 000055808 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\zlib1.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000024768 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CmcTbProxy.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000188608 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CMCPipeCenter.dll
2017-08-05 05:24 - 2017-06-19 02:04 - 000183488 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CMCAdapt.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000163520 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CMCAdapt_RTTO.dll
2017-03-04 10:19 - 2016-12-06 02:44 - 000056000 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBInfo.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000018112 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CMCNetTokenProxy.dll
2017-08-05 05:24 - 2017-06-19 02:04 - 000123584 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ActivationOnline.dll
2017-08-05 05:24 - 2017-06-19 02:05 - 000021696 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\fsclog.dll
2017-08-05 05:24 - 2017-06-19 02:05 - 000085696 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\logsys.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000032960 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DiskSearchImg.dll
2017-08-05 05:24 - 2017-06-19 02:05 - 000070848 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\MountImg.dll
2017-03-04 10:19 - 2016-12-06 02:44 - 000160448 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ImgFile.dll
2017-08-05 05:24 - 2017-06-19 02:04 - 000296640 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DsImgFile.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000078528 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\FatLib.dll
2017-08-05 05:24 - 2017-06-19 02:05 - 000305856 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NTFSUtil.dll
2017-03-04 10:19 - 2016-12-06 02:44 - 000210112 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NTFSLib.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000026304 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CallbackOperator.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000074432 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CheckImg.dll
2017-03-04 10:19 - 2016-12-06 02:44 - 000142016 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\vhdvmdk.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000040128 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\BootDriver.dll
2017-08-05 05:24 - 2017-06-19 02:05 - 000844992 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ExImage.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000195776 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EmailBackupSize.dll
2017-03-04 10:18 - 2016-12-06 02:43 - 000414400 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AndroidImage.dll
2017-08-05 05:24 - 2017-06-19 02:04 - 000162496 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EnumDisk.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000029376 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DeviceAdapter.dll
2017-03-04 10:19 - 2016-12-06 02:44 - 000114368 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\FileStorage.dll
2017-03-04 10:19 - 2016-12-06 02:44 - 000026816 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\GetDriverInfo.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000022720 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CorrectMbr.dll
2017-08-05 05:24 - 2017-06-19 02:04 - 000034496 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EnumTapeDevice.dll
2017-03-04 10:19 - 2016-12-06 02:44 - 000054464 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbTapeBrowse.dll
2017-03-04 10:19 - 2016-12-06 02:44 - 000066240 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\RegLib.dll
2017-08-05 05:24 - 2017-06-19 02:04 - 000026816 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AccountManager.dll
2017-08-05 05:24 - 2017-06-19 02:05 - 000072896 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NasOperator.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000221376 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EmailBrowser.dll
2017-03-04 10:19 - 2016-12-06 02:43 - 000079040 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CloudOperator.dll
2017-03-04 10:18 - 2016-12-06 02:43 - 000020672 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ActiveOnline.dll
2017-03-04 10:19 - 2016-12-06 02:44 - 000138432 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\VMConfig.dll
2017-03-04 10:18 - 2016-12-06 02:43 - 000021696 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AndroidDeviceManager.dll
2017-08-05 05:24 - 2017-06-19 02:05 - 000074944 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\SqlExBrowser.dll
2017-08-05 05:24 - 2017-06-19 02:05 - 000585920 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\SqlSMOCPlusPlus.dll
2017-03-04 10:19 - 2016-12-06 02:44 - 000045248 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbDataSwap.dll
2017-10-28 07:54 - 2017-11-15 19:41 - 001040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-03-04 10:19 - 2016-12-06 02:44 - 000210112 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\SmartBackup.dll
2016-08-07 14:36 - 2017-09-09 13:25 - 000688416 _____ () C:\Games\SDL2.dll
2016-08-07 14:36 - 2016-08-31 19:02 - 004969248 _____ () C:\Games\v8.dll
2016-08-07 14:36 - 2017-10-30 21:22 - 002546976 _____ () C:\Games\video.dll
2016-08-07 14:36 - 2016-08-31 19:02 - 001563936 _____ () C:\Games\icui18n.dll
2016-08-07 14:36 - 2016-08-31 19:02 - 001195296 _____ () C:\Games\icuuc.dll
2016-08-07 14:36 - 2016-01-27 01:49 - 002549760 _____ () C:\Games\libavcodec-56.dll
2016-08-07 14:36 - 2016-01-27 01:49 - 000491008 _____ () C:\Games\libavformat-56.dll
2016-08-07 14:36 - 2016-01-27 01:49 - 000332800 _____ () C:\Games\libavresample-2.dll
2016-08-07 14:36 - 2016-01-27 01:49 - 000442880 _____ () C:\Games\libavutil-54.dll
2016-08-07 14:36 - 2016-01-27 01:49 - 000485888 _____ () C:\Games\libswscale-3.dll
2016-08-07 14:36 - 2017-10-30 21:22 - 000901408 _____ () C:\Games\bin\chromehtml.DLL
2016-08-07 14:36 - 2016-07-04 16:17 - 000266560 _____ () C:\Games\openvr_api.dll
2016-12-12 21:26 - 2017-08-16 16:28 - 073130272 _____ () C:\Games\bin\cef\cef.win7\libcef.dll
2017-06-13 19:50 - 2017-09-06 20:04 - 000678400 _____ () C:\Games\bin\cef\cef.win7\SDL2.dll
2016-08-07 14:36 - 2015-09-24 17:52 - 000119208 _____ () C:\Games\winh264.dll
2017-08-20 06:04 - 2014-02-13 14:27 - 000222792 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 12.5\bin\TrayPopupE\traynet.dll
2017-08-20 06:04 - 2014-02-13 14:27 - 000275528 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 12.5\bin\TrayPopupE\libcurl.dll
2017-08-20 06:04 - 2014-02-13 14:27 - 000113166 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 12.5\bin\TrayPopupE\zlib1.dll
2017-08-20 06:04 - 2014-02-13 14:27 - 000249928 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 12.5\bin\TrayPopupE\uexper.dll
2017-10-28 07:54 - 2017-11-15 19:40 - 066906560 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SprtListen => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SprtListenPush => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKLM\...\batfile\DefaultIcon: %SystemRoot%\SysWow64\imageres.dll,-68 <==== ATTENTION
HKLM\...\cmdfile\DefaultIcon: %SystemRoot%\SysWow64\imageres.dll,-68 <==== ATTENTION
HKLM\...\comfile\DefaultIcon: %SystemRoot%\SysWow64\shell32.dll,2 <==== ATTENTION

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\bankofamerica.com -> bankofamerica.com
IE trusted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\com -> hxxp://www.msi.com
IE trusted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\com.tw -> hxxp://asia.msi.com.tw
IE trusted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\freetoolsassociation.com -> hxxp://activegs.freetoolsassociation.com
IE trusted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\virtualapple.org -> hxxp://www.virtualapple.org
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\1-2005-search.com -> www.1-2005-search.com

There are 11567 more sites.


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 20:34 - 2017-11-25 19:44 - 000002132 _____ C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1       localhost
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 api.recommendedsw.com
0.0.0.0 rp.yefeneri2.com
0.0.0.0 os.yefeneri2.com
0.0.0.0 os2.yefeneri2.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jeff\Pictures\img0.jpg
DNS Servers: 209.18.47.61 - 209.18.47.62
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\StartupFolder: => "Kodak software updater.lnk"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "EaseUS EPM tray"
HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\...\StartupApproved\Run: => "EADM"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{3A98A793-D6DD-47E0-B88D-07C4F6D25949}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{569A16D4-1B50-48C9-9039-9156A92EEEFC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{49831609-ED10-4D6B-89B4-B857A8A7924C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{10974C52-FA6B-4D38-97A8-8156B6B75FB5}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{E78FBA5E-6950-4865-BDF1-90A9EBFBAC74}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{AF14877B-3B9C-48DF-8925-09E4233C51D7}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{EF7BC177-5157-4716-A4DA-17E79CCB5698}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{802E385F-88CB-4970-AECA-D7042AA145A9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{FD4424B8-F2BA-478E-9B9F-225961E7F7B1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{D3EA4DFD-3152-444E-BB29-7AD7EA14452B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [UDP Query User{07403AE8-2EC0-47FE-9F32-00ECA4B88BF6}C:\games\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe] => (Allow) C:\games\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe
FirewallRules: [TCP Query User{0E67F5D0-D5C8-40C6-A936-01E04FE62241}C:\games\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe] => (Allow) C:\games\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe
FirewallRules: [{C4F24742-2694-439C-B7B1-F676E41BCAD9}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{A9791797-B4A4-4F25-8D1C-237536CC18E6}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{7F04C126-2637-4B24-A500-736B5799F763}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{F3424653-A818-4C32-8A95-8EB7970ED918}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{1338D34B-3483-4841-969A-9E16472339D7}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{9ABD2234-1DB6-4B5A-AF73-16B37A04651F}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe
FirewallRules: [{059D98EF-A666-476A-B4F5-B47F45B8409E}] => (Allow) C:\Games\steamapps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{DB72A6A4-1133-4061-8F38-31AC0519FEEA}] => (Allow) C:\Games\steamapps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{4EB8C3C1-AD0C-4C8C-ABD7-2C52B1701FF9}] => (Allow) C:\Games\steamapps\common\Gettysburg the Tide Turns\autorun.exe
FirewallRules: [{A25BEBFB-FB1E-4959-98CE-811C5898001F}] => (Allow) C:\Games\steamapps\common\Gettysburg the Tide Turns\autorun.exe
FirewallRules: [{9A344763-255E-47E8-A11B-9C996955DCCF}] => (Allow) C:\Games\steamapps\common\Gary Grigsby's War in the East\autorun.exe
FirewallRules: [{844D9C9F-E203-475F-8243-FF69A16CFAD8}] => (Allow) C:\Games\steamapps\common\Gary Grigsby's War in the East\autorun.exe
FirewallRules: [{271A5534-F3EA-4189-806D-8EB03645FA76}] => (Allow) C:\Games\steamapps\common\Hearts of Iron IV\hoi4.exe
FirewallRules: [{A6AA912E-D146-4FEF-9206-560595BAF053}] => (Allow) C:\Games\steamapps\common\Hearts of Iron IV\hoi4.exe
FirewallRules: [{5B4C5D46-E099-446B-81CF-79716304D2BC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{C11ABA18-4433-4BAF-8194-75C082B4F63B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{611E62A2-6DDB-4DE3-9A5E-D6FB44DC0295}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{63482A0A-C931-4281-A2BB-529AAE26DE80}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{11DC205D-6F7E-4D5C-B5E1-3D7A20307F0E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{00BC2CDD-046B-4C47-A3EF-2504EED87296}] => (Allow) C:\Games\Steam\SteamApps\common\Stellaris\stellaris.exe
FirewallRules: [{0543228D-AE36-472B-A7F4-2C65421ACD32}] => (Allow) C:\Games\Steam\SteamApps\common\Stellaris\stellaris.exe
FirewallRules: [UDP Query User{1F126F6E-2A75-46D0-9091-06FD0EF6BD48}C:\games\steam\steamapps\common\sid meier's civilization v\civilizationv.exe] => (Allow) C:\games\steam\steamapps\common\sid meier's civilization v\civilizationv.exe
FirewallRules: [TCP Query User{C1B638E4-9A08-4FD1-819C-74BFE20AAAB0}C:\games\steam\steamapps\common\sid meier's civilization v\civilizationv.exe] => (Allow) C:\games\steam\steamapps\common\sid meier's civilization v\civilizationv.exe
FirewallRules: [{DB8A5356-84E5-4057-9186-C84008154974}] => (Allow) C:\Games\Steam\Steam.exe
FirewallRules: [{31BBA42C-A2C6-4920-B834-55D742AF76CA}] => (Allow) C:\Games\Steam\Steam.exe
FirewallRules: [{F68DE8E3-74E0-4B5B-A567-BEA5A4518E6D}] => (Allow) C:\Games\Steam\bin\steamwebhelper.exe
FirewallRules: [{BC54592A-0644-469F-BE90-23C0D150104F}] => (Allow) C:\Games\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{C7E7E610-A8B0-42A7-90CE-2AC5F799FEA8}C:\program files (x86)\slitherine\panzer corps\update.exe] => (Allow) C:\program files (x86)\slitherine\panzer corps\update.exe
FirewallRules: [UDP Query User{3EAF9CB6-9E9D-4889-A495-02AA43AB41BC}C:\program files (x86)\slitherine\panzer corps\update.exe] => (Allow) C:\program files (x86)\slitherine\panzer corps\update.exe
FirewallRules: [{F8906465-EFFF-4EB4-8758-B3809C2CE246}] => (Allow) C:\Games\Steam.exe
FirewallRules: [{DD1ED6CB-31E9-458F-9BE2-72AC2558A560}] => (Allow) C:\Games\Steam.exe
FirewallRules: [{C45F7D96-1613-41F4-BE78-2F12A65AA880}] => (Allow) C:\Games\bin\steamwebhelper.exe
FirewallRules: [{D8F56787-E1BC-4E63-93FB-CA947F533BC3}] => (Allow) C:\Games\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{166D756E-23A0-4953-881A-478DC4A94B9C}C:\games\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) C:\games\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe
FirewallRules: [UDP Query User{27C11B03-7A3B-426D-91B3-A89FE38E6E57}C:\games\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) C:\games\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe
FirewallRules: [{CED4BD0D-CCDA-4352-B70C-27E5D92765F2}] => (Allow) C:\Games\steamapps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_DX11.exe
FirewallRules: [{A17C2D49-64B7-480B-B595-F162AF791908}] => (Allow) C:\Games\steamapps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_DX11.exe
FirewallRules: [{9275B623-D235-4FAA-8C8C-91213D2CBE72}] => (Allow) C:\Games\steamapps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_Mantle.exe
FirewallRules: [{2DE58CE3-325D-43D2-BAC8-2B60917E0274}] => (Allow) C:\Games\steamapps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_Mantle.exe
FirewallRules: [{4427B677-59EF-463A-B35E-BF83247C59EF}] => (Allow) C:\Games\steamapps\common\Sid Meier's Starships\Starships64.exe
FirewallRules: [{C2FF6E0A-7AB2-453A-83FD-6D32275FFCAC}] => (Allow) C:\Games\steamapps\common\Sid Meier's Starships\Starships64.exe
FirewallRules: [{6F824FAF-BEF8-42AB-B547-C4CAB29FDEED}] => (Allow) C:\Games\steamapps\common\Pillars of Eternity\PillarsOfEternity.exe
FirewallRules: [{EA36192E-AD15-47A4-974C-246EC21F9E4B}] => (Allow) C:\Games\steamapps\common\Pillars of Eternity\PillarsOfEternity.exe
FirewallRules: [{73780B87-4E87-4278-88EB-5589096AAE26}] => (Allow) C:\Games\steamapps\common\Age2HD\Launcher.exe
FirewallRules: [{F83E3774-05F3-4912-B36B-6EAE1E397967}] => (Allow) C:\Games\steamapps\common\Age2HD\Launcher.exe
FirewallRules: [{24C27D6E-11A3-4854-BFAA-C798E669625E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{507D6FC9-4E2A-42B7-BD6D-CDB9745904DB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{14959822-8549-4B6E-AAFE-A58B839051B7}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
FirewallRules: [{2D84512F-20BC-4F43-8BAD-87699B3B9E1C}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
FirewallRules: [{AA231BDD-A04C-41AE-AB54-7F8D1A91322E}] => (Allow) C:\Games\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{7E1C57E2-0694-4C55-A719-7CDCD0BFA945}] => (Allow) C:\Games\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{01F749E5-7FF3-4F52-A3A3-E46162B6BE32}] => (Allow) C:\Games\steamapps\common\Panzer Corps\autorun.exe
FirewallRules: [{34E44554-0E18-4F68-98E1-F8739CD3C7A9}] => (Allow) C:\Games\steamapps\common\Panzer Corps\autorun.exe
FirewallRules: [{3A4FF2D2-66A7-437C-9CFA-C9D91ED27828}] => (Allow) C:\Games\steamapps\common\Stellaris\stellaris.exe
FirewallRules: [{19DC3783-A4D8-4FF1-9BE3-C8E18909E168}] => (Allow) C:\Games\steamapps\common\Stellaris\stellaris.exe
FirewallRules: [{6B517A54-B878-48F9-B44C-9820C31EAE05}] => (Allow) C:\Games\steamapps\common\Baldur's Gate Enhanced Edition\Baldur.exe
FirewallRules: [{38E42320-7EE1-4CCD-B499-48469F48074D}] => (Allow) C:\Games\steamapps\common\Baldur's Gate Enhanced Edition\Baldur.exe
FirewallRules: [{42F08110-A3A7-485F-BBCE-0C722BA8459B}] => (Allow) C:\Games\steamapps\common\Baldur's Gate II Enhanced Edition\Baldur.exe
FirewallRules: [{CDA11751-438F-41D8-A735-C60780D15D79}] => (Allow) C:\Games\steamapps\common\Baldur's Gate II Enhanced Edition\Baldur.exe
FirewallRules: [{30B2CB9A-CE94-45B5-B244-9C4AF0234DC7}] => (Allow) C:\Games\steamapps\common\Icewind Dale Enhanced Edition\icewind.exe
FirewallRules: [{9B10EE18-3D9A-4740-8286-A24597A7042D}] => (Allow) C:\Games\steamapps\common\Icewind Dale Enhanced Edition\icewind.exe
FirewallRules: [{AB6B6298-5406-4964-8DF4-4BE4AD1CBEDD}] => (Allow) C:\Games\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{A7EEAF42-F4F7-48A8-BBA6-5042DFB693A1}] => (Allow) C:\Games\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{42B4E1E1-C4A9-4139-8EC0-8AB0A2D46CA5}] => (Allow) C:\Program Files\Acrylic Wi-Fi Home\Acrylic.exe
FirewallRules: [{A6BBC231-0D77-454C-9AB0-2B415659A869}] => (Allow) C:\Program Files\Acrylic Wi-Fi Home\Acrylic.exe
FirewallRules: [{7F1EB016-9B0F-4530-BFB0-D61DF46574FB}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe
FirewallRules: [{5526B856-F0C9-47EF-97EA-25B8F705EE93}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe
FirewallRules: [{BC3801FF-4DCD-4ABD-B997-0CEA1C927AB1}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe
FirewallRules: [{B58A21FE-32D6-4DD4-8E52-F5F535997DEF}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe
FirewallRules: [{E8BFD162-A396-4BCD-A7B2-1D9AD4982886}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
FirewallRules: [{71510003-9D98-46C7-948A-29AE1C40DE49}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
FirewallRules: [{9423FBA1-9625-486D-B5FC-1E3A2A8D56F6}] => (Allow) C:\Program Files (x86)\Origin Games\Renegade\RenegadeLauncher.exe
FirewallRules: [{7FA088DC-D9F4-45FD-90E6-7E8CDC2C2087}] => (Allow) C:\Program Files (x86)\Origin Games\Renegade\RenegadeLauncher.exe
FirewallRules: [{EE914A61-BD43-4494-8869-E5A0F83F62B4}] => (Allow) C:\Games\steamapps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI.exe
FirewallRules: [{5575249A-3574-4A87-9B6F-A1A0D8110DEE}] => (Allow) C:\Games\steamapps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI.exe
FirewallRules: [{9FAC6CE6-CE8A-40FC-9709-1D3BF990EDA4}] => (Allow) C:\Games\steamapps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI_DX12.exe
FirewallRules: [{7B1918DD-0B51-4A36-9035-48428DB43B01}] => (Allow) C:\Games\steamapps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI_DX12.exe
FirewallRules: [{237DF4D6-278B-49FF-87F5-472797A17A19}] => (Allow) C:\Users\Jeff\AppData\Local\Temp\HouseCall\tmase\nmap\bonjour.exe
FirewallRules: [{D38A0C10-A1A2-43D3-8FDE-D5686E5ED9C3}] => (Allow) C:\Users\Jeff\AppData\Local\Temp\HouseCall\tmase\drs\DrScaner.exe
FirewallRules: [{7D1EE80C-95A4-4FDE-BD6D-CC656DFFDA73}] => (Allow) C:\Users\Jeff\AppData\Local\Temp\HouseCall\tmase\drs\DrScaner.exe

==================== Restore Points =========================

23-11-2017 20:37:17 Removed Classic Shell
24-11-2017 16:03:53 Installed Classic Shell
24-11-2017 19:28:47 Tweaking.com - Windows Repair 2018

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/25/2017 07:45:28 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program ShellExperienceHost.exe version 10.0.16299.15 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 1584

Start Time: 01d36658278f1fda

Termination Time: 4294967295

Application Path: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe

Report Id: b5cc8c2e-8abd-4421-b94b-714ec0f49262

Faulting package full name: Microsoft.Windows.ShellExperienceHost_10.0.16299.15_neutral_neutral_cw5n1h2txyewy

Faulting package-relative application ID: App

Error: (11/25/2017 07:45:22 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Jeff-PC)
Description: Package Microsoft.Windows.ShellExperienceHost_10.0.16299.15_neutral_neutral_cw5n1h2txyewy+App was terminated because it took too long to suspend.

Error: (11/25/2017 01:54:21 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 57.0.0.6525, time stamp: 0x5a085587
Faulting module name: mbae64.dll, version: 1.11.1.40, time stamp: 0x5a0af087
Exception code: 0xc0000005
Fault offset: 0x00000000000210e2
Faulting process id: 0x1984
Faulting application start time: 0x01d365c02f3bd6af
Faulting application path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Faulting module path: C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.dll
Report Id: 7489d288-7754-48ec-ad4c-656e10eb8816
Faulting package full name:
Faulting package-relative application ID:

Error: (11/24/2017 10:48:36 PM) (Source: COM) (EventID: 10031) (User: )
Description: An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class {F6C29334-47DC-4397-9150-F549CF1D4861} was rejected

Error: (11/24/2017 10:48:36 PM) (Source: COM) (EventID: 10031) (User: )
Description: An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class {F6C29334-47DC-4397-9150-F549CF1D4861} was rejected

Error: (11/24/2017 09:06:59 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: Jeff-PC)
Description: Installing the performance counter strings for service .NET CLR Data () failed. The first DWORD in the Data section contains the error code.

Error: (11/24/2017 09:06:59 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: Jeff-PC)
Description: Installing the performance counter strings for service .NET CLR Networking () failed. The first DWORD in the Data section contains the error code.

Error: (11/24/2017 09:06:59 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: Jeff-PC)
Description: Installing the performance counter strings for service .NET CLR Networking 4.0.0.0 () failed. The first DWORD in the Data section contains the error code.

Error: (11/24/2017 09:06:59 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: Jeff-PC)
Description: Installing the performance counter strings for service .NET Data Provider for Oracle () failed. The first DWORD in the Data section contains the error code.

Error: (11/24/2017 09:06:59 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: Jeff-PC)
Description: Installing the performance counter strings for service .NET Data Provider for SqlServer () failed. The first DWORD in the Data section contains the error code.


System errors:
=============
Error: (11/25/2017 07:45:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Origin Web Helper Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

Error: (11/25/2017 07:45:23 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Origin Web Helper Service service to connect.

Error: (11/25/2017 07:44:52 PM) (Source: DCOM) (EventID: 10016) (User: Jeff-PC)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
{7022A3B3-D004-4F52-AF11-E9E987FEE25F}
 and APPID
{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
 to the user Jeff-PC\Jeff SID (S-1-5-21-4089348763-2620558389-2721033571-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (11/25/2017 07:44:47 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 7:43:34 PM on ‎11/‎25/‎2017 was unexpected.

Error: (11/25/2017 07:23:27 PM) (Source: DCOM) (EventID: 10010) (User: Jeff-PC)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Error: (11/25/2017 01:33:29 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Origin Web Helper Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

Error: (11/25/2017 01:33:29 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Origin Web Helper Service service to connect.

Error: (11/25/2017 01:32:57 AM) (Source: DCOM) (EventID: 10016) (User: Jeff-PC)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
{7022A3B3-D004-4F52-AF11-E9E987FEE25F}
 and APPID
{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
 to the user Jeff-PC\Jeff SID (S-1-5-21-4089348763-2620558389-2721033571-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (11/25/2017 01:32:14 AM) (Source: DCOM) (EventID: 10010) (User: Jeff-PC)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Error: (11/25/2017 01:32:13 AM) (Source: DCOM) (EventID: 10010) (User: Jeff-PC)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.


CodeIntegrity:
===================================
  Date: 2017-11-25 19:55:58.452
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Windows signing level requirements.

  Date: 2017-11-25 19:55:58.442
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\hmpalert.dll that did not meet the Windows signing level requirements.

  Date: 2017-11-25 19:49:58.024
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2017-11-25 19:49:57.976
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system.

  Date: 2017-11-25 19:49:05.083
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2017-11-25 19:49:04.966
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system.

  Date: 2017-11-25 19:45:08.301
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\hmpalert.dll that did not meet the Windows signing level requirements.

  Date: 2017-11-25 19:45:05.255
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\NisSrv.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\hmpalert.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-11-25 19:44:54.237
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\hmpalert.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-11-25 19:44:53.923
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\SecurityHealthService.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\hmpalert.dll that did not meet the Windows signing level requirements.


==================== Memory info ===========================

Processor: Intel® Core™2 Quad CPU Q8400 @ 2.66GHz
Percentage of memory in use: 57%
Total physical RAM: 8191.17 MB
Available physical RAM: 3479.95 MB
Total Virtual: 8703.17 MB
Available Virtual: 3543.71 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.22 GB) (Free:180.38 GB) NTFS
Drive d: (Storage Drive) (Fixed) (Total:931.51 GB) (Free:333.04 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 34C067AE)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=449 MB) - (Type=27)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: DB406037)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================


Google is my friend. Make Google your friend too.


#6 nasdaq

nasdaq

  • Malware Response Team
  • 40,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:06:19 AM

Posted 26 November 2017 - 09:33 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Press the Windows key + r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

Please copy the entire contents of the code box below to a new file.
 
Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

HKLM Group Policy restriction on software: *.avi*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: lsassw86s.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.jse <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.com <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.exe <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.com <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.pif <==== ATTENTION
HKLM Group Policy restriction on software: cipher.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.exe <==== ATTENTION
HKLM Group Policy restriction on software: ** <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.scr <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: lsassvrtdbks.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: scsvserv.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %programfiles(x86)%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.com <==== ATTENTION
HKLM Group Policy restriction on software: syskey.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.com <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: vssadmin.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.exe <==== ATTENTION
GroupPolicy: Restriction - Chrome <==== ATTENTION
HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
Toolbar: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
FF Plugin: @java.com/JavaPlugin,version=10.11.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [No File]
U3 idsvc; no ImagePath
ContextMenuHandlers4: [EncryptionMenu] -> {A470F8CF-A1E8-4f65-8335-227475AA5C46} =>  -> No File
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} =>  -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6-x32: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
Task: {1D2B73CD-A4C1-4596-BEF9-4EDF6C954915} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {288787EF-6C92-445F-A147-394C46E3D04D} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2C326DB5-DA25-4EA7-98B1-9622FA0F8B68} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {5D1F8F1B-9723-4175-92A0-DABA462CE062} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {63D13114-6E19-4080-868A-CAA7A78928F1} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {7C55CE6A-BE8C-41A9-9D8C-3E428327965A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {8EF9A698-72EB-4312-BFBC-BB7BACB106D4} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {99DFB1D8-DE1B-4876-A402-C73DC57EDB99} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {A8FDDA88-2131-4914-B7B0-A495A1E843FE} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {B22E3C00-30C6-4A3D-AC74-CF235B811B3A} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {B5260580-6A06-42AA-AB3D-B6C6440612B9} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {F10141D6-724C-4552-99B9-9313B46C4D84} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {F4302394-816E-4E5D-8EC3-32A39B387F6A} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Reset Chrome...
Open Google Chrome, click on menu icon google-chrome-setting-icon.png or the 3 vertical dots located right side top of the google chrome.
 
Click "Settings" then "Show advanced settings" at the bottom of the screen.
 
Click "Reset browser settings" button.
 
Restart Chrome.
===

Please let me know what problem persists with this computer.

#7 Torvald

Torvald
  • Topic Starter

  • Members
  • 366 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Antonio, TX USA
  • Local time:05:19 AM

Posted 26 November 2017 - 03:19 PM

nasdaq,

 

Here is the contents of my Fixlog.txt file:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 26-11-2017
Ran by Jeff (26-11-2017 13:41:25) Run:1
Running from C:\Users\Jeff\Downloads
Loaded Profiles: Jeff (Available Profiles: Jeff & DefaultAppPool)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

HKLM Group Policy restriction on software: *.avi*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: lsassw86s.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.jse <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.com <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.exe <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.com <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.pif <==== ATTENTION
HKLM Group Policy restriction on software: cipher.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.exe <==== ATTENTION
HKLM Group Policy restriction on software: ** <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.scr <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: lsassvrtdbks.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: scsvserv.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %programfiles(x86)%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.com <==== ATTENTION
HKLM Group Policy restriction on software: syskey.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.com <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: vssadmin.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.exe <==== ATTENTION
GroupPolicy: Restriction - Chrome <==== ATTENTION
HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
Toolbar: HKU\S-1-5-21-4089348763-2620558389-2721033571-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
FF Plugin: @java.com/JavaPlugin,version=10.11.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [No File]
U3 idsvc; no ImagePath
ContextMenuHandlers4: [EncryptionMenu] -> {A470F8CF-A1E8-4f65-8335-227475AA5C46} =>  -> No File
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} =>  -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6-x32: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
Task: {1D2B73CD-A4C1-4596-BEF9-4EDF6C954915} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {288787EF-6C92-445F-A147-394C46E3D04D} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2C326DB5-DA25-4EA7-98B1-9622FA0F8B68} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {5D1F8F1B-9723-4175-92A0-DABA462CE062} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {63D13114-6E19-4080-868A-CAA7A78928F1} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {7C55CE6A-BE8C-41A9-9D8C-3E428327965A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {8EF9A698-72EB-4312-BFBC-BB7BACB106D4} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {99DFB1D8-DE1B-4876-A402-C73DC57EDB99} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {A8FDDA88-2131-4914-B7B0-A495A1E843FE} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {B22E3C00-30C6-4A3D-AC74-CF235B811B3A} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {B5260580-6A06-42AA-AB3D-B6C6440612B9} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {F10141D6-724C-4552-99B9-9313B46C4D84} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {F4302394-816E-4E5D-8EC3-32A39B387F6A} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]

End
*****************

Restore point was successfully created.
Processes closed successfully.
HKLM Group Policy restriction on software: *.avi*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: lsassw86s.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: cipher.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: ** <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: lsassvrtdbks.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: scsvserv.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programfiles(x86)%\*\svchost.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: syskey.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *:\$Recycle.Bin <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: vssadmin.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.exe <==== ATTENTION => restored successfully
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\SOFTWARE\Policies\Microsoft\Internet Explorer => key removed successfully
HKU\S-1-5-21-4089348763-2620558389-2721033571-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully
HKLM\Software\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found
HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2 => key removed successfully
HKLM\System\CurrentControlSet\Services\idsvc => key removed successfully
idsvc => service removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\EncryptionMenu => key removed successfully
HKLM\Software\Classes\CLSID\{A470F8CF-A1E8-4f65-8335-227475AA5C46} => key not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\MSSE => key removed successfully
HKLM\Software\Classes\CLSID\{0365FE2C-F183-4091-AC82-BFC39FB75C49} => key not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => key removed successfully
HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => key not found
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\Gadgets => key removed successfully
HKLM\Software\Classes\CLSID\{6B9228DA-9C15-419e-856C-19E768A13BDC} => key not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => key removed successfully
HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D} => key removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => key removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => key not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1D2B73CD-A4C1-4596-BEF9-4EDF6C954915} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D2B73CD-A4C1-4596-BEF9-4EDF6C954915} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{288787EF-6C92-445F-A147-394C46E3D04D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{288787EF-6C92-445F-A147-394C46E3D04D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2C326DB5-DA25-4EA7-98B1-9622FA0F8B68} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2C326DB5-DA25-4EA7-98B1-9622FA0F8B68} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5D1F8F1B-9723-4175-92A0-DABA462CE062} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D1F8F1B-9723-4175-92A0-DABA462CE062} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => key not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{63D13114-6E19-4080-868A-CAA7A78928F1} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{63D13114-6E19-4080-868A-CAA7A78928F1} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7C55CE6A-BE8C-41A9-9D8C-3E428327965A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7C55CE6A-BE8C-41A9-9D8C-3E428327965A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8EF9A698-72EB-4312-BFBC-BB7BACB106D4} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8EF9A698-72EB-4312-BFBC-BB7BACB106D4} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{99DFB1D8-DE1B-4876-A402-C73DC57EDB99} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{99DFB1D8-DE1B-4876-A402-C73DC57EDB99} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A8FDDA88-2131-4914-B7B0-A495A1E843FE} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A8FDDA88-2131-4914-B7B0-A495A1E843FE} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B22E3C00-30C6-4A3D-AC74-CF235B811B3A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B22E3C00-30C6-4A3D-AC74-CF235B811B3A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B5260580-6A06-42AA-AB3D-B6C6440612B9} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5260580-6A06-42AA-AB3D-B6C6440612B9} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F10141D6-724C-4552-99B9-9313B46C4D84} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F10141D6-724C-4552-99B9-9313B46C4D84} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F4302394-816E-4E5D-8EC3-32A39B387F6A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4302394-816E-4E5D-8EC3-32A39B387F6A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d => key removed successfully
C:\ProgramData\TEMP => ":5C321E34" ADS removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 6053888 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 25390731 B
Java, Flash, Steam htmlcache => 582348781 B
Windows/system/drivers => 47235954 B
Edge => 171700 B
Chrome => 13008058 B
Firefox => 406698033 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 24354 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 57566 B
Jeff => 352512339 B
DefaultAppPool => 33058 B

RecycleBin => 2393192 B
EmptyTemp: => 1.3 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 13:43:38 ====

 

 

 

Please note that I was not able to reset my Chrome browser, however, as it kept freezing when accessing the Chrome settings.

 

Also, my computer still has the same problems as before:  If I do a restart (instead of a 100% power off), I am not able to right-click on icons in the taskbar, plus more importantly, it prevents me from accessing the Windows Start button.  I also still have multiple strange folders & files on my C: drive, some of which get updated/renamed each time my computer restarts.  So it looks like my computer infection is still present.


Google is my friend. Make Google your friend too.


#8 nasdaq

nasdaq

  • Malware Response Team
  • 40,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:06:19 AM

Posted 27 November 2017 - 09:21 AM



Hi,

I also still have multiple strange folders & files on my C: drive, some of which get updated/renamed each time my computer restarts.


They get rename to what?
Give me an example of the name.

===

--RogueKiller--
  • Download & SAVE to your Desktop Download RogueKiller
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or above, right-click the program file and select "Run as Administrator"
  • Accept the user agreements.
  • Execute the scan and wait until it has finished.
  • If a Windows opens to explain what [PUM's] are, read about it.
  • Click the RoguKiller icon on your taksbar to return to the report.
  • Click open the Report
  • Click Export TXT button
  • Save the file as ReportRogue.txt
  • Click the Remove button to delete the items in RED
  • Click Finish and close the program.
  • Locate the ReportRogue.txt file on your Desktop and copy/paste the contents in your next.
=======

We will check your BIOS and Master boot record.

Read carefully and follow these steps.
TDSS
  • Download TDSSKiller and save it to your Desktop.
  • Doubleclick on TDSSKiller.exe to run the application.
  • Then click on Start Scan.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • Important: Do NOT change the default action on your own unless instructed by a malware Helper! Doing so may render your computer unbootable.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
  • ===

    Download http://public.avast.com/~gmerek/aswMBR.exe (aswMBR.exe) to your desktop. Double click the aswMBR.exe to run it.
    • Click the "Scan" button to start scan.
    • Upon completion of the scan, click Save log, and save it to your desktop. (Note - do not select any Fix at this time) <- IMPORTANT
    • Please paste the contents of that log in your next reply.
    There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.
    ===

    Wait for further instructions.


#9 Torvald

Torvald
  • Topic Starter

  • Members
  • 366 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Antonio, TX USA
  • Local time:05:19 AM

Posted 27 November 2017 - 01:10 PM

nasdaq,

 

I am back at work today, so will give you info on the strange new folders & files on my C: drive after I get off work tonight, and will then also follow the additional guidance you've provided above.

 

Also wanted to mention that I have been getting many warnings lately on my Firefox browser from Noscript, alerting me to cross scripting site attacks (hope I've worded that correctly).

 

Best wishes.


Google is my friend. Make Google your friend too.


#10 nasdaq

nasdaq

  • Malware Response Team
  • 40,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:06:19 AM

Posted 27 November 2017 - 02:00 PM


Hi,

Also wanted to mention that I have been getting many warnings lately on my Firefox browser from Noscript, alerting me to cross scripting site attacks (hope I've worded that correctly).


Navigate to this page with Firefox.
https://addons.mozilla.org/en-US/firefox/addon/noscript/

Just click the Add to Firefox button.

When completed close Firefox.


Restart Firefox and let me know if the notification is gone.

#11 Torvald

Torvald
  • Topic Starter

  • Members
  • 366 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Antonio, TX USA
  • Local time:05:19 AM

Posted 27 November 2017 - 08:42 PM

Here is a description of the strange folders and files I've spotted on my C: drive since getting infected:

 

Not sure, but think a folder named "948cd7fdce1903128cb5c6e501" was created, and two previously separate folders named "amd64" and "i386" were incorporated into it.

 

For sure, though a folder named "948blogs187" was created when I was originally infected, and it contains a file named "jim_alaska_edge_pair.rtf".   This particular folder appears to stay the same and does not seem to change when I restart my computer.

 

Another folder named "948asetup150" is filled with the following files:  "claytonmanagementmeasureddelicate.txt", "compose.loyalty.objective.xls", "entitled-displacement.rtf", "finalcompelgatheringinternational.jpg", "fueltask.mdb", "gang.forest.sql", "include-top-affect-pay.xlsx", "intense-critical.pem", "thenluckrelativeassumed.docx", and "ultimate-fast-share-generally.doc".  This folder and the files in it get renamed each time my computer is restarted, and the date/time of the folder and the files within it get updated.

 

I also have similar strange folders named "Xcached215" and "Ytools150" on my C: system drive containing strangely named files.  Have not spotted any weird folders/files yet on my D: data drive.

 

There are also two extra listings in my Users folder i didn't notice before, named "Ajg3tqv" and "Vacr".

 

Did the Noscript thing to Firefox you recommended,ando will monitor to see if i get any more cross scripting warning messages.

 

Will now download and run the files that you recommended.


Google is my friend. Make Google your friend too.


#12 Torvald

Torvald
  • Topic Starter

  • Members
  • 366 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Antonio, TX USA
  • Local time:05:19 AM

Posted 28 November 2017 - 12:23 AM

Downloaded, installed and ran RogueKiller.  When installing it, I received the following error message:  "Setup.  IPersistFile::Save failed: Code 0x80070002.  The system cannot find the file specified."

 

After running the scan, there were no RED items highlighted/checked for removal, so I said to go ahead and remove the Orange checked items for the Unchecky program.

 

Restarted my computer, and the same infection problems reoccurred = not able to right-click on icons in my taskbar, not able to access Windows Settings via the Start button, IE11 browser not working properly, etc.  Therefore, completely powered my computer off, then started it back up again.  It is working temporarily, so will proceed next to downloading & running TDSSKiller.

 

In the meantime, here is my ReportRogue.txt file contents.

 

RogueKiller V12.11.26.0 (x64) [Nov 27 2017] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.16299) 64 bits version
Started in : Normal mode
User : Jeff [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 11/27/2017 19:56:32 (Duration : 00:49:28)
Switches : -refid

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 13 ¤¤¤
[PUP.OpenCandy] (X86) HKEY_LOCAL_MACHINE\Software\Unchecky -> Found
[PUP.OpenCandy] (X64) HKEY_USERS\.DEFAULT\Software\Unchecky -> Found
[PUP.OpenCandy] (X86) HKEY_USERS\.DEFAULT\Software\Unchecky -> Found
[PUP.OpenCandy] (X64) HKEY_USERS\S-1-5-21-4089348763-2620558389-2721033571-1001\Software\Unchecky -> Found
[PUP.OpenCandy] (X86) HKEY_USERS\S-1-5-21-4089348763-2620558389-2721033571-1001\Software\Unchecky -> Found
[PUP.OpenCandy] (X64) HKEY_USERS\S-1-5-18\Software\Unchecky -> Found
[PUP.OpenCandy] (X86) HKEY_USERS\S-1-5-18\Software\Unchecky -> Found
[PUP.OpenCandy] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Unchecky -> Found
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-4089348763-2620558389-2721033571-1001\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve  -> Found
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-4089348763-2620558389-2721033571-1001\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve  -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {237DF4D6-278B-49FF-87F5-472797A17A19} : v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|App=C:\Users\Jeff\AppData\Local\Temp\HouseCall\tmase\nmap\bonjour.exe|Name=bonjour4trend|Desc=bonjour4trend|EmbedCtxt=bonjour4trend|Edge=TRUE|Defer=App| [x] -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {D38A0C10-A1A2-43D3-8FDE-D5686E5ED9C3} : v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|App=C:\Users\Jeff\AppData\Local\Temp\HouseCall\tmase\drs\DrScaner.exe|Name=drs4trend|Desc=drs4trend|EmbedCtxt=drs4trend|Edge=TRUE|Defer=App| [x] -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {7D1EE80C-95A4-4FDE-BD6D-CC656DFFDA73} : v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|App=C:\Users\Jeff\AppData\Local\Temp\HouseCall\tmase\drs\DrScaner.exe|Name=rule4scaner|Desc=rule4scaner|EmbedCtxt=rule4scaner|Edge=TRUE|Defer=App| [x] -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 6 ¤¤¤
[PUP.OpenCandy][Folder] C:\ProgramData\Unchecky -> Found
[PUP.OpenCandy][File] C:\Users\Public\Desktop\Unchecky.lnk [LNK@] C:\PROGRA~2\Unchecky\unchecky.exe -> Found
[PUP.OpenCandy][Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unchecky -> Found
[PUP.OpenCandy][Folder] C:\ProgramData\Unchecky -> Found
[PUP.OpenCandy][Folder] C:\Program Files (x86)\Unchecky -> Found
[PUP.OpenCandy][File] C:\Users\Public\Desktop\Unchecky.lnk [LNK@] C:\PROGRA~2\Unchecky\unchecky.exe -> Found

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: Samsung SSD 850 EVO 500GB +++++
--- User ---
[MBR] 9c9ee9903436ae783dbc1ca784634271
[BSP] c3cae27f27bb520bfe4d6c93c4b0aba0 : HP|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 476388 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 975851520 | Size: 449 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: WDC WD1003FZEX-00MK2A0 +++++
--- User ---
[MBR] 7cea96396f98c8f5cf0e8fde995cc1cc
[BSP] f84f559fc28065403a9ab25fb2d2ad7d : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 953867 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

 


Edited by Torvald, 28 November 2017 - 12:25 AM.

Google is my friend. Make Google your friend too.


#13 Torvald

Torvald
  • Topic Starter

  • Members
  • 366 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Antonio, TX USA
  • Local time:05:19 AM

Posted 28 November 2017 - 12:37 AM

Downloaded, initialized and ran TDSSKiller.  It did not find any threats.  Ran it a second time, but still no threats founds.

 

Will download and run Avast next.

 

In the meantime, here is the first part of the contents of my TDSSKiller log text file:

 

23:27:22.0806 0464  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
23:27:24.0243 0464  ============================================================
23:27:24.0243 0464  Current date / time: 2017/11/27 23:27:24.0243
23:27:24.0243 0464  SystemInfo:
23:27:24.0243 0464  
23:27:24.0243 0464  OS Version: 6.2.9200 ServicePack: 0.0
23:27:24.0243 0464  Product type: Workstation
23:27:24.0243 0464  ComputerName: JEFF-PC
23:27:24.0243 0464  UserName: Jeff
23:27:24.0243 0464  Windows directory: C:\WINDOWS
23:27:24.0243 0464  System windows directory: C:\WINDOWS
23:27:24.0243 0464  Running under WOW64
23:27:24.0243 0464  Processor architecture: Intel x64
23:27:24.0243 0464  Number of processors: 4
23:27:24.0243 0464  Page size: 0x1000
23:27:24.0243 0464  Boot type: Normal boot
23:27:24.0243 0464  ============================================================
23:27:24.0556 0464  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
23:27:24.0556 0464  Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
23:27:24.0571 0464  ============================================================
23:27:24.0571 0464  \Device\Harddisk0\DR0:
23:27:24.0571 0464  MBR partitions:
23:27:24.0571 0464  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
23:27:24.0571 0464  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x3A272030
23:27:24.0571 0464  \Device\Harddisk1\DR1:
23:27:24.0571 0464  MBR partitions:
23:27:24.0571 0464  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x74705800
23:27:24.0571 0464  ============================================================
23:27:24.0571 0464  C: <-> \Device\Harddisk0\DR0\Partition2
23:27:24.0603 0464  D: <-> \Device\Harddisk1\DR1\Partition1
23:27:24.0603 0464  ============================================================
23:27:24.0603 0464  Initialize success
23:27:24.0603 0464  ============================================================
23:28:05.0368 5420  ============================================================
23:28:05.0368 5420  Scan started
23:28:05.0368 5420  Mode: Manual;
23:28:05.0368 5420  ============================================================
23:28:05.0758 5420  ================ Scan system memory ========================
23:28:05.0758 5420  System memory - ok
23:28:05.0758 5420  ================ Scan services =============================
23:28:05.0758 5420  [ 98E06CAC2C508118450095E581202230 ] !SASCORE        C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
23:28:05.0774 5420  !SASCORE - ok
23:28:05.0821 5420  [ 08312DEEF0D3F8647AA53AD90A69094E ] 1394ohci        C:\WINDOWS\System32\drivers\1394ohci.sys
23:28:05.0821 5420  1394ohci - ok
23:28:05.0836 5420  [ 645009E711BBF117CCEE917A03FB0CDD ] 3ware           C:\WINDOWS\system32\drivers\3ware.sys
23:28:05.0836 5420  3ware - ok
23:28:05.0915 5420  [ F2C2362B578E4956652AE0172B2091B3 ] a2AntiMalware   C:\Program Files\Emsisoft Anti-Malware\a2service.exe
23:28:06.0071 5420  a2AntiMalware - ok
23:28:06.0086 5420  [ 91A59E1A94F1A267FA9F8F6FC9AA9497 ] ACPI            C:\WINDOWS\system32\drivers\ACPI.sys
23:28:06.0102 5420  ACPI - ok
23:28:06.0102 5420  [ 44EA35A4B397898A83BF1B9B4B8DAE35 ] AcpiDev         C:\WINDOWS\System32\drivers\AcpiDev.sys
23:28:06.0102 5420  AcpiDev - ok
23:28:06.0118 5420  [ 91D113A1532B8AB1E25B7DE5AB3C2F83 ] acpiex          C:\WINDOWS\system32\Drivers\acpiex.sys
23:28:06.0118 5420  acpiex - ok
23:28:06.0118 5420  [ 620BB2682BA625DF037072D89F44F6EE ] acpipagr        C:\WINDOWS\System32\drivers\acpipagr.sys
23:28:06.0118 5420  acpipagr - ok
23:28:06.0133 5420  [ B9805A3C479390CEAEA5AEF5E4A90A2E ] AcpiPmi         C:\WINDOWS\System32\drivers\acpipmi.sys
23:28:06.0133 5420  AcpiPmi - ok
23:28:06.0133 5420  [ ABD4EB55C661143B015BD0B9B47B235C ] acpitime        C:\WINDOWS\System32\drivers\acpitime.sys
23:28:06.0133 5420  acpitime - ok
23:28:06.0149 5420  [ 38622FFE9369D3EC01C0097235BD9279 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
23:28:06.0149 5420  AdobeARMservice - ok
23:28:06.0165 5420  [ 5D0A6467159A017D3F2222CAE67031B3 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
23:28:06.0180 5420  AdobeFlashPlayerUpdateSvc - ok
23:28:06.0196 5420  [ 8C58BD711FAD5F11E8CFDBC5CED973A5 ] ADP80XX         C:\WINDOWS\system32\drivers\ADP80XX.SYS
23:28:06.0211 5420  ADP80XX - ok
23:28:06.0211 5420  [ 6FB5A2026B16D596DEABF550E7A4BD82 ] AFD             C:\WINDOWS\system32\drivers\afd.sys
23:28:06.0227 5420  AFD - ok
23:28:06.0227 5420  [ 56166D110D3ECFFC595E5FA02D9BA491 ] ahcache         C:\WINDOWS\system32\DRIVERS\ahcache.sys
23:28:06.0227 5420  ahcache - ok
23:28:06.0243 5420  [ 84FFB4AC2BA923364DF13F73751E05D1 ] AJRouter        C:\WINDOWS\System32\AJRouter.dll
23:28:06.0243 5420  AJRouter - ok
23:28:06.0243 5420  [ 084101AB03969D8ED00D5FFBE5F4C3DF ] ALG             C:\WINDOWS\System32\alg.exe
23:28:06.0243 5420  ALG - ok
23:28:06.0258 5420  [ 62619E31AFF88F906A7E793AC4A9FF51 ] AmdK8           C:\WINDOWS\System32\drivers\amdk8.sys
23:28:06.0258 5420  AmdK8 - ok
23:28:06.0274 5420  [ 735142DD039BEB35632765C41FC6E397 ] AmdPPM          C:\WINDOWS\System32\drivers\amdppm.sys
23:28:06.0274 5420  AmdPPM - ok
23:28:06.0274 5420  [ F1C16AABA27E9E153AEC7BD2AB853F30 ] amdsata         C:\WINDOWS\system32\drivers\amdsata.sys
23:28:06.0274 5420  amdsata - ok
23:28:06.0291 5420  [ C834D0F1ECB8473E9E6D18EE1BCEECB2 ] amdsbs          C:\WINDOWS\system32\drivers\amdsbs.sys
23:28:06.0291 5420  amdsbs - ok
23:28:06.0307 5420  [ 49203D2FFE30CBB36BE66A0E70F3D954 ] amdxata         C:\WINDOWS\system32\drivers\amdxata.sys
23:28:06.0307 5420  amdxata - ok
23:28:06.0307 5420  [ 4EB4D11F563FBEBDE8DE4E74B8851715 ] AppHostSvc      C:\WINDOWS\system32\inetsrv\apphostsvc.dll
23:28:06.0307 5420  AppHostSvc - ok
23:28:06.0323 5420  [ 3692C75C47285D388C886D162F54C430 ] AppID           C:\WINDOWS\system32\drivers\appid.sys
23:28:06.0323 5420  AppID - ok
23:28:06.0323 5420  [ A78F24AF599EA536C6028D80E4037664 ] AppIDSvc        C:\WINDOWS\System32\appidsvc.dll
23:28:06.0323 5420  AppIDSvc - ok
23:28:06.0338 5420  [ BDB770759D74988591A2E3B339CD1CCB ] Appinfo         C:\WINDOWS\System32\appinfo.dll
23:28:06.0338 5420  Appinfo - ok
23:28:06.0338 5420  [ 1E085E2302D568F0CE041732B3E887B0 ] applockerfltr   C:\WINDOWS\system32\drivers\applockerfltr.sys
23:28:06.0354 5420  applockerfltr - ok
23:28:06.0354 5420  [ 1D123729F547EEDFBE3F510346848C38 ] AppReadiness    C:\WINDOWS\system32\AppReadiness.dll
23:28:06.0369 5420  AppReadiness - ok
23:28:06.0401 5420  [ 9025C763611676B9905A922C5C3C1FA6 ] AppXSvc         C:\WINDOWS\system32\appxdeploymentserver.dll
23:28:06.0432 5420  AppXSvc - ok
23:28:06.0432 5420  [ B42C83DE28776B80DBA1310C56DD4F74 ] arcsas          C:\WINDOWS\system32\drivers\arcsas.sys
23:28:06.0432 5420  arcsas - ok
23:28:06.0463 5420  [ 9CDC69DDFDC91DC628F7515809329798 ] aspnet_state    C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
23:28:06.0463 5420  aspnet_state - ok
23:28:06.0463 5420  [ C2151380227CD1F7DDA2401C1F151367 ] AsyncMac        C:\WINDOWS\System32\drivers\asyncmac.sys
23:28:06.0463 5420  AsyncMac - ok
23:28:06.0479 5420  [ 6191B9B2EE0E8CB957C683B9B341CC86 ] atapi           C:\WINDOWS\system32\drivers\atapi.sys
23:28:06.0479 5420  atapi - ok
23:28:06.0479 5420  [ D52C8B37F02C93E0391AFD10320EE4C6 ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll
23:28:06.0494 5420  AudioEndpointBuilder - ok
23:28:06.0510 5420  [ 5D74B86053FFFBD9C94081DAB7338403 ] Audiosrv        C:\WINDOWS\System32\Audiosrv.dll
23:28:06.0526 5420  Audiosrv - ok
23:28:06.0526 5420  [ 947FF5992E26AFD4CAA34506678B70BC ] AxInstSV        C:\WINDOWS\System32\AxInstSV.dll
23:28:06.0526 5420  AxInstSV - ok
23:28:06.0541 5420  [ A921805C1ED3253DF48FCA4D724173EB ] b06bdrv         C:\WINDOWS\system32\drivers\bxvbda.sys
23:28:06.0557 5420  b06bdrv - ok
23:28:06.0557 5420  [ A5E8423AB9369A303254790D39E03D0F ] bam             C:\WINDOWS\system32\drivers\bam.sys
23:28:06.0557 5420  bam - ok
23:28:06.0557 5420  [ 2A7267AA15E508F6D05A5B562F1FD1CE ] BasicDisplay    C:\WINDOWS\System32\drivers\BasicDisplay.sys
23:28:06.0573 5420  BasicDisplay - ok
23:28:06.0573 5420  [ 2E1EE0F10FAF1250D1AC05BFB0E6BD3D ] BasicRender     C:\WINDOWS\System32\drivers\BasicRender.sys
23:28:06.0573 5420  BasicRender - ok
23:28:06.0573 5420  [ 739D089777D2B66DBE7201E5EA4BA2D7 ] bcmfn2          C:\WINDOWS\System32\drivers\bcmfn2.sys
23:28:06.0588 5420  bcmfn2 - ok
23:28:06.0588 5420  [ 72963E0676003016B431306A6F4951BF ] BDESVC          C:\WINDOWS\System32\bdesvc.dll
23:28:06.0588 5420  BDESVC - ok
23:28:06.0604 5420  [ EDDAA3A563E7EB71C991FE91249C7D81 ] Beep            C:\WINDOWS\system32\drivers\Beep.sys
23:28:06.0604 5420  Beep - ok
23:28:06.0619 5420  [ 86CAB4060251D418B6449D6CBCC852A6 ] BFE             C:\WINDOWS\System32\bfe.dll
23:28:06.0619 5420  BFE - ok
23:28:06.0651 5420  [ E223918B4E0B28CF7BE132C30D1E161A ] BITS            C:\WINDOWS\System32\qmgr.dll
23:28:06.0666 5420  BITS - ok
23:28:06.0666 5420  [ D030A1203680D66716F4E74053468627 ] bowser          C:\WINDOWS\system32\DRIVERS\bowser.sys
23:28:06.0666 5420  bowser - ok
23:28:06.0682 5420  [ 51C7B80F03FD20376516AE68F98479B1 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
23:28:06.0698 5420  BrokerInfrastructure - ok
23:28:06.0698 5420  [ 2BA1BED8E8168C301522AC7CFBFA2141 ] Browser         C:\WINDOWS\System32\browser.dll
23:28:06.0698 5420  Browser - ok
23:28:06.0713 5420  [ A4863B7B1F0DB513D6E34547BACC211A ] BthAvrcpTg      C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
23:28:06.0713 5420  BthAvrcpTg - ok
23:28:06.0713 5420  [ 9C9EE272C11252C651C5DE6A1AC1EDAA ] BthHFEnum       C:\WINDOWS\System32\drivers\bthhfenum.sys
23:28:06.0713 5420  BthHFEnum - ok
23:28:06.0729 5420  [ 69734E386826ED857C889330F35B4D9C ] bthhfhid        C:\WINDOWS\System32\drivers\BthHFHid.sys
23:28:06.0729 5420  bthhfhid - ok
23:28:06.0729 5420  [ BC58294295CBAD6637A526470305B5EA ] BthHFSrv        C:\WINDOWS\System32\BthHFSrv.dll
23:28:06.0744 5420  BthHFSrv - ok
23:28:06.0744 5420  [ A94AFAEA86F5F792BB4ECA095B231464 ] BTHMODEM        C:\WINDOWS\System32\drivers\bthmodem.sys
23:28:06.0744 5420  BTHMODEM - ok
23:28:06.0760 5420  [ 572BCA61B7E026E057AF7DF456AC7E0B ] bthserv         C:\WINDOWS\system32\bthserv.dll
23:28:06.0760 5420  bthserv - ok
23:28:06.0776 5420  [ 39E7437FC59CDD7A303ABD514E462E8B ] bttflt          C:\WINDOWS\system32\drivers\bttflt.sys
23:28:06.0776 5420  bttflt - ok
23:28:06.0776 5420  [ 522888590B0C19BC8128119060AE7901 ] buttonconverter C:\WINDOWS\System32\drivers\buttonconverter.sys
23:28:06.0776 5420  buttonconverter - ok
23:28:06.0776 5420  [ 2AB01CE5E233A6FBA3E91BD57772AA4B ] CAD             C:\WINDOWS\System32\drivers\CAD.sys
23:28:06.0791 5420  CAD - ok
23:28:06.0791 5420  [ E2C8EE32C053892E685A989071AAE333 ] camsvc          C:\WINDOWS\system32\CapabilityAccessManager.dll
23:28:06.0791 5420  camsvc - ok
23:28:06.0807 5420  [ F6F97879F53AD57194C6BC8272FD73EA ] CapImg          C:\WINDOWS\System32\drivers\capimg.sys
23:28:06.0807 5420  CapImg - ok
23:28:06.0807 5420  [ 9E82A95D77AC78C84BA75FF896B060BF ] cdfs            C:\WINDOWS\system32\DRIVERS\cdfs.sys
23:28:06.0807 5420  cdfs - ok
23:28:06.0823 5420  [ 147CEBE0C5F7A80135C54715521AD9E1 ] CDPSvc          C:\WINDOWS\System32\CDPSvc.dll
23:28:06.0838 5420  CDPSvc - ok
23:28:06.0838 5420  [ C2F158F11391F21C7D3FEB572D11C2D2 ] CDPUserSvc      C:\WINDOWS\System32\CDPUserSvc.dll
23:28:06.0854 5420  CDPUserSvc - ok
23:28:06.0854 5420  [ 6D83565C1652E80447EDEA6947FA89D7 ] cdrom           C:\WINDOWS\System32\drivers\cdrom.sys
23:28:06.0854 5420  cdrom - ok
23:28:06.0869 5420  [ 200A5398C0E7E78DBDF6C0D9E811F366 ] CertPropSvc     C:\WINDOWS\System32\certprop.dll
23:28:06.0869 5420  CertPropSvc - ok
23:28:06.0885 5420  [ D81954CE5E016FD716EDDB2B2FD9BA58 ] cht4iscsi       C:\WINDOWS\system32\drivers\cht4sx64.sys
23:28:06.0885 5420  cht4iscsi - ok
23:28:06.0901 5420  [ F9A8570805807FFD66488F0A858E1308 ] cht4vbd         C:\WINDOWS\System32\drivers\cht4vx64.sys
23:28:06.0916 5420  cht4vbd - ok
23:28:06.0932 5420  [ 9798D58461706930190F1F2F6BF21D80 ] circlass        C:\WINDOWS\System32\drivers\circlass.sys
23:28:06.0932 5420  circlass - ok
23:28:06.0932 5420  [ CC8F32D22A8616F3A38FE43B23611CC5 ] CldFlt          C:\WINDOWS\system32\drivers\cldflt.sys
23:28:06.0948 5420  CldFlt - ok
23:28:06.0948 5420  [ 68661D5E98E9A1F29E4B408CF02BBB38 ] CLFS            C:\WINDOWS\system32\drivers\CLFS.sys
23:28:06.0948 5420  CLFS - ok
23:28:06.0963 5420  [ BE9FA79096DD2CB43E7066897AB52E50 ] ClipSVC         C:\WINDOWS\System32\ClipSVC.dll
23:28:06.0979 5420  ClipSVC - ok
23:28:06.0994 5420  [ 2BA3BA38B5A6A667B0EAEC477276707B ] CmBatt          C:\WINDOWS\System32\drivers\CmBatt.sys
23:28:06.0994 5420  CmBatt - ok
23:28:07.0010 5420  [ 83CE170337E6F77350C0FFB055FBC4BF ] CNG             C:\WINDOWS\system32\Drivers\cng.sys
23:28:07.0010 5420  CNG - ok
23:28:07.0026 5420  [ C65AF00EF12A1755E7CA370B0C71935D ] cnghwassist     C:\WINDOWS\system32\DRIVERS\cnghwassist.sys
23:28:07.0026 5420  cnghwassist - ok
23:28:07.0041 5420  [ A50300498D56B2448F3593D25478D508 ] CompositeBus    C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_9c1fb8f4db31c348\CompositeBus.sys
23:28:07.0041 5420  CompositeBus - ok
23:28:07.0057 5420  COMSysApp - ok
23:28:07.0057 5420  [ 65602B0DB49199647FECB2D1212147BE ] condrv          C:\WINDOWS\system32\drivers\condrv.sys
23:28:07.0057 5420  condrv - ok
23:28:07.0073 5420  [ 67FDCB1F856EA3621B099210F1DF620E ] CoreMessagingRegistrar C:\WINDOWS\system32\coremessaging.dll
23:28:07.0073 5420  CoreMessagingRegistrar - ok
23:28:07.0088 5420  [ C8BD651E13895B93ED9EC5B4F1DF42BC ] Creative ALchemy AL6 Licensing Service C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
23:28:07.0213 5420  Creative ALchemy AL6 Licensing Service - ok
23:28:07.0213 5420  [ C0EAD9F8AB83D41FF07303C75589C2B8 ] Creative Audio Engine Licensing Service C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
23:28:07.0338 5420  Creative Audio Engine Licensing Service - ok
23:28:07.0354 5420  [ D64EF74FC6DA47EC2E460076F299E77D ] CryptSvc        C:\WINDOWS\system32\cryptsvc.dll
23:28:07.0354 5420  CryptSvc - ok
23:28:07.0354 5420  [ 69CDBA2B9C397E349A04FA70DD9170A2 ] CTAudSvcService C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
23:28:07.0416 5420  CTAudSvcService - ok
23:28:07.0432 5420  [ 807935024E2CCCF9D13BD5E3A8592204 ] CybereasonRansomFree C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFreeServiceHost.exe
23:28:07.0448 5420  CybereasonRansomFree - ok
23:28:07.0448 5420  [ 72BE43ABD786E86AAE7EA2193201E100 ] dam             C:\WINDOWS\system32\drivers\dam.sys
23:28:07.0463 5420  dam - ok
23:28:07.0479 5420  [ 79BDBB684629A526CCD958F06B9D6FAD ] DcomLaunch      C:\WINDOWS\system32\rpcss.dll
23:28:07.0494 5420  DcomLaunch - ok
23:28:07.0494 5420  [ F7FB921F438C3566CEC55657EA4E7D9C ] defragsvc       C:\WINDOWS\System32\defragsvc.dll
23:28:07.0510 5420  defragsvc - ok
23:28:07.0510 5420  [ B5F9123D6537856EA698386ABA27A232 ] DeviceAssociationService C:\WINDOWS\system32\das.dll
23:28:07.0526 5420  DeviceAssociationService - ok
23:28:07.0526 5420  [ 64A80A746FC460126FA4124AA2D93848 ] DeviceInstall   C:\WINDOWS\system32\umpnpmgr.dll
23:28:07.0541 5420  DeviceInstall - ok
23:28:07.0541 5420  [ A19F51A044B62C994144ED87A7A5A887 ] DevicesFlowUserSvc C:\WINDOWS\System32\DevicesFlowBroker.dll
23:28:07.0557 5420  DevicesFlowUserSvc - ok
23:28:07.0557 5420  [ 0D2A4CA81D1F7B5E5FBFE1E4F60246B8 ] DevQueryBroker  C:\WINDOWS\system32\DevQueryBroker.dll
23:28:07.0557 5420  DevQueryBroker - ok
23:28:07.0573 5420  [ 9910E9CFF5ECDCB225F82E72CE9DE459 ] Dfsc            C:\WINDOWS\system32\Drivers\dfsc.sys
23:28:07.0573 5420  Dfsc - ok
23:28:07.0573 5420  [ 309F4FBA6AC2CA70663C99690AE900C2 ] Dhcp            C:\WINDOWS\system32\dhcpcore.dll
23:28:07.0588 5420  Dhcp - ok
23:28:07.0588 5420  [ 8C46ADC4354DDE94CA459CB4BA822073 ] diagnosticshub.standardcollector.service C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
23:28:07.0588 5420  diagnosticshub.standardcollector.service - ok
23:28:07.0604 5420  [ E2BF09B816393AF73EDCB8ECF9BBDB2D ] diagsvc         C:\WINDOWS\system32\DiagSvc.dll
23:28:07.0604 5420  diagsvc - ok
23:28:07.0635 5420  [ 93AE3D0B61365651158E3C11F0A26228 ] DiagTrack       C:\WINDOWS\system32\diagtrack.dll
23:28:07.0651 5420  DiagTrack - ok
23:28:07.0666 5420  [ 811173C821171BB910219E53C7FD97AD ] Disk            C:\WINDOWS\system32\drivers\disk.sys
23:28:07.0666 5420  Disk - ok
23:28:07.0682 5420  [ 133E5277C2A50770EADFAC4AF2232D69 ] DmEnrollmentSvc C:\WINDOWS\system32\Windows.Internal.Management.dll
23:28:07.0682 5420  DmEnrollmentSvc - ok
23:28:07.0698 5420  [ 569FE16775E15A49DC904DE20BF8CAA0 ] dmvsc           C:\WINDOWS\System32\drivers\dmvsc.sys
23:28:07.0698 5420  dmvsc - ok
23:28:07.0698 5420  [ 10E72E3315305461D3F0C7560AE98CA5 ] dmwappushservice C:\WINDOWS\system32\dmwappushsvc.dll
23:28:07.0698 5420  dmwappushservice - ok
23:28:07.0713 5420  [ 4ACA3CE75B4C2243299C24A715E9B3CE ] Dnscache        C:\WINDOWS\System32\dnsrslvr.dll
23:28:07.0713 5420  Dnscache - ok
23:28:07.0729 5420  [ 24F0CF56DF2725291937B32597BA8D51 ] dot3svc         C:\WINDOWS\System32\dot3svc.dll
23:28:07.0729 5420  dot3svc - ok
23:28:07.0744 5420  [ 6D8971C942FEE43A0AB6B3192534AFB4 ] DPS             C:\WINDOWS\system32\dps.dll
23:28:07.0744 5420  DPS - ok
23:28:07.0744 5420  [ F4800922F4ABA619585CE320A72E6389 ] drmkaud         C:\WINDOWS\System32\drivers\drmkaud.sys
23:28:07.0744 5420  drmkaud - ok
23:28:07.0760 5420  [ A5A92C78F797E8459AF793540C05D26C ] DsmSvc          C:\WINDOWS\System32\DeviceSetupManager.dll
23:28:07.0760 5420  DsmSvc - ok
23:28:07.0760 5420  [ C7DC50CC0C6B0948A0C040622FCD70EA ] DsSvc           C:\WINDOWS\System32\DsSvc.dll
23:28:07.0776 5420  DsSvc - ok
23:28:07.0776 5420  [ 242176ADAFE7BA96CC7D72FFCE4A16C1 ] DusmSvc         C:\WINDOWS\System32\dusmsvc.dll
23:28:07.0776 5420  DusmSvc - ok
23:28:07.0807 5420  [ C248883ED585F2A309BE11AFD0C60318 ] DXGKrnl         C:\WINDOWS\System32\drivers\dxgkrnl.sys
23:28:07.0838 5420  DXGKrnl - ok
23:28:07.0838 5420  [ FA94398748930D840FE35A44F1D225A7 ] Eaphost         C:\WINDOWS\System32\eapsvc.dll
23:28:07.0838 5420  Eaphost - ok
23:28:07.0854 5420  [ 9FF412B8514C4465C4856E06C13FF921 ] EaseUS Agent    C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
23:28:07.0854 5420  EaseUS Agent - ok
23:28:07.0885 5420  [ C99D40C97841E0A7F0F90B8629593A97 ] ebdrv           C:\WINDOWS\system32\drivers\evbda.sys
23:28:07.0916 5420  ebdrv - ok
23:28:07.0932 5420  [ 94E06D509D50807774F35BEE3163E806 ] EFS             C:\WINDOWS\System32\lsass.exe
23:28:07.0932 5420  EFS - ok
23:28:07.0948 5420  [ 260BBD6B1ED06298E509B452354EDB91 ] EhStorClass     C:\WINDOWS\system32\drivers\EhStorClass.sys
23:28:07.0948 5420  EhStorClass - ok
23:28:07.0948 5420  [ F3BEBDC1B9DBA32F183079EAE6244837 ] EhStorTcgDrv    C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
23:28:07.0948 5420  EhStorTcgDrv - ok
23:28:07.0963 5420  [ A75880A9192B9DA69F46867B06276746 ] embeddedmode    C:\WINDOWS\System32\embeddedmodesvc.dll
23:28:07.0963 5420  embeddedmode - ok
23:28:07.0979 5420  [ 9E6CB1D3F6AD67AA7A2C831FB9B7E496 ] EntAppSvc       C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
23:28:07.0979 5420  EntAppSvc - ok
23:28:07.0979 5420  [ D1186D11D7FF6191CBC4BE68C8ADEAD2 ] epmntdrv        C:\WINDOWS\system32\epmntdrv.sys
23:28:07.0994 5420  epmntdrv - ok
23:28:07.0994 5420  [ 0E840AA66CAB02CBA9730C772BBE305B ] epp             C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp.sys
23:28:08.0026 5420  epp - ok
23:28:08.0026 5420  [ 1B63CA857FD03FD0A5A1379F2996784F ] ErrDev          C:\WINDOWS\System32\drivers\errdev.sys
23:28:08.0026 5420  ErrDev - ok
23:28:08.0041 5420  [ 20DF189AB6295E44AAC6D4610FAA9E85 ] ESProtectionDriver C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys
23:28:08.0041 5420  ESProtectionDriver - ok
23:28:08.0041 5420  [ C5713A2B4C9D9150041FB70C4A2ADE07 ] EUBAKUP         C:\WINDOWS\system32\drivers\eubakup.sys
23:28:08.0041 5420  EUBAKUP - ok
23:28:08.0057 5420  [ C5713A2B4C9D9150041FB70C4A2ADE07 ] EUBAKUP0        C:\WINDOWS\system32\drivers\EUBAKUP0.sys
23:28:08.0057 5420  EUBAKUP0 - ok
23:28:08.0057 5420  [ 5061B571167E1EE26E8D549CCDBE9CC6 ] EUBKMON         C:\WINDOWS\system32\drivers\EUBKMON.sys
23:28:08.0057 5420  EUBKMON - ok
23:28:08.0073 5420  [ 5061B571167E1EE26E8D549CCDBE9CC6 ] EUBKMON0        C:\WINDOWS\system32\drivers\EUBKMON0.sys
23:28:08.0073 5420  EUBKMON0 - ok
23:28:08.0073 5420  [ 44A0838432C8A31A5D6CBE0BF348CED6 ] EUDSKACS        C:\Windows\system32\drivers\eudskacs.sys
23:28:08.0073 5420  EUDSKACS - ok
23:28:08.0088 5420  [ D05585505CB20235E7C665158464551D ] EUFDDISK        C:\Windows\system32\drivers\EuFdDisk.sys
23:28:08.0088 5420  EUFDDISK - ok
23:28:08.0088 5420  [ 6B133EE401475A72D252D49F8736936E ] EUFDDISK0       C:\WINDOWS\system32\drivers\EUFDDISK0.sys
23:28:08.0104 5420  EUFDDISK0 - ok
23:28:08.0104 5420  [ 08C997734B2CECE882656BB2855E6E76 ] EuGdiDrv        C:\WINDOWS\system32\EuGdiDrv.sys
23:28:08.0104 5420  EuGdiDrv - ok
23:28:08.0119 5420  [ 6A5FA501A2D96001391FF3CBA32935AB ] EventSystem     C:\WINDOWS\system32\es.dll
23:28:08.0119 5420  EventSystem - ok
23:28:08.0135 5420  [ F1ACA42D448E3986565EA54275EEEA65 ] exfat           C:\WINDOWS\system32\drivers\exfat.sys
23:28:08.0135 5420  exfat - ok
23:28:08.0151 5420  [ 0AF4B36754A6EAE794EE4398E219A9E1 ] fastfat         C:\WINDOWS\system32\drivers\fastfat.sys
23:28:08.0151 5420  fastfat - ok
23:28:08.0166 5420  [ B1A38C0D977D8738779CA3EFEBDFCA8C ] Fax             C:\WINDOWS\system32\fxssvc.exe
23:28:08.0166 5420  Fax - ok
23:28:08.0182 5420  [ 7CD8426A33F06EB72BFEC51F7C264AF8 ] fdc             C:\WINDOWS\System32\drivers\fdc.sys
23:28:08.0182 5420  fdc - ok
23:28:08.0182 5420  [ 21EB16C5DDFBC19DEBE9EEC10EA423FB ] fdPHost         C:\WINDOWS\system32\fdPHost.dll
23:28:08.0182 5420  fdPHost - ok
23:28:08.0182 5420  [ 57F98EFE6CB82AE5400BA99C705AF45C ] FDResPub        C:\WINDOWS\system32\fdrespub.dll
23:28:08.0198 5420  FDResPub - ok
23:28:08.0198 5420  [ 02F93E4B9EC2821B6670208044FF5332 ] fhsvc           C:\WINDOWS\system32\fhsvc.dll
23:28:08.0198 5420  fhsvc - ok
23:28:08.0213 5420  [ DE51BBBCF358188F9736F031546F9908 ] FileCrypt       C:\WINDOWS\system32\drivers\filecrypt.sys
23:28:08.0213 5420  FileCrypt - ok
23:28:08.0213 5420  [ 822F664952B0F8D11BB6BD2F11779602 ] FileInfo        C:\WINDOWS\system32\drivers\fileinfo.sys
23:28:08.0213 5420  FileInfo - ok
23:28:08.0229 5420  [ 5A4935682A0D47A4EAC4BE3C2ACF74D6 ] Filetrace       C:\WINDOWS\system32\drivers\filetrace.sys
23:28:08.0229 5420  Filetrace - ok
23:28:08.0229 5420  [ 60641F22D1D38EAD197C25F0339C9712 ] flpydisk        C:\WINDOWS\System32\drivers\flpydisk.sys
23:28:08.0229 5420  flpydisk - ok
23:28:08.0244 5420  [ 0C98D8F7867A8644EDA43865B15908C0 ] FltMgr          C:\WINDOWS\system32\drivers\fltmgr.sys
23:28:08.0244 5420  FltMgr - ok
23:28:08.0260 5420  [ 9DCB91239DE1FE05F870AE3471E70559 ] FontCache       C:\WINDOWS\system32\FntCache.dll
23:28:08.0291 5420  FontCache - ok
23:28:08.0291 5420  [ A7C6894FFF261C0FEFDCB41BE83CF430 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
23:28:08.0291 5420  FontCache3.0.0.0 - ok
23:28:08.0307 5420  [ 6793F7AE8442C487C55352C78739E77A ] FrameServer     C:\WINDOWS\system32\FrameServer.dll
23:28:08.0307 5420  FrameServer - ok
23:28:08.0323 5420  [ FB55F4ACC55261B25B3FF1B5BF87F10A ] FsDepends       C:\WINDOWS\system32\drivers\FsDepends.sys
23:28:08.0323 5420  FsDepends - ok
23:28:08.0323 5420  [ BB82CC2F51F7C3D5DCD13FA3B040D8F8 ] Fs_Rec          C:\WINDOWS\system32\drivers\Fs_Rec.sys
23:28:08.0323 5420  Fs_Rec - ok
23:28:08.0338 5420  [ 11C39CA2326F1F1DBEC11C7A3D26A6A4 ] fvevol          C:\WINDOWS\system32\DRIVERS\fvevol.sys
23:28:08.0354 5420  fvevol - ok
23:28:08.0354 5420  [ 3B5DDF1061930A0A891FA63DB0CB878B ] gencounter      C:\WINDOWS\System32\drivers\vmgencounter.sys
23:28:08.0354 5420  gencounter - ok
23:28:08.0354 5420  [ 8B34E3F794F652082D7E8AF112F71681 ] genericusbfn    C:\WINDOWS\System32\drivers\genericusbfn.sys
23:28:08.0354 5420  genericusbfn - ok
23:28:08.0369 5420  [ 127C23F4720C8902A3AB0FEE12205317 ] GPIOClx0101     C:\WINDOWS\system32\Drivers\msgpioclx.sys
23:28:08.0369 5420  GPIOClx0101 - ok
23:28:08.0385 5420  [ A7A85B505944F99CB55C8669E4F7FC0F ] gpsvc           C:\WINDOWS\System32\gpsvc.dll
23:28:08.0401 5420  gpsvc - ok
23:28:08.0401 5420  [ C7DEA3458E50B691E69EFF0B47CBCCDB ] GpuEnergyDrv    C:\WINDOWS\system32\drivers\gpuenergydrv.sys
23:28:08.0401 5420  GpuEnergyDrv - ok
23:28:08.0416 5420  [ 141904F0581468B39B579EA33CA57549 ] GraphicsPerfSvc C:\WINDOWS\System32\GraphicsPerfSvc.dll
23:28:08.0416 5420  GraphicsPerfSvc - ok
23:28:08.0416 5420  [ E1B44A75947137F4143308D566889837 ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
23:28:08.0416 5420  gupdate - ok
23:28:08.0432 5420  [ E1B44A75947137F4143308D566889837 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
23:28:08.0432 5420  gupdatem - ok
23:28:08.0432 5420  [ 6B76F5915654F647B06EDBE63BCB5116 ] HdAudAddService C:\WINDOWS\system32\DRIVERS\HdAudio.sys
23:28:08.0448 5420  HdAudAddService - ok
23:28:08.0448 5420  [ 99A34FD1F6431A10D8C3BB50E170D0F2 ] HDAudBus        C:\WINDOWS\System32\drivers\HDAudBus.sys
23:28:08.0448 5420  HDAudBus - ok
23:28:08.0463 5420  [ 2443FC6EEB9CF092B62127D867901B02 ] HidBatt         C:\WINDOWS\System32\drivers\HidBatt.sys
23:28:08.0463 5420  HidBatt - ok
23:28:08.0463 5420  [ 205043CDC16ADE85E252DD54AE925161 ] HidBth          C:\WINDOWS\System32\drivers\hidbth.sys
23:28:08.0463 5420  HidBth - ok
23:28:08.0479 5420  [ B521DDDC9038C066B1B957BF063A531A ] hidi2c          C:\WINDOWS\System32\drivers\hidi2c.sys
23:28:08.0479 5420  hidi2c - ok
23:28:08.0479 5420  [ 5AC0EBFA76E93273A806176D3178E986 ] hidinterrupt    C:\WINDOWS\System32\drivers\hidinterrupt.sys
23:28:08.0479 5420  hidinterrupt - ok
23:28:08.0494 5420  [ 366AC0E05EBF5D5C375F65CD8BC7F0DF ] HidIr           C:\WINDOWS\System32\drivers\hidir.sys
23:28:08.0494 5420  HidIr - ok
23:28:08.0494 5420  [ 75F4CCB7FF03603E91DD0C7FF83DAABF ] hidserv         C:\WINDOWS\system32\hidserv.dll
23:28:08.0510 5420  hidserv - ok
23:28:08.0510 5420  [ 7CB54D02746024648FCE184FC3F941FF ] HidUsb          C:\WINDOWS\System32\drivers\hidusb.sys
23:28:08.0510 5420  HidUsb - ok
23:28:08.0510 5420  [ 7FD586369B597798535C098E63818AAC ] hitmanpro37     C:\WINDOWS\system32\drivers\hitmanpro37.sys
23:28:08.0526 5420  hitmanpro37 - ok
23:28:08.0526 5420  [ CF07C0A9D38A248D036DD9C47E4D0D6E ] hmpalert        C:\WINDOWS\system32\drivers\hmpalert.sys
23:28:08.0526 5420  hmpalert - ok
23:28:08.0557 5420  [ 2638395F6E61889D75C363A80A0E17F4 ] hmpalertsvc     C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe
23:28:08.0573 5420  hmpalertsvc - ok
23:28:08.0573 5420  [ B5E3F4730F2471C76946E04645203690 ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
23:28:08.0573 5420  HomeGroupListener - ok
23:28:08.0588 5420  [ 24C900B7296AA9867FB761A5801AFBD1 ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
23:28:08.0604 5420  HomeGroupProvider - ok
23:28:08.0604 5420  [ 835FB95D85D362057A72D21A48C2C7F8 ] HpSAMD          C:\WINDOWS\system32\drivers\HpSAMD.sys
23:28:08.0604 5420  HpSAMD - ok
23:28:08.0619 5420  [ 82C0A5B7D21442D063FFAFD0B6AAC086 ] HTTP            C:\WINDOWS\system32\drivers\HTTP.sys
23:28:08.0635 5420  HTTP - ok
23:28:08.0635 5420  [ AD930879F319969EB09449C015A32104 ] HvHost          C:\WINDOWS\System32\hvhostsvc.dll
23:28:08.0635 5420  HvHost - ok
23:28:08.0651 5420  [ 9F2CFC90306532866C62BDCDFD2532AA ] hvservice       C:\WINDOWS\system32\drivers\hvservice.sys
23:28:08.0651 5420  hvservice - ok
23:28:08.0651 5420  [ 3737FE486929AFC48F1D10677B698E52 ] HwNClx0101      C:\WINDOWS\system32\Drivers\mshwnclx.sys
23:28:08.0651 5420  HwNClx0101 - ok
23:28:08.0666 5420  [ 3C65EBF7F1BFD98426C355D66876ECEE ] hwpolicy        C:\WINDOWS\system32\drivers\hwpolicy.sys
23:28:08.0666 5420  hwpolicy - ok
23:28:08.0666 5420  [ 7E00234C67A322988AFEA717D5609C9E ] hyperkbd        C:\WINDOWS\System32\drivers\hyperkbd.sys
23:28:08.0666 5420  hyperkbd - ok
23:28:08.0666 5420  [ FBF5BB641DE99AE1DF4835E88D4F8993 ] HyperVideo      C:\WINDOWS\System32\drivers\HyperVideo.sys
23:28:08.0682 5420  HyperVideo - ok
23:28:08.0682 5420  [ 56FF074E50F9042FD2856AB3418F4B18 ] i8042prt        C:\WINDOWS\System32\drivers\i8042prt.sys
23:28:08.0682 5420  i8042prt - ok
23:28:08.0698 5420  [ B5EC43755E62591197DE5CBBDAA9FEB7 ] iagpio          C:\WINDOWS\System32\drivers\iagpio.sys
23:28:08.0698 5420  iagpio - ok
23:28:08.0698 5420  [ D8CA23F9C5FEF44296FDE1E005C06EC0 ] iai2c           C:\WINDOWS\System32\drivers\iai2c.sys
23:28:08.0698 5420  iai2c - ok
23:28:08.0698 5420  [ 7B769C9D19C013F94874C4B15D59A005 ] iaLPSS2i_GPIO2  C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys
23:28:08.0713 5420  iaLPSS2i_GPIO2 - ok
23:28:08.0713 5420  [ E0F1B3A2A70FABE3BE1C9140BB55E607 ] iaLPSS2i_GPIO2_BXT_P C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys
23:28:08.0713 5420  iaLPSS2i_GPIO2_BXT_P - ok
23:28:08.0729 5420  [ 89A869BCC0588A3009ECB875B09ECD39 ] iaLPSS2i_I2C    C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys
23:28:08.0729 5420  iaLPSS2i_I2C - ok
23:28:08.0729 5420  [ 2E693DF3C02A0859DB8DE25772751100 ] iaLPSS2i_I2C_BXT_P C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys
23:28:08.0729 5420  iaLPSS2i_I2C_BXT_P - ok
23:28:08.0744 5420  [ 16A10CCEDCF5AC4CAAE43DC9FC40392F ] iaLPSSi_GPIO    C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys
23:28:08.0744 5420  iaLPSSi_GPIO - ok
23:28:08.0744 5420  [ EB82A11613326691508D9ED9A4FE29E7 ] iaLPSSi_I2C     C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys
23:28:08.0744 5420  iaLPSSi_I2C - ok
23:28:08.0760 5420  [ 435883A27A376B125BD4DF888417C85F ] iaStorAV        C:\WINDOWS\system32\drivers\iaStorAV.sys
23:28:08.0776 5420  iaStorAV - ok
23:28:08.0776 5420  [ 7118E4390C4ACDE61E280CE52BCAF44E ] iaStorV         C:\WINDOWS\system32\drivers\iaStorV.sys
23:28:08.0776 5420  iaStorV - ok
23:28:08.0791 5420  [ 9DBE8C359ABACE1BE1BBAB687D114506 ] ibbus           C:\WINDOWS\System32\drivers\ibbus.sys
23:28:08.0807 5420  ibbus - ok
23:28:08.0807 5420  [ 113F3C05CE9B41144E6BF5FEDA4F09B7 ] icssvc          C:\WINDOWS\System32\tetheringservice.dll
23:28:08.0807 5420  icssvc - ok
23:28:08.0823 5420  [ 72AB18B50053FA57B08FD4065C11B16B ] IKEEXT          C:\WINDOWS\System32\ikeext.dll
23:28:08.0838 5420  IKEEXT - ok
23:28:08.0838 5420  [ 42CAF6216A6E516DC56BA319ACC7EEC5 ] IndirectKmd     C:\WINDOWS\System32\drivers\IndirectKmd.sys
23:28:08.0838 5420  IndirectKmd - ok
23:28:08.0869 5420  [ 329223D4AB29B4392E83304C304EF80D ] InstallService  C:\WINDOWS\system32\InstallService.dll
23:28:08.0885 5420  InstallService - ok
23:28:08.0916 5420  [ C44251AF46727BA1A4D2A703255C9071 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
23:28:08.0963 5420  IntcAzAudAddService - ok
23:28:08.0963 5420  [ 40943C1CD031ACE06A8374AD56B9E5EA ] intelide        C:\WINDOWS\system32\drivers\intelide.sys
23:28:08.0963 5420  intelide - ok
23:28:08.0979 5420  [ 327D9CCF5492543AEF3979F9EEAD02BE ] intelpep        C:\WINDOWS\system32\drivers\intelpep.sys
23:28:08.0979 5420  intelpep - ok
23:28:08.0979 5420  [ 10F2757836F41BFAEA2AE19F6FE869B2 ] intelppm        C:\WINDOWS\System32\drivers\intelppm.sys
23:28:08.0994 5420  intelppm - ok
23:28:08.0994 5420  [ E7E63F634298F3033B90B988A038698E ] IntuitUpdateServiceV4 C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
23:28:08.0994 5420  IntuitUpdateServiceV4 - ok
23:28:08.0994 5420  [ 8387E90B551B9B7F32EDC69909591E9E ] invdimm         C:\WINDOWS\System32\drivers\invdimm.sys
23:28:09.0010 5420  invdimm - ok
23:28:09.0010 5420  [ E207078E0E1BB3524277DB9077E4148E ] iorate          C:\WINDOWS\system32\drivers\iorate.sys
23:28:09.0010 5420  iorate - ok
23:28:09.0010 5420  [ FD8F64B7B345E539F2EA7F72846F83B4 ] IpFilterDriver  C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
23:28:09.0026 5420  IpFilterDriver - ok
23:28:09.0026 5420  [ 0076CE11539416052A7A79B2DCC53E6D ] iphlpsvc        C:\WINDOWS\System32\iphlpsvc.dll
23:28:09.0041 5420  iphlpsvc - ok
23:28:09.0041 5420  [ 8AAB863E72A4F9C578FED2EE3541545B ] IPMIDRV         C:\WINDOWS\System32\drivers\IPMIDrv.sys
23:28:09.0041 5420  IPMIDRV - ok
23:28:09.0057 5420  [ 7BEC2AF23F586EFF0DB4DBF4331B0C70 ] IPNAT           C:\WINDOWS\system32\drivers\ipnat.sys
23:28:09.0057 5420  IPNAT - ok
23:28:09.0057 5420  [ 35A54F19E703D4FE5919F812F6CC5D0A ] IPT             C:\WINDOWS\System32\drivers\ipt.sys
23:28:09.0073 5420  IPT - ok
23:28:09.0073 5420  [ F6C47021C41F721B628161B64D7DECB9 ] IpxlatCfgSvc    C:\WINDOWS\System32\IpxlatCfg.dll
23:28:09.0073 5420  IpxlatCfgSvc - ok
23:28:09.0088 5420  [ 359CDDBC825959DA28FA886B3C271B53 ] irda            C:\WINDOWS\system32\drivers\irda.sys
23:28:09.0088 5420  irda - ok
23:28:09.0088 5420  [ F88664A2A82DDA456180FFF95A771765 ] IRENUM          C:\WINDOWS\system32\drivers\irenum.sys
23:28:09.0088 5420  IRENUM - ok
23:28:09.0104 5420  [ 4F500A0171606B0E37964694140FCA16 ] irmon           C:\WINDOWS\System32\irmon.dll
23:28:09.0104 5420  irmon - ok
23:28:09.0104 5420  [ 2296B158C43C306B0AC5B4D57EA9F0E1 ] isapnp          C:\WINDOWS\system32\drivers\isapnp.sys
23:28:09.0104 5420  isapnp - ok
23:28:09.0119 5420  [ 2DC0765992CFECE3B13F3BFD20E69DCC ] iScsiPrt        C:\WINDOWS\System32\drivers\msiscsi.sys
23:28:09.0119 5420  iScsiPrt - ok
23:28:09.0119 5420  [ 73A968D4A85BB2552DDCF72CB15F06D2 ] JRAID           C:\WINDOWS\system32\drivers\jraid.sys
23:28:09.0135 5420  JRAID - ok
23:28:09.0135 5420  [ E320F986BBE0CD9324EA0A193EBF29B1 ] kbdclass        C:\WINDOWS\System32\drivers\kbdclass.sys
23:28:09.0135 5420  kbdclass - ok
23:28:09.0135 5420  [ AFF5DDCC1A79217C9526FF5E01A69E89 ] kbdhid          C:\WINDOWS\System32\drivers\kbdhid.sys
23:28:09.0151 5420  kbdhid - ok
23:28:09.0151 5420  [ 916E62AF3386F7A74603E5C545F6FF2D ] kdnic           C:\WINDOWS\System32\drivers\kdnic.sys
23:28:09.0151 5420  kdnic - ok
23:28:09.0166 5420  [ 547E9B25B4407A125D5F187E918BC217 ] keycrypt        C:\WINDOWS\system32\DRIVERS\KeyCrypt64.sys
23:28:09.0166 5420  keycrypt - ok
23:28:09.0166 5420  [ 94E06D509D50807774F35BEE3163E806 ] KeyIso          C:\WINDOWS\system32\lsass.exe
23:28:09.0166 5420  KeyIso - ok
23:28:09.0182 5420  [ FD7D7B7925E5198A4583E8C1D03D861B ] KSecDD          C:\WINDOWS\system32\Drivers\ksecdd.sys
23:28:09.0182 5420  KSecDD - ok
23:28:09.0182 5420  [ C1081E2B36F77781167FD9401119B98E ] KSecPkg         C:\WINDOWS\system32\Drivers\ksecpkg.sys
23:28:09.0182 5420  KSecPkg - ok
23:28:09.0198 5420  [ DD8C4726127CFE313233372D70787C37 ] ksthunk         C:\WINDOWS\system32\drivers\ksthunk.sys
23:28:09.0198 5420  ksthunk - ok
23:28:09.0213 5420  [ 6EAF246BC12DB548AC65A4CEFB14B547 ] KtmRm           C:\WINDOWS\system32\msdtckrm.dll
23:28:09.0213 5420  KtmRm - ok
23:28:09.0213 5420  [ E154D11E1EDAD53DF6A2204F3A604F28 ] LanmanServer    C:\WINDOWS\system32\srvsvc.dll
23:28:09.0229 5420  LanmanServer - ok
23:28:09.0229 5420  [ DBB81AAC130C4CAAB87E519467846A06 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
23:28:09.0244 5420  LanmanWorkstation - ok
23:28:09.0244 5420  [ D81931EF9914A135F9ECF409DC826266 ] lfsvc           C:\WINDOWS\System32\lfsvc.dll
23:28:09.0244 5420  lfsvc - ok
23:28:09.0260 5420  [ F180F46B88044C6F6D3C313A799E5857 ] LicenseManager  C:\WINDOWS\system32\LicenseManagerSvc.dll
23:28:09.0260 5420  LicenseManager - ok
23:28:09.0260 5420  [ CB5A6E117502156794F0DA9E61506006 ] lltdio          C:\WINDOWS\system32\drivers\lltdio.sys
23:28:09.0260 5420  lltdio - ok
23:28:09.0276 5420  [ 48199253D7F6119F88294F8845F0808D ] lltdsvc         C:\WINDOWS\System32\lltdsvc.dll
23:28:09.0276 5420  lltdsvc - ok
23:28:09.0291 5420  [ DCF6F1AA7A51CC08FED089363F83316E ] lmhosts         C:\WINDOWS\System32\lmhsvc.dll
23:28:09.0291 5420  lmhosts - ok
23:28:09.0291 5420  [ 20048BEE892138A745B1C23EBB0E069F ] LSI_SAS         C:\WINDOWS\system32\drivers\lsi_sas.sys
23:28:09.0307 5420  LSI_SAS - ok
23:28:09.0307 5420  [ 9EAB16572B576979D585DDEDB12417CD ] LSI_SAS2i       C:\WINDOWS\system32\drivers\lsi_sas2i.sys
23:28:09.0307 5420  LSI_SAS2i - ok
23:28:09.0323 5420  [ 3B7B359C0870317106DF3438D4FF491D ] LSI_SAS3i       C:\WINDOWS\system32\drivers\lsi_sas3i.sys
23:28:09.0323 5420  LSI_SAS3i - ok
23:28:09.0323 5420  [ 2DE03BA338A4B0ACDB416A30F1C7D56F ] LSI_SSS         C:\WINDOWS\system32\drivers\lsi_sss.sys
23:28:09.0323 5420  LSI_SSS - ok
23:28:09.0338 5420  [ CB538B44AC849D6D3A7D73B32A821DD9 ] LSM             C:\WINDOWS\System32\lsm.dll
23:28:09.0354 5420  LSM - ok
23:28:09.0354 5420  [ 9A497169E145FCE2D8AA7DBC67377F64 ] luafv           C:\WINDOWS\system32\drivers\luafv.sys
23:28:09.0354 5420  luafv - ok
23:28:09.0401 5420  [ 3176B64DAF37A70CD1F6BD57EB3825DE ] MacriumService  C:\Program Files\Macrium\Common\MacriumService.exe
23:28:09.0479 5420  MacriumService - ok
23:28:09.0494 5420  [ 3520DE00ABC5EFF0DBAFD41129AD970F ] MapsBroker      C:\WINDOWS\System32\moshost.dll
23:28:09.0494 5420  MapsBroker - ok
23:28:09.0494 5420  [ BF56CB9D02DEE8CA9CBA50220BE16F15 ] mausbhost       C:\WINDOWS\System32\drivers\mausbhost.sys
23:28:09.0510 5420  mausbhost - ok
23:28:09.0510 5420  [ 01BDEE1FFF6D2216797DFEE4ABD937D9 ] mausbip         C:\WINDOWS\System32\drivers\mausbip.sys
23:28:09.0510 5420  mausbip - ok
23:28:09.0573 5420  [ 164E27CF533B72CB9169E73C0315CA7C ] MB3Service      C:\Program Files\Malwarebytes\Anti-Ransomware\mb3service.exe
23:28:09.0619 5420  MB3Service - ok
23:28:09.0635 5420  [ 94FCA94EE7937EA3ED75F39DE4C8E292 ] MB3SwissArmy    C:\WINDOWS\system32\drivers\MB3SwissArmy.sys
23:28:09.0635 5420  MB3SwissArmy - ok
23:28:09.0651 5420  [ BBCE66F3D1C974A18337D57EA92BB314 ] MbaeSvc         C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
23:28:09.0651 5420  MbaeSvc - ok
23:28:09.0651 5420  [ 67173D816A3D957AC190813D2490F15B ] MBAMFarflt      C:\WINDOWS\system32\DRIVERS\farflt.sys
23:28:09.0651 5420  MBAMFarflt - ok
23:28:09.0666 5420  [ 78488AF2AB2111D67B3C4044707A519B ] MBAMSwissArmy   C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
23:28:09.0666 5420  MBAMSwissArmy - ok
23:28:09.0666 5420  [ C7B8B5053D646CBD30BE1BA6B487D396 ] megasas         C:\WINDOWS\system32\drivers\megasas.sys
23:28:09.0682 5420  megasas - ok
23:28:09.0682 5420  [ EB8ED3204499DDB2D3BA094A4563EE3E ] megasas2i       C:\WINDOWS\system32\drivers\MegaSas2i.sys
23:28:09.0682 5420  megasas2i - ok
23:28:09.0698 5420  [ F1C1D4E752DE1D58295040E5BE8813AF ] megasr          C:\WINDOWS\system32\drivers\megasr.sys
23:28:09.0698 5420  megasr - ok
23:28:09.0713 5420  [ 4965456A1B4B3039E4B9AB233F5E9B1E ] MessagingService C:\WINDOWS\System32\MessagingService.dll
23:28:09.0713 5420  MessagingService - ok
23:28:09.0729 5420  [ 16B078D1089FEA98710C9D07C152DCEE ] mlx4_bus        C:\WINDOWS\System32\drivers\mlx4_bus.sys
23:28:09.0729 5420  mlx4_bus - ok
23:28:09.0744 5420  [ 20C57CE47B1A877C48A4B68E9A4E21FA ] MMCSS           C:\WINDOWS\system32\drivers\mmcss.sys
23:28:09.0744 5420  MMCSS - ok
23:28:09.0744 5420  [ A4467A5C080318F0CCCF5ED463821F8B ] Modem           C:\WINDOWS\system32\drivers\modem.sys
23:28:09.0744 5420  Modem - ok
23:28:09.0744 5420  [ 78BE85C1F1C7F3AF6C87BCE127007D5A ] monitor         C:\WINDOWS\System32\drivers\monitor.sys
23:28:09.0760 5420  monitor - ok
23:28:09.0760 5420  [ 8E262B34A8BD184B4B3025AA8C396B00 ] mouclass        C:\WINDOWS\System32\drivers\mouclass.sys
23:28:09.0760 5420  mouclass - ok
23:28:09.0760 5420  [ C094A555F148495EA130D3BBC5232D5E ] mouhid          C:\WINDOWS\System32\drivers\mouhid.sys
23:28:09.0760 5420  mouhid - ok
23:28:09.0776 5420  [ 6434BC884502E95EEA2379C92DD22B60 ] mountmgr        C:\WINDOWS\system32\drivers\mountmgr.sys
23:28:09.0776 5420  mountmgr - ok
23:28:09.0776 5420  [ 30813D30C0F03BB6D2B584C665C83F25 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
23:28:09.0791 5420  MozillaMaintenance - ok
23:28:09.0791 5420  [ F36E4074C66DD31855A8D79EF0AE8066 ] mpsdrv          C:\WINDOWS\system32\drivers\mpsdrv.sys
23:28:09.0791 5420  mpsdrv - ok
23:28:09.0807 5420  [ A2C216233E8A1CF98315E76EBF69D73D ] MpsSvc          C:\WINDOWS\system32\mpssvc.dll
23:28:09.0823 5420  MpsSvc - ok
23:28:09.0823 5420  [ 7D5F1C98D86698751B3B44426D34BDF1 ] MQAC            C:\WINDOWS\system32\drivers\mqac.sys
23:28:09.0823 5420  MQAC - ok
23:28:09.0838 5420  [ 215D672CB71987CD98EB2298EFB84DDC ] MRxDAV          C:\WINDOWS\system32\drivers\mrxdav.sys
23:28:09.0838 5420  MRxDAV - ok
23:28:09.0854 5420  [ 6FC2E733C7172B6BFAD383B108E56F92 ] mrxsmb          C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
23:28:09.0854 5420  mrxsmb - ok
23:28:09.0869 5420  [ 6537678DEEA2A5B079052D75E21E46DA ] mrxsmb10        C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys
23:28:09.0869 5420  mrxsmb10 - ok
23:28:09.0869 5420  [ 67361BDD0329A545670E6A90652FE347 ] mrxsmb20        C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
23:28:09.0869 5420  mrxsmb20 - ok
23:28:09.0885 5420  [ 167408B38458ECAE545C57527BC99024 ] MsBridge        C:\WINDOWS\system32\drivers\bridge.sys
23:28:09.0885 5420  MsBridge - ok
23:28:09.0885 5420  [ D5778559A0F34EE0BF0457293C6B5F4F ] MSDTC           C:\WINDOWS\System32\msdtc.exe
23:28:09.0901 5420  MSDTC - ok
23:28:09.0901 5420  [ AE111778CA6AC08862B3C713F0413333 ] Msfs            C:\WINDOWS\system32\drivers\Msfs.sys
23:28:09.0901 5420  Msfs - ok
23:28:09.0916 5420  [ 6DDDFCAB646BBBCFC583135C4430E10F ] msgpiowin32     C:\WINDOWS\System32\drivers\msgpiowin32.sys
23:28:09.0916 5420  msgpiowin32 - ok
23:28:09.0916 5420  [ 01C6A86BEA8279E557A5056148F068BF ] mshidkmdf       C:\WINDOWS\System32\drivers\mshidkmdf.sys
23:28:09.0916 5420  mshidkmdf - ok
23:28:09.0932 5420  [ F65ABC7DE945047147F17330F79732CB ] mshidumdf       C:\WINDOWS\System32\drivers\mshidumdf.sys
23:28:09.0932 5420  mshidumdf - ok
23:28:09.0932 5420  [ 05B23012427801E710BDD12720B9020B ] msisadrv        C:\WINDOWS\system32\drivers\msisadrv.sys
23:28:09.0932 5420  msisadrv - ok
23:28:09.0948 5420  [ 21B88DF67507BD4DFF8A5487074BB31F ] MSiSCSI         C:\WINDOWS\system32\iscsiexe.dll
23:28:09.0948 5420  MSiSCSI - ok
23:28:09.0948 5420  msiserver - ok
23:28:09.0963 5420  [ B25B2CD3E052D68075A3814AAA0C6421 ] MSKSSRV         C:\WINDOWS\System32\drivers\MSKSSRV.sys
23:28:09.0963 5420  MSKSSRV - ok
23:28:09.0963 5420  [ C3F5EA6B9041A30B4F11BE2E7863E487 ] MsLldp          C:\WINDOWS\system32\drivers\mslldp.sys
23:28:09.0963 5420  MsLldp - ok
23:28:09.0979 5420  [ 6F1422468DF5B12D87EF1B7956429721 ] MSMQ            C:\WINDOWS\system32\mqsvc.exe
23:28:09.0979 5420  MSMQ - ok
23:28:09.0979 5420  [ 601D666820F0408B896791D19BE6D258 ] MSPCLOCK        C:\WINDOWS\System32\drivers\MSPCLOCK.sys
23:28:09.0979 5420  MSPCLOCK - ok
23:28:09.0994 5420  [ 46E61FBA0097E48E5628C74A3F72233A ] MSPQM           C:\WINDOWS\System32\drivers\MSPQM.sys
23:28:09.0994 5420  MSPQM - ok
23:28:09.0994 5420  [ 4EB9B77179BDEE89C496E60D4BF85CC1 ] MsRPC           C:\WINDOWS\system32\drivers\MsRPC.sys
23:28:10.0010 5420  MsRPC - ok
23:28:10.0010 5420  [ CBD56E0B55FB3672BA80382EC2F8835C ] mssmbios        C:\WINDOWS\System32\drivers\mssmbios.sys
23:28:10.0010 5420  mssmbios - ok
23:28:10.0026 5420  [ 5734B2A36D3BB13A638E5305EEEC582D ] MSTEE           C:\WINDOWS\System32\drivers\MSTEE.sys
23:28:10.0026 5420  MSTEE - ok
23:28:10.0026 5420  [ 85270E0DC6907C6B99F72A36F17AED34 ] MTConfig        C:\WINDOWS\System32\drivers\MTConfig.sys
23:28:10.0026 5420  MTConfig - ok
23:28:10.0041 5420  [ DB5B1539F5EBB3DD3A7ED25ADBC4D6D9 ] Mup             C:\WINDOWS\system32\Drivers\mup.sys
23:28:10.0041 5420  Mup - ok
23:28:10.0041 5420  [ 3C57FF3BCF496D24C39C2198158864BB ] mvumis          C:\WINDOWS\system32\drivers\mvumis.sys
23:28:10.0041 5420  mvumis - ok
23:28:10.0057 5420  [ 4D3B95406A0F80E4A94ACC9B33477887 ] NativeWifiP     C:\WINDOWS\system32\DRIVERS\nwifi.sys
23:28:10.0057 5420  NativeWifiP - ok
23:28:10.0073 5420  [ 05ABAE6A2165B434A33043264E81F4DF ] NaturalAuthentication C:\WINDOWS\System32\NaturalAuth.dll
23:28:10.0088 5420  NaturalAuthentication - ok
23:28:10.0088 5420  [ FBA9F5B9F59A665F248F70B905EDCE14 ] NcaSvc          C:\WINDOWS\System32\ncasvc.dll
23:28:10.0104 5420  NcaSvc - ok
23:28:10.0104 5420  [ 1A75CBB2C8161676CEA17E6FFE441FE7 ] NcbService      C:\WINDOWS\System32\ncbservice.dll
23:28:10.0119 5420  NcbService - ok
23:28:10.0119 5420  [ 3C7E074AE41D8DFB41A9E65904D8BF43 ] NcdAutoSetup    C:\WINDOWS\System32\NcdAutoSetup.dll
23:28:10.0119 5420  NcdAutoSetup - ok
23:28:10.0135 5420  [ 77B047B109CE758A017F58FAE5038D0D ] ndfltr          C:\WINDOWS\System32\drivers\ndfltr.sys
23:28:10.0135 5420  ndfltr - ok
23:28:10.0151 5420  [ 9D46AAE948FF894FE979E518E2FC1532 ] NDIS            C:\WINDOWS\system32\drivers\ndis.sys
23:28:10.0166 5420  NDIS - ok
23:28:10.0166 5420  [ 067AE5BA349CC35AF8975D22DC483DDF ] NdisCap         C:\WINDOWS\system32\drivers\ndiscap.sys
23:28:10.0166 5420  NdisCap - ok
23:28:10.0182 5420  [ 6FC4D7EB5D38CFB7966405036116F065 ] NdisImPlatform  C:\WINDOWS\system32\drivers\NdisImPlatform.sys
23:28:10.0182 5420  NdisImPlatform - ok
23:28:10.0182 5420  [ ED7CC4E16B76B2603C9F827188EA63B4 ] NdisTapi        C:\WINDOWS\system32\DRIVERS\ndistapi.sys
23:28:10.0182 5420  NdisTapi - ok
23:28:10.0198 5420  [ 8D977AFC195A3F4B15B05D02B2BD0292 ] Ndisuio         C:\WINDOWS\system32\drivers\ndisuio.sys
23:28:10.0198 5420  Ndisuio - ok
23:28:10.0198 5420  [ DC1D26D62F40B7552BCF49D92774F0C5 ] NdisVirtualBus  C:\WINDOWS\System32\drivers\NdisVirtualBus.sys
23:28:10.0213 5420  NdisVirtualBus - ok
23:28:10.0213 5420  [ 66F56AC744101DB870934D0EB31C2426 ] NdisWan         C:\WINDOWS\System32\drivers\ndiswan.sys
23:28:10.0213 5420  NdisWan - ok
23:28:10.0229 5420  [ 66F56AC744101DB870934D0EB31C2426 ] ndiswanlegacy   C:\WINDOWS\system32\DRIVERS\ndiswan.sys
23:28:10.0229 5420  ndiswanlegacy - ok
23:28:10.0229 5420  [ AC908EF74DB5BC1DC7FB2BF0205D4FF1 ] ndproxy         C:\WINDOWS\system32\DRIVERS\NDProxy.sys
23:28:10.0229 5420  ndproxy - ok
23:28:10.0244 5420  [ A791792DC412CCD83DA0AF6871682552 ] Ndu             C:\WINDOWS\system32\drivers\Ndu.sys
23:28:10.0244 5420  Ndu - ok
23:28:10.0244 5420  [ BE79982A50AC88BC0765F3AFECFCB596 ] NetAdapterCx    C:\WINDOWS\system32\drivers\NetAdapterCx.sys
23:28:10.0260 5420  NetAdapterCx - ok
23:28:10.0260 5420  [ AAC1622CA213F7DA660A04FD51B730C3 ] NetBIOS         C:\WINDOWS\system32\drivers\netbios.sys
23:28:10.0260 5420  NetBIOS - ok
23:28:10.0276 5420  [ 401C17200AA0433D94EA61695F111DC3 ] NetBT           C:\WINDOWS\system32\DRIVERS\netbt.sys
23:28:10.0276 5420  NetBT - ok
23:28:10.0291 5420  [ 94E06D509D50807774F35BEE3163E806 ] Netlogon        C:\WINDOWS\system32\lsass.exe
23:28:10.0291 5420  Netlogon - ok
23:28:10.0291 5420  [ 94BC40F88309B0B7DFE68B2C2BB15EB6 ] Netman          C:\WINDOWS\System32\netman.dll
23:28:10.0307 5420  Netman - ok
23:28:10.0307 5420  [ 97FF2186BBAA215727300404862D297B ] NetMsmqActivator C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
23:28:10.0307 5420  NetMsmqActivator - ok
23:28:10.0323 5420  [ 97FF2186BBAA215727300404862D297B ] NetPipeActivator C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
23:28:10.0323 5420  NetPipeActivator - ok
23:28:10.0338 5420  [ 79ED54CA41486399361778D533E55A99 ] netprofm        C:\WINDOWS\System32\netprofmsvc.dll
23:28:10.0338 5420  netprofm - ok
23:28:10.0354 5420  [ 2D63501E7273F5B730958B5061E609D4 ] NetSetupSvc     C:\WINDOWS\System32\NetSetupSvc.dll
23:28:10.0354 5420  NetSetupSvc - ok
23:28:10.0369 5420  [ 97FF2186BBAA215727300404862D297B ] NetTcpActivator C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
23:28:10.0369 5420  NetTcpActivator - ok
23:28:10.0369 5420  [ 97FF2186BBAA215727300404862D297B ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
23:28:10.0369 5420  NetTcpPortSharing - ok
23:28:10.0385 5420  [ FD1DA80FF495D4B928A65F40FCCCF387 ] netvsc          C:\WINDOWS\System32\drivers\netvsc.sys
23:28:10.0385 5420  netvsc - ok
23:28:10.0401 5420  [ E27ACE78CA1BDF4FBBF3323D6E9AFCDB ] NgcCtnrSvc      C:\WINDOWS\System32\NgcCtnrSvc.dll
23:28:10.0401 5420  NgcCtnrSvc - ok
23:28:10.0416 5420  [ A557C92583E81CA97D2C0F2467E7C2F9 ] NgcSvc          C:\WINDOWS\system32\ngcsvc.dll
23:28:10.0432 5420  NgcSvc - ok
23:28:10.0448 5420  [ 622C7AA8D98331DAA75526A5E643FFD8 ] NlaSvc          C:\WINDOWS\System32\nlasvc.dll
23:28:10.0448 5420  NlaSvc - ok
23:28:10.0448 5420  [ 84EB8F01B140618518AFF30B9951F132 ] Npfs            C:\WINDOWS\system32\drivers\Npfs.sys
23:28:10.0448 5420  Npfs - ok
23:28:10.0463 5420  [ 5CB8082E51DE7D19042F0FF8C517CB0D ] npsvctrig       C:\WINDOWS\System32\drivers\npsvctrig.sys
23:28:10.0463 5420  npsvctrig - ok
23:28:10.0463 5420  [ 3BA4E9585E9D7D7E6E68A18184DDDBF2 ] nsi             C:\WINDOWS\system32\nsisvc.dll
23:28:10.0479 5420  nsi - ok
23:28:10.0479 5420  [ 958921BB7AE2671983743FDA0DD587C4 ] nsiproxy        C:\WINDOWS\system32\drivers\nsiproxy.sys
23:28:10.0479 5420  nsiproxy - ok
23:28:10.0513 5420  [ 4738811FFC33F2AC222FB2B82C14BECF ] NTFS            C:\WINDOWS\system32\drivers\NTFS.sys
23:28:10.0529 5420  NTFS - ok
23:28:10.0545 5420  [ 0D1E03A5F87F4DE04D97622C686910A2 ] Null            C:\WINDOWS\system32\drivers\Null.sys
23:28:10.0545 5420  Null - ok
23:28:10.0560 5420  [ 532F27A2B62D70C327E763F035AED6C1 ] nvdimmn         C:\WINDOWS\System32\drivers\nvdimmn.sys
23:28:10.0560 5420  nvdimmn - ok
23:28:10.0560 5420  [ 6DD0B2337F74336EB1F83C3866538F9B ] NVHDA           C:\WINDOWS\system32\drivers\nvhda64v.sys
23:28:10.0576 5420  NVHDA - ok
23:28:10.0748 5420  [ AD43497946938DB4C9462AE257F0E96A ] nvlddmkm        C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_c791f781cd94491f\nvlddmkm.sys
23:28:10.0904 5420  nvlddmkm - ok
23:28:10.0920 5420  [ 7E04652EB1A476BC0A72ECDC613AF0C5 ] nvraid          C:\WINDOWS\system32\drivers\nvraid.sys
23:28:10.0920 5420  nvraid - ok
23:28:10.0920 5420  [ 880B3E874914DAEF97119876543AE117 ] nvstor          C:\WINDOWS\system32\drivers\nvstor.sys
23:28:10.0920 5420  nvstor - ok
23:28:10.0935 5420  [ 76C6E6CCA51F4AF28F5C40EFE740C8F6 ] NvStreamKms     C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
23:28:10.0935 5420  NvStreamKms - ok
23:28:10.0935 5420  [ 2719BB9316C497344DD7DB688B6E5F7D ] NvTelemetryContainer C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
23:28:10.0951 5420  NvTelemetryContainer - ok
23:28:10.0951 5420  [ E502016A185B5BB9DC341873F82CD49C ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
23:28:10.0951 5420  nvvad_WaveExtensible - ok
23:28:10.0967 5420  [ 0E171374583E0A9AB76245CF1673EEEF ] nvvhci          C:\WINDOWS\System32\drivers\nvvhci.sys
23:28:10.0967 5420  nvvhci - ok
23:28:10.0967 5420  [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv          C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
23:28:10.0982 5420  odserv - ok
23:28:10.0982 5420  [ 51F93600272C855ADFE209473E9B95EE ] OneSyncSvc      C:\WINDOWS\System32\APHostService.dll
23:28:10.0998 5420  OneSyncSvc - ok
23:28:11.0013 5420  [ F40104B18DBE36381C662F73DEC3B351 ] Origin Client Service C:\Program Files (x86)\Origin\OriginClientService.exe
23:28:11.0045 5420  Origin Client Service - ok
23:28:11.0076 5420  [ F08F4D90861E3E31FFEE28427B8D13CA ] Origin Web Helper Service C:\Program Files (x86)\Origin\OriginWebHelperService.exe
23:28:11.0107 5420  Origin Web Helper Service - ok
23:28:11.0107 5420  [ 5A432A042DAE460ABE7199B758E8606C ] ose             C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
23:28:11.0107 5420  ose - ok
23:28:11.0138 5420  [ EDD1DCD36F6115ACC6935C3F88FF54D7 ] P17             C:\WINDOWS\system32\drivers\P17.sys
23:28:11.0170 5420  P17 - ok
23:28:11.0185 5420  [ 11404911B5ADC7A2DC58021DF0490AA6 ] p2pimsvc        C:\WINDOWS\system32\pnrpsvc.dll
23:28:11.0185 5420  p2pimsvc - ok
23:28:11.0201 5420  [ B7E60F11B397C58CCC4E815301A97352 ] p2psvc          C:\WINDOWS\system32\p2psvc.dll
23:28:11.0201 5420  p2psvc - ok
23:28:11.0217 5420  PAExec - ok
23:28:11.0217 5420  [ 2E07EC2C1622F5E7B535D62DCD61F3AB ] Parport         C:\WINDOWS\System32\drivers\parport.sys
23:28:11.0217 5420  Parport - ok
23:28:11.0232 5420  [ 269884AAC55AE567A0A955703C62CA29 ] partmgr         C:\WINDOWS\system32\drivers\partmgr.sys
23:28:11.0232 5420  partmgr - ok
23:28:11.0248 5420  [ 463BB1CE5C1A4F2E58EF7986213F4F74 ] PcaSvc          C:\WINDOWS\System32\pcasvc.dll
23:28:11.0248 5420  PcaSvc - ok
23:28:11.0263 5420  [ 5B329AD314E26B77DF4B603B8E65CA60 ] pci             C:\WINDOWS\system32\drivers\pci.sys
23:28:11.0263 5420  pci - ok
23:28:11.0263 5420  [ E5AF806815ED797086629741F29E4156 ] pciide          C:\WINDOWS\system32\drivers\pciide.sys
23:28:11.0279 5420  pciide - ok
23:28:11.0280 5420  [ 2A631D447B988AFBE847CBAA8E5CC298 ] pcmcia          C:\WINDOWS\system32\drivers\pcmcia.sys
23:28:11.0280 5420  pcmcia - ok
23:28:11.0280 5420  [ ACD510CF2B631A2D36B2CFB7D31E22FD ] pcw             C:\WINDOWS\system32\drivers\pcw.sys
23:28:11.0296 5420  pcw - ok
23:28:11.0296 5420  [ 1796112EB89559910BC18865A29C8894 ] pdc             C:\WINDOWS\system32\drivers\pdc.sys
23:28:11.0296 5420  pdc - ok
23:28:11.0312 5420  [ F21127EDE5D72090A1B029AFF4AFFD17 ] PEAUTH          C:\WINDOWS\system32\drivers\peauth.sys
23:28:11.0312 5420  PEAUTH - ok
23:28:11.0327 5420  [ 35FD028E4323018202C0B7D115FD3AEF ] percsas2i       C:\WINDOWS\system32\drivers\percsas2i.sys
23:28:11.0327 5420  percsas2i - ok
23:28:11.0327 5420  [ F9F3D8BE9BC9241CC726197261362AC4 ] percsas3i       C:\WINDOWS\system32\drivers\percsas3i.sys
23:28:11.0343 5420  percsas3i - ok
23:28:11.0359 5420  [ EA780FAE0D6796D56D0CAF39360BF7C0 ] PerfHost        C:\WINDOWS\SysWow64\perfhost.exe
23:28:11.0374 5420  PerfHost - ok
23:28:11.0390 5420  [ 28658894160747DB9B8C6A9E45EEE47C ] PhoneSvc        C:\WINDOWS\System32\PhoneService.dll
23:28:11.0405 5420  PhoneSvc - ok
23:28:11.0421 5420  [ 615FE5145C718A4072D42B1A761DCA9F ] PimIndexMaintenanceSvc C:\WINDOWS\System32\PimIndexMaintenance.dll
23:28:11.0421 5420  PimIndexMaintenanceSvc - ok
23:28:11.0437 5420  [ 73B5A132EBF3A8075A7C68DFBB4DE719 ] pla             C:\WINDOWS\system32\pla.dll
23:28:11.0452 5420  pla - ok
23:28:11.0468 5420  [ 64A80A746FC460126FA4124AA2D93848 ] PlugPlay        C:\WINDOWS\system32\umpnpmgr.dll
23:28:11.0468 5420  PlugPlay - ok
23:28:11.0468 5420  [ 36D43EA5517F3F4AAAC8EE061C957EF1 ] pmem            C:\WINDOWS\System32\drivers\pmem.sys
23:28:11.0484 5420  pmem - ok
23:28:11.0484 5420  [ 59048555B59FD69287CFAB6022B5CC86 ] PNPMEM          C:\WINDOWS\System32\drivers\pnpmem.sys
23:28:11.0484 5420  PNPMEM - ok
23:28:11.0499 5420  [ 7815D5EEE3624640150B1365EB2E98C5 ] PNRPAutoReg     C:\WINDOWS\system32\pnrpauto.dll
23:28:11.0499 5420  PNRPAutoReg - ok
23:28:11.0499 5420  [ 11404911B5ADC7A2DC58021DF0490AA6 ] PNRPsvc         C:\WINDOWS\system32\pnrpsvc.dll
23:28:11.0515 5420  PNRPsvc - ok
23:28:11.0530 5420  [ E1BCA08929D806A087D90BC11C6020E8 ] PolicyAgent     C:\WINDOWS\System32\ipsecsvc.dll
23:28:11.0530 5420  PolicyAgent - ok
23:28:11.0546 5420  [ CECF1795361F76CB0F492404EC0906DB ] Power           C:\WINDOWS\system32\umpo.dll
23:28:11.0546 5420  Power - ok
23:28:11.0546 5420  [ C6010D36B68FB534D1B1245978C9921D ] PptpMiniport    C:\WINDOWS\System32\drivers\raspptp.sys
23:28:11.0562 5420  PptpMiniport - ok
23:28:11.0593 5420  [ 7CD1D9EE59F49FBD3E72876F19038BE0 ] PrintNotify     C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
23:28:11.0655 5420  PrintNotify - ok
23:28:11.0671 5420  [ 8803D4F36F1CB2E2203F5EB59571E89C ] PrintWorkflowUserSvc C:\WINDOWS\System32\PrintWorkflowService.dll
23:28:11.0671 5420  PrintWorkflowUserSvc - ok
23:28:11.0687 5420  [ B1111C47F128C946BDC87A18E44007EB ] Processor       C:\WINDOWS\System32\drivers\processr.sys
23:28:11.0687 5420  Processor - ok
23:28:11.0702 5420  [ A2CA8830BF77FAB39D6E5C45A404FB78 ] ProfSvc         C:\WINDOWS\system32\profsvc.dll
23:28:11.0702 5420  ProfSvc - ok
23:28:11.0718 5420  [ 5818FE76C3C6AE0CA723EBE483BF447F ] Psched          C:\WINDOWS\system32\drivers\pacer.sys
23:28:11.0718 5420  Psched - ok
23:28:11.0718 5420  [ 22E39E05518664028AF16CA45ADB10D6 ] PushToInstall   C:\WINDOWS\system32\PushToInstall.dll
23:28:11.0734 5420  PushToInstall - ok
23:28:11.0734 5420  [ C32ECB99AD25E9A04F01C8665DF29EF8 ] pwdrvio         C:\WINDOWS\system32\pwdrvio.sys
23:28:11.0734 5420  pwdrvio - ok
23:28:11.0749 5420  [ D619356B955EEFA642F5FF72755E8B3C ] pwdspio         C:\Windows\system32\pwdspio.sys
23:28:11.0749 5420  pwdspio - ok
23:28:11.0765 5420  [ 034BA34ADFA10F9D7E4989273DDABA33 ] QWAVE           C:\WINDOWS\system32\qwave.dll
23:28:11.0765 5420  QWAVE - ok
23:28:11.0765 5420  [ 16F9A6B593B52EB18F7ECB9D251BDF7A ] QWAVEdrv        C:\WINDOWS\system32\drivers\qwavedrv.sys
23:28:11.0765 5420  QWAVEdrv - ok
23:28:11.0780 5420  [ 13600C467512147E99052806F2C1307A ] Ramdisk         C:\WINDOWS\system32\DRIVERS\ramdisk.sys
23:28:11.0780 5420  Ramdisk - ok
23:28:11.0780 5420  [ F57D1DE0C9522BCD590A69D044641B5A ] RasAcd          C:\WINDOWS\system32\DRIVERS\rasacd.sys
23:28:11.0796 5420  RasAcd - ok
23:28:11.0796 5420  [ ED0EE10911C16AD8B21B9003C90E968F ] RasAgileVpn     C:\WINDOWS\System32\drivers\AgileVpn.sys
23:28:11.0796 5420  RasAgileVpn - ok
23:28:11.0812 5420  [ 66BA91D8A16B057A521111B2A8BDCC14 ] RasAuto         C:\WINDOWS\System32\rasauto.dll
23:28:11.0812 5420  RasAuto - ok
23:28:11.0812 5420  [ E0220BB6580D34001D4D1D133052DAA4 ] Rasl2tp         C:\WINDOWS\System32\drivers\rasl2tp.sys
23:28:11.0827 5420  Rasl2tp - ok
23:28:11.0843 5420  [ 0F8FB189206C1A53FB73FCF8F335A412 ] RasMan          C:\WINDOWS\System32\rasmans.dll
23:28:11.0843 5420  RasMan - ok
23:28:11.0859 5420  [ 12EE1D92F4E5FAE4B6F65195A2016CE5 ] RasPppoe        C:\WINDOWS\system32\DRIVERS\raspppoe.sys
23:28:11.0859 5420  RasPppoe - ok
23:28:11.0859 5420  [ 91CE469015979E5B3C3DBC2C41A476E8 ] RasSstp         C:\WINDOWS\System32\drivers\rassstp.sys
23:28:11.0859 5420  RasSstp - ok
23:28:11.0874 5420  [ 1B5433EF79752387EBA5AD568AA8B18D ] rdbss           C:\WINDOWS\system32\DRIVERS\rdbss.sys
23:28:11.0874 5420  rdbss - ok
23:28:11.0890 5420  [ 8A5285B38A203D15110E142DE68406DD ] rdpbus          C:\WINDOWS\System32\drivers\rdpbus.sys
23:28:11.0890 5420  rdpbus - ok
23:28:11.0905 5420  [ DF83769C92527DB50653F8FB57D001FF ] RDPDR           C:\WINDOWS\system32\drivers\rdpdr.sys
23:28:11.0905 5420  RDPDR - ok
23:28:11.0921 5420  [ 4D1A63ACEC42A88E52AFC4E84A8CE9EE ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
23:28:11.0921 5420  RdpVideoMiniport - ok
23:28:11.0921 5420  [ 12AF835862F2B6B2FB9DEA8BA2288587 ] rdyboost        C:\WINDOWS\system32\drivers\rdyboost.sys
23:28:11.0937 5420  rdyboost - ok
23:28:11.0952 5420  [ FB0577F6BC9E07549CEACF5224327499 ] ReFS            C:\WINDOWS\system32\drivers\ReFS.sys
23:28:11.0968 5420  ReFS - ok
23:28:11.0984 5420  [ 4136BCA61BCDCC79DCE145F9CB639CD6 ] ReFSv1          C:\WINDOWS\system32\drivers\ReFSv1.sys
23:28:11.0999 5420  ReFSv1 - ok
23:28:12.0015 5420  [ 16884710EB4898CB49B18609EEE34C6C ] RemoteAccess    C:\WINDOWS\System32\mprdim.dll
23:28:12.0015 5420  RemoteAccess - ok
23:28:12.0030 5420  [ 9D82CD53B622A85A10B4DA8F4724A8E4 ] RemoteRegistry  C:\WINDOWS\system32\regsvc.dll
23:28:12.0030 5420  RemoteRegistry - ok
23:28:12.0046 5420  [ 24C716C6A5AA3BEC3180BB15050C75C5 ] RetailDemo      C:\WINDOWS\system32\RDXService.dll
23:28:12.0046 5420  RetailDemo - ok
23:28:12.0062 5420  [ BBC228CA2F96B784B01FE7F1C5E3CFBB ] rhproxy         C:\WINDOWS\System32\drivers\rhproxy.sys
23:28:12.0062 5420  rhproxy - ok
23:28:12.0062 5420  [ 665A51DE515A2E8B0BDB3D6917D47DD9 ] RmSvc           C:\WINDOWS\System32\RMapi.dll
23:28:12.0077 5420  RmSvc - ok
23:28:12.0077 5420  [ D0F6698E56F0157EA72F2D754C6FD555 ] RpcEptMapper    C:\WINDOWS\System32\RpcEpMap.dll
23:28:12.0077 5420  RpcEptMapper - ok
23:28:12.0093 5420  [ EB65907BD63871669C54D5E5BAE4DD34 ] RpcLocator      C:\WINDOWS\system32\locator.exe
23:28:12.0093 5420  RpcLocator - ok
23:28:12.0109 5420  [ 79BDBB684629A526CCD958F06B9D6FAD ] RpcSs           C:\WINDOWS\system32\rpcss.dll
23:28:12.0124 5420  RpcSs - ok
23:28:12.0124 5420  [ 27B80E5766B114621980F82FB78E912A ] rspndr          C:\WINDOWS\system32\drivers\rspndr.sys
23:28:12.0124 5420  rspndr - ok
23:28:12.0140 5420  [ AB7C0639DF052528C2CB06D0EAE115EC ] rt640x64        C:\WINDOWS\System32\drivers\rt640x64.sys
23:28:12.0140 5420  rt640x64 - ok
23:28:12.0155 5420  [ F0FA6B67B16EEFDEF8E8AFAD47A4F9B8 ] s3cap           C:\WINDOWS\System32\drivers\vms3cap.sys
23:28:12.0155 5420  s3cap - ok
23:28:12.0155 5420  [ 94E06D509D50807774F35BEE3163E806 ] SamSs           C:\WINDOWS\system32\lsass.exe
23:28:12.0155 5420  SamSs - ok
23:28:12.0171 5420  [ 62220FB14D0AD7E97F61D6DC324C506F ] SamsungRapidDiskFltr C:\WINDOWS\system32\DRIVERS\SamsungRapidDiskFltr.sys
23:28:12.0171 5420  SamsungRapidDiskFltr - ok
23:28:12.0187 5420  [ 80E49A2AEA9C93477DE31F68E61655EC ] SamsungRapidFSFltr C:\WINDOWS\system32\DRIVERS\SamsungRapidFSFltr.sys
23:28:12.0187 5420  SamsungRapidFSFltr - ok
23:28:12.0187 5420  [ 8A71E4880D80CAE78C43AAB272C90500 ] SamsungRapidSvc C:\WINDOWS\system32\RAPID\SamsungRapidSvc.exe
23:28:12.0187 5420  SamsungRapidSvc - ok
23:28:12.0202 5420  [ 3289766038DB2CB14D07DC84392138D5 ] SASDIFSV        C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
23:28:12.0202 5420  SASDIFSV - ok
23:28:12.0202 5420  [ 58A38E75F3316A83C23DF6173D41F2B5 ] SASKUTIL        C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
23:28:12.0202 5420  SASKUTIL - ok
23:28:12.0218 5420  [ 324FA3C337EB54B43448F7B08444DC8D ] sbp2port        C:\WINDOWS\system32\drivers\sbp2port.sys
23:28:12.0218 5420  sbp2port - ok
23:28:12.0234 5420  [ CB56F3AD0499A2FFAD9BFEF20863ED44 ] SCardSvr        C:\WINDOWS\System32\SCardSvr.dll
23:28:12.0234 5420  SCardSvr - ok
23:28:12.0234 5420  [ 5CB8816960FE5C608F75607F34530BBB ] ScDeviceEnum    C:\WINDOWS\System32\ScDeviceEnum.dll
23:28:12.0249 5420  ScDeviceEnum - ok
23:28:12.0249 5420  [ 62A33CE69DB508BCEC63F4D3BFF400CE ] scfilter        C:\WINDOWS\system32\DRIVERS\scfilter.sys
23:28:12.0249 5420  scfilter - ok
23:28:12.0265 5420  [ 8A9F94596FFC128784B734CA314F2DAA ] Schedule        C:\WINDOWS\system32\schedsvc.dll
23:28:12.0280 5420  Schedule - ok
23:28:12.0280 5420  [ 7B057373146CC4E5A1F1DA665EA55DC7 ] scmbus          C:\WINDOWS\system32\drivers\scmbus.sys
23:28:12.0296 5420  scmbus - ok
23:28:12.0296 5420  [ 200A5398C0E7E78DBDF6C0D9E811F366 ] SCPolicySvc     C:\WINDOWS\System32\certprop.dll
23:28:12.0296 5420  SCPolicySvc - ok
23:28:12.0312 5420  [ 07487301FE9DB115FBE3B00132C483CA ] sdbus           C:\WINDOWS\System32\drivers\sdbus.sys
23:28:12.0312 5420  sdbus - ok
23:28:12.0327 5420  [ 6D3853838864886B4F10B074282772E0 ] SDFRd           C:\WINDOWS\System32\drivers\SDFRd.sys
23:28:12.0327 5420  SDFRd - ok
23:28:12.0327 5420  [ 368180051766E4289E3D47AF21F2668C ] SDRSVC          C:\WINDOWS\System32\SDRSVC.dll
23:28:12.0343 5420  SDRSVC - ok
23:28:12.0343 5420  [ C289832A3174DC9D393C7603C511DF79 ] sdstor          C:\WINDOWS\System32\drivers\sdstor.sys
23:28:12.0343 5420  sdstor - ok
23:28:12.0359 5420  [ 0356C85312D78F4C7F33C74B6000BB93 ] seclogon        C:\WINDOWS\system32\seclogon.dll
23:28:12.0359 5420  seclogon - ok
23:28:12.0374 5420  [ FCAF34447DB59EF1330EA576D16C54CC ] SecurityHealthService C:\WINDOWS\system32\SecurityHealthService.exe
23:28:12.0374 5420  SecurityHealthService - ok
23:28:12.0405 5420  [ FE3E7B59BBEDDDC449C86B693BE63542 ] SEMgrSvc        C:\WINDOWS\system32\SEMgrSvc.dll
23:28:12.0421 5420  SEMgrSvc - ok
23:28:12.0421 5420  [ 62EDAD383010E037C4D3846C7C021A00 ] SENS            C:\WINDOWS\System32\sens.dll
23:28:12.0421 5420  SENS - ok
23:28:12.0437 5420  [ DDBBE9A08C79D3BB50D6053507F7777D ] SensorDataService C:\WINDOWS\System32\SensorDataService.exe
23:28:12.0452 5420  SensorDataService - ok
23:28:12.0468 5420  [ AF51D8E33E08BD898D439CF31158F989 ] SensorService   C:\WINDOWS\system32\SensorService.dll
23:28:12.0484 5420  SensorService - ok
23:28:12.0484 5420  [ 25B028799D43FE6324CC9E79B31E6ACD ] SensrSvc        C:\WINDOWS\system32\sensrsvc.dll
23:28:12.0499 5420  SensrSvc - ok
23:28:12.0499 5420  [ 75A27472AFD009255DBDE52038E3BDB5 ] SerCx           C:\WINDOWS\system32\drivers\SerCx.sys
23:28:12.0499 5420  SerCx - ok
23:28:12.0515 5420  [ 84005F54308109A022413D628E966412 ] SerCx2          C:\WINDOWS\system32\drivers\SerCx2.sys
23:28:12.0515 5420  SerCx2 - ok
23:28:12.0530 5420  [ 40384793F74CFFA45BCC38DF65E978EC ] Serenum         C:\WINDOWS\System32\drivers\serenum.sys
23:28:12.0530 5420  Serenum - ok
23:28:12.0530 5420  [ 699470AD24D67908991A777716A352FD ] Serial          C:\WINDOWS\System32\drivers\serial.sys
23:28:12.0530 5420  Serial - ok
23:28:12.0546 5420  [ 92453F065F52A8EF0328A926B2C9502F ] sermouse        C:\WINDOWS\System32\drivers\sermouse.sys
23:28:12.0546 5420  sermouse - ok
23:28:12.0562 5420  [ 8958262EA3A871D45B14B7BA00F795C1 ] SessionEnv      C:\WINDOWS\system32\sessenv.dll
23:28:12.0577 5420  SessionEnv - ok
23:28:12.0593 5420  [ 1D8920C40F19B5FBA5F4897779840AD1 ] sfloppy         C:\WINDOWS\System32\drivers\sfloppy.sys
23:28:12.0593 5420  sfloppy - ok
23:28:12.0609 5420  [ B08841DD1EF979C5C6F9A7F101BA3D9C ] SharedAccess    C:\WINDOWS\System32\ipnathlp.dll
23:28:12.0609 5420  SharedAccess - ok
23:28:12.0624 5420  [ 63377493508564288721EF5421A216F5 ] SharedRealitySvc C:\WINDOWS\System32\SharedRealitySvc.dll
23:28:12.0624 5420  SharedRealitySvc - ok
23:28:12.0640 5420  [ 887458A234108B5B69038299BE7FAD88 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
23:28:12.0655 5420  ShellHWDetection - ok
23:28:12.0655 5420  [ 5ED18BE9FE76540A0596BB41C91719C6 ] shpamsvc        C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll
23:28:12.0671 5420  shpamsvc - ok
23:28:12.0671 5420  [ A871F9CC9CF388DC7193D22EF8D8C8DF ] SiSRaid2        C:\WINDOWS\system32\drivers\SiSRaid2.sys
23:28:12.0671 5420  SiSRaid2 - ok
23:28:12.0687 5420  [ D30FC341550CC364880950152AE8B1C5 ] SiSRaid4        C:\WINDOWS\system32\drivers\sisraid4.sys
23:28:12.0687 5420  SiSRaid4 - ok
23:28:12.0687 5420  [ 9CA6E573757C76A515EFD6DD795A3A1E ] smphost         C:\WINDOWS\System32\smphost.dll
23:28:12.0702 5420  smphost - ok
23:28:12.0702 5420  [ 222FA25F074A404AFD811C110CB169AE ] SmsRouter       C:\WINDOWS\system32\SmsRouterSvc.dll
23:28:12.0718 5420  SmsRouter - ok
23:28:12.0734 5420  [ FDADDEC855034107E5FAD708B4E2424D ] SNMPTRAP        C:\WINDOWS\System32\snmptrap.exe
23:28:12.0734 5420  SNMPTRAP - ok
23:28:12.0749 5420  [ 41A94860CC239360900D328EA306FE69 ] spaceport       C:\WINDOWS\system32\drivers\spaceport.sys
23:28:12.0749 5420  spaceport - ok
23:28:12.0765 5420  [ CCECE7E96B4F7B0E9F0FC82F6DADA917 ] SpatialGraphFilter C:\WINDOWS\system32\drivers\SpatialGraphFilter.sys
23:28:12.0765 5420  SpatialGraphFilter - ok
23:28:12.0765 5420  [ 545507AF670BC88B89200A118513ED9A ] SpbCx           C:\WINDOWS\system32\drivers\SpbCx.sys
23:28:12.0780 5420  SpbCx - ok
23:28:12.0796 5420  [ 5CF28E37F2BF80902DA50CF1A95294CE ] spectrum        C:\WINDOWS\system32\spectrum.exe
23:28:12.0796 5420  spectrum - ok
23:28:12.0812 5420  [ 4A1050E4096E1891EEFFC64282A4DD44 ] Spooler         C:\WINDOWS\System32\spoolsv.exe
23:28:12.0827 5420  Spooler - ok
23:28:12.0874 5420  [ 312D711FE1160E743D2827F607A189C9 ] sppsvc          C:\WINDOWS\system32\sppsvc.exe
23:28:12.0921 5420  sppsvc - ok
23:28:12.0937 5420  [ DA3895168C2AAAA6BD7B0C0632C59BE7 ] srv             C:\WINDOWS\system32\DRIVERS\srv.sys
23:28:12.0937 5420  srv - ok
23:28:12.0952 5420  [ C8A912159B40CD56D868466496EC3518 ] srv2            C:\WINDOWS\system32\DRIVERS\srv2.sys
23:28:12.0952 5420  srv2 - ok
23:28:12.0968 5420  [ FE7D52F9B83E2CC670E660529E930858 ] srvnet          C:\WINDOWS\system32\DRIVERS\srvnet.sys
23:28:12.0968 5420  srvnet - ok
23:28:12.0968 5420  [ 5319E85C030CDB3E779D774FEEFF4842 ] SSDPSRV         C:\WINDOWS\System32\ssdpsrv.dll
23:28:12.0984 5420  SSDPSRV - ok
23:28:12.0984 5420  [ 3BEF5FAC7F3DA3E25B80CC41B5060616 ] SstpSvc         C:\WINDOWS\system32\sstpsvc.dll
23:28:12.0999 5420  SstpSvc - ok
23:28:13.0046 5420  [ 22FC1054C424DA55323F3704F8C78CD2 ] StateRepository C:\WINDOWS\system32\windows.staterepository.dll
23:28:13.0077 5420  StateRepository - ok
23:28:13.0109 5420  [ A057004B295005ABFA3ACE1E63D7D2A2 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
23:28:13.0124 5420  Steam Client Service - ok
23:28:13.0124 5420  [ 162A805E13B3C0DD06AE8B6FC1900156 ] stexstor        C:\WINDOWS\system32\drivers\stexstor.sys
23:28:13.0124 5420  stexstor - ok
23:28:13.0140 5420  [ 3B3F5D6BB8A6A6F3630194A471989069 ] stisvc          C:\WINDOWS\System32\wiaservc.dll
23:28:13.0140 5420  stisvc - ok
23:28:13.0155 5420  [ 2F6634F70BC69D3B66EAA38AF65633C2 ] storahci        C:\WINDOWS\system32\drivers\storahci.sys
23:28:13.0155 5420  storahci - ok
23:28:13.0171 5420  [ A12CFAAA0F113A25D8CEFE58B1CBB207 ] storflt         C:\WINDOWS\system32\drivers\vmstorfl.sys
23:28:13.0171 5420  storflt - ok
23:28:13.0171 5420  [ DA0097E6C70EA25F6020CC97C7828F70 ] stornvme        C:\WINDOWS\system32\drivers\stornvme.sys
23:28:13.0171 5420  stornvme - ok
23:28:13.0187 5420  [ 57377953F5688158054BC8CB5A243115 ] storqosflt      C:\WINDOWS\system32\drivers\storqosflt.sys
23:28:13.0187 5420  storqosflt - ok
23:28:13.0202 5420  [ EEA240DD683FF1ECE15A4BFA5D9178A6 ] StorSvc         C:\WINDOWS\system32\storsvc.dll
23:28:13.0218 5420  StorSvc - ok
23:28:13.0218 5420  [ B59D29E535AF7E82717C2AD2C57EEC67 ] storufs         C:\WINDOWS\system32\drivers\storufs.sys
23:28:13.0218 5420  storufs - ok
23:28:13.0234 5420  [ 9B431079624306B5659B3B7208A71C75 ] storvsc         C:\WINDOWS\system32\drivers\storvsc.sys
23:28:13.0234 5420  storvsc - ok
23:28:13.0234 5420  [ 42FEF84684D217870F3C8813B6F58276 ] SupportSoft RemoteAssist C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe
23:28:13.0249 5420  SupportSoft RemoteAssist - ok
23:28:13.0249 5420  [ 587854AF01CABE83A62D81FFEEBCD6AA ] svsvc           C:\WINDOWS\system32\svsvc.dll
23:28:13.0249 5420  svsvc - ok
23:28:13.0265 5420  [ 027B27E4B9DB3931D64159B81BD915A0 ] swenum          C:\WINDOWS\System32\drivers\swenum.sys
23:28:13.0265 5420  swenum - ok
23:28:13.0280 5420  [ E0915F9B3C154FEF700C34A8E613B945 ] swprv           C:\WINDOWS\System32\swprv.dll
23:28:13.0280 5420  swprv - ok
23:28:13.0280 5420  [ AB15F9FDCD11D5283891BC956E8C5C95 ] Synth3dVsc      C:\WINDOWS\System32\drivers\Synth3dVsc.sys
23:28:13.0296 5420  Synth3dVsc - ok
23:28:13.0312 5420  [ 3309B708DADDCAA4C3806B5EAF0432DB ] SysMain         C:\WINDOWS\system32\sysmain.dll
23:28:13.0312 5420  SysMain - ok
23:28:13.0327 5420  [ 0839E5F9192B050F3B220562FF2C10AF ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
23:28:13.0327 5420  SystemEventsBroker - ok
23:28:13.0343 5420  [ 73F6476EE9F5448838B2883E0B710CD7 ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
23:28:13.0343 5420  TabletInputService - ok
23:28:13.0359 5420  [ AC1AA61B04116E540C5AFD18F11F2697 ] TapiSrv         C:\WINDOWS\System32\tapisrv.dll
23:28:13.0359 5420  TapiSrv - ok
23:28:13.0405 5420  [ 420A2A36A7E04D137DB35126C0C451A3 ] Tcpip           C:\WINDOWS\system32\drivers\tcpip.sys
23:28:13.0421 5420  Tcpip - ok
23:28:13.0452 5420  [ 420A2A36A7E04D137DB35126C0C451A3 ] Tcpip6          C:\WINDOWS\system32\drivers\tcpip.sys
23:28:13.0468 5420  Tcpip6 - ok
23:28:13.0484 5420  [ 74A1BF4093FA7B7D6C9366A39911A78E ] tcpipreg        C:\WINDOWS\system32\drivers\tcpipreg.sys
23:28:13.0484 5420  tcpipreg - ok
23:28:13.0499 5420  [ 571D82ABAC428D902ACA0CF60373C039 ] tdx             C:\WINDOWS\system32\DRIVERS\tdx.sys
23:28:13.0499 5420  tdx - ok
23:28:13.0624 5420  [ 70695B67EE8E743125FEBE689BDF9F0E ] TeamViewer      C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
23:28:13.0718 5420  TeamViewer - ok
23:28:13.0718 5420  [ B4B68E1DB59456419D9E49645729502A ] terminpt        C:\WINDOWS\System32\drivers\terminpt.sys
23:28:13.0718 5420  terminpt - ok
23:28:13.0749 5420  [ 96037700AEE1B4D5A6FFC62861E4FF8C ] TermService     C:\WINDOWS\System32\termsrv.dll
23:28:13.0749 5420  TermService - ok
23:28:13.0765 5420  [ E0F78207F33D6C10CBFB23E873837C87 ] Themes          C:\WINDOWS\system32\themeservice.dll
23:28:13.0765 5420  Themes - ok
23:28:13.0780 5420  [ B52BA61AB8E4BAA83EA86BAB312EE6ED ] TieringEngineService C:\WINDOWS\system32\TieringEngineService.exe
23:28:13.0780 5420  TieringEngineService - ok
23:28:13.0796 5420  [ BC834B233125DBB321B809972F2E270E ] tiledatamodelsvc C:\WINDOWS\system32\tileobjserver.dll
23:28:13.0796 5420  tiledatamodelsvc - ok
23:28:13.0812 5420  [ 9B3AA589825CF90E187DF432D806A316 ] TimeBrokerSvc   C:\WINDOWS\System32\TimeBrokerServer.dll
23:28:13.0812 5420  TimeBrokerSvc - ok
23:28:13.0827 5420  [ 17CEEADEDF0CD49404FE2C6DD10F75F6 ] TokenBroker     C:\WINDOWS\System32\TokenBroker.dll
23:28:13.0843 5420  TokenBroker - ok
23:28:13.0859 5420  [ 1658D060057C85DEC82BFCB018C4C22F ] TPM             C:\WINDOWS\System32\drivers\tpm.sys
23:28:13.0859 5420  TPM - ok
23:28:13.0874 5420  [ 39187852984778424A0EFD6B01FAB272 ] TrkWks          C:\WINDOWS\System32\trkwks.dll
23:28:13.0874 5420  TrkWks - ok
23:28:13.0874 5420  [ 0D5A09B08568760AE85A801FCBC0F83D ] TrueSight       C:\Windows\System32\drivers\TrueSight.sys
23:28:13.0874 5420  TrueSight - ok
23:28:13.0890 5420  [ 6E39B63A16B33827B861C56F0E58E021 ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
23:28:13.0890 5420  TrustedInstaller - ok
23:28:13.0905 5420  [ 8D811209E34358EAD3FD8E40F657E59C ] tsusbflt        C:\WINDOWS\system32\drivers\TsUsbFlt.sys
23:28:13.0905 5420  tsusbflt - ok
23:28:13.0905 5420  [ 68DE1735FB020AE8948BD7B60F2EBD3B ] TsUsbGD         C:\WINDOWS\System32\drivers\TsUsbGD.sys
23:28:13.0905 5420  TsUsbGD - ok
23:28:13.0921 5420  [ ACD39B0E5CFDA7B1AB7DF33FC5CC0E46 ] tunnel          C:\WINDOWS\System32\drivers\tunnel.sys
23:28:13.0921 5420  tunnel - ok
23:28:13.0921 5420  [ D5E68FCEDE15214BDB5D986D5B50E0BF ] tzautoupdate    C:\WINDOWS\system32\tzautoupdate.dll
23:28:13.0937 5420  tzautoupdate - ok
23:28:13.0937 5420  [ 04FC2C7F73AE58BF0DD674164E28A6DF ] UASPStor        C:\WINDOWS\System32\drivers\uaspstor.sys
23:28:13.0937 5420  UASPStor - ok
23:28:13.0952 5420  [ E437FC4B1833F6B745184F78C4921FB8 ] UcmCx0101       C:\WINDOWS\system32\Drivers\UcmCx.sys
23:28:13.0952 5420  UcmCx0101 - ok
23:28:13.0952 5420  [ 950A3E42167904CAB9AA64863C31CEB5 ] UcmTcpciCx0101  C:\WINDOWS\system32\Drivers\UcmTcpciCx.sys
23:28:13.0968 5420  UcmTcpciCx0101 - ok
23:28:13.0968 5420  [ 149CBBB74DFC3E52F242029A27B0F8EB ] UcmUcsi         C:\WINDOWS\System32\drivers\UcmUcsi.sys
23:28:13.0968 5420  UcmUcsi - ok
23:28:13.0984 5420  [ E6E91B3980A495D2A9D28A09580EA993 ] Ucx01000        C:\WINDOWS\system32\drivers\ucx01000.sys
23:28:13.0984 5420  Ucx01000 - ok
23:28:13.0984 5420  [ DACA289DFFA7658C04FEF6DCFA2AA9CE ] UdeCx           C:\WINDOWS\system32\drivers\udecx.sys
23:28:13.0999 5420  UdeCx - ok
23:28:13.0999 5420  [ 12383D410AEF99AD6979A8EFD3D61888 ] udfs            C:\WINDOWS\system32\DRIVERS\udfs.sys
23:28:13.0999 5420  udfs - ok
23:28:14.0015 5420  [ AB7FE51D818B6059C2F56FA62268CCAC ] UEFI            C:\WINDOWS\System32\drivers\UEFI.sys
23:28:14.0015 5420  UEFI - ok
23:28:14.0030 5420  [ 58447F28E697A93521DD20530A8D50ED ] Ufx01000        C:\WINDOWS\system32\drivers\ufx01000.sys
23:28:14.0030 5420  Ufx01000 - ok
23:28:14.0030 5420  [ 69ED2D00A7787D9D84E6C90CE0B02B2D ] UfxChipidea     C:\WINDOWS\System32\drivers\UfxChipidea.sys
23:28:14.0030 5420  UfxChipidea - ok
23:28:14.0046 5420  [ F061EC57330FBC597A4E7298BE667780 ] ufxsynopsys     C:\WINDOWS\System32\drivers\ufxsynopsys.sys
23:28:14.0046 5420  ufxsynopsys - ok
23:28:14.0062 5420  [ B26729B378282F72241859C13326E3E8 ] UI0Detect       C:\WINDOWS\system32\UI0Detect.exe
23:28:14.0062 5420  UI0Detect - ok
23:28:14.0077 5420  [ D40BCED160D332005AF612E1228825E6 ] umbus           C:\WINDOWS\System32\drivers\umbus.sys
23:28:14.0077 5420  umbus - ok
23:28:14.0077 5420  [ 64CF24D7B1FA4975C52A31BF4C82EB73 ] UmPass          C:\WINDOWS\System32\drivers\umpass.sys
23:28:14.0077 5420  UmPass - ok
23:28:14.0093 5420  [ E6B6BDA0412D3C56275E662A5A1937FD ] UmRdpService    C:\WINDOWS\System32\umrdp.dll
23:28:14.0093 5420  UmRdpService - ok
23:28:14.0109 5420  Unchecky - ok
23:28:14.0124 5420  [ 9DBB06555E1FA73B292644DF8A3454FF ] UnistoreSvc     C:\WINDOWS\System32\unistore.dll
23:28:14.0140 5420  UnistoreSvc - ok
23:28:14.0155 5420  [ D2931E3F67A990328DE5CE7E43F4467C ] upnphost        C:\WINDOWS\System32\upnphost.dll
23:28:14.0155 5420  upnphost - ok
23:28:14.0171 5420  [ ACE4C3B4C7D17B154FFC5BBE5F7A9835 ] UrsChipidea     C:\WINDOWS\System32\drivers\urschipidea.sys
23:28:14.0171 5420  UrsChipidea - ok
23:28:14.0171 5420  [ ECE40EB976A5ACB366808AECF6B235BA ] UrsCx01000      C:\WINDOWS\system32\drivers\urscx01000.sys
23:28:14.0171 5420  UrsCx01000 - ok
23:28:14.0187 5420  [ EB738F830D3E7EA62A218F101EF91FD4 ] UrsSynopsys     C:\WINDOWS\System32\drivers\urssynopsys.sys
23:28:14.0187 5420  UrsSynopsys - ok
23:28:14.0202 5420  [ B43E28E5CF868517EEC0923AB2BC366B ] usbccgp         C:\WINDOWS\System32\drivers\usbccgp.sys
23:28:14.0202 5420  usbccgp - ok
23:28:14.0202 5420  [ 1080D80B5F6D249F23BAE1C0C36233A4 ] usbcir          C:\WINDOWS\System32\drivers\usbcir.sys
23:28:14.0202 5420  usbcir - ok
23:28:14.0218 5420  [ EE162DA2C92026A5B96ED89737975AA8 ] usbehci         C:\WINDOWS\System32\drivers\usbehci.sys
23:28:14.0218 5420  usbehci - ok
23:28:14.0234 5420  [ C27FEE9758E3BEDE4D48B5EDBE1122CF ] usbhub          C:\WINDOWS\System32\drivers\usbhub.sys
23:28:14.0234 5420  usbhub - ok
23:28:14.0249 5420  [ 4FA9C956E569D0D380C2859542361780 ] USBHUB3         C:\WINDOWS\System32\drivers\UsbHub3.sys
23:28:14.0249 5420  USBHUB3 - ok
23:28:14.0265 5420  [ 44B954306BB2B311E070EDA276FECAB1 ] usbohci         C:\WINDOWS\System32\drivers\usbohci.sys
23:28:14.0265 5420  usbohci - ok
23:28:14.0280 5420  [ EEF26F9034F0608B93D4D239534BB0BA ] usbprint        C:\WINDOWS\System32\drivers\usbprint.sys
23:28:14.0280 5420  usbprint - ok
23:28:14.0280 5420  [ 913CFF365DB1803525DBD2AA8B8188B4 ] usbser          C:\WINDOWS\System32\drivers\usbser.sys
23:28:14.0280 5420  usbser - ok
23:28:14.0296 5420  [ 441CAE778B6A1FF6E618E37814A7A52A ] USBSTOR         C:\WINDOWS\System32\drivers\USBSTOR.SYS
23:28:14.0296 5420  USBSTOR - ok
23:28:14.0296 5420  [ 2D6BB2157B37B2D9DABF8C218F2A805B ] usbuhci         C:\WINDOWS\System32\drivers\usbuhci.sys
23:28:14.0312 5420  usbuhci - ok
23:28:14.0312 5420  [ 0B22D76E3BE6DA40AEE26C21217CBE58 ] USBXHCI         C:\WINDOWS\System32\drivers\USBXHCI.SYS
23:28:14.0327 5420  USBXHCI - ok
23:28:14.0343 5420  [ 583E586E926F025A430902D6679B9AD5 ] UserDataSvc     C:\WINDOWS\System32\userdataservice.dll
23:28:14.0359 5420  UserDataSvc - ok
23:28:14.0374 5420  [ F38944BBAA22D6386D0828EAA3147F1E ] UserManager     C:\WINDOWS\System32\usermgr.dll
23:28:14.0390 5420  UserManager - ok
23:28:14.0405 5420  [ 08D61B00BAE43FD326CFCEC87D11F986 ] UsoSvc          C:\WINDOWS\system32\usocore.dll
23:28:14.0421 5420  UsoSvc - ok
23:28:14.0437 5420  [ 94E06D509D50807774F35BEE3163E806 ] VaultSvc        C:\WINDOWS\system32\lsass.exe
23:28:14.0437 5420  VaultSvc - ok
23:28:14.0437 5420  [ C77C537077822D8EA529AD4EBFD971D6 ] vdrvroot        C:\WINDOWS\system32\drivers\vdrvroot.sys
23:28:14.0437 5420  vdrvroot - ok
23:28:14.0452 5420  [ 07C192BEEA76B1BD9D0310ED20551D54 ] vds             C:\WINDOWS\System32\vds.exe
23:28:14.0468 5420  vds - ok
23:28:14.0484 5420  [ 9D4EEE333603F3675685F644053499D5 ] VerifierExt     C:\WINDOWS\system32\drivers\VerifierExt.sys
23:28:14.0484 5420  VerifierExt - ok
23:28:14.0499 5420  [ F40CD2F44533F2618B5CA29BC03EEE81 ] vhdmp           C:\WINDOWS\System32\drivers\vhdmp.sys
23:28:14.0499 5420  vhdmp - ok
23:28:14.0515 5420  [ E10FEBB566E1F0A3936AB304F338637E ] vhf             C:\WINDOWS\System32\drivers\vhf.sys
23:28:14.0515 5420  vhf - ok
23:28:14.0515 5420  [ 164E6B2919FF12911F63C7EC526ED669 ] vmbus           C:\WINDOWS\system32\drivers\vmbus.sys
23:28:14.0515 5420  vmbus - ok
23:28:14.0530 5420  [ DC9E0600B356258E31403789119C78A9 ] VMBusHID        C:\WINDOWS\System32\drivers\VMBusHID.sys
23:28:14.0530 5420  VMBusHID - ok
23:28:14.0530 5420  [ B24F74B2710B66F647419697BDB9E163 ] vmgid           C:\WINDOWS\System32\drivers\vmgid.sys
23:28:14.0546 5420  vmgid - ok
23:28:14.0546 5420  [ CE70937143DBDB2B4BF3A0310EB9E189 ] vmicguestinterface C:\WINDOWS\System32\icsvc.dll
23:28:14.0562 5420  vmicguestinterface - ok
23:28:14.0562 5420  [ CE70937143DBDB2B4BF3A0310EB9E189 ] vmicheartbeat   C:\WINDOWS\System32\icsvc.dll
23:28:14.0562 5420  vmicheartbeat - ok
23:28:14.0577 5420  [ CE70937143DBDB2B4BF3A0310EB9E189 ] vmickvpexchange C:\WINDOWS\System32\icsvc.dll
23:28:14.0577 5420  vmickvpexchange - ok
23:28:14.0593 5420  [ FD73A74D26F5BEC303763FD9CDD2DFB2 ] vmicrdv         C:\WINDOWS\System32\icsvcext.dll
23:28:14.0593 5420  vmicrdv - ok
23:28:14.0609 5420  [ CE70937143DBDB2B4BF3A0310EB9E189 ] vmicshutdown    C:\WINDOWS\System32\icsvc.dll
23:28:14.0609 5420  vmicshutdown - ok
23:28:14.0609 5420  [ CE70937143DBDB2B4BF3A0310EB9E189 ] vmictimesync    C:\WINDOWS\System32\icsvc.dll
23:28:14.0624 5420  vmictimesync - ok
23:28:14.0624 5420  [ CE70937143DBDB2B4BF3A0310EB9E189 ] vmicvmsession   C:\WINDOWS\System32\icsvc.dll
23:28:14.0624 5420  vmicvmsession - ok
23:28:14.0640 5420  [ FD73A74D26F5BEC303763FD9CDD2DFB2 ] vmicvss         C:\WINDOWS\System32\icsvcext.dll
23:28:14.0640 5420  vmicvss - ok
23:28:14.0655 5420  [ D81F6B790519A60F3D1788B45D04B749 ] vnvdimm         C:\WINDOWS\System32\drivers\vnvdimm.sys
23:28:14.0655 5420  vnvdimm - ok
23:28:14.0655 5420  [ CD1474E804C0417BF2DC840AC5DF98EA ] volmgr          C:\WINDOWS\system32\drivers\volmgr.sys
23:28:14.0655 5420  volmgr - ok
23:28:14.0671 5420  [ 6D6CACED512C1EF1FEAC215E37E3A9BC ] volmgrx         C:\WINDOWS\system32\drivers\volmgrx.sys
23:28:14.0671 5420  volmgrx - ok
23:28:14.0687 5420  [ 6AF9BCB1FFD127B8F4E7E7B9FF9351EA ] volsnap         C:\WINDOWS\system32\drivers\volsnap.sys
23:28:14.0687 5420  volsnap - ok
23:28:14.0702 5420  [ 72A95A844D6BAF2924A4C15BEDFD6BCA ] volume          C:\WINDOWS\system32\drivers\volume.sys
23:28:14.0702 5420  volume - ok
23:28:14.0702 5420  [ 702273C7C1BE9D366BAF1305D382F03C ] vpci            C:\WINDOWS\System32\drivers\vpci.sys
23:28:14.0718 5420  vpci - ok
23:28:14.0718 5420  [ 075CE3C9E77D2666AFA888951E5F07A9 ] vsmraid         C:\WINDOWS\system32\drivers\vsmraid.sys
23:28:14.0718 5420  vsmraid - ok
23:28:14.0749 5420  [ 16144D396BFFEFDB0B8A2C964CBAD35D ] VSS             C:\WINDOWS\system32\vssvc.exe
23:28:14.0765 5420  VSS - ok
23:28:14.0765 5420  [ 26D00E85BE4726B114335250FCDEDA89 ] VSTXRAID        C:\WINDOWS\system32\drivers\vstxraid.sys
23:28:14.0780 5420  VSTXRAID - ok
23:28:14.0780 5420  [ 3DFDB573E4D49EA8F416B573525B7A86 ] vwifibus        C:\WINDOWS\System32\drivers\vwifibus.sys
23:28:14.0780 5420  vwifibus - ok
23:28:14.0796 5420  [ A40FA64655AB5B8773A96A821616C5FC ] vwififlt        C:\WINDOWS\system32\drivers\vwififlt.sys
23:28:14.0796 5420  vwififlt - ok
23:28:14.0812 5420  [ A17A4F2823C5424C9B8B990644817DC0 ] W32Time         C:\WINDOWS\system32\w32time.dll
23:28:14.0827 5420  W32Time - ok
23:28:14.0827 5420  [ AD72CFDA8E47BC32ED46DE4FD2434062 ] w3logsvc        C:\WINDOWS\system32\inetsrv\w3logsvc.dll
23:28:14.0827 5420  w3logsvc - ok
23:28:14.0843 5420  [ A76A55BF0B22D1075434F1D723B9D1AC ] W3SVC           C:\WINDOWS\system32\inetsrv\iisw3adm.dll
23:28:14.0859 5420  W3SVC - ok
23:28:14.0859 5420  [ 5B5430522E0BDF2A753D758710BE7C5E ] WacomPen        C:\WINDOWS\System32\drivers\wacompen.sys
23:28:14.0859 5420  WacomPen - ok
23:28:14.0874 5420  [ 451D40C28E7D1CF51A980B83FDEFF498 ] WalletService   C:\WINDOWS\system32\WalletService.dll
23:28:14.0874 5420  WalletService - ok
23:28:14.0890 5420  [ 478193CE0AAD5C8515568592F1F640D1 ] wanarp          C:\WINDOWS\system32\DRIVERS\wanarp.sys
23:28:14.0890 5420  wanarp - ok
23:28:14.0890 5420  [ 478193CE0AAD5C8515568592F1F640D1 ] wanarpv6        C:\WINDOWS\system32\DRIVERS\wanarp.sys
23:28:14.0905 5420  wanarpv6 - ok
23:28:14.0905 5420  [ E3B4C37F1F3D8078AA2AFBEE7F5468CF ] WarpJITSvc      C:\WINDOWS\System32\Windows.WARP.JITService.dll
23:28:14.0905 5420  WarpJITSvc - ok
23:28:14.0921 5420  [ A76A55BF0B22D1075434F1D723B9D1AC ] WAS             C:\WINDOWS\system32\inetsrv\iisw3adm.dll
23:28:14.0921 5420  WAS - ok
23:28:14.0952 5420  [ 1C1EB9C4DAF428B3BFDD58572768182C ] wbengine        C:\WINDOWS\system32\wbengine.exe
23:28:14.0968 5420  wbengine - ok
23:28:14.0984 5420  [ D38ACBA3FE7B12C30D13A68B35FAB71A ] WbioSrvc        C:\WINDOWS\System32\wbiosrvc.dll
23:28:14.0999 5420  WbioSrvc - ok
23:28:14.0999 5420  [ A8DFD1465C05D9EFBDFD5C3A25B7F496 ] wcifs           C:\WINDOWS\system32\drivers\wcifs.sys
23:28:14.0999 5420  wcifs - ok
23:28:15.0015 5420  [ EB1B7609CC9BFA19D81BC0A43CEE067B ] Wcmsvc          C:\WINDOWS\System32\wcmsvc.dll
23:28:15.0030 5420  Wcmsvc - ok
23:28:15.0046 5420  [ E2A66490B2D91A00554E5BCF217942F4 ] wcncsvc         C:\WINDOWS\System32\wcncsvc.dll
23:28:15.0046 5420  wcncsvc - ok
23:28:15.0062 5420  [ 9DE3FDFF295F2534DF0A8B6FC4F06355 ] wcnfs           C:\WINDOWS\system32\drivers\wcnfs.sys
23:28:15.0062 5420  wcnfs - ok
23:28:15.0062 5420  [ 6FD8F1FBED780A7F3DF329C834E52AC5 ] WdBoot          C:\WINDOWS\system32\drivers\WdBoot.sys
23:28:15.0077 5420  WdBoot - ok
23:28:15.0093 5420  [ FCC960498E3CD899F0A429F7CF9E77AD ] Wdf01000        C:\WINDOWS\system32\drivers\Wdf01000.sys
23:28:15.0093 5420  Wdf01000 - ok
23:28:15.0109 5420  [ 7D182F0F227FC141C5D2085175BE05F6 ] WdFilter        C:\WINDOWS\system32\drivers\WdFilter.sys
23:28:15.0109 5420  WdFilter - ok
23:28:15.0124 5420  [ AB406F30BE98CDB7AA7171336EF031BA ] WdiServiceHost  C:\WINDOWS\system32\wdi.dll
23:28:15.0124 5420  WdiServiceHost - ok
23:28:15.0124 5420  [ AB406F30BE98CDB7AA7171336EF031BA ] WdiSystemHost   C:\WINDOWS\system32\wdi.dll
23:28:15.0140 5420  WdiSystemHost - ok
23:28:15.0155 5420  [ 943FE2802DAB5644B188AE0EC2EF4740 ] wdiwifi         C:\WINDOWS\system32\DRIVERS\wdiwifi.sys
23:28:15.0155 5420  wdiwifi - ok
23:28:15.0171 5420  [ 0D38C257A7B34A818726BA2F323B196E ] WdNisDrv        C:\WINDOWS\system32\Drivers\WdNisDrv.sys
23:28:15.0171 5420  WdNisDrv - ok
23:28:15.0171 5420  WdNisSvc - ok
23:28:15.0187 5420  [ DF58AA71FBA55E15F572C93447696DEC ] wdnsfltr        C:\WINDOWS\system32\drivers\wdnsfltr.sys
23:28:15.0187 5420  wdnsfltr - ok
23:28:15.0202 5420  [ A339FDE695599D96C4F78CC22A993AFB ] WebClient       C:\WINDOWS\System32\webclnt.dll
23:28:15.0202 5420  WebClient - ok
23:28:15.0202 5420  [ 7997BC2386A9976C0645A28FA8A6E7EA ] Wecsvc          C:\WINDOWS\system32\wecsvc.dll
23:28:15.0218 5420  Wecsvc - ok
23:28:15.0218 5420  [ CEA146E0D096A491B265CD2340C2E31D ] WEPHOSTSVC      C:\WINDOWS\system32\wephostsvc.dll
23:28:15.0234 5420  WEPHOSTSVC - ok
23:28:15.0234 5420  [ 40610BA98D5830FB14C3695B3BCA647A ] wercplsupport   C:\WINDOWS\System32\wercplsupport.dll
23:28:15.0234 5420  wercplsupport - ok
23:28:15.0249 5420  [ AA2B3154D12ABE34640C866AC3472E33 ] WerSvc          C:\WINDOWS\System32\WerSvc.dll
23:28:15.0249 5420  WerSvc - ok
23:28:15.0265 5420  [ 86B816E9D24625287BDE9784953A5E86 ] WFDSConMgrSvc   C:\WINDOWS\System32\wfdsconmgrsvc.dll
23:28:15.0280 5420  WFDSConMgrSvc - ok
23:28:15.0280 5420  [ 4EAE206AF1D880C9C06FB4ACD17F0506 ] WFPLWFS         C:\WINDOWS\system32\drivers\wfplwfs.sys
23:28:15.0296 5420  WFPLWFS - ok
23:28:15.0296 5420  [ F78A2731EC972312C4C998174A9BB325 ] WiaRpc          C:\WINDOWS\System32\wiarpc.dll
23:28:15.0296 5420  WiaRpc - ok
23:28:15.0312 5420  [ C8D3FC38426E990E2787771678B19C6D ] WIMMount        C:\WINDOWS\system32\drivers\wimmount.sys
23:28:15.0312 5420  WIMMount - ok
23:28:15.0312 5420  WinDefend - ok
23:28:15.0343 5420  [ 0484B0D01EA6F7017519EBDDBADE759D ] WindowsTrustedRT C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys
23:28:15.0343 5420  WindowsTrustedRT - ok
23:28:15.0343 5420  [ 813EE0F4D4B8D599DB1968682D080732 ] WindowsTrustedRTProxy C:\WINDOWS\system32\drivers\WindowsTrustedRTProxy.sys
23:28:15.0343 5420  WindowsTrustedRTProxy - ok
23:28:15.0374 5420  [ B559AA04EF539CFF8FEA67C4ECD12074 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
23:28:15.0374 5420  WinHttpAutoProxySvc - ok
23:28:15.0390 5420  [ E23475E9150E6A50B12DB176EA5CDD56 ] WinMad          C:\WINDOWS\System32\drivers\winmad.sys
23:28:15.0390 5420  WinMad - ok
23:28:15.0405 5420  [ 0FBD5D358094E254A1508832D4042FF7 ] Winmgmt         C:\WINDOWS\system32\wbem\WMIsvc.dll
23:28:15.0405 5420  Winmgmt - ok
23:28:15.0421 5420  [ 3E27B5B573DCC8DE15A93F61C01713B6 ] WinNat          C:\WINDOWS\system32\drivers\winnat.sys
23:28:15.0421 5420  WinNat - ok
23:28:15.0452 5420  [ C2A88E382CD48E4772A5570D66BF1A90 ] WinRM           C:\WINDOWS\system32\WsmSvc.dll
23:28:15.0484 5420  WinRM - ok
23:28:15.0499 5420  [ E92F3539C4758F6A9F4B80CBAC75B3E6 ] WINUSB          C:\WINDOWS\System32\drivers\WinUSB.SYS
23:28:15.0499 5420  WINUSB - ok
23:28:15.0515 5420  [ 59126AFCC64270747B5CC9B44A4A48F4 ] WinVerbs        C:\WINDOWS\System32\drivers\winverbs.sys
23:28:15.0515 5420  WinVerbs - ok
23:28:15.0530 5420  [ 0A3ADAA0EFAFA26CA8570E24A13CE484 ] wisvc           C:\WINDOWS\system32\flightsettings.dll
23:28:15.0546 5420  wisvc - ok
23:28:15.0577 5420  [ 01884DA4486A1B8469D406248C42DF50 ] WlanSvc         C:\WINDOWS\System32\wlansvc.dll
23:28:15.0593 5420  WlanSvc - ok
23:28:15.0624 5420  [ 345056CEAC49D289098F7A33A2C7CA2B ] wlidsvc         C:\WINDOWS\system32\wlidsvc.dll
23:28:15.0655 5420  wlidsvc - ok
23:28:15.0671 5420  [ 56E1A46DD1C5D28B10F02E21D077EBF6 ] wlpasvc         C:\WINDOWS\System32\lpasvc.dll
23:28:15.0687 5420  wlpasvc - ok
23:28:15.0687 5420  [ E8C793ED028E132771988760819E3754 ] WmiAcpi         C:\WINDOWS\System32\drivers\wmiacpi.sys
23:28:15.0687 5420  WmiAcpi - ok
23:28:15.0702 5420  [ 7112092A3C6F41EDBE83636791C774D9 ] wmiApSrv        C:\WINDOWS\system32\wbem\WmiApSrv.exe
23:28:15.0702 5420  wmiApSrv - ok
23:28:15.0718 5420  WMPNetworkSvc - ok
23:28:15.0734 5420  [ 8D6E6F6C233AF450C50FA615530B44D2 ] Wof             C:\WINDOWS\system32\drivers\Wof.sys
23:28:15.0734 5420  Wof - ok
23:28:15.0765 5420  [ 1431D184691F7FA9AAC2064EB0EC6C96 ] workfolderssvc  C:\WINDOWS\system32\workfolderssvc.dll
23:28:15.0780 5420  workfolderssvc - ok
23:28:15.0780 5420  [ AE9793230B219113DE1163138645E5AE ] WPDBusEnum      C:\WINDOWS\system32\wpdbusenum.dll
23:28:15.0796 5420  WPDBusEnum - ok
23:28:15.0796 5420  [ 9EAE1EF282864674355B4B81DF6AE935 ] WpdUpFltr       C:\WINDOWS\system32\drivers\WpdUpFltr.sys
23:28:15.0796 5420  WpdUpFltr - ok
23:28:15.0812 5420  [ C75B59E441206A572CC64BBB60EE54B3 ] WpnService      C:\WINDOWS\system32\WpnService.dll
23:28:15.0812 5420  WpnService - ok
23:28:15.0827 5420  [ 07F4AF1730D55567EACE7ADDEA28FE48 ] WpnUserService  C:\WINDOWS\System32\WpnUserService.dll
23:28:15.0827 5420  WpnUserService - ok
23:28:15.0843 5420  [ 367B3ED0C688AFE28C376B0230814567 ] ws2ifsl         C:\WINDOWS\system32\drivers\ws2ifsl.sys
23:28:15.0843 5420  ws2ifsl - ok
23:28:15.0843 5420  [ 39DA352FAD220E83CE64DE8DCCB9736B ] wscsvc          C:\WINDOWS\System32\wscsvc.dll
23:28:15.0859 5420  wscsvc - ok
23:28:15.0859 5420  WSearch - ok
23:28:15.0905 5420  [ C502D4199DDE31CA8C368BB8968309D6 ] wuauserv        C:\WINDOWS\system32\wuaueng.dll
23:28:15.0937 5420  wuauserv - ok
23:28:15.0937 5420  [ BD5E68B369DF3453A0A87663C6C5476D ] WudfPf          C:\WINDOWS\system32\drivers\WudfPf.sys
23:28:15.0937 5420  WudfPf - ok
23:28:15.0952 5420  [ A86A249314FD0A780214028B0C31A386 ] WUDFRd          C:\WINDOWS\system32\drivers\WudfRd.sys
23:28:15.0952 5420  WUDFRd - ok
23:28:15.0968 5420  [ A86A249314FD0A780214028B0C31A386 ] WUDFWpdFs       C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
23:28:15.0968 5420  WUDFWpdFs - ok
23:28:15.0984 5420  [ 7D4B6DC3975945759AFA8E9892CF7846 ] WwanSvc         C:\WINDOWS\System32\wwansvc.dll
23:28:16.0015 5420  WwanSvc - ok
23:28:16.0015 5420  [ 42C738ED1552FE168F6EE1BAE8ACFCAC ] xbgm            C:\WINDOWS\system32\xbgmsvc.exe
23:28:16.0030 5420  xbgm - ok
23:28:16.0046 5420  [ A03C4D4D71304087820A0EF18FCF7582 ] XblAuthManager  C:\WINDOWS\System32\XblAuthManager.dll
23:28:16.0062 5420  XblAuthManager - ok
23:28:16.0077 5420  [ 77ADC2F5DBE303EF8B8D2D08AEE3F3DB ] XblGameSave     C:\WINDOWS\System32\XblGameSave.dll
23:28:16.0093 5420  XblGameSave - ok
23:28:16.0109 5420  [ 2244A4CEFE8F9C74091369ACE2E9EBC6 ] xboxgip         C:\WINDOWS\System32\drivers\xboxgip.sys
23:28:16.0109 5420  xboxgip - ok
23:28:16.0109 5420  [ 1A9550D746B8604D37A90436EF686777 ] XboxGipSvc      C:\WINDOWS\System32\XboxGipSvc.dll
23:28:16.0124 5420  XboxGipSvc - ok
23:28:16.0140 5420  [ 4951DD543AA2710760D90A58261ED665 ] XboxNetApiSvc   C:\WINDOWS\system32\XboxNetApiSvc.dll
23:28:16.0155 5420  XboxNetApiSvc - ok
23:28:16.0155 5420  [ 4A91B49C6B1E41151D47CB919ADF013A ] xinputhid       C:\WINDOWS\System32\drivers\xinputhid.sys
23:28:16.0155 5420  xinputhid - ok
23:28:16.0171 5420  [ 21E13F2CB269DEFEAE5E1D09887D47BB ] ZAM             C:\WINDOWS\System32\drivers\zam64.sys
23:28:16.0171 5420  ZAM - ok
23:28:16.0329 5420  [ 864FA7B8856FE853D381045771DB30E9 ] ZAMSvc          C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
23:28:16.0407 5420  ZAMSvc - ok
23:28:16.0423 5420  [ 21E13F2CB269DEFEAE5E1D09887D47BB ] ZAM_Guard       C:\WINDOWS\System32\drivers\zamguard64.sys
23:28:16.0423 5420  ZAM_Guard - ok
23:28:16.0423 5420  ================ Scan global ===============================
23:28:16.0423 5420  [ EB45383BE9D7ECB36D55B262E0D8EB46 ] C:\WINDOWS\system32\basesrv.dll
23:28:16.0438 5420  [ 79DA21044C98FD6CD01EA9E488DF82C5 ] C:\WINDOWS\system32\winsrv.dll
23:28:16.0438 5420  [ 9451BA31B1DC19CED2608D82863C6486 ] C:\WINDOWS\system32\sxssrv.dll
23:28:16.0454 5420  [ 16B7B5FC9533777CE5770CEE52D81A86 ] C:\WINDOWS\system32\services.exe
23:28:16.0470 5420  [Global] - ok
23:28:16.0470 5420  ================ Scan MBR ==================================
23:28:16.0470 5420  [ B1F7D7F6E4FBE98E578562A22A94D02C ] \Device\Harddisk0\DR0
23:28:16.0532 5420  \Device\Harddisk0\DR0 - ok
23:28:16.0532 5420  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
23:28:16.0532 5420  \Device\Harddisk1\DR1 - ok
23:28:16.0532 5420  ================ Scan VBR ==================================
23:28:16.0548 5420  [ 9E95BAB243D859FFFA874FAB5EF0EE3D ] \Device\Harddisk0\DR0\Partition1
23:28:16.0548 5420  \Device\Harddisk0\DR0\Partition1 - ok
23:28:16.0548 5420  [ 1E80C31509CEAFA536CF6EA01AE887A7 ] \Device\Harddisk0\DR0\Partition2
23:28:16.0548 5420  \Device\Harddisk0\DR0\Partition2 - ok
23:28:16.0548 5420  [ 8A8D682DB7593354CA6C437E6FCB44F2 ] \Device\Harddisk1\DR1\Partition1
23:28:16.0548 5420  \Device\Harddisk1\DR1\Partition1 - ok
23:28:16.0563 5420  ============================================================
23:28:16.0563 5420  Scan finished
23:28:16.0563 5420  ============================================================
23:28:16.0563 4964  Detected object count: 0
23:28:16.0563 4964  Actual detected object count: 0
23:29:01.0917 6240  ============================================================
23:29:01.0917 6240  Scan started
23:29:01.0917 6240  Mode: Manual;
23:29:01.0917 6240  ============================================================
23:29:02.0136 6240  ================ Scan system memory ========================
23:29:02.0136 6240  System memory - ok
23:29:02.0136 6240  ================ Scan services =============================
23:29:02.0152 6240  [ 98E06CAC2C508118450095E581202230 ] !SASCORE        C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
23:29:02.0152 6240  !SASCORE - ok
23:29:02.0198 6240  [ 08312DEEF0D3F8647AA53AD90A69094E ] 1394ohci        C:\WINDOWS\System32\drivers\1394ohci.sys
23:29:02.0198 6240  1394ohci - ok
23:29:02.0214 6240  [ 645009E711BBF117CCEE917A03FB0CDD ] 3ware           C:\WINDOWS\system32\drivers\3ware.sys
23:29:02.0214 6240  3ware - ok
23:29:02.0308 6240  [ F2C2362B578E4956652AE0172B2091B3 ] a2AntiMalware   C:\Program Files\Emsisoft Anti-Malware\a2service.exe
23:29:02.0339 6240  a2AntiMalware - ok
23:29:02.0355 6240  [ 91A59E1A94F1A267FA9F8F6FC9AA9497 ] ACPI            C:\WINDOWS\system32\drivers\ACPI.sys
23:29:02.0370 6240  ACPI - ok
23:29:02.0370 6240  [ 44EA35A4B397898A83BF1B9B4B8DAE35 ] AcpiDev         C:\WINDOWS\System32\drivers\AcpiDev.sys
23:29:02.0370 6240  AcpiDev - ok
23:29:02.0370 6240  [ 91D113A1532B8AB1E25B7DE5AB3C2F83 ] acpiex          C:\WINDOWS\system32\Drivers\acpiex.sys
23:29:02.0386 6240  acpiex - ok
23:29:02.0386 6240  [ 620BB2682BA625DF037072D89F44F6EE ] acpipagr        C:\WINDOWS\System32\drivers\acpipagr.sys
23:29:02.0386 6240  acpipagr - ok
23:29:02.0386 6240  [ B9805A3C479390CEAEA5AEF5E4A90A2E ] AcpiPmi         C:\WINDOWS\System32\drivers\acpipmi.sys
23:29:02.0386 6240  AcpiPmi - ok
23:29:02.0402 6240  [ ABD4EB55C661143B015BD0B9B47B235C ] acpitime        C:\WINDOWS\System32\drivers\acpitime.sys
23:29:02.0402 6240  acpitime - ok
23:29:02.0402 6240  [ 38622FFE9369D3EC01C0097235BD9279 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
23:29:02.0402 6240  AdobeARMservice - ok
23:29:02.0433 6240  [ 5D0A6467159A017D3F2222CAE67031B3 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
23:29:02.0433 6240  AdobeFlashPlayerUpdateSvc - ok
23:29:02.0448 6240  [ 8C58BD711FAD5F11E8CFDBC5CED973A5 ] ADP80XX         C:\WINDOWS\system32\drivers\ADP80XX.SYS
23:29:02.0448 6240  ADP80XX - ok
23:29:02.0464 6240  [ 6FB5A2026B16D596DEABF550E7A4BD82 ] AFD             C:\WINDOWS\system32\drivers\afd.sys
23:29:02.0464 6240  AFD - ok
23:29:02.0480 6240  [ 56166D110D3ECFFC595E5FA02D9BA491 ] ahcache         C:\WINDOWS\system32\DRIVERS\ahcache.sys
23:29:02.0480 6240  ahcache - ok
23:29:02.0480 6240  [ 84FFB4AC2BA923364DF13F73751E05D1 ] AJRouter        C:\WINDOWS\System32\AJRouter.dll
23:29:02.0495 6240  AJRouter - ok
23:29:02.0495 6240  [ 084101AB03969D8ED00D5FFBE5F4C3DF ] ALG             C:\WINDOWS\System32\alg.exe
23:29:02.0495 6240  ALG - ok
23:29:02.0511 6240  [ 62619E31AFF88F906A7E793AC4A9FF51 ] AmdK8           C:\WINDOWS\System32\drivers\amdk8.sys
23:29:02.0511 6240  AmdK8 - ok
23:29:02.0511 6240  [ 735142DD039BEB35632765C41FC6E397 ] AmdPPM          C:\WINDOWS\System32\drivers\amdppm.sys
23:29:02.0511 6240  AmdPPM - ok
23:29:02.0527 6240  [ F1C16AABA27E9E153AEC7BD2AB853F30 ] amdsata         C:\WINDOWS\system32\drivers\amdsata.sys
23:29:02.0527 6240  amdsata - ok
23:29:02.0527 6240  [ C834D0F1ECB8473E9E6D18EE1BCEECB2 ] amdsbs          C:\WINDOWS\system32\drivers\amdsbs.sys
23:29:02.0527 6240  amdsbs - ok
23:29:02.0542 6240  [ 49203D2FFE30CBB36BE66A0E70F3D954 ] amdxata         C:\WINDOWS\system32\drivers\amdxata.sys
23:29:02.0542 6240  amdxata - ok
23:29:02.0542 6240  [ 4EB4D11F563FBEBDE8DE4E74B8851715 ] AppHostSvc      C:\WINDOWS\system32\inetsrv\apphostsvc.dll
23:29:02.0542 6240  AppHostSvc - ok
23:29:02.0558 6240  [ 3692C75C47285D388C886D162F54C430 ] AppID           C:\WINDOWS\system32\drivers\appid.sys
23:29:02.0558 6240  AppID - ok
23:29:02.0558 6240  [ A78F24AF599EA536C6028D80E4037664 ] AppIDSvc        C:\WINDOWS\System32\appidsvc.dll
23:29:02.0558 6240  AppIDSvc - ok
23:29:02.0573 6240  [ BDB770759D74988591A2E3B339CD1CCB ] Appinfo         C:\WINDOWS\System32\appinfo.dll
23:29:02.0573 6240  Appinfo - ok
23:29:02.0573 6240  [ 1E085E2302D568F0CE041732B3E887B0 ] applockerfltr   C:\WINDOWS\system32\drivers\applockerfltr.sys
23:29:02.0573 6240  applockerfltr - ok
23:29:02.0589 6240  [ 1D123729F547EEDFBE3F510346848C38 ] AppReadiness    C:\WINDOWS\system32\AppReadiness.dll
23:29:02.0589 6240  AppReadiness - ok
23:29:02.0636 6240  [ 9025C763611676B9905A922C5C3C1FA6 ] AppXSvc         C:\WINDOWS\system32\appxdeploymentserver.dll
23:29:02.0652 6240  AppXSvc - ok
23:29:02.0652 6240  [ B42C83DE28776B80DBA1310C56DD4F74 ] arcsas          C:\WINDOWS\system32\drivers\arcsas.sys
23:29:02.0652 6240  arcsas - ok
23:29:02.0683 6240  [ 9CDC69DDFDC91DC628F7515809329798 ] aspnet_state    C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
23:29:02.0683 6240  aspnet_state - ok
23:29:02.0683 6240  [ C2151380227CD1F7DDA2401C1F151367 ] AsyncMac        C:\WINDOWS\System32\drivers\asyncmac.sys
23:29:02.0683 6240  AsyncMac - ok
23:29:02.0683 6240  [ 6191B9B2EE0E8CB957C683B9B341CC86 ] atapi           C:\WINDOWS\system32\drivers\atapi.sys
23:29:02.0683 6240  atapi - ok
23:29:02.0698 6240  [ D52C8B37F02C93E0391AFD10320EE4C6 ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll
23:29:02.0714 6240  AudioEndpointBuilder - ok
23:29:02.0730 6240  [ 5D74B86053FFFBD9C94081DAB7338403 ] Audiosrv        C:\WINDOWS\System32\Audiosrv.dll
23:29:02.0730 6240  Audiosrv - ok
23:29:02.0745 6240  [ 947FF5992E26AFD4CAA34506678B70BC ] AxInstSV        C:\WINDOWS\System32\AxInstSV.dll
23:29:02.0745 6240  AxInstSV - ok
23:29:02.0761 6240  [ A921805C1ED3253DF48FCA4D724173EB ] b06bdrv         C:\WINDOWS\system32\drivers\bxvbda.sys
23:29:02.0761 6240  b06bdrv - ok
23:29:02.0761 6240  [ A5E8423AB9369A303254790D39E03D0F ] bam             C:\WINDOWS\system32\drivers\bam.sys
23:29:02.0761 6240  bam - ok
23:29:02.0777 6240  [ 2A7267AA15E508F6D05A5B562F1FD1CE ] BasicDisplay    C:\WINDOWS\System32\drivers\BasicDisplay.sys
23:29:02.0777 6240  BasicDisplay - ok
23:29:02.0777 6240  [ 2E1EE0F10FAF1250D1AC05BFB0E6BD3D ] BasicRender     C:\WINDOWS\System32\drivers\BasicRender.sys
23:29:02.0777 6240  BasicRender - ok
23:29:02.0792 6240  [ 739D089777D2B66DBE7201E5EA4BA2D7 ] bcmfn2          C:\WINDOWS\System32\drivers\bcmfn2.sys
23:29:02.0792 6240  bcmfn2 - ok
23:29:02.0792 6240  [ 72963E0676003016B431306A6F4951BF ] BDESVC          C:\WINDOWS\System32\bdesvc.dll
23:29:02.0792 6240  BDESVC - ok
23:29:02.0808 6240  [ EDDAA3A563E7EB71C991FE91249C7D81 ] Beep            C:\WINDOWS\system32\drivers\Beep.sys
23:29:02.0808 6240  Beep - ok
23:29:02.0823 6240  [ 86CAB4060251D418B6449D6CBCC852A6 ] BFE             C:\WINDOWS\System32\bfe.dll
23:29:02.0823 6240  BFE - ok
23:29:02.0839 6240  [ E223918B4E0B28CF7BE132C30D1E161A ] BITS            C:\WINDOWS\System32\qmgr.dll
23:29:02.0855 6240  BITS - ok
 


Google is my friend. Make Google your friend too.


#14 Torvald

Torvald
  • Topic Starter

  • Members
  • 366 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Antonio, TX USA
  • Local time:05:19 AM

Posted 28 November 2017 - 12:39 AM

Here is the second part of my TDSSKiller log text file:

 

23:29:02.0855 6240  [ D030A1203680D66716F4E74053468627 ] bowser          C:\WINDOWS\system32\DRIVERS\bowser.sys
23:29:02.0855 6240  bowser - ok
23:29:02.0870 6240  [ 51C7B80F03FD20376516AE68F98479B1 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
23:29:02.0870 6240  BrokerInfrastructure - ok
23:29:02.0886 6240  [ 2BA1BED8E8168C301522AC7CFBFA2141 ] Browser         C:\WINDOWS\System32\browser.dll
23:29:02.0886 6240  Browser - ok
23:29:02.0886 6240  [ A4863B7B1F0DB513D6E34547BACC211A ] BthAvrcpTg      C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
23:29:02.0886 6240  BthAvrcpTg - ok
23:29:02.0902 6240  [ 9C9EE272C11252C651C5DE6A1AC1EDAA ] BthHFEnum       C:\WINDOWS\System32\drivers\bthhfenum.sys
23:29:02.0902 6240  BthHFEnum - ok
23:29:02.0902 6240  [ 69734E386826ED857C889330F35B4D9C ] bthhfhid        C:\WINDOWS\System32\drivers\BthHFHid.sys
23:29:02.0902 6240  bthhfhid - ok
23:29:02.0917 6240  [ BC58294295CBAD6637A526470305B5EA ] BthHFSrv        C:\WINDOWS\System32\BthHFSrv.dll
23:29:02.0917 6240  BthHFSrv - ok
23:29:02.0933 6240  [ A94AFAEA86F5F792BB4ECA095B231464 ] BTHMODEM        C:\WINDOWS\System32\drivers\bthmodem.sys
23:29:02.0933 6240  BTHMODEM - ok
23:29:02.0933 6240  [ 572BCA61B7E026E057AF7DF456AC7E0B ] bthserv         C:\WINDOWS\system32\bthserv.dll
23:29:02.0933 6240  bthserv - ok
23:29:02.0948 6240  [ 39E7437FC59CDD7A303ABD514E462E8B ] bttflt          C:\WINDOWS\system32\drivers\bttflt.sys
23:29:02.0948 6240  bttflt - ok
23:29:02.0948 6240  [ 522888590B0C19BC8128119060AE7901 ] buttonconverter C:\WINDOWS\System32\drivers\buttonconverter.sys
23:29:02.0948 6240  buttonconverter - ok
23:29:02.0964 6240  [ 2AB01CE5E233A6FBA3E91BD57772AA4B ] CAD             C:\WINDOWS\System32\drivers\CAD.sys
23:29:02.0964 6240  CAD - ok
23:29:02.0964 6240  [ E2C8EE32C053892E685A989071AAE333 ] camsvc          C:\WINDOWS\system32\CapabilityAccessManager.dll
23:29:02.0964 6240  camsvc - ok
23:29:02.0980 6240  [ F6F97879F53AD57194C6BC8272FD73EA ] CapImg          C:\WINDOWS\System32\drivers\capimg.sys
23:29:02.0980 6240  CapImg - ok
23:29:02.0980 6240  [ 9E82A95D77AC78C84BA75FF896B060BF ] cdfs            C:\WINDOWS\system32\DRIVERS\cdfs.sys
23:29:02.0980 6240  cdfs - ok
23:29:02.0995 6240  [ 147CEBE0C5F7A80135C54715521AD9E1 ] CDPSvc          C:\WINDOWS\System32\CDPSvc.dll
23:29:02.0995 6240  CDPSvc - ok
23:29:03.0011 6240  [ C2F158F11391F21C7D3FEB572D11C2D2 ] CDPUserSvc      C:\WINDOWS\System32\CDPUserSvc.dll
23:29:03.0011 6240  CDPUserSvc - ok
23:29:03.0027 6240  [ 6D83565C1652E80447EDEA6947FA89D7 ] cdrom           C:\WINDOWS\System32\drivers\cdrom.sys
23:29:03.0027 6240  cdrom - ok
23:29:03.0027 6240  [ 200A5398C0E7E78DBDF6C0D9E811F366 ] CertPropSvc     C:\WINDOWS\System32\certprop.dll
23:29:03.0027 6240  CertPropSvc - ok
23:29:03.0042 6240  [ D81954CE5E016FD716EDDB2B2FD9BA58 ] cht4iscsi       C:\WINDOWS\system32\drivers\cht4sx64.sys
23:29:03.0042 6240  cht4iscsi - ok
23:29:03.0058 6240  [ F9A8570805807FFD66488F0A858E1308 ] cht4vbd         C:\WINDOWS\System32\drivers\cht4vx64.sys
23:29:03.0073 6240  cht4vbd - ok
23:29:03.0073 6240  [ 9798D58461706930190F1F2F6BF21D80 ] circlass        C:\WINDOWS\System32\drivers\circlass.sys
23:29:03.0073 6240  circlass - ok
23:29:03.0089 6240  [ CC8F32D22A8616F3A38FE43B23611CC5 ] CldFlt          C:\WINDOWS\system32\drivers\cldflt.sys
23:29:03.0089 6240  CldFlt - ok
23:29:03.0105 6240  [ 68661D5E98E9A1F29E4B408CF02BBB38 ] CLFS            C:\WINDOWS\system32\drivers\CLFS.sys
23:29:03.0105 6240  CLFS - ok
23:29:03.0120 6240  [ BE9FA79096DD2CB43E7066897AB52E50 ] ClipSVC         C:\WINDOWS\System32\ClipSVC.dll
23:29:03.0120 6240  ClipSVC - ok
23:29:03.0136 6240  [ 2BA3BA38B5A6A667B0EAEC477276707B ] CmBatt          C:\WINDOWS\System32\drivers\CmBatt.sys
23:29:03.0136 6240  CmBatt - ok
23:29:03.0152 6240  [ 83CE170337E6F77350C0FFB055FBC4BF ] CNG             C:\WINDOWS\system32\Drivers\cng.sys
23:29:03.0152 6240  CNG - ok
23:29:03.0152 6240  [ C65AF00EF12A1755E7CA370B0C71935D ] cnghwassist     C:\WINDOWS\system32\DRIVERS\cnghwassist.sys
23:29:03.0167 6240  cnghwassist - ok
23:29:03.0183 6240  [ A50300498D56B2448F3593D25478D508 ] CompositeBus    C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_9c1fb8f4db31c348\CompositeBus.sys
23:29:03.0183 6240  CompositeBus - ok
23:29:03.0183 6240  COMSysApp - ok
23:29:03.0198 6240  [ 65602B0DB49199647FECB2D1212147BE ] condrv          C:\WINDOWS\system32\drivers\condrv.sys
23:29:03.0198 6240  condrv - ok
23:29:03.0214 6240  [ 67FDCB1F856EA3621B099210F1DF620E ] CoreMessagingRegistrar C:\WINDOWS\system32\coremessaging.dll
23:29:03.0214 6240  CoreMessagingRegistrar - ok
23:29:03.0230 6240  [ C8BD651E13895B93ED9EC5B4F1DF42BC ] Creative ALchemy AL6 Licensing Service C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
23:29:03.0230 6240  Creative ALchemy AL6 Licensing Service - ok
23:29:03.0230 6240  [ C0EAD9F8AB83D41FF07303C75589C2B8 ] Creative Audio Engine Licensing Service C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
23:29:03.0230 6240  Creative Audio Engine Licensing Service - ok
23:29:03.0245 6240  [ D64EF74FC6DA47EC2E460076F299E77D ] CryptSvc        C:\WINDOWS\system32\cryptsvc.dll
23:29:03.0245 6240  CryptSvc - ok
23:29:03.0261 6240  [ 69CDBA2B9C397E349A04FA70DD9170A2 ] CTAudSvcService C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
23:29:03.0261 6240  CTAudSvcService - ok
23:29:03.0261 6240  [ 807935024E2CCCF9D13BD5E3A8592204 ] CybereasonRansomFree C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFreeServiceHost.exe
23:29:03.0261 6240  CybereasonRansomFree - ok
23:29:03.0277 6240  [ 72BE43ABD786E86AAE7EA2193201E100 ] dam             C:\WINDOWS\system32\drivers\dam.sys
23:29:03.0277 6240  dam - ok
23:29:03.0292 6240  [ 79BDBB684629A526CCD958F06B9D6FAD ] DcomLaunch      C:\WINDOWS\system32\rpcss.dll
23:29:03.0292 6240  DcomLaunch - ok
23:29:03.0308 6240  [ F7FB921F438C3566CEC55657EA4E7D9C ] defragsvc       C:\WINDOWS\System32\defragsvc.dll
23:29:03.0308 6240  defragsvc - ok
23:29:03.0323 6240  [ B5F9123D6537856EA698386ABA27A232 ] DeviceAssociationService C:\WINDOWS\system32\das.dll
23:29:03.0323 6240  DeviceAssociationService - ok
23:29:03.0339 6240  [ 64A80A746FC460126FA4124AA2D93848 ] DeviceInstall   C:\WINDOWS\system32\umpnpmgr.dll
23:29:03.0339 6240  DeviceInstall - ok
23:29:03.0355 6240  [ A19F51A044B62C994144ED87A7A5A887 ] DevicesFlowUserSvc C:\WINDOWS\System32\DevicesFlowBroker.dll
23:29:03.0355 6240  DevicesFlowUserSvc - ok
23:29:03.0355 6240  [ 0D2A4CA81D1F7B5E5FBFE1E4F60246B8 ] DevQueryBroker  C:\WINDOWS\system32\DevQueryBroker.dll
23:29:03.0355 6240  DevQueryBroker - ok
23:29:03.0370 6240  [ 9910E9CFF5ECDCB225F82E72CE9DE459 ] Dfsc            C:\WINDOWS\system32\Drivers\dfsc.sys
23:29:03.0370 6240  Dfsc - ok
23:29:03.0370 6240  [ 309F4FBA6AC2CA70663C99690AE900C2 ] Dhcp            C:\WINDOWS\system32\dhcpcore.dll
23:29:03.0386 6240  Dhcp - ok
23:29:03.0386 6240  [ 8C46ADC4354DDE94CA459CB4BA822073 ] diagnosticshub.standardcollector.service C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
23:29:03.0386 6240  diagnosticshub.standardcollector.service - ok
23:29:03.0402 6240  [ E2BF09B816393AF73EDCB8ECF9BBDB2D ] diagsvc         C:\WINDOWS\system32\DiagSvc.dll
23:29:03.0402 6240  diagsvc - ok
23:29:03.0433 6240  [ 93AE3D0B61365651158E3C11F0A26228 ] DiagTrack       C:\WINDOWS\system32\diagtrack.dll
23:29:03.0433 6240  DiagTrack - ok
23:29:03.0448 6240  [ 811173C821171BB910219E53C7FD97AD ] Disk            C:\WINDOWS\system32\drivers\disk.sys
23:29:03.0448 6240  Disk - ok
23:29:03.0464 6240  [ 133E5277C2A50770EADFAC4AF2232D69 ] DmEnrollmentSvc C:\WINDOWS\system32\Windows.Internal.Management.dll
23:29:03.0464 6240  DmEnrollmentSvc - ok
23:29:03.0480 6240  [ 569FE16775E15A49DC904DE20BF8CAA0 ] dmvsc           C:\WINDOWS\System32\drivers\dmvsc.sys
23:29:03.0480 6240  dmvsc - ok
23:29:03.0480 6240  [ 10E72E3315305461D3F0C7560AE98CA5 ] dmwappushservice C:\WINDOWS\system32\dmwappushsvc.dll
23:29:03.0480 6240  dmwappushservice - ok
23:29:03.0495 6240  [ 4ACA3CE75B4C2243299C24A715E9B3CE ] Dnscache        C:\WINDOWS\System32\dnsrslvr.dll
23:29:03.0495 6240  Dnscache - ok
23:29:03.0495 6240  [ 24F0CF56DF2725291937B32597BA8D51 ] dot3svc         C:\WINDOWS\System32\dot3svc.dll
23:29:03.0511 6240  dot3svc - ok
23:29:03.0511 6240  [ 6D8971C942FEE43A0AB6B3192534AFB4 ] DPS             C:\WINDOWS\system32\dps.dll
23:29:03.0511 6240  DPS - ok
23:29:03.0511 6240  [ F4800922F4ABA619585CE320A72E6389 ] drmkaud         C:\WINDOWS\System32\drivers\drmkaud.sys
23:29:03.0527 6240  drmkaud - ok
23:29:03.0527 6240  [ A5A92C78F797E8459AF793540C05D26C ] DsmSvc          C:\WINDOWS\System32\DeviceSetupManager.dll
23:29:03.0527 6240  DsmSvc - ok
23:29:03.0542 6240  [ C7DC50CC0C6B0948A0C040622FCD70EA ] DsSvc           C:\WINDOWS\System32\DsSvc.dll
23:29:03.0542 6240  DsSvc - ok
23:29:03.0542 6240  [ 242176ADAFE7BA96CC7D72FFCE4A16C1 ] DusmSvc         C:\WINDOWS\System32\dusmsvc.dll
23:29:03.0542 6240  DusmSvc - ok
23:29:03.0573 6240  [ C248883ED585F2A309BE11AFD0C60318 ] DXGKrnl         C:\WINDOWS\System32\drivers\dxgkrnl.sys
23:29:03.0589 6240  DXGKrnl - ok
23:29:03.0605 6240  [ FA94398748930D840FE35A44F1D225A7 ] Eaphost         C:\WINDOWS\System32\eapsvc.dll
23:29:03.0605 6240  Eaphost - ok
23:29:03.0605 6240  [ 9FF412B8514C4465C4856E06C13FF921 ] EaseUS Agent    C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
23:29:03.0605 6240  EaseUS Agent - ok
23:29:03.0652 6240  [ C99D40C97841E0A7F0F90B8629593A97 ] ebdrv           C:\WINDOWS\system32\drivers\evbda.sys
23:29:03.0667 6240  ebdrv - ok
23:29:03.0667 6240  [ 94E06D509D50807774F35BEE3163E806 ] EFS             C:\WINDOWS\System32\lsass.exe
23:29:03.0667 6240  EFS - ok
23:29:03.0683 6240  [ 260BBD6B1ED06298E509B452354EDB91 ] EhStorClass     C:\WINDOWS\system32\drivers\EhStorClass.sys
23:29:03.0683 6240  EhStorClass - ok
23:29:03.0683 6240  [ F3BEBDC1B9DBA32F183079EAE6244837 ] EhStorTcgDrv    C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
23:29:03.0683 6240  EhStorTcgDrv - ok
23:29:03.0698 6240  [ A75880A9192B9DA69F46867B06276746 ] embeddedmode    C:\WINDOWS\System32\embeddedmodesvc.dll
23:29:03.0698 6240  embeddedmode - ok
23:29:03.0698 6240  [ 9E6CB1D3F6AD67AA7A2C831FB9B7E496 ] EntAppSvc       C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
23:29:03.0698 6240  EntAppSvc - ok
23:29:03.0714 6240  [ D1186D11D7FF6191CBC4BE68C8ADEAD2 ] epmntdrv        C:\WINDOWS\system32\epmntdrv.sys
23:29:03.0714 6240  epmntdrv - ok
23:29:03.0714 6240  [ 0E840AA66CAB02CBA9730C772BBE305B ] epp             C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp.sys
23:29:03.0714 6240  epp - ok
23:29:03.0730 6240  [ 1B63CA857FD03FD0A5A1379F2996784F ] ErrDev          C:\WINDOWS\System32\drivers\errdev.sys
23:29:03.0730 6240  ErrDev - ok
23:29:03.0730 6240  [ 20DF189AB6295E44AAC6D4610FAA9E85 ] ESProtectionDriver C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys
23:29:03.0730 6240  ESProtectionDriver - ok
23:29:03.0745 6240  [ C5713A2B4C9D9150041FB70C4A2ADE07 ] EUBAKUP         C:\WINDOWS\system32\drivers\eubakup.sys
23:29:03.0745 6240  EUBAKUP - ok
23:29:03.0745 6240  [ C5713A2B4C9D9150041FB70C4A2ADE07 ] EUBAKUP0        C:\WINDOWS\system32\drivers\EUBAKUP0.sys
23:29:03.0745 6240  EUBAKUP0 - ok
23:29:03.0761 6240  [ 5061B571167E1EE26E8D549CCDBE9CC6 ] EUBKMON         C:\WINDOWS\system32\drivers\EUBKMON.sys
23:29:03.0761 6240  EUBKMON - ok
23:29:03.0761 6240  [ 5061B571167E1EE26E8D549CCDBE9CC6 ] EUBKMON0        C:\WINDOWS\system32\drivers\EUBKMON0.sys
23:29:03.0761 6240  EUBKMON0 - ok
23:29:03.0761 6240  [ 44A0838432C8A31A5D6CBE0BF348CED6 ] EUDSKACS        C:\Windows\system32\drivers\eudskacs.sys
23:29:03.0761 6240  EUDSKACS - ok
23:29:03.0777 6240  [ D05585505CB20235E7C665158464551D ] EUFDDISK        C:\Windows\system32\drivers\EuFdDisk.sys
23:29:03.0777 6240  EUFDDISK - ok
23:29:03.0777 6240  [ 6B133EE401475A72D252D49F8736936E ] EUFDDISK0       C:\WINDOWS\system32\drivers\EUFDDISK0.sys
23:29:03.0777 6240  EUFDDISK0 - ok
23:29:03.0792 6240  [ 08C997734B2CECE882656BB2855E6E76 ] EuGdiDrv        C:\WINDOWS\system32\EuGdiDrv.sys
23:29:03.0792 6240  EuGdiDrv - ok
23:29:03.0808 6240  [ 6A5FA501A2D96001391FF3CBA32935AB ] EventSystem     C:\WINDOWS\system32\es.dll
23:29:03.0808 6240  EventSystem - ok
23:29:03.0808 6240  [ F1ACA42D448E3986565EA54275EEEA65 ] exfat           C:\WINDOWS\system32\drivers\exfat.sys
23:29:03.0823 6240  exfat - ok
23:29:03.0823 6240  [ 0AF4B36754A6EAE794EE4398E219A9E1 ] fastfat         C:\WINDOWS\system32\drivers\fastfat.sys
23:29:03.0823 6240  fastfat - ok
23:29:03.0839 6240  [ B1A38C0D977D8738779CA3EFEBDFCA8C ] Fax             C:\WINDOWS\system32\fxssvc.exe
23:29:03.0839 6240  Fax - ok
23:29:03.0855 6240  [ 7CD8426A33F06EB72BFEC51F7C264AF8 ] fdc             C:\WINDOWS\System32\drivers\fdc.sys
23:29:03.0855 6240  fdc - ok
23:29:03.0855 6240  [ 21EB16C5DDFBC19DEBE9EEC10EA423FB ] fdPHost         C:\WINDOWS\system32\fdPHost.dll
23:29:03.0855 6240  fdPHost - ok
23:29:03.0870 6240  [ 57F98EFE6CB82AE5400BA99C705AF45C ] FDResPub        C:\WINDOWS\system32\fdrespub.dll
23:29:03.0870 6240  FDResPub - ok
23:29:03.0870 6240  [ 02F93E4B9EC2821B6670208044FF5332 ] fhsvc           C:\WINDOWS\system32\fhsvc.dll
23:29:03.0886 6240  fhsvc - ok
23:29:03.0886 6240  [ DE51BBBCF358188F9736F031546F9908 ] FileCrypt       C:\WINDOWS\system32\drivers\filecrypt.sys
23:29:03.0886 6240  FileCrypt - ok
23:29:03.0886 6240  [ 822F664952B0F8D11BB6BD2F11779602 ] FileInfo        C:\WINDOWS\system32\drivers\fileinfo.sys
23:29:03.0886 6240  FileInfo - ok
23:29:03.0902 6240  [ 5A4935682A0D47A4EAC4BE3C2ACF74D6 ] Filetrace       C:\WINDOWS\system32\drivers\filetrace.sys
23:29:03.0902 6240  Filetrace - ok
23:29:03.0902 6240  [ 60641F22D1D38EAD197C25F0339C9712 ] flpydisk        C:\WINDOWS\System32\drivers\flpydisk.sys
23:29:03.0902 6240  flpydisk - ok
23:29:03.0917 6240  [ 0C98D8F7867A8644EDA43865B15908C0 ] FltMgr          C:\WINDOWS\system32\drivers\fltmgr.sys
23:29:03.0917 6240  FltMgr - ok
23:29:03.0948 6240  [ 9DCB91239DE1FE05F870AE3471E70559 ] FontCache       C:\WINDOWS\system32\FntCache.dll
23:29:03.0948 6240  FontCache - ok
23:29:03.0964 6240  [ A7C6894FFF261C0FEFDCB41BE83CF430 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
23:29:03.0964 6240  FontCache3.0.0.0 - ok
23:29:03.0964 6240  [ 6793F7AE8442C487C55352C78739E77A ] FrameServer     C:\WINDOWS\system32\FrameServer.dll
23:29:03.0980 6240  FrameServer - ok
23:29:03.0980 6240  [ FB55F4ACC55261B25B3FF1B5BF87F10A ] FsDepends       C:\WINDOWS\system32\drivers\FsDepends.sys
23:29:03.0980 6240  FsDepends - ok
23:29:03.0995 6240  [ BB82CC2F51F7C3D5DCD13FA3B040D8F8 ] Fs_Rec          C:\WINDOWS\system32\drivers\Fs_Rec.sys
23:29:03.0995 6240  Fs_Rec - ok
23:29:03.0995 6240  [ 11C39CA2326F1F1DBEC11C7A3D26A6A4 ] fvevol          C:\WINDOWS\system32\DRIVERS\fvevol.sys
23:29:04.0011 6240  fvevol - ok
23:29:04.0011 6240  [ 3B5DDF1061930A0A891FA63DB0CB878B ] gencounter      C:\WINDOWS\System32\drivers\vmgencounter.sys
23:29:04.0011 6240  gencounter - ok
23:29:04.0011 6240  [ 8B34E3F794F652082D7E8AF112F71681 ] genericusbfn    C:\WINDOWS\System32\drivers\genericusbfn.sys
23:29:04.0011 6240  genericusbfn - ok
23:29:04.0027 6240  [ 127C23F4720C8902A3AB0FEE12205317 ] GPIOClx0101     C:\WINDOWS\system32\Drivers\msgpioclx.sys
23:29:04.0027 6240  GPIOClx0101 - ok
23:29:04.0042 6240  [ A7A85B505944F99CB55C8669E4F7FC0F ] gpsvc           C:\WINDOWS\System32\gpsvc.dll
23:29:04.0058 6240  gpsvc - ok
23:29:04.0058 6240  [ C7DEA3458E50B691E69EFF0B47CBCCDB ] GpuEnergyDrv    C:\WINDOWS\system32\drivers\gpuenergydrv.sys
23:29:04.0058 6240  GpuEnergyDrv - ok
23:29:04.0058 6240  [ 141904F0581468B39B579EA33CA57549 ] GraphicsPerfSvc C:\WINDOWS\System32\GraphicsPerfSvc.dll
23:29:04.0058 6240  GraphicsPerfSvc - ok
23:29:04.0073 6240  [ E1B44A75947137F4143308D566889837 ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
23:29:04.0073 6240  gupdate - ok
23:29:04.0073 6240  [ E1B44A75947137F4143308D566889837 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
23:29:04.0073 6240  gupdatem - ok
23:29:04.0089 6240  [ 6B76F5915654F647B06EDBE63BCB5116 ] HdAudAddService C:\WINDOWS\system32\DRIVERS\HdAudio.sys
23:29:04.0089 6240  HdAudAddService - ok
23:29:04.0089 6240  [ 99A34FD1F6431A10D8C3BB50E170D0F2 ] HDAudBus        C:\WINDOWS\System32\drivers\HDAudBus.sys
23:29:04.0089 6240  HDAudBus - ok
23:29:04.0105 6240  [ 2443FC6EEB9CF092B62127D867901B02 ] HidBatt         C:\WINDOWS\System32\drivers\HidBatt.sys
23:29:04.0105 6240  HidBatt - ok
23:29:04.0105 6240  [ 205043CDC16ADE85E252DD54AE925161 ] HidBth          C:\WINDOWS\System32\drivers\hidbth.sys
23:29:04.0105 6240  HidBth - ok
23:29:04.0120 6240  [ B521DDDC9038C066B1B957BF063A531A ] hidi2c          C:\WINDOWS\System32\drivers\hidi2c.sys
23:29:04.0120 6240  hidi2c - ok
23:29:04.0120 6240  [ 5AC0EBFA76E93273A806176D3178E986 ] hidinterrupt    C:\WINDOWS\System32\drivers\hidinterrupt.sys
23:29:04.0120 6240  hidinterrupt - ok
23:29:04.0136 6240  [ 366AC0E05EBF5D5C375F65CD8BC7F0DF ] HidIr           C:\WINDOWS\System32\drivers\hidir.sys
23:29:04.0136 6240  HidIr - ok
23:29:04.0136 6240  [ 75F4CCB7FF03603E91DD0C7FF83DAABF ] hidserv         C:\WINDOWS\system32\hidserv.dll
23:29:04.0136 6240  hidserv - ok
23:29:04.0136 6240  [ 7CB54D02746024648FCE184FC3F941FF ] HidUsb          C:\WINDOWS\System32\drivers\hidusb.sys
23:29:04.0136 6240  HidUsb - ok
23:29:04.0152 6240  [ 7FD586369B597798535C098E63818AAC ] hitmanpro37     C:\WINDOWS\system32\drivers\hitmanpro37.sys
23:29:04.0152 6240  hitmanpro37 - ok
23:29:04.0152 6240  [ CF07C0A9D38A248D036DD9C47E4D0D6E ] hmpalert        C:\WINDOWS\system32\drivers\hmpalert.sys
23:29:04.0152 6240  hmpalert - ok
23:29:04.0183 6240  [ 2638395F6E61889D75C363A80A0E17F4 ] hmpalertsvc     C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe
23:29:04.0183 6240  hmpalertsvc - ok
23:29:04.0198 6240  [ B5E3F4730F2471C76946E04645203690 ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
23:29:04.0198 6240  HomeGroupListener - ok
23:29:04.0214 6240  [ 24C900B7296AA9867FB761A5801AFBD1 ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
23:29:04.0214 6240  HomeGroupProvider - ok
23:29:04.0214 6240  [ 835FB95D85D362057A72D21A48C2C7F8 ] HpSAMD          C:\WINDOWS\system32\drivers\HpSAMD.sys
23:29:04.0214 6240  HpSAMD - ok
23:29:04.0230 6240  [ 82C0A5B7D21442D063FFAFD0B6AAC086 ] HTTP            C:\WINDOWS\system32\drivers\HTTP.sys
23:29:04.0245 6240  HTTP - ok
23:29:04.0245 6240  [ AD930879F319969EB09449C015A32104 ] HvHost          C:\WINDOWS\System32\hvhostsvc.dll
23:29:04.0245 6240  HvHost - ok
23:29:04.0261 6240  [ 9F2CFC90306532866C62BDCDFD2532AA ] hvservice       C:\WINDOWS\system32\drivers\hvservice.sys
23:29:04.0261 6240  hvservice - ok
23:29:04.0261 6240  [ 3737FE486929AFC48F1D10677B698E52 ] HwNClx0101      C:\WINDOWS\system32\Drivers\mshwnclx.sys
23:29:04.0261 6240  HwNClx0101 - ok
23:29:04.0261 6240  [ 3C65EBF7F1BFD98426C355D66876ECEE ] hwpolicy        C:\WINDOWS\system32\drivers\hwpolicy.sys
23:29:04.0261 6240  hwpolicy - ok
23:29:04.0277 6240  [ 7E00234C67A322988AFEA717D5609C9E ] hyperkbd        C:\WINDOWS\System32\drivers\hyperkbd.sys
23:29:04.0277 6240  hyperkbd - ok
23:29:04.0277 6240  [ FBF5BB641DE99AE1DF4835E88D4F8993 ] HyperVideo      C:\WINDOWS\System32\drivers\HyperVideo.sys
23:29:04.0277 6240  HyperVideo - ok
23:29:04.0292 6240  [ 56FF074E50F9042FD2856AB3418F4B18 ] i8042prt        C:\WINDOWS\System32\drivers\i8042prt.sys
23:29:04.0292 6240  i8042prt - ok
23:29:04.0292 6240  [ B5EC43755E62591197DE5CBBDAA9FEB7 ] iagpio          C:\WINDOWS\System32\drivers\iagpio.sys
23:29:04.0292 6240  iagpio - ok
23:29:04.0292 6240  [ D8CA23F9C5FEF44296FDE1E005C06EC0 ] iai2c           C:\WINDOWS\System32\drivers\iai2c.sys
23:29:04.0292 6240  iai2c - ok
23:29:04.0308 6240  [ 7B769C9D19C013F94874C4B15D59A005 ] iaLPSS2i_GPIO2  C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys
23:29:04.0308 6240  iaLPSS2i_GPIO2 - ok
23:29:04.0308 6240  [ E0F1B3A2A70FABE3BE1C9140BB55E607 ] iaLPSS2i_GPIO2_BXT_P C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys
23:29:04.0308 6240  iaLPSS2i_GPIO2_BXT_P - ok
23:29:04.0323 6240  [ 89A869BCC0588A3009ECB875B09ECD39 ] iaLPSS2i_I2C    C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys
23:29:04.0323 6240  iaLPSS2i_I2C - ok
23:29:04.0323 6240  [ 2E693DF3C02A0859DB8DE25772751100 ] iaLPSS2i_I2C_BXT_P C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys
23:29:04.0339 6240  iaLPSS2i_I2C_BXT_P - ok
23:29:04.0339 6240  [ 16A10CCEDCF5AC4CAAE43DC9FC40392F ] iaLPSSi_GPIO    C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys
23:29:04.0339 6240  iaLPSSi_GPIO - ok
23:29:04.0339 6240  [ EB82A11613326691508D9ED9A4FE29E7 ] iaLPSSi_I2C     C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys
23:29:04.0339 6240  iaLPSSi_I2C - ok
23:29:04.0355 6240  [ 435883A27A376B125BD4DF888417C85F ] iaStorAV        C:\WINDOWS\system32\drivers\iaStorAV.sys
23:29:04.0355 6240  iaStorAV - ok
23:29:04.0370 6240  [ 7118E4390C4ACDE61E280CE52BCAF44E ] iaStorV         C:\WINDOWS\system32\drivers\iaStorV.sys
23:29:04.0370 6240  iaStorV - ok
23:29:04.0386 6240  [ 9DBE8C359ABACE1BE1BBAB687D114506 ] ibbus           C:\WINDOWS\System32\drivers\ibbus.sys
23:29:04.0386 6240  ibbus - ok
23:29:04.0402 6240  [ 113F3C05CE9B41144E6BF5FEDA4F09B7 ] icssvc          C:\WINDOWS\System32\tetheringservice.dll
23:29:04.0402 6240  icssvc - ok
23:29:04.0417 6240  [ 72AB18B50053FA57B08FD4065C11B16B ] IKEEXT          C:\WINDOWS\System32\ikeext.dll
23:29:04.0417 6240  IKEEXT - ok
23:29:04.0433 6240  [ 42CAF6216A6E516DC56BA319ACC7EEC5 ] IndirectKmd     C:\WINDOWS\System32\drivers\IndirectKmd.sys
23:29:04.0433 6240  IndirectKmd - ok
23:29:04.0448 6240  [ 329223D4AB29B4392E83304C304EF80D ] InstallService  C:\WINDOWS\system32\InstallService.dll
23:29:04.0464 6240  InstallService - ok
23:29:04.0495 6240  [ C44251AF46727BA1A4D2A703255C9071 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
23:29:04.0527 6240  IntcAzAudAddService - ok
23:29:04.0527 6240  [ 40943C1CD031ACE06A8374AD56B9E5EA ] intelide        C:\WINDOWS\system32\drivers\intelide.sys
23:29:04.0527 6240  intelide - ok
23:29:04.0542 6240  [ 327D9CCF5492543AEF3979F9EEAD02BE ] intelpep        C:\WINDOWS\system32\drivers\intelpep.sys
23:29:04.0542 6240  intelpep - ok
23:29:04.0542 6240  [ 10F2757836F41BFAEA2AE19F6FE869B2 ] intelppm        C:\WINDOWS\System32\drivers\intelppm.sys
23:29:04.0542 6240  intelppm - ok
23:29:04.0542 6240  [ E7E63F634298F3033B90B988A038698E ] IntuitUpdateServiceV4 C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
23:29:04.0542 6240  IntuitUpdateServiceV4 - ok
23:29:04.0558 6240  [ 8387E90B551B9B7F32EDC69909591E9E ] invdimm         C:\WINDOWS\System32\drivers\invdimm.sys
23:29:04.0558 6240  invdimm - ok
23:29:04.0558 6240  [ E207078E0E1BB3524277DB9077E4148E ] iorate          C:\WINDOWS\system32\drivers\iorate.sys
23:29:04.0558 6240  iorate - ok
23:29:04.0573 6240  [ FD8F64B7B345E539F2EA7F72846F83B4 ] IpFilterDriver  C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
23:29:04.0573 6240  IpFilterDriver - ok
23:29:04.0589 6240  [ 0076CE11539416052A7A79B2DCC53E6D ] iphlpsvc        C:\WINDOWS\System32\iphlpsvc.dll
23:29:04.0589 6240  iphlpsvc - ok
23:29:04.0605 6240  [ 8AAB863E72A4F9C578FED2EE3541545B ] IPMIDRV         C:\WINDOWS\System32\drivers\IPMIDrv.sys
23:29:04.0605 6240  IPMIDRV - ok
23:29:04.0605 6240  [ 7BEC2AF23F586EFF0DB4DBF4331B0C70 ] IPNAT           C:\WINDOWS\system32\drivers\ipnat.sys
23:29:04.0605 6240  IPNAT - ok
23:29:04.0620 6240  [ 35A54F19E703D4FE5919F812F6CC5D0A ] IPT             C:\WINDOWS\System32\drivers\ipt.sys
23:29:04.0620 6240  IPT - ok
23:29:04.0620 6240  [ F6C47021C41F721B628161B64D7DECB9 ] IpxlatCfgSvc    C:\WINDOWS\System32\IpxlatCfg.dll
23:29:04.0620 6240  IpxlatCfgSvc - ok
23:29:04.0636 6240  [ 359CDDBC825959DA28FA886B3C271B53 ] irda            C:\WINDOWS\system32\drivers\irda.sys
23:29:04.0636 6240  irda - ok
23:29:04.0636 6240  [ F88664A2A82DDA456180FFF95A771765 ] IRENUM          C:\WINDOWS\system32\drivers\irenum.sys
23:29:04.0636 6240  IRENUM - ok
23:29:04.0652 6240  [ 4F500A0171606B0E37964694140FCA16 ] irmon           C:\WINDOWS\System32\irmon.dll
23:29:04.0652 6240  irmon - ok
23:29:04.0652 6240  [ 2296B158C43C306B0AC5B4D57EA9F0E1 ] isapnp          C:\WINDOWS\system32\drivers\isapnp.sys
23:29:04.0652 6240  isapnp - ok
23:29:04.0667 6240  [ 2DC0765992CFECE3B13F3BFD20E69DCC ] iScsiPrt        C:\WINDOWS\System32\drivers\msiscsi.sys
23:29:04.0667 6240  iScsiPrt - ok
23:29:04.0667 6240  [ 73A968D4A85BB2552DDCF72CB15F06D2 ] JRAID           C:\WINDOWS\system32\drivers\jraid.sys
23:29:04.0667 6240  JRAID - ok
23:29:04.0683 6240  [ E320F986BBE0CD9324EA0A193EBF29B1 ] kbdclass        C:\WINDOWS\System32\drivers\kbdclass.sys
23:29:04.0683 6240  kbdclass - ok
23:29:04.0683 6240  [ AFF5DDCC1A79217C9526FF5E01A69E89 ] kbdhid          C:\WINDOWS\System32\drivers\kbdhid.sys
23:29:04.0683 6240  kbdhid - ok
23:29:04.0683 6240  [ 916E62AF3386F7A74603E5C545F6FF2D ] kdnic           C:\WINDOWS\System32\drivers\kdnic.sys
23:29:04.0683 6240  kdnic - ok
23:29:04.0698 6240  [ 547E9B25B4407A125D5F187E918BC217 ] keycrypt        C:\WINDOWS\system32\DRIVERS\KeyCrypt64.sys
23:29:04.0698 6240  keycrypt - ok
23:29:04.0698 6240  [ 94E06D509D50807774F35BEE3163E806 ] KeyIso          C:\WINDOWS\system32\lsass.exe
23:29:04.0698 6240  KeyIso - ok
23:29:04.0714 6240  [ FD7D7B7925E5198A4583E8C1D03D861B ] KSecDD          C:\WINDOWS\system32\Drivers\ksecdd.sys
23:29:04.0714 6240  KSecDD - ok
23:29:04.0714 6240  [ C1081E2B36F77781167FD9401119B98E ] KSecPkg         C:\WINDOWS\system32\Drivers\ksecpkg.sys
23:29:04.0714 6240  KSecPkg - ok
23:29:04.0730 6240  [ DD8C4726127CFE313233372D70787C37 ] ksthunk         C:\WINDOWS\system32\drivers\ksthunk.sys
23:29:04.0730 6240  ksthunk - ok
23:29:04.0730 6240  [ 6EAF246BC12DB548AC65A4CEFB14B547 ] KtmRm           C:\WINDOWS\system32\msdtckrm.dll
23:29:04.0745 6240  KtmRm - ok
23:29:04.0745 6240  [ E154D11E1EDAD53DF6A2204F3A604F28 ] LanmanServer    C:\WINDOWS\system32\srvsvc.dll
23:29:04.0745 6240  LanmanServer - ok
23:29:04.0761 6240  [ DBB81AAC130C4CAAB87E519467846A06 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
23:29:04.0761 6240  LanmanWorkstation - ok
23:29:04.0777 6240  [ D81931EF9914A135F9ECF409DC826266 ] lfsvc           C:\WINDOWS\System32\lfsvc.dll
23:29:04.0777 6240  lfsvc - ok
23:29:04.0777 6240  [ F180F46B88044C6F6D3C313A799E5857 ] LicenseManager  C:\WINDOWS\system32\LicenseManagerSvc.dll
23:29:04.0792 6240  LicenseManager - ok
23:29:04.0792 6240  [ CB5A6E117502156794F0DA9E61506006 ] lltdio          C:\WINDOWS\system32\drivers\lltdio.sys
23:29:04.0792 6240  lltdio - ok
23:29:04.0792 6240  [ 48199253D7F6119F88294F8845F0808D ] lltdsvc         C:\WINDOWS\System32\lltdsvc.dll
23:29:04.0808 6240  lltdsvc - ok
23:29:04.0808 6240  [ DCF6F1AA7A51CC08FED089363F83316E ] lmhosts         C:\WINDOWS\System32\lmhsvc.dll
23:29:04.0808 6240  lmhosts - ok
23:29:04.0823 6240  [ 20048BEE892138A745B1C23EBB0E069F ] LSI_SAS         C:\WINDOWS\system32\drivers\lsi_sas.sys
23:29:04.0823 6240  LSI_SAS - ok
23:29:04.0823 6240  [ 9EAB16572B576979D585DDEDB12417CD ] LSI_SAS2i       C:\WINDOWS\system32\drivers\lsi_sas2i.sys
23:29:04.0823 6240  LSI_SAS2i - ok
23:29:04.0839 6240  [ 3B7B359C0870317106DF3438D4FF491D ] LSI_SAS3i       C:\WINDOWS\system32\drivers\lsi_sas3i.sys
23:29:04.0839 6240  LSI_SAS3i - ok
23:29:04.0839 6240  [ 2DE03BA338A4B0ACDB416A30F1C7D56F ] LSI_SSS         C:\WINDOWS\system32\drivers\lsi_sss.sys
23:29:04.0839 6240  LSI_SSS - ok
23:29:04.0855 6240  [ CB538B44AC849D6D3A7D73B32A821DD9 ] LSM             C:\WINDOWS\System32\lsm.dll
23:29:04.0855 6240  LSM - ok
23:29:04.0870 6240  [ 9A497169E145FCE2D8AA7DBC67377F64 ] luafv           C:\WINDOWS\system32\drivers\luafv.sys
23:29:04.0870 6240  luafv - ok
23:29:04.0902 6240  [ 3176B64DAF37A70CD1F6BD57EB3825DE ] MacriumService  C:\Program Files\Macrium\Common\MacriumService.exe
23:29:04.0933 6240  MacriumService - ok
23:29:04.0933 6240  [ 3520DE00ABC5EFF0DBAFD41129AD970F ] MapsBroker      C:\WINDOWS\System32\moshost.dll
23:29:04.0933 6240  MapsBroker - ok
23:29:04.0948 6240  [ BF56CB9D02DEE8CA9CBA50220BE16F15 ] mausbhost       C:\WINDOWS\System32\drivers\mausbhost.sys
23:29:04.0948 6240  mausbhost - ok
23:29:04.0964 6240  [ 01BDEE1FFF6D2216797DFEE4ABD937D9 ] mausbip         C:\WINDOWS\System32\drivers\mausbip.sys
23:29:04.0964 6240  mausbip - ok
23:29:05.0011 6240  [ 164E27CF533B72CB9169E73C0315CA7C ] MB3Service      C:\Program Files\Malwarebytes\Anti-Ransomware\mb3service.exe
23:29:05.0042 6240  MB3Service - ok
23:29:05.0058 6240  [ 94FCA94EE7937EA3ED75F39DE4C8E292 ] MB3SwissArmy    C:\WINDOWS\system32\drivers\MB3SwissArmy.sys
23:29:05.0058 6240  MB3SwissArmy - ok
23:29:05.0058 6240  [ BBCE66F3D1C974A18337D57EA92BB314 ] MbaeSvc         C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
23:29:05.0073 6240  MbaeSvc - ok
23:29:05.0073 6240  [ 67173D816A3D957AC190813D2490F15B ] MBAMFarflt      C:\WINDOWS\system32\DRIVERS\farflt.sys
23:29:05.0073 6240  MBAMFarflt - ok
23:29:05.0073 6240  [ 78488AF2AB2111D67B3C4044707A519B ] MBAMSwissArmy   C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
23:29:05.0089 6240  MBAMSwissArmy - ok
23:29:05.0089 6240  [ C7B8B5053D646CBD30BE1BA6B487D396 ] megasas         C:\WINDOWS\system32\drivers\megasas.sys
23:29:05.0089 6240  megasas - ok
23:29:05.0089 6240  [ EB8ED3204499DDB2D3BA094A4563EE3E ] megasas2i       C:\WINDOWS\system32\drivers\MegaSas2i.sys
23:29:05.0089 6240  megasas2i - ok
23:29:05.0105 6240  [ F1C1D4E752DE1D58295040E5BE8813AF ] megasr          C:\WINDOWS\system32\drivers\megasr.sys
23:29:05.0105 6240  megasr - ok
23:29:05.0120 6240  [ 4965456A1B4B3039E4B9AB233F5E9B1E ] MessagingService C:\WINDOWS\System32\MessagingService.dll
23:29:05.0120 6240  MessagingService - ok
23:29:05.0136 6240  [ 16B078D1089FEA98710C9D07C152DCEE ] mlx4_bus        C:\WINDOWS\System32\drivers\mlx4_bus.sys
23:29:05.0136 6240  mlx4_bus - ok
23:29:05.0136 6240  [ 20C57CE47B1A877C48A4B68E9A4E21FA ] MMCSS           C:\WINDOWS\system32\drivers\mmcss.sys
23:29:05.0136 6240  MMCSS - ok
23:29:05.0152 6240  [ A4467A5C080318F0CCCF5ED463821F8B ] Modem           C:\WINDOWS\system32\drivers\modem.sys
23:29:05.0152 6240  Modem - ok
23:29:05.0152 6240  [ 78BE85C1F1C7F3AF6C87BCE127007D5A ] monitor         C:\WINDOWS\System32\drivers\monitor.sys
23:29:05.0152 6240  monitor - ok
23:29:05.0167 6240  [ 8E262B34A8BD184B4B3025AA8C396B00 ] mouclass        C:\WINDOWS\System32\drivers\mouclass.sys
23:29:05.0167 6240  mouclass - ok
23:29:05.0167 6240  [ C094A555F148495EA130D3BBC5232D5E ] mouhid          C:\WINDOWS\System32\drivers\mouhid.sys
23:29:05.0167 6240  mouhid - ok
23:29:05.0167 6240  [ 6434BC884502E95EEA2379C92DD22B60 ] mountmgr        C:\WINDOWS\system32\drivers\mountmgr.sys
23:29:05.0167 6240  mountmgr - ok
23:29:05.0183 6240  [ 30813D30C0F03BB6D2B584C665C83F25 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
23:29:05.0183 6240  MozillaMaintenance - ok
23:29:05.0183 6240  [ F36E4074C66DD31855A8D79EF0AE8066 ] mpsdrv          C:\WINDOWS\system32\drivers\mpsdrv.sys
23:29:05.0183 6240  mpsdrv - ok
23:29:05.0214 6240  [ A2C216233E8A1CF98315E76EBF69D73D ] MpsSvc          C:\WINDOWS\system32\mpssvc.dll
23:29:05.0214 6240  MpsSvc - ok
23:29:05.0214 6240  [ 7D5F1C98D86698751B3B44426D34BDF1 ] MQAC            C:\WINDOWS\system32\drivers\mqac.sys
23:29:05.0214 6240  MQAC - ok
23:29:05.0230 6240  [ 215D672CB71987CD98EB2298EFB84DDC ] MRxDAV          C:\WINDOWS\system32\drivers\mrxdav.sys
23:29:05.0230 6240  MRxDAV - ok
23:29:05.0245 6240  [ 6FC2E733C7172B6BFAD383B108E56F92 ] mrxsmb          C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
23:29:05.0245 6240  mrxsmb - ok
23:29:05.0245 6240  [ 6537678DEEA2A5B079052D75E21E46DA ] mrxsmb10        C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys
23:29:05.0261 6240  mrxsmb10 - ok
23:29:05.0261 6240  [ 67361BDD0329A545670E6A90652FE347 ] mrxsmb20        C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
23:29:05.0261 6240  mrxsmb20 - ok
23:29:05.0277 6240  [ 167408B38458ECAE545C57527BC99024 ] MsBridge        C:\WINDOWS\system32\drivers\bridge.sys
23:29:05.0277 6240  MsBridge - ok
23:29:05.0277 6240  [ D5778559A0F34EE0BF0457293C6B5F4F ] MSDTC           C:\WINDOWS\System32\msdtc.exe
23:29:05.0277 6240  MSDTC - ok
23:29:05.0292 6240  [ AE111778CA6AC08862B3C713F0413333 ] Msfs            C:\WINDOWS\system32\drivers\Msfs.sys
23:29:05.0292 6240  Msfs - ok
23:29:05.0292 6240  [ 6DDDFCAB646BBBCFC583135C4430E10F ] msgpiowin32     C:\WINDOWS\System32\drivers\msgpiowin32.sys
23:29:05.0292 6240  msgpiowin32 - ok
23:29:05.0308 6240  [ 01C6A86BEA8279E557A5056148F068BF ] mshidkmdf       C:\WINDOWS\System32\drivers\mshidkmdf.sys
23:29:05.0308 6240  mshidkmdf - ok
23:29:05.0308 6240  [ F65ABC7DE945047147F17330F79732CB ] mshidumdf       C:\WINDOWS\System32\drivers\mshidumdf.sys
23:29:05.0308 6240  mshidumdf - ok
23:29:05.0323 6240  [ 05B23012427801E710BDD12720B9020B ] msisadrv        C:\WINDOWS\system32\drivers\msisadrv.sys
23:29:05.0323 6240  msisadrv - ok
23:29:05.0323 6240  [ 21B88DF67507BD4DFF8A5487074BB31F ] MSiSCSI         C:\WINDOWS\system32\iscsiexe.dll
23:29:05.0323 6240  MSiSCSI - ok
23:29:05.0339 6240  msiserver - ok
23:29:05.0339 6240  [ B25B2CD3E052D68075A3814AAA0C6421 ] MSKSSRV         C:\WINDOWS\System32\drivers\MSKSSRV.sys
23:29:05.0339 6240  MSKSSRV - ok
23:29:05.0355 6240  [ C3F5EA6B9041A30B4F11BE2E7863E487 ] MsLldp          C:\WINDOWS\system32\drivers\mslldp.sys
23:29:05.0355 6240  MsLldp - ok
23:29:05.0355 6240  [ 6F1422468DF5B12D87EF1B7956429721 ] MSMQ            C:\WINDOWS\system32\mqsvc.exe
23:29:05.0355 6240  MSMQ - ok
23:29:05.0355 6240  [ 601D666820F0408B896791D19BE6D258 ] MSPCLOCK        C:\WINDOWS\System32\drivers\MSPCLOCK.sys
23:29:05.0355 6240  MSPCLOCK - ok
23:29:05.0370 6240  [ 46E61FBA0097E48E5628C74A3F72233A ] MSPQM           C:\WINDOWS\System32\drivers\MSPQM.sys
23:29:05.0370 6240  MSPQM - ok
23:29:05.0370 6240  [ 4EB9B77179BDEE89C496E60D4BF85CC1 ] MsRPC           C:\WINDOWS\system32\drivers\MsRPC.sys
23:29:05.0386 6240  MsRPC - ok
23:29:05.0386 6240  [ CBD56E0B55FB3672BA80382EC2F8835C ] mssmbios        C:\WINDOWS\System32\drivers\mssmbios.sys
23:29:05.0386 6240  mssmbios - ok
23:29:05.0402 6240  [ 5734B2A36D3BB13A638E5305EEEC582D ] MSTEE           C:\WINDOWS\System32\drivers\MSTEE.sys
23:29:05.0402 6240  MSTEE - ok
23:29:05.0402 6240  [ 85270E0DC6907C6B99F72A36F17AED34 ] MTConfig        C:\WINDOWS\System32\drivers\MTConfig.sys
23:29:05.0402 6240  MTConfig - ok
23:29:05.0402 6240  [ DB5B1539F5EBB3DD3A7ED25ADBC4D6D9 ] Mup             C:\WINDOWS\system32\Drivers\mup.sys
23:29:05.0402 6240  Mup - ok
23:29:05.0417 6240  [ 3C57FF3BCF496D24C39C2198158864BB ] mvumis          C:\WINDOWS\system32\drivers\mvumis.sys
23:29:05.0417 6240  mvumis - ok
23:29:05.0433 6240  [ 4D3B95406A0F80E4A94ACC9B33477887 ] NativeWifiP     C:\WINDOWS\system32\DRIVERS\nwifi.sys
23:29:05.0433 6240  NativeWifiP - ok
23:29:05.0448 6240  [ 05ABAE6A2165B434A33043264E81F4DF ] NaturalAuthentication C:\WINDOWS\System32\NaturalAuth.dll
23:29:05.0448 6240  NaturalAuthentication - ok
23:29:05.0464 6240  [ FBA9F5B9F59A665F248F70B905EDCE14 ] NcaSvc          C:\WINDOWS\System32\ncasvc.dll
23:29:05.0464 6240  NcaSvc - ok
23:29:05.0464 6240  [ 1A75CBB2C8161676CEA17E6FFE441FE7 ] NcbService      C:\WINDOWS\System32\ncbservice.dll
23:29:05.0480 6240  NcbService - ok
23:29:05.0480 6240  [ 3C7E074AE41D8DFB41A9E65904D8BF43 ] NcdAutoSetup    C:\WINDOWS\System32\NcdAutoSetup.dll
23:29:05.0480 6240  NcdAutoSetup - ok
23:29:05.0495 6240  [ 77B047B109CE758A017F58FAE5038D0D ] ndfltr          C:\WINDOWS\System32\drivers\ndfltr.sys
23:29:05.0495 6240  ndfltr - ok
23:29:05.0511 6240  [ 9D46AAE948FF894FE979E518E2FC1532 ] NDIS            C:\WINDOWS\system32\drivers\ndis.sys
23:29:05.0511 6240  NDIS - ok
23:29:05.0527 6240  [ 067AE5BA349CC35AF8975D22DC483DDF ] NdisCap         C:\WINDOWS\system32\drivers\ndiscap.sys
23:29:05.0527 6240  NdisCap - ok
23:29:05.0527 6240  [ 6FC4D7EB5D38CFB7966405036116F065 ] NdisImPlatform  C:\WINDOWS\system32\drivers\NdisImPlatform.sys
23:29:05.0527 6240  NdisImPlatform - ok
23:29:05.0542 6240  [ ED7CC4E16B76B2603C9F827188EA63B4 ] NdisTapi        C:\WINDOWS\system32\DRIVERS\ndistapi.sys
23:29:05.0542 6240  NdisTapi - ok
23:29:05.0542 6240  [ 8D977AFC195A3F4B15B05D02B2BD0292 ] Ndisuio         C:\WINDOWS\system32\drivers\ndisuio.sys
23:29:05.0542 6240  Ndisuio - ok
23:29:05.0558 6240  [ DC1D26D62F40B7552BCF49D92774F0C5 ] NdisVirtualBus  C:\WINDOWS\System32\drivers\NdisVirtualBus.sys
23:29:05.0558 6240  NdisVirtualBus - ok
23:29:05.0558 6240  [ 66F56AC744101DB870934D0EB31C2426 ] NdisWan         C:\WINDOWS\System32\drivers\ndiswan.sys
23:29:05.0558 6240  NdisWan - ok
23:29:05.0573 6240  [ 66F56AC744101DB870934D0EB31C2426 ] ndiswanlegacy   C:\WINDOWS\system32\DRIVERS\ndiswan.sys
23:29:05.0573 6240  ndiswanlegacy - ok
23:29:05.0573 6240  [ AC908EF74DB5BC1DC7FB2BF0205D4FF1 ] ndproxy         C:\WINDOWS\system32\DRIVERS\NDProxy.sys
23:29:05.0589 6240  ndproxy - ok
23:29:05.0589 6240  [ A791792DC412CCD83DA0AF6871682552 ] Ndu             C:\WINDOWS\system32\drivers\Ndu.sys
23:29:05.0589 6240  Ndu - ok
23:29:05.0605 6240  [ BE79982A50AC88BC0765F3AFECFCB596 ] NetAdapterCx    C:\WINDOWS\system32\drivers\NetAdapterCx.sys
23:29:05.0605 6240  NetAdapterCx - ok
23:29:05.0605 6240  [ AAC1622CA213F7DA660A04FD51B730C3 ] NetBIOS         C:\WINDOWS\system32\drivers\netbios.sys
23:29:05.0605 6240  NetBIOS - ok
23:29:05.0620 6240  [ 401C17200AA0433D94EA61695F111DC3 ] NetBT           C:\WINDOWS\system32\DRIVERS\netbt.sys
23:29:05.0620 6240  NetBT - ok
23:29:05.0636 6240  [ 94E06D509D50807774F35BEE3163E806 ] Netlogon        C:\WINDOWS\system32\lsass.exe
23:29:05.0636 6240  Netlogon - ok
23:29:05.0636 6240  [ 94BC40F88309B0B7DFE68B2C2BB15EB6 ] Netman          C:\WINDOWS\System32\netman.dll
23:29:05.0652 6240  Netman - ok
23:29:05.0652 6240  [ 97FF2186BBAA215727300404862D297B ] NetMsmqActivator C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
23:29:05.0652 6240  NetMsmqActivator - ok
23:29:05.0667 6240  [ 97FF2186BBAA215727300404862D297B ] NetPipeActivator C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
23:29:05.0667 6240  NetPipeActivator - ok
23:29:05.0667 6240  [ 79ED54CA41486399361778D533E55A99 ] netprofm        C:\WINDOWS\System32\netprofmsvc.dll
23:29:05.0683 6240  netprofm - ok
23:29:05.0683 6240  [ 2D63501E7273F5B730958B5061E609D4 ] NetSetupSvc     C:\WINDOWS\System32\NetSetupSvc.dll
23:29:05.0698 6240  NetSetupSvc - ok
23:29:05.0698 6240  [ 97FF2186BBAA215727300404862D297B ] NetTcpActivator C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
23:29:05.0698 6240  NetTcpActivator - ok
23:29:05.0698 6240  [ 97FF2186BBAA215727300404862D297B ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
23:29:05.0698 6240  NetTcpPortSharing - ok
23:29:05.0714 6240  [ FD1DA80FF495D4B928A65F40FCCCF387 ] netvsc          C:\WINDOWS\System32\drivers\netvsc.sys
23:29:05.0714 6240  netvsc - ok
23:29:05.0730 6240  [ E27ACE78CA1BDF4FBBF3323D6E9AFCDB ] NgcCtnrSvc      C:\WINDOWS\System32\NgcCtnrSvc.dll
23:29:05.0730 6240  NgcCtnrSvc - ok
23:29:05.0745 6240  [ A557C92583E81CA97D2C0F2467E7C2F9 ] NgcSvc          C:\WINDOWS\system32\ngcsvc.dll
23:29:05.0761 6240  NgcSvc - ok
23:29:05.0777 6240  [ 622C7AA8D98331DAA75526A5E643FFD8 ] NlaSvc          C:\WINDOWS\System32\nlasvc.dll
23:29:05.0777 6240  NlaSvc - ok
23:29:05.0777 6240  [ 84EB8F01B140618518AFF30B9951F132 ] Npfs            C:\WINDOWS\system32\drivers\Npfs.sys
23:29:05.0777 6240  Npfs - ok
23:29:05.0792 6240  [ 5CB8082E51DE7D19042F0FF8C517CB0D ] npsvctrig       C:\WINDOWS\System32\drivers\npsvctrig.sys
23:29:05.0792 6240  npsvctrig - ok
23:29:05.0792 6240  [ 3BA4E9585E9D7D7E6E68A18184DDDBF2 ] nsi             C:\WINDOWS\system32\nsisvc.dll
23:29:05.0792 6240  nsi - ok
23:29:05.0808 6240  [ 958921BB7AE2671983743FDA0DD587C4 ] nsiproxy        C:\WINDOWS\system32\drivers\nsiproxy.sys
23:29:05.0808 6240  nsiproxy - ok
23:29:05.0839 6240  [ 4738811FFC33F2AC222FB2B82C14BECF ] NTFS            C:\WINDOWS\system32\drivers\NTFS.sys
23:29:05.0839 6240  NTFS - ok
23:29:05.0855 6240  [ 0D1E03A5F87F4DE04D97622C686910A2 ] Null            C:\WINDOWS\system32\drivers\Null.sys
23:29:05.0855 6240  Null - ok
23:29:05.0870 6240  [ 532F27A2B62D70C327E763F035AED6C1 ] nvdimmn         C:\WINDOWS\System32\drivers\nvdimmn.sys
23:29:05.0870 6240  nvdimmn - ok
23:29:05.0886 6240  [ 6DD0B2337F74336EB1F83C3866538F9B ] NVHDA           C:\WINDOWS\system32\drivers\nvhda64v.sys
23:29:05.0886 6240  NVHDA - ok
23:29:06.0058 6240  [ AD43497946938DB4C9462AE257F0E96A ] nvlddmkm        C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_c791f781cd94491f\nvlddmkm.sys
23:29:06.0136 6240  nvlddmkm - ok
23:29:06.0152 6240  [ 7E04652EB1A476BC0A72ECDC613AF0C5 ] nvraid          C:\WINDOWS\system32\drivers\nvraid.sys
23:29:06.0152 6240  nvraid - ok
23:29:06.0167 6240  [ 880B3E874914DAEF97119876543AE117 ] nvstor          C:\WINDOWS\system32\drivers\nvstor.sys
23:29:06.0167 6240  nvstor - ok
23:29:06.0167 6240  [ 76C6E6CCA51F4AF28F5C40EFE740C8F6 ] NvStreamKms     C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
23:29:06.0167 6240  NvStreamKms - ok
23:29:06.0183 6240  [ 2719BB9316C497344DD7DB688B6E5F7D ] NvTelemetryContainer C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
23:29:06.0183 6240  NvTelemetryContainer - ok
23:29:06.0198 6240  [ E502016A185B5BB9DC341873F82CD49C ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
23:29:06.0198 6240  nvvad_WaveExtensible - ok
23:29:06.0198 6240  [ 0E171374583E0A9AB76245CF1673EEEF ] nvvhci          C:\WINDOWS\System32\drivers\nvvhci.sys
23:29:06.0198 6240  nvvhci - ok
23:29:06.0214 6240  [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv          C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
23:29:06.0214 6240  odserv - ok
23:29:06.0230 6240  [ 51F93600272C855ADFE209473E9B95EE ] OneSyncSvc      C:\WINDOWS\System32\APHostService.dll
23:29:06.0230 6240  OneSyncSvc - ok
23:29:06.0245 6240  [ F40104B18DBE36381C662F73DEC3B351 ] Origin Client Service C:\Program Files (x86)\Origin\OriginClientService.exe
23:29:06.0261 6240  Origin Client Service - ok
23:29:06.0298 6240  [ F08F4D90861E3E31FFEE28427B8D13CA ] Origin Web Helper Service C:\Program Files (x86)\Origin\OriginWebHelperService.exe
23:29:06.0313 6240  Origin Web Helper Service - ok
23:29:06.0313 6240  [ 5A432A042DAE460ABE7199B758E8606C ] ose             C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
23:29:06.0329 6240  ose - ok
23:29:06.0345 6240  [ EDD1DCD36F6115ACC6935C3F88FF54D7 ] P17             C:\WINDOWS\system32\drivers\P17.sys
23:29:06.0345 6240  P17 - ok
23:29:06.0360 6240  [ 11404911B5ADC7A2DC58021DF0490AA6 ] p2pimsvc        C:\WINDOWS\system32\pnrpsvc.dll
23:29:06.0360 6240  p2pimsvc - ok
23:29:06.0376 6240  [ B7E60F11B397C58CCC4E815301A97352 ] p2psvc          C:\WINDOWS\system32\p2psvc.dll
23:29:06.0376 6240  p2psvc - ok
23:29:06.0391 6240  PAExec - ok
23:29:06.0391 6240  [ 2E07EC2C1622F5E7B535D62DCD61F3AB ] Parport         C:\WINDOWS\System32\drivers\parport.sys
23:29:06.0391 6240  Parport - ok
23:29:06.0407 6240  [ 269884AAC55AE567A0A955703C62CA29 ] partmgr         C:\WINDOWS\system32\drivers\partmgr.sys
23:29:06.0407 6240  partmgr - ok
23:29:06.0423 6240  [ 463BB1CE5C1A4F2E58EF7986213F4F74 ] PcaSvc          C:\WINDOWS\System32\pcasvc.dll
23:29:06.0423 6240  PcaSvc - ok
23:29:06.0438 6240  [ 5B329AD314E26B77DF4B603B8E65CA60 ] pci             C:\WINDOWS\system32\drivers\pci.sys
23:29:06.0438 6240  pci - ok
23:29:06.0438 6240  [ E5AF806815ED797086629741F29E4156 ] pciide          C:\WINDOWS\system32\drivers\pciide.sys
23:29:06.0438 6240  pciide - ok
23:29:06.0454 6240  [ 2A631D447B988AFBE847CBAA8E5CC298 ] pcmcia          C:\WINDOWS\system32\drivers\pcmcia.sys
23:29:06.0454 6240  pcmcia - ok
23:29:06.0454 6240  [ ACD510CF2B631A2D36B2CFB7D31E22FD ] pcw             C:\WINDOWS\system32\drivers\pcw.sys
23:29:06.0454 6240  pcw - ok
23:29:06.0470 6240  [ 1796112EB89559910BC18865A29C8894 ] pdc             C:\WINDOWS\system32\drivers\pdc.sys
23:29:06.0470 6240  pdc - ok
23:29:06.0485 6240  [ F21127EDE5D72090A1B029AFF4AFFD17 ] PEAUTH          C:\WINDOWS\system32\drivers\peauth.sys
23:29:06.0485 6240  PEAUTH - ok
23:29:06.0485 6240  [ 35FD028E4323018202C0B7D115FD3AEF ] percsas2i       C:\WINDOWS\system32\drivers\percsas2i.sys
23:29:06.0485 6240  percsas2i - ok
23:29:06.0501 6240  [ F9F3D8BE9BC9241CC726197261362AC4 ] percsas3i       C:\WINDOWS\system32\drivers\percsas3i.sys
23:29:06.0501 6240  percsas3i - ok
23:29:06.0516 6240  [ EA780FAE0D6796D56D0CAF39360BF7C0 ] PerfHost        C:\WINDOWS\SysWow64\perfhost.exe
23:29:06.0532 6240  PerfHost - ok
23:29:06.0548 6240  [ 28658894160747DB9B8C6A9E45EEE47C ] PhoneSvc        C:\WINDOWS\System32\PhoneService.dll
23:29:06.0563 6240  PhoneSvc - ok
23:29:06.0563 6240  [ 615FE5145C718A4072D42B1A761DCA9F ] PimIndexMaintenanceSvc C:\WINDOWS\System32\PimIndexMaintenance.dll
23:29:06.0563 6240  PimIndexMaintenanceSvc - ok
23:29:06.0595 6240  [ 73B5A132EBF3A8075A7C68DFBB4DE719 ] pla             C:\WINDOWS\system32\pla.dll
23:29:06.0595 6240  pla - ok
23:29:06.0610 6240  [ 64A80A746FC460126FA4124AA2D93848 ] PlugPlay        C:\WINDOWS\system32\umpnpmgr.dll
23:29:06.0610 6240  PlugPlay - ok
23:29:06.0610 6240  [ 36D43EA5517F3F4AAAC8EE061C957EF1 ] pmem            C:\WINDOWS\System32\drivers\pmem.sys
23:29:06.0610 6240  pmem - ok
23:29:06.0626 6240  [ 59048555B59FD69287CFAB6022B5CC86 ] PNPMEM          C:\WINDOWS\System32\drivers\pnpmem.sys
23:29:06.0626 6240  PNPMEM - ok
23:29:06.0626 6240  [ 7815D5EEE3624640150B1365EB2E98C5 ] PNRPAutoReg     C:\WINDOWS\system32\pnrpauto.dll
23:29:06.0626 6240  PNRPAutoReg - ok
23:29:06.0641 6240  [ 11404911B5ADC7A2DC58021DF0490AA6 ] PNRPsvc         C:\WINDOWS\system32\pnrpsvc.dll
23:29:06.0641 6240  PNRPsvc - ok
23:29:06.0657 6240  [ E1BCA08929D806A087D90BC11C6020E8 ] PolicyAgent     C:\WINDOWS\System32\ipsecsvc.dll
23:29:06.0657 6240  PolicyAgent - ok
23:29:06.0673 6240  [ CECF1795361F76CB0F492404EC0906DB ] Power           C:\WINDOWS\system32\umpo.dll
23:29:06.0673 6240  Power - ok
23:29:06.0688 6240  [ C6010D36B68FB534D1B1245978C9921D ] PptpMiniport    C:\WINDOWS\System32\drivers\raspptp.sys
23:29:06.0688 6240  PptpMiniport - ok
23:29:06.0720 6240  [ 7CD1D9EE59F49FBD3E72876F19038BE0 ] PrintNotify     C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
23:29:06.0735 6240  PrintNotify - ok
23:29:06.0751 6240  [ 8803D4F36F1CB2E2203F5EB59571E89C ] PrintWorkflowUserSvc C:\WINDOWS\System32\PrintWorkflowService.dll
23:29:06.0751 6240  PrintWorkflowUserSvc - ok
23:29:06.0766 6240  [ B1111C47F128C946BDC87A18E44007EB ] Processor       C:\WINDOWS\System32\drivers\processr.sys
23:29:06.0766 6240  Processor - ok
23:29:06.0766 6240  [ A2CA8830BF77FAB39D6E5C45A404FB78 ] ProfSvc         C:\WINDOWS\system32\profsvc.dll
23:29:06.0782 6240  ProfSvc - ok
23:29:06.0782 6240  [ 5818FE76C3C6AE0CA723EBE483BF447F ] Psched          C:\WINDOWS\system32\drivers\pacer.sys
23:29:06.0782 6240  Psched - ok
23:29:06.0798 6240  [ 22E39E05518664028AF16CA45ADB10D6 ] PushToInstall   C:\WINDOWS\system32\PushToInstall.dll
23:29:06.0798 6240  PushToInstall - ok
23:29:06.0798 6240  [ C32ECB99AD25E9A04F01C8665DF29EF8 ] pwdrvio         C:\WINDOWS\system32\pwdrvio.sys
23:29:06.0813 6240  pwdrvio - ok
23:29:06.0813 6240  [ D619356B955EEFA642F5FF72755E8B3C ] pwdspio         C:\Windows\system32\pwdspio.sys
23:29:06.0813 6240  pwdspio - ok
23:29:06.0829 6240  [ 034BA34ADFA10F9D7E4989273DDABA33 ] QWAVE           C:\WINDOWS\system32\qwave.dll
23:29:06.0829 6240  QWAVE - ok
23:29:06.0829 6240  [ 16F9A6B593B52EB18F7ECB9D251BDF7A ] QWAVEdrv        C:\WINDOWS\system32\drivers\qwavedrv.sys
23:29:06.0845 6240  QWAVEdrv - ok
23:29:06.0845 6240  [ 13600C467512147E99052806F2C1307A ] Ramdisk         C:\WINDOWS\system32\DRIVERS\ramdisk.sys
23:29:06.0845 6240  Ramdisk - ok
23:29:06.0845 6240  [ F57D1DE0C9522BCD590A69D044641B5A ] RasAcd          C:\WINDOWS\system32\DRIVERS\rasacd.sys
23:29:06.0860 6240  RasAcd - ok
23:29:06.0860 6240  [ ED0EE10911C16AD8B21B9003C90E968F ] RasAgileVpn     C:\WINDOWS\System32\drivers\AgileVpn.sys
23:29:06.0860 6240  RasAgileVpn - ok
23:29:06.0876 6240  [ 66BA91D8A16B057A521111B2A8BDCC14 ] RasAuto         C:\WINDOWS\System32\rasauto.dll
23:29:06.0876 6240  RasAuto - ok
23:29:06.0876 6240  [ E0220BB6580D34001D4D1D133052DAA4 ] Rasl2tp         C:\WINDOWS\System32\drivers\rasl2tp.sys
23:29:06.0876 6240  Rasl2tp - ok
23:29:06.0891 6240  [ 0F8FB189206C1A53FB73FCF8F335A412 ] RasMan          C:\WINDOWS\System32\rasmans.dll
23:29:06.0907 6240  RasMan - ok
23:29:06.0907 6240  [ 12EE1D92F4E5FAE4B6F65195A2016CE5 ] RasPppoe        C:\WINDOWS\system32\DRIVERS\raspppoe.sys
23:29:06.0907 6240  RasPppoe - ok
23:29:06.0923 6240  [ 91CE469015979E5B3C3DBC2C41A476E8 ] RasSstp         C:\WINDOWS\System32\drivers\rassstp.sys
23:29:06.0923 6240  RasSstp - ok
23:29:06.0923 6240  [ 1B5433EF79752387EBA5AD568AA8B18D ] rdbss           C:\WINDOWS\system32\DRIVERS\rdbss.sys
23:29:06.0938 6240  rdbss - ok
23:29:06.0938 6240  [ 8A5285B38A203D15110E142DE68406DD ] rdpbus          C:\WINDOWS\System32\drivers\rdpbus.sys
23:29:06.0938 6240  rdpbus - ok
23:29:06.0954 6240  [ DF83769C92527DB50653F8FB57D001FF ] RDPDR           C:\WINDOWS\system32\drivers\rdpdr.sys
23:29:06.0954 6240  RDPDR - ok
23:29:06.0970 6240  [ 4D1A63ACEC42A88E52AFC4E84A8CE9EE ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
23:29:06.0970 6240  RdpVideoMiniport - ok
23:29:06.0970 6240  [ 12AF835862F2B6B2FB9DEA8BA2288587 ] rdyboost        C:\WINDOWS\system32\drivers\rdyboost.sys
23:29:06.0970 6240  rdyboost - ok
23:29:07.0001 6240  [ FB0577F6BC9E07549CEACF5224327499 ] ReFS            C:\WINDOWS\system32\drivers\ReFS.sys
23:29:07.0016 6240  ReFS - ok
23:29:07.0032 6240  [ 4136BCA61BCDCC79DCE145F9CB639CD6 ] ReFSv1          C:\WINDOWS\system32\drivers\ReFSv1.sys
23:29:07.0032 6240  ReFSv1 - ok
23:29:07.0048 6240  [ 16884710EB4898CB49B18609EEE34C6C ] RemoteAccess    C:\WINDOWS\System32\mprdim.dll
23:29:07.0048 6240  RemoteAccess - ok
23:29:07.0048 6240  [ 9D82CD53B622A85A10B4DA8F4724A8E4 ] RemoteRegistry  C:\WINDOWS\system32\regsvc.dll
23:29:07.0063 6240  RemoteRegistry - ok
23:29:07.0063 6240  [ 24C716C6A5AA3BEC3180BB15050C75C5 ] RetailDemo      C:\WINDOWS\system32\RDXService.dll
23:29:07.0079 6240  RetailDemo - ok
23:29:07.0079 6240  [ BBC228CA2F96B784B01FE7F1C5E3CFBB ] rhproxy         C:\WINDOWS\System32\drivers\rhproxy.sys
23:29:07.0079 6240  rhproxy - ok
23:29:07.0095 6240  [ 665A51DE515A2E8B0BDB3D6917D47DD9 ] RmSvc           C:\WINDOWS\System32\RMapi.dll
23:29:07.0095 6240  RmSvc - ok
23:29:07.0095 6240  [ D0F6698E56F0157EA72F2D754C6FD555 ] RpcEptMapper    C:\WINDOWS\System32\RpcEpMap.dll
23:29:07.0110 6240  RpcEptMapper - ok
23:29:07.0110 6240  [ EB65907BD63871669C54D5E5BAE4DD34 ] RpcLocator      C:\WINDOWS\system32\locator.exe
23:29:07.0110 6240  RpcLocator - ok
23:29:07.0126 6240  [ 79BDBB684629A526CCD958F06B9D6FAD ] RpcSs           C:\WINDOWS\system32\rpcss.dll
23:29:07.0141 6240  RpcSs - ok
23:29:07.0141 6240  [ 27B80E5766B114621980F82FB78E912A ] rspndr          C:\WINDOWS\system32\drivers\rspndr.sys
23:29:07.0141 6240  rspndr - ok
23:29:07.0157 6240  [ AB7C0639DF052528C2CB06D0EAE115EC ] rt640x64        C:\WINDOWS\System32\drivers\rt640x64.sys
23:29:07.0157 6240  rt640x64 - ok
23:29:07.0173 6240  [ F0FA6B67B16EEFDEF8E8AFAD47A4F9B8 ] s3cap           C:\WINDOWS\System32\drivers\vms3cap.sys
23:29:07.0173 6240  s3cap - ok
23:29:07.0173 6240  [ 94E06D509D50807774F35BEE3163E806 ] SamSs           C:\WINDOWS\system32\lsass.exe
23:29:07.0173 6240  SamSs - ok
23:29:07.0188 6240  [ 62220FB14D0AD7E97F61D6DC324C506F ] SamsungRapidDiskFltr C:\WINDOWS\system32\DRIVERS\SamsungRapidDiskFltr.sys
23:29:07.0188 6240  SamsungRapidDiskFltr - ok
23:29:07.0204 6240  [ 80E49A2AEA9C93477DE31F68E61655EC ] SamsungRapidFSFltr C:\WINDOWS\system32\DRIVERS\SamsungRapidFSFltr.sys
23:29:07.0204 6240  SamsungRapidFSFltr - ok
23:29:07.0204 6240  [ 8A71E4880D80CAE78C43AAB272C90500 ] SamsungRapidSvc C:\WINDOWS\system32\RAPID\SamsungRapidSvc.exe
23:29:07.0204 6240  SamsungRapidSvc - ok
23:29:07.0220 6240  [ 3289766038DB2CB14D07DC84392138D5 ] SASDIFSV        C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
23:29:07.0220 6240  SASDIFSV - ok
23:29:07.0220 6240  [ 58A38E75F3316A83C23DF6173D41F2B5 ] SASKUTIL        C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
23:29:07.0220 6240  SASKUTIL - ok
23:29:07.0235 6240  [ 324FA3C337EB54B43448F7B08444DC8D ] sbp2port        C:\WINDOWS\system32\drivers\sbp2port.sys
23:29:07.0235 6240  sbp2port - ok
23:29:07.0251 6240  [ CB56F3AD0499A2FFAD9BFEF20863ED44 ] SCardSvr        C:\WINDOWS\System32\SCardSvr.dll
23:29:07.0251 6240  SCardSvr - ok
23:29:07.0251 6240  [ 5CB8816960FE5C608F75607F34530BBB ] ScDeviceEnum    C:\WINDOWS\System32\ScDeviceEnum.dll
23:29:07.0266 6240  ScDeviceEnum - ok
23:29:07.0266 6240  [ 62A33CE69DB508BCEC63F4D3BFF400CE ] scfilter        C:\WINDOWS\system32\DRIVERS\scfilter.sys
23:29:07.0266 6240  scfilter - ok
23:29:07.0282 6240  [ 8A9F94596FFC128784B734CA314F2DAA ] Schedule        C:\WINDOWS\system32\schedsvc.dll
23:29:07.0282 6240  Schedule - ok
23:29:07.0298 6240  [ 7B057373146CC4E5A1F1DA665EA55DC7 ] scmbus          C:\WINDOWS\system32\drivers\scmbus.sys
23:29:07.0298 6240  scmbus - ok
23:29:07.0313 6240  [ 200A5398C0E7E78DBDF6C0D9E811F366 ] SCPolicySvc     C:\WINDOWS\System32\certprop.dll
23:29:07.0313 6240  SCPolicySvc - ok
23:29:07.0313 6240  [ 07487301FE9DB115FBE3B00132C483CA ] sdbus           C:\WINDOWS\System32\drivers\sdbus.sys
23:29:07.0313 6240  sdbus - ok
23:29:07.0329 6240  [ 6D3853838864886B4F10B074282772E0 ] SDFRd           C:\WINDOWS\System32\drivers\SDFRd.sys
23:29:07.0329 6240  SDFRd - ok
23:29:07.0329 6240  [ 368180051766E4289E3D47AF21F2668C ] SDRSVC          C:\WINDOWS\System32\SDRSVC.dll
23:29:07.0345 6240  SDRSVC - ok
23:29:07.0345 6240  [ C289832A3174DC9D393C7603C511DF79 ] sdstor          C:\WINDOWS\System32\drivers\sdstor.sys
23:29:07.0345 6240  sdstor - ok
23:29:07.0360 6240  [ 0356C85312D78F4C7F33C74B6000BB93 ] seclogon        C:\WINDOWS\system32\seclogon.dll
23:29:07.0360 6240  seclogon - ok
23:29:07.0360 6240  [ FCAF34447DB59EF1330EA576D16C54CC ] SecurityHealthService C:\WINDOWS\system32\SecurityHealthService.exe
23:29:07.0376 6240  SecurityHealthService - ok
23:29:07.0391 6240  [ FE3E7B59BBEDDDC449C86B693BE63542 ] SEMgrSvc        C:\WINDOWS\system32\SEMgrSvc.dll
23:29:07.0407 6240  SEMgrSvc - ok
23:29:07.0407 6240  [ 62EDAD383010E037C4D3846C7C021A00 ] SENS            C:\WINDOWS\System32\sens.dll
23:29:07.0407 6240  SENS - ok
23:29:07.0423 6240  [ DDBBE9A08C79D3BB50D6053507F7777D ] SensorDataService C:\WINDOWS\System32\SensorDataService.exe
23:29:07.0438 6240  SensorDataService - ok
23:29:07.0454 6240  [ AF51D8E33E08BD898D439CF31158F989 ] SensorService   C:\WINDOWS\system32\SensorService.dll
23:29:07.0454 6240  SensorService - ok
23:29:07.0470 6240  [ 25B028799D43FE6324CC9E79B31E6ACD ] SensrSvc        C:\WINDOWS\system32\sensrsvc.dll
23:29:07.0470 6240  SensrSvc - ok
23:29:07.0470 6240  [ 75A27472AFD009255DBDE52038E3BDB5 ] SerCx           C:\WINDOWS\system32\drivers\SerCx.sys
23:29:07.0470 6240  SerCx - ok
23:29:07.0485 6240  [ 84005F54308109A022413D628E966412 ] SerCx2          C:\WINDOWS\system32\drivers\SerCx2.sys
23:29:07.0485 6240  SerCx2 - ok
23:29:07.0485 6240  [ 40384793F74CFFA45BCC38DF65E978EC ] Serenum         C:\WINDOWS\System32\drivers\serenum.sys
23:29:07.0485 6240  Serenum - ok
23:29:07.0501 6240  [ 699470AD24D67908991A777716A352FD ] Serial          C:\WINDOWS\System32\drivers\serial.sys
23:29:07.0501 6240  Serial - ok
23:29:07.0501 6240  [ 92453F065F52A8EF0328A926B2C9502F ] sermouse        C:\WINDOWS\System32\drivers\sermouse.sys
23:29:07.0501 6240  sermouse - ok
23:29:07.0532 6240  [ 8958262EA3A871D45B14B7BA00F795C1 ] SessionEnv      C:\WINDOWS\system32\sessenv.dll
23:29:07.0532 6240  SessionEnv - ok
23:29:07.0548 6240  [ 1D8920C40F19B5FBA5F4897779840AD1 ] sfloppy         C:\WINDOWS\System32\drivers\sfloppy.sys
23:29:07.0548 6240  sfloppy - ok
23:29:07.0563 6240  [ B08841DD1EF979C5C6F9A7F101BA3D9C ] SharedAccess    C:\WINDOWS\System32\ipnathlp.dll
23:29:07.0563 6240  SharedAccess - ok
23:29:07.0579 6240  [ 63377493508564288721EF5421A216F5 ] SharedRealitySvc C:\WINDOWS\System32\SharedRealitySvc.dll
23:29:07.0579 6240  SharedRealitySvc - ok
23:29:07.0595 6240  [ 887458A234108B5B69038299BE7FAD88 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
23:29:07.0595 6240  ShellHWDetection - ok
23:29:07.0610 6240  [ 5ED18BE9FE76540A0596BB41C91719C6 ] shpamsvc        C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll
23:29:07.0610 6240  shpamsvc - ok
23:29:07.0626 6240  [ A871F9CC9CF388DC7193D22EF8D8C8DF ] SiSRaid2        C:\WINDOWS\system32\drivers\SiSRaid2.sys
23:29:07.0626 6240  SiSRaid2 - ok
23:29:07.0626 6240  [ D30FC341550CC364880950152AE8B1C5 ] SiSRaid4        C:\WINDOWS\system32\drivers\sisraid4.sys
23:29:07.0626 6240  SiSRaid4 - ok
23:29:07.0641 6240  [ 9CA6E573757C76A515EFD6DD795A3A1E ] smphost         C:\WINDOWS\System32\smphost.dll
23:29:07.0641 6240  smphost - ok
23:29:07.0657 6240  [ 222FA25F074A404AFD811C110CB169AE ] SmsRouter       C:\WINDOWS\system32\SmsRouterSvc.dll
23:29:07.0657 6240  SmsRouter - ok
23:29:07.0673 6240  [ FDADDEC855034107E5FAD708B4E2424D ] SNMPTRAP        C:\WINDOWS\System32\snmptrap.exe
23:29:07.0673 6240  SNMPTRAP - ok
23:29:07.0688 6240  [ 41A94860CC239360900D328EA306FE69 ] spaceport       C:\WINDOWS\system32\drivers\spaceport.sys
23:29:07.0688 6240  spaceport - ok
23:29:07.0704 6240  [ CCECE7E96B4F7B0E9F0FC82F6DADA917 ] SpatialGraphFilter C:\WINDOWS\system32\drivers\SpatialGraphFilter.sys
23:29:07.0704 6240  SpatialGraphFilter - ok
23:29:07.0704 6240  [ 545507AF670BC88B89200A118513ED9A ] SpbCx           C:\WINDOWS\system32\drivers\SpbCx.sys
23:29:07.0704 6240  SpbCx - ok
23:29:07.0720 6240  [ 5CF28E37F2BF80902DA50CF1A95294CE ] spectrum        C:\WINDOWS\system32\spectrum.exe
23:29:07.0735 6240  spectrum - ok
23:29:07.0751 6240  [ 4A1050E4096E1891EEFFC64282A4DD44 ] Spooler         C:\WINDOWS\System32\spoolsv.exe
23:29:07.0751 6240  Spooler - ok
23:29:07.0798 6240  [ 312D711FE1160E743D2827F607A189C9 ] sppsvc          C:\WINDOWS\system32\sppsvc.exe
23:29:07.0829 6240  sppsvc - ok
23:29:07.0845 6240  [ DA3895168C2AAAA6BD7B0C0632C59BE7 ] srv             C:\WINDOWS\system32\DRIVERS\srv.sys
23:29:07.0845 6240  srv - ok
23:29:07.0860 6240  [ C8A912159B40CD56D868466496EC3518 ] srv2            C:\WINDOWS\system32\DRIVERS\srv2.sys
23:29:07.0860 6240  srv2 - ok
23:29:07.0876 6240  [ FE7D52F9B83E2CC670E660529E930858 ] srvnet          C:\WINDOWS\system32\DRIVERS\srvnet.sys
23:29:07.0876 6240  srvnet - ok
23:29:07.0876 6240  [ 5319E85C030CDB3E779D774FEEFF4842 ] SSDPSRV         C:\WINDOWS\System32\ssdpsrv.dll
23:29:07.0891 6240  SSDPSRV - ok
23:29:07.0891 6240  [ 3BEF5FAC7F3DA3E25B80CC41B5060616 ] SstpSvc         C:\WINDOWS\system32\sstpsvc.dll
23:29:07.0891 6240  SstpSvc - ok
23:29:07.0938 6240  [ 22FC1054C424DA55323F3704F8C78CD2 ] StateRepository C:\WINDOWS\system32\windows.staterepository.dll
23:29:07.0970 6240  StateRepository - ok
23:29:07.0985 6240  [ A057004B295005ABFA3ACE1E63D7D2A2 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
23:29:08.0001 6240  Steam Client Service - ok
23:29:08.0016 6240  [ 162A805E13B3C0DD06AE8B6FC1900156 ] stexstor        C:\WINDOWS\system32\drivers\stexstor.sys
23:29:08.0016 6240  stexstor - ok
23:29:08.0016 6240  [ 3B3F5D6BB8A6A6F3630194A471989069 ] stisvc          C:\WINDOWS\System32\wiaservc.dll
23:29:08.0032 6240  stisvc - ok
23:29:08.0032 6240  [ 2F6634F70BC69D3B66EAA38AF65633C2 ] storahci        C:\WINDOWS\system32\drivers\storahci.sys
23:29:08.0032 6240  storahci - ok
23:29:08.0048 6240  [ A12CFAAA0F113A25D8CEFE58B1CBB207 ] storflt         C:\WINDOWS\system32\drivers\vmstorfl.sys
23:29:08.0048 6240  storflt - ok
23:29:08.0048 6240  [ DA0097E6C70EA25F6020CC97C7828F70 ] stornvme        C:\WINDOWS\system32\drivers\stornvme.sys
23:29:08.0048 6240  stornvme - ok
23:29:08.0063 6240  [ 57377953F5688158054BC8CB5A243115 ] storqosflt      C:\WINDOWS\system32\drivers\storqosflt.sys
23:29:08.0063 6240  storqosflt - ok
23:29:08.0079 6240  [ EEA240DD683FF1ECE15A4BFA5D9178A6 ] StorSvc         C:\WINDOWS\system32\storsvc.dll
23:29:08.0095 6240  StorSvc - ok
23:29:08.0095 6240  [ B59D29E535AF7E82717C2AD2C57EEC67 ] storufs         C:\WINDOWS\system32\drivers\storufs.sys
23:29:08.0095 6240  storufs - ok
23:29:08.0110 6240  [ 9B431079624306B5659B3B7208A71C75 ] storvsc         C:\WINDOWS\system32\drivers\storvsc.sys
23:29:08.0110 6240  storvsc - ok
23:29:08.0110 6240  [ 42FEF84684D217870F3C8813B6F58276 ] SupportSoft RemoteAssist C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe
23:29:08.0110 6240  SupportSoft RemoteAssist - ok
23:29:08.0126 6240  [ 587854AF01CABE83A62D81FFEEBCD6AA ] svsvc           C:\WINDOWS\system32\svsvc.dll
23:29:08.0126 6240  svsvc - ok
23:29:08.0126 6240  [ 027B27E4B9DB3931D64159B81BD915A0 ] swenum          C:\WINDOWS\System32\drivers\swenum.sys
23:29:08.0141 6240  swenum - ok
23:29:08.0141 6240  [ E0915F9B3C154FEF700C34A8E613B945 ] swprv           C:\WINDOWS\System32\swprv.dll
23:29:08.0157 6240  swprv - ok
23:29:08.0157 6240  [ AB15F9FDCD11D5283891BC956E8C5C95 ] Synth3dVsc      C:\WINDOWS\System32\drivers\Synth3dVsc.sys
23:29:08.0157 6240  Synth3dVsc - ok
23:29:08.0173 6240  [ 3309B708DADDCAA4C3806B5EAF0432DB ] SysMain         C:\WINDOWS\system32\sysmain.dll
23:29:08.0188 6240  SysMain - ok
23:29:08.0188 6240  [ 0839E5F9192B050F3B220562FF2C10AF ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
23:29:08.0204 6240  SystemEventsBroker - ok
23:29:08.0204 6240  [ 73F6476EE9F5448838B2883E0B710CD7 ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
23:29:08.0204 6240  TabletInputService - ok
23:29:08.0220 6240  [ AC1AA61B04116E540C5AFD18F11F2697 ] TapiSrv         C:\WINDOWS\System32\tapisrv.dll
23:29:08.0220 6240  TapiSrv - ok
23:29:08.0251 6240  [ 420A2A36A7E04D137DB35126C0C451A3 ] Tcpip           C:\WINDOWS\system32\drivers\tcpip.sys
23:29:08.0266 6240  Tcpip - ok
23:29:08.0298 6240  [ 420A2A36A7E04D137DB35126C0C451A3 ] Tcpip6          C:\WINDOWS\system32\drivers\tcpip.sys
23:29:08.0313 6240  Tcpip6 - ok
23:29:08.0329 6240  [ 74A1BF4093FA7B7D6C9366A39911A78E ] tcpipreg        C:\WINDOWS\system32\drivers\tcpipreg.sys
23:29:08.0329 6240  tcpipreg - ok
23:29:08.0345 6240  [ 571D82ABAC428D902ACA0CF60373C039 ] tdx             C:\WINDOWS\system32\DRIVERS\tdx.sys
23:29:08.0345 6240  tdx - ok
23:29:08.0454 6240  [ 70695B67EE8E743125FEBE689BDF9F0E ] TeamViewer      C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
23:29:08.0516 6240  TeamViewer - ok
23:29:08.0516 6240  [ B4B68E1DB59456419D9E49645729502A ] terminpt        C:\WINDOWS\System32\drivers\terminpt.sys
23:29:08.0516 6240  terminpt - ok
23:29:08.0532 6240  [ 96037700AEE1B4D5A6FFC62861E4FF8C ] TermService     C:\WINDOWS\System32\termsrv.dll
23:29:08.0548 6240  TermService - ok
23:29:08.0548 6240  [ E0F78207F33D6C10CBFB23E873837C87 ] Themes          C:\WINDOWS\system32\themeservice.dll
23:29:08.0563 6240  Themes - ok
23:29:08.0563 6240  [ B52BA61AB8E4BAA83EA86BAB312EE6ED ] TieringEngineService C:\WINDOWS\system32\TieringEngineService.exe
23:29:08.0579 6240  TieringEngineService - ok
23:29:08.0579 6240  [ BC834B233125DBB321B809972F2E270E ] tiledatamodelsvc C:\WINDOWS\system32\tileobjserver.dll
23:29:08.0595 6240  tiledatamodelsvc - ok
23:29:08.0595 6240  [ 9B3AA589825CF90E187DF432D806A316 ] TimeBrokerSvc   C:\WINDOWS\System32\TimeBrokerServer.dll
23:29:08.0610 6240  TimeBrokerSvc - ok
23:29:08.0626 6240  [ 17CEEADEDF0CD49404FE2C6DD10F75F6 ] TokenBroker     C:\WINDOWS\System32\TokenBroker.dll
23:29:08.0626 6240  TokenBroker - ok
23:29:08.0641 6240  [ 1658D060057C85DEC82BFCB018C4C22F ] TPM             C:\WINDOWS\System32\drivers\tpm.sys
23:29:08.0641 6240  TPM - ok
23:29:08.0657 6240  [ 39187852984778424A0EFD6B01FAB272 ] TrkWks          C:\WINDOWS\System32\trkwks.dll
23:29:08.0657 6240  TrkWks - ok
23:29:08.0657 6240  [ 0D5A09B08568760AE85A801FCBC0F83D ] TrueSight       C:\Windows\System32\drivers\TrueSight.sys
23:29:08.0657 6240  TrueSight - ok
23:29:08.0673 6240  [ 6E39B63A16B33827B861C56F0E58E021 ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
23:29:08.0673 6240  TrustedInstaller - ok
23:29:08.0688 6240  [ 8D811209E34358EAD3FD8E40F657E59C ] tsusbflt        C:\WINDOWS\system32\drivers\TsUsbFlt.sys
23:29:08.0688 6240  tsusbflt - ok
23:29:08.0688 6240  [ 68DE1735FB020AE8948BD7B60F2EBD3B ] TsUsbGD         C:\WINDOWS\System32\drivers\TsUsbGD.sys
23:29:08.0688 6240  TsUsbGD - ok
23:29:08.0704 6240  [ ACD39B0E5CFDA7B1AB7DF33FC5CC0E46 ] tunnel          C:\WINDOWS\System32\drivers\tunnel.sys
23:29:08.0704 6240  tunnel - ok
23:29:08.0704 6240  [ D5E68FCEDE15214BDB5D986D5B50E0BF ] tzautoupdate    C:\WINDOWS\system32\tzautoupdate.dll
23:29:08.0704 6240  tzautoupdate - ok
23:29:08.0720 6240  [ 04FC2C7F73AE58BF0DD674164E28A6DF ] UASPStor        C:\WINDOWS\System32\drivers\uaspstor.sys
23:29:08.0720 6240  UASPStor - ok
23:29:08.0720 6240  [ E437FC4B1833F6B745184F78C4921FB8 ] UcmCx0101       C:\WINDOWS\system32\Drivers\UcmCx.sys
23:29:08.0720 6240  UcmCx0101 - ok
23:29:08.0735 6240  [ 950A3E42167904CAB9AA64863C31CEB5 ] UcmTcpciCx0101  C:\WINDOWS\system32\Drivers\UcmTcpciCx.sys
23:29:08.0735 6240  UcmTcpciCx0101 - ok
23:29:08.0751 6240  [ 149CBBB74DFC3E52F242029A27B0F8EB ] UcmUcsi         C:\WINDOWS\System32\drivers\UcmUcsi.sys
23:29:08.0751 6240  UcmUcsi - ok
23:29:08.0751 6240  [ E6E91B3980A495D2A9D28A09580EA993 ] Ucx01000        C:\WINDOWS\system32\drivers\ucx01000.sys
23:29:08.0751 6240  Ucx01000 - ok
23:29:08.0766 6240  [ DACA289DFFA7658C04FEF6DCFA2AA9CE ] UdeCx           C:\WINDOWS\system32\drivers\udecx.sys
23:29:08.0766 6240  UdeCx - ok
23:29:08.0766 6240  [ 12383D410AEF99AD6979A8EFD3D61888 ] udfs            C:\WINDOWS\system32\DRIVERS\udfs.sys
23:29:08.0782 6240  udfs - ok
23:29:08.0782 6240  [ AB7FE51D818B6059C2F56FA62268CCAC ] UEFI            C:\WINDOWS\System32\drivers\UEFI.sys
23:29:08.0782 6240  UEFI - ok
23:29:08.0798 6240  [ 58447F28E697A93521DD20530A8D50ED ] Ufx01000        C:\WINDOWS\system32\drivers\ufx01000.sys
23:29:08.0798 6240  Ufx01000 - ok
23:29:08.0798 6240  [ 69ED2D00A7787D9D84E6C90CE0B02B2D ] UfxChipidea     C:\WINDOWS\System32\drivers\UfxChipidea.sys
23:29:08.0798 6240  UfxChipidea - ok
23:29:08.0813 6240  [ F061EC57330FBC597A4E7298BE667780 ] ufxsynopsys     C:\WINDOWS\System32\drivers\ufxsynopsys.sys
23:29:08.0813 6240  ufxsynopsys - ok
23:29:08.0829 6240  [ B26729B378282F72241859C13326E3E8 ] UI0Detect       C:\WINDOWS\system32\UI0Detect.exe
23:29:08.0829 6240  UI0Detect - ok
23:29:08.0845 6240  [ D40BCED160D332005AF612E1228825E6 ] umbus           C:\WINDOWS\System32\drivers\umbus.sys
23:29:08.0845 6240  umbus - ok
23:29:08.0845 6240  [ 64CF24D7B1FA4975C52A31BF4C82EB73 ] UmPass          C:\WINDOWS\System32\drivers\umpass.sys
23:29:08.0845 6240  UmPass - ok
23:29:08.0860 6240  [ E6B6BDA0412D3C56275E662A5A1937FD ] UmRdpService    C:\WINDOWS\System32\umrdp.dll
23:29:08.0860 6240  UmRdpService - ok
23:29:08.0860 6240  Unchecky - ok
23:29:08.0891 6240  [ 9DBB06555E1FA73B292644DF8A3454FF ] UnistoreSvc     C:\WINDOWS\System32\unistore.dll
23:29:08.0891 6240  UnistoreSvc - ok
23:29:08.0907 6240  [ D2931E3F67A990328DE5CE7E43F4467C ] upnphost        C:\WINDOWS\System32\upnphost.dll
23:29:08.0923 6240  upnphost - ok
23:29:08.0923 6240  [ ACE4C3B4C7D17B154FFC5BBE5F7A9835 ] UrsChipidea     C:\WINDOWS\System32\drivers\urschipidea.sys
23:29:08.0923 6240  UrsChipidea - ok
23:29:08.0938 6240  [ ECE40EB976A5ACB366808AECF6B235BA ] UrsCx01000      C:\WINDOWS\system32\drivers\urscx01000.sys
23:29:08.0938 6240  UrsCx01000 - ok
23:29:08.0938 6240  [ EB738F830D3E7EA62A218F101EF91FD4 ] UrsSynopsys     C:\WINDOWS\System32\drivers\urssynopsys.sys
23:29:08.0938 6240  UrsSynopsys - ok
23:29:08.0954 6240  [ B43E28E5CF868517EEC0923AB2BC366B ] usbccgp         C:\WINDOWS\System32\drivers\usbccgp.sys
23:29:08.0954 6240  usbccgp - ok
23:29:08.0954 6240  [ 1080D80B5F6D249F23BAE1C0C36233A4 ] usbcir          C:\WINDOWS\System32\drivers\usbcir.sys
23:29:08.0954 6240  usbcir - ok
23:29:08.0970 6240  [ EE162DA2C92026A5B96ED89737975AA8 ] usbehci         C:\WINDOWS\System32\drivers\usbehci.sys
23:29:08.0970 6240  usbehci - ok
23:29:08.0985 6240  [ C27FEE9758E3BEDE4D48B5EDBE1122CF ] usbhub          C:\WINDOWS\System32\drivers\usbhub.sys
23:29:08.0985 6240  usbhub - ok
23:29:09.0001 6240  [ 4FA9C956E569D0D380C2859542361780 ] USBHUB3         C:\WINDOWS\System32\drivers\UsbHub3.sys
23:29:09.0001 6240  USBHUB3 - ok
23:29:09.0016 6240  [ 44B954306BB2B311E070EDA276FECAB1 ] usbohci         C:\WINDOWS\System32\drivers\usbohci.sys
23:29:09.0016 6240  usbohci - ok
23:29:09.0016 6240  [ EEF26F9034F0608B93D4D239534BB0BA ] usbprint        C:\WINDOWS\System32\drivers\usbprint.sys
23:29:09.0016 6240  usbprint - ok
23:29:09.0032 6240  [ 913CFF365DB1803525DBD2AA8B8188B4 ] usbser          C:\WINDOWS\System32\drivers\usbser.sys
23:29:09.0032 6240  usbser - ok
23:29:09.0032 6240  [ 441CAE778B6A1FF6E618E37814A7A52A ] USBSTOR         C:\WINDOWS\System32\drivers\USBSTOR.SYS
23:29:09.0032 6240  USBSTOR - ok
23:29:09.0048 6240  [ 2D6BB2157B37B2D9DABF8C218F2A805B ] usbuhci         C:\WINDOWS\System32\drivers\usbuhci.sys
23:29:09.0048 6240  usbuhci - ok
23:29:09.0048 6240  [ 0B22D76E3BE6DA40AEE26C21217CBE58 ] USBXHCI         C:\WINDOWS\System32\drivers\USBXHCI.SYS
23:29:09.0063 6240  USBXHCI - ok
23:29:09.0079 6240  [ 583E586E926F025A430902D6679B9AD5 ] UserDataSvc     C:\WINDOWS\System32\userdataservice.dll
23:29:09.0095 6240  UserDataSvc - ok
23:29:09.0110 6240  [ F38944BBAA22D6386D0828EAA3147F1E ] UserManager     C:\WINDOWS\System32\usermgr.dll
23:29:09.0110 6240  UserManager - ok
23:29:09.0141 6240  [ 08D61B00BAE43FD326CFCEC87D11F986 ] UsoSvc          C:\WINDOWS\system32\usocore.dll
23:29:09.0141 6240  UsoSvc - ok
23:29:09.0157 6240  [ 94E06D509D50807774F35BEE3163E806 ] VaultSvc        C:\WINDOWS\system32\lsass.exe
23:29:09.0157 6240  VaultSvc - ok
23:29:09.0157 6240  [ C77C537077822D8EA529AD4EBFD971D6 ] vdrvroot        C:\WINDOWS\system32\drivers\vdrvroot.sys
23:29:09.0157 6240  vdrvroot - ok
23:29:09.0173 6240  [ 07C192BEEA76B1BD9D0310ED20551D54 ] vds             C:\WINDOWS\System32\vds.exe
23:29:09.0188 6240  vds - ok
23:29:09.0188 6240  [ 9D4EEE333603F3675685F644053499D5 ] VerifierExt     C:\WINDOWS\system32\drivers\VerifierExt.sys
23:29:09.0188 6240  VerifierExt - ok
23:29:09.0204 6240  [ F40CD2F44533F2618B5CA29BC03EEE81 ] vhdmp           C:\WINDOWS\System32\drivers\vhdmp.sys
23:29:09.0204 6240  vhdmp - ok
23:29:09.0220 6240  [ E10FEBB566E1F0A3936AB304F338637E ] vhf             C:\WINDOWS\System32\drivers\vhf.sys
23:29:09.0220 6240  vhf - ok
23:29:09.0235 6240  [ 164E6B2919FF12911F63C7EC526ED669 ] vmbus           C:\WINDOWS\system32\drivers\vmbus.sys
23:29:09.0235 6240  vmbus - ok
23:29:09.0235 6240  [ DC9E0600B356258E31403789119C78A9 ] VMBusHID        C:\WINDOWS\System32\drivers\VMBusHID.sys
23:29:09.0235 6240  VMBusHID - ok
23:29:09.0251 6240  [ B24F74B2710B66F647419697BDB9E163 ] vmgid           C:\WINDOWS\System32\drivers\vmgid.sys
23:29:09.0251 6240  vmgid - ok
23:29:09.0251 6240  [ CE70937143DBDB2B4BF3A0310EB9E189 ] vmicguestinterface C:\WINDOWS\System32\icsvc.dll
23:29:09.0266 6240  vmicguestinterface - ok
23:29:09.0266 6240  [ CE70937143DBDB2B4BF3A0310EB9E189 ] vmicheartbeat   C:\WINDOWS\System32\icsvc.dll
23:29:09.0266 6240  vmicheartbeat - ok
23:29:09.0282 6240  [ CE70937143DBDB2B4BF3A0310EB9E189 ] vmickvpexchange C:\WINDOWS\System32\icsvc.dll
23:29:09.0282 6240  vmickvpexchange - ok
23:29:09.0298 6240  [ FD73A74D26F5BEC303763FD9CDD2DFB2 ] vmicrdv         C:\WINDOWS\System32\icsvcext.dll
23:29:09.0298 6240  vmicrdv - ok
23:29:09.0298 6240  [ CE70937143DBDB2B4BF3A0310EB9E189 ] vmicshutdown    C:\WINDOWS\System32\icsvc.dll
23:29:09.0313 6240  vmicshutdown - ok
23:29:09.0313 6240  [ CE70937143DBDB2B4BF3A0310EB9E189 ] vmictimesync    C:\WINDOWS\System32\icsvc.dll
23:29:09.0313 6240  vmictimesync - ok
23:29:09.0329 6240  [ CE70937143DBDB2B4BF3A0310EB9E189 ] vmicvmsession   C:\WINDOWS\System32\icsvc.dll
23:29:09.0329 6240  vmicvmsession - ok
23:29:09.0345 6240  [ FD73A74D26F5BEC303763FD9CDD2DFB2 ] vmicvss         C:\WINDOWS\System32\icsvcext.dll
23:29:09.0345 6240  vmicvss - ok
23:29:09.0345 6240  [ D81F6B790519A60F3D1788B45D04B749 ] vnvdimm         C:\WINDOWS\System32\drivers\vnvdimm.sys
23:29:09.0345 6240  vnvdimm - ok
23:29:09.0360 6240  [ CD1474E804C0417BF2DC840AC5DF98EA ] volmgr          C:\WINDOWS\system32\drivers\volmgr.sys
23:29:09.0360 6240  volmgr - ok
23:29:09.0376 6240  [ 6D6CACED512C1EF1FEAC215E37E3A9BC ] volmgrx         C:\WINDOWS\system32\drivers\volmgrx.sys
23:29:09.0376 6240  volmgrx - ok
23:29:09.0391 6240  [ 6AF9BCB1FFD127B8F4E7E7B9FF9351EA ] volsnap         C:\WINDOWS\system32\drivers\volsnap.sys
23:29:09.0391 6240  volsnap - ok
23:29:09.0391 6240  [ 72A95A844D6BAF2924A4C15BEDFD6BCA ] volume          C:\WINDOWS\system32\drivers\volume.sys
23:29:09.0391 6240  volume - ok
23:29:09.0407 6240  [ 702273C7C1BE9D366BAF1305D382F03C ] vpci            C:\WINDOWS\System32\drivers\vpci.sys
23:29:09.0407 6240  vpci - ok
23:29:09.0407 6240  [ 075CE3C9E77D2666AFA888951E5F07A9 ] vsmraid         C:\WINDOWS\system32\drivers\vsmraid.sys
23:29:09.0423 6240  vsmraid - ok
23:29:09.0438 6240  [ 16144D396BFFEFDB0B8A2C964CBAD35D ] VSS             C:\WINDOWS\system32\vssvc.exe
23:29:09.0454 6240  VSS - ok
23:29:09.0454 6240  [ 26D00E85BE4726B114335250FCDEDA89 ] VSTXRAID        C:\WINDOWS\system32\drivers\vstxraid.sys
23:29:09.0454 6240  VSTXRAID - ok
23:29:09.0470 6240  [ 3DFDB573E4D49EA8F416B573525B7A86 ] vwifibus        C:\WINDOWS\System32\drivers\vwifibus.sys
23:29:09.0470 6240  vwifibus - ok
23:29:09.0485 6240  [ A40FA64655AB5B8773A96A821616C5FC ] vwififlt        C:\WINDOWS\system32\drivers\vwififlt.sys
23:29:09.0485 6240  vwififlt - ok
23:29:09.0501 6240  [ A17A4F2823C5424C9B8B990644817DC0 ] W32Time         C:\WINDOWS\system32\w32time.dll
23:29:09.0501 6240  W32Time - ok
23:29:09.0501 6240  [ AD72CFDA8E47BC32ED46DE4FD2434062 ] w3logsvc        C:\WINDOWS\system32\inetsrv\w3logsvc.dll
23:29:09.0516 6240  w3logsvc - ok
23:29:09.0516 6240  [ A76A55BF0B22D1075434F1D723B9D1AC ] W3SVC           C:\WINDOWS\system32\inetsrv\iisw3adm.dll
23:29:09.0532 6240  W3SVC - ok
23:29:09.0532 6240  [ 5B5430522E0BDF2A753D758710BE7C5E ] WacomPen        C:\WINDOWS\System32\drivers\wacompen.sys
23:29:09.0532 6240  WacomPen - ok
23:29:09.0548 6240  [ 451D40C28E7D1CF51A980B83FDEFF498 ] WalletService   C:\WINDOWS\system32\WalletService.dll
23:29:09.0548 6240  WalletService - ok
23:29:09.0563 6240  [ 478193CE0AAD5C8515568592F1F640D1 ] wanarp          C:\WINDOWS\system32\DRIVERS\wanarp.sys
23:29:09.0563 6240  wanarp - ok
23:29:09.0563 6240  [ 478193CE0AAD5C8515568592F1F640D1 ] wanarpv6        C:\WINDOWS\system32\DRIVERS\wanarp.sys
23:29:09.0563 6240  wanarpv6 - ok
23:29:09.0579 6240  [ E3B4C37F1F3D8078AA2AFBEE7F5468CF ] WarpJITSvc      C:\WINDOWS\System32\Windows.WARP.JITService.dll
23:29:09.0579 6240  WarpJITSvc - ok
23:29:09.0595 6240  [ A76A55BF0B22D1075434F1D723B9D1AC ] WAS             C:\WINDOWS\system32\inetsrv\iisw3adm.dll
23:29:09.0595 6240  WAS - ok
23:29:09.0610 6240  [ 1C1EB9C4DAF428B3BFDD58572768182C ] wbengine        C:\WINDOWS\system32\wbengine.exe
23:29:09.0626 6240  wbengine - ok
23:29:09.0641 6240  [ D38ACBA3FE7B12C30D13A68B35FAB71A ] WbioSrvc        C:\WINDOWS\System32\wbiosrvc.dll
23:29:09.0657 6240  WbioSrvc - ok
23:29:09.0657 6240  [ A8DFD1465C05D9EFBDFD5C3A25B7F496 ] wcifs           C:\WINDOWS\system32\drivers\wcifs.sys
23:29:09.0657 6240  wcifs - ok
23:29:09.0673 6240  [ EB1B7609CC9BFA19D81BC0A43CEE067B ] Wcmsvc          C:\WINDOWS\System32\wcmsvc.dll
23:29:09.0688 6240  Wcmsvc - ok
23:29:09.0704 6240  [ E2A66490B2D91A00554E5BCF217942F4 ] wcncsvc         C:\WINDOWS\System32\wcncsvc.dll
23:29:09.0704 6240  wcncsvc - ok
23:29:09.0704 6240  [ 9DE3FDFF295F2534DF0A8B6FC4F06355 ] wcnfs           C:\WINDOWS\system32\drivers\wcnfs.sys
23:29:09.0720 6240  wcnfs - ok
23:29:09.0720 6240  [ 6FD8F1FBED780A7F3DF329C834E52AC5 ] WdBoot          C:\WINDOWS\system32\drivers\WdBoot.sys
23:29:09.0720 6240  WdBoot - ok
23:29:09.0735 6240  [ FCC960498E3CD899F0A429F7CF9E77AD ] Wdf01000        C:\WINDOWS\system32\drivers\Wdf01000.sys
23:29:09.0735 6240  Wdf01000 - ok
23:29:09.0751 6240  [ 7D182F0F227FC141C5D2085175BE05F6 ] WdFilter        C:\WINDOWS\system32\drivers\WdFilter.sys
23:29:09.0751 6240  WdFilter - ok
23:29:09.0766 6240  [ AB406F30BE98CDB7AA7171336EF031BA ] WdiServiceHost  C:\WINDOWS\system32\wdi.dll
23:29:09.0766 6240  WdiServiceHost - ok
23:29:09.0766 6240  [ AB406F30BE98CDB7AA7171336EF031BA ] WdiSystemHost   C:\WINDOWS\system32\wdi.dll
23:29:09.0782 6240  WdiSystemHost - ok
23:29:09.0798 6240  [ 943FE2802DAB5644B188AE0EC2EF4740 ] wdiwifi         C:\WINDOWS\system32\DRIVERS\wdiwifi.sys
23:29:09.0798 6240  wdiwifi - ok
23:29:09.0798 6240  [ 0D38C257A7B34A818726BA2F323B196E ] WdNisDrv        C:\WINDOWS\system32\Drivers\WdNisDrv.sys
23:29:09.0813 6240  WdNisDrv - ok
23:29:09.0813 6240  WdNisSvc - ok
23:29:09.0813 6240  [ DF58AA71FBA55E15F572C93447696DEC ] wdnsfltr        C:\WINDOWS\system32\drivers\wdnsfltr.sys
23:29:09.0829 6240  wdnsfltr - ok
23:29:09.0829 6240  [ A339FDE695599D96C4F78CC22A993AFB ] WebClient       C:\WINDOWS\System32\webclnt.dll
23:29:09.0829 6240  WebClient - ok
23:29:09.0845 6240  [ 7997BC2386A9976C0645A28FA8A6E7EA ] Wecsvc          C:\WINDOWS\system32\wecsvc.dll
23:29:09.0845 6240  Wecsvc - ok
23:29:09.0860 6240  [ CEA146E0D096A491B265CD2340C2E31D ] WEPHOSTSVC      C:\WINDOWS\system32\wephostsvc.dll
23:29:09.0860 6240  WEPHOSTSVC - ok
23:29:09.0860 6240  [ 40610BA98D5830FB14C3695B3BCA647A ] wercplsupport   C:\WINDOWS\System32\wercplsupport.dll
23:29:09.0876 6240  wercplsupport - ok
23:29:09.0876 6240  [ AA2B3154D12ABE34640C866AC3472E33 ] WerSvc          C:\WINDOWS\System32\WerSvc.dll
23:29:09.0876 6240  WerSvc - ok
23:29:09.0891 6240  [ 86B816E9D24625287BDE9784953A5E86 ] WFDSConMgrSvc   C:\WINDOWS\System32\wfdsconmgrsvc.dll
23:29:09.0907 6240  WFDSConMgrSvc - ok
23:29:09.0907 6240  [ 4EAE206AF1D880C9C06FB4ACD17F0506 ] WFPLWFS         C:\WINDOWS\system32\drivers\wfplwfs.sys
23:29:09.0907 6240  WFPLWFS - ok
23:29:09.0923 6240  [ F78A2731EC972312C4C998174A9BB325 ] WiaRpc          C:\WINDOWS\System32\wiarpc.dll
23:29:09.0923 6240  WiaRpc - ok
23:29:09.0938 6240  [ C8D3FC38426E990E2787771678B19C6D ] WIMMount        C:\WINDOWS\system32\drivers\wimmount.sys
23:29:09.0938 6240  WIMMount - ok
23:29:09.0938 6240  WinDefend - ok
23:29:09.0954 6240  [ 0484B0D01EA6F7017519EBDDBADE759D ] WindowsTrustedRT C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys
23:29:09.0954 6240  WindowsTrustedRT - ok
23:29:09.0970 6240  [ 813EE0F4D4B8D599DB1968682D080732 ] WindowsTrustedRTProxy C:\WINDOWS\system32\drivers\WindowsTrustedRTProxy.sys
23:29:09.0970 6240  WindowsTrustedRTProxy - ok
23:29:09.0985 6240  [ B559AA04EF539CFF8FEA67C4ECD12074 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
23:29:09.0985 6240  WinHttpAutoProxySvc - ok
23:29:10.0001 6240  [ E23475E9150E6A50B12DB176EA5CDD56 ] WinMad          C:\WINDOWS\System32\drivers\winmad.sys
23:29:10.0001 6240  WinMad - ok
23:29:10.0016 6240  [ 0FBD5D358094E254A1508832D4042FF7 ] Winmgmt         C:\WINDOWS\system32\wbem\WMIsvc.dll
23:29:10.0016 6240  Winmgmt - ok
23:29:10.0016 6240  [ 3E27B5B573DCC8DE15A93F61C01713B6 ] WinNat          C:\WINDOWS\system32\drivers\winnat.sys
23:29:10.0016 6240  WinNat - ok
23:29:10.0063 6240  [ C2A88E382CD48E4772A5570D66BF1A90 ] WinRM           C:\WINDOWS\system32\WsmSvc.dll
23:29:10.0079 6240  WinRM - ok
23:29:10.0095 6240  [ E92F3539C4758F6A9F4B80CBAC75B3E6 ] WINUSB          C:\WINDOWS\System32\drivers\WinUSB.SYS
23:29:10.0095 6240  WINUSB - ok
23:29:10.0095 6240  [ 59126AFCC64270747B5CC9B44A4A48F4 ] WinVerbs        C:\WINDOWS\System32\drivers\winverbs.sys
23:29:10.0110 6240  WinVerbs - ok
23:29:10.0126 6240  [ 0A3ADAA0EFAFA26CA8570E24A13CE484 ] wisvc           C:\WINDOWS\system32\flightsettings.dll
23:29:10.0126 6240  wisvc - ok
23:29:10.0157 6240  [ 01884DA4486A1B8469D406248C42DF50 ] WlanSvc         C:\WINDOWS\System32\wlansvc.dll
23:29:10.0173 6240  WlanSvc - ok
23:29:10.0204 6240  [ 345056CEAC49D289098F7A33A2C7CA2B ] wlidsvc         C:\WINDOWS\system32\wlidsvc.dll
23:29:10.0220 6240  wlidsvc - ok
23:29:10.0235 6240  [ 56E1A46DD1C5D28B10F02E21D077EBF6 ] wlpasvc         C:\WINDOWS\System32\lpasvc.dll
23:29:10.0251 6240  wlpasvc - ok
23:29:10.0251 6240  [ E8C793ED028E132771988760819E3754 ] WmiAcpi         C:\WINDOWS\System32\drivers\wmiacpi.sys
23:29:10.0251 6240  WmiAcpi - ok
23:29:10.0266 6240  [ 7112092A3C6F41EDBE83636791C774D9 ] wmiApSrv        C:\WINDOWS\system32\wbem\WmiApSrv.exe
23:29:10.0266 6240  wmiApSrv - ok
23:29:10.0266 6240  WMPNetworkSvc - ok
23:29:10.0282 6240  [ 8D6E6F6C233AF450C50FA615530B44D2 ] Wof             C:\WINDOWS\system32\drivers\Wof.sys
23:29:10.0282 6240  Wof - ok
23:29:10.0313 6240  [ 1431D184691F7FA9AAC2064EB0EC6C96 ] workfolderssvc  C:\WINDOWS\system32\workfolderssvc.dll
23:29:10.0329 6240  workfolderssvc - ok
23:29:10.0329 6240  [ AE9793230B219113DE1163138645E5AE ] WPDBusEnum      C:\WINDOWS\system32\wpdbusenum.dll
23:29:10.0345 6240  WPDBusEnum - ok
23:29:10.0345 6240  [ 9EAE1EF282864674355B4B81DF6AE935 ] WpdUpFltr       C:\WINDOWS\system32\drivers\WpdUpFltr.sys
23:29:10.0345 6240  WpdUpFltr - ok
23:29:10.0360 6240  [ C75B59E441206A572CC64BBB60EE54B3 ] WpnService      C:\WINDOWS\system32\WpnService.dll
23:29:10.0360 6240  WpnService - ok
23:29:10.0376 6240  [ 07F4AF1730D55567EACE7ADDEA28FE48 ] WpnUserService  C:\WINDOWS\System32\WpnUserService.dll
23:29:10.0376 6240  WpnUserService - ok
23:29:10.0376 6240  [ 367B3ED0C688AFE28C376B0230814567 ] ws2ifsl         C:\WINDOWS\system32\drivers\ws2ifsl.sys
23:29:10.0376 6240  ws2ifsl - ok
23:29:10.0391 6240  [ 39DA352FAD220E83CE64DE8DCCB9736B ] wscsvc          C:\WINDOWS\System32\wscsvc.dll
23:29:10.0391 6240  wscsvc - ok
23:29:10.0407 6240  WSearch - ok
23:29:10.0438 6240  [ C502D4199DDE31CA8C368BB8968309D6 ] wuauserv        C:\WINDOWS\system32\wuaueng.dll
23:29:10.0454 6240  wuauserv - ok
23:29:10.0470 6240  [ BD5E68B369DF3453A0A87663C6C5476D ] WudfPf          C:\WINDOWS\system32\drivers\WudfPf.sys
23:29:10.0470 6240  WudfPf - ok
23:29:10.0485 6240  [ A86A249314FD0A780214028B0C31A386 ] WUDFRd          C:\WINDOWS\system32\drivers\WudfRd.sys
23:29:10.0485 6240  WUDFRd - ok
23:29:10.0501 6240  [ A86A249314FD0A780214028B0C31A386 ] WUDFWpdFs       C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
23:29:10.0501 6240  WUDFWpdFs - ok
23:29:10.0516 6240  [ 7D4B6DC3975945759AFA8E9892CF7846 ] WwanSvc         C:\WINDOWS\System32\wwansvc.dll
23:29:10.0532 6240  WwanSvc - ok
23:29:10.0532 6240  [ 42C738ED1552FE168F6EE1BAE8ACFCAC ] xbgm            C:\WINDOWS\system32\xbgmsvc.exe
23:29:10.0532 6240  xbgm - ok
23:29:10.0563 6240  [ A03C4D4D71304087820A0EF18FCF7582 ] XblAuthManager  C:\WINDOWS\System32\XblAuthManager.dll
23:29:10.0563 6240  XblAuthManager - ok
23:29:10.0595 6240  [ 77ADC2F5DBE303EF8B8D2D08AEE3F3DB ] XblGameSave     C:\WINDOWS\System32\XblGameSave.dll
23:29:10.0595 6240  XblGameSave - ok
23:29:10.0610 6240  [ 2244A4CEFE8F9C74091369ACE2E9EBC6 ] xboxgip         C:\WINDOWS\System32\drivers\xboxgip.sys
23:29:10.0610 6240  xboxgip - ok
23:29:10.0626 6240  [ 1A9550D746B8604D37A90436EF686777 ] XboxGipSvc      C:\WINDOWS\System32\XboxGipSvc.dll
23:29:10.0626 6240  XboxGipSvc - ok
23:29:10.0641 6240  [ 4951DD543AA2710760D90A58261ED665 ] XboxNetApiSvc   C:\WINDOWS\system32\XboxNetApiSvc.dll
23:29:10.0657 6240  XboxNetApiSvc - ok
23:29:10.0657 6240  [ 4A91B49C6B1E41151D47CB919ADF013A ] xinputhid       C:\WINDOWS\System32\drivers\xinputhid.sys
23:29:10.0657 6240  xinputhid - ok
23:29:10.0673 6240  [ 21E13F2CB269DEFEAE5E1D09887D47BB ] ZAM             C:\WINDOWS\System32\drivers\zam64.sys
23:29:10.0673 6240  ZAM - ok
23:29:10.0829 6240  [ 864FA7B8856FE853D381045771DB30E9 ] ZAMSvc          C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
23:29:10.0891 6240  ZAMSvc - ok
23:29:10.0907 6240  [ 21E13F2CB269DEFEAE5E1D09887D47BB ] ZAM_Guard       C:\WINDOWS\System32\drivers\zamguard64.sys
23:29:10.0907 6240  ZAM_Guard - ok
23:29:10.0923 6240  ================ Scan global ===============================
23:29:10.0923 6240  [ EB45383BE9D7ECB36D55B262E0D8EB46 ] C:\WINDOWS\system32\basesrv.dll
23:29:10.0923 6240  [ 79DA21044C98FD6CD01EA9E488DF82C5 ] C:\WINDOWS\system32\winsrv.dll
23:29:10.0938 6240  [ 9451BA31B1DC19CED2608D82863C6486 ] C:\WINDOWS\system32\sxssrv.dll
23:29:10.0954 6240  [ 16B7B5FC9533777CE5770CEE52D81A86 ] C:\WINDOWS\system32\services.exe
23:29:10.0954 6240  [Global] - ok
23:29:10.0954 6240  ================ Scan MBR ==================================
23:29:10.0954 6240  [ B1F7D7F6E4FBE98E578562A22A94D02C ] \Device\Harddisk0\DR0
23:29:11.0016 6240  \Device\Harddisk0\DR0 - ok
23:29:11.0016 6240  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
23:29:11.0016 6240  \Device\Harddisk1\DR1 - ok
23:29:11.0016 6240  ================ Scan VBR ==================================
23:29:11.0032 6240  [ 9E95BAB243D859FFFA874FAB5EF0EE3D ] \Device\Harddisk0\DR0\Partition1
23:29:11.0032 6240  \Device\Harddisk0\DR0\Partition1 - ok
23:29:11.0032 6240  [ 1E80C31509CEAFA536CF6EA01AE887A7 ] \Device\Harddisk0\DR0\Partition2
23:29:11.0032 6240  \Device\Harddisk0\DR0\Partition2 - ok
23:29:11.0032 6240  [ 8A8D682DB7593354CA6C437E6FCB44F2 ] \Device\Harddisk1\DR1\Partition1
23:29:11.0032 6240  \Device\Harddisk1\DR1\Partition1 - ok
23:29:11.0032 6240  ============================================================
23:29:11.0032 6240  Scan finished
23:29:11.0032 6240  ============================================================
23:29:11.0048 8128  Detected object count: 0
23:29:11.0048 8128  Actual detected object count: 0
23:29:55.0550 7204  Deinitialize success


Google is my friend. Make Google your friend too.


#15 Torvald

Torvald
  • Topic Starter

  • Members
  • 366 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Antonio, TX USA
  • Local time:05:19 AM

Posted 28 November 2017 - 12:57 AM

Okay, I downloaded Avast and double-clicked on the aswMBR.exe file to run it.

 

It asked me if I wanted to enable virtualization and I said "yes".

 

It then gave me a full screen error message that said:  "Your PC ran into a problem and needs to restart.  We're just collecting some error info, and then you can restart.  100% complete.  Stop code: Page fault in nonpaged area.  What failed: aswVmm.sys"

 

My computer then froze solid, so I manually turned it off, removed all power, then turned it back on to post this information for you.

 

Thank you for your help so far, but my computer is apparently being stubborn right now.

 

Please let me know what i should try next.  Thanks again.


Google is my friend. Make Google your friend too.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users