Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all 2798 articles
Browse latest View live

event ID 10016...Virus?

$
0
0
I got a call from someone saying my computer was infected. I eventually realized that this was probably a scam, but one of the things he led me to was the event viewer, where there were a bunch of error messages, mainly the 10016 one. here is what the message says...

The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


Is this something that I need to worry about, a virus perhaps? If so, how do I resolve this issue?

Unable to delete cookies

$
0
0
I've been trying to delete the cookies from my browser (IE11) and found many sites are retaining my login info and passwords even after deletion. I am unsure of the cause but I am worried a virus may be preventing them from being deleted.

I can delete my browsing history just fine, but I'm trying to remove all login data and passwords, but they remain in place.

Firewall hiding, File Explorer won't stay open, slower than a dead sloth & more! :(

$
0
0
Hail Mighty Techs! :bow:

What is occuring with my puter?? Just about everything that could go wrong is err..going wrong :sad:

To call it slow would be a massive understatement, it just took 35 mins for the browser to open & yet when it is open & I am on a site, like here, it all seems to work fine. But then opening something else, I click and wait & wait & wait & then everything freezes up & its "Not responding" when it unfreezes etc etc.

My Firewall disappeared (COMODO) doesn`t even show on the list in start menu or on Programs & Features, definately not running & icons all gone, but then I found it still in C: Programs. I tried to run it & nothing happens, tried running the installer exe & aside from asking if I wanted to allow it to change stuff, nothing happens, tried the crashrepair exe...Again nothing. Downloaded the program again & tried to install it, that freezes up & has never got passed 48%, mostly won`t get passed 7%. Skype also disappeared, I was using it, restarted puter & it was no longer installed lol No idea how many other things have gone.

Then there is File Explorer, dunno wassup with that, I click, it opens & a second later the screen goes black, the task bar reloads all the icons & explorer is closed again. Sometimes if I am quick I can get my cursor on to the page before everything goes black.

Windows are all being funky too, I click them and they stay behind each other, they don`t seem to want to come to the top & pop-ups come behind them too & I have no idea they are there. Other windows (especially browser) if minimised, won`t re-open, I can hover over it & the thumbnail will come up showing its there but it just won`t open, unless I make it full screen, then it will come up, but if I try to change that once its open it just disappears again & I can`t open the start menu when a browser is open.

I have run CCleaner & it only found about 4K MB to clean up, done scans with Malwarebytes & AVG & they both came up clean. Do you have any idea what could be wrong with my puter? :cry:

Windows 10 Home
Intel(R) Core(TM) i5 CPU 750 @ 2.67GHz
(RAM) 4.00 GB
64-bit OS

Any help much appreciated!
Munki

Really invisible malware that survives Win10 clean install?

$
0
0
Hey all, I found this site on Google and was impressed with answers so figured I would make an account. I've tried fixing these issues myself since 2016 and I'm about to check myself into an insane asylum because issues keep reappearing after completely reinstalling windows. Note: performance seems....fine? But I get an egregious amount of ADS while surfing with EDGE or Chrome, even with UBlock Origin installed. There also weird processes running (including a CMD prompt flash on startup).
Someone did hack my amazon account a few months ago and ordered some stuff so that prompted me to go nuclear and audit all of my online account passwords and update two-factor authentication, etc etc.

I would just like an expert to evaluate my running process and any potential hijacks that might be hidden in the registry (is that even possible??) Should I use the FRST tool like in the other threads and post the logs?

Thanks for taking the time.

Internet history remains after clearing it from pc

$
0
0
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.14393.953 BrowserJavaVersion: 11.31.2
Run by Alain at 8:17:11 on 2017-04-05
Microsoft Windows 10 Home 10.0.14393.0.1252.2.1033.18.6027.3856 [GMT -6:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET NOD32 Antivirus 9.0.408.0 *Enabled/Updated* {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
SP: ESET NOD32 Antivirus 9.0.408.0 *Enabled/Updated* {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe
C:\WINDOWS\System32\spoolsv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\system32\DbxSvc.exe
C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\WINDOWS\system32\dashost.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Splashtop\Splashtop Remote\SERVER\SRService.exe
C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files\TOSHIBA\Teco\TecoService.exe
C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\WINDOWS\system32\wbem\WmiApSrv.exe
C:\WINDOWS\System32\dwm.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\sihost.exe
C:\Program Files (x86)\Splashtop\Splashtop Remote\SERVER\SRServer.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\taskhostw.exe
C:\Windows\System32\RuntimeBroker.exe
C:\WINDOWS\system32\igfxEM.exe
C:\WINDOWS\system32\igfxHK.exe
C:\WINDOWS\system32\igfxTray.exe
C:\WINDOWS\SysWOW64\rundll32.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files (x86)\Splashtop\Splashtop Remote\SERVER\SRFeature.exe
C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe
C:\WINDOWS\system32\SettingSyncHost.exe
C:\WINDOWS\system32\ApplicationFrameHost.exe
C:\Windows\System32\smartscreen.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Users\Alain\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\WINDOWS\splwow64.exe
C:\WINDOWS\system32\AUDIODG.EXE
svchost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.bbc.com/
uWindow Title = Presented by TOSHIBA Leading Innovation >>>
uDefault_Page_URL = hxxp://toshiba13.msn.com
BHO: Skype for Business Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\office15\ochelper.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\office15\grooveex.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
uRun: [OneDrive] "C:\Users\Alain\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
uRun: [CCleaner Monitoring] "C:\Program Files (x86)\CCleaner\CCleaner64.exe" /MONITOR
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
uRun: [iCloudDrive] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [TPUReg] "C:\Program Files (x86)\TOSHIBA\Password Utility\TosPU.exe" /Retimes
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [qlu] C:\Program Files (x86)\QLU\qlu.exe
mRun: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
StartupFolder: C:\Users\Alain\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\SENDTO~1.LNK - C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\WDDMST~1.LNK - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
mPolicies-System: DSCAutomationHostEnabled = dword:2
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\office15\onbttnie.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\office15\ochelper.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
DPF: {63F5866B-A7C5-40B4-9A89-0CCA99726C8D} - hxxps://secure.logmeinrescue.com/Customer/x86/RescueDownloader.cab
TCP: NameServer = 192.168.1.254 75.153.171.114
TCP: Interfaces\{d4cb7153-97c6-4f4c-b510-571ffffb50a0} : DHCPNameServer = 64.59.135.133 64.59.128.120
TCP: Interfaces\{f32ee33e-832e-4880-9f6d-9e39ff0eb870} : DHCPNameServer = 192.168.1.254 75.153.171.114
TCP: Interfaces\{f32ee33e-832e-4880-9f6d-9e39ff0eb870}\2656C6B696E6E2734383 : DHCPNameServer = 192.168.2.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: intu-tt2012 - {02F985EF-502B-4597-993F-6BF9E004C138} - C:\Program Files (x86)\TurboTax 2012\ic2012pp.dll
Handler: intu-tt2013 - {9FF5EC07-1645-43BF-828F-C73CFA7BC1AF} - C:\Program Files (x86)\TurboTax 2013\ic2013pp.dll
Handler: intu-tt2014 - {97BB39CB-9ABA-4513-81E7-1D6FDA0854B8} - C:\Program Files (x86)\TurboTax 2014\ic2014pp.dll
Handler: intu-tt2015 - {5A676D6A-A3EF-4FAA-8DAC-F55CA235F67C} - C:\Program Files (x86)\TurboTax 2015\ic2015pp.dll
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\msosb.dll
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
x64-BHO: Skype for Business Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ochelper.dll
x64-BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll
x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
x64-Run: [TecoResident] C:\Program Files\TOSHIBA\Teco\TecoResident.exe
x64-Run: [TODDMain] C:\Program Files (x86)\TOSHIBA\System Setting\TODDMain.exe
x64-Run: [TosWaitSrv] C:\Program Files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
x64-Run: [TCrdMain] C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
x64-mPolicies-System: DSCAutomationHostEnabled = dword:2
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnie.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ochelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: intu-tt2012 - {02F985EF-502B-4597-993F-6BF9E004C138} - <orphaned>
x64-Handler: intu-tt2013 - {9FF5EC07-1645-43BF-828F-C73CFA7BC1AF} - <orphaned>
x64-Handler: intu-tt2014 - {97BB39CB-9ABA-4513-81E7-1D6FDA0854B8} - <orphaned>
x64-Handler: intu-tt2015 - {5A676D6A-A3EF-4FAA-8DAC-F55CA235F67C} - <orphaned>
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - <orphaned>
x64-Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
x64-CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Alain\AppData\Roaming\Mozilla\Firefox\Profiles\q1ql6pp4.default\
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Picasa2\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\4\NP_wtapp.dll
FF - plugin: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
FF - plugin: C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
FF - plugin: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll
.
============= SERVICES / DRIVERS ===============
.
R0 edevmon;edevmon;C:\WINDOWS\System32\drivers\edevmon.sys [2015-7-13 199304]
R0 iaStorA;iaStorA;C:\WINDOWS\System32\drivers\iaStorA.sys [2012-11-22 645952]
R0 intelpep;Intel(R) Power Engine Plug-in Driver;C:\WINDOWS\System32\drivers\intelpep.sys [2016-7-16 48152]
R0 iorate;iorate;C:\WINDOWS\System32\drivers\iorate.sys [2016-11-8 48992]
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\WINDOWS\System32\drivers\tos_sps64.sys [2012-11-22 499096]
R0 volume;Volume driver;C:\WINDOWS\System32\drivers\volume.sys [2016-7-16 16224]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [2016-7-16 107032]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [2016-7-16 17944]
R0 Wof;Windows Overlay File System Filter Driver;C:\WINDOWS\System32\drivers\wof.sys [2016-9-18 199008]
R1 ahcache;Application Compatibility Cache;C:\WINDOWS\System32\drivers\ahcache.sys [2016-10-28 227328]
R1 eamonm;eamonm;C:\WINDOWS\System32\drivers\eamonm.sys [2015-1-30 262792]
R1 FileCrypt;FileCrypt;C:\WINDOWS\System32\drivers\filecrypt.sys [2016-7-16 88576]
R1 GpuEnergyDrv;GPU Energy Driver;C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2016-7-16 8192]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2017-3-17 83768]
R2 CDPSvc;Connected Devices Platform Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
R2 CDPUserSvc_2a6e9e7;CDPUserSvc_2a6e9e7;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R2 ClickToRunSvc;Microsoft Office ClickToRun Service;C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe [2014-3-20 3042032]
R2 clreg;Virtual Registry for Containers;C:\WINDOWS\System32\drivers\registry.sys [2016-7-16 70144]
R2 CoreMessagingRegistrar;CoreMessaging;C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork [2016-7-16 44496]
R2 DbxSvc;DbxSvc;C:\WINDOWS\System32\DbxSvc.exe [2017-3-10 46408]
R2 DiagTrack;Connected User Experiences and Telemetry;C:\WINDOWS\System32\svchost.exe -k utcsvc [2016-7-16 44496]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2016-11-27 2770312]
R2 epfwwfpr;epfwwfpr;C:\WINDOWS\System32\drivers\epfwwfpr.sys [2015-1-30 181384]
R2 GFNEXSrv;GFNEX Service;C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe [2011-10-13 156672]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service;C:\WINDOWS\System32\igfxCUIService.exe [2016-5-3 337888]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-11-22 129856]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-11-22 166720]
R2 OneSyncSvc_2a6e9e7;Sync Host_2a6e9e7;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R2 PEGAGFN;PEGAGFN;C:\Program Files (x86)\TOSHIBA\Password Utility\PEGAGFN.sys [2009-9-11 14344]
R2 SplashtopRemoteService;Splashtop® Remote Service;C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe [2013-9-2 790368]
R2 SSUService;Splashtop Software Updater Service;C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe [2013-8-7 609056]
R2 storqosflt;Storage QoS Filter Driver;C:\WINDOWS\System32\drivers\storqosflt.sys [2016-7-16 78336]
R2 SynTPEnhService;SynTPEnh Caller Service;C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2015-9-12 246472]
R2 tiledatamodelsvc;Tile Data model server;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\TOSHIBA\Teco\TecoService.exe [2013-8-9 328544]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-11-22 365376]
R2 UserManager;User Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R2 wcifs;Windows Container Isolation;C:\WINDOWS\System32\drivers\wcifs.sys [2016-9-30 119648]
R2 wcnfs;Windows Container Name Virtualization;C:\WINDOWS\System32\drivers\wcnfs.sys [2016-7-16 66560]
R2 WDDMService;WDDMService;C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2011-3-9 288768]
R2 WDFME;WD File Management Engine;C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [2011-3-9 1066896]
R2 WDSC;WD File Management Shadow Engine;C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [2011-3-9 491920]
R2 WpnService;Windows Push Notifications System Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R3 AppXSvc;AppX Deployment Service (AppXSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2016-7-16 44496]
R3 DsSvc;Data Sharing Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
R3 IntcDAud;Intel(R) Display Audio;C:\WINDOWS\System32\drivers\IntcDAud.sys [2015-8-21 463112]
R3 iwdbus;IWD Bus Enumerator;C:\WINDOWS\System32\drivers\iwdbus.sys [2015-7-29 38896]
R3 lfsvc;Geolocation Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R3 LicenseManager;Windows License Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
R3 NcbService;Network Connection Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [2016-7-16 20480]
R3 PimIndexMaintenanceSvc_2a6e9e7;Contact Data_2a6e9e7;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R3 rt640x64;Realtek RT640 NT Driver;C:\WINDOWS\System32\drivers\rt640x64.sys [2016-7-16 589824]
R3 rtwlane_13;Realtek Wireless LAN 802.11n PCI-E Network Adapter;C:\WINDOWS\System32\drivers\rtwlane_13.sys [2016-7-16 3717120]
R3 SmbDrvI;SmbDrvI;C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [2015-9-12 42696]
R3 SmsRouter;Microsoft Windows SMS Router Service.;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
R3 StateRepository;State Repository Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
R3 TimeBrokerSvc;Time Broker;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
R3 TPCHSrv;TPCH Service;C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2013-9-4 466504]
R3 UnistoreSvc_2a6e9e7;User Data Storage_2a6e9e7;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R3 UserDataSvc_2a6e9e7;User Data Access_2a6e9e7;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R3 WSDScan;WSD Scan Support;C:\WINDOWS\System32\drivers\WSDScan.sys [2016-7-16 24576]
S0 eelam;eelam;C:\WINDOWS\System32\drivers\eelam.sys [2015-7-30 15488]
S2 dbupdate;Dropbox Update Service (dbupdate);C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-3-7 143144]
S2 DoSvc;Delivery Optimization;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S2 GamesAppIntegrationService;GamesAppIntegrationService;C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [2013-12-16 227904]
S2 MapsBroker;Downloaded Maps Manager;C:\WINDOWS\System32\svchost.exe -k NetworkService [2016-7-16 44496]
S3 AcpiDev;ACPI Devices driver;C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-7-16 18432]
S3 ADP80XX;ADP80XX;C:\WINDOWS\System32\drivers\adp80xx.sys [2016-7-16 1135456]
S3 AJRouter;AllJoyn Router Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
S3 applockerfltr;Smartlocker Filter Driver;C:\WINDOWS\System32\drivers\applockerfltr.sys [2016-7-16 15360]
S3 AppReadiness;App Readiness;C:\WINDOWS\System32\svchost.exe -k AppReadiness [2016-7-16 44496]
S3 bcmfn;bcmfn Service;C:\WINDOWS\System32\drivers\bcmfn.sys [2016-7-16 9728]
S3 bcmfn2;bcmfn2 Service;C:\WINDOWS\System32\drivers\bcmfn2.sys [2016-7-16 9728]
S3 BthHFSrv;Bluetooth Handsfree Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation [2016-7-16 44496]
S3 buttonconverter;Service for Portable Device Control devices;C:\WINDOWS\System32\drivers\buttonconverter.sys [2016-7-16 38912]
S3 CapImg;HID driver for CapImg touch screen;C:\WINDOWS\System32\drivers\capimg.sys [2016-10-28 118272]
S3 cht4iscsi;cht4iscsi;C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-7-16 346976]
S3 cht4vbd;Chelsio Virtual Bus Driver;C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-7-16 2104160]
S3 ClipSVC;Client License Service (ClipSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2016-7-16 44496]
S3 dbupdatem;Dropbox Update Service (dbupdatem);C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-3-7 143144]
S3 DcpSvc;DataCollectionPublishingService;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 DevQueryBroker;DevQuery Background Discovery Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 diagnosticshub.standardcollector.service;Microsoft (R) Diagnostics Hub Standard Collector Service;C:\WINDOWS\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2016-7-16 93184]
S3 DmEnrollmentSvc;Device Management Enrollment Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 dmwappushservice;dmwappushsvc;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 embeddedmode;Embedded Mode;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 EntAppSvc;Enterprise App Management Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
S3 FrameServer;Windows Camera Frame Server;C:\WINDOWS\System32\svchost.exe -k Camera [2016-7-16 44496]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 genericusbfn;Generic USB Function Class;C:\WINDOWS\System32\drivers\genericusbfn.sys [2016-7-16 20480]
S3 hidinterrupt;Common Driver for HID Buttons implemented with interrupts;C:\WINDOWS\System32\drivers\hidinterrupt.sys [2016-7-16 50016]
S3 HvHost;HV Host Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 iagpio;Intel Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iagpio.sys [2016-7-16 33280]
S3 iai2c;Intel(R) Serial IO I2C Host Controller;C:\WINDOWS\System32\drivers\iai2c.sys [2016-7-16 81408]
S3 iaLPSS2i_GPIO2;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-7-16 64512]
S3 iaLPSS2i_I2C;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2016-7-16 176384]
S3 iaLPSSi_GPIO;Intel(R) Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [2016-7-16 38128]
S3 iaLPSSi_I2C;Intel(R) Serial IO I2C Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [2016-7-16 113152]
S3 iaStorAV;Intel(R) SATA RAID Controller Windows;C:\WINDOWS\System32\drivers\iaStorAV.sys [2016-7-16 673120]
S3 ibbus;Mellanox InfiniBand Bus/AL (Filter Driver);C:\WINDOWS\System32\drivers\ibbus.sys [2016-7-16 526176]
S3 icssvc;Windows Mobile Hotspot Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
S3 IndirectKmd;Indirect Displays Kernel-Mode Driver;C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-7-16 35840]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\WINDOWS\System32\drivers\intelaud.sys [2015-12-1 50160]
S3 LSI_SAS2i;LSI_SAS2i;C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2016-7-16 105824]
S3 LSI_SAS3i;LSI_SAS3i;C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2016-7-16 101216]
S3 megasas2i;megasas2i;C:\WINDOWS\System32\drivers\MegaSas2i.sys [2016-10-11 64352]
S3 MessagingService_2a6e9e7;MessagingService_2a6e9e7;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
S3 mlx4_bus;Mellanox ConnectX Bus Enumerator;C:\WINDOWS\System32\drivers\mlx4_bus.sys [2016-7-16 842584]
S3 ndfltr;NetworkDirect Service;C:\WINDOWS\System32\drivers\ndfltr.sys [2016-7-16 108896]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library;C:\WINDOWS\System32\drivers\NetAdapterCx.sys [2016-7-16 90624]
S3 NetSetupSvc;Network Setup Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 NgcCtnrSvc;Microsoft Passport Container;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
S3 NgcSvc;Microsoft Passport;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 percsas2i;percsas2i;C:\WINDOWS\System32\drivers\percsas2i.sys [2016-7-16 58720]
S3 percsas3i;percsas3i;C:\WINDOWS\System32\drivers\percsas3i.sys [2016-7-16 61792]
S3 PhoneSvc;Phone Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
S3 ReFSv1;ReFSv1;C:\WINDOWS\System32\drivers\refsv1.sys [2016-7-16 928608]
S3 RetailDemo;Retail Demo Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\WINDOWS\System32\drivers\RtsUStor.sys [2012-11-22 252048]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 scmbus;Microsoft Storage Class Memory Bus Driver;C:\WINDOWS\System32\drivers\scmbus.sys [2016-7-16 88416]
S3 scmdisk0101;Microsoft NVDIMM-N disk driver;C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-7-16 123904]
S3 SensorDataService;Sensor Data Service;C:\WINDOWS\System32\SensorDataService.exe [2017-3-15 1312768]
S3 SensorService;Sensor Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 SerCx2;Serial UART Support Library;C:\WINDOWS\System32\drivers\SerCx2.sys [2016-7-16 151904]
S3 smphost;Microsoft Storage Spaces SMP;C:\WINDOWS\System32\svchost.exe -k smphost [2016-7-16 44496]
S3 stornvme;Microsoft Standard NVM Express Driver;C:\WINDOWS\System32\drivers\stornvme.sys [2016-9-30 81760]
S3 storufs;Microsoft Universal Flash Storage (UFS) Driver;C:\WINDOWS\System32\drivers\storufs.sys [2016-7-16 32096]
S3 TieringEngineService;Storage Tiers Management;C:\WINDOWS\System32\TieringEngineService.exe [2016-7-16 287744]
S3 TMachInfo;TMachInfo;C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2013-7-31 53864]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmCx.sys [2016-7-16 95744]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmTcpciCx.sys [2016-7-16 108544]
S3 UcmUcsi;USB Connector Manager UCSI Client;C:\WINDOWS\System32\drivers\UcmUcsi.sys [2016-7-16 50688]
S3 UdeCx;USB Device Emulation Support Library;C:\WINDOWS\System32\drivers\Udecx.sys [2016-7-16 45568]
S3 UEFI;Microsoft UEFI Driver;C:\WINDOWS\System32\drivers\uefi.sys [2016-7-16 28512]
S3 Ufx01000;USB Function Class Extension;C:\WINDOWS\System32\drivers\ufx01000.sys [2016-7-16 263008]
S3 UfxChipidea;USB Chipidea Controller;C:\WINDOWS\System32\drivers\UfxChipidea.sys [2016-7-16 96608]
S3 ufxsynopsys;USB Synopsys Controller;C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2016-7-16 137056]
S3 UrsChipidea;Chipidea USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urschipidea.sys [2016-7-16 28512]
S3 UrsCx01000;USB Role-Switch Support Library;C:\WINDOWS\System32\drivers\urscx01000.sys [2016-7-16 57696]
S3 UrsSynopsys;Synopsys USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urssynopsys.sys [2016-7-16 27488]
S3 USBAAPL64;Apple Mobile USB Driver;C:\WINDOWS\System32\drivers\usbaapl64.sys [2015-6-10 54784]
S3 UsoSvc;Update Orchestrator Service for Windows Update;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 vhf;Virtual HID Framework (VHF) Driver;C:\WINDOWS\System32\drivers\vhf.sys [2016-7-16 32256]
S3 vmgid;Microsoft Hyper-V Guest Infrastructure Driver;C:\WINDOWS\System32\drivers\vmgid.sys [2016-7-16 10240]
S3 vmicguestinterface;Hyper-V Guest Service Interface;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 vmicvmsession;Hyper-V PowerShell Direct Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 WalletService;WalletService;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\System32\drivers\wdcsam64.sys [2015-4-30 26880]
S3 wdiwifi;WDI Driver Framework;C:\WINDOWS\System32\drivers\WdiWiFi.sys [2017-3-15 719872]
S3 WdNisDrv;Windows Defender Network Inspection System Driver;C:\WINDOWS\System32\drivers\WdNisDrv.sys [2016-7-16 123232]
S3 WdNisSvc;Windows Defender Network Inspection Service;C:\Program Files\Windows Defender\NisSrv.exe [2016-7-16 347328]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;C:\WINDOWS\System32\svchost.exe -k WepHostSvcGroup [2016-7-16 44496]
S3 WinMad;WinMad Service;C:\WINDOWS\System32\drivers\winmad.sys [2016-7-16 32096]
S3 WinVerbs;WinVerbs Service;C:\WINDOWS\System32\drivers\winverbs.sys [2016-7-16 64864]
S3 wisvc;Windows Insider Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 workfolderssvc;Work Folders;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
S3 WpnUserService_2a6e9e7;Windows Push Notifications User Service_2a6e9e7;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
S3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\drivers\WUDFRd.sys [2016-7-16 216064]
S3 XblAuthManager;Xbox Live Auth Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 XblGameSave;Xbox Live Game Save;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 xboxgip;Xbox Game Input Protocol Driver;C:\WINDOWS\System32\drivers\xboxgip.sys [2017-3-15 258560]
S3 XboxNetApiSvc;Xbox Live Networking Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 xinputhid;XINPUT HID Filter Driver;C:\WINDOWS\System32\drivers\xinputhid.sys [2016-9-18 43520]
S4 shpamsvc;Shared PC Account Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S4 tzautoupdate;Auto Time Zone Updater;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
.
=============== Created Last 30 ================
.
2017-04-05 13:42:49 -------- d--h--w- C:\OneDriveTemp
2017-04-03 04:46:53 -------- d-----w- C:\WINDOWS\Panther
2017-04-02 17:43:07 -------- d-----w- C:\Program Files (x86)\Kodi
2017-04-02 05:58:22 -------- d-----w- C:\Users\Alain\AppData\Roaming\Kodi
2017-03-25 12:02:49 -------- d-----w- C:\Program Files\iPod
2017-03-25 12:02:48 -------- d---a-w- C:\Program Files\iTunes
2017-03-15 17:20:08 6667528 ----a-w- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
2017-03-15 17:20:07 5722320 ----a-w- C:\WINDOWS\SysWow64\windows.storage.dll
2017-03-15 17:20:06 5685760 ----a-w- C:\WINDOWS\SysWow64\Windows.Data.Pdf.dll
2017-03-15 17:20:05 6109184 ----a-w- C:\WINDOWS\SysWow64\mos.dll
2017-03-15 17:20:05 13873664 ----a-w- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
2017-03-15 17:20:04 3307008 ----a-w- C:\WINDOWS\SysWow64\MFMediaEngine.dll
2017-03-15 17:20:03 5380608 ----a-w- C:\WINDOWS\SysWow64\BingMaps.dll
2017-03-15 17:20:02 2643456 ----a-w- C:\WINDOWS\SysWow64\tquery.dll
2017-03-15 17:20:02 2483200 ----a-w- C:\WINDOWS\SysWow64\wininet.dll
2017-03-15 17:20:00 2646528 ----a-w- C:\WINDOWS\SysWow64\CertEnroll.dll
2017-03-15 17:18:59 783360 ----a-w- C:\WINDOWS\SysWow64\TSWorkspace.dll
2017-03-15 17:17:59 8076288 ----a-w- C:\WINDOWS\System32\mstscax.dll
2017-03-15 17:16:59 825024 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe
2017-03-15 17:15:59 95232 ----a-w- C:\WINDOWS\System32\tzautoupdate.dll
2017-03-15 17:14:49 8886976 ----a-w- C:\WINDOWS\SysWow64\OneDriveSetup.exe
2017-03-10 23:17:46 46408 ----a-w- C:\WINDOWS\System32\DbxSvc.exe
2017-03-10 23:17:46 45672 ----a-w- C:\WINDOWS\System32\drivers\dbx-stable.sys
2017-03-10 23:17:46 45672 ----a-w- C:\WINDOWS\System32\drivers\dbx-dev.sys
2017-03-10 23:17:46 45672 ----a-w- C:\WINDOWS\System32\drivers\dbx-canary.sys
2017-03-07 15:24:00 -------- d-----w- C:\Program Files (x86)\Dropbox
2017-03-07 15:23:55 -------- d-----w- C:\Users\Alain\AppData\Local\Dropbox
2017-03-07 15:23:55 -------- d-----w- C:\ProgramData\Dropbox
.
==================== Find3M ====================
.
2017-03-10 05:17:56 835576 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2017-03-10 05:17:56 177656 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2017-03-04 07:57:44 192352 ----a-w- C:\WINDOWS\SysWow64\aepic.dll
2017-03-04 07:57:43 315744 ----a-w- C:\WINDOWS\SysWow64\atmfd.dll
2017-03-04 07:57:40 484584 ----a-w- C:\WINDOWS\SysWow64\AudioSes.dll
2017-03-04 07:40:53 965472 ----a-w- C:\WINDOWS\SysWow64\ReAgent.dll
2017-03-04 07:35:25 142176 ----a-w- C:\WINDOWS\System32\acmigration.dll
2017-03-04 07:35:25 1294688 ----a-w- C:\WINDOWS\System32\aeinv.dll
2017-03-04 07:35:22 86368 ----a-w- C:\WINDOWS\System32\CompatTelRunner.exe
2017-03-04 07:35:22 655200 ----a-w- C:\WINDOWS\System32\generaltel.dll
2017-03-04 07:35:22 565088 ----a-w- C:\WINDOWS\System32\devinv.dll
2017-03-04 07:35:22 343904 ----a-w- C:\WINDOWS\System32\invagent.dll
2017-03-04 07:35:22 1617760 ----a-w- C:\WINDOWS\System32\appraiser.dll
2017-03-04 07:35:21 378720 ----a-w- C:\WINDOWS\System32\atmfd.dll
2017-03-04 07:35:21 242528 ----a-w- C:\WINDOWS\System32\aepic.dll
2017-03-04 07:35:15 590952 ----a-w- C:\WINDOWS\System32\AudioSes.dll
2017-03-04 07:35:09 38240 ----a-w- C:\WINDOWS\System32\DeviceCensus.exe
2017-03-04 07:35:09 315232 ----a-w- C:\WINDOWS\System32\dcntel.dll
2017-03-04 07:27:09 603488 ----a-w- C:\WINDOWS\System32\ContentDeliveryManager.Utilities.dll
2017-03-04 07:26:53 794416 ----a-w- C:\WINDOWS\System32\Windows.Internal.Shell.Broker.dll
2017-03-04 07:25:44 1117024 ----a-w- C:\WINDOWS\System32\ReAgent.dll
2017-03-04 07:24:33 90976 ----a-w- C:\WINDOWS\System32\drivers\IPMIDrv.sys
2017-03-04 07:24:33 354264 ----a-w- C:\WINDOWS\System32\systemreset.exe
2017-03-04 07:24:27 108384 ----a-w- C:\WINDOWS\System32\drivers\pdc.sys
2017-03-04 07:24:23 894096 ----a-w- C:\WINDOWS\System32\winresume.exe
2017-03-04 07:24:20 1051112 ----a-w- C:\WINDOWS\System32\winresume.efi
2017-03-04 07:24:05 2186896 ----a-w- C:\WINDOWS\System32\hevcdecoder.dll
2017-03-04 07:24:04 2482280 ----a-w- C:\WINDOWS\System32\msmpeg2vdec.dll
2017-03-04 07:23:13 2512304 ----a-w- C:\WINDOWS\System32\WMVDECOD.DLL
2017-03-04 07:22:41 2213760 ----a-w- C:\WINDOWS\System32\KernelBase.dll
2017-03-04 07:22:22 1354312 ----a-w- C:\WINDOWS\System32\winload.efi
2017-03-04 07:22:22 1172984 ----a-w- C:\WINDOWS\System32\winload.exe
2017-03-04 07:22:21 7786336 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2017-03-04 07:21:04 2255712 ----a-w- C:\WINDOWS\System32\drivers\ntfs.sys
2017-03-04 07:20:52 379744 ----a-w- C:\WINDOWS\System32\drivers\Classpnp.sys
2017-03-04 07:20:50 128352 ----a-w- C:\WINDOWS\System32\drivers\partmgr.sys
2017-03-04 07:19:11 2681200 ----a-w- C:\WINDOWS\System32\CoreUIComponents.dll
2017-03-04 07:19:02 2049480 ----a-w- C:\WINDOWS\System32\wmpmde.dll
2017-03-04 07:18:48 764392 ----a-w- C:\WINDOWS\System32\CoreMessaging.dll
2017-03-04 07:18:47 1181024 ----a-w- C:\WINDOWS\System32\drivers\ndis.sys
2017-03-04 07:18:27 118624 ----a-w- C:\WINDOWS\System32\drivers\tdx.sys
2017-03-04 07:17:22 409952 ----a-w- C:\WINDOWS\System32\drivers\FWPKCLNT.SYS
2017-03-04 07:15:25 63328 ----a-w- C:\WINDOWS\System32\drivers\dam.sys
2017-03-04 07:15:14 404320 ----a-w- C:\WINDOWS\System32\WinSetupUI.dll
2017-03-04 07:15:08 1000280 ----a-w- C:\WINDOWS\System32\SecConfig.efi
2017-03-04 07:13:27 635456 ----a-w- C:\WINDOWS\System32\ci.dll
2017-03-04 07:11:48 328008 ----a-w- C:\WINDOWS\System32\Windows.Storage.ApplicationData.dll
2017-03-04 07:11:41 266544 ----a-w- C:\WINDOWS\System32\policymanager.dll
2017-03-04 07:10:08 360040 ----a-w- C:\WINDOWS\System32\SystemSettingsAdminFlows.exe
2017-03-04 07:10:08 2828384 ----a-w- C:\WINDOWS\System32\d3d11.dll
2017-03-04 07:10:01 2189664 ----a-w- C:\WINDOWS\System32\drivers\dxgkrnl.sys
2017-03-04 07:08:59 130912 ----a-w- C:\WINDOWS\System32\drivers\storahci.sys
2017-03-04 07:08:20 342456 ----a-w- C:\WINDOWS\System32\wintrust.dll
2017-03-04 07:08:18 624048 ----a-w- C:\WINDOWS\System32\drivers\cng.sys
2017-03-04 07:08:17 509280 ----a-w- C:\WINDOWS\System32\drivers\storport.sys
2017-03-04 07:08:07 450400 ----a-w- C:\WINDOWS\System32\drivers\mrxsmb.sys
2017-03-04 07:08:02 223584 ----a-w- C:\WINDOWS\System32\drivers\mrxsmb20.sys
2017-03-04 07:06:36 1706488 ----a-w- C:\WINDOWS\SysWow64\KernelBase.dll
2017-03-04 07:04:33 2048496 ----a-w- C:\WINDOWS\SysWow64\CoreUIComponents.dll
2017-03-04 07:04:24 1362512 ----a-w- C:\WINDOWS\SysWow64\wmpmde.dll
2017-03-04 07:04:19 8169536 ----a-w- C:\WINDOWS\System32\Windows.Media.Protection.PlayReady.dll
2017-03-04 07:04:03 1063472 ----a-w- C:\WINDOWS\System32\mfds.dll
2017-03-04 07:01:57 137936 ----a-w- C:\WINDOWS\System32\AuthHost.exe
2017-03-04 07:01:53 128648 ----a-w- C:\WINDOWS\System32\gpapi.dll
2017-03-04 07:01:52 201568 ----a-w- C:\WINDOWS\System32\basecsp.dll
2017-03-04 06:59:01 1570208 ----a-w- C:\WINDOWS\System32\gdi32full.dll
2017-03-04 06:58:58 628552 ----a-w- C:\WINDOWS\System32\fontdrvhost.exe
2017-03-04 06:58:58 322912 ----a-w- C:\WINDOWS\System32\input.dll
2017-03-04 06:58:49 1416224 ----a-w- C:\WINDOWS\System32\msctf.dll
2017-03-04 06:57:36 2536288 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2017-03-04 06:57:26 372432 ----a-w- C:\WINDOWS\System32\Windows.Media.MediaControl.dll
2017-03-04 06:57:17 387872 ----a-w- C:\WINDOWS\System32\wmpps.dll
2017-03-04 06:56:04 263472 ----a-w- C:\WINDOWS\SysWow64\Windows.Storage.ApplicationData.dll
2017-03-04 06:56:03 248992 ----a-w- C:\WINDOWS\SysWow64\policymanager.dll
2017-03-04 06:54:12 2277288 ----a-w- C:\WINDOWS\SysWow64\d3d11.dll
2017-03-04 06:54:03 524776 ----a-w- C:\WINDOWS\SysWow64\dxgi.dll
2017-03-04 06:53:38 1431232 ----a-w- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.dll
2017-03-04 06:53:33 136032 ----a-w- C:\WINDOWS\SysWow64\CloudExperienceHostUser.dll
2017-03-04 06:53:19 781152 ----a-w- C:\WINDOWS\SysWow64\WWAHost.exe
2017-03-04 06:53:11 493912 ----a-w- C:\WINDOWS\SysWow64\SettingSyncHost.exe
2017-03-04 06:53:08 975744 ----a-w- C:\WINDOWS\SysWow64\twinapi.appcore.dll
2017-03-04 06:53:07 313568 ----a-w- C:\WINDOWS\SysWow64\wlanapi.dll
2017-03-04 06:53:03 861024 ----a-w- C:\WINDOWS\SysWow64\LicenseManager.dll
2017-03-04 06:52:59 549088 ----a-w- C:\WINDOWS\SysWow64\SHCore.dll
2017-03-04 06:52:02 272720 ----a-w- C:\WINDOWS\SysWow64\wintrust.dll
2017-03-04 06:51:38 576408 ----a-w- C:\WINDOWS\SysWow64\wer.dll
2017-03-04 06:51:37 1980768 ----a-w- C:\WINDOWS\SysWow64\msxml6.dll
2017-03-04 06:50:44 846560 ----a-w- C:\WINDOWS\SysWow64\WinTypes.dll
2017-03-04 06:46:40 4312248 ----a-w- C:\WINDOWS\SysWow64\explorer.exe
2017-03-04 06:46:40 321792 ----a-w- C:\WINDOWS\SysWow64\LockAppHost.exe
2017-03-04 06:45:15 173408 ----a-w- C:\WINDOWS\SysWow64\basecsp.dll
2017-03-04 06:45:07 112120 ----a-w- C:\WINDOWS\SysWow64\gpapi.dll
2017-03-04 06:42:57 7216640 ----a-w- C:\WINDOWS\System32\Windows.Data.Pdf.dll
2017-03-04 06:42:41 276832 ----a-w- C:\WINDOWS\SysWow64\input.dll
2017-03-04 06:42:39 1415240 ----a-w- C:\WINDOWS\SysWow64\gdi32full.dll
2017-03-04 06:42:35 321888 ----a-w- C:\WINDOWS\apppatch\AcRes.dll
2017-03-04 06:42:30 545944 ----a-w- C:\WINDOWS\SysWow64\fontdrvhost.exe
2017-03-04 06:42:29 1260784 ----a-w- C:\WINDOWS\SysWow64\msctf.dll
2017-03-04 06:40:36 306800 ----a-w- C:\WINDOWS\SysWow64\Windows.Media.MediaControl.dll
2017-03-04 06:39:58 372736 ----a-w- C:\WINDOWS\System32\RDXTaskFactory.dll
.
============= FINISH: 8:18:36.97 ===============

I do not have access to a boot disc or OS disc. I upgraded my Win 8 to Win 10.
My pc is slower than usual and when I delete my internet history it does not eliminate the history at all. I use eset nod 32 and it has worked very well over the last 2-4 years. Looking forward to your help.

Attached Files
File Type: txt attach.txt (10.2 KB)

Laptop extremely slow, disk usage 100%, hangs randomly

$
0
0
Hi everyone,

I'm not sure if this is the right place to start the thread, but I didn't know where else I should post it, so.

My laptop has become extremely slow during booting and regular use. I can easily get a cup of coffee across the street during booting time and by the time I come back, my laptop might still not be ready...

The booting itself is not the problem; the login screen shows up in about 40 seconds (in comparison to everything else, this is really fast). After logging in, actually, it takes almost 10 minutes before I can normally use the laptop. I tried opening programs earlier than the 10-min wait, but the laptop simply doesn't respond or opens the program 2 mins later (which immediately says 'doesn't respond').

Some specs:
Dell Inspiron 15 N5050
bought July 2012 (Windows 7), upgraded to Windows 10 in 2015
Processor: Intel (R) Celeron(R) CPU B815 @ 1.60 GHz
RAM: 3 GB
Hard Disk: 320 GB
64-bit Operating System

I ranAdwCleaner which had no result. I have AVG Free 2017 installed as AntiVirus program and ZoneAlarm as Firewall. I also ran Malwarebytes and the Sophos Virus Removal Tool; No threats were found.

Maybe the laptop is just getting old and I simply need to buy a new one? I hope someone can help me get the old thing back on track again, 'cause it still looks decent and other than the speed/performance issue, it always has worked fine!

Thanks in advance.
Jissie14

Problem with webpages switching without doing something

$
0
0
I wonder if anyone else is having or had this problem, I am running win 10 on my laptop and strange things are happening for example when I am in FB and start typing a comment suddenly I get another website coming up in the Laptop or if I playing a game like "hearts of vegas" it will suddenly switch to another site which has no relevance to game site, I use Chrome mainly but it does happen in microsoft edge and firefox but less frequently, it opens up a new tab or opens an existing tab never an advert
Any help and advice will be much appreciated :confused:
I am attaching an echo report obtain just after one of the switches

Attached Files
File Type: txt Command Echo 2.txt (35.6 KB)

Hijacked system - cannot run virus/malware scanners

$
0
0
It appears my system has been hijacked. I've tried a few old tricks from years ago to clean things up, and of course they don't work now. Windows defender has been disabled and I can't enable it, Malwarebytes can't find anything after running Rkill, Avast cannot load or update and I have drive by pop ups all over the place. :facepalm:

Here are the . DDS logs

DDS (Ver_2012-11-20.01) - NTFS_x86 NETWORK
Internet Explorer: 11.0.14393.953 BrowserJavaVersion: 11.101.2
Run by Owner at 7:28:10 on 2017-04-15
Microsoft Windows 10 Home 10.0.14393.0.1252.1.1033.18.2005.1127 [GMT -6:00]
.
AV: Avast Antivirus *Enabled/Updated* {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Avast Antivirus *Enabled/Updated* {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
FW: Avast Antivirus *Enabled* {B693136B-F6EE-DD1C-A0EF-229B8B0B29C4}
.
============== Running Processes ================
.
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\WINDOWS\system32\DllHost.exe
C:\Windows\helppane.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\Macromed\Flash\FlashPlayerPlugin_25_0_0_127.exe
C:\WINDOWS\system32\Macromed\Flash\FlashPlayerPlugin_25_0_0_127.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Windows\System32\smartscreen.exe
C:\WINDOWS\system32\conhost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://www.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
uSearch Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - <orphaned>
BHO: True Key Helper: {0F4B8786-5502-4803-8EBC-F652A1153BB6} - c:\program files\intel security\true key\msie\truekey_ie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.8.0_101\bin\ssv.dll
BHO: {9030D464-4C02-4ABF-8ECC-5164760863C6} - <orphaned>
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - <orphaned>
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre1.8.0_101\bin\jp2ssv.dll
TB: True Key: {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - c:\program files\intel security\true key\msie\truekey_ie.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [Dropbox Update] "c:\users\owner\appdata\local\dropbox\update\DropboxUpdate.exe" /c
uRun: [OneDrive] "c:\users\owner\appdata\local\microsoft\onedrive\OneDrive.exe" /background
uRun: [iCloudServices] "c:\program files\common files\apple\internet services\iCloudServices.exe"
uRun: [CCleaner Monitoring] "c:\program files\ccleaner\CCleaner.exe" /MONITOR
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [AvastUI.exe] "c:\program files\alwil software\avast5\AvLaunch.exe" /gui
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\owner\appdata\roaming\dropbox\bin\Dropbox.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.11.523\SSScheduler.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: DSCAutomationHostEnabled = dword:2
mPolicies-System: SoftwareSASGeneration = dword:1
IE: E&xport to Microsoft Excel - c:\program files\microsoft office\office11\EXCEL.EXE/3000
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - <orphaned>
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_45-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-0045-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_45-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_45-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 192.168.0.1 205.171.2.25
TCP: Interfaces\{30e2b29c-cd72-4dea-8c4e-a51cf9117d04} : DHCPNameServer = 192.168.0.1 205.171.2.25
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - <orphaned>
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - c:\windows\system32\tbauth.dll
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - c:\windows\system32\tbauth.dll
SSODL: WebCheck - <orphaned>
LSA: Notification Packages = scecli c:\program files\truekey\McAfeeTrueKeyPasswordFilter
mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\57.0.2987.133\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - c:\windows\system32\windows.storage.dll
Hosts: 0.0.0.1 mssplus.mcafee.com
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\hi7x2ycl.default\
FF - plugin: c:\program files\adobe\acrobat reader dc\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.33.3\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre1.8.0_101\bin\dtplugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre1.8.0_101\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.50906.0\npctrlui.dll
FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1228198.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_22_0_0_209.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_25_0_0_127.dll
.
============= SERVICES / DRIVERS ===============
.
R0 intelpep;Intel(R) Power Engine Plug-in Driver;c:\windows\system32\drivers\intelpep.sys [2016-7-16 42520]
R0 iorate;iorate;c:\windows\system32\drivers\iorate.sys [2016-11-8 42336]
R0 volume;Volume driver;c:\windows\system32\drivers\volume.sys [2016-7-16 14176]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;c:\windows\system32\drivers\WindowsTrustedRT.sys [2016-7-16 86040]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;c:\windows\system32\drivers\WindowsTrustedRTProxy.sys [2016-7-16 15384]
R0 Wof;Windows Overlay File System Filter Driver;c:\windows\system32\drivers\wof.sys [2016-9-25 173408]
R1 ahcache;Application Compatibility Cache;c:\windows\system32\drivers\ahcache.sys [2016-10-28 188928]
R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2012-4-29 31064]
R1 aswNetSec;aswNetSec;c:\windows\system32\drivers\aswNetSec.sys [2016-3-17 388488]
R2 CoreMessagingRegistrar;CoreMessaging;c:\windows\system32\svchost.exe -k LocalServiceNoNetwork [2016-7-16 38792]
R2 tiledatamodelsvc;Tile Data model server;c:\windows\system32\svchost.exe -k appmodel [2016-7-16 38792]
R2 UserManager;User Manager;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
R3 ADP80XX;ADP80XX;c:\windows\system32\drivers\adp80xx.sys [2016-7-16 1038176]
R3 iaStorAV;Intel(R) SATA RAID Controller Windows;c:\windows\system32\drivers\iaStorAV.sys [2016-7-16 524640]
R3 LSI_SAS2i;LSI_SAS2i;c:\windows\system32\drivers\lsi_sas2i.sys [2016-7-16 89952]
R3 LSI_SAS3i;LSI_SAS3i;c:\windows\system32\drivers\lsi_sas3i.sys [2016-7-16 85856]
R3 megasas2i;megasas2i;c:\windows\system32\drivers\MegaSas2i.sys [2016-10-11 56672]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;c:\windows\system32\drivers\NdisVirtualBus.sys [2016-7-16 15872]
R3 percsas2i;percsas2i;c:\windows\system32\drivers\percsas2i.sys [2016-7-16 51552]
R3 percsas3i;percsas3i;c:\windows\system32\drivers\percsas3i.sys [2016-7-16 54624]
R3 rt640x86;Realtek RT640 NT Driver;c:\windows\system32\drivers\rt640x86.sys [2016-7-16 494080]
R3 StateRepository;State Repository Service;c:\windows\system32\svchost.exe -k appmodel [2016-7-16 38792]
R3 stornvme;Microsoft Standard NVM Express Driver;c:\windows\system32\drivers\stornvme.sys [2016-7-16 66912]
R3 storufs;Microsoft Universal Flash Storage (UFS) Driver;c:\windows\system32\drivers\storufs.sys [2016-7-16 26976]
S1 aswbidsdriver;aswbidsdriver;c:\windows\system32\drivers\aswbidsdriverx.sys [2017-3-15 255184]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-9-3 764064]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-9-3 472760]
S1 FileCrypt;FileCrypt;c:\windows\system32\drivers\filecrypt.sys [2016-7-16 77312]
S1 GpuEnergyDrv;GPU Energy Driver;c:\windows\system32\drivers\gpuenergydrv.sys [2016-7-16 7680]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-9-3 106904]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-2-20 118800]
S2 avast! Antivirus;Avast Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2017-4-5 261712]
S2 avast! Firewall;Avast Firewall Service;c:\program files\alwil software\avast5\afwServ.exe [2017-4-5 310496]
S2 CDPSvc;Connected Devices Platform Service;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
S2 CDPUserSvc_18d5c;CDPUserSvc_18d5c;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
S2 clreg;Virtual Registry for Containers;c:\windows\system32\drivers\registry.sys [2016-7-16 58368]
S2 DiagTrack;Connected User Experiences and Telemetry;c:\windows\system32\svchost.exe -k utcsvc [2016-7-16 38792]
S2 DoSvc;Delivery Optimization;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S2 Fitbit Connect;Fitbit Connect Service;c:\program files\fitbit connect\FitbitConnectService.exe [2014-5-19 1436192]
S2 InstallerService;Service Installer TrueKey;c:\program files\truekey\mcafee.truekey.installerservice.exe -originalversion 4.4.127.0 --> c:\program files\truekey\Mcafee.TrueKey.InstallerService.exe -originalversion 4.4.127.0 [?]
S2 MapsBroker;Downloaded Maps Manager;c:\windows\system32\svchost.exe -k NetworkService [2016-7-16 38792]
S2 OneSyncSvc_18d5c;Sync Host_18d5c;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2017-2-27 317400]
S2 storqosflt;Storage QoS Filter Driver;c:\windows\system32\drivers\storqosflt.sys [2016-7-16 62976]
S2 TrueKey;Intel Security True Key;c:\program files\truekey\McAfee.TrueKey.Service.exe [2017-4-14 997360]
S2 TrueKeyScheduler;Intel Security True Key Scheduler;c:\program files\truekey\McTkSchedulerService.exe [2017-1-20 17304]
S2 wcifs;Windows Container Isolation;c:\windows\system32\drivers\wcifs.sys [2016-9-29 95072]
S2 wcnfs;Windows Container Name Virtualization;c:\windows\system32\drivers\wcnfs.sys [2016-7-16 52736]
S2 WpnService;Windows Push Notifications System Service;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 AcpiDev;ACPI Devices driver;c:\windows\system32\drivers\AcpiDev.sys [2016-7-16 12800]
S3 AJRouter;AllJoyn Router Service;c:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 38792]
S3 applockerfltr;Smartlocker Filter Driver;c:\windows\system32\drivers\applockerfltr.sys [2016-7-16 12288]
S3 AppReadiness;App Readiness;c:\windows\system32\svchost.exe -k AppReadiness [2016-7-16 38792]
S3 AppXSvc;AppX Deployment Service (AppXSVC);c:\windows\system32\svchost.exe -k wsappx [2016-7-16 38792]
S3 aswbIDSAgent;aswbIDSAgent;c:\program files\alwil software\avast5\aswidsagent.exe [2017-4-5 5758120]
S3 aswHwid;aswHwid;c:\windows\system32\drivers\aswHwid.sys [2014-4-29 34136]
S3 bcmfn;bcmfn Service;c:\windows\system32\drivers\bcmfn.sys [2016-7-16 8192]
S3 bcmfn2;bcmfn2 Service;c:\windows\system32\drivers\bcmfn2.sys [2016-7-16 8192]
S3 BthHFSrv;Bluetooth Handsfree Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2016-7-16 38792]
S3 buttonconverter;Service for Portable Device Control devices;c:\windows\system32\drivers\buttonconverter.sys [2016-7-16 27648]
S3 CapImg;HID driver for CapImg touch screen;c:\windows\system32\drivers\capimg.sys [2016-10-28 97792]
S3 ClipSVC;Client License Service (ClipSVC);c:\windows\system32\svchost.exe -k wsappx [2016-7-16 38792]
S3 DcpSvc;DataCollectionPublishingService;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 DevQueryBroker;DevQuery Background Discovery Broker;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 diagnosticshub.standardcollector.service;Microsoft (R) Diagnostics Hub Standard Collector Service;c:\windows\system32\diagsvcs\DiagnosticsHub.StandardCollector.Service.exe [2016-7-16 69632]
S3 DmEnrollmentSvc;Device Management Enrollment Service;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 dmwappushservice;dmwappushsvc;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 DsSvc;Data Sharing Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 embeddedmode;Embedded Mode;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 EntAppSvc;Enterprise App Management Service;c:\windows\system32\svchost.exe -k appmodel [2016-7-16 38792]
S3 FrameServer;Windows Camera Frame Server;c:\windows\system32\svchost.exe -k Camera [2016-7-16 38792]
S3 genericusbfn;Generic USB Function Class;c:\windows\system32\drivers\genericusbfn.sys [2016-7-16 17920]
S3 GPIO;Intel SoC GPIO Controller Driver;c:\windows\system32\drivers\iaiogpio.sys [2016-7-16 22016]
S3 hidinterrupt;Common Driver for HID Buttons implemented with interrupts;c:\windows\system32\drivers\hidinterrupt.sys [2016-7-16 38240]
S3 iagpio;Intel Serial IO GPIO Controller Driver;c:\windows\system32\drivers\iagpio.sys [2016-7-16 25600]
S3 iai2c;Intel(R) Serial IO I2C Host Controller;c:\windows\system32\drivers\iai2c.sys [2016-7-16 66560]
S3 iaioi2c;Intel(R) Atom(TM) Processor I2C Controller Service;c:\windows\system32\drivers\iaioi2c.sys [2016-7-16 61936]
S3 icssvc;Windows Mobile Hotspot Service;c:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 38792]
S3 IndirectKmd;Indirect Displays Kernel-Mode Driver;c:\windows\system32\drivers\IndirectKmd.sys [2016-7-16 30208]
S3 lfsvc;Geolocation Service;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 LicenseManager;Windows License Manager Service;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\3.11.523\McCHSvc.exe [2017-3-20 321768]
S3 MessagingService_18d5c;MessagingService_18d5c;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
S3 NcbService;Network Connection Broker;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library;c:\windows\system32\drivers\NetAdapterCx.sys [2016-7-16 62976]
S3 NetSetupSvc;Network Setup Service;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 NgcCtnrSvc;Microsoft Passport Container;c:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 38792]
S3 NgcSvc;Microsoft Passport;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 PhoneSvc;Phone Service;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
S3 PimIndexMaintenanceSvc_18d5c;Contact Data_18d5c;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
S3 RetailDemo;Retail Demo Service;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 SensorDataService;Sensor Data Service;c:\windows\system32\SensorDataService.exe [2017-3-15 894976]
S3 SensorService;Sensor Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 SerCx2;Serial UART Support Library;c:\windows\system32\drivers\SerCx2.sys [2016-7-16 117600]
S3 smphost;Microsoft Storage Spaces SMP;c:\windows\system32\svchost.exe -k smphost [2016-7-16 38792]
S3 SmsRouter;Microsoft Windows SMS Router Service.;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 TieringEngineService;Storage Tiers Management;c:\windows\system32\TieringEngineService.exe [2016-7-16 253440]
S3 TimeBrokerSvc;Time Broker;c:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 38792]
S3 TrueKeyServiceHelper;Intel Security True Key Helper Service;c:\program files\truekey\McAfee.TrueKey.ServiceHelper.exe [2017-4-14 73968]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;c:\windows\system32\drivers\UcmCx.sys [2016-7-16 68608]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension;c:\windows\system32\drivers\UcmTcpciCx.sys [2016-7-16 76800]
S3 UcmUcsi;USB Connector Manager UCSI Client;c:\windows\system32\drivers\UcmUcsi.sys [2016-7-16 35840]
S3 UdeCx;USB Device Emulation Support Library;c:\windows\system32\drivers\Udecx.sys [2016-7-16 33280]
S3 UEFI;Microsoft UEFI Driver;c:\windows\system32\drivers\uefi.sys [2016-7-16 23392]
S3 Ufx01000;USB Function Class Extension;c:\windows\system32\drivers\ufx01000.sys [2016-7-16 205152]
S3 UfxChipidea;USB Chipidea Controller;c:\windows\system32\drivers\UfxChipidea.sys [2016-7-16 75616]
S3 ufxsynopsys;USB Synopsys Controller;c:\windows\system32\drivers\ufxsynopsys.sys [2016-7-16 107360]
S3 UnistoreSvc_18d5c;User Data Storage_18d5c;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
S3 UrsChipidea;Chipidea USB Role-Switch Driver;c:\windows\system32\drivers\urschipidea.sys [2016-7-16 22880]
S3 UrsCx01000;USB Role-Switch Support Library;c:\windows\system32\drivers\urscx01000.sys [2016-7-16 42336]
S3 UrsSynopsys;Synopsys USB Role-Switch Driver;c:\windows\system32\drivers\urssynopsys.sys [2016-7-16 21856]
S3 UserDataSvc_18d5c;User Data Access_18d5c;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
S3 UsoSvc;Update Orchestrator Service for Windows Update;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 vhf;Virtual HID Framework (VHF) Driver;c:\windows\system32\drivers\vhf.sys [2016-7-16 24064]
S3 vmgid;Microsoft Hyper-V Guest Infrastructure Driver;c:\windows\system32\drivers\vmgid.sys [2016-7-16 8704]
S3 vmicguestinterface;Hyper-V Guest Service Interface;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 vmicvmsession;Hyper-V PowerShell Direct Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 w3logsvc;W3C Logging Service;c:\windows\system32\svchost.exe -k apphost [2016-7-16 38792]
S3 WalletService;WalletService;c:\windows\system32\svchost.exe -k appmodel [2016-7-16 38792]
S3 wdiwifi;WDI Driver Framework;c:\windows\system32\drivers\WdiWiFi.sys [2017-3-15 518656]
S3 WdNisDrv;Windows Defender Network Inspection System Driver;c:\windows\system32\drivers\WdNisDrv.sys [2016-7-16 100192]
S3 WdNisSvc;Windows Defender Network Inspection Service;c:\program files\windows defender\NisSrv.exe [2017-4-11 271496]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;c:\windows\system32\svchost.exe -k WepHostSvcGroup [2016-7-16 38792]
S3 wisvc;Windows Insider Service;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 workfolderssvc;Work Folders;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
S3 WpnUserService_18d5c;Windows Push Notifications User Service_18d5c;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\drivers\WUDFRd.sys [2016-7-16 161280]
S3 XblAuthManager;Xbox Live Auth Manager;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 XblGameSave;Xbox Live Game Save;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 xboxgip;Xbox Game Input Protocol Driver;c:\windows\system32\drivers\xboxgip.sys [2017-3-15 216576]
S3 XboxNetApiSvc;XboxNetApiSvc;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 xinputhid;XINPUT HID Filter Driver;c:\windows\system32\drivers\xinputhid.sys [2016-9-25 34304]
S4 NAUpdate;Nero Update;c:\program files\nero\update\NASvc.exe [2011-3-29 598312]
S4 shpamsvc;Shared PC Account Manager;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S4 tzautoupdate;Auto Time Zone Updater;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
.
=============== File Associations ===============
.
ShellExec: SZBrowser.exe: open="c:\program files\avast software\szbrowser\Launcher.exe" "%1"
.
=============== Created Last 30 ================
.
2017-04-15 04:44:14 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2017-04-11 22:52:55 3774464 ----a-w- c:\windows\system32\SettingsHandlers_nt.dll
2017-04-05 00:38:18 232016 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2017-04-05 00:38:18 232016 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2017-03-18 16:56:59 -------- d-----w- c:\users\owner\appdata\local\Quicken_Inc
2017-03-18 16:33:54 7280072 ----a-w- c:\windows\system32\cdintf500.dll
2017-03-17 00:05:49 527816 ----a-w- c:\program files\mozilla firefox\minidump-analyzer.exe
.
==================== Find3M ====================
.
2017-04-15 12:46:16 170200 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2017-04-01 18:52:38 835576 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2017-04-01 18:52:38 177656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2017-03-28 07:10:34 484584 ----a-w- c:\windows\system32\AudioSes.dll
2017-03-28 07:10:28 315744 ----a-w- c:\windows\system32\atmfd.dll
2017-03-28 06:59:06 448864 ----a-w- c:\windows\system32\ContentDeliveryManager.Utilities.dll
2017-03-28 06:21:41 890984 ----a-w- c:\windows\system32\winresume.efi
2017-03-28 06:21:27 167848 ----a-w- c:\windows\system32\wscapi.dll
2017-03-28 06:20:03 1725136 ----a-w- c:\windows\system32\KernelBase.dll
2017-03-28 06:19:36 5999968 ----a-w- c:\windows\system32\ntoskrnl.exe
2017-03-28 06:19:26 601712 ----a-w- c:\windows\system32\oleaut32.dll
2017-03-28 06:15:53 2048496 ----a-w- c:\windows\system32\CoreUIComponents.dll
2017-03-28 06:14:35 583136 ----a-w- c:\windows\system32\CoreMessaging.dll
2017-03-28 06:13:10 950624 ----a-w- c:\windows\system32\drivers\ndis.sys
2017-03-28 06:07:35 263472 ----a-w- c:\windows\system32\Windows.Storage.ApplicationData.dll
2017-03-28 06:05:23 1896800 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2017-03-28 06:05:16 342880 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2017-03-28 06:05:07 1504056 ----a-w- c:\windows\system32\WindowsCodecs.dll
2017-03-28 06:04:58 1431232 ----a-w- c:\windows\system32\Windows.ApplicationModel.Store.dll
2017-03-28 06:04:53 136032 ----a-w- c:\windows\system32\CloudExperienceHostUser.dll
2017-03-28 06:04:38 5721808 ----a-w- c:\windows\system32\windows.storage.dll
2017-03-28 06:04:32 975744 ----a-w- c:\windows\system32\twinapi.appcore.dll
2017-03-28 06:04:31 861024 ----a-w- c:\windows\system32\LicenseManager.dll
2017-03-28 06:02:55 576408 ----a-w- c:\windows\system32\wer.dll
2017-03-28 06:02:48 1980768 ----a-w- c:\windows\system32\msxml6.dll
2017-03-28 06:02:01 846560 ----a-w- c:\windows\system32\WinTypes.dll
2017-03-28 05:59:49 80224 ----a-w- c:\windows\system32\rdpudd.dll
2017-03-28 05:59:11 6667520 ----a-w- c:\windows\system32\Windows.Media.Protection.PlayReady.dll
2017-03-28 05:59:01 4023008 ----a-w- c:\windows\system32\mfcore.dll
2017-03-28 05:58:59 1851688 ----a-w- c:\windows\system32\mfmp4srcsnk.dll
2017-03-28 05:58:53 981888 ----a-w- c:\windows\system32\mfnetcore.dll
2017-03-28 05:58:53 1360464 ----a-w- c:\windows\system32\mfnetsrc.dll
2017-03-28 05:58:53 1344448 ----a-w- c:\windows\system32\mfsrcsnk.dll
2017-03-28 05:58:52 1277856 ----a-w- c:\windows\system32\mfasfsrcsnk.dll
2017-03-28 05:58:50 1202936 ----a-w- c:\windows\system32\mfmpeg2srcsnk.dll
2017-03-28 05:58:34 240992 ----a-w- c:\windows\system32\drivers\msiscsi.sys
2017-03-28 05:58:27 961192 ----a-w- c:\windows\system32\ole32.dll
2017-03-28 05:58:04 125792 ----a-w- c:\windows\system32\CloudExperienceHostBroker.dll
2017-03-28 05:58:03 198496 ----a-w- c:\windows\system32\CloudExperienceHost.dll
2017-03-28 05:53:54 545944 ----a-w- c:\windows\system32\fontdrvhost.exe
2017-03-28 05:53:53 1412128 ----a-w- c:\windows\system32\gdi32full.dll
2017-03-28 05:52:22 1966944 ----a-w- c:\windows\system32\drivers\tcpip.sys
2017-03-28 05:52:00 306800 ----a-w- c:\windows\system32\Windows.Media.MediaControl.dll
2017-03-28 05:48:07 5685760 ----a-w- c:\windows\system32\Windows.Data.Pdf.dll
2017-03-28 05:45:46 281088 ----a-w- c:\windows\system32\RDXTaskFactory.dll
2017-03-28 05:42:28 95232 ----a-w- c:\windows\system32\UserDataTimeUtil.dll
2017-03-28 05:42:06 51712 ----a-w- c:\windows\system32\usoapi.dll
2017-03-28 05:41:51 26112 ----a-w- c:\windows\system32\odbcconf.dll
2017-03-28 05:41:48 31232 ----a-w- c:\windows\system32\drivers\BasicRender.sys
2017-03-28 05:40:53 37376 ----a-w- c:\windows\system32\atmlib.dll
2017-03-28 05:40:27 46080 ----a-w- c:\windows\system32\drivers\BasicDisplay.sys
2017-03-28 05:40:19 224256 ----a-w- c:\windows\system32\ExSMime.dll
2017-03-28 05:40:13 42496 ----a-w- c:\windows\system32\musdialoghandlers.dll
2017-03-28 05:39:48 141824 ----a-w- c:\windows\system32\Windows.Devices.Radios.dll
2017-03-28 05:39:46 186880 ----a-w- c:\windows\system32\RdpRelayTransport.dll
2017-03-28 05:39:43 123392 ----a-w- c:\windows\system32\dmcertinst.exe
2017-03-28 05:39:23 85504 ----a-w- c:\windows\system32\Family.Authentication.dll
2017-03-28 05:39:22 199168 ----a-w- c:\windows\system32\MusNotification.exe
2017-03-28 05:39:19 166400 ----a-w- c:\windows\system32\dafpos.dll
2017-03-28 05:39:17 40960 ----a-w- c:\windows\system32\TokenBrokerUI.dll
2017-03-28 05:38:17 584192 ----a-w- c:\windows\system32\UIRibbonRes.dll
2017-03-28 05:38:05 156672 ----a-w- c:\windows\system32\UserDeviceRegistration.dll
2017-03-28 05:38:03 79360 ----a-w- c:\windows\system32\MusNotificationUx.exe
2017-03-28 05:37:58 138240 ----a-w- c:\windows\system32\DisplayManager.dll
2017-03-28 05:37:47 177664 ----a-w- c:\windows\system32\Windows.Web.Diagnostics.dll
2017-03-28 05:37:46 123904 ----a-w- c:\windows\system32\Windows.Networking.HostName.dll
2017-03-28 05:37:29 215552 ----a-w- c:\windows\system32\apds.dll
2017-03-28 05:37:19 255488 ----a-w- c:\windows\system32\unimdm.tsp
2017-03-28 05:36:49 136192 ----a-w- c:\windows\system32\WinRtTracing.dll
2017-03-28 05:36:42 94208 ----a-w- c:\windows\system32\Windows.StateRepositoryClient.dll
2017-03-28 05:36:38 87040 ----a-w- c:\windows\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-03-28 05:36:34 129024 ----a-w- c:\windows\system32\Windows.Devices.SerialCommunication.dll
2017-03-28 05:36:33 59904 ----a-w- c:\windows\system32\Windows.System.UserDeviceAssociation.dll
2017-03-28 05:36:27 330752 ----a-w- c:\windows\system32\aadcloudap.dll
2017-03-28 05:34:43 299520 ----a-w- c:\windows\system32\UserDataAccountApis.dll
2017-03-28 05:34:38 271872 ----a-w- c:\windows\system32\Windows.Devices.SmartCards.Phone.dll
2017-03-28 05:34:37 216576 ----a-w- c:\windows\system32\DeveloperOptionsSettingsHandlers.dll
2017-03-28 05:34:32 237568 ----a-w- c:\windows\system32\SyncSettings.dll
2017-03-28 05:34:15 222720 ----a-w- c:\windows\system32\NetworkBindingEngineMigPlugin.dll
2017-03-28 05:34:08 417280 ----a-w- c:\windows\system32\MusUpdateHandlers.dll
2017-03-28 05:34:07 115712 ----a-w- c:\windows\system32\Windows.ApplicationModel.Core.dll
2017-03-28 05:34:01 117760 ----a-w- c:\windows\system32\AuthBroker.dll
2017-03-28 05:33:59 557568 ----a-w- c:\windows\system32\StoreAgent.dll
2017-03-28 05:33:06 483840 ----a-w- c:\windows\system32\Windows.Devices.AllJoyn.dll
2017-03-28 05:33:02 670208 ----a-w- c:\windows\system32\Windows.Devices.PointOfService.dll
2017-03-28 05:33:02 609280 ----a-w- c:\windows\system32\Windows.Media.Import.dll
2017-03-28 05:31:59 332800 ----a-w- c:\windows\system32\Windows.Cortana.Desktop.dll
2017-03-28 05:31:51 431616 ----a-w- c:\windows\system32\efswrt.dll
2017-03-28 05:31:51 390656 ----a-w- c:\windows\system32\CredProvDataModel.dll
2017-03-28 05:31:46 273920 ----a-w- c:\windows\system32\PrintDialogs3D.dll
2017-03-28 05:31:43 498688 ----a-w- c:\windows\system32\mbsmsapi.dll
2017-03-28 05:31:38 728064 ----a-w- c:\windows\system32\enterprisecsps.dll
2017-03-28 05:30:59 517632 ----a-w- c:\windows\system32\FlightSettings.dll
2017-03-28 05:30:59 262144 ----a-w- c:\windows\system32\Windows.Devices.Picker.dll
2017-03-28 05:30:24 787968 ----a-w- c:\windows\system32\sbe.dll
2017-03-28 05:30:10 816640 ----a-w- c:\windows\system32\NaturalLanguage6.dll
2017-03-28 05:30:09 846336 ----a-w- c:\windows\system32\WebcamUi.dll
2017-03-28 05:30:02 75264 ----a-w- c:\windows\system32\updatepolicy.dll
2017-03-28 05:29:50 529920 ----a-w- c:\windows\system32\StructuredQuery.dll
2017-03-28 05:29:44 747520 ----a-w- c:\windows\system32\Windows.Media.Ocr.dll
.
============= FINISH: 7:29:48.58 ===============

Attached Files
File Type: txt attach.txt (16.8 KB)

Check my system please

$
0
0
Could someone please check my system??
I do not have a specific problem other than it is running slow and the hard drive hammers almost all of the time. Every once and awhile I get a screen popup from Google wanting me to prove I am not a robot. It says my PC is generating a lot of traffic. AV scans turn up negative.
Thanks,
Julian

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.18639 BrowserJavaVersion: 11.121.2
Run by JG at 12:31:52 on 2017-04-18
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3957.2817 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {71A27EC9-3DA6-45FC-60A7-004F623C6189}
SP: Microsoft Security Essentials *Disabled/Updated* {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Intel\AMT\atchksrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Intel\AMT\LMS.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Intel\AMT\UNS.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\Intel\AMT\atchk.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\ContourStoryteller\ContourAutoplay.exe
C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
C:\Program Files (x86)\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\NETGEAR\WNDA3100v3\WNDA3100v3.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
mWinlogon: Userinit = userinit.exe
BHO: AcroIEHlprObj Class: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll
EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - C:\Program Files (x86)\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [ContourCameraFinder] "C:\Program Files (x86)\ContourStoryteller\ContourAutoplay.exe"
mRun: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
dRun: [KSS] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe" autorun
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ACROBA~1.LNK - C:\Program Files (x86)\Adobe\Acrobat 6.0\Distillr\acrotray.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
StartupFolder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop (1).ini
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\NETGEA~1.LNK - C:\Program Files (x86)\NETGEAR\WNDA3100v3\WNDA3100v3.EXE
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.254.254
TCP: Interfaces\{9F009CC5-0A6E-40CF-B394-4B78E2459293} : DHCPNameServer = 192.168.254.254
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [atchk] "C:\Program Files (x86)\Intel\AMT\atchk.exe"
x64-Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\JG\AppData\Roaming\Mozilla\Firefox\Profiles\audmwbwx.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2016-8-25 295000]
R2 ADExchange;ArcSoft Exchange Service;C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [2012-2-16 43112]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-9-22 83768]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 UNS;Intel(R) Active Management Technology User Notification Service;C:\Program Files (x86)\Intel\AMT\UNS.exe [2014-6-21 2519040]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2014-6-21 70168]
R3 VBAudioVACMME;VB-Audio Virtual Cable (WDM);C:\Windows\System32\drivers\vbaudio_cable64_win7.sys [2013-7-11 41192]
R3 WNDA3100v3;NETGEAR WNDA3100v3 USB Wireless LAN Card Driver;C:\Windows\System32\drivers\WNDA3100v3.sys [2014-10-8 2225808]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-3-20 105096]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-3-20 125064]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2011-4-12 71168]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2017-4-12 114688]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2014-3-11 135928]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2016-11-14 361816]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2014-6-21 19456]
S3 Revoflt;Revoflt;C:\Windows\System32\drivers\revoflt.sys [2014-9-5 31800]
S3 RTL2832U_IRHID;HID Infrared Remote Receiver;C:\Windows\System32\drivers\RTL2832U_IRHID.sys [2009-10-5 44320]
S3 RTL2832UBDA;REALTEK 2832U BDA Driver;C:\Windows\System32\drivers\RTL2832UBDA.sys [2010-6-11 224288]
S3 RTL2832UUSB;REALTEK 2832U USB Driver;C:\Windows\System32\drivers\RTL2832UUSB.sys [2010-6-11 38944]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-6-21 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2014-6-21 30208]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2016-3-28 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2014-6-21 1255736]
.
=============== Created Last 30 ================
.
2017-04-18 12:18:11 12774864 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D8B1E59E-6A89-426E-B3D1-598C566DC724}\mpengine.dll
2017-04-18 12:17:09 12774864 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2017-04-05 20:03:57 -------- d-----w- C:\Users\JG\AppData\Roaming\Unitrunker
2017-04-05 20:03:57 -------- d-----w- C:\Program Files (x86)\Unitrunker
2017-04-05 00:38:18 232016 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
2017-04-04 13:10:59 90112 ----a-w- C:\Windows\SysWow64\pintlgnt.ime
2017-04-03 15:57:35 142336 ----a-w- C:\Windows\System32\poqexec.exe
2017-04-03 15:57:35 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2017-04-03 15:07:19 90624 ----a-w- C:\Windows\SysWow64\olepro32.dll
2017-03-23 12:41:22 1167568 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4FBE345A-BEC9-49EC-BE4B-2BEE1451FD6A}\gapaengine.dll
2017-03-20 04:48:06 28352 ----a-w- C:\Windows\SysWow64\aspnet_counters.dll
2017-03-20 04:48:06 19112 ----a-w- C:\Windows\SysWow64\msvcr110_clr0400.dll
2017-03-20 04:48:06 19112 ----a-w- C:\Windows\SysWow64\msvcr100_clr0400.dll
2017-03-20 04:48:06 19112 ----a-w- C:\Windows\SysWow64\msvcp110_clr0400.dll
2017-03-20 04:41:38 30400 ----a-w- C:\Windows\System32\aspnet_counters.dll
2017-03-20 04:41:38 19112 ----a-w- C:\Windows\System32\msvcr110_clr0400.dll
2017-03-20 04:41:38 19112 ----a-w- C:\Windows\System32\msvcr100_clr0400.dll
2017-03-20 04:41:38 19112 ----a-w- C:\Windows\System32\msvcp110_clr0400.dll
.
==================== Find3M ====================
.
2017-04-07 22:06:58 532136 ------w- C:\Windows\System32\MpSigStub.exe
2017-03-25 19:07:13 4604416 ----a-w- C:\Windows\SysWow64\jscript9.dll
2017-03-25 18:55:14 2767360 ----a-w- C:\Windows\SysWow64\wininet.dll
2017-03-25 18:48:24 499200 ----a-w- C:\Windows\SysWow64\vbscript.dll
2017-03-25 18:47:47 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2017-03-25 18:47:21 2055680 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2017-03-25 18:46:31 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2017-03-25 18:46:28 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2017-03-25 18:45:33 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2017-03-25 18:45:20 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2017-03-25 18:45:03 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2017-03-25 18:44:44 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2017-03-25 18:35:43 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2017-03-25 18:35:29 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2017-03-25 18:16:09 66560 ----a-w- C:\Windows\System32\iesetup.dll
2017-03-25 18:14:52 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2017-03-25 18:14:34 417792 ----a-w- C:\Windows\System32\html.iec
2017-03-25 18:13:58 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2017-03-25 18:13:43 576512 ----a-w- C:\Windows\System32\vbscript.dll
2017-03-25 17:56:51 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
2017-03-25 17:56:50 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2017-03-25 17:56:17 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2017-03-25 17:45:17 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2017-03-25 17:41:08 6045696 ----a-w- C:\Windows\System32\jscript9.dll
2017-03-25 17:30:52 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2017-03-25 17:19:30 341504 ----a-w- C:\Windows\SysWow64\html.iec
2017-03-25 16:57:57 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2017-03-25 16:57:30 2131456 ----a-w- C:\Windows\System32\inetcpl.cpl
2017-03-25 16:27:02 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2017-03-25 16:24:24 3241472 ----a-w- C:\Windows\System32\wininet.dll
2017-03-24 22:50:50 405504 ----a-w- C:\Windows\System32\gdi32.dll
2017-03-24 22:42:06 313344 ----a-w- C:\Windows\SysWow64\gdi32.dll
2017-03-22 15:32:05 98816 ----a-w- C:\Windows\System32\wudriver.dll
2017-03-22 15:32:05 3165184 ----a-w- C:\Windows\System32\wucltux.dll
2017-03-22 15:32:05 192512 ----a-w- C:\Windows\System32\wuwebv.dll
2017-03-22 15:30:15 91136 ----a-w- C:\Windows\System32\WinSetupUI.dll
2017-03-22 15:24:42 174080 ----a-w- C:\Windows\SysWow64\wuwebv.dll
2017-03-22 15:15:15 37888 ----a-w- C:\Windows\System32\wuapp.exe
2017-03-22 15:15:08 12288 ----a-w- C:\Windows\System32\wu.upgrade.ps.dll
2017-03-22 15:05:37 35328 ----a-w- C:\Windows\SysWow64\wuapp.exe
2017-03-22 15:05:35 93696 ----a-w- C:\Windows\SysWow64\wudriver.dll
2017-03-21 01:52:34 802904 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2017-03-21 01:52:34 144472 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2017-03-14 15:34:31 986344 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2017-03-14 15:34:30 265448 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2017-03-14 15:30:37 144384 ----a-w- C:\Windows\System32\cdd.dll
2017-03-10 16:35:56 382696 ----a-w- C:\Windows\System32\atmfd.dll
2017-03-10 16:31:58 41472 ----a-w- C:\Windows\System32\lpk.dll
2017-03-10 16:31:56 100864 ----a-w- C:\Windows\System32\fontsub.dll
2017-03-10 16:31:55 14336 ----a-w- C:\Windows\System32\dciman32.dll
2017-03-10 16:31:53 46080 ----a-w- C:\Windows\System32\atmlib.dll
2017-03-10 16:27:18 308456 ----a-w- C:\Windows\SysWow64\atmfd.dll
2017-03-10 16:20:40 25600 ----a-w- C:\Windows\SysWow64\lpk.dll
2017-03-10 16:19:45 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2017-03-10 16:19:38 10240 ----a-w- C:\Windows\SysWow64\dciman32.dll
2017-03-10 16:00:56 3219968 ----a-w- C:\Windows\System32\win32k.sys
2017-03-10 15:53:56 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2017-03-08 20:20:26 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2017-03-08 20:10:53 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2017-03-08 04:37:51 631176 ----a-w- C:\Windows\System32\winresume.efi
2017-03-08 04:36:43 706792 ----a-w- C:\Windows\System32\winload.efi
2017-03-08 04:36:43 5548264 ----a-w- C:\Windows\System32\ntoskrnl.exe
2017-03-08 04:36:41 95464 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2017-03-08 04:36:41 154856 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2017-03-08 04:34:53 1732864 ----a-w- C:\Windows\System32\ntdll.dll
2017-03-08 04:26:43 4000488 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2017-03-08 04:26:43 3945192 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2017-03-08 04:24:21 1314112 ----a-w- C:\Windows\SysWow64\ntdll.dll
2017-03-08 04:21:58 342528 ----a-w- C:\Windows\SysWow64\certcli.dll
2017-03-08 04:03:58 148480 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2017-03-08 04:03:54 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2017-03-08 04:03:53 62464 ----a-w- C:\Windows\System32\drivers\appid.sys
2017-03-08 04:03:13 64000 ----a-w- C:\Windows\System32\auditpol.exe
2017-03-08 04:00:11 338432 ----a-w- C:\Windows\System32\conhost.exe
2017-03-08 03:59:18 296960 ----a-w- C:\Windows\System32\rstrui.exe
2017-03-08 03:57:53 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2017-03-08 03:56:37 159744 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2017-03-08 03:56:03 291328 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2017-03-08 03:56:01 129536 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2017-03-08 03:55:18 30720 ----a-w- C:\Windows\System32\lsass.exe
2017-03-08 03:55:15 112640 ----a-w- C:\Windows\System32\smss.exe
2017-03-08 03:54:22 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2017-03-08 03:54:20 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2017-03-08 03:54:20 2048 ----a-w- C:\Windows\SysWow64\user.exe
2017-03-08 03:54:20 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2017-03-08 03:53:34 36352 ----a-w- C:\Windows\SysWow64\cryptbase.dll
2017-03-08 03:53:27 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2017-03-08 03:53:27 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2017-03-08 03:53:27 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2017-03-08 03:53:27 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2017-03-07 16:30:47 85504 ----a-w- C:\Windows\System32\asycfilt.dll
2017-03-07 16:17:40 67584 ----a-w- C:\Windows\SysWow64\asycfilt.dll
2017-03-07 14:05:55 243200 ----a-w- C:\Windows\System32\rdpudd.dll
2017-03-04 01:27:12 1574912 ----a-w- C:\Windows\System32\quartz.dll
2017-03-04 01:27:05 93696 ----a-w- C:\Windows\System32\mfmjpegdec.dll
2017-03-04 01:14:51 1329664 ----a-w- C:\Windows\SysWow64\quartz.dll
2017-03-04 01:14:31 77312 ----a-w- C:\Windows\SysWow64\mfmjpegdec.dll
2017-02-14 16:33:00 757248 ----a-w- C:\Windows\System32\win32spl.dll
2017-02-14 16:19:08 497664 ----a-w- C:\Windows\SysWow64\win32spl.dll
2017-02-11 16:33:21 2048 ----a-w- C:\Windows\System32\tzres.dll
.
============= FINISH: 12:32:48.14 ===============

Attached Files
File Type: txt attach.txt (4.0 KB)

Error about procedure entry point & dll file

$
0
0
Hello,
I have an HP laptop running Windows 7 64-bit.

I believe I have some sort of malware or virus, though I am not sure. I can open some programs, like MS Outlook but for most all other programs, I get an error message like this:

"The procedure entry point_onexit could not be located in the dynamic link library msvcrt.dll"

I tried to follow the steps outlined in the sticky of this forum which says to download and run the DDS file, but I can't open my browser and get online because I get the error message. And when I tried to burn it onto a CD (using my other computer), and tried to run the program from the CD (on my infected laptop), I get this message:

"The procedure entry point wcschr could not be located in the dynamic link library msvcrt.dll:

Any help is greatly appreciated. I'm really not sure what to do at this point. Thank you in advance :)

I have a virus on my computer because I can't go on firefox

$
0
0
Hello, I have a virus on my emachine windows 7 desktop computer. I get this message saying Threat blocked! We've stopped this threat from spreading.
Win32:Mywebsearch-R[PUP]
in...6)\MyWebSearch\bar\1.bin\mwsoestb.dll
C:\Windows\SysWOW64\WerFault.exe
More threats may be lurking!
Scan Started

The AVG recommend me to scan my whole computer, but I can't because the scan doesn't go all the way through it's stops at 5%

Also, they said that the virus has been removed but it hasn't.
My computer has been running slower because of this virus, and I can't bring up firefox. It takes a long time for it to load, saying not responding.
So how can I get rid of this virus? thank you!

sh4ldr folder??

$
0
0
so i noticed this folder pop up in my C: drive. looking inside it has a few files, initrd.gz, shldr, shldr.mbr, and vmlinuz. ive learned that this is a folder for spy hunter.. but.. ive heard spy hunter is malicious (thanks to my boyfriend for telling me to download it.. i just use it to scan since it hasnt picked up anything.) so im not sure if this folder is safe. in fact i don't even know if spy hunter is safe.
i'm mainly worried because i was.. Borrowing.. some software illegally. i have removed all the software that i downloaded.
sometimes i hear my computer turn on by itself in the middle of the night. it's a laptop, when im asleep i keep it closed, but i can hear it make a ding noise sometimes and the screen light up while its closed. maybe im just paranoid but i dont think thats normal.

PUP Optional NewTabTV

$
0
0
What is that? Colored orange for severity on my MBAM scan.

File: 2
PUP.Optional.NewTabTV, C:\USERS\HOME\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_search.newtabtvsearch.com_0.localstorage, No Action By User, [2544], [359410],1.0.1802
PUP.Optional.NewTabTV, C:\USERS\HOME\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_search.newtabtvsearch.com_0.localstorage-journal, No Action By User, [2544], [359410],1.0.1802

Computer running very slowly

$
0
0
Hi,

Just recently my machine has started to run very slowly. Programs are slow to start and my download speed has dropped from 150Mbps to 40Mbps, even when everything is turned off. I regularly run SpyBot Pro, Malwarebytes Premium, Zemana and Kaspersky Internet Security Suite and they all return zero problems. I've tried disabling all of those with no effect and I've also run CCleaner and System Mechanic, which shows my system status as good. I'm now at a loss as to what the problem can be. Below is my DDS.txt and attached is my attach.txt.

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.18639 BrowserJavaVersion: 11.111.2
Run by John at 10:32:20 on 2017-04-25
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.16349.9371 [GMT 1:00]
.
AV: Kaspersky Internet Security *Enabled/Updated* {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AV: Spybot - Search and Destroy *Enabled/Updated* {1A0DDE8C-B4BA-EFDD-22A8-0F557C7985F0}
AV: Malwarebytes *Disabled/Updated* {23007AD3-69FE-687C-2629-D584AFFAF72B}
SP: Spybot - Search and Destroy *Enabled/Updated* {A16C3F68-9280-E053-1818-342707FECF4D}
SP: Malwarebytes *Disabled/Updated* {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
SP: Kaspersky Internet Security *Enabled/Updated* {3D579475-6DDE-A186-1569-44B9F9DE8725}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security *Enabled* {BE0DF4B4-018B-AF50-0486-D6FE7C8A8AE3}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Driver-Soft\DriverGenius\DriverGenius.exe
C:\Program Files (x86)\System Mechanic\iologovernor64.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
C:\Windows\system32\DbxSvc.exe
C:\Program Files\NetDrive2\mounter.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\NordVPN\nordvpn-service.exe
C:\Program Files (x86)\Google\Update\1.3.33.3\GoogleCrashHandler.exe
C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
C:\Program Files (x86)\Google\Update\1.3.33.3\GoogleCrashHandler64.exe
C:\Program Files\NetDrive2\nd2sp.exe
C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Windows\system32\RAPID\SamsungRapidSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avpui.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Everything\Everything.exe
C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe
C:\Program Files (x86)\Acronis\TrueImageHome\acronis_drive.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Users\John\AppData\Local\Avanquest\Avanquest Message\AQNotif.exe
C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
C:\Program Files\Common Files\Commtouch\AntiVirus5\vsedsps.exe
C:\Users\John\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe
C:\Program Files\Common Files\Commtouch\AntiVirus5\vseqrts.exe
C:\Program Files (x86)\Zemana AntiLogger\ZAM.exe
C:\Program Files\Common Files\Commtouch\AntiVirus5\vseamps.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Program Files (x86)\TeamViewer\tv_w32.exe
C:\Program Files (x86)\TeamViewer\tv_x64.exe
C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
C:\Program Files (x86)\AtomTime Pro\AtomTime.EXE
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\E_YUBNPE.EXE
C:\Windows\system32\taskmgr.exe
C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome-nm-host.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\E_YUBNPE.EXE
C:\Program Files\Core Temp\Core Temp.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\E_YUBNPE.EXE
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://192.168.0.6/
mWinlogon: Userinit = userinit.exe,
BHO: Kaspersky Protection: {2E38825B-8815-42CF-9126-C58BC28D4591} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\IEExt\ie_plugin.dll
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
BHO: RoboForm Toolbar Helper: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll
BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL
BHO: Microsoft OneDrive for Business Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll
TB: &RoboForm Toolbar: {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
TB: Kaspersky Protection Toolbar: {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\IEExt\ie_plugin.dll
TB: &RoboForm Toolbar: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
TB: Soda PDF 8 Toolbar: {A2689669-AD38-4AFD-B370-23E97E2B9D18} - C:\Program Files (x86)\Soda PDF 8\creator-ie-plugin.dll
TB: Kaspersky Protection Toolbar: {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\IEExt\ie_plugin.dll
EB: E-Web Print: {A60C1DC7-64B3-4AD9-8E67-035D11B8B2B0} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
uRun: [Avanquest Message] "C:\Users\John\AppData\Local\Avanquest\Avanquest Message\AQNotif.exe"
uRun: [Google Photos Backup] "C:\Users\John\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe" /autostart
uRun: [Epic Privacy Browser Installer] "C:\Users\John\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe" /c
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
uRun: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
uRun: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
mRun: [AtomTime] "C:\Program Files (x86)\AtomTime Pro\AtomTime.EXE"
mRun: [Bonus.SSR.FR12] "C:\Program Files (x86)\ABBYY FineReader 12\Bonus.ScreenshotReader.exe" /autorun
mRun: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
mRun: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
mRun: [AcronisTibMounterMonitor] C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
mRun: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:60
mPolicies-Explorer: NoDrives = dword:1088
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Customize Menu - C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
IE: Fill Forms - C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComFillForms.html
IE: Save Forms - C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComSavePass.html
IE: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
IE: Show RoboForm Toolbar - C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComShowToolbar.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
LSP: %windir%\system32\vsocklib.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {A4150320-98EC-4DB6-9BFB-EBF4B6FBEB16} - hxxp://192.168.0.5/codebase/DVM_IPCam2.ocx
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{0F4EB55E-CD09-4DF0-9DD8-9D3973281C36} : DHCPNameServer = 78.46.223.24 162.242.211.137
TCP: Interfaces\{CFFA7950-3B50-4886-A756-925FDA8A7ECF} : DHCPNameServer = 8.8.8.8 8.8.4.4
TCP: Interfaces\{D4BA916A-32E7-4A20-A3A4-0C2172A2C19D} : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{D4BA916A-32E7-4A20-A3A4-0C2172A2C19D}\65D433231343533343 : DHCPNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{D4BA916A-32E7-4A20-A3A4-0C2172A2C19D}\65D4731393335303D22374 : DHCPNameServer = 192.168.0.1
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
AppInit_DLLs= C:\PROGRA~2\KEYCRY~1\KEYCRY~3.DLL
SSODL: WebCheck - <orphaned>
x64-BHO: Kaspersky Protection: {2E38825B-8815-42CF-9126-C58BC28D4591} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\IEExt\ie_plugin.dll
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-BHO: RoboForm Toolbar Helper: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll
x64-BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL
x64-BHO: Microsoft OneDrive for Business Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll
x64-TB: &RoboForm Toolbar: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-TB: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll
x64-TB: Kaspersky Protection Toolbar: {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\IEExt\ie_plugin.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [Everything] "C:\Program Files\Everything\Everything.exe" -startup
x64-Run: [SamsungRapidApp] C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe
x64-Run: [ZAM] "C:\Program Files (x86)\Zemana AntiLogger\ZAM.exe" /minimized
x64-Run: [Acronis Scheduler2 Service] "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"
x64-Run: [Malwarebytes TrayApp] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe
x64-Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {724d43aa-0d85-11d4-9908-00400523e39a} - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - <orphaned>
x64-Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
Hosts: 127.0.0.1 spywareinfo.comÂ*-Â*This website is for sale!Â*-Â*spywareinfo Resources and Information.
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\8dkzrv6z.default-1489759735055\
FF - prefs.js: browser.startup.homepage - resource://extension-at-one-tab-dot-com/data/onetab.html
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Soda PDF 8\np-previewer.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\John\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll
FF - plugin: C:\Users\John\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2015-5-7 83656]
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2015-5-7 43720]
R0 cm_km;AO Kaspersky Lab Cryptographic Module x64 (56 bit);C:\Windows\System32\drivers\cm_km.sys [2016-6-10 238936]
R0 file_tracker;Acronis File Tracker Driver;C:\Windows\System32\drivers\file_tracker.sys [2017-1-23 375136]
R0 fltsrv;Acronis Storage Filter Management;C:\Windows\System32\drivers\fltsrv.sys [2017-1-23 181592]
R0 klbackupdisk;Kaspersky Lab klbackupdisk;C:\Windows\System32\drivers\klbackupdisk.sys [2016-6-7 63920]
R0 SamsungRapidDiskFltr;SAMSUNG RAPID Mode Disk Filter Driver;C:\Windows\System32\drivers\SamsungRapidDiskFltr.sys [2015-11-12 268976]
R0 SamsungRapidFSFltr;SamsungRapidFSFltr;C:\Windows\System32\drivers\SamsungRapidFSFltr.sys [2014-9-16 111280]
R0 tib;Acronis TIB Manager;C:\Windows\System32\drivers\tib.sys [2017-1-23 1310560]
R0 vsock;vSockets Virtual Machine Communication Interface Sockets driver;C:\Windows\System32\drivers\vsock.sys [2016-9-14 93248]
R1 AntiLog32;AntiLog32;C:\Windows\System32\drivers\AntiLog64.sys [2015-2-24 49752]
R1 AppleCharger;AppleCharger;C:\Windows\System32\drivers\AppleCharger.sys [2015-2-15 22240]
R1 klbackupflt;Kaspersky Lab klbackupflt;C:\Windows\System32\drivers\klbackupflt.sys [2016-6-15 86352]
R1 klhk;Kaspersky Lab service driver;C:\Windows\System32\drivers\klhk.sys [2017-3-30 314864]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2017-3-30 57936]
R1 klpd;Kaspersky Lab format recognizer driver;C:\Windows\System32\drivers\klpd.sys [2016-5-31 45488]
R1 kltdi;kltdi;C:\Windows\System32\drivers\kltdi.sys [2016-5-17 75696]
R1 Klwtp;KLwtp - WFP callout traffic inspector;C:\Windows\System32\drivers\klwtp.sys [2017-3-30 135904]
R1 kneps;kneps;C:\Windows\System32\drivers\kneps.sys [2016-6-14 199392]
R1 RawDisk3;RawDisk3;C:\Windows\System32\drivers\rawdsk3.sys [2015-9-6 32912]
R1 SDHookDriver;Hook Test Driver;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookDrv64.sys [2015-2-21 64160]
R1 Uim_DEVIM;UIM Direct Device Image Plugin;C:\Windows\System32\drivers\uim_devim.sys [2015-7-22 25904]
R1 ZAM;ZAM Helper Driver;C:\Windows\System32\drivers\zam64.sys [2017-1-17 203680]
R1 ZAM_Guard;ZAM Guard Driver;C:\Windows\System32\drivers\zamguard64.sys [2017-1-17 203680]
R2 afcdpsrv;Acronis Nonstop Backup Service;C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2017-4-13 6086232]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2017-4-10 543112]
R2 AMP;Active Malware Protection Minifilter Driver;C:\Windows\System32\drivers\amp.sys [2016-10-11 181512]
R2 AMPSE;Active Malware Protection Support Driver;C:\Windows\System32\drivers\ampse.sys [2017-4-12 1793288]
R2 AODDriver4.3;AODDriver4.3;C:\Program Files\AMD\ATI.ACE\Fuel\amd64\aoddriver2.sys [2014-2-11 59616]
R2 AVP17.0.0;Kaspersky Anti-Virus Service 17.0.0;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe [2016-6-28 241544]
R2 ClickToRunSvc;Microsoft Office Click-to-Run Service;C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2017-1-17 3737792]
R2 DbxSvc;DbxSvc;C:\Windows\System32\DbxSvc.exe [2017-4-17 48944]
R2 Dokan_NetDrive2;Dokan_NetDrive2;C:\Program Files\NetDrive2\dokan.sys [2015-3-27 117952]
R2 DokanMounter_Dokan_NetDrive2;DokanMounter_Dokan_NetDrive2;C:\Program Files\NetDrive2\mounter.exe [2015-1-28 28160]
R2 kldisk;kldisk;C:\Windows\System32\drivers\kldisk.sys [2016-5-31 78216]
R2 nordvpn-service;nordvpn-service;C:\Program Files (x86)\NordVPN\nordvpn-service.exe [2017-4-5 410800]
R2 notifierNetDrive2;NetDrive2 Notifier;C:\Program Files\NetDrive2\nd2sp.exe [2015-3-27 75112]
R2 SamsungRapidSvc;Samsung RAPID Mode Service;system32\RAPID\SamsungRapidSvc.exe --> system32\RAPID\SamsungRapidSvc.exe [?]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2015-2-21 1740760]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2015-2-21 4088608]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2015-2-21 235984]
R2 syncagentsrv;Acronis Sync Agent Service;C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [2016-12-21 7013704]
R2 TeamViewer;TeamViewer 12;C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2016-11-4 10883824]
R2 tib_mounter;Acronis TIB Mounter;C:\Windows\System32\drivers\tib_mounter.sys [2017-4-13 214360]
R2 virtual_file;Acronis Virtual File Driver;C:\Windows\System32\drivers\virtual_file.sys [2017-4-13 324448]
R2 vseamps;vseamps;C:\Program Files\Common Files\Commtouch\AntiVirus5\vseamps.exe [2016-10-11 122120]
R2 vsedsps;vsedsps;C:\Program Files\Common Files\Commtouch\AntiVirus5\vsedsps.exe [2016-10-11 119560]
R2 vseqrts;vseqrts;C:\Program Files\Common Files\Commtouch\AntiVirus5\vseqrts.exe [2016-10-11 181512]
R2 ZAMSvc;ZAM Controller Service;C:\Program Files (x86)\Zemana AntiLogger\ZAM.exe [2017-1-17 14522512]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2016-12-20 96256]
R3 keycrypt;keycrypt;C:\Windows\System32\drivers\KeyCrypt64.sys [2015-2-24 161408]
R3 klflt;Kaspersky Lab Kernel DLL;C:\Windows\System32\drivers\klflt.sys [2017-4-11 195296]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;C:\Windows\System32\drivers\klkbdflt.sys [2016-5-19 52144]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2015-6-7 41648]
R3 kltap;Kaspersky Security Data Escort Adapter;C:\Windows\System32\drivers\kltap.sys [2016-6-7 52152]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\Windows\System32\drivers\LEqdUsb.sys [2015-6-18 87696]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\Windows\System32\drivers\LHidEqd.sys [2015-6-18 23184]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2016-6-29 1030400]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2015-5-7 60640]
S1 UsbCharger;UsbCharger;C:\Windows\System32\drivers\UsbCharger.sys [2015-2-15 22240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-3-20 105096]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-3-20 125064]
S2 dbupdate;Dropbox Update Service (dbupdate);C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-5-6 143144]
S2 MBAMService;Malwarebytes Service;C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [2017-2-16 4355024]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 CisUtMonitor;CisUtMonitor;C:\Windows\System32\drivers\CisUtMonitor.sys [2015-2-24 33360]
S3 dbupdatem;Dropbox Update Service (dbupdatem);C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-5-6 143144]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2016-9-5 131712]
S3 EPSON_PM_RPCV4_06;EPSON V3 Service4(06);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE [2016-11-12 152640]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2015-2-21 58056]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2014-3-31 1512640]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2017-4-12 114688]
S3 klvssbrigde64;klvssbrigde64;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\vssbridge64.exe [2016-6-28 77328]
S3 KSDE1.0.0;Kaspersky Secure Connection Service 1.0.0;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [2016-6-28 241544]
S3 mmsminisrv;Acronis Managed Machine Service Mini;C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe [2017-2-13 4795288]
S3 mobile_backup_server;Acronis Mobile Backup Server;C:\Program Files (x86)\Common Files\Acronis\MobileBackupServer\mobile_backup_server.exe [2017-1-6 2908352]
S3 mobile_backup_status_server;Acronis Mobile Backup Status Server;C:\Program Files (x86)\Acronis\TrueImageHome\mobile_backup_status_server.exe [2017-4-10 1612400]
S3 ptun0901;TAP Adapter V9 for Private Tunnel;C:\Windows\System32\drivers\ptun0901.sys [2016-4-21 27136]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2015-2-15 19456]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;C:\Program Files\SiSoftware\SiSoftware Sandra Lite Platinum\RpcAgentSrv.exe [2017-4-23 137264]
S3 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-2-27 317400]
S3 ss_conn_service;SAMSUNG Mobile Connectivity Service;C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [2016-6-8 754784]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\System32\drivers\ssudmdm.sys [2016-9-5 165504]
S3 tapnord;TAP-Windows Adapter V9 | NordVPN-9.21.2;C:\Windows\System32\drivers\tapnord.sys [2016-10-13 35376]
S3 tnd;Acronis Try&Decide filter;C:\Windows\System32\drivers\tnd.sys [2017-1-23 688864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2015-2-15 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2015-2-15 30208]
S3 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2017-2-20 915944]
S3 VUSB3HUB;VIA USB 3 Root Hub Service;C:\Windows\System32\drivers\ViaHub3.sys [2015-2-15 225792]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2015-2-15 1255736]
S3 WSDScan;WSD Scan Support via UMB;C:\Windows\System32\drivers\WSDScan.sys [2009-7-14 25088]
S3 xhcdrv;VIA USB eXtensible Host Controller Service;C:\Windows\System32\drivers\xhcdrv.sys [2017-1-26 294912]
S4 ABBYY.Licensing.FineReader.Professional.12.0;ABBYY FineReader 12 PE Licensing Service;C:\Program Files (x86)\ABBYY FineReader 12\NetworkLicenseServer.exe [2014-1-23 925904]
S4 Altaro.Agent.exe;Altaro VM Backup Engine;C:\Program Files\Altaro\Altaro Backup\Altaro.Agent.exe [2015-9-22 230840]
S4 Altaro.HyperV.WAN.RemoteService.exe;Altaro Offsite Server;C:\Program Files\Altaro\Altaro Backup\BackupServer\Altaro.HyperV.WAN.RemoteService.exe [2015-9-22 187832]
S4 Altaro.SubAgent.exe;Altaro VM Backup Hyper-V Host Agent;C:\Program Files\Altaro\Altaro Backup\Altaro.SubAgent.exe [2015-9-22 114104]
S4 Altaro.UI.Service.exe;Altaro VM Backup Controller;C:\Program Files\Altaro\Altaro Backup\Altaro.UI.Service.exe [2015-9-22 433592]
S4 AMD FUEL Service;AMD FUEL Service;C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2015-8-4 344064]
S4 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-14 27136]
S4 EpsonCustomerParticipation;EpsonCustomerParticipation;C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe [2013-5-1 651328]
S4 EpsonScanSvc;Epson Scanner Service;C:\Windows\System32\escsvc64.exe [2015-3-8 144560]
S4 Everything;Everything;C:\Program Files\Everything\Everything.exe [2015-8-11 1441792]
S4 Soda PDF 8 CrashHandler;Soda PDF 8 CrashHandler;C:\Program Files\Soda PDF 8\crash-handler-ws.exe [2016-4-19 920016]
S4 Soda PDF 8 Creator;Soda PDF 8 Creator;C:\Program Files\Soda PDF 8\creator-ws.exe [2016-4-19 733136]
S4 Soda PDF 8 Manager;Soda PDF 8 Manager;C:\ProgramData\LULU Software\Soda PDF 8 Manager\Soda PDF 8\Soda Manager.exe [2016-5-18 887800]
S4 Soda PDF 8;Soda PDF 8;C:\Program Files\Soda PDF 8\ws.exe [2016-4-19 2263504]
.
=============== File Associations ===============
.
ShellExec: Soda PDF 8.exe: edit="C:\Program Files\Soda PDF 8\soda.exe" --file "%1"
ShellExec: Soda PDF 8.exe: open="C:\Program Files\Soda PDF 8\soda.exe" --file "%1"
.
=============== Created Last 30 ================
.
2017-04-23 17:44:21 0 ---ha-w- C:\Users\John\AppData\Local\BITB116.tmp
2017-04-23 09:32:54 -------- d-----w- C:\Program Files\SiSoftware
2017-04-22 03:14:47 12993592 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E0D27A8E-4BAE-4833-ACD8-79EB837FD65F}\mpengine.dll
2017-04-17 15:14:04 48944 ----a-w- C:\Windows\System32\DbxSvc.exe
2017-04-15 22:08:49 -------- d--h--w- C:\OneDriveTemp
2017-04-13 10:03:35 324448 ----a-w- C:\Windows\System32\drivers\virtual_file.sys
2017-04-13 10:03:32 214360 ----a-w- C:\Windows\System32\drivers\tib_mounter.sys
2017-04-13 10:03:19 370008 ----a-w- C:\Windows\System32\drivers\snapman.sys
2017-04-13 09:53:21 517907000 ----a-w- C:\Users\John\AppData\Local\AcronisTrueImage2017_8041.exe
2017-04-12 21:53:54 -------- d-----w- C:\Windows\pss
2017-04-12 21:44:24 1793288 ----a-r- C:\Windows\System32\drivers\ampse.sys
2017-04-12 21:44:09 -------- d-----w- C:\ProgramData\Commtouch
2017-04-12 21:44:09 -------- d-----w- C:\Program Files\Common Files\Commtouch
2017-04-12 21:44:09 -------- d-----w- C:\Program Files (x86)\Common Files\Commtouch
2017-04-12 20:00:36 -------- d-----w- C:\ProgramData\ioloGovernor
2017-04-12 20:00:26 -------- d-----w- C:\Users\John\AppData\Roaming\ioloGovernor
2017-04-12 19:59:12 -------- d-----w- C:\Users\John\AppData\Local\iolo
2017-04-12 19:59:12 -------- d-----w- C:\Program Files\Common Files\iolo
2017-04-12 19:58:50 -------- d-----w- C:\Program Files (x86)\System Mechanic
2017-04-12 19:44:31 -------- d-----w- C:\Users\John\AppData\Roaming\iolo
2017-04-12 18:53:41 -------- d-----w- C:\iolo
2017-04-12 18:30:04 74703 ----a-w- C:\Windows\SysWow64\mfc45.dat
2017-04-12 16:35:36 872376 ----a-w- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
2017-04-12 16:35:36 65992 ----a-w- C:\Program Files (x86)\Mozilla Firefox\gmp-clearkey\0.1\clearkey.dll
2017-04-12 13:55:39 -------- d-sh--w- C:\$RECYCLE.BIN
2017-04-11 22:20:19 110176 ----a-w- C:\Windows\System32\klfphc.dll
2017-04-11 22:20:06 -------- d-----w- C:\Windows\ELAMBKUP
2017-04-11 22:19:57 -------- d-----w- C:\ProgramData\Kaspersky Lab
2017-04-11 22:19:38 195296 ----a-w- C:\Windows\System32\drivers\klflt.sys
2017-04-11 22:16:59 -------- d-----w- C:\ProgramData\Kaspersky Lab Setup Files
2017-04-10 17:32:02 522632 ----a-w- C:\Windows\System32\GameManager64.dll
2017-04-10 17:32:02 356744 ----a-w- C:\Windows\SysWow64\GameManager32.dll
2017-04-10 17:32:00 543112 ----a-w- C:\Windows\System32\dgtrayicon.exe
2017-04-10 17:30:48 505736 ----a-w- C:\Windows\System32\amdgfxinfo64.dll
2017-04-10 17:29:56 10311560 ----a-w- C:\Windows\System32\amdvlk64.dll
2017-04-10 17:29:52 8470408 ----a-w- C:\Windows\SysWow64\amdvlk32.dll
2017-04-10 17:29:48 166280 ----a-w- C:\Windows\System32\amduve64.dll
2017-04-10 17:29:46 135560 ----a-w- C:\Windows\SysWow64\amduve32.dll
2017-04-10 17:29:42 66952 ----a-w- C:\Windows\System32\amdmmcl6.dll
2017-04-10 17:29:40 82824 ----a-w- C:\Windows\System32\amdmcl64.dll
2017-04-10 17:29:40 54664 ----a-w- C:\Windows\SysWow64\amdmmcl.dll
2017-04-10 17:29:38 66440 ----a-w- C:\Windows\SysWow64\amdmcl32.dll
2017-04-10 17:29:36 26826120 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2017-04-10 16:56:40 -------- d-----w- C:\Program Files (x86)\AnvSoft
2017-04-10 11:00:44 -------- d-----w- C:\Users\John\AppData\Local\FileZilla
2017-04-08 23:04:01 -------- d-----w- C:\Program Files (x86)\Kodi
2017-04-05 00:38:18 232016 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
2017-03-30 09:15:30 57936 ----a-w- C:\Windows\System32\drivers\klim6.sys
2017-03-30 09:15:30 314864 ----a-w- C:\Windows\System32\drivers\klhk.sys
2017-03-30 09:15:30 135904 ----a-w- C:\Windows\System32\drivers\klwtp.sys
2017-03-28 21:30:26 366568 ----a-w- C:\Windows\SysWow64\vmnetdhcp.exe
2017-03-28 21:30:22 66520 ----a-w- C:\Windows\System32\vnetinst.dll
2017-03-28 21:30:22 46032 ----a-w- C:\Windows\System32\drivers\vmnet.sys
2017-03-28 21:30:22 43992 ----a-w- C:\Windows\System32\drivers\vmnetuserif.sys
2017-03-28 21:30:22 400872 ----a-w- C:\Windows\SysWow64\vmnat.exe
2017-03-28 21:30:13 1149416 ----a-w- C:\Windows\System32\vnetlib64.dll
2017-03-28 21:28:31 -------- d-----w- C:\Program Files (x86)\Common Files\ThinPrint
2017-03-28 21:28:30 -------- d-----w- C:\Program Files\Common Files\VMware
.
==================== Find3M ====================
.
2017-04-25 09:28:20 186304 ----a-w- C:\Windows\System32\drivers\MBAMChameleon.sys
2017-04-25 09:28:16 82720 ----a-w- C:\Windows\System32\drivers\mwac.sys
2017-04-25 09:28:16 43968 ----a-w- C:\Windows\System32\drivers\mbam.sys
2017-04-25 09:28:16 251832 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2017-04-25 09:28:16 111544 ----a-w- C:\Windows\System32\drivers\farflt.sys
2017-04-24 06:52:49 65536 ----a-w- C:\Windows\System32\spu_storage.bin
2017-04-13 22:58:02 802904 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2017-04-13 22:58:02 144472 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2017-04-13 10:06:04 375136 ----a-w- C:\Windows\System32\drivers\file_tracker.sys
2017-04-13 10:03:34 688864 ----a-w- C:\Windows\System32\drivers\tnd.sys
2017-04-13 10:03:31 1310560 ----a-w- C:\Windows\System32\drivers\tib.sys
2017-04-13 05:53:54 77440 ----a-w- C:\Windows\System32\drivers\mbae64.sys
2017-04-11 22:31:29 199392 ----a-w- C:\Windows\System32\drivers\kneps.sys
2017-04-10 17:32:32 161344 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2017-04-10 17:32:30 207760 ----a-w- C:\Windows\System32\atiuxp64.dll
2017-04-10 17:32:26 7663888 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2017-04-10 17:32:22 9446336 ----a-w- C:\Windows\System32\atiumd64.dll
2017-04-10 17:32:20 143864 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2017-04-10 17:32:18 185088 ----a-w- C:\Windows\System32\atiu9p64.dll
2017-04-10 17:30:52 13254256 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2017-04-10 17:29:22 32732552 ----a-w- C:\Windows\System32\atio6axx.dll
2017-03-25 19:07:13 4604416 ----a-w- C:\Windows\SysWow64\jscript9.dll
2017-03-25 18:55:14 2767360 ----a-w- C:\Windows\SysWow64\wininet.dll
2017-03-25 18:48:24 499200 ----a-w- C:\Windows\SysWow64\vbscript.dll
2017-03-25 18:47:47 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2017-03-25 18:47:21 2055680 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2017-03-25 18:46:31 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2017-03-25 18:46:28 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2017-03-25 18:45:33 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2017-03-25 18:45:20 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2017-03-25 18:45:03 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2017-03-25 18:44:44 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2017-03-25 18:35:43 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2017-03-25 18:35:29 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2017-03-25 18:16:09 66560 ----a-w- C:\Windows\System32\iesetup.dll
2017-03-25 18:14:52 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2017-03-25 18:14:34 417792 ----a-w- C:\Windows\System32\html.iec
2017-03-25 18:13:58 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2017-03-25 18:13:43 576512 ----a-w- C:\Windows\System32\vbscript.dll
2017-03-25 17:56:51 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
2017-03-25 17:56:50 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2017-03-25 17:56:17 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2017-03-25 17:45:17 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2017-03-25 17:41:08 6045696 ----a-w- C:\Windows\System32\jscript9.dll
2017-03-25 17:30:52 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2017-03-25 17:19:30 341504 ----a-w- C:\Windows\SysWow64\html.iec
2017-03-25 16:57:57 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2017-03-25 16:57:30 2131456 ----a-w- C:\Windows\System32\inetcpl.cpl
2017-03-25 16:27:02 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2017-03-25 16:24:24 3241472 ----a-w- C:\Windows\System32\wininet.dll
2017-03-24 22:50:50 405504 ----a-w- C:\Windows\System32\gdi32.dll
2017-03-24 22:42:06 313344 ----a-w- C:\Windows\SysWow64\gdi32.dll
2017-03-22 21:21:46 45672 ----a-w- C:\Windows\System32\drivers\dbx-stable.sys
2017-03-22 21:21:46 45672 ----a-w- C:\Windows\System32\drivers\dbx-dev.sys
2017-03-22 21:21:46 45672 ----a-w- C:\Windows\System32\drivers\dbx-canary.sys
2017-03-22 15:32:05 98816 ----a-w- C:\Windows\System32\wudriver.dll
2017-03-22 15:32:05 3165184 ----a-w- C:\Windows\System32\wucltux.dll
2017-03-22 15:32:05 192512 ----a-w- C:\Windows\System32\wuwebv.dll
2017-03-22 15:30:15 91136 ----a-w- C:\Windows\System32\WinSetupUI.dll
2017-03-22 15:24:42 174080 ----a-w- C:\Windows\SysWow64\wuwebv.dll
2017-03-22 15:15:15 37888 ----a-w- C:\Windows\System32\wuapp.exe
2017-03-22 15:15:08 12288 ----a-w- C:\Windows\System32\wu.upgrade.ps.dll
2017-03-22 15:05:37 35328 ----a-w- C:\Windows\SysWow64\wuapp.exe
2017-03-22 15:05:35 93696 ----a-w- C:\Windows\SysWow64\wudriver.dll
2017-03-22 11:44:34 161408 ----a-w- C:\Windows\System32\drivers\KeyCrypt64.sys
2017-03-21 18:01:38 98264 ----a-w- C:\Windows\System32\vmnetbridge.dll
2017-03-21 18:01:38 66520 ----a-w- C:\Windows\System32\drivers\vmnetbridge.sys
2017-03-21 18:01:38 46040 ----a-w- C:\Windows\System32\drivers\vmnetadapter.sys
2017-03-19 23:48:06 28352 ----a-w- C:\Windows\SysWow64\aspnet_counters.dll
2017-03-19 23:48:06 19112 ----a-w- C:\Windows\SysWow64\msvcr110_clr0400.dll
2017-03-19 23:48:06 19112 ----a-w- C:\Windows\SysWow64\msvcr100_clr0400.dll
2017-03-19 23:48:06 19112 ----a-w- C:\Windows\SysWow64\msvcp110_clr0400.dll
2017-03-19 23:41:38 30400 ----a-w- C:\Windows\System32\aspnet_counters.dll
2017-03-19 23:41:38 19112 ----a-w- C:\Windows\System32\msvcr110_clr0400.dll
2017-03-19 23:41:38 19112 ----a-w- C:\Windows\System32\msvcr100_clr0400.dll
2017-03-19 23:41:38 19112 ----a-w- C:\Windows\System32\msvcp110_clr0400.dll
2017-03-14 15:34:31 986344 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2017-03-14 15:34:30 265448 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2017-03-14 15:30:37 144384 ----a-w- C:\Windows\System32\cdd.dll
2017-03-10 16:35:56 382696 ----a-w- C:\Windows\System32\atmfd.dll
2017-03-10 16:31:58 41472 ----a-w- C:\Windows\System32\lpk.dll
2017-03-10 16:31:56 100864 ----a-w- C:\Windows\System32\fontsub.dll
2017-03-10 16:31:55 14336 ----a-w- C:\Windows\System32\dciman32.dll
2017-03-10 16:31:53 46080 ----a-w- C:\Windows\System32\atmlib.dll
2017-03-10 16:27:18 308456 ----a-w- C:\Windows\SysWow64\atmfd.dll
2017-03-10 16:20:40 25600 ----a-w- C:\Windows\SysWow64\lpk.dll
2017-03-10 16:19:45 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2017-03-10 16:19:38 10240 ----a-w- C:\Windows\SysWow64\dciman32.dll
2017-03-10 16:00:56 3219968 ----a-w- C:\Windows\System32\win32k.sys
2017-03-10 15:53:56 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2017-03-08 20:20:26 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2017-03-08 20:10:53 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2017-03-08 04:37:51 631176 ----a-w- C:\Windows\System32\winresume.efi
2017-03-08 04:36:43 706792 ----a-w- C:\Windows\System32\winload.efi
2017-03-08 04:36:43 5548264 ----a-w- C:\Windows\System32\ntoskrnl.exe
2017-03-08 04:36:41 95464 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2017-03-08 04:36:41 154856 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2017-03-08 04:34:53 1732864 ----a-w- C:\Windows\System32\ntdll.dll
2017-03-08 04:26:43 4000488 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2017-03-08 04:26:43 3945192 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
.
============= FINISH: 10:39:19.53 ===============

Attached Files
File Type: txt attach.txt (15.3 KB)

Possible malware/spyware - akamai

$
0
0
Hi to the Forum Volunteers. I'm using Windows 10 Home, version 1607, 64-bit operating system.

My problem seems to be mostly with one website ancestry.com. I have a problem loading pages, esp the tree pages on the site. This happens in Firefox, IE and Chrome. I've contacted Ancestry who've been unable to help.

When I try to load a page, it can take up to a minute - last time checking this morning it was taking 40 seconds. While the page is attempting to load, a number of messages flash by at the bottom of the page. The most persistent is "connecting to a248.e.akamai.net" - that can last 30 seconds or more. I also get a number of others including "transferring data from bam.nr-data.net".

This is so frustrating as I typically spend a lot of time on the site, but time spent is no longer so productive with this problem. Please help.

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.14393.953 BrowserJavaVersion: 11.121.2
Run by Mary at 10:58:01 on 2017-04-26
Microsoft Windows 10 Home 10.0.14393.0.1252.44.1033.18.12249.8198 [GMT 1:00]
.
AV: Avira Antivirus *Enabled/Updated* {B3F630BD-538D-1B4A-14FA-14B63235278F}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes *Enabled/Updated* {23007AD3-69FE-687C-2629-D584AFFAF72B}
SP: Avira Antivirus *Enabled/Updated* {0897D159-75B7-14C4-2E4A-2FC449B26D32}
SP: Malwarebytes *Disabled/Updated* {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\dashost.exe
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\Bin\IpOverUsbSvc.exe
C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\EscSvc64.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\System32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\DbxSvc.exe
C:\WINDOWS\System32\dwm.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\system32\taskhostw.exe
C:\Windows\System32\RuntimeBroker.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\WINDOWS\system32\SettingSyncHost.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe
C:\Users\Mary\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Users\Mary\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Users\Mary\AppData\Local\FlickrUploadrWindows\app-1.0.1.292\Flickr.exe
C:\Users\Mary\AppData\Local\Amazon Music\Amazon Music Helper.exe
C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files\McAfee Security Scan\3.11.523\SSScheduler.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVE.EXE
C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\fontdrvhost.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.14.662.0_x64__kzf8qxf38zg5c\SkypeHost.exe
C:\WINDOWS\system32\ApplicationFrameHost.exe
C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.14.662.0_x64__kzf8qxf38zg5c\SkypeApp.exe
C:\Windows\System32\PickerHost.exe
C:\Windows\System32\smartscreen.exe
C:\WINDOWS\system32\AUDIODG.EXE
svchost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://www.google.com/
uSearch Bar = hxxp://www.google.com/ie
uDefault_Page_URL = Dell Official Site | Dell United States
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
BHO: AcroIEHlprObj Class: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\java\jre1.8.0_121\bin\ssv.dll
BHO: Adobe Acrobat Create PDF Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
BHO: Microsoft OneDrive for Business Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\java\jre1.8.0_121\bin\jp2ssv.dll
BHO: Adobe Acrobat Create PDF from Selection: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
TB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
TB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
uRun: [GoogleChromeAutoLaunch_F1202FEEC9EAEB77B053C1DC4089370E] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
uRun: [Fitbit Connect] "C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe" /autorun
uRun: [OneDrive] "C:\Users\Mary\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
uRun: [Google Update] C:\Users\Mary\AppData\Local\Google\Update\1.3.33.3\GoogleUpdateCore.exe
uRun: [FlickrUploadr] "C:\Users\Mary\AppData\Local\FlickrUploadrWindows\Update.exe" --processStart Flickr.exe
uRun: [Spotify Web Helper] "C:\Users\Mary\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
uRun: [Spotify] "C:\Users\Mary\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized
uRun: [Adobe Acrobat Synchronizer] "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe"
uRun: [Amazon Music] "C:\Users\Mary\AppData\Local\Amazon Music\Amazon Music Helper.exe"
mRun: [CLMLServer_For_P2G8] "C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
mRun: [CLVirtualDrive] "C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
mRun: [Fitbit Connect] "C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe" /autorun
mRun: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
mRun: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
mRun: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe /SysAutoRun
mRun: [Avira SystrayStartTrigger] "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe"
mRun: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
mRun: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
mRun: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
mRun: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\Mary\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
StartupFolder: C:\Users\Mary\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONEDRI~1.LNK - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVE.EXE
StartupFolder: C:\Users\Mary\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
StartupFolder: C:\Users\Mary\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\SENDTO~1.LNK - C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\ADOBEA~1.LNK - C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-100000000002}\SC_Acrobat.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\IMAGEB~1.LNK - C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\MCAFEE~1.LNK - C:\Program Files\McAfee Security Scan\3.11.523\SSScheduler.exe
mPolicies-System: DSCAutomationHostEnabled = dword:2
IE: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
TCP: NameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{9fcd9ffe-77fe-4937-ba0d-29a434869822} : NameServer = 54.72.70.84,212.71.249.225
TCP: Interfaces\{9fcd9ffe-77fe-4937-ba0d-29a434869822} : DHCPNameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{9fcd9ffe-77fe-4937-ba0d-29a434869822}\35B4953443136473 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{9fcd9ffe-77fe-4937-ba0d-29a434869822}\E4F4B4941402C457D6961602633303F523631373 : NameServer = 54.72.70.84,212.71.249.225
TCP: Interfaces\{9fcd9ffe-77fe-4937-ba0d-29a434869822}\E4F4B4941402C457D6961602633303F523631373 : DHCPNameServer = 192.168.137.1
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-BHO: Adobe Acrobat Create PDF Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll
x64-BHO: <No Name>: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - LocalServer32 - <no file>
x64-BHO: Microsoft OneDrive for Business Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL
x64-BHO: Adobe Acrobat Create PDF from Selection: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll
x64-TB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
x64-Run: [RtHDVBg] "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX4
x64-Run: [Malwarebytes TrayApp] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe
x64-mPolicies-System: DSCAutomationHostEnabled = dword:2
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
x64-Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - <orphaned>
x64-Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - <orphaned>
x64-Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
x64-CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Mary\AppData\Roaming\Mozilla\Firefox\Profiles\gnnrkk7f.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.ie/?gws_rd=cr&ei=eBO0WM6MNsaLgAaDjaiYDQ
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll
FF - plugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll
FF - plugin: C:\Program Files (x86)\Glance29\npglance.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\java\jre1.8.0_121\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\java\jre1.8.0_121\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\browser\plugins\npMozCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
FF - plugin: C:\Users\Mary\AppData\Local\Citrix\Plugins\104\npappdetector.dll
FF - plugin: C:\Users\Mary\AppData\Local\Google\Update\1.3.33.3\npGoogleUpdate3.dll
FF - plugin: C:\Users\Mary\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Mary\AppData\Roaming\Mozilla\plugins\npo1d.dll
FF - plugin: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll
.
============= SERVICES / DRIVERS ===============
.
R0 iaStorA;iaStorA;C:\WINDOWS\System32\drivers\iaStorA.sys [2012-10-27 651832]
R0 intelpep;Intel(R) Power Engine Plug-in Driver;C:\WINDOWS\System32\drivers\intelpep.sys [2016-7-16 48152]
R0 iorate;iorate;C:\WINDOWS\System32\drivers\iorate.sys [2016-11-8 48992]
R0 volume;Volume driver;C:\WINDOWS\System32\drivers\volume.sys [2016-7-16 16224]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [2016-7-16 107032]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [2016-7-16 17944]
R0 Wof;Windows Overlay File System Filter Driver;C:\WINDOWS\System32\drivers\wof.sys [2016-9-25 199008]
R1 ahcache;Application Compatibility Cache;C:\WINDOWS\System32\drivers\ahcache.sys [2016-10-27 227328]
R1 avgtp;avgtp;C:\WINDOWS\System32\drivers\avgtpx64.sys [2013-10-24 46368]
R1 avkmgr;avkmgr;C:\WINDOWS\System32\drivers\avkmgr.sys [2013-10-17 44488]
R1 CLVirtualDrive;CLVirtualDrive;C:\WINDOWS\System32\drivers\CLVirtualDrive.sys [2013-8-23 92536]
R1 FileCrypt;FileCrypt;C:\WINDOWS\System32\drivers\filecrypt.sys [2016-7-16 88576]
R1 glancedrv;glancedrv;C:\WINDOWS\System32\drivers\glancedrv.sys [2015-2-18 36384]
R1 GpuEnergyDrv;GPU Energy Driver;C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2016-7-16 8192]
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-5-14 759048]
R2 AdobeUpdateService;AdobeUpdateService;C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [2016-10-25 744640]
R2 AGSService;Adobe Genuine Software Integrity Service;C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2016-3-3 2227312]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-10-17 487432]
R2 AntiVirService;Avira Real-Time Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-10-17 487432]
R2 avgntflt;avgntflt;C:\WINDOWS\System32\drivers\avgntflt.sys [2013-10-17 161824]
R2 Avira.ServiceHost;Avira Service Host;C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [2017-3-9 349560]
R2 avnetflt;avnetflt;C:\WINDOWS\System32\drivers\avnetflt.sys [2013-10-17 88488]
R2 CDPSvc;Connected Devices Platform Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
R2 CDPUserSvc_37a5d263;CDPUserSvc_37a5d263;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R2 ClickToRunSvc;Microsoft Office ClickToRun Service;C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe [2016-5-6 3294920]
R2 clreg;Virtual Registry for Containers;C:\WINDOWS\System32\drivers\registry.sys [2016-7-16 70144]
R2 CoreMessagingRegistrar;CoreMessaging;C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork [2016-7-16 44496]
R2 DbxSvc;DbxSvc;C:\WINDOWS\System32\DbxSvc.exe [2017-4-17 48944]
R2 DiagTrack;Connected User Experiences and Telemetry;C:\WINDOWS\System32\svchost.exe -k utcsvc [2016-7-16 44496]
R2 DoSvc;Delivery Optimization;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R2 EpsonScanSvc;Epson Scanner Service;C:\WINDOWS\System32\escsvc64.exe [2015-2-28 135824]
R2 Fitbit Connect;Fitbit Connect Service;C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [2014-5-19 1436192]
R2 IpOverUsbSvc;Windows Phone IP over USB Transport (IpOverUsbSvc);C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\Bin\IpOverUsbSvc.exe [2012-9-26 14760]
R2 MBAMChameleon;MBAMChameleon;C:\WINDOWS\System32\drivers\MBAMChameleon.sys [2017-1-26 186304]
R2 MBAMService;Malwarebytes Service;C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [2017-1-26 4355024]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2017-2-8 458176]
R2 OneSyncSvc_37a5d263;Sync Host_37a5d263;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [2015-4-17 494592]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-8-14 39056]
R2 RtkAudioService;Realtek Audio Service;C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2016-1-4 312056]
R2 storqosflt;Storage QoS Filter Driver;C:\WINDOWS\System32\drivers\storqosflt.sys [2016-7-16 78336]
R2 tiledatamodelsvc;Tile Data model server;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
R2 UserManager;User Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R2 wcifs;Windows Container Isolation;C:\WINDOWS\System32\drivers\wcifs.sys [2016-9-29 119648]
R2 wcnfs;Windows Container Name Virtualization;C:\WINDOWS\System32\drivers\wcnfs.sys [2016-7-16 66560]
R2 WpnService;Windows Push Notifications System Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R3 AppXSvc;AppX Deployment Service (AppXSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2016-7-16 44496]
R3 BtFilter;BtFilter;C:\WINDOWS\System32\drivers\btfilter.sys [2016-7-13 610336]
R3 BthA2DP;Bluetooth Stereo;C:\WINDOWS\System32\drivers\BthA2DP.sys [2016-9-29 168448]
R3 BthHFAud;Bluetooth Hands-Free;C:\WINDOWS\System32\drivers\BthHfAud.sys [2016-7-16 37376]
R3 BthHFSrv;Bluetooth Handsfree Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation [2016-7-16 44496]
R3 BthLEEnum;Bluetooth Low Energy Driver;C:\WINDOWS\System32\drivers\BthLEEnum.sys [2016-9-29 249856]
R3 DsSvc;Data Sharing Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
R3 IntcDAud;Intel(R) Display Audio;C:\WINDOWS\System32\drivers\IntcDAud.sys [2013-8-23 342528]
R3 lfsvc;Geolocation Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R3 LicenseManager;Windows License Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
R3 MBAMFarflt;MBAMFarflt;C:\WINDOWS\System32\drivers\farflt.sys [2017-1-26 111544]
R3 MBAMProtection;MBAMProtection;C:\WINDOWS\System32\drivers\mbam.sys [2017-1-26 43968]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [2015-6-30 251832]
R3 MBAMWebProtection;MBAMWebProtection;C:\WINDOWS\System32\drivers\mwac.sys [2017-1-26 92096]
R3 NcbService;Network Connection Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [2016-7-16 20480]
R3 PimIndexMaintenanceSvc_37a5d263;Contact Data_37a5d263;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R3 rt640x64;Realtek RT640 NT Driver;C:\WINDOWS\System32\drivers\rt640x64.sys [2016-7-16 589824]
R3 SmsRouter;Microsoft Windows SMS Router Service.;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
R3 StateRepository;State Repository Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
R3 TimeBrokerSvc;Time Broker;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
R3 UnistoreSvc_37a5d263;User Data Storage_37a5d263;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R3 UserDataSvc_37a5d263;User Data Access_37a5d263;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\drivers\WUDFRd.sys [2016-7-16 216064]
S2 AntiVirMailService;Avira Mail Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [2015-4-1 1115552]
S2 CLKMSVC10_38F51D56;CyberLink Product - 2013/08/22 19:12:48;C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2012-7-13 236144]
S2 dbupdate;Dropbox Update Service (dbupdate);C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-5-29 143144]
S2 MapsBroker;Downloaded Maps Manager;C:\WINDOWS\System32\svchost.exe -k NetworkService [2016-7-16 44496]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-1-16 317400]
S3 AcpiDev;ACPI Devices driver;C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-7-16 18432]
S3 ADP80XX;ADP80XX;C:\WINDOWS\System32\drivers\adp80xx.sys [2016-7-16 1135456]
S3 AJRouter;AllJoyn Router Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
S3 amdkmpfd;AMD PCI Root Bus Lower Filter;C:\WINDOWS\System32\drivers\amdkmpfd.sys [2013-8-23 36520]
S3 applockerfltr;Smartlocker Filter Driver;C:\WINDOWS\System32\drivers\applockerfltr.sys [2016-7-16 15360]
S3 AppReadiness;App Readiness;C:\WINDOWS\System32\svchost.exe -k AppReadiness [2016-7-16 44496]
S3 bcmfn;bcmfn Service;C:\WINDOWS\System32\drivers\bcmfn.sys [2016-7-16 9728]
S3 bcmfn2;bcmfn2 Service;C:\WINDOWS\System32\drivers\bcmfn2.sys [2016-7-16 9728]
S3 becldr3Service;BCL EasyConverter SDK 3 Loader;C:\Program Files\BCL Technologies\easyConverter SDK 3\Common\becldr.exe [2013-7-3 263168]
S3 BrYNSvc;BrYNSvc;C:\Program Files (x86)\Browny02\BrYNSvc.exe [2016-3-31 266240]
S3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;C:\WINDOWS\System32\drivers\btath_bus.sys [2013-8-23 33944]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\WINDOWS\System32\drivers\btath_hcrp.sys [2013-8-23 178840]
S3 BTATH_RCP;Bluetooth AVRCP Device;C:\WINDOWS\System32\drivers\btath_rcp.sys [2013-8-23 135832]
S3 buttonconverter;Service for Portable Device Control devices;C:\WINDOWS\System32\drivers\buttonconverter.sys [2016-7-16 38912]
S3 CapImg;HID driver for CapImg touch screen;C:\WINDOWS\System32\drivers\capimg.sys [2016-10-27 118272]
S3 cht4iscsi;cht4iscsi;C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-7-16 346976]
S3 cht4vbd;Chelsio Virtual Bus Driver;C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-7-16 2104160]
S3 ClipSVC;Client License Service (ClipSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2016-7-16 44496]
S3 dbupdatem;Dropbox Update Service (dbupdatem);C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-5-29 143144]
S3 DcpSvc;DataCollectionPublishingService;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 DevQueryBroker;DevQuery Background Discovery Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 diagnosticshub.standardcollector.service;Microsoft (R) Diagnostics Hub Standard Collector Service;C:\WINDOWS\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2016-7-16 93184]
S3 DmEnrollmentSvc;Device Management Enrollment Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 dmwappushservice;dmwappushsvc;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 embeddedmode;Embedded Mode;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 EntAppSvc;Enterprise App Management Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
S3 FrameServer;Windows Camera Frame Server;C:\WINDOWS\System32\svchost.exe -k Camera [2016-7-16 44496]
S3 genericusbfn;Generic USB Function Class;C:\WINDOWS\System32\drivers\genericusbfn.sys [2016-7-16 20480]
S3 hidinterrupt;Common Driver for HID Buttons implemented with interrupts;C:\WINDOWS\System32\drivers\hidinterrupt.sys [2016-7-16 50016]
S3 HvHost;HV Host Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 iagpio;Intel Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iagpio.sys [2016-7-16 33280]
S3 iai2c;Intel(R) Serial IO I2C Host Controller;C:\WINDOWS\System32\drivers\iai2c.sys [2016-7-16 81408]
S3 iaLPSS2i_GPIO2;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-7-16 64512]
S3 iaLPSS2i_I2C;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2016-7-16 176384]
S3 iaLPSSi_GPIO;Intel(R) Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [2016-7-16 38128]
S3 iaLPSSi_I2C;Intel(R) Serial IO I2C Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [2016-7-16 113152]
S3 iaStorAV;Intel(R) SATA RAID Controller Windows;C:\WINDOWS\System32\drivers\iaStorAV.sys [2016-7-16 673120]
S3 ibbus;Mellanox InfiniBand Bus/AL (Filter Driver);C:\WINDOWS\System32\drivers\ibbus.sys [2016-7-16 526176]
S3 icssvc;Windows Mobile Hotspot Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
S3 IndirectKmd;Indirect Displays Kernel-Mode Driver;C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-7-16 35840]
S3 lehidmini;Bluetooth Low Energy Hid Device;C:\WINDOWS\System32\drivers\leath_hid.sys [2013-8-23 39704]
S3 LSI_SAS2i;LSI_SAS2i;C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2016-7-16 105824]
S3 LSI_SAS3i;LSI_SAS3i;C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2016-7-16 101216]
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files\McAfee Security Scan\3.11.523\McCHSvc.exe [2017-3-20 404376]
S3 megasas2i;megasas2i;C:\WINDOWS\System32\drivers\MegaSas2i.sys [2016-10-12 64352]
S3 MessagingService_37a5d263;MessagingService_37a5d263;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
S3 mlx4_bus;Mellanox ConnectX Bus Enumerator;C:\WINDOWS\System32\drivers\mlx4_bus.sys [2016-7-16 842584]
S3 ndfltr;NetworkDirect Service;C:\WINDOWS\System32\drivers\ndfltr.sys [2016-7-16 108896]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library;C:\WINDOWS\System32\drivers\NetAdapterCx.sys [2016-7-16 90624]
S3 NetSetupSvc;Network Setup Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 NgcCtnrSvc;Microsoft Passport Container;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
S3 NgcSvc;Microsoft Passport;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;C:\WINDOWS\System32\drivers\nvstusb.sys [2013-8-23 445288]
S3 percsas2i;percsas2i;C:\WINDOWS\System32\drivers\percsas2i.sys [2016-7-16 58720]
S3 percsas3i;percsas3i;C:\WINDOWS\System32\drivers\percsas3i.sys [2016-7-16 61792]
S3 PhoneSvc;Phone Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
S3 qca_shb;Qualcomm Atheros UART Bus Driver;C:\WINDOWS\System32\drivers\qca_shb.sys [2013-8-23 99328]
S3 ReFSv1;ReFSv1;C:\WINDOWS\System32\drivers\refsv1.sys [2016-7-16 928608]
S3 RetailDemo;Retail Demo Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 scmbus;Microsoft Storage Class Memory Bus Driver;C:\WINDOWS\System32\drivers\scmbus.sys [2016-7-16 88416]
S3 scmdisk0101;Microsoft NVDIMM-N disk driver;C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-7-16 123904]
S3 SensorDataService;Sensor Data Service;C:\WINDOWS\System32\SensorDataService.exe [2017-3-15 1312768]
S3 SensorService;Sensor Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 SerCx2;Serial UART Support Library;C:\WINDOWS\System32\drivers\SerCx2.sys [2016-7-16 151904]
S3 smphost;Microsoft Storage Spaces SMP;C:\WINDOWS\System32\svchost.exe -k smphost [2016-7-16 44496]
S3 stornvme;Microsoft Standard NVM Express Driver;C:\WINDOWS\System32\drivers\stornvme.sys [2016-9-29 81760]
S3 storufs;Microsoft Universal Flash Storage (UFS) Driver;C:\WINDOWS\System32\drivers\storufs.sys [2016-7-16 32096]
S3 SWDUMon;SWDUMon;C:\WINDOWS\System32\drivers\SWDUMon.sys [2013-10-24 16152]
S3 TieringEngineService;Storage Tiers Management;C:\WINDOWS\System32\TieringEngineService.exe [2016-7-16 287744]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmCx.sys [2016-7-16 95744]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmTcpciCx.sys [2016-7-16 108544]
S3 UcmUcsi;USB Connector Manager UCSI Client;C:\WINDOWS\System32\drivers\UcmUcsi.sys [2016-7-16 50688]
S3 UdeCx;USB Device Emulation Support Library;C:\WINDOWS\System32\drivers\Udecx.sys [2016-7-16 45568]
S3 UEFI;Microsoft UEFI Driver;C:\WINDOWS\System32\drivers\uefi.sys [2016-7-16 28512]
S3 Ufx01000;USB Function Class Extension;C:\WINDOWS\System32\drivers\ufx01000.sys [2016-7-16 263008]
S3 UfxChipidea;USB Chipidea Controller;C:\WINDOWS\System32\drivers\UfxChipidea.sys [2016-7-16 96608]
S3 ufxsynopsys;USB Synopsys Controller;C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2016-7-16 137056]
S3 UrsChipidea;Chipidea USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urschipidea.sys [2016-7-16 28512]
S3 UrsCx01000;USB Role-Switch Support Library;C:\WINDOWS\System32\drivers\urscx01000.sys [2016-7-16 57696]
S3 UrsSynopsys;Synopsys USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urssynopsys.sys [2016-7-16 27488]
S3 UsoSvc;Update Orchestrator Service for Windows Update;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 vhf;Virtual HID Framework (VHF) Driver;C:\WINDOWS\System32\drivers\vhf.sys [2016-7-16 32256]
S3 vmgid;Microsoft Hyper-V Guest Infrastructure Driver;C:\WINDOWS\System32\drivers\vmgid.sys [2016-7-16 10240]
S3 vmicguestinterface;Hyper-V Guest Service Interface;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 vmicvmsession;Hyper-V PowerShell Direct Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 WalletService;WalletService;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\System32\drivers\wdcsam64.sys [2008-5-6 14464]
S3 wdiwifi;WDI Driver Framework;C:\WINDOWS\System32\drivers\WdiWiFi.sys [2017-3-15 719872]
S3 WdNisDrv;Windows Defender Network Inspection System Driver;C:\WINDOWS\System32\drivers\WdNisDrv.sys [2016-7-16 123232]
S3 WdNisSvc;Windows Defender Network Inspection Service;C:\Program Files\Windows Defender\NisSrv.exe [2017-4-11 347328]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;C:\WINDOWS\System32\svchost.exe -k WepHostSvcGroup [2016-7-16 44496]
S3 WinMad;WinMad Service;C:\WINDOWS\System32\drivers\winmad.sys [2016-7-16 32096]
S3 WinVerbs;WinVerbs Service;C:\WINDOWS\System32\drivers\winverbs.sys [2016-7-16 64864]
S3 wisvc;Windows Insider Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 workfolderssvc;Work Folders;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
S3 WpnUserService_37a5d263;Windows Push Notifications User Service_37a5d263;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
S3 WSDScan;WSD Scan Support;C:\WINDOWS\System32\drivers\WSDScan.sys [2016-7-16 24576]
S3 XblAuthManager;Xbox Live Auth Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 XblGameSave;Xbox Live Game Save;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 xboxgip;Xbox Game Input Protocol Driver;C:\WINDOWS\System32\drivers\xboxgip.sys [2017-3-15 258560]
S3 XboxNetApiSvc;Xbox Live Networking Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 xinputhid;XINPUT HID Filter Driver;C:\WINDOWS\System32\drivers\xinputhid.sys [2016-9-25 43520]
S4 AntiVirWebService;Avira Web Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [2013-10-17 1519136]
S4 shpamsvc;Shared PC Account Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S4 tzautoupdate;Auto Time Zone Updater;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
.
=============== Created Last 30 ================
.
2017-04-26 08:34:29 -------- d--h--w- C:\OneDriveTemp
2017-04-25 10:43:11 52168 ----a-w- C:\Program Files (x86)\Mozilla Firefox\tobedeleted\mozAF8B.tmp
2017-04-25 10:43:11 517064 ----a-w- C:\Program Files (x86)\Mozilla Firefox\tobedeleted\mozAF9B.tmp
2017-04-25 10:43:10 52526536 ----a-w- C:\Program Files (x86)\Mozilla Firefox\tobedeleted\mozAE8C.tmp
2017-04-25 10:43:10 321480 ----a-w- C:\Program Files (x86)\Mozilla Firefox\tobedeleted\mozAF67.tmp
2017-04-25 10:43:10 1340360 ----a-w- C:\Program Files (x86)\Mozilla Firefox\tobedeleted\mozAF79.tmp
2017-04-25 10:43:10 122312 ----a-w- C:\Program Files (x86)\Mozilla Firefox\tobedeleted\mozAF8A.tmp
2017-04-23 22:14:49 -------- d-----w- C:\Users\Mary\AppData\Local\Tempzxpsigne7990f0510b6c960
2017-04-23 22:14:39 -------- d-----w- C:\Users\Mary\AppData\Local\Tempzxpsign1ee33b7731b3f00d
2017-04-22 22:02:35 -------- d-----w- C:\Users\Mary\AppData\Local\Tempzxpsign1784313674279535
2017-04-22 22:02:32 -------- d-----w- C:\Users\Mary\AppData\Local\Tempzxpsignd3702ffceca17e7f
2017-04-22 22:00:48 -------- d-----w- C:\Users\Mary\AppData\Local\Tempzxpsignbaec54c41210fe33
2017-04-22 22:00:44 -------- d-----w- C:\Users\Mary\AppData\Local\Tempzxpsign8dc7ea75161d5f51
2017-04-20 23:41:36 -------- d-----w- C:\Users\Mary\AppData\Local\Tempzxpsign233c1ea52a9a97bd
2017-04-20 23:41:30 -------- d-----w- C:\Users\Mary\AppData\Local\Tempzxpsign1a71aff0d83998bc
2017-04-18 00:26:02 -------- d-----w- C:\Users\Mary\AppData\Local\Tempzxpsign7238e83cb1164258
2017-04-18 00:25:59 -------- d-----w- C:\Users\Mary\AppData\Local\Tempzxpsign773db3347baa9a8c
2017-04-17 15:14:04 48944 ----a-w- C:\WINDOWS\System32\DbxSvc.exe
2017-04-16 14:11:32 -------- d-----w- C:\Users\Mary\AppData\Local\Tempzxpsign0cbd8a463c5dd354
2017-04-16 14:11:26 -------- d-----w- C:\Users\Mary\AppData\Local\Tempzxpsign3d1ba100efd1f7b7
2017-04-12 14:47:59 -------- d-----w- C:\Users\Mary\AppData\Local\Tempzxpsignf4f6ddbc52f674d3
2017-04-12 14:47:55 -------- d-----w- C:\Users\Mary\AppData\Local\Tempzxpsignfdcbae0aaa7cd4c3
2017-04-11 19:50:58 3612672 ----a-w- C:\WINDOWS\System32\win32kfull.sys
2017-04-02 05:19:12 388384 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE
2017-04-02 05:14:28 29432 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll
2017-04-02 05:04:36 209104 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
.
==================== Find3M ====================
.
2017-04-26 09:10:31 92096 ----a-w- C:\WINDOWS\System32\drivers\mwac.sys
2017-04-14 14:58:48 111544 ----a-w- C:\WINDOWS\System32\drivers\farflt.sys
2017-04-14 14:58:47 43968 ----a-w- C:\WINDOWS\System32\drivers\mbam.sys
2017-04-14 14:58:45 251832 ----a-w- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
2017-04-14 14:58:17 77440 ----a-w- C:\WINDOWS\System32\drivers\mbae64.sys
2017-04-11 21:07:22 150264 ------w- C:\WINDOWS\System32\drivers\rikvm_38F51D56.sys
2017-04-08 00:05:44 97856 ----a-w- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
2017-04-07 23:28:37 186304 ----a-w- C:\WINDOWS\System32\drivers\MBAMChameleon.sys
2017-04-01 18:52:38 835576 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2017-04-01 18:52:38 177656 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2017-03-28 07:10:34 484584 ----a-w- C:\WINDOWS\SysWow64\AudioSes.dll
2017-03-28 07:10:28 315744 ----a-w- C:\WINDOWS\SysWow64\atmfd.dll
2017-03-28 06:36:11 142176 ----a-w- C:\WINDOWS\System32\acmigration.dll
2017-03-28 06:36:08 343904 ----a-w- C:\WINDOWS\System32\invagent.dll
2017-03-28 06:36:05 565088 ----a-w- C:\WINDOWS\System32\devinv.dll
2017-03-28 06:36:05 1617760 ----a-w- C:\WINDOWS\System32\appraiser.dll
2017-03-28 06:36:05 1294688 ----a-w- C:\WINDOWS\System32\aeinv.dll
2017-03-28 06:35:59 379232 ----a-w- C:\WINDOWS\System32\atmfd.dll
2017-03-28 06:32:26 198856 ----a-w- C:\WINDOWS\System32\wscapi.dll
2017-03-28 06:29:11 2213248 ----a-w- C:\WINDOWS\System32\KernelBase.dll
2017-03-28 06:28:05 7786336 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2017-03-28 06:28:03 773720 ----a-w- C:\WINDOWS\System32\oleaut32.dll
2017-03-28 06:26:21 603488 ----a-w- C:\WINDOWS\System32\ContentDeliveryManager.Utilities.dll
2017-03-28 06:26:11 218520 ----a-w- C:\WINDOWS\System32\LsaIso.exe
2017-03-28 06:22:07 2681200 ----a-w- C:\WINDOWS\System32\CoreUIComponents.dll
2017-03-28 06:21:27 167848 ----a-w- C:\WINDOWS\SysWow64\wscapi.dll
2017-03-28 06:20:43 2717184 ----a-w- C:\WINDOWS\SysWow64\PrintConfig.dll
2017-03-28 06:20:11 764392 ----a-w- C:\WINDOWS\System32\CoreMessaging.dll
2017-03-28 06:20:04 1181024 ----a-w- C:\WINDOWS\System32\drivers\ndis.sys
2017-03-28 06:19:26 601712 ----a-w- C:\WINDOWS\SysWow64\oleaut32.dll
2017-03-28 06:18:07 1705976 ----a-w- C:\WINDOWS\SysWow64\KernelBase.dll
2017-03-28 06:15:53 2048496 ----a-w- C:\WINDOWS\SysWow64\CoreUIComponents.dll
2017-03-28 06:12:54 328008 ----a-w- C:\WINDOWS\System32\Windows.Storage.ApplicationData.dll
2017-03-28 06:11:30 360040 ----a-w- C:\WINDOWS\System32\SystemSettingsAdminFlows.exe
2017-03-28 06:11:30 2187616 ----a-w- C:\WINDOWS\System32\drivers\dxgkrnl.sys
2017-03-28 06:11:14 1860288 ----a-w- C:\WINDOWS\System32\Windows.ApplicationModel.Store.dll
2017-03-28 06:11:11 1738560 ----a-w- C:\WINDOWS\System32\WindowsCodecs.dll
2017-03-28 06:11:09 402784 ----a-w- C:\WINDOWS\System32\drivers\dxgmms1.sys
2017-03-28 06:10:53 178528 ----a-w- C:\WINDOWS\System32\CloudExperienceHostUser.dll
2017-03-28 06:10:44 1157008 ----a-w- C:\WINDOWS\System32\twinapi.appcore.dll
2017-03-28 06:10:42 146776 ----a-w- C:\WINDOWS\System32\CloudExperienceHostCommon.dll
2017-03-28 06:10:41 7220184 ----a-w- C:\WINDOWS\System32\windows.storage.dll
2017-03-28 06:10:29 1293152 ----a-w- C:\WINDOWS\System32\LicenseManager.dll
2017-03-28 06:09:48 97128 ----a-w- C:\WINDOWS\System32\Windows.Security.Credentials.UI.CredentialPicker.dll
2017-03-28 06:09:40 624048 ----a-w- C:\WINDOWS\System32\drivers\cng.sys
2017-03-28 06:09:22 2446704 ----a-w- C:\WINDOWS\System32\msxml6.dll
2017-03-28 06:09:18 682816 ----a-w- C:\WINDOWS\System32\wer.dll
2017-03-28 06:08:48 1100128 ----a-w- C:\WINDOWS\System32\hvix64.exe
2017-03-28 06:08:43 1267504 ----a-w- C:\WINDOWS\System32\WinTypes.dll
2017-03-28 06:08:39 989024 ----a-w- C:\WINDOWS\System32\hvax64.exe
2017-03-28 06:07:35 263472 ----a-w- C:\WINDOWS\SysWow64\Windows.Storage.ApplicationData.dll
2017-03-28 06:06:47 92512 ----a-w- C:\WINDOWS\System32\rdpudd.dll
2017-03-28 06:05:31 4260576 ----a-w- C:\WINDOWS\System32\mfcore.dll
2017-03-28 06:05:29 8168512 ----a-w- C:\WINDOWS\System32\Windows.Media.Protection.PlayReady.dll
2017-03-28 06:05:17 1702392 ----a-w- C:\WINDOWS\System32\mfasfsrcsnk.dll
2017-03-28 06:05:15 1848584 ----a-w- C:\WINDOWS\System32\mfsrcsnk.dll
2017-03-28 06:05:14 1988048 ----a-w- C:\WINDOWS\System32\mfmp4srcsnk.dll
2017-03-28 06:05:14 1072248 ----a-w- C:\WINDOWS\System32\mfnetcore.dll
2017-03-28 06:05:11 1302136 ----a-w- C:\WINDOWS\System32\mfmpeg2srcsnk.dll
2017-03-28 06:05:07 1504056 ----a-w- C:\WINDOWS\SysWow64\WindowsCodecs.dll
2017-03-28 06:04:59 277344 ----a-w- C:\WINDOWS\System32\drivers\msiscsi.sys
2017-03-28 06:04:58 1431232 ----a-w- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.dll
2017-03-28 06:04:54 1276760 ----a-w- C:\WINDOWS\System32\ole32.dll
2017-03-28 06:04:53 136032 ----a-w- C:\WINDOWS\SysWow64\CloudExperienceHostUser.dll
2017-03-28 06:04:39 116568 ----a-w- C:\WINDOWS\SysWow64\CloudExperienceHostCommon.dll
2017-03-28 06:04:38 5721808 ----a-w- C:\WINDOWS\SysWow64\windows.storage.dll
2017-03-28 06:04:32 975744 ----a-w- C:\WINDOWS\SysWow64\twinapi.appcore.dll
2017-03-28 06:04:31 861024 ----a-w- C:\WINDOWS\SysWow64\LicenseManager.dll
2017-03-28 06:04:31 241504 ----a-w- C:\WINDOWS\System32\CloudExperienceHost.dll
2017-03-28 06:04:30 160088 ----a-w- C:\WINDOWS\System32\CloudExperienceHostBroker.dll
2017-03-28 06:04:17 1600632 ----a-w- C:\WINDOWS\System32\sppobjs.dll
2017-03-28 06:02:55 576408 ----a-w- C:\WINDOWS\SysWow64\wer.dll
2017-03-28 06:02:48 1980768 ----a-w- C:\WINDOWS\SysWow64\msxml6.dll
2017-03-28 06:02:01 846560 ----a-w- C:\WINDOWS\SysWow64\WinTypes.dll
2017-03-28 06:00:09 1569184 ----a-w- C:\WINDOWS\System32\gdi32full.dll
2017-03-28 06:00:05 628552 ----a-w- C:\WINDOWS\System32\fontdrvhost.exe
2017-03-28 05:59:11 6667520 ----a-w- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
2017-03-28 05:59:05 2533728 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2017-03-28 05:59:01 4023008 ----a-w- C:\WINDOWS\SysWow64\mfcore.dll
2017-03-28 05:58:59 1851688 ----a-w- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll
2017-03-28 05:58:53 981888 ----a-w- C:\WINDOWS\SysWow64\mfnetcore.dll
2017-03-28 05:58:53 1360464 ----a-w- C:\WINDOWS\SysWow64\mfnetsrc.dll
2017-03-28 05:58:53 1344448 ----a-w- C:\WINDOWS\SysWow64\mfsrcsnk.dll
2017-03-28 05:58:52 1277856 ----a-w- C:\WINDOWS\SysWow64\mfasfsrcsnk.dll
2017-03-28 05:58:50 1202936 ----a-w- C:\WINDOWS\SysWow64\mfmpeg2srcsnk.dll
2017-03-28 05:58:45 387872 ----a-w- C:\WINDOWS\System32\wmpps.dll
2017-03-28 05:58:44 372440 ----a-w- C:\WINDOWS\System32\Windows.Media.MediaControl.dll
2017-03-28 05:58:27 961192 ----a-w- C:\WINDOWS\SysWow64\ole32.dll
2017-03-28 05:53:54 545944 ----a-w- C:\WINDOWS\SysWow64\fontdrvhost.exe
2017-03-28 05:53:54 1414728 ----a-w- C:\WINDOWS\SysWow64\gdi32full.dll
2017-03-28 05:52:00 306800 ----a-w- C:\WINDOWS\SysWow64\Windows.Media.MediaControl.dll
2017-03-28 05:48:07 5685760 ----a-w- C:\WINDOWS\SysWow64\Windows.Data.Pdf.dll
2017-03-28 05:44:50 7216640 ----a-w- C:\WINDOWS\System32\Windows.Data.Pdf.dll
2017-03-28 05:42:28 95232 ----a-w- C:\WINDOWS\SysWow64\UserDataTimeUtil.dll
2017-03-28 05:42:06 51712 ----a-w- C:\WINDOWS\SysWow64\usoapi.dll
2017-03-28 05:41:51 372736 ----a-w- C:\WINDOWS\System32\RDXTaskFactory.dll
2017-03-28 05:41:51 26112 ----a-w- C:\WINDOWS\SysWow64\odbcconf.dll
2017-03-28 05:40:58 49664 ----a-w- C:\WINDOWS\SysWow64\XblAuthManagerProxy.dll
2017-03-28 05:40:53 37376 ----a-w- C:\WINDOWS\SysWow64\atmlib.dll
2017-03-28 05:40:19 224256 ----a-w- C:\WINDOWS\SysWow64\ExSMime.dll
.
============= FINISH: 10:59:19.06 ===============




I've been having problems for a number of weeks

Attached Files
File Type: txt attach.txt (18.9 KB)

Cat.exe and kitty.exe malware

$
0
0
Hey guys. My Sophos antivirus started blocking several pop-ups roughly two weeks ago. Sophos has been telling me that CAT.exe and Kitty.exe have been trying to open pop-ups. I find that the pop-ups really kick off whenever I am browsing a Google website such as gmail or google photos. I have used several anti malware/spyware programs such as Unhackme, Malwarebytes etc. The scans always find several issues, they clean them then restart my computer. When the computer is rebooted they do another scan and get rid of what is left. However, when I start the browser I start getting blocked pop ups every time.

*I do not have a bootable windows CD* And I am not sure if I have a bootable partition in HD*

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.14393.953
Run by BrendanJR at 12:40:51 on 2017-05-01
Microsoft Windows 10 Pro 10.0.14393.0.1252.44.1033.18.8088.5405 [GMT 1:00]
.
AV: Sophos Home *Enabled/Updated* {FFADE7EA-DC92-4602-D6B2-626CD3450A0F}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Sophos Home *Enabled/Updated* {44CC060E-FAA8-498C-EC02-591EA8C240B2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\system32\igfxCUIService.exe
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\ibmpmsvc.exe
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\System32\spoolsv.exe
C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\WINDOWS\system32\ibtsiva.exe
C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files\lenovo\SystemAgent\SystemAgentService.exe
C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Sophos Data Recorder\SDRService.exe
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsClient.exe
C:\Program Files (x86)\Lenovo\QuickControl\QuickControlMasterSvc.exe
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsAgent.exe
C:\Program Files (x86)\ScreenShot\SSSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_filter.exe
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
C:\Program Files\Sophos\Sophos System Protection\ssp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
C:\Program Files (x86)\Common Files\Sophos\Web Intelligence\swi_fc.exe
C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\dashost.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\Program Files (x86)\Lenovo\QuickControl\QuickControl.exe
C:\WINDOWS\system32\taskhostw.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Lenovo\QuickControl\QuickControlInput.exe
C:\Program Files (x86)\Lenovo\QuickControl\QuickControlInput.exe
C:\WINDOWS\system32\igfxEM.exe
C:\WINDOWS\system32\igfxHK.exe
C:\WINDOWS\system32\igfxTray.exe
C:\Windows\System32\RuntimeBroker.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe
C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE
C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Lenovo\HOTKEY\extapsup.exe
C:\Windows\System32\TpShocks.exe
C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe
C:\Users\BRENDA~1\AppData\Local\Temp\Monitor.exe
C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe
C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe
C:\Windows\SysWOW64\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
C:\Users\BrendanJR\AppData\Local\Apps\2.0\91Y1RLVH.YV2\MHO5ZVT5.D24\lsb...tion_91a10ba61c75c82d_0001.0005_a24d0d716055ed94\LSB.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files\lenovo\QuickSnipService\QuickSnipService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files\lenovo\QuickSnipService\QuickSnipInput.exe
C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
C:\WINDOWS\system32\ApplicationFrameHost.exe
C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
C:\WINDOWS\system32\fontdrvhost.exe
C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\taskhostw.exe
C:\WINDOWS\system32\AUDIODG.EXE
C:\Users\BrendanJR\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\WINDOWS\system32\svchost.exe -k SDRSVC
C:\Windows\System32\smartscreen.exe
C:\WINDOWS\System32\svchost.exe -k swprv
svchost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uProxyOverride = <local>
mWinlogon: Userinit = C:\WINDOWS\System32\userinit.exe
uRun: [OneDrive] "C:\Users\BrendanJR\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
uRun: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [WinPatrol] C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe
uRunOnce: [Uninstall C:\Users\BrendanJR\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64] C:\WINDOWS\System32\cmd.exe /q /c rmdir /s /q "C:\Users\BrendanJR\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"
mRun: [Fastboot] "C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" /analysis
mRun: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [Sophos AutoUpdate Monitor] "C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe"
mRun: [EaseUS Cleanup] "C:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.10\bin\CleanUpUI.exe" 10 300
mRun: [EaseUS EPM Tray Agent] "C:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.10\bin\TrayPopupE\TrayTipAgentE.exe"
dRunOnce: [Application Restart #1] C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe /Crashed
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: DSCAutomationHostEnabled = dword:2
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{3938f304-245e-49fb-b782-f4cd25f86124} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{3938f304-245e-49fb-b782-f4cd25f86124}\25F636B6162696C6C6 : DHCPNameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{3938f304-245e-49fb-b782-f4cd25f86124}\3596475636F6D6333413238393 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{3938f304-245e-49fb-b782-f4cd25f86124}\35B4950303641413 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{3938f304-245e-49fb-b782-f4cd25f86124}\35B4954464445403 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{3938f304-245e-49fb-b782-f4cd25f86124}\55D494F5449616D6F6E646F585 : DHCPNameServer = 192.168.43.1
TCP: Interfaces\{3938f304-245e-49fb-b782-f4cd25f86124}\A756E67657563747 : DHCPNameServer = 208.67.222.222 208.67.220.220
TCP: Interfaces\{3938f304-245e-49fb-b782-f4cd25f86124}\B6572696 : DHCPNameServer = 10.81.224.1
TCP: Interfaces\{3938f304-245e-49fb-b782-f4cd25f86124}\E6163716 : DHCPNameServer = 192.168.0.254 192.168.0.254
TCP: Interfaces\{3938f304-245e-49fb-b782-f4cd25f86124}\F4960275966496 : DHCPNameServer = 192.168.120.1
TCP: Interfaces\{451b8356-419a-41c7-a11e-4f84ea3da408} : DHCPNameServer = 192.168.42.129
TCP: Interfaces\{b8468cd5-e061-424f-a12b-e57e0178a255} : DHCPNameServer = 192.168.42.129
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
AppInit_DLLs= C:\PROGRA~2\Sophos\SOPHOS~1\\SOPHOS~1.DLL
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
x64-Run: [Integrated Camera_Monitor] "C:\Program Files (x86)\SunplusIT Integrated Camera\Monitor.exe"
x64-Run: [LenovoOptMouseUpdate] C:\Program Files\Lenovo\HOTKEY\extapsup.exe
x64-Run: [IgfxTray] "C:\WINDOWS\System32\igfxtray.exe"
x64-Run: [TpShocks] TpShocks.exe
x64-Run: [LnvMobHotspotClient] C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe
x64-mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
x64-mPolicies-System: DSCAutomationHostEnabled = dword:2
x64-Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
x64-CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
.
============= SERVICES / DRIVERS ===============
.
R0 Fastboot;Fastboot;C:\WINDOWS\System32\drivers\Fastboot.sys [2015-4-20 66288]
R0 iaStorA;iaStorA;C:\WINDOWS\System32\drivers\iaStorA.sys [2015-4-20 644968]
R0 intelpep;Intel(R) Power Engine Plug-in Driver;C:\WINDOWS\System32\drivers\intelpep.sys [2016-7-16 48152]
R0 iorate;iorate;C:\WINDOWS\System32\drivers\iorate.sys [2016-11-12 48992]
R0 pwdrvio;pwdrvio;C:\WINDOWS\System32\pwdrvio.sys [2017-1-11 19152]
R0 TPDIGIMN;TPDIGIMN;C:\WINDOWS\System32\drivers\ApsHM64.sys [2013-6-21 25856]
R0 volume;Volume driver;C:\WINDOWS\System32\drivers\volume.sys [2016-7-16 16224]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [2016-7-16 107032]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [2016-7-16 17944]
R0 Wof;Windows Overlay File System Filter Driver;C:\WINDOWS\System32\drivers\wof.sys [2016-11-12 199008]
R1 ahcache;Application Compatibility Cache;C:\WINDOWS\System32\drivers\ahcache.sys [2016-11-12 227328]
R1 FileCrypt;FileCrypt;C:\WINDOWS\System32\drivers\filecrypt.sys [2016-7-16 88576]
R1 GpuEnergyDrv;GPU Energy Driver;C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2016-7-16 8192]
R1 SAVOnAccess;SAVOnAccess;C:\WINDOWS\System32\drivers\savonaccess.sys [2016-4-8 201168]
R1 SMIDriver;Synaptics SMI Driver;C:\WINDOWS\System32\drivers\smi.sys [2016-7-13 39488]
R1 swi_callout;swi_callout;C:\WINDOWS\System32\drivers\swi_callout.sys [2017-4-5 47760]
R1 ZAM_Guard;ZAM Guard Driver;C:\WINDOWS\System32\drivers\zamguard64.sys [2017-4-18 203680]
R2 CDPSvc;Connected Devices Platform Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
R2 CDPUserSvc_50252;CDPUserSvc_50252;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R2 clreg;Virtual Registry for Containers;C:\WINDOWS\System32\drivers\registry.sys [2016-7-16 70144]
R2 CoreMessagingRegistrar;CoreMessaging;C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork [2016-7-16 44496]
R2 DiagTrack;Connected User Experiences and Telemetry;C:\WINDOWS\System32\svchost.exe -k utcsvc [2016-7-16 44496]
R2 FastbootService;FastbootService;C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [2015-4-20 140016]
R2 ibtsiva;Intel Bluetooth Service;C:\WINDOWS\System32\ibtsiva --> C:\WINDOWS\System32\ibtsiva [?]
R2 igfxCUIService2.0.0.0;Intel(R) HD Graphics Control Panel Service;C:\WINDOWS\System32\igfxCUIService.exe [2016-6-27 382456]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-5-12 733696]
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [2013-7-4 155448]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2015-4-20 169432]
R2 Lenovo QuickSnip Service;Lenovo QuickSnip Service;C:\Program Files\Lenovo\QuickSnipService\QuickSnipService.exe [2015-4-20 219976]
R2 Lenovo Settings Service;Lenovo Settings Service;C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [2015-4-20 2044408]
R2 Lenovo System Agent Service;Lenovo System Agent Service;C:\Program Files\Lenovo\SystemAgent\SystemAgentService.exe [2015-4-20 562504]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;C:\Program Files\Lenovo\HOTKEY\micmute.exe [2015-4-20 110072]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe [2015-4-20 136288]
R2 LocationTaskManager;Location Task Manager;C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe [2013-6-21 465912]
R2 OneSyncSvc_50252;Sync Host_50252;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R2 QuickControlMasterSvc;Lenovo QuickControl Master Service;C:\Program Files (x86)\Lenovo\QuickControl\QuickControlMasterSvc.exe [2013-7-16 59384]
R2 SAVAdminService;Sophos Anti-Virus status reporter;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2016-10-25 229672]
R2 SAVService;Sophos Anti-Virus;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [2016-10-25 200064]
R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [2017-2-2 780424]
R2 Sophos MCS Agent;Sophos MCS Agent;C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsAgent.exe [2016-9-4 1379856]
R2 Sophos MCS Client;Sophos MCS Client;C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsClient.exe [2016-9-4 1805368]
R2 Sophos Web Control Service;Sophos Web Control Service;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [2016-9-13 360040]
R2 SophosDataRecorderService;Sophos Data Recorder;C:\Program Files\Sophos\Sophos Data Recorder\SDRService.exe [2016-9-12 996240]
R2 sophossps;Sophos System Protection Service;C:\Program Files\Sophos\Sophos System Protection\ssp.exe [2016-9-12 5366040]
R2 SSSvc;SSSvc;C:\Program Files (x86)\ScreenShot\SSSvc.exe [2017-1-11 139744]
R2 storqosflt;Storage QoS Filter Driver;C:\WINDOWS\System32\drivers\storqosflt.sys [2016-7-16 78336]
R2 swi_filter;Sophos Web Filter;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_filter.exe [2016-9-13 475384]
R2 swi_service;Sophos Web Intelligence Service;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2016-9-13 3644368]
R2 SynTPEnhService;SynTPEnh Caller Service;C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2016-4-21 259176]
R2 tiledatamodelsvc;Tile Data model server;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
R2 TPHKLOAD;Lenovo Hotkey Client Loader;C:\Program Files\Lenovo\HOTKEY\tphkload.exe [2015-4-20 125432]
R2 UserManager;User Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R2 wcifs;Windows Container Isolation;C:\WINDOWS\System32\drivers\wcifs.sys [2016-11-12 119648]
R2 wcnfs;Windows Container Name Virtualization;C:\WINDOWS\System32\drivers\wcnfs.sys [2016-7-16 66560]
R2 WpnService;Windows Push Notifications System Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R3 AppXSvc;AppX Deployment Service (AppXSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2016-7-16 44496]
R3 BthLEEnum;Bluetooth Low Energy Driver;C:\WINDOWS\System32\drivers\BthLEEnum.sys [2016-11-12 249856]
R3 DsSvc;Data Sharing Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
R3 e1dexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver D;C:\WINDOWS\System32\drivers\e1d64x64.sys [2014-3-14 457496]
R3 EuMusDesignVirtualAudioCableWdm;@oem117.inf,%DeviceName% (WDM);Virtual Audio Cable (WDM);C:\WINDOWS\System32\drivers\vrtaucbl.sys [2010-2-15 66728]
R3 ibtusb;Intel(R) Wireless Bluetooth(R);C:\WINDOWS\System32\drivers\ibtusb.sys [2015-7-14 231168]
R3 ISCT;Intel(R) Smart Connect Technology Device Driver;C:\WINDOWS\System32\drivers\ISCTD64.sys [2013-7-30 47008]
R3 iwdbus;IWD Bus Enumerator;C:\WINDOWS\System32\drivers\iwdbus.sys [2015-3-4 30512]
R3 lfsvc;Geolocation Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R3 LicenseManager;Windows License Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
R3 NcbService;Network Connection Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [2016-7-16 20480]
R3 NETwNb64;___ Intel(R) Wireless Adapter Driver for Windows 8.1 - 64 Bit;C:\WINDOWS\System32\drivers\Netwbw02.sys [2016-7-16 3485696]
R3 PimIndexMaintenanceSvc_50252;Contact Data_50252;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R3 Power Manager DBC Service;Lenovo Settings Power Service;C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe [2015-4-20 1668904]
R3 QuickControlService;Lenovo QuickControl Service;C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe [2013-7-16 138232]
R3 RTSPER;Realtek PCIE Card Reader - PER;C:\WINDOWS\System32\drivers\RtsPer.sys [2015-6-15 761600]
R3 SensorService;Sensor Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
R3 SmbDrvI;SmbDrvI;C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [2016-1-8 51296]
R3 SmsRouter;Microsoft Windows SMS Router Service.;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
R3 SPUVCbv;SPUVCb Driver Service;C:\WINDOWS\System32\drivers\SPUVCBv_x64.sys [2015-8-24 698080]
R3 StateRepository;State Repository Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
R3 TimeBrokerSvc;Time Broker;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
R3 UnistoreSvc_50252;User Data Storage_50252;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R3 usb3Hub;UoIP Hub;C:\WINDOWS\System32\drivers\usb3Hub.sys [2013-6-21 206744]
R3 UserDataSvc_50252;User Data Access_50252;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\drivers\WUDFRd.sys [2016-7-16 216064]
S2 DoSvc;Delivery Optimization;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S2 MapsBroker;Downloaded Maps Manager;C:\WINDOWS\System32\svchost.exe -k NetworkService [2016-7-16 44496]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-2-27 317400]
S2 valWBFPolicyService;Synaptics FP WBF Policy Service;C:\WINDOWS\System32\valWBFPolicyService.exe [2016-7-13 86544]
S2 valWbioSyncSvc;BiometricSensorDataSynchronization;C:\WINDOWS\System32\valWbioSyncSvc.exe [2016-7-13 56848]
S3 AcpiDev;ACPI Devices driver;C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-7-16 18432]
S3 ADP80XX;ADP80XX;C:\WINDOWS\System32\drivers\adp80xx.sys [2016-7-16 1135456]
S3 AJRouter;AllJoyn Router Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
S3 applockerfltr;Smartlocker Filter Driver;C:\WINDOWS\System32\drivers\applockerfltr.sys [2016-7-16 15360]
S3 AppReadiness;App Readiness;C:\WINDOWS\System32\svchost.exe -k AppReadiness [2016-7-16 44496]
S3 AppvStrm;AppvStrm;C:\WINDOWS\System32\drivers\AppVStrm.sys [2016-11-12 127328]
S3 AppvVemgr;AppvVemgr;C:\WINDOWS\System32\drivers\AppvVemgr.sys [2016-7-16 157024]
S3 AppvVfs;AppvVfs;C:\WINDOWS\System32\drivers\AppvVfs.sys [2016-7-16 141152]
S3 bcmfn;bcmfn Service;C:\WINDOWS\System32\drivers\bcmfn.sys [2016-7-16 9728]
S3 bcmfn2;bcmfn2 Service;C:\WINDOWS\System32\drivers\bcmfn2.sys [2016-7-16 9728]
S3 BthHFSrv;Bluetooth Handsfree Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation [2016-7-16 44496]
S3 buttonconverter;Service for Portable Device Control devices;C:\WINDOWS\System32\drivers\buttonconverter.sys [2016-7-16 38912]
S3 CapImg;HID driver for CapImg touch screen;C:\WINDOWS\System32\drivers\capimg.sys [2016-11-12 118272]
S3 cht4iscsi;cht4iscsi;C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-7-16 346976]
S3 cht4vbd;Chelsio Virtual Bus Driver;C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-7-16 2104160]
S3 ClipSVC;Client License Service (ClipSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2016-7-16 44496]
S3 DcpSvc;DataCollectionPublishingService;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 DevQueryBroker;DevQuery Background Discovery Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\WINDOWS\System32\drivers\ssudbus.sys [2016-4-25 131712]
S3 diagnosticshub.standardcollector.service;Microsoft (R) Diagnostics Hub Standard Collector Service;C:\WINDOWS\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2016-7-16 93184]
S3 DmEnrollmentSvc;Device Management Enrollment Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 dmwappushservice;dmwappushsvc;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 embeddedmode;Embedded Mode;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 EntAppSvc;Enterprise App Management Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
S3 epmntdrv;epmntdrv;C:\WINDOWS\System32\epmntdrv.sys [2017-3-13 33448]
S3 EuGdiDrv;EuGdiDrv;C:\WINDOWS\System32\EuGdiDrv.sys [2017-3-13 10848]
S3 FrameServer;Windows Camera Frame Server;C:\WINDOWS\System32\svchost.exe -k Camera [2016-7-16 44496]
S3 genericusbfn;Generic USB Function Class;C:\WINDOWS\System32\drivers\genericusbfn.sys [2016-7-16 20480]
S3 hidinterrupt;Common Driver for HID Buttons implemented with interrupts;C:\WINDOWS\System32\drivers\hidinterrupt.sys [2016-7-16 50016]
S3 HvHost;HV Host Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 iagpio;Intel Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iagpio.sys [2016-7-16 33280]
S3 iai2c;Intel(R) Serial IO I2C Host Controller;C:\WINDOWS\System32\drivers\iai2c.sys [2016-7-16 81408]
S3 iaLPSS2i_GPIO2;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-7-16 64512]
S3 iaLPSS2i_I2C;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2016-7-16 176384]
S3 iaLPSSi_GPIO;Intel(R) Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [2016-7-16 38128]
S3 iaLPSSi_I2C;Intel(R) Serial IO I2C Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [2016-7-16 113152]
S3 iaStorAV;Intel(R) SATA RAID Controller Windows;C:\WINDOWS\System32\drivers\iaStorAV.sys [2016-7-16 673120]
S3 ibbus;Mellanox InfiniBand Bus/AL (Filter Driver);C:\WINDOWS\System32\drivers\ibbus.sys [2016-7-16 526176]
S3 icssvc;Windows Mobile Hotspot Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
S3 IndirectKmd;Indirect Displays Kernel-Mode Driver;C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-7-16 35840]
S3 IntcDAud;Intel(R) Display Audio;C:\WINDOWS\System32\drivers\IntcDAud.sys [2016-5-12 481768]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-5-12 822232]
S3 LnvHotSpotSvc;Lenovo Settings Mobile Hotspot Service;C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe [2015-4-20 468984]
S3 LSCWinService;LSCWinService;C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [2016-1-8 272864]
S3 LSI_SAS2i;LSI_SAS2i;C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2016-7-16 105824]
S3 LSI_SAS3i;LSI_SAS3i;C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2016-7-16 101216]
S3 megasas2i;megasas2i;C:\WINDOWS\System32\drivers\MegaSas2i.sys [2016-11-12 64352]
S3 MessagingService_50252;MessagingService_50252;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
S3 mlx4_bus;Mellanox ConnectX Bus Enumerator;C:\WINDOWS\System32\drivers\mlx4_bus.sys [2016-7-16 842584]
S3 MsSecFlt;Microsoft Security Events Component Minifilter;C:\WINDOWS\System32\drivers\mssecflt.sys [2016-7-16 179040]
S3 ndfltr;NetworkDirect Service;C:\WINDOWS\System32\drivers\ndfltr.sys [2016-7-16 108896]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library;C:\WINDOWS\System32\drivers\NetAdapterCx.sys [2016-7-16 90624]
S3 NetSetupSvc;Network Setup Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 NgcCtnrSvc;Microsoft Passport Container;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
S3 NgcSvc;Microsoft Passport;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 percsas2i;percsas2i;C:\WINDOWS\System32\drivers\percsas2i.sys [2016-7-16 58720]
S3 percsas3i;percsas3i;C:\WINDOWS\System32\drivers\percsas3i.sys [2016-7-16 61792]
S3 PhoneSvc;Phone Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
S3 pwdspio;pwdspio;C:\WINDOWS\System32\pwdspio.sys [2017-1-11 12504]
S3 ReFSv1;ReFSv1;C:\WINDOWS\System32\drivers\refsv1.sys [2016-7-16 928608]
S3 RetailDemo;Retail Demo Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 scmbus;Microsoft Storage Class Memory Bus Driver;C:\WINDOWS\System32\drivers\scmbus.sys [2016-7-16 88416]
S3 scmdisk0101;Microsoft NVDIMM-N disk driver;C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-7-16 123904]
S3 sdcfilter;sdcfilter;C:\WINDOWS\System32\drivers\sdcfilter.sys [2016-11-14 38144]
S3 Sense;Windows Defender Advanced Threat Protection Service;C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2016-11-12 2889896]
S3 SensorDataService;Sensor Data Service;C:\WINDOWS\System32\SensorDataService.exe [2017-3-15 1312768]
S3 SerCx2;Serial UART Support Library;C:\WINDOWS\System32\drivers\SerCx2.sys [2016-7-16 151904]
S3 smphost;Microsoft Storage Spaces SMP;C:\WINDOWS\System32\svchost.exe -k smphost [2016-7-16 44496]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\WINDOWS\System32\drivers\ssudmdm.sys [2014-1-22 165504]
S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);C:\WINDOWS\System32\drivers\ssudserd.sys [2016-1-11 165504]
S3 stornvme;Microsoft Standard NVM Express Driver;C:\WINDOWS\System32\drivers\stornvme.sys [2016-11-12 81760]
S3 storufs;Microsoft Universal Flash Storage (UFS) Driver;C:\WINDOWS\System32\drivers\storufs.sys [2016-7-16 32096]
S3 TieringEngineService;Storage Tiers Management;C:\WINDOWS\System32\TieringEngineService.exe [2016-7-16 287744]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmCx.sys [2016-7-16 95744]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmTcpciCx.sys [2016-7-16 108544]
S3 UcmUcsi;USB Connector Manager UCSI Client;C:\WINDOWS\System32\drivers\UcmUcsi.sys [2016-7-16 50688]
S3 UdeCx;USB Device Emulation Support Library;C:\WINDOWS\System32\drivers\Udecx.sys [2016-7-16 45568]
S3 UEFI;Microsoft UEFI Driver;C:\WINDOWS\System32\drivers\uefi.sys [2016-7-16 28512]
S3 Ufx01000;USB Function Class Extension;C:\WINDOWS\System32\drivers\ufx01000.sys [2016-7-16 263008]
S3 UfxChipidea;USB Chipidea Controller;C:\WINDOWS\System32\drivers\UfxChipidea.sys [2016-7-16 96608]
S3 ufxsynopsys;USB Synopsys Controller;C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2016-7-16 137056]
S3 UrsChipidea;Chipidea USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urschipidea.sys [2016-7-16 28512]
S3 UrsCx01000;USB Role-Switch Support Library;C:\WINDOWS\System32\drivers\urscx01000.sys [2016-7-16 57696]
S3 UrsSynopsys;Synopsys USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urssynopsys.sys [2016-7-16 27488]
S3 usbrndis6;USB RNDIS6 Adapter;C:\WINDOWS\System32\drivers\usb80236.sys [2016-7-16 23040]
S3 UsoSvc;Update Orchestrator Service for Windows Update;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 vhf;Virtual HID Framework (VHF) Driver;C:\WINDOWS\System32\drivers\vhf.sys [2016-7-16 32256]
S3 vmgid;Microsoft Hyper-V Guest Infrastructure Driver;C:\WINDOWS\System32\drivers\vmgid.sys [2016-7-16 10240]
S3 vmicguestinterface;Hyper-V Guest Service Interface;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 vmicvmsession;Hyper-V PowerShell Direct Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 WalletService;WalletService;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
S3 wdiwifi;WDI Driver Framework;C:\WINDOWS\System32\drivers\WdiWiFi.sys [2017-3-15 719872]
S3 wdm_usb;wdm_usb;C:\WINDOWS\System32\drivers\usb2ser.sys [2016-8-16 159936]
S3 WdNisDrv;Windows Defender Network Inspection System Driver;C:\WINDOWS\System32\drivers\WdNisDrv.sys [2016-7-16 123232]
S3 WdNisSvc;Windows Defender Network Inspection Service;C:\Program Files\Windows Defender\NisSrv.exe [2017-4-16 347328]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;C:\WINDOWS\System32\svchost.exe -k WepHostSvcGroup [2016-7-16 44496]
S3 WinMad;WinMad Service;C:\WINDOWS\System32\drivers\winmad.sys [2016-7-16 32096]
S3 WinVerbs;WinVerbs Service;C:\WINDOWS\System32\drivers\winverbs.sys [2016-7-16 64864]
S3 wisvc;Windows Insider Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 workfolderssvc;Work Folders;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
S3 WpnUserService_50252;Windows Push Notifications User Service_50252;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
S3 XblAuthManager;Xbox Live Auth Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 XblGameSave;Xbox Live Game Save;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 xboxgip;Xbox Game Input Protocol Driver;C:\WINDOWS\System32\drivers\xboxgip.sys [2017-3-15 258560]
S3 XboxNetApiSvc;Xbox Live Networking Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 xinputhid;XINPUT HID Filter Driver;C:\WINDOWS\System32\drivers\xinputhid.sys [2016-11-12 43520]
S4 AppVClient;Microsoft App-V Client;C:\WINDOWS\System32\AppVClient.exe [2017-1-11 822624]
S4 BrcmSetSecurity;BrcmSetSecurity;C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [2013-7-26 283296]
S4 shpamsvc;Shared PC Account Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S4 SophosBootDriver;SophosBootDriver;C:\WINDOWS\System32\drivers\SophosBootDriver.sys [2016-11-14 27904]
S4 tzautoupdate;Auto Time Zone Updater;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
S4 UevAgentDriver;UevAgentDriver;C:\WINDOWS\System32\drivers\UevAgentDriver.sys [2016-7-16 40288]
S4 UevAgentService;User Experience Virtualization Service;C:\WINDOWS\System32\AgentService.exe [2016-7-16 1227264]
.
=============== File Associations ===============
.
ShellExec: SZBrowser.exe: open="C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" "%1"
.
=============== Created Last 30 ================
.
2017-05-01 11:29:14 30087 ----a-w- C:\ProgramData\agent.uninstall.1493638149.bdinstall.bin
2017-04-23 22:50:15 -------- d-----w- C:\ProgramData\dbg
2017-04-23 14:16:15 -------- d-----w- C:\Program Files\Malwarebytes
2017-04-23 14:02:03 -------- d-----w- C:\Program Files\HitmanPro
2017-04-23 14:01:50 -------- d-----w- C:\ProgramData\HitmanPro
2017-04-23 14:00:15 -------- d-----w- C:\AdwCleaner
2017-04-22 14:50:21 -------- d-----w- C:\@RestoreQuarantine
2017-04-22 14:28:15 -------- d-----w- C:\ProgramData\RegRun
2017-04-22 14:27:31 40304 ----a-w- C:\WINDOWS\SysWow64\drivers\Partizan.sys
2017-04-22 14:27:11 2 --shatr- C:\WINDOWS\winstart.bat
2017-04-22 14:27:03 49968 ----a-w- C:\WINDOWS\System32\partizan.exe
2017-04-22 14:27:03 14984 ----a-w- C:\WINDOWS\SysWow64\drivers\UnHackMeDrv.sys
2017-04-22 14:26:49 -------- d---a-w- C:\Program Files (x86)\UnHackMe
2017-04-20 18:29:42 -------- d-----w- C:\Program Files (x86)\AirShowPcSender
2017-04-19 07:52:50 1190000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FCD6F575-9670-1B44-D27A-F29E7FFBE241}\GapaEngine.dll
2017-04-17 23:15:21 203680 ----a-w- C:\WINDOWS\System32\drivers\zamguard64.sys
2017-04-17 23:15:18 -------- d---a-w- C:\Program Files (x86)\Zemana AntiMalware
2017-04-17 23:15:08 -------- d-----w- C:\Users\BrendanJR\AppData\Local\Zemana
2017-04-17 13:40:53 -------- d-----w- C:\ProgramData\Software
2017-04-16 12:12:59 87040 ----a-w- C:\WINDOWS\SysWow64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-16 12:11:59 975872 ----a-w- C:\WINDOWS\HelpPane.exe
2017-04-05 18:45:01 47760 ----a-w- C:\WINDOWS\System32\drivers\swi_callout.sys
.
==================== Find3M ====================
.
2017-04-25 20:30:38 180 ----a-w- C:\WINDOWS\System32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-04-16 22:38:56 532136 ------w- C:\WINDOWS\System32\MpSigStub.exe
2017-04-01 18:52:38 835576 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2017-04-01 18:52:38 177656 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2017-03-28 07:10:34 484584 ----a-w- C:\WINDOWS\SysWow64\AudioSes.dll
2017-03-28 07:10:28 315744 ----a-w- C:\WINDOWS\SysWow64\atmfd.dll
2017-03-28 06:36:11 142176 ----a-w- C:\WINDOWS\System32\acmigration.dll
2017-03-28 06:36:08 343904 ----a-w- C:\WINDOWS\System32\invagent.dll
2017-03-28 06:36:05 565088 ----a-w- C:\WINDOWS\System32\devinv.dll
2017-03-28 06:36:05 1617760 ----a-w- C:\WINDOWS\System32\appraiser.dll
2017-03-28 06:36:05 1294688 ----a-w- C:\WINDOWS\System32\aeinv.dll
2017-03-28 06:35:59 379232 ----a-w- C:\WINDOWS\System32\atmfd.dll
2017-03-28 06:32:26 198856 ----a-w- C:\WINDOWS\System32\wscapi.dll
2017-03-28 06:29:11 2213248 ----a-w- C:\WINDOWS\System32\KernelBase.dll
2017-03-28 06:28:05 7786336 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2017-03-28 06:28:03 773720 ----a-w- C:\WINDOWS\System32\oleaut32.dll
2017-03-28 06:26:23 573280 ----a-w- C:\WINDOWS\System32\AppVCatalog.dll
2017-03-28 06:26:21 603488 ----a-w- C:\WINDOWS\System32\ContentDeliveryManager.Utilities.dll
2017-03-28 06:26:20 754528 ----a-w- C:\WINDOWS\System32\AppVOrchestration.dll
2017-03-28 06:26:11 218520 ----a-w- C:\WINDOWS\System32\LsaIso.exe
2017-03-28 06:22:07 2681200 ----a-w- C:\WINDOWS\System32\CoreUIComponents.dll
2017-03-28 06:21:27 167848 ----a-w- C:\WINDOWS\SysWow64\wscapi.dll
2017-03-28 06:20:43 2717184 ----a-w- C:\WINDOWS\SysWow64\PrintConfig.dll
2017-03-28 06:20:11 764392 ----a-w- C:\WINDOWS\System32\CoreMessaging.dll
2017-03-28 06:20:04 1181024 ----a-w- C:\WINDOWS\System32\drivers\ndis.sys
2017-03-28 06:19:26 601712 ----a-w- C:\WINDOWS\SysWow64\oleaut32.dll
2017-03-28 06:18:07 1705976 ----a-w- C:\WINDOWS\SysWow64\KernelBase.dll
2017-03-28 06:15:53 2048496 ----a-w- C:\WINDOWS\SysWow64\CoreUIComponents.dll
2017-03-28 06:12:54 328008 ----a-w- C:\WINDOWS\System32\Windows.Storage.ApplicationData.dll
2017-03-28 06:11:30 360040 ----a-w- C:\WINDOWS\System32\SystemSettingsAdminFlows.exe
2017-03-28 06:11:30 2187616 ----a-w- C:\WINDOWS\System32\drivers\dxgkrnl.sys
2017-03-28 06:11:14 1860288 ----a-w- C:\WINDOWS\System32\Windows.ApplicationModel.Store.dll
2017-03-28 06:11:11 1738560 ----a-w- C:\WINDOWS\System32\WindowsCodecs.dll
2017-03-28 06:11:09 402784 ----a-w- C:\WINDOWS\System32\drivers\dxgmms1.sys
2017-03-28 06:10:53 178528 ----a-w- C:\WINDOWS\System32\CloudExperienceHostUser.dll
2017-03-28 06:10:44 1157008 ----a-w- C:\WINDOWS\System32\twinapi.appcore.dll
2017-03-28 06:10:42 146776 ----a-w- C:\WINDOWS\System32\CloudExperienceHostCommon.dll
2017-03-28 06:10:41 7220184 ----a-w- C:\WINDOWS\System32\windows.storage.dll
2017-03-28 06:10:29 1293152 ----a-w- C:\WINDOWS\System32\LicenseManager.dll
2017-03-28 06:09:48 97128 ----a-w- C:\WINDOWS\System32\Windows.Security.Credentials.UI.CredentialPicker.dll
2017-03-28 06:09:40 624048 ----a-w- C:\WINDOWS\System32\drivers\cng.sys
2017-03-28 06:09:22 2446704 ----a-w- C:\WINDOWS\System32\msxml6.dll
2017-03-28 06:09:18 682816 ----a-w- C:\WINDOWS\System32\wer.dll
2017-03-28 06:08:48 1100128 ----a-w- C:\WINDOWS\System32\hvix64.exe
2017-03-28 06:08:43 1267504 ----a-w- C:\WINDOWS\System32\WinTypes.dll
2017-03-28 06:08:39 989024 ----a-w- C:\WINDOWS\System32\hvax64.exe
2017-03-28 06:07:35 263472 ----a-w- C:\WINDOWS\SysWow64\Windows.Storage.ApplicationData.dll
2017-03-28 06:06:47 92512 ----a-w- C:\WINDOWS\System32\rdpudd.dll
2017-03-28 06:05:31 4260576 ----a-w- C:\WINDOWS\System32\mfcore.dll
2017-03-28 06:05:29 8168512 ----a-w- C:\WINDOWS\System32\Windows.Media.Protection.PlayReady.dll
2017-03-28 06:05:17 1702392 ----a-w- C:\WINDOWS\System32\mfasfsrcsnk.dll
2017-03-28 06:05:15 1848584 ----a-w- C:\WINDOWS\System32\mfsrcsnk.dll
2017-03-28 06:05:14 1988048 ----a-w- C:\WINDOWS\System32\mfmp4srcsnk.dll
2017-03-28 06:05:14 1072248 ----a-w- C:\WINDOWS\System32\mfnetcore.dll
2017-03-28 06:05:11 1302136 ----a-w- C:\WINDOWS\System32\mfmpeg2srcsnk.dll
2017-03-28 06:05:07 1504056 ----a-w- C:\WINDOWS\SysWow64\WindowsCodecs.dll
2017-03-28 06:04:59 277344 ----a-w- C:\WINDOWS\System32\drivers\msiscsi.sys
2017-03-28 06:04:58 1431232 ----a-w- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.dll
2017-03-28 06:04:54 1276760 ----a-w- C:\WINDOWS\System32\ole32.dll
2017-03-28 06:04:53 136032 ----a-w- C:\WINDOWS\SysWow64\CloudExperienceHostUser.dll
2017-03-28 06:04:39 116568 ----a-w- C:\WINDOWS\SysWow64\CloudExperienceHostCommon.dll
2017-03-28 06:04:38 5721808 ----a-w- C:\WINDOWS\SysWow64\windows.storage.dll
2017-03-28 06:04:32 975744 ----a-w- C:\WINDOWS\SysWow64\twinapi.appcore.dll
2017-03-28 06:04:31 861024 ----a-w- C:\WINDOWS\SysWow64\LicenseManager.dll
2017-03-28 06:04:31 241504 ----a-w- C:\WINDOWS\System32\CloudExperienceHost.dll
2017-03-28 06:04:30 160088 ----a-w- C:\WINDOWS\System32\CloudExperienceHostBroker.dll
2017-03-28 06:04:17 1600632 ----a-w- C:\WINDOWS\System32\sppobjs.dll
2017-03-28 06:02:55 576408 ----a-w- C:\WINDOWS\SysWow64\wer.dll
2017-03-28 06:02:48 1980768 ----a-w- C:\WINDOWS\SysWow64\msxml6.dll
2017-03-28 06:02:01 846560 ----a-w- C:\WINDOWS\SysWow64\WinTypes.dll
2017-03-28 06:00:09 1569184 ----a-w- C:\WINDOWS\System32\gdi32full.dll
2017-03-28 06:00:05 628552 ----a-w- C:\WINDOWS\System32\fontdrvhost.exe
2017-03-28 05:59:11 6667520 ----a-w- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
2017-03-28 05:59:05 2533728 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2017-03-28 05:59:01 4023008 ----a-w- C:\WINDOWS\SysWow64\mfcore.dll
2017-03-28 05:58:59 1851688 ----a-w- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll
2017-03-28 05:58:53 981888 ----a-w- C:\WINDOWS\SysWow64\mfnetcore.dll
2017-03-28 05:58:53 1360464 ----a-w- C:\WINDOWS\SysWow64\mfnetsrc.dll
2017-03-28 05:58:53 1344448 ----a-w- C:\WINDOWS\SysWow64\mfsrcsnk.dll
2017-03-28 05:58:52 1277856 ----a-w- C:\WINDOWS\SysWow64\mfasfsrcsnk.dll
2017-03-28 05:58:50 1202936 ----a-w- C:\WINDOWS\SysWow64\mfmpeg2srcsnk.dll
2017-03-28 05:58:45 387872 ----a-w- C:\WINDOWS\System32\wmpps.dll
2017-03-28 05:58:44 372440 ----a-w- C:\WINDOWS\System32\Windows.Media.MediaControl.dll
2017-03-28 05:58:27 961192 ----a-w- C:\WINDOWS\SysWow64\ole32.dll
2017-03-28 05:53:54 545944 ----a-w- C:\WINDOWS\SysWow64\fontdrvhost.exe
2017-03-28 05:53:54 1414728 ----a-w- C:\WINDOWS\SysWow64\gdi32full.dll
2017-03-28 05:52:00 306800 ----a-w- C:\WINDOWS\SysWow64\Windows.Media.MediaControl.dll
2017-03-28 05:48:07 5685760 ----a-w- C:\WINDOWS\SysWow64\Windows.Data.Pdf.dll
2017-03-28 05:44:50 7216640 ----a-w- C:\WINDOWS\System32\Windows.Data.Pdf.dll
2017-03-28 05:42:28 95232 ----a-w- C:\WINDOWS\SysWow64\UserDataTimeUtil.dll
2017-03-28 05:42:06 51712 ----a-w- C:\WINDOWS\SysWow64\usoapi.dll
2017-03-28 05:41:51 372736 ----a-w- C:\WINDOWS\System32\RDXTaskFactory.dll
2017-03-28 05:41:51 26112 ----a-w- C:\WINDOWS\SysWow64\odbcconf.dll
2017-03-28 05:41:49 299008 ----a-w- C:\WINDOWS\System32\rdpinit.exe
2017-03-28 05:41:47 415744 ----a-w- C:\WINDOWS\System32\rdpshell.exe
2017-03-28 05:40:58 49664 ----a-w- C:\WINDOWS\SysWow64\XblAuthManagerProxy.dll
2017-03-28 05:40:53 37376 ----a-w- C:\WINDOWS\SysWow64\atmlib.dll
2017-03-28 05:40:19 224256 ----a-w- C:\WINDOWS\SysWow64\ExSMime.dll
2017-03-28 05:39:48 141824 ----a-w- C:\WINDOWS\SysWow64\Windows.Devices.Radios.dll
2017-03-28 05:39:17 40960 ----a-w- C:\WINDOWS\SysWow64\TokenBrokerUI.dll
.
============= FINISH: 12:41:09.17 ===============

Attached Files
File Type: txt attach.txt (7.6 KB)

Files on Flash Drive Keeps converted to short cuts and the original File disappears

$
0
0
Files on Flash Drive Keeps converted to short cuts and the original File disappears .

I have tried to format more than once and tried scan with AVG and nothing is wrong. but after I format the flash drive and opens it again after few seconds a shortcut file appears , and If i paste any file in the flash drive it gets converted to shortcut after the paste is done. here is the DDS.txt

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16555
Run by Ahmed at 16:19:17 on 2017-05-01
Microsoft Windows 7 Home Basic 6.1.7601.1.1252.1.1033.18.4087.2539 [GMT 2:00]
.
AV: AVG Antivirus *Enabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG Antivirus *Enabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
C:\Windows\system32\taskeng.exe
D:\Foxit PhantomPDF\FoxitConnectedPDFService.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe
C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe
C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
"C:\Users\Ahmed\AppData\Local\Temp\eco\svchost.exe" //B "C:\Users\Ahmed\AppData\Local\Temp\eco\explre.vbs"
C:\Users\Ahmed\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mWinlogon: Userinit = userinit.exe
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Foxit PhantomPDF Create PDF ToolBar Helper: {A5DD10F7-5ABB-4EEF-B4C8-6748D44DAF2A} - D:\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll
TB: Foxit PhantomPDF Create PDF ToolBar: {BFD9D8A8-57FF-488A-B919-065EC77CF82F} - D:\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll
uRun: [Facebook Update] "C:\Users\Ahmed\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
uRun: [GoogleChromeAutoLaunch_E596B4967FD0B468DDB30184879486CF] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
uRun: [explre] C:\Users\Ahmed\AppData\Local\Temp\eco\svchost.exe //B "C:\Users\Ahmed\AppData\Local\Temp\eco\explre.vbs"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AvgUi] "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
dRunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
StartupFolder: C:\Users\Ahmed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explre.vbs
StartupFolder: C:\Users\Ahmed\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\FACEBO~1.LNK - C:\Users\Ahmed\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe
StartupFolder: C:\Users\Ahmed\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\THE_BI~1.LNK - C:\ProgramData\{0915bc8a-c9cb-04e5-0915-5bc8ac9cf22b}\The+Big+Bang+Theory+S08E21+HDTV+x264-LOL+[eztv].exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Append Link Page to Another PDF - D:\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll/IEContextMenuLinkAppendPDF.html
IE: Append to Another PDF - D:\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll/IEContextMenuCurrentAppendPDF.html
IE: Convert Link Page to Foxit PDF - D:\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll/IEContextMenuLinkNewPDF.html
IE: Convert to Foxit PDF - D:\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll/IEContextMenuCurrentNewPDF.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{13476563-DCA2-4915-9751-3D5F3DC2B51C} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{13476563-DCA2-4915-9751-3D5F3DC2B51C}\24745613D295758647A575258656D6C66326746496167594 : DHCPNameServer = 192.168.43.1
TCP: Interfaces\{13476563-DCA2-4915-9751-3D5F3DC2B51C}\8445340205F627471626C6560284F6473707F6470253132403 : DHCPNameServer = 192.168.43.1
TCP: Interfaces\{D941D675-AFFA-4377-A954-549CB3F2F2DF} : DHCPNameServer = 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
AppInit_DLLs=
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.91\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
IFEO: volaro - tasklist.exe
IFEO: vonteera - tasklist.exe
x64-mStart Page = hxxp://www.google.com
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre8\bin\ssv.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre8\bin\jp2ssv.dll
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [AvgUi] "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
x64-Run: [AVGUI.exe] "C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe" /gui
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
x64-IFEO: volaro - tasklist.exe
x64-IFEO: vonteera - tasklist.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Ahmed\AppData\Roaming\Mozilla\Firefox\Profiles\15jrb249.default\
FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
FF - plugin: C:\Users\Ahmed\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll
.
============= SERVICES / DRIVERS ===============
.
R0 iaStorA;iaStorA;C:\Windows\System32\drivers\iaStorA.sys [2014-6-27 630632]
R0 iaStorF;iaStorF;C:\Windows\System32\drivers\iaStorF.sys [2014-6-27 28008]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2009-1-1 20464]
R1 avgbdisk;avgbdisk;C:\Windows\System32\drivers\avgbdiska.sys [2017-4-9 166136]
R1 avgbidsdriver;avgbidsdriver;C:\Windows\System32\drivers\avgbidsdrivera.sys [2017-4-9 310056]
R1 avgRdr;avgRdr;C:\Windows\System32\drivers\avgRdr2.sys [2017-4-9 102136]
R1 avgSnx;avgSnx;C:\Windows\System32\drivers\avgSnx.sys [2017-4-9 1006040]
R1 avgSP;avgSP;C:\Windows\System32\drivers\avgsp.sys [2017-4-9 557912]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2014-6-27 89600]
R2 AVG Antivirus;AVG Antivirus;C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [2017-4-9 262696]
R2 avgMonFlt;avgMonFlt;C:\Windows\System32\drivers\avgmonflt.sys [2017-4-9 129776]
R2 avgStm;avgStm;C:\Windows\System32\drivers\avgStm.sys [2017-4-9 165048]
R2 avgsvc;AVG Service;C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [2017-3-23 1428680]
R2 FoxitPhantomService;FoxitPhantomService;D:\Foxit PhantomPDF\FoxitConnectedPDFService.exe [2017-2-24 1659080]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2014-6-27 31040]
R3 AVerBDA6x_x64;AVerMedia SAA716x BDA Service;C:\Windows\System32\drivers\AVerBDA716x_x64.sys [2014-6-27 1354880]
R3 enecir;ENE CIR Receiver;C:\Windows\System32\drivers\enecir.sys [2014-6-27 76112]
R3 JMCR;JMCR;C:\Windows\System32\drivers\jmcr.sys [2014-6-27 176880]
R3 johci;JMicron 1394 Filter Driver;C:\Windows\System32\drivers\johci.sys [2014-6-27 26208]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2014-6-27 884952]
S3 3057mBda64;DTV-DVB service;C:\Windows\System32\drivers\3057mBda64.sys [2014-6-27 1117056]
S3 avgbIDSAgent;avgbIDSAgent;C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [2017-4-9 7448992]
S3 avgHwid;avgHwid;C:\Windows\System32\drivers\avgHwid.sys [2017-4-9 39288]
S3 dtultrascsibus;DAEMON Tools Ultra Virtual SCSI Bus;C:\Windows\System32\drivers\dtultrascsibus.sys [2017-3-23 30264]
S3 dtultrausbbus;DAEMON Tools Ultra Virtual USB Bus;C:\Windows\System32\drivers\dtultrausbbus.sys [2017-3-23 47672]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-6-29 59392]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2017-04-26 17:34:09 175230 --sha-w- C:\Users\Ahmed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explre.vbs
2017-04-19 21:05:29 12774864 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9EC8FAE3-C3AC-4E14-B9C7-DB02BED00AB8}\mpengine.dll
2017-04-19 20:08:30 75888 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9EC8FAE3-C3AC-4E14-B9C7-DB02BED00AB8}\offreg.5028.dll
2017-04-09 19:15:02 165048 ----a-w- C:\Windows\System32\drivers\avgStm.sys
2017-04-09 19:15:01 557912 ----a-w- C:\Windows\System32\drivers\avgsp.sys
2017-04-09 19:15:01 340688 ----a-w- C:\Windows\System32\drivers\avgVmm.sys
2017-04-09 19:15:00 76688 ----a-w- C:\Windows\System32\drivers\avgRvrt.sys
2017-04-09 19:15:00 129776 ----a-w- C:\Windows\System32\drivers\avgmonflt.sys
2017-04-09 19:14:59 39288 ----a-w- C:\Windows\System32\drivers\avgHwid.sys
2017-04-09 19:14:59 102136 ----a-w- C:\Windows\System32\drivers\avgRdr2.sys
2017-04-09 19:14:59 1006040 ----a-w- C:\Windows\System32\drivers\avgSnx.sys
2017-04-09 19:14:58 50848 ----a-w- C:\Windows\System32\drivers\avgbuniva.sys
2017-04-09 19:14:58 336408 ----a-w- C:\Windows\System32\drivers\avgbloga.sys
2017-04-09 19:14:57 310056 ----a-w- C:\Windows\System32\drivers\avgbidsdrivera.sys
2017-04-09 19:14:57 192096 ----a-w- C:\Windows\System32\drivers\avgbidsha.sys
2017-04-09 19:14:56 166136 ----a-w- C:\Windows\System32\drivers\avgbdiska.sys
2017-04-09 19:14:30 400928 ----a-w- C:\Windows\System32\avgBoot.exe
2017-04-02 19:14:29 -------- d-----w- C:\Users\Ahmed\AppData\Local\Activision
.
==================== Find3M ====================
.
2017-03-23 21:39:42 47672 ----a-w- C:\Windows\System32\drivers\dtultrausbbus.sys
2017-03-23 21:39:07 30264 ----a-w- C:\Windows\System32\drivers\dtultrascsibus.sys
2017-03-23 21:07:48 66872 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2017-03-23 20:57:34 103736 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2013-02-07 12:22:00 50330 ----a-w- C:\Program Files (x86)\AntiDust.exe
.
============= FINISH: 16:22:00.06 ===============

Attached Files
File Type: txt attach.txt (7.7 KB)

Checkup needed 5.2.17

$
0
0
This is my windows 7 machine and I just need a checkup to be sure my computer is free of malware, viruses, rootkits... etc and problem free. Thank you!

-------------------------------------------------------------------------------------------------

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.18523 BrowserJavaVersion: 11.101.2
Run by Administrator56109 at 9:31:45 on 2017-05-02
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.5942.3071 [GMT -4:00]
.
AV: Avira Antivirus *Enabled/Outdated* {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Avira Antivirus *Enabled/Updated* {B3F630BD-538D-1B4A-14FA-14B63235278F}
SP: Avira Antivirus *Enabled/Updated* {0897D159-75B7-14C4-2E4A-2FC449B26D32}
SP: Avira Antivirus *Enabled/Outdated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\Hpservice.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files\Macrium\Reflect\ReflectService.exe
C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\NetWorx\networx.exe
C:\Program Files (x86)\BatteryCare\BatteryCare.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Common Files\LogiShrd\sp6\LU\LULnchr.exe
C:\Program Files\Common Files\LogiShrd\sp6\LU\LogitechUpdate.exe
C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Avira\Antivirus\sched.exe
C:\Program Files (x86)\Avira\Antivirus\avguard.exe
C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sandboxie\SandboxieRpcSs.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\Sandboxie\32\SbieSvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\CompatTelRunner.exe
C:\Windows\system32\CompatTelRunner.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mSearch Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll
uRun: [BatteryCare] C:\Program Files (x86)\BatteryCare\BatteryCare.exe
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
uRunOnce: [Report] \AdwCleaner\AdwCleaner[C1].txt
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [ZALFree] "C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe" /MINIMIZED
mRun: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Avira SystrayStartTrigger] "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe"
mRun: [avgnt] "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
mRunOnce: [{28d41884-9b36-4f54-bed2-92863f08e65d}] "C:\ProgramData\Package Cache\{28d41884-9b36-4f54-bed2-92863f08e65d}\Avira.OE.Setup.Bundle.exe" /burn.runonce
mRunOnce: [{761cd2c4-5249-4346-8318-a499d06d2681}] "C:\ProgramData\Package Cache\{761cd2c4-5249-4346-8318-a499d06d2681}\Avira.OE.Setup.Bundle.exe" /burn.runonce
mRunOnce: [{3d9e0476-943f-4962-99dc-b9c937a43840}] "C:\ProgramData\Package Cache\{3d9e0476-943f-4962-99dc-b9c937a43840}\Avira.OE.Setup.Bundle.exe" /burn.runonce
mRunOnce: [{92a7fd6b-31e5-472f-862e-79214c5032ef}] "C:\ProgramData\Package Cache\{92a7fd6b-31e5-472f-862e-79214c5032ef}\Avira.OE.Setup.Bundle.exe" /burn.runonce
uPolicies-Explorer: NoDrives = dword:0
uPolicies-Explorer: HideSCAPower = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{44F5BABE-A795-44D8-88CF-09E2C4B06E41} : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{44F5BABE-A795-44D8-88CF-09E2C4B06E41}\84F4D454D223635423 : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{44F5BABE-A795-44D8-88CF-09E2C4B06E41}\84F4D454D2934414 : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{44F5BABE-A795-44D8-88CF-09E2C4B06E41}\84F6D656F5831354B4 : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{44F5BABE-A795-44D8-88CF-09E2C4B06E41}\C696E6B6379737 : DHCPNameServer = 75.75.75.75 75.75.76.76
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs= C:\PROGRA~2\KEYCRY~1\KEYCRY~3.DLL
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
x64-mStart Page = hxxp://www.google.com
x64-mSearch Page = hxxp://www.google.com
x64-mDefault_Page_URL = hxxp://www.google.com
x64-mDefault_Search_URL = hxxp://www.google.com
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_102\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_102\bin\jp2ssv.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background
x64-Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
x64-Run: [NetWorx] "C:\Program Files\NetWorx\networx.exe" /auto
x64-RunOnce: [MSPCLOCK] rundll32.exe streamci,StreamingDeviceSetup {97ebaacc-95bd-11d0-a3ea-00a0c9223196},{53172480-4791-11D0-A5D6-28DB04C10000},{53172480-4791-11D0-A5D6-28DB04C10000}
x64-RunOnce: [MSPQM] rundll32.exe streamci,StreamingDeviceSetup {DDF4358E-BB2C-11D0-A42F-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196}
x64-RunOnce: [MSKSSRV] rundll32.exe streamci,StreamingDeviceSetup {96E080C7-143C-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196}
x64-RunOnce: [MSTEE.CxTransform] rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},C:\Windows\inf\ksfilter.inf,MSTEE.Interface.Install
x64-RunOnce: [MSTEE.Splitter] rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},C:\Windows\inf\ksfilter.inf,MSTEE.Interface.Install
x64-RunOnce: [WDM_DRMKAUD] rundll32.exe streamci,StreamingDeviceSetup {EEC12DB6-AD9C-4168-8658-B03DAEF417FE},{ABD61E00-9350-47e2-A632-4438B90C6641},{FFBB6E3F-CCFE-4D84-90D9-421418B03A8E},C:\Windows\inf\WDMAUDIO.inf,WDM_DRMKAUD.Interface.Install
x64-RunOnce: [*WerKernelReporting] C:\Windows\System32\WerFault.exe -k -rq
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
x64-DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
x64-SSODL: WebCheck - <orphaned>
x64-STS: FencesShlExt Class - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences Pro\FencesMenu64.dll
Hosts: 0.0.0.0 fr.a2dfp.net
Hosts: 0.0.0.0 m.fr.a2dfp.net
Hosts: 0.0.0.0 mfr.a2dfp.net
Hosts: 0.0.0.0 ad.a8.net
Hosts: 0.0.0.0 asy.a8ww.net
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath -
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.sys [2016-8-16 35328]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2014-7-22 173472]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2010-10-25 89600]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\Antivirus\sched.exe [2016-8-16 488920]
R2 AntiVirService;Avira Real-Time Protection;C:\Program Files (x86)\Avira\Antivirus\avguard.exe [2016-8-16 488920]
R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2016-8-16 176968]
R2 Avira.ServiceHost;Avira Service Host;C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [2017-3-9 349560]
R2 avnetflt;avnetflt;C:\Windows\System32\drivers\avnetflt.sys [2016-8-16 78600]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 hmpalert;HitmanPro.Alert Support Driver;C:\Windows\System32\drivers\hmpalert.sys [2014-12-27 93144]
R2 hmpalertsvc;HitmanPro.Alert Service;C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [2014-12-27 1876816]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-7-21 103992]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-8-5 291896]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-9-17 92216]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2010-6-15 30520]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-9-28 26680]
R2 ReflectService.exe;Macrium Reflect Image Mounting Service;C:\Program Files\Macrium\Reflect\ReflectService.exe [2013-4-16 417912]
R2 RoxioNow Service;RoxioNow Service;C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-9-11 399344]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-10-25 2533400]
R3 clwvd;HP Webcam Splitter;C:\Windows\System32\drivers\clwvd.sys [2010-9-3 31088]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-5-1 56344]
R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-2-26 158976]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-6-21 287232]
R3 keycrypt;keycrypt;C:\Windows\System32\drivers\KeyCrypt64.sys [2013-6-4 143904]
R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2015-5-27 188552]
S2 AntiVirMailService;Avira Mail Protection;C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [2016-8-16 1119712]
S2 AntiVirWebService;Avira Web Protection;C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [2016-8-16 1520680]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-5 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-5 125112]
S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2013-5-27 17480]
S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2013-5-27 9800]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2016-11-19 114688]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368]
S3 PSMounterEx;Macrium Reflect Image Explorer Driver;C:\Windows\System32\drivers\psmounterex.sys [2013-4-16 63096]
S3 PSSDK42;PSSDK42;C:\Windows\System32\drivers\pssdk42.sys [2011-2-5 53312]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2010-10-25 232992]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-10-25 344680]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-5-15 56832]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-1-5 1255736]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120]
.
=============== Created Last 30 ================
.
2017-04-04 02:57:15 321480 ----a-w- C:\Program Files (x86)\Mozilla Firefox\tobedeleted\mozDEF.tmp
2017-04-03 12:14:03 527816 ----a-w- C:\Program Files (x86)\Mozilla Firefox\minidump-analyzer.exe
.
==================== Find3M ====================
.
2017-04-30 19:36:21 192216 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2017-04-14 10:41:26 802904 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2017-04-14 10:41:26 144472 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2017-04-03 12:14:29 78600 ----a-w- C:\Windows\System32\drivers\avnetflt.sys
2017-04-03 12:14:29 51248 ----a-w- C:\Windows\System32\drivers\avusbflt.sys
2017-04-03 12:14:29 35328 ----a-w- C:\Windows\System32\drivers\avkmgr.sys
2017-04-03 12:14:29 176968 ----a-w- C:\Windows\System32\drivers\avgntflt.sys
.
============= FINISH: 9:32:23.81 ===============

Attached Files
File Type: txt attach.txt (506.6 KB)

IE randomly closes and reopens..

$
0
0
For some weeks now, IE randomly goes black and a message appears saying that it has stopped working and it checks to see if it can solve the problem. Lately, a strange message has appeared about an adobe problem with an email address which looks odd. I'm wondering if I have an infection.
Can someone help me check this out please?

Do I have a (rootkit) virus?

$
0
0
Hello there!

First of all, thanks ahead for time spent helping me with my problem, it is truly appreciated!

So, onto my problem..

Since a short period of barely 2 weeks my RAM usage has been sky-high. I have a total of 16GB memory, which has never let me down in the over 3 years that I've used it. During usage of my computer, my memory has normally (in idle situations) never really exceeded 20%, except recently it idles between 40-70%. Sometimes it even spikes up to 80-90% and occasionally it sits at 98-100%; which basically makes my computer un-usable (as you can see on this image; nothing using much memory, yet sitting at 98%). Whenever I reboot my computer, the problem 'resets' itself and after boot it sits on 40-70% again (rarely it sits on 98-100% again after rebooting!).

To add to this; I've also had a few blue screen crashes (which I normally never get). I have pictures of my phone of the stop codes and 'what failed' (I can supply the information if needed). The last time it crashed (6 days ago), it could not boot and wanted to do an automatic repair, after which booting succeeded. After this I used the program "WhoCrashed" to find out what the problem was, I have the logs from that saved on my desktop and can attach them if needed.

At first I thought it was a memory leak caused by a driver, but after reviewing/updating my drivers, the problem didn't go away and it didn't make sense (to me) that the problem re-occured after a reboot. I highly doubt my RAM sticks are broken, which caused me to search on the internet. After some research I found more and more 'results' regarding rootkit virusses and where they would be located/their actions. Seeing results about these virusses hiding in memory, made me 'paranoid' about the situation.

I've tried some programs on detecting a potential virus (TDSSKiller, GMER), including some 'manual' solutions such as checking bootlogs for weird stuff, but I found that I simply don't know enough about Windows 10 or this subject to find the potential issue. There were some odd results, however I decided not to post/attach the logs, as the 'instructions' topic requests "only attach the logs we've requested".

In addition; when installing my Windows 10 on my new SSD, I burned a disc with a Windows 10 ISO file. I guess this means that I do have access to a Windows boot disc (if it's the same thing?); however I really see using this as a last resort.

TL;DR: strange high memory usage on my computer, not sure if it's a virus or something else.

Thanks ahead,

Rob


--> Below dds.scr (and in attachement) after some stupid issues with Windows only recognizing it as a CAD script... :nonono:

======================
======================

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.15063.0 BrowserJavaVersion: 11.131.2
Run by Rob at 0:56:14 on 2017-05-07
Microsoft Windows 10 Home 10.0.15063.0.1252.31.1033.18.16325.11984 [GMT 2:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee VirusScan *Enabled/Updated* {8BCDACFA-D264-3528-5EF8-E94FD0BC1FBC}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee VirusScan *Enabled/Updated* {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501}
FW: McAfee Firewall *Enabled* {B3F62DDF-980B-3470-75A7-407A2E6F58C7}
.
============== Running Processes ===============
.
c:\windows\system32\svchost.exe -k dcomlaunch -s PlugPlay
C:\WINDOWS\system32\fontdrvhost.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k dcomlaunch -s LSM
C:\WINDOWS\system32\fontdrvhost.exe
C:\WINDOWS\system32\dwm.exe
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s lmhosts
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s TimeBrokerSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NcbService
c:\windows\system32\svchost.exe -k netsvcs -s Schedule
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s hidserv
c:\windows\system32\svchost.exe -k netsvcs -s ProfSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s EventLog
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
c:\windows\system32\svchost.exe -k netsvcs -s UserManager
C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
c:\windows\system32\svchost.exe -k localservice -s nsi
c:\windows\system32\svchost.exe -k netsvcs -s Themes
c:\windows\system32\svchost.exe -k localservice -s EventSystem
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s Dhcp
c:\windows\system32\svchost.exe -k netsvcs -s SENS
c:\windows\system32\svchost.exe -k networkservice -s NlaSvc
c:\windows\system32\svchost.exe -k networkservice -s Dnscache
C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -s FontCache
c:\windows\system32\svchost.exe -k localservice -s netprofm
c:\windows\system32\svchost.exe -k localservice -s WinHttpAutoProxySvc
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe -k appmodel -s StateRepository
c:\windows\system32\svchost.exe -k netsvcs -s ShellHWDetection
C:\WINDOWS\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k networkservice -s LanmanWorkstation
C:\WINDOWS\System32\svchost.exe -k utcsvc
c:\windows\system32\svchost.exe -k networkservice -s CryptSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DeviceAssociationService
c:\windows\system32\svchost.exe -k localservicenonetwork -s DPS
c:\windows\system32\svchost.exe -k netsvcs -s IKEEXT
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe
C:\Windows\system32\mfevtps.exe
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
C:\Program Files\Killer Networking\Network Manager\KillerService.exe
c:\windows\system32\svchost.exe -k netsvcs -s Winmgmt
C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
c:\windows\system32\svchost.exe -k netsvcs -s LanmanServer
c:\program files\common files\mcafee\modulecore\modulecoreservice.exe
C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe
C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe
C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe
C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s PcaSvc
C:\ProgramData\ANDREA VACONDIO\PDFsam Manager\PDFsam Enhanced\PDFsam Manager.exe
C:\Program Files (x86)\Origin\OriginWebHelperService.exe
C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
C:\WINDOWS\SysWOW64\PnkBstrA.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SysMain
C:\Program Files (x86)\TunnelBear\TBear.Maintenance.exe
C:\Program Files (x86)\Popcorn Time\Updater.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TrkWks
C:\Windows\SysWoW64\vmnetdhcp.exe
C:\Windows\SysWoW64\vmnat.exe
C:\Windows\SearchIndexer.exe
c:\windows\system32\svchost.exe -k netsvcs -s WpnService
c:\windows\system32\svchost.exe -k localservice -s WdiServiceHost
c:\windows\system32\svchost.exe -k appmodel -s tiledatamodelsvc
C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
c:\windows\system32\svchost.exe -k netsvcs -s iphlpsvc
C:\WINDOWS\system32\dashost.exe
C:\Windows\system32\mfevtps.exe
c:\windows\system32\sihost.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
C:\WINDOWS\system32\wbem\wmiprvse.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
c:\windows\system32\svchost.exe -k netsvcs -s TokenBroker
C:\Windows\SearchIndexer.exe
C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe
C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
C:\Windows\SysWoW64\muachost.exe
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s SSDPSRV
c:\windows\system32\taskhostw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\VideoCardMonitorII.exe
C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\EyeRest.exe
C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\NahimicMonitor.exe
C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\TriggerModeMonitor.exe
C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe
C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Windows\System32\RuntimeBroker.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\McAfee\MfeAV\MFEAvSvc.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\McAfee\VSCore_15_6\McApExe.exe
c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe
C:\WINDOWS\system32\SettingSyncHost.exe
C:\Program Files\Common Files\McAfee\CSP\2.3.322.0\McCSPServiceHost.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted -s PolicyAgent
c:\windows\system32\svchost.exe -k localservice -s CDPSvc
C:\Program Files\Windows Defender\MSASCuiL.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files (x86)\Gyazo\GyStation.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe
C:\Program Files (x86)\MSI\Fast Boot\FastBoot.exe
C:\Program Files (x86)\ROCCAT\Kone Pure Mouse\KonePureMonitor.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
c:\windows\system32\svchost.exe -k netsvcs -s Appinfo
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe
c:\windows\system32\svchost.exe -k localservicepeernet -s p2pimsvc
c:\windows\system32\svchost.exe -k localservicepeernet -s PNRPsvc
c:\windows\system32\svchost.exe -k netsvcs
c:\program files\common files\mcafee\modulecore\ModuleCoreService.exe
C:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s Netman
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s wscsvc
c:\windows\system32\svchost.exe -k netsvcs -s lfsvc
C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
c:\windows\system32\taskhostw.exe
C:\WINDOWS\system32\ApplicationFrameHost.exe
C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s StorSvc
c:\windows\system32\svchost.exe -k netsvcs -s BITS
svchost.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -s WdiSystemHost
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs -s wlidsvc
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\backgroundTaskHost.exe
C:\Windows\System32\smartscreen.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs -s Browser
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uLocal Page = %11%\blank.htm
uProxyOverride = <local>
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll
BHO: McAfee WebAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
BHO: Microsoft OneDrive for Business Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll
uRun: [Gyazo] C:\Program Files (x86)\Gyazo\GyStation.exe
uRun: [Akamai NetSession Interface] "C:\Users\Rob\AppData\Local\Akamai\netsession_win.exe"
uRun: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [Fast Boot] C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe
mRun: [RoccatKonePure] "C:\Program Files (x86)\ROCCAT\Kone Pure Mouse\KonePureMonitor.EXE"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\KILLER~1.LNK - C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe
mPolicies-System: DSCAutomationHostEnabled = dword:2
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
IE: {48A61126-9A19-4C50-A214-FF08CB94995C} - {29B24532-6CE1-41BA-8BF0-F580EA174AF1} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
TCP: Interfaces\{bf76f55c-b430-426e-8fc6-94fdb9e6c5a4} : DHCPNameServer = 172.18.12.1
TCP: Interfaces\{cf52085e-f5ae-4d14-93b5-e8e701f1fa70} : DHCPNameServer = 192.168.0.1
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
SSODL: WebCheck - <orphaned>
LSA: Security Packages = ""
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll
x64-BHO: McAfee WebAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-BHO: Microsoft OneDrive for Business Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll
x64-Run: [SecurityHealth] C:\Program Files (x86)\Windows Defender\MSASCuiL.exe
x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
x64-Run: [ShadowPlay] "C:\WINDOWS\System32\rundll32.exe" C:\WINDOWS\System32\nvspcap64.dll,ShadowPlayOnSystemStart
x64-mPolicies-System: DSCAutomationHostEnabled = dword:2
x64-mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
x64-mPolicies-System: PromptOnSecureDesktop = dword:0
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-IE: {48A61126-9A19-4C50-A214-FF08CB94995C} - {29B24532-6CE1-41BA-8BF0-F580EA174AF1} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
x64-Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll
x64-Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - <orphaned>
x64-Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - <orphaned>
x64-Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
x64-CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
.
============= SERVICES / DRIVERS ===============
.
R0 intelpep;Intel(R) Power Engine Plug-in Driver;C:\WINDOWS\System32\drivers\intelpep.sys [2017-3-18 74840]
R0 iorate;Disk I/O Rate Filter Driver;C:\WINDOWS\System32\drivers\iorate.sys [2017-3-18 49568]
R0 mfehidk;McAfee Inc. mfehidk;C:\WINDOWS\System32\drivers\mfehidk.sys [2016-8-2 923640]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\WINDOWS\System32\drivers\mfewfpk.sys [2016-9-9 254800]
R0 volume;Volume driver;C:\WINDOWS\System32\drivers\volume.sys [2017-3-18 16288]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [2017-3-18 70232]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [2017-3-18 18520]
R0 Wof;Windows Overlay File System Filter Driver;C:\WINDOWS\System32\drivers\wof.sys [2017-3-18 208288]
R1 ahcache;Application Compatibility Cache;C:\WINDOWS\System32\drivers\ahcache.sys [2017-3-18 239616]
R1 BfLwf;Killer Bandwidth Control;C:\WINDOWS\System32\drivers\bwcW10x64.sys [2016-1-22 144456]
R1 FileCrypt;FileCrypt;C:\WINDOWS\System32\drivers\filecrypt.sys [2017-3-18 54272]
R1 GpuEnergyDrv;GPU Energy Driver;C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2017-3-18 8192]
R2 AGSService;Adobe Genuine Software Integrity Service;C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2016-9-26 2227312]
R2 CDPSvc;Connected Devices Platform Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
R2 CDPUserSvc_393a4;CDPUserSvc_393a4;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R2 ClickToRunSvc;Klik-en-klaar-service van Microsoft Office;C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe [2017-1-9 3801280]
R2 clreg;Virtual Registry for Containers;C:\WINDOWS\System32\drivers\registry.sys [2017-3-18 14336]
R2 CoreMessagingRegistrar;CoreMessaging;C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork [2017-3-18 47664]
R2 DiagTrack;Connected User Experiences and Telemetry;C:\WINDOWS\System32\svchost.exe -k utcsvc [2017-3-18 47664]
R2 DusmSvc;Data Usage;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
R2 GamingApp_Service;GamingApp_Service;C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe [2017-1-2 45008]
R2 GamingHotkey_Service;GamingHotkey_Service;C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe [2017-1-2 2019792]
R2 HomeNetSvc;McAfee Home Network;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2017-1-2 641520]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-2-13 731648]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2017-1-2 169432]
R2 Killer Service V2;Killer Service V2;C:\Program Files\Killer Networking\Network Manager\KillerService.exe [2016-1-28 454872]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [2017-5-1 188256]
R2 McAPExe;McAfee AP Service;C:\Program Files\Common Files\McAfee\VSCore_15_6\mcapexe.exe [2017-2-5 994312]
R2 McBootDelayStartSvc;McAfee Boot Delay Start Service;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2017-1-2 641520]
R2 mccspsvc;McAfee CSP Service;C:\Program Files\Common Files\McAfee\CSP\2.3.322.0\McCSPServiceHost.exe [2017-2-28 2054080]
R2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2017-1-2 641520]
R2 mcpltsvc;McAfee Platform Services;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2017-1-2 641520]
R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2017-1-2 641520]
R2 mfemms;McAfee Service Controller;C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [2017-1-2 385112]
R2 ModuleCoreService;McAfee Module Core Service;C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [2017-2-5 1551000]
R2 MSI_ActiveX_Service;MSI_ActiveX_Service;C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe [2017-1-2 78776]
R2 MSI_FastBoot;MSI_FastBoot;C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [2017-1-2 105296]
R2 MSI_Trigger_Service;MSI_Trigger_Service;C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [2017-1-2 29728]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container;C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-1-2 492480]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2017-1-14 462968]
R2 NvTelemetryContainer;NVIDIA Telemetry Container;C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [2017-1-2 425408]
R2 OneSyncSvc_393a4;OneSyncSvc_393a4;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R2 Origin Web Helper Service;Origin Web Helper Service;C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2017-1-2 3116440]
R2 PDFsam Manager;PDFsam Manager;C:\ProgramData\ANDREA VACONDIO\PDFsam Manager\PDFsam Enhanced\PDFsam Manager.exe [2015-11-13 1050224]
R2 PEFService;Intel Security PEF Service;C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [2017-1-2 1104304]
R2 SecurityHealthService;Windows Defender Security Center Service;C:\WINDOWS\System32\SecurityHealthService.exe [2017-3-18 335808]
R2 storqosflt;Storage QoS Filter Driver;C:\WINDOWS\System32\drivers\storqosflt.sys [2017-3-18 79872]
R2 tiledatamodelsvc;Tile Data model server;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
R2 TunnelBearMaintenance;TunnelBear Maintenance;C:\Program Files (x86)\TunnelBear\TBear.Maintenance.exe [2016-12-16 38272]
R2 Update service;Update service;C:\Program Files (x86)\Popcorn Time\Updater.exe [2017-1-2 339968]
R2 UserManager;User Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2016-9-6 916040]
R2 wcifs;Windows Container Isolation;C:\WINDOWS\System32\drivers\wcifs.sys [2017-3-18 141720]
R2 Windows Indexer;Windows Indexer;C:\Windows\SearchIndexer.exe [2017-3-27 64512]
R2 WpnService;Windows Push Notifications System Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R2 WpnUserService_393a4;WpnUserService_393a4;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R3 AppXSvc;AppX Deployment Service (AppXSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2017-3-18 47664]
R3 cfwids;McAfee Inc. cfwids;C:\WINDOWS\System32\drivers\cfwids.sys [2016-9-9 88464]
R3 ClientAnalyticsService;ClientAnalyticsService;C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [2017-1-2 1752992]
R3 I2cHkBurn;I2cHkBurn;C:\WINDOWS\System32\drivers\I2cHkBurn.sys [2017-1-2 41760]
R3 KillerEth;NDIS Miniport Driver for Killer PCI-E Gigabit Ethernet Controller;C:\WINDOWS\System32\drivers\e2xw10x64.sys [2017-3-18 145920]
R3 lfsvc;Geolocation Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R3 MBfilt;MBfilt;C:\WINDOWS\System32\drivers\MBfilt64.sys [2017-1-2 41088]
R3 mfeaack;McAfee Inc. mfeaack;C:\WINDOWS\System32\drivers\mfeaack.sys [2016-8-2 487184]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\WINDOWS\System32\drivers\mfeavfk.sys [2016-8-2 366328]
R3 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2017-1-2 241040]
R3 mfefirek;McAfee Inc. mfefirek;C:\WINDOWS\System32\drivers\mfefirek.sys [2016-9-9 518704]
R3 mfencbdc;McAfee Inc. mfencbdc;C:\WINDOWS\System32\drivers\mfencbdc.sys [2017-1-19 498648]
R3 mfeplk;McAfee Inc. mfeplk;C:\WINDOWS\System32\drivers\mfeplk.sys [2016-9-9 110256]
R3 mfesapsn;McAfee Process Start Notification Service;C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [2017-5-1 46240]
R3 mfevtp;McAfee Validation Trust Protection Service;C:\WINDOWS\System32\mfevtps.exe [2017-1-2 343792]
R3 NcbService;Network Connection Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [2017-3-18 20992]
R3 NTIOLib_FastBoot;NTIOLib_FastBoot;C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [2017-1-2 13368]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\WINDOWS\System32\drivers\nvvad64v.sys [2017-1-14 47552]
R3 nvvhci;NVVHCI Enumerator Service;C:\WINDOWS\System32\drivers\nvvhci.sys [2017-1-14 59448]
R3 RTCore64;RTCore64;C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [2013-3-11 13368]
R3 StateRepository;State Repository Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
R3 tap-tb-0901;TunnelBear Adapter V9;C:\WINDOWS\System32\drivers\tap-tb-0901.sys [2016-10-17 38656]
R3 TimeBrokerSvc;Time Broker;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
R3 TokenBroker;TokenBroker;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R3 XtuAcpiDriver;Intel(R) Extreme Tuning Utility Service;C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [2015-6-6 63840]
S0 mfeelamk;McAfee Inc. mfeelamk;C:\WINDOWS\System32\drivers\mfeelamk.sys [2016-9-9 85048]
S2 CldFlt;Windows Cloud Files Filter Driver;C:\WINDOWS\System32\drivers\cldflt.sys [2017-3-18 12288]
S2 DoSvc;Delivery Optimization;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S2 MapsBroker;Downloaded Maps Manager;C:\WINDOWS\System32\svchost.exe -k NetworkService [2017-3-18 47664]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-2-22 317400]
S3 AcpiDev;ACPI Devices driver;C:\WINDOWS\System32\drivers\AcpiDev.sys [2017-3-18 20480]
S3 ADP80XX;ADP80XX;C:\WINDOWS\System32\drivers\adp80xx.sys [2017-3-18 1135512]
S3 AJRouter;AllJoyn Router Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 applockerfltr;Smartlocker Filter Driver;C:\WINDOWS\System32\drivers\applockerfltr.sys [2017-3-18 17920]
S3 AppReadiness;App Readiness;C:\WINDOWS\System32\svchost.exe -k AppReadiness [2017-3-18 47664]
S3 bcmfn2;bcmfn2 Service;C:\WINDOWS\System32\drivers\bcmfn2.sys [2017-3-18 9728]
S3 BthHFSrv;Bluetooth Handsfree Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation [2017-3-18 47664]
S3 buttonconverter;Service for Portable Device Control devices;C:\WINDOWS\System32\drivers\buttonconverter.sys [2017-3-18 39424]
S3 CAD;Charge Arbitration Driver;C:\WINDOWS\System32\drivers\CAD.sys [2017-3-18 53664]
S3 CapImg;HID driver for CapImg touch screen;C:\WINDOWS\System32\drivers\capimg.sys [2017-3-18 122880]
S3 cht4iscsi;cht4iscsi;C:\WINDOWS\System32\drivers\cht4sx64.sys [2017-3-18 347032]
S3 cht4vbd;Chelsio Virtual Bus Driver;C:\WINDOWS\System32\drivers\cht4vx64.sys [2017-3-18 2104224]
S3 ClipSVC;Client License Service (ClipSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2017-3-18 47664]
S3 CMUSBDAC;USB Audio Class 1.0 and 2.0 DAC Device Driver;C:\WINDOWS\System32\drivers\CMUSBDAC.sys [2016-11-30 3792904]
S3 DevicesFlowUserSvc_393a4;DevicesFlowUserSvc_393a4;C:\WINDOWS\System32\svchost.exe -k DevicesFlow [2017-3-18 47664]
S3 DevQueryBroker;DevQuery Background Discovery Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 diagnosticshub.standardcollector.service;Microsoft (R) Diagnostics Hub Standard Collector Service;C:\WINDOWS\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2017-3-18 86528]
S3 DmEnrollmentSvc;Device Management Enrollment Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 dmwappushservice;dmwappushsvc;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 DsSvc;Data Sharing Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 embeddedmode;Embedded Mode;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 EntAppSvc;Enterprise App Management Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2017-1-9 1591264]
S3 FrameServer;Windows Camera Frame Server;C:\WINDOWS\System32\svchost.exe -k Camera [2017-3-18 47664]
S3 genericusbfn;Generic USB Function Class;C:\WINDOWS\System32\drivers\genericusbfn.sys [2017-3-18 21504]
S3 hidinterrupt;Common Driver for HID Buttons implemented with interrupts;C:\WINDOWS\System32\drivers\hidinterrupt.sys [2017-3-18 51104]
S3 HipShieldK;McAfee Inc. HipShieldK;C:\WINDOWS\System32\drivers\HipShieldK.sys [2017-1-2 207968]
S3 HvHost;HV Host Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 iagpio;Intel Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iagpio.sys [2017-3-18 33280]
S3 iai2c;Intel(R) Serial IO I2C Host Controller;C:\WINDOWS\System32\drivers\iai2c.sys [2017-3-18 81408]
S3 iaLPSS2i_GPIO2;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2017-3-18 70656]
S3 iaLPSS2i_GPIO2_BXT_P;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2017-3-18 85504]
S3 iaLPSS2i_I2C;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2017-3-18 165376]
S3 iaLPSS2i_I2C_BXT_P;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2017-3-18 168448]
S3 iaLPSSi_GPIO;Intel(R) Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [2017-3-18 38128]
S3 iaLPSSi_I2C;Intel(R) Serial IO I2C Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [2017-3-18 113152]
S3 iaStorAV;Intel(R) SATA RAID Controller Windows;C:\WINDOWS\System32\drivers\iaStorAV.sys [2017-3-18 673184]
S3 ibbus;Mellanox InfiniBand Bus/AL (Filter Driver);C:\WINDOWS\System32\drivers\ibbus.sys [2017-3-18 526240]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2017-1-2 171632]
S3 icssvc;Windows Mobile Hotspot Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 IndirectKmd;Indirect Displays Kernel-Mode Driver;C:\WINDOWS\System32\drivers\IndirectKmd.sys [2017-3-18 36864]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-2-13 820184]
S3 IpxlatCfgSvc;IP Translation Configuration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 LicenseManager;Windows License Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 LSI_SAS2i;LSI_SAS2i;C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2017-3-18 123808]
S3 LSI_SAS3i;LSI_SAS3i;C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2017-3-18 103328]
S3 mausbhost;MA-USB Host Controller Driver;C:\WINDOWS\System32\drivers\mausbhost.sys [2017-3-18 405408]
S3 mausbip;MA-USB IP Filter Driver;C:\WINDOWS\System32\drivers\mausbip.sys [2017-3-18 51104]
S3 megasas2i;megasas2i;C:\WINDOWS\System32\drivers\MegaSas2i.sys [2017-3-18 64416]
S3 MessagingService_393a4;MessagingService_393a4;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
S3 mfencrk;McAfee Inc. mfencrk;C:\WINDOWS\System32\drivers\mfencrk.sys [2017-1-19 109320]
S3 mlx4_bus;Mellanox ConnectX Bus Enumerator;C:\WINDOWS\System32\drivers\mlx4_bus.sys [2017-3-18 842656]
S3 NaturalAuthentication;Natural Authentication;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 ndfltr;NetworkDirect Service;C:\WINDOWS\System32\drivers\ndfltr.sys [2017-3-18 108960]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library;C:\WINDOWS\System32\drivers\NetAdapterCx.sys [2017-3-18 122368]
S3 NetSetupSvc;Network Setup Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 netvsc;netvsc;C:\WINDOWS\System32\drivers\netvsc.sys [2017-3-18 119296]
S3 NgcCtnrSvc;Microsoft Passport Container;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 NgcSvc;Microsoft Passport;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 NTIOLib_1_0_3;NTIOLib_1_0_3;C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [2017-1-2 13368]
S3 NvContainerNetworkService;NVIDIA NetworkService Container;C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-1-2 492480]
S3 nvdimmn;Microsoft NVDIMM-N device driver;C:\WINDOWS\System32\drivers\nvdimmn.sys [2017-3-18 80896]
S3 NvStreamKms;NVIDIA KMS;C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2017-5-1 30144]
S3 NVVADARM;NVIDIA Miracast Audio;C:\WINDOWS\System32\drivers\nvvadarm.sys [2017-1-2 39056]
S3 Origin Client Service;Origin Client Service;C:\Program Files (x86)\Origin\OriginClientService.exe [2017-1-2 2147216]
S3 percsas2i;percsas2i;C:\WINDOWS\System32\drivers\percsas2i.sys [2017-3-18 58784]
S3 percsas3i;percsas3i;C:\WINDOWS\System32\drivers\percsas3i.sys [2017-3-18 61848]
S3 PhoneSvc;Phone Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 PimIndexMaintenanceSvc_393a4;PimIndexMaintenanceSvc_393a4;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
S3 ReFS;ReFS;C:\WINDOWS\System32\drivers\refs.sys [2017-3-18 1735584]
S3 ReFSv1;ReFSv1;C:\WINDOWS\System32\drivers\refsv1.sys [2017-3-18 936864]
S3 RetailDemo;Retail Demo Service;C:\WINDOWS\System32\svchost.exe -k rdxgroup [2017-3-18 47664]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 scmbus;Microsoft Storage Class Memory Bus Driver;C:\WINDOWS\System32\drivers\scmbus.sys [2017-3-18 91040]
S3 SDFRd;SDF Reflector;C:\WINDOWS\System32\drivers\SDFRd.sys [2017-3-18 31128]
S3 SEMgrSvc;Payments and NFC/SE Manager;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 SensorDataService;Sensor Data Service;C:\WINDOWS\System32\SensorDataService.exe [2017-3-18 1284608]
S3 SensorService;Sensor Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 SerCx2;Serial UART Support Library;C:\WINDOWS\System32\drivers\SerCx2.sys [2017-3-18 154016]
S3 smphost;Microsoft Storage Spaces SMP;C:\WINDOWS\System32\svchost.exe -k smphost [2017-3-18 47664]
S3 SmsRouter;Microsoft Windows SMS Router Service.;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 SpatialGraphFilter;Holographic Spatial Graph Filter;C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [2017-3-18 40352]
S3 spectrum;Windows Perception Service;C:\WINDOWS\System32\Spectrum.exe [2017-3-18 891904]
S3 stornvme;Microsoft Standard NVM Express Driver;C:\WINDOWS\System32\drivers\stornvme.sys [2017-3-18 95648]
S3 storufs;Microsoft Universal Flash Storage (UFS) Driver;C:\WINDOWS\System32\drivers\storufs.sys [2017-3-18 36760]
S3 TieringEngineService;Storage Tiers Management;C:\WINDOWS\System32\TieringEngineService.exe [2017-3-18 302592]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmCx.sys [2017-3-18 104448]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmTcpciCx.sys [2017-3-18 179200]
S3 UcmUcsi;USB Connector Manager UCSI Client;C:\WINDOWS\System32\drivers\UcmUcsi.sys [2017-3-18 51712]
S3 UdeCx;USB Device Emulation Support Library;C:\WINDOWS\System32\drivers\Udecx.sys [2017-3-18 45568]
S3 UEFI;Microsoft UEFI Driver;C:\WINDOWS\System32\drivers\uefi.sys [2017-3-18 29600]
S3 Ufx01000;USB Function Class Extension;C:\WINDOWS\System32\drivers\ufx01000.sys [2017-3-18 263584]
S3 UfxChipidea;USB Chipidea Controller;C:\WINDOWS\System32\drivers\UfxChipidea.sys [2017-3-18 98712]
S3 ufxsynopsys;USB Synopsys Controller;C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2017-3-18 138656]
S3 UnistoreSvc_393a4;UnistoreSvc_393a4;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
S3 UrsChipidea;Chipidea USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urschipidea.sys [2017-3-18 29600]
S3 UrsCx01000;USB Role-Switch Support Library;C:\WINDOWS\System32\drivers\urscx01000.sys [2017-3-18 59288]
S3 UrsSynopsys;Synopsys USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urssynopsys.sys [2017-3-18 28064]
S3 UserDataSvc_393a4;UserDataSvc_393a4;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
S3 UsoSvc;Update Orchestrator Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 vhf;Virtual HID Framework (VHF) Driver;C:\WINDOWS\System32\drivers\vhf.sys [2017-3-18 35328]
S3 vmgid;Microsoft Hyper-V Guest Infrastructure Driver;C:\WINDOWS\System32\drivers\vmgid.sys [2017-3-18 10240]
S3 vmicguestinterface;Hyper-V Guest Service Interface;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 vmicvmsession;Hyper-V PowerShell Direct Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 WalletService;WalletService;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
S3 wcnfs;Windows Container Name Virtualization;C:\WINDOWS\System32\drivers\wcnfs.sys [2017-3-18 72192]
S3 wdiwifi;WDI Driver Framework;C:\WINDOWS\System32\drivers\WdiWiFi.sys [2017-3-18 759808]
S3 WdNisDrv;Windows Defender Antivirus Network Inspection System Driver;C:\WINDOWS\System32\drivers\WdNisDrv.sys [2017-3-18 121248]
S3 WdNisSvc;Windows Defender Antivirus Network Inspection Service;C:\Program Files\Windows Defender\NisSrv.exe [2017-3-18 342264]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;C:\WINDOWS\System32\svchost.exe -k WepHostSvcGroup [2017-3-18 47664]
S3 WFDSConMgrSvc;Wi-Fi Direct Services Connection Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 WinMad;WinMad Service;C:\WINDOWS\System32\drivers\winmad.sys [2017-3-18 32160]
S3 WinNat;Windows NAT Driver;C:\WINDOWS\System32\drivers\winnat.sys [2017-3-18 217088]
S3 WinVerbs;WinVerbs Service;C:\WINDOWS\System32\drivers\winverbs.sys [2017-3-18 64920]
S3 wisvc;Windows Insider Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 wlpasvc;LPA Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 workfolderssvc;Work Folders;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 xbgm;Xbox Game Monitoring;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 XblAuthManager;Xbox Live Auth Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 XblGameSave;Xbox Live Game Save;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 xboxgip;Xbox Game Input Protocol Driver;C:\WINDOWS\System32\drivers\xboxgip.sys [2017-3-18 277504]
S3 XboxGipSvc;Xbox Accessory Management Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 XboxNetApiSvc;Xbox Live Networking Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 xinputhid;XINPUT HID Filter Driver;C:\WINDOWS\System32\drivers\xinputhid.sys [2017-3-18 46592]
S4 shpamsvc;Shared PC Account Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S4 tzautoupdate;Auto Time Zone Updater;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\WINDOWS\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2017-05-06 21:17:50 -------- d-----w- C:\WINDOWS\pss
2017-05-06 21:02:39 134592 ----a-w- C:\WINDOWS\SysWow64\nvStreaming.exe
2017-05-06 21:02:35 536864 ----a-w- C:\WINDOWS\System32\vulkan-1.dll
2017-05-06 21:02:35 525600 ----a-w- C:\WINDOWS\SysWow64\vulkan-1.dll
2017-05-06 21:02:35 254240 ----a-w- C:\WINDOWS\System32\vulkaninfo.exe
2017-05-06 21:02:35 233760 ----a-w- C:\WINDOWS\SysWow64\vulkaninfo.exe
2017-05-06 21:02:35 -------- d-----w- C:\Program Files (x86)\VulkanRT
2017-05-06 21:02:17 -------- d-----w- C:\temp
2017-05-03 19:48:36 -------- d-----w- C:\Users\Rob\Valley
2017-05-03 19:47:51 -------- d-----w- C:\Program Files (x86)\Unigine
2017-05-01 12:19:35 -------- d-----w- C:\WINDOWS\LastGood.Tmp
2017-05-01 12:18:30 1988216 ----a-w- C:\WINDOWS\System32\nvdispco6438189.dll
2017-05-01 12:18:30 1589880 ----a-w- C:\WINDOWS\System32\nvdispgenco6438189.dll
2017-05-01 12:10:57 -------- d---a-w- C:\Program Files\WhoCrashed
2017-04-29 20:24:39 -------- d-----w- C:\Users\Rob\AppData\Roaming\Jubler
2017-04-29 20:24:22 -------- d-----w- C:\Program Files\Jubler
2017-04-24 17:01:57 512960 ----a-w- C:\WINDOWS\System32\OpenCL.dll
2017-04-24 17:01:57 420408 ----a-w- C:\WINDOWS\SysWow64\OpenCL.dll
2017-04-24 16:57:54 -------- d-----w- C:\Users\Rob\AppData\Roaming\MAXON
2017-04-23 21:53:33 1988032 ----a-w- C:\WINDOWS\System32\nvdispco6438165.dll
2017-04-23 21:53:33 1591352 ----a-w- C:\WINDOWS\System32\nvdispgenco6438165.dll
2017-04-23 21:41:43 153536 ----a-w- C:\WINDOWS\System32\nvaudcap64v.dll
2017-04-23 21:41:43 127424 ----a-w- C:\WINDOWS\SysWow64\nvaudcap32v.dll
2017-04-23 12:48:19 110144 ----a-w- C:\WINDOWS\SysWow64\WindowsAccessBridge-64.dll
2017-04-19 00:15:42 447776 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE
2017-04-19 00:12:32 28408 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll
2017-04-19 00:04:32 207056 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
2017-04-18 15:13:13 -------- d-----w- C:\Users\Rob\AppData\Roaming\TunnelBear
2017-04-18 15:13:13 -------- d-----w- C:\Users\Rob\AppData\Local\IsolatedStorage
2017-04-18 15:13:09 -------- d---a-w- C:\Program Files (x86)\TunnelBear
2017-04-15 21:28:52 9481728 ----a-w- C:\WINDOWS\System32\prm0013.dll
2017-04-15 21:28:50 543648 ----a-w- C:\WINDOWS\System32\securekernel.exe
2017-04-15 21:28:50 388000 ----a-w- C:\WINDOWS\System32\drivers\USBXHCI.SYS
2017-04-15 21:28:32 -------- d-----w- C:\WINDOWS\System32\Microsoft
2017-04-15 21:28:32 -------- d-----w- C:\WINDOWS\ServiceProfiles
2017-04-15 11:42:58 -------- d-----w- C:\Users\Rob\AppData\Local\DBG
2017-04-15 11:42:54 -------- d-----w- C:\ProgramData\Microsoft OneDrive
2017-04-15 11:42:12 -------- d-----w- C:\ProgramData\USOShared
2017-04-15 11:41:30 -------- d-----r- C:\Users\Rob\Music
2017-04-15 11:41:29 -------- d-----r- C:\Users\Rob\Videos
2017-04-15 11:41:29 -------- d-----r- C:\Users\Rob\Pictures
2017-04-15 11:41:21 -------- d-sh--we C:\ProgramData\Documents
2017-04-15 11:41:21 -------- d-sh--w- C:\Recovery
2017-04-15 11:36:40 -------- d-----w- C:\WINDOWS\System32\wbem\MOF\good
2017-04-15 11:36:40 -------- d-----w- C:\WINDOWS\System32\wbem\MOF\bad
2017-04-15 11:33:09 2233344 ----a-w- C:\WINDOWS\SysWow64\PrintConfig.dll
2017-04-15 11:30:59 -------- d-----w- C:\WINDOWS\System32\SleepStudy
2017-04-13 15:55:12 -------- dc----w- C:\WINDOWS\Panther
2017-04-12 15:41:01 -------- d-----w- C:\Users\Rob\AppData\Local\UNP
2017-04-12 15:05:28 -------- d---a-w- C:\Program Files\UNP
2017-04-12 15:05:28 -------- d-----w- C:\WINDOWS\System32\UNP
2017-04-11 19:42:33 31232 ------w- C:\WINDOWS\System32\DdcWnsListener.dll
2017-04-11 19:42:33 261632 ------w- C:\WINDOWS\System32\indexeddbserver.dll
2017-04-10 16:09:41 -------- d-----w- C:\Users\Rob\AppData\Local\Jagex
2017-04-10 16:09:35 -------- d-----w- C:\ProgramData\Jagex
2017-04-10 16:08:37 -------- d-----w- C:\Program Files\Jagex
.
==================== Find3M ====================
.
2017-05-01 20:52:54 1951 ----a-w- C:\WINDOWS\NvContainerRecovery.bat
2017-05-01 20:51:10 6437312 ----a-w- C:\WINDOWS\System32\nvcpl.dll
2017-05-01 20:51:10 2479552 ----a-w- C:\WINDOWS\System32\nvsvc64.dll
2017-05-01 20:51:08 81856 ----a-w- C:\WINDOWS\System32\nv3dappshextr.dll
2017-05-01 20:51:08 69752 ----a-w- C:\WINDOWS\System32\nvshext.dll
2017-05-01 20:51:08 548800 ----a-w- C:\WINDOWS\System32\nv3dappshext.dll
2017-05-01 20:51:08 392312 ----a-w- C:\WINDOWS\System32\nvmctray.dll
2017-05-01 20:51:08 1762752 ----a-w- C:\WINDOWS\System32\nvsvcr.dll
2017-04-26 05:40:34 1882048 ----a-w- C:\WINDOWS\System32\nvspcap64.dll
2017-04-26 05:40:34 1472960 ----a-w- C:\WINDOWS\SysWow64\nvspcap.dll
2017-04-26 05:40:33 1755072 ----a-w- C:\WINDOWS\System32\nvspbridge64.dll
2017-04-26 05:40:33 1317312 ----a-w- C:\WINDOWS\SysWow64\nvspbridge.dll
2017-04-26 05:40:33 121280 ----a-w- C:\WINDOWS\System32\NvRtmpStreamer64.dll
2017-04-26 05:03:24 1951 ----a-w- C:\WINDOWS\NvTelemetryContainerRecovery.bat
2017-04-25 21:11:41 7944687 ----a-w- C:\WINDOWS\System32\nvcoproc.bin
2017-04-25 15:02:11 348360 ----a-w- C:\WINDOWS\SysWow64\PnkBstrB.xtr
2017-04-25 15:02:11 348360 ----a-w- C:\WINDOWS\SysWow64\PnkBstrB.exe
2017-04-25 15:01:51 280904 ----a-w- C:\WINDOWS\SysWow64\PnkBstrB.ex0
2017-04-24 17:24:09 466456 ----a-w- C:\WINDOWS\System32\wrap_oal.dll
2017-04-24 17:24:09 444952 ----a-w- C:\WINDOWS\SysWow64\wrap_oal.dll
2017-04-24 17:24:09 122904 ----a-w- C:\WINDOWS\System32\OpenAL32.dll
2017-04-24 17:24:09 109080 ----a-w- C:\WINDOWS\SysWow64\OpenAL32.dll
2017-04-23 12:48:00 110144 ----a-w- C:\WINDOWS\System32\WindowsAccessBridge-64.dll
2017-04-23 12:47:43 97856 ----a-w- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
2017-04-20 01:59:14 59448 ----a-w- C:\WINDOWS\System32\drivers\nvvhci.sys
2017-04-15 21:28:04 8704 ----a-w- C:\WINDOWS\SysWow64\dpnhupnp.dll
2017-04-03 16:56:16 835576 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2017-04-03 16:56:16 177656 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2017-04-02 06:15:32 87904 ----a-w- C:\WINDOWS\System32\UNPUXWorker.exe
2017-03-28 03:32:48 47552 ----a-w- C:\WINDOWS\System32\drivers\nvvad64v.sys
2017-03-27 17:00:56 64512 ----a-w- C:\WINDOWS\SearchIndexer.exe
2017-03-26 18:35:58 76152 ----a-w- C:\WINDOWS\SysWow64\PnkBstrA.exe
2017-03-18 21:01:14 207872 ----a-w- C:\WINDOWS\SysWow64\msclmd.dll
2017-03-18 21:01:13 230400 ----a-w- C:\WINDOWS\System32\msclmd.dll
2017-03-18 20:59:55 705024 ----a-w- C:\WINDOWS\SysWow64\MsSpellCheckingFacility.dll
2017-03-18 20:58:59 9728 ----a-w- C:\WINDOWS\SysWow64\nddeapi.dll
2017-03-18 20:57:58 97280 ----a-w- C:\WINDOWS\System32\WaaSAssessment.dll
2017-03-18 20:56:58 928712 ----a-w- C:\WINDOWS\SysWow64\mfreadwrite.dll
2017-03-18 11:40:24 118272 ----a-w- C:\WINDOWS\SysWow64\poqexec.exe
2017-03-18 11:40:23 140288 ----a-w- C:\WINDOWS\System32\poqexec.exe
2017-03-18 11:40:22 247200 ----a-w- C:\WINDOWS\System32\wdscore.dll
2017-03-18 11:40:21 846744 ----a-w- C:\WINDOWS\System32\SmiEngine.dll
2017-03-18 11:40:21 762784 ----a-w- C:\WINDOWS\System32\NetSetupEngine.dll
2017-03-18 11:40:21 206848 ----a-w- C:\WINDOWS\System32\PkgMgr.exe
2017-03-18 11:40:21 143776 ----a-w- C:\WINDOWS\System32\NetSetupApi.dll
2017-03-18 11:40:21 133024 ----a-w- C:\WINDOWS\System32\SSShim.dll
2017-03-18 11:40:21 111616 ----a-w- C:\WINDOWS\System32\NetDriverInstall.dll
2017-03-18 05:54:00 2021680 ----a-w- C:\WINDOWS\System32\wmpmde.dll
2017-03-18 05:46:20 3584 ----a-w- C:\WINDOWS\SysWow64\drivers\en-US\wfplwfs.sys.mui
2017-03-18 05:45:24 11776 ----a-w- C:\WINDOWS\SysWow64\drivers\en-US\NdisImPlatform.sys.mui
2017-03-18 05:44:56 6656 ----a-w- C:\WINDOWS\SysWow64\drivers\en-US\ndiscap.sys.mui
2017-03-18 05:40:28 276400 ----a-w- C:\WINDOWS\System32\wmpeffects.dll
2017-03-18 05:40:26 387416 ----a-w- C:\WINDOWS\System32\wmpps.dll
2017-03-18 05:11:52 1339352 ----a-w- C:\WINDOWS\SysWow64\wmpmde.dll
2017-03-18 05:09:30 8192 ----a-w- C:\WINDOWS\SysWow64\drivers\en-US\fwpkclnt.sys.mui
2017-03-18 05:00:38 7168 ----a-w- C:\WINDOWS\System32\msdxm.ocx
2017-03-18 05:00:38 7168 ----a-w- C:\WINDOWS\System32\dxmasf.dll
2017-03-18 04:59:56 11264 ----a-w- C:\WINDOWS\System32\spwmp.dll
2017-03-18 04:59:52 2560 ----a-w- C:\WINDOWS\System32\wmerror.dll
2017-03-18 04:58:00 214528 ----a-w- C:\WINDOWS\System32\wmpdxm.dll
2017-03-18 04:57:26 249016 ----a-w- C:\WINDOWS\SysWow64\wmpeffects.dll
2017-03-18 04:57:26 153976 ----a-w- C:\WINDOWS\SysWow64\wmpps.dll
2017-03-18 04:56:26 9261568 ----a-w- C:\WINDOWS\System32\wmploc.DLL
2017-03-18 04:56:24 123904 ----a-w- C:\WINDOWS\System32\wmpshell.dll
2017-03-18 04:55:42 566272 ----a-w- C:\WINDOWS\System32\quickassist.exe
2017-03-18 04:54:52 231424 ----a-w- C:\WINDOWS\System32\unregmp2.exe
2017-03-18 04:44:58 5632 ----a-w- C:\WINDOWS\SysWow64\msdxm.ocx
2017-03-18 04:44:58 5632 ----a-w- C:\WINDOWS\SysWow64\dxmasf.dll
2017-03-18 04:44:14 9216 ----a-w- C:\WINDOWS\SysWow64\spwmp.dll
2017-03-18 04:44:10 2560 ----a-w- C:\WINDOWS\SysWow64\wmerror.dll
2017-03-18 04:42:36 172032 ----a-w- C:\WINDOWS\SysWow64\wmpdxm.dll
2017-03-18 04:41:12 100352 ----a-w- C:\WINDOWS\SysWow64\wmpshell.dll
2017-03-18 04:41:10 9261568 ----a-w- C:\WINDOWS\SysWow64\wmploc.DLL
2017-03-18 04:40:32 458752 ----a-w- C:\WINDOWS\SysWow64\quickassist.exe
2017-03-18 04:39:50 190976 ----a-w- C:\WINDOWS\SysWow64\unregmp2.exe
2017-03-18 03:00:30 44032 ----a-w- C:\WINDOWS\System32\msdxm.tlb
2017-03-18 03:00:30 18944 ----a-w- C:\WINDOWS\System32\amcompat.tlb
2017-03-18 02:52:46 44032 ----a-w- C:\WINDOWS\SysWow64\msdxm.tlb
2017-03-18 02:52:46 18944 ----a-w- C:\WINDOWS\SysWow64\amcompat.tlb
2017-03-10 21:17:28 525600 ----a-w- C:\WINDOWS\SysWow64\vulkan-1-1-0-42-1.dll
2017-03-10 21:17:20 233760 ----a-w- C:\WINDOWS\SysWow64\vulkaninfo-1-1-0-42-1.exe
2017-03-10 21:17:14 536864 ----a-w- C:\WINDOWS\System32\vulkan-1-1-0-42-1.dll
2017-03-10 21:17:10 254240 ----a-w- C:\WINDOWS\System32\vulkaninfo-1-1-0-42-1.exe
2017-03-04 06:18:32 198656 ------w- C:\WINDOWS\SysWow64\indexeddbserver.dll
2017-02-10 09:26:14 35480 ----a-w- C:\WINDOWS\System32\TsWpfWrp.exe
2017-02-10 09:26:14 124624 ----a-w- C:\WINDOWS\System32\PresentationCFFRasterizerNative_v0300.dll
2017-02-10 09:26:14 1166520 ----a-w- C:\WINDOWS\System32\PresentationNative_v0300.dll
2017-02-10 09:21:38 35480 ----a-w- C:\WINDOWS\SysWow64\TsWpfWrp.exe
2017-02-10 09:21:36 778936 ----a-w- C:\WINDOWS\SysWow64\PresentationNative_v0300.dll
2017-02-10 09:21:36 103120 ----a-w- C:\WINDOWS\SysWow64\PresentationCFFRasterizerNative_v0300.dll
.
============= FINISH: 0:56:28,91 ===============

Attached Files
File Type: txt attach.txt (7.2 KB)
Viewing all 2798 articles
Browse latest View live