Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all 2798 articles
Browse latest View live

Win 32-Tls Hack-A Trojan

$
0
0
Ok i have been discussing the fact thati was part of that hack of CCleaner ver 5.33 here is link to those threads >>> http://www.techsupportforum.com/foru...r-1210873.html

I ran Avast a/v on my WinXp Lenovo adter discovering that the supposed new CCleaner version they told us to upgrade to version 5.34 also had two trojans Floxif.Trace in the value and registry.So this was not good.
I also ran about 2 hrs ago my Avast av to see if it would come up with something and lo&behold it found a Win 32TlsHack-A[Trj] in my
D:\System Volume Information-RESTORE{ EF02A767-847C-48BC-A8F2-DD4434CCDD04} \RP2836\A4564495.exe

Avast then told me it resolve issue and placed it in Virus chest.It didn't tell me to restart my PC though,so not sure if it resolved the issue like the claim.
So what should i do and is this realted to the CCleaner issues.

Yahoo is not my default search engine!

$
0
0
i've googled this and all links say that i need to uninstall a spicific software that i can't seem to find in my programs list.. so here i am

recently whenever I type search anything from the address field it opens yahoo search engine when i have google search engine as my default.. if i try again then it goes to google.. open a new tab type a word .. Yahoo.. try again .. google...

what's happening? and how to stop this?

and i've noticed connectivity issues with that as well which got me worried even more.. sometimes the connection totally drops for a while then comes back .. could be related to the yahoo thing or just my crappy ISP


video: https://imgur.com/u649du4


Computer acting "sluggish". Screen freezing...

$
0
0
Hello,

I have noticed in the past week that my computer is acting rather "sluggish". When I open an internet browser such as Chrome, Firefox, or Explorer the screen will freeze for about 30 seconds. Also, when I try to type anything into a search or log in somewhere, my screen will also freeze for at least 30 seconds. I am not sure why this is happening. I have not downloaded anything new that I can recall. Below is a copy of my DDS file and I have attached the Attach file per the instructions as well. I appreciate your assistance!



DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.15063.608 BrowserJavaVersion: 11.31.2
Run by Ryan Laptop at 23:52:03 on 2017-09-24
Microsoft Windows 10 Home 10.0.15063.0.1252.1.1033.18.16332.12365 [GMT -4:00]
.
AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
c:\windows\system32\svchost.exe -k dcomlaunch -s PlugPlay
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\fontdrvhost.exe
C:\WINDOWS\system32\fontdrvhost.exe
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k dcomlaunch -s LSM
C:\WINDOWS\system32\dwm.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NcbService
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s hidserv
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s TimeBrokerSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s EventLog
C:\Windows\System32\WUDFHost.exe
c:\windows\system32\svchost.exe -k localservice -s nsi
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s Dhcp
C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe
c:\windows\system32\svchost.exe -k networkservice -s NlaSvc
c:\windows\system32\svchost.exe -k localservice -s netprofm
c:\windows\system32\svchost.exe -k appmodel -s StateRepository
c:\windows\system32\svchost.exe -k netsvcs -s Schedule
c:\windows\system32\svchost.exe -k netsvcs -s ProfSvc
c:\windows\system32\svchost.exe -k netsvcs -s Themes
c:\windows\system32\svchost.exe -k localservice -s EventSystem
c:\windows\system32\svchost.exe -k netsvcs -s SENS
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -s FontCache
C:\Program Files\IDT\WDM\STacSV64.exe
c:\windows\system32\svchost.exe -k netsvcs -s UserManager
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Program Files\HitmanPro\hmpsched.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe -k networkservice -s Dnscache
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe -k netsvcs -s ShellHWDetection
C:\WINDOWS\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k wbiosvcgroup -s WbioSrvc
c:\windows\system32\svchost.exe -k localservicenonetwork
c:\windows\system32\svchost.exe -k networkservice -s LanmanWorkstation
c:\windows\system32\svchost.exe -k networkservice -s CryptSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s PcaSvc
c:\windows\system32\svchost.exe -k localservicenonetwork -s DPS
c:\windows\system32\svchost.exe -k localservice -s WinHttpAutoProxySvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DeviceAssociationService
c:\windows\system32\svchost.exe -k appmodel -s tiledatamodelsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TrkWks
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Windows\system32\vfsFPService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s FDResPub
C:\WINDOWS\System32\svchost.exe -k utcsvc
c:\windows\system32\svchost.exe -k netsvcs -s WpnService
c:\windows\system32\svchost.exe -k netsvcs -s Winmgmt
C:\Program Files (x86)\NETGEAR\A6210\NetgearSwitchUSB.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
c:\windows\system32\svchost.exe -k localservice -s WdiServiceHost
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE
C:\WINDOWS\system32\dashost.exe
c:\windows\system32\svchost.exe -k netsvcs -s iphlpsvc
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s SSDPSRV
c:\windows\system32\svchost.exe -k netsvcs -s LanmanServer
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted -s PolicyAgent
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
c:\windows\system32\svchost.exe -k localservice -s CDPSvc
c:\windows\system32\svchost.exe -k netsvcs -s DoSvc
C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s StorSvc
c:\windows\system32\sihost.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
c:\windows\system32\taskhostw.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
c:\windows\system32\svchost.exe -k netsvcs -s TokenBroker
c:\windows\system32\svchost.exe -k netsvcs -s Appinfo
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Windows\System32\RuntimeBroker.exe
c:\windows\system32\svchost.exe -k netsvcs -s lfsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s Netman
C:\Program Files\Windows Defender\MSASCuiL.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe
C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\spool\drivers\x64\3\E_YATIH5A.EXE
C:\Users\Ryan Laptop\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
C:\Windows\System32\spool\drivers\x64\3\E_YATIH5A.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinZip\FAHWindow64.exe
C:\Program Files\WinZip\WZUpdateNotifier.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\WinZip\WzPreloader.exe
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files (x86)\NETGEAR\A6210\A6210.EXE
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s RmSvc
c:\windows\system32\svchost.exe -k localservice -s SstpSvc
c:\windows\system32\svchost.exe -k networkservice -s TapiSrv
c:\windows\system32\svchost.exe -k netsvcs
C:\WINDOWS\Explorer.exe
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s wscsvc
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\System32\InstallAgent.exe
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s wcncsvc
C:\Windows\System32\InstallAgentUserBroker.exe
c:\windows\system32\svchost.exe -k localservice -s LicenseManager
c:\windows\system32\svchost.exe -k netsvcs -s seclogon
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TabletInputService
C:\WINDOWS\System32\svchost.exe -k netsvcs -s Browser
C:\Windows\System32\LockAppHost.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -s lmhosts
C:\Users\Ryan Laptop\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
c:\windows\system32\taskhostw.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -s WdiSystemHost
C:\WINDOWS\servicing\TrustedInstaller.exe
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.15063.410_none_9e914f9d2d85dacb\TiWorker.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DsSvc
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\HP SimplePass\TouchControl.exe
C:\Program Files (x86)\HP SimplePass\BioMonitor.exe
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Common Files\AuthenTec\TrueService.exe
C:\Program Files\Common Files\AuthenTec\TrueService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Ryan Laptop\Downloads\HijackThis.exe
C:\Users\Ryan Laptop\Downloads\HijackThis.exe
C:\WINDOWS\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Windows\System32\smartscreen.exe
C:\WINDOWS\system32\AUDIODG.EXE
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://yorkrsg.losscontrol360.com/
uSearch Bar = Preserve
uProxyServer = 172.17.1.1:8080
BHO: E-Web Print: {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
BHO: HP SimplePass Browser Helper Object: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass\IEBHO.dll
BHO: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
TB: WOT: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
TB: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
TB: HP SimplePass Toolbar: {C98EE38D-21E4-4A50-907D-2B56FEC7013E} - C:\Program Files (x86)\HP SimplePass\IEBHO.dll
TB: E-Web Print: {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
EB: E-Web Print: {A60C1DC7-64B3-4AD9-8E67-035D11B8B2B0} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
uRun: [EPLTarget\P0000000000000000] C:\WINDOWS\System32\spool\DRIVERS\x64\3\E_YATIH5A.EXE /EPT "EPLTarget\P0000000000000000" /M "WP-4020 Series"
uRun: [OneDrive] "C:\Users\Ryan Laptop\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
uRun: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
uRun: [PCShowServer] "C:\Users\Ryan Laptop\AppData\Local\DIRECTV Player\PCShowServerPMWrapper.exe"
uRun: [Octoshape Streaming Services] "C:\Users\Ryan Laptop\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
uRun: [EPLTarget\P0000000000000001] C:\WINDOWS\System32\spool\DRIVERS\x64\3\E_YATIH5A.EXE /EPT "EPLTarget\P0000000000000001" /M "WP-4020 Series"
uRun: [EPLTarget\P0000000000000002] C:\WINDOWS\System32\spool\DRIVERS\x64\3\E_YATIH5A.EXE /EPT "EPLTarget\P0000000000000002" /M "WP-4020 Series"
uRunOnce: [Uninstall 17.3.6966.0824\amd64] C:\WINDOWS\System32\cmd.exe /q /c rmdir /s /q "C:\Users\Ryan Laptop\AppData\Local\Microsoft\OneDrive\17.3.6966.0824\amd64"
uRunOnce: [Uninstall 17.3.6966.0824] C:\WINDOWS\System32\cmd.exe /q /c rmdir /s /q "C:\Users\Ryan Laptop\AppData\Local\Microsoft\OneDrive\17.3.6966.0824"
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [HPQuickWebProxy] "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [PCEqualizer] "C:\Program Files (x86)\PC Equalizer\PCEqualizer.exe"
mRun: [A6210] C:\Program Files (x86)\NETGEAR\A6210\A6210.EXE
StartupFolder: C:\Users\RYANLA~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Peace.lnk - C:\Program Files\EqualizerAPO\config\Peace.exe
StartupFolder: C:\Users\RYANLA~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\SIDEBA~1.LNK - C:\Program Files\Windows Sidebar\sidebar.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FAH.lnk - C:\Program Files\WinZip\FAHConsole.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\UPDATE~1.LNK - C:\Program Files\WinZip\WZUpdateNotifier.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\WINZIP~1.LNK - C:\Program Files\WinZip\WzPreloader.exe
uPolicies-Explorer: NoDrives = dword:0
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: DSCAutomationHostEnabled = dword:2
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {C5A7D325-20E3-4183-9FBE-BEF5359188E3} - hxxps://yorkrsg.losscontrol360.com/Pages/Forms/RapidSketchIncludes/eRapidSketch.cab
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{079518c6-e768-4b5b-ba26-8e8d31e44262} : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{0e1e91e3-6ccf-4bf9-84d9-4899283f5ad7} : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{2e6a78a9-7094-4e4d-b45d-9b77c9f6cd0e} : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{2e6a78a9-7094-4e4d-b45d-9b77c9f6cd0e} : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{e401a6b1-503d-4065-9102-4c661608377d} : DHCPNameServer = 75.75.75.75 75.75.76.76
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
SSODL: WebCheck - <orphaned>
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
x64-BHO: HP SimplePass Browser Helper Object: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass\x64\IEBHO.dll
x64-BHO: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
x64-BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll
x64-TB: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
x64-TB: HP SimplePass Toolbar: {C98EE38D-21E4-4A50-907D-2B56FEC7013E} - C:\Program Files (x86)\HP SimplePass\x64\IEBHO.dll
x64-Run: [SecurityHealth] C:\Program Files (x86)\Windows Defender\MSASCuiL.exe
x64-Run: [IgfxTray] "C:\WINDOWS\System32\igfxtray.exe"
x64-Run: [HotKeysCmds] "C:\WINDOWS\System32\hkcmd.exe"
x64-Run: [Persistence] "C:\WINDOWS\System32\igfxpers.exe"
x64-Run: [CnxtCoInstallerDefer] C:\Program Files\CONEXANT\PREINSTALL\SETUP563FB4250\KESLYN.EXE -REBOOTED_FROM_NO_ENUM_INSTALL_METHOD=1 -S
x64-Run: [SetDefault] C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe
x64-Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-mPolicies-Explorer: NoDrives = dword:0
x64-mPolicies-System: DSCAutomationHostEnabled = dword:2
x64-IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
x64-Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
x64-Notify: GoToAssist - C:\Program Files (x86)\Citrix\GoToAssist\822\G2AWinLogon_x64.dll
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
x64-mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\60.0.3112.113\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
x64-CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
Hosts: 127.0.0.1 ads.mcafee.com
Hosts: 127.0.0.1 analytics.microsoft.com
Hosts: 127.0.0.1 metrics.bitdefender.com
Hosts: 127.0.0.1 metrics.mcafee.com
Hosts: 127.0.0.1 om.symantec.com
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Ryan Laptop\AppData\Roaming\Mozilla\Firefox\Profiles\v0f3oso5.default-1388968658828\
FF - prefs.js: browser.search.selectedEngine - Speedial
FF - prefs.js: browser.startup.homepage - about:home
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Ryan Laptop\AppData\Local\Citrix\Plugins\104\npappdetector.dll
FF - plugin: C:\Users\Ryan Laptop\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
FF - plugin: C:\Windows\npMSDM.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll
FF - plugin: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll
FF - plugin: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.nspdlsd.aflt - spd_wnzp01_14_28_ff
FF - user.js: extensions.nspdlsd.instlRef - 142905_b
FF - user.js: extensions.nspdlsd.cr - 1894968798
FF - user.js: extensions.nspdlsd.cd - 2XzuyEtN2Y1L1QzutBtDtCtDyB0AtB0AyByB0ByBtBtC0AtBtN0D0Tzu0SzytByDtN1L2XzutBtFtBtCtFtCtCtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEyEyByCzz0E0AzytGzztByCzztGyC0AyE0EtGzzyDyC0FtGtC0E0FyDzztBzytDzyyDyEtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtAyCyBtCyCtC0FtGyC0A0C0EtG0Azy0E0FtG0CtD0EyEtGtDyB0ByEyEyBtAyDtDtC0DtC2Q
.
============= SERVICES / DRIVERS ===============
.
R0 intelpep;Intel(R) Power Engine Plug-in Driver;C:\WINDOWS\System32\drivers\intelpep.sys [2017-3-18 74840]
R0 iorate;Disk I/O Rate Filter Driver;C:\WINDOWS\System32\drivers\iorate.sys [2017-3-18 49568]
R0 volume;Volume driver;C:\WINDOWS\System32\drivers\volume.sys [2017-3-18 16288]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [2017-3-18 70232]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [2017-3-18 18520]
R0 Wof;Windows Overlay File System Filter Driver;C:\WINDOWS\System32\drivers\wof.sys [2017-3-18 208288]
R1 ahcache;Application Compatibility Cache;C:\WINDOWS\System32\drivers\ahcache.sys [2017-3-18 239616]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit;C:\WINDOWS\System32\drivers\mbae64.sys [2017-9-24 77440]
R1 FileCrypt;FileCrypt;C:\WINDOWS\System32\drivers\filecrypt.sys [2017-3-18 54272]
R1 GpuEnergyDrv;GPU Energy Driver;C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2017-3-18 8192]
R1 MpKsl3f7889d9;MpKsl3f7889d9;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{16001E19-721E-4792-8F13-726E5CF98B98}\MpKsl3f7889d9.sys [2017-9-24 44928]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2017-7-30 89600]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-3-2 83768]
R2 CDPSvc;Connected Devices Platform Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
R2 CDPUserSvc_20b757;Connected Devices Platform User Service_20b757;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R2 clreg;Virtual Registry for Containers;C:\WINDOWS\System32\drivers\registry.sys [2017-3-18 14336]
R2 CoreMessagingRegistrar;CoreMessaging;C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork [2017-3-18 47664]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2015-3-18 822496]
R2 DiagTrack;Connected User Experiences and Telemetry;C:\WINDOWS\System32\svchost.exe -k utcsvc [2017-3-18 47664]
R2 DoSvc;Delivery Optimization;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R2 DusmSvc;Data Usage;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
R2 EPSON_PM_RPCV4_05;EPSON V3 Service4(05);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE [2016-10-23 136576]
R2 EpsonCustomerParticipation;EpsonCustomerParticipation;C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe [2011-3-17 674800]
R2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe [2011-12-11 260424]
R2 HitmanProScheduler;HitmanPro Scheduler;C:\Program Files\HitmanPro\hmpsched.exe [2013-4-23 135488]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2013-8-19 270624]
R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [2015-7-26 321896]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-3-5 35200]
R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-2-24 212944]
R2 MBAMChameleon;MBAMChameleon;C:\WINDOWS\System32\drivers\MBAMChameleon.sys [2017-9-24 192960]
R2 MBAMService;Malwarebytes Service;C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [2017-9-24 6058960]
R2 NetgearSwitchUSB;NetgearSwitchUSB;C:\Program Files (x86)\NETGEAR\A6210\NetgearSwitchUSB.exe [2015-9-17 192232]
R2 OneSyncSvc_20b757;Sync Host_20b757;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R2 SecurityHealthService;Windows Defender Security Center Service;C:\WINDOWS\System32\SecurityHealthService.exe [2017-7-11 336320]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2014-10-8 534184]
R2 storqosflt;Storage QoS Filter Driver;C:\WINDOWS\System32\drivers\storqosflt.sys [2017-3-18 79872]
R2 SynTPEnhService;SynTPEnh Caller Service;C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2016-4-28 253960]
R2 tiledatamodelsvc;Tile Data model server;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-2-27 2656536]
R2 UserManager;User Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R2 vfsFPService;Validity Fingerprint Service;C:\WINDOWS\System32\vfsFPService.exe [2009-6-3 721712]
R2 wcifs;Windows Container Isolation;C:\WINDOWS\System32\drivers\wcifs.sys [2017-7-11 142752]
R2 WpnService;Windows Push Notifications System Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R2 WpnUserService_20b757;Windows Push Notifications User Service_20b757;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R3 CAD;Charge Arbitration Driver;C:\WINDOWS\System32\drivers\CAD.sys [2017-3-18 53664]
R3 DsSvc;Data Sharing Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
R3 IntcDAud;Intel(R) Display Audio;C:\WINDOWS\System32\drivers\IntcDAud.sys [2012-2-27 317440]
R3 lfsvc;Geolocation Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R3 LicenseManager;Windows License Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
R3 MBAMFarflt;MBAMFarflt;C:\WINDOWS\System32\drivers\farflt.sys [2017-9-24 101824]
R3 MBAMProtection;MBAMProtection;C:\WINDOWS\System32\drivers\mbam.sys [2017-9-24 45472]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [2017-9-24 253888]
R3 MBAMWebProtection;MBAMWebProtection;C:\WINDOWS\System32\drivers\mwac.sys [2017-9-24 94144]
R3 NcbService;Network Connection Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [2017-3-18 20992]
R3 PimIndexMaintenanceSvc_20b757;Contact Data_20b757;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\WINDOWS\System32\drivers\RtsPStor.sys [2015-6-3 374016]
R3 rt640x64;Realtek RT640 NT Driver;C:\WINDOWS\System32\drivers\rt640x64.sys [2017-3-18 604160]
R3 rtwlane_13;Realtek Wireless LAN 802.11n PCI-E Network Adapter;C:\WINDOWS\System32\drivers\rtwlane_13.sys [2017-3-18 3717120]
R3 Sftfs;Sftfs;C:\WINDOWS\System32\drivers\Sftfslh.sys [2014-10-8 766632]
R3 Sftplay;Sftplay;C:\WINDOWS\System32\drivers\Sftplaylh.sys [2014-10-8 273576]
R3 Sftredir;Sftredir;C:\WINDOWS\System32\drivers\Sftredirlh.sys [2014-10-8 29352]
R3 Sftvol;Sftvol;C:\WINDOWS\System32\drivers\Sftvollh.sys [2014-10-8 23208]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2014-10-8 211104]
R3 SmbDrvI;SmbDrvI;C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [2016-1-27 52904]
R3 StateRepository;State Repository Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
R3 TimeBrokerSvc;Time Broker;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
R3 TokenBroker;TokenBroker;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R3 TrueService;TrueAPI Service component;C:\Program Files\Common Files\AuthenTec\TrueService.exe [2011-12-9 269640]
R3 UnistoreSvc_20b757;User Data Storage_20b757;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R3 UserDataSvc_20b757;User Data Access_20b757;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R3 WdNisDrv;Windows Defender Antivirus Network Inspection System Driver;C:\WINDOWS\System32\drivers\WdNisDrv.sys [2017-3-18 121248]
R3 WdNisSvc;Windows Defender Antivirus Network Inspection Service;C:\Program Files\Windows Defender\NisSrv.exe [2017-3-18 342264]
R3 WirelessButtonDriver64;HP Wireless Button Driver Service;C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [2017-6-21 30368]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\drivers\WUDFRd.sys [2017-3-18 220672]
S2 BingDesktopUpdate;Bing Desktop Update service;C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [2014-6-3 173792]
S2 CldFlt;Windows Cloud Files Filter Driver;C:\WINDOWS\System32\drivers\cldflt.sys [2017-3-18 12288]
S2 CLKMSVC10_38F51D56;CyberLink Product - 2015/11/08 17:56:21;C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2012-2-8 244720]
S2 GamesAppIntegrationService;GamesAppIntegrationService;C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [2016-9-1 350064]
S2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
S2 hpsrv;HP Service;C:\WINDOWS\System32\hpservice.exe [2011-5-27 30520]
S2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2016-9-25 2413056]
S2 MapsBroker;Downloaded Maps Manager;C:\WINDOWS\System32\svchost.exe -k NetworkService [2017-3-18 47664]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 AcpiDev;ACPI Devices driver;C:\WINDOWS\System32\drivers\AcpiDev.sys [2017-3-18 20480]
S3 ADP80XX;ADP80XX;C:\WINDOWS\System32\drivers\adp80xx.sys [2017-3-18 1135512]
S3 AJRouter;AllJoyn Router Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 applockerfltr;Smartlocker Filter Driver;C:\WINDOWS\System32\drivers\applockerfltr.sys [2017-3-18 17920]
S3 AppReadiness;App Readiness;C:\WINDOWS\System32\svchost.exe -k AppReadiness [2017-3-18 47664]
S3 AppXSvc;AppX Deployment Service (AppXSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2017-3-18 47664]
S3 bcmfn2;bcmfn2 Service;C:\WINDOWS\System32\drivers\bcmfn2.sys [2017-3-18 9728]
S3 BthHFSrv;Bluetooth Handsfree Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation [2017-3-18 47664]
S3 buttonconverter;Service for Portable Device Control devices;C:\WINDOWS\System32\drivers\buttonconverter.sys [2017-9-16 39424]
S3 CapImg;HID driver for CapImg touch screen;C:\WINDOWS\System32\drivers\capimg.sys [2017-3-18 122880]
S3 cht4iscsi;cht4iscsi;C:\WINDOWS\System32\drivers\cht4sx64.sys [2017-3-18 347032]
S3 cht4vbd;Chelsio Virtual Bus Driver;C:\WINDOWS\System32\drivers\cht4vx64.sys [2017-3-18 2104224]
S3 ClipSVC;Client License Service (ClipSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2017-3-18 47664]
S3 DevicesFlowUserSvc_20b757;DevicesFlow_20b757;C:\WINDOWS\System32\svchost.exe -k DevicesFlow [2017-3-18 47664]
S3 DevQueryBroker;DevQuery Background Discovery Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\WINDOWS\System32\drivers\ssudbus.sys [2016-9-5 131712]
S3 diagnosticshub.standardcollector.service;Microsoft (R) Diagnostics Hub Standard Collector Service;C:\WINDOWS\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2017-3-18 86528]
S3 DIRECTIO;DIRECTIO;C:\Program Files\PerformanceTest\DirectIo64.sys [2014-8-19 31160]
S3 DmEnrollmentSvc;Device Management Enrollment Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 dmwappushservice;dmwappushsvc;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 embeddedmode;Embedded Mode;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 EntAppSvc;Enterprise App Management Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
S3 FrameServer;Windows Camera Frame Server;C:\WINDOWS\System32\svchost.exe -k Camera [2017-3-18 47664]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2016-9-1 210288]
S3 genericusbfn;Generic USB Function Class;C:\WINDOWS\System32\drivers\genericusbfn.sys [2017-3-18 21504]
S3 hidinterrupt;Common Driver for HID Buttons implemented with interrupts;C:\WINDOWS\System32\drivers\hidinterrupt.sys [2017-3-18 51104]
S3 HvHost;HV Host Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 iagpio;Intel Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iagpio.sys [2017-3-18 33280]
S3 iai2c;Intel(R) Serial IO I2C Host Controller;C:\WINDOWS\System32\drivers\iai2c.sys [2017-3-18 81408]
S3 iaLPSS2i_GPIO2;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2017-3-18 70656]
S3 iaLPSS2i_GPIO2_BXT_P;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2017-3-18 85504]
S3 iaLPSS2i_I2C;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2017-3-18 165376]
S3 iaLPSS2i_I2C_BXT_P;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2017-3-18 168448]
S3 iaLPSSi_GPIO;Intel(R) Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [2017-3-18 38128]
S3 iaLPSSi_I2C;Intel(R) Serial IO I2C Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [2017-3-18 113152]
S3 iaStorAV;Intel(R) SATA RAID Controller Windows;C:\WINDOWS\System32\drivers\iaStorAV.sys [2017-3-18 673184]
S3 ibbus;Mellanox InfiniBand Bus/AL (Filter Driver);C:\WINDOWS\System32\drivers\ibbus.sys [2017-3-18 526240]
S3 icssvc;Windows Mobile Hotspot Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 IndirectKmd;Indirect Displays Kernel-Mode Driver;C:\WINDOWS\System32\drivers\IndirectKmd.sys [2017-3-18 36864]
S3 IpxlatCfgSvc;IP Translation Configuration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 LSI_SAS2i;LSI_SAS2i;C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2017-3-18 123808]
S3 LSI_SAS3i;LSI_SAS3i;C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2017-3-18 103328]
S3 mausbhost;MA-USB Host Controller Driver;C:\WINDOWS\System32\drivers\mausbhost.sys [2017-3-18 405408]
S3 mausbip;MA-USB IP Filter Driver;C:\WINDOWS\System32\drivers\mausbip.sys [2017-3-18 51104]
S3 megasas2i;megasas2i;C:\WINDOWS\System32\drivers\MegaSas2i.sys [2017-3-18 64416]
S3 MessagingService_20b757;MessagingService_20b757;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
S3 mlx4_bus;Mellanox ConnectX Bus Enumerator;C:\WINDOWS\System32\drivers\mlx4_bus.sys [2017-3-18 842656]
S3 NaturalAuthentication;Natural Authentication;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 ndfltr;NetworkDirect Service;C:\WINDOWS\System32\drivers\ndfltr.sys [2017-3-18 108960]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library;C:\WINDOWS\System32\drivers\NetAdapterCx.sys [2017-3-18 122368]
S3 NetSetupSvc;Network Setup Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 netvsc;netvsc;C:\WINDOWS\System32\drivers\netvsc.sys [2017-7-11 118784]
S3 NgcCtnrSvc;Microsoft Passport Container;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 NgcSvc;Microsoft Passport;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 nvdimmn;Microsoft NVDIMM-N device driver;C:\WINDOWS\System32\drivers\nvdimmn.sys [2017-3-18 80896]
S3 percsas2i;percsas2i;C:\WINDOWS\System32\drivers\percsas2i.sys [2017-3-18 58784]
S3 percsas3i;percsas3i;C:\WINDOWS\System32\drivers\percsas3i.sys [2017-3-18 61848]
S3 PhoneSvc;Phone Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 ReFS;ReFS;C:\WINDOWS\System32\drivers\refs.sys [2017-3-18 1735584]
S3 ReFSv1;ReFSv1;C:\WINDOWS\System32\drivers\refsv1.sys [2017-3-18 936864]
S3 RetailDemo;Retail Demo Service;C:\WINDOWS\System32\svchost.exe -k rdxgroup [2017-3-18 47664]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 scmbus;Microsoft Storage Class Memory Bus Driver;C:\WINDOWS\System32\drivers\scmbus.sys [2017-3-18 91040]
S3 SDFRd;SDF Reflector;C:\WINDOWS\System32\drivers\SDFRd.sys [2017-3-18 31128]
S3 SEMgrSvc;Payments and NFC/SE Manager;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 SensorDataService;Sensor Data Service;C:\WINDOWS\System32\SensorDataService.exe [2017-3-18 1284608]
S3 SensorService;Sensor Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 SerCx2;Serial UART Support Library;C:\WINDOWS\System32\drivers\SerCx2.sys [2017-3-18 154016]
S3 smphost;Microsoft Storage Spaces SMP;C:\WINDOWS\System32\svchost.exe -k smphost [2017-3-18 47664]
S3 SmsRouter;Microsoft Windows SMS Router Service.;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 SpatialGraphFilter;Holographic Spatial Graph Filter;C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [2017-3-18 40352]
S3 spectrum;Windows Perception Service;C:\WINDOWS\System32\Spectrum.exe [2017-3-18 891904]
S3 SRS_AE_Service;SRS Audio;C:\WINDOWS\System32\drivers\SRS_AE_amd64.sys [2012-6-21 549704]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\WINDOWS\System32\drivers\ssudmdm.sys [2016-9-5 165504]
S3 stornvme;Microsoft Standard NVM Express Driver;C:\WINDOWS\System32\drivers\stornvme.sys [2017-3-18 95648]
S3 storufs;Microsoft Universal Flash Storage (UFS) Driver;C:\WINDOWS\System32\drivers\storufs.sys [2017-3-18 36760]
S3 TieringEngineService;Storage Tiers Management;C:\WINDOWS\System32\TieringEngineService.exe [2017-3-18 302592]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmCx.sys [2017-9-16 104960]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmTcpciCx.sys [2017-3-18 179200]
S3 UcmUcsi;USB Connector Manager UCSI Client;C:\WINDOWS\System32\drivers\UcmUcsi.sys [2017-8-8 51712]
S3 UdeCx;USB Device Emulation Support Library;C:\WINDOWS\System32\drivers\Udecx.sys [2017-3-18 45568]
S3 UEFI;Microsoft UEFI Driver;C:\WINDOWS\System32\drivers\uefi.sys [2017-3-18 29600]
S3 Ufx01000;USB Function Class Extension;C:\WINDOWS\System32\drivers\ufx01000.sys [2017-3-18 263584]
S3 UfxChipidea;USB Chipidea Controller;C:\WINDOWS\System32\drivers\UfxChipidea.sys [2017-3-18 98712]
S3 ufxsynopsys;USB Synopsys Controller;C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2017-3-18 138656]
S3 UrsChipidea;Chipidea USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urschipidea.sys [2017-3-18 29600]
S3 UrsCx01000;USB Role-Switch Support Library;C:\WINDOWS\System32\drivers\urscx01000.sys [2017-3-18 59288]
S3 UrsSynopsys;Synopsys USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urssynopsys.sys [2017-3-18 28064]
S3 UsoSvc;Update Orchestrator Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 vhf;Virtual HID Framework (VHF) Driver;C:\WINDOWS\System32\drivers\vhf.sys [2017-3-18 35328]
S3 vmgid;Microsoft Hyper-V Guest Infrastructure Driver;C:\WINDOWS\System32\drivers\vmgid.sys [2017-3-18 10240]
S3 vmicguestinterface;Hyper-V Guest Service Interface;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 vmicvmsession;Hyper-V PowerShell Direct Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 WalletService;WalletService;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
S3 wcnfs;Windows Container Name Virtualization;C:\WINDOWS\System32\drivers\wcnfs.sys [2017-3-18 72192]
S3 wdiwifi;WDI Driver Framework;C:\WINDOWS\System32\drivers\WdiWiFi.sys [2017-7-11 757248]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;C:\WINDOWS\System32\svchost.exe -k WepHostSvcGroup [2017-3-18 47664]
S3 WFDSConMgrSvc;Wi-Fi Direct Services Connection Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 WinMad;WinMad Service;C:\WINDOWS\System32\drivers\winmad.sys [2017-3-18 32160]
S3 WinNat;Windows NAT Driver;C:\WINDOWS\System32\drivers\winnat.sys [2017-3-18 217088]
S3 WinVerbs;WinVerbs Service;C:\WINDOWS\System32\drivers\winverbs.sys [2017-3-18 64920]
S3 wisvc;Windows Insider Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 wlpasvc;LPA Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 workfolderssvc;Work Folders;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 xbgm;Xbox Game Monitoring;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 XblAuthManager;Xbox Live Auth Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 XblGameSave;Xbox Live Game Save;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 xboxgip;Xbox Game Input Protocol Driver;C:\WINDOWS\System32\drivers\xboxgip.sys [2017-7-11 277504]
S3 XboxGipSvc;Xbox Accessory Management Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 XboxNetApiSvc;Xbox Live Networking Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 xinputhid;XINPUT HID Filter Driver;C:\WINDOWS\System32\drivers\xinputhid.sys [2017-3-18 46592]
S4 shpamsvc;Shared PC Account Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S4 tzautoupdate;Auto Time Zone Updater;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
SUnknown MpKsl4d6cb44e;MpKsl4d6cb44e; [x]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\WINDOWS\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2017-09-24 06:25:13 192960 ----a-w- C:\WINDOWS\System32\drivers\MBAMChameleon.sys
2017-09-24 06:24:59 94144 ----a-w- C:\WINDOWS\System32\drivers\mwac.sys
2017-09-24 06:24:59 101824 ----a-w- C:\WINDOWS\System32\drivers\farflt.sys
2017-09-24 06:24:54 45472 ----a-w- C:\WINDOWS\System32\drivers\mbam.sys
2017-09-24 06:24:49 253888 ----a-w- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
2017-09-24 06:24:22 77440 ----a-w- C:\WINDOWS\System32\drivers\mbae64.sys
2017-09-24 06:24:16 -------- d-----w- C:\Program Files\Malwarebytes
2017-09-24 06:23:53 -------- d-----w- C:\ProgramData\MB2Migration
2017-09-24 06:22:47 44928 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{16001E19-721E-4792-8F13-726E5CF98B98}\MpKsl3f7889d9.sys
2017-09-24 06:12:50 13482976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{16001E19-721E-4792-8F13-726E5CF98B98}\mpengine.dll
2017-09-22 04:19:24 13482976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2017-09-20 23:33:19 1078240 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7888B270-3728-43BB-9F56-831E5BC333FE}\gapaengine.dll
2017-09-17 02:52:59 918528 ----a-w- C:\WINDOWS\SysWow64\Windows.Networking.Vpn.dll
2017-09-17 02:22:00 1078240 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{36C54442-8571-439B-9073-6F1CEA2B5542}\gapaengine.dll
2017-09-05 00:09:46 18654464 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
2017-08-28 22:26:29 112592 ----a-w- C:\Program Files (x86)\Mozilla Firefox\AccessibleHandler.dll
.
==================== Find3M ====================
.
2017-09-20 23:18:31 152560 ------w- C:\WINDOWS\System32\drivers\rikvm_38F51D56.sys
2017-09-05 05:31:34 1596592 ----a-w- C:\WINDOWS\System32\gdi32full.dll
2017-09-05 05:31:28 750560 ----a-w- C:\WINDOWS\System32\fontdrvhost.exe
2017-09-05 05:31:26 1346112 ----a-w- C:\WINDOWS\System32\user32.dll
2017-09-05 05:31:20 1147296 ----a-w- C:\WINDOWS\System32\hvix64.exe
2017-09-05 05:31:20 1024928 ----a-w- C:\WINDOWS\System32\hvax64.exe
2017-09-05 05:31:18 821664 ----a-w- C:\WINDOWS\System32\hvloader.exe
2017-09-05 05:31:16 115792 ----a-w- C:\WINDOWS\System32\win32u.dll
2017-09-05 05:30:55 287648 ----a-w- C:\WINDOWS\System32\drivers\sdbus.sys
2017-09-05 05:27:55 136096 ----a-w- C:\WINDOWS\System32\drivers\ksecdd.sys
2017-09-05 05:27:02 2399728 ----a-w- C:\WINDOWS\System32\KernelBase.dll
2017-09-05 05:26:51 8319904 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2017-09-05 05:26:19 1930840 ----a-w- C:\WINDOWS\System32\ntdll.dll
2017-09-05 05:25:54 159648 ----a-w- C:\WINDOWS\System32\drivers\partmgr.sys
2017-09-05 05:25:09 2969880 ----a-w- C:\WINDOWS\System32\CoreUIComponents.dll
2017-09-05 05:24:21 519584 ----a-w- C:\WINDOWS\System32\drivers\netio.sys
2017-09-05 05:24:11 923040 ----a-w- C:\WINDOWS\System32\CoreMessaging.dll
2017-09-05 05:23:47 1242528 ----a-w- C:\WINDOWS\System32\drivers\ndis.sys
2017-09-05 05:23:22 4462120 ----a-w- C:\WINDOWS\System32\setupapi.dll
2017-09-05 05:21:55 189344 ----a-w- C:\WINDOWS\System32\drivers\dumpsd.sys
2017-09-05 05:20:27 1057824 ----a-w- C:\WINDOWS\System32\MrmCoreR.dll
2017-09-05 05:19:29 4848960 ----a-w- C:\WINDOWS\explorer.exe
2017-09-05 05:19:03 2443168 ----a-w- C:\WINDOWS\System32\drivers\dxgkrnl.sys
2017-09-05 05:18:59 2972552 ----a-w- C:\WINDOWS\System32\d3d10warp.dll
2017-09-05 05:18:34 7326128 ----a-w- C:\WINDOWS\System32\windows.storage.dll
2017-09-05 05:18:29 820128 ----a-w- C:\WINDOWS\System32\WWAHost.exe
2017-09-05 05:18:23 5477096 ----a-w- C:\WINDOWS\System32\OneCoreUAPCommonProxyStub.dll
2017-09-05 05:18:19 1668344 ----a-w- C:\WINDOWS\System32\propsys.dll
2017-09-05 05:18:14 212384 ----a-w- C:\WINDOWS\System32\browserbroker.dll
2017-09-05 05:18:09 685512 ----a-w- C:\WINDOWS\System32\SHCore.dll
2017-09-05 05:17:08 316320 ----a-w- C:\WINDOWS\System32\WerFault.exe
2017-09-05 05:16:55 872472 ----a-w- C:\WINDOWS\System32\ClipSVC.dll
2017-09-05 05:16:50 546208 ----a-w- C:\WINDOWS\System32\drivers\storport.sys
2017-09-05 05:16:46 1320344 ----a-w- C:\WINDOWS\System32\wpx.dll
2017-09-05 05:16:41 228256 ----a-w- C:\WINDOWS\System32\drivers\mrxsmb20.sys
2017-09-05 05:16:39 410168 ----a-w- C:\WINDOWS\System32\Faultrep.dll
2017-09-05 05:16:36 724200 ----a-w- C:\WINDOWS\System32\wer.dll
2017-09-05 05:16:30 182688 ----a-w- C:\WINDOWS\System32\wermgr.exe
2017-09-05 05:16:21 49720 ----a-w- C:\WINDOWS\System32\tbs.dll
2017-09-05 05:16:17 715168 ----a-w- C:\WINDOWS\System32\drivers\fvevol.sys
2017-09-05 05:15:49 3116184 ----a-w- C:\WINDOWS\System32\combase.dll
2017-09-05 05:15:48 871448 ----a-w- C:\WINDOWS\System32\winhttp.dll
2017-09-05 05:15:44 654976 ----a-w- C:\WINDOWS\System32\AppXDeploymentClient.dll
2017-09-05 05:15:43 257440 ----a-w- C:\WINDOWS\System32\AppxAllUserStore.dll
2017-09-05 05:15:42 381824 ----a-w- C:\WINDOWS\System32\wevtapi.dll
2017-09-05 05:14:56 94624 ----a-w- C:\WINDOWS\System32\rdpudd.dll
2017-09-05 05:14:44 7907344 ----a-w- C:\WINDOWS\System32\Windows.Media.Protection.PlayReady.dll
2017-09-05 05:14:41 4708504 ----a-w- C:\WINDOWS\System32\mfcore.dll
2017-09-05 05:14:24 958664 ----a-w- C:\WINDOWS\System32\msvproc.dll
2017-09-05 05:14:18 1146176 ----a-w- C:\WINDOWS\System32\mfds.dll
2017-09-05 05:14:15 254176 ----a-w- C:\WINDOWS\System32\mfps.dll
2017-09-05 05:13:46 1619816 ----a-w- C:\WINDOWS\System32\sppobjs.dll
2017-09-05 05:13:15 64680 ----a-w- C:\WINDOWS\System32\appidapi.dll
2017-09-05 05:12:59 1409048 ----a-w- C:\WINDOWS\SysWow64\gdi32full.dll
2017-09-05 05:12:57 1292880 ----a-w- C:\WINDOWS\SysWow64\user32.dll
2017-09-05 05:12:54 627080 ----a-w- C:\WINDOWS\SysWow64\fontdrvhost.exe
2017-09-05 05:12:49 81176 ----a-w- C:\WINDOWS\SysWow64\win32u.dll
2017-09-05 05:11:28 2675104 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2017-09-05 05:11:21 610720 ----a-w- C:\WINDOWS\System32\drivers\afd.sys
2017-09-05 05:11:13 387936 ----a-w- C:\WINDOWS\System32\wmpps.dll
2017-09-05 04:53:54 1620880 ----a-w- C:\WINDOWS\SysWow64\ntdll.dll
2017-09-05 04:53:33 1839872 ----a-w- C:\WINDOWS\SysWow64\KernelBase.dll
2017-09-05 04:52:15 2259760 ----a-w- C:\WINDOWS\SysWow64\CoreUIComponents.dll
2017-09-05 04:50:17 4330920 ----a-w- C:\WINDOWS\SysWow64\setupapi.dll
2017-09-05 04:46:19 4471888 ----a-w- C:\WINDOWS\SysWow64\explorer.exe
2017-09-05 04:45:57 85784 ----a-w- C:\WINDOWS\SysWow64\CredentialUIBroker.exe
2017-09-05 04:45:44 2476712 ----a-w- C:\WINDOWS\SysWow64\d3d10warp.dll
2017-09-05 04:45:09 5821496 ----a-w- C:\WINDOWS\SysWow64\windows.storage.dll
2017-09-05 04:45:08 750496 ----a-w- C:\WINDOWS\SysWow64\WWAHost.exe
2017-09-05 04:45:07 23679488 ----a-w- C:\WINDOWS\System32\edgehtml.dll
2017-09-05 04:44:52 569264 ----a-w- C:\WINDOWS\SysWow64\SHCore.dll
2017-09-05 04:43:54 280480 ----a-w- C:\WINDOWS\SysWow64\WerFault.exe
2017-09-05 04:43:24 611096 ----a-w- C:\WINDOWS\SysWow64\wer.dll
2017-09-05 04:43:19 359560 ----a-w- C:\WINDOWS\SysWow64\Faultrep.dll
2017-09-05 04:43:17 169376 ----a-w- C:\WINDOWS\SysWow64\wermgr.exe
2017-09-05 04:43:12 42456 ----a-w- C:\WINDOWS\SysWow64\tbs.dll
2017-09-05 04:42:31 2330520 ----a-w- C:\WINDOWS\SysWow64\combase.dll
2017-09-05 04:42:30 519680 ----a-w- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
2017-09-05 04:42:28 182688 ----a-w- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
2017-09-05 04:42:27 291904 ----a-w- C:\WINDOWS\SysWow64\wevtapi.dll
2017-09-05 04:42:25 703056 ----a-w- C:\WINDOWS\SysWow64\winhttp.dll
2017-09-05 04:41:24 4671832 ----a-w- C:\WINDOWS\SysWow64\mfcore.dll
2017-09-05 04:41:23 6761560 ----a-w- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
2017-09-05 04:41:06 1106904 ----a-w- C:\WINDOWS\SysWow64\mfds.dll
2017-09-05 04:41:04 1013912 ----a-w- C:\WINDOWS\SysWow64\msvproc.dll
2017-09-05 04:40:13 52768 ----a-w- C:\WINDOWS\SysWow64\appidapi.dll
2017-09-05 04:37:39 583160 ----a-w- C:\WINDOWS\SysWow64\CoreMessaging.dll
2017-09-05 04:31:02 3668992 ----a-w- C:\WINDOWS\System32\win32kfull.sys
2017-09-05 04:30:53 463360 ----a-w- C:\WINDOWS\System32\werui.dll
2017-09-05 04:30:51 1639936 ----a-w- C:\WINDOWS\System32\GdiPlus.dll
2017-09-05 04:30:47 77824 ----a-w- C:\WINDOWS\System32\wsqmcons.exe
2017-09-05 04:30:45 1275904 ----a-w- C:\WINDOWS\System32\werconcpl.dll
2017-09-05 04:30:38 584192 ----a-w- C:\WINDOWS\System32\UIRibbonRes.dll
2017-09-05 04:30:35 184320 ----a-w- C:\WINDOWS\System32\DWWIN.EXE
2017-09-05 04:30:24 89088 ----a-w- C:\WINDOWS\System32\winsrvext.dll
2017-09-05 04:30:22 93184 ----a-w- C:\WINDOWS\System32\wercplsupport.dll
2017-09-05 04:30:12 447488 ----a-w- C:\WINDOWS\System32\win32k.sys
2017-09-05 04:29:27 37376 ----a-w- C:\WINDOWS\System32\SEMgrPS.dll
2017-09-05 04:28:48 2199552 ----a-w- C:\WINDOWS\System32\Windows.UI.Xaml.Resources.dll
2017-09-05 04:28:15 39424 ----a-w- C:\WINDOWS\System32\drivers\buttonconverter.sys
.
============= FINISH: 23:52:54.02 ===============

Attached Files
File Type: txt attach.txt (12.8 KB)

Infected with INSANE bitcoinminer. Desperate for help

$
0
0
Hello everyone
First and foremost, thanks for your time . I appreciate ur good will to help.



Background information :


1) SSD has been formatted 1 week ago or less (Cant remember) the second drive (1tb) remained as backup.


2) each time I open Skype /Certain games/ Battle.net EVEN Google Chrome.
my GPU temp jumps from 30 idle to 50 and the GPU uses its full functions (Clock speed jumps to max, etc)


3)My computer's clock time is not stable, keeps on changing (has been like that for more than a year, even tho I formatted 2 times since the problem arise) I suspect this problem is due to having a motherboard battery burnt although it may be a virus in the BIOS.( my assumptions) I never tried to replace a motherboard battery, I currently have Asus Z97 motherboard.


PC scanned with - Rogue-killer, Anti-malware bytes and Hitman PRO.
SSD Has been formatted 2 times in the last 3 years and a half
from win 8.1 to win10. and from win10 to win7. (SINCE THE FIRST FORMAT THE CLOCK STARTED BUGGING.
since then I have had the problem with time.


*bitcoin miner : New problem that I have just noticed recently, which is taking all my attention to cure my GPU.


*Note: Currently If I don't run the apps I mentioned above my GPU temp is OK. therefore the main problems are Clock time changes, and Temp jumps super high for no reason while running certain applications.

I used Process Explorer to try and track which applications cause GPU traffic,
that's how I know when the bitcoin miner works and when it doesn't.

I came here thanks to Combo-fix (Didn't run a scan yet)
Thanks in advance, I will be waiting for your help

Best regards,

John.


LOGS :

Attached Files
File Type: txt FRST.txt (209.1 KB)
File Type: txt Addition.txt (33.3 KB)

Need Help with HijackThis Log

$
0
0
I need one of the experts to tell me what needs to be removed ... I am having problems with all my browsers stalling and locking up. Do you see anything that will help resolve the problem?:ermm:

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 7:51:36 PM, on 9/30/2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18792)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Webshots\webshots.scr
C:\Program Files (x86)\Comodo\Internet Security Essentials\vkise.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
D:\Computer Help Files\Anti_virus\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IseUI] C:\Program Files (x86)\COMODO\Internet Security Essentials\vkise.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Webshots.lnk = C:\Program Files (x86)\Webshots\Launcher.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - https://fpdownload.macromedia.com/pub/s ... tor/sw.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B412A748-0051-4B58-9E89-41E67CFEB28B}: NameServer = 156.154.70.22,156.154.71.22
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: COMODO Internet Security Helper Service (CmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: DisplayLinkManager (DisplayLinkService) - DisplayLink Corp. - C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: isesrv - COMODO - C:\Program Files (x86)\COMODO\Internet Security Essentials\isesrv.exe
O23 - Service: @Keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @Comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7427 bytes

Can malware change your email?

$
0
0
My mother tells me my grandfather keeps getting an email in her name (It's spam email) but the email is different. He says hes been getting these from her for a while, but I nor anyone else on her contact list has gotten emails from her like that. Im not experienced when it comes to worms or malware. Would malware sending out emails show in the recently sent folder, because there were none. I just cleaned out her pc a few days ago, I didn't find any malware or any problems really.

System is bogging down

$
0
0
My home grown system has issues. Something has gotten into it. I believe it started getting noticeably about a week ago. I vaguely remember doing an update, for I believe was Malwarebytes. Since then all kinds of issues have happened. The most noticeable was that I was getting errors for net.exe. I finally got Malwarebytes back running, but I'm not sure if I trust the installation. I did do a root scan with mssstool64 and that turned out okay. Using the MS SFC I verified that I had issues with net1.exe that could not be corrected.

I am getting extremely slow shut downs and restarts. I recently had an issue with explorer not wanting to start. That appeared to be an issue with Autodesk360, which I uninstalled, so that is now working.

Any help weeding out the bug would be appreciated.
Attached is attach.txt and sfcdetails.txt

Thank you,
Randy

DDS.TXT -
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.18792 BrowserJavaVersion: 11.31.2
Run by Randy at 19:41:40 on 2017-10-05
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.16362.8605 [GMT -4:00]
.
AV: Norton Security *Enabled/Updated* {30744133-1E94-7B35-F4A3-82A5AEF1CBAA}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Security *Enabled/Updated* {8B15A0D7-38AE-74BB-CE13-B9D7D5768117}
FW: Norton Security *Enabled* {084FC016-54FB-7A6D-DFFC-2B9050228CD1}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\nvwmi64.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\nvwmi64.exe
C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\LSI SoftModem\agr64svc.exe
C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Corsair\Corsair Link\CorsairLINK_HardwareMonitor.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Program Files\FileOpen\Services\FileOpenManager64.exe
C:\Windows\system32\hasplms.exe
C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
C:\Windows\SysWOW64\lkcitdl.exe
C:\Windows\system32\hasplmv.exe
C:\Windows\SysWOW64\lkads.exe
C:\Windows\SysWOW64\lktsrv.exe
C:\Program Files\Autodesk\Inventor 2015\Moldflow\bin\mitsijm.exe
C:\Program Files\Autodesk\Inventor 2016\Moldflow\bin\mitsijm.exe
C:\Program Files\Autodesk\Inventor 2017\Moldflow\bin\mitsijm.exe
C:\Program Files\Autodesk\Inventor 2018\Moldflow\bin\mitsijm.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe
C:\Program Files\FileOpen\Services\FileOpenBroker64.exe
C:\Program Files\NVIDIA Corporation\nview\nViewMain64.exe
C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe
C:\Program Files (x86)\Norton Security\Engine\22.10.1.10\NS.exe
C:\Program Files\NVIDIA Corporation\nview\nViewMain.exe
C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe
C:\Users\Randy\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Users\Randy\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Users\Randy\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files (x86)\Timberline Office\Shared\Sage.CRE.PervasiveLicenseService.exe
C:\Program Files (x86)\Norton Security\Engine\22.10.1.10\NS.exe
C:\Program Files (x86)\Pervasive Software\PSQL\bin\notifyviewer.exe
C:\Program Files (x86)\Sage\SIM\Client\Sage.Sim.Client.WindowsService.exe
C:\Program Files\ShareSync\Tray\ShareSyncTray.exe
C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe
C:\Program Files\Autodesk\Autodesk SketchBook Pro 2015\SketchBookSnapshot.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\Pervasive Software\PSQL\bin\w3dbsmgr.exe
C:\Program Files (x86)\Sage\SIM\Client\SimNotify.exe
C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe
C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\AlarmClock.exe
C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe
C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe
C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRManager.exe
C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe
C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\acwebbrowser.exe
C:\Program Files\TrueKey\McTkSchedulerService.exe
C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe
C:\Program Files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe
C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe
C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
C:\Program Files (x86)\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe
C:\Program Files (x86)\Common Files\Sage\LS1\ServiceHost\Sage.LS1.ServiceHost.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\acwebbrowser.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\UI0Detect.exe
C:\Windows\system32\net.exe
C:\Windows\system32\UI0Detect.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\prevhost.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\net.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uProxyOverride = <local>
mWinlogon: Userinit = userinit.exe,
BHO: True Key Helper: {0F4B8786-5502-4803-8EBC-F652A1153BB6} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
BHO: Norton Identity Safety: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security\Engine32\22.10.1.10\coieplg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL
BHO: Microsoft OneDrive for Business Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine32\22.10.1.10\coieplg.dll
TB: True Key: {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll
uRun: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
uRun: [HP Officejet Pro 8600 (NET)] "C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe" -deviceID "CN2A9BWH2705KD:NW" -scfn "HP Officejet Pro 8600 (NET)" -AutoStart 1
uRun: [Akamai NetSession Interface] "C:\Users\Randy\AppData\Local\Akamai\netsession_win.exe"
uRun: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
uRun: [OneDrive] "C:\Users\Randy\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
mRun: [STCAgent] "C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe"
mRun: [ZyngaGamesAgent] "C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe"
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
mRun: [SimNotify.exe] C:\Program Files (x86)\Sage\SIM\Client\SimNotify.exe
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
mRun: [ADSK DLMSession] C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe
mRun: [Autodesk Desktop App] "C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray
StartupFolder: C:\Users\Randy\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\SENDTO~1.LNK - C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\RUNNOT~1.LNK - C:\Windows\Installer\{0A3238D7-AB32-1130-B717-F3E3F18B4A8C}\ico_notifyviewer.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SHARES~1.LNK - C:\Program Files\ShareSync\Tray\ShareSyncTray.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SKETCH~1.LNK - C:\Program Files\Autodesk\Autodesk SketchBook Pro 2015\SketchBookSnapshot.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\STARTP~1.LNK - C:\Windows\Installer\{0A3238D7-AB32-1130-B717-F3E3F18B4A8C}\ico_w3dbsmgr.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 10.100.100.200
TCP: Interfaces\{6026CFA6-A22A-429E-9EE0-E7E254AD1D9D} : DHCPNameServer = 10.100.100.200
TCP: Interfaces\{9B682F1B-8848-4BDD-8BFF-BE409C3EC4B6} : DHCPNameServer = 75.75.75.75 75.75.76.76
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
SSODL: WebCheck - <orphaned>
LSA: Notification Packages = scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter"
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
x64-BHO: True Key Helper: {0F4B8786-5502-4803-8EBC-F652A1153BB6} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-BHO: GBHO.BHO: {45d30484-7ded-43d9-957a-d2fd1f046511} -
x64-BHO: Norton Identity Safety: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security\Engine\22.10.1.10\coieplg.dll
x64-BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL
x64-BHO: Microsoft OneDrive for Business Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL
x64-TB: Smart Recovery 2: {1d09c093-f71e-43c3-b948-19316cbd695e} -
x64-TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine\22.10.1.10\coieplg.dll
x64-TB: True Key: {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [Logitech Download Assistant] C:\Windows\System32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
x64-Run: [nwiz] "C:\Program Files\NVIDIA Corporation\nview\nwiz.exe" /installquiet
x64-Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
x64-Run: [CnxtCoInstallerDefer] C:\Program Files\CONEXANT\PREINSTALL\SETUP582EFB190\SETUP64.EXE -REBOOTED_FROM_NO_ENUM_INSTALL_METHOD=1 -S
x64-Run: [FileOpenBroker] C:\Program Files\FileOpen\Services\FileOpenBroker64.exe
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
x64-Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - <orphaned>
x64-Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - <orphaned>
x64-Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {28B89EEF-1007-0000-7102-CF3F3A09B77D} - msiexec /fus {28B89EEF-1007-0000-7102-CF3F3A09B77D}
x64-mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.100\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
x64-mASetup: {AD99243B-F007-0000-B1CC-22A4DDD4B96F} - msiexec /fus {AD99243B-F007-0000-B1CC-22A4DDD4B96F}
x64-mASetup: {CD301C75-E007-0409-8A4F-E62AF995F11C} - msiexec /fus {CD301C75-E007-0409-8A4F-E62AF995F11C}
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\y6iuiy1g.default\
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Users\Randy\AppData\Roaming\Mozilla\plugins\npatgpc.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_185.dll
.
============= SERVICES / DRIVERS ===============
.
R0 nipbcfk;National Instruments Class Upper Filter Driver;C:\Windows\System32\drivers\nipbcfk.sys [2012-12-18 16984]
R0 SymEFASI;Symantec Extended File Attributes (SI);C:\Windows\System32\drivers\NSx64\160A010.00A\symefasi64.sys [2017-9-6 1868416]
R1 AppleCharger;AppleCharger;C:\Windows\System32\drivers\AppleCharger.sys [2014-6-17 21104]
R1 BHDrvx64;BHDrvx64;C:\Program Files (x86)\Norton Security\NortonData\22.7.0.76\Definitions\BASHDefs\20171004.001\BHDrvx64.sys [2017-10-5 1872032]
R1 ccSet_NS;NS Settings Manager;C:\Windows\System32\drivers\NSx64\160A010.00A\ccsetx64.sys [2017-9-6 187520]
R1 IDSVia64;IDSVia64;C:\Program Files (x86)\Norton Security\NortonData\22.7.0.76\Definitions\IPSDefs\20171004.001\IDSvia64.sys [2017-10-4 1056920]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NSx64\160A010.00A\ironx64.sys [2017-9-6 301288]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\NSx64\160A010.00A\symnets.sys [2017-9-6 566912]
R2 AdAppMgrSvc;Autodesk Desktop App Service;C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [2017-4-24 1353208]
R2 aksdf;aksdf;C:\Windows\System32\drivers\aksdf.sys [2016-11-16 390472]
R2 Autodesk Content Service;Autodesk Content Service;C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2014-2-7 31192]
R2 ClickToRunSvc;Microsoft Office Click-to-Run Service;C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2016-4-6 4122824]
R2 DES2 Service;DES2 Service for Energy Saving.;C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [2014-6-17 68136]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 FileOpenManager;FileOpen Manager;C:\Program Files\FileOpen\Services\FileOpenManager64.exe [2017-9-6 363176]
R2 hasplms;Sentinel LDK License Manager;C:\Windows\System32\hasplms.exe -run --> C:\Windows\System32\hasplms.exe -run [?]
R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [2014-5-21 49464]
R2 mitsijm2015;Autodesk Simulation Moldflow MITSI 2015 Job Manager;C:\Program Files\Autodesk\Inventor 2015\Moldflow\bin\mitsijm.exe [2013-10-11 968480]
R2 mitsijm2016;Autodesk Simulation Moldflow MITSI 2016 Job Manager;C:\Program Files\Autodesk\Inventor 2016\Moldflow\bin\mitsijm.exe [2014-9-30 968480]
R2 mitsijm2017;Autodesk Simulation Moldflow MITSI 2017 Job Manager;C:\Program Files\Autodesk\Inventor 2017\Moldflow\bin\mitsijm.exe [2015-8-4 967456]
R2 mitsijm2018;Autodesk Simulation Moldflow MITSI 2018 Job Manager;C:\Program Files\Autodesk\Inventor 2018\Moldflow\bin\mitsijm.exe [2016-9-25 967664]
R2 NIApplicationWebServer;NI Application Web Server;C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [2012-5-22 53960]
R2 niLXIDiscovery;NI LXI Discovery Service;C:\Program Files (x86)\ivi foundation\visa\WinNT\NIvisa\niLxiDiscovery.exe [2012-11-7 236768]
R2 nimDNSResponder;NI mDNS Responder Service;C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [2012-5-31 258776]
R2 NS;Norton Security;C:\Program Files (x86)\Norton Security\Engine\22.10.1.10\ns.exe [2017-9-6 326144]
R2 NVWMI;NVIDIA WMI Provider;C:\Windows\System32\nvwmi64.exe [2015-10-13 3079800]
R2 Sage.CRE.PervasiveLicenseService;Sage Pervasive License Service;C:\Program Files (x86)\Timberline Office\Shared\Sage.CRE.PervasiveLicenseService.exe [2013-7-8 34608]
R2 Sage.LS1.ServiceHost;Sage Service Host (v13.1);C:\Program Files (x86)\Common Files\Sage\LS1\ServiceHost\Sage.LS1.ServiceHost.exe [2013-7-8 108848]
R2 SageInstMgrClient;Sage Installation Manager Client;C:\Program Files (x86)\Sage\SIM\Client\Sage.Sim.Client.WindowsService.exe [2013-7-8 17712]
R2 SDLService;SDLService;C:\Program Files (x86)\Realtek\Smart Dual Lan\SDLService.exe [2014-6-17 95264]
R2 Smart TimeLock;Smart TimeLock Service;C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe [2014-6-17 114688]
R2 SplashtopRemoteService;Splashtop® Remote Service;C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe [2017-8-2 731648]
R2 SSUService;Splashtop Software Updater Service;C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe [2013-10-8 609056]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-10-13 417400]
R2 TrueKeyScheduler;Intel Security True Key Scheduler;C:\Program Files\TrueKey\McTkSchedulerService.exe [2016-10-14 16928]
R2 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-3-24 493384]
R2 WCUService_STC_IE;Splashtop Connect IE Software Updater Service;C:\Program Files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [2011-3-22 497480]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2017-7-11 158336]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\Windows\System32\drivers\LEqdUsb.sys [2015-6-17 87696]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\Windows\System32\drivers\LHidEqd.sys [2015-6-17 23184]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-11-18 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-11-18 181248]
R3 rtkio;rtkio;C:\Program Files (x86)\Realtek\Smart Dual Lan\rtkio.sys [2014-6-17 17392]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2014-6-17 412264]
S2 AcfXAudioService;AcfXAudioService;C:\Windows\System32\svchost.exe -k AcfXAudioService [2009-7-13 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-4-21 107656]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-4-21 128648]
S2 InstallerService;Service Installer TrueKey;C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe -originalversion 4.4.127.0 --> C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe -originalversion 4.4.127.0 [?]
S2 TrueKey;Intel Security True Key;C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [2017-7-12 1001920]
S3 acfva;acfva;C:\Windows\System32\drivers\ACFVA64.sys [2016-11-18 122624]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 dgcfltr;DGC Filter Driver;C:\Windows\System32\drivers\ACFDCP64.sys [2016-11-18 34944]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2011-4-12 71168]
S3 etdrv;etdrv;C:\Windows\etdrv.sys [2014-6-17 25640]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2014-6-19 1591264]
S3 GVTDrv64;GVTDrv64;C:\Windows\GVTDrv64.sys [2014-6-17 30528]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2017-9-12 116224]
S3 mi-raysat_3dsmax2015_64;mental ray Satellite for Autodesk 3ds Max Design 2015 64-bit;C:\Program Files\Autodesk\3ds Max Design 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe [2011-9-15 86016]
S3 mi-raysat_3dsmax2016_64;mental ray Satellite for Autodesk 3ds Max 2016 64-bit;C:\Program Files\Autodesk\3ds Max 2016\NVIDIA\Satellite\raysat_3dsmax2016_64server.exe [2011-9-15 86016]
S3 nipalfwedl;nipalfwedl;C:\Windows\System32\drivers\nipalfwedl.sys [2012-12-19 13624]
S3 nipalusbedl;nipalusbedl;C:\Windows\System32\drivers\nipalusbedl.sys [2012-12-19 13624]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 ser2at;ATEN USB to Serial port driver;C:\Windows\System32\drivers\ser2at64.sys [2009-10-15 96256]
S3 ser2attr;Tripp Lite USB to Serial port;C:\Windows\System32\drivers\ser2attr64.sys [2009-11-16 96256]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TrueKeyServiceHelper;TrueKeyServiceHelper;C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [2017-7-12 87760]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2014-6-18 1255736]
S4 NIApplicationWebServer64;NI Application Web Server (64-bit);C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [2012-5-22 76488]
.
=============== File Associations ===============
.
ShellExec: pi11.exe: Open="C:\Program Files (x86)\Microsoft Digital Image 2006\pi.exe" "%1"
.
=============== Created Last 30 ================
.
2017-10-05 23:16:32 -------- d--h--w- C:\OneDriveTemp
2017-10-03 18:45:45 -------- d-----w- C:\Windows\Microsoft Antimalware
2017-10-03 13:45:16 77440 ----a-w- C:\Windows\System32\drivers\mbae64.sys
2017-09-30 02:21:37 -------- d-----w- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-09-28 13:19:24 -------- d-----w- C:\Program Files\Malwarebytes
2017-09-28 13:15:52 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2017-09-28 13:09:51 112592 ----a-w- C:\Program Files (x86)\Mozilla Firefox\AccessibleHandler.dll
2017-09-28 13:09:49 55248 ----a-w- C:\Program Files (x86)\Mozilla Firefox\pingsender.exe
2017-09-13 00:25:59 880640 ----a-w- C:\Windows\System32\advapi32.dll
2017-09-08 10:54:34 448712 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE
2017-09-08 10:53:08 28360 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll
2017-09-08 10:46:08 207048 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
2017-09-06 18:05:14 566912 ----a-w- C:\Windows\System32\drivers\NSx64\160A010.00A\symnets.sys
2017-09-06 18:05:13 810136 ----a-w- C:\Windows\System32\drivers\NSx64\160A010.00A\srtsp64.sys
2017-09-06 18:05:13 49304 ----a-w- C:\Windows\System32\drivers\NSx64\160A010.00A\srtspx64.sys
2017-09-06 18:05:13 301288 ----a-w- C:\Windows\System32\drivers\NSx64\160A010.00A\ironx64.sys
2017-09-06 18:05:13 24608 ----a-w- C:\Windows\System32\drivers\NSx64\160A010.00A\symelam.sys
2017-09-06 18:05:13 187520 ----a-w- C:\Windows\System32\drivers\NSx64\160A010.00A\ccsetx64.sys
2017-09-06 18:05:13 1868416 ----a-w- C:\Windows\System32\drivers\NSx64\160A010.00A\symefasi64.sys
2017-09-06 18:04:36 -------- d-----w- C:\Windows\System32\drivers\NSx64\160A010.00A
2017-09-06 14:03:29 -------- d-----w- C:\Users\Randy\AppData\Roaming\FileOpen
2017-09-06 14:03:22 -------- d-----w- C:\ProgramData\FileOpen
2017-09-06 14:03:20 -------- d-----w- C:\Program Files\FileOpen
2017-09-06 01:03:02 17407232 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSO.DLL
.
==================== Find3M ====================
.
2017-10-05 23:12:50 25640 ----a-w- C:\Windows\gdrv.sys
2017-09-14 22:55:21 15728682 ----a-w- C:\Windows\System32\net1.exe
2017-08-16 15:29:31 806912 ----a-w- C:\Windows\System32\usp10.dll
2017-08-16 15:10:30 629760 ----a-w- C:\Windows\SysWow64\usp10.dll
2017-08-16 14:57:58 3224576 ----a-w- C:\Windows\System32\win32k.sys
2017-08-15 15:29:34 1867264 ----a-w- C:\Windows\System32\ExplorerFrame.dll
2017-08-15 15:10:42 1499648 ----a-w- C:\Windows\SysWow64\ExplorerFrame.dll
2017-08-14 17:35:10 303104 ----a-w- C:\Windows\SysWow64\mmcbase.dll
2017-08-14 17:35:10 2150912 ----a-w- C:\Windows\SysWow64\mmcndmgr.dll
2017-08-14 17:35:10 128512 ----a-w- C:\Windows\SysWow64\mmcshext.dll
2017-08-14 17:35:06 172544 ----a-w- C:\Windows\SysWow64\cic.dll
2017-08-14 17:35:03 355328 ----a-w- C:\Windows\System32\mmcbase.dll
2017-08-14 17:35:03 3203584 ----a-w- C:\Windows\System32\mmcndmgr.dll
2017-08-14 17:35:03 131072 ----a-w- C:\Windows\System32\mmcshext.dll
2017-08-14 17:34:59 211968 ----a-w- C:\Windows\System32\cic.dll
2017-08-13 21:37:59 2144256 ----a-w- C:\Windows\System32\mmc.exe
2017-08-13 21:30:41 1401344 ----a-w- C:\Windows\SysWow64\mmc.exe
2017-08-13 17:24:23 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2017-08-13 17:24:07 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2017-08-13 17:06:46 66560 ----a-w- C:\Windows\System32\iesetup.dll
2017-08-13 17:05:51 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2017-08-13 17:05:42 417792 ----a-w- C:\Windows\System32\html.iec
2017-08-13 17:05:20 576512 ----a-w- C:\Windows\System32\vbscript.dll
2017-08-13 17:05:13 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2017-08-13 16:51:21 5981696 ----a-w- C:\Windows\System32\jscript9.dll
2017-08-13 16:51:09 116224 ----a-w- C:\Windows\System32\ieetwcollector.exe
2017-08-13 16:51:07 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2017-08-13 16:50:39 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2017-08-13 16:46:10 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2017-08-13 16:41:42 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2017-08-13 16:30:33 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2017-08-13 16:29:56 499200 ----a-w- C:\Windows\SysWow64\vbscript.dll
2017-08-13 16:29:44 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2017-08-13 16:29:41 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2017-08-13 16:29:24 341504 ----a-w- C:\Windows\SysWow64\html.iec
2017-08-13 16:29:11 87552 ----a-w- C:\Windows\System32\tdc.ocx
2017-08-13 16:28:17 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2017-08-13 16:17:51 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2017-08-13 16:17:19 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2017-08-13 16:02:26 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2017-08-13 16:01:54 2134528 ----a-w- C:\Windows\System32\inetcpl.cpl
2017-08-13 16:01:46 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2017-08-13 16:01:15 73216 ----a-w- C:\Windows\SysWow64\tdc.ocx
2017-08-13 15:48:04 4547072 ----a-w- C:\Windows\SysWow64\jscript9.dll
2017-08-13 15:43:48 2058752 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2017-08-13 15:43:00 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2017-08-13 15:40:24 3241472 ----a-w- C:\Windows\System32\wininet.dll
2017-08-13 15:17:15 2767872 ----a-w- C:\Windows\SysWow64\wininet.dll
2017-08-11 06:42:11 631176 ----a-w- C:\Windows\System32\winresume.efi
2017-08-11 06:38:49 706792 ----a-w- C:\Windows\System32\winload.efi
2017-08-11 06:38:48 95464 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2017-08-11 06:38:48 5547752 ----a-w- C:\Windows\System32\ntoskrnl.exe
2017-08-11 06:38:48 154856 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2017-08-11 06:36:37 1732864 ----a-w- C:\Windows\System32\ntdll.dll
2017-08-11 06:34:58 60416 ----a-w- C:\Windows\System32\msobjs.dll
2017-08-11 06:24:04 4001000 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2017-08-11 06:24:04 3945704 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2017-08-11 06:21:22 1314112 ----a-w- C:\Windows\SysWow64\ntdll.dll
2017-08-11 06:20:50 71680 ----a-w- C:\Windows\System32\PrintBrmUi.exe
2017-08-11 06:20:32 48640 ----a-w- C:\Windows\System32\wpnpinst.exe
2017-08-11 06:20:29 61952 ----a-w- C:\Windows\System32\ntprint.exe
2017-08-11 06:12:12 25088 ----a-w- C:\Windows\System32\netbtugc.exe
2017-08-11 06:09:32 61952 ----a-w- C:\Windows\SysWow64\ntprint.exe
2017-08-11 06:07:27 148480 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2017-08-11 06:07:20 62464 ----a-w- C:\Windows\System32\drivers\appid.sys
2017-08-11 06:07:20 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2017-08-11 06:06:40 64000 ----a-w- C:\Windows\System32\auditpol.exe
2017-08-11 06:03:40 338432 ----a-w- C:\Windows\System32\conhost.exe
2017-08-11 06:03:37 26624 ----a-w- C:\Windows\SysWow64\netbtugc.exe
2017-08-11 06:02:48 296960 ----a-w- C:\Windows\System32\rstrui.exe
2017-08-11 06:01:43 7168 ----a-w- C:\Windows\SysWow64\comcat.dll
2017-08-11 06:00:09 159744 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2017-08-11 06:00:01 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2017-08-11 06:00:01 262656 ----a-w- C:\Windows\System32\drivers\netbt.sys
2017-08-11 05:59:55 460800 ----a-w- C:\Windows\System32\drivers\srv.sys
2017-08-11 05:59:48 405504 ----a-w- C:\Windows\System32\drivers\srv2.sys
2017-08-11 05:59:41 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2017-08-11 05:59:35 291328 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2017-08-11 05:59:32 129536 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2017-08-11 05:58:55 26112 ----a-w- C:\Windows\System32\drivers\nsiproxy.sys
2017-08-11 05:58:52 30720 ----a-w- C:\Windows\System32\lsass.exe
2017-08-11 05:58:48 112640 ----a-w- C:\Windows\System32\smss.exe
2017-08-11 05:56:33 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2017-08-11 05:56:31 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2017-08-11 05:56:31 2048 ----a-w- C:\Windows\SysWow64\user.exe
2017-08-11 05:56:31 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2017-08-11 05:55:46 36352 ----a-w- C:\Windows\SysWow64\cryptbase.dll
2017-08-11 05:55:39 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2017-08-11 05:55:39 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2017-08-11 05:55:39 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2017-08-11 05:55:39 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2017-07-29 14:56:30 117248 ----a-w- C:\Windows\System32\drivers\tdx.sys
2017-07-26 16:21:17 102568 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2017-07-21 14:26:31 282624 ----a-w- C:\Windows\SysWow64\mstext40.dll
2017-07-21 14:26:30 518144 ----a-w- C:\Windows\SysWow64\msjetoledb40.dll
2017-07-21 14:26:30 409600 ----a-w- C:\Windows\SysWow64\msexch40.dll
2017-07-21 14:26:30 290816 ----a-w- C:\Windows\SysWow64\msjtes40.dll
2017-07-20 03:21:02 440792 ----a-w- C:\Windows\System32\AcSignOpt.exe
2017-07-20 03:21:00 41944 ----a-w- C:\Windows\System32\AcSignExt.dll
2017-07-14 15:29:15 486400 ----a-w- C:\Windows\System32\wer.dll
.
============= FINISH: 19:44:11.10 ===============

Attached Files
File Type: txt attach.txt (35.0 KB)
File Type: txt sfcdetails.txt (61.1 KB)

Can't Get Rid of VidSquare Malware

$
0
0
I have run scans on both Malwarebytes and Avast several times trying to find it, but to no success. I have even tried looking for the program manually and reinstalling my browser but I've yet to find it. Please help, and thanks in advance.

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: BrowserJavaVersion: 11.144.2
Run by PC at 15:55:08 on 2017-10-08
Microsoft Windows 10 Pro 10.0.15063.0.1252.1.1033.18.12250.8756 [GMT -4:00]
.
AV: Avast Antivirus *Enabled/Updated* {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Avast Antivirus *Enabled/Updated* {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
.
============== Running Processes ===============
.
C:\WINDOWS\TEMP\MSUPOCISRV.EXE
c:\windows\system32\svchost.exe -k dcomlaunch -s PlugPlay
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\fontdrvhost.exe
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k dcomlaunch -s LSM
c:\windows\system32\svchost.exe -k networkservice -s TermService
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NcbService
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s hidserv
c:\windows\system32\svchost.exe -k netsvcs -s ProfSvc
c:\windows\system32\svchost.exe -k netsvcs -s Schedule
c:\windows\system32\svchost.exe -k netsvcs -s UserManager
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s TimeBrokerSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s EventLog
c:\windows\system32\svchost.exe -k localservice -s nsi
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s Dhcp
c:\windows\system32\svchost.exe -k networkservice -s NlaSvc
c:\windows\system32\svchost.exe -k localservice -s netprofm
C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s CscService
c:\windows\system32\svchost.exe -k localservice -s EventSystem
c:\windows\system32\svchost.exe -k netsvcs -s Themes
c:\windows\system32\svchost.exe -k netsvcs -s SENS
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -s FontCache
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s UmRdpService
c:\windows\system32\svchost.exe -k netsvcs -s CertPropSvc
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe -k networkservice -s LanmanWorkstation
c:\windows\system32\svchost.exe -k netsvcs -s SessionEnv
C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s fhsvc
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k networkservice -s Dnscache
c:\windows\system32\svchost.exe -k localservicenonetwork
c:\windows\system32\svchost.exe -k appmodel -s StateRepository
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe -k localservice -s WinHttpAutoProxySvc
c:\windows\system32\svchost.exe -k netsvcs -s Winmgmt
c:\windows\system32\svchost.exe -k netsvcs -s iphlpsvc
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe -k netsvcs -s ShellHWDetection
c:\program files\avast software\avast\avastsvc.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\WINDOWS\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k iissvcs
c:\windows\system32\svchost.exe -k apphost -s AppHostSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DeviceAssociationService
C:\WINDOWS\System32\svchost.exe -k utcsvc
c:\windows\system32\svchost.exe -k localservicenonetwork -s DPS
c:\windows\system32\svchost.exe -k netsvcs -s WpnService
c:\windows\system32\svchost.exe -k appmodel -s tiledatamodelsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SysMain
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s PcaSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TrkWks
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
c:\windows\system32\svchost.exe -k localservice -s WdiServiceHost
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\dashost.exe
c:\windows\system32\svchost.exe -k netsvcs -s LanmanServer
c:\windows\system32\svchost.exe -k netsvcs -s Browser
c:\windows\system32\svchost.exe -k netsvcs -s Appinfo
c:\windows\system32\svchost.exe -k networkservice -s CryptSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s Netman
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s wscsvc
C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
c:\windows\system32\svchost.exe -k netsvcs -s TokenBroker
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
c:\windows\system32\taskhostw.exe
c:\windows\system32\svchost.exe -k localservice -s CDPSvc
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files (x86)\Java\jre1.8.0_101\bin\keytool.exe
C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\SearchIndexer.exe
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s SSDPSRV
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s StorSvc
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\WINDOWS\system32\svchost.exe -k SDRSVC
c:\windows\system32\svchost.exe -k localservice -s LicenseManager
c:\windows\system32\svchost.exe -k netsvcs -s lfsvc
C:\Program Files (x86)\Origin\OriginWebHelperService.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -s lmhosts
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DsSvc
C:\WINDOWS\system32\fontdrvhost.exe
C:\WINDOWS\system32\dwm.exe
C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
c:\windows\system32\sihost.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
c:\windows\system32\taskhostw.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
C:\Program Files\Tablet\Wacom\WacomHost.exe
C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\WINDOWS\system32\AUDIODG.EXE
C:\Program Files\AVAST Software\Avast\AvastUI.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -s WdiSystemHost
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=N360&pvid=21.6.0.32
BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - LocalServer32 - <no file>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll
uRun: [OneDrive] "C:\Users\PC\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
uRun: [KOab1err] "C:\Program Files (x86)\KODAK VERITE\ErrorApp\KOab1err.exe"
uRun: [KOBAAmon] "C:\Program Files (x86)\KODAK VERITE 50 Series\KOBAAmon.exe"
uRun: [Discord] C:\Users\PC\AppData\Local\Discord\app-0.0.298\Discord.exe
uRun: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [GIZMO2] "C:\Program Files (x86)\GIZMO2\GIZMO.exe" -BootProcess
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [KOBAAmon] "C:\Program Files (x86)\KODAK VERITE 50 Series\KOBAAmon.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mPolicies-System: DSCAutomationHostEnabled = dword:2
IE: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
IE: En&queue current page with BID - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidqueue.htm
IE: Enqueue link tar&get with BID - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlinkqueue.htm
IE: Open &link target with BID - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlink.htm
IE: Open current page with BI&D - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebid.htm
IE: Open current page with BID Link Explorer - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlinkexplorer.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.5.1.0.cab
TCP: NameServer = 8.8.8.8
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{21be2b2b-2417-4d5c-becb-d7ca9a13e336} : NameServer = 8.8.8.8
TCP: Interfaces\{21be2b2b-2417-4d5c-becb-d7ca9a13e336} : DHCPNameServer = 8.8.8.8
TCP: Interfaces\{4101755d-c0dc-4d8b-ac3a-ae5e589f822d} : NameServer = 8.8.8.8
TCP: Interfaces\{4819076B-7BEB-4803-AB95-8B7116383033} : NameServer = 8.8.8.8
TCP: Interfaces\{4819076B-7BEB-4803-AB95-8B7116383033} : DHCPNameServer =
TCP: Interfaces\{517b287c-54bb-4846-a6db-8dec1cf653c4} : NameServer = 8.8.8.8
TCP: Interfaces\{517b287c-54bb-4846-a6db-8dec1cf653c4} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{53063399-7ddd-4b00-bf0c-98e30266c43c} : NameServer = 8.8.8.8
TCP: Interfaces\{94c081dc-a2b9-4449-b3e0-20073725ba4f} : NameServer = 8.8.8.8
TCP: Interfaces\{adb17148-d708-48f9-a13a-90da034e3ded} : NameServer = 8.8.8.8
TCP: Interfaces\{adb17148-d708-48f9-a13a-90da034e3ded} : DHCPNameServer = 8.8.8.8
TCP: Interfaces\{F238FF27-86C3-458D-AA4F-6A9425CDA365} : NameServer = 8.8.8.8
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned>
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
x64-BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - <orphaned>
x64-BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - <orphaned>
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [NvBackend] "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
x64-Run: [KOBAAmon] "C:\Program Files (x86)\KODAK VERITE 50 Series\KOBAAmon.exe"
x64-Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
x64-Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
x64-mPolicies-System: DSCAutomationHostEnabled = dword:2
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned>
x64-Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
x64-mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.100\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
x64-CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\asg2687h.default\
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_144\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll
FF - plugin: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll
FF - plugin: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypchub.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll
FF - plugin: C:\Users\PC\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll
FF - plugin: C:\Users\PC\AppData\LocalLow\Square Enix\nprun3d.dll
FF - plugin: C:\Users\PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll
.
============= SERVICES / DRIVERS ===============
.
R?2 CDPSvc;Connected Devices Platform Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
R?3 aswbIDSAgent;aswbIDSAgent;C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-9-17 7452288]
R0 intelpep;Intel(R) Power Engine Plug-in Driver;C:\WINDOWS\System32\drivers\intelpep.sys [2017-3-18 74840]
R0 iorate;Disk I/O Rate Filter Driver;C:\WINDOWS\System32\drivers\iorate.sys [2017-3-18 49568]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\WINDOWS\System32\drivers\iusb3hcs.sys [2012-5-26 16152]
R0 PxHlpa64;PxHlpa64;C:\WINDOWS\System32\drivers\PxHlpa64.sys [2014-1-6 56336]
R0 volume;Volume driver;C:\WINDOWS\System32\drivers\volume.sys [2017-3-18 16288]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [2017-3-18 70232]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [2017-3-18 18520]
R0 Wof;Windows Overlay File System Filter Driver;C:\WINDOWS\System32\drivers\wof.sys [2017-3-18 208288]
R1 ahcache;Application Compatibility Cache;C:\WINDOWS\System32\drivers\ahcache.sys [2017-3-18 239616]
R1 aswbidsdriver;aswbidsdriver;C:\WINDOWS\System32\drivers\aswbidsdrivera.sys [2017-9-17 321032]
R1 aswSnx;aswSnx;C:\WINDOWS\System32\drivers\aswSnx.sys [2017-9-17 1020536]
R1 aswSP;aswSP;C:\WINDOWS\System32\drivers\aswSP.sys [2017-9-17 587168]
R1 FileCrypt;FileCrypt;C:\WINDOWS\System32\drivers\filecrypt.sys [2017-3-18 54272]
R1 GpuEnergyDrv;GPU Energy Driver;C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2017-3-18 8192]
R1 SymEFASI;Symantec Extended File Attributes (SI);C:\WINDOWS\System32\drivers\N360x64\1605020.00F\SymEFASI64.sys [2015-8-6 1620720]
R1 WindroyeBoxDrv;WindroyeBox Support Driver;C:\Program Files\WindroyeBox\WindroyeBoxDrv.sys [2015-3-3 252672]
R2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [2012-9-23 171600]
R2 aswMonFlt;aswMonFlt;C:\WINDOWS\System32\drivers\aswMonFlt.sys [2017-9-17 147776]
R2 aswStm;aswStm;C:\WINDOWS\System32\drivers\aswStm.sys [2017-9-17 201352]
R2 avast! Antivirus;Avast Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-9-17 275208]
R2 CDPUserSvc_1245b07;Connected Devices Platform User Service_1245b07;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R2 clreg;Virtual Registry for Containers;C:\WINDOWS\System32\drivers\registry.sys [2017-3-18 14336]
R2 CoreMessagingRegistrar;CoreMessaging;C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork [2017-3-18 47664]
R2 cpuz135;cpuz135;C:\WINDOWS\System32\drivers\cpuz135_x64.sys [2012-6-4 23816]
R2 DiagTrack;Connected User Experiences and Telemetry;C:\WINDOWS\System32\svchost.exe -k utcsvc [2017-3-18 47664]
R2 DusmSvc;Data Usage;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2011-12-8 607456]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-5-26 161560]
R2 MBAMService;Malwarebytes Service;C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [2017-9-26 6058960]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2017-6-20 462968]
R2 NvNetworkService;NVIDIA Network Service;C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2015-12-25 1879488]
R2 OneSyncSvc_1245b07;Sync Host_1245b07;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R2 Origin Web Helper Service;Origin Web Helper Service;C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2017-7-26 3000168]
R2 SecurityHealthService;Windows Defender Security Center Service;C:\WINDOWS\System32\SecurityHealthService.exe [2017-7-11 336320]
R2 storqosflt;Storage QoS Filter Driver;C:\WINDOWS\System32\drivers\storqosflt.sys [2017-3-18 79872]
R2 tiledatamodelsvc;Tile Data model server;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
R2 UserManager;User Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R2 wcifs;Windows Container Isolation;C:\WINDOWS\System32\drivers\wcifs.sys [2017-7-11 142752]
R2 WpnService;Windows Push Notifications System Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R2 WpnUserService_1245b07;Windows Push Notifications User Service_1245b07;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R2 WTabletServicePro;Wacom Professional Service;C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [2013-12-14 598808]
R3 DsSvc;Data Sharing Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
R3 IntcDAud;Intel(R) Display Audio;C:\WINDOWS\System32\drivers\IntcDAud.sys [2012-5-26 331264]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;C:\WINDOWS\System32\drivers\L1C63x64.sys [2017-3-18 121344]
R3 lfsvc;Geolocation Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R3 LicenseManager;Windows License Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
R3 ManyCam;ManyCam Virtual Webcam;C:\WINDOWS\System32\drivers\mcvidrv.sys [2013-11-26 42016]
R3 mcaudrv_simple;ManyCam Virtual Microphone;C:\WINDOWS\System32\drivers\mcaudrv_x64.sys [2013-12-6 35232]
R3 NcbService;Network Connection Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [2017-3-18 20992]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\WINDOWS\System32\drivers\nvvad64v.sys [2016-8-30 56384]
R3 PimIndexMaintenanceSvc_1245b07;Contact Data_1245b07;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R3 StateRepository;State Repository Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
R3 TimeBrokerSvc;Time Broker;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
R3 TokenBroker;TokenBroker;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R3 UnistoreSvc_1245b07;User Data Storage_1245b07;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R3 UserDataSvc_1245b07;User Data Access_1245b07;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\WINDOWS\System32\drivers\viahduaa.sys [2015-6-22 701136]
R3 wacomrouterfilter;Wacom Router Filter Driver;C:\WINDOWS\System32\drivers\wacomrouterfilter.sys [2013-12-14 15344]
R3 WSDScan;WSD Scan Support;C:\WINDOWS\System32\drivers\WSDScan.sys [2017-3-18 24576]
R4 MBAMSwissArmy;MBAMSwissArmy;C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [2017-9-26 253888]
S2 Apple Mobile Device Service;Apple Mobile Device Service;"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" --> C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [?]
S2 CldFlt;Windows Cloud Files Filter Driver;C:\WINDOWS\System32\drivers\cldflt.sys [2017-3-18 12288]
S2 DoSvc;Delivery Optimization;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S2 MapsBroker;Downloaded Maps Manager;C:\WINDOWS\System32\svchost.exe -k NetworkService [2017-3-18 47664]
S2 NvStreamSvc;NVIDIA Streamer Service;C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2015-12-25 2521024]
S2 RalinkRegistryWriter;Ralink Registry Writer;"C:\Program Files (x86)\Ralink\Common\RaRegistry.exe" --> C:\Program Files (x86)\Ralink\Common\RaRegistry.exe [?]
S2 RalinkRegistryWriter64;Ralink Registry Writer 64;"C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe" --> C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe [?]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-7-18 317408]
S2 UNS;Intel(R) Management and Security Application User Notification Service;"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" --> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [?]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;C:\WINDOWS\System32\viakaraokesrv.exe --> C:\WINDOWS\System32\viakaraokesrv.exe [?]
S3 AcpiDev;ACPI Devices driver;C:\WINDOWS\System32\drivers\AcpiDev.sys [2017-3-18 20480]
S3 ADP80XX;ADP80XX;C:\WINDOWS\System32\drivers\adp80xx.sys [2017-3-18 1135512]
S3 AJRouter;AllJoyn Router Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 applockerfltr;Smartlocker Filter Driver;C:\WINDOWS\System32\drivers\applockerfltr.sys [2017-3-18 17920]
S3 AppReadiness;App Readiness;C:\WINDOWS\System32\svchost.exe -k AppReadiness [2017-3-18 47664]
S3 AppvStrm;AppvStrm;C:\WINDOWS\System32\drivers\AppVStrm.sys [2017-3-18 127904]
S3 AppvVemgr;AppvVemgr;C:\WINDOWS\System32\drivers\AppvVemgr.sys [2017-3-18 161696]
S3 AppvVfs;AppvVfs;C:\WINDOWS\System32\drivers\AppvVfs.sys [2017-3-18 143776]
S3 AppXSvc;AppX Deployment Service (AppXSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2017-3-18 47664]
S3 aswHwid;aswHwid;C:\WINDOWS\System32\drivers\aswHwid.sys [2017-9-17 47008]
S3 BazisVirtualCDBus;WinCDEmu Virtual Bus Driver;C:\WINDOWS\System32\drivers\BazisVirtualCDBus.sys [2011-6-4 198480]
S3 bcmfn2;bcmfn2 Service;C:\WINDOWS\System32\drivers\bcmfn2.sys [2017-3-18 9728]
S3 BEService;BattlEye Service;C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2015-2-1 814464]
S3 BthHFSrv;Bluetooth Handsfree Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation [2017-3-18 47664]
S3 buttonconverter;Service for Portable Device Control devices;C:\WINDOWS\System32\drivers\buttonconverter.sys [2017-9-13 39424]
S3 CAD;Charge Arbitration Driver;C:\WINDOWS\System32\drivers\CAD.sys [2017-3-18 53664]
S3 CapImg;HID driver for CapImg touch screen;C:\WINDOWS\System32\drivers\capimg.sys [2017-3-18 122880]
S3 cht4iscsi;cht4iscsi;C:\WINDOWS\System32\drivers\cht4sx64.sys [2017-3-18 347032]
S3 cht4vbd;Chelsio Virtual Bus Driver;C:\WINDOWS\System32\drivers\cht4vx64.sys [2017-3-18 2104224]
S3 ClipSVC;Client License Service (ClipSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2017-3-18 47664]
S3 DevicesFlowUserSvc_1245b07;DevicesFlow_1245b07;C:\WINDOWS\System32\svchost.exe -k DevicesFlow [2017-3-18 47664]
S3 DevQueryBroker;DevQuery Background Discovery Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\WINDOWS\System32\drivers\ssudbus.sys [2017-5-18 131984]
S3 diagnosticshub.standardcollector.service;Microsoft (R) Diagnostics Hub Standard Collector Service;C:\WINDOWS\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2017-3-18 86528]
S3 DmEnrollmentSvc;Device Management Enrollment Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 dmwappushservice;dmwappushsvc;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 EasyAntiCheat;EasyAntiCheat;C:\WINDOWS\System32\EasyAntiCheat.exe --> C:\WINDOWS\System32\EasyAntiCheat.exe [?]
S3 embeddedmode;Embedded Mode;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 EntAppSvc;Enterprise App Management Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
S3 FrameServer;Windows Camera Frame Server;C:\WINDOWS\System32\svchost.exe -k Camera [2017-3-18 47664]
S3 genericusbfn;Generic USB Function Class;C:\WINDOWS\System32\drivers\genericusbfn.sys [2017-3-18 21504]
S3 hidinterrupt;Common Driver for HID Buttons implemented with interrupts;C:\WINDOWS\System32\drivers\hidinterrupt.sys [2017-3-18 51104]
S3 HvHost;HV Host Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 iagpio;Intel Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iagpio.sys [2017-3-18 33280]
S3 iai2c;Intel(R) Serial IO I2C Host Controller;C:\WINDOWS\System32\drivers\iai2c.sys [2017-3-18 81408]
S3 iaLPSS2i_GPIO2;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2017-3-18 70656]
S3 iaLPSS2i_GPIO2_BXT_P;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2017-3-18 85504]
S3 iaLPSS2i_I2C;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2017-3-18 165376]
S3 iaLPSS2i_I2C_BXT_P;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2017-3-18 168448]
S3 iaLPSSi_GPIO;Intel(R) Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [2017-3-18 38128]
S3 iaLPSSi_I2C;Intel(R) Serial IO I2C Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [2017-3-18 113152]
S3 iaStorAV;Intel(R) SATA RAID Controller Windows;C:\WINDOWS\System32\drivers\iaStorAV.sys [2017-3-18 673184]
S3 ibbus;Mellanox InfiniBand Bus/AL (Filter Driver);C:\WINDOWS\System32\drivers\ibbus.sys [2017-3-18 526240]
S3 icssvc;Windows Mobile Hotspot Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 IndirectKmd;Indirect Displays Kernel-Mode Driver;C:\WINDOWS\System32\drivers\IndirectKmd.sys [2017-3-18 36864]
S3 IpxlatCfgSvc;IP Translation Configuration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 LSI_SAS2i;LSI_SAS2i;C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2017-3-18 123808]
S3 LSI_SAS3i;LSI_SAS3i;C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2017-3-18 103328]
S3 mausbhost;MA-USB Host Controller Driver;C:\WINDOWS\System32\drivers\mausbhost.sys [2017-3-18 405408]
S3 mausbip;MA-USB IP Filter Driver;C:\WINDOWS\System32\drivers\mausbip.sys [2017-3-18 51104]
S3 MBAMWebProtection;MBAMWebProtection;C:\WINDOWS\System32\drivers\mwac.sys [2017-9-26 94144]
S3 megasas2i;megasas2i;C:\WINDOWS\System32\drivers\MegaSas2i.sys [2017-3-18 64416]
S3 MessagingService_1245b07;MessagingService_1245b07;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
S3 mlx4_bus;Mellanox ConnectX Bus Enumerator;C:\WINDOWS\System32\drivers\mlx4_bus.sys [2017-3-18 842656]
S3 MsSecFlt;Microsoft Security Events Component Minifilter;C:\WINDOWS\System32\drivers\mssecflt.sys [2017-3-18 230816]
S3 NaturalAuthentication;Natural Authentication;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 ndfltr;NetworkDirect Service;C:\WINDOWS\System32\drivers\ndfltr.sys [2017-3-18 108960]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library;C:\WINDOWS\System32\drivers\NetAdapterCx.sys [2017-3-18 122368]
S3 NetSetupSvc;Network Setup Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 netvsc;netvsc;C:\WINDOWS\System32\drivers\netvsc.sys [2017-6-20 118784]
S3 NgcCtnrSvc;Microsoft Passport Container;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 NgcSvc;Microsoft Passport;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 nvdimmn;Microsoft NVDIMM-N device driver;C:\WINDOWS\System32\drivers\nvdimmn.sys [2017-3-18 80896]
S3 NvStreamKms;NvStreamKms;C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2015-12-25 26560]
S3 Origin Client Service;Origin Client Service;C:\Program Files (x86)\Origin\OriginClientService.exe [2016-12-26 2120032]
S3 percsas2i;percsas2i;C:\WINDOWS\System32\drivers\percsas2i.sys [2017-3-18 58784]
S3 percsas3i;percsas3i;C:\WINDOWS\System32\drivers\percsas3i.sys [2017-3-18 61848]
S3 PhoneSvc;Phone Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 ReFS;ReFS;C:\WINDOWS\System32\drivers\refs.sys [2017-3-18 1735584]
S3 ReFSv1;ReFSv1;C:\WINDOWS\System32\drivers\refsv1.sys [2017-3-18 936864]
S3 RetailDemo;Retail Demo Service;C:\WINDOWS\System32\svchost.exe -k rdxgroup [2017-3-18 47664]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 scmbus;Microsoft Storage Class Memory Bus Driver;C:\WINDOWS\System32\drivers\scmbus.sys [2017-3-18 91040]
S3 SDFRd;SDF Reflector;C:\WINDOWS\System32\drivers\SDFRd.sys [2017-3-18 31128]
S3 SEMgrSvc;Payments and NFC/SE Manager;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 Sense;Windows Defender Advanced Threat Protection Service;C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2017-3-18 3913064]
S3 SensorDataService;Sensor Data Service;C:\WINDOWS\System32\SensorDataService.exe [2017-3-18 1284608]
S3 SensorService;Sensor Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 SerCx2;Serial UART Support Library;C:\WINDOWS\System32\drivers\SerCx2.sys [2017-3-18 154016]
S3 smphost;Microsoft Storage Spaces SMP;C:\WINDOWS\System32\svchost.exe -k smphost [2017-3-18 47664]
S3 SmsRouter;Microsoft Windows SMS Router Service.;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 SpatialGraphFilter;Holographic Spatial Graph Filter;C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [2017-3-18 40352]
S3 spectrum;Windows Perception Service;C:\WINDOWS\System32\Spectrum.exe [2017-3-18 891904]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\WINDOWS\System32\drivers\ssudmdm.sys [2017-5-18 166288]
S3 stornvme;Microsoft Standard NVM Express Driver;C:\WINDOWS\System32\drivers\stornvme.sys [2017-3-18 95648]
S3 storufs;Microsoft Universal Flash Storage (UFS) Driver;C:\WINDOWS\System32\drivers\storufs.sys [2017-3-18 36760]
S3 SWDUMon;SWDUMon;C:\WINDOWS\System32\drivers\SWDUMon.sys [2012-6-18 15672]
S3 TieringEngineService;Storage Tiers Management;C:\WINDOWS\System32\TieringEngineService.exe [2017-3-18 302592]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmCx.sys [2017-9-13 104960]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmTcpciCx.sys [2017-3-18 179200]
S3 UcmUcsi;USB Connector Manager UCSI Client;C:\WINDOWS\System32\drivers\UcmUcsi.sys [2017-8-10 51712]
S3 UdeCx;USB Device Emulation Support Library;C:\WINDOWS\System32\drivers\Udecx.sys [2017-3-18 45568]
S3 UEFI;Microsoft UEFI Driver;C:\WINDOWS\System32\drivers\uefi.sys [2017-3-18 29600]
S3 Ufx01000;USB Function Class Extension;C:\WINDOWS\System32\drivers\ufx01000.sys [2017-3-18 263584]
S3 UfxChipidea;USB Chipidea Controller;C:\WINDOWS\System32\drivers\UfxChipidea.sys [2017-3-18 98712]
S3 ufxsynopsys;USB Synopsys Controller;C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2017-3-18 138656]
S3 UrsChipidea;Chipidea USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urschipidea.sys [2017-3-18 29600]
S3 UrsCx01000;USB Role-Switch Support Library;C:\WINDOWS\System32\drivers\urscx01000.sys [2017-3-18 59288]
S3 UrsSynopsys;Synopsys USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urssynopsys.sys [2017-3-18 28064]
S3 UsoSvc;Update Orchestrator Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 vhf;Virtual HID Framework (VHF) Driver;C:\WINDOWS\System32\drivers\vhf.sys [2017-3-18 35328]
S3 vmgid;Microsoft Hyper-V Guest Infrastructure Driver;C:\WINDOWS\System32\drivers\vmgid.sys [2017-3-18 10240]
S3 vmicguestinterface;Hyper-V Guest Service Interface;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 vmicvmsession;Hyper-V PowerShell Direct Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 VSStandardCollectorService140;Visual Studio Standard Collector Service;C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [2016-6-20 108776]
S3 w3logsvc;W3C Logging Service;C:\WINDOWS\System32\svchost.exe -k apphost [2017-3-18 47664]
S3 WalletService;WalletService;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
S3 wcnfs;Windows Container Name Virtualization;C:\WINDOWS\System32\drivers\wcnfs.sys [2017-3-18 72192]
S3 wdiwifi;WDI Driver Framework;C:\WINDOWS\System32\drivers\WdiWiFi.sys [2017-7-11 757248]
S3 WdNisDrv;Windows Defender Antivirus Network Inspection System Driver;C:\WINDOWS\System32\drivers\WdNisDrv.sys [2017-3-18 121248]
S3 WdNisSvc;Windows Defender Antivirus Network Inspection Service;C:\Program Files\Windows Defender\NisSrv.exe [2017-3-18 342264]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;C:\WINDOWS\System32\svchost.exe -k WepHostSvcGroup [2017-3-18 47664]
S3 WFDSConMgrSvc;Wi-Fi Direct Services Connection Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 WinMad;WinMad Service;C:\WINDOWS\System32\drivers\winmad.sys [2017-3-18 32160]
S3 WinNat;Windows NAT Driver;C:\WINDOWS\System32\drivers\winnat.sys [2017-3-18 217088]
S3 WinVerbs;WinVerbs Service;C:\WINDOWS\System32\drivers\winverbs.sys [2017-3-18 64920]
S3 wisvc;Windows Insider Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 wlpasvc;LPA Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 workfolderssvc;Work Folders;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\drivers\WUDFRd.sys [2017-3-18 220672]
S3 xbgm;Xbox Game Monitoring;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 XblAuthManager;Xbox Live Auth Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 XblGameSave;Xbox Live Game Save;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 xboxgip;Xbox Game Input Protocol Driver;C:\WINDOWS\System32\drivers\xboxgip.sys [2017-6-20 277504]
S3 XboxGipSvc;Xbox Accessory Management Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 XboxNetApiSvc;Xbox Live Networking Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 xinputhid;XINPUT HID Filter Driver;C:\WINDOWS\System32\drivers\xinputhid.sys [2017-3-18 46592]
S4 AppVClient;Microsoft App-V Client;C:\WINDOWS\System32\AppVClient.exe [2017-9-13 849824]
S4 shpamsvc;Shared PC Account Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S4 tzautoupdate;Auto Time Zone Updater;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S4 UevAgentDriver;UevAgentDriver;C:\WINDOWS\System32\drivers\UevAgentDriver.sys [2017-3-18 40344]
S4 UevAgentService;User Experience Virtualization Service;C:\WINDOWS\System32\AgentService.exe [2017-3-18 1200640]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\WINDOWS\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2017-10-08 18:44:59 61304 ----a-w- C:\WINDOWS\System32\drivers\lpsport.sys.150748829925002
2017-10-02 01:31:00 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe
2017-09-27 01:25:05 192960 ----a-w- C:\WINDOWS\System32\drivers\MBAMChameleon.sys
2017-09-27 01:24:57 94144 ----a-w- C:\WINDOWS\System32\drivers\mwac.sys
2017-09-27 01:24:54 45472 ----a-w- C:\WINDOWS\System32\drivers\mbam.sys
2017-09-27 01:24:51 253888 ----a-w- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
2017-09-27 01:24:46 77440 ----a-w- C:\WINDOWS\System32\drivers\mbae64.sys
2017-09-27 01:24:43 -------- d-----w- C:\ProgramData\Malwarebytes
2017-09-22 19:57:08 -------- d-----w- C:\Program Files\UNP
2017-09-22 19:55:30 -------- d-----w- C:\Users\PC\AppData\Local\CEF
2017-09-22 02:03:12 -------- d-----w- C:\Users\PC\AppData\Local\PeerDistRepub
2017-09-22 00:42:37 -------- d-----w- C:\Users\PC\AppData\Local\Google
2017-09-19 00:57:41 -------- d-----w- C:\Program Files\Malwarebytes
2017-09-17 20:14:07 -------- d---a-w- C:\Program Files\iTunes
2017-09-17 19:40:40 -------- d--h--w- C:\$AV_ASW
2017-09-17 19:35:09 -------- d-----r- C:\Program Files (x86)\Skype
2017-09-17 18:54:46 81696 ----a-w- C:\WINDOWS\System32\drivers\msidntfs.sys
2017-09-17 18:11:10 -------- d-----w- C:\Users\PC\AppData\Roaming\AVAST Software
2017-09-17 18:07:45 -------- d-----w- C:\Program Files\AVAST Software
2017-09-17 18:06:59 -------- d-----w- C:\ProgramData\AVAST Software
2017-09-17 17:31:51 -------- d-----w- C:\WINDOWS\pss
2017-09-17 17:06:58 -------- d-----w- C:\Users\PC\AppData\Local\uniwtca
2017-09-17 16:58:42 -------- d-----w- C:\WINDOWS\SysWow64\wudiokv
2017-09-17 16:58:42 -------- d-----w- C:\WINDOWS\System32\wudiokv
2017-09-17 04:52:28 12288 ----a-w- C:\WINDOWS\truncates.exe
2017-09-17 01:02:46 44928 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6501094F-2E5D-40BF-8675-B1E561684ABB}\MpKsla92cfe82.sys
2017-09-17 01:02:39 1078240 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{23FBE1C1-A180-49BA-B445-C4735D6C993C}\gapaengine.dll
2017-09-17 01:02:22 13482976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6501094F-2E5D-40BF-8675-B1E561684ABB}\mpengine.dll
2017-09-16 00:40:38 -------- d-----w- C:\ProgramData\KingsIsle Entertainment
2017-09-15 22:40:14 13482976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2017-09-13 13:17:59 849824 ----a-w- C:\WINDOWS\System32\AppVClient.exe
2017-09-13 00:38:34 -------- d-----w- C:\WINDOWS\PCHEALTH
.
==================== Find3M ====================
.
2017-10-08 18:42:13 363440 ----a-w- C:\WINDOWS\System32\drivers\aswVmm.sys
2017-10-08 18:42:13 201352 ----a-w- C:\WINDOWS\System32\drivers\aswStm.sys
2017-10-08 18:42:12 84416 ----a-w- C:\WINDOWS\System32\drivers\aswRvrt.sys
2017-10-08 18:42:12 47008 ----a-w- C:\WINDOWS\System32\drivers\aswHwid.sys
2017-10-08 18:42:12 147776 ----a-w- C:\WINDOWS\System32\drivers\aswMonFlt.sys
2017-10-08 18:42:12 110376 ----a-w- C:\WINDOWS\System32\drivers\aswRdr2.sys
2017-10-08 18:41:56 1020536 ----a-w- C:\WINDOWS\System32\drivers\aswSnx.sys
2017-10-08 18:41:52 57736 ----a-w- C:\WINDOWS\System32\drivers\aswbuniva.sys
2017-10-08 18:41:52 343288 ----a-w- C:\WINDOWS\System32\drivers\aswbloga.sys
2017-10-08 18:41:52 321032 ----a-w- C:\WINDOWS\System32\drivers\aswbidsdrivera.sys
2017-10-08 18:41:52 198976 ----a-w- C:\WINDOWS\System32\drivers\aswbidsha.sys
2017-09-25 20:02:24 361784 ----a-w- C:\WINDOWS\System32\drivers\asw1c15e9b2822da0c4.tmp
2017-09-18 23:37:35 199312 ----a-w- C:\WINDOWS\System32\drivers\aswf606807d2351aeaf.tmp
2017-09-17 19:02:30 61304 ----a-w- C:\WINDOWS\System32\drivers\lpsport.sys
2017-09-17 18:10:09 84416 ----a-w- C:\WINDOWS\System32\drivers\asw6a8361799e62bb7d.tmp
2017-09-17 18:10:09 590880 ----a-w- C:\WINDOWS\System32\drivers\aswfd31bf1922ab8d8d.tmp
2017-09-17 18:10:09 47016 ----a-w- C:\WINDOWS\System32\drivers\asw24c943620a763a75.tmp
2017-09-17 18:10:09 147784 ----a-w- C:\WINDOWS\System32\drivers\aswb67baa6bf9decdac.tmp
2017-09-17 18:10:09 110376 ----a-w- C:\WINDOWS\System32\drivers\aswb36e0f16b3ab7166.tmp
2017-09-17 18:09:46 1016384 ----a-w- C:\WINDOWS\System32\drivers\asw95d159b480176aad.tmp
2017-09-17 18:09:42 57736 ----a-w- C:\WINDOWS\System32\drivers\asw6a13e6a3c8c6bf54.tmp
2017-09-17 18:09:42 343296 ----a-w- C:\WINDOWS\System32\drivers\aswd24024077f8c27ee.tmp
2017-09-17 18:09:42 320528 ----a-w- C:\WINDOWS\System32\drivers\asw54e09bd0c3de726d.tmp
2017-09-17 18:09:42 198976 ----a-w- C:\WINDOWS\System32\drivers\asw37b33612c8127abf.tmp
2017-09-05 05:31:34 1596592 ----a-w- C:\WINDOWS\System32\gdi32full.dll
2017-09-05 05:31:28 750560 ----a-w- C:\WINDOWS\System32\fontdrvhost.exe
2017-09-05 05:31:26 1346112 ----a-w- C:\WINDOWS\System32\user32.dll
2017-09-05 05:31:20 1147296 ----a-w- C:\WINDOWS\System32\hvix64.exe
2017-09-05 05:31:20 1024928 ----a-w- C:\WINDOWS\System32\hvax64.exe
2017-09-05 05:31:18 821664 ----a-w- C:\WINDOWS\System32\hvloader.exe
2017-09-05 05:31:16 115792 ----a-w- C:\WINDOWS\System32\win32u.dll
2017-09-05 05:30:55 287648 ----a-w- C:\WINDOWS\System32\drivers\sdbus.sys
2017-09-05 05:27:55 136096 ----a-w- C:\WINDOWS\System32\drivers\ksecdd.sys
2017-09-05 05:27:02 2399728 ----a-w- C:\WINDOWS\System32\KernelBase.dll
2017-09-05 05:26:51 8319904 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2017-09-05 05:26:19 1930840 ----a-w- C:\WINDOWS\System32\ntdll.dll
2017-09-05 05:25:54 159648 ----a-w- C:\WINDOWS\System32\drivers\partmgr.sys
2017-09-05 05:25:09 2969880 ----a-w- C:\WINDOWS\System32\CoreUIComponents.dll
2017-09-05 05:24:21 519584 ----a-w- C:\WINDOWS\System32\drivers\netio.sys
2017-09-05 05:24:11 923040 ----a-w- C:\WINDOWS\System32\CoreMessaging.dll
2017-09-05 05:23:47 1242528 ----a-w- C:\WINDOWS\System32\drivers\ndis.sys
2017-09-05 05:23:22 4462120 ----a-w- C:\WINDOWS\System32\setupapi.dll
2017-09-05 05:21:55 189344 ----a-w- C:\WINDOWS\System32\drivers\dumpsd.sys
2017-09-05 05:20:27 1057824 ----a-w- C:\WINDOWS\System32\MrmCoreR.dll
2017-09-05 05:19:29 4848960 ----a-w- C:\WINDOWS\explorer.exe
2017-09-05 05:19:03 2443168 ----a-w- C:\WINDOWS\System32\drivers\dxgkrnl.sys
2017-09-05 05:18:59 2972552 ----a-w- C:\WINDOWS\System32\d3d10warp.dll
2017-09-05 05:18:34 7326128 ----a-w- C:\WINDOWS\System32\windows.storage.dll
2017-09-05 05:18:29 820128 ----a-w- C:\WINDOWS\System32\WWAHost.exe
2017-09-05 05:18:23 5477096 ----a-w- C:\WINDOWS\System32\OneCoreUAPCommonProxyStub.dll
2017-09-05 05:18:19 1668344 ----a-w- C:\WINDOWS\System32\propsys.dll
2017-09-05 05:18:14 212384 ----a-w- C:\WINDOWS\System32\browserbroker.dll
2017-09-05 05:18:09 685512 ----a-w- C:\WINDOWS\System32\SHCore.dll
2017-09-05 05:17:08 316320 ----a-w- C:\WINDOWS\System32\WerFault.exe
2017-09-05 05:16:55 872472 ----a-w- C:\WINDOWS\System32\ClipSVC.dll
2017-09-05 05:16:50 546208 ----a-w- C:\WINDOWS\System32\drivers\storport.sys
2017-09-05 05:16:46 1320344 ----a-w- C:\WINDOWS\System32\wpx.dll
2017-09-05 05:16:41 228256 ----a-w- C:\WINDOWS\System32\drivers\mrxsmb20.sys
2017-09-05 05:16:39 410168 ----a-w- C:\WINDOWS\System32\Faultrep.dll
2017-09-05 05:16:36 724200 ----a-w- C:\WINDOWS\System32\wer.dll
2017-09-05 05:16:30 182688 ----a-w- C:\WINDOWS\System32\wermgr.exe
2017-09-05 05:16:21 49720 ----a-w- C:\WINDOWS\System32\tbs.dll
2017-09-05 05:16:17 715168 ----a-w- C:\WINDOWS\System32\drivers\fvevol.sys
2017-09-05 05:15:49 3116184 ----a-w- C:\WINDOWS\System32\combase.dll
2017-09-05 05:15:48 871448 ----a-w- C:\WINDOWS\System32\winhttp.dll
2017-09-05 05:15:44 654976 ----a-w- C:\WINDOWS\System32\AppXDeploymentClient.dll
2017-09-05 05:15:43 257440 ----a-w- C:\WINDOWS\System32\AppxAllUserStore.dll
2017-09-05 05:15:42 381824 ----a-w- C:\WINDOWS\System32\wevtapi.dll
2017-09-05 05:14:56 94624 ----a-w- C:\WINDOWS\System32\rdpudd.dll
2017-09-05 05:14:44 7907344 ----a-w- C:\WINDOWS\System32\Windows.Media.Protection.PlayReady.dll
2017-09-05 05:14:41 4708504 ----a-w- C:\WINDOWS\System32\mfcore.dll
2017-09-05 05:14:24 958664 ----a-w- C:\WINDOWS\System32\msvproc.dll
2017-09-05 05:14:18 1146176 ----a-w- C:\WINDOWS\System32\mfds.dll
2017-09-05 05:14:15 254176 ----a-w- C:\WINDOWS\System32\mfps.dll
2017-09-05 05:13:46 1619816 ----a-w- C:\WINDOWS\System32\sppobjs.dll
2017-09-05 05:13:27 78240 ----a-w- C:\WINDOWS\System32\SyncAppvPublishingServer.exe
2017-09-05 05:13:15 64680 ----a-w- C:\WINDOWS\System32\appidapi.dll
2017-09-05 05:11:28 2675104 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2017-09-05 05:11:21 610720 ----a-w- C:\WINDOWS\System32\drivers\afd.sys
2017-09-05 05:11:13 387936 ----a-w- C:\WINDOWS\System32\wmpps.dll
2017-09-05 04:53:54 1620880 ----a-w- C:\WINDOWS\SysWow64\ntdll.dll
2017-09-05 04:53:33 1839872 ----a-w- C:\WINDOWS\SysWow64\KernelBase.dll
2017-09-05 04:52:15 2259760 ----a-w- C:\WINDOWS\SysWow64\CoreUIComponents.dll
2017-09-05 04:50:17 4330920 ----a-w- C:\WINDOWS\SysWow64\setupapi.dll
2017-09-05 04:46:19 4471888 ----a-w- C:\WINDOWS\SysWow64\explorer.exe
2017-09-05 04:45:57 85784 ----a-w- C:\WINDOWS\SysWow64\CredentialUIBroker.exe
2017-09-05 04:45:44 2476712 ----a-w- C:\WINDOWS\SysWow64\d3d10warp.dll
2017-09-05 04:45:09 5821496 ----a-w- C:\WINDOWS\SysWow64\windows.storage.dll
2017-09-05 04:45:08 750496 ----a-w- C:\WINDOWS\SysWow64\WWAHost.exe
2017-09-05 04:45:07 23679488 ----a-w- C:\WINDOWS\System32\edgehtml.dll
2017-09-05 04:44:52 569264 ----a-w- C:\WINDOWS\SysWow64\SHCore.dll
2017-09-05 04:43:54 280480 ----a-w- C:\WINDOWS\SysWow64\WerFault.exe
2017-09-05 04:43:24 611096 ----a-w- C:\WINDOWS\SysWow64\wer.dll
2017-09-05 04:43:19 359560 ----a-w- C:\WINDOWS\SysWow64\Faultrep.dll
2017-09-05 04:43:17 169376 ----a-w- C:\WINDOWS\SysWow64\wermgr.exe
2017-09-05 04:43:12 42456 ----a-w- C:\WINDOWS\SysWow64\tbs.dll
2017-09-05 04:42:31 2330520 ----a-w- C:\WINDOWS\SysWow64\combase.dll
2017-09-05 04:42:30 519680 ----a-w- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
2017-09-05 04:42:28 182688 ----a-w- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
2017-09-05 04:42:27 291904 ----a-w- C:\WINDOWS\SysWow64\wevtapi.dll
.
============= FINISH: 15:56:26.45 ===============

Trojan Emotet

$
0
0
I just ran MBAM on my Lenovo PC running on Win XP and it detected and quarantineed
Trojan Emotet in D:\WINDOWS\SYSTEM 32\wzcdlg.dll
MBAM, as i said, quarantinned it and asked me to reboot,PC was norticeably slower before but now appears OK.
Do i need to do anything else? I understood that this Trojan affects email.

I might be infected

$
0
0
I noticed a dent in system performance lately and have a very minimal boot setup so I am having trouble narrowing it down any further on my own.

Specifically, there is a lot of stuttering when launching new applications or browsing the web while streaming 1080p video. The worst of it is the audio which cuts out and sometimes slows down.

I reinstalled Firefox thinking that might be it, but didn't have any effect.

Here is my DDS.txt:

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer:
Run by a at 8:39:51 on 2017-10-17
#Option Extended Search is enabled.
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.16323.12421 [GMT -5:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ZoneAlarm Free Firewall Firewall *Enabled* {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}
.
============== Running Processes ===============
.
E:\Windows\system32\lsm.exe
E:\Windows\system32\svchost.exe -k DcomLaunch
E:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
E:\Windows\system32\svchost.exe -k RPCSS
E:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
E:\Windows\system32\svchost.exe -k LocalService
E:\Windows\system32\svchost.exe -k netsvcs
E:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
E:\Windows\system32\svchost.exe -k NetworkService
E:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
E:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
E:\Windows\System32\svchost.exe -k utcsvc
E:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
E:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
E:\Windows\system32\sppsvc.exe
E:\Windows\system32\SearchIndexer.exe
E:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
E:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
E:\Windows\system32\Dwm.exe
E:\Windows\Explorer.EXE
E:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe
E:\Windows\System32\svchost.exe -k secsvcs
E:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
E:\Program Files\IDT\wdm\sttray64.exe
E:\Windows\system32\wbem\wmiprvse.exe
E:\ProgramData\Battle.net\Agent\Agent.5845\Agent.exe
E:\Program Files (x86)\Battle.net\Battle.net.9397\Battle.net.exe
E:\Program Files (x86)\Battle.net\Battle.net.9397\Battle.net Helper.exe
E:\Program Files (x86)\Battle.net\Battle.net.9397\Battle.net Helper.exe
E:\Program Files (x86)\Mozilla Firefox\firefox.exe
E:\Program Files (x86)\Mozilla Firefox\firefox.exe
E:\Program Files (x86)\Mozilla Firefox\firefox.exe
E:\Program Files (x86)\Mozilla Firefox\firefox.exe
E:\Windows\system32\taskmgr.exe
E:\Windows\system32\SearchProtocolHost.exe
E:\Windows\system32\SearchFilterHost.exe
E:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
uRun: [TSMApplication] "E:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe"
mRun: [ZoneAlarm] "E:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe"
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: HideSCAHealth = dword:1
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - E:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{63052A2B-D4A5-4C36-91A2-01AB322E9A36} : DHCPNameServer = 172.18.11.1
TCP: Interfaces\{A52C1C54-21B8-44F2-82D7-32EF9AE52F01} : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{A52C1C54-21B8-44F2-82D7-32EF9AE52F01} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{C3AE998E-3078-447E-8C88-1B6C43CE4106} : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{C3AE998E-3078-447E-8C88-1B6C43CE4106} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{C3AE998E-3078-447E-8C88-1B6C43CE4106}\35D4D2A4332303140273531343 : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{C3AE998E-3078-447E-8C88-1B6C43CE4106}\35D4D2A4332303140273531343 : DHCPNameServer = 192.168.43.1
SSODL: WebCheck - <orphaned>
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.8.0_144\bin\ssv.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll
x64-Run: [SysTrayApp] E:\Program Files\IDT\WDM\sttray64.exe
x64-IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - E:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "E:\Program Files (x86)\Google\Chrome\Application\61.0.3163.100\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
.
================= FIREFOX ===================
.
FF - ProfilePath - E:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\39665wj1.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - plugin: E:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll
FF - plugin: E:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_159.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: content.notify.ontimer - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.switch.threshold - 750000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R0 SCMNdisP;General NDIS Protocol Driver;E:\Windows\System32\drivers\SCMNdisP.sys [2017-10-10 25312]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver;E:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2017-10-10 27552]
R2 DiagTrack;Diagnostics Tracking Service;E:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 LGCoreTemp;Logitech CPU Core Tempurature;E:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys [2015-6-21 14184]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container;E:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-10 518080]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;E:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2017-10-10 462968]
R3 ETDSMBus;ETDSMBus;E:\Windows\System32\drivers\ETDSMBus.sys [2017-10-10 32840]
R3 LGBusEnum;Logitech Gaming Virtual Bus Enumerator Driver;E:\Windows\System32\drivers\LGBusEnum.sys [2017-8-18 36496]
R3 LGJoyXlCore;Logitech Translation Layer Driver (LGS);E:\Windows\System32\drivers\LGJoyXlCore.sys [2017-8-18 67736]
R3 MonitorFunction;Driver for Monitor;E:\Windows\System32\drivers\TVMonitor.sys [2017-10-14 18336]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);E:\Windows\System32\drivers\nvvad64v.sys [2017-10-15 50624]
R3 nvvhci;NVVHCI Enumerator Service;E:\Windows\System32\drivers\nvvhci.sys [2017-10-11 57792]
R3 WNDA3100v3;NETGEAR WNDA3100v3 USB Wireless LAN Card Driver;E:\Windows\System32\drivers\WNDA3100v3.sys [2014-12-8 2225808]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;E:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-5 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;E:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-5 125112]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);E:\Windows\System32\drivers\ssudbus.sys [2017-5-18 131984]
S3 dmvsc;dmvsc;E:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;E:\Windows\System32\drivers\LGVirHid.sys [2017-8-18 26008]
S3 NvStreamKms;NVIDIA KMS;E:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2017-10-15 30144]
S3 pmxdrv;pmxdrv;E:\Windows\System32\drivers\pmxdrv.sys [2017-10-13 31152]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;E:\Windows\System32\drivers\rdpvideominiport.sys [2017-10-11 20992]
S3 RTL8167;Realtek 8167 NT Driver;E:\Windows\System32\drivers\Rt64win7.sys [2017-10-10 1075688]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);E:\Windows\System32\drivers\ssudmdm.sys [2017-5-18 166288]
S3 Synth3dVsc;Synth3dVsc;E:\Windows\System32\drivers\Synth3dVsc.sys [2010-11-21 88960]
S3 tap-tb-0901;TunnelBear Adapter V9;E:\Windows\System32\drivers\tap-tb-0901.sys [2017-9-6 38656]
S3 terminpt;Microsoft Remote Desktop Input Driver;E:\Windows\System32\drivers\terminpt.sys [2010-11-21 34816]
S3 TsUsbFlt;TsUsbFlt;E:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;E:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 tsusbhub;tsusbhub;E:\Windows\System32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 TunnelBearMaintenance;TunnelBear Maintenance;E:\Program Files (x86)\TunnelBear\TunnelBear.Maintenance.exe [2017-9-6 37248]
S3 WatAdminSvc;Windows Activation Technologies Service;E:\Windows\System32\Wat\WatAdminSvc.exe [2017-10-11 1255736]
S3 ZAPrivacyService;ZoneAlarm Privacy Service;E:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [2016-11-1 114936]
S4 IEEtwCollectorService;Internet Explorer ETW Collector Service;E:\Windows\System32\ieetwcollector.exe [2017-10-11 116224]
S4 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;E:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-2-13 731648]
S4 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;E:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-2-13 820184]
S4 LogiRegistryService;Logitech Gaming Registry Service;E:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [2017-8-18 225400]
S4 NvContainerNetworkService;NVIDIA NetworkService Container;E:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-10 518080]
S4 NvTelemetryContainer;NVIDIA Telemetry Container;E:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [2017-10-10 460736]
S4 Origin Client Service;Origin Client Service;E:\Program Files (x86)\Origin\OriginClientService.exe [2017-10-15 2120032]
S4 Origin Web Helper Service;Origin Web Helper Service;E:\Program Files (x86)\Origin\OriginWebHelperService.exe [2017-10-15 3000168]
S4 ss_conn_service;SAMSUNG Mobile Connectivity Service;E:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [2017-10-13 743688]
S4 TeamViewer;TeamViewer 12;E:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2017-10-14 10803440]
S4 ZoneAlarm ICM Service;ZoneAlarm ICM Service;E:\Program Files (x86)\CheckPoint\ZoneAlarm\ICM-Service.exe [2017-4-14 1058616]
.
=============== Created Last 60 ================
.
2017-10-17 09:35:08 75888 ----a-w- E:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2D7AE1E1-F96B-44C2-B90E-86935A035835}\offreg.2976.dll
2017-10-17 07:14:17 -------- d-----w- E:\Users\a\AppData\Local\Macromedia
2017-10-17 07:10:44 -------- d-----w- E:\Users\a\AppData\Local\Package Cache
2017-10-16 11:51:25 -------- d-----w- E:\Users\a\AppData\Roaming\TunnelBear
2017-10-16 11:51:25 -------- d-----w- E:\Users\a\AppData\Local\IsolatedStorage
2017-10-16 11:50:58 -------- d-----w- E:\Program Files (x86)\TunnelBear
2017-10-16 11:41:32 -------- d-----w- E:\Users\a\AppData\Local\Google
2017-10-16 07:48:46 -------- d-----w- E:\Users\a\AppData\Roaming\mIRC
2017-10-16 07:48:46 -------- d-----w- E:\Program Files (x86)\mIRC
2017-10-16 06:29:57 -------- d-----w- E:\Users\a\AppData\Local\pip
2017-10-16 05:26:46 -------- d-----w- E:\Users\a\.idlerc
2017-10-16 05:24:08 -------- d-----w- E:\Users\a\AppData\Roaming\livestreamer
2017-10-16 02:15:29 -------- d-----w- E:\Users\a\AppData\Local\Trend Micro
2017-10-16 02:15:06 -------- d-----w- E:\ProgramData\Trend Micro
2017-10-16 02:15:05 -------- d-----w- E:\Windows\Trend Micro
2017-10-16 02:13:12 332512 ----a-w- E:\Windows\System32\drivers\tmcomm.sys
2017-10-15 11:31:51 50624 ----a-w- E:\Windows\System32\drivers\nvvad64v.sys
2017-10-15 09:09:14 -------- d-----w- E:\Program Files (x86)\CheckPoint
2017-10-15 09:08:35 -------- d-----w- E:\ProgramData\CheckPoint
2017-10-15 05:39:59 -------- d-----w- E:\Program Files (x86)\Origin Games
2017-10-15 05:35:30 -------- d-----w- E:\Users\a\AppData\Roaming\Origin
2017-10-15 05:34:35 -------- d-----w- E:\Program Files (x86)\Origin
2017-10-15 05:32:38 -------- d-----w- E:\Users\a\.QtWebEngineProcess
2017-10-15 05:32:38 -------- d-----w- E:\Users\a\.Origin
2017-10-15 05:32:35 -------- d-----w- E:\Users\a\AppData\Local\Origin
2017-10-15 05:14:33 -------- d-----w- E:\ProgramData\Origin
2017-10-15 04:47:48 -------- d-----w- E:\Program Files (x86)\Titanfall 2
2017-10-14 22:19:34 18336 ----a-w- E:\Windows\System32\drivers\TVMonitor.sys
2017-10-14 08:55:56 -------- d-----w- E:\Users\a\AppData\Local\TeamViewer
2017-10-14 08:45:43 -------- d-----w- E:\Users\a\AppData\Roaming\TeamViewer
2017-10-14 08:45:39 -------- d-----w- E:\Program Files (x86)\TeamViewer
2017-10-14 07:10:52 75888 ----a-w- E:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2D7AE1E1-F96B-44C2-B90E-86935A035835}\offreg.5256.dll
2017-10-13 11:45:20 -------- d-----w- E:\Program Files (x86)\Amazon.com
2017-10-13 07:53:50 31152 ----a-w- E:\Windows\System32\drivers\pmxdrv.sys
2017-10-13 07:52:31 -------- d-----w- E:\Intel
2017-10-13 07:01:19 -------- d-----w- E:\Program Files\SAMSUNG
2017-10-13 07:01:08 -------- d-----w- E:\ProgramData\Samsung
2017-10-13 06:54:30 -------- d-----w- E:\Program Files (x86)\Battle.net
2017-10-13 06:45:52 -------- d-----w- E:\Windows\System32\appmgmt
2017-10-12 13:34:04 -------- d-----w- E:\Users\a\AppData\Roaming\IDT
2017-10-12 02:19:52 -------- d-----w- E:\Windows\CheckSur
2017-10-12 01:28:43 3928064 ----a-w- E:\Windows\System32\d2d1.dll
2017-10-12 01:28:43 3419136 ----a-w- E:\Windows\SysWow64\d2d1.dll
2017-10-11 13:19:28 -------- d-----w- E:\Users\a\AppData\Local\Deployment
2017-10-11 13:19:28 -------- d-----w- E:\Users\a\AppData\Local\Apps
2017-10-11 12:59:27 6101504 ----a-w- E:\Windows\System32\stlang64.dll
2017-10-11 12:59:27 464384 ----a-w- E:\Windows\System32\slapoi64.dll
2017-10-11 12:59:27 1897984 ----a-w- E:\Windows\System32\IDTNC64.cpl
2017-10-11 12:59:27 1703424 ----a-w- E:\Windows\sttray64.exe
2017-10-11 12:31:46 -------- d-----w- E:\Users\a\AppData\Roaming\TradeSkillMaster
2017-10-11 11:41:42 -------- d-----w- E:\Program Files\CCleaner
2017-10-11 11:27:12 -------- d-----w- E:\Users\a\AppData\Local\HP_Inc
2017-10-11 11:14:45 -------- d-----w- E:\Users\a\AppData\Local\Hewlett-Packard
2017-10-11 11:12:57 -------- d-----w- E:\Users\a\AppData\Roaming\hpqLog
2017-10-11 11:12:11 -------- d-----w- E:\Program Files\IDT
2017-10-11 11:07:51 150016 ----a-w- E:\Windows\SysWow64\staco.dll
2017-10-11 11:07:44 733184 ----a-w- E:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iKernel.dll
2017-10-11 11:07:44 69715 ----a-w- E:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\ctor.dll
2017-10-11 11:07:44 5632 ----a-w- E:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\DotNetInstaller.exe
2017-10-11 11:07:44 32768 ----a-w- E:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2017-10-11 11:07:44 303236 ----a-w- E:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\setup.dll
2017-10-11 11:07:44 266240 ----a-w- E:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iscript.dll
2017-10-11 11:07:44 180356 ----a-w- E:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iGdi.dll
2017-10-11 11:07:44 172032 ----a-w- E:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iuser.dll
2017-10-11 11:07:29 181248 ----a-w- E:\Windows\System32\staco64.dll
2017-10-11 10:53:15 -------- d-----w- E:\Program Files (x86)\Common Files\IObit
2017-10-11 09:32:33 87040 ----a-w- E:\Windows\System32\drivers\WUDFPf.sys
2017-10-11 09:32:33 84992 ----a-w- E:\Windows\System32\WUDFSvc.dll
2017-10-11 09:32:33 744448 ----a-w- E:\Windows\System32\WUDFx.dll
2017-10-11 09:32:33 45056 ----a-w- E:\Windows\System32\WUDFCoinstaller.dll
2017-10-11 09:32:33 229888 ----a-w- E:\Windows\System32\WUDFHost.exe
2017-10-11 09:32:33 198656 ----a-w- E:\Windows\System32\drivers\WUDFRd.sys
2017-10-11 09:32:33 194048 ----a-w- E:\Windows\System32\WUDFPlatform.dll
2017-10-11 09:28:11 31232 ----a-w- E:\Windows\SysWow64\prevhost.exe
2017-10-11 09:28:11 31232 ----a-w- E:\Windows\System32\prevhost.exe
2017-10-11 09:20:30 -------- d-----w- E:\Windows\System32\MRT
2017-10-11 09:20:28 126925120 -c--a-w- E:\Windows\System32\MRT-KB890830.exe
2017-10-11 09:20:15 -------- d-----w- E:\Windows\System32\SRSLabs
2017-10-11 09:14:54 -------- d-----w- E:\Program Files (x86)\VideoLAN
2017-10-11 08:57:05 927544 ----a-w- E:\Windows\System32\vulkan-1.dll
2017-10-11 08:57:05 798008 ----a-w- E:\Windows\SysWow64\vulkan-1.dll
2017-10-11 08:57:05 591160 ----a-w- E:\Windows\System32\vulkaninfo.exe
2017-10-11 08:57:05 490296 ----a-w- E:\Windows\SysWow64\vulkaninfo.exe
2017-10-11 08:57:05 -------- d-----w- E:\Program Files (x86)\VulkanRT
2017-10-11 08:38:46 -------- d-----w- E:\Program Files (x86)\Overwatch
2017-10-11 08:35:39 -------- d-----w- E:\Program Files (x86)\StarCraft
2017-10-11 08:34:54 -------- d-----w- E:\Users\a\AppData\Roaming\.mono
2017-10-11 08:34:54 -------- d-----w- E:\ProgramData\.mono
2017-10-11 08:34:53 -------- d-----w- E:\Users\a\AppData\Local\Blizzard
2017-10-11 08:34:22 -------- d-----w- E:\Program Files (x86)\Hearthstone
2017-10-11 08:21:20 221184 ----a-w- E:\Windows\System32\UIAnimation.dll
2017-10-11 08:21:20 187392 ----a-w- E:\Windows\SysWow64\UIAnimation.dll
2017-10-11 08:21:20 1648128 ----a-w- E:\Windows\System32\DWrite.dll
2017-10-11 08:21:20 1251328 ----a-w- E:\Windows\SysWow64\DWrite.dll
2017-10-11 08:21:20 1180160 ----a-w- E:\Windows\System32\FntCache.dll
2017-10-11 08:21:15 2565120 ----a-w- E:\Windows\System32\d3d10warp.dll
2017-10-11 08:21:15 1987584 ----a-w- E:\Windows\SysWow64\d3d10warp.dll
2017-10-11 08:21:14 647680 ----a-w- E:\Windows\System32\d3d10level9.dll
2017-10-11 08:21:14 603648 ----a-w- E:\Windows\SysWow64\d3d10level9.dll
2017-10-11 08:21:14 2777088 ----a-w- E:\Windows\System32\msmpeg2vdec.dll
2017-10-11 08:21:14 2285056 ----a-w- E:\Windows\SysWow64\msmpeg2vdec.dll
2017-10-11 08:21:12 1424896 ----a-w- E:\Windows\System32\WindowsCodecs.dll
2017-10-11 08:21:12 1230848 ----a-w- E:\Windows\SysWow64\WindowsCodecs.dll
2017-10-11 08:09:23 3229696 ----a-w- E:\Windows\explorer.exe
2017-10-11 08:09:23 2972672 ----a-w- E:\Windows\SysWow64\explorer.exe
2017-10-11 08:08:14 46080 ----a-w- E:\Windows\System32\drivers\tcpipreg.sys
2017-10-11 08:04:35 396800 ----a-w- E:\Windows\System32\webio.dll
2017-10-11 08:04:35 316416 ----a-w- E:\Windows\SysWow64\webio.dll
2017-10-11 08:02:49 353280 ----a-w- E:\Program Files\Common Files\Microsoft Shared\ink\InkDiv.dll
2017-10-11 08:02:49 275456 ----a-w- E:\Windows\System32\InkEd.dll
2017-10-11 08:02:49 274944 ----a-w- E:\Program Files (x86)\Common Files\Microsoft Shared\ink\InkDiv.dll
2017-10-11 08:02:49 216064 ----a-w- E:\Windows\SysWow64\InkEd.dll
2017-10-11 08:02:49 2104320 ----a-w- E:\Program Files\Common Files\Microsoft Shared\ink\InkObj.dll
2017-10-11 08:02:49 18432 ----a-w- E:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2017-10-11 08:02:49 169984 ----a-w- E:\Program Files\Common Files\Microsoft Shared\ink\rtscom.dll
2017-10-11 08:02:49 16384 ----a-w- E:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2017-10-11 08:02:49 1416192 ----a-w- E:\Program Files (x86)\Common Files\Microsoft Shared\ink\InkObj.dll
2017-10-11 08:02:49 126464 ----a-w- E:\Program Files (x86)\Common Files\Microsoft Shared\ink\rtscom.dll
2017-10-11 08:00:58 73664 ----a-w- E:\Windows\System32\drivers\disk.sys
2017-10-11 07:59:37 286720 ----a-w- E:\Program Files (x86)\Common Files\System\Ole DB\msdaora.dll
2017-10-11 07:59:37 176128 ----a-w- E:\Windows\SysWow64\msorcl32.dll
2017-10-11 07:59:37 156672 ----a-w- E:\Windows\System32\mtxoci.dll
2017-10-11 07:59:37 111616 ----a-w- E:\Windows\SysWow64\mtxoci.dll
2017-10-11 07:57:16 7168 ----a-w- E:\Windows\System32\kbdgeoqw.dll
2017-10-11 07:57:16 7168 ----a-w- E:\Windows\System32\KBDAZEL.DLL
2017-10-11 07:57:16 6656 ----a-w- E:\Windows\SysWow64\kbdgeoqw.dll
2017-10-11 07:57:16 6656 ----a-w- E:\Windows\SysWow64\KBDAZEL.DLL
2017-10-11 07:56:00 72192 ----a-w- E:\Windows\System32\aelupsvc.dll
2017-10-11 07:56:00 6656 ----a-w- E:\Windows\System32\shimeng.dll
2017-10-11 07:56:00 5120 ----a-w- E:\Windows\SysWow64\shimeng.dll
2017-10-11 07:56:00 342016 ----a-w- E:\Windows\System32\apphelp.dll
2017-10-11 07:56:00 295936 ----a-w- E:\Windows\SysWow64\apphelp.dll
2017-10-11 07:56:00 23552 ----a-w- E:\Windows\System32\sdbinst.exe
2017-10-11 07:56:00 20992 ----a-w- E:\Windows\SysWow64\sdbinst.exe
2017-10-11 07:54:40 44032 ----a-w- E:\Windows\System32\tsgqec.dll
2017-10-11 07:54:40 3722752 ----a-w- E:\Windows\System32\mstscax.dll
2017-10-11 07:54:40 36864 ----a-w- E:\Windows\SysWow64\tsgqec.dll
2017-10-11 07:54:40 3221504 ----a-w- E:\Windows\SysWow64\mstscax.dll
2017-10-11 07:54:40 158720 ----a-w- E:\Windows\System32\aaclient.dll
2017-10-11 07:54:40 131584 ----a-w- E:\Windows\SysWow64\aaclient.dll
2017-10-11 07:54:02 465920 ----a-w- E:\Windows\System32\WMPhoto.dll
2017-10-11 07:54:02 417792 ----a-w- E:\Windows\SysWow64\WMPhoto.dll
2017-10-11 07:53:29 -------- d-----w- E:\Users\a\AppData\Local\Logitech
2017-10-11 07:52:52 -------- d-----w- E:\Program Files\Logitech Gaming Software
2017-10-11 07:51:35 -------- d-----w- E:\Users\a\AppData\Roaming\Logishrd
2017-10-11 07:51:23 879104 ----a-w- E:\Windows\System32\tdh.dll
2017-10-11 07:51:23 635392 ----a-w- E:\Windows\SysWow64\tdh.dll
2017-10-11 07:47:35 69888 ----a-w- E:\Windows\System32\drivers\stream.sys
2017-10-11 07:44:09 223752 ----a-w- E:\Windows\System32\drivers\fvevol.sys
2017-10-11 07:36:09 68608 ----a-w- E:\Windows\System32\taskhost.exe
2017-10-11 07:28:28 -------- d-----w- E:\Program Files (x86)\TradeSkillMaster Application
2017-10-11 07:17:58 -------- d-----w- E:\Program Files (x86)\IDT
2017-10-11 07:16:35 -------- d-----w- E:\Program Files (x86)\StarCraft II
2017-10-11 07:13:20 -------- d-----w- E:\Users\a\AppData\Roaming\discord
2017-10-11 07:13:12 -------- d-----w- E:\Users\a\AppData\Local\SquirrelTemp
2017-10-11 07:13:12 -------- d-----w- E:\Users\a\AppData\Local\Discord
2017-10-11 07:10:41 1887232 ----a-w- E:\Windows\System32\d3d11.dll
2017-10-11 07:10:41 1505280 ----a-w- E:\Windows\SysWow64\d3d11.dll
2017-10-11 07:10:12 -------- d-----w- E:\Windows\Migration
2017-10-11 07:08:21 -------- d-----w- E:\Program Files (x86)\World of Warcraft
2017-10-11 07:07:44 -------- d-----w- E:\ProgramData\Blizzard Entertainment
2017-10-11 07:07:40 -------- d-----w- E:\Users\a\AppData\Local\CrashDumps
2017-10-11 07:06:48 -------- d-----w- E:\Users\a\AppData\Local\Blizzard Entertainment
2017-10-11 07:06:47 -------- d-----w- E:\Users\a\AppData\Roaming\Battle.net
2017-10-11 07:06:06 -------- d-----w- E:\Program Files (x86)\Blizzard App
2017-10-11 07:05:46 -------- d-----w- E:\Users\a\AppData\Local\Battle.net
2017-10-11 07:05:36 -------- d-----w- E:\ProgramData\Battle.net
2017-10-11 06:58:49 8199504 ----a-w- E:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2017-10-11 06:58:47 13890840 ----a-w- E:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2D7AE1E1-F96B-44C2-B90E-86935A035835}\mpengine.dll
2017-10-11 06:50:22 81408 ----a-w- E:\Windows\System32\imagehlp.dll
2017-10-11 06:50:22 5120 ----a-w- E:\Windows\SysWow64\wmi.dll
2017-10-11 06:50:22 5120 ----a-w- E:\Windows\System32\wmi.dll
2017-10-11 06:50:22 23408 ----a-w- E:\Windows\System32\drivers\fs_rec.sys
2017-10-11 06:50:22 159232 ----a-w- E:\Windows\SysWow64\imagehlp.dll
2017-10-11 06:49:27 4296704 ----a-w- E:\Windows\System32\D3DCompiler_47.dll
2017-10-11 06:49:27 3550208 ----a-w- E:\Windows\SysWow64\D3DCompiler_47.dll
2017-10-11 06:46:59 95744 ----a-w- E:\Windows\System32\synceng.dll
2017-10-11 06:42:43 142336 ----a-w- E:\Windows\System32\poqexec.exe
2017-10-11 06:42:43 123904 ----a-w- E:\Windows\SysWow64\poqexec.exe
2017-10-11 06:40:14 -------- d-----w- E:\Windows\pss
2017-10-11 06:39:21 -------- d-----w- E:\Windows\SysWow64\Wat
2017-10-11 06:39:21 -------- d-----w- E:\Windows\System32\Wat
2017-10-11 06:15:21 -------- d-----w- E:\Windows\Panther
2017-10-11 06:12:08 803328 ----a-w- E:\Windows\SysWow64\FlashPlayerApp.exe
2017-10-11 06:12:08 144896 ----a-w- E:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2017-10-11 06:11:52 -------- d-----w- E:\Users\a\AppData\Local\Adobe
2017-10-11 06:07:23 110144 ----a-w- E:\Windows\System32\WindowsAccessBridge-64.dll
2017-10-11 06:07:12 -------- d-----w- E:\ProgramData\Oracle
2017-10-11 05:59:46 -------- d-----w- E:\Windows\AutoKMS
2017-10-11 05:57:08 -------- d-----w- E:\ProgramData\Microsoft Toolkit
2017-10-11 05:46:57 -------- d-----w- E:\Users\a\AppData\Roaming\qBittorrent
2017-10-11 05:46:44 -------- d-----w- E:\Users\a\AppData\Local\qBittorrent
2017-10-11 05:46:34 -------- d-----w- E:\Program Files\qBittorrent
2017-10-11 05:38:34 -------- d-----w- E:\ProgramData\AomeiBR
2017-10-11 04:52:48 -------- d-----w- E:\Windows\Downloaded Installations
2017-10-11 04:51:04 859648 ----a-w- E:\Windows\System32\IKEEXT.DLL
2017-10-11 04:51:04 830464 ----a-w- E:\Windows\System32\nshwfp.dll
2017-10-11 04:51:04 656896 ----a-w- E:\Windows\SysWow64\nshwfp.dll
2017-10-11 04:51:04 324096 ----a-w- E:\Windows\System32\FWPUCLNT.DLL
2017-10-11 04:51:04 216576 ----a-w- E:\Windows\SysWow64\FWPUCLNT.DLL
2017-10-11 04:48:20 -------- d-----w- E:\Users\a\AppData\Local\Mozilla
2017-10-11 04:46:55 23552 ----a-w- E:\Windows\System32\drivers\tdtcp.sys
2017-10-11 04:44:58 -------- d-----w- E:\Users\a\AppData\Local\NVIDIA
2017-10-11 04:44:57 -------- d-----w- E:\Users\a\AppData\Local\CEF
2017-10-11 04:43:01 -------- d-----w- E:\Users\a\AppData\Local\NVIDIA Corporation
2017-10-11 04:42:38 -------- d-----w- E:\ProgramData\{74E9F814-C737-42CC-B721-DBBC4059367A}
2017-10-11 04:39:57 1951 ----a-w- E:\Windows\NvContainerRecovery.bat
2017-10-11 04:38:28 -------- d-----w- E:\Program Files\NVIDIA Corporation
2017-10-11 04:37:20 122856 ----a-w- E:\Windows\System32\RtNicProp64.dll
2017-10-11 04:37:20 118824 ----a-w- E:\Windows\System32\RTNUninst64.dll
2017-10-11 04:37:20 1075688 ----a-w- E:\Windows\System32\drivers\Rt64win7.sys
2017-10-11 04:37:07 1615472 ----a-w- E:\Windows\System32\nvhdagenco6420103.dll
2017-10-11 03:47:08 200272 ----a-w- E:\Windows\System32\drivers\TeeDriverx64.sys
2017-10-11 03:44:23 4172536 ----a-w- E:\Windows\System32\drivers\athrx.sys
2017-10-11 03:44:13 9728 ----a-w- E:\Windows\System32\Wdfres.dll
2017-10-11 03:44:13 785512 ----a-w- E:\Windows\System32\drivers\Wdf01000.sys
2017-10-11 03:44:13 54376 ----a-w- E:\Windows\System32\drivers\WdfLdr.sys
2017-10-11 03:44:13 2560 ----a-w- E:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2017-10-11 03:44:09 32840 ----a-w- E:\Windows\System32\drivers\ETDSMBus.sys
2017-10-11 03:44:09 1804696 ----a-w- E:\Windows\System32\WdfCoInstaller01011.dll
2017-10-11 03:34:45 -------- d-----w- E:\Users\a\AppData\Local\ElevatedDiagnostics
2017-10-11 03:24:35 -------- d-----w- E:\Program Files (x86)\Common Files\postureAgent
2017-10-11 03:24:19 -------- d-----w- E:\Users\a\AppData\Roaming\WinBatch
2017-10-11 03:23:50 -------- d-----w- E:\Windows\IObit
2017-10-11 03:23:50 -------- d-----w- E:\ProgramData\ProductData
2017-10-11 03:22:46 27552 ----a-w- E:\Windows\SysWow64\drivers\HWiNFO64A.SYS
2017-10-11 03:22:46 -------- d-----w- E:\ProgramData\IObit
2017-10-11 03:22:36 -------- d-----w- E:\Users\a\AppData\Roaming\IObit
2017-10-11 03:22:32 -------- d-----w- E:\Users\a\AppData\Local\Programs
2017-10-11 03:21:06 25312 ----a-r- E:\Windows\System32\drivers\SCMNdisP.sys
2017-10-11 03:20:42 -------- d-sh--w- E:\Windows\Installer
2017-09-13 23:20:30 798008 ----a-w- E:\Windows\SysWow64\vulkan-1-1-0-61-0.dll
2017-09-13 23:20:14 490296 ----a-w- E:\Windows\SysWow64\vulkaninfo-1-1-0-61-0.exe
2017-09-13 23:19:50 927544 ----a-w- E:\Windows\System32\vulkan-1-1-0-61-0.dll
2017-09-13 23:19:38 591160 ----a-w- E:\Windows\System32\vulkaninfo-1-1-0-61-0.exe
2017-09-06 21:45:26 38656 ----a-w- E:\Windows\System32\drivers\tap-tb-0901.sys
.
==================== Find6M ====================
.
2017-10-11 07:56:00 562176 ----a-w- E:\Windows\apppatch\AcLayers.dll
2017-10-11 07:56:00 470528 ----a-w- E:\Windows\apppatch\AcSpecfc.dll
2017-10-11 07:56:00 350208 ----a-w- E:\Windows\apppatch\AppPatch64\AcLayers.dll
2017-10-11 07:56:00 211968 ----a-w- E:\Windows\apppatch\AcXtrnal.dll
2017-10-11 07:56:00 135168 ----a-w- E:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2017-10-11 07:56:00 103424 ----a-w- E:\Windows\apppatch\AppPatch64\acspecfc.dll
2017-10-11 06:39:24 419840 ----a-w- E:\Windows\System32\systemcpl.dll
2017-10-11 06:39:24 14848 ----a-w- E:\Windows\System32\slwga.dll
2017-10-11 06:39:24 13824 ----a-w- E:\Windows\SysWow64\slwga.dll
2017-10-11 01:05:52 1796032 ----a-w- E:\Windows\System32\nvspcap64.dll
2017-10-11 01:05:52 1577920 ----a-w- E:\Windows\SysWow64\nvspcap.dll
2017-10-11 01:05:51 918976 ----a-w- E:\Windows\System32\NvRtmpStreamer64.dll
2017-10-11 01:05:47 186304 ----a-w- E:\Windows\System32\nvaudcap64v.dll
2017-10-11 01:05:47 152512 ----a-w- E:\Windows\SysWow64\nvaudcap32v.dll
2017-10-10 23:26:14 1951 ----a-w- E:\Windows\NvTelemetryContainerRecovery.bat
2017-10-06 11:44:54 5960312 ----a-w- E:\Windows\System32\nvcpl.dll
2017-10-06 11:44:54 2587584 ----a-w- E:\Windows\System32\nvsvc64.dll
2017-10-06 11:44:52 81856 ----a-w- E:\Windows\System32\nv3dappshextr.dll
2017-10-06 11:44:52 607168 ----a-w- E:\Windows\System32\nv3dappshext.dll
2017-10-06 11:44:52 449656 ----a-w- E:\Windows\System32\nvmctray.dll
2017-10-06 11:44:52 1766520 ----a-w- E:\Windows\System32\nvsvcr.dll
2017-10-06 11:44:52 122816 ----a-w- E:\Windows\System32\nvshext.dll
2017-09-29 15:02:33 8257351 ----a-w- E:\Windows\System32\nvcoproc.bin
2017-09-19 07:23:48 1755072 ----a-w- E:\Windows\System32\nvspbridge64.dll
2017-09-19 07:23:47 1317312 ----a-w- E:\Windows\SysWow64\nvspbridge.dll
2017-09-16 19:23:33 512960 ----a-w- E:\Windows\System32\OpenCL.dll
2017-09-16 19:23:33 418752 ----a-w- E:\Windows\SysWow64\OpenCL.dll
2017-09-16 19:23:33 1988216 ----a-w- E:\Windows\System32\nvdispco6438569.dll
2017-09-16 19:23:33 1606592 ----a-w- E:\Windows\System32\nvdispgenco6438569.dll
2017-09-13 15:33:50 631176 ----a-w- E:\Windows\System32\winresume.efi
2017-09-13 15:32:36 706792 ----a-w- E:\Windows\System32\winload.efi
2017-09-13 15:32:35 5547752 ----a-w- E:\Windows\System32\ntoskrnl.exe
2017-09-13 15:32:33 95464 ----a-w- E:\Windows\System32\drivers\ksecdd.sys
2017-09-13 15:32:33 154856 ----a-w- E:\Windows\System32\drivers\ksecpkg.sys
2017-09-13 15:31:56 1732864 ----a-w- E:\Windows\System32\ntdll.dll
2017-09-13 15:27:59 731648 ----a-w- E:\Windows\System32\kerberos.dll
2017-09-13 15:13:35 4001512 ----a-w- E:\Windows\SysWow64\ntkrnlpa.exe
2017-09-13 15:13:35 3945704 ----a-w- E:\Windows\SysWow64\ntoskrnl.exe
2017-09-13 15:10:46 1314112 ----a-w- E:\Windows\SysWow64\ntdll.dll
2017-09-13 15:08:59 554496 ----a-w- E:\Windows\SysWow64\kerberos.dll
2017-09-13 15:05:20 324608 ----a-w- E:\Windows\System32\drivers\nwifi.sys
2017-09-13 15:00:54 148480 ----a-w- E:\Windows\System32\appidpolicyconverter.exe
2017-09-13 15:00:50 62464 ----a-w- E:\Windows\System32\drivers\appid.sys
2017-09-13 15:00:50 17920 ----a-w- E:\Windows\System32\appidcertstorecheck.exe
2017-09-13 15:00:10 64000 ----a-w- E:\Windows\System32\auditpol.exe
2017-09-13 14:57:12 338432 ----a-w- E:\Windows\System32\conhost.exe
2017-09-13 14:56:20 296960 ----a-w- E:\Windows\System32\rstrui.exe
2017-09-13 14:53:40 159744 ----a-w- E:\Windows\System32\drivers\mrxsmb.sys
2017-09-13 14:53:06 291328 ----a-w- E:\Windows\System32\drivers\mrxsmb10.sys
2017-09-13 14:53:04 129536 ----a-w- E:\Windows\System32\drivers\mrxsmb20.sys
2017-09-13 14:52:23 30720 ----a-w- E:\Windows\System32\lsass.exe
2017-09-13 14:52:20 112640 ----a-w- E:\Windows\System32\smss.exe
2017-09-13 14:50:26 50176 ----a-w- E:\Windows\SysWow64\auditpol.exe
2017-09-13 14:47:00 25600 ----a-w- E:\Windows\SysWow64\setup16.exe
2017-09-13 14:46:59 7680 ----a-w- E:\Windows\SysWow64\instnm.exe
2017-09-13 14:46:59 14336 ----a-w- E:\Windows\SysWow64\ntvdm64.dll
2017-09-13 14:46:58 2048 ----a-w- E:\Windows\SysWow64\user.exe
2017-09-13 14:46:13 36352 ----a-w- E:\Windows\SysWow64\cryptbase.dll
2017-09-13 14:46:06 6144 ---ha-w- E:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2017-09-13 14:46:06 4608 ---ha-w- E:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-13 14:46:06 3584 ---ha-w- E:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2017-09-13 14:46:06 3072 ---ha-w- E:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2017-09-08 15:34:37 1680616 ----a-w- E:\Windows\System32\drivers\ntfs.sys
2017-09-08 15:30:58 2319872 ----a-w- E:\Windows\System32\tquery.dll
2017-09-08 15:30:58 149504 ----a-w- E:\Windows\System32\t2embed.dll
2017-09-08 15:30:53 2058240 ----a-w- E:\Windows\System32\Query.dll
2017-09-08 15:30:48 99840 ----a-w- E:\Windows\System32\mssprxy.dll
2017-09-08 15:30:48 778240 ----a-w- E:\Windows\System32\mssvp.dll
2017-09-08 15:30:48 75264 ----a-w- E:\Windows\System32\msscntrs.dll
2017-09-08 15:30:48 491520 ----a-w- E:\Windows\System32\mssph.dll
2017-09-08 15:30:48 288256 ----a-w- E:\Windows\System32\mssphtb.dll
2017-09-08 15:30:48 2222080 ----a-w- E:\Windows\System32\mssrch.dll
2017-09-08 15:30:48 14336 ----a-w- E:\Windows\System32\msshooks.dll
2017-09-08 15:30:48 115200 ----a-w- E:\Windows\System32\mssitlb.dll
2017-09-08 15:30:44 405504 ----a-w- E:\Windows\System32\gdi32.dll
2017-09-08 15:14:08 591872 ----a-w- E:\Windows\System32\SearchIndexer.exe
2017-09-08 15:13:47 249856 ----a-w- E:\Windows\System32\SearchProtocolHost.exe
2017-09-08 15:13:17 113664 ----a-w- E:\Windows\System32\SearchFilterHost.exe
2017-09-08 15:10:06 312832 ----a-w- E:\Windows\SysWow64\gdi32.dll
2017-09-08 15:10:05 1549824 ----a-w- E:\Windows\SysWow64\tquery.dll
2017-09-08 15:10:04 109568 ----a-w- E:\Windows\SysWow64\t2embed.dll
2017-09-08 15:10:01 1363968 ----a-w- E:\Windows\SysWow64\Query.dll
2017-09-08 15:09:57 666624 ----a-w- E:\Windows\SysWow64\mssvp.dll
2017-09-08 15:09:57 59392 ----a-w- E:\Windows\SysWow64\msscntrs.dll
2017-09-08 15:09:57 34816 ----a-w- E:\Windows\SysWow64\mssprxy.dll
2017-09-08 15:09:57 337408 ----a-w- E:\Windows\SysWow64\mssph.dll
2017-09-08 15:09:57 197120 ----a-w- E:\Windows\SysWow64\mssphtb.dll
2017-09-08 15:09:57 1400320 ----a-w- E:\Windows\SysWow64\mssrch.dll
2017-09-08 15:09:57 104448 ----a-w- E:\Windows\SysWow64\mssitlb.dll
2017-09-08 15:00:25 3222016 ----a-w- E:\Windows\System32\win32k.sys
2017-09-08 15:00:05 427520 ----a-w- E:\Windows\SysWow64\SearchIndexer.exe
2017-09-08 15:00:01 164352 ----a-w- E:\Windows\SysWow64\SearchProtocolHost.exe
2017-09-08 14:59:28 86528 ----a-w- E:\Windows\SysWow64\SearchFilterHost.exe
2017-09-08 14:59:17 9728 ----a-w- E:\Windows\SysWow64\msshooks.dll
2017-09-08 14:20:51 8704 ----a-w- E:\Windows\SysWow64\msjint40.dll
2017-09-08 14:20:51 640512 ----a-w- E:\Windows\SysWow64\mswstr10.dll
2017-09-08 14:20:50 345088 ----a-w- E:\Windows\SysWow64\msexcl40.dll
2017-09-07 21:38:01 2724864 ----a-w- E:\Windows\System32\mshtml.tlb
2017-09-07 21:37:46 4096 ----a-w- E:\Windows\System32\ieetwcollectorres.dll
2017-09-07 21:19:26 66560 ----a-w- E:\Windows\System32\iesetup.dll
.
============= FINISH: 8:39:59.09 ===============

Attached Files
File Type: rar Attach.rar (2.3 KB)

ESET online scanner found malware

$
0
0
I was doing a normal monthly online scan and found malware.

Windows defender won't turn on now also.

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.15063.608
Run by 93 at 11:52:24 on 2017-10-21
Microsoft Windows 10 Home 10.0.15063.0.1252.1.1033.18.7105.4007 [GMT -7:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes *Enabled/Updated* {23007AD3-69FE-687C-2629-D584AFFAF72B}
SP: Malwarebytes *Enabled/Updated* {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\fontdrvhost.exe
c:\windows\system32\svchost.exe -k dcomlaunch -s PlugPlay
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k dcomlaunch -s LSM
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\System32\WUDFHost.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NcbService
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s hidserv
c:\windows\system32\svchost.exe -k netsvcs -s Schedule
c:\windows\system32\svchost.exe -k netsvcs -s ProfSvc
c:\windows\system32\svchost.exe -k netsvcs -s UserManager
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s EventLog
c:\windows\system32\svchost.exe -k localservice -s nsi
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s TimeBrokerSvc
c:\windows\system32\svchost.exe -k localservice -s EventSystem
c:\windows\system32\svchost.exe -k netsvcs -s Themes
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s Dhcp
c:\windows\system32\svchost.exe -k netsvcs -s SENS
c:\windows\system32\svchost.exe -k networkservice -s NlaSvc
C:\WINDOWS\system32\igfxCUIService.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -s FontCache
c:\windows\system32\svchost.exe -k localservice -s netprofm
c:\windows\system32\svchost.exe -k netsvcs -s Winmgmt
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Program Files\Sandboxie\SbieSvc.exe
c:\windows\system32\svchost.exe -k networkservice -s Dnscache
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe -k appmodel -s StateRepository
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe -k netsvcs -s ShellHWDetection
C:\WINDOWS\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k networkservice -s LanmanWorkstation
c:\windows\system32\svchost.exe -k localservice -s WinHttpAutoProxySvc
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
c:\windows\system32\svchost.exe -k networkservice -s CryptSvc
c:\windows\system32\svchost.exe -k localservicenonetwork -s DPS
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
c:\windows\system32\svchost.exe -k networkservice -s TapiSrv
C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
c:\windows\system32\svchost.exe -k netsvcs -s iphlpsvc
c:\windows\system32\svchost.exe -k netsvcs -s LanmanServer
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s PcaSvc
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SysMain
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TrkWks
c:\windows\system32\svchost.exe -k netsvcs -s WpnService
C:\WINDOWS\system32\fxssvc.exe
c:\windows\system32\svchost.exe -k localservice -s WdiServiceHost
c:\windows\system32\svchost.exe -k appmodel -s tiledatamodelsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DeviceAssociationService
c:\windows\system32\svchost.exe -k localservice -s CDPSvc
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\svchost.exe -k netsvcs -s TokenBroker
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s SSDPSRV
c:\windows\system32\svchost.exe -k netsvcs -s DoSvc
c:\windows\system32\svchost.exe -k netsvcs -s lfsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\windows\system32\svchost.exe -k localservice -s LicenseManager
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s wscsvc
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s StorSvc
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
C:\WINDOWS\system32\dashost.exe
c:\windows\system32\svchost.exe -k netsvcs -s BITS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -s lmhosts
C:\WINDOWS\system32\fontdrvhost.exe
C:\WINDOWS\system32\dwm.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
c:\windows\system32\sihost.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
c:\windows\system32\taskhostw.exe
C:\WINDOWS\system32\igfxEM.exe
C:\WINDOWS\system32\igfxHK.exe
C:\WINDOWS\system32\igfxTray.exe
C:\WINDOWS\Explorer.EXE
c:\windows\system32\svchost.exe -k unistacksvcgroup
C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\Windows Defender\MSASCuiL.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Users\93\AppData\Local\FluxSoftware\Flux\flux.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\Program Files\CCleaner\CCleaner64.exe
C:\Users\93\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\WINDOWS\system32\ApplicationFrameHost.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeHost.exe
c:\windows\system32\svchost.exe -k netsvcs -s Appinfo
C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DsSvc
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Windows\System32\smartscreen.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -s WdiSystemHost
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://www.pugetsystems.com/welcome.php?oid=117561
uLocal Page = %11%\blank.htm
BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
EB: Canon Easy-WebPrint EX: {21347690-EC41-4F9A-8887-1F4AEE672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
uRun: [OneDrive] "C:\Users\93\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
uRun: [f.lux] "C:\Users\93\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
uRun: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
uRun: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
uRunOnce: [Uninstall 17.3.6966.0824\amd64] C:\WINDOWS\System32\cmd.exe /q /c rmdir /s /q "C:\Users\93\AppData\Local\Microsoft\OneDrive\17.3.6966.0824\amd64"
uRunOnce: [Uninstall 17.3.6966.0824] C:\WINDOWS\System32\cmd.exe /q /c rmdir /s /q "C:\Users\93\AppData\Local\Microsoft\OneDrive\17.3.6966.0824"
mRun: [CanonQuickMenu] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: DSCAutomationHostEnabled = dword:2
IE: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.0.1 205.171.3.25
TCP: Interfaces\{dbb5ab4c-4765-46c1-8ced-39aa33d4c16e} : DHCPNameServer = 192.168.0.1 205.171.3.25
TCP: Interfaces\{ef0754b1-f733-49e6-aaff-90432a3d9c36} : DHCPNameServer = 192.168.0.1 205.171.3.25
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
SSODL: WebCheck - <orphaned>
LSA: Security Packages = ""
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
x64-BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
x64-Run: [SecurityHealth] C:\Program Files (x86)\Windows Defender\MSASCuiL.exe
x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
x64-Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
x64-mPolicies-System: DSCAutomationHostEnabled = dword:2
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
x64-mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.62\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
x64-CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\it167470.default\
FF - plugin: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\WINDOWS\System32\Macromed\Flash\NPSWF64_27_0_0_170.dll
.
============= SERVICES / DRIVERS ===============
.
R0 intelpep;Intel(R) Power Engine Plug-in Driver;C:\WINDOWS\System32\drivers\intelpep.sys [2017-3-18 74840]
R0 iorate;Disk I/O Rate Filter Driver;C:\WINDOWS\System32\drivers\iorate.sys [2017-3-18 49568]
R0 volume;Volume driver;C:\WINDOWS\System32\drivers\volume.sys [2017-3-18 16288]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [2017-3-18 70232]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [2017-3-18 18520]
R0 Wof;Windows Overlay File System Filter Driver;C:\WINDOWS\System32\drivers\wof.sys [2017-3-18 208288]
R1 ahcache;Application Compatibility Cache;C:\WINDOWS\System32\drivers\ahcache.sys [2017-3-18 239616]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit;C:\WINDOWS\System32\drivers\mbae64.sys [2017-7-23 77440]
R1 FileCrypt;FileCrypt;C:\WINDOWS\System32\drivers\filecrypt.sys [2017-3-18 54272]
R1 GpuEnergyDrv;GPU Energy Driver;C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2017-3-18 8192]
R1 MpKsl013e1eba;MpKsl013e1eba;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9C17B88B-5A7A-403C-AF17-C1AB4DD1878A}\MpKsl013e1eba.sys [2017-10-13 58120]
R1 MpKsl0becec6c;MpKsl0becec6c;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{24438AFE-BF2F-456E-B4F9-EC5A70711CDD}\MpKsl0becec6c.sys [2017-10-13 58120]
R1 MpKsl0dde1adb;MpKsl0dde1adb;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E3A90663-6AAD-47C2-88C6-DF5146CEB343}\MpKsl0dde1adb.sys [2017-10-11 58120]
R1 MpKsl2114210e;MpKsl2114210e;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{095309E2-92E9-4370-B212-DD8018D2C755}\MpKsl2114210e.sys [2017-10-14 58120]
R1 MpKsl2f680faf;MpKsl2f680faf;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2632593E-2296-45FD-9992-6EF87533DEF6}\MpKsl2f680faf.sys [2017-10-16 58120]
R1 MpKsl4a019c94;MpKsl4a019c94;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E5D8B5CC-EB7B-4B0C-8F9A-9F283AEF6655}\MpKsl4a019c94.sys [2017-10-16 58120]
R1 MpKsl5577933f;MpKsl5577933f;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5F6E261C-60F8-4C8A-9A3D-C6F8F6BEEC97}\MpKsl5577933f.sys [2017-10-19 58120]
R1 MpKsl5b8f605b;MpKsl5b8f605b;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FA7D57E0-B77E-4184-B89E-960E919ED6F4}\MpKsl5b8f605b.sys [2017-10-13 58120]
R1 MpKsl5f721d8e;MpKsl5f721d8e;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{41DAFD85-B896-4F27-917A-C81751E920B4}\MpKsl5f721d8e.sys [2017-10-18 58120]
R1 MpKsl719291b1;MpKsl719291b1;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E132DDAD-B0FF-413F-B8C6-2F4E79C57904}\MpKsl719291b1.sys [2017-10-18 58120]
R1 MpKsl8c42b6b0;MpKsl8c42b6b0;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D38BBEB8-9A6C-4775-8612-FB6A0401E950}\MpKsl8c42b6b0.sys [2017-10-14 58120]
R1 MpKsl9ed82714;MpKsl9ed82714;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3E9637AC-9C01-4D5A-A744-46FA07681841}\MpKsl9ed82714.sys [2017-10-14 58120]
R1 MpKslaa5c3cda;MpKslaa5c3cda;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5F6E261C-60F8-4C8A-9A3D-C6F8F6BEEC97}\MpKslaa5c3cda.sys [2017-10-20 58120]
R1 MpKslac23430e;MpKslac23430e;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BA27733-2719-4D22-AAB2-2FADF7808401}\MpKslac23430e.sys [2017-10-20 58120]
R1 MpKslc46a7c3a;MpKslc46a7c3a;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F7B602DD-D8AC-4858-86AD-31A8335525C2}\MpKslc46a7c3a.sys [2017-10-19 58120]
R1 MpKslc523f3f5;MpKslc523f3f5;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3E9637AC-9C01-4D5A-A744-46FA07681841}\MpKslc523f3f5.sys [2017-10-14 58120]
R1 MpKsld8bd337a;MpKsld8bd337a;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E465A86C-8691-45FC-8B0D-CD1A6E309E21}\MpKsld8bd337a.sys [2017-10-20 58120]
R1 MpKsldeacfa6c;MpKsldeacfa6c;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6CD12840-A6F9-457B-8AFF-1CFEEA259D3B}\MpKsldeacfa6c.sys [2017-10-19 58120]
R1 MpKslfc82725d;MpKslfc82725d;C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6CD12840-A6F9-457B-8AFF-1CFEEA259D3B}\MpKslfc82725d.sys [2017-10-18 58120]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2017-9-7 83768]
R2 asComSvc;ASUS Com Service;C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [2017-9-14 936728]
R2 CDPSvc;Connected Devices Platform Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
R2 CDPUserSvc_1bcc4d4;Connected Devices Platform User Service_1bcc4d4;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R2 clreg;Virtual Registry for Containers;C:\WINDOWS\System32\drivers\registry.sys [2017-3-18 14336]
R2 CoreMessagingRegistrar;CoreMessaging;C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork [2017-3-18 47664]
R2 DiagTrack;Connected User Experiences and Telemetry;C:\WINDOWS\System32\svchost.exe -k utcsvc [2017-3-18 47664]
R2 DoSvc;Delivery Optimization;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R2 DusmSvc;Data Usage;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
R2 igfxCUIService2.0.0.0;Intel(R) HD Graphics Control Panel Service;C:\WINDOWS\System32\igfxCUIService.exe [2016-11-1 373744]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2015-6-24 223008]
R2 MBAMChameleon;MBAMChameleon;C:\WINDOWS\System32\drivers\MbamChameleon.sys [2017-10-14 192952]
R2 MBAMService;Malwarebytes Service;C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [2017-7-23 6058960]
R2 OneSyncSvc_1bcc4d4;Sync Host_1bcc4d4;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R2 SecurityHealthService;Windows Defender Security Center Service;C:\WINDOWS\System32\SecurityHealthService.exe [2017-10-11 336320]
R2 storqosflt;Storage QoS Filter Driver;C:\WINDOWS\System32\drivers\storqosflt.sys [2017-3-18 79872]
R2 tiledatamodelsvc;Tile Data model server;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
R2 UserManager;User Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R2 wcifs;Windows Container Isolation;C:\WINDOWS\System32\drivers\wcifs.sys [2017-7-10 142752]
R2 WpnService;Windows Push Notifications System Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R2 WpnUserService_1bcc4d4;Windows Push Notifications User Service_1bcc4d4;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R3 DsSvc;Data Sharing Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
R3 e1dexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver D;C:\WINDOWS\System32\drivers\e1d62x64.sys [2017-4-25 534512]
R3 Intel(R) Security Assist;Intel(R) Security Assist;C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [2015-5-19 335872]
R3 lfsvc;Geolocation Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R3 LicenseManager;Windows License Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
R3 MBAMFarflt;MBAMFarflt;C:\WINDOWS\System32\drivers\farflt.sys [2017-10-14 110016]
R3 MBAMProtection;MBAMProtection;C:\WINDOWS\System32\drivers\mbam.sys [2017-10-14 45504]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2017-10-14 252232]
R3 MBAMWebProtection;MBAMWebProtection;C:\WINDOWS\System32\drivers\mwac.sys [2017-10-14 94144]
R3 NcbService;Network Connection Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [2017-3-18 20992]
R3 PimIndexMaintenanceSvc_1bcc4d4;Contact Data_1bcc4d4;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2017-6-5 207496]
R3 StateRepository;State Repository Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
R3 TimeBrokerSvc;Time Broker;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
R3 TokenBroker;TokenBroker;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R3 UnistoreSvc_1bcc4d4;User Data Storage_1bcc4d4;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R3 UserDataSvc_1bcc4d4;User Data Access_1bcc4d4;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\drivers\WUDFRd.sys [2017-3-18 220672]
S2 CldFlt;Windows Cloud Files Filter Driver;C:\WINDOWS\System32\drivers\cldflt.sys [2017-3-18 12288]
S2 isaHelperSvc;Intel(R) Security Assist Helper;C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [2015-5-19 7680]
S2 MapsBroker;Downloaded Maps Manager;C:\WINDOWS\System32\svchost.exe -k NetworkService [2017-3-18 47664]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-7-18 317408]
S3 AcpiDev;ACPI Devices driver;C:\WINDOWS\System32\drivers\AcpiDev.sys [2017-3-18 20480]
S3 ADP80XX;ADP80XX;C:\WINDOWS\System32\drivers\adp80xx.sys [2017-3-18 1135512]
S3 AJRouter;AllJoyn Router Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 applockerfltr;Smartlocker Filter Driver;C:\WINDOWS\System32\drivers\applockerfltr.sys [2017-3-18 17920]
S3 AppReadiness;App Readiness;C:\WINDOWS\System32\svchost.exe -k AppReadiness [2017-3-18 47664]
S3 AppXSvc;AppX Deployment Service (AppXSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2017-3-18 47664]
S3 bcmfn2;bcmfn2 Service;C:\WINDOWS\System32\drivers\bcmfn2.sys [2017-3-18 9728]
S3 BthHFSrv;Bluetooth Handsfree Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation [2017-3-18 47664]
S3 buttonconverter;Service for Portable Device Control devices;C:\WINDOWS\System32\drivers\buttonconverter.sys [2017-9-14 39424]
S3 CAD;Charge Arbitration Driver;C:\WINDOWS\System32\drivers\CAD.sys [2017-3-18 53664]
S3 CapImg;HID driver for CapImg touch screen;C:\WINDOWS\System32\drivers\capimg.sys [2017-3-18 122880]
S3 cht4iscsi;cht4iscsi;C:\WINDOWS\System32\drivers\cht4sx64.sys [2017-3-18 347032]
S3 cht4vbd;Chelsio Virtual Bus Driver;C:\WINDOWS\System32\drivers\cht4vx64.sys [2017-3-18 2104224]
S3 ClipSVC;Client License Service (ClipSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2017-3-18 47664]
S3 DevicesFlowUserSvc_1bcc4d4;DevicesFlow_1bcc4d4;C:\WINDOWS\System32\svchost.exe -k DevicesFlow [2017-3-18 47664]
S3 DevQueryBroker;DevQuery Background Discovery Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 diagnosticshub.standardcollector.service;Microsoft (R) Diagnostics Hub Standard Collector Service;C:\WINDOWS\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2017-3-18 86528]
S3 DmEnrollmentSvc;Device Management Enrollment Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 dmwappushservice;dmwappushsvc;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 embeddedmode;Embedded Mode;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 EntAppSvc;Enterprise App Management Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
S3 FrameServer;Windows Camera Frame Server;C:\WINDOWS\System32\svchost.exe -k Camera [2017-3-18 47664]
S3 genericusbfn;Generic USB Function Class;C:\WINDOWS\System32\drivers\genericusbfn.sys [2017-3-18 21504]
S3 hidinterrupt;Common Driver for HID Buttons implemented with interrupts;C:\WINDOWS\System32\drivers\hidinterrupt.sys [2017-3-18 51104]
S3 HvHost;HV Host Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 iagpio;Intel Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iagpio.sys [2017-3-18 33280]
S3 iai2c;Intel(R) Serial IO I2C Host Controller;C:\WINDOWS\System32\drivers\iai2c.sys [2017-3-18 81408]
S3 iaLPSS2i_GPIO2;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2017-3-18 70656]
S3 iaLPSS2i_GPIO2_BXT_P;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2017-3-18 85504]
S3 iaLPSS2i_I2C;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2017-3-18 165376]
S3 iaLPSS2i_I2C_BXT_P;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2017-3-18 168448]
S3 iaLPSSi_GPIO;Intel(R) Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [2017-3-18 38128]
S3 iaLPSSi_I2C;Intel(R) Serial IO I2C Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [2017-3-18 113152]
S3 iaStorAV;Intel(R) SATA RAID Controller Windows;C:\WINDOWS\System32\drivers\iaStorAV.sys [2017-3-18 673184]
S3 ibbus;Mellanox InfiniBand Bus/AL (Filter Driver);C:\WINDOWS\System32\drivers\ibbus.sys [2017-3-18 526240]
S3 icssvc;Windows Mobile Hotspot Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 IndirectKmd;Indirect Displays Kernel-Mode Driver;C:\WINDOWS\System32\drivers\IndirectKmd.sys [2017-3-18 36864]
S3 IntcDAud;Intel(R) Display Audio;C:\WINDOWS\System32\drivers\IntcDAud.sys [2016-5-12 481768]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2015-5-22 881152]
S3 IpxlatCfgSvc;IP Translation Configuration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 LSI_SAS2i;LSI_SAS2i;C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2017-3-18 123808]
S3 LSI_SAS3i;LSI_SAS3i;C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2017-3-18 103328]
S3 mausbhost;MA-USB Host Controller Driver;C:\WINDOWS\System32\drivers\mausbhost.sys [2017-3-18 405408]
S3 mausbip;MA-USB IP Filter Driver;C:\WINDOWS\System32\drivers\mausbip.sys [2017-3-18 51104]
S3 megasas2i;megasas2i;C:\WINDOWS\System32\drivers\MegaSas2i.sys [2017-3-18 64416]
S3 MessagingService_1bcc4d4;MessagingService_1bcc4d4;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-3-18 47664]
S3 mlx4_bus;Mellanox ConnectX Bus Enumerator;C:\WINDOWS\System32\drivers\mlx4_bus.sys [2017-3-18 842656]
S3 NaturalAuthentication;Natural Authentication;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 ndfltr;NetworkDirect Service;C:\WINDOWS\System32\drivers\ndfltr.sys [2017-3-18 108960]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library;C:\WINDOWS\System32\drivers\NetAdapterCx.sys [2017-3-18 122368]
S3 NetSetupSvc;Network Setup Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 netvsc;netvsc;C:\WINDOWS\System32\drivers\netvsc.sys [2017-7-10 118784]
S3 NgcCtnrSvc;Microsoft Passport Container;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 NgcSvc;Microsoft Passport;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 nvdimmn;Microsoft NVDIMM-N device driver;C:\WINDOWS\System32\drivers\nvdimmn.sys [2017-3-18 80896]
S3 percsas2i;percsas2i;C:\WINDOWS\System32\drivers\percsas2i.sys [2017-3-18 58784]
S3 percsas3i;percsas3i;C:\WINDOWS\System32\drivers\percsas3i.sys [2017-3-18 61848]
S3 PhoneSvc;Phone Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 ReFS;ReFS;C:\WINDOWS\System32\drivers\refs.sys [2017-3-18 1735584]
S3 ReFSv1;ReFSv1;C:\WINDOWS\System32\drivers\refsv1.sys [2017-3-18 936864]
S3 RetailDemo;Retail Demo Service;C:\WINDOWS\System32\svchost.exe -k rdxgroup [2017-3-18 47664]
S3 RtlWlanu;Realtek Wireless LAN 802.11n USB 2.0 Network Adapter;C:\WINDOWS\System32\drivers\rtwlanu.sys [2017-3-18 5707264]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 scmbus;Microsoft Storage Class Memory Bus Driver;C:\WINDOWS\System32\drivers\scmbus.sys [2017-3-18 91040]
S3 SDFRd;SDF Reflector;C:\WINDOWS\System32\drivers\SDFRd.sys [2017-3-18 31128]
S3 SEMgrSvc;Payments and NFC/SE Manager;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 SensorDataService;Sensor Data Service;C:\WINDOWS\System32\SensorDataService.exe [2017-3-18 1284608]
S3 SensorService;Sensor Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 SerCx2;Serial UART Support Library;C:\WINDOWS\System32\drivers\SerCx2.sys [2017-3-18 154016]
S3 smphost;Microsoft Storage Spaces SMP;C:\WINDOWS\System32\svchost.exe -k smphost [2017-3-18 47664]
S3 SmsRouter;Microsoft Windows SMS Router Service.;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 SpatialGraphFilter;Holographic Spatial Graph Filter;C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [2017-3-18 40352]
S3 spectrum;Windows Perception Service;C:\WINDOWS\System32\Spectrum.exe [2017-3-18 891904]
S3 stornvme;Microsoft Standard NVM Express Driver;C:\WINDOWS\System32\drivers\stornvme.sys [2017-3-18 95648]
S3 storufs;Microsoft Universal Flash Storage (UFS) Driver;C:\WINDOWS\System32\drivers\storufs.sys [2017-3-18 36760]
S3 TieringEngineService;Storage Tiers Management;C:\WINDOWS\System32\TieringEngineService.exe [2017-3-18 302592]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmCx.sys [2017-9-14 104960]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmTcpciCx.sys [2017-3-18 179200]
S3 UcmUcsi;USB Connector Manager UCSI Client;C:\WINDOWS\System32\drivers\UcmUcsi.sys [2017-9-14 51712]
S3 UdeCx;USB Device Emulation Support Library;C:\WINDOWS\System32\drivers\Udecx.sys [2017-3-18 45568]
S3 UEFI;Microsoft UEFI Driver;C:\WINDOWS\System32\drivers\uefi.sys [2017-3-18 29600]
S3 Ufx01000;USB Function Class Extension;C:\WINDOWS\System32\drivers\ufx01000.sys [2017-3-18 263584]
S3 UfxChipidea;USB Chipidea Controller;C:\WINDOWS\System32\drivers\UfxChipidea.sys [2017-3-18 98712]
S3 ufxsynopsys;USB Synopsys Controller;C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2017-3-18 138656]
S3 UrsChipidea;Chipidea USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urschipidea.sys [2017-3-18 29600]
S3 UrsCx01000;USB Role-Switch Support Library;C:\WINDOWS\System32\drivers\urscx01000.sys [2017-3-18 59288]
S3 UrsSynopsys;Synopsys USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urssynopsys.sys [2017-3-18 28064]
S3 UsoSvc;Update Orchestrator Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 vhf;Virtual HID Framework (VHF) Driver;C:\WINDOWS\System32\drivers\vhf.sys [2017-3-18 35328]
S3 vmgid;Microsoft Hyper-V Guest Infrastructure Driver;C:\WINDOWS\System32\drivers\vmgid.sys [2017-3-18 10240]
S3 vmicguestinterface;Hyper-V Guest Service Interface;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 vmicvmsession;Hyper-V PowerShell Direct Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 WalletService;WalletService;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
S3 wcnfs;Windows Container Name Virtualization;C:\WINDOWS\System32\drivers\wcnfs.sys [2017-3-18 72192]
S3 wdiwifi;WDI Driver Framework;C:\WINDOWS\System32\drivers\WdiWiFi.sys [2017-7-10 757248]
S3 WdNisDrv;Windows Defender Antivirus Network Inspection System Driver;C:\WINDOWS\System32\drivers\WdNisDrv.sys [2017-3-18 121248]
S3 WdNisSvc;Windows Defender Antivirus Network Inspection Service;C:\Program Files\Windows Defender\NisSrv.exe [2017-3-18 342264]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;C:\WINDOWS\System32\svchost.exe -k WepHostSvcGroup [2017-3-18 47664]
S3 WFDSConMgrSvc;Wi-Fi Direct Services Connection Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 WinMad;WinMad Service;C:\WINDOWS\System32\drivers\winmad.sys [2017-3-18 32160]
S3 WinNat;Windows NAT Driver;C:\WINDOWS\System32\drivers\winnat.sys [2017-3-18 217088]
S3 WinVerbs;WinVerbs Service;C:\WINDOWS\System32\drivers\winverbs.sys [2017-3-18 64920]
S3 wisvc;Windows Insider Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 wlpasvc;LPA Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 workfolderssvc;Work Folders;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 xbgm;Xbox Game Monitoring;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 XblAuthManager;Xbox Live Auth Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 XblGameSave;Xbox Live Game Save;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 xboxgip;Xbox Game Input Protocol Driver;C:\WINDOWS\System32\drivers\xboxgip.sys [2017-7-10 277504]
S3 XboxGipSvc;Xbox Accessory Management Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 XboxNetApiSvc;Xbox Live Networking Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 xinputhid;XINPUT HID Filter Driver;C:\WINDOWS\System32\drivers\xinputhid.sys [2017-3-18 46592]
S4 shpamsvc;Shared PC Account Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S4 tzautoupdate;Auto Time Zone Updater;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\WINDOWS\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2017-10-21 14:45:47 13890840 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9FD3F768-0149-4600-A98D-2FEED3FE3895}\mpengine.dll
2017-10-21 13:13:54 13890840 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2017-10-20 20:59:23 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BA27733-2719-4D22-AAB2-2FADF7808401}\MpKslac23430e.sys
2017-10-20 12:22:19 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E465A86C-8691-45FC-8B0D-CD1A6E309E21}\MpKsld8bd337a.sys
2017-10-20 10:05:05 58120 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5F6E261C-60F8-4C8A-9A3D-C6F8F6BEEC97}\MpKslaa5c3cda.sys
2017-10-19 20:31:57 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5F6E261C-60F8-4C8A-9A3D-C6F8F6BEEC97}\MpKsl5577933f.sys
2017-10-19 13:33:05 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F7B602DD-D8AC-4858-86AD-31A8335525C2}\MpKslc46a7c3a.sys
2017-10-19 12:10:52 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6CD12840-A6F9-457B-8AFF-1CFEEA259D3B}\MpKsldeacfa6c.sys
2017-10-18 20:20:31 58120 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6CD12840-A6F9-457B-8AFF-1CFEEA259D3B}\MpKslfc82725d.sys
2017-10-18 14:27:38 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{41DAFD85-B896-4F27-917A-C81751E920B4}\MpKsl5f721d8e.sys
2017-10-18 12:24:12 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E132DDAD-B0FF-413F-B8C6-2F4E79C57904}\MpKsl719291b1.sys
2017-10-17 05:43:27 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E5D8B5CC-EB7B-4B0C-8F9A-9F283AEF6655}\MpKsl4a019c94.sys
2017-10-17 00:40:30 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2632593E-2296-45FD-9992-6EF87533DEF6}\MpKsl2f680faf.sys
2017-10-14 23:59:54 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{095309E2-92E9-4370-B212-DD8018D2C755}\MpKsl2114210e.sys
2017-10-14 23:50:59 58120 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3E9637AC-9C01-4D5A-A744-46FA07681841}\MpKslc523f3f5.sys
2017-10-14 21:27:17 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3E9637AC-9C01-4D5A-A744-46FA07681841}\MpKsl9ed82714.sys
2017-10-14 13:40:57 192952 ----a-w- C:\WINDOWS\System32\drivers\MbamChameleon.sys
2017-10-14 13:40:56 94144 ----a-w- C:\WINDOWS\System32\drivers\mwac.sys
2017-10-14 13:40:56 110016 ----a-w- C:\WINDOWS\System32\drivers\farflt.sys
2017-10-14 13:40:53 45504 ----a-w- C:\WINDOWS\System32\drivers\mbam.sys
2017-10-14 13:40:50 252232 ----a-w- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
2017-10-14 12:55:09 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D38BBEB8-9A6C-4775-8612-FB6A0401E950}\MpKsl8c42b6b0.sys
2017-10-14 02:47:56 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{24438AFE-BF2F-456E-B4F9-EC5A70711CDD}\MpKsl0becec6c.sys
2017-10-13 19:49:01 18896 ----a-w- C:\Program Files (x86)\Mozilla Firefox\qipcap64.dll
2017-10-13 13:52:30 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9C17B88B-5A7A-403C-AF17-C1AB4DD1878A}\MpKsl013e1eba.sys
2017-10-13 07:49:27 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FA7D57E0-B77E-4184-B89E-960E919ED6F4}\MpKsl5b8f605b.sys
2017-10-11 21:04:36 58120 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E3A90663-6AAD-47C2-88C6-DF5146CEB343}\MpKsl0dde1adb.sys
2017-10-11 12:30:59 126925120 -c--a-w- C:\WINDOWS\System32\MRT-KB890830.exe
2017-10-11 12:05:26 5304496 ----a-w- C:\WINDOWS\System32\Windows.StateRepository.dll
2017-10-11 12:04:59 8333312 ----a-w- C:\WINDOWS\System32\BingMaps.dll
2017-09-29 03:19:52 1057976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9124BC07-F8E7-414E-95EF-0E0CE6E41FEE}\gapaengine.dll
2017-09-25 17:34:36 -------- d-----w- C:\Program Files\iPod
2017-09-25 17:34:05 -------- d---a-w- C:\Program Files\iTunes
.
==================== Find3M ====================
.
2017-10-21 17:12:16 180 ----a-w- C:\WINDOWS\System32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-10-13 00:21:46 835576 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2017-10-13 00:21:46 177656 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2017-10-11 13:46:23 230400 ----a-w- C:\WINDOWS\System32\msclmd.dll
2017-10-11 13:46:23 207872 ----a-w- C:\WINDOWS\SysWow64\msclmd.dll
2017-10-04 20:15:42 77440 ----a-w- C:\WINDOWS\System32\drivers\mbae64.sys
2017-09-30 05:52:01 1595152 ----a-w- C:\WINDOWS\System32\gdi32full.dll
2017-09-30 05:51:44 1458320 ----a-w- C:\WINDOWS\System32\msctf.dll
2017-09-30 05:51:12 1147288 ----a-w- C:\WINDOWS\System32\hvix64.exe
2017-09-30 05:50:48 1068208 ----a-w- C:\WINDOWS\System32\Windows.UI.dll
2017-09-30 05:50:46 1024920 ----a-w- C:\WINDOWS\System32\hvax64.exe
2017-09-30 05:50:44 1346112 ----a-w- C:\WINDOWS\System32\user32.dll
2017-09-30 05:49:44 777400 ----a-w- C:\WINDOWS\System32\oleaut32.dll
2017-09-30 05:49:27 135576 ----a-w- C:\WINDOWS\System32\drivers\ksecdd.sys
2017-09-30 05:49:25 1004136 ----a-w- C:\WINDOWS\System32\ucrtbase.dll
2017-09-30 05:48:27 644696 ----a-w- C:\WINDOWS\System32\advapi32.dll
2017-09-30 05:48:26 2399728 ----a-w- C:\WINDOWS\System32\KernelBase.dll
2017-09-30 05:48:12 8319384 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2017-09-30 05:48:04 2327448 ----a-w- C:\WINDOWS\System32\drivers\ntfs.sys
2017-09-30 05:47:28 1194792 ----a-w- C:\WINDOWS\System32\rpcrt4.dll
2017-09-30 05:47:05 2969880 ----a-w- C:\WINDOWS\System32\CoreUIComponents.dll
2017-09-30 05:45:54 511896 ----a-w- C:\WINDOWS\System32\drivers\usbhub.sys
2017-09-30 05:44:52 181912 ----a-w- C:\WINDOWS\System32\sspicli.dll
2017-09-30 05:44:03 712600 ----a-w- C:\WINDOWS\System32\drivers\dxgmms2.sys
2017-09-30 05:43:49 2442136 ----a-w- C:\WINDOWS\System32\drivers\dxgkrnl.sys
2017-09-30 05:43:47 7318888 ----a-w- C:\WINDOWS\System32\windows.storage.dll
2017-09-30 05:42:43 4848952 ----a-w- C:\WINDOWS\explorer.exe
2017-09-30 05:42:08 1506712 ----a-w- C:\WINDOWS\System32\twinapi.appcore.dll
2017-09-30 05:42:03 820120 ----a-w- C:\WINDOWS\System32\WWAHost.exe
2017-09-30 05:41:48 259400 ----a-w- C:\WINDOWS\System32\MusNotifyIcon.exe
2017-09-30 05:41:48 228248 ----a-w- C:\WINDOWS\System32\drivers\mrxsmb20.sys
2017-09-30 05:41:47 961944 ----a-w- C:\WINDOWS\System32\efscore.dll
2017-09-30 05:41:45 651672 ----a-w- C:\WINDOWS\System32\SettingSyncHost.exe
2017-09-30 05:41:44 5477600 ----a-w- C:\WINDOWS\System32\OneCoreUAPCommonProxyStub.dll
2017-09-30 05:41:35 257432 ----a-w- C:\WINDOWS\System32\AppxAllUserStore.dll
2017-09-30 05:41:11 654976 ----a-w- C:\WINDOWS\System32\AppXDeploymentClient.dll
2017-09-30 05:41:00 2086808 ----a-w- C:\WINDOWS\System32\UpdateAgent.dll
2017-09-30 05:40:49 642680 ----a-w- C:\WINDOWS\System32\drivers\cng.sys
2017-09-30 05:40:45 184728 ----a-w- C:\WINDOWS\System32\drivers\appid.sys
2017-09-30 05:40:44 724704 ----a-w- C:\WINDOWS\System32\wer.dll
2017-09-30 05:40:38 336320 ----a-w- C:\WINDOWS\System32\SecurityHealthService.exe
2017-09-30 05:40:33 408984 ----a-w- C:\WINDOWS\System32\msv1_0.dll
2017-09-30 05:40:29 72944 ----a-w- C:\WINDOWS\System32\easinvoker.exe
2017-09-30 05:40:13 558912 ----a-w- C:\WINDOWS\System32\Windows.ApplicationModel.dll
2017-09-30 05:40:03 173976 ----a-w- C:\WINDOWS\System32\drivers\usbccgp.sys
2017-09-30 05:39:45 203672 ----a-w- C:\WINDOWS\System32\basecsp.dll
2017-09-30 05:38:42 2239136 ----a-w- C:\WINDOWS\System32\mfsrcsnk.dll
2017-09-30 05:38:33 7910072 ----a-w- C:\WINDOWS\System32\Windows.Media.Protection.PlayReady.dll
2017-09-30 05:36:38 2672024 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2017-09-30 05:36:28 57976 ----a-w- C:\WINDOWS\System32\lsass.exe
2017-09-30 02:29:54 1408536 ----a-w- C:\WINDOWS\SysWow64\gdi32full.dll
2017-09-30 02:29:46 804784 ----a-w- C:\WINDOWS\SysWow64\Windows.UI.dll
2017-09-30 02:26:30 1292872 ----a-w- C:\WINDOWS\SysWow64\user32.dll
2017-09-30 02:26:24 1333136 ----a-w- C:\WINDOWS\SysWow64\msctf.dll
2017-09-30 02:10:34 480920 ----a-w- C:\WINDOWS\SysWow64\advapi32.dll
2017-09-30 02:10:20 606072 ----a-w- C:\WINDOWS\SysWow64\oleaut32.dll
2017-09-30 02:10:14 1839872 ----a-w- C:\WINDOWS\SysWow64\KernelBase.dll
2017-09-30 02:10:08 1150776 ----a-w- C:\WINDOWS\SysWow64\ucrtbase.dll
2017-09-30 02:09:16 2259760 ----a-w- C:\WINDOWS\SysWow64\CoreUIComponents.dll
2017-09-30 02:09:02 787712 ----a-w- C:\WINDOWS\SysWow64\rpcrt4.dll
2017-09-30 02:06:28 4471368 ----a-w- C:\WINDOWS\SysWow64\explorer.exe
2017-09-30 02:05:47 750488 ----a-w- C:\WINDOWS\SysWow64\WWAHost.exe
2017-09-30 02:05:45 5827744 ----a-w- C:\WINDOWS\SysWow64\windows.storage.dll
2017-09-30 02:05:39 559000 ----a-w- C:\WINDOWS\SysWow64\SettingSyncHost.exe
2017-09-30 02:05:36 1266544 ----a-w- C:\WINDOWS\SysWow64\twinapi.appcore.dll
2017-09-30 02:05:34 2603744 ----a-w- C:\WINDOWS\SysWow64\OneCoreUAPCommonProxyStub.dll
2017-09-30 02:04:52 612120 ----a-w- C:\WINDOWS\SysWow64\wer.dll
2017-09-30 02:04:50 4215184 ----a-w- C:\WINDOWS\SysWow64\Windows.StateRepository.dll
2017-09-30 02:04:45 347544 ----a-w- C:\WINDOWS\SysWow64\msv1_0.dll
2017-09-30 02:04:39 438096 ----a-w- C:\WINDOWS\SysWow64\Windows.ApplicationModel.dll
2017-09-30 02:04:17 519680 ----a-w- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
2017-09-30 02:04:13 182680 ----a-w- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
2017-09-30 02:03:27 6768288 ----a-w- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
2017-09-30 02:03:17 1439032 ----a-w- C:\WINDOWS\SysWow64\mfsrcsnk.dll
2017-09-30 02:02:53 175512 ----a-w- C:\WINDOWS\SysWow64\basecsp.dll
2017-09-30 02:01:54 124544 ----a-w- C:\WINDOWS\SysWow64\sspicli.dll
2017-09-29 07:46:30 23678976 ----a-w- C:\WINDOWS\System32\edgehtml.dll
2017-09-29 07:45:00 2953216 ----a-w- C:\WINDOWS\SysWow64\win32kfull.sys
2017-09-29 07:44:19 133120 ----a-w- C:\WINDOWS\SysWow64\t2embed.dll
2017-09-29 07:43:14 2199552 ----a-w- C:\WINDOWS\SysWow64\Windows.UI.Xaml.Resources.dll
2017-09-29 07:43:07 142336 ----a-w- C:\WINDOWS\SysWow64\smartscreenps.dll
2017-09-29 07:43:05 60928 ----a-w- C:\WINDOWS\SysWow64\usoapi.dll
2017-09-29 07:42:56 18944 ----a-w- C:\WINDOWS\SysWow64\mgmtapi.dll
2017-09-29 07:41:56 13844992 ----a-w- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
2017-09-29 07:41:50 50176 ----a-w- C:\WINDOWS\SysWow64\wbem\Win32_Tpm.dll
2017-09-29 07:41:09 110080 ----a-w- C:\WINDOWS\SysWow64\BitLockerCsp.dll
2017-09-29 07:40:57 6728192 ----a-w- C:\WINDOWS\SysWow64\twinui.dll
2017-09-29 07:40:50 371200 ----a-w- C:\WINDOWS\SysWow64\daxexec.dll
2017-09-29 07:40:25 86528 ----a-w- C:\WINDOWS\SysWow64\updatepolicy.dll
2017-09-29 07:39:51 364032 ----a-w- C:\WINDOWS\SysWow64\msIso.dll
2017-09-29 07:39:01 20511232 ----a-w- C:\WINDOWS\SysWow64\edgehtml.dll
2017-09-29 07:38:55 471040 ----a-w- C:\WINDOWS\SysWow64\TpmCoreProvisioning.dll
2017-09-29 07:38:51 229376 ----a-w- C:\WINDOWS\SysWow64\scksp.dll
2017-09-29 07:38:35 1135616 ----a-r- C:\WINDOWS\SysWow64\icuuc.dll
2017-09-29 07:38:18 2671616 ----a-w- C:\WINDOWS\SysWow64\tquery.dll
2017-09-29 07:38:15 370688 ----a-w- C:\WINDOWS\SysWow64\FirewallAPI.dll
2017-09-29 07:38:11 463360 ----a-w- C:\WINDOWS\SysWow64\webio.dll
2017-09-29 07:38:03 5721600 ----a-w- C:\WINDOWS\SysWow64\BingMaps.dll
2017-09-29 07:38:03 308224 ----a-w- C:\WINDOWS\SysWow64\cryptngc.dll
2017-09-29 07:37:45 306688 ----a-w- C:\WINDOWS\SysWow64\Windows.Graphics.dll
.
============= FINISH: 11:53:09.68 ===============

Attached Thumbnails
Click image for larger version

Name:	malware found.jpg
Views:	N/A
Size:	83.3 KB
ID:	314697  
Attached Files
File Type: txt attach.txt (9.1 KB)
File Type: txt malware found 21 october 2017.txt (438 Bytes)

exe opens in notepad

$
0
0
exe opens in notepad
Just as the title says.
I have tried:

https://support.microsoft.com/en-us/...a-or-windows-7

and downloaded the default.exe, right click, merge

Neither one helped.
I am logged in as an admin on my computer
Thx< Dave
:banghead:


DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 11.151.2
Run by DaveThomas at 14:24:48 on 2017-10-21
.
============== Running Processes ================
.
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Program Files (x86)\Stardock\Object Desktop\WindowFX4\WindowFXSRV.exe
C:\Program Files (x86)\Stardock\Object Desktop\WindowFX4\WFX32.exe
C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
C:\Program Files (x86)\Origin\OriginWebHelperService.exe
C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
C:\Windows\system32\PnkBstrA.exe
c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe
C:\Program Files (x86)\Razer\Naga\RazerNagaSysTray.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files (x86)\Common Files\SNP2UVC\tsnp2uvc.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Tablet\Wacom\WacomHost.exe
C:\Program Files (x86)\Overwolf\Overwolf.exe
C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
C:\Program Files\Logitech Gaming Software\Applets\LCDPop3.exe
C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
C:\Program Files (x86)\Overwolf\0.107.254.0\OverwolfBrowser.exe
C:\Program Files (x86)\Common Files\Overwolf\0.107.254.0\OverwolfHelper.exe
C:\Program Files (x86)\Overwolf\0.107.254.0\OverwolfBrowser.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
.
============== Pseudo HJT Report ===============
.
BHO: AutorunsDisabled - <orphaned>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll
uRun: [Overwolf] "C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe" -overwolfsilent
uRun: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
mRun: [Razer Naga Driver] C:\Program Files (x86)\Razer\Naga\RazerNagaSysTray.exe
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [AvgUi] "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
mRun: [TkBellExe] "C:\Program Files (x86)\Real\realplayer\update\realsched.exe" -osboot
mRun: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
mRun: [SPIRunE] Rundll32 SPIRunE.dll,RunDLLEntry
mRun: [snp2uvc] C:\Windows\vsnp2uvc.exe
mRun: [tsnp2uvc] C:\Program Files (x86)\Common Files\SNP2UVC\tsnp2uvc.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: DisableThumbnails = dword:0
uPolicies-Explorer: DisableThumbnailsOnNetworkFolders = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
mPolicies-System: SoftwareSASGeneration = dword:1
DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://i.dell.com/images/global/js/scanner/SysProExe.cab
DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_144-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0071-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_71-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-00144-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_144-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_144-windows-i586.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{E72235FA-EBC4-4094-B2B5-7E8281242C39} : DHCPNameServer = 75.75.75.75 75.75.76.76
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - <orphaned>
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - <orphaned>
Handler: vipresg - {47BE2E5B-703B-444F-ABD3-05717D2191C6} - <orphaned>
Notify: WBSrv - C:\PROGRA~2\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - C:\PROGRA~2\COMMON~1\Stardock\mcpcore.dll
SSODL: WebCheck - <orphaned>
SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - C:\Program Files (x86)\Stardock\Object Desktop\IconPackager\iprepair.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
x64-BHO: AutorunsDisabled - <orphaned>
x64-Run: [Thermal Controller] "C:\Program Files\Alienware\Command Center\ThermalController.exe" /auto
x64-Run: [MacDrive 8 application for Digidesign] "C:\Program Files\Mediafour\MacDrive 8\MacDriveD.exe"
x64-Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe /minimized
x64-Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
x64-Run: [AlienFX Controller] "C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe"
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [AvgUi] "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
x64-Run: [AVGUI.exe] "C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe" /gui
x64-Run: [DigidesignMMERefresh] C:\Program Files\Avid\Pro Tools First\MMERefresh.exe
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
x64-DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
x64-Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - <orphaned>
x64-Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - <orphaned>
x64-Handler: vipresg - {47BE2E5B-703B-444F-ABD3-05717D2191C6} - <orphaned>
x64-Notify: WB - <no file>
x64-SSODL: WebCheck - <orphaned>
x64-STS: {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - <orphaned>
x64-STS: FencesShlExt Class - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll
x64-mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.100\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\DaveThomas\AppData\Roaming\Mozilla\Firefox\Profiles\09ad09mm.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.zbrushcentral.com/forumdisplay.php?101-ZBrush-Questions-and-Troubleshooting-Forum
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll
FF - plugin: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll
FF - plugin: C:\Windows\System32\Macromed\Flash\NPSWF64_27_0_0_130.dll
FF - plugin: C:\Windows\System32\npDeployJava1.dll
FF - plugin: C:\Windows\System32\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R? androidusb;ADB Interface Driver
R? AtiHDAudioService;AMD Function Driver for HD Audio Service
R? avgbdisk;avgbdisk
R? avgbIDSAgent;avgbIDSAgent
R? avgbidsdriver;avgbidsdriver
R? avgbidsh;avgbidsh
R? avgblog;avgblog
R? avgbuniv;avgbuniv
R? avgHwid;avgHwid
R? avgRdr;avgRdr
R? avgSnx;avgSnx
R? avgStm;avgStm
R? avgVmm;avgVmm
R? cfwids;McAfee Inc. cfwids
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64
R? cpudrv64;cpudrv64
R? cpuz134;cpuz134
R? cpuz137;cpuz137
R? Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service
R? Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service
R? Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service
R? DDDriver;DDDriver
R? DellDataVault;Dell Data Vault
R? DellProf;DellProf
R? digiSPTIService64;digiSPTIService64
R? ElRawDisk;ElRawDisk
R? FLEXnet Licensing Service 64;FLEXnet Licensing Service 64
R? hidkmdf;KMDF Driver
R? HTCAND64;HTC Device Driver
R? htcnprot;HTC NDIS Protocol Driver
R? IEEtwCollectorService;Internet Explorer ETW Collector Service
R? L6PODLV;PODxt Live Service
R? massfilter_hs;HS HandSet Mass Storage Filter Driver
R? MBAMService;MBAMService
R? MBAMWebAccessControl;MBAMWebAccessControl
R? McShield;McShield
R? mfeavfk;McAfee Inc. mfeavfk
R? mfefirek;McAfee Inc. mfefirek
R? mfehidk;McAfee Inc. mfehidk
R? mfenlfk;McAfee NDIS Light Filter
R? mferkdet;McAfee Inc. mferkdet
R? mfevtp;McAfee Validation Trust Protection Service
R? mfewfpk;McAfee Inc. mfewfpk
R? mio;Master IO Filter Driver
R? nlsX86cc;Nalpeiron Licensing Service
R? NvStreamKms;NvStreamKms
R? nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM)
R? Origin Client Service;Origin Client Service
R? OverwolfUpdater;Overwolf Updater Windows SCM
R? PCDSRVC{90AB3B40-A9A6E5C8-06020200}_0;PCDSRVC{90AB3B40-A9A6E5C8-06020200}_0 - PCDR Kernel Mode Service Helper Driver
R? PROCEXP151;PROCEXP151
R? RDID1142;ME-80
R? RdpVideoMiniport;Remote Desktop Video Miniport Driver
R? rspLLL;rspLLL
R? RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader
R? rzudd;Razer Mouse Driver
R? SWDUMon;SWDUMon
R? SwitchBoard;Adobe SwitchBoard
R? Synth3dVsc;Synth3dVsc
R? TsUsbFlt;TsUsbFlt
R? tsusbhub;tsusbhub
R? VGPU;VGPU
R? WacHidRouter;Wacom Hid Router
R? WatAdminSvc;Windows Activation Technologies Service
R? WinRing0_1_2_0;WinRing0_1_2_0
R? zghsdiag;ZTE General Handset Diagnostic Port
R? zghsmdm;ZTE General Handset USB Modem Proprietary
R? zghsnmea;ZTE General Handset NMEA Port
S? AGSService;Adobe Genuine Software Integrity Service
S? AVG Antivirus;AVG Antivirus
S? avgMonFlt;avgMonFlt
S? avgRvrt;avgRvrt
S? avgSP;avgSP
S? avgsvc;AVG Service
S? avgtp;avgtp
S? AvidAssetCacheService;Avid Asset Cache Service
S? AvidAssetDeliveryService;Avid Asset Delivery Service
S? AvidProjectSyncService;Avid Project Sync Service
S? AvidTransportClient;Avid Transport Client
S? BPowMon;Broadcom Power monitoring service
S? cpuz132;cpuz132
S? DiagTrack;Diagnostics Tracking Service
S? DigiNet;Digidesign Ethernet Support
S? Futuremark SystemInfo Service;Futuremark SystemInfo Service
S? IAStorDataMgrSvc;Intel(R) Rapid Storage Technology
S? IOCBIOS;IOCBIOS
S? k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0
S? LGBusEnum;Logitech Gaming Virtual Bus Enumerator Driver
S? LGCoreTemp;Logitech CPU Core Tempurature
S? LGJoyHidFilter;Logitech Gaming HID Filter Driver (LGS)
S? LGJoyXlCore;Logitech Translation Layer Driver (LGS)
S? LGVirHid;Logitech Gamepanel Virtual HID Device Driver
S? LogiRegistryService;Logitech Gaming Registry Service
S? MacDrive8ServiceD;MacDrive 8 service for Digidesign
S? MBAMProtector;MBAMProtector
S? MDFSYSNT;MacDrive file system driver
S? MDPMGRNT;MacDrive Partition Driver
S? nvoclk64;NVIDIA Enthusiasts Platform KDM
S? Origin Web Helper Service;Origin Web Helper Service
S? PaceLicenseDServices;PACE License Services
S? PassThru Service;Internet Pass-Through Service
S? PxHlpa64;PxHlpa64
S? RawDisk3;RawDisk3
S? RealPlayer Cloud Service;RealPlayer Cloud Service
S? RegHiveRecovery;Registry Hive Recovery Driver
S? rtsuvc;USB2.0 1080p UVC Camera
S? RzFilter;RzFilter
S? RzSynapse;Razer Driver
S? SupportAssistAgent;Dell SupportAssist Agent
S? t3;Sound Blaster X-Fi Xtreme Audio
S? TabletServiceWacom;TabletServiceWacom
S? voxaldriver;Voxal Filter Driver 2.12.01
S? WacHidRouterPro;Wacom Hid Router Pro
S? wacomrouterfilter;Wacom Router Filter Driver
S? WindowFX;Stardock WindowFX
S? WTabletServicePro;Wacom Professional Service
.
=============== File Associations ===============
.
FileExt: .jse: JSEFile=NOTEPAD.EXE %1
FileExt: .wsf: WSFFile=NOTEPAD.EXE %1
ShellExec: switch.exe: open="C:\Program Files (x86)\NCH Software\Switch\switch" "%L"
.
=============== Created Last 30 ================
.
2017-10-21 20:38:48 876 ----a-w- C:\exe.reg
2017-10-21 04:41:03 -------- d-----w- C:\Users\DaveThomas\.thumbnails
2017-10-19 18:18:19 402608 ----a-w- C:\Windows\System32\avgBoot.exe
2017-10-18 18:36:15 -------- d-----w- C:\Users\DaveThomas\.android
2017-10-18 18:35:33 -------- d-----w- C:\Users\DaveThomas\AppData\Roaming\MyPhoneExplorer
2017-10-18 04:21:55 97232 ----a-w- C:\Program Files (x86)\Mozilla Firefox\gmp-clearkey\0.1\clearkey.dll
2017-10-18 04:21:55 892616 ----a-w- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
2017-10-12 18:45:33 -------- d-----w- C:\Users\DaveThomas\AppData\Roaming\Software Informer
2017-10-12 15:13:59 -------- d-----w- C:\Program Files\Pixologic
2017-10-12 05:38:25 126925120 -c--a-w- C:\Windows\System32\MRT-KB890830.exe
2017-10-11 23:46:19 -------- d-----w- C:\Program Files (x86)\Common Files\Overwolf
2017-10-11 23:46:18 -------- d-----w- C:\Program Files (x86)\Overwolf
2017-10-11 23:45:41 -------- d-----w- C:\ProgramData\Overwolf
2017-10-11 23:43:28 -------- d-----w- C:\Users\DaveThomas\AppData\Local\Overwolf
2017-10-10 18:15:29 52976 ----a-w- C:\Windows\System32\drivers\voxaldriverx64.sys
2017-10-10 18:02:47 -------- d-----w- C:\Users\DaveThomas\AppData\Roaming\NCH Software
2017-10-10 04:14:15 18896 ----a-w- C:\Program Files (x86)\Mozilla Firefox\qipcap64.dll
2017-10-08 18:51:24 -------- d-----w- C:\Users\DaveThomas\AppData\Roaming\AIMP
2017-10-08 18:49:39 -------- d-----w- C:\Users\DaveThomas\AppData\Local\Apple Computer
2017-10-07 19:01:43 48304 ----a-w- C:\Windows\System32\drivers\RegHiveRecovery.sys
2017-10-07 19:01:09 -------- d-----w- C:\Program Files (x86)\Windows Kits
2017-10-07 18:48:25 26368 ----a-w- C:\Windows\System32\drivers\rspLLL64.sys
2017-10-07 18:48:25 -------- d-----w- C:\Program Files\LatencyMon
2017-10-07 18:48:12 -------- d-----w- C:\Users\DaveThomas\AppData\Local\Programs
2017-10-07 18:37:57 -------- d-----w- C:\Users\DaveThomas\AppData\Local\PaceAP
2017-10-07 18:28:32 -------- d-----w- C:\Program Files (x86)\ASIO4ALL v2
2017-09-30 22:39:44 -------- d-----w- C:\Users\DaveThomas\AppData\Roaming\PreSonus
2017-09-30 22:23:37 -------- d-----w- C:\Users\DaveThomas\AppData\Roaming\Avid
2017-09-30 22:04:16 -------- d-----w- C:\Program Files (x86)\iLok License Manager
2017-09-30 22:04:16 -------- d-----w- C:\Program Files (x86)\Common Files\PACE
2017-09-30 21:55:36 -------- d-----w- C:\Users\DaveThomas\AppData\Local\Avid
2017-09-30 18:00:47 -------- d-----w- C:\Users\DaveThomas\AppData\Roaming\BOSS-TONE-STUDIO-for-ME-80
2017-09-30 18:00:45 -------- d-----w- C:\Program Files (x86)\BOSS TONE STUDIO for ME-80
2017-09-30 17:55:48 -------- d-----w- C:\Users\DaveThomas\AppData\Local\ElevatedDiagnostics
2017-09-30 17:39:33 -------- d-----w- C:\Users\DaveThomas\AppData\Local\Macromedia
2017-09-29 17:27:43 -------- d-----w- C:\Users\DaveThomas\AppData\Local\TeamSpeak 3
2017-09-29 17:27:40 -------- d-----w- C:\Users\DaveThomas\AppData\Roaming\NVIDIA
2017-09-29 17:27:40 -------- d-----w- C:\Users\DaveThomas\.QtWebEngineProcess
2017-09-29 17:27:38 -------- d-----w- C:\Users\DaveThomas\.TeamSpeak 3
2017-09-29 17:27:24 -------- d-----w- C:\Users\DaveThomas\AppData\Roaming\TS3Client
2017-09-29 16:56:38 -------- d-----w- C:\Users\DaveThomas\AppData\Local\Activision
2017-09-29 15:43:51 -------- d-----w- C:\Users\DaveThomas\AppData\Local\Steam
2017-09-29 04:35:02 714560 ----a-w- C:\Windows\System32\RDDP1142.EXE
2017-09-29 04:35:02 637952 ----a-w- C:\Windows\System32\RDCP1142.CPL
2017-09-29 04:35:02 275456 ----a-w- C:\Windows\SysWow64\RDAH1142.DAT
2017-09-29 04:35:02 202880 ----a-w- C:\Windows\System32\drivers\RDWM1142.sys
2017-09-29 04:35:02 17920 ----a-w- C:\Windows\System32\RDCI1142.DLL
2017-09-29 04:35:02 116736 ----a-w- C:\Windows\System32\RDAS1142.DLL
2017-09-29 04:35:02 102400 ----a-w- C:\Windows\SysWow64\RDAW1142.DLL
2017-09-29 04:35:02 -------- d-----w- C:\Program Files\RdDrv001
2017-09-29 03:57:49 -------- d-----w- C:\Users\DaveThomas\AppData\Roaming\com.adobe.configurator2.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1
2017-09-28 23:57:48 -------- d-----w- C:\Users\DaveThomas\AppData\Roaming\AVG
2017-09-28 23:49:52 -------- d-----w- C:\Users\DaveThomas\AppData\Local\Mozilla
2017-09-28 23:46:57 -------- d-----w- C:\Users\DaveThomas\AppData\Roaming\Intel Corporation
2017-09-28 23:46:18 -------- d-----w- C:\Users\DaveThomas\AppData\Local\ArcSoft
2017-09-28 23:46:00 -------- d-----w- C:\Users\DaveThomas\AppData\Local\Logitech
2017-09-28 23:45:56 -------- d-----w- C:\Users\DaveThomas\AppData\Local\Adobe
2017-09-28 23:45:45 -------- d-----w- C:\Users\DaveThomas\AppData\Local\CEF
2017-09-28 23:45:15 -------- d-----w- C:\Users\DaveThomas\AppData\Roaming\Stardock
2017-09-28 23:45:14 -------- d-----w- C:\Users\DaveThomas\AppData\Local\Google
2017-09-28 23:43:39 -------- d-----w- C:\Users\DaveThomas\AppData\Roaming\WTablet
2017-09-28 23:43:33 -------- d-----w- C:\Users\DaveThomas\AppData\Local\NVIDIA Corporation
2017-09-24 22:55:59 -------- d-----w- C:\ProgramData\SupportAssist
2017-09-24 16:04:34 246272 ----a-w- C:\Windows\SysWow64\rsnp2uvc.dll
2017-09-24 16:04:34 238080 ----a-w- C:\Windows\System32\rsnp2uvc.dll
2017-09-24 16:04:33 -------- d-----w- C:\Program Files (x86)\Common Files\SNP2UVC
2017-09-23 04:32:17 127440 ----a-w- C:\Program Files (x86)\Mozilla Firefox\AccessibleHandler.dll
2017-09-22 19:19:03 94952 ----a-w- C:\Windows\System32\CompatTelRunner.exe
2017-09-22 19:19:03 620544 ----a-w- C:\Windows\System32\generaltel.dll
2017-09-22 19:19:03 535552 ----a-w- C:\Windows\System32\devinv.dll
2017-09-22 19:19:03 325632 ----a-w- C:\Windows\System32\invagent.dll
2017-09-22 19:19:03 311296 ----a-w- C:\Windows\System32\centel.dll
2017-09-22 19:19:03 217088 ----a-w- C:\Windows\System32\aepic.dll
2017-09-22 19:19:03 1691136 ----a-w- C:\Windows\System32\aitstatic.exe
2017-09-22 19:19:03 1555968 ----a-w- C:\Windows\System32\appraiser.dll
2017-09-22 19:19:03 127488 ----a-w- C:\Windows\System32\acmigration.dll
2017-09-22 19:19:03 1206272 ----a-w- C:\Windows\System32\aeinv.dll
2017-09-22 19:03:42 -------- d-----w- C:\ProgramData\PC-Doctor for Windows
.
==================== Find3M ====================
.
2017-10-20 14:37:58 97856 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2017-10-19 18:18:12 76832 ----a-w- C:\Windows\System32\drivers\avgRvrt.sys
2017-10-19 18:18:12 579584 ----a-w- C:\Windows\System32\drivers\avgSP.sys
2017-10-19 18:18:12 39424 ----a-w- C:\Windows\System32\drivers\avgHwid.sys
2017-10-19 18:18:12 355856 ----a-w- C:\Windows\System32\drivers\avgVmm.sys
2017-10-19 18:18:12 193768 ----a-w- C:\Windows\System32\drivers\avgStm.sys
2017-10-19 18:18:12 140192 ----a-w- C:\Windows\System32\drivers\avgMonFlt.sys
2017-10-19 18:18:12 102792 ----a-w- C:\Windows\System32\drivers\avgRdr2.sys
2017-10-19 18:18:02 1012952 ----a-w- C:\Windows\System32\drivers\avgSnx.sys
2017-10-19 18:17:56 51336 ----a-w- C:\Windows\System32\drivers\avgbuniva.sys
2017-10-19 18:17:56 336896 ----a-w- C:\Windows\System32\drivers\avgbloga.sys
2017-10-19 18:17:56 314640 ----a-w- C:\Windows\System32\drivers\avgbidsdrivera.sys
2017-10-19 18:17:56 192584 ----a-w- C:\Windows\System32\drivers\avgbidsha.sys
2017-10-19 18:17:56 166624 ----a-w- C:\Windows\System32\drivers\avgbdiska.sys
2017-10-09 21:05:47 2211784 ----a-w- C:\Windows\System32\Wintab32.dll
2017-10-09 21:05:46 2380744 ----a-w- C:\Windows\System32\Wacom_Tablet.dll
2017-10-09 21:05:46 2373576 ----a-w- C:\Windows\System32\Wacom_Touch_Tablet.dll
2017-10-09 21:05:46 2273224 ----a-w- C:\Windows\System32\WacomMT.dll
2017-10-09 21:05:44 1865672 ----a-w- C:\Windows\SysWow64\Wacom_Touch_Tablet.dll
2017-10-09 21:05:44 1712072 ----a-w- C:\Windows\SysWow64\Wintab32.dll
2017-10-09 21:05:43 1872840 ----a-w- C:\Windows\SysWow64\Wacom_Tablet.dll
2017-10-09 21:05:43 1750984 ----a-w- C:\Windows\SysWow64\WacomMT.dll
2017-10-08 18:38:57 1804680 ----a-w- C:\Windows\System32\wdfcoinstaller01011.dll
2017-10-08 18:38:57 17912 ----a-w- C:\Windows\System32\drivers\wacomrouterfilter.sys
2017-10-08 18:38:57 115192 ----a-w- C:\Windows\System32\drivers\wachidrouter.sys
2017-09-30 22:04:19 25432 ----a-w- C:\Windows\System32\drivers\iLokDrvr.sys
2017-09-30 17:38:38 803328 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2017-09-30 17:38:38 144896 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2017-09-20 19:11:35 466520 ----a-w- C:\Windows\System32\wrap_oal.dll
2017-09-20 19:11:35 445016 ----a-w- C:\Windows\SysWow64\wrap_oal.dll
2017-09-20 19:11:35 123480 ----a-w- C:\Windows\System32\OpenAL32.dll
2017-09-20 19:11:35 109144 ----a-w- C:\Windows\SysWow64\OpenAL32.dll
2017-09-13 15:33:50 631176 ----a-w- C:\Windows\System32\winresume.efi
2017-09-13 15:32:36 706792 ----a-w- C:\Windows\System32\winload.efi
2017-09-13 15:32:35 5547752 ----a-w- C:\Windows\System32\ntoskrnl.exe
2017-09-13 15:32:33 95464 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2017-09-13 15:32:33 154856 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2017-09-13 15:31:56 1732864 ----a-w- C:\Windows\System32\ntdll.dll
2017-09-13 15:27:59 731648 ----a-w- C:\Windows\System32\kerberos.dll
2017-09-13 15:13:35 4001512 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2017-09-13 15:13:35 3945704 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2017-09-13 15:10:46 1314112 ----a-w- C:\Windows\SysWow64\ntdll.dll
2017-09-13 15:08:59 554496 ----a-w- C:\Windows\SysWow64\kerberos.dll
2017-09-13 15:05:20 324608 ----a-w- C:\Windows\System32\drivers\nwifi.sys
2017-09-13 15:00:54 148480 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2017-09-13 15:00:50 62464 ----a-w- C:\Windows\System32\drivers\appid.sys
2017-09-13 15:00:50 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2017-09-13 15:00:10 64000 ----a-w- C:\Windows\System32\auditpol.exe
2017-09-13 14:57:12 338432 ----a-w- C:\Windows\System32\conhost.exe
2017-09-13 14:56:20 296960 ----a-w- C:\Windows\System32\rstrui.exe
2017-09-13 14:53:40 159744 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2017-09-13 14:53:06 291328 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2017-09-13 14:53:04 129536 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2017-09-13 14:52:23 30720 ----a-w- C:\Windows\System32\lsass.exe
2017-09-13 14:52:20 112640 ----a-w- C:\Windows\System32\smss.exe
2017-09-13 14:50:26 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2017-09-13 14:47:00 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2017-09-13 14:46:59 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2017-09-13 14:46:59 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2017-09-13 14:46:58 2048 ----a-w- C:\Windows\SysWow64\user.exe
2017-09-13 14:46:13 36352 ----a-w- C:\Windows\SysWow64\cryptbase.dll
2017-09-13 14:46:06 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2017-09-13 14:46:06 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-13 14:46:06 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2017-09-13 14:46:06 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2017-09-08 15:34:37 1680616 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2017-09-08 15:30:58 2319872 ----a-w- C:\Windows\System32\tquery.dll
2017-09-08 15:30:58 149504 ----a-w- C:\Windows\System32\t2embed.dll
2017-09-08 15:30:53 2058240 ----a-w- C:\Windows\System32\Query.dll
2017-09-08 15:30:48 99840 ----a-w- C:\Windows\System32\mssprxy.dll
2017-09-08 15:30:48 778240 ----a-w- C:\Windows\System32\mssvp.dll
2017-09-08 15:30:48 75264 ----a-w- C:\Windows\System32\msscntrs.dll
2017-09-08 15:30:48 491520 ----a-w- C:\Windows\System32\mssph.dll
2017-09-08 15:30:48 288256 ----a-w- C:\Windows\System32\mssphtb.dll
2017-09-08 15:30:48 2222080 ----a-w- C:\Windows\System32\mssrch.dll
2017-09-08 15:30:48 14336 ----a-w- C:\Windows\System32\msshooks.dll
2017-09-08 15:30:48 115200 ----a-w- C:\Windows\System32\mssitlb.dll
2017-09-08 15:30:44 405504 ----a-w- C:\Windows\System32\gdi32.dll
2017-09-08 15:14:08 591872 ----a-w- C:\Windows\System32\SearchIndexer.exe
2017-09-08 15:13:47 249856 ----a-w- C:\Windows\System32\SearchProtocolHost.exe
2017-09-08 15:13:17 113664 ----a-w- C:\Windows\System32\SearchFilterHost.exe
2017-09-08 15:10:06 312832 ----a-w- C:\Windows\SysWow64\gdi32.dll
2017-09-08 15:10:05 1549824 ----a-w- C:\Windows\SysWow64\tquery.dll
2017-09-08 15:10:04 109568 ----a-w- C:\Windows\SysWow64\t2embed.dll
2017-09-08 15:10:01 1363968 ----a-w- C:\Windows\SysWow64\Query.dll
2017-09-08 15:09:57 666624 ----a-w- C:\Windows\SysWow64\mssvp.dll
2017-09-08 15:09:57 59392 ----a-w- C:\Windows\SysWow64\msscntrs.dll
2017-09-08 15:09:57 34816 ----a-w- C:\Windows\SysWow64\mssprxy.dll
2017-09-08 15:09:57 337408 ----a-w- C:\Windows\SysWow64\mssph.dll
2017-09-08 15:09:57 197120 ----a-w- C:\Windows\SysWow64\mssphtb.dll
2017-09-08 15:09:57 1400320 ----a-w- C:\Windows\SysWow64\mssrch.dll
2017-09-08 15:09:57 104448 ----a-w- C:\Windows\SysWow64\mssitlb.dll
2017-09-08 15:00:25 3222016 ----a-w- C:\Windows\System32\win32k.sys
2017-09-08 15:00:05 427520 ----a-w- C:\Windows\SysWow64\SearchIndexer.exe
2017-09-08 15:00:01 164352 ----a-w- C:\Windows\SysWow64\SearchProtocolHost.exe
2017-09-08 14:59:28 86528 ----a-w- C:\Windows\SysWow64\SearchFilterHost.exe
2017-09-08 14:59:17 9728 ----a-w- C:\Windows\SysWow64\msshooks.dll
2017-09-08 14:20:51 8704 ----a-w- C:\Windows\SysWow64\msjint40.dll
2017-09-08 14:20:51 640512 ----a-w- C:\Windows\SysWow64\mswstr10.dll
2017-09-08 14:20:50 345088 ----a-w- C:\Windows\SysWow64\msexcl40.dll
.
============= FINISH: 14:27:20.41 ===============

Attached Files
File Type: txt attach.txt (7.9 KB)

Malware, incessant beeping and bogged surfing

$
0
0
This is a Win 10 laptop: Aspire (ACER) ES 15

A few days ago my laptop began to drop off audio sounds as if a communication program was running, but it wasn't. I turned off the "auto detect and lower volume" setting, but then the bleeps of starting a program and stopping one (such as you hear plugging in and unplugging most USB devices) began to be constant. It's making it almost impossible to even use this forum. Logs below:

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.15063.608
Run by macdonald at 19:34:57 on 2017-10-20
Microsoft Windows 10 Home 10.0.15063.0.1252.1.1033.18.3922.1331 [GMT -7:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee VirusScan *Enabled/Updated* {8BCDACFA-D264-3528-5EF8-E94FD0BC1FBC}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee VirusScan *Enabled/Updated* {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501}
FW: McAfee Firewall *Enabled* {B3F62DDF-980B-3470-75A7-407A2E6F58C7}
.
============== Running Processes ===============
.
c:\windows\system32\svchost.exe -k dcomlaunch -s PlugPlay
C:\WINDOWS\system32\fontdrvhost.exe
C:\WINDOWS\system32\fontdrvhost.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k dcomlaunch -s LSM
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s lmhosts
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NcbService
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s TimeBrokerSvc
c:\windows\system32\svchost.exe -k netsvcs -s Schedule
c:\windows\system32\svchost.exe -k netsvcs -s ProfSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s EventLog
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s hidserv
c:\windows\system32\svchost.exe -k localservice -s nsi
c:\windows\system32\svchost.exe -k netsvcs -s UserManager
c:\windows\system32\svchost.exe -k appmodel -s StateRepository
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s Dhcp
c:\windows\system32\svchost.exe -k networkservice -s NlaSvc
c:\windows\system32\svchost.exe -k networkservice -s Dnscache
c:\windows\system32\svchost.exe -k localservice -s EventSystem
c:\windows\system32\svchost.exe -k netsvcs -s Themes
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe -k localservice -s netprofm
c:\windows\system32\svchost.exe -k netsvcs -s SENS
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\system32\igfxCUIService.exe
c:\windows\system32\svchost.exe -k localservice -s FontCache
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -s WinHttpAutoProxySvc
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe -k netsvcs -s Winmgmt
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe -k netsvcs -s ShellHWDetection
C:\WINDOWS\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k networkservice -s LanmanWorkstation
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DeviceAssociationService
c:\windows\system32\svchost.exe -k netsvcs -s IKEEXT
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted -s PolicyAgent
c:\windows\system32\svchost.exe -k netsvcs -s LanmanServer
c:\windows\system32\svchost.exe -k netsvcs -s Browser
C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
c:\windows\system32\svchost.exe -k networkservice -s CryptSvc
C:\WINDOWS\System32\svchost.exe -k utcsvc
c:\windows\system32\svchost.exe -k localservicenonetwork -s DPS
c:\windows\system32\svchost.exe -k netsvcs -s iphlpsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s PcaSvc
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SysMain
c:\windows\system32\svchost.exe -k appmodel -s tiledatamodelsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TrkWks
c:\windows\system32\svchost.exe -k netsvcs -s WpnService
c:\windows\system32\svchost.exe -k localservice -s WdiServiceHost
c:\windows\system32\sihost.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\svchost.exe -k netsvcs -s TokenBroker
C:\WINDOWS\Explorer.EXE
c:\windows\system32\taskhostw.exe
C:\Users\macdonald\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
c:\windows\system32\svchost.exe -k localservice -s CDPSvc
C:\Program Files\Acer\Acer Quick Access\QASvc.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Acer\Acer Quick Access\QALSvc.exe
c:\windows\system32\svchost.exe -k netsvcs -s Appinfo
C:\Program Files\Acer\Acer Quick Access\QAAgent.exe
C:\WINDOWS\system32\igfxEM.exe
C:\WINDOWS\system32\igfxHK.exe
C:\WINDOWS\system32\igfxTray.exe
C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Program Files\Acer\Acer Quick Access\QAAdminAgent.exe
C:\Program Files\Acer\Acer Quick Access\QALockHandler.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Windows\System32\RuntimeBroker.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
c:\windows\system32\svchost.exe -k localservice -s LicenseManager
C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeHost.exe
C:\Program Files\Windows Defender\MSASCuiL.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\McAfee Security Scan\3.11.599\SSScheduler.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s Netman
c:\windows\system32\svchost.exe -k unistacksvcgroup
C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe
C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k netsvcs -s DoSvc
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s SSDPSRV
c:\windows\system32\svchost.exe -k netsvcs -s lfsvc
C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
C:\Program Files (x86)\Acer\Care Center\ACCStd.exe
C:\Program Files (x86)\Intel\TXE Components\DAL\jhi_service.exe
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s wscsvc
C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s StorSvc
C:\WINDOWS\system32\ApplicationFrameHost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs -s wlidsvc
C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
c:\windows\system32\svchost.exe -k netsvcs -s BITS
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVShNotify.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
c:\program files\common files\mcafee\modulecore\modulecoreservice.exe
c:\program files\common files\mcafee\modulecore\ModuleCoreService.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
C:\WINDOWS\system32\mfevtps.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\McAfee\VSCore_15_7\McApExe.exe
C:\Program Files\Common Files\McAfee\CSP\2.6.319.0\McCSPServiceHost.exe
C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
C:\Program Files\McAfee\MfeAV\MFEAvSvc.exe
C:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exe
C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHOST.EXE
c:\windows\system32\taskhostw.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
c:\windows\system32\svchost.exe -k localservice -s W32Time
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DsSvc
C:\PROGRA~1\COMMON~1\McAfee\Platform\MSM\McSmtFwk.exe
C:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -s WdiSystemHost
C:\Windows\System32\smartscreen.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\System32\svchost.exe -k WerSvcGroup
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\system32\AUDIODG.EXE
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uLocal Page = %11%\blank.htm
BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
BHO: McAfee WebAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
EB: Canon Easy-WebPrint EX: {21347690-EC41-4F9A-8887-1F4AEE672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
uRun: [OneDrive] "C:\Users\macdonald\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
mRun: [CanonQuickMenu] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files\McAfee Security Scan\3.11.599\SSScheduler.exe
mPolicies-System: DSCAutomationHostEnabled = dword:2
IE: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
IE: {48A61126-9A19-4C50-A214-FF08CB94995C} - {29B24532-6CE1-41BA-8BF0-F580EA174AF1} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
TCP: NameServer = 192.168.1.254 75.153.171.122
TCP: Interfaces\{886df459-9ede-4b10-b635-97336340365b} : NameServer = Freedome
TCP: Interfaces\{886df459-9ede-4b10-b635-97336340365b} : DHCPNameServer = 192.168.1.254 75.153.171.122
TCP: Interfaces\{9d9c3f08-7f8a-405b-a234-b6faa801886e} : NameServer = Freedome
TCP: Interfaces\{b31d046c-04cc-4187-a154-9c717fa0a2f8} : NameServer = Freedome
TCP: Interfaces\{b31d046c-04cc-4187-a154-9c717fa0a2f8} : DHCPNameServer = 192.168.1.254 75.153.171.122
TCP: Interfaces\{fed08d21-7cdf-4e1a-9b8b-8faa39c2280b} : NameServer = Freedome
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
SSODL: WebCheck - <orphaned>
LSA: Security Packages = ""
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
x64-BHO: McAfee WebAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-BHO: The Amazon 1Button App for Internet Explorer: {BAC72C85-CEC6-4B86-AF06-FA20C259FAB8} -
x64-TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
x64-Run: [SecurityHealth] C:\Program Files (x86)\Windows Defender\MSASCuiL.exe
x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
x64-mPolicies-System: DSCAutomationHostEnabled = dword:2
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-IE: {48A61126-9A19-4C50-A214-FF08CB94995C} - {29B24532-6CE1-41BA-8BF0-F580EA174AF1} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
x64-Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\MSC\McSnIePl64.dll
x64-Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - <orphaned>
x64-Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - <orphaned>
x64-Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
x64-CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
Hosts: 0.0.0.1 mssplus.mcafee.com
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\macdonald\AppData\Roaming\Mozilla\Firefox\Profiles\cq8lbz2k.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo!
FF - prefs.js: browser.startup.homepage - hxxp://www.nytimes.com/
FF - prefs.js: keyword.URL - hxxps://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=994519&p=
FF - plugin: c:\PROGRA~1\mcafee\msc\npMcSnFFPl64.dll
FF - plugin: c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll
FF - plugin: c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrlui.dll
FF - plugin: C:\WINDOWS\System32\Macromed\Flash\NPSWF64_27_0_0_159.dll
.
============= SERVICES / DRIVERS ===============
.
R0 intelpep;Intel(R) Power Engine Plug-in Driver;C:\WINDOWS\System32\drivers\intelpep.sys [2017-3-18 74840]
R0 iorate;Disk I/O Rate Filter Driver;C:\WINDOWS\System32\drivers\iorate.sys [2017-3-18 49568]
R0 mfehidk;McAfee Inc. mfehidk;C:\WINDOWS\System32\drivers\mfehidk.sys [2016-8-2 933360]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\WINDOWS\System32\drivers\mfewfpk.sys [2016-8-2 253424]
R0 volume;Volume driver;C:\WINDOWS\System32\drivers\volume.sys [2017-3-18 16288]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [2017-3-18 70232]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [2017-3-18 18520]
R0 Wof;Windows Overlay File System Filter Driver;C:\WINDOWS\System32\drivers\wof.sys [2017-3-18 208288]
R1 ahcache;Application Compatibility Cache;C:\WINDOWS\System32\drivers\ahcache.sys [2017-3-18 239616]
R1 FileCrypt;FileCrypt;C:\WINDOWS\System32\drivers\filecrypt.sys [2017-3-18 54272]
R1 GpuEnergyDrv;GPU Energy Driver;C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2017-3-18 8192]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe [2015-5-29 323152]
R2 CCDMonitorService;CCDMonitorService;C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2016-4-2 2267352]
R2 CDPSvc;Connected Devices Platform Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
R2 ClickToRunSvc;Microsoft Office Click-to-Run Service;C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe [2016-6-26 7923888]
R2 clreg;Virtual Registry for Containers;C:\WINDOWS\System32\drivers\registry.sys [2017-3-18 14336]
R2 CoreMessagingRegistrar;CoreMessaging;C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork [2017-3-18 47664]
R2 DiagTrack;Connected User Experiences and Telemetry;C:\WINDOWS\System32\svchost.exe -k utcsvc [2017-3-18 47664]
R2 DoSvc;Delivery Optimization;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R2 DusmSvc;Data Usage;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
R2 GamesAppIntegrationService;GamesAppIntegrationService;C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [2015-4-14 373312]
R2 igfxCUIService2.0.0.0;Intel(R) HD Graphics Control Panel Service;C:\WINDOWS\System32\igfxCUIService.exe [2016-2-5 354936]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface;C:\Program Files (x86)\Intel\TXE Components\DAL\jhi_service.exe [2015-4-21 174368]
R2 McAPExe;McAfee AP Service;C:\Program Files\Common Files\McAfee\VSCore_15_7\mcapexe.exe [2017-8-16 728808]
R2 mccspsvc;McAfee CSP Service;C:\Program Files\Common Files\McAfee\CSP\2.6.319.0\McCSPServiceHost.exe [2017-9-26 2145496]
R2 mfemms;McAfee Service Controller;C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [2016-11-11 394704]
R2 ModuleCoreService;McAfee Module Core Service;C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [2017-3-14 1622856]
R2 storqosflt;Storage QoS Filter Driver;C:\WINDOWS\System32\drivers\storqosflt.sys [2017-3-18 79872]
R2 wcifs;Windows Container Isolation;C:\WINDOWS\System32\drivers\wcifs.sys [2017-7-12 142752]
R3 BtFilter;BtFilter;C:\WINDOWS\System32\drivers\btfilter.sys [2016-7-13 610336]
R3 CAD;Charge Arbitration Driver;C:\WINDOWS\System32\drivers\CAD.sys [2017-3-18 53664]
R3 cfwids;McAfee Inc. cfwids;C:\WINDOWS\System32\drivers\cfwids.sys [2016-8-2 77800]
R3 DsSvc;Data Sharing Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
R3 iagpio;Intel Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iagpio.sys [2017-3-18 33280]
R3 iai2c;Intel(R) Serial IO I2C Host Controller;C:\WINDOWS\System32\drivers\iai2c.sys [2017-3-18 81408]
R3 igfxLP;igfxLP;C:\WINDOWS\System32\drivers\igdkmd64lp.sys [2016-2-5 7322064]
R3 IntcDAud;Intel(R) Display Audio;C:\WINDOWS\System32\drivers\IntcDAud.sys [2016-2-5 480520]
R3 Intel(R) Security Assist;Intel(R) Security Assist;C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [2015-5-19 335872]
R3 lfsvc;Geolocation Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
R3 LicenseManager;Windows License Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
R3 LMDriver;Launch Manager Wireless Driver;C:\WINDOWS\System32\drivers\LMDriver.sys [2016-2-1 21408]
R3 mfeaack;McAfee Inc. mfeaack;C:\WINDOWS\System32\drivers\mfeaack.sys [2016-8-2 487408]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\WINDOWS\System32\drivers\mfeavfk.sys [2016-8-2 355312]
R3 mfefirek;McAfee Inc. mfefirek;C:\WINDOWS\System32\drivers\mfefirek.sys [2016-8-2 506352]
R3 mfencbdc;McAfee LLC. mfencbdc;C:\WINDOWS\System32\drivers\mfencbdc.sys [2017-6-27 504792]
R3 mfeplk;McAfee Inc. mfeplk;C:\WINDOWS\System32\drivers\mfeplk.sys [2016-9-9 116208]
R3 mfevtp;McAfee Validation Trust Protection Service;C:\WINDOWS\System32\mfevtps.exe [2016-11-11 350160]
R3 NcbService;Network Connection Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [2017-3-18 20992]
R3 RadioShim;Shim for HID-KMDF Interface layer;C:\WINDOWS\System32\drivers\RadioShim.sys [2016-2-1 14752]
R3 rt640x64;Realtek RT640 NT Driver;C:\WINDOWS\System32\drivers\rt640x64.sys [2016-6-26 889584]
R3 RTSUER;Realtek USB Card Reader - UER;C:\WINDOWS\System32\drivers\RtsUer.sys [2016-6-26 411712]
R3 SynRMIHID;Synaptics HID Service;C:\WINDOWS\System32\drivers\SynRMIHID.sys [2016-3-21 57448]
R3 TXEIx64;Intel(R) Trusted Execution Engine Interface ;C:\WINDOWS\System32\drivers\TXEIx64.sys [2015-10-15 146200]
R3 UEFI;Microsoft UEFI Driver;C:\WINDOWS\System32\drivers\uefi.sys [2017-3-18 29600]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\drivers\WUDFRd.sys [2017-3-18 220672]
S0 mfeelamk;McAfee Inc. mfeelamk;C:\WINDOWS\System32\drivers\mfeelamk.sys [2016-8-2 84544]
S2 CldFlt;Windows Cloud Files Filter Driver;C:\WINDOWS\System32\drivers\cldflt.sys [2017-3-18 12288]
S2 isaHelperSvc;Intel(R) Security Assist Helper;C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [2015-5-19 7680]
S2 MapsBroker;Downloaded Maps Manager;C:\WINDOWS\System32\svchost.exe -k NetworkService [2017-3-18 47664]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [2017-9-7 590880]
S3 AcpiDev;ACPI Devices driver;C:\WINDOWS\System32\drivers\AcpiDev.sys [2017-3-18 20480]
S3 ADP80XX;ADP80XX;C:\WINDOWS\System32\drivers\adp80xx.sys [2017-3-18 1135512]
S3 AJRouter;AllJoyn Router Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 applockerfltr;Smartlocker Filter Driver;C:\WINDOWS\System32\drivers\applockerfltr.sys [2017-3-18 17920]
S3 AppReadiness;App Readiness;C:\WINDOWS\System32\svchost.exe -k AppReadiness [2017-3-18 47664]
S3 AppXSvc;AppX Deployment Service (AppXSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2017-3-18 47664]
S3 bcmfn2;bcmfn2 Service;C:\WINDOWS\System32\drivers\bcmfn2.sys [2017-3-18 9728]
S3 BthHFSrv;Bluetooth Handsfree Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation [2017-3-18 47664]
S3 buttonconverter;Service for Portable Device Control devices;C:\WINDOWS\System32\drivers\buttonconverter.sys [2017-9-12 39424]
S3 CapImg;HID driver for CapImg touch screen;C:\WINDOWS\System32\drivers\capimg.sys [2017-3-18 122880]
S3 cht4iscsi;cht4iscsi;C:\WINDOWS\System32\drivers\cht4sx64.sys [2017-3-18 347032]
S3 cht4vbd;Chelsio Virtual Bus Driver;C:\WINDOWS\System32\drivers\cht4vx64.sys [2017-3-18 2104224]
S3 ClientAnalyticsService;ClientAnalyticsService;C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [2017-1-27 1511728]
S3 ClipSVC;Client License Service (ClipSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2017-3-18 47664]
S3 DevQueryBroker;DevQuery Background Discovery Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 diagnosticshub.standardcollector.service;Microsoft (R) Diagnostics Hub Standard Collector Service;C:\WINDOWS\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2017-3-18 86528]
S3 DmEnrollmentSvc;Device Management Enrollment Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 dmwappushservice;dmwappushsvc;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 embeddedmode;Embedded Mode;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 EntAppSvc;Enterprise App Management Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2017-3-18 47664]
S3 FrameServer;Windows Camera Frame Server;C:\WINDOWS\System32\svchost.exe -k Camera [2017-3-18 47664]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2014-12-16 265808]
S3 genericusbfn;Generic USB Function Class;C:\WINDOWS\System32\drivers\genericusbfn.sys [2017-3-18 21504]
S3 hidinterrupt;Common Driver for HID Buttons implemented with interrupts;C:\WINDOWS\System32\drivers\hidinterrupt.sys [2017-3-18 51104]
S3 HipShieldK;McAfee Inc. HipShieldK;C:\WINDOWS\System32\drivers\HipShieldK.sys [2016-11-11 209608]
S3 HvHost;HV Host Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 iaLPSS2i_GPIO2;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2017-3-18 70656]
S3 iaLPSS2i_GPIO2_BXT_P;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2017-3-18 85504]
S3 iaLPSS2i_I2C;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2017-3-18 165376]
S3 iaLPSS2i_I2C_BXT_P;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2017-3-18 168448]
S3 iaLPSSi_GPIO;Intel(R) Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [2017-3-18 38128]
S3 iaLPSSi_I2C;Intel(R) Serial IO I2C Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [2017-3-18 113152]
S3 iaStorAV;Intel(R) SATA RAID Controller Windows;C:\WINDOWS\System32\drivers\iaStorAV.sys [2017-3-18 673184]
S3 ibbus;Mellanox InfiniBand Bus/AL (Filter Driver);C:\WINDOWS\System32\drivers\ibbus.sys [2017-3-18 526240]
S3 icssvc;Windows Mobile Hotspot Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 IndirectKmd;Indirect Displays Kernel-Mode Driver;C:\WINDOWS\System32\drivers\IndirectKmd.sys [2017-3-18 36864]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [2015-9-3 887784]
S3 IpxlatCfgSvc;IP Translation Configuration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 LSI_SAS2i;LSI_SAS2i;C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2017-3-18 123808]
S3 LSI_SAS3i;LSI_SAS3i;C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2017-3-18 103328]
S3 mausbhost;MA-USB Host Controller Driver;C:\WINDOWS\System32\drivers\mausbhost.sys [2017-3-18 405408]
S3 mausbip;MA-USB IP Filter Driver;C:\WINDOWS\System32\drivers\mausbip.sys [2017-3-18 51104]
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files\McAfee Security Scan\3.11.599\McCHSvc.exe [2017-9-5 404376]
S3 megasas2i;megasas2i;C:\WINDOWS\System32\drivers\MegaSas2i.sys [2017-3-18 64416]
S3 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2016-11-11 242640]
S3 mfencrk;McAfee LLC. mfencrk;C:\WINDOWS\System32\drivers\mfencrk.sys [2017-6-27 108504]
S3 mfesapsn;McAfee Process Start Notification Service;C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [2017-9-7 111608]
S3 mlx4_bus;Mellanox ConnectX Bus Enumerator;C:\WINDOWS\System32\drivers\mlx4_bus.sys [2017-3-18 842656]
S3 NaturalAuthentication;Natural Authentication;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 ndfltr;NetworkDirect Service;C:\WINDOWS\System32\drivers\ndfltr.sys [2017-3-18 108960]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library;C:\WINDOWS\System32\drivers\NetAdapterCx.sys [2017-3-18 122368]
S3 NetSetupSvc;Network Setup Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-3-18 47664]
S3 netvsc;netvsc;C:\WINDOWS\System32\drivers\netvsc.sys [2017-5-21 118784]
S3 NgcCtnrSvc;Microsoft Passport Container;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-3-18 47664]
S3 NgcSvc;Microsoft Passport;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-3-18 47664]
S3 nvdimmn;Microsoft NVDIMM-N device driver;C:\WINDOWS\System32\drivers\nvdimmn.sys [2017-3-18 80896]
S3 percsas2i;percsas2i;C:\WINDOWS\System32\drivers\percsas2i.sys [2017-3-18 58784]
S3 percsas3i;percsas3i;C:\WINDOWS\System32\drivers\percsas3i.sys [2017-3-18 61848]
S3 PhoneSvc;Phone Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2017-3-18 47664]
S3 ReFS;ReFS;C:\WINDOWS\System32\drivers\refs.sys [2017-3-18 1735584]
S3 ReFSv1;ReFSv1;C:\WINDOWS\System32\drivers\refsv1.sys [2017-3-18 936864]
S3 scmbus;Microsoft Storage Class Memory Bus Driver;C:\WINDOWS\System32\drivers\scmbus.sys [2017-3-18 91040]
S3 SDFRd;SDF Reflector;C:\WINDOWS\System32\drivers\SDFRd.sys [2017-3-18 31128]
S3 SerCx2;Serial UART Support Library;C:\WINDOWS\System32\drivers\SerCx2.sys [2017-3-18 154016]
S3 SpatialGraphFilter;Holographic Spatial Graph Filter;C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [2017-3-18 40352]
S3 stornvme;Microsoft Standard NVM Express Driver;C:\WINDOWS\System32\drivers\stornvme.sys [2017-3-18 95648]
S3 storufs;Microsoft Universal Flash Storage (UFS) Driver;C:\WINDOWS\System32\drivers\storufs.sys [2017-3-18 36760]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmCx.sys [2017-9-12 104960]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmTcpciCx.sys [2017-3-18 179200]
S3 UcmUcsi;USB Connector Manager UCSI Client;C:\WINDOWS\System32\drivers\UcmUcsi.sys [2017-8-8 51712]
S3 UdeCx;USB Device Emulation Support Library;C:\WINDOWS\System32\drivers\Udecx.sys [2017-3-18 45568]
S3 Ufx01000;USB Function Class Extension;C:\WINDOWS\System32\drivers\ufx01000.sys [2017-3-18 263584]
S3 UfxChipidea;USB Chipidea Controller;C:\WINDOWS\System32\drivers\UfxChipidea.sys [2017-3-18 98712]
S3 ufxsynopsys;USB Synopsys Controller;C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2017-3-18 138656]
S3 UrsChipidea;Chipidea USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urschipidea.sys [2017-3-18 29600]
S3 UrsCx01000;USB Role-Switch Support Library;C:\WINDOWS\System32\drivers\urscx01000.sys [2017-3-18 59288]
S3 UrsSynopsys;Synopsys USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urssynopsys.sys [2017-3-18 28064]
S3 vhf;Virtual HID Framework (VHF) Driver;C:\WINDOWS\System32\drivers\vhf.sys [2017-3-18 35328]
S3 vmgid;Microsoft Hyper-V Guest Infrastructure Driver;C:\WINDOWS\System32\drivers\vmgid.sys [2017-3-18 10240]
S3 wcnfs;Windows Container Name Virtualization;C:\WINDOWS\System32\drivers\wcnfs.sys [2017-3-18 72192]
S3 wdiwifi;WDI Driver Framework;C:\WINDOWS\System32\drivers\WdiWiFi.sys [2017-7-12 757248]
S3 WdNisDrv;Windows Defender Antivirus Network Inspection System Driver;C:\WINDOWS\System32\drivers\WdNisDrv.sys [2017-3-18 121248]
S3 WinMad;WinMad Service;C:\WINDOWS\System32\drivers\winmad.sys [2017-3-18 32160]
S3 WinNat;Windows NAT Driver;C:\WINDOWS\System32\drivers\winnat.sys [2017-3-18 217088]
S3 WinVerbs;WinVerbs Service;C:\WINDOWS\System32\drivers\winverbs.sys [2017-3-18 64920]
S3 xboxgip;Xbox Game Input Protocol Driver;C:\WINDOWS\System32\drivers\xboxgip.sys [2017-6-13 277504]
S3 xinputhid;XINPUT HID Filter Driver;C:\WINDOWS\System32\drivers\xinputhid.sys [2017-3-18 46592]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\WINDOWS\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2017-10-13 05:45:44 466096 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE
2017-10-13 05:44:16 29352 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll
2017-10-13 05:39:58 209072 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
2017-10-12 22:31:42 18896 ----a-w- C:\Program Files (x86)\Mozilla Firefox\qipcap64.dll
2017-10-10 20:55:56 126925120 -c--a-w- C:\WINDOWS\System32\MRT-KB890830.exe
2017-10-10 20:45:59 804864 ----a-w- C:\WINDOWS\System32\fvewiz.dll
2017-09-29 07:08:39 -------- d-----w- C:\ProgramData\McAfee Security Scan
2017-09-22 04:44:35 -------- d-----w- C:\Users\macdonald\AppData\Local\Programs
.
==================== Find3M ====================
.
2017-10-20 16:25:01 180 ----a-w- C:\WINDOWS\System32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-10-13 00:21:46 835576 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2017-10-13 00:21:46 177656 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2017-10-11 13:16:32 207872 ----a-w- C:\WINDOWS\SysWow64\msclmd.dll
2017-10-11 13:16:30 230400 ----a-w- C:\WINDOWS\System32\msclmd.dll
2017-09-30 05:52:01 1595152 ----a-w- C:\WINDOWS\System32\gdi32full.dll
2017-09-30 05:51:44 1458320 ----a-w- C:\WINDOWS\System32\msctf.dll
2017-09-30 05:51:12 1147288 ----a-w- C:\WINDOWS\System32\hvix64.exe
2017-09-30 05:50:48 1068208 ----a-w- C:\WINDOWS\System32\Windows.UI.dll
2017-09-30 05:50:46 1024920 ----a-w- C:\WINDOWS\System32\hvax64.exe
2017-09-30 05:50:44 1346112 ----a-w- C:\WINDOWS\System32\user32.dll
2017-09-30 05:49:44 777400 ----a-w- C:\WINDOWS\System32\oleaut32.dll
2017-09-30 05:49:27 135576 ----a-w- C:\WINDOWS\System32\drivers\ksecdd.sys
2017-09-30 05:49:25 1004136 ----a-w- C:\WINDOWS\System32\ucrtbase.dll
2017-09-30 05:48:27 644696 ----a-w- C:\WINDOWS\System32\advapi32.dll
2017-09-30 05:48:26 2399728 ----a-w- C:\WINDOWS\System32\KernelBase.dll
2017-09-30 05:48:12 8319384 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2017-09-30 05:48:04 2327448 ----a-w- C:\WINDOWS\System32\drivers\ntfs.sys
2017-09-30 05:47:28 1194792 ----a-w- C:\WINDOWS\System32\rpcrt4.dll
2017-09-30 05:47:05 2969880 ----a-w- C:\WINDOWS\System32\CoreUIComponents.dll
2017-09-30 05:45:54 511896 ----a-w- C:\WINDOWS\System32\drivers\usbhub.sys
2017-09-30 05:44:52 181912 ----a-w- C:\WINDOWS\System32\sspicli.dll
2017-09-30 05:44:03 712600 ----a-w- C:\WINDOWS\System32\drivers\dxgmms2.sys
2017-09-30 05:43:49 2442136 ----a-w- C:\WINDOWS\System32\drivers\dxgkrnl.sys
2017-09-30 05:43:47 7318888 ----a-w- C:\WINDOWS\System32\windows.storage.dll
2017-09-30 05:42:43 4848952 ----a-w- C:\WINDOWS\explorer.exe
2017-09-30 05:42:08 1506712 ----a-w- C:\WINDOWS\System32\twinapi.appcore.dll
2017-09-30 05:42:03 820120 ----a-w- C:\WINDOWS\System32\WWAHost.exe
2017-09-30 05:41:48 259400 ----a-w- C:\WINDOWS\System32\MusNotifyIcon.exe
2017-09-30 05:41:48 228248 ----a-w- C:\WINDOWS\System32\drivers\mrxsmb20.sys
2017-09-30 05:41:47 961944 ----a-w- C:\WINDOWS\System32\efscore.dll
2017-09-30 05:41:45 651672 ----a-w- C:\WINDOWS\System32\SettingSyncHost.exe
2017-09-30 05:41:44 5477600 ----a-w- C:\WINDOWS\System32\OneCoreUAPCommonProxyStub.dll
2017-09-30 05:41:35 257432 ----a-w- C:\WINDOWS\System32\AppxAllUserStore.dll
2017-09-30 05:41:28 5304496 ----a-w- C:\WINDOWS\System32\Windows.StateRepository.dll
2017-09-30 05:41:11 654976 ----a-w- C:\WINDOWS\System32\AppXDeploymentClient.dll
2017-09-30 05:41:00 2086808 ----a-w- C:\WINDOWS\System32\UpdateAgent.dll
2017-09-30 05:40:49 642680 ----a-w- C:\WINDOWS\System32\drivers\cng.sys
2017-09-30 05:40:45 184728 ----a-w- C:\WINDOWS\System32\drivers\appid.sys
2017-09-30 05:40:44 724704 ----a-w- C:\WINDOWS\System32\wer.dll
2017-09-30 05:40:38 336320 ----a-w- C:\WINDOWS\System32\SecurityHealthService.exe
2017-09-30 05:40:33 408984 ----a-w- C:\WINDOWS\System32\msv1_0.dll
2017-09-30 05:40:29 72944 ----a-w- C:\WINDOWS\System32\easinvoker.exe
2017-09-30 05:40:13 558912 ----a-w- C:\WINDOWS\System32\Windows.ApplicationModel.dll
2017-09-30 05:40:03 173976 ----a-w- C:\WINDOWS\System32\drivers\usbccgp.sys
2017-09-30 05:39:45 203672 ----a-w- C:\WINDOWS\System32\basecsp.dll
2017-09-30 05:38:42 2239136 ----a-w- C:\WINDOWS\System32\mfsrcsnk.dll
2017-09-30 05:38:33 7910072 ----a-w- C:\WINDOWS\System32\Windows.Media.Protection.PlayReady.dll
2017-09-30 05:36:38 2672024 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2017-09-30 05:36:28 57976 ----a-w- C:\WINDOWS\System32\lsass.exe
2017-09-30 02:29:54 1408536 ----a-w- C:\WINDOWS\SysWow64\gdi32full.dll
2017-09-30 02:29:46 804784 ----a-w- C:\WINDOWS\SysWow64\Windows.UI.dll
2017-09-30 02:26:30 1292872 ----a-w- C:\WINDOWS\SysWow64\user32.dll
2017-09-30 02:26:24 1333136 ----a-w- C:\WINDOWS\SysWow64\msctf.dll
2017-09-30 02:10:34 480920 ----a-w- C:\WINDOWS\SysWow64\advapi32.dll
2017-09-30 02:10:20 606072 ----a-w- C:\WINDOWS\SysWow64\oleaut32.dll
2017-09-30 02:10:14 1839872 ----a-w- C:\WINDOWS\SysWow64\KernelBase.dll
2017-09-30 02:10:08 1150776 ----a-w- C:\WINDOWS\SysWow64\ucrtbase.dll
2017-09-30 02:09:16 2259760 ----a-w- C:\WINDOWS\SysWow64\CoreUIComponents.dll
2017-09-30 02:09:02 787712 ----a-w- C:\WINDOWS\SysWow64\rpcrt4.dll
2017-09-30 02:06:28 4471368 ----a-w- C:\WINDOWS\SysWow64\explorer.exe
2017-09-30 02:05:47 750488 ----a-w- C:\WINDOWS\SysWow64\WWAHost.exe
2017-09-30 02:05:45 5827744 ----a-w- C:\WINDOWS\SysWow64\windows.storage.dll
2017-09-30 02:05:39 559000 ----a-w- C:\WINDOWS\SysWow64\SettingSyncHost.exe
2017-09-30 02:05:36 1266544 ----a-w- C:\WINDOWS\SysWow64\twinapi.appcore.dll
2017-09-30 02:05:34 2603744 ----a-w- C:\WINDOWS\SysWow64\OneCoreUAPCommonProxyStub.dll
2017-09-30 02:04:52 612120 ----a-w- C:\WINDOWS\SysWow64\wer.dll
2017-09-30 02:04:50 4215184 ----a-w- C:\WINDOWS\SysWow64\Windows.StateRepository.dll
2017-09-30 02:04:45 347544 ----a-w- C:\WINDOWS\SysWow64\msv1_0.dll
2017-09-30 02:04:39 438096 ----a-w- C:\WINDOWS\SysWow64\Windows.ApplicationModel.dll
2017-09-30 02:04:17 519680 ----a-w- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
2017-09-30 02:04:13 182680 ----a-w- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
2017-09-30 02:03:27 6768288 ----a-w- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
2017-09-30 02:03:17 1439032 ----a-w- C:\WINDOWS\SysWow64\mfsrcsnk.dll
2017-09-30 02:02:53 175512 ----a-w- C:\WINDOWS\SysWow64\basecsp.dll
2017-09-30 02:01:54 124544 ----a-w- C:\WINDOWS\SysWow64\sspicli.dll
2017-09-29 07:46:30 23678976 ----a-w- C:\WINDOWS\System32\edgehtml.dll
2017-09-29 07:45:00 2953216 ----a-w- C:\WINDOWS\SysWow64\win32kfull.sys
2017-09-29 07:44:19 133120 ----a-w- C:\WINDOWS\SysWow64\t2embed.dll
2017-09-29 07:43:14 2199552 ----a-w- C:\WINDOWS\SysWow64\Windows.UI.Xaml.Resources.dll
2017-09-29 07:43:07 142336 ----a-w- C:\WINDOWS\SysWow64\smartscreenps.dll
2017-09-29 07:43:05 60928 ----a-w- C:\WINDOWS\SysWow64\usoapi.dll
2017-09-29 07:42:56 18944 ----a-w- C:\WINDOWS\SysWow64\mgmtapi.dll
2017-09-29 07:41:56 13844992 ----a-w- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
2017-09-29 07:41:50 50176 ----a-w- C:\WINDOWS\SysWow64\wbem\Win32_Tpm.dll
2017-09-29 07:41:09 110080 ----a-w- C:\WINDOWS\SysWow64\BitLockerCsp.dll
2017-09-29 07:40:57 6728192 ----a-w- C:\WINDOWS\SysWow64\twinui.dll
2017-09-29 07:40:50 371200 ----a-w- C:\WINDOWS\SysWow64\daxexec.dll
2017-09-29 07:40:25 86528 ----a-w- C:\WINDOWS\SysWow64\updatepolicy.dll
2017-09-29 07:39:51 364032 ----a-w- C:\WINDOWS\SysWow64\msIso.dll
2017-09-29 07:39:01 20511232 ----a-w- C:\WINDOWS\SysWow64\edgehtml.dll
2017-09-29 07:38:55 471040 ----a-w- C:\WINDOWS\SysWow64\TpmCoreProvisioning.dll
2017-09-29 07:38:51 229376 ----a-w- C:\WINDOWS\SysWow64\scksp.dll
2017-09-29 07:38:35 1135616 ----a-r- C:\WINDOWS\SysWow64\icuuc.dll
2017-09-29 07:38:18 2671616 ----a-w- C:\WINDOWS\SysWow64\tquery.dll
2017-09-29 07:38:15 370688 ----a-w- C:\WINDOWS\SysWow64\FirewallAPI.dll
2017-09-29 07:38:11 463360 ----a-w- C:\WINDOWS\SysWow64\webio.dll
2017-09-29 07:38:03 5721600 ----a-w- C:\WINDOWS\SysWow64\BingMaps.dll
2017-09-29 07:38:03 308224 ----a-w- C:\WINDOWS\SysWow64\cryptngc.dll
2017-09-29 07:37:45 306688 ----a-w- C:\WINDOWS\SysWow64\Windows.Graphics.dll
.
============= FINISH: 19:37:33.48 ===============

Attached Files
File Type: txt attach.txt (5.9 KB)

Japanese Porn Malware

$
0
0
I was visiting some Japanese websites to view manga images. I notiiced later a file in my

download folder. Foolishly, I clicked on it, and watched in horror as it installed sometthing.

Now, every 5 minutes a window pops up with japanese porno on it.

I saved the original file, and have it zipped up. It seems to be a self-executing zip file in exe

format.

When I log on to the computer, I can see a windows command box (black box) open and doing

something. There is a file listed in 'applications' with no name that I am unable to terminate.

I can see nothing unusual in hijack this logs or malwarebytes scans.

The file infected a non-privleged account, and the administrator account is not infected.

Attached are two screen shots, one of the pop-up window, and one of the task manager,

I was unable to upload the 7-zip file that includes the original executable that I ran to get

infected, it was rejected, however I can email it.

Jamie




Viewing image 0JIZF.png

Viewing image UDhqr.png

Computer Keeps trying to open .tmp files

$
0
0
Computer has been constantly trying to open .tmp files but i don't know the name of the file or how to locate it. There is a possibility that there are multiple files, as well.

Task manager also shows processes with no names that lead to a svchost.exe. Its protected under "TrustedInstaller" profile.

I've checked the startup and there are two programs named RevoTemp and loevmcue that have no publisher. As in, it is blank.

Ran full virus scans and removed the Trojans accordingly but when checking for viruses again after restarting, there are more.

Lag after everything I do

$
0
0
before I post the logs I wonder if there's an easier way to get rid of this. I'm pretty sure it's malware. Basically, there is about 2-3 seconds of lag after almost everything I do. In the middle of typing a sentence, 2-3 seconds for my cursor to change when I hover over something with my mouse, dragging a scrollbar, etc. Could it be a keylogger do you think? In that case they'll see what I'm typing right now.

I've used malware bytes and super anti-spware, they found lots of things but didn't get rid of this. I think prevention is usually better than cure so I make backups with Acronis True Image, but my backups (at least some of them) have become corrupted and I can't use them. The other problem is I'll lose everything that's been installed after the backup I use. It would be nice if there's a backup program that would tell me everything that's gone on my computer since the last backup- So, if I restore before it and don't have this problem, I'll know it happened sometimes after that backup, narrow it down basically to the point it came to my system, and if it could restore everything BUT that, that would be good.

Having an issue with win7, not sure if it's a virus or simply corrupted files.

$
0
0
Background:
Was on computer late one night checking facebook, seldom use it, but son lives in USVI, and I hadn't heard from him since after Irma and it's sometimes the most reliable means to communicate, might miss a 'call' but it's there :)
Anyway, checked FB, shut down and went to sleep, in the morning I turned on the computer and was met with an X on action center notifications (Turn on update,find Av, configure update,They all were on/set up) network (no connections available, does work, using it now), as well as sound (audio service not running).

When attempting to open windows explorer, control panel etc, I get a message saying:

"windows cannot access the specified device, path or file. You may not have the appropriate permmissions to access them"

I can not enter control panel or explorer, a command prompt will get me anywhere on my computer, and even though it say's no connection for network, I can reach anywhere on my network that I have a shortcut for on my desktop, the same for files on my computer.

The only reall error that shows up when I'm motivated to start digging is a 'shell32.dll' error, but if I remember right, there are hundreds of actions that go through shell32, so doesn't help me narrow it down any.

My normal practice is to backup once a week, but been in and out of hospital for a while and my last backup was in may....

Spybot as well as malware bytes show no infection, so not sure what the issue is.

Other issues, I can open pretty much any download, as long as it is NOT a zip file, an open anything on my computer or navigate to any disk, computer. network location either through another program (as in save here, look here etc), just not through 'normal' methods.

Recovery by using the install DVD doesn't work either.

I have copied all the important files over to another drive, so a fresh install isn't a dealbreaker, but I have several large games and other programs that were installed over the net, lousy internet here so reinstalling many of them means staying up to 3-4 am, would prefer to avoid that....

Basically, my question is, is it a virus, or a corrupted file system?
If a virus, How can I get rid of it, if it's a corrupted file, where should I look to repair it?

Did attempt a repair install of w7, as well as a (can't think of a polite word for going to w10, I owe a lot of what I know about wine to w10....),install while saving files, and they will not even start.
responce was "windows can not retrieve a response from this computer' (from memory)


As mentioned, I am not certain if it is a virus or a corrupted file/system just want to avoid sleepless nights of reinstalling programs :)

(and yeah, I know I tend to ramble, but well, you try to make sense when loaded with narcotics...)

edit: no, don't like them, want them, but they are the only things that work. Vicious circle. So, if I get goofy you know why....

Exe not working

$
0
0
I have been having a problem trying to solve this by doing various recommendations from the Net. None are working and I fear that if I keep on fiddling with things, it could make an annoying problem worse. Some of the proposed solutions involved downloading exe files which of course do not open, A couple I did manage to use, FixExec and exefix did nothing. I created an Exe.reg notepad file and have been into my registry files and changed settings but nothing works. I think a virus may have been behind it.

Before posting here I also did a Hitman Pro scan and I kept the notepad results. I can also post that if deemed helpful. Thank you.

Below is the dds text:

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16800 BrowserJavaVersion: 11.51.2
Run by Raymond at 11:25:52 on 2017-11-14
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\Update\1.3.33.5\GoogleCrashHandler.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\AERTSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Common Files\DVDVideoSoft\lib\app_updater.exe
C:\Windows\ehome\ehRecvr.exe
C:\Windows\ehome\ehsched.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\OpenOffice 4\program\scalc.exe
C:\Program Files\OpenOffice 4\program\soffice.exe
C:\Program Files\OpenOffice 4\program\soffice.bin
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uStart Page = Google
uSearch Bar = Google
uSearch Page = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=
mStart Page = Google
mSearch Bar = Google
mSearch Page = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=
uSearchAssistant = hxxp://www.google.com/ie
dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - <orphaned>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.8.0_51\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - LocalServer32 - <no file>
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre1.8.0_51\bin\jp2ssv.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uPolicies-Explorer: NoDrives = dword:0
uPolicies-Explorer: NoDriveTypeAutoRun = dword:221
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: SoftwareSASGeneration = dword:1
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 192.168.178.1
TCP: Interfaces\{C0E7945C-A4EC-4A2F-9E76-1D3197EE9606} : DHCPNameServer = 192.168.178.1
Handler: AutorunsDisabled - <Clsid value has no data>
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\49.0.2623.112\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
============= SERVICES / DRIVERS ===============
.
.
=============== File Associations ===============
.
FileExt: .txt: soffice.StarWriterDocument.6="c:\program files\openoffice 4\program\swriter.exe" -o "%1" [UserChoice]
.
=============== Created Last 30 ================
.
2017-11-13 0324 -------- d-----w- c:\users\raymond\appdata\local\iSkysoft
2017-11-12 22:36:00 876 ----a-w- c:\users\raymond\Exe.reg
2017-11-10 06:00:12 11282328 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{f6110767-5df6-4862-9b96-b1dff4e429be}\mpengine.dll
2017-11-01 02:32:51 -------- d-----w- c:\users\raymond\appdata\local\{BF486113-999F-4C81-87D4-F2481426C22B}
2017-10-28 23:34:30 -------- d-----w- c:\users\raymond\appdata\local\{2D2927EA-DE07-4B87-8572-144791627C48}
2017-10-20 20:24:47 0 ----a-w- c:\windows\ativpsrm.bin
.
==================== Find3M ====================
.
.
============= FINISH: 11:26:06.67 ===============
Attached Files
File Type: txt attach.txt (5.3 KB, 1 views)

Computer keeps trying to reach several IPs

$
0
0
In last couple day, comp start try 2 reach out from my comp out to random IPs (block by peerblock), go thru 1000s of ports from 1 internal IP. Only new thing install is bluestack android emulater. Also new 11-14 msft updates: "nov security monthly rollback..." and "win malicious sfot remove tool -
nov '17". I uninstall bluestack but ip attempt still continue.

Run scans: Norton AV, super antispyware, MBAM and spybot sd - all come bak clean, no infect no rootkit, etc. Unfortunately no hav restore pt (sys restore somhow turn off at some pt in past w/o my know?) to go back to.

Try 2 connect 2 follwing IPs thousands time/minute (but only when internet adapter turn on. when i turn off, attempt stop, duno if important or obvious)

Quote:

"ei du pont de nemours and co, inc"
52.35.84.242
52.42.120.251

"merit compuyter network"
35.166.159.188
I do no know if some soft is attempt 2 update, or if infection, or what. Try 2 google info about IPs but only find generic amazon info, no hint what this could be


DDS contents as reqwuest:

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.18838 BrowserJavaVersion: 11.151.2
Run by at 4:00:54 on 2017-11-16
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.12279.7112 [GMT -8:00]
.
AV: Norton Security Suite *Disabled/Updated* {30744133-1E94-7B35-F4A3-82A5AEF1CBAA}
AV: Malwarebytes *Enabled/Updated* {23007AD3-69FE-687C-2629-D584AFFAF72B}
SP: Malwarebytes *Enabled/Updated* {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Security Suite *Disabled/Updated* {8B15A0D7-38AE-74BB-CE13-B9D7D5768117}
FW: Norton Security Suite *Enabled* {084FC016-54FB-7A6D-DFFC-2B9050228CD1}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files (x86)\Backblaze\bzserv.exe
C:\Windows\system32\DbxSvc.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Norton Security Suite\Engine\22.11.2.7\N360.exe
C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
C:\Program Files (x86)\Skype\Updater\Updater.exe
C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Norton Security Suite\Engine\22.11.2.7\N360.exe
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\SysWOW64\muachost.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
C:\Program Files\PeerBlock\peerblock.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\SysWOW64\Ctxfihlp.exe
C:\Windows\SysWOW64\CTXFISPI.EXE
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\sysWOW64\wbem\wmiprvse.exe
C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uDefault_Page_URL = hxxp://www.alienware.com/
mWinlogon: Userinit = userinit.exe,
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: Norton Identity Safety: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine32\22.11.2.7\coIEPlg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine32\22.11.2.7\coIEPlg.dll
uRun: [PeerBlock] C:\Program Files\PeerBlock\peerblock.exe
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [Battle.net] "C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe" --autostarted
mRun: [VolPanel] "C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
mRun: [UpdReg] C:\Windows\UpdReg.EXE
mRun: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
mRun: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [CTxfiHlp] CTXFIHLP.EXE
dRun: [Backblaze] "C:\Program Files (x86)\Backblaze\bzbui.exe" -quiet
dRunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
mPolicies-System: DSCAutomationHostEnabled = dword:2
IE: Call this number using SideSync - <no file>
IE: Send image to &Bluetooth Device... - <no file>
IE: Send page to &Bluetooth Device... - <no file>
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{31343272-88BD-4405-B81D-B1ACE866391C} : DHCPNameServer = 75.75.75.75 75.75.76.76
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll",CreateReaderUserSettings
x64-BHO: Norton Identity Safety: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\22.11.2.7\coIEPlg.dll
x64-TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\22.11.2.7\coIEPlg.dll
x64-Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe
x64-Run: [Command Center Controllers] "C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe"
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [BoxSync] "C:\Program Files\Box\Box Sync\BoxSync.exe" -m
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://www.oracle.com/technetwork/java/index.html
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.94\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
Hosts: 127.0.0.1 spywareinfo.com*-*This website is for sale!*-*spywareinfo Resources and Information.
.
============= SERVICES / DRIVERS ===============
.
R0 MBAMChameleon;MBAMChameleon;C:\Windows\System32\drivers\MbamChameleon.sys [2017-11-15 193464]
R0 SymEFASI;Symantec Extended File Attributes (SI);C:\Windows\System32\drivers\N360x64\160B020.007\symefasi64.sys [2017-11-15 1938584]
R1 BHDrvx64;BHDrvx64;C:\Program Files (x86)\Norton Security Suite\NortonData\22.5.2.15\Definitions\BASHDefs\20171108.001\BHDrvx64.sys [2017-11-9 1872024]
R1 ccSet_N360;N360 Settings Manager;C:\Windows\System32\drivers\N360x64\160B020.007\ccsetx64.sys [2017-11-15 187544]
R1 ElRawDisk;ElRawDisk;C:\Windows\System32\drivers\ElRawDsk.sys [2017-7-18 30752]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit;C:\Windows\System32\drivers\mbae64.sys [2017-11-14 77432]
R1 IDSVia64;IDSVia64;C:\Program Files (x86)\Norton Security Suite\NortonData\22.5.2.15\Definitions\IPSDefs\20171115.001\IDSvia64.sys [2017-11-15 1056920]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\N360x64\160B020.007\ironx64.sys [2017-11-15 309984]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\N360x64\160B020.007\symnets.sys [2017-11-15 566936]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2014-7-22 173472]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2014-12-11 98208]
R2 bzserv;Backblaze Service;C:\Program Files (x86)\Backblaze\bzserv.exe [2014-2-21 444648]
R2 DbxSvc;DbxSvc;C:\Windows\System32\DbxSvc.exe [2017-11-13 51016]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 IOCBIOS;IOCBIOS;C:\ProgramData\Intel\Extreme Tuning Utility\IOCbios\64bit\iOCbios.sys [2009-7-9 27096]
R2 iocbios2;iocbios2;C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [2014-6-17 28912]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2013-8-20 72216]
R2 MBAMService;Malwarebytes Service;C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [2017-11-14 6234056]
R2 N360;Norton 360;C:\Program Files (x86)\Norton Security Suite\Engine\22.11.2.7\n360.exe [2017-11-15 326144]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container;C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-25 518080]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2017-10-26 462968]
R2 NvTelemetryContainer;NVIDIA Telemetry Container;C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [2017-10-25 460736]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2013-8-9 1153368]
R2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
R2 ss_conn_service;SAMSUNG Mobile Connectivity Service;C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [2017-6-16 754784]
R3 CT20XUT.SYS;CT20XUT.SYS;C:\Windows\System32\drivers\CT20XUT.sys [2012-12-18 232880]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\Windows\System32\drivers\CTEXFIFX.sys [2012-12-18 1448368]
R3 CTHWIUT.SYS;CTHWIUT.SYS;C:\Windows\System32\drivers\CTHWIUT.sys [2012-12-18 97712]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2017-10-23 158360]
R3 ha20x22k;Creative 20X2 HAL Driver;C:\Windows\System32\drivers\ha20x22k.sys [2012-12-18 1617328]
R3 LGPBTDD;LGPBTDD.sys Display Driver;C:\Windows\System32\drivers\LGPBTDD.sys [2009-7-1 30728]
R3 MBAMFarflt;MBAMFarflt;C:\Windows\System32\drivers\farflt.sys [2017-11-15 110016]
R3 MBAMProtection;MBAMProtection;C:\Windows\System32\drivers\mbam.sys [2017-11-15 46008]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\mbamswissarmy.sys [2017-11-15 253880]
R3 MBAMWebProtection;MBAMWebProtection;C:\Windows\System32\drivers\mwac.sys [2017-11-15 84256]
R3 mio;Master IO Filter Driver;C:\Windows\System32\drivers\mio.sys [2011-5-4 7680]
R3 Neo_VPN;VPN Client Device Driver - VPN;C:\Windows\System32\drivers\neo_vpn.sys [2017-1-3 29744]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\Windows\System32\drivers\nvvad64v.sys [2017-10-25 50624]
R3 nvvhci;NVVHCI Enumerator Service;C:\Windows\System32\drivers\nvvhci.sys [2017-10-26 57792]
R3 pbfilter;pbfilter;C:\Program Files\PeerBlock\pbfilter.sys [2013-8-9 22600]
S2 AlienFusionService;Alienware Fusion Service;C:\Program Files\Alienware\Command Center\AlienFusionService.exe [2012-6-18 14704]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-4-21 107656]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-4-21 128648]
S2 dbupdate;Dropbox Update Service (dbupdate);C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-1-3 143144]
S2 XTU3SERVICE;Intel(R) Extreme Tuning Utility Service;C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe [2015-3-25 17720]
S3 BoxSyncUpdateService;Box Sync Update Service;C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [2017-8-7 36680]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2009-11-21 35104]
S3 chromoting;Chrome Remote Desktop Service;C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe [2017-11-2 71512]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-11-21 79360]
S3 CT20XUT;CT20XUT;C:\Windows\System32\drivers\CT20XUT.sys [2012-12-18 232880]
S3 CTEXFIFX;CTEXFIFX;C:\Windows\System32\drivers\CTEXFIFX.sys [2012-12-18 1448368]
S3 CTHWIUT;CTHWIUT;C:\Windows\System32\drivers\CTHWIUT.sys [2012-12-18 97712]
S3 dbupdatem;Dropbox Update Service (dbupdatem);C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-1-3 143144]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2017-5-18 131984]
S3 I2cHkBurn;I2cHkBurn;C:\Windows\System32\drivers\I2cHkBurn.sys [2017-10-25 41760]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2017-11-14 116224]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2009-11-21 317480]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;C:\Windows\System32\drivers\LGBusEnum.sys [2009-11-23 22408]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;C:\Windows\System32\drivers\LGVirHid.sys [2009-11-23 16008]
S3 MonitorFunction;Driver for Monitor;C:\Windows\System32\drivers\TVMonitor.sys [2014-7-10 16376]
S3 NvContainerNetworkService;NVIDIA NetworkService Container;C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-25 518080]
S3 NvStreamKms;NVIDIA KMS;C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2017-10-25 30144]
S3 PAExec;PAExec;C:\Windows\PAExec.exe -service --> C:\Windows\PAExec.exe -service [?]
S3 PSKMAD;PSKMAD;C:\Windows\System32\drivers\PSKMAD.sys [2015-9-30 50320]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2017-9-14 19456]
S3 SaiK0CCB;SaiK0CCB;C:\Windows\System32\drivers\SaiK0CCB.sys [2012-9-20 180544]
S3 SaiU0CCB;SaiU0CCB;C:\Windows\System32\drivers\SaiU0CCB.sys [2012-9-20 47168]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\System32\drivers\ssudmdm.sys [2017-5-18 166288]
S3 Te.Service;Te.Service;C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [2014-10-24 122368]
S3 TeamViewer;TeamViewer 10;C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2014-12-2 5613328]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2017-9-14 56832]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-8-10 1255736]
.
=============== File Associations ===============
.
FileExt: .js: Applications\atom.exe="C:\Users\\AppData\Local\atom\app-1.17.2\atom.exe" "%1" [UserChoice]
.
=============== Created Last 30 ================
.
2017-11-16 06:53:25 566936 ----a-w- C:\Windows\System32\drivers\N360x64\160B020.007\symnets.sys
2017-11-16 06:53:25 468616 ----a-w- C:\Windows\System32\drivers\N360x64\160B020.007\symtdiv.sys
2017-11-16 06:53:25 24608 ----a-w- C:\Windows\System32\drivers\N360x64\160B020.007\symelam.sys
2017-11-16 06:53:25 1938584 ----a-w- C:\Windows\System32\drivers\N360x64\160B020.007\symefasi64.sys
2017-11-16 06:53:24 812696 ----a-w- C:\Windows\System32\drivers\N360x64\160B020.007\srtsp64.sys
2017-11-16 06:53:24 49304 ----a-w- C:\Windows\System32\drivers\N360x64\160B020.007\srtspx64.sys
2017-11-16 06:53:24 309984 ----a-w- C:\Windows\System32\drivers\N360x64\160B020.007\ironx64.sys
2017-11-16 06:53:24 187544 ----a-w- C:\Windows\System32\drivers\N360x64\160B020.007\ccsetx64.sys
2017-11-16 06:53:06 -------- d-----w- C:\Windows\System32\drivers\N360x64\160B020.007
2017-11-16 00:59:15 136312 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2017-11-16 00:59:04 927544 ----a-w- C:\Windows\System32\vulkan-1.dll
2017-11-16 00:59:04 798008 ----a-w- C:\Windows\SysWow64\vulkan-1.dll
2017-11-16 00:59:04 591160 ----a-w- C:\Windows\System32\vulkaninfo.exe
2017-11-16 00:59:04 490296 ----a-w- C:\Windows\SysWow64\vulkaninfo.exe
2017-11-16 00:59:04 -------- d-----w- C:\Program Files (x86)\VulkanRT
2017-11-15 11:28:07 193464 ----a-w- C:\Windows\System32\drivers\MbamChameleon.sys
2017-11-15 11:28:05 110016 ----a-w- C:\Windows\System32\drivers\farflt.sys
2017-11-15 11:28:02 84256 ----a-w- C:\Windows\System32\drivers\mwac.sys
2017-11-15 11:28:02 46008 ----a-w- C:\Windows\System32\drivers\mbam.sys
2017-11-15 11:28:02 253880 ----a-w- C:\Windows\System32\drivers\mbamswissarmy.sys
2017-11-14 21:35:06 77432 ----a-w- C:\Windows\System32\drivers\mbae64.sys
2017-11-14 21:34:49 -------- d-----w- C:\ProgramData\MB3CoreBackup
2017-11-13 10:26:48 51016 ----a-w- C:\Windows\System32\DbxSvc.exe
2017-11-13 10:26:48 45672 ----a-w- C:\Windows\System32\drivers\dbx-dev.sys
2017-11-13 10:26:48 45640 ----a-w- C:\Windows\System32\drivers\dbx-stable.sys
2017-11-13 10:26:48 45640 ----a-w- C:\Windows\System32\drivers\dbx-canary.sys
2017-11-10 10:34:51 2023936 ----a-w- C:\Windows\System32\aitstatic.exe
2017-11-10 10:34:50 670208 ----a-w- C:\Windows\System32\generaltel.dll
2017-11-10 10:34:50 605184 ----a-w- C:\Windows\System32\aeinv.dll
2017-11-10 10:34:50 603648 ----a-w- C:\Windows\System32\devinv.dll
2017-11-10 10:34:50 407392 ----a-w- C:\Windows\System32\centel.dll
2017-11-10 10:34:50 370688 ----a-w- C:\Windows\System32\invagent.dll
2017-11-10 10:34:50 241664 ----a-w- C:\Windows\System32\aepic.dll
2017-11-10 10:34:50 181760 ----a-w- C:\Windows\System32\acmigration.dll
2017-11-10 10:34:50 1570304 ----a-w- C:\Windows\System32\appraiser.dll
2017-11-10 10:34:50 134376 ----a-w- C:\Windows\System32\CompatTelRunner.exe
2017-11-03 05:04:37 -------- d-----w- C:\ShadowPlay
2017-11-02 09:15:19 -------- d-----w- C:\Users\\AppData\Roaming\Guild Wars 2
2017-10-31 08:06:19 1989056 ----a-w- C:\Windows\System32\nvdispco6438813.dll
2017-10-31 08:06:19 1673848 ----a-w- C:\Windows\System32\nvdispgenco6438813.dll
2017-10-29 19:59:48 -------- d---a-w- C:\Program Files (x86)\BlueStacks
2017-10-29 19:59:21 -------- d-----w- C:\Users\\AppData\Local\Bluestacks
2017-10-27 07:54:56 82040 ----a-w- C:\Windows\System32\nv3dappshextr.dll
2017-10-27 07:54:55 7855841 ----a-w- C:\Windows\System32\nvcoproc.bin
2017-10-27 07:54:55 607352 ----a-w- C:\Windows\System32\nv3dappshext.dll
2017-10-27 07:54:55 2587584 ----a-w- C:\Windows\System32\nvsvc64.dll
2017-10-27 07:54:55 123000 ----a-w- C:\Windows\System32\nvshext.dll
2017-10-27 07:54:54 5960640 ----a-w- C:\Windows\System32\nvcpl.dll
2017-10-27 07:54:54 449472 ----a-w- C:\Windows\System32\nvmctray.dll
2017-10-27 07:54:54 1766336 ----a-w- C:\Windows\System32\nvsvcr.dll
2017-10-27 07:53:59 1951 ----a-w- C:\Windows\NvContainerRecovery.bat
2017-10-27 07:53:34 532088 ----a-w- C:\Windows\System32\OpenCL.dll
2017-10-27 07:53:34 437696 ----a-w- C:\Windows\SysWow64\OpenCL.dll
2017-10-27 07:49:29 57792 ----a-w- C:\Windows\System32\drivers\nvvhci.sys
2017-10-27 07:49:12 45496 ----a-w- C:\Windows\System32\nvhdap64.dll
2017-10-27 07:49:12 225208 ----a-w- C:\Windows\System32\drivers\nvhda64v.sys
2017-10-27 07:49:12 1615472 ----a-w- C:\Windows\System32\nvhdagenco6420103.dll
2017-10-27 07:49:07 492232 ----a-w- C:\Windows\System32\nvumdshimx.dll
2017-10-27 07:49:07 22096064 ----a-w- C:\Windows\System32\nvwgf2umx.dll
2017-10-27 07:49:07 19362944 ----a-w- C:\Windows\SysWow64\nvwgf2um.dll
2017-10-27 07:48:58 36193912 ----a-w- C:\Windows\System32\nvoglv64.dll
2017-10-27 07:48:18 1606592 ----a-w- C:\Windows\System32\nvdispgenco6438800.dll
2017-10-27 07:48:16 1988032 ----a-w- C:\Windows\System32\nvdispco6438800.dll
2017-10-27 07:48:16 18207576 ----a-w- C:\Windows\System32\nvd3dumx.dll
2017-10-27 07:48:14 15027984 ----a-w- C:\Windows\SysWow64\nvd3dum.dll
2017-10-27 07:48:11 4284680 ----a-w- C:\Windows\System32\nvapi64.dll
2017-10-27 07:48:11 3798848 ----a-w- C:\Windows\SysWow64\nvapi.dll
2017-10-26 05:04:56 -------- d-----w- C:\Users\\AppData\Roaming\MSI
2017-10-26 05:02:47 -------- d-----w- C:\Users\\AppData\Roaming\NVIDIA
2017-10-26 05:00:57 -------- d-----w- C:\Windows\SysWow64\LiveUpdate
2017-10-25 21:48:15 918976 ----a-w- C:\Windows\System32\NvRtmpStreamer64.dll
2017-10-25 21:48:15 1796032 ----a-w- C:\Windows\System32\nvspcap64.dll
2017-10-25 21:48:15 1577920 ----a-w- C:\Windows\SysWow64\nvspcap.dll
2017-10-25 21:47:23 1951 ----a-w- C:\Windows\NvTelemetryContainerRecovery.bat
2017-10-25 21:46:55 50624 ----a-w- C:\Windows\System32\drivers\nvvad64v.sys
2017-10-25 21:43:22 11248 ----a-w- C:\Windows\acpimof.dll
2017-10-25 21:40:44 1692840 ----a-w- C:\Windows\SysWow64\muachost.exe
2017-10-25 21:40:40 41760 ----a-w- C:\Windows\System32\drivers\I2cHkBurn.sys
2017-10-25 21:40:40 31520 ----a-w- C:\Windows\System32\FintekIcon1.dll
2017-10-25 21:40:32 -------- d-----w- C:\Program Files (x86)\MSI
2017-10-25 21:40:32 -------- d-----w- C:\MSI
2017-10-25 21:40:26 -------- d-----w- C:\Users\\AppData\Local\NVIDIA Corporation
2017-10-25 21:39:35 186304 ----a-w- C:\Windows\System32\nvaudcap64v.dll
2017-10-25 21:39:35 152512 ----a-w- C:\Windows\SysWow64\nvaudcap32v.dll
.
==================== Find3M ====================
.
2017-11-16 06:53:49 102600 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2017-11-14 20:19:00 127017032 -c--a-w- C:\Windows\System32\MRT-KB890830.exe
2017-11-14 09:47:24 803328 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2017-11-14 09:47:24 144896 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2017-10-25 21:27:16 466520 ----a-w- C:\Windows\System32\wrap_oal.dll
2017-10-25 21:27:15 445016 ----a-w- C:\Windows\SysWow64\wrap_oal.dll
2017-10-25 21:27:15 123480 ----a-w- C:\Windows\System32\OpenAL32.dll
2017-10-25 21:27:15 109144 ----a-w- C:\Windows\SysWow64\OpenAL32.dll
2017-10-20 20:18:39 97856 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2017-10-18 02:06:57 344064 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2017-10-18 02:06:46 99840 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2017-10-18 02:06:40 56320 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2017-10-18 02:06:40 327168 ----a-w- C:\Windows\System32\drivers\usbport.sys
2017-10-18 02:06:39 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2017-10-18 02:06:37 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2017-10-18 02:06:35 7808 ----a-w- C:\Windows\System32\drivers\usbd.sys
2017-10-16 23:07:21 1680616 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2017-10-16 22:34:01 3222528 ----a-w- C:\Windows\System32\win32k.sys
2017-10-16 21:55:15 339968 ----a-w- C:\Windows\SysWow64\msexcl40.dll
2017-10-14 08:23:45 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2017-10-14 08:23:37 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2017-10-14 08:12:05 66560 ----a-w- C:\Windows\System32\iesetup.dll
2017-10-14 08:11:31 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2017-10-14 08:11:27 576512 ----a-w- C:\Windows\System32\vbscript.dll
2017-10-14 08:11:27 417792 ----a-w- C:\Windows\System32\html.iec
2017-10-14 08:11:00 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2017-10-14 08:09:27 5979648 ----a-w- C:\Windows\System32\jscript9.dll
2017-10-14 08:01:18 116224 ----a-w- C:\Windows\System32\ieetwcollector.exe
2017-10-14 08:01:17 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2017-10-14 08:00:59 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2017-10-14 07:55:55 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2017-10-14 07:47:21 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2017-10-14 07:47:00 87552 ----a-w- C:\Windows\System32\tdc.ocx
2017-10-14 07:28:00 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2017-10-14 07:27:51 2134528 ----a-w- C:\Windows\System32\inetcpl.cpl
2017-10-14 07:21:58 3241472 ----a-w- C:\Windows\System32\wininet.dll
2017-10-14 07:03:12 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2017-10-14 06:53:24 499200 ----a-w- C:\Windows\SysWow64\vbscript.dll
2017-10-14 06:53:05 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2017-10-14 06:52:38 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2017-10-14 06:52:31 341504 ----a-w- C:\Windows\SysWow64\html.iec
2017-10-14 06:51:50 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2017-10-14 06:45:19 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2017-10-14 06:45:05 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2017-10-14 06:35:28 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2017-10-14 06:35:07 73216 ----a-w- C:\Windows\SysWow64\tdc.ocx
2017-10-14 06:33:00 4542464 ----a-w- C:\Windows\SysWow64\jscript9.dll
2017-10-14 06:23:38 2058752 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2017-10-14 06:23:25 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2017-10-14 06:10:41 2767872 ----a-w- C:\Windows\SysWow64\wininet.dll
2017-10-12 00:58:25 382696 ----a-w- C:\Windows\System32\atmfd.dll
2017-10-12 00:40:31 308456 ----a-w- C:\Windows\SysWow64\atmfd.dll
2017-10-12 00:39:11 591872 ----a-w- C:\Windows\System32\SearchIndexer.exe
2017-10-12 00:38:44 249856 ----a-w- C:\Windows\System32\SearchProtocolHost.exe
2017-10-12 00:38:15 113664 ----a-w- C:\Windows\System32\SearchFilterHost.exe
2017-10-12 00:26:21 427520 ----a-w- C:\Windows\SysWow64\SearchIndexer.exe
2017-10-12 00:26:07 164352 ----a-w- C:\Windows\SysWow64\SearchProtocolHost.exe
2017-10-12 00:25:47 86528 ----a-w- C:\Windows\SysWow64\SearchFilterHost.exe
2017-10-12 00:25:28 9728 ----a-w- C:\Windows\SysWow64\msshooks.dll
2017-10-12 00:24:38 4096 ----a-w- C:\Windows\SysWow64\msdxm.ocx
2017-10-12 00:24:38 4096 ----a-w- C:\Windows\SysWow64\dxmasf.dll
2017-10-12 00:24:37 8192 ----a-w- C:\Windows\SysWow64\spwmp.dll
2017-10-12 00:20:09 113152 ----a-w- C:\Windows\System32\drivers\luafv.sys
2017-10-12 00:16:05 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2017-09-13 23:20:30 798008 ----a-w- C:\Windows\SysWow64\vulkan-1-1-0-61-0.dll
2017-09-13 23:20:14 490296 ----a-w- C:\Windows\SysWow64\vulkaninfo-1-1-0-61-0.exe
2017-09-13 23:19:50 927544 ----a-w- C:\Windows\System32\vulkan-1-1-0-61-0.dll
2017-09-13 23:19:38 591160 ----a-w- C:\Windows\System32\vulkaninfo-1-1-0-61-0.exe
2017-09-13 15:33:50 631176 ----a-w- C:\Windows\System32\winresume.efi
2017-09-13 15:32:36 706792 ----a-w- C:\Windows\System32\winload.efi
2017-09-13 15:32:35 5547752 ----a-w- C:\Windows\System32\ntoskrnl.exe
2017-09-13 15:32:33 95464 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2017-09-13 15:32:33 154856 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2017-09-13 15:31:56 1732864 ----a-w- C:\Windows\System32\ntdll.dll
2017-09-13 15:27:59 731648 ----a-w- C:\Windows\System32\kerberos.dll
2017-09-13 15:13:35 4001512 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2017-09-13 15:13:35 3945704 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2017-09-13 15:10:46 1314112 ----a-w- C:\Windows\SysWow64\ntdll.dll
2017-09-13 15:08:59 554496 ----a-w- C:\Windows\SysWow64\kerberos.dll
2017-09-13 15:05:20 324608 ----a-w- C:\Windows\System32\drivers\nwifi.sys
2017-09-13 15:00:54 148480 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2017-09-13 15:00:50 62464 ----a-w- C:\Windows\System32\drivers\appid.sys
2017-09-13 15:00:50 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2017-09-13 15:00:10 64000 ----a-w- C:\Windows\System32\auditpol.exe
2017-09-13 14:57:12 338432 ----a-w- C:\Windows\System32\conhost.exe
2017-09-13 14:56:20 296960 ----a-w- C:\Windows\System32\rstrui.exe
2017-09-13 14:53:40 159744 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2017-09-13 14:53:06 291328 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2017-09-13 14:53:04 129536 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2017-09-13 14:52:23 30720 ----a-w- C:\Windows\System32\lsass.exe
2017-09-13 14:52:20 112640 ----a-w- C:\Windows\System32\smss.exe
2017-09-13 14:50:26 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2017-09-13 14:47:00 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2017-09-13 14:46:59 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2017-09-13 14:46:59 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2017-09-13 14:46:58 2048 ----a-w- C:\Windows\SysWow64\user.exe
2017-09-13 14:46:13 36352 ----a-w- C:\Windows\SysWow64\cryptbase.dll
2017-09-13 14:46:06 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2017-09-13 14:46:06 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-13 14:46:06 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
.
============= FINISH: 4:01:18.53 ===============

Attached Files
File Type: txt attach.txt (8.8 KB)

Exe not working

$
0
0
I have been having a problem trying to solve this by doing various recommendations from the Net. None are working and I fear that if I keep on fiddling with things, it could make an annoying problem worse. Some of the proposed solutions involved downloading exe files which of course do not open, A couple I did manage to use, FixExec and exefix did nothing. I created an Exe.reg notepad file and have been into my registry files and changed settings but nothing works. I think a virus may have been behind it. I did run a program called Hitman Pro when I first had the problem and kept the log if that would help. Please help. Thank you.

Continued from here
Viewing all 2798 articles
Browse latest View live