For about the past week my computer has presented intermittent faults, such as being unable to restart or shutdown or, more obviously, faults when trying to use USB sticks. For example, when trying to load new photos into Lightroom from an SDHC via a USB card reader the system sometimes enters a busy state which never completes. The only way I have found to exit this state is to physically power down. More specifically I am unable to create a Win 10 recovery USB: the process of calculating the size of USB required never completes - even after 12 hours. Furthermore, the process cannot be cancelled - a busy state is entered as described above.
I naturally suspect a faulty Win 10 update but have no way of knowing which update this might be. Obviously, I should also suspect a malware infection and am starting from that point, rather than a Windows Update issue. I have run DDS script as recommended and made the attachments as required:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.16299.15
Run by Tony at 15:56:41 on 2018-02-01
Microsoft Windows 10 Home 10.0.16299.0.1252.44.1033.18.16375.13489 [GMT 0:00]
.
AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: COMODO Antivirus *Disabled/Updated* {08B84BA8-CC77-5A8B-A100-3F522B1B6106}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: COMODO Advanced Protection *Enabled/Updated* {B3D9AA4C-EA4D-5505-9BB0-0420509C2BBB}
FW: COMODO Firewall *Disabled* {3083CA8D-8618-5BD3-8A5F-9667D5C8267D}
.
============== Running Processes ===============
.
c:\windows\system32\svchost.exe -k dcomlaunch -p -s PlugPlay
C:\WINDOWS\system32\fontdrvhost.exe
C:\WINDOWS\system32\fontdrvhost.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p
c:\windows\system32\svchost.exe -k rpcss -p
c:\windows\system32\svchost.exe -k dcomlaunch -p -s LSM
C:\WINDOWS\system32\dwm.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s NcbService
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s TimeBrokerSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s hidserv
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s TabletInputService
c:\windows\system32\svchost.exe -k netsvcs -p -s Schedule
c:\windows\system32\svchost.exe -k netsvcs -p -s ProfSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s EventLog
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork -p
C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
c:\windows\system32\svchost.exe -k localservice -p -s SEMgrSvc
c:\windows\system32\svchost.exe -k netsvcs -p -s UserManager
c:\windows\system32\svchost.exe -k localservice -p -s nsi
C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s Dhcp
c:\windows\system32\svchost.exe -k netsvcs -p -s Themes
c:\windows\system32\svchost.exe -k localservice -p -s EventSystem
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s SysMain
c:\windows\system32\svchost.exe -k networkservice -p -s NlaSvc
c:\windows\system32\svchost.exe -k netsvcs -p -s Winmgmt
c:\windows\system32\svchost.exe -k netsvcs -p -s lfsvc
c:\windows\system32\svchost.exe -k netsvcs -p -s SENS
c:\windows\system32\svchost.exe -k localservice -p -s netprofm
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -p -s FontCache
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s lmhosts
c:\windows\system32\svchost.exe -k networkservice -p -s Dnscache
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s WinHttpAutoProxySvc
c:\windows\system32\svchost.exe -k localservicenonetwork -p -s NcdAutoSetup
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -p -s FDResPub
c:\windows\system32\svchost.exe -k localservice -p -s fdPHost
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
c:\windows\system32\svchost.exe -k networkservice -p -s CryptSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s HomeGroupProvider
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s DeviceAssociationService
c:\windows\system32\svchost.exe -k appmodel -p -s StateRepository
C:\WINDOWS\system32\dashost.exe
C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -p -s SSDPSRV
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
c:\windows\system32\sihost.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
C:\Program Files\Tablet\Wacom\WacomHost.exe
c:\windows\system32\taskhostw.exe
c:\windows\system32\taskhostw.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p
c:\windows\system32\svchost.exe -k netsvcs -p -s TokenBroker
c:\windows\system32\svchost.exe -k netsvcs -p -s ShellHWDetection
C:\WINDOWS\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k networkservice -p -s LanmanWorkstation
c:\windows\system32\svchost.exe -k netsvcs -p -s Appinfo
c:\windows\system32\svchost.exe -k netsvcs -p -s IKEEXT
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted -p -s PolicyAgent
c:\windows\system32\svchost.exe -k netsvcs -p -s LanmanServer
c:\windows\system32\svchost.exe -k apphost -s AppHostSvc
c:\windows\system32\svchost.exe -k localservicenonetwork -p -s DPS
C:\WINDOWS\System32\svchost.exe -k utcsvc -p
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\system32\svchost.exe -k netsvcs -p -s iphlpsvc
c:\windows\system32\svchost.exe -k iissvcs
C:\Program Files (x86)\COMODO\Internet Security Essentials\isesrv.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\FoxitConnectedPDFService.exe
C:\WINDOWS\system32\mqsvc.exe
c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe
C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Windows\System32\svchost.exe -k HPZ12
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s TrkWks
c:\windows\system32\viakaraokesrv.exe
C:\WINDOWS\system32\SearchIndexer.exe
c:\windows\system32\svchost.exe -k netsvcs -p -s WpnService
c:\windows\system32\svchost.exe -k netsvcs -p -s Browser
c:\windows\system32\svchost.exe -k localservice -p -s WdiServiceHost
C:\WINDOWS\system32\EscSvc64.exe
C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
C:\WINDOWS\Explorer.EXE
c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -p -s upnphost
c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Windows\System32\RuntimeBroker.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\WINDOWS\system32\SettingSyncHost.exe
c:\windows\system32\svchost.exe -k localservice -p -s LicenseManager
C:\Windows\System32\RuntimeBroker.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup
C:\Program Files\Windows Defender\MSASCuiL.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s PcaSvc
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files (x86)\Comodo\Internet Security Essentials\vkise.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\EaseUS\EaseUS Partition Master 12.8\bin\TrayPopupE\TrayTipAgentE.exe
C:\Windows\System32\RuntimeBroker.exe
c:\windows\system32\svchost.exe -k netsvcs
C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc
C:\WINDOWS\system32\ApplicationFrameHost.exe
C:\Windows\System32\RuntimeBroker.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s StorSvc
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s gpsvc
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -p -s wcncsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s Netman
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wlidsvc
svchost.exe
C:\Windows\System32\smartscreen.exe
C:\Program Files\WindowsApps\Microsoft.WindowsStore_11712.1001.16.0_x64__8wekyb3d8bbwe\WinStore.App.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\System32\RuntimeBroker.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s XblAuthManager
C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
C:\Windows\System32\RuntimeBroker.exe
c:\windows\system32\svchost.exe -k netsvcs -p -s BITS
svchost.exe
C:\WINDOWS\system32\AUDIODG.EXE
c:\windows\system32\taskhostw.exe
C:\WINDOWS\system32\svchost.exe -k appmodel -p -s tiledatamodelsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s WdiSystemHost
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://uk.yahoo.com/?fr=fp-comodo&type=33090001005_hp_sp
BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
uRun: [OneDrive] "C:\Users\Tony\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
uRun: [iCloudServices] "C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe"
uRun: [iCloudDrive] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
uRun: [iCloudPhotos] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
mRun: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
mRun: [iSkysoft Helper Compact.exe] C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
mRun: [IseUI] C:\Program Files (x86)\COMODO\Internet Security Essentials\vkise.exe
mRun: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
mRun: [EaseUS EPM Tray Agent] "C:\Program Files (x86)\EaseUS\EaseUS Partition Master 12.8\bin\TrayPopupE\TrayTipAgentE.exe"
uPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-Explorer: NoDriveTypeAutoRun = dword:221
mPolicies-System: DSCAutomationHostEnabled = dword:2
mPolicies-System: EnableFullTrustStartupTasks = dword:2
mPolicies-System: EnableUwpStartupTasks = dword:2
mPolicies-System: SupportFullTrustStartupTasks = dword:1
mPolicies-System: SupportUwpStartupTasks = dword:1
IE: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE/3000
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
TCP: NameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{29474fee-b88a-47fa-a7d9-541e4225df64} : NameServer = 194.168.4.100,194.168.8.100
TCP: Interfaces\{29474fee-b88a-47fa-a7d9-541e4225df64} : DHCPNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{6a952068-e907-4a13-87cf-2fd98d531ea8} : DHCPNameServer = 194.168.4.100 194.168.8.100
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
SSODL: WebCheck - <orphaned>
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
x64-BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-Run: [SecurityHealth] C:\Program Files (x86)\Windows Defender\MSASCuiL.exe
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [Windows Mobile Device Center] C:\WINDOWS\WindowsMobile\wmdc.exe
x64-Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
x64-Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
x64-Run: [Eraser] "C:\Program Files\Eraser\Eraser.exe" -atRestart
x64-Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
x64-Run: [AdobeGCInvoker-1.0] "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe"
x64-Run: [WindowsDefender] "C:\Program Files (x86)\Windows Defender\MSASCuiL.exe"
x64-mPolicies-Explorer: NoDriveTypeAutoRun = dword:221
x64-mPolicies-System: DSCAutomationHostEnabled = dword:2
x64-mPolicies-System: EnableFullTrustStartupTasks = dword:2
x64-mPolicies-System: EnableUwpStartupTasks = dword:2
x64-mPolicies-System: SupportFullTrustStartupTasks = dword:1
x64-mPolicies-System: SupportUwpStartupTasks = dword:1
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
x64-mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.132\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
x64-CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
Hosts: 127.0.0.1
spywareinfo.com*-*This website is for sale!*-*spywareinfo Resources and Information.
.
============= SERVICES / DRIVERS ===============
.
R0 intelpep;Intel(R) Power Engine Plug-in Driver;C:\WINDOWS\System32\drivers\intelpep.sys [2017-9-29 130640]
R0 iorate;Disk I/O Rate Filter Driver;C:\WINDOWS\System32\drivers\iorate.sys [2017-9-29 56728]
R0 pwdrvio;pwdrvio;C:\WINDOWS\System32\pwdrvio.sys [2016-9-16 19152]
R0 SCMNdisP;General NDIS Protocol Driver;C:\WINDOWS\System32\drivers\SCMNdisP.sys [2016-3-23 29472]
R0 volume;Volume driver;C:\WINDOWS\System32\drivers\volume.sys [2017-9-29 15392]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [2017-9-29 71248]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [2017-9-29 18000]
R0 Wof;Windows Overlay File System Filter Driver;C:\WINDOWS\System32\drivers\wof.sys [2017-9-29 209304]
R1 ahcache;Application Compatibility Cache;C:\WINDOWS\System32\drivers\ahcache.sys [2017-9-29 240640]
R1 bam;Background Activity Moderator Driver;C:\WINDOWS\System32\drivers\bam.sys [2018-1-16 59800]
R1 cmderd;COMODO Internet Security Eradication Driver;C:\WINDOWS\System32\drivers\cmderd.sys [2018-1-11 44056]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\WINDOWS\System32\drivers\cmdguard.sys [2018-1-11 830448]
R1 cmdhlp;COMODO Internet Security Helper Driver;C:\WINDOWS\System32\drivers\cmdhlp.sys [2018-1-11 50776]
R1 FileCrypt;FileCrypt;C:\WINDOWS\System32\drivers\filecrypt.sys [2017-9-29 55808]
R1 GpuEnergyDrv;GPU Energy Driver;C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2017-9-29 8192]
R1 isedrv;Internet Security Essentials;C:\WINDOWS\System32\drivers\isedrv.sys [2017-8-31 62208]
R2 AdobeUpdateService;AdobeUpdateService;C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [2017-9-20 817760]
R2 AGSService;Adobe Genuine Software Integrity Service;C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2018-1-5 2319848]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2018-1-5 83768]
R2 CDPSvc;Connected Devices Platform Service;C:\WINDOWS\System32\svchost.exe -k LocalService -p [2017-9-29 48688]
R2 CDPUserSvc_3507e;CDPUserSvc_3507e;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-9-29 48688]
R2 CldFlt;Windows Cloud Files Filter Driver;C:\WINDOWS\System32\drivers\cldflt.sys [2018-1-16 385024]
R2 CoreMessagingRegistrar;CoreMessaging;C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p [2017-9-29 48688]
R2 DiagTrack;Connected User Experiences and Telemetry;C:\WINDOWS\System32\svchost.exe -k utcsvc -p [2017-9-29 48688]
R2 DusmSvc;Data Usage;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p [2017-9-29 48688]
R2 EpsonScanSvc;Epson Scanner Service;C:\WINDOWS\System32\escsvc64.exe [2017-8-17 135824]
R2 FoxitReaderService;Foxit Reader Service;C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [2017-6-24 1659592]
R2 isesrv;isesrv;C:\Program Files (x86)\Comodo\Internet Security Essentials\isesrv.exe [2017-8-31 133840]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container;C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-6-30 495224]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2018-1-7 462968]
R2 OneSyncSvc_3507e;OneSyncSvc_3507e;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-9-29 48688]
R2 SecurityHealthService;Windows Defender Security Centre Service;C:\WINDOWS\System32\SecurityHealthService.exe [2018-1-16 519152]
R2 storqosflt;Storage QoS Filter Driver;C:\WINDOWS\System32\drivers\storqosflt.sys [2017-9-29 79872]
R2 UserManager;User Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service;C:\WINDOWS\System32\ViakaraokeSrv.exe [2012-12-11 27768]
R2 wcifs;Windows Container Isolation;C:\WINDOWS\System32\drivers\wcifs.sys [2018-1-16 147864]
R2 WpnService;Windows Push Notifications System Service;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
R2 WpnUserService_3507e;WpnUserService_3507e;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-9-29 48688]
R2 WTabletServicePro;Wacom Professional Service;C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [2014-11-24 671000]
R3 amdiox64;AMD IO Driver;C:\WINDOWS\System32\drivers\amdiox64.sys [2012-10-21 46136]
R3 AppXSvc;AppX Deployment Service (AppXSVC);C:\WINDOWS\System32\svchost.exe -k wsappx -p [2017-9-29 48688]
R3 ClipSVC;Client License Service (ClipSVC);C:\WINDOWS\System32\svchost.exe -k wsappx -p [2017-9-29 48688]
R3 FocusriteUSBSwRoot;USB Audio Root;C:\WINDOWS\System32\drivers\FocusriteUSBSwRoot.sys [2017-1-22 102088]
R3 hidkmdf;KMDF Driver;C:\WINDOWS\System32\drivers\hidkmdf.sys [2012-10-21 14136]
R3 lfsvc;Geolocation Service;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
R3 LicenseManager;Windows License Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalService -p [2017-9-29 48688]
R3 NcbService;Network Connection Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p [2017-9-29 48688]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [2017-9-29 21504]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\WINDOWS\System32\drivers\nvvad64v.sys [2017-6-30 48248]
R3 nvvhci;NVVHCI Enumerator Service;C:\WINDOWS\System32\drivers\nvvhci.sys [2017-6-30 57976]
R3 PimIndexMaintenanceSvc_3507e;PimIndexMaintenanceSvc_3507e;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-9-29 48688]
R3 rt640x64;Realtek RT640 NT Driver;C:\WINDOWS\System32\drivers\rt640x64.sys [2017-9-29 604160]
R3 SEMgrSvc;Payments and NFC/SE Manager;C:\WINDOWS\System32\svchost.exe -k LocalService -p [2017-9-29 48688]
R3 StateRepository;State Repository Service;C:\WINDOWS\System32\svchost.exe -k appmodel -p [2017-9-29 48688]
R3 tiledatamodelsvc;Tile Data model server;C:\WINDOWS\System32\svchost.exe -k appmodel -p [2017-9-29 48688]
R3 TimeBrokerSvc;Time Broker;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p [2017-9-29 48688]
R3 TokenBroker;Web Account Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
R3 UnistoreSvc_3507e;UnistoreSvc_3507e;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-9-29 48688]
R3 usbfilter;AMD USB Filter Driver;C:\WINDOWS\System32\drivers\usbfilter.sys [2014-12-9 60640]
R3 UserDataSvc_3507e;UserDataSvc_3507e;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-9-29 48688]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\WINDOWS\System32\drivers\viahduaa.sys [2015-8-11 692400]
R3 WacHidRouter;Wacom Hid Router;C:\WINDOWS\System32\drivers\wachidrouter.sys [2012-10-21 100664]
R3 wacomrouterfilter;Wacom Router Filter Driver;C:\WINDOWS\System32\drivers\wacomrouterfilter.sys [2012-10-21 15160]
R3 WdNisDrv;Windows Defender Antivirus Network Inspection System Driver;C:\WINDOWS\System32\drivers\WdNisDrv.sys [2017-9-29 119192]
R3 WdNisSvc;Windows Defender Antivirus Network Inspection Service;C:\Program Files\Windows Defender\NisSrv.exe [2017-9-29 355304]
R3 XblAuthManager;Xbox Live Auth Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
S2 AODService;AODService;C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe [2010-3-12 136544]
S2 MapsBroker;Downloaded Maps Manager;C:\WINDOWS\System32\svchost.exe -k NetworkService -p [2017-9-29 48688]
S3 AcpiDev;ACPI Devices driver;C:\WINDOWS\System32\drivers\AcpiDev.sys [2017-9-29 20480]
S3 ADP80XX;ADP80XX;C:\WINDOWS\System32\drivers\adp80xx.sys [2017-9-29 1135512]
S3 ahcix64s;ahcix64s;C:\WINDOWS\System32\drivers\ahcix64s.sys [2009-7-14 226616]
S3 AJRouter;AllJoyn Router Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p [2017-9-29 48688]
S3 applockerfltr;Smartlocker Filter Driver;C:\WINDOWS\System32\drivers\applockerfltr.sys [2017-9-29 18432]
S3 AppReadiness;App Readiness;C:\WINDOWS\System32\svchost.exe -k AppReadiness -p [2017-9-29 48688]
S3 bcmfn2;bcmfn2 Service;C:\WINDOWS\System32\drivers\bcmfn2.sys [2017-9-29 9728]
S3 BthHFSrv;Bluetooth Handsfree Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation [2017-9-29 48688]
S3 bttflt;Microsoft Hyper-V VHDPMEM BTT Filter;C:\WINDOWS\System32\drivers\bttflt.sys [2017-9-29 37784]
S3 buttonconverter;Service for Portable Device Control devices;C:\WINDOWS\System32\drivers\buttonconverter.sys [2017-9-29 39424]
S3 CAD;Charge Arbitration Driver;C:\WINDOWS\System32\drivers\CAD.sys [2017-9-29 60312]
S3 camsvc;Capability Access Manager Service;C:\WINDOWS\System32\svchost.exe -k appmodel -p [2017-9-29 48688]
S3 CapImg;HID driver for CapImg touch screen;C:\WINDOWS\System32\drivers\capimg.sys [2017-9-29 122368]
S3 cht4iscsi;cht4iscsi;C:\WINDOWS\System32\drivers\cht4sx64.sys [2017-9-29 357272]
S3 cht4vbd;Chelsio Virtual Bus Driver;C:\WINDOWS\System32\drivers\cht4vx64.sys [2017-9-29 1723288]
S3 cmdvirth;COMODO Virtual Service Manager;C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2018-1-11 2875816]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-10-20 79360]
S3 DevicesFlowUserSvc_3507e;DevicesFlowUserSvc_3507e;C:\WINDOWS\System32\svchost.exe -k DevicesFlow [2017-9-29 48688]
S3 DevQueryBroker;DevQuery Background Discovery Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p [2017-9-29 48688]
S3 diagnosticshub.standardcollector.service;Microsoft (R) Diagnostics Hub Standard Collector Service;C:\WINDOWS\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2017-9-29 85504]
S3 diagsvc;Diagnostic Execution Service;C:\WINDOWS\System32\svchost.exe -k diagnostics [2017-9-29 48688]
S3 DmEnrollmentSvc;Device Management Enrollment Service;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
S3 dmwappushservice;dmwappushsvc;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
S3 DoSvc;Delivery Optimization;C:\WINDOWS\System32\svchost.exe -k NetworkService -p [2017-9-29 48688]
S3 DsSvc;Data Sharing Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p [2017-9-29 48688]
S3 embeddedmode;Embedded Mode;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p [2017-9-29 48688]
S3 EntAppSvc;Enterprise App Management Service;C:\WINDOWS\System32\svchost.exe -k appmodel -p [2017-9-29 48688]
S3 epmntdrv;epmntdrv;C:\WINDOWS\System32\epmntdrv.sys [2018-1-30 33448]
S3 EuGdiDrv;EuGdiDrv;C:\WINDOWS\System32\EuGdiDrv.sys [2018-1-30 10848]
S3 FrameServer;Windows Camera Frame Server;C:\WINDOWS\System32\svchost.exe -k Camera [2017-9-29 48688]
S3 genericusbfn;Generic USB Function Class;C:\WINDOWS\System32\drivers\genericusbfn.sys [2017-9-29 20992]
S3 GraphicsPerfSvc;GraphicsPerfSvc;C:\WINDOWS\System32\svchost.exe -k GraphicsPerfSvcGroup [2017-9-29 48688]
S3 hidinterrupt;Common Driver for HID Buttons implemented with interrupts;C:\WINDOWS\System32\drivers\hidinterrupt.sys [2017-9-29 50584]
S3 HvHost;HV Host Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p [2017-9-29 48688]
S3 HwNClx0101;Microsoft Hardware Notifications Class Extension Driver;C:\WINDOWS\System32\drivers\mshwnclx.sys [2017-9-29 27136]
S3 iagpio;Intel Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iagpio.sys [2017-9-29 36864]
S3 iai2c;Intel(R) Serial IO I2C Host Controller;C:\WINDOWS\System32\drivers\iai2c.sys [2017-9-29 91648]
S3 iaLPSS2i_GPIO2;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2017-9-29 79360]
S3 iaLPSS2i_GPIO2_BXT_P;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2017-9-29 88576]
S3 iaLPSS2i_I2C;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2017-9-29 171520]
S3 iaLPSS2i_I2C_BXT_P;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2017-9-29 174592]
S3 iaLPSSi_GPIO;Intel(R) Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [2017-9-29 38128]
S3 iaLPSSi_I2C;Intel(R) Serial IO I2C Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [2017-9-29 113152]
S3 iaStorAV;Intel(R) SATA RAID Controller Windows;C:\WINDOWS\System32\drivers\iaStorAV.sys [2017-9-29 674200]
S3 ibbus;Mellanox InfiniBand Bus/AL (Filter Driver);C:\WINDOWS\System32\drivers\ibbus.sys [2017-9-29 526232]
S3 icssvc;Windows Mobile Hotspot Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p [2017-9-29 48688]
S3 IndirectKmd;Indirect Displays Kernel-Mode Driver;C:\WINDOWS\System32\drivers\IndirectKmd.sys [2017-9-29 39424]
S3 InstallService;Windows Store Install Service;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
S3 invdimm;Microsoft iNVDIMM device driver;C:\WINDOWS\System32\drivers\invdimm.sys [2017-9-29 38912]
S3 IPT;IPT;C:\WINDOWS\System32\drivers\ipt.sys [2017-9-29 26112]
S3 IpxlatCfgSvc;IP Translation Configuration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p [2017-9-29 48688]
S3 LSI_SAS2i;LSI_SAS2i;C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2017-9-29 123800]
S3 LSI_SAS3i;LSI_SAS3i;C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2017-9-29 103320]
S3 mausbhost;MA-USB Host Controller Driver;C:\WINDOWS\System32\drivers\mausbhost.sys [2017-9-29 505240]
S3 mausbip;MA-USB IP Filter Driver;C:\WINDOWS\System32\drivers\mausbip.sys [2017-9-29 55840]
S3 megasas2i;megasas2i;C:\WINDOWS\System32\drivers\MegaSas2i.sys [2017-9-29 63520]
S3 MessagingService_3507e;MessagingService_3507e;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2017-9-29 48688]
S3 mlx4_bus;Mellanox ConnectX Bus Enumerator;C:\WINDOWS\System32\drivers\mlx4_bus.sys [2017-9-29 842648]
S3 NaturalAuthentication;Natural Authentication;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
S3 ndfltr;NetworkDirect Service;C:\WINDOWS\System32\drivers\ndfltr.sys [2017-9-29 108952]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library;C:\WINDOWS\System32\drivers\NetAdapterCx.sys [2017-9-29 132608]
S3 NetSetupSvc;Network Setup Service;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
S3 netvsc;netvsc;C:\WINDOWS\System32\drivers\netvsc.sys [2018-1-16 192512]
S3 NgcCtnrSvc;Microsoft Passport Container;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p [2017-9-29 48688]
S3 NgcSvc;Microsoft Passport;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p [2017-9-29 48688]
S3 NvContainerNetworkService;NVIDIA NetworkService Container;C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-6-30 495224]
S3 nvdimmn;Microsoft NVDIMM-N device driver;C:\WINDOWS\System32\drivers\nvdimmn.sys [2017-9-29 88576]
S3 percsas2i;percsas2i;C:\WINDOWS\System32\drivers\percsas2i.sys [2017-9-29 58776]
S3 percsas3i;percsas3i;C:\WINDOWS\System32\drivers\percsas3i.sys [2017-9-29 61848]
S3 PhoneSvc;Phone Service;C:\WINDOWS\System32\svchost.exe -k LocalService -p [2017-9-29 48688]
S3 PNPMEM;Microsoft Memory Module Driver;C:\WINDOWS\System32\drivers\pnpmem.sys [2017-9-29 16896]
S3 PrintWorkflowUserSvc_3507e;PrintWorkflowUserSvc_3507e;C:\WINDOWS\System32\svchost.exe -k PrintWorkflow [2017-9-29 48688]
S3 PSSDK42;PSSDK42;C:\WINDOWS\System32\drivers\pssdk42.sys [2013-11-20 53312]
S3 PSSDKLBF;PSSDKLBF;C:\WINDOWS\System32\drivers\pssdklbf.sys [2013-11-20 65600]
S3 PushToInstall;Windows PushToInstall Service;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
S3 pwdspio;pwdspio;C:\WINDOWS\System32\pwdspio.sys [2016-9-16 12504]
S3 Ramdisk;Windows RAM Disk Driver;C:\WINDOWS\System32\drivers\ramdisk.sys [2017-9-29 39832]
S3 ReFS;ReFS;C:\WINDOWS\System32\drivers\refs.sys [2017-9-29 1849752]
S3 ReFSv1;ReFSv1;C:\WINDOWS\System32\drivers\refsv1.sys [2017-9-29 936856]
S3 RetailDemo;Retail Demo Service;C:\WINDOWS\System32\svchost.exe -k rdxgroup [2017-9-29 48688]
S3 rhproxy;Resource Hub proxy driver;C:\WINDOWS\System32\drivers\rhproxy.sys [2017-9-29 103936]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2017-9-29 48688]
S3 scmbus;Microsoft Storage Class Memory Bus Driver;C:\WINDOWS\System32\drivers\scmbus.sys [2017-9-29 118168]
S3 SDFRd;SDF Reflector;C:\WINDOWS\System32\drivers\SDFRd.sys [2017-9-29 33176]
S3 SensorDataService;Sensor Data Service;C:\WINDOWS\System32\SensorDataService.exe [2017-9-29 1288704]
S3 SensorService;Sensor Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p [2017-9-29 48688]
S3 SerCx2;Serial UART Support Library;C:\WINDOWS\System32\drivers\SerCx2.sys [2017-9-29 154520]
S3 SharedRealitySvc;Spatial Data Service;C:\WINDOWS\System32\svchost.exe -k LocalService -p [2017-9-29 48688]
S3 smphost;Microsoft Storage Spaces SMP;C:\WINDOWS\System32\svchost.exe -k smphost [2017-9-29 48688]
S3 SmsRouter;Microsoft Windows SMS Router Service.;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p [2017-9-29 48688]
S3 SpatialGraphFilter;Holographic Spatial Graph Filter;C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [2017-9-29 56216]
S3 spectrum;Windows Perception Service;C:\WINDOWS\System32\Spectrum.exe [2018-1-16 956416]
S3 stornvme;Microsoft Standard NVM Express Driver;C:\WINDOWS\System32\drivers\stornvme.sys [2018-1-16 103320]
S3 storufs;Microsoft Universal Flash Storage (UFS) Driver;C:\WINDOWS\System32\drivers\storufs.sys [2017-12-13 45464]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TieringEngineService;Storage Tiers Management;C:\WINDOWS\System32\TieringEngineService.exe [2017-9-29 302592]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmCx.sys [2017-12-13 114688]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmTcpciCx.sys [2017-9-29 146944]
S3 UcmUcsi;USB Connector Manager UCSI Client;C:\WINDOWS\System32\drivers\UcmUcsi.sys [2017-12-13 57344]
S3 UdeCx;USB Device Emulation Support Library;C:\WINDOWS\System32\drivers\Udecx.sys [2017-9-29 45056]
S3 UEFI;Microsoft UEFI Driver;C:\WINDOWS\System32\drivers\uefi.sys [2017-9-29 28568]
S3 Ufx01000;USB Function Class Extension;C:\WINDOWS\System32\drivers\ufx01000.sys [2017-9-29 266648]
S3 UfxChipidea;USB Chipidea Controller;C:\WINDOWS\System32\drivers\UfxChipidea.sys [2017-9-29 97312]
S3 ufxsynopsys;USB Synopsys Controller;C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2017-9-29 140696]
S3 UrsChipidea;Chipidea USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urschipidea.sys [2017-9-29 28568]
S3 UrsCx01000;USB Role-Switch Support Library;C:\WINDOWS\System32\drivers\urscx01000.sys [2017-12-13 60824]
S3 UrsSynopsys;Synopsys USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urssynopsys.sys [2017-9-29 27544]
S3 UsoSvc;Update Orchestrator Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2017-9-29 48688]
S3 vhf;Virtual HID Framework (VHF) Driver;C:\WINDOWS\System32\drivers\vhf.sys [2017-9-29 34816]
S3 vmgid;Microsoft Hyper-V Guest Infrastructure Driver;C:\WINDOWS\System32\drivers\vmgid.sys [2017-9-29 10240]
S3 vmicguestinterface;Hyper-V Guest Service Interface;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p [2017-9-29 48688]
S3 vmicvmsession;Hyper-V PowerShell Direct Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p [2017-9-29 48688]
S3 vnvdimm;Microsoft virtual NVDIMM device driver;C:\WINDOWS\System32\drivers\vnvdimm.sys [2017-9-29 43008]
S3 w3logsvc;W3C Logging Service;C:\WINDOWS\System32\svchost.exe -k apphost [2017-9-29 48688]
S3 WalletService;WalletService;C:\WINDOWS\System32\svchost.exe -k appmodel -p [2017-9-29 48688]
S3 WarpJITSvc;WarpJITSvc;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2017-9-29 48688]
S3 wcnfs;Windows Container Name Virtualization;C:\WINDOWS\System32\drivers\wcnfs.sys [2017-9-29 76288]
S3 wdiwifi;WDI Driver Framework;C:\WINDOWS\System32\drivers\WdiWiFi.sys [2017-12-13 770048]
S3 wdnsfltr;Windows Defender Network Stream Filter Driver;C:\WINDOWS\System32\drivers\wdnsfltr.sys [2017-9-29 33792]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;C:\WINDOWS\System32\svchost.exe -k WepHostSvcGroup [2017-9-29 48688]
S3 WFDSConMgrSvc;Wi-Fi Direct Services Connection Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p [2017-9-29 48688]
S3 WinMad;WinMad Service;C:\WINDOWS\System32\drivers\winmad.sys [2017-9-29 32152]
S3 WinNat;Windows NAT Driver;C:\WINDOWS\System32\drivers\winnat.sys [2018-1-16 225792]
S3 WinVerbs;WinVerbs Service;C:\WINDOWS\System32\drivers\winverbs.sys [2017-9-29 64920]
S3 wisvc;Windows Insider Service;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
S3 wlpasvc;Local Profile Assistant Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p [2017-9-29 48688]
S3 workfolderssvc;Work Folders;C:\WINDOWS\System32\svchost.exe -k LocalService -p [2017-9-29 48688]
S3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\drivers\WUDFRd.sys [2017-9-29 259584]
S3 xbgm;Xbox Game Monitoring;C:\WINDOWS\System32\xbgmsvc.exe [2017-9-29 59512]
S3 XblGameSave;Xbox Live Game Save;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
S3 xboxgip;Xbox Game Input Protocol Driver;C:\WINDOWS\System32\drivers\xboxgip.sys [2017-9-29 281600]
S3 XboxGipSvc;Xbox Accessory Management Service;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
S3 XboxNetApiSvc;Xbox Live Networking Service;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
S3 xinputhid;XINPUT HID Filter Driver;C:\WINDOWS\System32\drivers\xinputhid.sys [2017-9-29 46592]
S4 AODDriver;AODDriver;C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver.sys [2010-3-12 52280]
S4 NvStreamKms;NVIDIA KMS;C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2017-6-30 30328]
S4 NvTelemetryContainer;NVIDIA Telemetry Container;C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [2017-5-11 450168]
S4 shpamsvc;Shared PC Account Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs -p [2017-9-29 48688]
S4 tzautoupdate;Auto Time Zone Updater;C:\WINDOWS\System32\svchost.exe -k LocalService -p [2017-9-29 48688]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\WINDOWS\System32\NOTEPAD.EXE %1 [UserChoice]
FileExt: .js: JSFile="C:\Program Files (x86)\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1"
.
=============== Created Last 30 ================
.
2018-02-01 15:44:45 14047160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{742FD558-4F7B-40ED-991B-86C17EE3B87E}\mpengine.dll
2018-01-30 16:39:51 -------- d-----w- C:\ProgramData\SystemAcCrux
2018-01-30 16:39:37 30320 ----a-w- C:\WINDOWS\System32\drivers\EPMVolFlt.sys
2018-01-30 16:39:36 4094608 ----a-w- C:\WINDOWS\System32\BootMan.exe
2018-01-30 16:39:36 33448 ----a-w- C:\WINDOWS\System32\epmntdrv.sys
2018-01-30 16:39:36 3076240 ----a-w- C:\WINDOWS\SysWow64\BootMan.exe
2018-01-30 16:39:36 30320 ----a-w- C:\WINDOWS\System32\EPMVolFlt.sys
2018-01-30 16:39:36 21088 ----a-w- C:\WINDOWS\SysWow64\EuEpmGdi.dll
2018-01-30 16:39:36 17504 ----a-w- C:\WINDOWS\System32\EuEpmGdi.dll
2018-01-30 16:39:36 131728 ----a-w- C:\WINDOWS\System32\setupempdrvx64.exe
2018-01-30 16:39:36 10848 ----a-w- C:\WINDOWS\System32\EuGdiDrv.sys
2018-01-30 16:39:23 -------- d-----w- C:\Program Files (x86)\EaseUS
2018-01-24 20:00:28 -------- d-----w- C:\Program Files\iPod
2018-01-24 20:00:08 -------- d-----w- C:\Program Files\iTunes
2018-01-16 19:04:45 824632 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe
2018-01-16 19:04:45 822584 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe
2018-01-16 19:04:38 403968 ----a-w- C:\WINDOWS\System32\WpAXHolder.dll
2018-01-16 19:04:22 106496 ----a-w- C:\WINDOWS\SysWow64\Chakradiag.dll
2018-01-16 19:04:19 140800 ----a-w- C:\WINDOWS\System32\Chakradiag.dll
2018-01-11 18:00:59 924984 ----a-w- C:\WINDOWS\System32\guard64.dll
2018-01-11 18:00:59 830448 ----a-w- C:\WINDOWS\System32\drivers\cmdguard.sys
2018-01-11 18:00:59 710920 ----a-w- C:\WINDOWS\SysWow64\guard32.dll
2018-01-11 18:00:59 50776 ----a-w- C:\WINDOWS\System32\drivers\cmdhlp.sys
2018-01-11 18:00:59 467368 ----a-w- C:\WINDOWS\System32\cmdvrt64.dll
2018-01-11 18:00:59 44056 ----a-w- C:\WINDOWS\System32\drivers\cmderd.sys
2018-01-10 13:41:48 1057976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{58F4D502-D487-447D-985F-D3278C987F82}\gapaengine.dll
2018-01-10 13:41:46 152080 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Scans\MpPayloadData\mpengine.exe
2018-01-10 13:41:39 14047160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2018-01-09 18:30:42 835576 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2018-01-09 18:30:42 177648 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2018-01-07 12:36:32 136312 ----a-w- C:\WINDOWS\SysWow64\nvStreaming.exe
2018-01-07 12:36:31 927544 ----a-w- C:\WINDOWS\System32\vulkan-1.dll
2018-01-07 12:36:31 798008 ----a-w- C:\WINDOWS\SysWow64\vulkan-1.dll
2018-01-07 12:36:31 591160 ----a-w- C:\WINDOWS\System32\vulkaninfo.exe
2018-01-07 12:36:31 490296 ----a-w- C:\WINDOWS\SysWow64\vulkaninfo.exe
2018-01-07 12:36:31 -------- d-----w- C:\Program Files (x86)\VulkanRT
2018-01-07 11:17:22 123000 ----a-w- C:\WINDOWS\System32\nvshext.dll
.
==================== Find3M ====================
.
2018-02-01 15:44:18 548000 ------w- C:\WINDOWS\System32\MpSigStub.exe
2018-01-09 18:30:52 129365736 -c--a-w- C:\WINDOWS\System32\MRT-KB890830.exe
2018-01-09 00:20:17 51528 ----a-w- C:\WINDOWS\System32\cmdcsr.dll
2018-01-09 00:15:53 371112 ----a-w- C:\WINDOWS\SysWow64\cmdvrt32.dll
2018-01-01 17:15:38 956416 ----a-w- C:\WINDOWS\System32\Spectrum.exe
2018-01-01 12:54:36 924648 ----a-w- C:\WINDOWS\System32\winresume.exe
2018-01-01 12:53:26 1090984 ----a-w- C:\WINDOWS\System32\winresume.efi
2018-01-01 12:52:23 66712 ----a-w- C:\WINDOWS\System32\iumcrypt.dll
2018-01-01 12:51:59 59800 ----a-w- C:\WINDOWS\System32\drivers\bam.sys
2018-01-01 12:51:56 1055128 ----a-w- C:\WINDOWS\System32\hvax64.exe
2018-01-01 12:51:31 191816 ----a-w- C:\WINDOWS\System32\skci.dll
2018-01-01 12:51:23 1209240 ----a-w- C:\WINDOWS\System32\winload.exe
2018-01-01 12:51:18 1414784 ----a-w- C:\WINDOWS\System32\winload.efi
2018-01-01 12:50:58 479912 ----a-w- C:\WINDOWS\System32\ucrtbase_enclave.dll
2018-01-01 12:50:35 77208 ----a-w- C:\WINDOWS\System32\hvloader.dll
2018-01-01 12:50:17 780464 ----a-w- C:\WINDOWS\System32\fontdrvhost.exe
2018-01-01 12:50:07 5905752 ----a-w- C:\WINDOWS\System32\StartTileData.dll
2018-01-01 12:49:34 8605080 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2018-01-01 12:49:34 292376 ----a-w- C:\WINDOWS\System32\wscapi.dll
2018-01-01 12:49:31 599448 ----a-w- C:\WINDOWS\System32\securekernel.exe
2018-01-01 12:49:10 319352 ----a-w- C:\WINDOWS\System32\wow64.dll
2018-01-01 12:48:26 1954048 ----a-w- C:\WINDOWS\System32\ntdll.dll
2018-01-01 12:48:18 7831760 ----a-w- C:\WINDOWS\System32\d3d10warp.dll
2018-01-01 12:48:18 382360 ----a-w- C:\WINDOWS\System32\atmfd.dll
2018-01-01 12:47:06 649304 ----a-w- C:\WINDOWS\System32\advapi32.dll
2018-01-01 12:47:01 82840 ----a-w- C:\WINDOWS\System32\drivers\volmgr.sys
2018-01-01 12:46:23 898216 ----a-w- C:\WINDOWS\System32\CoreMessaging.dll
2018-01-01 12:46:21 733592 ----a-w- C:\WINDOWS\System32\drivers\acpi.sys
2018-01-01 12:45:54 2395032 ----a-w- C:\WINDOWS\System32\drivers\ntfs.sys
2018-01-01 12:45:48 1277848 ----a-w- C:\WINDOWS\System32\drivers\ndis.sys
2018-01-01 12:45:17 398744 ----a-w- C:\WINDOWS\System32\drivers\fltMgr.sys
2018-01-01 12:43:31 1173576 ----a-w- C:\WINDOWS\System32\rpcrt4.dll
2018-01-01 12:43:16 367336 ----a-w- C:\WINDOWS\System32\Windows.Storage.ApplicationData.dll
2018-01-01 12:43:03 62872 ----a-w- C:\WINDOWS\System32\drivers\fsdepends.sys
2018-01-01 12:42:46 571288 ----a-w- C:\WINDOWS\System32\drivers\spaceport.sys
2018-01-01 12:42:36 494488 ----a-w- C:\WINDOWS\System32\pcasvc.dll
2018-01-01 12:42:34 184984 ----a-w- C:\WINDOWS\System32\sspicli.dll
2018-01-01 12:42:20 109976 ----a-w- C:\WINDOWS\System32\drivers\vmbus.sys
2018-01-01 12:42:01 1029016 ----a-w- C:\WINDOWS\System32\efscore.dll
2018-01-01 12:41:32 549552 ----a-w- C:\WINDOWS\System32\WWanAPI.dll
2018-01-01 12:41:24 559512 ----a-w- C:\WINDOWS\System32\drivers\storport.sys
2018-01-01 12:41:18 7676296 ----a-w- C:\WINDOWS\System32\windows.storage.dll
2018-01-01 12:40:19 1206680 ----a-w- C:\WINDOWS\System32\hvix64.exe
2018-01-01 12:39:58 508264 ----a-w- C:\WINDOWS\System32\systemreset.exe
2018-01-01 12:39:53 902416 ----a-w- C:\WINDOWS\System32\winhttp.dll
2018-01-01 12:39:44 362904 ----a-w- C:\WINDOWS\System32\drivers\pci.sys
2018-01-01 12:39:17 677784 ----a-w- C:\WINDOWS\System32\drivers\cng.sys
2018-01-01 12:39:06 129432 ----a-w- C:\WINDOWS\System32\drivers\hvsocket.sys
2018-01-01 12:38:53 519152 ----a-w- C:\WINDOWS\System32\SecurityHealthService.exe
2018-01-01 12:38:43 38808 ----a-w- C:\WINDOWS\System32\drivers\Diskdump.sys
2018-01-01 12:38:24 3904808 ----a-w- C:\WINDOWS\explorer.exe
2018-01-01 12:38:15 727448 ----a-w- C:\WINDOWS\System32\drivers\fvevol.sys
2018-01-01 12:38:09 103320 ----a-w- C:\WINDOWS\System32\drivers\stornvme.sys
2018-01-01 12:37:57 461720 ----a-w- C:\WINDOWS\System32\wifitask.exe
2018-01-01 12:37:09 1426664 ----a-w- C:\WINDOWS\System32\AudioEng.dll
2018-01-01 12:36:57 113560 ----a-w- C:\WINDOWS\System32\icfupgd.dll
2018-01-01 12:36:32 57752 ----a-w- C:\WINDOWS\System32\drivers\netbios.sys
2018-01-01 12:36:25 413888 ----a-w- C:\WINDOWS\System32\AUDIOKSE.dll
2018-01-01 12:36:25 166296 ----a-w- C:\WINDOWS\System32\drivers\partmgr.sys
2018-01-01 12:36:20 374032 ----a-w- C:\WINDOWS\System32\vac.exe
2018-01-01 12:35:34 75160 ----a-w- C:\WINDOWS\System32\SecurityHealthProxyStub.dll
2018-01-01 12:35:16 1170008 ----a-w- C:\WINDOWS\System32\AudioSes.dll
2018-01-01 12:34:51 1336344 ----a-w- C:\WINDOWS\System32\ole32.dll
2018-01-01 12:34:45 7385088 ----a-w- C:\WINDOWS\System32\Windows.Media.Protection.PlayReady.dll
2018-01-01 12:34:45 260896 ----a-w- C:\WINDOWS\System32\mfps.dll
2018-01-01 12:34:43 87384 ----a-w- C:\WINDOWS\System32\remoteaudioendpoint.dll
2018-01-01 12:33:42 603920 ----a-w- C:\WINDOWS\System32\audiodg.exe
2018-01-01 12:33:36 2773400 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2018-01-01 12:32:57 4481240 ----a-w- C:\WINDOWS\System32\mfcore.dll
2018-01-01 12:32:30 617304 ----a-w- C:\WINDOWS\System32\TextInputFramework.dll
2018-01-01 12:27:27 713624 ----a-w- C:\WINDOWS\System32\drivers\vhdmp.sys
2018-01-01 12:27:26 163736 ----a-w- C:\WINDOWS\System32\drivers\wfplwfs.sys
2018-01-01 12:26:45 81304 ----a-w- C:\WINDOWS\System32\drivers\vmbkmcl.sys
2018-01-01 12:26:25 428952 ----a-w- C:\WINDOWS\System32\drivers\rdbss.sys
2018-01-01 12:25:50 147864 ----a-w- C:\WINDOWS\System32\drivers\wcifs.sys
2018-01-01 12:25:26 615768 ----a-w- C:\WINDOWS\System32\services.exe
2018-01-01 12:21:36 1103768 ----a-w- C:\WINDOWS\System32\drivers\http.sys
2018-01-01 12:21:34 614296 ----a-w- C:\WINDOWS\System32\drivers\afd.sys
2018-01-01 12:06:49 311192 ----a-w- C:\WINDOWS\SysWow64\atmfd.dll
2018-01-01 12:03:39 650328 ----a-w- C:\WINDOWS\SysWow64\fontdrvhost.exe
2018-01-01 12:03:38 777904 ----a-w- C:\WINDOWS\SysWow64\rpcrt4.dll
2018-01-01 12:03:36 566664 ----a-w- C:\WINDOWS\SysWow64\CoreMessaging.dll
2018-01-01 12:03:03 123512 ----a-w- C:\WINDOWS\SysWow64\sspicli.dll
2018-01-01 11:53:43 1615712 ----a-w- C:\WINDOWS\SysWow64\ntdll.dll
2018-01-01 11:49:35 258808 ----a-w- C:\WINDOWS\SysWow64\wscapi.dll
2018-01-01 11:49:11 481464 ----a-w- C:\WINDOWS\SysWow64\advapi32.dll
2018-01-01 11:46:57 289816 ----a-w- C:\WINDOWS\SysWow64\Windows.Storage.ApplicationData.dll
2018-01-01 11:46:25 3485392 ----a-w- C:\WINDOWS\SysWow64\explorer.exe
2018-01-01 11:45:54 5615968 ----a-w- C:\WINDOWS\SysWow64\d3d10warp.dll
2018-01-01 11:45:34 6092152 ----a-w- C:\WINDOWS\SysWow64\windows.storage.dll
2018-01-01 11:45:26 450928 ----a-w- C:\WINDOWS\SysWow64\WWanAPI.dll
2018-01-01 11:42:56 982528 ----a-w- C:\WINDOWS\SysWow64\AudioSes.dll
2018-01-01 11:42:47 386424 ----a-w- C:\WINDOWS\SysWow64\AUDIOKSE.dll
2018-01-01 11:42:41 4644912 ----a-w- C:\WINDOWS\SysWow64\mfcore.dll
2018-01-01 11:42:40 6479552 ----a-w- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
2018-01-01 11:42:33 1246432 ----a-w- C:\WINDOWS\SysWow64\AudioEng.dll
2018-01-01 11:42:32 74992 ----a-w- C:\WINDOWS\SysWow64\remoteaudioendpoint.dll
2018-01-01 11:42:32 129184 ----a-w- C:\WINDOWS\SysWow64\mfps.dll
2018-01-01 11:42:32 1003152 ----a-w- C:\WINDOWS\SysWow64\ole32.dll
2018-01-01 11:37:35 25247232 ----a-w- C:\WINDOWS\System32\edgehtml.dll
.
============= FINISH: 15:57:18.82 ===============