HP Pavilion g7, Win XP, Super slow boot and operation, CPU max and overheating, Outlook receive errors and generally slow.
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.19081
Run by Hodie at 18:29:06 on 2018-08-07
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3894.1370 [GMT -5:00]
.
AV: Avast Antivirus *Enabled/Updated* {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Avast Antivirus *Enabled/Updated* {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\ptumlcmsvc64.exe
C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
C:\Windows\sysWow64\SearchProtocolHost.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uProxyServer = localhost:8080
mWinlogon: Userinit = userinit.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - <orphaned>
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL
BHO: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - <orphaned>
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [iCloudServices] "C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe"
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
dRunOnce: [iCloud] "C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloud.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: SoftwareSASGeneration = dword:1
IE: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.4.0/GarminAxControl_32.CAB
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://uhc.webex.com/client/WBXclient-T27L10NSP32EP5-14362/webex/ieatgpc1.cab
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{61A21C53-CE0F-4214-BA30-8A64E88F8D1B} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{695076B3-72BF-4452-8C0C-61DD9CF93C7E} : DHCPNameServer = 172.20.10.1
TCP: Interfaces\{FC761777-E592-4B4B-A5E1-2F915004E613} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{FC761777-E592-4B4B-A5E1-2F915004E613}\2375942554431383 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{FC761777-E592-4B4B-A5E1-2F915004E613}\2375942554638333 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{FC761777-E592-4B4B-A5E1-2F915004E613}\4415C4F4447454 : DHCPNameServer = 192.168.254.254
TCP: Interfaces\{FC761777-E592-4B4B-A5E1-2F915004E613}\44F65726C65645275656022697028496C647F6E6 : DHCPNameServer = 8.8.8.8 8.8.4.4
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\MSOXMLMF.DLL
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\68.0.3440.84\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll",CreateReaderUserSettings
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - <orphaned>
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL
x64-BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - <orphaned>
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
x64-Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
x64-Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL
x64-Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - <orphaned>
x64-Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Hodie\AppData\Roaming\Mozilla\Firefox\Profiles\km5jf2y2.default-1473202271514\
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Hodie\AppData\Local\Citrix\Plugins\104\npappdetector.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswbidsh;aswbidsh;C:\Windows\System32\drivers\aswbidsha.sys [2017-2-3 201320]
R0 aswblog;aswblog;C:\Windows\System32\drivers\aswbloga.sys [2017-2-3 346664]
R0 aswbuniv;aswbuniv;C:\Windows\System32\drivers\aswbuniva.sys [2017-2-3 59568]
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2014-2-3 85968]
R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2014-2-3 381552]
R1 aswArPot;aswArPot;C:\Windows\System32\drivers\aswArPot.sys [2017-10-27 199712]
R1 aswbidsdriver;aswbidsdriver;C:\Windows\System32\drivers\aswbidsdrivera.sys [2017-2-3 229392]
R1 aswHdsKe;aswHdsKe;C:\Windows\System32\drivers\aswHdsKe.sys [2017-11-24 249016]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2014-2-3 1027720]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2014-2-3 466720]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2018-4-27 83768]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2014-2-3 163272]
R2 aswStm;aswStm;C:\Windows\System32\drivers\aswStm.sys [2014-2-3 214808]
R2 avast! Antivirus;Avast Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2018-8-6 322464]
R2 ClickToRunSvc;Microsoft Office Click-to-Run Service;C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2016-2-7 8765104]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2013-11-4 92160]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-7-21 103992]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-8-5 291896]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-3-5 35200]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-2-20 13592]
R2 ptumlcmsvc;PTUML290 Connection Manager Service;C:\Windows\System32\ptumlcmsvc64.exe [2012-3-8 174592]
R2 RoxioNow Service;RoxioNow Service;C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-9-11 399344]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-2-20 2320920]
R3 aswbIDSAgent;aswbIDSAgent;C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2018-8-6 7963320]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys [2011-3-23 31088]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2009-9-17 56344]
R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-12-8 158976]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-4-2 317440]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-1-18 565352]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-10-4 107624]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-10-3 128608]
S3 aswHwid;aswHwid;C:\Windows\System32\drivers\aswHwid.sys [2014-5-6 46968]
S3 aswTap;avast! SecureLine TAP Adapter v3;C:\Windows\System32\drivers\aswTap.sys [2014-7-17 44640]
S3 btwampfl;Bluetooth AMP USB Filter;C:\Windows\System32\drivers\btwampfl.sys [2011-2-20 620584]
S3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\System32\drivers\btwdpan.sys [2012-1-18 89640]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2011-2-20 39976]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2018-8-6 116224]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\drivers\netaapl64.sys [2013-7-25 23040]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368]
S3 PTUMLBUS;PTUML USB Composite Device Driver;C:\Windows\System32\drivers\PTUMLBUS.sys [2012-3-8 105600]
S3 PTUMLCVsp;PANTECH UML290 Connection Manager Port;C:\Windows\System32\drivers\PTUMLCVsp.sys [2012-3-8 183424]
S3 PTUMLMBMP;PANTECH UML290 Mobile Broadband;C:\Windows\System32\drivers\PTUMLMBMP.sys [2012-3-8 235776]
S3 PTUMLMdm;PANTECH UML290;C:\Windows\System32\drivers\PTUMLMdm.sys [2012-3-8 183424]
S3 PTUMLNET61;PANTECH UML290 WWAN (NDIS6.1);C:\Windows\System32\drivers\PTUMLNET61.sys [2012-3-8 111872]
S3 PTUMLNVsp;PANTECH UML290 NMEA Port;C:\Windows\System32\drivers\PTUMLNVsp.sys [2012-3-8 184448]
S3 PTUMLRMNET;PANTECH UML290 RMNET Service;C:\Windows\System32\drivers\PTUMLRMNET.sys [2012-3-8 63744]
S3 PTUMLVsp;PANTECH UML290 Diagnostic Port;C:\Windows\System32\drivers\PTUMLVsp.sys [2012-3-8 183424]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2014-12-18 19456]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2011-2-20 329832]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-12-18 56832]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2015-6-10 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-12-27 1255736]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2018-08-06 16:43:04 2860032 ----a-w- C:\Windows\System32\aitstatic.exe
2018-08-06 16:43:04 1602048 ----a-w- C:\Windows\System32\appraiser.dll
2018-08-06 16:43:03 783872 ----a-w- C:\Windows\System32\generaltel.dll
2018-08-06 16:43:03 680960 ----a-w- C:\Windows\System32\aeinv.dll
2018-08-06 16:43:03 612352 ----a-w- C:\Windows\System32\devinv.dll
2018-08-06 16:43:03 470016 ----a-w- C:\Windows\System32\centel.dll
2018-08-06 16:43:03 443392 ----a-w- C:\Windows\System32\invagent.dll
2018-08-06 16:43:03 301056 ----a-w- C:\Windows\System32\acmigration.dll
2018-08-06 16:43:03 246272 ----a-w- C:\Windows\System32\aepic.dll
2018-08-06 16:43:03 140992 ----a-w- C:\Windows\System32\CompatTelRunner.exe
2018-08-06 16:39:59 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2018-08-06 16:18:54 -------- d-----w- C:\Users\Hodie\AppData\Roaming\Roxio Log Files
.
==================== Find3M ====================
.
2018-08-06 15:39:36 214808 ----a-w- C:\Windows\System32\drivers\aswStm.sys
2018-08-06 15:39:32 381552 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2018-08-06 15:39:30 85968 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2018-08-06 15:39:29 163272 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2018-08-06 15:39:28 46968 ----a-w- C:\Windows\System32\drivers\aswHwid.sys
2018-08-06 15:39:26 199712 ----a-w- C:\Windows\System32\drivers\aswArPot.sys
2018-08-06 15:39:22 111864 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2018-08-06 15:36:40 1027720 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2018-08-06 15:36:28 249016 ----a-w- C:\Windows\System32\drivers\aswHdsKe.sys
2018-08-06 15:36:22 59568 ----a-w- C:\Windows\System32\drivers\aswbuniva.sys
2018-08-06 15:36:22 346664 ----a-w- C:\Windows\System32\drivers\aswbloga.sys
2018-08-06 15:36:22 229392 ----a-w- C:\Windows\System32\drivers\aswbidsdrivera.sys
2018-08-06 15:36:22 201320 ----a-w- C:\Windows\System32\drivers\aswbidsha.sys
2018-06-28 19:25:07 2560 ----a-w- C:\Windows\apppatch\AcRes.dll
2018-06-16 16:46:18 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2018-06-16 16:46:05 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2018-06-16 16:32:15 66560 ----a-w- C:\Windows\System32\iesetup.dll
2018-06-16 16:31:31 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2018-06-16 16:31:25 576512 ----a-w- C:\Windows\System32\vbscript.dll
2018-06-16 16:31:24 417280 ----a-w- C:\Windows\System32\html.iec
2018-06-16 16:30:50 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2018-06-16 16:27:52 5779968 ----a-w- C:\Windows\System32\jscript9.dll
2018-06-16 16:19:49 116224 ----a-w- C:\Windows\System32\ieetwcollector.exe
2018-06-16 16:19:48 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2018-06-16 16:19:28 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2018-06-16 16:19:14 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2018-06-16 16:12:00 969216 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2018-06-16 16:06:25 498176 ----a-w- C:\Windows\SysWow64\vbscript.dll
2018-06-16 16:06:19 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2018-06-16 16:05:36 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2018-06-16 16:05:24 341504 ----a-w- C:\Windows\SysWow64\html.iec
2018-06-16 16:04:30 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2018-06-16 16:02:19 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2018-06-16 16:02:00 87552 ----a-w- C:\Windows\System32\tdc.ocx
2018-06-16 15:56:02 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2018-06-16 15:55:36 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2018-06-16 15:42:51 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2018-06-16 15:42:23 73216 ----a-w- C:\Windows\SysWow64\tdc.ocx
2018-06-16 15:40:10 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2018-06-16 15:39:57 2135552 ----a-w- C:\Windows\System32\inetcpl.cpl
2018-06-16 15:34:39 4496384 ----a-w- C:\Windows\SysWow64\jscript9.dll
2018-06-16 15:28:49 2060288 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2018-06-16 15:27:57 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2018-06-16 15:27:14 3241472 ----a-w- C:\Windows\System32\wininet.dll
2018-06-16 15:08:41 2767872 ----a-w- C:\Windows\SysWow64\wininet.dll
2018-06-13 16:19:39 1867776 ----a-w- C:\Windows\System32\ExplorerFrame.dll
2018-06-13 15:54:52 1499648 ----a-w- C:\Windows\SysWow64\ExplorerFrame.dll
2018-06-13 15:40:41 3226112 ----a-w- C:\Windows\System32\win32k.sys
2018-06-13 08:06:35 133315992 -c--a-w- C:\Windows\System32\MRT-KB890830.exe
2018-06-08 16:27:27 95424 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2018-06-08 16:27:27 708288 ----a-w- C:\Windows\System32\winload.efi
2018-06-08 16:27:27 5577408 ----a-w- C:\Windows\System32\ntoskrnl.exe
2018-06-08 16:27:27 154816 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2018-06-08 16:23:39 631640 ----a-w- C:\Windows\System32\winresume.efi
2018-06-08 16:22:54 1665344 ----a-w- C:\Windows\System32\ntdll.dll
2018-06-08 16:21:06 369664 ----a-w- C:\Windows\System32\zipfldr.dll
2018-06-08 16:21:04 361984 ----a-w- C:\Windows\System32\wow64win.dll
2018-06-08 16:21:04 243712 ----a-w- C:\Windows\System32\wow64.dll
2018-06-08 16:21:04 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2018-06-08 16:21:03 215552 ----a-w- C:\Windows\System32\winsrv.dll
2018-06-08 16:21:01 210432 ----a-w- C:\Windows\System32\wdigest.dll
2018-06-08 16:19:36 182272 ----a-w- C:\Windows\System32\dnsrslvr.dll
2018-06-08 16:19:22 44032 ----a-w- C:\Windows\System32\csrsrv.dll
2018-06-08 16:19:20 43520 ----a-w- C:\Windows\System32\cryptbase.dll
2018-06-08 16:19:20 22016 ----a-w- C:\Windows\System32\credssp.dll
2018-06-08 16:19:17 8704 ----a-w- C:\Windows\System32\comcat.dll
2018-06-08 16:02:51 4050624 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2018-06-08 16:02:51 3962048 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2018-06-08 15:57:51 1314072 ----a-w- C:\Windows\SysWow64\ntdll.dll
2018-06-08 15:54:31 17408 ----a-w- C:\Windows\SysWow64\credssp.dll
2018-06-08 15:53:59 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2018-06-08 15:44:53 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2018-06-08 15:44:14 148480 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2018-06-08 15:44:10 62464 ----a-w- C:\Windows\System32\drivers\appid.sys
2018-06-08 15:44:10 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2018-06-08 15:43:21 64000 ----a-w- C:\Windows\System32\auditpol.exe
2018-06-08 15:39:37 338432 ----a-w- C:\Windows\System32\conhost.exe
2018-06-08 15:38:59 129024 ----a-w- C:\Windows\System32\drivers\videoprt.sys
2018-06-08 15:38:30 296960 ----a-w- C:\Windows\System32\rstrui.exe
2018-06-08 15:34:44 159744 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2018-06-08 15:34:22 291328 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2018-06-08 15:34:19 129536 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2018-06-08 15:33:10 30720 ----a-w- C:\Windows\System32\lsass.exe
2018-06-08 15:33:05 112640 ----a-w- C:\Windows\System32\smss.exe
2018-06-08 15:29:59 7168 ----a-w- C:\Windows\SysWow64\comcat.dll
2018-06-08 15:28:20 30720 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
2018-06-08 15:27:08 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2018-06-08 15:21:32 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2018-06-08 15:21:30 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2018-06-08 15:21:30 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2018-06-08 15:21:29 2048 ----a-w- C:\Windows\SysWow64\user.exe
2018-06-08 15:19:55 36352 ----a-w- C:\Windows\SysWow64\cryptbase.dll
2018-06-08 15:19:40 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2018-06-08 15:19:40 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2018-06-08 15:19:40 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2018-06-08 15:19:40 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2018-06-07 16:20:20 22528 ----a-w- C:\Windows\System32\wfapigp.dll
2018-06-07 16:19:48 828928 ----a-w- C:\Windows\System32\MPSSVC.dll
2018-06-07 16:19:29 108544 ----a-w- C:\Windows\System32\icfupgd.dll
2018-06-07 16:19:21 749568 ----a-w- C:\Windows\System32\FirewallAPI.dll
.
============= FINISH: 18:29:44.88 ===============
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.19081
Run by Hodie at 18:29:06 on 2018-08-07
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3894.1370 [GMT -5:00]
.
AV: Avast Antivirus *Enabled/Updated* {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Avast Antivirus *Enabled/Updated* {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\ptumlcmsvc64.exe
C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
C:\Windows\sysWow64\SearchProtocolHost.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uProxyServer = localhost:8080
mWinlogon: Userinit = userinit.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - <orphaned>
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL
BHO: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - <orphaned>
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [iCloudServices] "C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe"
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
dRunOnce: [iCloud] "C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloud.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: SoftwareSASGeneration = dword:1
IE: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.4.0/GarminAxControl_32.CAB
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://uhc.webex.com/client/WBXclient-T27L10NSP32EP5-14362/webex/ieatgpc1.cab
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{61A21C53-CE0F-4214-BA30-8A64E88F8D1B} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{695076B3-72BF-4452-8C0C-61DD9CF93C7E} : DHCPNameServer = 172.20.10.1
TCP: Interfaces\{FC761777-E592-4B4B-A5E1-2F915004E613} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{FC761777-E592-4B4B-A5E1-2F915004E613}\2375942554431383 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{FC761777-E592-4B4B-A5E1-2F915004E613}\2375942554638333 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{FC761777-E592-4B4B-A5E1-2F915004E613}\4415C4F4447454 : DHCPNameServer = 192.168.254.254
TCP: Interfaces\{FC761777-E592-4B4B-A5E1-2F915004E613}\44F65726C65645275656022697028496C647F6E6 : DHCPNameServer = 8.8.8.8 8.8.4.4
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\MSOXMLMF.DLL
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\68.0.3440.84\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll",CreateReaderUserSettings
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - <orphaned>
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL
x64-BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - <orphaned>
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
x64-Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
x64-Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL
x64-Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - <orphaned>
x64-Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Hodie\AppData\Roaming\Mozilla\Firefox\Profiles\km5jf2y2.default-1473202271514\
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Hodie\AppData\Local\Citrix\Plugins\104\npappdetector.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswbidsh;aswbidsh;C:\Windows\System32\drivers\aswbidsha.sys [2017-2-3 201320]
R0 aswblog;aswblog;C:\Windows\System32\drivers\aswbloga.sys [2017-2-3 346664]
R0 aswbuniv;aswbuniv;C:\Windows\System32\drivers\aswbuniva.sys [2017-2-3 59568]
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2014-2-3 85968]
R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2014-2-3 381552]
R1 aswArPot;aswArPot;C:\Windows\System32\drivers\aswArPot.sys [2017-10-27 199712]
R1 aswbidsdriver;aswbidsdriver;C:\Windows\System32\drivers\aswbidsdrivera.sys [2017-2-3 229392]
R1 aswHdsKe;aswHdsKe;C:\Windows\System32\drivers\aswHdsKe.sys [2017-11-24 249016]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2014-2-3 1027720]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2014-2-3 466720]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2018-4-27 83768]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2014-2-3 163272]
R2 aswStm;aswStm;C:\Windows\System32\drivers\aswStm.sys [2014-2-3 214808]
R2 avast! Antivirus;Avast Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2018-8-6 322464]
R2 ClickToRunSvc;Microsoft Office Click-to-Run Service;C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2016-2-7 8765104]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2013-11-4 92160]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-7-21 103992]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-8-5 291896]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-3-5 35200]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-2-20 13592]
R2 ptumlcmsvc;PTUML290 Connection Manager Service;C:\Windows\System32\ptumlcmsvc64.exe [2012-3-8 174592]
R2 RoxioNow Service;RoxioNow Service;C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-9-11 399344]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-2-20 2320920]
R3 aswbIDSAgent;aswbIDSAgent;C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2018-8-6 7963320]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys [2011-3-23 31088]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2009-9-17 56344]
R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-12-8 158976]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-4-2 317440]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-1-18 565352]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-10-4 107624]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-10-3 128608]
S3 aswHwid;aswHwid;C:\Windows\System32\drivers\aswHwid.sys [2014-5-6 46968]
S3 aswTap;avast! SecureLine TAP Adapter v3;C:\Windows\System32\drivers\aswTap.sys [2014-7-17 44640]
S3 btwampfl;Bluetooth AMP USB Filter;C:\Windows\System32\drivers\btwampfl.sys [2011-2-20 620584]
S3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\System32\drivers\btwdpan.sys [2012-1-18 89640]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2011-2-20 39976]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2018-8-6 116224]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\drivers\netaapl64.sys [2013-7-25 23040]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368]
S3 PTUMLBUS;PTUML USB Composite Device Driver;C:\Windows\System32\drivers\PTUMLBUS.sys [2012-3-8 105600]
S3 PTUMLCVsp;PANTECH UML290 Connection Manager Port;C:\Windows\System32\drivers\PTUMLCVsp.sys [2012-3-8 183424]
S3 PTUMLMBMP;PANTECH UML290 Mobile Broadband;C:\Windows\System32\drivers\PTUMLMBMP.sys [2012-3-8 235776]
S3 PTUMLMdm;PANTECH UML290;C:\Windows\System32\drivers\PTUMLMdm.sys [2012-3-8 183424]
S3 PTUMLNET61;PANTECH UML290 WWAN (NDIS6.1);C:\Windows\System32\drivers\PTUMLNET61.sys [2012-3-8 111872]
S3 PTUMLNVsp;PANTECH UML290 NMEA Port;C:\Windows\System32\drivers\PTUMLNVsp.sys [2012-3-8 184448]
S3 PTUMLRMNET;PANTECH UML290 RMNET Service;C:\Windows\System32\drivers\PTUMLRMNET.sys [2012-3-8 63744]
S3 PTUMLVsp;PANTECH UML290 Diagnostic Port;C:\Windows\System32\drivers\PTUMLVsp.sys [2012-3-8 183424]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2014-12-18 19456]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2011-2-20 329832]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-12-18 56832]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2015-6-10 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-12-27 1255736]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2018-08-06 16:43:04 2860032 ----a-w- C:\Windows\System32\aitstatic.exe
2018-08-06 16:43:04 1602048 ----a-w- C:\Windows\System32\appraiser.dll
2018-08-06 16:43:03 783872 ----a-w- C:\Windows\System32\generaltel.dll
2018-08-06 16:43:03 680960 ----a-w- C:\Windows\System32\aeinv.dll
2018-08-06 16:43:03 612352 ----a-w- C:\Windows\System32\devinv.dll
2018-08-06 16:43:03 470016 ----a-w- C:\Windows\System32\centel.dll
2018-08-06 16:43:03 443392 ----a-w- C:\Windows\System32\invagent.dll
2018-08-06 16:43:03 301056 ----a-w- C:\Windows\System32\acmigration.dll
2018-08-06 16:43:03 246272 ----a-w- C:\Windows\System32\aepic.dll
2018-08-06 16:43:03 140992 ----a-w- C:\Windows\System32\CompatTelRunner.exe
2018-08-06 16:39:59 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2018-08-06 16:18:54 -------- d-----w- C:\Users\Hodie\AppData\Roaming\Roxio Log Files
.
==================== Find3M ====================
.
2018-08-06 15:39:36 214808 ----a-w- C:\Windows\System32\drivers\aswStm.sys
2018-08-06 15:39:32 381552 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2018-08-06 15:39:30 85968 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2018-08-06 15:39:29 163272 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2018-08-06 15:39:28 46968 ----a-w- C:\Windows\System32\drivers\aswHwid.sys
2018-08-06 15:39:26 199712 ----a-w- C:\Windows\System32\drivers\aswArPot.sys
2018-08-06 15:39:22 111864 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2018-08-06 15:36:40 1027720 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2018-08-06 15:36:28 249016 ----a-w- C:\Windows\System32\drivers\aswHdsKe.sys
2018-08-06 15:36:22 59568 ----a-w- C:\Windows\System32\drivers\aswbuniva.sys
2018-08-06 15:36:22 346664 ----a-w- C:\Windows\System32\drivers\aswbloga.sys
2018-08-06 15:36:22 229392 ----a-w- C:\Windows\System32\drivers\aswbidsdrivera.sys
2018-08-06 15:36:22 201320 ----a-w- C:\Windows\System32\drivers\aswbidsha.sys
2018-06-28 19:25:07 2560 ----a-w- C:\Windows\apppatch\AcRes.dll
2018-06-16 16:46:18 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2018-06-16 16:46:05 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2018-06-16 16:32:15 66560 ----a-w- C:\Windows\System32\iesetup.dll
2018-06-16 16:31:31 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2018-06-16 16:31:25 576512 ----a-w- C:\Windows\System32\vbscript.dll
2018-06-16 16:31:24 417280 ----a-w- C:\Windows\System32\html.iec
2018-06-16 16:30:50 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2018-06-16 16:27:52 5779968 ----a-w- C:\Windows\System32\jscript9.dll
2018-06-16 16:19:49 116224 ----a-w- C:\Windows\System32\ieetwcollector.exe
2018-06-16 16:19:48 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2018-06-16 16:19:28 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2018-06-16 16:19:14 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2018-06-16 16:12:00 969216 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2018-06-16 16:06:25 498176 ----a-w- C:\Windows\SysWow64\vbscript.dll
2018-06-16 16:06:19 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2018-06-16 16:05:36 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2018-06-16 16:05:24 341504 ----a-w- C:\Windows\SysWow64\html.iec
2018-06-16 16:04:30 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2018-06-16 16:02:19 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2018-06-16 16:02:00 87552 ----a-w- C:\Windows\System32\tdc.ocx
2018-06-16 15:56:02 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2018-06-16 15:55:36 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2018-06-16 15:42:51 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2018-06-16 15:42:23 73216 ----a-w- C:\Windows\SysWow64\tdc.ocx
2018-06-16 15:40:10 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2018-06-16 15:39:57 2135552 ----a-w- C:\Windows\System32\inetcpl.cpl
2018-06-16 15:34:39 4496384 ----a-w- C:\Windows\SysWow64\jscript9.dll
2018-06-16 15:28:49 2060288 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2018-06-16 15:27:57 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2018-06-16 15:27:14 3241472 ----a-w- C:\Windows\System32\wininet.dll
2018-06-16 15:08:41 2767872 ----a-w- C:\Windows\SysWow64\wininet.dll
2018-06-13 16:19:39 1867776 ----a-w- C:\Windows\System32\ExplorerFrame.dll
2018-06-13 15:54:52 1499648 ----a-w- C:\Windows\SysWow64\ExplorerFrame.dll
2018-06-13 15:40:41 3226112 ----a-w- C:\Windows\System32\win32k.sys
2018-06-13 08:06:35 133315992 -c--a-w- C:\Windows\System32\MRT-KB890830.exe
2018-06-08 16:27:27 95424 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2018-06-08 16:27:27 708288 ----a-w- C:\Windows\System32\winload.efi
2018-06-08 16:27:27 5577408 ----a-w- C:\Windows\System32\ntoskrnl.exe
2018-06-08 16:27:27 154816 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2018-06-08 16:23:39 631640 ----a-w- C:\Windows\System32\winresume.efi
2018-06-08 16:22:54 1665344 ----a-w- C:\Windows\System32\ntdll.dll
2018-06-08 16:21:06 369664 ----a-w- C:\Windows\System32\zipfldr.dll
2018-06-08 16:21:04 361984 ----a-w- C:\Windows\System32\wow64win.dll
2018-06-08 16:21:04 243712 ----a-w- C:\Windows\System32\wow64.dll
2018-06-08 16:21:04 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2018-06-08 16:21:03 215552 ----a-w- C:\Windows\System32\winsrv.dll
2018-06-08 16:21:01 210432 ----a-w- C:\Windows\System32\wdigest.dll
2018-06-08 16:19:36 182272 ----a-w- C:\Windows\System32\dnsrslvr.dll
2018-06-08 16:19:22 44032 ----a-w- C:\Windows\System32\csrsrv.dll
2018-06-08 16:19:20 43520 ----a-w- C:\Windows\System32\cryptbase.dll
2018-06-08 16:19:20 22016 ----a-w- C:\Windows\System32\credssp.dll
2018-06-08 16:19:17 8704 ----a-w- C:\Windows\System32\comcat.dll
2018-06-08 16:02:51 4050624 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2018-06-08 16:02:51 3962048 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2018-06-08 15:57:51 1314072 ----a-w- C:\Windows\SysWow64\ntdll.dll
2018-06-08 15:54:31 17408 ----a-w- C:\Windows\SysWow64\credssp.dll
2018-06-08 15:53:59 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2018-06-08 15:44:53 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2018-06-08 15:44:14 148480 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2018-06-08 15:44:10 62464 ----a-w- C:\Windows\System32\drivers\appid.sys
2018-06-08 15:44:10 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2018-06-08 15:43:21 64000 ----a-w- C:\Windows\System32\auditpol.exe
2018-06-08 15:39:37 338432 ----a-w- C:\Windows\System32\conhost.exe
2018-06-08 15:38:59 129024 ----a-w- C:\Windows\System32\drivers\videoprt.sys
2018-06-08 15:38:30 296960 ----a-w- C:\Windows\System32\rstrui.exe
2018-06-08 15:34:44 159744 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2018-06-08 15:34:22 291328 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2018-06-08 15:34:19 129536 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2018-06-08 15:33:10 30720 ----a-w- C:\Windows\System32\lsass.exe
2018-06-08 15:33:05 112640 ----a-w- C:\Windows\System32\smss.exe
2018-06-08 15:29:59 7168 ----a-w- C:\Windows\SysWow64\comcat.dll
2018-06-08 15:28:20 30720 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
2018-06-08 15:27:08 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2018-06-08 15:21:32 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2018-06-08 15:21:30 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2018-06-08 15:21:30 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2018-06-08 15:21:29 2048 ----a-w- C:\Windows\SysWow64\user.exe
2018-06-08 15:19:55 36352 ----a-w- C:\Windows\SysWow64\cryptbase.dll
2018-06-08 15:19:40 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2018-06-08 15:19:40 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2018-06-08 15:19:40 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2018-06-08 15:19:40 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2018-06-07 16:20:20 22528 ----a-w- C:\Windows\System32\wfapigp.dll
2018-06-07 16:19:48 828928 ----a-w- C:\Windows\System32\MPSSVC.dll
2018-06-07 16:19:29 108544 ----a-w- C:\Windows\System32\icfupgd.dll
2018-06-07 16:19:21 749568 ----a-w- C:\Windows\System32\FirewallAPI.dll
.
============= FINISH: 18:29:44.88 ===============