Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all articles
Browse latest Browse all 2798

Possible Trojan/Rootkit?

$
0
0
Hi, I'm experiencing an issue where I can't open any of the icons on my taskbar, can't access pictures (The remote procedure call failed.) and I can't access video files (Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item.). For reference, it sounds a lot like a previous thread I read (http://www.techsupportforum.com/foru...-425946-2.html), however, I'd rather have live support then follow the steps there.

I have Zonealarm firewall and BitDefender Antivirus active.

[LOGS]

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.14393.0 BrowserJavaVersion: 11.101.2
Run by Andrew Hoyland at 22:29:32 on 2016-10-19
Microsoft Windows 10 Home 10.0.14393.0.1252.1.1033.18.12238.8202 [GMT 11:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Bitdefender Antivirus Free Edition *Enabled/Updated* {3FB17364-4FCC-0FA7-6BBF-973897395371}
SP: Bitdefender Antivirus Free Edition *Enabled/Updated* {84D09280-69F6-0029-510F-AC4AECBE19CC}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ZoneAlarm Free Firewall Firewall *Enabled* {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\dashost.exe
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe -k apphost
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\sysWow64\CtHdaSvc.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\WINDOWS\system32\svchost.exe -k iissvcs
C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\system32\taskhostw.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files\Bitdefender\Antivirus Free Edition\gziface.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files (x86)\AlienRespawn\TOASTER.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files (x86)\AlienRespawn\Components\DSUpdate\DSUpd.exe
C:\Program Files (x86)\AlienRespawn\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
svchost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
C:\WINDOWS\system32\SettingSyncHost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Users\Andrew Hoyland\AppData\Local\FluxSoftware\Flux\flux.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe
C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Alienware\Command Center\AlienFusionService.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Alienware\Command Center\AlienFusionController.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Andrew Hoyland\AppData\Local\Discord\app-0.0.296\Discord.exe
C:\Users\Andrew Hoyland\AppData\Local\Discord\app-0.0.296\Discord.exe
C:\Users\Andrew Hoyland\AppData\Local\Discord\app-0.0.296\Discord.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\WINDOWS\SysWoW64\NOTEPAD.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\ApplicationFrameHost.exe
C:\WINDOWS\system32\AUDIODG.EXE
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\AlienRespawn\sftservice.EXE
C:\WINDOWS\System32\svchost.exe -k WerSvcGroup
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\System32\LocationNotificationWindows.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - <orphaned>
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll
uRun: [Dropbox Update] "C:\Users\Andrew Hoyland\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
uRun: [BingSvc] C:\Users\Andrew Hoyland\AppData\Local\Microsoft\BingSvc\BingSvc.exe
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
uRun: [iCloudDrive] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
uRun: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
uRun: [f.lux] "C:\Users\Andrew Hoyland\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
uRun: [Discord] C:\Users\Andrew Hoyland\AppData\Local\Discord\app-0.0.296\Discord.exe
uRunOnce: [Uninstall C:\Users\Andrew Hoyland\AppData\Local\Microsoft\OneDrive\17.3.5951.0827_1\amd64] C:\WINDOWS\System32\cmd.exe /q /c rmdir /s /q "C:\Users\Andrew Hoyland\AppData\Local\Microsoft\OneDrive\17.3.5951.0827_1\amd64"
uRunOnce: [Uninstall C:\Users\Andrew Hoyland\AppData\Local\Microsoft\OneDrive\17.3.5951.0827_1] C:\WINDOWS\System32\cmd.exe /q /c rmdir /s /q "C:\Users\Andrew Hoyland\AppData\Local\Microsoft\OneDrive\17.3.5951.0827_1"
mRun: [AlienwareOn-ScreenDisplay] C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
mRun: [PDVD9LanguageShortcut] c:\program files (x86)\cyberlink\powerdvd9\language\language.exe
mRun: [IAStorIcon] c:\program files (x86)\intel\intel(r) rapid storage technology\iastoricon.exe
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [UpdReg] C:\WINDOWS\UpdReg.EXE
mRun: [Sound Blaster Recon3Di Control Panel] "C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe" /r
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [ZoneAlarm] "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe"
mRun: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
mPolicies-Explorer: NoDriveTypeAutoRun = dword:60
mPolicies-System: DSCAutomationHostEnabled = dword:2
IE: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_91-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-0091-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_91-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_91-windows-i586.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{e02bb29d-6561-449e-a9d4-66ecb8a3b9d0} : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{e02bb29d-6561-449e-a9d4-66ecb8a3b9d0}\1405F5631363633313336383 : DHCPNameServer = 10.10.100.254
TCP: Interfaces\{f5f7a027-09a3-4ec5-8987-e6a47d68c131} : DHCPNameServer = 192.168.0.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
SSODL: WebCheck - <orphaned>
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
x64-mStart Page = about:blank
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [Command Center Controllers] c:\program files\alienware\command center\awccstartuporchestrator.exe
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
x64-Run: [ShadowPlay] "C:\WINDOWS\System32\rundll32.exe" C:\WINDOWS\System32\nvspcap64.dll,ShadowPlayOnSystemStart
x64-mPolicies-Explorer: NoDriveTypeAutoRun = dword:60
x64-mPolicies-System: DSCAutomationHostEnabled = dword:2
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
x64-mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.143\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
.
================= FIREFOX ===================
.
FF - ProfilePath -
.
============= SERVICES / DRIVERS ===============
.
R0 EMSC;COMPAL Embedded System Control;C:\WINDOWS\System32\drivers\EMSC.sys [2009-6-27 16752]
R0 iaStorAV;Intel(R) SATA RAID Controller Windows;C:\WINDOWS\System32\drivers\iaStorAV.sys [2016-7-16 673120]
R0 intelpep;Intel(R) Power Engine Plug-in Driver;C:\WINDOWS\System32\drivers\intelpep.sys [2016-7-16 48152]
R0 iorate;iorate;C:\WINDOWS\System32\drivers\iorate.sys [2016-7-16 45920]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\WINDOWS\System32\drivers\iusb3hcs.sys [2013-5-18 16152]
R0 PxHlpa64;PxHlpa64;C:\WINDOWS\System32\drivers\PxHlpa64.sys [2013-5-17 56336]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\WINDOWS\System32\drivers\stdcfltn.sys [2013-5-18 22128]
R0 volume;Volume driver;C:\WINDOWS\System32\drivers\volume.sys [2016-7-16 16224]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [2016-7-16 107032]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [2016-7-16 17944]
R0 Wof;Windows Overlay File System Filter Driver;C:\WINDOWS\System32\drivers\wof.sys [2016-8-26 199008]
R1 ahcache;Application Compatibility Cache;C:\WINDOWS\System32\drivers\ahcache.sys [2016-7-16 227328]
R1 FileCrypt;FileCrypt;C:\WINDOWS\System32\drivers\filecrypt.sys [2016-7-16 88576]
R1 GpuEnergyDrv;GPU Energy Driver;C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2016-7-16 8192]
R1 gzflt;gzflt;C:\WINDOWS\System32\drivers\gzflt.sys [2016-6-28 148696]
R2 AdobeUpdateService;AdobeUpdateService;C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [2016-8-24 744640]
R2 AGSService;Adobe Genuine Software Integrity Service;C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2015-9-4 2207960]
R2 AlienFusionService;Alienware Fusion Service;C:\Program Files\Alienware\Command Center\AlienFusionService.exe [2012-2-10 14664]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-3-2 83768]
R2 CDPSvc;Connected Devices Platform Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
R2 CDPUserSvc_53549;CDPUserSvc_53549;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R2 clreg;Virtual Registry for Containers;C:\WINDOWS\System32\drivers\registry.sys [2016-7-16 70144]
R2 CoreMessagingRegistrar;CoreMessaging;C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork [2016-7-16 44496]
R2 CtHdaSvc;Sound Core3D Service;C:\Windows\SysWOW64\CtHdaSvc.exe [2015-6-12 133640]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2015-3-18 822496]
R2 DiagTrack;Connected User Experiences and Telemetry;C:\WINDOWS\System32\svchost.exe -k utcsvc [2016-7-16 44496]
R2 DoSvc;Delivery Optimization;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R2 gzserv;Bitdefender Antivirus Free Edition;C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe [2016-6-28 79552]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-5-17 13592]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container;C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-9-22 455616]
R2 NVIDIA Wireless Controller Service;NVIDIA Wireless Controller Service;C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [2016-9-22 1163712]
R2 OneSyncSvc_53549;Sync Host_53549;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2014-10-8 534184]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\AlienRespawn\SftService.exe [2013-5-17 1695040]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe [2016-9-22 426040]
R2 storqosflt;Storage QoS Filter Driver;C:\WINDOWS\System32\drivers\storqosflt.sys [2016-7-16 78336]
R2 tiledatamodelsvc;Tile Data model server;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
R2 UserManager;User Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R2 wcifs;Windows Container Isolation;C:\WINDOWS\System32\drivers\wcifs.sys [2016-9-30 119648]
R2 wcnfs;Windows Container Name Virtualization;C:\WINDOWS\System32\drivers\wcnfs.sys [2016-7-16 66560]
R2 WpnService;Windows Push Notifications System Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R2 ZAPrivacyService;ZoneAlarm Privacy Service;C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [2016-6-30 114424]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;C:\WINDOWS\System32\drivers\AmpPal.sys [2012-1-10 195584]
R3 AppXSvc;AppX Deployment Service (AppXSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2016-7-16 44496]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\WINDOWS\System32\drivers\CtClsFlt.sys [2013-5-17 172704]
R3 cthda;Sound Core3D(CtHda.sys);C:\WINDOWS\System32\drivers\cthda.sys [2015-6-12 1075496]
R3 DellRbtn;Airplane Mode Switch;C:\WINDOWS\System32\drivers\DellRbtn.sys [2015-8-15 19440]
R3 ibtfltcoex;Intel Corporation;C:\WINDOWS\System32\drivers\ibtfltcoex.sys [2015-7-1 79632]
R3 kiox_ff_driver;Kionix freefall detection service;C:\WINDOWS\System32\drivers\kiox_ff_driver.sys [2015-6-15 41456]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;C:\WINDOWS\System32\drivers\L1C62x64.sys [2014-4-21 128200]
R3 lfsvc;Geolocation Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R3 LicenseManager;Windows License Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
R3 NcbService;Network Connection Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [2016-7-16 20480]
R3 NETwNe64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit;C:\WINDOWS\System32\drivers\NETwew01.sys [2016-7-16 3343872]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\WINDOWS\System32\drivers\nvvad64v.sys [2016-6-16 46016]
R3 PimIndexMaintenanceSvc_53549;Contact Data_53549;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\WINDOWS\System32\drivers\RtsPStor.sys [2015-6-3 374016]
R3 Sftfs;Sftfs;C:\WINDOWS\System32\drivers\Sftfslh.sys [2014-10-8 766632]
R3 Sftplay;Sftplay;C:\WINDOWS\System32\drivers\Sftplaylh.sys [2014-10-8 273576]
R3 Sftredir;Sftredir;C:\WINDOWS\System32\drivers\Sftredirlh.sys [2014-10-8 29352]
R3 Sftvol;Sftvol;C:\WINDOWS\System32\drivers\Sftvollh.sys [2014-10-8 23208]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2014-10-8 211104]
R3 StateRepository;State Repository Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
R3 TimeBrokerSvc;Time Broker;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
R3 UnistoreSvc_53549;User Data Storage_53549;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R3 USBAAPL64;Apple Mobile USB Driver;C:\WINDOWS\System32\drivers\usbaapl64.sys [2015-6-11 54784]
R3 UserDataSvc_53549;User Data Access_53549;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
R3 wisvc;Windows Insider Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
R3 XtuAcpiDriver;Intel(R) Extreme Tuning Utility Service;C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [2015-6-6 63840]
S1 bdfwfpf;bdfwfpf;C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys [2016-6-28 121928]
S2 CLKMSVC10_9EC60124;CyberLink Product - 2013/05/17 07:35:01;C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2011-8-12 248304]
S2 MapsBroker;Downloaded Maps Manager;C:\WINDOWS\System32\svchost.exe -k NetworkService [2016-7-16 44496]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-5-23 324224]
S3 AcpiDev;ACPI Devices driver;C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-7-16 18432]
S3 ADP80XX;ADP80XX;C:\WINDOWS\System32\drivers\adp80xx.sys [2016-7-16 1135456]
S3 AJRouter;AllJoyn Router Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;C:\WINDOWS\System32\drivers\AmpPal.sys [2012-1-10 195584]
S3 applockerfltr;Smartlocker Filter Driver;C:\WINDOWS\System32\drivers\applockerfltr.sys [2016-7-16 15360]
S3 AppReadiness;App Readiness;C:\WINDOWS\System32\svchost.exe -k AppReadiness [2016-7-16 44496]
S3 avckf;avckf;C:\WINDOWS\System32\drivers\avckf.sys [2016-6-28 593144]
S3 bcmfn;bcmfn Service;C:\WINDOWS\System32\drivers\bcmfn.sys [2016-7-16 9728]
S3 bcmfn2;bcmfn2 Service;C:\WINDOWS\System32\drivers\bcmfn2.sys [2016-7-16 9728]
S3 BthHFSrv;Bluetooth Handsfree Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation [2016-7-16 44496]
S3 buttonconverter;Service for Portable Device Control devices;C:\WINDOWS\System32\drivers\buttonconverter.sys [2016-7-16 38912]
S3 CapImg;HID driver for CapImg touch screen;C:\WINDOWS\System32\drivers\capimg.sys [2016-7-16 117248]
S3 CEDRIVER60;CEDRIVER60;C:\Program Files (x86)\Cheat Engine 6.4\dbk64.sys [2015-5-9 64064]
S3 cht4iscsi;cht4iscsi;C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-7-16 346976]
S3 cht4vbd;Chelsio Virtual Bus Driver;C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-7-16 2104160]
S3 ClipSVC;Client License Service (ClipSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2016-7-16 44496]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2016-3-17 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2016-3-17 79360]
S3 DcpSvc;DataCollectionPublishingService;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 DevQueryBroker;DevQuery Background Discovery Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 diagnosticshub.standardcollector.service;Microsoft (R) Diagnostics Hub Standard Collector Service;C:\WINDOWS\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2016-7-16 93184]
S3 DmEnrollmentSvc;Device Management Enrollment Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 dmwappushservice;dmwappushsvc;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 DsSvc;Data Sharing Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 EasyAntiCheat;EasyAntiCheat;C:\WINDOWS\System32\EasyAntiCheat.exe --> C:\WINDOWS\System32\EasyAntiCheat.exe [?]
S3 embeddedmode;Embedded Mode;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 EntAppSvc;Enterprise App Management Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
S3 FrameServer;Windows Camera Frame Server;C:\WINDOWS\System32\svchost.exe -k Camera [2016-7-16 44496]
S3 genericusbfn;Generic USB Function Class;C:\WINDOWS\System32\drivers\genericusbfn.sys [2016-7-16 20480]
S3 hidinterrupt;Common Driver for HID Buttons implemented with interrupts;C:\WINDOWS\System32\drivers\hidinterrupt.sys [2016-7-16 50016]
S3 HvHost;HV Host Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 iagpio;Intel Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iagpio.sys [2016-7-16 33280]
S3 iai2c;Intel(R) Serial IO I2C Host Controller;C:\WINDOWS\System32\drivers\iai2c.sys [2016-7-16 81408]
S3 iaLPSS2i_GPIO2;Intel(R) Serial IO GPIO Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-7-16 64512]
S3 iaLPSS2i_I2C;Intel(R) Serial IO I2C Driver v2;C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2016-7-16 176384]
S3 iaLPSSi_GPIO;Intel(R) Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [2016-7-16 38128]
S3 iaLPSSi_I2C;Intel(R) Serial IO I2C Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [2016-7-16 113152]
S3 ibbus;Mellanox InfiniBand Bus/AL (Filter Driver);C:\WINDOWS\System32\drivers\ibbus.sys [2016-7-16 526176]
S3 icssvc;Windows Mobile Hotspot Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
S3 IndirectKmd;Indirect Displays Kernel-Mode Driver;C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-7-16 35840]
S3 LSI_SAS2i;LSI_SAS2i;C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2016-7-16 105824]
S3 LSI_SAS3i;LSI_SAS3i;C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2016-7-16 101216]
S3 megasas2i;megasas2i;C:\WINDOWS\System32\drivers\MegaSas2i.sys [2016-10-12 64352]
S3 MessagingService_53549;MessagingService_53549;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
S3 mlx4_bus;Mellanox ConnectX Bus Enumerator;C:\WINDOWS\System32\drivers\mlx4_bus.sys [2016-7-16 842584]
S3 ndfltr;NetworkDirect Service;C:\WINDOWS\System32\drivers\ndfltr.sys [2016-7-16 108896]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library;C:\WINDOWS\System32\drivers\NetAdapterCx.sys [2016-7-16 90624]
S3 NetSetupSvc;Network Setup Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 NgcCtnrSvc;Microsoft Passport Container;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 44496]
S3 NgcSvc;Microsoft Passport;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\WINDOWS\System32\drivers\nusb3hub.sys [2012-3-2 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\WINDOWS\System32\drivers\nusb3xhc.sys [2012-3-2 180736]
S3 NvContainerNetworkService;NVIDIA NetworkService Container;C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-9-22 455616]
S3 NvStreamKms;NVIDIA KMS;C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-10-11 27584]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;C:\WINDOWS\System32\drivers\nvstusb.sys [2013-5-18 449384]
S3 percsas2i;percsas2i;C:\WINDOWS\System32\drivers\percsas2i.sys [2016-7-16 58720]
S3 percsas3i;percsas3i;C:\WINDOWS\System32\drivers\percsas3i.sys [2016-7-16 61792]
S3 PhoneSvc;Phone Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
S3 ReFSv1;ReFSv1;C:\WINDOWS\System32\drivers\refsv1.sys [2016-7-16 928608]
S3 RetailDemo;Retail Demo Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 scmbus;Microsoft Storage Class Memory Bus Driver;C:\WINDOWS\System32\drivers\scmbus.sys [2016-7-16 88416]
S3 scmdisk0101;Microsoft NVDIMM-N disk driver;C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-7-16 123904]
S3 ScreamBAudioSvc;ScreamBee Audio;C:\WINDOWS\System32\drivers\ScreamingBAudio64.sys [2014-2-7 38992]
S3 SensorDataService;Sensor Data Service;C:\WINDOWS\System32\SensorDataService.exe [2016-9-15 1312768]
S3 SensorService;Sensor Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 SerCx2;Serial UART Support Library;C:\WINDOWS\System32\drivers\SerCx2.sys [2016-7-16 151904]
S3 smphost;Microsoft Storage Spaces SMP;C:\WINDOWS\System32\svchost.exe -k smphost [2016-7-16 44496]
S3 SmsRouter;Microsoft Windows SMS Router Service.;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 stornvme;Microsoft Standard NVM Express Driver;C:\WINDOWS\System32\drivers\stornvme.sys [2016-9-30 81760]
S3 storufs;Microsoft Universal Flash Storage (UFS) Driver;C:\WINDOWS\System32\drivers\storufs.sys [2016-7-16 32096]
S3 tap0901cn;Speedify Virtual Adapter;C:\WINDOWS\System32\drivers\tap0901cn.sys [2014-12-6 39616]
S3 TieringEngineService;Storage Tiers Management;C:\WINDOWS\System32\TieringEngineService.exe [2016-7-16 287744]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmCx.sys [2016-7-16 95744]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmTcpciCx.sys [2016-7-16 108544]
S3 UcmUcsi;USB Connector Manager UCSI Client;C:\WINDOWS\System32\drivers\UcmUcsi.sys [2016-7-16 50688]
S3 UdeCx;USB Device Emulation Support Library;C:\WINDOWS\System32\drivers\Udecx.sys [2016-7-16 45568]
S3 UEFI;Microsoft UEFI Driver;C:\WINDOWS\System32\drivers\uefi.sys [2016-7-16 28512]
S3 Ufx01000;USB Function Class Extension;C:\WINDOWS\System32\drivers\ufx01000.sys [2016-7-16 263008]
S3 UfxChipidea;USB Chipidea Controller;C:\WINDOWS\System32\drivers\UfxChipidea.sys [2016-7-16 96608]
S3 ufxsynopsys;USB Synopsys Controller;C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2016-7-16 137056]
S3 UrsChipidea;Chipidea USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urschipidea.sys [2016-7-16 28512]
S3 UrsCx01000;USB Role-Switch Support Library;C:\WINDOWS\System32\drivers\urscx01000.sys [2016-7-16 57696]
S3 UrsSynopsys;Synopsys USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urssynopsys.sys [2016-7-16 27488]
S3 UsoSvc;Update Orchestrator Service for Windows Update;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 VBAudioVACMME;@oem43.inf,%DeviceName% (WDM);VB-Audio Virtual Cable (WDM);C:\WINDOWS\System32\drivers\vbaudio_cable64_win7.sys [2014-10-11 41192]
S3 VBAudioVMAUXVAIOMME;@oem185.inf,%DeviceName% (WDM);VB-Audio VoiceMeeter AUX VAIO (WDM);C:\WINDOWS\System32\drivers\vbaudio_vmauxvaio64_win7.sys [2015-9-5 41192]
S3 VBAudioVMVAIOMME;@oem184.inf,%DeviceName% (WDM);VB-Audio VoiceMeeter VAIO (WDM);C:\WINDOWS\System32\drivers\vbaudio_vmvaio64_win7.sys [2015-9-5 41192]
S3 vhf;Virtual HID Framework (VHF) Driver;C:\WINDOWS\System32\drivers\vhf.sys [2016-7-16 32256]
S3 vmgid;Microsoft Hyper-V Guest Infrastructure Driver;C:\WINDOWS\System32\drivers\vmgid.sys [2016-7-16 10240]
S3 vmicguestinterface;Hyper-V Guest Service Interface;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 vmicvmsession;Hyper-V PowerShell Direct Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 44496]
S3 w3logsvc;W3C Logging Service;C:\WINDOWS\System32\svchost.exe -k apphost [2016-7-16 44496]
S3 WalletService;WalletService;C:\WINDOWS\System32\svchost.exe -k appmodel [2016-7-16 44496]
S3 wdiwifi;WDI Driver Framework;C:\WINDOWS\System32\drivers\WdiWiFi.sys [2016-9-30 719360]
S3 WdNisDrv;Windows Defender Network Inspection System Driver;C:\WINDOWS\System32\drivers\WdNisDrv.sys [2016-7-16 123232]
S3 WdNisSvc;Windows Defender Network Inspection Service;C:\Program Files\Windows Defender\NisSrv.exe [2016-7-16 347328]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;C:\WINDOWS\System32\svchost.exe -k WepHostSvcGroup [2016-7-16 44496]
S3 WinMad;WinMad Service;C:\WINDOWS\System32\drivers\winmad.sys [2016-7-16 32096]
S3 WinVerbs;WinVerbs Service;C:\WINDOWS\System32\drivers\winverbs.sys [2016-7-16 64864]
S3 workfolderssvc;Work Folders;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
S3 WpnUserService_53549;Windows Push Notifications User Service_53549;C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup [2016-7-16 44496]
S3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\drivers\WUDFRd.sys [2016-7-16 216064]
S3 XblAuthManager;Xbox Live Auth Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 XblGameSave;Xbox Live Game Save;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 xboxgip;Xbox Game Input Protocol Driver;C:\WINDOWS\System32\drivers\xboxgip.sys [2016-7-16 258560]
S3 XboxNetApiSvc;Xbox Live Networking Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S3 xinputhid;XINPUT HID Filter Driver;C:\WINDOWS\System32\drivers\xinputhid.sys [2016-9-1 43520]
S4 shpamsvc;Shared PC Account Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2016-7-16 44496]
S4 tzautoupdate;Auto Time Zone Updater;C:\WINDOWS\System32\svchost.exe -k LocalService [2016-7-16 44496]
.
=============== File Associations ===============
.
ShellExec: SC2Editor.exe: open="C:/Program Files (x86)/StarCraft II/Support/SC2Editor.exe" "%1"
ShellExec: SC2Switcher.exe: open="C:/Program Files (x86)/StarCraft II/Support/SC2Switcher.exe" "%1"
.
=============== Created Last 30 ================
.
2016-10-18 08:21:39 -------- d-----w- C:\extensions
2016-10-12 01:56:40 6183104 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerInstaller.exe
2016-10-11 22:45:07 73216 ----a-w- C:\WINDOWS\System32\Windows.StateRepositoryBroker.dll
2016-10-11 22:45:07 4136960 ----a-w- C:\WINDOWS\System32\Windows.StateRepository.dll
2016-10-11 22:45:07 122880 ----a-w- C:\WINDOWS\System32\Windows.StateRepositoryClient.dll
2016-10-11 22:45:03 1656832 ----a-w- C:\WINDOWS\System32\GdiPlus.dll
2016-10-11 22:45:00 775168 ----a-w- C:\WINDOWS\System32\GamePanel.exe
2016-10-11 22:45:00 503808 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\Microsoft.Ink.dll
2016-10-10 06:22:59 -------- d-----w- C:\Users\Andrew Hoyland\AppData\Local\Deployment
2016-09-30 23:36:16 229048 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
2016-09-30 08:12:45 -------- d-----w- C:\Users\Andrew Hoyland\AppData\Local\SLAM
2016-09-30 02:34:59 813568 ----a-w- C:\Program Files (x86)\Common Files\System\Ole DB\oledb32.dll
2016-09-30 02:33:59 988512 ----a-w- C:\WINDOWS\System32\hvax64.exe
2016-09-22 09:46:43 134712 ----a-w- C:\WINDOWS\SysWow64\nvStreaming.exe
2016-09-22 09:46:27 261920 ----a-w- C:\WINDOWS\System32\vulkan-1.dll
2016-09-22 09:46:27 125216 ----a-w- C:\WINDOWS\System32\vulkaninfo.exe
2016-09-22 09:46:26 269600 ----a-w- C:\WINDOWS\SysWow64\vulkan-1.dll
2016-09-22 09:46:26 110880 ----a-w- C:\WINDOWS\SysWow64\vulkaninfo.exe
2016-09-22 08:33:59 120256 ----a-w- C:\WINDOWS\System32\NvRtmpStreamer64.dll
2016-09-22 08:33:58 1842624 ----a-w- C:\WINDOWS\System32\nvspcap64.dll
2016-09-22 08:33:58 1755072 ----a-w- C:\WINDOWS\System32\nvspbridge64.dll
2016-09-22 08:33:58 1317312 ----a-w- C:\WINDOWS\SysWow64\nvspbridge.dll
2016-09-22 08:33:57 1444288 ----a-w- C:\WINDOWS\SysWow64\nvspcap.dll
2016-09-22 08:33:20 1951 ----a-w- C:\WINDOWS\NvContainerRecovery.bat
.
==================== Find3M ====================
.
2016-10-19 10:36:32 192216 ----a-w- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
2016-10-19 10:32:24 109272 ----a-w- C:\WINDOWS\System32\drivers\mbamchameleon.sys
2016-10-19 10:11:22 153072 ------w- C:\WINDOWS\System32\drivers\rikvm_9EC60124.sys
2016-10-11 21:47:40 177664 ----a-w- C:\WINDOWS\SysWow64\Windows.Web.Diagnostics.dll
2016-10-11 21:47:28 783360 ----a-w- C:\WINDOWS\SysWow64\TSWorkspace.dll
2016-10-05 10:35:31 279904 ----a-w- C:\WINDOWS\System32\drivers\sdbus.sys
2016-10-05 10:34:30 894088 ----a-w- C:\WINDOWS\System32\winresume.exe
2016-10-05 10:34:29 1051104 ----a-w- C:\WINDOWS\System32\winresume.efi
2016-10-05 10:33:05 128864 ----a-w- C:\WINDOWS\System32\drivers\tm.sys
2016-10-05 10:31:27 2213248 ----a-w- C:\WINDOWS\System32\KernelBase.dll
2016-10-05 10:31:04 1353768 ----a-w- C:\WINDOWS\System32\winload.efi
2016-10-05 10:31:04 1172472 ----a-w- C:\WINDOWS\System32\winload.exe
2016-10-05 10:30:04 7812448 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2016-10-05 10:22:30 1181536 ----a-w- C:\WINDOWS\System32\drivers\ndis.sys
2016-10-05 10:17:31 1322848 ----a-w- C:\WINDOWS\System32\wpx.dll
2016-10-05 10:16:12 187232 ----a-w- C:\WINDOWS\System32\drivers\dumpsd.sys
2016-10-05 10:13:51 1859264 ----a-w- C:\WINDOWS\System32\Windows.ApplicationModel.Store.dll
2016-10-05 10:13:34 146784 ----a-w- C:\WINDOWS\System32\CloudExperienceHostCommon.dll
2016-10-05 10:12:49 619368 ----a-w- C:\WINDOWS\System32\drivers\cng.sys
2016-10-05 10:12:25 2446696 ----a-w- C:\WINDOWS\System32\msxml6.dll
2016-10-05 10:12:12 1112928 ----a-w- C:\WINDOWS\System32\AppxPackaging.dll
2016-10-05 10:09:21 4129928 ----a-w- C:\WINDOWS\System32\mfcore.dll
2016-10-05 10:09:12 244816 ----a-w- C:\WINDOWS\System32\mfps.dll
2016-10-05 10:09:12 1071728 ----a-w- C:\WINDOWS\System32\mfnetcore.dll
2016-10-05 10:09:07 64352 ----a-w- C:\WINDOWS\System32\drivers\MegaSas2i.sys
2016-10-05 10:08:36 241504 ----a-w- C:\WINDOWS\System32\CloudExperienceHost.dll
2016-10-05 10:04:52 628032 ----a-w- C:\WINDOWS\System32\fontdrvhost.exe
2016-10-05 10:04:02 2537824 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2016-10-05 10:03:25 1705976 ----a-w- C:\WINDOWS\SysWow64\KernelBase.dll
2016-10-05 09:51:04 1430720 ----a-w- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.dll
2016-10-05 09:50:41 116576 ----a-w- C:\WINDOWS\SysWow64\CloudExperienceHostCommon.dll
2016-10-05 09:49:21 1980768 ----a-w- C:\WINDOWS\SysWow64\msxml6.dll
2016-10-05 09:48:51 1022304 ----a-w- C:\WINDOWS\SysWow64\AppxPackaging.dll
2016-10-05 09:46:27 3892352 ----a-w- C:\WINDOWS\SysWow64\mfcore.dll
2016-10-05 09:46:20 1360456 ----a-w- C:\WINDOWS\SysWow64\mfnetsrc.dll
2016-10-05 09:46:15 980824 ----a-w- C:\WINDOWS\SysWow64\mfnetcore.dll
2016-10-05 09:44:01 22568960 ----a-w- C:\WINDOWS\System32\edgehtml.dll
2016-10-05 09:41:58 545944 ----a-w- C:\WINDOWS\SysWow64\fontdrvhost.exe
2016-10-05 09:38:50 584192 ----a-w- C:\WINDOWS\System32\UIRibbonRes.dll
2016-10-05 09:38:10 237568 ----a-w- C:\WINDOWS\System32\Windows.Web.Diagnostics.dll
2016-10-05 09:36:20 113664 ----a-w- C:\WINDOWS\System32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-05 09:35:56 101888 ----a-w- C:\WINDOWS\System32\UserDeviceRegistration.Ngc.dll
2016-10-05 09:35:55 196096 ----a-w- C:\WINDOWS\System32\UserDeviceRegistration.dll
2016-10-05 09:35:28 327680 ----a-w- C:\WINDOWS\System32\wc_storage.dll
2016-10-05 09:35:26 352768 ----a-w- C:\WINDOWS\System32\cloudAP.dll
2016-10-05 09:34:11 144896 ----a-w- C:\WINDOWS\System32\drivers\dfsc.sys
2016-10-05 09:34:07 463360 ----a-w- C:\WINDOWS\System32\daxexec.dll
2016-10-05 09:33:53 296960 ----a-w- C:\WINDOWS\System32\mfsensorgroup.dll
2016-10-05 09:33:50 157696 ----a-w- C:\WINDOWS\System32\credprovs.dll
2016-10-05 09:33:18 651264 ----a-w- C:\WINDOWS\System32\Windows.Devices.AllJoyn.dll
2016-10-05 09:33:11 268800 ----a-w- C:\WINDOWS\System32\UserMgrProxy.dll
2016-10-05 09:32:52 223744 ----a-w- C:\WINDOWS\System32\Windows.Networking.HostName.dll
2016-10-05 09:32:27 379904 ----a-w- C:\WINDOWS\System32\apprepsync.dll
2016-10-05 09:32:19 590336 ----a-w- C:\WINDOWS\System32\efswrt.dll
2016-10-05 09:32:09 146432 ----a-w- C:\WINDOWS\System32\AuthBroker.dll
2016-10-05 09:31:59 837632 ----a-w- C:\WINDOWS\System32\wbiosrvc.dll
2016-10-05 09:31:53 425472 ----a-w- C:\WINDOWS\System32\bcdedit.exe
2016-10-05 09:31:50 561664 ----a-w- C:\WINDOWS\System32\Windows.ApplicationModel.Wallet.dll
2016-10-05 09:31:41 176128 ----a-w- C:\WINDOWS\System32\apprepapi.dll
2016-10-05 09:31:29 58880 ----a-w- C:\WINDOWS\SysWow64\ConfigureExpandedStorage.dll
2016-10-05 09:31:26 480768 ----a-w- C:\WINDOWS\System32\dsreg.dll
2016-10-05 09:31:11 748544 ----a-w- C:\WINDOWS\System32\ChatApis.dll
2016-10-05 09:30:16 396800 ----a-w- C:\WINDOWS\System32\ncsi.dll
2016-10-05 09:29:58 956416 ----a-w- C:\WINDOWS\System32\AppXDeploymentExtensions.desktop.dll
2016-10-05 09:29:27 1145856 ----a-w- C:\WINDOWS\System32\EmailApis.dll
2016-10-05 09:29:19 368640 ----a-w- C:\WINDOWS\System32\nlasvc.dll
2016-10-05 09:29:14 6285312 ----a-w- C:\WINDOWS\System32\Windows.Media.dll
2016-10-05 09:29:12 9129984 ----a-w- C:\WINDOWS\System32\twinui.dll
2016-10-05 09:28:35 584192 ----a-w- C:\WINDOWS\SysWow64\UIRibbonRes.dll
2016-10-05 09:28:30 406016 ----a-w- C:\WINDOWS\System32\AppXDeploymentClient.dll
2016-10-05 09:28:24 156672 ----a-w- C:\WINDOWS\SysWow64\UserDeviceRegistration.dll
2016-10-05 09:28:20 3059200 ----a-w- C:\WINDOWS\System32\msi.dll
2016-10-05 09:28:06 123904 ----a-w- C:\WINDOWS\SysWow64\Windows.Networking.HostName.dll
2016-10-05 09:27:14 94208 ----a-w- C:\WINDOWS\SysWow64\Windows.StateRepositoryClient.dll
2016-10-05 09:27:13 87040 ----a-w- C:\WINDOWS\SysWow64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-05 09:27:05 945664 ----a-w- C:\WINDOWS\System32\WpcWebFilter.dll
2016-10-05 09:26:58 327680 ----a-w- C:\WINDOWS\SysWow64\daxexec.dll
2016-10-05 09:26:48 137216 ----a-w- C:\WINDOWS\SysWow64\credprovs.dll
2016-10-05 09:26:46 620544 ----a-w- C:\WINDOWS\System32\wbem\MDMSettingsProv.dll
2016-10-05 09:26:34 88576 ----a-w- C:\WINDOWS\SysWow64\UserDeviceRegistration.Ngc.dll
2016-10-05 09:26:33 590848 ----a-w- C:\WINDOWS\System32\vbscript.dll
2016-10-05 09:26:09 184320 ----a-w- C:\WINDOWS\SysWow64\UserMgrProxy.dll
2016-10-05 09:26:06 182784 ----a-w- C:\WINDOWS\SysWow64\mfsensorgroup.dll
2016-10-05 09:25:56 1589248 ----a-w- C:\WINDOWS\System32\msdtctm.dll
2016-10-05 09:25:36 299520 ----a-w- C:\WINDOWS\SysWow64\UserDataAccountApis.dll
2016-10-05 09:25:14 117760 ----a-w- C:\WINDOWS\SysWow64\AuthBroker.dll
2016-10-05 09:25:08 822784 ----a-w- C:\WINDOWS\SysWow64\Chakradiag.dll
2016-10-05 09:25:04 404992 ----a-w- C:\WINDOWS\SysWow64\dsreg.dll
2016-10-05 09:24:41 99328 ----a-w- C:\WINDOWS\System32\adsmsext.dll
2016-10-05 09:24:09 483840 ----a-w- C:\WINDOWS\SysWow64\Windows.Devices.AllJoyn.dll
2016-10-05 09:23:45 426496 ----a-w- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Wallet.dll
2016-10-05 09:23:38 187904 ----a-w- C:\WINDOWS\System32\dialclient.dll
2016-10-05 09:23:27 284672 ----a-w- C:\WINDOWS\SysWow64\apprepsync.dll
2016-10-05 09:23:27 1908224 ----a-w- C:\WINDOWS\System32\AzureSettingSyncProvider.dll
2016-10-05 09:23:14 125952 ----a-w- C:\WINDOWS\SysWow64\apprepapi.dll
2016-10-05 09:23:05 431616 ----a-w- C:\WINDOWS\SysWow64\efswrt.dll
2016-10-05 09:22:55 7654912 ----a-w- C:\WINDOWS\System32\mos.dll
2016-10-05 09:22:16 73216 ----a-w- C:\WINDOWS\System32\offreg.dll
2016-10-05 09:22:08 4749312 ----a-w- C:\WINDOWS\System32\SettingsHandlers_nt.dll
2016-10-05 09:21:45 8075264 ----a-w- C:\WINDOWS\System32\mstscax.dll
2011-12-20 23:32:52 81608 -csha-w- C:\WINDOWS\Panther\Rollback\Boot\Info.exe
.
============= FINISH: 22:30:42.32 ===============

Attached Files
File Type: txt attach.txt (20.0 KB)

Viewing all articles
Browse latest Browse all 2798

Trending Articles