• Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Solved Friends Computer Needs a Checkup

Status
Not open for further replies.
20:21:29.0651 0x10fc TDSS rootkit removing tool 3.1.0.15 Apr 18 2017 11:34:02

20:21:31.0968 0x10fc ============================================================
20:21:31.0968 0x10fc Current date / time: 2017/04/19 20:21:31.0968
20:21:31.0968 0x10fc SystemInfo:
20:21:31.0968 0x10fc
20:21:31.0968 0x10fc OS Version: 6.1.7601 ServicePack: 1.0
20:21:31.0968 0x10fc Product type: Workstation
20:21:31.0968 0x10fc ComputerName: MITCH-PC
20:21:31.0969 0x10fc UserName: Mitch
20:21:31.0969 0x10fc Windows directory: C:\windows
20:21:31.0969 0x10fc System windows directory: C:\windows
20:21:31.0969 0x10fc Running under WOW64
20:21:31.0969 0x10fc Processor architecture: Intel x64
20:21:31.0969 0x10fc Number of processors: 4
20:21:31.0969 0x10fc Page size: 0x1000
20:21:31.0969 0x10fc Boot type: Normal boot
20:21:31.0969 0x10fc CodeIntegrityOptions = 0x00000003
20:21:31.0969 0x10fc ============================================================
20:21:33.0158 0x10fc KLMD registered as C:\windows\system32\drivers\12245035.sys
20:21:33.0158 0x10fc KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 7601.17835, osProperties = 0x1
20:21:33.0867 0x10fc System UUID: {4AC945B0-CE72-7664-3072-5B55CC6AF9F4}
20:21:34.0413 0x10fc Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:21:34.0416 0x10fc ============================================================
20:21:34.0416 0x10fc \Device\Harddisk0\DR0:
20:21:34.0416 0x10fc MBR partitions:
20:21:34.0417 0x10fc \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x3838A000
20:21:34.0417 0x10fc ============================================================
20:21:34.0450 0x10fc C: <-> \Device\Harddisk0\DR0\Partition1
20:21:34.0450 0x10fc ============================================================
20:21:34.0450 0x10fc Initialize success
20:21:34.0450 0x10fc ============================================================
20:21:43.0318 0x08e4 ============================================================
20:21:43.0318 0x08e4 Scan started
20:21:43.0318 0x08e4 Mode: Manual; SigCheck; TDLFS;
20:21:43.0318 0x08e4 ============================================================
20:21:43.0318 0x08e4 KSN ping started
20:21:46.0146 0x08e4 KSN ping finished: true
20:21:49.0475 0x08e4 ================ Scan system memory ========================
20:21:49.0475 0x08e4 System memory - ok
20:21:49.0475 0x08e4 ================ Scan services =============================
20:21:49.0643 0x08e4 [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci C:\windows\system32\drivers\1394ohci.sys
20:21:49.0757 0x08e4 1394ohci - ok
20:21:49.0809 0x08e4 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI C:\windows\system32\drivers\ACPI.sys
20:21:49.0845 0x08e4 ACPI - ok
20:21:49.0874 0x08e4 [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys
20:21:49.0908 0x08e4 AcpiPmi - ok
20:21:50.0032 0x08e4 [ 368290D0A612D62DA6F3D798B1BB8FE7, D573BF8543F37BC51B88A2473EDFD28AFBCCC446E8CADD54A90FA48D8739D222 ] AdobeFlashPlayerUpdateSvc C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
20:21:50.0049 0x08e4 AdobeFlashPlayerUpdateSvc - ok
20:21:50.0130 0x08e4 [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx C:\windows\system32\drivers\adp94xx.sys
20:21:50.0163 0x08e4 adp94xx - ok
20:21:50.0204 0x08e4 [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci C:\windows\system32\drivers\adpahci.sys
20:21:50.0232 0x08e4 adpahci - ok
20:21:50.0279 0x08e4 [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320 C:\windows\system32\drivers\adpu320.sys
20:21:50.0301 0x08e4 adpu320 - ok
20:21:50.0327 0x08e4 [ 4B78B431F225FD8624C5655CB1DE7B61, 198A5AF2125C7C41F531A652D200C083A55A97DC541E3C0B5B253C7329949156 ] AeLookupSvc C:\windows\System32\aelupsvc.dll
20:21:50.0380 0x08e4 AeLookupSvc - ok
20:21:50.0444 0x08e4 [ 1C7857B62DE5994A75B054A9FD4C3825, 83F963D7E636532B1AD30B1E727EC429317CA540F6EB3BB268FCC0B163B67767 ] AFD C:\windows\system32\drivers\afd.sys
20:21:50.0483 0x08e4 AFD - ok
20:21:50.0525 0x08e4 [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440 C:\windows\system32\drivers\agp440.sys
20:21:50.0542 0x08e4 agp440 - ok
20:21:50.0576 0x08e4 [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG C:\windows\System32\alg.exe
20:21:50.0613 0x08e4 ALG - ok
20:21:50.0651 0x08e4 [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide C:\windows\system32\drivers\aliide.sys
20:21:50.0667 0x08e4 aliide - ok
20:21:50.0679 0x08e4 [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide C:\windows\system32\drivers\amdide.sys
20:21:50.0695 0x08e4 amdide - ok
20:21:50.0731 0x08e4 [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8 C:\windows\system32\drivers\amdk8.sys
20:21:50.0751 0x08e4 AmdK8 - ok
20:21:50.0767 0x08e4 [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM C:\windows\system32\drivers\amdppm.sys
20:21:50.0801 0x08e4 AmdPPM - ok
20:21:50.0839 0x08e4 [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata C:\windows\system32\drivers\amdsata.sys
20:21:50.0858 0x08e4 amdsata - ok
20:21:50.0885 0x08e4 [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs C:\windows\system32\drivers\amdsbs.sys
20:21:50.0908 0x08e4 amdsbs - ok
20:21:50.0930 0x08e4 [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata C:\windows\system32\drivers\amdxata.sys
20:21:50.0946 0x08e4 amdxata - ok
20:21:50.0981 0x08e4 [ 89A69C3F2F319B43379399547526D952, 8ABDB4B8E106F96EBBA0D4D04C4F432296516E107E7BA5644ED2E50CF9BB491A ] AppID C:\windows\system32\drivers\appid.sys
20:21:51.0042 0x08e4 AppID - ok
20:21:51.0076 0x08e4 [ 0BC381A15355A3982216F7172F545DE1, C33AF13CB218F7BF52E967452573DF2ADD20A95C6BF99229794FEF07C4BBE725 ] AppIDSvc C:\windows\System32\appidsvc.dll
20:21:51.0106 0x08e4 AppIDSvc - ok
20:21:51.0121 0x08e4 [ 3977D4A871CA0D4F2ED1E7DB46829731, 2AF1C3225994769C3FD25CD7E9603964B035576F25B0B6D91545566E0722FFAA ] Appinfo C:\windows\System32\appinfo.dll
20:21:51.0151 0x08e4 Appinfo - ok
20:21:51.0191 0x08e4 [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc C:\windows\system32\drivers\arc.sys
20:21:51.0209 0x08e4 arc - ok
20:21:51.0238 0x08e4 [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas C:\windows\system32\drivers\arcsas.sys
20:21:51.0263 0x08e4 arcsas - ok
20:21:51.0297 0x08e4 [ A629E4799D4CD6361D1B5D573EA5C2CD, 0D62557BA9C081A3304C898FAADD596ED33271D266291917E1CCBA6A0D52F901 ] aswHwid C:\windows\system32\drivers\aswHwid.sys
20:21:51.0343 0x08e4 aswHwid - ok
20:21:51.0441 0x08e4 [ 97F952A9050CAD88681F5F0F46B8D5A5, 5B939B906868EB4EF9E54E9769B84AA87B57EEB3883F9FC45067A354315C9A89 ] aswKbd C:\windows\system32\drivers\aswKbd.sys
20:21:51.0463 0x08e4 aswKbd - ok
20:21:51.0497 0x08e4 [ 9C6C17C495E960E52EDE5D038EE92AE1, C056799A124C7473E871D73E3661D58B2EA01EE6F3614AEDB239463D0FBB9841 ] aswMonFlt C:\windows\system32\drivers\aswMonFlt.sys
20:21:51.0527 0x08e4 aswMonFlt - ok
20:21:51.0548 0x08e4 [ 8F492911129B1B32818BF894DC0C2C73, 1F6F2019EB3B3B20636F661A4692079FCAA521C626AF6A731D5D493B415719A7 ] aswRdr C:\windows\system32\drivers\aswRdr2.sys
20:21:51.0573 0x08e4 aswRdr - ok
20:21:51.0605 0x08e4 [ 4ABDD84A67378E866BC15DDC9916BA71, 7F67252BE1B9979507F16C8B48D6B2D103B80C4B0765ED3E495DE48E5250EF63 ] aswRvrt C:\windows\system32\drivers\aswRvrt.sys
20:21:51.0623 0x08e4 aswRvrt - ok
20:21:51.0694 0x08e4 [ 409CDD1400B404F655EEC1B5850FD3BE, 2D8A141B18BA155632CE110343AC7A8AB790FB76781C7E757157D9B195CCD5BA ] aswSnx C:\windows\system32\drivers\aswSnx.sys
20:21:51.0752 0x08e4 aswSnx - ok
20:21:51.0823 0x08e4 [ CDB1BE967AFF65D8395B6DF2EA8CBCCF, B72DEDDE020AC0FA4DC382B7B1C5427B8D63E83DB34BB747DC5008AFB9698E57 ] aswSP C:\windows\system32\drivers\aswSP.sys
20:21:51.0855 0x08e4 aswSP - ok
20:21:51.0877 0x08e4 [ F6B5E463A0BB934C26FB319EDC726F65, 8B4E94181E7C2B479F7F675C221419B42C55C74F02A0DD8FFD9643A5A19AB944 ] aswStm C:\windows\system32\drivers\aswStm.sys
20:21:51.0890 0x08e4 aswStm - ok
20:21:51.0921 0x08e4 [ FE0EE5CA72BC0D41DCAAFCA70B78274B, 1D81CAF4EBAB4A9FE542F9C27D67617530295B889E3E2B2C72C669BA55078364 ] aswVmm C:\windows\system32\drivers\aswVmm.sys
20:21:51.0947 0x08e4 aswVmm - ok
20:21:51.0987 0x08e4 [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
20:21:52.0038 0x08e4 AsyncMac - ok
20:21:52.0066 0x08e4 [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi C:\windows\system32\drivers\atapi.sys
20:21:52.0082 0x08e4 atapi - ok
20:21:52.0170 0x08e4 [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
20:21:52.0217 0x08e4 AudioEndpointBuilder - ok
20:21:52.0234 0x08e4 [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioSrv C:\windows\System32\Audiosrv.dll
20:21:52.0278 0x08e4 AudioSrv - ok
20:21:52.0363 0x08e4 [ 8EF7C84BB20329D6DCAC09CF6B19345A, 98F2F312F273C52653DC72F8A69ACBD79F588FF1B53CC7DFA85C26B6F7EF620B ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
20:21:52.0377 0x08e4 avast! Antivirus - ok
20:21:52.0462 0x08e4 [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV C:\windows\System32\AxInstSV.dll
20:21:52.0505 0x08e4 AxInstSV - ok
20:21:52.0569 0x08e4 [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv C:\windows\system32\drivers\bxvbda.sys
20:21:52.0631 0x08e4 b06bdrv - ok
20:21:52.0684 0x08e4 [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a C:\windows\system32\DRIVERS\b57nd60a.sys
20:21:52.0738 0x08e4 b57nd60a - ok
20:21:52.0782 0x08e4 [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC C:\windows\System32\bdesvc.dll
20:21:52.0816 0x08e4 BDESVC - ok
20:21:52.0867 0x08e4 [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep C:\windows\system32\drivers\Beep.sys
20:21:52.0942 0x08e4 Beep - ok
20:21:53.0022 0x08e4 [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE C:\windows\System32\bfe.dll
20:21:53.0090 0x08e4 BFE - ok
20:21:53.0141 0x08e4 [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS C:\windows\System32\qmgr.dll
20:21:53.0193 0x08e4 BITS - ok
20:21:53.0220 0x08e4 [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive C:\windows\system32\DRIVERS\blbdrive.sys
20:21:53.0239 0x08e4 blbdrive - ok
20:21:53.0275 0x08e4 [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser C:\windows\system32\DRIVERS\bowser.sys
20:21:53.0320 0x08e4 bowser - ok
20:21:53.0372 0x08e4 [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo C:\windows\system32\drivers\BrFiltLo.sys
20:21:53.0413 0x08e4 BrFiltLo - ok
20:21:53.0436 0x08e4 [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp C:\windows\system32\drivers\BrFiltUp.sys
20:21:53.0461 0x08e4 BrFiltUp - ok
20:21:53.0541 0x08e4 [ 8EF0D5C41EC907751B8429162B1239ED, 9CC25F1F93FACA6F6CE23F78EB58590C39A2E3C8A3ACDF400E8A9DE0757EADAE ] Browser C:\windows\System32\browser.dll
20:21:53.0611 0x08e4 Browser - ok
20:21:53.0669 0x08e4 [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid C:\windows\System32\Drivers\Brserid.sys
20:21:53.0731 0x08e4 Brserid - ok
20:21:53.0763 0x08e4 [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys
20:21:53.0804 0x08e4 BrSerWdm - ok
20:21:53.0841 0x08e4 [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys
20:21:53.0886 0x08e4 BrUsbMdm - ok
20:21:53.0901 0x08e4 [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys
20:21:53.0920 0x08e4 BrUsbSer - ok
20:21:53.0948 0x08e4 [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM C:\windows\system32\drivers\bthmodem.sys
20:21:53.0994 0x08e4 BTHMODEM - ok
20:21:54.0052 0x08e4 [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv C:\windows\system32\bthserv.dll
20:21:54.0108 0x08e4 bthserv - ok
20:21:54.0156 0x08e4 [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
20:21:54.0243 0x08e4 cdfs - ok
20:21:54.0273 0x08e4 [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom C:\windows\system32\DRIVERS\cdrom.sys
20:21:54.0326 0x08e4 cdrom - ok
20:21:54.0358 0x08e4 [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc C:\windows\System32\certprop.dll
20:21:54.0416 0x08e4 CertPropSvc - ok
20:21:54.0460 0x08e4 [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass C:\windows\system32\drivers\circlass.sys
20:21:54.0486 0x08e4 circlass - ok
20:21:54.0531 0x08e4 [ FE1EC06F2253F691FE36217C592A0206, B9F122DB5E665ECDF29A5CB8BB6B531236F31A54A95769D6C5C1924C87FE70CE ] CLFS C:\windows\system32\CLFS.sys
20:21:54.0558 0x08e4 CLFS - ok
20:21:54.0616 0x08e4 [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:21:54.0627 0x08e4 clr_optimization_v2.0.50727_32 - ok
20:21:54.0680 0x08e4 [ D1CEEA2B47CB998321C579651CE3E4F8, 654013B8FD229A50017B08DEC6CA19C7DDA8CE0771260E057A92625201D539B1 ] clr_optimization_v2.0.50727_64 C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
20:21:54.0691 0x08e4 clr_optimization_v2.0.50727_64 - ok
20:21:54.0789 0x08e4 [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:21:54.0801 0x08e4 clr_optimization_v4.0.30319_32 - ok
20:21:54.0876 0x08e4 [ C6F9AF94DCD58122A4D7E89DB6BED29D, CB0E5AE60EC76323585FB86D89E8DB7ADB5EDF6EA3D0B27E9ECE75B8CAA8BFDE ] clr_optimization_v4.0.30319_64 C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
20:21:54.0887 0x08e4 clr_optimization_v4.0.30319_64 - ok
20:21:54.0906 0x08e4 [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt C:\windows\system32\DRIVERS\CmBatt.sys
20:21:54.0943 0x08e4 CmBatt - ok
20:21:54.0978 0x08e4 [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide C:\windows\system32\drivers\cmdide.sys
20:21:54.0994 0x08e4 cmdide - ok
20:21:55.0043 0x08e4 [ 9AC4F97C2D3E93367E2148EA940CD2CD, 530E089E5CF868AECDB2B5548EBE76E0CA98FC74A72897292AB2485734402E3B ] CNG C:\windows\system32\Drivers\cng.sys
20:21:55.0078 0x08e4 CNG - ok
20:21:55.0165 0x08e4 [ 20506F12AFAD3DB588D007EA9325FBBC, 275ECBD0F668782ACE055AD5CA600A6885CFCDD4943BC52A2EA8339AF71EABAE ] CnxtHdAudService C:\windows\system32\drivers\CHDRT64.sys
20:21:55.0226 0x08e4 CnxtHdAudService - ok
20:21:55.0261 0x08e4 [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt C:\windows\system32\drivers\compbatt.sys
20:21:55.0276 0x08e4 Compbatt - ok
20:21:55.0299 0x08e4 [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus C:\windows\system32\DRIVERS\CompositeBus.sys
20:21:55.0338 0x08e4 CompositeBus - ok
20:21:55.0362 0x08e4 COMSysApp - ok
20:21:55.0378 0x08e4 [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk C:\windows\system32\drivers\crcdisk.sys
20:21:55.0394 0x08e4 crcdisk - ok
20:21:55.0425 0x08e4 [ 4F5414602E2544A4554D95517948B705, 50121AD32ACF73F541DF3B655020F7B610B3E7B5E8C7B39D37D5958F28CB376E ] CryptSvc C:\windows\system32\cryptsvc.dll
20:21:55.0463 0x08e4 CryptSvc - ok
20:21:55.0563 0x08e4 [ 72794D112CBAFF3BC0C29BF7350D4741, 060C207F27306A3464FBCD8B08BDC97E34923ECA349933ECB059848BD08F41ED ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
20:21:55.0590 0x08e4 cvhsvc - ok
20:21:55.0650 0x08e4 [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] DcomLaunch C:\windows\system32\rpcss.dll
20:21:55.0693 0x08e4 DcomLaunch - ok
20:21:55.0741 0x08e4 [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc C:\windows\System32\defragsvc.dll
20:21:55.0791 0x08e4 defragsvc - ok
20:21:55.0829 0x08e4 [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC C:\windows\system32\Drivers\dfsc.sys
20:21:55.0888 0x08e4 DfsC - ok
20:21:55.0957 0x08e4 [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp C:\windows\system32\dhcpcore.dll
20:21:55.0995 0x08e4 Dhcp - ok
20:21:56.0021 0x08e4 [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache C:\windows\system32\drivers\discache.sys
20:21:56.0090 0x08e4 discache - ok
20:21:56.0162 0x08e4 [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk C:\windows\system32\drivers\disk.sys
20:21:56.0180 0x08e4 Disk - ok
20:21:56.0271 0x08e4 [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache C:\windows\System32\dnsrslvr.dll
20:21:56.0333 0x08e4 Dnscache - ok
20:21:56.0380 0x08e4 [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc C:\windows\System32\dot3svc.dll
20:21:56.0432 0x08e4 dot3svc - ok
20:21:56.0461 0x08e4 [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS C:\windows\system32\dps.dll
20:21:56.0548 0x08e4 DPS - ok
20:21:56.0583 0x08e4 [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud C:\windows\system32\drivers\drmkaud.sys
20:21:56.0633 0x08e4 drmkaud - ok
20:21:57.0462 0x08e4 [ F5BEE30450E18E6B83A5012C100616FD, 44D0577D159FC2BDF4EAD1DC2C7FD14925D075225EF97608CAC52DEE405B08FD ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
20:21:57.0504 0x08e4 DXGKrnl - ok
20:21:57.0579 0x08e4 [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost C:\windows\System32\eapsvc.dll
20:21:57.0633 0x08e4 EapHost - ok
20:21:57.0866 0x08e4 [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv C:\windows\system32\drivers\evbda.sys
20:21:58.0040 0x08e4 ebdrv - ok
20:21:58.0071 0x08e4 [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] EFS C:\windows\System32\lsass.exe
20:21:58.0117 0x08e4 EFS - ok
20:21:58.0219 0x08e4 [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr C:\windows\ehome\ehRecvr.exe
20:21:58.0277 0x08e4 ehRecvr - ok
20:21:58.0311 0x08e4 [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched C:\windows\ehome\ehsched.exe
20:21:58.0326 0x08e4 ehSched - ok
20:21:58.0386 0x08e4 [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor C:\windows\system32\drivers\elxstor.sys
20:21:58.0419 0x08e4 elxstor - ok
20:21:58.0428 0x08e4 [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev C:\windows\system32\drivers\errdev.sys
20:21:58.0462 0x08e4 ErrDev - ok
20:21:58.0503 0x08e4 [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem C:\windows\system32\es.dll
20:21:58.0558 0x08e4 EventSystem - ok
20:21:58.0606 0x08e4 [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat C:\windows\system32\drivers\exfat.sys
20:21:58.0649 0x08e4 exfat - ok
20:21:58.0685 0x08e4 [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat C:\windows\system32\drivers\fastfat.sys
20:21:58.0736 0x08e4 fastfat - ok
20:21:58.0804 0x08e4 [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax C:\windows\system32\fxssvc.exe
20:21:58.0835 0x08e4 Fax - ok
20:21:58.0861 0x08e4 [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc C:\windows\system32\drivers\fdc.sys
20:21:58.0896 0x08e4 fdc - ok
20:21:58.0935 0x08e4 [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost C:\windows\system32\fdPHost.dll
20:21:58.0964 0x08e4 fdPHost - ok
20:21:58.0980 0x08e4 [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub C:\windows\system32\fdrespub.dll
20:21:59.0035 0x08e4 FDResPub - ok
20:21:59.0081 0x08e4 [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo C:\windows\system32\drivers\fileinfo.sys
20:21:59.0099 0x08e4 FileInfo - ok
20:21:59.0119 0x08e4 [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace C:\windows\system32\drivers\filetrace.sys
20:21:59.0174 0x08e4 Filetrace - ok
20:21:59.0208 0x08e4 [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk C:\windows\system32\drivers\flpydisk.sys
20:21:59.0227 0x08e4 flpydisk - ok
20:21:59.0246 0x08e4 [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr C:\windows\system32\drivers\fltmgr.sys
20:21:59.0271 0x08e4 FltMgr - ok
20:21:59.0328 0x08e4 [ 5C4CB4086FB83115B153E47ADD961A0C, 0C3AB7D04BEB3A8FDE00B0C86E6FE064B1CEBB3E4DE1A29CD27830806FA300B3 ] FontCache C:\windows\system32\FntCache.dll
20:21:59.0393 0x08e4 FontCache - ok
20:21:59.0451 0x08e4 [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
20:21:59.0460 0x08e4 FontCache3.0.0.0 - ok
20:21:59.0472 0x08e4 [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends C:\windows\system32\drivers\FsDepends.sys
20:21:59.0489 0x08e4 FsDepends - ok
20:21:59.0522 0x08e4 [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
20:21:59.0537 0x08e4 Fs_Rec - ok
20:21:59.0572 0x08e4 [ 1F7B25B858FA27015169FE95E54108ED, 72DD12E924AA7273B3E4BDD2A2C581DECE304C8EF3D44EA79ABB032F3F95DCE5 ] fvevol C:\windows\system32\DRIVERS\fvevol.sys
20:21:59.0598 0x08e4 fvevol - ok
20:21:59.0627 0x08e4 [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx C:\windows\system32\drivers\gagp30kx.sys
20:21:59.0645 0x08e4 gagp30kx - ok
20:21:59.0712 0x08e4 [ C403C5DB49A0F9AAF4F2128EDC0106D8, 3C6948B63278022D8182F773C5FA15784514F76C1546118DDBADBA322B962D12 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
20:21:59.0726 0x08e4 GamesAppService - ok
20:21:59.0776 0x08e4 Giraffic - ok
20:21:59.0832 0x08e4 [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC963E18D47B94D24 ] gpsvc C:\windows\System32\gpsvc.dll
20:21:59.0883 0x08e4 gpsvc - ok
20:21:59.0951 0x08e4 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:21:59.0962 0x08e4 gupdate - ok
20:21:59.0976 0x08e4 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:21:59.0987 0x08e4 gupdatem - ok
20:22:00.0038 0x08e4 [ CC839E8D766CC31A7710C9F38CF3E375, 327D57F18B4A2D1CB06C5682D3364097ECD3CF40C2719AA1F41D0B49A26003E4 ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
20:22:00.0051 0x08e4 gusvc - ok
20:22:00.0107 0x08e4 [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys
20:22:00.0157 0x08e4 hcw85cir - ok
20:22:00.0225 0x08e4 [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
20:22:00.0258 0x08e4 HdAudAddService - ok
20:22:00.0301 0x08e4 [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus C:\windows\system32\DRIVERS\HDAudBus.sys
20:22:00.0357 0x08e4 HDAudBus - ok
20:22:00.0394 0x08e4 [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt C:\windows\system32\drivers\HidBatt.sys
20:22:00.0430 0x08e4 HidBatt - ok
20:22:00.0469 0x08e4 [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth C:\windows\system32\drivers\hidbth.sys
20:22:00.0493 0x08e4 HidBth - ok
20:22:00.0523 0x08e4 [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr C:\windows\system32\drivers\hidir.sys
20:22:00.0545 0x08e4 HidIr - ok
20:22:00.0574 0x08e4 [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv C:\windows\system32\hidserv.dll
20:22:00.0681 0x08e4 hidserv - ok
20:22:00.0724 0x08e4 [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb C:\windows\system32\drivers\hidusb.sys
20:22:00.0763 0x08e4 HidUsb - ok
20:22:00.0787 0x08e4 [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc C:\windows\system32\kmsvc.dll
20:22:00.0851 0x08e4 hkmsvc - ok
20:22:00.0911 0x08e4 [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\windows\system32\ListSvc.dll
20:22:00.0950 0x08e4 HomeGroupListener - ok
20:22:01.0046 0x08e4 [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\windows\system32\provsvc.dll
20:22:01.0096 0x08e4 HomeGroupProvider - ok
20:22:01.0176 0x08e4 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys
20:22:01.0193 0x08e4 HpSAMD - ok
20:22:01.0238 0x08e4 [ 0EA7DE1ACB728DD5A369FD742D6EEE28, 21C489412EB33A12B22290EB701C19BA57006E8702E76F730954F0784DDE9779 ] HTTP C:\windows\system32\drivers\HTTP.sys
20:22:01.0325 0x08e4 HTTP - ok
20:22:01.0378 0x08e4 [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys
20:22:01.0393 0x08e4 hwpolicy - ok
20:22:01.0462 0x08e4 [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt C:\windows\system32\DRIVERS\i8042prt.sys
20:22:01.0484 0x08e4 i8042prt - ok
20:22:01.0524 0x08e4 [ D469B77687E12FE43E344806740B624D, DFDD486FD040813BF4E5DDB504CF9E0BFBF6D4E540DDDA4829F9B675ACF63E89 ] iaStor C:\windows\system32\DRIVERS\iaStor.sys
20:22:01.0551 0x08e4 iaStor - ok
20:22:01.0603 0x08e4 [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV C:\windows\system32\drivers\iaStorV.sys
20:22:01.0633 0x08e4 iaStorV - ok
20:22:01.0707 0x08e4 [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
20:22:01.0729 0x08e4 IDriverT - detected UnsignedFile.Multi.Generic ( 1 )
20:22:04.0482 0x08e4 Detect skipped due to KSN trusted
20:22:04.0482 0x08e4 IDriverT - ok
20:22:04.0601 0x08e4 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD, 2B9512324DBA4A97F6AC34E8067EE08E3B6874CD60F6CB4209AFC22A34D2BE99 ] idsvc C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
20:22:04.0631 0x08e4 idsvc - ok
20:22:05.0682 0x08e4 [ 370C2A8629B30F910F740387795DDC6F, 7D2D69F0BC12E86236014003EEA7479BD0FDE9A469459B6550DC3AED07A02030 ] igfx C:\windows\system32\DRIVERS\igdkmd64.sys
20:22:06.0229 0x08e4 igfx - ok
20:22:06.0305 0x08e4 [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp C:\windows\system32\drivers\iirsp.sys
20:22:06.0325 0x08e4 iirsp - ok
20:22:06.0390 0x08e4 [ FCD84C381E0140AF901E58D48882D26B, 76955FFC230C801E8ED890E32076075F04CD6E5EC79E594FDE6D23797A36B406 ] IKEEXT C:\windows\System32\ikeext.dll
20:22:06.0479 0x08e4 IKEEXT - ok
20:22:06.0537 0x08e4 [ FC727061C0F47C8059E88E05D5C8E381, C7A3782F5D86C7FDE57AA1F2EE81638C5FC3072ACC6E572BA2EC7B3CFF389800 ] IntcDAud C:\windows\system32\DRIVERS\IntcDAud.sys
20:22:06.0557 0x08e4 IntcDAud - ok
20:22:06.0576 0x08e4 [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide C:\windows\system32\drivers\intelide.sys
20:22:06.0593 0x08e4 intelide - ok
20:22:06.0614 0x08e4 [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm C:\windows\system32\DRIVERS\intelppm.sys
20:22:06.0649 0x08e4 intelppm - ok
20:22:06.0697 0x08e4 [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum C:\windows\system32\ipbusenum.dll
20:22:06.0749 0x08e4 IPBusEnum - ok
20:22:06.0786 0x08e4 [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
20:22:06.0827 0x08e4 IpFilterDriver - ok
20:22:06.0873 0x08e4 [ A34A587FFFD45FA649FBA6D03784D257, C9A2BCD4E2A5EB6E320092A3AFD5737ECDCDA0B83EE42314A23C4978F2974767 ] iphlpsvc C:\windows\System32\iphlpsvc.dll
20:22:06.0941 0x08e4 iphlpsvc - ok
20:22:06.0966 0x08e4 [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys
20:22:07.0020 0x08e4 IPMIDRV - ok
20:22:07.0047 0x08e4 [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT C:\windows\system32\drivers\ipnat.sys
20:22:07.0104 0x08e4 IPNAT - ok
20:22:07.0145 0x08e4 [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM C:\windows\system32\drivers\irenum.sys
20:22:07.0166 0x08e4 IRENUM - ok
20:22:07.0184 0x08e4 [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp C:\windows\system32\drivers\isapnp.sys
20:22:07.0200 0x08e4 isapnp - ok
20:22:07.0221 0x08e4 [ D931D7309DEB2317035B07C9F9E6B0BD, 13AD84172ED8C6153F8A98499C01733B74E48464CE07D099508E38D409913ED3 ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys
20:22:07.0246 0x08e4 iScsiPrt - ok
20:22:07.0287 0x08e4 [ CD91D1BD200D9F39682A08E987F0DBE2, 45396B0DD37C7FAAE23F985D5F26C25E944EDA1B9A4248B5CB16A4C4831E713B ] JLTECH0227 C:\windows\system32\Drivers\jl2005c.sys
20:22:07.0305 0x08e4 JLTECH0227 - ok
20:22:07.0323 0x08e4 [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass C:\windows\system32\DRIVERS\kbdclass.sys
20:22:07.0340 0x08e4 kbdclass - ok
20:22:07.0364 0x08e4 [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid C:\windows\system32\drivers\kbdhid.sys
20:22:07.0398 0x08e4 kbdhid - ok
20:22:07.0427 0x08e4 [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] KeyIso C:\windows\system32\lsass.exe
20:22:07.0439 0x08e4 KeyIso - ok
20:22:07.0485 0x08e4 [ 97A7070AEA4C058B6418519E869A63B4, 15345C2D6CA159BD498002974A0BD21CAB611124D85E3320248B47652AEF23C8 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
20:22:07.0503 0x08e4 KSecDD - ok
20:22:07.0518 0x08e4 [ 26C43A7C2862447EC59DEDA188D1DA07, 5363BF87E650FE2010ACA9417D6920FF4ED752256FF47732882E9B2BA1ED154B ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys
20:22:07.0539 0x08e4 KSecPkg - ok
20:22:07.0569 0x08e4 [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk C:\windows\system32\drivers\ksthunk.sys
20:22:07.0620 0x08e4 ksthunk - ok
20:22:07.0670 0x08e4 [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm C:\windows\system32\msdtckrm.dll
20:22:07.0710 0x08e4 KtmRm - ok
20:22:07.0744 0x08e4 [ EBED8B3FF4A823C1A6EEBEED7B29353F, 0942200EEDEDA1FF4E634CDC5182D8EDC9BC9F66E89A5DAB8DF82C3FBB2F0D59 ] L1C C:\windows\system32\DRIVERS\L1C62x64.sys
20:22:07.0760 0x08e4 L1C - ok
20:22:07.0807 0x08e4 [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer C:\windows\system32\srvsvc.dll
20:22:07.0862 0x08e4 LanmanServer - ok
20:22:07.0914 0x08e4 [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\windows\System32\wkssvc.dll
20:22:07.0964 0x08e4 LanmanWorkstation - ok
20:22:08.0028 0x08e4 [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
20:22:08.0064 0x08e4 lltdio - ok
20:22:08.0119 0x08e4 [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc C:\windows\System32\lltdsvc.dll
20:22:08.0182 0x08e4 lltdsvc - ok
20:22:08.0204 0x08e4 [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts C:\windows\System32\lmhsvc.dll
20:22:08.0234 0x08e4 lmhosts - ok
20:22:08.0345 0x08e4 [ 2ED1786B7542CDA261029F6B526EDF44, C6131B65B045EF5B4F62CF6CF089DF0921BA6A8EFC83BCBA45D5DDE78E9D78E2 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
20:22:08.0360 0x08e4 LMS - ok
20:22:08.0396 0x08e4 [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC C:\windows\system32\drivers\lsi_fc.sys
20:22:08.0415 0x08e4 LSI_FC - ok
20:22:08.0445 0x08e4 [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS C:\windows\system32\drivers\lsi_sas.sys
20:22:08.0464 0x08e4 LSI_SAS - ok
20:22:08.0474 0x08e4 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2 C:\windows\system32\drivers\lsi_sas2.sys
20:22:08.0491 0x08e4 LSI_SAS2 - ok
20:22:08.0513 0x08e4 [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI C:\windows\system32\drivers\lsi_scsi.sys
20:22:08.0532 0x08e4 LSI_SCSI - ok
20:22:08.0545 0x08e4 [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv C:\windows\system32\drivers\luafv.sys
20:22:08.0601 0x08e4 luafv - ok
20:22:08.0663 0x08e4 [ A8D28D5B3E2A528D1EF0E338E44F2820, 40D1EFDD253BC0A0D984A5AD8A2721C3E83B15F14D538204714E6D5B00D92CEB ] MBAMProtector C:\windows\system32\drivers\mbam.sys
20:22:08.0678 0x08e4 MBAMProtector - ok
20:22:08.0758 0x08e4 [ 83C982A395D00BAFF6515FB38424EA76, 0E1B66F84A483D47550347D4A9426B95A066DB5104C4284F606A16768A11DB0C ] MBAMService C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
20:22:08.0792 0x08e4 MBAMService - ok
20:22:08.0833 0x08e4 [ AE757332EA130E94E646621CC695B52A, E688CF34A4206F32B5C7301119D8459C3456FC178FA1DAA6215CE15F2C824C43 ] MBAMWebAccessControl C:\windows\system32\drivers\mwac.sys
20:22:08.0849 0x08e4 MBAMWebAccessControl - ok
20:22:08.0881 0x08e4 [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll
20:22:08.0896 0x08e4 Mcx2Svc - ok
20:22:08.0920 0x08e4 [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas C:\windows\system32\drivers\megasas.sys
20:22:08.0937 0x08e4 megasas - ok
20:22:08.0968 0x08e4 [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR C:\windows\system32\drivers\MegaSR.sys
20:22:08.0994 0x08e4 MegaSR - ok
20:22:09.0031 0x08e4 [ A6518DCC42F7A6E999BB3BEA8FD87567, 8A9AE992F93F37E0723761EA271A7E1AA8172702C471041A17324474FC96B9BC ] MEIx64 C:\windows\system32\DRIVERS\HECIx64.sys
20:22:09.0047 0x08e4 MEIx64 - ok
20:22:09.0083 0x08e4 [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS C:\windows\system32\mmcss.dll
20:22:09.0144 0x08e4 MMCSS - ok
20:22:09.0198 0x08e4 [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem C:\windows\system32\drivers\modem.sys
20:22:09.0250 0x08e4 Modem - ok
20:22:09.0277 0x08e4 [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor C:\windows\system32\DRIVERS\monitor.sys
20:22:09.0319 0x08e4 monitor - ok
20:22:09.0338 0x08e4 [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass C:\windows\system32\DRIVERS\mouclass.sys
20:22:09.0355 0x08e4 mouclass - ok
20:22:09.0382 0x08e4 [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid C:\windows\system32\drivers\mouhid.sys
20:22:09.0420 0x08e4 mouhid - ok
20:22:09.0473 0x08e4 [ 32E7A3D591D671A6DF2DB515A5CBE0FA, 47CED0B9067AE8BF5EEF60B17ADEE5906BEDCC56E4CB460B7BFBC12BB9A69E63 ] mountmgr C:\windows\system32\drivers\mountmgr.sys
20:22:09.0491 0x08e4 mountmgr - ok
20:22:09.0506 0x08e4 [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio C:\windows\system32\drivers\mpio.sys
20:22:09.0527 0x08e4 mpio - ok
20:22:09.0547 0x08e4 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
20:22:09.0585 0x08e4 mpsdrv - ok
20:22:09.0649 0x08e4 [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc C:\windows\system32\mpssvc.dll
20:22:09.0701 0x08e4 MpsSvc - ok
20:22:09.0724 0x08e4 [ DC722758B8261E1ABAFD31A3C0A66380, 88BBE073E2CCD1DAB4656DDC53D5161E8A91D035ADAC1465D0CEBA86F1BB6D9A ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
20:22:09.0767 0x08e4 MRxDAV - ok
20:22:09.0800 0x08e4 [ A5D9106A73DC88564C825D317CAC68AC, 0457B2AEA4E05A91D0E43F317894A614434D8CEBE35020785387F307E231FBE4 ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
20:22:09.0847 0x08e4 mrxsmb - ok
20:22:09.0886 0x08e4 [ D711B3C1D5F42C0C2415687BE09FC163, 9B3013AC60BD2D0FF52086658BA5FF486ADE15954A552D7DD590580E8BAE3EFF ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
20:22:09.0914 0x08e4 mrxsmb10 - ok
20:22:09.0930 0x08e4 [ 9423E9D355C8D303E76B8CFBD8A5C30C, 220B33F120C2DD937FE4D5664F4B581DC0ACF78D62EB56B7720888F67B9644CC ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
20:22:09.0953 0x08e4 mrxsmb20 - ok
20:22:09.0971 0x08e4 [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci C:\windows\system32\DRIVERS\msahci.sys
20:22:09.0987 0x08e4 msahci - ok
20:22:10.0000 0x08e4 [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm C:\windows\system32\drivers\msdsm.sys
20:22:10.0021 0x08e4 msdsm - ok
20:22:10.0035 0x08e4 [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC C:\windows\System32\msdtc.exe
20:22:10.0076 0x08e4 MSDTC - ok
20:22:10.0115 0x08e4 [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs C:\windows\system32\drivers\Msfs.sys
20:22:10.0151 0x08e4 Msfs - ok
20:22:10.0183 0x08e4 [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys
20:22:10.0241 0x08e4 mshidkmdf - ok
20:22:10.0273 0x08e4 [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv C:\windows\system32\drivers\msisadrv.sys
20:22:10.0288 0x08e4 msisadrv - ok
20:22:10.0321 0x08e4 [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI C:\windows\system32\iscsiexe.dll
20:22:10.0371 0x08e4 MSiSCSI - ok
20:22:10.0373 0x08e4 msiserver - ok
20:22:10.0429 0x08e4 [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
20:22:10.0464 0x08e4 MSKSSRV - ok
20:22:10.0485 0x08e4 [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
20:22:10.0540 0x08e4 MSPCLOCK - ok
20:22:10.0566 0x08e4 [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM C:\windows\system32\drivers\MSPQM.sys
20:22:10.0626 0x08e4 MSPQM - ok
20:22:10.0659 0x08e4 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC C:\windows\system32\drivers\MsRPC.sys
20:22:10.0687 0x08e4 MsRPC - ok
20:22:10.0711 0x08e4 [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios C:\windows\system32\DRIVERS\mssmbios.sys
20:22:10.0727 0x08e4 mssmbios - ok
20:22:10.0749 0x08e4 [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE C:\windows\system32\drivers\MSTEE.sys
20:22:10.0797 0x08e4 MSTEE - ok
20:22:10.0820 0x08e4 [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig C:\windows\system32\drivers\MTConfig.sys
20:22:10.0838 0x08e4 MTConfig - ok
20:22:10.0850 0x08e4 [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup C:\windows\system32\Drivers\mup.sys
20:22:10.0867 0x08e4 Mup - ok
20:22:10.0896 0x08e4 [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent C:\windows\system32\qagentRT.dll
20:22:10.0939 0x08e4 napagent - ok
20:22:10.0981 0x08e4 [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
20:22:11.0032 0x08e4 NativeWifiP - ok
20:22:11.0089 0x08e4 [ 79B47FD40D9A817E932F9D26FAC0A81C, 53E260B8BFC50BA45FA73BFCF4E58C233890D0EAA9DEFDCCBB55FD3EB992FF2D ] NDIS C:\windows\system32\drivers\ndis.sys
20:22:11.0137 0x08e4 NDIS - ok
20:22:11.0164 0x08e4 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys
20:22:11.0200 0x08e4 NdisCap - ok
20:22:11.0221 0x08e4 [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
20:22:11.0257 0x08e4 NdisTapi - ok
20:22:11.0281 0x08e4 [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
20:22:11.0316 0x08e4 Ndisuio - ok
20:22:11.0336 0x08e4 [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
20:22:11.0390 0x08e4 NdisWan - ok
20:22:11.0410 0x08e4 [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy C:\windows\system32\drivers\NDProxy.sys
20:22:11.0445 0x08e4 NDProxy - ok
20:22:11.0471 0x08e4 [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
20:22:11.0527 0x08e4 NetBIOS - ok
20:22:11.0610 0x08e4 [ 09594D1089C523423B32A4229263F068, 7426A9B8BA27D3225928DDEFBD399650ABB90798212F56B7D12158AC22CCCE37 ] NetBT C:\windows\system32\DRIVERS\netbt.sys
20:22:11.0654 0x08e4 NetBT - ok
20:22:11.0671 0x08e4 [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] Netlogon C:\windows\system32\lsass.exe
20:22:11.0684 0x08e4 Netlogon - ok
20:22:11.0725 0x08e4 [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman C:\windows\System32\netman.dll
20:22:11.0788 0x08e4 Netman - ok
20:22:11.0817 0x08e4 [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm C:\windows\System32\netprofm.dll
20:22:11.0860 0x08e4 netprofm - ok
20:22:11.0892 0x08e4 [ 3E5A36127E201DDF663176B66828FAFE, 5A08BA9EFB1A72DF1DD839BA5FA2B8994012BA62A515588FF62333B33B60045B ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
20:22:11.0903 0x08e4 NetTcpPortSharing - ok
20:22:11.0947 0x08e4 [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960 C:\windows\system32\drivers\nfrd960.sys
20:22:11.0964 0x08e4 nfrd960 - ok
20:22:11.0994 0x08e4 [ 1EE99A89CC788ADA662441D1E9830529, 6B4FDD74BB81E12BD4B25A3E8AECB0FA77FA0075D454DD1D6DC1790ADF1F2AA8 ] NlaSvc C:\windows\System32\nlasvc.dll
20:22:12.0052 0x08e4 NlaSvc - ok
20:22:12.0072 0x08e4 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs C:\windows\system32\drivers\Npfs.sys
20:22:12.0108 0x08e4 Npfs - ok
20:22:12.0139 0x08e4 [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi C:\windows\system32\nsisvc.dll
20:22:12.0183 0x08e4 nsi - ok
20:22:12.0210 0x08e4 [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys
20:22:12.0269 0x08e4 nsiproxy - ok
20:22:12.0337 0x08e4 [ A2F74975097F52A00745F9637451FDD8, C681DDBD3382C477C2A030E828B5CFB529CB57C7847BD9AFF25E2A5E58B2DAF3 ] Ntfs C:\windows\system32\drivers\Ntfs.sys
20:22:12.0409 0x08e4 Ntfs - ok
20:22:12.0427 0x08e4 [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null C:\windows\system32\drivers\Null.sys
20:22:12.0461 0x08e4 Null - ok
20:22:12.0483 0x08e4 [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid C:\windows\system32\drivers\nvraid.sys
20:22:12.0504 0x08e4 nvraid - ok
20:22:12.0516 0x08e4 [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor C:\windows\system32\drivers\nvstor.sys
20:22:12.0537 0x08e4 nvstor - ok
20:22:12.0577 0x08e4 [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp C:\windows\system32\drivers\nv_agp.sys
20:22:12.0597 0x08e4 nv_agp - ok
20:22:12.0629 0x08e4 [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394 C:\windows\system32\drivers\ohci1394.sys
20:22:12.0650 0x08e4 ohci1394 - ok
20:22:12.0694 0x08e4 [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:22:12.0706 0x08e4 ose - ok
20:22:12.0914 0x08e4 [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
20:22:13.0099 0x08e4 osppsvc - ok
20:22:13.0136 0x08e4 [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc C:\windows\system32\pnrpsvc.dll
20:22:13.0173 0x08e4 p2pimsvc - ok
20:22:13.0202 0x08e4 [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc C:\windows\system32\p2psvc.dll
20:22:13.0226 0x08e4 p2psvc - ok
20:22:13.0255 0x08e4 [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport C:\windows\system32\drivers\parport.sys
20:22:13.0276 0x08e4 Parport - ok
20:22:13.0299 0x08e4 [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr C:\windows\system32\drivers\partmgr.sys
20:22:13.0317 0x08e4 partmgr - ok
20:22:13.0348 0x08e4 [ 3AEAA8B561E63452C655DC0584922257, 04C072969B58657602EB0C21CEDF24FCEE14E61B90A0F758F93925EF2C9FC32D ] PcaSvc C:\windows\System32\pcasvc.dll
20:22:13.0384 0x08e4 PcaSvc - ok
20:22:13.0414 0x08e4 [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci C:\windows\system32\drivers\pci.sys
20:22:13.0436 0x08e4 pci - ok
20:22:13.0452 0x08e4 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide C:\windows\system32\DRIVERS\pciide.sys
20:22:13.0468 0x08e4 pciide - ok
20:22:13.0492 0x08e4 [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia C:\windows\system32\drivers\pcmcia.sys
20:22:13.0515 0x08e4 pcmcia - ok
20:22:13.0532 0x08e4 [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw C:\windows\system32\drivers\pcw.sys
20:22:13.0549 0x08e4 pcw - ok
20:22:13.0576 0x08e4 [ 68769C3356B3BE5D1C732C97B9A80D6E, FB2D61145980A2899D1B7729184C54070315B0E63C9A22400A76CCD39E00029C ] PEAUTH C:\windows\system32\drivers\peauth.sys
20:22:13.0654 0x08e4 PEAUTH - ok
20:22:13.0727 0x08e4 [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost C:\windows\SysWow64\perfhost.exe
20:22:13.0741 0x08e4 PerfHost - ok
20:22:13.0777 0x08e4 [ 91111CEBBDE8015E822C46120ED9537C, 255B85FEF663C2E0652CECF3F9B67B12B576F924A34415DEE13F0F5137E1E7F7 ] PGEffect C:\windows\system32\DRIVERS\pgeffect.sys
20:22:13.0792 0x08e4 PGEffect - ok
20:22:13.0862 0x08e4 [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla C:\windows\system32\pla.dll
20:22:13.0952 0x08e4 pla - ok
20:22:14.0009 0x08e4 [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay C:\windows\system32\umpnpmgr.dll
20:22:14.0051 0x08e4 PlugPlay - ok
20:22:14.0085 0x08e4 [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll
20:22:14.0099 0x08e4 PNRPAutoReg - ok
20:22:14.0135 0x08e4 [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc C:\windows\system32\pnrpsvc.dll
20:22:14.0155 0x08e4 PNRPsvc - ok
20:22:14.0213 0x08e4 [ 4F15D75ADF6156BF56ECED6D4A55C389, 2ADA3EA69A5D7EC2A4D2DD89178DB94EAFDDF95F07B0070D654D9F7A5C12A044 ] PolicyAgent C:\windows\System32\ipsecsvc.dll
20:22:14.0274 0x08e4 PolicyAgent - ok
20:22:14.0305 0x08e4 [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power C:\windows\system32\umpo.dll
20:22:14.0339 0x08e4 Power - ok
20:22:14.0386 0x08e4 [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys
20:22:14.0440 0x08e4 PptpMiniport - ok
20:22:14.0462 0x08e4 [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor C:\windows\system32\drivers\processr.sys
20:22:14.0482 0x08e4 Processor - ok
20:22:14.0512 0x08e4 [ 53E83F1F6CF9D62F32801CF66D8352A8, 1225FED810BE8E0729EEAE5B340035CCBB9BACD3EF247834400F9B72D05ACE48 ] ProfSvc C:\windows\system32\profsvc.dll
20:22:14.0553 0x08e4 ProfSvc - ok
20:22:14.0571 0x08e4 [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] ProtectedStorage C:\windows\system32\lsass.exe
20:22:14.0585 0x08e4 ProtectedStorage - ok
20:22:14.0610 0x08e4 [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched C:\windows\system32\DRIVERS\pacer.sys
20:22:14.0680 0x08e4 Psched - ok
20:22:14.0746 0x08e4 [ C8FCB4899F8B70CC34E0D9876A80963C, E4CFC69C3EE1BC5C0FFF96CE034EAD8DD9727DA165A790CB57979AA0A6CEE350 ] QIOMem C:\windows\system32\DRIVERS\QIOMem.sys
20:22:14.0788 0x08e4 QIOMem - ok
20:22:14.0869 0x08e4 [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300 C:\windows\system32\drivers\ql2300.sys
20:22:14.0947 0x08e4 ql2300 - ok
20:22:14.0964 0x08e4 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx C:\windows\system32\drivers\ql40xx.sys
20:22:14.0990 0x08e4 ql40xx - ok
20:22:15.0028 0x08e4 [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE C:\windows\system32\qwave.dll
20:22:15.0058 0x08e4 QWAVE - ok
20:22:15.0071 0x08e4 [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys
20:22:15.0110 0x08e4 QWAVEdrv - ok
20:22:15.0137 0x08e4 [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys
20:22:15.0208 0x08e4 RasAcd - ok
20:22:15.0257 0x08e4 [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys
20:22:15.0294 0x08e4 RasAgileVpn - ok
20:22:15.0328 0x08e4 [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto C:\windows\System32\rasauto.dll
20:22:15.0376 0x08e4 RasAuto - ok
20:22:15.0397 0x08e4 [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys
20:22:15.0458 0x08e4 Rasl2tp - ok
20:22:15.0490 0x08e4 [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan C:\windows\System32\rasmans.dll
20:22:15.0529 0x08e4 RasMan - ok
20:22:15.0543 0x08e4 [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys
20:22:15.0603 0x08e4 RasPppoe - ok
20:22:15.0644 0x08e4 [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys
20:22:15.0696 0x08e4 RasSstp - ok
20:22:15.0732 0x08e4 [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss C:\windows\system32\DRIVERS\rdbss.sys
20:22:15.0777 0x08e4 rdbss - ok
20:22:15.0794 0x08e4 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus C:\windows\system32\drivers\rdpbus.sys
20:22:15.0846 0x08e4 rdpbus - ok
20:22:15.0892 0x08e4 [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys
20:22:15.0927 0x08e4 RDPCDD - ok
20:22:15.0936 0x08e4 [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys
20:22:15.0990 0x08e4 RDPENCDD - ok
20:22:16.0014 0x08e4 [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys
20:22:16.0051 0x08e4 RDPREFMP - ok
20:22:16.0072 0x08e4 [ E61608AA35E98999AF9AAEEEA6114B0A, F754CDE89DC96786D2A3C4D19EE2AEF1008E634E4DE3C0CBF927436DE90C04A6 ] RDPWD C:\windows\system32\drivers\RDPWD.sys
20:22:16.0097 0x08e4 RDPWD - ok
20:22:16.0133 0x08e4 [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost C:\windows\system32\drivers\rdyboost.sys
20:22:16.0156 0x08e4 rdyboost - ok
20:22:16.0186 0x08e4 [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess C:\windows\System32\mprdim.dll
20:22:16.0218 0x08e4 RemoteAccess - ok
20:22:16.0255 0x08e4 [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry C:\windows\system32\regsvc.dll
20:22:16.0289 0x08e4 RemoteRegistry - ok
20:22:16.0307 0x08e4 [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper C:\windows\System32\RpcEpMap.dll
20:22:16.0358 0x08e4 RpcEptMapper - ok
20:22:16.0385 0x08e4 [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator C:\windows\system32\locator.exe
20:22:16.0398 0x08e4 RpcLocator - ok
20:22:16.0430 0x08e4 [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] RpcSs C:\windows\system32\rpcss.dll
20:22:16.0470 0x08e4 RpcSs - ok
20:22:16.0488 0x08e4 [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr C:\windows\system32\DRIVERS\rspndr.sys
20:22:16.0548 0x08e4 rspndr - ok
20:22:16.0604 0x08e4 [ 135A64530D7699AD48F29D73A658DD11, 35838AE8ACFD9047C68DD0C8910557A82998E5CD778D5B98D4767AFA4BCE85BB ] RSUSBSTOR C:\windows\system32\Drivers\RtsUStor.sys
20:22:16.0628 0x08e4 RSUSBSTOR - ok
20:22:16.0646 0x08e4 [ E5DC911D0FEB72CAFF2BBDD6E7C3672F, E50825E0413049898A81DDF2AFE24BC92E48A0E9AA7653776F0F6EEE7D82E5D6 ] RSUSBVSTOR C:\windows\system32\Drivers\RTSUVSTOR.sys
20:22:16.0671 0x08e4 RSUSBVSTOR - ok
20:22:16.0736 0x08e4 [ 64FDF4FE366CA42DA2B7D9D424B6E39B, FC3844152E29B703373788F24862CDD307837AA53D21F978FB9C038A34593B95 ] RTL8192Ce C:\windows\system32\DRIVERS\rtl8192Ce.sys
20:22:16.0781 0x08e4 RTL8192Ce - ok
20:22:16.0794 0x08e4 [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] SamSs C:\windows\system32\lsass.exe
20:22:16.0808 0x08e4 SamSs - ok
20:22:16.0841 0x08e4 [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port C:\windows\system32\drivers\sbp2port.sys
20:22:16.0860 0x08e4 sbp2port - ok
20:22:16.0908 0x08e4 [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr C:\windows\System32\SCardSvr.dll
20:22:16.0943 0x08e4 SCardSvr - ok
20:22:16.0961 0x08e4 [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter C:\windows\system32\DRIVERS\scfilter.sys
20:22:17.0014 0x08e4 scfilter - ok
20:22:17.0067 0x08e4 [ 262F6592C3299C005FD6BEC90FC4463A, 54095E37F0B6CC677A3E9BDD40F4647C713273D197DB341063AA7F342A60C4A7 ] Schedule C:\windows\system32\schedsvc.dll
20:22:17.0147 0x08e4 Schedule - ok
20:22:17.0182 0x08e4 [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc C:\windows\System32\certprop.dll
20:22:17.0211 0x08e4 SCPolicySvc - ok
20:22:17.0238 0x08e4 [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC C:\windows\System32\SDRSVC.dll
20:22:17.0269 0x08e4 SDRSVC - ok
20:22:17.0320 0x08e4 [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv C:\windows\system32\drivers\secdrv.sys
20:22:17.0369 0x08e4 secdrv - ok
20:22:17.0395 0x08e4 [ BC617A4E1B4FA8DF523A061739A0BD87, 10C4057F6B321EB5237FF619747B74F5401BC17D15A8C7060829E8204A2297F9 ] seclogon C:\windows\system32\seclogon.dll
20:22:17.0426 0x08e4 seclogon - ok
20:22:17.0448 0x08e4 [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS C:\windows\System32\sens.dll
20:22:17.0497 0x08e4 SENS - ok
20:22:17.0536 0x08e4 [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc C:\windows\system32\sensrsvc.dll
20:22:17.0550 0x08e4 SensrSvc - ok
20:22:17.0596 0x08e4 [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum C:\windows\system32\drivers\serenum.sys
20:22:17.0638 0x08e4 Serenum - ok
20:22:17.0684 0x08e4 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial C:\windows\system32\drivers\serial.sys
20:22:17.0723 0x08e4 Serial - ok
20:22:17.0772 0x08e4 [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse C:\windows\system32\drivers\sermouse.sys
20:22:17.0810 0x08e4 sermouse - ok
20:22:17.0874 0x08e4 [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv C:\windows\system32\sessenv.dll
20:22:17.0922 0x08e4 SessionEnv - ok
20:22:17.0940 0x08e4 [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk C:\windows\system32\drivers\sffdisk.sys
20:22:17.0960 0x08e4 sffdisk - ok
20:22:17.0975 0x08e4 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys
20:22:18.0018 0x08e4 sffp_mmc - ok
20:22:18.0042 0x08e4 [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys
20:22:18.0086 0x08e4 sffp_sd - ok
20:22:18.0108 0x08e4 [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy C:\windows\system32\drivers\sfloppy.sys
20:22:18.0152 0x08e4 sfloppy - ok
20:22:18.0216 0x08e4 [ C6CC9297BD53E5229653303E556AA539, 921E21EDED244FEE15B56564B97C97785F45AB862C1012BFA0B96B121DC90076 ] Sftfs C:\windows\system32\DRIVERS\Sftfslh.sys
20:22:18.0253 0x08e4 Sftfs - ok
20:22:18.0323 0x08e4 [ 13693B6354DD6E72DC5131DA7D764B90, 447EFDA7CFB1F62EA316219D996406C8DC374097DB903F362D6E945227D8BB2D ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
20:22:18.0343 0x08e4 sftlist - ok
20:22:18.0447 0x08e4 [ 390AA7BC52CEE43F6790CDEA1E776703, 0D008289E4B14EF56D5233B7C8C789A36503FBAA8896660776557D6F08808FA7 ] Sftplay C:\windows\system32\DRIVERS\Sftplaylh.sys
20:22:18.0469 0x08e4 Sftplay - ok
20:22:18.0483 0x08e4 [ 617E29A0B0A2807466560D4C4E338D3E, 5E95D38DB9A6776EB4A15A952FA7949831D6F660EED8C3E79BD09D102BAC5D67 ] Sftredir C:\windows\system32\DRIVERS\Sftredirlh.sys
20:22:18.0498 0x08e4 Sftredir - ok
20:22:18.0521 0x08e4 [ 8F571F016FA1976F445147E9E6C8AE9B, 527AB960F2E08F598D1B953BDA4EA749831DD3C765DA278044B8AB22365F02B5 ] Sftvol C:\windows\system32\DRIVERS\Sftvollh.sys
20:22:18.0536 0x08e4 Sftvol - ok
20:22:18.0563 0x08e4 [ C3CDDD18F43D44AB713CF8C4916F7696, 38093295825AFDD08D7E32CC4EF2A6C447F6D6E3C6F7EA5554C25E7C3F16FC92 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
20:22:18.0576 0x08e4 sftvsa - ok
20:22:18.0615 0x08e4 [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess C:\windows\System32\ipnathlp.dll
20:22:18.0654 0x08e4 SharedAccess - ok
20:22:18.0686 0x08e4 [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\windows\System32\shsvcs.dll
20:22:18.0747 0x08e4 ShellHWDetection - ok
20:22:18.0776 0x08e4 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2 C:\windows\system32\drivers\SiSRaid2.sys
20:22:18.0795 0x08e4 SiSRaid2 - ok
20:22:18.0815 0x08e4 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4 C:\windows\system32\drivers\sisraid4.sys
20:22:18.0835 0x08e4 SiSRaid4 - ok
20:22:18.0873 0x08e4 [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb C:\windows\system32\DRIVERS\smb.sys
20:22:18.0912 0x08e4 Smb - ok
20:22:18.0949 0x08e4 [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP C:\windows\System32\snmptrap.exe
20:22:18.0964 0x08e4 SNMPTRAP - ok
20:22:18.0972 0x08e4 [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr C:\windows\system32\drivers\spldr.sys
20:22:18.0989 0x08e4 spldr - ok
20:22:19.0022 0x08e4 [ B96C17B5DC1424D56EEA3A99E97428CD, AF0A85066A7983878DC1C663811CE61C6CA1912DC956184F878B7B82DB93C651 ] Spooler C:\windows\System32\spoolsv.exe
20:22:19.0066 0x08e4 Spooler - ok
20:22:19.0182 0x08e4 [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc C:\windows\system32\sppsvc.exe
20:22:19.0298 0x08e4 sppsvc - ok
20:22:19.0327 0x08e4 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify C:\windows\system32\sppuinotify.dll
20:22:19.0359 0x08e4 sppuinotify - ok
20:22:19.0394 0x08e4 [ 441FBA48BFF01FDB9D5969EBC1838F0B, 306128F1AD489F87161A089D1BDC1542A4CB742D91A0C12A7CD1863FDB8932C0 ] srv C:\windows\system32\DRIVERS\srv.sys
20:22:19.0445 0x08e4 srv - ok
20:22:19.0483 0x08e4 [ B4ADEBBF5E3677CCE9651E0F01F7CC28, 726DB2283113AB2A9681E8E9F61132303D6D86E9CD034C40EE4A8C9DB29E87F7 ] srv2 C:\windows\system32\DRIVERS\srv2.sys
20:22:19.0536 0x08e4 srv2 - ok
20:22:19.0586 0x08e4 [ 0C4540311E11664B245A263E1154CEF8, 63376322BFFAFF2F166AF3FDD3F1A346C21FAE21F406F659F8630779D1D6525D ] SrvHsfHDA C:\windows\system32\DRIVERS\VSTAZL6.SYS
20:22:19.0616 0x08e4 SrvHsfHDA - ok
20:22:19.0670 0x08e4 [ 02071D207A9858FBE3A48CBFD59C4A04, FEA4DEBAEC3465E0C7C1E8B721805922F6BBCB96A60A193B11688F4252F4B89E ] SrvHsfV92 C:\windows\system32\DRIVERS\VSTDPV6.SYS
20:22:19.0765 0x08e4 SrvHsfV92 - ok
20:22:19.0817 0x08e4 [ 18E40C245DBFAF36FD0134A7EF2DF396, 0138A68958112101A5D3BD94114F320CE80B0C9A93E009AC78DE7415FCCC7DE7 ] SrvHsfWinac C:\windows\system32\DRIVERS\VSTCNXT6.SYS
20:22:19.0862 0x08e4 SrvHsfWinac - ok
20:22:19.0881 0x08e4 [ 27E461F0BE5BFF5FC737328F749538C3, AFA4704ED8FFC1A0BAB40DFB81D3AE3F3D933A3C9BF54DDAF39FF9AF3646D9E6 ] srvnet C:\windows\system32\DRIVERS\srvnet.sys
20:22:19.0904 0x08e4 srvnet - ok
20:22:19.0941 0x08e4 [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV C:\windows\System32\ssdpsrv.dll
20:22:19.0998 0x08e4 SSDPSRV - ok
20:22:20.0019 0x08e4 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc C:\windows\system32\sstpsvc.dll
20:22:20.0052 0x08e4 SstpSvc - ok
20:22:20.0078 0x08e4 [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor C:\windows\system32\drivers\stexstor.sys
20:22:20.0096 0x08e4 stexstor - ok
20:22:20.0159 0x08e4 [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc C:\windows\System32\wiaservc.dll
20:22:20.0192 0x08e4 stisvc - ok
20:22:20.0210 0x08e4 [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum C:\windows\system32\DRIVERS\swenum.sys
20:22:20.0227 0x08e4 swenum - ok
20:22:20.0272 0x08e4 [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv C:\windows\System32\swprv.dll
20:22:20.0318 0x08e4 swprv - ok
20:22:20.0424 0x08e4 [ F5B46DF59FEAA48A442AED7EEB754D4B, 8415FDD5E7B4D4819BB9B0937CDF254548C871045787958BCF708096204B1714 ] SynTP C:\windows\system32\DRIVERS\SynTP.sys
20:22:20.0461 0x08e4 SynTP - ok
20:22:20.0571 0x08e4 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D, 3C13217548BE61F2BDB8BD41F77345CDDA1F97BF0AE17241C335B9807EB3DBB8 ] SysMain C:\windows\system32\sysmain.dll
20:22:20.0659 0x08e4 SysMain - ok
20:22:20.0689 0x08e4 [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\windows\System32\TabSvc.dll
20:22:20.0709 0x08e4 TabletInputService - ok
20:22:20.0737 0x08e4 [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv C:\windows\System32\tapisrv.dll
20:22:20.0775 0x08e4 TapiSrv - ok
20:22:20.0801 0x08e4 [ 1BE03AC720F4D302EA01D40F588162F6, AB644862BF1D2E824FD846180DEC4E2C0FAFCC517451486DE5A92E5E78A952E4 ] TBS C:\windows\System32\tbssvc.dll
20:22:20.0833 0x08e4 TBS - ok
20:22:20.0930 0x08e4 [ ACB82BDA8F46C84F465C1AFA517DC4B9, DE785AC33A0D63699E5E3E85E4C33694A15FBC9B93D432E8865C88E44CDF3E17 ] Tcpip C:\windows\system32\drivers\tcpip.sys
20:22:21.0011 0x08e4 Tcpip - ok
20:22:21.0069 0x08e4 [ ACB82BDA8F46C84F465C1AFA517DC4B9, DE785AC33A0D63699E5E3E85E4C33694A15FBC9B93D432E8865C88E44CDF3E17 ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys
20:22:21.0141 0x08e4 TCPIP6 - ok
20:22:21.0176 0x08e4 [ DF687E3D8836BFB04FCC0615BF15A519, 7C5B1E72673B4299DFC21E869F0FBB28198CA54DF4F4AF7080005F2D82467784 ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys
20:22:21.0227 0x08e4 tcpipreg - ok
20:22:21.0262 0x08e4 [ FD542B661BD22FA69CA789AD0AC58C29, 75FFAF1834B1E22DF37608ED451F161052FF1FE3C681B4E20A68DCA92CC7FD8C ] tdcmdpst C:\windows\system32\DRIVERS\tdcmdpst.sys
20:22:21.0276 0x08e4 tdcmdpst - ok
20:22:21.0292 0x08e4 [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE C:\windows\system32\drivers\tdpipe.sys
20:22:21.0311 0x08e4 TDPIPE - ok
20:22:21.0347 0x08e4 [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP C:\windows\system32\drivers\tdtcp.sys
20:22:21.0364 0x08e4 TDTCP - ok
20:22:21.0391 0x08e4 [ DDAD5A7AB24D8B65F8D724F5C20FD806, B71F2967A4EE7395E4416C1526CB85368AEA988BDD1F2C9719C48B08FAFA9661 ] tdx C:\windows\system32\DRIVERS\tdx.sys
20:22:21.0429 0x08e4 tdx - ok
20:22:21.0453 0x08e4 [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD C:\windows\system32\DRIVERS\termdd.sys
20:22:21.0470 0x08e4 TermDD - ok
20:22:21.0516 0x08e4 [ 2E648163254233755035B46DD7B89123, 6FA0D07CE18A3A69D82EE49D875F141E39406E92C34EAC76AC4EB052E6EBCBCD ] TermService C:\windows\System32\termsrv.dll
20:22:21.0578 0x08e4 TermService - ok
20:22:21.0604 0x08e4 [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes C:\windows\system32\themeservice.dll
20:22:21.0622 0x08e4 Themes - ok
20:22:21.0639 0x08e4 [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER C:\windows\system32\mmcss.dll
20:22:21.0670 0x08e4 THREADORDER - ok
20:22:21.0745 0x08e4 [ 71C321649B28638EE80A2EEB164C1DC8, D75D296B506DCC38A4DED82C71141388AEB60B065785DCC5BC2F4B3B77ACEDC7 ] TMachInfo C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
20:22:21.0755 0x08e4 TMachInfo - ok
20:22:21.0776 0x08e4 [ 8E2C799D3476EAC32C3BA0DF7CE6AF19, CFE8A69E3F2A42C3BA2B38EC9233076D0AD32C441500E6407219F2E866905D9B ] TODDSrv C:\Windows\system32\TODDSrv.exe
20:22:21.0788 0x08e4 TODDSrv - ok
20:22:21.0899 0x08e4 [ 1C73689B900428C7D054A41C4687F55C, 6DD3CDC09E4A62F40A81872789A5C8678C0FE23DD911C2951DFF5494B6BFC012 ] TosCoSrv C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
20:22:21.0921 0x08e4 TosCoSrv - ok
20:22:21.0984 0x08e4 [ 63AAFCF3EA5DBB17123E0BAE9AFE4D58, ACAD9D96CE58EDB620AC13ACA8C6F4122BA8B2AF78468A760F21A01B43D93312 ] TOSHIBA eco Utility Service C:\Program Files\TOSHIBA\TECO\TecoService.exe
20:22:21.0997 0x08e4 TOSHIBA eco Utility Service - ok
20:22:22.0047 0x08e4 [ 29D0886CF250FCEF1BF9E65AB8D2C0C8, 8D852DB100AC68A07A6E2AD21198410EAAB36E83BB8BAEA71CB698680B5DCE71 ] TOSHIBA HDD SSD Alert Service C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
20:22:22.0057 0x08e4 TOSHIBA HDD SSD Alert Service - ok
20:22:22.0097 0x08e4 [ 09FF7B0B1B5C3D225495CB6F5A9B39F8, 0D2CC72B7E02B92C9A1D6B76300B75A39427046903326642B9D511A51A795027 ] tos_sps64 C:\windows\system32\DRIVERS\tos_sps64.sys
20:22:22.0127 0x08e4 tos_sps64 - ok
20:22:22.0206 0x08e4 [ 098B8A408C17E125A3D9A8E1166780C8, F25F09F62713C8234CB2B6A40A4455502C8004090BFB9EE9465546AD48369956 ] TPCHSrv C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
20:22:22.0230 0x08e4 TPCHSrv - ok
20:22:22.0262 0x08e4 [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks C:\windows\System32\trkwks.dll
20:22:22.0316 0x08e4 TrkWks - ok
20:22:22.0381 0x08e4 [ 0D5A09B08568760AE85A801FCBC0F83D, 347ACBA74FDCBEAC671521739F8A34EC0E378CAF716C31F55616F9F843E4D0D3 ] TrueSight C:\Windows\System32\drivers\TrueSight.sys
20:22:22.0397 0x08e4 TrueSight - ok
20:22:22.0448 0x08e4 [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
20:22:22.0505 0x08e4 TrustedInstaller - ok
20:22:22.0519 0x08e4 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30, CA302C2ED6A6BF4670BAAA4F5C14C0238CF0C80316856AA0DB053F4D593033AC ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys
20:22:22.0554 0x08e4 tssecsrv - ok
20:22:22.0593 0x08e4 [ D11C783E3EF9A3C52C0EBE83CC5000E9, A136C355D4C8945729163D15801364A614E23217B15F9313C85BA45BB71A74EB ] TsUsbFlt C:\windows\system32\drivers\tsusbflt.sys
20:22:22.0612 0x08e4 TsUsbFlt - ok
20:22:22.0628 0x08e4 [ 9CC2CCAE8A84820EAECB886D477CBCB8, 50D8AA2D7477A6618A0C31BB4D1C4887B457865FB1105E2E7B984EEFA337B804 ] TsUsbGD C:\windows\system32\drivers\TsUsbGD.sys
20:22:22.0665 0x08e4 TsUsbGD - ok
20:22:22.0702 0x08e4 [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel C:\windows\system32\DRIVERS\tunnel.sys
20:22:22.0741 0x08e4 tunnel - ok
20:22:22.0770 0x08e4 [ 550B567F9364D8F7684C3FB3EA665A72, A214BBBBAB9F0DD525FA5A818CEB8E9294B4A96676317255D7ACF6049049C933 ] TVALZ C:\windows\system32\DRIVERS\TVALZ_O.SYS
20:22:22.0784 0x08e4 TVALZ - ok
20:22:22.0795 0x08e4 [ 9C7191F4B2E49BFF47A6C1144B5923FA, DF4E663499946F4E68B7528CA399574D1EB69797FF81F681943B84F3E5E6A40E ] TVALZFL C:\windows\system32\DRIVERS\TVALZFL.sys
20:22:22.0809 0x08e4 TVALZFL - ok
20:22:22.0830 0x08e4 [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35 C:\windows\system32\drivers\uagp35.sys
20:22:22.0848 0x08e4 uagp35 - ok
20:22:22.0884 0x08e4 [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs C:\windows\system32\DRIVERS\udfs.sys
20:22:22.0952 0x08e4 udfs - ok
20:22:22.0996 0x08e4 [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect C:\windows\system32\UI0Detect.exe
20:22:23.0041 0x08e4 UI0Detect - ok
20:22:23.0078 0x08e4 [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys
20:22:23.0097 0x08e4 uliagpkx - ok
20:22:23.0127 0x08e4 [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus C:\windows\system32\DRIVERS\umbus.sys
20:22:23.0165 0x08e4 umbus - ok
20:22:23.0198 0x08e4 [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass C:\windows\system32\drivers\umpass.sys
20:22:23.0217 0x08e4 UmPass - ok
20:22:23.0390 0x08e4 [ 7E5E1603D0FF2D240AE70295C5C3FEFC, 1E5F8E415ACE3C6DFBE636473DBE051329174F2A085516B6FC1515A54014D02B ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
20:22:23.0458 0x08e4 UNS - ok
20:22:23.0495 0x08e4 [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost C:\windows\System32\upnphost.dll
20:22:23.0556 0x08e4 upnphost - ok
20:22:23.0594 0x08e4 [ 6F1A3157A1C89435352CEB543CDB359C, 325B46220779C5FE3B6F19FF794474837FAB9675D9C98ACB68CCE47B1CFE5F12 ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys
20:22:23.0615 0x08e4 usbccgp - ok
20:22:23.0647 0x08e4 [ AF0892A803FDDA7492F595368E3B68E7, F263346DEB4D742EB436CF578F187AC8521D84CED52E98475E6198EC52244F07 ] usbcir C:\windows\system32\drivers\usbcir.sys
20:22:23.0672 0x08e4 usbcir - ok
20:22:23.0684 0x08e4 [ C025055FE7B87701EB042095DF1A2D7B, D7B34B6C2C5BD3C8141895AC21BB637EA5E3C4F7A85EEF4C4C36E6BB2045A3D9 ] usbehci C:\windows\system32\DRIVERS\usbehci.sys
20:22:23.0720 0x08e4 usbehci - ok
20:22:23.0759 0x08e4 [ 287C6C9410B111B68B52CA298F7B8C24, 98900C08FE662A00DF8B37837B2BEBF9ACB7989C387AF36B2109B05A4F462D4E ] usbhub C:\windows\system32\DRIVERS\usbhub.sys
20:22:23.0806 0x08e4 usbhub - ok
20:22:23.0836 0x08e4 [ 9840FC418B4CBD632D3D0A667A725C31, 776D86A032DCA2842EF7AADB35473193CA80547223EFAA7F110F296C377077B0 ] usbohci C:\windows\system32\drivers\usbohci.sys
20:22:23.0873 0x08e4 usbohci - ok
20:22:23.0891 0x08e4 [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint C:\windows\system32\drivers\usbprint.sys
20:22:23.0931 0x08e4 usbprint - ok
20:22:23.0953 0x08e4 [ FED648B01349A3C8395A5169DB5FB7D6, DC4D7594C24ADD076927B9347F1B50B91CF03A4ABDB284248D5711D9C19DEB96 ] USBSTOR C:\windows\system32\DRIVERS\USBSTOR.SYS
20:22:23.0991 0x08e4 USBSTOR - ok
20:22:24.0012 0x08e4 [ 62069A34518BCF9C1FD9E74B3F6DB7CD, C58E21424718729324B285BEE1C96551540FCC3FD650B2D10895EBA48D981E25 ] usbuhci C:\windows\system32\drivers\usbuhci.sys
20:22:24.0030 0x08e4 usbuhci - ok
20:22:24.0066 0x08e4 [ 454800C2BC7F3927CE030141EE4F4C50, 10901E62DAA70657C499AD590DECCCA6E46FDDF4A193B2F19279E1B8ED7B1E44 ] usbvideo C:\windows\system32\Drivers\usbvideo.sys
20:22:24.0093 0x08e4 usbvideo - ok
20:22:24.0115 0x08e4 [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms C:\windows\System32\uxsms.dll
20:22:24.0168 0x08e4 UxSms - ok
20:22:24.0194 0x08e4 [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] VaultSvc C:\windows\system32\lsass.exe
20:22:24.0207 0x08e4 VaultSvc - ok
20:22:24.0222 0x08e4 [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys
20:22:24.0239 0x08e4 vdrvroot - ok
20:22:24.0269 0x08e4 [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds C:\windows\System32\vds.exe
20:22:24.0328 0x08e4 vds - ok
20:22:24.0374 0x08e4 [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga C:\windows\system32\DRIVERS\vgapnp.sys
20:22:24.0395 0x08e4 vga - ok
20:22:24.0410 0x08e4 [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave C:\windows\System32\drivers\vga.sys
20:22:24.0467 0x08e4 VgaSave - ok
20:22:24.0498 0x08e4 [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp C:\windows\system32\drivers\vhdmp.sys
20:22:24.0522 0x08e4 vhdmp - ok
20:22:24.0538 0x08e4 [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide C:\windows\system32\drivers\viaide.sys
20:22:24.0554 0x08e4 viaide - ok
20:22:24.0587 0x08e4 [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr C:\windows\system32\drivers\volmgr.sys
20:22:24.0605 0x08e4 volmgr - ok
20:22:24.0626 0x08e4 [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx C:\windows\system32\drivers\volmgrx.sys
20:22:24.0654 0x08e4 volmgrx - ok
20:22:24.0673 0x08e4 [ DF8126BD41180351A093A3AD2FC8903B, AEFF4AA89CDDAAAD43CDE17C6B6EB2A397A0AC1651CBD51B889161EC2BC6527A ] volsnap C:\windows\system32\drivers\volsnap.sys
20:22:24.0699 0x08e4 volsnap - ok
20:22:24.0724 0x08e4 [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid C:\windows\system32\drivers\vsmraid.sys
20:22:24.0746 0x08e4 vsmraid - ok
20:22:24.0816 0x08e4 [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS C:\windows\system32\vssvc.exe
20:22:24.0888 0x08e4 VSS - ok
20:22:24.0916 0x08e4 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus C:\windows\system32\DRIVERS\vwifibus.sys
20:22:24.0937 0x08e4 vwifibus - ok
20:22:24.0947 0x08e4 [ 6A3D66263414FF0D6FA754C646612F3F, 30F6BA594B0D3B94113064015A16D97811CD989DF1715CCE21CEAB9894C1B4FB ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys
20:22:24.0971 0x08e4 vwififlt - ok
20:22:25.0020 0x08e4 [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time C:\windows\system32\w32time.dll
20:22:25.0060 0x08e4 W32Time - ok
20:22:25.0083 0x08e4 [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen C:\windows\system32\drivers\wacompen.sys
20:22:25.0124 0x08e4 WacomPen - ok
20:22:25.0154 0x08e4 [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP C:\windows\system32\DRIVERS\wanarp.sys
20:22:25.0235 0x08e4 WANARP - ok
20:22:25.0239 0x08e4 [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys
20:22:25.0277 0x08e4 Wanarpv6 - ok
20:22:25.0374 0x08e4 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C, 4150DAB33E8D61076F1D4767BCAFC9B4ECCCCBD58FD4FB3CFE5B8D27DCDCAB61 ] WatAdminSvc C:\windows\system32\Wat\WatAdminSvc.exe
20:22:25.0414 0x08e4 WatAdminSvc - ok
20:22:25.0484 0x08e4 [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine C:\windows\system32\wbengine.exe
20:22:25.0560 0x08e4 wbengine - ok
20:22:25.0585 0x08e4 [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc C:\windows\System32\wbiosrvc.dll
20:22:25.0608 0x08e4 WbioSrvc - ok
20:22:25.0642 0x08e4 [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc C:\windows\System32\wcncsvc.dll
20:22:25.0690 0x08e4 wcncsvc - ok
20:22:25.0722 0x08e4 [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
20:22:25.0736 0x08e4 WcsPlugInService - ok
20:22:25.0758 0x08e4 [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd C:\windows\system32\drivers\wd.sys
20:22:25.0774 0x08e4 Wd - ok
20:22:25.0804 0x08e4 [ 441BD2D7B4F98134C3A4F9FA570FD250, FF20815273014C5A27C2B75E2C70FE674809293627056199F502DFDF4CECFCA1 ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys
20:22:25.0842 0x08e4 Wdf01000 - ok
20:22:25.0861 0x08e4 [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiServiceHost C:\windows\system32\wdi.dll
20:22:25.0897 0x08e4 WdiServiceHost - ok
20:22:25.0901 0x08e4 [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiSystemHost C:\windows\system32\wdi.dll
20:22:25.0921 0x08e4 WdiSystemHost - ok
20:22:25.0954 0x08e4 [ 3DB6D04E1C64272F8B14EB8BC4616280, 9138642B1C19F895D4ECFD930160C80FBF15813CE63BBF4C899842C300FD3026 ] WebClient C:\windows\System32\webclnt.dll
20:22:25.0996 0x08e4 WebClient - ok
20:22:26.0019 0x08e4 [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc C:\windows\system32\wecsvc.dll
20:22:26.0089 0x08e4 Wecsvc - ok
20:22:26.0110 0x08e4 [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport C:\windows\System32\wercplsupport.dll
20:22:26.0143 0x08e4 wercplsupport - ok
20:22:26.0189 0x08e4 [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc C:\windows\System32\WerSvc.dll
20:22:26.0221 0x08e4 WerSvc - ok
20:22:26.0229 0x08e4 [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf C:\windows\system32\DRIVERS\wfplwf.sys
20:22:26.0264 0x08e4 WfpLwf - ok
20:22:26.0285 0x08e4 [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount C:\windows\system32\drivers\wimmount.sys
20:22:26.0301 0x08e4 WIMMount - ok
20:22:26.0304 0x08e4 WinHttpAutoProxySvc - ok
20:22:26.0369 0x08e4 [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll
20:22:26.0405 0x08e4 Winmgmt - ok
20:22:26.0489 0x08e4 [ BCB1310604AA415C4508708975B3931E, 9D943F086D454345153A0DD426B4432532A44FD87950386B186E1CAD2AC70565 ] WinRM C:\windows\system32\WsmSvc.dll
20:22:26.0573 0x08e4 WinRM - ok
20:22:26.0633 0x08e4 [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc C:\windows\System32\wlansvc.dll
20:22:26.0694 0x08e4 Wlansvc - ok
20:22:26.0750 0x08e4 [ 06C8FA1CF39DE6A735B54D906BA791C6, D8FEC7DE227781CDA876904701B2AA995268F74DCD6CB34AA0296C557FC283B6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
20:22:26.0760 0x08e4 wlcrasvc - ok
20:22:26.0907 0x08e4 [ 2BACD71123F42CEA603F4E205E1AE337, 1FEF20554110371D738F462ECFFA999158EFEED02062414C58C1B61C422BF0B9 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
20:22:26.0971 0x08e4 wlidsvc - ok
20:22:27.0012 0x08e4 [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi C:\windows\system32\DRIVERS\wmiacpi.sys
20:22:27.0049 0x08e4 WmiAcpi - ok
20:22:27.0089 0x08e4 [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe
20:22:27.0108 0x08e4 wmiApSrv - ok
20:22:27.0141 0x08e4 WMPNetworkSvc - ok
20:22:27.0163 0x08e4 [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc C:\windows\System32\wpcsvc.dll
20:22:27.0176 0x08e4 WPCSvc - ok
20:22:27.0199 0x08e4 [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum C:\windows\system32\wpdbusenum.dll
20:22:27.0217 0x08e4 WPDBusEnum - ok
20:22:27.0235 0x08e4 [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys
20:22:27.0270 0x08e4 ws2ifsl - ok
20:22:27.0291 0x08e4 [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc C:\windows\System32\wscsvc.dll
20:22:27.0311 0x08e4 wscsvc - ok
20:22:27.0314 0x08e4 WSearch - ok
20:22:27.0408 0x08e4 [ D9EF901DCA379CFE914E9FA13B73B4C4, 3BE9693B7B2AFEE23D72AF5DA211379724D752F0EC18ACB7D3DE3DDFC5AE0004 ] wuauserv C:\windows\system32\wuaueng.dll
20:22:27.0478 0x08e4 wuauserv - ok
20:22:27.0502 0x08e4 [ D3381DC54C34D79B22CEE0D65BA91B7C, 70DC4ADCA4C0C28BB133287511E329D1B6B9B97F96CDE5B1D2F1F59FE1A965D9 ] WudfPf C:\windows\system32\drivers\WudfPf.sys
20:22:27.0562 0x08e4 WudfPf - ok
20:22:27.0606 0x08e4 [ CF8D590BE3373029D57AF80914190682, FB9641777E90A58C063FBE95F081DC6D2F4770827DE19108A9DC3E3D6B17B4BF ] WUDFRd C:\windows\system32\DRIVERS\WUDFRd.sys
20:22:27.0648 0x08e4 WUDFRd - ok
20:22:27.0675 0x08e4 [ 7A95C95B6C4CF292D689106BCAE49543, 9029F489E1E817CE12839B8C6656E46190497D445DC3F43C20CF96E5E6BD0691 ] wudfsvc C:\windows\System32\WUDFSvc.dll
20:22:27.0707 0x08e4 wudfsvc - ok
20:22:27.0732 0x08e4 [ 9A3452B3C2A46C073166C5CF49FAD1AE, D6F95F51D8E37BA4CF403965EC08CCFEEA9EEFDBFC7752432EAEC19925BDA115 ] WwanSvc C:\windows\System32\wwansvc.dll
20:22:27.0776 0x08e4 WwanSvc - ok
20:22:27.0851 0x08e4 [ 21E13F2CB269DEFEAE5E1D09887D47BB, 543991CA8D1C65113DFF039B85AE3F9A87F503DAEC30F46929FD454BC57E5A91 ] ZAM C:\windows\System32\drivers\zam64.sys
20:22:27.0873 0x08e4 ZAM - ok
20:22:28.0721 0x08e4 [ C78761C2A5475EA16ADCD438CC17841F, 2EC81397DE7BEF39EA1E1758FE778A0A31C8D04B6AD76D9C0917D95808366A70 ] ZAMSvc C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
20:22:29.0018 0x08e4 ZAMSvc - ok
20:22:29.0109 0x08e4 [ 21E13F2CB269DEFEAE5E1D09887D47BB, 543991CA8D1C65113DFF039B85AE3F9A87F503DAEC30F46929FD454BC57E5A91 ] ZAM_Guard C:\windows\System32\drivers\zamguard64.sys
20:22:29.0130 0x08e4 ZAM_Guard - ok
20:22:29.0133 0x08e4 ================ Scan global ===============================
20:22:29.0159 0x08e4 [ BA0CD8C393E8C9F83354106093832C7B, 18D8A4780A2BAA6CEF7FBBBDA0EF6BF2DADF146E1E578A618DD5859E8ADBF1A8 ] C:\windows\system32\basesrv.dll
20:22:29.0197 0x08e4 [ EB6A48CC998E1090E44E8E7F1009A640, 94001F8AEB2A398E7C267C90183ABED2AFA6FC4C219027C861C6C1329093464A ] C:\windows\system32\winsrv.dll
20:22:29.0209 0x08e4 [ EB6A48CC998E1090E44E8E7F1009A640, 94001F8AEB2A398E7C267C90183ABED2AFA6FC4C219027C861C6C1329093464A ] C:\windows\system32\winsrv.dll
20:22:29.0231 0x08e4 [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\windows\system32\sxssrv.dll
20:22:29.0271 0x08e4 [ 24ACB7E5BE595468E3B9AA488B9B4FCB, 63541E3432FCE953F266AE553E7A394978D6EE3DB52388D885F668CF42C5E7E2 ] C:\windows\system32\services.exe
20:22:29.0279 0x08e4 [ Global ] - ok
20:22:29.0279 0x08e4 ================ Scan MBR ==================================
20:22:29.0290 0x08e4 [ 5B5E648D12FCADC244C1EC30318E1EB9 ] \Device\Harddisk0\DR0
20:22:29.0702 0x08e4 \Device\Harddisk0\DR0 - detected TDSS File System ( 1 )
20:22:29.0702 0x08e4 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
20:22:32.0533 0x08e4 ================ Scan VBR ==================================
20:22:32.0588 0x08e4 [ 8AC23BED265B9837B514C7AD0AE3474B ] \Device\Harddisk0\DR0\Partition1
20:22:32.0589 0x08e4 \Device\Harddisk0\DR0\Partition1 - ok
20:22:32.0589 0x08e4 ================ Scan generic autorun ======================
20:22:32.0590 0x08e4 TPwrMain - ok
20:22:32.0591 0x08e4 HSON - ok
20:22:32.0592 0x08e4 TCrdMain - ok
20:22:32.0658 0x08e4 [ 6B640D9B1C114DDB8A534A9101DCEF29, 2993E6282D8DC6CD431D7B79C9C7EB3AF9AB3BBDD8F90C85142D14DC2575BB99 ] C:\Program Files\CONEXANT\SAII\SAIICpl.exe
20:22:32.0672 0x08e4 SmartAudio - ok
20:22:32.0727 0x08e4 [ 8D8839FDB43DE6F35D4A26294B8B9549, 536C38B0D78A170180495098AAE6187DA428C8338E971F264B083808C8949EBF ] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe
20:22:32.0746 0x08e4 cAudioFilterAgent - ok
20:22:32.0747 0x08e4 SynTPEnh - ok
20:22:32.0770 0x08e4 Teco - ok
20:22:32.0770 0x08e4 TosWaitSrv - ok
20:22:32.0807 0x08e4 [ F82483A80D49ACCA81193A294FB233CD, 7EEA9E7F62A92AD98569B1A4F4809D91D7ED671821A738EB75BC6E469DB44494 ] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe
20:22:32.0815 0x08e4 TosVolRegulator - ok
20:22:32.0883 0x08e4 [ 426350B428CD70D037A3326EB9E5EDFD, B7B1A20D1D75661533CF983EA0C6E520B928AF6FCCDA70C488FC8FC566B5AF7F ] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
20:22:32.0904 0x08e4 TosSENotify - ok
20:22:32.0906 0x08e4 TosNC - ok
20:22:32.0908 0x08e4 TosReelTimeMonitor - ok
20:22:33.0450 0x08e4 [ C78761C2A5475EA16ADCD438CC17841F, 2EC81397DE7BEF39EA1E1758FE778A0A31C8D04B6AD76D9C0917D95808366A70 ] C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
20:22:33.0743 0x08e4 ZAM - ok
20:22:33.0800 0x08e4 [ BB752714D14CB1F13969D721F1A3A60F, 32B95C75704BE37B349E0493AA8D2FCDAE8007275124646125650456D3A1563F ] C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
20:22:33.0813 0x08e4 TSleepSrv - ok
20:22:33.0977 0x08e4 [ 02F4246866BF35BF2244E5CF72E25895, AA08D3E65CCF6F4F79D169575C9B4FE8BA078246BFB30C380939A4A3B6092074 ] C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe
20:22:34.0049 0x08e4 NortonOnlineBackupReminder - ok
20:22:34.0102 0x08e4 [ 2D7816ACDA1CC85C873CBC19A4121D58, 3F3E41EBEF81DB8C2A84A8E75D1E4852046A10A5DCB8CCCC2ADF7FD0DC8EEF66 ] C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe
20:22:34.0135 0x08e4 ToshibaAppPlace - detected UnsignedFile.Multi.Generic ( 1 )
20:22:36.0883 0x08e4 Detect skipped due to KSN trusted
20:22:36.0883 0x08e4 ToshibaAppPlace - ok
20:22:36.0965 0x08e4 [ 4EB0C6C3EF4D8885CF2B5D0062F31E44, A3967758E30609D29A4856F373DD2C971B341F914825D720387ACFD7499EDC3D ] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
20:22:36.0997 0x08e4 DivXUpdate - ok
20:22:37.0479 0x08e4 [ 70050353213574B62CA9EC28F65F2F3E, 3EBC0ABFC9ABFE4508E21A032A28D12B73CB91DE1FD830069FF902336A271E68 ] C:\Program Files\AVAST Software\Avast\AvastUI.exe
20:22:37.0818 0x08e4 AvastUI.exe - ok
20:22:37.0917 0x08e4 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
20:22:37.0976 0x08e4 Sidebar - ok
20:22:38.0014 0x08e4 [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
20:22:38.0048 0x08e4 mctadmin - ok
20:22:38.0105 0x08e4 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
20:22:38.0145 0x08e4 Sidebar - ok
20:22:38.0169 0x08e4 [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
20:22:38.0188 0x08e4 mctadmin - ok
20:22:38.0470 0x08e4 [ FB5B78A3DE88FD3B725DA574497BC225, 0096C3ED0E29153E6A9E84C121B79A170FEDFE521AEA1BC602BC536E1795E5F3 ] C:\Program Files\CCleaner\CCleaner64.exe
20:22:38.0642 0x08e4 CCleaner - ok
20:22:38.0649 0x08e4 Waiting for KSN requests completion. In queue: 13
20:22:39.0649 0x08e4 Waiting for KSN requests completion. In queue: 13
20:22:40.0649 0x08e4 Waiting for KSN requests completion. In queue: 13
20:22:41.0721 0x08e4 AV detected via SS2: avast! Antivirus, C:\Program Files\AVAST Software\Avast\VisthAux.exe ( 12.1.3076.0 ), 0x41000 ( enabled : updated )
20:22:41.0723 0x08e4 FW detected via SS2: avast! Antivirus, C:\Program Files\AVAST Software\Avast\VisthAux.exe ( 12.1.3076.0 ), 0x40010 ( disabled )
20:22:41.0726 0x08e4 Win FW state via NFP2: enabled ( trusted )
20:22:44.0549 0x08e4 ============================================================
20:22:44.0549 0x08e4 Scan finished
20:22:44.0549 0x08e4 ============================================================
20:22:44.0555 0x1518 Detected object count: 1
20:22:44.0555 0x1518 Actual detected object count: 1
20:23:05.0003 0x1518 \Device\Harddisk0\DR0\TDLFS - deleted
20:23:05.0003 0x1518 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Delete
20:23:09.0012 0x0714 Deinitialize success
 
--------------- QuickScript | g3n-h@ckm@n | V3_02.04.17.1 ---------------

----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 19/04/2017 20:24:50

Updated 02/04/2017 | 14.30 (GMT) by g3n-h@ckm@n
Contact : http://www.sosvirus.net/

Time Zone : (UTC-08:00) Pacific Time (US & Canada)
[Mitch (Administrator)] - [MITCH-PC] (S-1-5-21-2113883840-1160270776-2747418757-1000)

System: Microsoft Windows 7 Home Premium - Service Pack 1 - (6.1.7601) - BuildType: Multiprocessor Free - OSLanguage: 1033 (0409)
System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True
Boot : Microsoft Windows 7 Home Premium |C:\windows|\Device\Harddisk0\Partition2
Boot : Normal boot
PC: Satellite L755 - TOSHIBA - IdNumber: XB319792W - UUID: 71136460-FBBA-11E0-961F-047D7B056E26
Processor : X64 - 2394 Mhz - Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz
InsydeH2O Version 03.60.453.40 - en|US|iso8859-1 - INSYDE - S/N: XB319792W - 3.40 - TOSQCI - 1
CoreTemp : ? Celsius

----------| Script


Registry saved : C:\QuickDiag\Save\Registry [19.04.2017 @ 20_24_51]

Key : [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\87566282.sys] Deleted Successfully
Key : [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\87566282.sys] Deleted Successfully
Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Classes\Applications\FreeTorrentViewer.exe] Deleted Successfully
Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Blehjoqlir] Deleted Successfully
Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\MCAFEE] Deleted Successfully
Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Strongvault] Deleted Successfully
Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Tific] Not Found !
Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\AppDataLow\Software\Yahoo] Deleted Successfully
Key : [HKLM\Software\REGSERVO] Deleted Successfully
Key : [HKLM\Software\WOW6432Node\AdobeFlashPlayerUpdate] Deleted Successfully
Key : [HKLM\Software\WOW6432Node\Tific] Not Found !
Key : [HKLM\SYSTEM\CurrentControlSet\Control\Class\{522119B9-1B9A-498A-AC52-148B533EFD50}] Deleted Successfully
Key : [HKLM\SYSTEM\CurrentControlSet\Control\Class\{87C077B2-3D3B-4156-938A-EA51B451D6C6}] Deleted Successfully
Key : [HKLM\SYSTEM\CurrentControlSet\Control\Class\{FB58BE68-EA9E-4803-847F-2CE814E7B159}] Deleted Successfully
C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\extensions\ekdjfcdinekpfcedakhpngcnaamhiihn Moved Successfully
C:\Program Files (x86)\FreeTorrentViewer Moved Successfully
C:\windows\Installer\262be5.msi' Not Found !
C:\windows\Installer\9118a6.msi Moved Successfully
C:\windows\Installer\938618.msi Moved Successfully
C:\windows\System32\gatherNetworkInfo.vbs Moved Successfully
C:\Users\Mitch\AppData\Local\Tific Moved Successfully
C:\Users\Mitch\AppData\LocalLow\Yahoo! Not Found !
C:\Users\Mitch\AppData\Roaming\FreeTorrentViewer Moved Successfully
C:\Users\Mitch\AppData\Roaming\Tific Not Found !
C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeTorrentViewer Moved Successfully
C:\ProgramData\McAfee Moved Successfully
C:\ProgramData\REGSERVO64 Moved Successfully
C:\ProgramData\Yahoo! Not Found !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REGSERVO Moved Successfully
C:\Program Files (x86)\FreeTorrentViewer Not Found !
C:\Program Files (x86)\Yahoo! Not Found !
C:\ProgramData\Temp:373E1720 Not Moved ! -> Reboot !
C:\ProgramData\Temp:D1B5B4F1 Not Moved ! -> Reboot !
ADS : @C:\ProgramData\Temp:373E1720 Deleted successfully
ADS : @C:\ProgramData\Temp:D1B5B4F1 Deleted successfully

-------------- | CleanDisk :

FreeSpace : 411439
Cleaning.......
FreeSpace : 411439

----------(EOF)----------
 
I'd like you to re-run the Quick Diag fix, I had edited in a couple new items, just re run the entire fix for me, making sure to create a new restore point prior and reboot after.


Eliminate restrictive settings with this tool.

  • Temporarily disable your antivirus --- Your antivirus may flag this tool as malware, it is safe to run I assure you.
  • Download SupRestric.exe save to your desktop.
  • Close all running programs.
  • Double click the file to launch it.
  • Windows: 7/8/10 Vista and run as administrator
  • Click Yes at any prompt.
  • The analysis takes only a few moments.
  • The report is on the desktop ( CTR.txt )
  • Copy paste report in next reply.
  • A reboot is needed to complete the repairs.
HijackThis.



1- Please Click HERE to download HijackThis. -- Unzip to your desktop.
2- Right click run as admin.
3- Click on the Main Menu button if not already there.
4- Select Do a system scan and save a logfile.
5- Copy paste the log here.
 
AdsFix Scan and clean.
  • Disable Windows Defender, Firewall & Antivirus prior to running this tool!!
  • Save AdsFix to your desktop.
  • Right Click & Run As Administrator.
  • With an infected machine, it could take several seconds to be charged.
  • You will then be prompted to install Certificates.
  • Install then click OK.
  • Right Click & Run As Administrator Again.
2017-04-06_08h45_40-png.1937


  • Click Options then select Unlock the deletion.
  • Then click on clean.
  • Enter your country
  • Don’t use the machine while scanning and be patient
  • Once the scan has completed, please copy and paste the report in your next reply.
  • The report will be C:\AdsFix_date_hour.txt or on your dektop with the same name.

Then go ahead and remove the out dated version of malwarebytes that is installed.


Malwarebytes.
  • Download MalwareBytes Anti-Malware : https://www.malwarebytes.com/mwb-download/ take the free version ( on the left )
  • Perform the installation
  • Uncheck "Enable Free Trial of Malwarebytes Anti-Malware Premium" if it's asked
  • Malwarebytes will update, let this update,
  • Click on the "Settings" tab and then on the "Detection and Protection" tab, Check the box "Search for Rootkits"
  • Click on the "Analysis" tab and then on "Start analysis"
  • Once the review is complete, check that all detections are checked and then click [Delete Selection]
  • If Malwarebytes asks you to restart your PC, click "Yes"
  • When restarting your PC, restarts Malwarebytes
  • Opens the "History" tab and then "Application logs"
  • Double click on the last Scan Log in date (the one above)
  • At the bottom click [Export] -> select "Text file (* .txt)"
  • In the explorer selects the desktop, name it mbam.txt, click [Save]
 
re-ran quick fix:
--------------- QuickScript | g3n-h@ckm@n | V3_02.04.17.1 ---------------

----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 19/04/2017 20:49:25

Updated 02/04/2017 | 14.30 (GMT) by g3n-h@ckm@n
Contact : http://www.sosvirus.net/

Time Zone : (UTC-08:00) Pacific Time (US & Canada)
[Mitch (Administrator)] - [MITCH-PC] (S-1-5-21-2113883840-1160270776-2747418757-1000)

System: Microsoft Windows 7 Home Premium - Service Pack 1 - (6.1.7601) - BuildType: Multiprocessor Free - OSLanguage: 1033 (0409)
System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True
Boot : Microsoft Windows 7 Home Premium |C:\windows|\Device\Harddisk0\Partition2
Boot : Normal boot
PC: Satellite L755 - TOSHIBA - IdNumber: XB319792W - UUID: 71136460-FBBA-11E0-961F-047D7B056E26
Processor : X64 - 2394 Mhz - Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz
InsydeH2O Version 03.60.453.40 - en|US|iso8859-1 - INSYDE - S/N: XB319792W - 3.40 - TOSQCI - 1
CoreTemp : ? Celsius

----------| Script


Registry saved : C:\QuickDiag\Save\Registry [19.04.2017 @ 20_49_26]

Key : [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\87566282.sys] Not Found !
Key : [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\87566282.sys] Not Found !
Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Classes\Applications\FreeTorrentViewer.exe] Not Found !
Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Blehjoqlir] Not Found !
Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\MCAFEE] Not Found !
Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Strongvault] Not Found !
Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Tific] Not Found !
Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\AppDataLow\Software\Yahoo] Not Found !
Key : [HKLM\Software\REGSERVO] Not Found !
Key : [HKLM\Software\WOW6432Node\AdobeFlashPlayerUpdate] Not Found !
Key : [HKLM\Software\WOW6432Node\Tific] Not Found !
Key : [HKLM\SYSTEM\CurrentControlSet\Control\Class\{03F52937-1FD6-44FB-82C6-FE988F1B1D61}] Deleted Successfully
Key : [HKLM\SYSTEM\CurrentControlSet\Control\Class\{522119B9-1B9A-498A-AC52-148B533EFD50}] Deleted Successfully
Key : [HKLM\SYSTEM\CurrentControlSet\Control\Class\{87C077B2-3D3B-4156-938A-EA51B451D6C6}] Deleted Successfully
Key : [HKLM\SYSTEM\CurrentControlSet\Control\Class\{FB58BE68-EA9E-4803-847F-2CE814E7B159}] Deleted Successfully
C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\extensions\ekdjfcdinekpfcedakhpngcnaamhiihn Not Found !
C:\Program Files (x86)\FreeTorrentViewer Not Found !
C:\windows\Installer\262be5.msi' Not Found !
C:\windows\Installer\9118a6.msi Not Found !
C:\windows\Installer\938618.msi Not Found !
C:\windows\System32\gatherNetworkInfo.vbs Not Found !
C:\Users\Mitch\AppData\Local\Tific Not Found !
C:\Users\Mitch\AppData\LocalLow\Yahoo! Not Found !
C:\Users\Mitch\AppData\Roaming\FreeTorrentViewer Not Found !
C:\Users\Mitch\AppData\Roaming\Tific Not Found !
C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeTorrentViewer Not Found !
C:\ProgramData\McAfee Not Found !
C:\ProgramData\REGSERVO64 Not Found !
C:\ProgramData\Yahoo! Not Found !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REGSERVO Not Found !
C:\Program Files (x86)\FreeTorrentViewer Not Found !
C:\Program Files (x86)\Yahoo! Not Found !
C:\ProgramData\Temp:373E1720 Not Found !
C:\ProgramData\Temp:D1B5B4F1 Not Found !

-------------- | CleanDisk :

FreeSpace : 411401
Cleaning.......
FreeSpace : 411401

----------(EOF)----------
 
SuspRestrict
Report Restricted to Pierre13 (CTR version 2.5.0.0) of 19 \ 04 \ 2017 at 20:53:28
Mitch's PC
Microsoft Windows 7 Home Premium Service Pack 1 (64-bit) [6.1.7601]

Repair error 2203 performed.

Control presence restrictions

[BKDR_BLACKEN.A] key DisableFirstRunCustomize deleted.
[BKDR_BLACKEN.A] key WarnOnClose corrected.
Authorization installation Java (x86) deleted.
Authorization installation Java (x64) deleted.
Restriction Display Recent documents deleted.
Restriction Display Documents deleted.
Restriction Synchronization Background Information Streams and Web Slices Removed.
Restriction discovery of RSS feeds and Web Slices deleted.
Numeric keypad active.
User Restriction for Windows Installer Removed.
Windows Update Search Reverted.
Windows Firewall service enabled.
Windows Firewall settings restored by default and enabled.

240 controlled restrictions.

12 Restricted Restriction (s).
Reboot the PC to take the repair (s) into account.


The report is on the desktop (C: \ Users \ Mitch \ Desktop \ CTR.txt)
 
Logfile of HiJackThis Fork (Alpha) by Alex Dragokas v.2.6.4.17

Platform: x64 Windows 7 (Home Premium), 6.1.7601, Service Pack: 1
Time: 19.04.2017 - 20:57
Language: OS: English (0x409). Display: English (0x409). Non-Unicode: English (0x409)
Elevated: Yes
Ran by: Mitch (group: Administrator) on MITCH-PC

Chrome: 57.0.2987.133
Internet Explorer: 9.0.8112.16447

Boot mode: Normal

Running processes:
Number | Path
1 C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
1 C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
1 C:\Program Files (x86)\Giraffic\Veoh_Giraffic.exe
1 C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe
9 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
1 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
1 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
1 C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
1 C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
1 C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
1 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
1 C:\Program Files\AVAST Software\Avast\avastui.exe
1 C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
1 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
1 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
1 C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
1 C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
1 C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
1 C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
1 C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe
1 C:\Program Files\Toshiba\TECO\Teco.exe
1 C:\Program Files\Toshiba\TECO\TecoService.exe
1 C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSENotify.exe
1 C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
1 C:\Program Files\Toshiba\TPHM\TPCHSrv.exe
1 C:\Program Files\Toshiba\TPHM\TPCHWMsg.exe
1 C:\Program Files\Windows Media Player\wmpnetwk.exe
1 C:\Users\Mitch\Desktop\HiJackThis\HiJackThis.exe
1 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
1 C:\Windows\System32\SearchFilterHost.exe
1 C:\Windows\System32\SearchIndexer.exe
1 C:\Windows\System32\SearchProtocolHost.exe
1 C:\Windows\System32\TODDSrv.exe
1 C:\Windows\System32\audiodg.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\dwm.exe
1 C:\Windows\System32\lsass.exe
1 C:\Windows\System32\lsm.exe
1 C:\Windows\System32\notepad.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\spoolsv.exe
1 C:\Windows\System32\sppsvc.exe
9 C:\Windows\System32\svchost.exe
1 C:\Windows\System32\taskeng.exe
1 C:\Windows\System32\wbem\WmiPrvSE.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\explorer.exe

R4 - HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - Google - http://www.google.com/search?q={searchTerms}
O4 - HKCU\..\Run: [CCleaner] C:\Program Files\CCleaner\CCleaner64.exe /AUTO
O4 - HKLM\..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe /r
O4 - HKLM\..\Run: [TosNC] C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
O4 - HKLM\..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
O4 - HKLM\..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
O4 - HKLM\..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe
O4 - HKLM\..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe
O4 - HKLM\..\Run: [ZAM] C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe /minimized
O4 - HKLM\..\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe
O4 - HKU\S-1-5-19\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe /autoRun
O4 - HKU\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe
O4 - HKU\S-1-5-20\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe /autoRun
O4 - HKU\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe
O4-32 - HKLM\..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui
O4-32 - HKLM\..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe /CHECKNOW
O4-32 - HKLM\..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe UNATTENDED
O4-32 - HKLM\..\Run: [TSleepSrv] C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
O4-32 - HKLM\..\Run: [ToshibaAppPlace] C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe
O9-32 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (HKLM)
O9-32 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (HKLM)
O16-32 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0) - http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
O17 - DHCP DNS - 1: 192.168.1.1
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - Task (Disabled): \OfficeSoftwareProtectionPlatform\SvcRestartTask - C:\windows\system32\sc.exe start osppsvc
O22 - Task (Queued): \Microsoft\Windows Live\SOXE\Extractor Definitions Update Task - {3519154C-227E-47F3-9CC9-12C3F05817F1} - (no file)
O22 - Task (Queued): \Microsoft\Windows\Application Experience\ProgramDataUpdater - C:\windows\system32\rundll32.exe aepdu.dll,AePduRunUpdate
O22 - Task (Queued): avast! Emergency Update - C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
O22 - Task (Ready): CCleanerSkipUAC - C:\Program Files\CCleaner\CCleaner.exe $(Arg0)
O22 - Task (Ready): GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Task (Ready): GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O22 - Task (Ready): SafeZone scheduled Autoupdate 1463186051 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
O22 - Task (Ready): \AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs
O22 - Task (Ready): \Microsoft\Windows\Media Center\mcupdate_scheduled - C:\windows\ehome\mcupdate.exe -crl -hms -pscn 15
O22 - Task (Ready): \Microsoft\Windows\NetTrace\GatherNetworkInfo - C:\windows\system32\gatherNetworkInfo.vbs (file missing)
O22 - Task (Ready): \Microsoft\Windows\Windows Activation Technologies\ValidationTask - C:\windows\system32\Wat\WatAdminSvc.exe /run
O22 - Task (Ready): \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline - C:\windows\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask"
O22 - Task (Ready): {1426D1E5-5A00-4D59-985A-2107F1BEF83C} - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
O22 - Task (Ready): {2FB9F27A-DE3A-4CD6-B8B6-B233E63B6955} - C:\Program Files (x86)\Microsoft Office\Options14\MSOO.EXE
O22 - Task (Ready): {65C76270-92BA-4F63-B82C-13F0D18DD623} - C:\windows\system32\pcalua.exe -a "C:\Users\Mitch\Desktop\OpenOffice 4.1.1 (en-US) Installation Files\setup.exe" -d "C:\Users\Mitch\Desktop\OpenOffice 4.1.1 (en-US) Installation Files"
O22 - Task (Ready): {A8D2B036-36FC-403B-8061-05969D1469A2} - C:\Program Files (x86)\Microsoft Office\Options14\MSOO.EXE
O22 - Task (Ready): {E210F47C-43C1-4A1F-B297-CCB4BE5B7E4D} - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
O23 - Service R2: Avast Antivirus - (avast! Antivirus) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service R2: Intel(R) Management and Security Application Local Management Service - (LMS) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service R2: Intel(R) Management and Security Application User Notification Service - (UNS) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service R2: TOSHIBA Optical Disc Drive Service - (TODDSrv) - C:\Windows\system32\TODDSrv.exe
O23 - Service R2: TOSHIBA Power Saver - (TosCoSrv) - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service R2: TOSHIBA eco Utility Service - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service R2: Veoh Giraffic Video Accelerator - (Giraffic) - C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe
O23 - Service R2: ZAM Controller Service - (ZAMSvc) - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
O23 - Service R3: TOSHIBA HDD SSD Alert Service - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service R3: TPCH Service - (TPCHSrv) - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service S2: Google Update Service (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service S2: MBAMService - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service S3: Adobe Flash Player Update Service - (AdobeFlashPlayerUpdateSvc) - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service S3: GamesAppService - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service S3: Google Software Updater - (gusvc) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service S3: Google Update Service (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service S3: InstallDriver Table Manager - (IDriverT) - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service S3: TMachInfo - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe

--
End of file - Time spent: 15 sec. - 21546 bytes, CRC32: FFFFFFFF. Sign: ⁽ⷿ
 
: Hijack This Fix.

Start HijackThis , Right Click Run as Admin.
Close all other open programs prior to running this tool!!

Click System Scan Only.
Then check mark the items listed below.


O4 - HKLM\..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe /r
O4 - HKLM\..\Run: [TosNC] C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
O4 - HKLM\..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
O4 - HKLM\..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
O4 - HKLM\..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe
O4 - HKLM\..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe
O4 - HKLM\..\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe
O4 - HKU\S-1-5-19\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe /autoRun
O4 - HKU\S-1-5-20\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe /autoRun
O4-32 - HKLM\..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe /CHECKNOW
O4-32 - HKLM\..\Run: [TSleepSrv] C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
O4-32 - HKLM\..\Run: [ToshibaAppPlace] C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe
O22 - Task (Queued): \Microsoft\Windows Live\SOXE\Extractor Definitions Update Task - {3519154C-227E-47F3-9CC9-12C3F05817F1} - (no file)
O22 - Task (Queued): \Microsoft\Windows\Application Experience\ProgramDataUpdater - C:\windows\system32\rundll32.exe aepdu.dll,AePduRunUpdate
O22 - Task (Ready): \Microsoft\Windows\Media Center\mcupdate_scheduled - C:\windows\ehome\mcupdate.exe -crl -hms -pscn 15
O22 - Task (Ready): \Microsoft\Windows\NetTrace\GatherNetworkInfo - C:\windows\system32\gatherNetworkInfo.vbs (file missing)
O22 - Task (Ready): \Microsoft\Windows\Windows Activation Technologies\ValidationTask - C:\windows\system32\Wat\WatAdminSvc.exe /run
O22 - Task (Ready): \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline - C:\windows\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask"
O22 - Task (Ready): {1426D1E5-5A00-4D59-985A-2107F1BEF83C} - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
O23 - Service R2: TOSHIBA Power Saver - (TosCoSrv) - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service R2: TOSHIBA eco Utility Service - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service S3: Adobe Flash Player Update Service - (AdobeFlashPlayerUpdateSvc) - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service S3: GamesAppService - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe




Now click on fix checked.
After the fix is complete, then reboot your machine.
 
We got a problem. My friend had to leave and had me close the AdsFix program when it was at 51%. It had deleted 41 items by then, but I couldn't grab any log file. I will see him again next week, would interrupting that fix cause any significant issues? And are you willing to wait a week to continue with the logs/fixes?
 
Just checking in, my friend will be here in a few hours, what should the first step be? Should I re-run the Adsfix and let it finish or move on to another step?
 
I'd also like you to re run ZHP Diag, there was an update that should have fixed the error. It now runs on my machine. Delete the copy that you have and re run please...


ZHP Diag Scan



Download ZHP Diag to your desktop.


1. Right Click Run as Admin.

2. Click the Options button.

Click on Check All
Then Click Validate
Then click close.

upload_2017-4-26_17-16-39.png





2. Click the Scanner button.


upload_2017-2-23_3-32-26-png.1647



When complete please push the report button.
A notepad will open... copy and paste the report in your next reply.
 
Last edited:
Here's the AdsFix log. The previous entries did not re-appear so I can't know what those were unfortunately.


---------- | AdsFix | g3n-h@ckm@n | V4_05.04.17.1

----- Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- Start 21:01:30 - 19/04/2017

update on : 05/04/2017 | 12.10 (GMT) by g3n-h@ckm@n
Contact : http://www.sosvirus.net
Assistance : http://www.sosvirus.net/forum-virus-securite.html
Feedbacks : http://www.sosvirus.net/feedbacks-t75915.html
Facebook : https://www.facebook.com/AdsFixAntiAdware
C:\Users\Mitch\Desktop\AdsFix.exe
Boot: Normal boot
[Mitch (Administrator)] - [MITCH-PC] - (united states [0409])
SID = S-1-5-21-2113883840-1160270776-2747418757-1000 || [4d69746368205e5e]
PC : Intel Corp. - Base Board Product Name - PSK1WU-0P4048
Processor : X64 - 2394 - Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz
Bios : INSYDE - 06/08/2012 - V.3.40
CoreTemp : ? C


System : Windows 7 Home Premium (64 bits) HomePremium Service Pack 1
RAM memory = Total (MB) : 4141 | Free (MB) : 2320
Pagefile = Total (MB) : 8280 | Free (MB) : 6289
Virtual = Total (MB) : 4194 | Free (MB) : 3971

C:\ -> [Fixed] | [TI106234W0C] | Total : 449.77 Go | Free : 404.76 Go -> NTFS [ATA]

Registry saved, to restore : Click on Options & Restore the register (C:\AdsFix\Save\Registry [19.04.2017 @ 21_01_28]) or an element
Restore files or folders deleted by mistake : Click on Options & Restore Files | Folders, Select an item >> "restore"

---------- | Windows Updates

Last detection : 2012-08-12 21:11:03
Last downloaded : 2012-11-16 02:18:27
Last installation : 2012-11-16 03:04:58
Next search : 2017-04-20 03:55:12

Windows Is Activated

---------- | Browsers

IE : 9.0.8112.16447 (© Microsoft Corporation. All rights reserved.)
GC : 57.0.2987.133 (Copyright 2016 Google Inc. All rights reserved.)

---------- | Security (atcav : 0)

AM : Malwarebytes' Anti-Malware (2.3.55.0) [Update : 08/09/2015 10:46:40]
FW : avast! Antivirus Disabled
WMI : OK
WU: Windows Update Service [Auto(2)] = Order
FW: Windows FireWall Service [Auto(2)] = Order
WMI: Windows Management Instrumentation (System Information) [Auto(2)] = Started

---------- | FlashPlayer

ActiveX : 18.0.0.232
Plugin : 18.0.0.232

---------- | Killed processes

1424 | [Owner : SYSTEM |Parent : 724(services.exe)] - (.Microsoft Corporation - Spooler SubSystem App.) - (6.1.7601.17514) = C:\Windows\System32\spoolsv.exe
1492 | [Owner : SYSTEM |Parent : 464(svchost.exe)] - (.Microsoft Corporation - Task Scheduler Engine.) - (6.1.7601.17514) = C:\Windows\System32\taskeng.exe
1668 | [Owner : SYSTEM |Parent : 724(services.exe)] - (.Giraffic - Giraffic Video Accelerator Watchdog.) - (0.86.412.230) = C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe
1896 | [Owner : SYSTEM |Parent : 724(services.exe)] - (.Microsoft Corporation - Microsoft Application Virtualization Virtual Service Agent.) - (4.6.2.22610) = C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
2068 | [Owner : SYSTEM |Parent : 724(services.exe)] - (.TOSHIBA Corporation - TDCSrv Application.) - (1.0.0.8) = C:\Windows\System32\TODDSrv.exe
2096 | [Owner : SYSTEM |Parent : 724(services.exe)] - (.TOSHIBA Corporation - TOSHIBA Power Saver.) - (1.0.0.5) = C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
2104 | [Owner : SYSTEM |Parent : 1668()] - (.Giraffic - Giraffic Video Accelerator.) - (0.86.412.230) = C:\Program Files (x86)\Giraffic\Veoh_Giraffic.exe
2312 | [Owner : SYSTEM |Parent : 724(services.exe)] - (.Microsoft Corp. - Microsoft® Windows Live ID Service.) - (7.250.4232.0) = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
2384 | [Owner : SYSTEM |Parent : 724(services.exe)] - (.Copyright 2017. - ZAM.) - (2.72.0.101) = C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
2552 | [Owner : SYSTEM |Parent : 724(services.exe)] - (.Microsoft Corporation - Microsoft Application Virtualization Client Service.) - (4.6.2.22610) = C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
2960 | [Owner : SYSTEM |Parent : 724(services.exe)] - (.TOSHIBA Corporation - TOSHIBA eco Utility Service.) - (1.3.0.0) = C:\Program Files\Toshiba\TECO\TecoService.exe
3420 | [Owner : Mitch |Parent : 3212(explorer.exe)] - (.TOSHIBA Corporation - TOSHIBA Power Saver.) - (1.0.0.7) = C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
3596 | [Owner : SYSTEM |Parent : 724(services.exe)] - (.Microsoft Corporation - Microsoft Office Client Virtualization Service.) - (14.0.6114.5003) = C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
3684 | [Owner : Mitch |Parent : 3212(explorer.exe)] - (.TOSHIBA Corporation - TOSHIBA Flash Cards Main Module.) - (1.0.11.64) = C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
3904 | [Owner : Mitch |Parent : 3212(explorer.exe)] - (.Conexant Systems, Inc. - Conexant High Definition Audio Filter Agent.) - (1.7.32.0) = C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
4076 | [Owner : LOCAL SERVICE |Parent : 724(services.exe)] - (.Microsoft Corporation - PresentationFontCache.exe.) - (3.0.6920.5011) = C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
2860 | [Owner : Mitch |Parent : 3212(explorer.exe)] - (.TOSHIBA Corporation - TOSHIBA eco Utility.) - (1.3.0.0) = C:\Program Files\Toshiba\TECO\Teco.exe
3076 | [Owner : Mitch |Parent : 3212(explorer.exe)] - (.TOSHIBA Corporation - Message Center.) - (1.6.0.64) = C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
3280 | [Owner : Mitch |Parent : 3212(explorer.exe)] - (.TOSHIBA Corporation - Monitor of TOSHIBA ReelTime.) - (1.7.9.0) = C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe
1136 | [Owner : Mitch |Parent : 3488()] - (.- DivX Update.) - (1.0.6.15) = C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
4376 | [Owner : Mitch |Parent : 5116()] - (.Microsoft Corporation - Notepad.) - (6.1.7600.16385) = C:\Windows\System32\notepad.exe
3724 | [Owner : Mitch |Parent : 3212(explorer.exe)] - (.Google Inc. - Google Chrome.) - (57.0.2987.133) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
3500 | [Owner : Mitch |Parent : 3724(chrome.exe)] - (.Google Inc. - Google Chrome.) - (57.0.2987.133) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
3224 | [Owner : Mitch |Parent : 3724(chrome.exe)] - (.Google Inc. - Google Chrome.) - (57.0.2987.133) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
3296 | [Owner : SYSTEM |Parent : 724(services.exe)] - (.Intel Corporation - Local Manageability Service.) - (7.0.2.1164) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
2976 | [Owner : NETWORK SERVICE |Parent : 724(services.exe)] - (.Microsoft Corporation - Windows Media Player Network Sharing Service.) - (12.0.7601.17514) = C:\Program Files\Windows Media Player\wmpnetwk.exe
2804 | [Owner : SYSTEM |Parent : 724(services.exe)] - (.TOSHIBA Corporation - TOSHIBA PC Health Monitor.) - (1.0.0.17) = C:\Program Files\Toshiba\TPHM\TPCHSrv.exe
4580 | [Owner : SYSTEM |Parent : 724(services.exe)] - (.TOSHIBA Corporation - TosSmartSrv.exe.) - (1.1.0.8) = C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
4976 | [Owner : Mitch |Parent : 2892()] - (.TOSHIBA Corporation - TosSENotify.exe.mui.) - (1.0.64.16) = C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSENotify.exe
4300 | [Owner : Mitch |Parent : 1536()] - (.TOSHIBA Corporation - TOSHIBA PC Health Monitor.) - (1.0.0.10) = C:\Program Files\Toshiba\TPHM\TPCHWMsg.exe
2164 | [Owner : SYSTEM |Parent : 724(services.exe)] - (.Intel Corporation - User Notification Service.) - (7.0.2.1164) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
304 | [Owner : NETWORK SERVICE |Parent : 724(services.exe)] - (.Microsoft Corporation - Microsoft Software Protection Platform Service.) - (6.1.7601.17514) = C:\Windows\System32\sppsvc.exe

---------- | Tasks



---------- | Services

Service : WINDEFEND : Restored

---------- | AppCertDlls | AppInit_DLLs


---------- | DNSapi.dll

C:\windows\System32\dnsapi.dll : \drivers\etc\hosts
C:\windows\SysWOW64\dnsapi.dll : \drivers\etc\hosts

---------- | Hosts


---------- | SafeBoot


---------- | Winsock


---------- | DNS


---------- | Register

Deleted successfully : HKLM\SOFTWARE\Classes\YahooAUService.BCCImpl : BCCImpl Class
Deleted successfully : HKLM\SOFTWARE\Classes\YahooAUService.BCCImpl.1 : BCCImpl Class
Deleted successfully : HKLM\SOFTWARE\Classes\YahooAUService.YAUEnumJob : YAUEnumJob Class
Deleted successfully : HKLM\SOFTWARE\Classes\YahooAUService.YAUEnumJob.1 : YAUEnumJob Class
Deleted successfully : HKLM\SOFTWARE\Classes\YahooAUService.YAUJob.1 : YAUJob Class
Deleted successfully : HKLM\SOFTWARE\Classes\YahooAUService.YAUManager.1 : YAUManager Class
Deleted successfully : HKLM\SOFTWARE\Classes\AppID\protector_dll.DLL : #
Deleted successfully : HKLM\SOFTWARE\Classes\AppID\YahooAUService.EXE : #
Deleted successfully : HKLM\SOFTWARE\Classes\AppID\{51B4D471-086A-4137-AD28-84EED05088AE} : SuperfishIEAddon #
Deleted successfully : HKLM\SOFTWARE\Classes\AppID\{96FBC13C-8214-4100-88E0-FF74D7A1CB4D} : protector_dll #
Deleted successfully : HKLM\SOFTWARE\Classes\AppID\{C1352D97-77A9-4DD5-8042-BA14D5C8E266} : YahooAUService #
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\Classes\YahooAUService.YAUJob : YAUJob Class
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4BB3A9A2-28E2-492D-A01A-62E95656B4CD}
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7666F922-5FCE-40DB-877A-793329B9D84E}
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{90AFF435-B544-4F94-A0C2-CC020EACA4E3}
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{93D47509-1A2B-4D7C-A0F7-85C80B6F31A5}
Deleted successfully : HKLM\SOFTWARE\Classes\TypeLib\{9F5C5784-A417-472C-81F6-336A2981B26E} : C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
Deleted successfully : HKLM\SOFTWARE\Classes\TypeLib\{A10D8738-B424-49F5-AE07-682C60F77D12} : C:\PROGRA~2\COMMON~1\ULEADS~1\DVD\LXBURN~1.DLL
Deleted successfully : HKLM\SOFTWARE\Classes\Interface\{5C05E85E-B0E8-453E-8DD8-8FCA7B8F797A} : {9F5C5784-A417-472C-81F6-336A2981B26E}
Deleted successfully : HKLM\Software\Classes\WOW6432Node\Interface\{5C05E85E-B0E8-453E-8DD8-8FCA7B8F797A} : {9F5C5784-A417-472C-81F6-336A2981B26E}
Deleted successfully : HKLM\SOFTWARE\Classes\Interface\{B029974B-0BC4-424D-9363-F5D494D2A9BD} : {9F5C5784-A417-472C-81F6-336A2981B26E}
Deleted successfully : HKLM\Software\Classes\WOW6432Node\Interface\{B029974B-0BC4-424D-9363-F5D494D2A9BD} : {9F5C5784-A417-472C-81F6-336A2981B26E}
Deleted successfully : HKLM\SOFTWARE\Classes\Interface\{B6AF2444-EA13-40E0-8948-78E7AE610862} : {9F5C5784-A417-472C-81F6-336A2981B26E}
Deleted successfully : HKLM\Software\Classes\WOW6432Node\Interface\{B6AF2444-EA13-40E0-8948-78E7AE610862} : {9F5C5784-A417-472C-81F6-336A2981B26E}
Deleted successfully : HKLM\SOFTWARE\Classes\Interface\{BF838BD9-E55F-4A01-ABBA-B2171E63A35B} : {9F5C5784-A417-472C-81F6-336A2981B26E}
Deleted successfully : HKLM\Software\Classes\WOW6432Node\Interface\{BF838BD9-E55F-4A01-ABBA-B2171E63A35B} : {9F5C5784-A417-472C-81F6-336A2981B26E}
Deleted successfully : HKLM\SOFTWARE\Classes\Interface\{C186994A-066E-4D08-8F33-CF1262640A4C} : {9F5C5784-A417-472C-81F6-336A2981B26E}
Deleted successfully : HKLM\Software\Classes\WOW6432Node\Interface\{C186994A-066E-4D08-8F33-CF1262640A4C} : {9F5C5784-A417-472C-81F6-336A2981B26E}
Deleted successfully : HKLM\SOFTWARE\Classes\Interface\{D00A1789-6A8F-4AEB-A723-8ED53D445957} : {9F5C5784-A417-472C-81F6-336A2981B26E}
Deleted successfully : HKLM\Software\Classes\WOW6432Node\Interface\{D00A1789-6A8F-4AEB-A723-8ED53D445957} : {9F5C5784-A417-472C-81F6-336A2981B26E}
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3459D5C6-ED0D-450E-AAA7-E18B952A4A49} : {A10D8738-B424-49F5-AE07-682C60F77D12}
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7CB88608-C06A-41A5-89DE-79AD6A8A7E1F} : {A10D8738-B424-49F5-AE07-682C60F77D12}
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9FE3269F-9610-43DD-9478-8373CAFE17DC} : {A10D8738-B424-49F5-AE07-682C60F77D12}
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C3CDB7DC-2B68-43CC-BBBA-D09BBCF4BE88} : {A10D8738-B424-49F5-AE07-682C60F77D12}
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E691B211-582E-486A-A9BD-01559020156B} : {A10D8738-B424-49F5-AE07-682C60F77D12}
Deleted successfully : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\TBSBtnCfg.exe
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\TBSbtnSt.exe
Deleted successfully : HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\AI_RecycleBin
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\NPCCU
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\PCTools
---------- | AdsFix | g3n-h@ckm@n | V4_05.04.17.1

----- Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- Start 15:48:41 - 26/04/2017

update on : 05/04/2017 | 12.10 (GMT) by g3n-h@ckm@n
Contact : http://www.sosvirus.net
Assistance : http://www.sosvirus.net/forum-virus-securite.html
Feedbacks : http://www.sosvirus.net/feedbacks-t75915.html
Facebook : https://www.facebook.com/AdsFixAntiAdware
C:\Users\Mitch\Desktop\AdsFix.exe
Boot: Normal boot
[Mitch (Administrator)] - [MITCH-PC] - (Unied States [0409])
SID = S-1-5-21-2113883840-1160270776-2747418757-1000 || [4d69746368205e5e]
PC : Intel Corp. - Base Board Product Name - PSK1WU-0P4048
Processor : X64 - 2394 - Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz
Bios : INSYDE - 06/08/2012 - V.3.40
CoreTemp : ? C


System : Windows 7 Home Premium (64 bits) HomePremium Service Pack 1
RAM memory = Total (MB) : 4141 | Free (MB) : 2863
Pagefile = Total (MB) : 8280 | Free (MB) : 6977
Virtual = Total (MB) : 4194 | Free (MB) : 3945

C:\ -> [Fixed] | [TI106234W0C] | Total : 449.77 Go | Free : 405.64 Go -> NTFS [ATA]

Registry saved, to restore : Click on Options & Restore the register (C:\AdsFix\Save\Registry [26.04.2017 @ 15_48_40]) or an element
Restore files or folders deleted by mistake : Click on Options & Restore Files | Folders, Select an item >> "restore"

---------- | Windows Updates

Last detection : 2012-08-12 21:11:03
Last downloaded : 2012-11-16 02:18:27
Last installation : 2012-11-16 03:04:58
Next search : 2017-04-26 01:45:49

Windows Is Activated

---------- | Browsers

IE : 9.0.8112.16447 (© Microsoft Corporation. All rights reserved.)
GC : 57.0.2987.133 (Copyright 2016 Google Inc. All rights reserved.)

---------- | Security (atcav : 0)

AM : Malwarebytes' Anti-Malware (2.3.55.0) [Update : 08/09/2015 10:46:40]
FW : avast! Antivirus Disabled
WMI : OK
WU: Windows Update Service [Auto(2)] = Started
AS: Windows Defender [Manual(3)] = Order
FW: Windows FireWall Service [Auto(2)] = Order
WMI: Windows Management Instrumentation (System Information) [Auto(2)] = Started

---------- | FlashPlayer

ActiveX : 18.0.0.232
Plugin : 18.0.0.232

---------- | Killed processes

1612 | [Owner : SYSTEM |Parent : 712(services.exe)] - (.Microsoft Corporation - Spooler SubSystem App.) - (6.1.7601.17514) = C:\Windows\System32\spoolsv.exe
1824 | [Owner : SYSTEM |Parent : 712(services.exe)] - (.Giraffic - Giraffic Video Accelerator Watchdog.) - (0.86.412.230) = C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe
1384 | [Owner : SYSTEM |Parent : 1824()] - (.Giraffic - Giraffic Video Accelerator.) - (0.86.412.230) = C:\Program Files (x86)\Giraffic\Veoh_Giraffic.exe
1452 | [Owner : Mitch |Parent : 1512(explorer.exe)] - (.TOSHIBA Corporation - TOSHIBA Power Saver.) - (1.0.0.7) = C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
536 | [Owner : Mitch |Parent : 1512(explorer.exe)] - (.TOSHIBA Corporation - TOSHIBA Flash Cards Main Module.) - (1.0.11.64) = C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
2080 | [Owner : Mitch |Parent : 1512(explorer.exe)] - (.Conexant Systems, Inc. - Conexant High Definition Audio Filter Agent.) - (1.7.32.0) = C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
2372 | [Owner : SYSTEM |Parent : 712(services.exe)] - (.Microsoft Corporation - Microsoft Application Virtualization Virtual Service Agent.) - (4.6.2.22610) = C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
2432 | [Owner : Mitch |Parent : 1512(explorer.exe)] - (.TOSHIBA Corporation - TOSHIBA eco Utility.) - (1.3.0.0) = C:\Program Files\Toshiba\TECO\Teco.exe
2504 | [Owner : Mitch |Parent : 1512(explorer.exe)] - (.TOSHIBA Corporation - Toshiba Volume Regulator.) - (1.0.0.6) = C:\Program Files\Toshiba\TosVolRegulator\TosVolRegulator.exe
2584 | [Owner : SYSTEM |Parent : 712(services.exe)] - (.TOSHIBA Corporation - TDCSrv Application.) - (1.0.0.8) = C:\Windows\System32\TODDSrv.exe
2600 | [Owner : Mitch |Parent : 1512(explorer.exe)] - (.TOSHIBA Corporation - Message Center.) - (1.6.0.64) = C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
2616 | [Owner : Mitch |Parent : 1512(explorer.exe)] - (.TOSHIBA Corporation - Monitor of TOSHIBA ReelTime.) - (1.7.9.0) = C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe
2660 | [Owner : SYSTEM |Parent : 712(services.exe)] - (.TOSHIBA Corporation - TOSHIBA Power Saver.) - (1.0.0.5) = C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
2828 | [Owner : SYSTEM |Parent : 712(services.exe)] - (.Microsoft Corp. - Microsoft® Windows Live ID Service.) - (7.250.4232.0) = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
2912 | [Owner : SYSTEM |Parent : 712(services.exe)] - (.Copyright 2017. - ZAM.) - (2.72.0.101) = C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
3040 | [Owner : Mitch |Parent : 2856()] - (.- DivX Update.) - (1.0.6.15) = C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2096 | [Owner : Mitch |Parent : 376(svchost.exe)] - (.Microsoft Corporation - Task Scheduler Engine.) - (6.1.7601.17514) = C:\Windows\System32\taskeng.exe
3012 | [Owner : SYSTEM |Parent : 712(services.exe)] - (.Microsoft Corporation - Microsoft Application Virtualization Client Service.) - (4.6.2.22610) = C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
3212 | [Owner : SYSTEM |Parent : 712(services.exe)] - (.TOSHIBA Corporation - TOSHIBA eco Utility Service.) - (1.3.0.0) = C:\Program Files\Toshiba\TECO\TecoService.exe
3372 | [Owner : SYSTEM |Parent : 712(services.exe)] - (.Microsoft Corporation - Microsoft Office Client Virtualization Service.) - (14.0.6114.5003) = C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
4864 | [Owner : NETWORK SERVICE |Parent : 712(services.exe)] - (.Microsoft Corporation - Microsoft Distributed Transaction Coordinator Service.) - (2001.12.8530.16385) = C:\Windows\System32\msdtc.exe
2468 | [Owner : SYSTEM |Parent : 712(services.exe)] - (.TOSHIBA Corporation - TOSHIBA PC Health Monitor.) - (1.0.0.17) = C:\Program Files\Toshiba\TPHM\TPCHSrv.exe
4412 | [Owner : SYSTEM |Parent : 712(services.exe)] - (.TOSHIBA Corporation - TosSmartSrv.exe.) - (1.1.0.8) = C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
1164 | [Owner : Mitch |Parent : 2556()] - (.TOSHIBA Corporation - TosSENotify.exe.mui.) - (1.0.64.16) = C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSENotify.exe
4996 | [Owner : Mitch |Parent : 2496()] - (.TOSHIBA Corporation - TOSHIBA PC Health Monitor.) - (1.0.0.10) = C:\Program Files\Toshiba\TPHM\TPCHWMsg.exe
384 | [Owner : SYSTEM |Parent : 712(services.exe)] - (.Intel Corporation - Local Manageability Service.) - (7.0.2.1164) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
4396 | [Owner : NETWORK SERVICE |Parent : 712(services.exe)] - (.Microsoft Corporation - Windows Media Player Network Sharing Service.) - (12.0.7601.17514) = C:\Program Files\Windows Media Player\wmpnetwk.exe
4616 | [Owner : SYSTEM |Parent : 712(services.exe)] - (.Intel Corporation - User Notification Service.) - (7.0.2.1164) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

---------- | Tasks



---------- | Services


---------- | AppCertDlls | AppInit_DLLs


---------- | DNSapi.dll

C:\windows\System32\dnsapi.dll : \drivers\etc\hosts
C:\windows\SysWOW64\dnsapi.dll : \drivers\etc\hosts

---------- | Hosts


---------- | SafeBoot


---------- | Winsock


---------- | DNS


---------- | Register

Deleted successfully : HKLM\SOFTWARE\Classes\YahooAUService.YAUManager : YAUManager Class
Deleted successfully : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]~[DefaultScope] : {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Deleted successfully : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes]~[DefaultScope]
Deleted successfully : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\690D05DFEA2A0F04DB7236B2BC991975 : 02:\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}\
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Software Update : (Yahoo! Software Update) C:\PROGRA~2\Yahoo!\SOFTWA~1\UNINST~1.EXE

---------- | Folders | Files

Deleted successfully : C:\Program Files (x86)\Netwaiting\Aboutn.dll (Copyright © Avanquest Software 2009.-.About) ABOUTN.DLL
Deleted successfully : C:\Program Files (x86)\Netwaiting\NetWaiting.exe (Copyright © Avanquest Software 1997-2008.-.NetWaiting) netwaiting.exe
Deleted successfully : C:\Program Files (x86)\Common Files\PC Tools
Deleted successfully : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetZero\NetZero Internet Service.lnk (.-.)
Deleted successfully : C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cfhdojbkjhnklbpkdaibdccddilifddb
Deleted successfully : C:\Users\Mitch\Documents\My Web Backups
Deleted successfully : C:\ProgramData\PC Tools
Deleted successfully : C:\Users\John\AppData\Local\Temp
Deleted successfully : C:\Users\Mitch\AppData\Local\Apps
Deleted successfully : C:\Users\Mitch\AppData\Local\DDMSettings

---------- | .LNK


---------- | opening unknown extension


---------- | Proxy


---------- | Internet Explorer

Repaired : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main]~[Local Page] : C:\Windows\SysWOW64\blank.htm -> C:\windows\System32\blank.htm
Repaired : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter]~[Enabled] : -> 2
Repaired : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter]~[EnabledV8] : -> 1
Repaired : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet settings]~[WarNonBadCertReceving] : -> 1
Repaired : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet settings]~[WarNonHTTPSToHTTPRedirect] : -> 1

---------- | Yandex : X

---------- | Google Chrome

Deleted successfully : C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Web Data (.-.) Reseted successfully : SearchURL
Deleted successfully : C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Preferences (.-.) Reseted successfully : Preferences
Deleted successfully : C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Web Data (.-.) Reseted successfully : SearchURL
Deleted successfully : C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Preferences (.-.) Reseted successfully : Preferences
Deleted successfully : C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (.-.) Reseted successfully : Preferences
Deleted successfully : C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\extensions\cfhdojbkjhnklbpkdaibdccddilifddb = (Changelog)
Deleted successfully : C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\extensions\nlgfkngkdcjlfgcfdmjoafonkkhacilj = perisistent: false
Deleted successfully : C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm = ids: [ idmofbkcelhplfjnmmdolenpigiiiecc ggedfkijiiammpnbdadhllnehapomdge njjegkblellcjnakomndbaloifhcoccg ]

C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo = : Google & co - http://www.youtube.com - http://www.youtube.com/ - Google & co - http://clients2.google.com/service/update2/crx
C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\extensions\coobgpohoikkiipiblmjeljniedjpjpf = : Google & co - http://www.google.com/webhp?source=search_app - Google & co - [*://www.google.com/search*://www.google.com/webhp*://www.google.com/imgres] - http://clients2.google.com/service/update2/crx
C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\extensions\nneajnkjbffgblleaoojgaacokifdkhm = : __MSG_extdesc__ - __MSG_extname__
C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\extensions\pjkljhegncpnkpknbcohdijeoejaedia = : Google & co - https://mail.google.com/mail/ca - Google & co - [*://mail.google.com/mail/ca] - http://clients2.google.com/service/update2/crx
C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\extensions\gomekmidlodglbbmalcneegieacbdmki = : Avast Browser Security and Web Reputation Plugin. - Avast Online Security - matches:[\u003Call_urls>] - https://clients2.google.com/service/update2/crx
C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\extensions\nmmhkkegccagdldgiimedpiccmgmieda = : Google & co - Google & co - 203784468217.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx
C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\extensions\nneajnkjbffgblleaoojgaacokifdkhm = : __MSG_extdesc__ - __MSG_extname__

---------- | SrWare Iron : X

---------- | Comodo Dragon : X

---------- | Firefox : X

---------- | SeaMonkey : X

---------- | Pale moon : X

---------- | Opera : X

---------- | Spark (Baidu) : X

---------- | StartMenuInternet


---------- | Javascript


---------- | Firewall


---------- | ADS


Other(s) report(s)


Analyzed : 411216 | Modified : 5 | Deleted : 23

---------- |EOF| ---------- | 17:21:48 | [27 Ko]
 
  • Like
Reactions: Malnutrition
Ran the HighjackThis fix, and updated and ran MWB here's the found log, quarantined all and the ZHPDiag scan. Next step?

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 4/26/17
Scan Time: 6:13 PM
Logfile: mbam.txt
Administrator: Yes

-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.103
Update Package Version: 1.0.1816
License: Free

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Mitch-PC\Mitch

-Scan Summary-
Scan Type: Custom Scan
Result: Completed
Objects Scanned: 173782
Time Elapsed: 1 hr, 24 min, 56 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 2
PUP.Optional.REGServo, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\REGSERVO.exe, No Action By User, [2028], [366351],1.0.1816
PUP.Optional.REGServo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\REGSERVO.exe, No Action By User, [2028], [366351],1.0.1816

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 2
Trojan.Injector.BHO, C:\SETTINGS.INI, No Action By User, [16597], [302129],1.0.1816
PUP.Optional.REGServo, C:\USERS\MITCH\DOWNLOADS\REGSERVO_SETUP_2.1.6.EXE, No Action By User, [2028], [344366],1.0.1816

Physical Sector: 0
(No malicious items detected)


(end)

~ ZHPDiag v2017.4.26.72 By Nicolas Coolman (2017/04/26)
~ Run by Mitch (Administrator) (2017/04/26 19:44:43)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ State version: Version KO
~ Mode: Scan
~ Report: C:\Users\Mitch\Desktop\ZHPDiag.txt
~ Report: C:\Users\Mitch\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ System startup: Normal (Normal boot)
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601) =>.Microsoft Corporation

---\\ Internet Browsers (2) - 0s
~ GCIE: Google Chrome v57.0.2987.133
~ MSIE: Internet Explorer v9.0.8112.16421

---\\ Windows Product Information (4) - 0s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ System protection software (1) - 2s
Avast Free Antivirus v12.1.2272 (Protection)

---\\ System protection software (Superfluous) (1) - 2s
~ Zemana AntiMalware v2.72.101 (Superfluous)

---\\ Surveillance software (2) - 2s
~ Adobe Flash Player 18 NPAPI (Surveillance)
~ Adobe Reader X MUI (Surveillance)

---\\ Information on the system (6) - 0s
~ Operating System: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 4140.912 MB (70% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 411 GB (89%) free of 460 GB : OK =>.Disk Space

---\\ Connection to the system mode (3) - 0s
~ Computer Name: MITCH-PC
~ User Name: Mitch
~ Logged in as Administrator

---\\ Enumeration of the disk units (1) - 0s
~ Drive C: has 411 GB free of 460 GB (System)

---\\ State of the Windows Security Center (12) - 0s
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] WarnOnHTTPSToHTTPRedirect: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Search Generic System Files (24) - 1s
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - 24/02/2011 - (.Microsoft Corporation - Windows Explorer.) -- C:\windows\Explorer.exe [2871808] =>.Microsoft Corporation
[MD5.DD81D91FF3B0763C392422865C9AC12E] - 13/07/2009 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\windows\System32\rundll32.exe [45568] =>.Microsoft Corporation
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - 13/07/2009 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\windows\System32\Wininit.exe [129024] =>.Microsoft Corporation
[MD5.5A45FA344F4AD99D903F4B20E43B89EC] - 02/06/2012 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\windows\System32\wininet.dll [1392128] =>.Microsoft Corporation
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - 20/11/2010 - (.Microsoft Corporation - Windows Logon Application.) -- C:\windows\System32\Winlogon.exe [390656] =>.Microsoft Corporation
[MD5.067FA52BFB59A56110A12312EF9AF243] - 20/11/2010 - (.Microsoft Corporation - Software Licensing Library.) -- C:\windows\System32\sppcomapi.dll [232448] =>.Microsoft Corporation
[MD5.492D07D79E7024CA310867B526D9636D] - 02/03/2011 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\windows\System32\dnsapi.dll [357888] =>.Microsoft Corporation
[MD5.B40420876B9288E0A1C8CCA8A84E5DC9] - 02/03/2011 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\windows\Syswow64\dnsapi.dll [270336] =>.Microsoft Corporation
[MD5.1C7857B62DE5994A75B054A9FD4C3825] - 27/12/2011 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\windows\System32\drivers\AFD.sys [498688] =>.Microsoft Corporation
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - 13/07/2009 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\windows\System32\drivers\atapi.sys [24128] =>.Microsoft Windows®
[MD5.B8BD2BB284668C84865658C77574381A] - 13/07/2009 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\windows\System32\drivers\Cdfs.sys [92160] =>.Microsoft Corporation
[MD5.F036CE71586E93D94DAB220D7BDF4416] - 20/11/2010 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\windows\System32\drivers\Cdrom.sys [147456] =>.Microsoft Corporation
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - 20/11/2010 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\windows\System32\drivers\DfsC.sys [102400] =>.Microsoft Corporation
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - 20/11/2010 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\windows\System32\drivers\HDAudBus.sys [122368] =>.Microsoft Corporation
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - 13/07/2009 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\windows\System32\drivers\i8042prt.sys [105472] =>.Microsoft Corporation
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - 13/07/2009 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\windows\System32\drivers\IpNat.sys [116224] =>.Microsoft Corporation
[MD5.A5D9106A73DC88564C825D317CAC68AC] - 26/04/2011 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\windows\System32\drivers\MRxSmb.sys [158208] =>.Microsoft Corporation
[MD5.09594D1089C523423B32A4229263F068] - 20/11/2010 - (.Microsoft Corporation - MBT Transport driver.) -- C:\windows\System32\drivers\netBT.sys [261632] =>.Microsoft Corporation
[MD5.A2F74975097F52A00745F9637451FDD8] - 10/03/2011 - (.Microsoft Corporation - NT File System Driver.) -- C:\windows\System32\drivers\ntfs.sys [1659776] =>.Microsoft Windows®
[MD5.0086431C29C35BE1DBC43F52CC273887] - 13/07/2009 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\windows\System32\drivers\Parport.sys [97280] =>.Microsoft Corporation
[MD5.471815800AE33E6F1C32FB1B97C490CA] - 20/11/2010 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\windows\System32\drivers\Rasl2tp.sys [129536] =>.Microsoft Corporation
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - 13/07/2009 - (.Microsoft Corporation - SMB Transport driver.) -- C:\windows\System32\drivers\smb.sys [93184] =>.Microsoft Corporation
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - 20/11/2010 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\windows\System32\drivers\tdx.sys [119296] =>.Microsoft Corporation
[MD5.DF8126BD41180351A093A3AD2FC8903B] - 24/02/2011 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\windows\System32\drivers\volsnap.sys [296320] =>.Microsoft Windows®

---\\ Non Microsoft non disabled Windows Services (8) - 1s
O23 - Service: Avast Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe =>.AVAST Software a.s.®
O23 - Service: Veoh Giraffic Video Accelerator (Giraffic) . (.Giraffic - Giraffic Video Accelerator Watchdog.) - C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe =>.GIRAFFIC TECHNOLOGIES LTD®
O23 - Service: Google Update Service (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation®
O23 - Service: Malwarebytes Service (MBAMService) . (.Malwarebytes - Malwarebytes Service.) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation®
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) . (.TOSHIBA Corporation - TDCSrv Application.) - C:\Windows\system32\TODDSrv.exe =>.Toshiba Corporation
O23 - Service: Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe =>.Intel Corporation®
O23 - Service: ZAM Controller Service (ZAMSvc) . (.Copyright 2017. - ZAM.) - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe =>.Zemana Ltd.®

---\\ Services not Microsoft (SR=Run, SS=Stop) (14) - 13s
SR - Auto [19/07/2016] [ 197128] Avast Antivirus (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe =>.AVAST Software a.s.®
SR - Auto [13/05/2013] [ 2245232] Veoh Giraffic Video Accelerator (Giraffic) . (.Giraffic.) - C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe =>.GIRAFFIC TECHNOLOGIES LTD®
SS - Auto [28/08/2015] [ 144200] Google Update Service (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [28/08/2015] [ 144200] Google Update Service (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [20/10/2011] [ 182768] Google Software Updater (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe =>.Google Inc®
SS - Demand [04/04/2005] [ 69632] InstallDriver Table Manager (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe =>.Macrovision Corporation
SR - Auto [20/12/2010] [ 325656] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation®
SS - Auto [20/01/2017] [ 4355024] Malwarebytes Service (MBAMService) . (.Malwarebytes.) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation®
SS - Demand [11/07/2011] [ 57216] TMachInfo (TMachInfo) . (.TOSHIBA Corporation.) - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe =>.TOSHIBA CORPORATION®
SR - Auto [20/10/2010] [ 138656] TOSHIBA Optical Disc Drive Service (TODDSrv) . (.TOSHIBA Corporation.) - C:\Windows\system32\TODDSrv.exe =>.TOSHIBA CORPORATION®
SS - Demand [09/06/2011] [ 138152] TOSHIBA HDD SSD Alert Service (TOSHIBA HDD SSD Alert Service) . (.TOSHIBA Corporation.) - C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe =>.TOSHIBA CORPORATION®
SS - Demand [01/07/2011] [ 828856] TPCH Service (TPCHSrv) . (.TOSHIBA Corporation.) - C:\Program Files\Toshiba\TPHM\TPCHSrv.exe =>.TOSHIBA CORPORATION®
SR - Auto [20/12/2010] [ 2656280] Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe =>.Intel Corporation®
SR - Auto [02/02/2017] [14416624] ZAM Controller Service (ZAMSvc) . (.Copyright 2017..) - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe =>.Zemana Ltd.®

---\\ Task Planned Automatically (16) - 7s
[MD5.932B0CBB2DFBFD4BC1843B16740E9CD6] [APT] [avast! Emergency Update] (.AVAST Software.) -- C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [1648720] (.Activate.) =>.AVAST Software a.s.®
[MD5.7245B4C192D20107B4A3E887AED3F76E] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6490904] (.Activate.) =>.Piriform Ltd®
[MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] (.Activate.) =>.Google Inc®
[MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] (.Activate.) =>.Google Inc®
[MD5.5FA35D553BE9D2279ECC0BD7A569A744] [APT] [SafeZone scheduled Autoupdate 1463186051] (.Avast Software.) -- C:\Program Files\AVAST Software\SZBrowser\launcher.exe [735736] (.Activate.) =>.AVAST Software s.r.o.®
[MD5.69C8604D12C6F9C88AB0C81D50F0C3D1] [APT] [{65C76270-92BA-4F63-B82C-13F0D18DD623}] (...) -- C:\Users\Mitch\Desktop\OpenOffice 4.1.1 (en-US) Installation Files\setup.exe [478720] (.Activate.)
[MD5.283E10FD63971145CC1E750FFA46180E] [APT] [AVAST Software\Avast settings backup] (.AVAST Software.) -- C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [826808] (.Activate.) =>.AVAST Software s.r.o.®
O39 - APT: avast! Emergency Update - (.AVAST Software.) -- C:\windows\System32\Tasks\avast! Emergency Update [4180] =>.AVAST Software a.s.®
O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\windows\System32\Tasks\CCleanerSkipUAC [2790] =>.Piriform Ltd®
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore [3202] =>.Google Inc®
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA [3330] =>.Google Inc®
O39 - APT: SafeZone scheduled Autoupdate 1463186051 - (.Avast Software.) -- C:\windows\System32\Tasks\SafeZone scheduled Autoupdate 1463186051 [3890] =>.AVAST Software s.r.o.®
O39 - APT: Unknown - (...) -- C:\windows\System32\Tasks\{1426D1E5-5A00-4D59-985A-2107F1BEF83C} [3032]
O39 - APT: Unknown - (...) -- C:\windows\System32\Tasks\{2FB9F27A-DE3A-4CD6-B8B6-B233E63B6955} [2982]
O39 - APT: {65C76270-92BA-4F63-B82C-13F0D18DD623} - (...) -- C:\windows\System32\Tasks\{65C76270-92BA-4F63-B82C-13F0D18DD623} [3294]
O39 - APT: Unknown - (...) -- C:\windows\System32\Tasks\{A8D2B036-36FC-403B-8061-05969D1469A2} [2982]

---\\ Auto loading programs from Registry and folders (8) - 1s
O4 - HKLM\..\Run: [ZAM] . (.Copyright 2017. - ZAM.) -- C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe =>.Zemana Ltd.®
O4 - HKLM\..\Run: [Malwarebytes TrayApp] . (.Malwarebytes - Malwarebytes Tray Application.) -- C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe =>.Malwarebytes Corporation®
O4 - HKCU\..\Run: [CCleaner] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - HKLM\..\Wow6432Node\Run: [NortonOnlineBackupReminder] . (.Toshiba - Toshiba Online Backup Service.) -- C:\Program Files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TOBuActivation.exe =>.Symantec Corporation®
O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastui.exe =>.AVAST Software a.s.®
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-2113883840-1160270776-2747418757-1000\..\Run: [CCleaner] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®

---\\ Process running (12) - 1s
[MD5.8EF7C84BB20329D6DCAC09CF6B19345A] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128] [PID.1252] =>.AVAST Software a.s.®
[MD5.1B9100ACCFC9FD8B1D991F4BB80EC401] - (.Giraffic - Giraffic Video Accelerator Watchdog.) -- C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe [2245232] [PID.1680] =>.GIRAFFIC TECHNOLOGIES LTD®
[MD5.00000000000000000000000000000000] - (.TOSHIBA Corporation - TDCSrv Application.) -- C:\Windows\system32\TODDSrv.exe [0] [PID.1576] =>.Toshiba Corporation
[MD5.2BACD71123F42CEA603F4E205E1AE337] - (.Microsoft Corp. - Microsoft® Windows Live ID Service.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2292096] [PID.1456] =>.Microsoft Corporation®
[MD5.BF45D1E087B701D5215EBE57E2EDCA47] - (.Giraffic - Giraffic Video Accelerator.) -- C:\Program Files (x86)\Giraffic\Veoh_Giraffic.exe [4001376] [PID.1460] =>.GIRAFFIC TECHNOLOGIES LTD®
[MD5.2A46FFE841EC43001D5A293A54DB34DE] - (.Microsoft Corp. - Microsoft® Windows Live ID Service Monitor.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE [223104] [PID.2136] =>.Microsoft Corporation®
[MD5.C78761C2A5475EA16ADCD438CC17841F] - (.Copyright 2017. - ZAM.) -- C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14416624] [PID.2180] =>.Zemana Ltd.®
[MD5.C78761C2A5475EA16ADCD438CC17841F] - (.Copyright 2017. - ZAM.) -- C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14416624] [PID.2840] =>.Zemana Ltd.®
[MD5.70050353213574B62CA9EC28F65F2F3E] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastui.exe [8900328] [PID.3536] =>.AVAST Software a.s.®
[MD5.2ED1786B7542CDA261029F6B526EDF44] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [325656] [PID.868] =>.Intel Corporation®
[MD5.7E5E1603D0FF2D240AE70295C5C3FEFC] - (.Intel Corporation - User Notification Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2656280] [PID.3788] =>.Intel Corporation®
[MD5.7E3F7FDB19CA6C7FEF4FD02BF5E2E65F] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Mitch\Downloads\ZHPDiag3.exe [2719744] [PID.4200] =>.Nicolas Coolman

---\\ Google Chrome, Start,Search,Extensions (13) - 0s
G0 - GCSP: Preferences [User Data\Default][HomePage] http://apis.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://connect.facebook.net =>.Facebook
G0 - GCSP: Preferences [User Data\Default][HomePage] http://fonts.googleapis.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://fonts.gstatic.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://nicolascoolman.com =>.Nicolas Coolman
G0 - GCSP: Preferences [User Data\Default][HomePage] http://staticxx.facebook.com =>.Facebook
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.facebook.com =>.Facebook
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google-analytics.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.nicolascoolman.com =>.Nicolas Coolman
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.paypalobjects.com
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [nneajnkjbffgblleaoojgaacokifdkhm] __MSG_extname__
G2 - GCE: Preference [User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (2) - 0s
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll =>.Adobe Systems Incorporated
P2 - FPN: [HKLM] [@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (.WildTangent.) -- C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll =>.WildTangent

---\\ Internet Explorer Extensions, Start, Search (17) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com =>.Google Inc.
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer
R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2

---\\ Internet Explorer, Proxy Management (7) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=C:\windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation

---\\ Hosts file redirection (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ Global shortcuts Startup (91) - 4s
O4 - GS\Desktop [Administrator]: AdsFix_Donate.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.paypal.com/ =>.Microsoft Corporation
O4 - GS\Desktop [Administrator]: Veoh Web Player.lnk . (.Veoh Networks - Veoh Web Player Beta.) C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe /showplayer {087E17D7B2CA0D412673C947F2D84BDD} =>.Veoh Networks
O4 - GS\Desktop [Administrator]: Vivitar Experience Image Manager.lnk . (...) C:\Program Files (x86)\Vivitar Experience Image Manager\Vivitar.exe
O4 - GS\Desktop [Administrator]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleane.) C:\Users\Mitch\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Mitch\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Administrator]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: TOSHIBA Disc Creator(Audio).lnk . (.TOSHIBA Corporation - TOSHIBA Disc Creator.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Disc Creator\ToDisc.exe /SendTo:AD =>.TOSHIBA CORPORATION®
O4 - GS\sendTo [Administrator]: TOSHIBA Disc Creator(Data).lnk . (.TOSHIBA Corporation - TOSHIBA Disc Creator.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Disc Creator\ToDisc.exe /SendTo:DD =>.TOSHIBA CORPORATION®
O4 - GS\sendTo [Administrator]: TOSHIBA Disc Creator(Image).lnk . (.TOSHIBA Corporation - TOSHIBA Disc Creator.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Disc Creator\ToDisc.exe /SendTo:ITD =>.TOSHIBA CORPORATION®
O4 - GS\TaskBar [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrator]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Programs [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Guest]: AdsFix_Donate.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.paypal.com/ =>.Microsoft Corporation
O4 - GS\Desktop [Guest]: Veoh Web Player.lnk . (.Veoh Networks - Veoh Web Player Beta.) C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe /showplayer {087E17D7B2CA0D412673C947F2D84BDD} =>.Veoh Networks
O4 - GS\Desktop [Guest]: Vivitar Experience Image Manager.lnk . (...) C:\Program Files (x86)\Vivitar Experience Image Manager\Vivitar.exe
O4 - GS\Desktop [Guest]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleane.) C:\Users\Mitch\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Mitch\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Guest]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: TOSHIBA Disc Creator(Audio).lnk . (.TOSHIBA Corporation - TOSHIBA Disc Creator.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Disc Creator\ToDisc.exe /SendTo:AD =>.TOSHIBA CORPORATION®
O4 - GS\sendTo [Guest]: TOSHIBA Disc Creator(Data).lnk . (.TOSHIBA Corporation - TOSHIBA Disc Creator.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Disc Creator\ToDisc.exe /SendTo:DD =>.TOSHIBA CORPORATION®
O4 - GS\sendTo [Guest]: TOSHIBA Disc Creator(Image).lnk . (.TOSHIBA Corporation - TOSHIBA Disc Creator.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Disc Creator\ToDisc.exe /SendTo:ITD =>.TOSHIBA CORPORATION®
O4 - GS\TaskBar [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Guest]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Programs [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Mitch]: AdsFix_Donate.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.paypal.com/ =>.Microsoft Corporation
O4 - GS\Desktop [Mitch]: Veoh Web Player.lnk . (.Veoh Networks - Veoh Web Player Beta.) C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe /showplayer {087E17D7B2CA0D412673C947F2D84BDD} =>.Veoh Networks
O4 - GS\Desktop [Mitch]: Vivitar Experience Image Manager.lnk . (...) C:\Program Files (x86)\Vivitar Experience Image Manager\Vivitar.exe
O4 - GS\Desktop [Mitch]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleane.) C:\Users\Mitch\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [Mitch]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Mitch\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Mitch]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\sendTo [Mitch]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Mitch]: TOSHIBA Disc Creator(Audio).lnk . (.TOSHIBA Corporation - TOSHIBA Disc Creator.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Disc Creator\ToDisc.exe /SendTo:AD =>.TOSHIBA CORPORATION®
O4 - GS\sendTo [Mitch]: TOSHIBA Disc Creator(Data).lnk . (.TOSHIBA Corporation - TOSHIBA Disc Creator.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Disc Creator\ToDisc.exe /SendTo:DD =>.TOSHIBA CORPORATION®
O4 - GS\sendTo [Mitch]: TOSHIBA Disc Creator(Image).lnk . (.TOSHIBA Corporation - TOSHIBA Disc Creator.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Disc Creator\ToDisc.exe /SendTo:ITD =>.TOSHIBA CORPORATION®
O4 - GS\TaskBar [Mitch]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Mitch]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Mitch]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Mitch]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Programs [Mitch]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\CommonDesktop [Public]: Avast Free Antivirus.lnk . (.AVAST Software - avast! Antivirus.) C:\Program Files\AVAST Software\Avast\AvastUI.exe =>.AVAST Software a.s.®
O4 - GS\CommonDesktop [Public]: Avast SafeZone Browser.lnk . (.Avast Software - Avast SafeZone Browser.) C:\Program Files\AVAST Software\SZBrowser\launcher.exe =>.AVAST Software s.r.o.®
O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - GS\CommonDesktop [Public]: Zemana AntiMalware.lnk . (.Copyright 2017. - ZAM.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe =>.Zemana Ltd.®
O4 - GS\Programs [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Command Prompt.lnk . (.Microsoft Corporation - Windows Command Processor.) C:\windows\system32\cmd.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\windows\explorer.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff =>.Microsoft Corporation®
O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - Private Character Editor.) C:\windows\system32\eudcedit.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Windows Calculator.) C:\windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Display Switch.) C:\windows\system32\displayswitch.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Math Input Panel Accessory.) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Windows Mobility Center.) C:\windows\system32\mblctr.exe /open =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\windows\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\windows\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Windows Sound Recorder.) C:\windows\system32\SoundRecorder.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Sticky Notes.) C:\windows\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) C:\windows\System32\mobsync.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - Windows host process (Rundll32).) C:\windows\system32\rundll32.exe %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\windows\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Microsoft® Disk Defragmenter.) C:\windows\system32\dfrgui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Disk Space Cleanup Manager for Windows.) C:\windows\system32\cleanmgr.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Resource and Performance Monitor.) C:\windows\system32\perfmon.exe /res =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - System Information.) C:\windows\system32\msinfo32.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Microsoft® Windows System Restore.) C:\windows\system32\rstrui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\windows\system32\taskschd.msc /s =>..Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Windows Easy Transfer Post Migration Applic.) C:\windows\system32\migwiz\postmig.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Windows Easy Transfer Application.) C:\windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Adobe Reader X.lnk . (...) C:\Windows\Installer\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}\SC_Reader.ico =>.Adobe Inc.
O4 - GS\ProgramsCommon [Public]: Avast SafeZone Browser.lnk . (.Avast Software - Avast SafeZone Browser.) C:\Program Files\AVAST Software\SZBrowser\launcher.exe =>.AVAST Software s.r.o.®
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\ProgramsCommon [Public]: Media Center.lnk . (.Microsoft Corporation - Windows Media Center.) C:\windows\ehome\ehshell.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Microsoft Office 2010.lnk . (...) C:\Windows\Installer\{95140000-0070-0000-0000-0000000FF1CE}\oobeicon.exe
O4 - GS\ProgramsCommon [Public]: Sidebar.lnk . (.Microsoft Corporation - Windows Desktop Gadgets.) C:\Program Files (x86)\Windows Sidebar\sidebar.exe /showgadgets =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Anytime Upgrade.lnk . (.Microsoft Corporation - Windows Anytime Upgrade User Interface.) C:\windows\system32\WindowsAnytimeUpgradeUI.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows DVD Maker.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\DVD Maker\DVDMaker.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\windows\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Live Mail.lnk . (.Microsoft Corporation - Windows Live Mail.) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Windows Live Messenger.lnk . (.Microsoft Corporation - Windows Live Messenger.) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Windows Live Movie Maker.lnk . (.Microsoft Corporation - Windows Live Movie Maker.) C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Windows Live Photo Gallery.lnk . (.Microsoft Corporation - Windows Live Photo Gallery.) C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: XPS Viewer.lnk . (.Microsoft Corporation - XPS Viewer.) C:\windows\system32\xpsrchvw.exe =>.Microsoft Corporation

---\\ Lop.com/Domain Hijackers (5) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = hsd1.ca.comcast.net.
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76 =>.UK Milton Keynes Dedicated Server Hosting
O17 - HKLM\System\CCS\Services\Tcpip\..\{1C541FE9-C89C-4A5B-A474-C4A84D4970EA}: DhcpNameServer = 192.168.1.254 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{2CC683C3-C270-4C4C-B59E-95069212356D}: DhcpNameServer = 75.75.75.75 75.75.76.76 =>.UK Milton Keynes Dedicated Server Hosting
O17 - HKLM\System\CCS\Services\Tcpip\..\{2CC683C3-C270-4C4C-B59E-95069212356D}: DhcpDomain = hsd1.ca.comcast.net.

---\\ Extra protocols (24) - 1s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: livecall [64Bits] - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll =>.Microsoft Corporation®
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: msnim [64Bits] - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll =>.Microsoft Corporation®
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: wlmailhtml [64Bits] - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll =>.Microsoft Corporation®
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll =>.Microsoft Corporation®
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®

---\\ Software installed (99) - 8s
O42 - Logiciel: 9-lab Removal Tool - (..) [HKLM][64Bits] -- 9-lab Removal Tool =>.9-Lab®
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AFF7E080-1974-45BF-9310-10DE1A1F5ED0} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Flash Player 18 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Flash Player 18 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Reader X MUI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-FFFF-7B44-AA0000000001} =>.Adobe Systems Incorporated
O42 - Logiciel: Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver - (.Atheros Communications Inc..) [HKLM][64Bits] -- {3108C217-BE83-42E4-AE9E-A56A2A92E549} =>.Atheros Communications Inc.®
O42 - Logiciel: Avast Free Antivirus - (.AVAST Software.) [HKLM][64Bits] -- Avast =>.AVAST Software a.s.®
O42 - Logiciel: Bejeweled 3 - (.WildTangent.) [HKLM][64Bits] -- WTA-449bd985-3c9d-415e-91db-c4c8da29a06b =>.WildTangent Inc®
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Ltd®
O42 - Logiciel: Chuzzle Deluxe - (.WildTangent.) [HKLM][64Bits] -- WTA-2b98a26a-9857-4cda-b8c0-eee3bb490993 =>.WildTangent Inc®
O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM][64Bits] -- {64BF0187-F3D2-498B-99EA-163AF9AE6EC9} =>.Cisco Systems, Inc.
O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM][64Bits] -- {51C7AD07-C3F6-4635-8E8A-231306D810FE} =>.Cisco Systems, Inc.
O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM][64Bits] -- {ED5776D5-59B4-46B7-AF81-5F2D94D7C640} =>.Cisco Systems, Inc.
O42 - Logiciel: Conexant HD Audio - (.Conexant.) [HKLM][64Bits] -- CNXT_AUDIO_HDA =>.Conexant Systems, Inc.®
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} =>.Microsoft
O42 - Logiciel: DivX Setup - (.DivX, LLC.) [HKLM][64Bits] -- DivX Setup =>.DivX, LLC®
O42 - Logiciel: FATE - The Traitor Soul - (.WildTangent.) [HKLM][64Bits] -- WTA-77bd5c54-5d8d-4416-9bba-1ba4a88ce1b7 =>.WildTangent Inc®
O42 - Logiciel: ffdshow [rev 2527] [2008-12-19] - (..) [HKLM][64Bits] -- ffdshow_is1
O42 - Logiciel: Fishdom (TM) 2 - (.WildTangent.) [HKLM][64Bits] -- WTA-acdb0c5a-477e-4756-b925-430ed43ca90f =>.WildTangent Inc®
O42 - Logiciel: FreeTorrentViewer - (.Free Torrent Viewer.) [HKLM][64Bits] -- FreeTorrentViewer
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Inc®
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {18455581-E099-4BA8-BC6B-F34B2F06600C} =>.Google Inc.
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: Haali Media Splitter - (.Mike Matsnev.) [HKLM][64Bits] -- HaaliMkx =>.Mike Matsnev
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A} =>.Intel Corporation®
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel Corporation®
O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {3E29EE6C-963A-4aae-86C1-DC237C4A49FC} =>.Intel Corporation®
O42 - Logiciel: Java Auto Updater - (.Sun Microsystems, Inc..) [HKLM][64Bits] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Sun Microsystems, Inc.
O42 - Logiciel: Java(TM) 6 Update 25 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83216025FF} =>.Oracle
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM][64Bits] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4} =>.Microsoft Corporation
O42 - Logiciel: Label@Once 1.0 - (.Corel.) [HKLM][64Bits] -- {0D795777-9D60-4692-8386-F2B3F2B5E5BF} =>.Corel
O42 - Logiciel: Malwarebytes version 3.0.6.1469 - (.Malwarebytes.) [HKLM][64Bits] -- {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1 =>.Malwarebytes Corporation®
O42 - Logiciel: Mesh Runtime - (.Microsoft Corporation.) [HKLM][64Bits] -- {8C6D6116-B724-4810-8F2D-D047E6B7D68E} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Application Error Reporting - (.Microsoft Corporation.) [HKLM][64Bits] -- {95120000-00B9-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} =>.Microsoft
O42 - Logiciel: MSVCRT_amd64 - (.Microsoft.) [HKLM][64Bits] -- {D0B44725-3666-492D-BEF6-587A14BD9BD9} =>.Microsoft
O42 - Logiciel: Netwaiting - (.Conexant Systems, Inc.) [HKLM][64Bits] -- {74B8998B-2B1B-4414-AD5D-17E7E9B5FF0A} =>.Conexant Systems, Inc
O42 - Logiciel: Penguins! - (.WildTangent.) [HKLM][64Bits] -- WTA-2c05a9e4-d186-474f-bd85-2496b970ba27 =>.WildTangent Inc®
O42 - Logiciel: Plants vs. Zombies - Game of the Year - (.WildTangent.) [HKLM][64Bits] -- WTA-e1c833ce-2952-47e7-8161-c2ec26e43ff2 =>.WildTangent Inc®
O42 - Logiciel: PlayReady PC Runtime amd64 - (.Microsoft Corporation.) [HKLM][64Bits] -- {BCA9334F-B6C9-4F65-9A73-AC5A329A4D04} =>.Microsoft Corporation
O42 - Logiciel: PlayReady PC Runtime x86 - (.Microsoft Corporation.) [HKLM][64Bits] -- {CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61} =>.Microsoft Corporation
O42 - Logiciel: Polar Bowler - (.WildTangent.) [HKLM][64Bits] -- WTA-1bd9480c-a72e-4acf-9df8-d55787d9bcd7 =>.WildTangent Inc®
O42 - Logiciel: Realtek USB 2.0 Reader Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {62BBB2F0-E220-4821-A564-730807D2C34D} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Realtek WLAN Driver - (.REALTEK Semiconductor Corp..) [HKLM][64Bits] -- {9D3D8C60-A55F-4fed-B2B9-173001290E16} =>.Realtek Semiconductor Corp®
O42 - Logiciel: REGSERVO - (.TuneUp System Software Pvt Ltd..) [HKLM][64Bits] -- REGSERVO_is1
O42 - Logiciel: SafeZone Stable 1.48.2066.114 - (.Avast Software.) [HKLM][64Bits] -- SafeZone 1.48.2066.114 =>.AVAST Software s.r.o.®
O42 - Logiciel: Skype Launcher - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {DA84ECBF-4B79-47F2-B34C-95C38484C058} =>.Macrovision Corporation®
O42 - Logiciel: Strongvault Online Backup - (.Strongvault.) [HKLM][64Bits] -- {59DB31A9-BCB0-4985-ACA6-F6477C7BE367}
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey =>.Synaptics Incorporated
O42 - Logiciel: Tom Clancy's Splinter Cell - (.WildTangent.) [HKLM][64Bits] -- WTA-64342a07-e20d-4fb5-9bd4-5c83fc3e1740 =>.WildTangent Inc®
O42 - Logiciel: Toshiba App Place - (.Toshiba.) [HKLM][64Bits] -- {ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2} =>.Toshiba
O42 - Logiciel: TOSHIBA Application Installer - (.TOSHIBA.) [HKLM][64Bits] -- {970472D0-F5F9-4158-A6E3-1AE49EFEF2D3} =>.Toshiba
O42 - Logiciel: TOSHIBA Assist - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {C2A276E3-154E-44DC-AAF1-FFDD7FD30E35} =>.Macrovision Corporation®
O42 - Logiciel: Toshiba Book Place - (.K-NFB Reading Technology, Inc..) [HKLM][64Bits] -- {A14962A7-2B7D-456E-BFCD-F54E3A88D41F} =>.K-NFB Reading Technology, Inc.
O42 - Logiciel: TOSHIBA Bulletin Board - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {1C8C049A-145F-4A6E-8290-B5C245EBE39D} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Bulletin Board - (.TOSHIBA Corporation.) [HKLM][64Bits] -- InstallShield_{1C8C049A-145F-4A6E-8290-B5C245EBE39D} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Disc Creator - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {5DA0E02F-970B-424B-BF41-513A5018E4C0} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA eco Utility - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {C2F94B5E-201A-4754-8F2F-4395E1D90DA3} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Face Recognition - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {F67FA545-D8E5-4209-86B1-AEE045D1003F} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Face Recognition - (.TOSHIBA Corporation.) [HKLM][64Bits] -- InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Hardware Setup - (.TOSHIBA.) [HKLM][64Bits] -- {C4FFA951-9678-4D51-84B4-AFD15D3C45AD} =>.Toshiba
O42 - Logiciel: TOSHIBA Hardware Setup - (.TOSHIBA.) [HKLM][64Bits] -- InstallShield_{C4FFA951-9678-4D51-84B4-AFD15D3C45AD} =>.Toshiba
O42 - Logiciel: TOSHIBA HDD/SSD Alert - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {D4322448-B6AF-4316-B859-D8A0E84DCB38} =>.Toshiba Corporation
O42 - Logiciel: Toshiba Laptop Checkup - (.Symantec Corporation.) [HKLM][64Bits] -- NortonPCCheckup =>.Symantec Corporation®
O42 - Logiciel: TOSHIBA Media Controller - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {C7A4F26F-F9B0-41B2-8659-99181108CDE3} =>.Macrovision Corporation®
O42 - Logiciel: TOSHIBA Media Controller Plug-in - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {F26FDF57-483E-42C8-A9C9-EEE1EDB256E0} =>.Toshiba Corporation
O42 - Logiciel: Toshiba Online Backup - (.Toshiba.) [HKLM][64Bits] -- {C57BCDE1-7CB9-467D-B3BA-7E119916CDC1} =>.Toshiba
O42 - Logiciel: TOSHIBA PC Health Monitor - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Quality Application - (.TOSHIBA.) [HKLM][64Bits] -- {E69992ED-A7F6-406C-9280-1C156417BC49} =>.Toshiba
O42 - Logiciel: TOSHIBA Recovery Media Creator - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {B65BBB06-1F8E-48F5-8A54-B024A9E15FDF} =>.TOSHIBA CORPORATION®
O42 - Logiciel: TOSHIBA ReelTime - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {24811C12-F4A9-4D0F-8494-A7B8FE46123C} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA ReelTime - (.TOSHIBA Corporation.) [HKLM][64Bits] -- InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Resolution+ Plug-in for Windows Media Player - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Service Station - (.TOSHIBA.) [HKLM][64Bits] -- {AC6569FA-6919-442A-8552-073BE69E247A} =>.Toshiba
O42 - Logiciel: TOSHIBA Sleep Utility - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {654F7484-88C5-46DC-AB32-C66BCB0E2102} =>.TOSHIBA CORPORATION®
O42 - Logiciel: TOSHIBA Supervisor Password - (.TOSHIBA.) [HKLM][64Bits] -- {CBD6B23D-41D5-4A46-8019-6208516C9712} =>.Toshiba
O42 - Logiciel: TOSHIBA Supervisor Password - (.TOSHIBA.) [HKLM][64Bits] -- InstallShield_{CBD6B23D-41D5-4A46-8019-6208516C9712} =>.Toshiba
O42 - Logiciel: TOSHIBA Value Added Package - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {066CFFF8-12BF-4390-A673-75F95EFF188E} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Value Added Package - (.TOSHIBA Corporation.) [HKLM][64Bits] -- InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E} =>.TOSHIBA CORPORATION®
O42 - Logiciel: TOSHIBA Web Camera Application - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {6F3C8901-EBD3-470D-87F8-AC210F6E5E02} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Web Camera Application - (.TOSHIBA Corporation.) [HKLM][64Bits] -- InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Wireless LAN Indicator - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {5B01BCB7-A5D3-476F-AF11-E515BA206591} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBARegistration - (.TOSHIBA.) [HKLM][64Bits] -- {5AF550B4-BB67-4E7E-82F1-2C4300279050} =>.Toshiba
O42 - Logiciel: Uninstall Dual Mode Camera (TDC13E0) - (..) [HKLM][64Bits] -- TDC13E0_2009_0603_1515_is1
O42 - Logiciel: Update Installer for WildTangent Games App - (.WildTangent.) [HKLM][64Bits] -- {2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App =>.WildTangent
O42 - Logiciel: VC80CRTRedist - 8.0.50727.6195 - (.DivX, Inc.) [HKLM][64Bits] -- {933B4015-4618-4716-A828-5289FC03165F} =>.DivX, Inc
O42 - Logiciel: Veoh Giraffic Video Accelerator - (.Giraffic.) [HKLM][64Bits] -- Giraffic =>.GIRAFFIC TECHNOLOGIES LTD®
O42 - Logiciel: Veoh Web Player - (.Veoh Networks, Inc..) [HKLM][64Bits] -- Veoh Web Player Beta
O42 - Logiciel: Virtual Villagers 5 - New Believers - (.WildTangent.) [HKLM][64Bits] -- WTA-52f1d0ea-61e5-4e73-9487-ae54e69b2437 =>.WildTangent Inc®
O42 - Logiciel: Vivitar Experience Image Manager - (..) [HKLM][64Bits] -- Vivitar Experience Image Manager
O42 - Logiciel: WebEx - (.Cisco WebEx LLC.) [HKCU][64Bits] -- ActiveTouchMeetingClient =>.WebEx Communications Inc.®
O42 - Logiciel: WebM Media Foundation Components - (.WebM Project.) [HKLM][64Bits] -- webmmf =>.WebM Project
O42 - Logiciel: WildTangent Games - (.WildTangent.) [HKLM][64Bits] -- WildTangent toshiba Master Uninstall =>.WildTangent
O42 - Logiciel: WildTangent Games App (Toshiba Games) - (.WildTangent.) [HKLM][64Bits] -- {70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-toshiba =>.WildTangent
O42 - Logiciel: Zemana AntiMalware - (.Zemana Ltd..) [HKLM][64Bits] -- {8F0CD7D1-42F3-4195-95CD-833578D45057}_is1 =>.Zemana Ltd.
O42 - Logiciel: Zoola Games - (..) [HKLM][64Bits] -- Zoola Games
O42 - Logiciel: Zuma's Revenge - (.WildTangent.) [HKLM][64Bits] -- WTA-54d4bc45-6230-4afa-82ed-66eaac5d1226 =>.WildTangent Inc®

---\\ HKCU & HKLM Software Keys (74) - 8s
HKLM\SOFTWARE\Wow6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\Wow6432Node\Atheros Communications Inc. =>.Qualcomm Atheros
HKLM\SOFTWARE\Wow6432Node\AVAST Software =>.AVAST Software
HKLM\SOFTWARE\Wow6432Node\DivX =>.DivX Inc.
HKLM\SOFTWARE\Wow6432Node\DivXNetworks =>.DivXNetworks
HKLM\SOFTWARE\Wow6432Node\Eset =>.ESET
HKLM\SOFTWARE\Wow6432Node\Giraffic =>.Giraffic
HKLM\SOFTWARE\Wow6432Node\GNU =>.GNU
HKLM\SOFTWARE\Wow6432Node\Google =>.Google
HKLM\SOFTWARE\Wow6432Node\HaaliMkx =>.Haali Media
HKLM\SOFTWARE\Wow6432Node\Hyperlync
HKLM\SOFTWARE\Wow6432Node\InstallShield =>.InstallShield
HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel
HKLM\SOFTWARE\Wow6432Node\JavaSoft =>.JavaSoft
HKLM\SOFTWARE\Wow6432Node\JL2005D =>.Jeilin
HKLM\SOFTWARE\Wow6432Node\JL2005D_5 =>.Jeilin
HKLM\SOFTWARE\Wow6432Node\JL2005D_7 =>.Jeilin
HKLM\SOFTWARE\Wow6432Node\JL6_DECODE
HKLM\SOFTWARE\Wow6432Node\Licenses =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware =>.Malwarebytes' Anti-Malware
HKLM\SOFTWARE\Wow6432Node\MimarSinan =>.Mimar Sinan
HKLM\SOFTWARE\Wow6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\Norton =>.Symantec Corporation
HKLM\SOFTWARE\Wow6432Node\Norton PC Checkup =>.Symantec Corporation
HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Wow6432Node\Piriform =>.Piriform
HKLM\SOFTWARE\Wow6432Node\REALTEK Semiconductor Corp. =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\SOS
HKLM\SOFTWARE\Wow6432Node\Symantec =>.Symantec
HKLM\SOFTWARE\Wow6432Node\TightVNC =>.TightVNC Project
HKLM\SOFTWARE\Wow6432Node\TOSHIBA =>.Toshiba Corporation
HKLM\SOFTWARE\Wow6432Node\TOSHIBA CORPORATION =>.Toshiba Corporation
HKLM\SOFTWARE\Wow6432Node\TrendMicro =>.TrendMicro
HKLM\SOFTWARE\Wow6432Node\Ulead Systems =>.Ulead Systems
HKLM\SOFTWARE\Wow6432Node\WildTangent =>.WildTangent
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\9-lab =>.9-lab
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\AVAST Software =>.AVAST Software
HKCU\SOFTWARE\Caphyon =>.Caphyon
HKCU\SOFTWARE\DivX =>.DivX Inc.
HKCU\SOFTWARE\DivXNetworks =>.DivXNetworks
HKCU\SOFTWARE\g3n-h@ckm@n =>.g3n-h@ckm@n
HKCU\SOFTWARE\GNU =>.GNU
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\Intel =>.Intel
HKCU\SOFTWARE\JavaSoft =>.JavaSoft
HKCU\SOFTWARE\KineticJump
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\Malwarebytes =>.Malwarebytes
HKCU\SOFTWARE\Mixi.DJ
HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKCU\SOFTWARE\ORL
HKCU\SOFTWARE\Piriform =>.Piriform
HKCU\SOFTWARE\QtProject =>.QtProject
HKCU\SOFTWARE\SimonTatham =>.Simon Tatham
HKCU\SOFTWARE\Stronghold Online Backup
HKCU\SOFTWARE\Synaptics =>.Synaptics
HKCU\SOFTWARE\Sysinternals =>.Sysinternals
HKCU\SOFTWARE\TightVNC =>.TightVNC Project
HKCU\SOFTWARE\Toshiba =>.Toshiba Corporation
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation
HKCU\SOFTWARE\Veoh
HKCU\SOFTWARE\WebEx =>.Cisco Systems, Inc.
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZebHelpProcess Helper =>.Nicolas Coolman
HKCU\SOFTWARE\Zemana =>.Zemana
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKCU\SOFTWARE\AppDataLow\Software\DivX =>.DivX Inc.

---\\ Contents of the Common Files folders (207) - 5s
O43 - CFD: 08/09/2015 - [] D -- C:\Program Files\9-lab =>.9-Lab®
O43 - CFD: 13/05/2016 - [] D -- C:\Program Files\AVAST Software =>.AVAST Software s.r.o.®
O43 - CFD: 09/09/2015 - [] D -- C:\Program Files\CCleaner =>.Piriform Ltd
O43 - CFD: 03/12/2015 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\CONEXANT =>.Conexant Systems, Inc.®
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\DivX =>.DivX
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\DVD Maker =>.Aone Software
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Google =>.Google
O43 - CFD: 10/07/2013 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 26/04/2017 - [] D -- C:\Program Files\Malwarebytes =>.Malwarebytes
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\PlayReady =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Synaptics =>.Synaptics Incorporated®
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Toshiba =>.Toshiba Corporation
O43 - CFD: 13/07/2009 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Vivitar Experience Image Manager =>.Adobe Systems Incorporated®
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Windows Journal =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Windows Live =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 20/11/2010 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems, Incorporated®
O43 - CFD: 08/09/2015 - [] D -- C:\Program Files (x86)\Adware Removal Tool by TSA =>.TSA Softwares
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Cisco =>.Cisco Systems, Inc.
O43 - CFD: 26/04/2017 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Conexant =>.Conexant Systems, Inc.®
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Corel =>.Corel Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\DivX =>.DivX
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\ffdshow =>.Open Source
O43 - CFD: 26/04/2017 - [] D -- C:\Program Files (x86)\Giraffic =>.GIRAFFIC TECHNOLOGIES LTD®
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Haali =>.Haali
O43 - CFD: 14/08/2012 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield Software
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Java =>.Oracle
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Microsoft Application Virtualization Client =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition =>.Microsoft Corporation
O43 - CFD: 28/12/2011 - [] HD -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\MTA
O43 - CFD: 26/04/2017 - [] D -- C:\Program Files (x86)\Netwaiting
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Norton PC Checkup =>.Symantec Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\NortonInstaller =>.Symantec
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\PlayReady =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Realtek WLAN Driver =>.Realtek Semiconductor Corp.
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\TDC13E0
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\TOSHIBA =>.Toshiba Corporation
O43 - CFD: 20/10/2011 - [] HD -- C:\Program Files (x86)\TOSHIBA Corporation =>.Toshiba Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\TOSHIBA Games =>.Toshiba Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Toshiba Online Backup =>.Toshiba Corporation
O43 - CFD: 19/04/2017 - [0] HD -- C:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Veoh Networks =>.Veoh Networks
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\WildTangent Games =>.WildTangent Games
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Windows Live =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 20/11/2010 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 04/02/2017 - [] D -- C:\Program Files (x86)\Zemana AntiMalware =>.Zemana
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Zoola Games
O43 - CFD: 08/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool
O43 - CFD: 10/07/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 10/07/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 02/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software =>.AVAST Software
O43 - CFD: 09/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd
O43 - CFD: 10/07/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel Label@Once
O43 - CFD: 10/07/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus =>.DivX Inc.
O43 - CFD: 10/07/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow =>.Open Source
O43 - CFD: 10/07/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 10/07/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter =>.Mike Matsnev
O43 - CFD: 10/07/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 26/04/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes =>.Malwarebytes
O43 - CFD: 10/07/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English) =>.Microsoft Corporation
O43 - CFD: 10/07/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 26/04/2017 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Netwaiting
O43 - CFD: 26/04/2017 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetZero
O43 - CFD: 10/07/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype =>.Skype
O43 - CFD: 09/09/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 21/11/2010 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC =>.Wacom Technology
O43 - CFD: 09/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOSHIBA =>.Toshiba Corporation
O43 - CFD: 10/07/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live =>.Microsoft Corporation
O43 - CFD: 03/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware =>.Zemana
O43 - CFD: 08/09/2015 - [] D -- C:\ProgramData\9-lab =>.9-lab
O43 - CFD: 10/07/2013 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 13/07/2009 - [] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 13/05/2016 - [] D -- C:\ProgramData\AVAST Software =>.AVAST Software
O43 - CFD: 13/07/2009 - [] SD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\ProgramData\DivX =>.DivX
O43 - CFD: 13/07/2009 - [] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\ProgramData\Favorites =>.Microsoft Corporation
O43 - CFD: 27/11/2016 - [] D -- C:\ProgramData\Giraffic =>.Giraffic
O43 - CFD: 14/08/2012 - [] D -- C:\ProgramData\Google =>.Google
O43 - CFD: 26/04/2017 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes
O43 - CFD: 19/04/2017 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\ProgramData\Norton =>.Symantec Corporation
O43 - CFD: 27/01/2012 - [] HD -- C:\ProgramData\NortonInstaller =>.Symantec
O43 - CFD: 19/04/2017 - [] D -- C:\ProgramData\RogueKiller =>.Adlice
O43 - CFD: 13/07/2009 - [] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 01/08/2011 - [] HD -- C:\ProgramData\Sun =>.Oracle
O43 - CFD: 30/05/2015 - [0] AHD -- C:\ProgramData\TEMP =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\ProgramData\Toshiba =>.Toshiba Corporation
O43 - CFD: 08/01/2013 - [] D -- C:\ProgramData\Toshiba Book Place =>.Toshiba Corporation
O43 - CFD: 27/12/2011 - [] HD -- C:\ProgramData\VirtualizedApplications =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\ProgramData\WebEx =>.Cisco Systems, Inc.
O43 - CFD: 14/08/2012 - [] D -- C:\ProgramData\WildTangent =>.WildTangent
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\Adobe =>.Adobe
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\Adobe AIR =>.Adobe Inc.
O43 - CFD: 13/04/2017 - [] D -- C:\Program Files (x86)\Common Files\AV =>.Avast
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER =>.Designer
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\DivX Shared =>.DivX
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\InstallShield =>.InstallShield
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\Intel =>.Intel Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\Java =>.Oracle
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared =>.Microsoft Corporation
O43 - CFD: 10/07/2013 - [] D -- C:\Program Files (x86)\Common Files\MSSoap =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\postureAgent =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\PX Storage Engine =>.Sonic Solutions
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\Toshiba Shared =>.Toshiba Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\Ulead Systems =>.Ulead Systems
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\WebM Project =>.WebM Project
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Common Files\Windows Live =>.Microsoft Corporation
O43 - CFD: 08/09/2015 - [] D -- C:\Users\Mitch\AppData\Roaming\9-lab =>.9-lab
O43 - CFD: 14/08/2012 - [] D -- C:\Users\Mitch\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 09/09/2015 - [] D -- C:\Users\Mitch\AppData\Roaming\AVAST Software =>.AVAST Software
O43 - CFD: 09/07/2013 - [] D -- C:\Users\Mitch\AppData\Roaming\Book Place
O43 - CFD: 05/03/2012 - [] HD -- C:\Users\Mitch\AppData\Roaming\DivX =>.DivX
O43 - CFD: 26/12/2011 - [] HD -- C:\Users\Mitch\AppData\Roaming\Google =>.Google
O43 - CFD: 26/12/2011 - [] HD -- C:\Users\Mitch\AppData\Roaming\Identities =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Users\Mitch\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 21/11/2010 - [0] HD -- C:\Users\Mitch\AppData\Roaming\Media Center Programs =>.Microsoft Corporation
O43 - CFD: 10/07/2013 - [] SD -- C:\Users\Mitch\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 09/02/2012 - [] HD -- C:\Users\Mitch\AppData\Roaming\Product_RM
O43 - CFD: 30/08/2016 - [] D -- C:\Users\Mitch\AppData\Roaming\SoftGrid Client =>.Microsoft Corporation
O43 - CFD: 01/06/2013 - [] HD -- C:\Users\Mitch\AppData\Roaming\Toshiba =>.Toshiba Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Users\Mitch\AppData\Roaming\vlc =>.VideoLan Team
O43 - CFD: 26/12/2011 - [] HD -- C:\Users\Mitch\AppData\Roaming\WinBatch =>.winbatch.com
O43 - CFD: 26/04/2017 - [] D -- C:\Users\Mitch\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 08/09/2015 - [] D -- C:\Users\Mitch\AppData\Roaming\ZHP.$quar
O43 - CFD: 02/07/2015 - [] HD -- C:\Users\Mitch\AppData\Local\Adobe =>.Adobe
O43 - CFD: 26/12/2011 - [] SHD -- C:\Users\Mitch\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 21/07/2016 - [] D -- C:\Users\Mitch\AppData\Local\CEF =>.CEF
O43 - CFD: 26/04/2017 - [0] HD -- C:\Users\Mitch\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 07/02/2016 - [] HD -- C:\Users\Mitch\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 31/10/2016 - [] HD -- C:\Users\Mitch\AppData\Local\Google =>.Google
O43 - CFD: 26/12/2011 - [] SHD -- C:\Users\Mitch\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 08/01/2013 - [] D -- C:\Users\Mitch\AppData\Local\Kjs.AppLife.Update
O43 - CFD: 15/09/2015 - [] D -- C:\Users\Mitch\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 08/09/2015 - [] D -- C:\Users\Mitch\AppData\Local\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 08/09/2015 - [] D -- C:\Users\Mitch\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 26/12/2011 - [] HD -- C:\Users\Mitch\AppData\Local\SoftGrid Client =>.Microsoft Corporation
O43 - CFD: 26/04/2017 - [] D -- C:\Users\Mitch\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 26/12/2011 - [] SHD -- C:\Users\Mitch\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Users\Mitch\AppData\Local\TOSHIBA =>.Toshiba Corporation
O43 - CFD: 19/04/2017 - [0] D -- C:\Users\Mitch\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 17/02/2012 - [] HD -- C:\Users\Mitch\AppData\Local\Vivitar Experience Image Manager
O43 - CFD: 08/09/2015 - [] D -- C:\Users\Mitch\AppData\Local\Zemana =>.Zemana
O43 - CFD: 26/04/2017 - [] D -- C:\Users\Mitch\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 08/09/2015 - [0] D -- C:\Users\Mitch\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 10/07/2013 - [] RD -- C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 12/07/2012 - [] RD -- C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 02/01/2012 - [0] HD -- C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter =>.Mike Matsnev
O43 - CFD: 10/07/2013 - [] RD -- C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 30/06/2013 - [] RD -- C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 10/07/2013 - [] D -- C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Veoh Networks, Inc
O43 - CFD: 10/07/2013 - [] D -- C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vivitar Experience Image Manager
O43 - CFD: 10/07/2013 - [] D -- C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoola Games
O43 - CFD: 13/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] HD -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] HD -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] HD -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] HD -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 01/08/2011 - [] -- C:\windows\System32\Config\systemprofile\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 10/02/2015 - [] D -- C:\windows\System32\Config\systemprofile\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 26/12/2011 - [] -- C:\windows\System32\Config\systemprofile\AppData\Local\Google =>.Google
O43 - CFD: 01/08/2011 - [] -- C:\windows\System32\Config\systemprofile\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 01/08/2011 - [] -- C:\windows\System32\Config\systemprofile\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 15/02/2012 - [0] D -- C:\windows\System32\Config\systemprofile\AppData\Local\SoftGrid Client =>.Microsoft Corporation
O43 - CFD: 01/08/2011 - [] -- C:\windows\System32\Config\systemprofile\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 08/09/2015 - [] -- C:\windows\System32\Config\systemprofile\AppData\Local\Zemana =>.Zemana
O43 - CFD: 14/08/2012 - [] SD -- C:\windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 26/04/2017 - [] D -- C:\windows\System32\Config\systemprofile\AppData\Roaming\SoftGrid Client =>.Microsoft Corporation
O43 - CFD: 11/09/2012 - [0] -- C:\windows\System32\Config\systemprofile\AppData\Roaming\TightVNC =>.TightVNC Project

---\\ ShellIconOverlayIdentifiers (SIOI) (3) - 1s
O106 - SIOI: avast [00avast] - {472083B0-C522-11CF-8763-00608CC02F24}. (.AVAST Software - avast! Shell Extension.) -- C:\Program Files\AVAST Software\Avast\ashShell.dll =>.AVAST Software a.s.®
O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation

---\\ System Drivers List (82) - 14s
O58 - SDL:2009/07/13 18:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\windows\System32\drivers\adp94xx.sys [491088] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\windows\System32\drivers\adpahci.sys [339536] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\windows\System32\drivers\adpu320.sys [182864] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\windows\System32\drivers\aliide.sys [15440] =>.Microsoft Windows®
O58 - SDL:2011/03/10 23:41:12 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\windows\System32\drivers\amdsata.sys [107904] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\windows\System32\drivers\amdsbs.sys [194128] =>.Microsoft Windows®
O58 - SDL:2011/03/10 23:41:12 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\windows\System32\drivers\amdxata.sys [27008] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\windows\System32\drivers\arc.sys [87632] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\windows\System32\drivers\arcsas.sys [97856] =>.Microsoft Windows®
O58 - SDL:2016/07/19 18:28:46 A . (.AVAST Software - avast! HWID.) -- C:\windows\System32\drivers\aswHwid.sys [37656] =>.AVAST Software a.s.® (.AVAST Software)
O58 - SDL:2016/07/19 18:28:25 A . (.AVAST Software - avast! Keyboard Filter Driver.) -- C:\windows\System32\drivers\aswKbd.sys [37144] =>.AVAST Software a.s.®
O58 - SDL:2016/07/19 18:28:46 A . (.AVAST Software - avast! File System Minifilter for Windows 2.) -- C:\windows\System32\drivers\aswMonFlt.sys [108304] =>.AVAST Software a.s.®
O58 - SDL:2016/07/19 18:28:45 A . (.AVAST Software - avast! WFP Redirect Driver.) -- C:\windows\System32\drivers\aswRdr2.sys [103064] =>.AVAST Software a.s.®
O58 - SDL:2016/07/19 18:28:46 A . (.AVAST Software - avast! Revert.) -- C:\windows\System32\drivers\aswRvrt.sys [74544] =>.AVAST Software a.s.® (.AVAST Software)
O58 - SDL:2016/07/19 18:28:29 A . (.AVAST Software - avast! Virtualization Driver.) -- C:\windows\System32\drivers\aswSnx.sys [1070904] =>.AVAST Software a.s.®
O58 - SDL:2016/07/19 18:30:05 A . (.AVAST Software - avast! self protection module.) -- C:\windows\System32\drivers\aswsp.sys [473592] =>.AVAST Software a.s.®
O58 - SDL:2016/07/19 18:28:46 A . (.AVAST Software - Stream Filter.) -- C:\windows\System32\drivers\aswStm.sys [162904] =>.AVAST Software a.s.®
O58 - SDL:2016/08/05 17:08:07 A . (.AVAST Software - avast! VM Monitor.) -- C:\windows\System32\drivers\aswvmm.sys [292704] =>.AVAST Software a.s.® (.AVAST Software)
O58 - SDL:2009/06/10 13:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\windows\System32\drivers\b57nd60a.sys [270848] =>.Broadcom Corporation
O58 - SDL:2009/06/10 13:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\windows\System32\drivers\BrFiltLo.sys [18432] =>.Brother Industries, Ltd.
O58 - SDL:2009/06/10 13:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\windows\System32\drivers\BrFiltUp.sys [8704] =>.Brother Industries, Ltd.
O58 - SDL:2009/07/13 18:19:07 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- C:\windows\System32\drivers\BrSerId.sys [286720] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 13:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\windows\System32\drivers\BrSerWdm.sys [47104] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 13:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\windows\System32\drivers\BrUsbMdm.sys [14976] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 13:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\windows\System32\drivers\BrUsbSer.sys [14720] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 13:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\windows\System32\drivers\bxvbda.sys [468480] =>.Broadcom Corporation
O58 - SDL:2011/07/07 15:02:16 A . (.Conexant Systems Inc. - 64-bit High Definition Audio Function Drive.) -- C:\windows\System32\drivers\CHDRT64.sys [1576576] =>.Conexant Systems, Inc.®
O58 - SDL:2009/07/13 18:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\windows\System32\drivers\cmdide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\windows\System32\drivers\elxstor.sys [530496] =>.Microsoft Windows®
O58 - SDL:2009/06/10 13:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\windows\System32\drivers\evbda.sys [3286016] =>.Broadcom Corporation
O58 - SDL:2011/12/26 12:57:17 RSH . (.Authors - .) -- C:\windows\System32\drivers\fbd.sys [13] =>.EasyCo LLC
O58 - SDL:2009/06/10 13:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\windows\System32\drivers\hcw85cir.sys [31232] =>.Hauppauge Computer Works, Inc.
O58 - SDL:2010/10/19 16:34:26 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\windows\System32\drivers\HECIx64.sys [56344] =>.Intel Corporation®
O58 - SDL:2010/11/20 20:23:47 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\windows\System32\drivers\HpSAMD.sys [78720] =>.Microsoft Windows®
O58 - SDL:2011/01/12 17:51:44 A . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\windows\System32\drivers\iaStor.sys [439320] =>.Intel Corporation®
O58 - SDL:2011/03/10 23:41:26 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\windows\System32\drivers\iaStorV.sys [410496] =>.Microsoft Windows®
O58 - SDL:2011/04/04 20:10:14 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\windows\System32\drivers\igdkmd64.sys [12262624] =>.Intel Corporation
O58 - SDL:2009/07/13 18:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\windows\System32\drivers\iirsp.sys [44112] =>.Microsoft Windows®
O58 - SDL:2010/10/15 01:28:16 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\windows\System32\drivers\IntcDAud.sys [317440] =>.Intel(R) Corporation
O58 - SDL:2009/06/02 13:26:26 A . (.Windows (R) Codename Longhorn DDK provider - Universal Serial Bus Camera Driver.) -- C:\windows\System32\drivers\jl2005c.sys [80880] =>.JEILIN TECHNOLOGIES CORPORATION®
O58 - SDL:2010/11/08 12:44:40 A . (.Atheros Communications, Inc. - Atheros L1c PCI-E Gigabit Ethernet Controll.) -- C:\windows\System32\drivers\L1C62x64.sys [76912] =>.Atheros Communications Inc.®
O58 - SDL:2009/07/13 18:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\windows\System32\drivers\lsi_fc.sys [114752] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\windows\System32\drivers\lsi_sas.sys [106560] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\windows\System32\drivers\lsi_sas2.sys [65600] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\windows\System32\drivers\lsi_scsi.sys [115776] =>.Microsoft Windows®
O58 - SDL:2017/03/22 11:02:44 A . (.Authors - .) -- C:\windows\System32\drivers\mbae64.sys [77440] =>.Malwarebytes Corporation®
O58 - SDL:2017/04/26 19:41:51 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- C:\windows\System32\drivers\MBAMSwissArmy.sys [251832] =>.Malwarebytes Corporation®
O58 - SDL:2009/07/13 18:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\windows\System32\drivers\megasas.sys [35392] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\windows\System32\drivers\MegaSR.sys [284736] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\windows\System32\drivers\nfrd960.sys [51264] =>.Microsoft Windows®
O58 - SDL:2011/03/10 23:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\windows\System32\drivers\nvraid.sys [148352] =>.Microsoft Windows®
O58 - SDL:2011/03/10 23:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\windows\System32\drivers\nvstor.sys [166272] =>.Microsoft Windows®
O58 - SDL:2011/02/08 19:07:00 A . (.TOSHIBA Corporation - TOSHIBA Universal Camera Filter Driver.) -- C:\windows\System32\drivers\PGEffect.sys [38096] =>.TOSHIBA CORPORATION®
O58 - SDL:2009/06/15 13:58:50 A . (.TOSHIBA - Generic IO & Memory Access.) -- C:\windows\System32\drivers\QIOMem.sys [12800] =>.Toshiba
O58 - SDL:2009/07/13 18:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\windows\System32\drivers\ql2300.sys [1524816] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\windows\System32\drivers\ql40xx.sys [128592] =>.Microsoft Windows®
O58 - SDL:2011/07/08 17:06:08 A . (.Realtek Semiconductor Corp. - Realtek Turbo Mode Filter Driver for 39.) -- C:\windows\System32\drivers\rtcrfilt64.sys [18024] =>.Realtek Semiconductor Corp®
O58 - SDL:2010/03/31 11:10:18 A . (.Realtek Semiconductor Corporation - Realtek RTL8187B NDIS Driver.) -- C:\windows\System32\drivers\rtl8187B.sys [450048] =>.Realtek Semiconductor Corporation
O58 - SDL:2010/04/01 14:01:10 A . (.Realtek Semiconductor Corporation - Realtek RTL8187S PCIE NDIS Driverr.) -- C:\windows\System32\drivers\rtl8187Se.sys [442368] =>.Realtek Semiconductor Corporation
O58 - SDL:2011/01/05 01:08:58 A . (.Realtek Semiconductor Corporation - Realtek RTL81892CE NDIS Driverr.) -- C:\windows\System32\drivers\rtl8192ce.sys [1109096] =>.Realtek Semiconductor Corp®
O58 - SDL:2010/12/17 16:04:28 A . (.Realtek Semiconductor Corporation - Realtek RTL81892SE NDIS Driverr.) -- C:\windows\System32\drivers\rtl8192se.sys [1221224] =>.Realtek Semiconductor Corp®
O58 - SDL:2010/12/22 16:24:00 A . (.Realtek Semiconductor Corporation - Realtek RTL819xP NDIS Driverr.) -- C:\windows\System32\drivers\rtl819xp.sys [626792] =>.Realtek Semiconductor Corp®
O58 - SDL:2010/12/01 16:12:06 A . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/V.) -- C:\windows\System32\drivers\RtsUStor.sys [250984] =>.Realtek Semiconductor Corp®
O58 - SDL:2011/07/08 17:06:08 A . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/V.) -- C:\windows\System32\drivers\rtsuvstor.sys [307304] =>.Realtek Semiconductor Corp®
O58 - SDL:2009/06/10 13:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\windows\System32\drivers\secdrv.sys [23040] =>.Macrovision Corporation, Macrovision Europe Limited,
O58 - SDL:2009/07/13 18:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\windows\System32\drivers\sisraid2.sys [43584] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\windows\System32\drivers\sisraid4.sys [80464] =>.Microsoft Windows®
O58 - SDL:2016/08/30 16:15:58 A . (.Authors - .) -- C:\windows\System32\drivers\staport.sys [44952] =>.AVAST Software a.s.®
O58 - SDL:2009/07/13 18:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\windows\System32\drivers\stexstor.sys [24656] =>.Microsoft Windows®
O58 - SDL:2011/02/03 19:59:06 A . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\windows\System32\drivers\SynTP.sys [1413680] =>.Synaptics Incorporated®
O58 - SDL:2009/07/30 20:22:04 A . (.TOSHIBA Corporation. - TOSHIBA ODD Writing Driver for x64..) -- C:\windows\System32\drivers\tdcmdpst.sys [27784] =>.TOSHIBA CORPORATION®
O58 - SDL:2009/06/24 15:36:48 A . (.TOSHIBA Corporation - tos_sps64.) -- C:\windows\System32\drivers\tos_sps64.sys [482384] =>.TOSHIBA CORPORATION®
O58 - SDL:2017/04/19 16:55:39 A . (.Authors - .) -- C:\windows\System32\drivers\TrueSight.sys [28272] =>.Adlice®
O58 - SDL:2009/06/19 19:15:22 A . (.TOSHIBA Corporation - TOSHIBA TVALZ Filter Driver for x64.) -- C:\windows\System32\drivers\TVALZFL.sys [14472] =>.TOSHIBA CORPORATION®
O58 - SDL:2009/07/14 15:31:18 A . (.TOSHIBA Corporation - TOSHIBA ACPI-Based Value Added Logical and.) -- C:\windows\System32\drivers\TVALZ_O.SYS [26840] =>.TOSHIBA CORPORATION®
O58 - SDL:2009/07/13 18:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\windows\System32\drivers\viaide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2009/07/13 18:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\windows\System32\drivers\vsmraid.sys [161872] =>.Microsoft Windows®
O58 - SDL:2009/06/10 14:01:11 A . (.Conexant Systems, Inc. - HSF_HWAZL WDM driver.) -- C:\windows\System32\drivers\VSTAZL6.SYS [292864] =>.Conexant Systems, Inc.
O58 - SDL:2009/06/10 14:01:11 A . (.Conexant Systems, Inc. - HSF_CNXT driver.) -- C:\windows\System32\drivers\VSTCNXT6.SYS [740864] =>.Conexant Systems, Inc.
O58 - SDL:2009/06/10 14:01:11 A . (.Conexant Systems, Inc. - HSF_DP driver.) -- C:\windows\System32\drivers\VSTDPV6.SYS [1485312] =>.Conexant Systems, Inc.
O58 - SDL:2016/09/04 14:33:24 A . (.Zemana Ltd. - ZAM.) -- C:\windows\System32\drivers\zam64.sys [203680] =>.Zemana Ltd.®
O58 - SDL:2016/09/04 14:33:21 A . (.Zemana Ltd. - ZAM.) -- C:\windows\System32\drivers\zamguard64.sys [203680] =>.Zemana Ltd.®

---\\ Last modified or created user files (1) - 20s
O61 - LFC: 2017/04/19 20:57:07 A . (.Trend Micro Inc. & Stanislav Polshyn.) -- C:\Users\Mitch\Desktop\HiJackThis\HiJackThis.exe [1147984]

---\\ File Associations Shell Spawning (10) - 1s
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S

---\\ Start Menu Internet (12) - 0s
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: <SafeZoneStable> <SafeZone Stable>[HKLM\..\Shell\open\Command] (.Avast Software - Avast SafeZone Browser.) -- C:\Program Files\AVAST Software\SZBrowser\Launcher.exe =>.AVAST Software s.r.o.®
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <SafeZoneStable> <SafeZone Stable>[HKLM\..\InstallInfo\ShowIconsCommand] (.Avast Software - Avast SafeZone Browser.) -- C:\Program Files\AVAST Software\SZBrowser\launcher.exe =>.AVAST Software
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <SafeZoneStable> <SafeZone Stable>[HKLM\..\InstallInfo\ReinstallCommand] (.Avast Software - Avast SafeZone Browser.) -- C:\Program Files\AVAST Software\SZBrowser\launcher.exe =>.AVAST Software
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <SafeZoneStable> <SafeZone Stable>[HKLM\..\InstallInfo\HideIconsCommand] (.Avast Software - Avast SafeZone Browser.) -- C:\Program Files\AVAST Software\SZBrowser\launcher.exe =>.AVAST Software

---\\ Search Browser Infection (1) - 0s
O69 - SBI: SearchScopes [HKCU] {012E1000-F331-11DB-8314-0800200C9A66} - (Google) - http://www.google.com/ =>.Google Inc.

---\\ Search Svchost Services (32) - 1s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\windows\System32\aelupsvc.dll [72192] =>.Microsoft Corporation
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\windows\System32\certprop.dll [80384] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\windows\System32\certprop.dll [80384] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\windows\system32\srvsvc.dll [236032] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\windows\System32\gpsvc.dll [777728] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\windows\System32\ikeext.dll [853504] =>.Microsoft Corporation
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\windows\System32\Audiosrv.dll [679424] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\windows\System32\rasauto.dll [99328] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\windows\System32\rasmans.dll [344064] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [97792] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\Sens.dll [64512] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\windows\System32\ipnathlp.dll [359424] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [316928] =>.Microsoft Corporation
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- C:\windows\System32\termsrv.dll [680960] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\windows\system32\wuaueng.dll [2428952] =>.Microsoft Windows Component Publisher®
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\windows\System32\qmgr.dll [849920] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [370688] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\windows\System32\iphlpsvc.dll [569344] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\windows\system32\seclogon.dll [30720] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\windows\System32\appinfo.dll [70656] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\windows\system32\iscsiexe.dll [156672] =>.Microsoft Corporation
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) -- C:\windows\system32\mmcss.dll [67584] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\windows\system32\wbem\WMIsvc.dll [242688] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [121856] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\windows\System32\browser.dll [136192] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\windows\System32\eapsvc.dll [111104] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\windows\system32\schedsvc.dll [1110016] =>.Microsoft Corporation
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\windows\system32\kmsvc.dll [90624] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\windows\System32\wercplsupport.dll [84480] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\windows\system32\profsvc.dll [209920] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\windows\system32\themeservice.dll [44544] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\windows\System32\bdesvc.dll [100864] =>.Microsoft Corporation

---\\ Additional Scan (O88) (1) - 0s
~ No malicious or unnecessary items found.

---\\ Summary of the elements found (1) - 0s
~ No malicious or unnecessary items found.

~ Unselected Options:
~ End of the scan, 50558 items in 01mn48s (887)(0)
 
My friend wants to install OpenOffice, yet when we attempted it consistently comes up with this error. How do we fix it?
 

Attachments

  • registry error.png
    registry error.png
    1.1 MB · Views: 10
Just a heads up. He left for tonight and will be back next Wednesday. The final thing I did to clear the clutter was run Delfix and ONLY remove all the tools on the desktop. Was this okay to do?
 
Status
Not open for further replies.