Rat infection

  • Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.
Status
Not open for further replies.
ZHP Diag Scan Click here to download.
Save to your desktop.
Right Click Run as Admin.
Click the Options button.
Click on Check All
Then click close.
Click the Scanner button.
When complete please push the report button.
A notepad will open... attach the report in your next reply.
 
Capture1.PNG
 

Attachments

ZHPDiag Diagnostic Report​

~ ZHPDiag v2022.10.4.79 By Nicolas Coolman (2022/10/04)
~ Run by TeaTang (Administrator) (2022/10/04 16:05:24)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Legal
~ State version: Version KO
~ Mode: Scan
~ Report: C:\Users\TeaTang\Desktop\ZHPDiag.txt
~ Report: C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ System startup: Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 17134) =>.Microsoft Corporation


---\ Internet Browsers (1) - 0s
~ MSIE: Internet Explorer v11.165.17134.0

---\ Windows Product Information (3) - 0s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK

---\ System protection software (2) - 2s
Windows Defender W10 (Activate) (Protection)
Malwarebytes version 4.5.12.204 v4.5.12.204 (Protection)

---\ Informations on the system (7) - 0s
~ Operating System: AMD64 Family 16 Model 5 Stepping 3, AuthenticAMD
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 12580.404 MB (77% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 834 GB (87%) free of 953 GB : OK =>.Disk Space
Total RAM: 12580.404 MB (75% free) : OK =>.RAM Value

---\ Connection to the system mode (3) - 0s
~ Computer Name: DESKTOP-GRKBJ8K
~ User Name: TeaTang
~ Logged in as Administrator

---\ Enumeration of the disk units (1) - 5s
~ Drive C: has 834 GB free of 953 GB (System)

---\ SYSTEM DISK MAIN FEATURES (27) - 22s
~ Model: TOSHIBA HDWD110 ATA Device vMS2OA8J0 (953 Gb )
~ Media Type: HDD Fixed Disk ( Bus: ATA)


---\ SYSTEM DISK GENERAL ATTRIBUTES
OK - N0 - Indicateur d'usure du périphérique de stockage (Storage Device Wear Indicator) (%): 0
OK - N1 - Temps de latence maximal de vidage (Maximum Flash latency) (ms): 0.466
OK - N2 - Temps de latence maximal d'écriture (Maximum write latency) (ms): 9.033
OK - N3 - Temps de latence maximal de lecture (Maximum read latency) (ms): 7.177


---\ S.M.A.R.T. PARAMETERS - [Flag][Value][Worst] [Threshold][Raw Value]
OK - 01 - Taux d'erreur de lecture (Raw Read Error Rate) - [11][100][100] [16][0]
OK - 02 - Performance de débit (Throughput Performance) - [5][141][141] [54][73]
OK - 03 - Temps moyen de mise en rotation (ms) (Spin-Up Time) - [7][121][121] [24][190]
OK - 04 - Nombre de démarrages/arrêts (Start/Stop Count) - [18][99][99] [0][5859]
OK - 05 - Nombre de secteurs réalloués (Reallocated Sector Count) - [51][100][100] [5][0]
OK - 07 - Taux d’erreurs de recherche (Seek Error Rate) - [11][100][100] [67][0]
OK - 08 - Recherche de performance de temps (Seek Time Performance) - [5][115][115] [20][34]
OK - 09 - Heures de fonctionnement (Power-On Hours Count (POH) - [18][100][100] [0][4334]
OK - 0A - Nombre d'essai de relance de rotation (Spin Retry Count) - [19][100][100] [60][0]
OK - 0C - Nombre total de cycles d’alimentation (Power Cycle Count) - [50][99][99] [0][4322]
OK - C0 - Nombre de Rétractation d'armature magnétique (Power-off Retract Count) - [50][96][96] [0][5893]
OK - C1 - Cycles de charge/décharge (Load/Unload Cycle Count) - [18][96][96] [0][5898]
OK - C2 - Température interne actuelle (Enclosure Temperature) - [2][162][162] [0][37]
OK - C4 - Nombre d'opérations de réallocations (remap) (Reallocation Event Count) - [50][100][100] [0][0]
OK - C5 - Nombre de secteurs instables (Current Pending Sector Count) - [34][100][100] [0][0]
OK - C6 - Total d'erreurs incorrigibles d'un secteur (Off-Line Uncorrectable Sector Count) - [8][100][100] [0][0]
OK - C7 - Nombre d'erreurs dans le transfert de données (Ultra ATA CRC Error Rate) - [10][200][200] [0][967]

---\ State of the Windows Security Center (7) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\ Search Generic System Files (25) - 3s
[MD5.E4A81EDDFF8B844D85C8B45354E4144E] - 12/07/2018 - (.Microsoft Corporation - Windows Explorer.) -- C:\Windows\Explorer.exe [3932672] =>.Microsoft Windows®
[MD5.73C519F050C20580F8A62C849D49215A] - 12/04/2018 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe [69632] [Unsigned] =>.Microsoft Corporation
[MD5.A58B0CB069DA7840B935872ADCD7F0C2] - 12/04/2018 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\Windows\System32\Wininit.exe [366792] [Unsigned] =>.Microsoft Corporation
[MD5.73FF1844030943E6D81A405FF419A245] - 12/07/2018 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\Windows\System32\wininet.dll [3440128] [Unsigned] =>.Microsoft Corporation
[MD5.3E56F9D58EBBB1B33E31B86267DBECFC] - 12/07/2018 - (.Microsoft Corporation - Windows Logon Application.) -- C:\Windows\System32\Winlogon.exe [677376] [Unsigned] =>.Microsoft Corporation
[MD5.7A377800FF15426B7D89768A8727CFEF] - 12/04/2018 - (.Microsoft Corporation - Software Licensing Library.) -- C:\Windows\System32\sppcomapi.dll [415232] [Unsigned] =>.Microsoft Corporation
[MD5.F4B9F200B9D7EBC8BD4C8E39F02A44E3] - 12/07/2018 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\System32\dnsapi.dll [766608] =>.Microsoft Windows®
[MD5.BE663A3C8E4F3ED2E8404A808614BCE3] - 12/07/2018 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\Syswow64\dnsapi.dll [573904] =>.Microsoft Windows®
[MD5.63C79AD0202728F4608757340B7D602B] - 12/07/2018 - (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng.dll [2903040] [Unsigned] =>.Microsoft Corporation
[MD5.4DCCC3E02A22ED4A4ADB11386F226071] - 12/04/2018 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [626592] [Unsigned] =>.Microsoft Corporation
[MD5.90AB4ED8EBD72A1C096A40CC35404B91] - 12/04/2018 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [28568] [Unsigned] =>.Microsoft Corporation
[MD5.D3CBC6DE5955D014407C7BD1FFE80F00] - 12/04/2018 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [93696] [Unsigned] =>.Microsoft Corporation
[MD5.6834DBBA2A1DBA5B9B6360D0B9A3CBB5] - 12/07/2018 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [159744] [Unsigned] =>.Microsoft Corporation
[MD5.8A1C10410FDA4287A76EC5A64371E221] - 12/07/2018 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [141312] [Unsigned] =>.Microsoft Corporation
[MD5.DED74127C7A2266715C0B8EA2EE75214] - 12/04/2018 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [86016] [Unsigned] =>.Microsoft Corporation
[MD5.DA179667B8CEC22E4ECBBF4210DC0E35] - 12/04/2018 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\Windows\System32\drivers\i8042prt.sys [105984] [Unsigned] =>.Microsoft Corporation
[MD5.7408B83959A4B8271EF67FD06A6B366B] - 12/04/2018 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [214528] [Unsigned] =>.Microsoft Corporation
[MD5.3C0FA2ED75875481D00F3D77B1A3E336] - 12/04/2018 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [500632] [Unsigned] =>.Microsoft Corporation
[MD5.045A018E0BA5F9B75C5928A31C0E822C] - 12/04/2018 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [311296] [Unsigned] =>.Microsoft Corporation
[MD5.FCEFE8F8E6F5D46BB4BFA6DDEF6392E6] - 12/07/2018 - (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [2420632] [Unsigned] =>.Microsoft Corporation
[MD5.13B175715A4391E4E5D2AB2EBC8CDBB5] - 12/04/2018 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\Windows\System32\drivers\Parport.sys [98816] [Unsigned] =>.Microsoft Corporation
[MD5.775ED7E51B58CF9EB415A1DBA540DACF] - 12/04/2018 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [106496] [Unsigned] =>.Microsoft Corporation
[MD5.3DE4216324BE32FC3AF7667AE2406EE5] - 12/07/2018 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [182784] [Unsigned] =>.Microsoft Corporation
[MD5.16071C42E21CE3378FA449322FB9AB1D] - 12/04/2018 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [121248] [Unsigned] =>.Microsoft Corporation
[MD5.F0EE4E6028CCA58BEA9A04E7BEAB7DB4] - 12/04/2018 - (.Microsoft Corporation - Volume Shadow Copy driver.) -- C:\Windows\System32\drivers\volsnap.sys [398240] [Unsigned] =>.Microsoft Corporation

---\ No disabled Windows Services (56) - 3s
O23 - Service: C:\Windows\System32\AudioEndpointBuilder.dll (AudioEndpointBuilder) . (.Microsoft Corporation - Windows Audio Endpoint Builder.) - C:\Windows\System32\AudioEndpointBuilder.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\audiosrv.dll (Audiosrv) . (.Microsoft Corporation - Windows Audio Service.) - C:\Windows\System32\Audiosrv.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\bfe.dll (BFE) . (.Microsoft Corporation - Base Filtering Engine.) - C:\Windows\System32\bfe.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\system32\bisrv.dll (BrokerInfrastructure) . (.Microsoft Corporation - Background Tasks Infrastructure Service.) - C:\Windows\System32\bisrv.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\cdpusersvc.dll (CDPUserSvc) . (.Microsoft Corporation - Microsoft (R) CDP User Components.) - C:\Windows\System32\CDPUserSvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Connected Devices Platform User Service_1725c86 (CDPUserSvc_1725c86) . (.Microsoft Corporation - Host Process for Windows Services.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
O23 - Service: C:\Windows\System32\coremessaging.dll (CoreMessagingRegistrar) . (.Microsoft Corporation - Microsoft CoreMessaging Dll.) - C:\Windows\System32\coremessaging.dll =>.Microsoft Windows®
O23 - Service: C:\Windows\System32\cryptsvc.dll (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) - C:\Windows\System32\cryptsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\das.dll (DeviceAssociationService) . (.Microsoft Corporation - Device Association Service.) - C:\Windows\System32\das.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dhcpcore.dll (Dhcp) . (.Microsoft Corporation - DHCP Client Service.) - C:\Windows\System32\dhcpcore.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dnsapi.dll (Dnscache) . (.Microsoft Corporation - DNS Caching Resolver Service.) - C:\Windows\System32\dnsrslvr.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dosvc.dll (DoSvc) . (.Microsoft Corporation - Host Process for Windows Services.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
O23 - Service: C:\Windows\System32\dusmsvc.dll (DusmSvc) . (.Microsoft Corporation - Data Usage Service.) - C:\Windows\System32\dusmsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Microsoft Edge Update Service (edgeupdate) (edgeupdate) . (.Microsoft Corporation - Microsoft Edge Update.) - C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe =>.Microsoft®
O23 - Service: C:\Windows\System32\wevtsvc.dll (EventLog) . (.Microsoft Corporation - Host Process for Windows Services.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
O23 - Service: @comres.dll,-2450 (EventSystem) . (.Microsoft Corporation - COM+.) - C:\Windows\System32\es.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\FntCache.dll (FontCache) . (.Microsoft Corporation - Windows Font Cache Service.) - C:\Windows\System32\FntCache.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: @gpapi.dll,-112 (gpsvc) . (.Microsoft Corporation - Group Policy Client.) - C:\Windows\System32\gpsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\ikeext.dll (IKEEXT) . (.Microsoft Corporation - IKE extension.) - C:\Windows\System32\ikeext.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\iphlpsvc.dll (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) - C:\Windows\System32\iphlpsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\srvsvc.dll (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) - C:\Windows\System32\srvsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wkssvc.dll (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) - C:\Windows\System32\wkssvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\system32\lsm.dll (LSM) . (.Microsoft Corporation - Local Session Manager Service.) - C:\Windows\System32\lsm.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\moshost.dll (MapsBroker) . (.Microsoft Corporation - Downloaded Maps Manager.) - C:\Windows\System32\moshost.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\FirewallAPI.dll (mpssvc) . (.Microsoft Corporation - Microsoft Protection Service.) - C:\Windows\System32\mpssvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\nlasvc.dll (NlaSvc) . (.Microsoft Corporation - Network Location Awareness 2.) - C:\Windows\System32\nlasvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\nsisvc.dll (nsi) . (.Microsoft Corporation - Network Store Interface RPC server.) - C:\Windows\System32\nsisvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) . (.NVIDIA Corporation - NVIDIA Container.) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe =>.NVIDIA Corporation®
O23 - Service: C:\Windows\System32\APHostRes.dll (OneSyncSvc) . (.Microsoft Corporation - Accounts Host Service.) - C:\Windows\System32\APHostService.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Sync Host_1725c86 (OneSyncSvc_1725c86) . (.Microsoft Corporation - Host Process for Windows Services.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
O23 - Service: C:\Windows\System32\umpo.dll (Power) . (.Microsoft Corporation - User-mode Power Service.) - C:\Windows\System32\umpo.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\profsvc.dll (ProfSvc) . (.Microsoft Corporation - ProfSvc.) - C:\Windows\System32\profsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\rasmans.dll (RasMan) . (.Microsoft Corporation - Remote Access Connection Manager.) - C:\Windows\System32\rasmans.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\system32\RpcEpMap.dll (RpcEptMapper) . (.Microsoft Corporation - RPC Endpoint Mapper.) - C:\Windows\System32\RpcEpMap.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: @combase.dll,-5010 (RpcSs) . (.Microsoft Corporation - Distributed COM Services.) - C:\Windows\System32\rpcss.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\schedsvc.dll (Schedule) . (.Microsoft Corporation - Task Scheduler Service.) - C:\Windows\System32\schedsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\SecurityHealthAgent.dll (SecurityHealthService) . (.Microsoft Corporation - Windows Security Health Service.) - C:\Windows\System32\SecurityHealthService.exe [Unsigned] =>.Microsoft Corporation
O23 - Service: Windows Remediation Service (sedsvc) . (.Microsoft Corporation - sedsvc.) - C:\Program Files\rempl\sedsvc.exe =>.Microsoft®
O23 - Service: C:\Windows\System32\Sens.dll (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) - C:\Windows\System32\sens.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\SgrmBroker.exe,-100 (SgrmBroker) . (.Microsoft Corporation - System Guard Runtime Monitor Broker Service.) - C:\Windows\System32\SgrmBroker.exe [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\shsvcs.dll (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) - C:\Windows\System32\shsvcs.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\spoolsv.exe,-1 (Spooler) . (.Microsoft Corporation - Spooler SubSystem App.) - C:\Windows\System32\spoolsv.exe [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\sppsvc.exe,-101 (sppsvc) . (.Microsoft Corporation - Microsoft Software Protection Platform Serv.) - C:\Windows\System32\sppsvc.exe [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\system32\SystemEventsBrokerServer.dll (SystemEventsBroker) . (.Microsoft Corporation - System Events Broker.) - C:\Windows\System32\SystemEventsBrokerServer.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\themeservice.dll (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) - C:\Windows\System32\themeservice.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\usermgr.dll (UserManager) . (.Microsoft Corporation - UserMgr.) - C:\Windows\System32\usermgr.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\usocore.dll (UsoSvc) . (.Microsoft Corporation - Update Session Orchestrator Core.) - C:\Windows\System32\usocore.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wcmsvc.dll (Wcmsvc) . (.Microsoft Corporation - Windows Connection Manager Service DLL.) - C:\Windows\System32\wcmsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) . (.Microsoft Corporation - Antimalware Service Executable.) - C:\Program Files\Windows Defender\MsMpEng.exe =>.Microsoft Corporation®
O23 - Service: C:\Windows\System32\wbem\wmisvc.dll (Winmgmt) . (.Microsoft Corporation - WMI.) - C:\Windows\System32\wbem\WMIsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wlansvc.dll (WlanSvc) . (.Microsoft Corporation - Windows WLAN AutoConfig Service DLL.) - C:\Windows\System32\wlansvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wpnservice.dll (WpnService) . (.Microsoft Corporation - Windows Push Notification System Service.) - C:\Windows\System32\WpnService.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\WpnUserService.dll (WpnUserService) . (.Microsoft Corporation - Windows Push Notification User Service.) - C:\Windows\System32\WpnUserService.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Windows Push Notifications User Service_1725c86 (WpnUserService_1725c86) . (.Microsoft Corporation - Host Process for Windows Services.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
O23 - Service: C:\Windows\System32\wscsvc.dll (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) - C:\Windows\System32\wscsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\SearchIndexer.exe,-103 (WSearch) . (.Microsoft Corporation - Microsoft Windows Search Indexer.) - C:\Windows\System32\SearchIndexer.exe [Unsigned] =>.Microsoft Corporation

---\ Services not Microsoft (SR=Run, SS=Stop) (65) - 8s
SR - Boot [12/04/2018] [ 107416] (3ware) . (.LSI.) - C:\Windows\System32\drivers\3ware.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 1135520] (ADP80XX) . (.PMC-Sierra.) - C:\Windows\System32\drivers\ADP80XX.SYS =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 83360] (amdsata) . (.Advanced Micro Devices.) - C:\Windows\System32\drivers\amdsata.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 259480] (amdsbs) . (.AMD Technologies Inc..) - C:\Windows\System32\drivers\amdsbs.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 27032] (amdxata) . (.Advanced Micro Devices.) - C:\Windows\System32\drivers\amdxata.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 132000] Adaptec SAS/SATA-II RAID S (arcsas) . (.PMC-Sierra, Inc..) - C:\Windows\System32\drivers\arcsas.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 533912] QLogic Network Adapter VBD (b06bdrv) . (.QLogic Corporation.) - C:\Windows\System32\drivers\bxvbda.sys =>.Microsoft Windows®
SR - Demand [20/07/2017] [ 47176] VirtIO Balloon Service (BALLOON) . (.Red Hat, Inc..) - C:\Windows\System32\drivers\balloon.sys {56C6D267ADE07F72EEB4603BBF84CEA5}. =>.Red Hat, Inc.
SR - Demand [12/04/2018] [ 9728] bcmfn2 Service (bcmfn2) . (...) - C:\Windows\System32\drivers\bcmfn2.sys [Unsigned] =>.Broadcom Corporation
SR - Boot [12/04/2018] [ 321432] (cht4iscsi) . (.Chelsio Communications.) - C:\Windows\System32\drivers\cht4sx64.sys =>.Microsoft Windows®
SR - Demand [12/04/2018] [ 1836952] Chelsio Virtual Bus Driver (cht4vbd) . (.Chelsio Communications.) - C:\Windows\System32\drivers\cht4vx64.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 3419032] QLogic 10 Gigabit Ethernet Ada (ebdrv) . (.QLogic Corporation.) - C:\Windows\System32\drivers\evbda.sys =>.Microsoft Windows®
SR - System [14/05/2017] [ 42616] ElbyCDIO Driver (ElbyCDIO) . (.Elaborate Bytes AG.) - C:\Windows\System32\Drivers\ElbyCDIO.sys =>.Microsoft Windows Hardware Compatibility Publisher®
SR - Boot [12/04/2018] [ 64408] (HpSAMD) . (.Hewlett-Packard Company.) - C:\Windows\System32\drivers\HpSAMD.sys =>.Microsoft Windows®
SR - Demand [12/04/2018] [ 36864] Intel Serial IO GPIO Controlle (iagpio) . (.Intel(R) Corporation.) - C:\Windows\System32\drivers\iagpio.sys [Unsigned] =>.Intel(R) Corporation
SR - Demand [12/04/2018] [ 91648] Intel(R) Serial IO I2C Host Cont (iai2c) . (.Intel(R) Corporation.) - C:\Windows\System32\drivers\iai2c.sys [Unsigned] =>.Intel(R) Corporation
SR - Demand [12/04/2018] [ 79360] Intel(R) S (iaLPSS2i_GPIO2) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaLPSS2i_GPIO2.sys [Unsigned] =>.Intel Corporation
SR - Demand [12/04/2018] [ 88576] In (iaLPSS2i_GPIO2_BXT_P) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [Unsigned] =>.Intel Corporation
SR - Demand [12/04/2018] [ 171520] Intel(R) Seria (iaLPSS2i_I2C) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaLPSS2i_I2C.sys [Unsigned] =>.Intel Corporation
SR - Demand [12/04/2018] [ 174592] Intel( (iaLPSS2i_I2C_BXT_P) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [Unsigned] =>.Intel Corporation
SR - Demand [12/04/2018] [ 38128] Intel(R) Serial IO (iaLPSSi_GPIO) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaLPSSi_GPIO.sys =>.Intel Corporation - Client Components Group®
SR - Demand [12/04/2018] [ 113152] Intel(R) Serial IO I (iaLPSSi_I2C) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaLPSSi_I2C.sys [Unsigned] =>.Intel Corporation
SR - Boot [12/04/2018] [ 885144] Intel Chipset SATA RAI (iaStorAVC) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaStorAVC.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 412064] Intel RAID Controller Wi (iaStorV) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaStorV.sys =>.Microsoft Windows®
SR - Demand [12/04/2018] [ 526232] Mellanox InfiniBand Bus/A (ibbus) . (.Mellanox.) - C:\Windows\System32\drivers\ibbus.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 145816] (ItSas35i) . (.Avago Technologies.) - C:\Windows\System32\drivers\ItSas35i.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 108952] (LSI_SAS) . (.LSI Corporation.) - C:\Windows\System32\drivers\lsi_sas.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 124312] (LSI_SAS2i) . (.LSI Corporation.) - C:\Windows\System32\drivers\lsi_sas2i.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 128408] (LSI_SAS3i) . (.Avago Technologies.) - C:\Windows\System32\drivers\lsi_sas3i.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 82848] (LSI_SSS) . (.LSI Corporation.) - C:\Windows\System32\drivers\lsi_sss.sys =>.Microsoft Windows®
SR - Boot [08/08/2022] [ 21480] MbamElam (MbamElam) . (.Malwarebytes.) - C:\Windows\System32\DRIVERS\MbamElam.sys =>.Microsoft®
SS - Demand [08/08/2022] [ 8680192] Malwarebytes Service (MBAMService) . (.Malwarebytes.) - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe =>.Malwarebytes Inc.®
SR - Demand [09/08/2022] [ 239544] MBAMSwissArmy (MBAMSwissArmy) . (.Malwarebytes.) - C:\Windows\System32\Drivers\mbamswissarmy.sys =>.Microsoft®
SR - Boot [12/04/2018] [ 59800] (megasas) . (.Avago Technologies.) - C:\Windows\System32\drivers\megasas.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 75160] (megasas2i) . (.Avago Technologies.) - C:\Windows\System32\drivers\MegaSas2i.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 82328] (megasas35i) . (.Avago Technologies.) - C:\Windows\System32\drivers\megasas35i.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 575896] (megasr) . (.LSI Corporation, Inc..) - C:\Windows\System32\drivers\megasr.sys =>.Microsoft Windows®
SR - Demand [12/04/2018] [ 842648] Mellanox ConnectX Bus E (mlx4_bus) . (.Mellanox.) - C:\Windows\System32\drivers\mlx4_bus.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 63904] (mvumis) . (.Marvell Semiconductor, Inc..) - C:\Windows\System32\drivers\mvumis.sys =>.Microsoft Windows®
SR - Demand [12/04/2018] [ 108952] NetworkDirect Service (ndfltr) . (.Mellanox.) - C:\Windows\System32\drivers\ndfltr.sys =>.Microsoft Windows®
SR - Auto [27/10/2017] [ 462968] NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe =>.NVIDIA Corporation®
SR - Demand [09/11/2017] [ 233904] Service for NVIDIA High Definiti (NVHDA) . (.NVIDIA Corporation.) - C:\Windows\System32\drivers\nvhda64v.sys =>.NVIDIA Corporation®
SR - Demand [09/11/2017] [16936048] (nvlddmkm) . (.NVIDIA Corporation.) - C:\Windows\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_2e7fa54192fe16d0\nvlddmkm.sys =>.NVIDIA Corporation®
SR - Boot [12/04/2018] [ 150424] (nvraid) . (.NVIDIA Corporation.) - C:\Windows\System32\drivers\nvraid.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 166304] (nvstor) . (.NVIDIA Corporation.) - C:\Windows\System32\drivers\nvstor.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 58776] (percsas2i) . (.Avago Technologies.) - C:\Windows\System32\drivers\percsas2i.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 61848] (percsas3i) . (.Avago Technologies.) - C:\Windows\System32\drivers\percsas3i.sys =>.Microsoft Windows®
SR - Demand [12/04/2018] [ 604160] Realtek RT640 NT Dri (rt640x64) . (.Realtek.) - C:\Windows\System32\drivers\rt640x64.sys [Unsigned] =>.Realtek
SR - Demand [26/02/2019] [ 8287464] Realtek Wireless L (RtlWlanu) . (.Realtek Semiconductor Corporation.) - C:\Windows\System32\drivers\rtwlanu.sys =>.Realtek Semiconductor Corp.®
SR - Boot [12/04/2018] [ 44952] (SiSRaid2) . (.Silicon Integrated Systems Corp..) - C:\Windows\System32\drivers\SiSRaid2.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 81816] (SiSRaid4) . (.Silicon Integrated Systems.) - C:\Windows\System32\drivers\sisraid4.sys =>.Microsoft Windows®
SS - Demand [26/07/2022] [ 2663312] Steam Client Service (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\steamservice.exe =>.Valve Corp.®
SR - Boot [12/04/2018] [ 31128] (stexstor) . (.Promise Technology, Inc..) - C:\Windows\System32\drivers\stexstor.sys =>.Microsoft Windows®
SR - Demand [19/07/2022] [ 242656] VirtualBox NDIS 6.0 Miniport Service (VBoxNetAdp) . (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys =>.Oracle Corporation®
SR - System [19/07/2022] [ 252560] VirtualBox NDIS6 Bridge (VBoxNetLwf) . (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxNetLwf.sys =>.Oracle Corporation®
SS - Demand [19/07/2022] [ 748664] VirtualBox system service (VBoxSDS) . (.Oracle Corporation.) - C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe =>.Oracle Corporation®
SR - System [19/07/2022] [ 1081592] VirtualBox Service (VBoxSup) . (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxSup.sys =>.Oracle Corporation®
SR - System [19/07/2022] [ 191184] VirtualBox USB Monitor Service (VBoxUSBMon) . (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxUSBMon.sys =>.Oracle Corporation®
SR - Demand [22/02/2020] [ 44544] (VClone) . (.Elaborate Bytes AG.) - C:\Windows\System32\drivers\VClone.sys =>.Microsoft®
SR - Boot [20/07/2017] [ 40008] (viostor) . (.Red Hat, Inc..) - C:\Windows\System32\drivers\viostor.sys {56C6D267ADE07F72EEB4603BBF84CEA5}. =>.Red Hat, Inc.
SR - Demand [20/07/2017] [ 43080] VirtIO RNG Service (VirtRng) . (.Red Hat, Inc..) - C:\Windows\System32\drivers\viorng.sys {56C6D267ADE07F72EEB4603BBF84CEA5}. =>.Red Hat, Inc.
SR - Boot [12/04/2018] [ 166808] (vsmraid) . (.VIA Technologies Inc.,Ltd.) - C:\Windows\System32\drivers\vsmraid.sys =>.Microsoft Windows®
SR - Boot [12/04/2018] [ 305560] VIA StorX Storage RAID Co (VSTXRAID) . (.VIA Corporation.) - C:\Windows\System32\drivers\vstxraid.sys =>.Microsoft Windows®
SR - Demand [12/04/2018] [ 32152] WinMad Service (WinMad) . (.Mellanox.) - C:\Windows\System32\drivers\winmad.sys =>.Microsoft Windows®
SR - Demand [12/04/2018] [ 64920] WinVerbs Service (WinVerbs) . (.Mellanox.) - C:\Windows\System32\drivers\winverbs.sys =>.Microsoft Windows®

---\ Auto loading programs from Registry and folders (9) - 1s
O4 - HKLM\..\Run: [SecurityHealth] . (.Microsoft Corporation - Windows Defender notification icon.) -- C:\Program Files\Windows Defender\MSASCuiL.exe =>.Microsoft Windows®
O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\TeaTang\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - HKCU\..\Run: [Steam] . (.Valve Corporation - Steam.) -- C:\Program Files (x86)\Steam\steam.exe =>.Valve Corp.®
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
O4 - HKUS\S-1-5-19\..\StartupApproved\Run: [OneDriveSetup] . (. - .) -- 0x020000000000000000000000 =>.SUP.Orphan
O4 - HKUS\S-1-5-20\..\StartupApproved\Run: [OneDriveSetup] . (. - .) -- 0x020000000000000000000000 =>.SUP.Orphan
O4 - HKUS\S-1-5-21-3407470762-2713599730-1590247004-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\TeaTang\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - HKUS\S-1-5-21-3407470762-2713599730-1590247004-1001\..\Run: [Steam] . (.Valve Corporation - Steam.) -- C:\Program Files (x86)\Steam\steam.exe =>.Valve Corp.®

---\ Process running (17) - 3s
[MD5.025D6E81F4BF7E57FFDFCE132C98B8BA] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968] [PID.6312] =>.NVIDIA Corporation®
[MD5.025D6E81F4BF7E57FFDFCE132C98B8BA] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968] [PID.9316] =>.NVIDIA Corporation®
[MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.7948] [Unsigned] =>.Mozilla Corporation
[MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.9356] [Unsigned] =>.Mozilla Corporation
[MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.8072] [Unsigned] =>.Mozilla Corporation
[MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.6804] [Unsigned] =>.Mozilla Corporation
[MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.2564] [Unsigned] =>.Mozilla Corporation
[MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.744] [Unsigned] =>.Mozilla Corporation
[MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.9380] [Unsigned] =>.Mozilla Corporation
[MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.7696] [Unsigned] =>.Mozilla Corporation
[MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.9240] [Unsigned] =>.Mozilla Corporation
[MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.912] [Unsigned] =>.Mozilla Corporation
[MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.5500] [Unsigned] =>.Mozilla Corporation
[MD5.B026CE833592C42C8839BD784EA92463] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\TeaTang\Desktop\ZHPDiag3.exe [3310792] [PID.6552] [Unsigned] =>.Nicolas Coolman
[MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.9748] [Unsigned] =>.Mozilla Corporation
[MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.1956] [Unsigned] =>.Mozilla Corporation
[MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.2084] [Unsigned] =>.Mozilla Corporation

---\ Internet Explorer Extensions, Start, Search (15) - 1s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Browser.) (11.00.17134.1 (WinBuild.160101.0800)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation

---\ INTERNET EXPLORER, trusted site and sensitive site (100) - 1s
~ IE Restricted Site Potentially Unwanted: 008i.com
~ IE Restricted Site Potentially Unwanted: 008k.com
~ IE Restricted Site Potentially Unwanted: 00hq.com
~ IE Restricted Site Potentially Unwanted: 0190-dialers.com
~ IE Restricted Site Potentially Unwanted: 01i.info
~ IE Restricted Site Potentially Unwanted: 02pmnzy5eo29bfk4.com
~ IE Restricted Site Potentially Unwanted: 0411dd.com
~ IE Restricted Site Potentially Unwanted: 0511zfhl.com
~ IE Restricted Site Potentially Unwanted: 05p.com
~ IE Restricted Site Potentially Unwanted: 0632qyw.com
~ IE Restricted Site Potentially Unwanted: 07ic5do2myz3vzpk.com
~ IE Restricted Site Potentially Unwanted: 08nigbmwk43i01y6.com
~ IE Restricted Site Potentially Unwanted: 093qpeuqpmz6ebfa.com
~ IE Restricted Site Potentially Unwanted: 0calories.net
~ IE Restricted Site Potentially Unwanted: 0cj.net
~ IE Restricted Site Potentially Unwanted: 0scan.com
~ IE Restricted Site Potentially Unwanted: 1-britney-spears-nude.com
~ IE Restricted Site Potentially Unwanted: 1-domains-registrations.com
~ IE Restricted Site Potentially Unwanted: 1-se.com
~ IE Restricted Site Potentially Unwanted: 1001movie.com
~ IE Restricted Site Potentially Unwanted: 1001night.biz
~ IE Restricted Site Potentially Unwanted: 100gal.net
~ IE Restricted Site Potentially Unwanted: 100sexlinks.com
~ IE Restricted Site Potentially Unwanted: 101hotteens.com
~ IE Restricted Site Potentially Unwanted: 101lottery.com
~ IE Restricted Site Potentially Unwanted: 110hobart.com
~ IE Restricted Site Potentially Unwanted: 114anhui.com
~ IE Restricted Site Potentially Unwanted: 123expressview.com
~ IE Restricted Site Potentially Unwanted: 123found.com
~ IE Restricted Site Potentially Unwanted: 123keno.com
~ IE Restricted Site Potentially Unwanted: 12don.info
~ IE Restricted Site Potentially Unwanted: 1331675235.com
~ IE Restricted Site Potentially Unwanted: 143fuck.com
~ IE Restricted Site Potentially Unwanted: 17gamo.com
~ IE Restricted Site Potentially Unwanted: 17webplace.com
~ IE Restricted Site Potentially Unwanted: 180solutions.com
~ IE Restricted Site Potentially Unwanted: 1autocity.com
~ IE Restricted Site Potentially Unwanted: 1ive.net
~ IE Restricted Site Potentially Unwanted: 1se.ru
~ IE Restricted Site Potentially Unwanted: 1sexparty.com
~ IE Restricted Site Potentially Unwanted: 1stfind.com
~ IE Restricted Site Potentially Unwanted: 1stpagehere.com
~ IE Restricted Site Potentially Unwanted: 1traff.us
~ IE Restricted Site Potentially Unwanted: 1ze.net
~ IE Restricted Site Potentially Unwanted: 2-antispyware.com
~ IE Restricted Site Potentially Unwanted: 2004search.cc
~ IE Restricted Site Potentially Unwanted: 2004synchronationals.org
~ IE Restricted Site Potentially Unwanted: 2009download-best-soft.com
~ IE Restricted Site Potentially Unwanted: 2019wyt.com
~ IE Restricted Site Potentially Unwanted: 2020search.com
~ IE Restricted Site Potentially Unwanted: 20health.com
~ IE Restricted Site Potentially Unwanted: 20x2p.com
~ IE Restricted Site Potentially Unwanted: 23drf.com
~ IE Restricted Site Potentially Unwanted: 24-7find.com
~ IE Restricted Site Potentially Unwanted: 24kstudio.net
~ IE Restricted Site Potentially Unwanted: 24qas.info
~ IE Restricted Site Potentially Unwanted: 24teen.com
~ IE Restricted Site Potentially Unwanted: 2828hfdy.com
~ IE Restricted Site Potentially Unwanted: 2pursuit.com
~ IE Restricted Site Potentially Unwanted: 30search.com
~ IE Restricted Site Potentially Unwanted: 31234.com
~ IE Restricted Site Potentially Unwanted: 3344g.com
~ IE Restricted Site Potentially Unwanted: 33search.cc
~ IE Restricted Site Potentially Unwanted: 34f.com
~ IE Restricted Site Potentially Unwanted: 34yo.com
~ IE Restricted Site Potentially Unwanted: 356563.net
~ IE Restricted Site Potentially Unwanted: 366ent.com
~ IE Restricted Site Potentially Unwanted: 36site.com
~ IE Restricted Site Potentially Unwanted: 3bomb.com
~ IE Restricted Site Potentially Unwanted: 3d-downloadportal.net
~ IE Restricted Site Potentially Unwanted: 3dxxx3d.com
~ IE Restricted Site Potentially Unwanted: 3xpowered.com
~ IE Restricted Site Potentially Unwanted: 4-counter.com
~ IE Restricted Site Potentially Unwanted: 404dnserror.com
~ IE Restricted Site Potentially Unwanted: 404dnspage.com
~ IE Restricted Site Potentially Unwanted: 404dnswebsite.com
~ IE Restricted Site Potentially Unwanted: 404mispage.com
~ IE Restricted Site Potentially Unwanted: 4buy.net
~ IE Restricted Site Potentially Unwanted: 4corn.net
~ IE Restricted Site Potentially Unwanted: 4ourtraff.com
~ IE Restricted Site Potentially Unwanted: 4pokertips.com
~ IE Restricted Site Potentially Unwanted: 4uiokwnbe.com
~ IE Restricted Site Potentially Unwanted: 50plus-login.com
~ IE Restricted Site Potentially Unwanted: 515515.net
~ IE Restricted Site Potentially Unwanted: 53ia49772x7r16ks.com
~ IE Restricted Site Potentially Unwanted: 53t3ghkjksd.com
~ IE Restricted Site Potentially Unwanted: 5foot.org
~ IE Restricted Site Potentially Unwanted: 5hvx2m8sixttkn8a.com
~ IE Restricted Site Potentially Unwanted: 5wheel.org
~ IE Restricted Site Potentially Unwanted: 600pics.com
~ IE Restricted Site Potentially Unwanted: 680130.net
~ IE Restricted Site Potentially Unwanted: 69teenage.com
~ IE Restricted Site Potentially Unwanted: 6bdsm.com
~ IE Restricted Site Potentially Unwanted: 700xxx.com
~ IE Restricted Site Potentially Unwanted: 75tz.com
~ IE Restricted Site Potentially Unwanted: 76text-crypt.net
~ IE Restricted Site Potentially Unwanted: 772123.com
~ IE Restricted Site Potentially Unwanted: 777search.com
~ IE Restricted Site Potentially Unwanted: 777top.com
~ Microsoft Internet Explorer Restricted Site(s) Domains: 0(Good) / 6084(Bad)

---\ Internet Explorer, Proxy Management (3) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 =>.Default.Value
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=

---\ Hosts file redirection (2) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Nombre lignes détournées ou corrompues 0/21 (Hosts file redirected or corrupted)

---\ Global shortcuts Startup (53) - 7s
O4 - GS\Desktop [Administrator]: Cyber Hunter.lnk . (.NetEase - Cyber Hunter.) C:\Program Files (x86)\Cyber Hunter\launcher.exe {0A399503A667F69C5AFA53B47EDCC135}.
O4 - GS\Desktop [Administrator]: Discord.lnk . (.GitHub - Update.) C:\Users\TeaTang\AppData\Local\Discord\Update.exe --processStart Discord.exe =>.SUP.Discord
O4 - GS\Desktop [Administrator]: LibreWolf.lnk . (.Mozilla Corporation - LibreWolf.) C:\Program Files\LibreWolf\librewolf.exe [Unsigned] =>.Mozilla Corporation
O4 - GS\Desktop [Administrator]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPCleaner.exe [Unsigned] =>.Nicolas Coolman
O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPDiag3.exe [Unsigned] =>.Nicolas Coolman
O4 - GS\sendTo [Administrator]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - Transfers files between device.) C:\Windows\System32\fsquirt.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation
O4 - GS\Programs [Administrator]: Cyber Hunter.lnk . (.NetEase - Cyber Hunter.) C:\Program Files (x86)\Cyber Hunter\launcher.exe {0A399503A667F69C5AFA53B47EDCC135}.
O4 - GS\Programs [Administrator]: Cyber Hunteruninstall.lnk . (.Netease - Cyber Hunter Uninstaller.) C:\Program Files (x86)\Cyber Hunter\uninstall.exe {0A399503A667F69C5AFA53B47EDCC135}.
O4 - GS\Programs [Administrator]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\TeaTang\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - GS\Desktop [Guest]: Cyber Hunter.lnk . (.NetEase - Cyber Hunter.) C:\Program Files (x86)\Cyber Hunter\launcher.exe {0A399503A667F69C5AFA53B47EDCC135}.
O4 - GS\Desktop [Guest]: Discord.lnk . (.GitHub - Update.) C:\Users\TeaTang\AppData\Local\Discord\Update.exe --processStart Discord.exe =>.SUP.Discord
O4 - GS\Desktop [Guest]: LibreWolf.lnk . (.Mozilla Corporation - LibreWolf.) C:\Program Files\LibreWolf\librewolf.exe [Unsigned] =>.Mozilla Corporation
O4 - GS\Desktop [Guest]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPCleaner.exe [Unsigned] =>.Nicolas Coolman
O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPDiag3.exe [Unsigned] =>.Nicolas Coolman
O4 - GS\sendTo [Guest]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - Transfers files between device.) C:\Windows\System32\fsquirt.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation
O4 - GS\Programs [Guest]: Cyber Hunter.lnk . (.NetEase - Cyber Hunter.) C:\Program Files (x86)\Cyber Hunter\launcher.exe {0A399503A667F69C5AFA53B47EDCC135}.
O4 - GS\Programs [Guest]: Cyber Hunteruninstall.lnk . (.Netease - Cyber Hunter Uninstaller.) C:\Program Files (x86)\Cyber Hunter\uninstall.exe {0A399503A667F69C5AFA53B47EDCC135}.
O4 - GS\Programs [Guest]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\TeaTang\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - GS\Desktop [TeaTang]: Cyber Hunter.lnk . (.NetEase - Cyber Hunter.) C:\Program Files (x86)\Cyber Hunter\launcher.exe {0A399503A667F69C5AFA53B47EDCC135}.
O4 - GS\Desktop [TeaTang]: Discord.lnk . (.GitHub - Update.) C:\Users\TeaTang\AppData\Local\Discord\Update.exe --processStart Discord.exe =>.SUP.Discord
O4 - GS\Desktop [TeaTang]: LibreWolf.lnk . (.Mozilla Corporation - LibreWolf.) C:\Program Files\LibreWolf\librewolf.exe [Unsigned] =>.Mozilla Corporation
O4 - GS\Desktop [TeaTang]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPCleaner.exe [Unsigned] =>.Nicolas Coolman
O4 - GS\Desktop [TeaTang]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPDiag3.exe [Unsigned] =>.Nicolas Coolman
O4 - GS\sendTo [TeaTang]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - Transfers files between device.) C:\Windows\System32\fsquirt.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\sendTo [TeaTang]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation
O4 - GS\Programs [TeaTang]: Cyber Hunter.lnk . (.NetEase - Cyber Hunter.) C:\Program Files (x86)\Cyber Hunter\launcher.exe {0A399503A667F69C5AFA53B47EDCC135}.
O4 - GS\Programs [TeaTang]: Cyber Hunteruninstall.lnk . (.Netease - Cyber Hunter Uninstaller.) C:\Program Files (x86)\Cyber Hunter\uninstall.exe {0A399503A667F69C5AFA53B47EDCC135}.
O4 - GS\Programs [TeaTang]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\TeaTang\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - GS\CommonDesktop [Public]: 3D Vision Photo Viewer.lnk . (.NVIDIA Corporation - NVIDIA 3D Vision Photo Viewer.) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe =>.NVIDIA Corporation®
O4 - GS\CommonDesktop [Public]: AnyBurn.lnk . (.Power Software Ltd - AnyBurn.) C:\Program Files\AnyBurn\AnyBurn.exe {19EA4DAF089570861408E9F05EFD9B89}. =>.Power Software Ltd
O4 - GS\CommonDesktop [Public]: Malwarebytes.lnk . (.Malwarebytes - .) C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbam.exe [Unsigned] =>.Malwarebytes
O4 - GS\CommonDesktop [Public]: Oracle VM VirtualBox.lnk . (.Oracle Corporation - Oracle VM VirtualBox.) C:\Program Files (x86)\Oracle\VirtualBox\VirtualBox.exe [Unsigned] =>.Oracle Corporation
O4 - GS\CommonDesktop [Public]: Steam.lnk . (.Valve Corporation - Steam.) C:\Program Files (x86)\Steam\Steam.exe =>.Valve Corp.®
O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\Programs [Public]: Cyber Hunter.lnk . (.NetEase - Cyber Hunter.) C:\Program Files (x86)\Cyber Hunter\launcher.exe {0A399503A667F69C5AFA53B47EDCC135}.
O4 - GS\Programs [Public]: Cyber Hunteruninstall.lnk . (.Netease - Cyber Hunter Uninstaller.) C:\Program Files (x86)\Cyber Hunter\uninstall.exe {0A399503A667F69C5AFA53B47EDCC135}.
O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\TeaTang\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\internet explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\Windows\system32\notepad.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\Windows\system32\quickassist.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\Windows\system32\mstsc.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Steps Recorder.) C:\Windows\system32\psr.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\Windows\system32\charmap.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\Windows\System32\Control.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Malwarebytes.lnk . (.Malwarebytes - .) C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbam.exe [Unsigned] =>.Malwarebytes

---\ Lop.com/Domain Hijackers (2) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{2631d501-1595-41ba-a828-60c54973e613}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress

---\ Extra protocols (22) - 1s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\System32\MSVidCtl.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\System32\MSVidCtl.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll [Unsigned] =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation

---\ AppInit_DLLs Registry value Autorun (1) - 0s
O20 - Winlogon : UserInit . (.Microsoft Corporation - Userinit Logon Application.) - C:\Windows\system32\userinit.exe =>.Microsoft Corporation

---\ List of key exploring StartupApproved (8) - 0s
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:OneDrive =>.Microsoft Corporation
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:Steam =>.Valve
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:Discord =>.SUP.Discord
[HKEY_USERS\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:OneDrive =>.Microsoft Corporation
[HKEY_USERS\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:Steam =>.Valve
[HKEY_USERS\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:Discord =>.SUP.Discord
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:SecurityHealth =>.Microsoft Corporation
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:AvastUI.exe =>.Avast Software s.r.o

---\ ASIC (ActiveSetup Installed Components) (5) - 1s
O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Microsoft Windows Media Player Setup Utilit.) -- C:\Windows\System32\unregmp2.exe [Unsigned] =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll [Unsigned] =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Microsoft Windows Media Player Setup Utilit.) -- C:\Windows\System32\unregmp2.exe [Unsigned] =>.Microsoft Corporation
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe [Unsigned] =>.Microsoft Corporation
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft Corporation®

---\ Software installed (30) - 9s
O42 - Logiciel: 7-Zip 22.01 (x64) - (.Igor Pavlov.) [HKLM][64Bits] -- 7-Zip [Unsigned] =>.Igor Pavlov
O42 - Logiciel: AnyBurn - (.Power Software Ltd.) [HKLM][64Bits] -- AnyBurn [Unsigned] =>.Power Software Ltd
O42 - Logiciel: LibreWolf - (.LibreWolf.) [HKLM][64Bits] -- LibreWolf LibreWolf [Unsigned]
O42 - Logiciel: Malwarebytes version 4.5.12.204 - (.Malwarebytes.) [HKLM][64Bits] -- {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1 =>.Malwarebytes Inc.®
O42 - Logiciel: Microsoft Edge Update - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Edge Update [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Microsoft Edge WebView2 Runtime - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft EdgeWebView =>.Microsoft®
O42 - Logiciel: Microsoft OneDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- OneDriveSetup.exe =>.Microsoft®
O42 - Logiciel: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 - (.Microsoft Corporation.) [HKLM][64Bits] -- {196BB40D-1578-3D01-B289-BEFC77A11A1E} [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.32.31332 - (.Microsoft Corporation.) [HKLM][64Bits] -- {3746f21b-c990-4045-bb33-1cf98cff7a68} =>.Microsoft®
O42 - Logiciel: Microsoft Visual C++ 2022 X64 Additional Runtime - 14.32.31332 - (.Microsoft Corporation.) [HKLM][64Bits] -- {F4499EE3-A166-496C-81BB-51D1BCDC70A9} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.32.31332 - (.Microsoft Corporation.) [HKLM][64Bits] -- {3407B900-37F5-4CC2-B612-5CD5D580A163} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: NVIDIA 3D Vision Driver 388.13 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision [Unsigned] =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Ansel - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel [Unsigned] =>.NVIDIA Corporation (Hidden)
O42 - Logiciel: NVIDIA Control Panel 388.13 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel [Unsigned] =>.NVIDIA Corporation (Hidden)
O42 - Logiciel: NVIDIA Display Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainer [Unsigned] =>.NVIDIA Corporation (Hidden)
O42 - Logiciel: NVIDIA Display Container LS - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainerLS [Unsigned] =>.NVIDIA Corporation (Hidden)
O42 - Logiciel: NVIDIA Display Session Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplaySessionContainer [Unsigned] =>.NVIDIA Corporation (Hidden)
O42 - Logiciel: NVIDIA Display Watchdog Plugin - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayPluginWatchdog [Unsigned] =>.NVIDIA Corporation (Hidden)
O42 - Logiciel: NVIDIA Graphics Driver 388.13 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver [Unsigned] =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA HD Audio Driver 1.3.35.1 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver [Unsigned] =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Install Application - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer [Unsigned] =>.NVIDIA Corporation (Hidden)
O42 - Logiciel: NVIDIA Stereoscopic 3D Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- NVIDIAStereo =>.NVIDIA Corporation® (Hidden)
O42 - Logiciel: Oracle VM VirtualBox 6.1.36 - (.Oracle Corporation.) [HKLM][64Bits] -- {8B78A2AB-34B5-4546-8CCF-B78C916BBD98} [Unsigned] =>.Oracle Corporation
O42 - Logiciel: Quake Champions - (.id Software.) [HKLM][64Bits] -- Steam App 611500 =>.Valve Corp.®
O42 - Logiciel: Steam - (.Valve Corporation.) [HKLM][64Bits] -- Steam =>.Valve Corp.®
O42 - Logiciel: TP-Link TL-WN722N Driver - (.TP-Link.) [HKLM][64Bits] -- {F9C15685-38A9-46A1-9826-97204015C19C} [Unsigned] =>.TP-LINK
O42 - Logiciel: Update for Windows 10 for x64-based Systems (KB4023057) - (.Microsoft Corporation.) [HKLM][64Bits] -- {8F2D6CEB-BC98-4B69-A5C1-78BED238FE77} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Update for Windows 10 for x64-based Systems (KB4480730) - (.Microsoft Corporation.) [HKLM][64Bits] -- {0746492E-47B6-4251-940C-44462DFD74BB} [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player [Unsigned] =>.VideoLAN
O42 - Logiciel: Vulkan Run Time Libraries 1.0.61.0 - (.LunarG, Inc..) [HKLM][64Bits] -- VulkanRT1.0.61.0 =>.LunarG, Inc.® (Hidden)

---\ HKCU & HKLM Software Keys (97) - 9s
HKLM\SOFTWARE\7-Zip =>.Igor Pavlov
HKLM\SOFTWARE\Avast Software =>.AVAST Software
HKLM\SOFTWARE\COMODO =>.Comodo
HKLM\SOFTWARE\Google =>.Google
HKLM\SOFTWARE\HitmanPro =>.EIDOS hitman Game
HKLM\SOFTWARE\Intel =>.Intel
HKLM\SOFTWARE\Khronos =>.Khronos
HKLM\SOFTWARE\KPRM
HKLM\SOFTWARE\Macromedia =>.Macromedia
HKLM\SOFTWARE\Malwarebytes =>.Malwarebytes
HKLM\SOFTWARE\Mozilla =>.Mozilla
HKLM\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\OEM =>.OEM
HKLM\SOFTWARE\Oracle =>.Oracle
HKLM\SOFTWARE\Partner =>.Google Inc.
HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKLM\SOFTWARE\TrendMicro =>.TrendMicro
HKLM\SOFTWARE\VideoLAN =>.VideoLan Team
HKLM\SOFTWARE\WOW6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\Adware Removal Tool by TSA =>.TSA Softwares
HKLM\SOFTWARE\WOW6432Node\AMD =>.AMD
HKLM\SOFTWARE\WOW6432Node\AnyBurn
HKLM\SOFTWARE\WOW6432Node\Avast Software =>.AVAST Software
HKLM\SOFTWARE\WOW6432Node\Google =>.Google
HKLM\SOFTWARE\WOW6432Node\Id
HKLM\SOFTWARE\WOW6432Node\Intel =>.Intel
HKLM\SOFTWARE\WOW6432Node\Khronos =>.Khronos
HKLM\SOFTWARE\WOW6432Node\Licenses =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\WOW6432Node\Malwarebytes Anti-Rootkit =>.Malwarebytes
HKLM\SOFTWARE\WOW6432Node\MCPR
HKLM\SOFTWARE\WOW6432Node\MicroWorld =>.MicroWorld Technologies Inc.
HKLM\SOFTWARE\WOW6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\WOW6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\WOW6432Node\NVIDIA Corporation =>.nVidia Corporation
HKLM\SOFTWARE\WOW6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\WOW6432Node\TP-Link =>.TP-LINK
HKLM\SOFTWARE\WOW6432Node\TrendMicro =>.TrendMicro
HKLM\SOFTWARE\WOW6432Node\Valve =>.Valve
HKLM\SOFTWARE\WOW6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\7-Zip =>.Igor Pavlov
HKCU\SOFTWARE\AnyBurn
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\AVAST Software =>.AVAST Software
HKCU\SOFTWARE\Chromium =>.Chromium
HKCU\SOFTWARE\Elaborate Bytes =>.Elaborate Bytes
HKCU\SOFTWARE\Geek Uninstaller =>.Geek Uninstaller
HKCU\SOFTWARE\GNU =>.GNU
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\LibreWolf
HKCU\SOFTWARE\Licenses =>.Microsoft Corporation
HKCU\SOFTWARE\Malwarebytes =>.Malwarebytes
HKCU\SOFTWARE\MicroWorld =>.MicroWorld Technologies Inc.
HKCU\SOFTWARE\Netease
HKCU\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
HKCU\SOFTWARE\nwjs =>.NW.js
HKCU\SOFTWARE\Oracle =>.Oracle
HKCU\SOFTWARE\QtProject =>.QtProject
HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Smart Code ltd
HKCU\SOFTWARE\Sysinternals =>.Sysinternals
HKCU\SOFTWARE\The Silicon Realms Toolworks =>.The Silicon Realms Toolworks
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\Valve =>.Valve
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKU\.DEFAULT\SOFTWARE\Malwarebytes =>.Malwarebytes
HKU\.DEFAULT\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
HKU\.DEFAULT\SOFTWARE\SetID =>.Bitdefender
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\7-Zip =>.Igor Pavlov
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\AnyBurn
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\AVAST Software =>.AVAST Software
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Chromium =>.Chromium
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Elaborate Bytes =>.Elaborate Bytes
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Geek Uninstaller =>.Geek Uninstaller
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\GNU =>.GNU
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Google =>.Google
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\LibreWolf
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Licenses =>.Microsoft Corporation
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Malwarebytes =>.Malwarebytes
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\MicroWorld =>.MicroWorld Technologies Inc.
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Netease
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\nwjs =>.NW.js
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Oracle =>.Oracle
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\QtProject =>.QtProject
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Smart Code ltd
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Sysinternals =>.Sysinternals
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\The Silicon Realms Toolworks =>.The Silicon Realms Toolworks
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Trolltech =>.Trolltech
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Valve =>.Valve
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\ZHP =>.Nicolas Coolman

---\ Packages (1) - 0s
C:\Program Files (x86)\WindowsApps\325289AEDD75.TorrentRTFREE_1.1.11.0_x64__qtx9tqphctw9r - (.Vlasenko Bros..) [][Torrent RT FREE]

---\ Contents of the Common Files folders (177) - 4s
O43 - CFD: 15/09/2022 - [] D -- C:\Program Files\7-Zip =>.Igor Pavlov
O43 - CFD: 09/08/2022 - [] D -- C:\Program Files\AnyBurn =>.Power Software Limited®
O43 - CFD: 01/10/2022 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 09/08/2022 - [] D -- C:\Program Files\CUAssistant
O43 - CFD: 23/09/2022 - [] D -- C:\Program Files\FreeFixer
O43 - CFD: 09/08/2022 - [] D -- C:\Program Files\internet explorer =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\Program Files\LibreWolf [Unsigned]
O43 - CFD: 08/08/2022 - [] D -- C:\Program Files\Malwarebytes =>.Malwarebytes
O43 - CFD: 12/07/2018 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\Program Files\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 14/09/2022 - [] D -- C:\Program Files\Oracle =>.Oracle
O43 - CFD: 12/07/2018 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\Program Files\rempl =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\Program Files\ruxim =>.Microsoft®
O43 - CFD: 08/08/2022 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 09/08/2022 - [] D -- C:\Program Files\UNP =>.Microsoft Corporation
O43 - CFD: 23/09/2022 - [] D -- C:\Program Files\VideoLAN =>.VideoLan Team
O43 - CFD: 09/08/2022 - [] RD -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 09/08/2022 - [] D -- C:\Program Files\Windows Defender Advanced Threat Protection =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 09/08/2022 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\Program Files\windows nt =>.Microsoft Corporation
O43 - CFD: 09/08/2022 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\Program Files\Windows Security =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] SHD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 04/10/2022 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 04/10/2022 - [] D -- C:\Program Files (x86)\Adware Removal Tool by TSA =>.TSA Softwares
O43 - CFD: 23/09/2022 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 06/09/2022 - [] D -- C:\Program Files (x86)\Cyber Hunter {0A399503A667F69C5AFA53B47EDCC135}.
O43 - CFD: 12/08/2022 - [0] D -- C:\Program Files (x86)\Elaborate Bytes =>.Elaborate Bytes
O43 - CFD: 08/08/2022 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield
O43 - CFD: 09/08/2022 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 30/09/2022 - [] D -- C:\Program Files (x86)\Microsoft =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 30/09/2022 - [] D -- C:\Program Files (x86)\Mplayer =>.Arpad Gereoffy
O43 - CFD: 12/07/2018 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\Program Files (x86)\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 12/07/2018 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 01/10/2022 - [] D -- C:\Program Files (x86)\Steam =>.Steam Games
O43 - CFD: 08/08/2022 - [] D -- C:\Program Files (x86)\TP-Link =>.TP-LINK
O43 - CFD: 08/08/2022 - [] D -- C:\Program Files (x86)\VulkanRT =>.LunarG, Inc
O43 - CFD: 09/08/2022 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 09/08/2022 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\Program Files (x86)\windows nt =>.Microsoft Corporation
O43 - CFD: 09/08/2022 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] SHD -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 15/09/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip =>.Igor Pavlov
O43 - CFD: 12/04/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 12/07/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 09/08/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyBurn
O43 - CFD: 12/04/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 14/09/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox =>.Oracle
O43 - CFD: 12/04/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation
O43 - CFD: 11/08/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam =>.Steam Games
O43 - CFD: 12/04/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-Link =>.TP-LINK
O43 - CFD: 23/09/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team
O43 - CFD: 08/08/2022 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 01/10/2022 - [] D -- C:\ProgramData\Avira =>.Avira Software
O43 - CFD: 08/08/2022 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\ProgramData\Licenses =>.Microsoft Corporation
O43 - CFD: 09/08/2022 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes
O43 - CFD: 09/08/2022 - [0] D -- C:\ProgramData\Malwarebytes' Anti-Malware (portable) =>.Malwarebytes
O43 - CFD: 30/09/2022 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 =>.Mozilla Corporation
O43 - CFD: 04/10/2022 - [] D -- C:\ProgramData\NVIDIA =>.nVidia Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\ProgramData\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\ProgramData\Packages =>.Microsoft Corporation
O43 - CFD: 04/10/2022 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [0] D -- C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 30/09/2022 - [0] AD -- C:\ProgramData\TEMP =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\ProgramData\TP-Link =>.TP-LINK
O43 - CFD: 08/08/2022 - [] D -- C:\ProgramData\USOPrivate =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\ProgramData\USOShared =>.Microsoft Corporation
O43 - CFD: 16/09/2022 - [] D -- C:\ProgramData\VirtualBox =>.Oracle
O43 - CFD: 12/04/2018 - [] D -- C:\ProgramData\WindowsHolographicDevices =>.Microsoft Corporation
O43 - CFD: 17/08/2022 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared =>.Microsoft Corporation
O43 - CFD: 23/09/2022 - [0] D -- C:\Program Files (x86)\Common Files\MicroWorld =>.MicroWorld Technologies Inc.
O43 - CFD: 12/04/2018 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 06/09/2022 - [] D -- C:\Program Files (x86)\Common Files\Steam =>.Steam Games
O43 - CFD: 09/08/2022 - [] D -- C:\Program Files (x86)\Common Files\system =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\Users\TeaTang\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 09/08/2022 - [] D -- C:\Users\TeaTang\AppData\Roaming\anyburn
O43 - CFD: 06/09/2022 - [] D -- C:\Users\TeaTang\AppData\Roaming\CC
O43 - CFD: 15/09/2022 - [] D -- C:\Users\TeaTang\AppData\Roaming\discord
O43 - CFD: 22/09/2022 - [] D -- C:\Users\TeaTang\AppData\Roaming\FreeFixer
O43 - CFD: 01/10/2022 - [] D -- C:\Users\TeaTang\AppData\Roaming\Geek Uninstaller =>.Geek Uninstaller
O43 - CFD: 08/08/2022 - [] D -- C:\Users\TeaTang\AppData\Roaming\librewolf
O43 - CFD: 16/09/2022 - [] SD -- C:\Users\TeaTang\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 10/08/2022 - [] D -- C:\Users\TeaTang\AppData\Roaming\Netease
O43 - CFD: 30/09/2022 - [] D -- C:\Users\TeaTang\AppData\Roaming\vlc =>.VideoLan Team
O43 - CFD: 12/08/2022 - [] D -- C:\Users\TeaTang\AppData\Roaming\Warsow 2.1
O43 - CFD: 04/10/2022 - [] D -- C:\Users\TeaTang\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 08/08/2022 - [0] SHD -- C:\Users\TeaTang\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 01/10/2022 - [] D -- C:\Users\TeaTang\AppData\Local\Avira =>.Avira Software
O43 - CFD: 11/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\cache =>.Legitimate
O43 - CFD: 08/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\CEF =>.CEF
O43 - CFD: 08/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\Comms =>.Microsoft Corporation
O43 - CFD: 13/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\ConnectedDevicesPlatform =>.Microsoft Corporation
O43 - CFD: 30/09/2022 - [] D -- C:\Users\TeaTang\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\D3DSCache =>.Legitimate
O43 - CFD: 09/08/2022 - [0] D -- C:\Users\TeaTang\AppData\Local\DBG =>.DBG
O43 - CFD: 14/09/2022 - [] D -- C:\Users\TeaTang\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 15/09/2022 - [] D -- C:\Users\TeaTang\AppData\Local\Discord
O43 - CFD: 22/09/2022 - [] D -- C:\Users\TeaTang\AppData\Local\FreeFixer
O43 - CFD: 08/08/2022 - [0] SHD -- C:\Users\TeaTang\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\librewolf
O43 - CFD: 08/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\mbam =>.Malwarebytes
O43 - CFD: 04/10/2022 - [] D -- C:\Users\TeaTang\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\MicrosoftEdge =>.Microsoft Corporation
O43 - CFD: 12/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\NVIDIA =>.nVidia Corporation
O43 - CFD: 12/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\OneDrive =>.Microsoft Corporation
O43 - CFD: 03/10/2022 - [] D -- C:\Users\TeaTang\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 15/08/2022 - [0] D -- C:\Users\TeaTang\AppData\Local\PeerDistRepub =>.Microsoft Corporation
O43 - CFD: 03/10/2022 - [0] D -- C:\Users\TeaTang\AppData\Local\PlaceholderTileLogoFolder =>.Microsoft Corporation
O43 - CFD: 11/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\Publishers =>.Microsoft Corporation
O43 - CFD: 14/09/2022 - [] D -- C:\Users\TeaTang\AppData\Local\SquirrelTemp =>.Squirrels
O43 - CFD: 11/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\Steam =>.Steam Games
O43 - CFD: 04/10/2022 - [] D -- C:\Users\TeaTang\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [0] SHD -- C:\Users\TeaTang\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\TP-Link =>.TP-LINK
O43 - CFD: 10/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\UniCompactView
O43 - CFD: 10/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\UniSDK
O43 - CFD: 12/08/2022 - [] D -- C:\Users\TeaTang\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 04/10/2022 - [] D -- C:\Users\TeaTang\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 08/08/2022 - [0] D -- C:\Users\TeaTang\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 29/08/2022 - [0] D -- C:\Users\TeaTang\AppData\Local\Programs\LNV
O43 - CFD: 28/08/2022 - [] SD -- C:\Users\TeaTang\AppData\LocalLow\Microsoft =>.Microsoft Corporation
O43 - CFD: 04/10/2022 - [] D -- C:\Users\TeaTang\AppData\LocalLow\Mozilla =>.Mozilla Corporation
O43 - CFD: 01/10/2022 - [] D -- C:\Users\TeaTang\Desktop\AutoLogger
O43 - CFD: 01/10/2022 - [] D -- C:\Users\TeaTang\Desktop\AVbr
O43 - CFD: 02/10/2022 - [0] D -- C:\Users\TeaTang\Desktop\ClearLNK
O43 - CFD: 15/09/2022 - [] D -- C:\Users\TeaTang\Desktop\FuguIta-7.1-amd64-202209131.img
O43 - CFD: 15/09/2022 - [] D -- C:\Users\TeaTang\Desktop\FuguIta-7.1-amd64-202209131.iso
O43 - CFD: 01/10/2022 - [] D -- C:\Users\TeaTang\Desktop\geek
O43 - CFD: 28/08/2022 - [] D -- C:\Users\TeaTang\Desktop\How to disable the AutoRun feature in Windows 10_files
O43 - CFD: 04/10/2022 - [] D -- C:\Users\TeaTang\Desktop\KillEmAll
O43 - CFD: 02/10/2022 - [] D -- C:\Users\TeaTang\Desktop\LOG =>.Unknown
O43 - CFD: 04/10/2022 - [] D -- C:\Users\TeaTang\Desktop\New folder
O43 - CFD: 04/10/2022 - [] D -- C:\Users\TeaTang\Desktop\ProcessExplorer
O43 - CFD: 28/08/2022 - [] D -- C:\Users\TeaTang\Desktop\Three Methods to Disable AutoRun in Windows 10_files
O43 - CFD: 12/04/2018 - [] RD -- C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] RD -- C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] RD -- C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 08/08/2022 - [] D -- C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LibreWolf
O43 - CFD: 12/04/2018 - [] D -- C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] RD -- C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 13/08/2022 - [] D -- C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam =>.Steam Games
O43 - CFD: 12/04/2018 - [] RD -- C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] RD -- C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 08/08/2022 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 01/10/2022 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Programs =>.Microsoft Corporation

---\ ShellIconOverlayIdentifiers (SIOI) (2) - 0s
O106 - SIOI: [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll [Unsigned] =>.Microsoft Corporation
O106 - SIOI: [Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81}. (.Microsoft Corporation - Client Side Caching UI.) -- C:\Windows\System32\cscui.dll [Unsigned] =>.Microsoft Corporation

---\ Search Context Menu Handlers (SCMH) (31) - 3s
O108 - CMH1: 7-Zip [64Bits] - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) -- C:\Program Files\7-Zip\7-zip.dll [Unsigned] =>.Igor Pavlov
O108 - CMH1: EPP [64Bits] - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Microsoft Security Client Shell Extension.) -- C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows®
O108 - CMH1: ModernSharing [64Bits] - {e2bf9676-5f8f-435c-97eb-11607a5bedf7} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH1: Open With [64Bits] - {09799AFB-AD67-11d1-ABCD-00C04FC30936} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH1: Open With EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH1: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH1: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Microsoft (C) Work Folders Shell Extension.) -- C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH2: NvAppShExt [64Bits] - {A929C4CE-FD36-4270-B4F5-34ECAC5BD63C} . (.NVIDIA Corporation - NVIDIA Shell Extensions.) -- C:\Windows\system32\nv3dappshext.dll [Unsigned] =>.NVIDIA Corporation
O108 - CMH2: OpenContainingFolderMenu [64Bits] - {37ea3a21-7493-4208-a011-7f9ea79ce9f5} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH2: OpenGLShExt [64Bits] - {E97DEC16-A50D-49bb-AE24-CF682282E08D} . (.NVIDIA Corporation - NVIDIA Shell Extensions.) -- C:\Windows\system32\nv3dappshext.dll [Unsigned] =>.NVIDIA Corporation
O108 - CMH3: CopyAsPathMenu [64Bits] - {f3d06e7c-1e45-4a26-847e-f9fcdee59be0} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH3: MBAMShlExt [64Bits] - {57CE581A-0CB6-4266-9CA0-19364C90A0B3} . (.Malwarebytes - Malwarebytes.) -- C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll =>.Malwarebytes Inc.®
O108 - CMH3: SendTo [64Bits] - {7BA4C740-9E81-11CF-99D3-00AA004AE837} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH4: 7-Zip [64Bits] - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) -- C:\Program Files\7-Zip\7-zip.dll [Unsigned] =>.Igor Pavlov
O108 - CMH4: EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH4: EPP [64Bits] - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Microsoft Security Client Shell Extension.) -- C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows®
O108 - CMH4: Offline Files [64Bits] - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Microsoft Corporation - Client Side Caching UI.) -- C:\Windows\System32\cscui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH4: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH4: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Microsoft (C) Work Folders Shell Extension.) -- C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH5: New [64Bits] - {D969A300-E7FF-11d0-A93B-00A0C90F2719} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH5: NvCplDesktopContext [64Bits] - {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} . (.NVIDIA Corporation - NVIDIA Display Shell Extension.) -- C:\Windows\System32\nvshext.dll [Unsigned] =>.NVIDIA Corporation
O108 - CMH5: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH5: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Microsoft (C) Work Folders Shell Extension.) -- C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH6: 7-Zip [64Bits] - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) -- C:\Program Files\7-Zip\7-zip.dll [Unsigned] =>.Igor Pavlov
O108 - CMH6: Library Location [64Bits] - {3dad6c5d-2167-4cae-9914-f99e41c12cfa} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH6: MBAMShlExt [64Bits] - {57CE581A-0CB6-4266-9CA0-19364C90A0B3} . (.Malwarebytes - Malwarebytes.) -- C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll =>.Malwarebytes Inc.®
O108 - CMH6: Offline Files [64Bits] - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Microsoft Corporation - Client Side Caching UI.) -- C:\Windows\System32\cscui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH6: PintoStartScreen [64Bits] - {470C0EBD-5D73-4d58-9CED-E91E22E23282} . (.Microsoft Corporation - App Resolver.) -- C:\Windows\System32\appresolver.dll =>.Microsoft Windows®
O108 - CMH7: EnhancedStorageShell [64Bits] - {2854F705-3548-414C-A113-93E27C808C85} . (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH7: EPP [64Bits] - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Microsoft Security Client Shell Extension.) -- C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows®
O108 - CMH7: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation

---\ Image File Execution Options (11) - 0s
O50 - IFEO:C:\Windows\System32\ie4uinit.exe - (.Microsoft Corporation - IE Per-User Initialization Utility.) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - IE 7.0 Unattended Install Utility.) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\MRT.exe - (.Microsoft Corporation - Microsoft Windows Malicious Software Remova.) [CFGOptions\\1] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Microsoft (R) HTML Application host.) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation Host.) [MitigationOptions\\1118481] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\\2097152] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\\4294967296] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\spoolsv.exe - (.Microsoft Corporation - Spooler SubSystem App.) [MitigationOptions\\2097152] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Host Process for Windows Services.) [MinimumStackCommitInBytes\\32768] =>.Microsoft Windows Publisher®
O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Host Process for Windows Services.) [MitigationAuditOptions\\17660905521152] =>.Microsoft Windows Publisher®

---\ System Drivers List (415) - 16s
O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - 1394 OpenHCI Driver.) -- C:\Windows\System32\drivers\1394ohci.sys [237568] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:48 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\drivers\3ware.sys [107416] =>.Microsoft Windows®
O58 - SDL:2022/08/09 17:03:49 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- C:\Windows\System32\drivers\6247C596.sys [255928] =>.Malwarebytes Corporation®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - ACPI Driver for NT.) -- C:\Windows\System32\drivers\acpi.sys [654232] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - ACPI Devices Driver.) -- C:\Windows\System32\drivers\AcpiDev.sys [20480] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - ACPIEx Driver.) -- C:\Windows\System32\drivers\acpiex.sys [127904] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - ACPI Processor Aggregator Device Driver.) -- C:\Windows\System32\drivers\acpipagr.sys [12800] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - ACPI Power Metering Driver.) -- C:\Windows\System32\drivers\acpipmi.sys [14848] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - ACPI Wake Alarm.) -- C:\Windows\System32\drivers\acpitime.sys [13824] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:48 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\Windows\System32\drivers\adp80xx.sys [1135520] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:23 A . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\afd.sys [626592] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - AF_UNIX socket provider.) -- C:\Windows\System32\drivers\afunix.sys [39424] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:33 A . (.Microsoft Corporation - RAS Agile Vpn Miniport Call Manager.) -- C:\Windows\System32\drivers\agilevpn.sys [108032] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:28 A . (.Microsoft Corporation - Application Compatibility Cache.) -- C:\Windows\System32\drivers\ahcache.sys [254464] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\amdk8.sys [181760] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\amdppm.sys [179712] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:48 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [83360] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [259480] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [27032] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:19 A . (.Microsoft Corporation - AppID Driver.) -- C:\Windows\System32\drivers\appid.sys [192928] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:19 A . (.Microsoft Corporation - Applocker Filter.) -- C:\Windows\System32\drivers\applockerfltr.sys [18432] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 12:20:20 A . (.Microsoft Corporation - Microsoft Application Virtualization Stream.) -- C:\Windows\System32\drivers\AppVStrm.sys [127384] =>.Microsoft Windows®
O58 - SDL:2018/04/12 12:20:20 A . (.Microsoft Corporation - Microsoft Application Virtualization VE Man.) -- C:\Windows\System32\drivers\AppvVemgr.sys [162712] =>.Microsoft Windows®
O58 - SDL:2018/04/12 12:20:20 A . (.Microsoft Corporation - Microsoft Application Virtualization VFS Fi.) -- C:\Windows\System32\drivers\AppvVfs.sys [143768] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [132000] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:34 A . (.Microsoft Corporation - MS Remote Access serial network driver.) -- C:\Windows\System32\drivers\asyncmac.sys [28672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [28568] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - ATAPI Driver Extension.) -- C:\Windows\System32\drivers\ataport.sys [194976] =>.Microsoft Windows®
O58 - SDL:2017/07/20 05:46:00 A . (.Red Hat, Inc. - Red Hat VirtIO Balloon driver.) -- C:\Windows\System32\drivers\balloon.sys [47176] {56C6D267ADE07F72EEB4603BBF84CEA5}. =>.Red Hat, Inc.
O58 - SDL:2018/04/12 02:34:40 A . (.Microsoft Corporation - BAM Kernel Driver.) -- C:\Windows\System32\drivers\bam.sys [60320] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft Basic Display Driver.) -- C:\Windows\System32\drivers\BasicDisplay.sys [63488] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft Basic Render Driver.) -- C:\Windows\System32\drivers\BasicRender.sys [34816] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Battery Class Driver.) -- C:\Windows\System32\drivers\battc.sys [39840] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (. - BCM Function 2 Device Driver.) -- C:\Windows\System32\drivers\bcmfn2.sys [9728] [Unsigned] =>.Broadcom Corporation
O58 - SDL:2018/04/12 02:34:36 A . (.Microsoft Corporation - BEEP Driver.) -- C:\Windows\System32\drivers\beep.sys [10240] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - Windows Bind Filter Driver.) -- C:\Windows\System32\drivers\bindflt.sys [92056] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:58 A . (.Microsoft Corporation - NT Lan Manager Datagram Receiver Driver.) -- C:\Windows\System32\drivers\bowser.sys [101888] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - MAC Bridge Driver.) -- C:\Windows\System32\drivers\bridge.sys [116736] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - Microsoft Bluetooth Audio Multiprofile Mana.) -- C:\Windows\System32\drivers\BtaMPM.sys [33792] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - Bluetooth Hands-Free Audio and Call Control.) -- C:\Windows\System32\drivers\bthhfenum.sys [112128] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - Bluetooth Communications Driver.) -- C:\Windows\System32\drivers\bthmodem.sys [67072] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - VHD BTT Filter Driver.) -- C:\Windows\System32\drivers\bttflt.sys [38304] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Button Converter Driver.) -- C:\Windows\System32\drivers\buttonconverter.sys [39936] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:48 A . (.QLogic Corporation - QLogic Gigabit Ethernet VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [533912] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - Charge Arbiration Driver.) -- C:\Windows\System32\drivers\CAD.sys [60320] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - CapImg HID Driver.) -- C:\Windows\System32\drivers\capimg.sys [123392] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:23 A . (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\cdfs.sys [93696] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\cdrom.sys [159744] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - Event Aggregation Kernel Mode Library.) -- C:\Windows\System32\drivers\CEA.sys [78752] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Chelsio Communications - Chelsio iSCSI Crash Dump Driver.) -- C:\Windows\System32\drivers\cht4dx64.sys [143768] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Chelsio Communications - Chelsio iSCSI VMiniport Driver.) -- C:\Windows\System32\drivers\cht4sx64.sys [321432] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Chelsio Communications - VF library for Chelsio ® T5/T6 Chipset.) -- C:\Windows\System32\drivers\cht4vfx.sys [29184] [Unsigned] =>.Chelsio Communications
O58 - SDL:2018/04/12 02:33:49 A . (.Chelsio Communications - Virtual Bus Driver for Chelsio ® T5/T6 Chip.) -- C:\Windows\System32\drivers\cht4vx64.sys [1836952] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - Consumer IR Class Driver for eHome.) -- C:\Windows\System32\drivers\circlass.sys [49152] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - SCSI Class System Dll.) -- C:\Windows\System32\drivers\Classpnp.sys [413600] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Cloud Files Mini Filter Driver.) -- C:\Windows\System32\drivers\cldflt.sys [414208] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:22 A . (.Microsoft Corporation - Common Log File System Driver.) -- C:\Windows\System32\drivers\clfs.sys [382872] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - CLIP Service.) -- C:\Windows\System32\drivers\ClipSp.sys [1018784] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Control Method Battery Driver.) -- C:\Windows\System32\drivers\CmBatt.sys [32256] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Kernel Configuration Manager Initial Config.) -- C:\Windows\System32\drivers\cmimcext.sys [28576] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:22 A . (.Microsoft Corporation - Kernel Cryptography, Next Generation.) -- C:\Windows\System32\drivers\cng.sys [709824] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - CNG Hardware Assist algorithm provider.) -- C:\Windows\System32\drivers\cnghwassist.sys [39328] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - Console Driver.) -- C:\Windows\System32\drivers\condrv.sys [55200] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:51 A . (.Microsoft Corporation - Crash Dump Driver.) -- C:\Windows\System32\drivers\crashdmp.sys [88472] =>.Microsoft Windows®
O58 - SDL:2018/04/12 12:20:19 A . (.Microsoft Corporation - Windows Client Side Caching Driver.) -- C:\Windows\System32\drivers\csc.sys [561152] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:40 A . (.Microsoft Corporation - DAM Kernel Driver.) -- C:\Windows\System32\drivers\dam.sys [91544] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - Xbox Device Authentication Driver.) -- C:\Windows\System32\drivers\devauthe.sys [45568] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:50 A . (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\dfsc.sys [141312] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - PnP Disk Driver.) -- C:\Windows\System32\drivers\disk.sys [94112] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:23 A . (.Microsoft Corporation - Crash Dump Disk Driver.) -- C:\Windows\System32\drivers\Diskdump.sys [39328] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Boot Over USB Dump Driver.) -- C:\Windows\System32\drivers\Dmpusbstor.sys [15360] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Dynamic Memory.) -- C:\Windows\System32\drivers\dmvsc.sys [47104] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:46 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\Windows\System32\drivers\drmk.sys [98304] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:46 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\Windows\System32\drivers\drmkaud.sys [16232] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - ATAPI Dump Driver.) -- C:\Windows\System32\drivers\Dumpata.sys [36256] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:35:21 A . (.Microsoft Corporation - Bitlocker Drive Encryption Crashdump Filter.) -- C:\Windows\System32\drivers\dumpfve.sys [91664] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - SD Crashdump Port Driver.) -- C:\Windows\System32\drivers\dumpsd.sys [188832] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - SD Host Controller Crashdump Port Driver.) -- C:\Windows\System32\drivers\dumpsdport.sys [32256] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Storport Dump Driver.) -- C:\Windows\System32\drivers\Dumpstorport.sys [25600] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:33 A . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\drivers\dxgkrnl.sys [2830240] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:33 A . (.Microsoft Corporation - DirectX Graphics MMS.) -- C:\Windows\System32\drivers\dxgmms1.sys [413080] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:33 A . (.Microsoft Corporation - DirectX Graphics MMS.) -- C:\Windows\System32\drivers\dxgmms2.sys [792984] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:25 A . (.Microsoft Corporation - Enhanced Storage Class driver for IEEE 1667.) -- C:\Windows\System32\drivers\EhStorClass.sys [88472] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - Microsoft driver for storage devices suppor.) -- C:\Windows\System32\drivers\EhStorTcgDrv.sys [118680] =>.Microsoft Windows®
O58 - SDL:2017/05/14 19:29:02 A . (.Elaborate Bytes AG - ElbyCD Windows x64 I/O driver.) -- C:\Windows\System32\drivers\ElbyCDIO.sys [42616] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Error Device Driver.) -- C:\Windows\System32\drivers\errdev.sys [13824] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:48 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3419032] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - Microsoft Extended FAT File System.) -- C:\Windows\System32\drivers\exfat.sys [357888] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - Fast FAT File System Driver.) -- C:\Windows\System32\drivers\fastfat.sys [375200] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Floppy Disk Controller Driver.) -- C:\Windows\System32\drivers\fdc.sys [32768] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Windows sandboxing and encryption filter.) -- C:\Windows\System32\drivers\filecrypt.sys [55808] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - FileInfo Filter Driver.) -- C:\Windows\System32\drivers\fileinfo.sys [86432] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - File Trace Filter Driver.) -- C:\Windows\System32\drivers\filetrace.sys [36352] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Floppy Driver.) -- C:\Windows\System32\drivers\flpydisk.sys [26624] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Microsoft Filesystem Filter Manager.) -- C:\Windows\System32\drivers\fltMgr.sys [402848] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - File System Dependency Manager Mini Filter.) -- C:\Windows\System32\drivers\fsdepends.sys [62872] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - File System Recognizer Driver.) -- C:\Windows\System32\drivers\fs_rec.sys [34208] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:35:21 A . (.Microsoft Corporation - BitLocker Drive Encryption Driver.) -- C:\Windows\System32\drivers\fvevol.sys [744864] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - FWP/IPsec Kernel-Mode API.) -- C:\Windows\System32\drivers\FWPKCLNT.SYS [466840] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - Generic USB Function Class Driver.) -- C:\Windows\System32\drivers\genericusbfn.sys [20992] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - GPU Energy Kernel Driver.) -- C:\Windows\System32\drivers\gpuenergydrv.sys [8192] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\hdaudbus.sys [86016] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - High Definition Audio Function Driver.) -- C:\Windows\System32\drivers\HdAudio.sys [436736] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Hid Battery Driver.) -- C:\Windows\System32\drivers\hidbatt.sys [38304] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - Bluetooth Miniport Driver for HID Devices.) -- C:\Windows\System32\drivers\hidbth.sys [115200] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Hid Class Library.) -- C:\Windows\System32\drivers\hidclass.sys [173568] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - I2C HID Miniport Driver.) -- C:\Windows\System32\drivers\hidi2c.sys [54272] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - HID Button over Interrupt Driver.) -- C:\Windows\System32\drivers\hidinterrupt.sys [50592] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - Infrared Miniport Driver for Input Devices.) -- C:\Windows\System32\drivers\hidir.sys [47104] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - Hid Parsing Library.) -- C:\Windows\System32\drivers\hidparse.sys [46080] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - USB Miniport Driver for Input Devices.) -- C:\Windows\System32\drivers\hidusb.sys [42496] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:48 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [64408] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:22 A . (.Microsoft Corporation - HTTP Protocol Stack.) -- C:\Windows\System32\drivers\http.sys [1026464] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Hyper-V Crashdump.) -- C:\Windows\System32\drivers\hvcrash.sys [33184] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Hypervisor Boot Driver.) -- C:\Windows\System32\drivers\hvservice.sys [73632] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - Microsoft Hyper-V Socket Provider.) -- C:\Windows\System32\drivers\hvsocket.sys [130456] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Hardware Policy Driver.) -- C:\Windows\System32\drivers\hwpolicy.sys [29592] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft VMBus Synthetic Keyboard Driver.) -- C:\Windows\System32\drivers\hyperkbd.sys [16896] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft VMBus Video Device Miniport Drive.) -- C:\Windows\System32\drivers\HyperVideo.sys [28672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - i8042 Port Driver.) -- C:\Windows\System32\drivers\i8042prt.sys [105984] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:45 A . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\Windows\System32\drivers\iagpio.sys [36864] [Unsigned] =>.Intel(R) Corporation
O58 - SDL:2018/04/12 02:33:45 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\Windows\System32\drivers\iai2c.sys [91648] [Unsigned] =>.Intel(R) Corporation
O58 - SDL:2018/04/12 02:33:45 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\Windows\System32\drivers\iaLPSS2i_GPIO2.sys [79360] [Unsigned] =>.Intel Corporation
O58 - SDL:2018/04/12 02:33:45 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\Windows\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [88576] [Unsigned] =>.Intel Corporation
O58 - SDL:2018/04/12 02:33:45 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\Windows\System32\drivers\iaLPSS2i_I2C.sys [171520] [Unsigned] =>.Intel Corporation
O58 - SDL:2018/04/12 02:33:45 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\Windows\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [174592] [Unsigned] =>.Intel Corporation
O58 - SDL:2018/04/12 02:33:48 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group®
O58 - SDL:2018/04/12 02:33:45 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_I2C.sys [113152] [Unsigned] =>.Intel Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\Windows\System32\drivers\iaStorAVC.sys [885144] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [412064] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\Windows\System32\drivers\ibbus.sys [526232] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Indirect displays kernel-mode filter driver.) -- C:\Windows\System32\drivers\IndirectKmd.sys [38912] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Intel PCI IDE Driver.) -- C:\Windows\System32\drivers\intelide.sys [19360] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - Intel Power Engine Plugin.) -- C:\Windows\System32\drivers\intelpep.sys [177192] =>.Microsoft Windows Hardware Abstraction Layer Publisher®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\intelppm.sys [200704] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - I/O rate control Filter.) -- C:\Windows\System32\drivers\iorate.sys [58272] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:33 A . (.Microsoft Corporation - IP FILTER DRIVER.) -- C:\Windows\System32\drivers\ipfltdrv.sys [85504] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - WMI IPMI DRIVER.) -- C:\Windows\System32\drivers\IPMIDrv.sys [92064] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\ipnat.sys [214528] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - IPT Driver.) -- C:\Windows\System32\drivers\ipt.sys [32256] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:43 A . (.Microsoft Corporation - IRDA Protocol Driver.) -- C:\Windows\System32\drivers\irda.sys [119808] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:41 A . (.Microsoft Corporation - Infra-Red Bus Enumerator.) -- C:\Windows\System32\drivers\irenum.sys [19968] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - PNP ISA Bus Driver.) -- C:\Windows\System32\drivers\isapnp.sys [22944] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.Avago Technologies - Avago SAS Gen3.5 Driver (StorPort).) -- C:\Windows\System32\drivers\ItSas35i.sys [145816] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Keyboard Class Driver.) -- C:\Windows\System32\drivers\kbdclass.sys [63904] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - HID Keyboard Filter Driver.) -- C:\Windows\System32\drivers\kbdhid.sys [40448] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Microsoft Kernel Debugger Network Miniport.) -- C:\Windows\System32\drivers\kdnic.sys [23040] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:43 A . (.Microsoft Corporation - Network Power Dependency Broker.) -- C:\Windows\System32\drivers\KNetPwrDepBroker.sys [13824] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:52 A . (.Microsoft Corporation - Kernel CSA Library.) -- C:\Windows\System32\drivers\ks.sys [401920] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:50 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\drivers\ksecdd.sys [139672] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:22 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\drivers\ksecpkg.sys [170912] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:26 A . (.Microsoft Corporation - Kernel Streaming WOW Thunk Service.) -- C:\Windows\System32\drivers\ksthunk.sys [27136] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) -- C:\Windows\System32\drivers\lltdio.sys [65024] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:48 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [108952] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2i.sys [124312] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas3i.sys [128408] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sss.sys [82848] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:27 A . (.Microsoft Corporation - LUA File Virtualization Filter Driver.) -- C:\Windows\System32\drivers\luafv.sys [128000] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - MA-USB Host Controller Driver.) -- C:\Windows\System32\drivers\mausbhost.sys [505240] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - MA-USB IP Driver.) -- C:\Windows\System32\drivers\mausbip.sys [56736] =>.Microsoft Windows®
O58 - SDL:2022/08/08 18:55:22 A . (.Malwarebytes - Malwarebytes Anti-Exploit.) -- C:\Windows\System32\drivers\mbae64.sys [158640] =>.Microsoft®
O58 - SDL:2022/08/08 18:54:45 A . (.Malwarebytes - Malwarebytes Early Launch Anti-Malware Driv.) -- C:\Windows\System32\drivers\MbamElam.sys [21480] =>.Microsoft®
O58 - SDL:2022/08/09 09:56:19 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- C:\Windows\System32\drivers\mbamswissarmy.sys [239544] =>.Microsoft®
O58 - SDL:2018/04/12 02:34:36 A . (.Microsoft Corporation - Medium changer class driver.) -- C:\Windows\System32\drivers\mcd.sys [23552] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:48 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [59800] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\MegaSas2i.sys [75160] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas35i.sys [82328] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\megasr.sys [575896] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Mellanox - MLX4 Bus Driver.) -- C:\Windows\System32\drivers\mlx4_bus.sys [842648] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - MMCSS Driver.) -- C:\Windows\System32\drivers\mmcss.sys [43520] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:38 A . (.Microsoft Corporation - Modem Device Driver.) -- C:\Windows\System32\drivers\modem.sys [42496] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:47 A . (.Microsoft Corporation - Monitor Driver.) -- C:\Windows\System32\drivers\monitor.sys [44544] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Mouse Class Driver.) -- C:\Windows\System32\drivers\mouclass.sys [56728] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - HID Mouse Filter Driver.) -- C:\Windows\System32\drivers\mouhid.sys [33280] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Mount Point Manager.) -- C:\Windows\System32\drivers\mountmgr.sys [104352] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:34 A . (.Microsoft Corporation - Microsoft Protection Service Driver.) -- C:\Windows\System32\drivers\mpsdrv.sys [75776] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:57:00 A . (.Microsoft Corporation - Windows NT WebDav Minirdr.) -- C:\Windows\System32\drivers\mrxdav.sys [144384] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\mrxsmb.sys [500632] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Longhorn SMB 2.0 Redirector.) -- C:\Windows\System32\drivers\mrxsmb20.sys [226208] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Mailslot driver.) -- C:\Windows\System32\drivers\msfs.sys [31232] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - GPIO Class Extension Driver.) -- C:\Windows\System32\drivers\msgpioclx.sys [169368] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - GPIO Button Driver.) -- C:\Windows\System32\drivers\msgpiowin32.sys [50592] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Pass-through HID to KMDF Filter Driver.) -- C:\Windows\System32\drivers\mshidkmdf.sys [8704] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Pass-through Driver for HID-UMDF Interface.) -- C:\Windows\System32\drivers\mshidumdf.sys [11776] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Hardware Notification Class Extension Drive.) -- C:\Windows\System32\drivers\mshwnclx.sys [27136] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - ISA Driver.) -- C:\Windows\System32\drivers\msisadrv.sys [18848] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft iSCSI Initiator Driver.) -- C:\Windows\System32\drivers\msiscsi.sys [280984] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:52 A . (.Microsoft Corporation - MS KS Server.) -- C:\Windows\System32\drivers\mskssrv.sys [32256] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - Microsoft Link-Layer Discovery Protocol Dri.) -- C:\Windows\System32\drivers\mslldp.sys [84480] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:25 A . (.Microsoft Corporation - MS Proxy Clock.) -- C:\Windows\System32\drivers\mspclock.sys [10752] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:25 A . (.Microsoft Corporation - MS Proxy Quality Manager.) -- C:\Windows\System32\drivers\mspqm.sys [10752] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:50 A . (.Microsoft Corporation - Kernel Remote Procedure Call Provider.) -- C:\Windows\System32\drivers\msrpc.sys [375712] =>.Microsoft Windows®
O58 - SDL:2018/04/12 12:20:26 A . (.Microsoft Corporation - Microsoft Security Events Component file sy.) -- C:\Windows\System32\drivers\mssecflt.sys [304032] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - System Management BIOS Driver.) -- C:\Windows\System32\drivers\mssmbios.sys [40864] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:25 A . (.Microsoft Corporation - WDM Tee/Communication Transform Filter.) -- C:\Windows\System32\drivers\mstee.sys [12800] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - Microsoft Multi-Touch HID Driver.) -- C:\Windows\System32\drivers\MTConfig.sys [16896] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Multiple UNC Provider Driver.) -- C:\Windows\System32\drivers\mup.sys [124832] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\drivers\mvumis.sys [63904] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\Windows\System32\drivers\ndfltr.sys [108952] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Network Driver Interface Specification (NDI.) -- C:\Windows\System32\drivers\ndis.sys [1285536] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:38 A . (.Microsoft Corporation - Microsoft NDIS Packet Capture Filter Driver.) -- C:\Windows\System32\drivers\ndiscap.sys [53760] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - Microsoft Network Adapter Multiplexor.) -- C:\Windows\System32\drivers\NdisImPlatform.sys [128512] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:33 A . (.Microsoft Corporation - NDIS 3.0 connection wrapper driver.) -- C:\Windows\System32\drivers\ndistapi.sys [27136] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - NDIS User mode I/O driver.) -- C:\Windows\System32\drivers\ndisuio.sys [65024] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - Microsoft Virtual Network Adapter Enumerato.) -- C:\Windows\System32\drivers\NdisVirtualBus.sys [20992] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:34 A . (.Microsoft Corporation - MS PPP Framing Driver (Strong Encryption).) -- C:\Windows\System32\drivers\ndiswan.sys [192512] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:33 A . (.Microsoft Corporation - NDIS Proxy.) -- C:\Windows\System32\drivers\ndproxy.sys [63488] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - Windows Network Data Usage Monitoring Drive.) -- C:\Windows\System32\drivers\Ndu.sys [128000] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Network Adapter Class Extension for WDF.) -- C:\Windows\System32\drivers\NetAdapterCx.sys [175104] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - NetBIOS interface driver.) -- C:\Windows\System32\drivers\netbios.sys [58264] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netbt.sys [311296] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Network I/O Subsystem.) -- C:\Windows\System32\drivers\netio.sys [536472] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Virtual NDIS Miniport.) -- C:\Windows\System32\drivers\netvsc.sys [197632] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - NPFS Driver.) -- C:\Windows\System32\drivers\npfs.sys [73216] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Named pipe service triggers.) -- C:\Windows\System32\drivers\npsvctrig.sys [26112] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\drivers\nsiproxy.sys [44544] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:50 A . (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [2420632] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:28 A . (.Microsoft Corporation - NTOS extension host driver.) -- C:\Windows\System32\drivers\ntosext.sys [19872] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - NULL Driver.) -- C:\Windows\System32\drivers\null.sys [7168] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - NVDIMM device driver.) -- C:\Windows\System32\drivers\nvdimm.sys [104448] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2017/11/09 04:38:54 A . (.NVIDIA Corporation - NVIDIA HDMI Audio Driver.) -- C:\Windows\System32\drivers\nvhda64v.sys [233904] =>.NVIDIA Corporation®
O58 - SDL:2018/04/12 02:33:48 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [150424] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:48 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [166304] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:44 A . (.Microsoft Corporation - NativeWiFi Miniport Driver.) -- C:\Windows\System32\drivers\nwifi.sys [528384] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - QoS Packet Scheduler.) -- C:\Windows\System32\drivers\pacer.sys [152984] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Parallel Port Driver.) -- C:\Windows\System32\drivers\parport.sys [98816] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Partition driver.) -- C:\Windows\System32\drivers\partmgr.sys [166816] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - NT Plug and Play PCI Enumerator.) -- C:\Windows\System32\drivers\pci.sys [375712] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\pciide.sys [16288] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - PCI IDE Bus Driver Extension.) -- C:\Windows\System32\drivers\pciidex.sys [53656] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - PCMCIA Bus Driver.) -- C:\Windows\System32\drivers\pcmcia.sys [120216] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Performance Counters for Windows Driver.) -- C:\Windows\System32\drivers\pcw.sys [53152] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Power Dependency Coordinator Driver.) -- C:\Windows\System32\drivers\pdc.sys [140192] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:43 A . (.Microsoft Corporation - Protected Environment Authentication and Au.) -- C:\Windows\System32\drivers\PEAuth.sys [726528] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\percsas2i.sys [58776] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\percsas3i.sys [61848] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Persistent memory driver.) -- C:\Windows\System32\drivers\pmem.sys [105984] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - Plug and Play Memory Driver.) -- C:\Windows\System32\drivers\pnpmem.sys [16896] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:46 A . (.Microsoft Corporation - Port Class (Class Driver for Port/Miniport.) -- C:\Windows\System32\drivers\portcls.sys [379392] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\processr.sys [178176] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - Microsoft Quality Windows Audio Video Exper.) -- C:\Windows\System32\drivers\qwavedrv.sys [49152] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - RAM Disk Driver.) -- C:\Windows\System32\drivers\ramdisk.sys [39840] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:33 A . (.Microsoft Corporation - RAS Automatic Connection Driver.) -- C:\Windows\System32\drivers\rasacd.sys [17408] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:34 A . (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\rasl2tp.sys [106496] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:33 A . (.Microsoft Corporation - RAS PPPoE mini-port/call-manager driver.) -- C:\Windows\System32\drivers\raspppoe.sys [82944] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:34 A . (.Microsoft Corporation - Peer-to-Peer Tunneling Protocol.) -- C:\Windows\System32\drivers\raspptp.sys [97280] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:34 A . (.Microsoft Corporation - RAS SSTP Miniport Call Manager.) -- C:\Windows\System32\drivers\rassstp.sys [78848] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:50 A . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) -- C:\Windows\System32\drivers\rdbss.sys [433560] =>.Microsoft Windows®
O58 - SDL:2018/04/12 12:20:20 A . (.Microsoft Corporation - Microsoft RDP Bus Device driver.) -- C:\Windows\System32\drivers\rdpbus.sys [27136] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:57:34 A . (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [182784] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 12:20:22 A . (.Microsoft Corporation - Microsoft RDP Video Miniport driver.) -- C:\Windows\System32\drivers\rdpvideominiport.sys [30616] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:43 A . (.Microsoft Corporation - ReadyBoost Driver.) -- C:\Windows\System32\drivers\rdyboost.sys [284064] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:49 A . (.Microsoft Corporation - NT ReFS FS Driver.) -- C:\Windows\System32\drivers\refs.sys [1921944] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:49 A . (.Microsoft Corporation - NT ReFS FS Driver.) -- C:\Windows\System32\drivers\refsv1.sys [945568] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft RemoteFX VM Transport.) -- C:\Windows\System32\drivers\RfxVmt.sys [43008] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - ResourceHub Proxy Driver.) -- C:\Windows\System32\drivers\rhproxy.sys [104448] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2022/08/11 15:51:38 N . (.AVG Technologies - Remover Driver.) -- C:\Windows\System32\drivers\rm.sys [55248] =>.AVG Technologies CZ, s.r.o.®
O58 - SDL:2018/04/12 02:34:29 A . (.Microsoft Corporation - Reliable Multicast Transport.) -- C:\Windows\System32\drivers\rmcast.sys [150016] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:36 A . (.Microsoft Corporation - Remote NDIS Miniport.) -- C:\Windows\System32\drivers\RNDISMP.sys [35328] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:38 A . (.Microsoft Corporation - Legacy Non-Pnp Modem Device Driver.) -- C:\Windows\System32\drivers\rootmdm.sys [13312] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) -- C:\Windows\System32\drivers\rspndr.sys [81920] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Realtek - Realtek 8136/8168/8169 NDIS 6.40 64-bit Dri.) -- C:\Windows\System32\drivers\rt640x64.sys [604160] [Unsigned] =>.Realtek
O58 - SDL:2018/04/12 02:33:53 RA . (.Realtek - Realtek PCIe GBE Family Controller Flight.) -- C:\Windows\System32\drivers\rteth.sys [65536] [Unsigned] =>.Realtek
O58 - SDL:2019/02/26 19:50:01 A . (.Realtek Semiconductor Corporation - Realtek WLAN USB NDIS Driver 66263.) -- C:\Windows\System32\drivers\rtwlanu.sys [8287464] =>.Realtek Semiconductor Corp.®
O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - SBP-2 Protocol Driver.) -- C:\Windows\System32\drivers\sbp2port.sys [109984] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:37 A . (.Microsoft Corporation - Microsoft Smart Card Reader Filter Driver.) -- C:\Windows\System32\drivers\scfilter.sys [43008] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Storage Class Memory Bus Driver.) -- C:\Windows\System32\drivers\scmbus.sys [128416] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:36 A . (.Microsoft Corporation - SCSI Port Driver.) -- C:\Windows\System32\drivers\scsiport.sys [176032] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - SecureDigital Bus Driver.) -- C:\Windows\System32\drivers\sdbus.sys [287128] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - SDF Reflector.) -- C:\Windows\System32\drivers\SDFRd.sys [33176] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - SD Host Controller Port Driver.) -- C:\Windows\System32\drivers\sdport.sys [97696] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - SD Storage Class Driver.) -- C:\Windows\System32\drivers\sdstor.sys [97176] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Serial Class Extension.) -- C:\Windows\System32\drivers\SerCx.sys [75680] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Serial Class Extension V2.) -- C:\Windows\System32\drivers\SerCx2.sys [154528] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Serial Port Enumerator.) -- C:\Windows\System32\drivers\serenum.sys [25088] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Serial Device Driver.) -- C:\Windows\System32\drivers\serial.sys [84992] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Serial Mouse Filter Driver.) -- C:\Windows\System32\drivers\sermouse.sys [28160] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - SCSI Floppy Driver.) -- C:\Windows\System32\drivers\sfloppy.sys [17920] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - System Guard Runtime Monitor Agent Driver.) -- C:\Windows\System32\drivers\SgrmAgent.sys [63896] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [44952] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [81816] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Sleep Study Helper.) -- C:\Windows\System32\drivers\SleepStudyHelper.sys [34208] =>.Microsoft Windows®
O58 - SDL:2018/04/12 12:20:26 A . (.Microsoft Corporation - SMB Network Direct Driver.) -- C:\Windows\System32\drivers\smbdirect.sys [152064] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:36 A . (.Microsoft Corporation - Smart Card Driver Library.) -- C:\Windows\System32\drivers\smclib.sys [21504] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Storage Spaces Dump Driver.) -- C:\Windows\System32\drivers\spacedump.sys [175008] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - Storage Spaces Driver.) -- C:\Windows\System32\drivers\spaceport.sys [611232] =>.Microsoft Windows®
O58 - SDL:2018/04/12 12:20:24 A . (.Microsoft Corporation - Holographic Spatial Graph Filter.) -- C:\Windows\System32\drivers\SpatialGraphFilter.sys [57752] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - SPB Class Extension.) -- C:\Windows\System32\drivers\SpbCx.sys [82328] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:23 A . (.Microsoft Corporation - Smb 2.0 Server driver.) -- C:\Windows\System32\drivers\srv2.sys [737792] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:50 A . (.Microsoft Corporation - Server Network driver.) -- C:\Windows\System32\drivers\srvnet.sys [266752] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\Windows\System32\drivers\stexstor.sys [31128] =>.Microsoft Windows®
O58 - SDL:2011/08/24 11:56:28 A . (. - Spyware Terminator 2012 driver.) -- C:\Windows\System32\drivers\stflt.sys [51496] =>.Crawler, LLC®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - MS AHCI Storport Miniport Driver.) -- C:\Windows\System32\drivers\storahci.sys [156056] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - Microsoft NVM Express Storport Miniport Dri.) -- C:\Windows\System32\drivers\stornvme.sys [105368] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:22 A . (.Microsoft Corporation - Microsoft Storage Port Driver.) -- C:\Windows\System32\drivers\storport.sys [562080] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - Storage QoS Filter.) -- C:\Windows\System32\drivers\storqosflt.sys [82432] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - MS UFS Storport Miniport Driver.) -- C:\Windows\System32\drivers\storufs.sys [48544] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Storage VSC Driver.) -- C:\Windows\System32\drivers\storvsc.sys [40352] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:36 A . (.Microsoft Corporation - WDM CODEC Class Device Driver 2.0.) -- C:\Windows\System32\drivers\stream.sys [75264] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft RemoteFX Synth3D Video VSC.) -- C:\Windows\System32\drivers\Synth3dVsc.sys [64512] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:36 A . (.Microsoft Corporation - SCSI Tape Class Driver.) -- C:\Windows\System32\drivers\tape.sys [31232] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Export driver for kernel mode TPM API.) -- C:\Windows\System32\drivers\tbs.sys [27544] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:50 A . (.Microsoft Corporation - TCP/IP Driver.) -- C:\Windows\System32\drivers\tcpip.sys [2712992] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) -- C:\Windows\System32\drivers\tcpipreg.sys [51712] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - TDI Wrapper.) -- C:\Windows\System32\drivers\tdi.sys [40352] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [121248] =>.Microsoft Windows®
O58 - SDL:2018/04/12 12:20:28 A . (.Microsoft Corporation - Terminal Server Input Driver.) -- C:\Windows\System32\drivers\terminpt.sys [37280] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Kernel Transaction Manager Driver.) -- C:\Windows\System32\drivers\tm.sys [128920] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - TPM Device Driver.) -- C:\Windows\System32\drivers\tpm.sys [232352] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Remote Desktop USB Hub Filter Driver.) -- C:\Windows\System32\drivers\TsUsbFlt.sys [63488] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Remote Desktop Generic USB Driver.) -- C:\Windows\System32\drivers\TsUsbGD.sys [35328] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 12:20:19 A . (.Microsoft Corporation - Remote Desktop USB Hub.) -- C:\Windows\System32\drivers\tsusbhub.sys [126464] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - Microsoft Tunnel Interface Driver.) -- C:\Windows\System32\drivers\tunnel.sys [119296] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft Uasp Driver.) -- C:\Windows\System32\drivers\uaspstor.sys [79776] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - USB Connector Manager KMDF Class Extension.) -- C:\Windows\System32\drivers\UcmCx.sys [128512] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - UCM-TCPCI KMDF Class Extension.) -- C:\Windows\System32\drivers\UcmTcpciCx.sys [152576] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - USB Connector Manager UCSI Client.) -- C:\Windows\System32\drivers\UcmUcsi.sys [57856] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:35 A . (.Microsoft Corporation - USB Controller Extension.) -- C:\Windows\System32\drivers\Ucx01000.sys [226720] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - 'udecx.DRIVER'.) -- C:\Windows\System32\drivers\Udecx.sys [45056] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:38 A . (.Microsoft Corporation - UDF File System Driver.) -- C:\Windows\System32\drivers\udfs.sys [324608] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - UEFI Driver for NT.) -- C:\Windows\System32\drivers\uefi.sys [29600] =>.Microsoft Windows®
O58 - SDL:2018/04/12 12:20:25 A . (.Microsoft Corporation - Microsoft User Experience Virtualization Ag.) -- C:\Windows\System32\drivers\UevAgentDriver.sys [40344] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - USB Function Driver Class Extension.) -- C:\Windows\System32\drivers\ufx01000.sys [282008] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - UFX Chipidea Client Driver.) -- C:\Windows\System32\drivers\UfxChipidea.sys [98200] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - UFX Synopsys Client Driver.) -- C:\Windows\System32\drivers\ufxsynopsys.sys [144288] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - User-Mode Bus Enumerator.) -- C:\Windows\System32\drivers\umbus.sys [56832] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - Generic pass-through driver.) -- C:\Windows\System32\drivers\umpass.sys [14336] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - USB Role-Switch Driver for Chipidea Core.) -- C:\Windows\System32\drivers\urschipidea.sys [29088] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - USB Role-Switch Class Extension.) -- C:\Windows\System32\drivers\urscx01000.sys [67992] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - USB Role-Switch Driver for Synopsys Core.) -- C:\Windows\System32\drivers\urssynopsys.sys [28064] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:34 A . (.Microsoft Corporation - Remote NDIS USB Driver.) -- C:\Windows\System32\drivers\usb8023.sys [22016] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:40 A . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\Windows\System32\drivers\USBCAMD2.sys [37376] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) -- C:\Windows\System32\drivers\usbccgp.sys [168864] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:46 A . (.Microsoft Corporation - USB Consumer IR Driver for eHome.) -- C:\Windows\System32\drivers\usbcir.sys [102912] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Universal Serial Bus Driver.) -- C:\Windows\System32\drivers\usbd.sys [32152] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - EHCI eUSB Miniport Driver.) -- C:\Windows\System32\drivers\usbehci.sys [95648] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Default Hub Driver for USB.) -- C:\Windows\System32\drivers\usbhub.sys [514464] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - USB3 HUB Driver.) -- C:\Windows\System32\drivers\USBHUB3.SYS [565152] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - OHCI USB Miniport Driver.) -- C:\Windows\System32\drivers\usbohci.sys [30208] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:14 A . (...) -- C:\Windows\System32\drivers\UsbPmApi.sys [39936] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - USB 1.1 & 2.0 Port Driver.) -- C:\Windows\System32\drivers\usbport.sys [412576] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:47 A . (.Microsoft Corporation - USB Printer driver.) -- C:\Windows\System32\drivers\usbprint.sys [27136] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - USB Serial Driver.) -- C:\Windows\System32\drivers\usbser.sys [72192] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - USB Mass Storage Class Driver.) -- C:\Windows\System32\drivers\USBSTOR.SYS [131488] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - UHCI USB Miniport Driver.) -- C:\Windows\System32\drivers\usbuhci.sys [35328] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - USB XHCI Driver.) -- C:\Windows\System32\drivers\USBXHCI.SYS [434592] =>.Microsoft Windows®
O58 - SDL:2022/07/19 15:50:14 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Host-Only Network Adapt.) -- C:\Windows\System32\drivers\VBoxNetAdp6.sys [242656] =>.Oracle Corporation®
O58 - SDL:2022/07/19 15:50:18 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Lightweight Filter Driv.) -- C:\Windows\System32\drivers\VBoxNetLwf.sys [252560] =>.Oracle Corporation®
O58 - SDL:2022/07/19 15:50:22 A . (.Oracle Corporation - VirtualBox Support Driver.) -- C:\Windows\System32\drivers\VBoxSup.sys [1081592] =>.Oracle Corporation®
O58 - SDL:2022/07/19 15:50:28 A . (.Oracle Corporation - VirtualBox USB Monitor Driver.) -- C:\Windows\System32\drivers\VBoxUSBMon.sys [191184] =>.Oracle Corporation®
O58 - SDL:2020/02/22 11:43:04 A . (.Elaborate Bytes AG - Virtual CloneDrive storage miniport.) -- C:\Windows\System32\drivers\VClone.sys [44544] =>.Microsoft®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Virtual Drive Root Enumerator.) -- C:\Windows\System32\drivers\vdrvroot.sys [56224] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Driver Verifier Extension.) -- C:\Windows\System32\drivers\VerifierExt.sys [217496] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - VHD Miniport Driver.) -- C:\Windows\System32\drivers\vhdmp.sys [705440] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Virtual HID Framework (VHF) Driver.) -- C:\Windows\System32\drivers\vhf.sys [35328] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:23 A . (.Microsoft Corporation - Video Port Driver.) -- C:\Windows\System32\drivers\videoprt.sys [44544] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2017/07/20 05:46:11 A . (.Red Hat, Inc. - Red Hat VirtIO RNG Driver.) -- C:\Windows\System32\drivers\viorng.sys [43080] {56C6D267ADE07F72EEB4603BBF84CEA5}. =>.Red Hat, Inc.
O58 - SDL:2017/07/20 05:46:14 A . (.Red Hat, Inc. - Red Hat VirtIO SCSI driver.) -- C:\Windows\System32\drivers\viostor.sys [40008] {56C6D267ADE07F72EEB4603BBF84CEA5}. =>.Red Hat, Inc.
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Hyper-V VMBus KMCL.) -- C:\Windows\System32\drivers\vmbkmcl.sys [81824] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:08 A . (.Microsoft Corporation - Hyper-V VMBus Root KMCL.) -- C:\Windows\System32\drivers\vmbkmclr.sys [82432] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft Hyper-V Virtual Machine Bus Child.) -- C:\Windows\System32\drivers\vmbus.sys [114080] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft VMBus HID Miniport.) -- C:\Windows\System32\drivers\VMBusHID.sys [25088] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Virtual Machine Generation Counter.) -- C:\Windows\System32\drivers\vmgencounter.sys [13312] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Virtual Machine Guest Infrastructure Driver.) -- C:\Windows\System32\drivers\vmgid.sys [10240] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft S3 Emulated Device Cap Driver.) -- C:\Windows\System32\drivers\vms3cap.sys [9216] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Virtual Storage Filter Driver.) -- C:\Windows\System32\drivers\vmstorfl.sys [47520] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\drivers\volmgr.sys [83360] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Volume Manager Extension Driver.) -- C:\Windows\System32\drivers\volmgrx.sys [373144] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:39 A . (.Microsoft Corporation - Volume Shadow Copy driver.) -- C:\Windows\System32\drivers\volsnap.sys [398240] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Volume driver.) -- C:\Windows\System32\drivers\volume.sys [16288] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Virtual PCI Bus.) -- C:\Windows\System32\drivers\vpci.sys [75168] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [166808] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\drivers\VSTXRAID.SYS [305560] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:43 A . (.Microsoft Corporation - Virtual Wireless Bus Driver.) -- C:\Windows\System32\drivers\vwifibus.sys [27136] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:43 A . (.Microsoft Corporation - Virtual WiFi Filter Driver.) -- C:\Windows\System32\drivers\vwififlt.sys [76288] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:43 A . (.Microsoft Corporation - Virtual WiFi Miniport Driver.) -- C:\Windows\System32\drivers\vwifimp.sys [44544] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - Wacom Serial Pen Tablet HID Driver.) -- C:\Windows\System32\drivers\wacompen.sys [30720] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:33 A . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) -- C:\Windows\System32\drivers\wanarp.sys [81920] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:08 A . (.Microsoft Corporation - Watchdog Driver.) -- C:\Windows\System32\drivers\watchdog.sys [56320] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Windows Container Isolation FS Filter Drive.) -- C:\Windows\System32\drivers\wcifs.sys [151960] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Windows Container Name Virtualization FS Fi.) -- C:\Windows\System32\drivers\wcnfs.sys [82944] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:58 A . (.Microsoft Corporation - Microsoft antimalware boot driver.) -- C:\Windows\System32\drivers\WdBoot.sys [44616] =>.Microsoft Windows Early Launch Anti-malware Publisher®
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Kernel Mode Driver Framework Runtime.) -- C:\Windows\System32\drivers\Wdf01000.sys [924856] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:58 A . (.Microsoft Corporation - Microsoft antimalware file system filter dr.) -- C:\Windows\System32\drivers\WdFilter.sys [331680] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Kernel Mode Driver Framework Loader.) -- C:\Windows\System32\drivers\WdfLdr.sys [61624] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:57:00 A . (.Microsoft Corporation - WDI Driver Framework Driver.) -- C:\Windows\System32\drivers\WdiWiFi.sys [781824] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:15 A . (.Microsoft Corporation - WDM Companion Filter.) -- C:\Windows\System32\drivers\WdmCompanionFilter.sys [21408] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:58 A . (.Microsoft Corporation - Windows Defender Network Stream Filter.) -- C:\Windows\System32\drivers\WdNisDrv.sys [44032] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:23 A . (.Microsoft Corporation - Windows Error Reporting Kernel Driver.) -- C:\Windows\System32\drivers\werkernel.sys [45984] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:34 A . (.Microsoft Corporation - WFP NDIS 6.30 Lightweight Filter Driver.) -- C:\Windows\System32\drivers\wfplwfs.sys [164768] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Wim file system Driver.) -- C:\Windows\System32\drivers\wimmount.sys [35744] =>.Microsoft Windows®
O58 - SDL:2018/07/12 15:56:34 A . (.Microsoft Corporation - Windows Trusted Runtime Interface Driver.) -- C:\Windows\System32\drivers\WindowsTrustedRT.sys [72768] =>.Microsoft Windows Hardware Abstraction Layer Publisher®
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Windows Trusted Runtime Service Proxy Drive.) -- C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys [18472] =>.Microsoft Windows Hardware Abstraction Layer Publisher®
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Windows Hypervisor Interface Driver.) -- C:\Windows\System32\drivers\winhv.sys [31640] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Windows Hypervisor Root Interface Driver.) -- C:\Windows\System32\drivers\winhvr.sys [68096] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Mellanox - Kernel WinMad.) -- C:\Windows\System32\drivers\winmad.sys [32152] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Windows NAT Driver.) -- C:\Windows\System32\drivers\winnat.sys [227840] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Windows WinUSB Class Driver.) -- C:\Windows\System32\drivers\winusb.sys [92672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:49 A . (.Mellanox - Kernel WinVerbs.) -- C:\Windows\System32\drivers\winverbs.sys [64920] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Windows Management Interface for ACPI.) -- C:\Windows\System32\drivers\wmiacpi.sys [18432] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - WMILIB WMI support library Dll.) -- C:\Windows\System32\drivers\wmilib.sys [20384] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Windows Overlay Filter.) -- C:\Windows\System32\drivers\wof.sys [209816] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:33:58 A . (.Microsoft Corporation - Windows Portable Device Upper Class Filter.) -- C:\Windows\System32\drivers\WpdUpFltr.sys [30112] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - WPP Trace Recorder.) -- C:\Windows\System32\drivers\WppRecorder.sys [33184] =>.Microsoft Windows®
O58 - SDL:2018/04/12 02:34:39 A . (.Microsoft Corporation - Winsock2 IFS Layer.) -- C:\Windows\System32\drivers\ws2ifsl.sys [23040] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:28 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\drivers\WUDFPf.sys [125440] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:28 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\drivers\WUDFRd.sys [264192] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - Game Input Protocol Driver.) -- C:\Windows\System32\drivers\xboxgip.sys [295424] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - XINPUT filter driver for HID.) -- C:\Windows\System32\drivers\xinputhid.sys [46592] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/02/26 19:50:01 A . (.Realtek Semiconductor Corporation - Realtek WLAN USB NDIS Driver 66263.) -- C:\Windows\System32\rtwlanu.sys [8287464] =>.Realtek Semiconductor Corp.®
O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - Full/Desktop Multi-User Win32 Driver.) -- C:\Windows\System32\win32k.sys [482304] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:33 A . (.Microsoft Corporation - Base Win32k Kernel Driver.) -- C:\Windows\System32\win32kbase.sys [2236928] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:35 A . (.Microsoft Corporation - Full/Desktop Win32k Kernel Driver.) -- C:\Windows\System32\win32kfull.sys [3652608] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/04/12 02:34:48 A . (.Microsoft Corporation - Full/Desktop Multi-User Win32 Driver.) -- C:\Windows\SysWOW64\win32k.sys [315904] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - Full/Desktop Win32k Kernel Driver.) -- C:\Windows\SysWOW64\win32kfull.sys [2895360] [Unsigned] =>.Microsoft Corporation

---\ Last modified or created user files (11) - 11s
O61 - LFC: 2022/10/04 11:54:36 A . (..) -- C:\Users\TeaTang\Desktop\adware-removal-tool-by-tsa.exe [752296] {317DD1C55F51AC2756D9C93C060C6FA5}.
O61 - LFC: 2022/10/01 16:11:40 A . (.Company © regist & Drongo.) -- C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger.exe [16439448] [Unsigned]
O61 - LFC: 2022/10/01 05:30:02 A . (..) -- C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger\AV\av_z.exe [1605632] [Unsigned]
O61 - LFC: 2022/10/01 05:30:06 A . (.Alex Dragokas.) -- C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger\CheckBrowsersLNK\Check Browsers LNK.exe [1504328] {31F8F5FB790C592476CE0F3320DC4AF1}.
O61 - LFC: 2022/10/01 05:30:06 A . (.Stanislav Polshyn & Trend Micro Inc..) -- C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger\HiJackThis\HiJackThis.exe [7482296] {31F8F5FB790C592476CE0F3320DC4AF1}.
O61 - LFC: 2022/10/01 05:30:06 A . (.© random/random.) -- C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger\RSIT\RSIT.exe [1206272] [Unsigned]
O61 - LFC: 2022/10/01 05:30:06 A . (.© random/random.) -- C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger\RSIT\RSITx64.exe [1329152] [Unsigned]
O61 - LFC: 2022/10/01 05:05:02 A . (..) -- C:\Users\TeaTang\Desktop\AVbr\AV_block_remover\taskhostw.exe [9281536] [Unsigned]
O61 - LFC: 2022/10/01 16:06:21 A . (.Company © regist.) -- C:\Users\TeaTang\Desktop\AVbr\AVbr.exe [9322315] [Unsigned]
O61 - LFC: 2022/10/02 21:57:29 A . (.Alex Dragokas.) -- C:\Users\TeaTang\Desktop\ClearLNK.exe [1029112] {31F8F5FB790C592476CE0F3320DC4AF1}.
O61 - LFC: 2022/10/04 11:50:20 A . (.d7xTech, Inc..) -- C:\Users\TeaTang\Desktop\KillEmAll\KillEmAll.exe [1693312] {1877A57C210DBBD1CCE4B4424F5D2F9F}.

---\ File Associations Shell Spawning (10) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- '%1' %* =>.Default.Value
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe [Unsigned] =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- '%1' %* =>.Default.Value
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- '%1' %* =>.Default.Value
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe [Unsigned] =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- '%1' %* =>.Default.Value
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- C:\Windows\System32\WScript.exe '%1' %* =>.Default.Value
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe [Unsigned] =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- '%1' /S =>.Default.Value

---\ Start Menu Internet (5) - 0s
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Mozilla Corporation - LibreWolf.) -- C:\Program Files\LibreWolf\librewolf.exe [Unsigned] =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

---\ Search Browser Infection (3) - 0s
O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKCU] [64Bits]{67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} - (Google) - http://www.google.com/ =>.Google Inc.
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com

---\ Search Svchost Services (49) - 2s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [188928] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [188928] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\System32\srvsvc.dll [271360] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\Windows\System32\gpsvc.dll [1267712] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\IKEEXT.DLL [990208] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [786432] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\Windows\System32\seclogon.dll [30720] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\System32\iscsiexe.dll [150528] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [109568] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\Windows\System32\schedsvc.dll [889344] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [224256] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [394240] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [397312] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\Windows\System32\wercplsupport.dll [119808] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: InstallService (InstallService) . (.Microsoft Corporation - InstallService.) -- C:\Windows\System32\InstallService.dll [1487360] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: LxpSvc (LxpSvc) . (.Microsoft Corporation - Provides infrastructure support for deployi.) -- C:\Windows\System32\LanguageOverlayServer.dll [199680] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\Windows\System32\Windows.SharedPC.AccountManager.dll [195584] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: PushToInstall (PushToInstall) . (.Microsoft Corporation - PushToInstall.) -- C:\Windows\System32\PushToInstall.dll [262144] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\Windows\System32\XblGameSave.dll [1308672] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Microsoft Network Connectivity Assistant Se.) -- C:\Windows\System32\NcaSvc.dll [167936] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - Windows Managent Service DLL.) -- C:\Windows\System32\Windows.Internal.Management.dll [827392] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\Windows\System32\XblAuthManager.dll [1115648] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [402944] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: NaturalAuthentication (NaturalAuthentication) . (.Microsoft Corporation - Natural Authentication Service.) -- C:\Windows\System32\NaturalAuth.dll [824832] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Network Setup Service.) -- C:\Windows\System32\NetSetupSvc.dll [335360] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft® Account Service.) -- C:\Windows\System32\wlidsvc.dll [2248192] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Device Setup Manager.) -- C:\Windows\System32\DeviceSetupManager.dll [235520] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\Windows\System32\usermgr.dll [1027584] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\System32\themeservice.dll [69632] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxGipSvc (XboxGipSvc) . (.Microsoft Corporation - Xbox Gip Management Service.) -- C:\Windows\System32\XboxGipSvc.dll [58880] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [166912] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: TokenBroker (TokenBroker) . (.Microsoft Corporation - Token Broker.) -- C:\Windows\System32\TokenBroker.dll [1395712] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Geolocation Service.) -- C:\Windows\System32\lfsvc.dll [44544] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Irmon (Irmon) . (.Microsoft Corporation - Infrared Monitor.) -- C:\Windows\System32\irmon.dll [24576] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [104960] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [932352] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [497664] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\Sens.dll [73216] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [604672] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [308224] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng.dll [2903040] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [1374208] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [613376] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\Windows\System32\dmwappushsvc.dll [57856] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Flight Settings.) -- C:\Windows\System32\flightsettings.dll [858112] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Windows Push Notification System Service.) -- C:\Windows\System32\WpnService.dll [280576] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\Windows\System32\XboxNetApiSvc.dll [1148928] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Update Session Orchestrator Core.) -- C:\Windows\System32\usocore.dll [1374208] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Software installation Service.) -- C:\Windows\System32\appmgmts.dll [197120] [Unsigned] =>.Microsoft Corporation

---\ Firewall Active Exception List (4) - 1s
O87 - FAEL: '{AF477CB3-E0D6-4864-AAC4-D8CE3CD48B35}' [In-None-P6-TRUE] .(.Valve Corporation - Steam.) -- C:\Program Files (x86)\Steam\Steam.exe =>.Valve Corp.®
O87 - FAEL: '{A24850F9-C9A9-4126-855B-6C139A99C1A6}' [In-None-P17-TRUE] .(.Valve Corporation - Steam.) -- C:\Program Files (x86)\Steam\Steam.exe =>.Valve Corp.®
O87 - FAEL: '{5FD1BC2B-ABD7-4896-80C2-E1EE08088A1F}' [In-None-P6-TRUE] .(.Valve Corporation - Steam Client WebHelper.) -- C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe =>.Valve Corp.®
O87 - FAEL: '{097601F0-855B-4DFB-BC38-A43DF1473A6F}' [In-None-P17-TRUE] .(.Valve Corporation - Steam Client WebHelper.) -- C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe =>.Valve Corp.®

---\ Product Upgrade Codes (6) - 0s
O90 - PUC: '009B70435F732CC46B21C55D5D081A36' [HKLM] . (.Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.32.31332.) =>.Microsoft Corporation
O90 - PUC: '3EE9944F661AC69418BB151DCBCD079A' [HKLM] . (.Microsoft Visual C++ 2022 X64 Additional Runtime - 14.32.31332.) =>.Microsoft Corporation
O90 - PUC: 'BA2A87B85B436454C8FC7BC819B6DB89' [HKLM] . (.Oracle VM VirtualBox 6.1.36.) -- C:\Windows\Installer\{8B78A2AB-34B5-4546-8CCF-B78C916BBD98}\IconVirtualBox =>.Oracle
O90 - PUC: 'BEC6D2F889CB96B45A1C87EB2D83EF77' [HKLM] . (.Update for Windows 10 for x64-based Systems (KB4023057).) =>.Microsoft Corporation
O90 - PUC: 'D04BB691875110D32B98EBCF771AA1E1' [HKLM] . (.Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319.) =>.bl.org
O90 - PUC: 'E29464706B74152449C04464D2DF47BB' [HKLM] . (.Update for Windows 10 for x64-based Systems (KB4480730).) =>.Microsoft Corporation

---\ Windows Installer Scan (1) - 1s
[MD5.CC9E931DA9620ED5D79DADF653A85292] [WIS][2022/09/14 20:49:38] (.Oracle Corporation - Oracle VM VirtualBox 6.1.36 installation pa.) -- C:\Windows\Installer\1642052f.msi [110116864] =>.Oracle Corporation

---\ FEATURE CONTROL. (128) - 0s
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:infopath.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:KMPlayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPfewgsrv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGUI.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGuiIT.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLgPad.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLOGON.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:Scale_for_R3.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:ieuser.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK]:YahooMusicEngine.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:devenv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:dexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:helppane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS]:msfeedssync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG]:msiexec.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:cs.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:waol.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:wm.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS]:helppane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS]:wlmail.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:outlook.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:sidebar.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING]:communicator.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msimn.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:winmail.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:msimn.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:outlook.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:winmail.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:excel.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:infopath.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:powerpnt.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:winword.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD]:msn.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:wmplayer.exe =>.Legitimate

---\ Observer Of Events (108) - 55s
Application.Error: Application Error (159)
~Numéro: 7832
~Date: 10/04/2022 03:57:40 PM
~ID: 1000
~Description: Faulting application name: %1, version: %2, time stamp: 0xa38b9ab2 Faulting module name: %4, version: %5, time stamp: 0xb7ab6594 Exception code: 0xc0000005 Fault offset: 0x0000000000008ee5 Faulting process id: 0x2024 Faulting application start time:
~Suggestion: Réparer ou réinstaller l'application.
Application.Warning: ESENT (46)
~Numéro: 7383
~Date: 10/02/2022 09:29:16 PM
~ID: 636
~Description: %1 (%2) %3Flush map file '%4' will be deleted. Reason: %5.
~Suggestion: Aucune
Application.Error: VSS (2)
~Numéro: 7335
~Date: 10/02/2022 09:24:44 PM
~ID: 8193
~Description: Volume Shadow Copy Service error: Unexpected error calling routine %1. hr = %2. Operation: Executing Asynchronous OperationContext: Current State: DoSnapshotSet
~Suggestion: Utiliser la procédure de reconstruction du VSS
Application.Error: Application Hang (8)
~Numéro: 6972
~Date: 10/01/2022 12:44:50 PM
~ID: 1002
~Description: The program %1 version %2 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 2010 Start Time: 01d8d57a360e
~Suggestion: Essayer les commandes suivantes ipconfig /release et ipconfig / renew.
Application.Error: Microsoft-Windows-CAPI2 (20)
~Numéro: 6728
~Date: 10/01/2022 11:35:08 AM
~ID: 513
~Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.%1.
Application.Error: Perflib (2)
~Numéro: 6007
~Date: 09/30/2022 04:39:56 PM
~ID: 1023
~Description: rdyboost4
Application.Error: COM (8)
~Numéro: 5463
~Date: 09/23/2022 03:00:21 AM
~ID: 10031
~Description: {41FD88F7-F295-4D39-91AC-A85F3149A05B}
System.Error: Service Control Manager (282)
~Numéro: 5977
~Date: 10/04/2022 03:57:41 PM
~ID: 7034
~Description: The %1 service terminated unexpectedly. It has done this %2 time(s).
System.Error: Microsoft-Windows-Kernel-Power (158)
~Numéro: 5969
~Date: 10/04/2022 03:36:55 PM
~ID: 137
~Description: 4
System.Error: DCOM (167)
~Numéro: 5953
~Date: 10/04/2022 12:29:46 PM
~ID: 10010
~Description: Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy!App.AppXwdz8g2fxr36xz0tdtagygnvemf85s7gg.mca
System.Warning: Microsoft-Windows-Time-Service (39)
~Numéro: 5899
~Date: 10/04/2022 07:03:07 AM
~ID: 134
~Description: NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on '%3'. NtpClient will try again in %2 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)
~Suggestion: Resynchroniser le client avec l'homologue de source de temps
System.Warning: Microsoft-Windows-DNS-Client (11)
~Numéro: 5846
~Date: 10/03/2022 02:33:14 PM
~ID: 1014
~Description: Name resolution for the name %1 timed out after none of the configured DNS servers responded.
~Suggestion: https://social.technet.microsoft.co...ent-id-1014-microsoft-windows-dns-client.aspx
System.Error: cdrom (43)
~Numéro: 5378
~ID: 7
~Description: The device, %1, has a bad block.
System.Error: EventLog (5)
~Numéro: 5244
~Date: 10/01/2022 12:14:31 PM
~ID: 6008
~Description: The previous system shutdown at %1 on %2 was unexpected.
System.Error: Schannel (66)
~Numéro: 5171
~Date: 10/01/2022 11:22:02 AM
~ID: 4103
~Description: A fatal error occurred while creating a TLS %1 credential. The internal error state is %2.
System.Warning: Display (2)
~Numéro: 4690
~Date: 09/27/2022 12:58:33 AM
~ID: 4101
~Description: Display driver %1 stopped responding and has successfully recovered.
System.Warning: mfehidk (2)
~Numéro: 4591
~Date: 09/23/2022 02:05:17 AM
~ID: 512
~Description: \Device\mfehidk**\stinger64.exe1312
System.Error: Microsoft-Windows-WindowsUpdateClient (195)
~Numéro: 4438
~Date: 09/21/2022 02:07:28 AM
~ID: 20
~Description: Installation Failure: Windows failed to install the following update with error %1: %2.
~Suggestion: http://kb.eventtracker.com/evtpass/...crosoft-Windows-WindowsUpdateClient_63351.asp
System.Warning: Disk (5)
~Numéro: 4068
~Date: 09/14/2022 08:16:31 PM
~ID: 158
~Description: Disk %2 has the same disk identifiers as one or more disks connected to the system. Go to Microsoft's support website (http://support.microsoft.com) and search for KB2983588 to resolve the issue.
~Suggestion: https://support.microsoft.com/en-hk/help/2983588/event-id-158-is-logged-for-identical-disk-guids
System.Warning: Microsoft-Windows-Kernel-PnP (15)
~Numéro: 1144
~Date: 08/09/2022 09:53:46 AM
~ID: 219
~Description: The driver %5 failed to load for the device %2.
~Suggestion: Vérifier que le pilote a bien été chargé dans les informations système

---\ Additional Scan (O88) (20) - 5s
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\qBittorrent\qbittorrent.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\qBittorrent\qbittorrent.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\KMPlayer\KMPlayer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\KMPlayer\KMPlayer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\qbittorrent_4.4.4_x64_setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\qbittorrent_4.4.4_x64_setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\VirtualBox-6.1.36-152435-Win.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\VirtualBox-6.1.36-152435-Win.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\AppData\Local\Popcorn-Time\Popcorn-Time.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\AppData\Local\Popcorn-Time\Popcorn-Time.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\qBittorrent\qbittorrent.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\qBittorrent\qbittorrent.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\KMPlayer\KMPlayer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\KMPlayer\KMPlayer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\qbittorrent_4.4.4_x64_setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\qbittorrent_4.4.4_x64_setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\VirtualBox-6.1.36-152435-Win.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\VirtualBox-6.1.36-152435-Win.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\AppData\Local\Popcorn-Time\Popcorn-Time.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\AppData\Local\Popcorn-Time\Popcorn-Time.exe.ApplicationCompany =>.SUP.Orphan.MUICache

---\ Summary of the elements found (5) - 0s
https://nicolascoolman.eu/2017/09/12/origine-lignes-orphelines/ =>.SUP.Orphan
https://nicolascoolman.eu/forum/Topic/Discord-logiciel-potentiellement-superflu-lps/ =>.SUP.Discord
https://nicolascoolman.eu/forum/Topic/warning-eventlogapp-evenement-dapplication/ =>Warning.EventLogApp
https://nicolascoolman.eu/forum/Topic/warning-eventlogsys-evenement-systeme/ =>Warning.EventLogSys
https://nicolascoolman.eu/forum/Topic/orphan-muicache-logiciel-potentiellement-superflu-lps/ =>.SUP.Orphan.MUICache

~ Unselected Options: WR,
~ End of the scan, 13270 items in 03mn01s (1727)(0)


Serial Number​

[00A657F778B31AE523D667131718D16EB2] [04/10/2022] (.Malwarebytes Inc..) - C:\Users\TeaTang\Desktop\adwcleaner.exe
[00A657F778B31AE523D667131718D16EB2] [08/08/2022] (.Malwarebytes Inc..) - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
[00A657F778B31AE523D667131718D16EB2] [08/08/2022] (.Malwarebytes Inc..) - C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll
[00A657F778B31AE523D667131718D16EB2] [08/08/2022] (.Malwarebytes Inc..) - C:\Program Files\Malwarebytes\Anti-Malware\mbuns.exe
[00A657F778B31AE523D667131718D16EB2] [13/09/2022] (.Malwarebytes Inc..) - C:\ProgramData\Malwarebytes\MBAMService\lkg_db\Actions.dll
[00A657F778B31AE523D667131718D16EB2] [13/09/2022] (.Malwarebytes Inc..) - C:\ProgramData\Malwarebytes\MBAMService\lkg_db\BrowserSDKDLL.dll
[00A657F778B31AE523D667131718D16EB2] [13/09/2022] (.Malwarebytes Inc..) - C:\ProgramData\Malwarebytes\MBAMService\lkg_db\ig.exe
[00A657F778B31AE523D667131718D16EB2] [13/09/2022] (.Malwarebytes Inc..) - C:\ProgramData\Malwarebytes\MBAMService\lkg_db\MBAMCore.dll
[00A657F778B31AE523D667131718D16EB2] [13/09/2022] (.Malwarebytes Inc..) - C:\ProgramData\Malwarebytes\MBAMService\lkg_db\sample.dll
[00C82FAC5D4F7288471464A39982A0D37F] [01/10/2022] (.CrystalBit Solutions.) - C:\Users\TeaTang\Desktop\geek\geek.exe
[00C82FAC5D4F7288471464A39982A0D37F] [03/10/2022] (.CrystalBit Solutions.) - C:\Users\TeaTang\AppData\Local\Temp\geek64.exe
[01993E38970DE6088DE6B6CB39BBEE24] [08/09/2022] (.Cisco WebEx LLC.) - C:\Users\TeaTang\AppData\Local\Discord\app-1.0.9006\modules\discord_voice-2\discord_voice\openh264-2.2.0-win32.dll
[01E20D5BE0B5190B1DBFDE9BEF380D9A] [08/08/2022] (.Discord Inc..) - C:\Users\TeaTang\AppData\Local\Discord\Update.exe =>.SUP.Discord
[01E20D5BE0B5190B1DBFDE9BEF380D9A] [12/09/2022] (.Discord Inc..) - C:\Users\TeaTang\AppData\Local\Discord\app-1.0.9006\modules\discord_voice-2\discord_voice\capture_helper.exe =>.SUP.Discord
[01E20D5BE0B5190B1DBFDE9BEF380D9A] [12/09/2022] (.Discord Inc..) - C:\Users\TeaTang\AppData\Local\Discord\app-1.0.9006\modules\discord_voice-2\discord_voice\mediapipe.dll =>.SUP.Discord
[0320BE3EB866526927F999B97B04346E] [26/02/2019] (.Realtek Semiconductor Corp..) - C:\Windows\System32\drivers\rtwlanu.sys
[0320BE3EB866526927F999B97B04346E] [26/02/2019] (.Realtek Semiconductor Corp..) - C:\Windows\System32\rtwlanu.sys
[0407ABB64E9990180789EACB81F5F914] [24/03/2022] (.VideoLAN.) - C:\Program Files\VideoLAN\VLC\vlc.exe
[044E3BF58976880FFD074448A8F7A058] [09/08/2022] (.Malwarebytes Corporation.) - C:\Windows\System32\drivers\6247C596.sys
[0689B3BCEB4409890A32D71976B132A4] [22/03/2022] (.Valve Corp..) - C:\Program Files (x86)\Steam\uninstall.exe
[0689B3BCEB4409890A32D71976B132A4] [26/07/2022] (.Valve Corp..) - C:\Program Files (x86)\Common Files\Steam\steamservice.exe
[0689B3BCEB4409890A32D71976B132A4] [26/07/2022] (.Valve Corp..) - C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
[0689B3BCEB4409890A32D71976B132A4] [26/07/2022] (.Valve Corp..) - C:\Program Files (x86)\Steam\steam.exe
[09268FAA1AD6894D179E5B87A2F06462] [14/09/2017] (.LunarG, Inc..) - C:\Program Files (x86)\VulkanRT\1.0.61.0\UninstallVulkanRT.exe
[0A399503A667F69C5AFA53B47EDCC135] [07/06/2021] (.NetEase(Hangzhou) Network Co. Ltd..) - C:\Program Files (x86)\Cyber Hunter\launcher.exe =>.Not verified
[0A399503A667F69C5AFA53B47EDCC135] [07/06/2021] (.NetEase(Hangzhou) Network Co. Ltd..) - C:\Program Files (x86)\Cyber Hunter\uninstall.exe =>.Not verified
[14781BC862E8DC503A559346F5DCC518] [09/11/2017] (.NVIDIA Corporation.) - C:\Windows\System32\drivers\nvhda64v.sys
[14781BC862E8DC503A559346F5DCC518] [09/11/2017] (.NVIDIA Corporation.) - C:\Windows\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_2e7fa54192fe16d0\nvlddmkm.sys
[14781BC862E8DC503A559346F5DCC518] [27/10/2017] (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe
[14781BC862E8DC503A559346F5DCC518] [27/10/2017] (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe
[14781BC862E8DC503A559346F5DCC518] [27/10/2017] (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
[1535EDA3C8F2FED30D4497572760F240] [24/08/2011] (.Crawler, LLC.) - C:\Windows\System32\drivers\stflt.sys
[1877A57C210DBBD1CCE4B4424F5D2F9F] [04/10/2022] (.d7xTech, Inc.) - C:\Users\TeaTang\Desktop\KillEmAll\KillEmAll.exe =>.Not verified
[19EA4DAF089570861408E9F05EFD9B89] [13/07/2022] (.Power Software Limited.) - C:\Program Files\AnyBurn\AnyBurn.exe =>.Not verified
[266D333EDE17A8B472053E4FA3934572] [11/08/2022] (.AVG Technologies CZ, s.r.o..) - C:\Windows\System32\drivers\rm.sys
[317DD1C55F51AC2756D9C93C060C6FA5] [04/10/2022] (.Pawan Kumar.) - C:\Users\TeaTang\Desktop\adware-removal-tool-by-tsa.exe =>.Not verified
[31F8F5FB790C592476CE0F3320DC4AF1] [01/10/2022] (.Stanislav Polshyn.) - C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger\CheckBrowsersLNK\Check Browsers LNK.exe =>.Not verified
[31F8F5FB790C592476CE0F3320DC4AF1] [01/10/2022] (.Stanislav Polshyn.) - C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger\HiJackThis\HiJackThis.exe =>.Not verified
[31F8F5FB790C592476CE0F3320DC4AF1] [02/10/2022] (.Stanislav Polshyn.) - C:\Users\TeaTang\Desktop\ClearLNK.exe =>.Not verified
[51CA009816FDBD80F120E015EE75823E] [19/07/2022] (.Oracle Corporation.) - C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe
[51CA009816FDBD80F120E015EE75823E] [19/07/2022] (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys
[51CA009816FDBD80F120E015EE75823E] [19/07/2022] (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxNetLwf.sys
[51CA009816FDBD80F120E015EE75823E] [19/07/2022] (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxSup.sys
[51CA009816FDBD80F120E015EE75823E] [19/07/2022] (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxUSBMon.sys
[56C6D267ADE07F72EEB4603BBF84CEA5] [20/07/2017] (.Red Hat, Inc..) - C:\Windows\System32\drivers\balloon.sys =>.Not verified
[56C6D267ADE07F72EEB4603BBF84CEA5] [20/07/2017] (.Red Hat, Inc..) - C:\Windows\System32\drivers\viorng.sys =>.Not verified
[56C6D267ADE07F72EEB4603BBF84CEA5] [20/07/2017] (.Red Hat, Inc..) - C:\Windows\System32\drivers\viostor.sys =>.Not verified
[58ED019DDA867257493E61E5F18DFAF4] [16/10/2017] (.Power Software Limited.) - C:\Program Files\AnyBurn\abcmd.exe
[7D9E9888D0F97A5432827A5E] [01/10/2022] (.McAfee, LLC.) - C:\Users\TeaTang\Desktop\MCPR.exe =>.Not verified
 
OK I’ll have a look when I return home from work.
 
FRST Fix.

Download attached fixlist.txt file and save it to the Desktop. NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


Download GlassWire Firewall.
Install on your machine.
Then Run kill em all.
Then restart Glasswire.
Go to firewall icon click it within the program.
Then start your browser.
You will get an alert from Glasswire.
Then click Analyze.
Under Virus Total.
Click enable virustotal, in Glasswire settings.
Unlock the feature then click enable manual file analysis
Then click auto analysis of all apps.
Click ok.

Now you will be able to see anything and everything that is connected inbound or outbound on your machine, if there is a rat then this will tell you without a doubt.
 

Attachments

By the way after i done the ''fix'' using FRST.
I was unable to login only in this site.
So i downloaded and installed another browser.

Fix result of Farbar Recovery Scan Tool (x64) Version: 30-08-2022
Ran by TeaTang (05-10-2022 16:07:58) Run:1
Running from C:\Users\TeaTang\Desktop
Loaded Profiles: TeaTang
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
RemoveProxy:
DeleteKey: HKLM\SOFTWARE\Avast Software
DeleteKey: HKLM\SOFTWARE\COMODO
DeleteKey: HKLM\SOFTWARE\HitmanPro
DeleteKey: HKLM\SOFTWARE\TrendMicro
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Adware Removal Tool by TSA
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Avast Software
DeleteKey: HKLM\SOFTWARE\WOW6432Node\MCPR
DeleteKey: HKLM\SOFTWARE\WOW6432Node\MicroWorld
DeleteKey: HKLM\SOFTWARE\WOW6432Node\TrendMicro
DeleteKey: HKCU\SOFTWARE\AVAST Software
DeleteKey: HKCU\SOFTWARE\MicroWorld
DeleteKey: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\AVAST Software
DeleteKey: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\MicroWorld
VirusTotal: c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.20970.0_x64__8wekyb3d8bbwe\hxtsr.exe
C:\ProgramData\Avira
C:\Program Files (x86)\Common Files\MicroWorld
C:\Users\TeaTang\AppData\Local\Avira
C:\Windows\System32\drivers\rm.sys
C:\Windows\System32\drivers\stflt.sys
CMD: wmic nicconfig where (IPEnabled=TRUE) call SetDNSServerSearchOrder ("76.76.19.19", "94.140.15.15")
CMD: sc stop WSearch
CMD: sc config WSearch start= disabled
CMD: sc stop lfsvc
CMD: sc config lfsvc start= disabled
CMD: del /s /q %ProgramData%\Microsoft\Diagnosis\ETLLogs\AutoLogger\AutoLogger-Diagtrack-Listener.etl
CMD: reg add HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\parameters /v DisabledComponents /t REG_DWORD /d 0xFFFFFFFF
CMD: reg add hklm\system\currentcontrolset\services\tcpip6\parameters /v DisabledComponents /t REG_DWORD /d 0xFFFFFFFF
CMD: ipconfig /flushdns
C:\Windows\Temp\*.*
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
emptytemp:
Reboot:
End::
*****************

Processes closed successfully.
SystemRestore: On => completed
Restore point was successfully created.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


========= End of RemoveProxy: =========

HKLM\SOFTWARE\Avast Software => removed successfully
HKLM\SOFTWARE\COMODO => removed successfully
HKLM\SOFTWARE\HitmanPro => removed successfully
HKLM\SOFTWARE\TrendMicro => removed successfully
HKLM\SOFTWARE\WOW6432Node\Adware Removal Tool by TSA => removed successfully
RegLink Found. Source: "" => Target: "HKLM\SOFTWARE\Avast Software"
"HKLM\SOFTWARE\WOW6432Node\Avast Software" => removed successfully
HKLM\SOFTWARE\WOW6432Node\MCPR => removed successfully
HKLM\SOFTWARE\WOW6432Node\MicroWorld => removed successfully
HKLM\SOFTWARE\WOW6432Node\TrendMicro => removed successfully
HKCU\SOFTWARE\AVAST Software => removed successfully
HKCU\SOFTWARE\MicroWorld => removed successfully
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\AVAST Software => not found
HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\MicroWorld => not found
VirusTotal: c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.20970.0_x64__8wekyb3d8bbwe\hxtsr.exe => https://www.virustotal.com/gui/file...bb1549d65272c7dcfcb8535c6c64af1abd-1664952323
C:\ProgramData\Avira => moved successfully
C:\Program Files (x86)\Common Files\MicroWorld => moved successfully
C:\Users\TeaTang\AppData\Local\Avira => moved successfully
C:\Windows\System32\drivers\rm.sys => moved successfully
C:\Windows\System32\drivers\stflt.sys => moved successfully

========= wmic nicconfig where (IPEnabled=TRUE) call SetDNSServerSearchOrder ("76.76.19.19", "94.140.15.15") =========

Executing (\\DESKTOP-GRKBJ8K\ROOT\CIMV2:Win32_NetworkAdapterConfiguration.Index=10)->SetDNSServerSearchOrder()

Method execution successful.

Out Parameters:
instance of __PARAMETERS
{
ReturnValue = 0;
};
Executing (\\DESKTOP-GRKBJ8K\ROOT\CIMV2:Win32_NetworkAdapterConfiguration.Index=13)->SetDNSServerSearchOrder()

Method execution successful.

Out Parameters:
instance of __PARAMETERS
{
ReturnValue = 0;
};

========= End of CMD: =========


========= sc stop WSearch =========


SERVICE_NAME: WSearch
TYPE : 10 WIN32_OWN_PROCESS
STATE : 3 STOP_PENDING
(NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x1
WAIT_HINT : 0x7530

========= End of CMD: =========


========= sc config WSearch start= disabled =========

[SC] ChangeServiceConfig SUCCESS

========= End of CMD: =========


========= sc stop lfsvc =========


SERVICE_NAME: lfsvc
TYPE : 30 WIN32
STATE : 3 STOP_PENDING
(STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x2
WAIT_HINT : 0x2710

========= End of CMD: =========


========= sc config lfsvc start= disabled =========

[SC] ChangeServiceConfig SUCCESS

========= End of CMD: =========


========= del /s /q %ProgramData%\Microsoft\Diagnosis\ETLLogs\AutoLogger\AutoLogger-Diagtrack-Listener.etl =========

Could Not Find C:\ProgramData\Microsoft\Diagnosis\ETLLogs\AutoLogger\AutoLogger-Diagtrack-Listener.etl

========= End of CMD: =========


========= reg add HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\parameters /v DisabledComponents /t REG_DWORD /d 0xFFFFFFFF =========

The operation completed successfully.


========= End of CMD: =========


========= reg add hklm\system\currentcontrolset\services\tcpip6\parameters /v DisabledComponents /t REG_DWORD /d 0xFFFFFFFF =========

The operation completed successfully.


========= End of CMD: =========


========= ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


=========== "C:\Windows\Temp\*.*" ==========

C:\Windows\Temp\HighPerformancePlan.log => moved successfully
Could not move "C:\Windows\Temp\MpCmdRun.log" => Scheduled to move on reboot.
C:\Windows\Temp\MpSigStub.log => moved successfully
C:\Windows\Temp\PowerPlan.log => moved successfully
C:\Windows\Temp\sa.9WZDNCRFHW41_0__.Public.InstallAgent.dat => moved successfully
C:\Windows\Temp\sa.9WZDNCRFJ27N_0__.Public.InstallAgent.dat => moved successfully
C:\Windows\Temp\UsoStoreFile.xml => moved successfully

========= End -> "C:\Windows\Temp\*.*" ========


=========== "C:\WINDOWS\system32\*.tmp" ==========

not found

========= End -> "C:\WINDOWS\system32\*.tmp" ========


=========== "C:\WINDOWS\syswow64\*.tmp" ==========

not found

========= End -> "C:\WINDOWS\syswow64\*.tmp" ========


=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 786432 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10611814 B
Java, Discord, Steam htmlcache => 0 B
Windows/system/drivers => 40960 B
Edge => 14534675 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 12096 B
TeaTang => 7108396 B

RecycleBin => 0 B
EmptyTemp: => 31.6 MB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 05-10-2022 16:10:21)

C:\Windows\Temp\MpCmdRun.log => Is moved successfully

==== End of Fixlog 16:10:21 ====
 
The kill em all program you used earlier.

As far as not being able to log into the site, I’m not sure on that. There was nothing in the fix related to chrome or Firefox. Only redundant files.
 
Ok now test for a while and see if any unusual connection attempts are made, you will be able to see with glassware, if anyone is attempting to connect.

Also, how is your internet now, and better, what symptoms have you had today?
 
After i installed GlassWire,it seems my pc is times faster.
But the internet speed it's the same (i download max with ~500 kb/s,incase my speed is 18 mb/s)
 
For the moment i don't have any strange activity.
So yes,only the slow internet is the issue for the moment.
I setted up the fastest DNS server.
 

Attachments

Can you hook your machine up directly to the modem via Ethernet cable, bypassing the router and rerun your speed test. Post new screen shot of speed test via modem, with only your computer online at the time. I noticed your average of 4.3, if you are paying for 18 and have several devices connected, this about right. Also, if you are running torrent software that can cause issues with internet, as it chews bandwidth.
 
Last edited:
So I imagine we can call this solved then? No problem on sharing the ip . That’s irrelevant to the issue.
 
Status
Not open for further replies.