Inactive Irql_not_less_or_equal (Virus?)

Status
Not open for further replies.

ksleano

Posts: 11   +0
I am using windows 10
So my problem began when I accidentally clicked an adobe flash plugin. My computer started to became so slow to the point that it is unusable and windows explorer started not responding as well. I turned off my laptop forcefully and I cannot even get it to start booting so I've decided to use the "Reset PC" option in windows recovery. It did its thing but to no avail, still not working so it reverted itself back. I have also tried using the Startup Repair and I finally was able to log in my computer. Before I start celebrating I have tried seeing if I could sleep/hibernate without problems. I did have problems and thought maybe its the RAM and THEN it finally revealed itself.
For a brief moment I found the error irql_not_less_or_equal.

Fast forward a day an a half im reading about people with the same problems as I did
http://www.tomshardware.com/answers/id-2887562/virus-caused-irql-equal-bsod.html
https://www.techspot.com/community/members/broni.246533/

Right now Im trying to follow @Broni 's advice on a thread 5 years ago
I have downloaded Farbar already and have the txt files
 
==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-09 20:33 - 2017-09-24 13:35 - 000000000 ___DC C:\WINDOWS\Panther
2017-11-09 19:45 - 2015-06-26 18:51 - 000000000 __SHD C:\Users\kslea_000\IntelGraphicsProfiles
2017-11-09 19:43 - 2017-09-28 11:03 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-11-09 19:43 - 2017-09-28 10:09 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-11-09 19:27 - 2017-09-28 11:03 - 000004156 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{77459B5D-8BB4-4107-B886-3F7F7C3559E8}
2017-11-09 19:25 - 2015-06-24 22:19 - 000000000 ____D C:\Users\kslea_000\.p2
2017-11-09 19:25 - 2014-10-08 10:37 - 000000000 ____D C:\Users\kslea_000\AppData\Local\Eclipse
2017-11-09 19:23 - 2015-01-22 14:39 - 000000000 ____D C:\Program Files (x86)\Intel Driver Update Utility
2017-11-09 18:46 - 2017-09-28 10:19 - 000000000 ____D C:\Users\kslea_000
2017-11-09 18:44 - 2017-09-28 10:18 - 001817588 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-11-09 17:31 - 2017-09-13 06:03 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2017-11-09 16:50 - 2017-09-13 06:03 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-11-09 12:45 - 2017-09-13 00:18 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2017-11-09 12:09 - 2017-09-13 06:03 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2017-11-09 10:17 - 2017-09-13 06:03 - 000000000 ____D C:\WINDOWS\registration
2017-11-09 10:15 - 2017-09-13 06:03 - 000000000 ___HD C:\Program Files\WindowsApps
2017-11-09 08:05 - 2017-09-13 06:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-11-09 07:27 - 2015-02-27 00:00 - 000002243 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-11-07 07:44 - 2014-08-18 15:44 - 000000588 _____ C:\Users\kslea_000\AppData\Roaming\WB.CFG
2017-11-06 09:12 - 2017-09-13 06:03 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-11-03 21:15 - 2017-09-13 06:03 - 000000000 ____D C:\WINDOWS\rescache
2017-11-03 21:05 - 2014-10-19 12:05 - 000000000 ____D C:\Users\kslea_000\AppData\Local\ElevatedDiagnostics
2017-11-03 16:50 - 2017-04-14 22:56 - 000018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys
2017-11-03 16:47 - 2017-09-13 06:01 - 000000000 ____D C:\WINDOWS\INF
2017-11-02 09:50 - 2017-10-02 20:11 - 000000000 ___RD C:\Users\kslea_000\Documents\Scanned Documents
2017-11-02 09:38 - 2015-06-20 07:41 - 000002426 _____ C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-11-02 09:38 - 2015-06-20 07:41 - 000000000 ___RD C:\Users\kslea_000\OneDrive
2017-11-02 09:21 - 2015-10-24 16:39 - 000000000 ____D C:\Program Files (x86)\Browny02
2017-11-02 09:09 - 2017-02-05 23:17 - 000000000 ____D C:\Users\kslea_000\Downloads\install
2017-11-02 09:01 - 2015-10-24 16:40 - 000007891 _____ C:\WINDOWS\BRRBCOM.INI
2017-10-29 22:16 - 2017-01-06 10:06 - 000000000 ____D C:\Users\kslea_000\Desktop\CS Classes
2017-10-28 19:42 - 2016-11-04 13:55 - 000000000 ____D C:\ProgramData\Promethean
2017-10-28 19:42 - 2016-11-04 13:55 - 000000000 ____D C:\ProgramData\Activ Software
2017-10-28 09:32 - 2015-01-22 07:27 - 000000000 ___RD C:\Users\kslea_000\Desktop\Work
2017-10-28 00:51 - 2016-07-24 21:23 - 000000000 ____D C:\Users\kslea_000\.gimp-2.8
2017-10-27 23:09 - 2016-04-11 14:13 - 000000000 ____D C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2017-10-27 20:55 - 2016-07-24 21:28 - 000000000 ____D C:\Users\kslea_000\AppData\Local\gtk-2.0
2017-10-25 22:14 - 2017-04-08 07:29 - 000000000 ___HD C:\Users\kslea_000\.git
2017-10-25 16:52 - 2017-09-19 20:33 - 000000000 ____D C:\Users\kslea_000\.config
2017-10-25 16:29 - 2017-02-23 19:06 - 000000000 ____D C:\Users\kslea_000\AppData\Roaming\GitHub
2017-10-25 16:29 - 2017-02-23 19:06 - 000000000 ____D C:\Users\kslea_000\AppData\Local\GitHub
2017-10-25 15:55 - 2017-04-06 17:36 - 000000000 ____D C:\ProgramData\Git
2017-10-25 15:26 - 2017-09-28 11:03 - 000004588 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-10-25 15:26 - 2017-09-13 06:03 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-10-25 15:26 - 2017-09-13 06:03 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-10-25 09:46 - 2016-07-22 06:06 - 001445516 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2017-10-24 08:01 - 2014-10-03 08:58 - 000000000 ____D C:\Users\kslea_000\AppData\Roaming\Skype
2017-10-22 11:45 - 2017-04-14 22:55 - 000000000 ____D C:\Program Files\Intel
2017-10-22 11:44 - 2016-03-26 10:26 - 000000000 ____D C:\Program Files\Common Files\McAfee
2017-10-22 11:44 - 2014-08-26 23:15 - 000000000 ____D C:\Program Files\Java
2017-10-19 20:35 - 2015-09-08 11:34 - 000000000 ____D C:\Users\kslea_000\Desktop\IDE
2017-10-19 18:22 - 2017-09-28 11:03 - 000000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
2017-10-19 18:21 - 2014-06-01 22:27 - 000000000 ____D C:\Program Files\Lenovo
2017-10-19 18:16 - 2014-06-01 22:27 - 000000000 ____D C:\WINDOWS\Downloaded Installations
2017-10-19 17:55 - 2014-06-01 22:32 - 000000000 ____D C:\ProgramData\Energy Manager
2017-10-19 16:20 - 2017-09-28 11:03 - 000003366 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3820140182-2222416168-2024790571-1001
2017-10-19 15:42 - 2014-08-19 05:18 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-10-19 15:21 - 2014-08-19 05:18 - 126925120 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-10-18 08:08 - 2017-09-13 06:03 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2017-10-17 20:52 - 2014-08-19 16:45 - 000000000 ____D C:\ProgramData\Oracle
2017-10-17 20:51 - 2017-04-11 17:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-10-17 20:51 - 2014-08-26 23:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2017-10-17 20:49 - 2017-04-11 17:15 - 000110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2017-10-17 20:49 - 2014-06-01 22:23 - 000000000 ____D C:\ProgramData\McAfee
2017-10-17 20:48 - 2016-03-26 10:27 - 000000000 ____D C:\Users\kslea_000\AppData\Local\tkdata
2017-10-17 09:22 - 2017-01-29 09:54 - 000000000 ____D C:\Program Files (x86)\Autodesk
2017-10-17 09:22 - 2017-01-29 09:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
2017-10-17 09:22 - 2016-11-17 14:24 - 000000000 ____D C:\Users\kslea_000\AppData\Local\Autodesk
2017-10-17 09:22 - 2014-11-18 20:00 - 000000000 ____D C:\ProgramData\Autodesk
2017-10-13 09:28 - 2017-03-30 07:09 - 000000000 ____D C:\Users\kslea_000\Desktop\FAST
2017-10-13 09:27 - 2014-08-19 04:48 - 000000000 ___RD C:\Users\kslea_000\Desktop\shortcuts
2017-10-13 08:42 - 2017-09-28 10:21 - 000000000 ____D C:\Users\kslea_000\AppData\Local\Packages
2017-10-13 00:25 - 2017-01-29 09:46 - 000000000 ____D C:\Program Files\Autodesk
2017-10-13 00:19 - 2017-09-28 10:27 - 000000000 ____D C:\spring-framework-5.0.0.RELEASE
2017-10-12 23:54 - 2015-06-09 02:07 - 000000000 ____D C:\Users\kslea_000\.eclipse
2017-10-12 23:46 - 2014-10-08 10:27 - 000000000 ____D C:\Eclipse
2017-10-12 23:30 - 2017-09-24 12:41 - 000000000 ____D C:\Users\kslea_000\AppData\Roaming\Postman
2017-10-10 10:57 - 2017-09-28 11:03 - 000004374 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater

==================== Files in the root of some directories =======

2015-02-07 10:02 - 2015-02-07 10:02 - 000036352 ___SH () C:\Users\kslea_000\AppData\Roaming\Thumbs.db
2014-08-18 15:44 - 2017-11-07 07:44 - 000000588 _____ () C:\Users\kslea_000\AppData\Roaming\WB.CFG
2015-06-16 11:53 - 2017-05-19 10:50 - 000000600 _____ () C:\Users\kslea_000\AppData\Roaming\winscp.rnd
2014-11-09 06:48 - 2014-11-09 06:48 - 000022528 _____ () C:\Users\kslea_000\AppData\Local\1714473640extsetup17144825001.exe
2014-11-09 06:48 - 2014-11-09 06:48 - 000643948 _____ () C:\Users\kslea_000\AppData\Local\1714473640extsq.dll
2014-08-19 04:51 - 2014-08-18 20:00 - 000001014 _____ () C:\Users\kslea_000\AppData\Local\7396d5af-93b3-4d36-bfec-04bbd1449761.dat
2014-08-18 20:02 - 2014-08-18 20:02 - 000000230 _____ () C:\Users\kslea_000\AppData\Local\9d23df9e-bfca-43b9-ac54-1557fa13a733.dat
2014-12-01 15:48 - 2014-12-17 22:48 - 000000001 _____ () C:\Users\kslea_000\AppData\Local\DSI.DAT
2014-12-17 22:48 - 2014-12-17 22:48 - 000022528 _____ () C:\Users\kslea_000\AppData\Local\dsisetup3638243432.exe
2014-12-01 15:48 - 2014-12-01 15:48 - 000022528 _____ () C:\Users\kslea_000\AppData\Local\dsisetup4346390622.exe
2014-08-18 20:02 - 2014-08-18 20:02 - 000000230 _____ () C:\Users\kslea_000\AppData\Local\ed3681de-6547-4ee3-b1b5-7dc739c61302.dat
2014-11-09 06:48 - 2014-11-09 06:48 - 000000008 _____ () C:\Users\kslea_000\AppData\Local\ext2.dat
2014-08-18 20:02 - 2014-08-18 20:02 - 000000278 _____ () C:\Users\kslea_000\AppData\Local\f50cdcdf-ea65-49ae-ac9b-d6b331e429f9.dat
2014-10-13 14:40 - 2017-05-19 14:34 - 000000600 _____ () C:\Users\kslea_000\AppData\Local\PUTTY.RND
2017-10-27 20:55 - 2017-10-27 20:55 - 000002755 _____ () C:\Users\kslea_000\AppData\Local\recently-used.xbel
2015-01-16 23:02 - 2017-08-18 06:58 - 000007598 _____ () C:\Users\kslea_000\AppData\Local\resmon.resmoncfg
2017-10-28 18:59 - 2017-10-28 18:59 - 000005019 _____ () C:\ProgramData\dfnpcrng.nwi
2017-04-14 22:56 - 2017-04-14 22:56 - 000000000 _____ () C:\ProgramData\DP45977C.lfl
2015-08-10 19:03 - 2015-06-11 19:03 - 000000032 _____ () C:\ProgramData\hash.dat
2017-10-28 18:59 - 2017-10-28 18:59 - 000000016 _____ () C:\ProgramData\mntemp

Files to move or delete:
====================
C:\ProgramData\hash.dat


Some files in TEMP:
====================
2017-11-09 19:33 - 2017-11-09 19:33 - 001444000 _____ (Sysinternals - www.sysinternals.com) C:\Users\kslea_000\AppData\Local\Temp\procexp64.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-11-03 21:05

==================== End of FRST.txt ============================
 
==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630312 2017-09-13] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-07-06] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-07-06] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-07-06] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3743648 2015-09-02] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [6340312 2013-07-19] (Realtek semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-11-04] (Intel Corporation)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15813616 2014-06-01] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2014-06-01] (Lenovo(beijing) Limited)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [IgfxTray] => C:\windows\system32\igfxtray.exe [401912 2017-04-23] ()
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-25] (Logitech, Inc.)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-07-06] (Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [1046496 2016-11-11] (DivX, LLC)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [GoPro Studio Importer] => C:\Program Files (x86)\GoPro\Tools\Importer\GoPro Importer.exe [3218184 2015-10-02] (GoPro)
HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4513792 2014-05-22] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [DSATray] => C:\Program Files (x86)\Intel Driver Update Utility\DsaTray.exe [130808 2017-06-14] (Intel)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files (x86)\DAEMON Tools Lite\DTAgent.exe [4468056 2015-06-18] (Disc Soft Ltd)
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\Run: [Google Update] => C:\Users\kslea_000\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-04-28] (Google Inc.)
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\Run: [Google Photos Backup] => C:\Users\kslea_000\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe [3790936 2016-04-08] (Google, Inc)
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\Run: [Akamai NetSession Interface] => C:\Users\kslea_000\AppData\Local\Akamai\netsession_win.exe [4490200 2017-01-03] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\Run: [ApacheTomcatMonitor8.5_Tomcat8] => C:\Program Files\Apache Software Foundation\Tomcat 8.5\bin\Tomcat8w.exe [110208 2017-09-28] (Apache Software Foundation)
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\Run: [Chromium] => c:\users\kslea_000\appdata\local\chromium\application\chrome.exe --auto-launch-at-startup --profile-directory=Default --restore-last-session
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\Run: [MySQL Notifier] => C:\Program Files (x86)\MySQL\MySQL Notifier 1.1\MySqlNotifier.exe [754176 2016-07-29] (Oracle Corporation)
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\Policies\Explorer: []
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ALFA Wireless Utility.lnk [2017-04-17]
ShortcutTarget: ALFA Wireless Utility.lnk -> C:\Program Files (x86)\ALFA\Common\RaUI.exe (ALFA Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GoPro Importer.lnk [2015-05-03]
ShortcutTarget: GoPro Importer.lnk -> C:\Program Files (x86)\GoPro\Tools\Importer\GoPro Importer.exe (GoPro)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-09-05]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LibreOffice 5.3.lnk [2017-03-12]
ShortcutTarget: LibreOffice 5.3.lnk -> C:\Program Files\LibreOffice 5\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{1edac82d-842b-411c-9021-cdb5508894b4}: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{318aadff-d8e2-4f0e-bb40-4a6fe5d6e776}: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{32a9ad5f-10ec-46fb-807b-70a761bc50d9}: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{868a0501-f3f2-4542-a0ca-353dddf752b2}: [DhcpNameServer] 134.71.71.73 134.71.71.71 134.71.71.72
Tcpip\..\Interfaces\{fbddbd58-0c86-47ec-a0aa-7c6eea23cd57}: [DhcpNameServer] 209.18.47.61 209.18.47.62

Internet Explorer:
==================
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.search.yahoo.com/yhs/web?hspart=elm&hsimp=yhs-001&type=hdr_s_16_45_orgnl&param1=1&param2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1Qzu0Bzz0E0EyCyDzzzz0FzytD0EyCzz0B0BtN0D0Tzu0StCyByByEtN1L2XzutAtFtByEtFtCtBtFyDtBtN1L1Czu1M1Q1CtBzztFtDtFtCtN1L1G1B1V1N2Y1L1Qzu2StAtC0CyDyD0CzztAtGyDtCtB0EtG0D0E0E0BtGyBtDyDyCtGyEyD0AyEtDtB0CtDyBtDtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCtC0Czz0F0CtCyCtG0E0AyEzytGyEtCyCtBtG0AtBtAtCtG0AtBtA0DyB0FyCzytBtBtB0C2QtN0A0LzutB%26cr%3D1615632634%26a%3Dhdr_s_16_45_orgnl%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BInsider%2BPreview
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBDDI6Pk-fpITtt_7-dx2uy24NiqV9uao1hAZn4E9dQ5LuDKfTYXv1pKYiqLhwsIrHrbtITDWporGxfn17g9VCOfPmCPmOkUzk6uMUFXbcCuBUiF4GlrjuG0HNeD4rE6xEumUVZNF39VnJuNTILnz7B8V8PSJI4fgVFktfLw,,&q={searchTerms}
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.search.yahoo.com/yhs/web?hspart=elm&hsimp=yhs-001&type=hdr_s_16_45_orgnl&param1=1&param2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1Qzu0Bzz0E0EyCyDzzzz0FzytD0EyCzz0B0BtN0D0Tzu0StCyByByEtN1L2XzutAtFtByEtFtCtBtFyDtBtN1L1Czu1M1Q1CtBzztFtDtFtCtN1L1G1B1V1N2Y1L1Qzu2StAtC0CyDyD0CzztAtGyDtCtB0EtG0D0E0E0BtGyBtDyDyCtGyEyD0AyEtDtB0CtDyBtDtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCtC0Czz0F0CtCyCtG0E0AyEzytGyEtCyCtBtG0AtBtAtCtG0AtBtA0DyB0FyCzytBtBtB0C2QtN0A0LzutB%26cr%3D1615632634%26a%3Dhdr_s_16_45_orgnl%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BInsider%2BPreview
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://home.lenovo.com
SearchScopes: HKLM -> DefaultScope {11A6201F-575B-433A-B3CB-08312F8D06BC} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_16_45_orgnl&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1Qzu0Bzz0E0EyCyDzzzz0FzytD0EyCzz0B0BtN0D0Tzu0StCyByByEtN1L2XzutAtFtByEtFtCtBtFyDtBtN1L1Czu1M1Q1CtBzztFtDtFtCtN1L1G1B1V1N2Y1L1Qzu2StAtC0CyDyD0CzztAtGyDtCtB0EtG0D0E0E0BtGyBtDyDyCtGyEyD0AyEtDtB0CtDyBtDtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCtC0Czz0F0CtCyCtG0E0AyEzytGyEtCyCtBtG0AtBtAtCtG0AtBtA0DyB0FyCzytBtBtB0C2QtN0A0LzutB%26cr%3D1615632634%26a%3Dhdr_s_16_45_orgnl%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BInsider%2BPreview&p={searchTerms}
SearchScopes: HKLM -> {11A6201F-575B-433A-B3CB-08312F8D06BC} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_16_45_orgnl&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1Qzu0Bzz0E0EyCyDzzzz0FzytD0EyCzz0B0BtN0D0Tzu0StCyByByEtN1L2XzutAtFtByEtFtCtBtFyDtBtN1L1Czu1M1Q1CtBzztFtDtFtCtN1L1G1B1V1N2Y1L1Qzu2StAtC0CyDyD0CzztAtGyDtCtB0EtG0D0E0E0BtGyBtDyDyCtGyEyD0AyEtDtB0CtDyBtDtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCtC0Czz0F0CtCyCtG0E0AyEzytGyEtCyCtBtG0AtBtAtCtG0AtBtA0DyB0FyCzytBtBtB0C2QtN0A0LzutB%26cr%3D1615632634%26a%3Dhdr_s_16_45_orgnl%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BInsider%2BPreview&p={searchTerms}
SearchScopes: HKLM -> {f7bb050c-e116-44da-89c2-6f2b68c54836} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_16_45_orgnl&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1Qzu0Bzz0E0EyCyDzzzz0FzytD0EyCzz0B0BtN0D0Tzu0StCyByByEtN1L2XzutAtFtByEtFtCtBtFyDtBtN1L1Czu1M1Q1CtBzztFtDtFtCtN1L1G1B1V1N2Y1L1Qzu2StAtC0CyDyD0CzztAtGyDtCtB0EtG0D0E0E0BtGyBtDyDyCtGyEyD0AyEtDtB0CtDyBtDtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCtC0Czz0F0CtCyCtG0E0AyEzytGyEtCyCtBtG0AtBtAtCtG0AtBtA0DyB0FyCzytBtBtB0C2QtN0A0LzutB%26cr%3D1615632634%26a%3Dhdr_s_16_45_orgnl%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BInsider%2BPreview&p={searchTerms}
SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_16_45_orgnl&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1Qzu0Bzz0E0EyCyDzzzz0FzytD0EyCzz0B0BtN0D0Tzu0StCyByByEtN1L2XzutAtFtByEtFtCtBtFyDtBtN1L1Czu1M1Q1CtBzztFtDtFtCtN1L1G1B1V1N2Y1L1Qzu2StAtC0CyDyD0CzztAtGyDtCtB0EtG0D0E0E0BtGyBtDyDyCtGyEyD0AyEtDtB0CtDyBtDtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCtC0Czz0F0CtCyCtG0E0AyEzytGyEtCyCtBtG0AtBtAtCtG0AtBtA0DyB0FyCzytBtBtB0C2QtN0A0LzutB%26cr%3D1615632634%26a%3Dhdr_s_16_45_orgnl%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BInsider%2BPreview&p={searchTerms}
SearchScopes: HKLM-x32 -> {f7bb050c-e116-44da-89c2-6f2b68c54836} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001 -> DefaultScope {3E3D6C0C-3B02-11E5-82B5-B8EE6588F90E} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_16_45_orgnl&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1Qzu0Bzz0E0EyCyDzzzz0FzytD0EyCzz0B0BtN0D0Tzu0StCyByByEtN1L2XzutAtFtByEtFtCtBtFyDtBtN1L1Czu1M1Q1CtBzztFtDtFtCtN1L1G1B1V1N2Y1L1Qzu2StAtC0CyDyD0CzztAtGyDtCtB0EtG0D0E0E0BtGyBtDyDyCtGyEyD0AyEtDtB0CtDyBtDtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCtC0Czz0F0CtCyCtG0E0AyEzytGyEtCyCtBtG0AtBtAtCtG0AtBtA0DyB0FyCzytBtBtB0C2QtN0A0LzutB%26cr%3D1615632634%26a%3Dhdr_s_16_45_orgnl%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BInsider%2BPreview&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001 -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL =
SearchScopes: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001 -> {3E3D6C0C-3B02-11E5-82B5-B8EE6588F90E} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_16_45_orgnl&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1Qzu0Bzz0E0EyCyDzzzz0FzytD0EyCzz0B0BtN0D0Tzu0StCyByByEtN1L2XzutAtFtByEtFtCtBtFyDtBtN1L1Czu1M1Q1CtBzztFtDtFtCtN1L1G1B1V1N2Y1L1Qzu2StAtC0CyDyD0CzztAtGyDtCtB0EtG0D0E0E0BtGyBtDyDyCtGyEyD0AyEtDtB0CtDyBtDtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCtC0Czz0F0CtCyCtG0E0AyEzytGyEtCyCtBtG0AtBtAtCtG0AtBtA0DyB0FyCzytBtBtB0C2QtN0A0LzutB%26cr%3D1615632634%26a%3Dhdr_s_16_45_orgnl%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BInsider%2BPreview&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001 -> {f7bb050c-e116-44da-89c2-6f2b68c54836} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_151\bin\ssv.dll [2017-10-17] (Oracle Corporation)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-17] (Oracle Corporation)
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: TBSB07898 Class -> {FCBCCB87-9224-4B8D-B117-F56D924BEB18} -> C:\Program Files (x86)\Coupons.com CouponBar\tbcore3.dll => No File
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - Coupons.com CouponBar - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files (x86)\Coupons.com CouponBar\tbcore3.dll No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001 -> No Name - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - No File
Toolbar: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001 -> No Name - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - No File
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-11-2017
Ran by kslea_000 (administrator) on TUBULERRR (09-11-2017 20:33:20)
Running from C:\Users\kslea_000\Desktop
Loaded Profiles: kslea_000 (Available Profiles: kslea_000)
Platform: Windows 10 Home Version 1709 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\WINDOWS\System32\igfxCUIService.exe
(Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Nitro PDF Software) C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel) C:\Program Files (x86)\Intel Driver Update Utility\DSAService.exe
() C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe
() C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe
(Pharos Systems International) C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\ALFA\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\ALFA\Common\RaRegistry64.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Dropbox, Inc.) C:\WINDOWS\System32\DbxSvc.exe
(Nalpeiron Ltd.) C:\WINDOWS\SysWOW64\NLSSRV32.EXE
() C:\Program Files (x86)\Steam\SteamApps\common\wallpaper_engine\bin\wallpaperservice32_c.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\Program Files (x86)\Steam\SteamApps\common\wallpaper_engine\wallpaper32.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\WINDOWS\System32\igfxEM.exe
(Intel Corporation) C:\WINDOWS\System32\igfxHK.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Oracle Corporation) C:\Program Files (x86)\MySQL\MySQL Notifier 1.1\MySQLNotifier.exe
(The Document Foundation) C:\Program Files\LibreOffice 5\program\soffice.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(The Document Foundation) C:\Program Files\LibreOffice 5\program\soffice.bin
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
() C:\Program Files\Lenovo\iMController\AutoUpdate.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Lenovo) C:\Users\kslea_000\AppData\Local\Apps\2.0\KMKEJA67.X0D\TKCYTGLA.ZO3\lsb...tion_2d7b41b05b24775e_0001.0006_49d2acb6f7b8d10a\LSB.exe
() C:\Program Files\Lenovo\iMController\LegacyFeatures.exe
() C:\Program Files\Lenovo\iMController\PluginCommunication.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\System32\smartscreen.exe
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-11-2017
Ran by kslea_000 (09-11-2017 20:38:57)
Running from C:\Users\kslea_000\Desktop
Windows 10 Home Version 1709 (X64) (2017-09-28 19:11:16)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3820140182-2222416168-2024790571-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3820140182-2222416168-2024790571-503 - Limited - Disabled)
Guest (S-1-5-21-3820140182-2222416168-2024790571-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3820140182-2222416168-2024790571-1006 - Limited - Enabled)
kslea_000 (S-1-5-21-3820140182-2222416168-2024790571-1001 - Administrator - Enabled) => C:\Users\kslea_000
WDAGUtilityAccount (S-1-5-21-3820140182-2222416168-2024790571-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

. . (HKLM\...\{89B9210B-8111-438F-B51B-7AB64F658E2C}) (Version: 7.1 - Intel) Hidden
. . . (HKLM-x32\...\{DEAF3493-EBF3-40F2-9D8A-5BD016E9E47C}) (Version: 2.8.1.9 - Intel) Hidden
µTorrent (HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\uTorrent) (Version: 3.5.0.43804 - BitTorrent Inc.)
64 Bit HP CIO Components Installer (HKLM\...\{FD868C71-6CCF-42E2-B90D-0504AB0036FE}) (Version: 13.2.1 - Hewlett-Packard) Hidden
7-Zip 15.05 beta x64 (HKLM\...\7-Zip) (Version: - )
ACA & MEP 2017 Object Enabler (HKLM\...\{28B89EEF-0004-0000-5102-CF3F3A09B77D}) (Version: 7.9.45.0 - Autodesk) Hidden
ACAD Private (HKLM\...\{28B89EEF-0001-0000-3102-CF3F3A09B77D}) (Version: 21.0.52.0 - Autodesk) Hidden
ActivInspire Core Resources (ENU) v1 (HKLM-x32\...\{FCD243AC-C4FF-48B5-AE57-7B91EDD2EE90}) (Version: 1.6.3 - Promethean)
ActivInspire Help (USA) v2 (HKLM-x32\...\{CB4E57A7-BA3A-41BD-8B14-3CD49D6DFBC6}) (Version: 2.0.0 - Promethean)
ActivInspire HWR Resources (ENU) v1 (HKLM-x32\...\{3D8C96C4-CEB6-4B97-BA4C-9BB7DF083224}) (Version: 1.7.1 - Promethean)
ActivInspire v2 (HKLM-x32\...\{7327AE03-C66E-410B-AD29-A7AA991FB3B4}) (Version: 2.8.66693 - Promethean)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 21.0.0.198 - Adobe Systems Incorporated)
Adobe Digital Editions 4.5 (HKLM-x32\...\Adobe Digital Editions 4.5) (Version: 4.5.1 - Adobe Systems Incorporated)
Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.183 - Adobe Systems Incorporated)
Adobe Flash Player 27 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 27.0.0.183 - Adobe Systems Incorporated)
Advanced Auto Clicker (HKLM-x32\...\Advanced Auto Clicker) (Version: - )
Akamai NetSession Interface (HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\Akamai) (Version: - Akamai Technologies, Inc)
ALFA Wireless LAN Card (HKLM-x32\...\{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}) (Version: 1.0.0.0 - ALFA)
Android Studio (HKLM\...\Android Studio) (Version: 1.0 - Google Inc.)
Android Studio (HKLM-x32\...\Android Studio) (Version: 1.0 - Google Inc.)
Apache Tomcat 8.5 Tomcat8 (remove only) (HKLM\...\Apache Tomcat 8.5 Tomcat8) (Version: 8.5.23 - )
Application Insights Tools for Visual Studio 2013 (HKLM-x32\...\{05F508E8-2DC6-4B12-B6A9-51000536216A}) (Version: 2.4 - Microsoft Corporation) Hidden
Application Insights Tools for Visual Studio 2015 RC (HKLM-x32\...\{D160EB10-3249-44B8-91FE-FA266004BE3E}) (Version: 3.2 - Microsoft Corporation) Hidden
Application Verifier x64 External Package (HKLM\...\{77F3D72C-465F-BD51-890E-CC3914B1365F}) (Version: 8.100.26936 - Microsoft) Hidden
Arduino (HKLM-x32\...\Arduino) (Version: 1.6.5-r2 - Arduino LLC)
ArduinoTool (HKLM-x32\...\{81239E37-E2D7-6FE7-5404-C6D247544386}) (Version: 1.0.0 - UNKNOWN) Hidden
ArduinoTool (HKLM-x32\...\ArduinoTool) (Version: 1.0.0 - UNKNOWN)
Auto Mouse Click v7.2 (HKLM-x32\...\{F5E3859D-0720-41F0-BAF5-4CBCDFD8F406}_is1) (Version: 7.2 - MurGee.com)
AutoCAD 2017 - English (HKLM\...\{28B89EEF-0001-0409-2102-CF3F3A09B77D}) (Version: 21.0.52.0 - Autodesk) Hidden
AutoCAD 2017 (HKLM\...\{28B89EEF-0001-0000-0102-CF3F3A09B77D}) (Version: 21.0.52.0 - Autodesk) Hidden
AutoCAD 2017 Language Pack - English (HKLM\...\{28B89EEF-0001-0409-1102-CF3F3A09B77D}) (Version: 21.0.52.0 - Autodesk) Hidden
Autodesk AutoCAD 2017 - English (HKLM\...\AutoCAD 2017 - English) (Version: 21.0.52.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2017 Add-in 64 bit (HKLM\...\{276A67E0-71EB-4827-B5F7-2ACF02BC1A5B}) (Version: 4.37.6853 - Autodesk)
Autodesk Featured Apps 2016-2017 (HKLM-x32\...\{27C15055-713B-4D0E-881F-19598A2DFD59}) (Version: 2.2.0 - Autodesk)
Autodesk License Service (x64) - 3.1 (HKLM\...\{EB6FE58F-8576-4272-BB9C-6B47D9EDFA4D}) (Version: 3.1.26.0 - Autodesk)
AzureTools.Notifications (HKLM-x32\...\{3FBFCF2C-392A-4632-9442-14C305B44D5E}) (Version: 2.1.10731.1602 - Microsoft Corporation) Hidden
AzureTools.Notifications (HKLM-x32\...\{AE75FA48-59DB-4C47-9B34-756093C15213}) (Version: 2.6.30331.1601 - Microsoft Corporation) Hidden
Battle for Wesnoth 1.12.4 (HKLM-x32\...\Battle for Wesnoth 1.12.4) (Version: 1.12.4 - )
Behaviors SDK (Windows Phone) for Visual Studio 2013 (HKLM-x32\...\{594DB57D-58D1-4AA3-AE6C-BF99484F52F8}) (Version: 12.0.50716.0 - Microsoft Corporation) Hidden
Behaviors SDK (Windows) for Visual Studio 2013 (HKLM-x32\...\{28C7344F-E894-4CF5-8D05-EDC7ED71796C}) (Version: 12.0.50429.0 - Microsoft Corporation) Hidden
Blend for Visual Studio 2013 (HKLM-x32\...\{EBC890A6-DE7C-44B4-AA03-119B6190D3E1}) (Version: 12.0.41002.1 - Microsoft Corporation) Hidden
Blend for Visual Studio 2013 ENU resources (HKLM-x32\...\{9ED1634C-4E71-4992-A1BA-7C4BE6EE39E1}) (Version: 12.0.41002.1 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for .NET 4.5 (HKLM-x32\...\{37E53780-3944-4A6A-842F-727128E8616E}) (Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for Silverlight 5 (HKLM-x32\...\{0C03A66F-1FF0-45F9-8D67-0D806EBFFBA1}) (Version: 3.0.40218.0 - Microsoft Corporation) Hidden
BlocklyPropClient version 0.6.2 (HKLM-x32\...\{68253492-3191-4F74-B077-379DD3235D37}_is1) (Version: 0.6.2 - Parallax Inc.)
Bonjour (HKLM\...\{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}) (Version: 2.0.2.0 - Apple Inc.)
Bonjour Print Services (HKLM\...\{0DA20600-6130-443B-9D4B-F30520315FA6}) (Version: 2.0.2.0 - Apple Inc.)
Brother MFL-Pro Suite MFC-J870DW (HKLM-x32\...\{7B4C83B6-17C1-4BFD-B86D-4D7AD4498CBB}) (Version: 1.0.3.0 - Brother Industries, Ltd.)
Build Tools - amd64 (HKLM\...\{CC1F74DF-058F-406C-BC7D-F14D6E5F7CBD}) (Version: 12.0.31101 - Microsoft Corporation) Hidden
Build Tools - x86 (HKLM-x32\...\{B255880F-8C5E-4FAF-8F9C-7DBA635B2615}) (Version: 12.0.31101 - Microsoft Corporation) Hidden
Build Tools Language Resources - amd64 (HKLM\...\{E43BBAEB-4914-44C6-88C0-E7A1DBD20A91}) (Version: 12.0.31101 - Microsoft Corporation) Hidden
Build Tools Language Resources - x86 (HKLM-x32\...\{D37FDF2F-8766-4BDF-A0E3-A60BDBB630ED}) (Version: 12.0.31101 - Microsoft Corporation) Hidden
Cura 15.04.6 (HKLM-x32\...\Cura_15.04.6) (Version: - )
CyberLink PowerDirector 10 (HKLM\...\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.1.0.0074 - Disc Soft Ltd)
Dependency Package Update (HKLM\...\{0788641D-D31A-478D-BB34-C41564AE9F93}) (Version: 1.6.36.00 - Lenovo Inc.) Hidden
Dependency Package Update (HKLM\...\{5252431C-288E-409D-ADCF-24407E0E6F70}) (Version: 1.6.32.00 - Lenovo Inc.) Hidden
Dependency Package Update (HKLM\...\{FFED38DF-94DC-4FF9-96C1-A6990EDA6B03}) (Version: 1.6.29.00 - Lenovo Inc.) Hidden
Dependency Package Update (HKLM-x32\...\{1D2682EA-75DD-44B6-BF2D-CD3C49EAD012}) (Version: 1.6.38.01 - Lenovo Group Limited) Hidden
Dependency Package Update (HKLM-x32\...\{3117B53D-A409-4D99-A0DE-11A1A40696FA}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Dependency Package Update (HKLM-x32\...\{4430150F-61B3-4142-BE04-EAC68C8DDA18}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Dependency Package Update (HKLM-x32\...\{4AF6C9BC-D8DB-4286-94D9-474CE54ADAA2}) (Version: 1.6.38.00 - Lenovo Group Limited) Hidden
Dependency Package Update (HKLM-x32\...\{503B47A9-E34A-4841-ADD7-417191D5DB5E}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Dependency Package Update (HKLM-x32\...\{546FF45D-2467-4950-AAFB-0A06ACBB6B2C}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Dependency Package Update (HKLM-x32\...\{5B2190E9-199D-450A-94B3-4D6826C770C2}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Dependency Package Update (HKLM-x32\...\{5BEFE1E1-F597-4B79-913B-15FFDB25B744}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Dependency Package Update (HKLM-x32\...\{63DE35C9-B080-4D03-B110-99E14FD35BCE}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Dependency Package Update (HKLM-x32\...\{65316098-0220-4D5C-B37A-6136083A0897}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Dependency Package Update (HKLM-x32\...\{E966DBE4-5075-465E-BA81-BC9A3A3204B3}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Disconnect Desktop (HKLM-x32\...\{5339EADE-2D0C-4F66-95CE-0502F8DE2BEF}) (Version: 1.0.3 - Disconnect) Hidden
Disconnect Desktop (HKLM-x32\...\Disconnect Desktop 1.0.3) (Version: 1.0.3 - Disconnect)
DivX Setup (HKLM\...\DivX Setup) (Version: 3.0.0.99 - DivX, LLC)
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.3.2.2 - Dolby Laboratories Inc)
Dotfuscator and Analytics Community Edition (HKLM-x32\...\{2386192E-D6DB-4AD2-9564-65586A0AE53E}) (Version: 5.5.4954.46574 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition 5.18.0 (HKLM-x32\...\{7C361160-7ADC-46CE-AFDC-D10C6EADD032}) (Version: 5.18.0.2789 - PreEmptive Solutions) Hidden
Download Windows Universal Tools (HKLM-x32\...\{EFA507A3-9D2B-37E3-8530-8EC1FFA750C5}) (Version: 14.0.22823 - Microsoft Corporation) Hidden
Energy Manager (HKLM-x32\...\{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.0.0.31 - Lenovo) Hidden
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.0.0.31 - Lenovo)
Extended Update (HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\UpdaterEX) (Version: - Extended Update) <==== ATTENTION
Geekbench 3 (HKLM-x32\...\Geekbench 3) (Version: - Primate Labs Inc.)
GIMP 2.8.18 (HKLM\...\GIMP-2_is1) (Version: 2.8.18 - The GIMP Team)
Git version 2.14.3 (HKLM\...\Git_is1) (Version: 2.14.3 - The Git Development Community)
GitHub (HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\5f7eb300e2ea4ebf) (Version: 3.3.4.0 - GitHub, Inc.)
GlassFish Server Open Source Edition 4.1 (HKLM\...\nbi-glassfish-mod-4.1.0.13.0) (Version: - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 63.0.3239.40 - Google Inc.)
Google Photos Backup (HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\Google Photos Backup) (Version: 1.1.2.13 - Google, Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
GoPro App (HKLM-x32\...\{F521FF84-E690-40CF-977C-4103A4D8E5D0}) (Version: 5.7.549 - GoPro, Inc.) Hidden
GoPro Studio 2.5.7 (HKLM-x32\...\{b996dca2-156c-4d2c-b9a3-59fac08cef33}) (Version: 2.5.7.549 - GoPro, Inc.)
Haskell Platform 8.0.2 (HKLM\...\HaskellPlatform-8.0.2) (Version: - Haskell.org)
Haskell Stack (HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\Haskell Stack) (Version: - )
HP Support Solutions Framework (HKLM-x32\...\{00612F78-52C4-46C0-97F0-F50B6036B5E2}) (Version: 12.8.37.11 - HP Inc.)
IDA Pro Free v5.0 (HKLM-x32\...\IDA Pro Free_is1) (Version: - Hex-Rays SA)
IIS 10.0 Express (HKLM\...\{5456A561-2429-411B-B2C8-CAE4411D446B}) (Version: 10.0.1733 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version: - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version: - )
Inkscape 0.91 (HKLM\...\{81922150-317E-4BB0-A31D-FF1C14F707C5}) (Version: 0.91 - inkscape.org)
Intel DnX USB Driver version 1.0.0 (HKLM\...\{B00B3C46-414C-4232-8021-29D40A90901F}_is1) (Version: 1.0.0 - Intel Corporation)
Intel Edison Device USB driver (HKLM\...\Intel Edison Device USB driver) (Version: 1.2.1 - Intel)
Intel Phone Flash Tool Lite version 5.2.4.0 (HKLM-x32\...\{50253A32-080B-4931-987E-ECF7F0E42CAC}_is1) (Version: 5.2.4.0 - Intel Corporation)
Intel XDK IoT Edition (HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\ARP_for_prd_iot_0.0.2571) (Version: 0.0.2571 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4624 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.8.1000 - Intel Corporation)
Intel® Driver Update Utility (HKLM-x32\...\{411cfca4-41d9-44e3-9d3e-2de29d4804e4}) (Version: 2.8.1.9 - Intel)
Intel® Edison (HKLM-x32\...\ARP_for_prd_edison_2015.0.1.16) (Version: 2015.0.1.16 - Intel Corporation)
Intel® Hardware Accelerated Execution Manager (HKLM\...\{6F73FF93-0B55-4194-AE45-C19DA1F33E97}) (Version: 6.0.3 - Intel Corporation)
Java 8 Update 151 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180151F0}) (Version: 8.0.1510.12 - Oracle Corporation)
Java SE Development Kit 8 Update 11 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180110}) (Version: 8.0.110 - Oracle Corporation)
Java SE Development Kit 8 Update 121 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180121}) (Version: 8.0.1210.13 - Oracle Corporation)
JetBrains PyCharm Community Edition 4.0.4 (HKLM-x32\...\PyCharm Community Edition 4.0.4) (Version: 139.1001 - JetBrains s.r.o.)
JetBrains WebStorm 2016.3.3 (HKLM-x32\...\WebStorm 2016.3.3) (Version: 163.12024.17 - JetBrains s.r.o.)
Kit SDK de vérification de Visual Studio 2012 - fra (HKLM-x32\...\{8A3862F9-F587-3DFA-AAFC-C1F0E116F05C}) (Version: 12.0.30501 - Microsoft Corporation) Hidden
Kits Configuration Installer (HKLM-x32\...\{B74E65FD-CC47-41C5-4B89-791A3F61942D}) (Version: 8.100.25984 - Microsoft) Hidden
Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.36.00 - Lenovo Group Limited)
Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10240 - Realtek Semiconductor Corp.)
Lenovo OneKey Recovery (HKLM\...\{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.2105 - CyberLink Corp.) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.2105 - CyberLink Corp.)
Lenovo Photos (HKLM-x32\...\Lenovo Photos) (Version: 4.8.5 - CEWE COLOR AG u Co. OHG)
Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.69.4 - ELAN Microelectronic Corp.)
Lenovo PowerDVD10 (HKLM-x32\...\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo Reach (HKLM-x32\...\{3245D8C8-7FE0-4FD4-B04B-2720A333D592}) (Version: 1.1.3.7 - Stoneware, Inc.)
Lenovo Service Bridge (HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\dda9ca0b023f4c56) (Version: 1.6.5.0 - Lenovo)
Lenovo Solution Center (HKLM\...\{06913C0C-88EB-42AF-9D94-3E9136CEE9BC}) (Version: 3.6.002.003 - Lenovo)
Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.07.0053 - Lenovo)
LibreOffice 5.3.0.3 (HKLM\...\{769A4A4C-3EBD-4469-B13B-5083F1C7717F}) (Version: 5.3.0.3 - The Document Foundation)
LocalESPC (HKLM-x32\...\{62910715-63E3-0AB0-0B29-99140DE1C15E}) (Version: 8.59.29989 - Microsoft Corporation) Hidden
LocalESPC Dev12 (HKLM-x32\...\{492498A3-F88C-FE2F-755C-9B1B91724CA5}) (Version: 8.100.25984 - Microsoft Corporation) Hidden
LocalESPCui for en-us (HKLM-x32\...\{326A5052-061C-F656-31E3-3B73842ABD46}) (Version: 8.59.29989 - Microsoft) Hidden
LocalESPCui for en-us Dev12 (HKLM-x32\...\{B1C38F27-D377-8C98-D98D-29B67C0B978D}) (Version: 8.100.25984 - Microsoft) Hidden
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
Logitech Unifying Software 2.50 (HKLM\...\Logitech Unifying) (Version: 2.50.25 - Logitech)
M3D - Beta Edition version 2016.05.06.1.4.2.6 (HKLM-x32\...\{8B5DDA80-9D03-465C-948D-CFE832FC37E3}_is1) (Version: 2016.05.06.1.4.2.6 - M3D LLC)
Makeblock Board Driver 1.1 (HKLM\...\{2C496F36-2241-4DEF-9C45-E4C2CEC5E998}_is1) (Version: - Maker Works)
Maple 2015 (HKLM\...\Maple 2015) (Version: 2015 - Maplesoft)
MatterControl version 1.2.2 (HKLM-x32\...\{EE5A0E0E-8608-4272-94D6-C2CDCD9307F2}_is1) (Version: 1.2.2 - MatterHackers, Inc.)
mBlock (HKLM-x32\...\{1E9DFEBB-4088-4693-A521-C755318BD492}_is1) (Version: 3.4.8 - Maker Works Technology Co. Ltd.,)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.163.2 - McAfee, Inc.)
Memory Profiler (HKLM-x32\...\{54F76D6C-0EC3-43D9-8BCC-73E31AB0BF06}) (Version: 12.0.31101 - Microsoft Corporation) Hidden
Memory Profiler (HKLM-x32\...\{A88AEB8B-A6C5-41BC-8F71-F704DD1E0D00}) (Version: 12.0.31101 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\...\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6 RC Multi-Targeting Pack (ENU) (HKLM-x32\...\{E689C2B1-3711-4FF7-95C4-1F4932A2B493}) (Version: 4.6.00057 - Microsoft Corporation)
Microsoft .NET Framework 4.6 RC Multi-Targeting Pack (HKLM-x32\...\{F1052F45-79C1-48D6-979F-CC5B6F864615}) (Version: 4.6.00057 - Microsoft Corporation)
Microsoft .NET Framework 4.6 RC SDK (HKLM-x32\...\{7318F8D8-AFC9-499C-9909-1CA56E7E7FB4}) (Version: 4.6.00057 - Microsoft
 
==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001_Classes\CLSID\{0D327DA6-B4DF-4842-B833-2CFF84F0948F}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2017\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001_Classes\CLSID\{144DF3B2-2402-47AE-9583-5A045929A8D4}\InprocServer32 -> C:\Users\kslea_000\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\kslea_000\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\kslea_000\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001_Classes\CLSID\{720DB9AF-D62C-4ED0-A377-429C22312852}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2017\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\kslea_000\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\kslea_000\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\kslea_000\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\kslea_000\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\kslea_000\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2017\en-US\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-3820140182-2222416168-2024790571-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\kslea_000\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\windows\system32\AcSignIcon.dll [2016-02-06] (Autodesk, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-06-14] (Igor Pavlov)
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2016-02-06] (Autodesk)
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2014-05-12] ()
ContextMenuHandlers1: [NP8ShellExtension] -> {9C4B85B8-956C-49BF-9BA5-101384E562B2} => C:\Program Files\Nitro\Pro 9\NPShellExtension.dll [2014-07-16] (Nitro PDF)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-06-14] (Igor Pavlov)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2017-04-23] (Intel Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-06-14] (Igor Pavlov)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {27162A75-576F-4FAF-81B2-74246029F28E} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\WINDOWS\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\task.vbs"
Task: {2F5D86F6-2D97-4F5E-A5E7-7BC6E06511E3} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3820140182-2222416168-2024790571-1001Core => C:\Users\kslea_000\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-22] (Google Inc.)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe
Task: {3B7235E3-2E86-415D-94DB-8EE5620AA74A} - System32\Tasks\Lenovo\LSC\Time72Task => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe
Task: {3E9CD821-409C-446E-BC3A-8655853AEEE1} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2015-07-01] (Lenovo)
Task: {43CB4A5A-6485-4718-92A9-EAA6BEFA90AC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-06-22] (HP Inc.)
Task: {445C283D-2321-43FF-A408-19B6037C8623} - System32\Tasks\Lenovo\LSC\Lenovo Solution Center Notifications => C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe [2017-06-09] (Lenovo)
Task: {4AA6BB37-84DB-47D9-8E04-F00EE2B70823} - System32\Tasks\MySQL\Installer\ManifestUpdate => C:\Program Files (x86)\MySQL\MySQL Installer for Windows\MySQLInstallerConsole.exe [2017-08-18] (Oracle Corporation)
Task: {4DA2FD32-66DB-4B63-ABAD-3A2EB3DFDBDC} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3820140182-2222416168-2024790571-1001UA1d1e916c202f304 => C:\Users\kslea_000\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-22] (Google Inc.)
Task: {584E40D9-A94C-4233-8B68-D61DF4C1047D} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSC.Services.UpdateStatusService.exe [2017-06-09] ()
Task: {595E9318-224C-4431-B9FC-C71E07AFB3C4} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_27_0_0_183_pepper.exe [2017-10-25] (Adobe Systems Incorporated)
Task: {5F16911D-D6B5-4247-8B93-E7ABCC8A2E21} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3820140182-2222416168-2024790571-1001Core1d1e916c1dfb96d => C:\Users\kslea_000\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-22] (Google Inc.)
Task: {619AE81A-504A-4104-97D5-209283349D91} - System32\Tasks\Microsoft\XblGameSave\XblGameSaveTask
Task: {61CC3BB7-9789-416A-BAC3-E38AC4076342} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2015-03-06] ()
Task: {67EA7172-8250-42B4-B495-6DD66EC9EB93} - System32\Tasks\{AC1F975C-3FF9-4554-98F7-CF167312C988} => C:\WINDOWS\system32\pcalua.exe -a C:\Users\KSLEA_~1\AppData\Local\Temp\DivXSetup.exe -d C:\WINDOWS\SysWOW64 -c /update all <==== ATTENTION
Task: {6DB0D03D-0625-4F31-8AAF-544370904F39} - System32\Tasks\Lenovo\LSC\RebootCountTask => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe
Task: {6F367145-396F-4F49-BFD5-15D02E19AE13} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe <==== ATTENTION
Task: {75DDC9FF-6B53-41DF-870F-9A45190E5A30} - System32\Tasks\{C10883CB-B3EE-493B-A57F-0FFA8E2D8B7D} => C:\WINDOWS\system32\pcalua.exe -a C:\Users\kslea_000\Desktop\edison\XboxController\driver\win7-64bit\Xbox360_64Eng.exe -d C:\Users\kslea_000\Desktop\edison\XboxController\driver\win7-64bit
Task: {77468288-0E4F-4E12-AE2C-FF1E5687226C} - System32\Tasks\Disconnect Desktop Updater => C:\Program Files (x86)\Disconnect\Disconnect Desktop\Disconnect Desktop Updater.exe [2015-01-18] (Disconnect)
Task: {7803F4CB-4AEA-49F5-BB41-D1C083F76904} - System32\Tasks\{B2ECA58D-CBAF-4637-B6E5-31FF57E5B130} => C:\windows\system32\pcalua.exe -a C:\Users\kslea_000\Downloads\forge-1.7.10-10.13.2.1230-installer-win.exe -d C:\Users\kslea_000\Downloads
Task: {82B68E5D-FE3D-468C-868E-C10A19D8DE0F} - System32\Tasks\SpeechRuntimeTask => C:\WINDOWS\system32\speech_onecore\common\SpeechRuntime.exe [2017-09-13] (Microsoft Corporation)
Task: {82F1613E-B3C2-4BBB-9654-BAC546BE452C} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {83AB3EF7-FE42-4426-A5E4-EA3358CC04C1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {84FC844B-FB0A-48B3-9EB5-C3BF85CD2CB4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {8706F977-7A3E-4151-9B20-969017924164} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {87B6B660-73DA-4565-BF00-6DE4E5C8FDA2} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [2016-03-17] (Intel Corporation)
Task: {8A4B9119-381F-4C03-9827-0D31F627B023} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-10s -> No File <==== ATTENTION
Task: {8E845FE2-1588-4B05-B103-E4E5C9DB4B5D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3820140182-2222416168-2024790571-1001Core1d258133756f4f5 => C:\Users\kslea_000\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-22] (Google Inc.)
Task: {9E11590A-52F3-4A88-A91B-1D5608916C87} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {A29B91AF-0D2F-49D1-BA15-38D16A6E8B1D} - System32\Tasks\{ACBED8A6-0893-4809-AC2D-ADB178790942} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxp://ui.skype.com/ui/0/6.20.0.104/en/abandoninstall?source=lightinstaller&page=tsPlugin
Task: {A49305B9-1727-40B8-AEA5-AF3AFBF0B149} - \Pokki -> No File <==== ATTENTION
Task: {A5983E21-92C1-442E-974F-933E1FBEEEA2} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe
Task: {AE35E9F7-0DFD-4FBC-B01A-5BC74697E2F5} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-10s -> No File <==== ATTENTION
Task: {B0481764-8F3B-40EB-9B67-504F81F5A597} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe <==== ATTENTION
Task: {B49ED5E6-0783-4CE8-B425-5292B95D2A92} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2017-06-09] (Lenovo)
Task: {B9C01113-EFFC-4BAE-BE27-E2A2E07EFE9F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {C78E616A-8237-48E5-AF44-D75E053789C3} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {C83F8D49-1874-48FD-8051-62835CECA3FF} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-10s -> No File <==== ATTENTION
Task: {CAF29945-6604-4537-876B-8CFE2D7707CB} - System32\Tasks\MySQLNotifierTask => C:\Program Files (x86)\MySQL\MySQL Notifier 1.1\MySQLNotifier.exe [2016-07-29] (Oracle Corporation)
Task: {CB6DB451-19B3-4FA3-BE42-0691BF2D0D6A} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.)
Task: {D0F13344-4E51-433B-8F06-7984A2E3BEC0} - System32\Tasks\Microsoft\Windows\PLA\LSC Memory => C:\windows\system32\rundll32.exe C:\windows\system32\pla.dll,PlaHost "LSC Memory" "$(Arg0)"
Task: {D476CB3D-87DC-4437-875B-8D240A74E74B} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe
Task: {D51672C5-A3FD-45CF-A734-FF10D879A007} - System32\Tasks\{8FA1624B-CEA2-47EC-A596-0C2D3D457418} => C:\windows\system32\pcalua.exe -a "C:\Users\kslea_000\Downloads\CDM v2.12.00 WHQL Certified.exe" -d C:\Users\kslea_000\Downloads
Task: {DF6F8B82-3D5E-42A3-BA6F-69E8B6784CD0} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3820140182-2222416168-2024790571-1001UA => C:\Users\kslea_000\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-22] (Google Inc.)
Task: {E0733D1F-A21B-47B4-B278-EC225E35C92E} - \Microsoft\Windows\Setup\GWXTriggers\Logon-10s -> No File <==== ATTENTION
Task: {E414EB8F-DCF0-4098-8D21-133905EC54B6} - \Microsoft\Windows\Setup\GWXTriggers\Time-10s -> No File <==== ATTENTION
Task: {E8897EA1-89CA-4F11-BED4-EE75E4B9A096} - System32\Tasks\{03971296-CF73-434E-89EC-B2BF0860F5DA} => C:\WINDOWS\system32\pcalua.exe -a C:\Users\kslea_000\AppData\Local\{48D27E8E-6C7A-1236-01E2-37DE258ACB46}\uninst.exe -c -FN="C:\Users\kslea_000\AppData\Roaming\{488F7E34-6DDD-1342-06EB-3490DA39C9AE}\UpdateTask.exe"-P=/Uninstall /s /noun /DelSelfDir
Task: {ED3F8F72-664D-4DB6-A4FA-4E2EC138FA20} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-3820140182-2222416168-2024790571-1001 => "C:\WINDOWS\system32\rundll32.exe" dfshim.dll,ShOpenVerbShortcut C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo\Lenovo Service Bridge.appref-ms
Task: {EE683068-C7FD-430B-AB73-6DDA1280C19A} - System32\Tasks\UpdaterEX => C:\Users\kslea_000\AppData\Roaming\UpdaterEX\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
Task: {EF6E28F8-C695-440B-B00C-0AD08C789C58} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3820140182-2222416168-2024790571-1001UA1d258133767a57b => C:\Users\kslea_000\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-22] (Google Inc.)
Task: {F5B87028-E2AE-48E6-B47E-26137287E293} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {F5C00E6B-65BA-472C-8797-A4816806FDCC} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-25] (Adobe Systems Incorporated)
Task: {FE926F9E-5724-4A41-BADC-83AC9D4295D6} - System32\Tasks\DivXUpdate => C:\Program Files (x86)\Common Files\DivX Shared\Qt4.8\DivXUpdate.exe [2016-11-11] (DivX, LLC)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\DriverToolkit Autorun.job => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3820140182-2222416168-2024790571-1001Core.job => C:\Users\kslea_000\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3820140182-2222416168-2024790571-1001Core1d1e916c1dfb96d.job => C:\Users\kslea_000\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3820140182-2222416168-2024790571-1001UA.job => C:\Users\kslea_000\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3820140182-2222416168-2024790571-1001UA1d1e916c202f304.job => C:\Users\kslea_000\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\UpdaterEX.job => C:\Users\KSLEA_~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Minecraft Debugger.lnk -> C:\Users\kslea_000\AppData\Roaming\.minecraft\minecraft launcher\Debug.bat ()
Shortcut: C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Apache Tomcat 8.5 Tomcat8\Tomcat Home Page.lnk -> hxxp://tomcat.apache.org
Shortcut: C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Apache Tomcat 8.5 Tomcat8\Tomcat Host Manager.lnk -> hxxp://127.0.0.1:8080/host-manager/htm
Shortcut: C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Apache Tomcat 8.5 Tomcat8\Tomcat Manager.lnk -> hxxp://127.0.0.1:8080/manager/htm
Shortcut: C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Apache Tomcat 8.5 Tomcat8\Welcome.lnk -> hxxp://127.0.0.1:8080

ShortcutWithArgument: C:\Users\kslea_000\Desktop\Udemy.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=bnjgaggikmmmdfjcienbbbjhkcegnaei
ShortcutWithArgument: C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Angular Udemy.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=bnjgaggikmmmdfjcienbbbjhkcegnaei
ShortcutWithArgument: C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Blackboard Learn.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=agihlfgekidinokgnfjadggijfjjbjcp
ShortcutWithArgument: C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\CAL POLY FAST Slack.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=eaiiehadmfapighpcibiikpihikplpjb
ShortcutWithArgument: C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Handshake.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=hfaneidkjnbomobjbbakliamblnojhmd
ShortcutWithArgument: C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Listen to KFI Radio Live _ Stream Onl.._.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=peiijbbdbiiepmgnaojcopklepedfkog
ShortcutWithArgument: C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Mail - ksleano@cpp.edu (1).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=mfelnnlfnkpgnoponopclbnbogfgjmje
ShortcutWithArgument: C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Mail - ksleano@cpp.edu.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=mfelnnlfnkpgnoponopclbnbogfgjmje
ShortcutWithArgument: C:\Users\kslea_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Podcasts.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=olkommdpchdepnbkeaainpbmlnbbidnj
 
==================== Loaded Modules (Whitelisted) ==============

2017-09-13 05:58 - 2017-09-13 05:58 - 000184576 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2014-07-16 14:08 - 2014-07-16 14:08 - 000417800 _____ () c:\program files\nitro\pro 9\nitro_updateservice.exe
2017-09-13 17:15 - 2017-09-13 17:15 - 039511040 _____ () C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe
2014-06-01 22:27 - 2012-04-24 02:43 - 000390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2015-10-24 16:39 - 2005-04-21 20:36 - 000143360 _____ () C:\WINDOWS\system32\BrSNMP64.dll
2017-02-14 08:21 - 2017-02-14 08:16 - 000025600 _____ () C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\bin\wallpaperservice32_c.exe
2017-02-14 08:16 - 2017-05-04 18:26 - 000735232 _____ () C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe
2017-09-13 05:59 - 2017-09-13 07:13 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-09-13 05:59 - 2017-09-13 07:13 - 001807360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-01-27 09:50 - 2017-01-27 09:50 - 000440424 _____ () C:\Program Files\LibreOffice 5\program\glew32.dll
2017-01-27 09:51 - 2017-01-27 09:51 - 001348200 _____ () C:\Program Files\LibreOffice 5\program\libxml2.dll
2017-01-27 09:51 - 2017-01-27 09:51 - 000228968 _____ () C:\Program Files\LibreOffice 5\program\libxslt.dll
2015-03-06 19:53 - 2015-03-06 19:53 - 000074168 _____ () C:\Program Files\Lenovo\iMController\AutoUpdate.exe
2015-03-06 19:53 - 2015-03-06 19:53 - 000020920 _____ () C:\Program Files\Lenovo\iMController\LegacyFeatures.exe
2015-03-06 19:53 - 2015-03-06 19:53 - 000026552 _____ () C:\Program Files\Lenovo\iMController\PluginCommunication.exe
2017-11-09 07:27 - 2017-11-07 20:07 - 004063064 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.40\libglesv2.dll
2017-11-09 07:27 - 2017-11-07 20:07 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.40\libegl.dll
2017-09-13 05:58 - 2017-09-13 05:58 - 000047616 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUITelemetry.dll
2017-09-13 05:58 - 2017-09-13 05:58 - 004173824 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIDataModel.dll
2017-09-13 05:58 - 2017-09-13 05:58 - 003634176 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIViewModels.dll
2017-02-05 23:20 - 2009-02-27 16:38 - 000139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\WINDOWS:nlsPreferences [386]
AlternateDataStreams: C:\ProgramData\Temp:054203E4 [150]
AlternateDataStreams: C:\ProgramData\Temp:1D93852F [254]
AlternateDataStreams: C:\ProgramData\Temp:373E1720 [131]
AlternateDataStreams: C:\ProgramData\Temp:46107B6C [118]
AlternateDataStreams: C:\ProgramData\Temp:69E87FA2 [138]
AlternateDataStreams: C:\ProgramData\Temp:A9967A61 [139]
AlternateDataStreams: C:\ProgramData\Temp:F4C624DE [123]
AlternateDataStreams: C:\Users\kslea_000\Downloads\2016-04-10 17.05.36.jpg:com.dropbox.attributes [990]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\Software\Classes\.scr: AutoCADScriptFile =>

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 05:25 - 2015-09-05 09:20 - 000000856 _____ C:\WINDOWS\system32\Drivers\etc\hosts

0.0.0.1 mssplus.mcafee.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\kslea_000\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{7d846230-b085-44a5-989e-cdbd68dd0a12}.jpeg
DNS Servers: 209.18.47.61 - 209.18.47.62
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"
HKLM\...\StartupApproved\StartupFolder: => "aiStarter.lnk"
HKLM\...\StartupApproved\StartupFolder: => "GoPro Importer.lnk"
HKLM\...\StartupApproved\StartupFolder: => "ALFA Wireless Utility.lnk"
HKLM\...\StartupApproved\Run: => "IAStorIcon"
HKLM\...\StartupApproved\Run: => "RtsFT"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run: => "ActivManager"
HKLM\...\StartupApproved\Run: => "ActivRelayKA"
HKLM\...\StartupApproved\Run32: => "DSATray"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "GoPro Studio Importer"
HKLM\...\StartupApproved\Run32: => "Dropbox"
HKLM\...\StartupApproved\Run32: => "PDFHook"
HKLM\...\StartupApproved\Run32: => "GrooveMonitor"
HKLM\...\StartupApproved\Run32: => "Autodesk Desktop App"
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\StartupApproved\StartupFolder: => "Dropbox.lnk"
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\StartupApproved\Run: => "Google Photos Backup"
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\StartupApproved\Run: => "BlueStacks Agent"
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\StartupApproved\Run: => "Chromium"
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\StartupApproved\Run: => "Autodesk Sync"
HKU\S-1-5-21-3820140182-2222416168-2024790571-1001\...\StartupApproved\Run: => "Akamai NetSession Interface"
 
==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{5880A28B-1F12-43D5-BE37-03B99B23F8F8}C:\program files\java\jdk1.8.0_121\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_121\bin\java.exe
FirewallRules: [TCP Query User{437C57C4-7CDF-4B2C-BBF0-457B0E03AACA}C:\program files\java\jdk1.8.0_121\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_121\bin\java.exe
FirewallRules: [{71A9EF2D-F542-41D3-BEE0-BC9B6F2F10F3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Risk of Rain\Risk of Rain.exe
FirewallRules: [{D4F33766-8772-4551-82F3-8945DDCECEB5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Risk of Rain\Risk of Rain.exe
FirewallRules: [UDP Query User{93791672-E01B-43A8-977D-34DC682DD620}C:\program files\java\jre1.8.0_131\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_131\bin\javaw.exe
FirewallRules: [TCP Query User{0A2084A5-FFC3-4DE4-B283-DA2A36DBD4CE}C:\program files\java\jre1.8.0_131\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_131\bin\javaw.exe
FirewallRules: [{0E3B9F72-AE61-488D-AD50-4032CB8FC5EE}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe
FirewallRules: [{BEC674EA-20EF-468F-A903-452B73D0C2CD}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe
FirewallRules: [UDP Query User{D8289053-80D2-4136-A3DD-A92485D1EE43}C:\program files (x86)\mblock\arduino\java\bin\java.exe] => (Allow) C:\program files (x86)\mblock\arduino\java\bin\java.exe
FirewallRules: [TCP Query User{C07AAC86-3662-4F56-84C9-DD452DFD53BA}C:\program files (x86)\mblock\arduino\java\bin\java.exe] => (Allow) C:\program files (x86)\mblock\arduino\java\bin\java.exe
FirewallRules: [UDP Query User{40CF1642-68CF-44BF-81AF-73CDAACEFF45}C:\program files (x86)\mblock\mblock.exe] => (Allow) C:\program files (x86)\mblock\mblock.exe
FirewallRules: [TCP Query User{7F5FADDD-CF6F-4931-B2D6-312140143AD1}C:\program files (x86)\mblock\mblock.exe] => (Allow) C:\program files (x86)\mblock\mblock.exe
FirewallRules: [UDP Query User{E4CAB1F9-762C-4A3F-A6FB-CBB441E7A30E}C:\program files (x86)\mblock\arduino\java\bin\java.exe] => (Allow) C:\program files (x86)\mblock\arduino\java\bin\java.exe
FirewallRules: [TCP Query User{8A34DE52-7297-46E6-A3A6-33A0AB678765}C:\program files (x86)\mblock\arduino\java\bin\java.exe] => (Allow) C:\program files (x86)\mblock\arduino\java\bin\java.exe
FirewallRules: [UDP Query User{BE230B41-01B4-4C09-A902-601702B3248E}C:\users\kslea_000\desktop\work\2017\scribbler tree\blocklypropclient\propeller-tools\windows\proploader.exe] => (Allow) C:\users\kslea_000\desktop\work\2017\scribbler tree\blocklypropclient\propeller-tools\windows\proploader.exe
FirewallRules: [TCP Query User{E01CB09F-CCAD-4E5C-B273-958B433D0850}C:\users\kslea_000\desktop\work\2017\scribbler tree\blocklypropclient\propeller-tools\windows\proploader.exe] => (Allow) C:\users\kslea_000\desktop\work\2017\scribbler tree\blocklypropclient\propeller-tools\windows\proploader.exe
FirewallRules: [UDP Query User{60C1ACF6-091D-4DE4-82BD-CEB889ABA416}C:\users\kslea_000\desktop\work\2017\scribbler tree\blocklypropclient\blocklypropclient.exe] => (Allow) C:\users\kslea_000\desktop\work\2017\scribbler tree\blocklypropclient\blocklypropclient.exe
FirewallRules: [TCP Query User{ACC826D7-0F3C-4224-BF7A-2DD2D504235E}C:\users\kslea_000\desktop\work\2017\scribbler tree\blocklypropclient\blocklypropclient.exe] => (Allow) C:\users\kslea_000\desktop\work\2017\scribbler tree\blocklypropclient\blocklypropclient.exe
FirewallRules: [{A408C267-FBF6-4DA9-9634-E685C0545CEA}] => (Allow) C:\Program Files (x86)\ALFA\Common\RaMediaServer.exe
FirewallRules: [{B4CB0D59-9439-4A77-B73D-477032DA88AF}] => (Allow) C:\Program Files (x86)\ALFA\Common\RaMediaServer.exe
FirewallRules: [holoshellapp-In-TCP] => (Allow) %systemroot%\holoshell\holoshellapp.exe
FirewallRules: [holoshellapp-Out-TCP] => (Allow) %systemroot%\holoshell\holoshellapp.exe
FirewallRules: [compositor-In-TCP] => (Allow) LPort=48862
FirewallRules: [compositor-Out-TCP] => (Allow) LPort=48862
FirewallRules: [{55BB8B57-A604-4114-B82D-70367C071B9B}] => (Block) C:\program files\java\jre1.8.0_111\bin\java.exe
FirewallRules: [{EDC00C5F-4FC3-4DEC-99E0-38E072FD68C3}] => (Block) C:\program files\java\jre1.8.0_111\bin\java.exe
FirewallRules: [UDP Query User{71CED363-362B-441D-87FF-0F37D0589235}C:\program files\java\jre1.8.0_111\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_111\bin\java.exe
FirewallRules: [TCP Query User{B1F7FADC-3E2A-4F14-BF78-9CED2B476CBE}C:\program files\java\jre1.8.0_111\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_111\bin\java.exe
FirewallRules: [{4CCF26AD-F749-46CE-9251-678D12FC8342}] => (Allow) C:\program files\java\jre1.8.0_111\bin\javaw.exe
FirewallRules: [{2ADB9630-0ED8-438C-AA4E-074C102369B0}] => (Allow) C:\program files\java\jre1.8.0_111\bin\javaw.exe
FirewallRules: [UDP Query User{6E264D15-279D-4FC1-A47D-A8D120090B0E}C:\program files\java\jre1.8.0_111\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_111\bin\javaw.exe
FirewallRules: [TCP Query User{5A54C663-1EFC-4EA4-9E70-F11A9241CE6F}C:\program files\java\jre1.8.0_111\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_111\bin\javaw.exe
FirewallRules: [{A4F4B215-813F-4AC6-8211-055B2F794F4C}] => (Block) C:\users\kslea_000\eclipse\java-mars\eclipse\eclipse.exe
FirewallRules: [{F1769D7A-B6F2-4C55-97C6-FAC9C9F613D0}] => (Block) C:\users\kslea_000\eclipse\java-mars\eclipse\eclipse.exe
FirewallRules: [UDP Query User{15383DD9-F389-4E14-880B-4D60002BB9D0}C:\users\kslea_000\eclipse\java-mars\eclipse\eclipse.exe] => (Allow) C:\users\kslea_000\eclipse\java-mars\eclipse\eclipse.exe
FirewallRules: [TCP Query User{A6D79335-CCA9-4EA8-A19D-AB39652B2C3F}C:\users\kslea_000\eclipse\java-mars\eclipse\eclipse.exe] => (Allow) C:\users\kslea_000\eclipse\java-mars\eclipse\eclipse.exe
FirewallRules: [{0749164F-7095-4605-9C97-9CB9919E8324}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{A05083BE-C973-4A52-84F6-7C4C1310368F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [UDP Query User{E33C5D1D-8024-4C03-BF52-ACBF75082205}C:\program files (x86)\mblock\arduino\java\bin\javaw.exe] => (Allow) C:\program files (x86)\mblock\arduino\java\bin\javaw.exe
FirewallRules: [TCP Query User{8BE4290D-1540-4626-879B-C889CC34A785}C:\program files (x86)\mblock\arduino\java\bin\javaw.exe] => (Allow) C:\program files (x86)\mblock\arduino\java\bin\javaw.exe
FirewallRules: [UDP Query User{740A358D-8D5F-47A2-A1E3-5D3732414064}C:\program files (x86)\mblock\arduino\java\bin\javaw.exe] => (Allow) C:\program files (x86)\mblock\arduino\java\bin\javaw.exe
FirewallRules: [TCP Query User{AA749550-B373-481C-9664-E47C7B59B552}C:\program files (x86)\mblock\arduino\java\bin\javaw.exe] => (Allow) C:\program files (x86)\mblock\arduino\java\bin\javaw.exe
FirewallRules: [UDP Query User{97EC15B1-2F61-45D9-8BF0-0D54643C0CD2}C:\program files (x86)\mblock\mblock.exe] => (Allow) C:\program files (x86)\mblock\mblock.exe
FirewallRules: [TCP Query User{2F82E3FF-CABE-4DE4-B57C-4215CCA45F2F}C:\program files (x86)\mblock\mblock.exe] => (Allow) C:\program files (x86)\mblock\mblock.exe
FirewallRules: [UDP Query User{D501A778-199A-4320-BBB9-CEBA1686C0E8}C:\program files (x86)\s4a\s4a.exe] => (Block) C:\program files (x86)\s4a\s4a.exe
FirewallRules: [TCP Query User{CD7CD724-EDD1-4068-8720-480D0754B595}C:\program files (x86)\s4a\s4a.exe] => (Block) C:\program files (x86)\s4a\s4a.exe
FirewallRules: [UDP Query User{0FB5E776-7DFB-4ACC-AB00-A229A66CE06D}C:\warthunder\win64\aces.exe] => (Allow) C:\warthunder\win64\aces.exe
FirewallRules: [TCP Query User{9D82DD99-14A2-4E3B-903E-45E7A6D8DE93}C:\warthunder\win64\aces.exe] => (Allow) C:\warthunder\win64\aces.exe
FirewallRules: [{7B97FBD6-A1E7-4919-AB36-01498B0FA14E}] => (Allow) C:\WarThunder\bpreport.exe
FirewallRules: [{CCEC89D5-EA39-46CA-B8E0-070F661617D9}] => (Allow) C:\WarThunder\bpreport.exe
FirewallRules: [{BCDF77C6-0AAC-4B20-B489-FBFDF74AA5A4}] => (Allow) C:\WarThunder\launcher.exe
FirewallRules: [{585ABE5B-519E-42CD-B95D-0057411359CC}] => (Allow) C:\WarThunder\launcher.exe
FirewallRules: [UDP Query User{9743EBDA-77C2-4BB1-9609-786A46EF9F5D}C:\program files\java\jre1.8.0_66\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [TCP Query User{340C9C82-D781-4EA8-B26B-C0C5A2414F6F}C:\program files\java\jre1.8.0_66\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [UDP Query User{4E34F021-975D-4F54-B209-E502CE7B8056}C:\program files (x86)\smart view\smart view.exe] => (Allow) C:\program files (x86)\smart view\smart view.exe
FirewallRules: [TCP Query User{FB02F3B7-7D69-4114-B1B2-4C07679F9261}C:\program files (x86)\smart view\smart view.exe] => (Allow) C:\program files (x86)\smart view\smart view.exe
FirewallRules: [UDP Query User{BACC6567-4E56-4A76-86C6-FCBB14A1445A}C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\nw.exe] => (Allow) C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\nw.exe
FirewallRules: [TCP Query User{4BE2144F-C15D-4379-A9E0-91BD01BD32C0}C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\nw.exe] => (Allow) C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\nw.exe
FirewallRules: [UDP Query User{2B2A4475-B767-4FBF-9959-AE29211F3AE1}C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\node.exe] => (Allow) C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\node.exe
FirewallRules: [TCP Query User{4436E561-1239-4731-974D-0D2E407112B4}C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\node.exe] => (Allow) C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\node.exe
FirewallRules: [UDP Query User{60BBC4B4-9AAB-4D29-8085-B15FE4C6ADE3}C:\program files\java\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_51\bin\javaw.exe
FirewallRules: [TCP Query User{381ACE18-ED71-4CF5-81E4-6C6A010D46EF}C:\program files\java\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_51\bin\javaw.exe
FirewallRules: [UDP Query User{9F63A21D-AC72-4743-8BCF-BCA381EA03DE}C:\program files\java\jdk1.8.0_11\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_11\bin\java.exe
FirewallRules: [TCP Query User{7BB729BD-5FC0-42D0-ABE5-1FB772CE2B34}C:\program files\java\jdk1.8.0_11\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_11\bin\java.exe
FirewallRules: [{09A656DE-D767-4A5A-BEF6-0C5AFDE1A90B}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{4A67A0DD-7136-498C-80E7-45EDA3DC25FA}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{8B1DB30D-D2D4-4BDD-94F3-350E803E7F47}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{D0D10595-A316-41D1-88EF-65FAA9AB2B9E}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{4BB6794C-B1D3-47FB-A507-972C272931F8}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{3F884598-D501-4CE0-AFCB-CC2D5E7FDD84}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{452BFE62-325D-4723-83C1-24798B74356E}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{8CEB1D13-0E5C-46AE-A9B3-7CB6CEA3AD59}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{D3FBD710-DFC7-45A2-BE93-BEC909CD4EBD}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{00CD5B4B-6882-479D-AE10-F9117FD462E6}] => (Allow) C:\Users\kslea_000\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{67E20F0E-4FDD-4AD9-BE6C-EB934F0494E5}] => (Allow) C:\Users\kslea_000\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{DD40EF3E-F309-4686-A6AD-D61D8B9F1B8D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{2B2E3B62-6296-49B2-A041-4F432280276A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{38AE4C48-B262-4002-86F5-357CC85D1759}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{D13EA913-EA8B-4B07-AC74-8E3588BADD93}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{7CDEC14E-8A13-44D6-8358-EE2DFBD448BC}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{1505FC31-5F6B-41EF-934C-18F063A9C16E}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [TCP Query User{6F97FEC8-60F7-4522-9C94-2A1BD50283B5}C:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe
FirewallRules: [UDP Query User{C9192559-A2C2-412F-8F79-C7A06637E3C0}C:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe
FirewallRules: [TCP Query User{75417E24-EFA7-449F-A250-2B814E9A1540}C:\users\kslea_000\downloads\utorrent.exe] => (Allow) C:\users\kslea_000\downloads\utorrent.exe
FirewallRules: [UDP Query User{75E57F00-BC7D-44AB-AF5B-243C2E6406C8}C:\users\kslea_000\downloads\utorrent.exe] => (Allow) C:\users\kslea_000\downloads\utorrent.exe
FirewallRules: [TCP Query User{8549E9CA-154A-44FF-9E19-B48BA08154B7}C:\program files (x86)\divx\divx media server\divxmediaserver.exe] => (Allow) C:\program files (x86)\divx\divx media server\divxmediaserver.exe
FirewallRules: [UDP Query User{F09BBDD9-A3EE-43C3-9212-2AF7533FF620}C:\program files (x86)\divx\divx media server\divxmediaserver.exe] => (Allow) C:\program files (x86)\divx\divx media server\divxmediaserver.exe
FirewallRules: [TCP Query User{5F476EB3-D614-423B-9249-624F18FCE60F}C:\users\kslea_000\appdata\local\android\android-studio\bin\studio64.exe] => (Allow) C:\users\kslea_000\appdata\local\android\android-studio\bin\studio64.exe
FirewallRules: [UDP Query User{887FB442-A3D2-47E2-846E-364EF61DC7A9}C:\users\kslea_000\appdata\local\android\android-studio\bin\studio64.exe] => (Allow) C:\users\kslea_000\appdata\local\android\android-studio\bin\studio64.exe
FirewallRules: [TCP Query User{9CC1B4BA-B4D2-43FB-8F17-B1311B935D31}C:\program files\java\jdk1.8.0_11\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_11\bin\java.exe
FirewallRules: [UDP Query User{B405422C-80EC-4D72-9410-528CA6795DCC}C:\program files\java\jdk1.8.0_11\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_11\bin\java.exe
FirewallRules: [TCP Query User{200F830F-43AA-4A53-B91C-DD71502ACABC}C:\users\kslea_000\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\kslea_000\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{EE926AF4-1863-4CB0-BFF7-E745429C3D6C}C:\users\kslea_000\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\kslea_000\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{95DC8700-1677-4FF6-B56E-6E38E2970BD7}C:\games\world_of_tanks\wotlauncher.exe] => (Allow) C:\games\world_of_tanks\wotlauncher.exe
FirewallRules: [UDP Query User{417FBDCE-85AF-4506-BE9D-35957A1D58BA}C:\games\world_of_tanks\wotlauncher.exe] => (Allow) C:\games\world_of_tanks\wotlauncher.exe
FirewallRules: [TCP Query User{673C9453-EAA9-485C-9F64-9BC5A0A2DE06}C:\games\world_of_tanks\worldoftanks.exe] => (Allow) C:\games\world_of_tanks\worldoftanks.exe
FirewallRules: [UDP Query User{B3EAFDF8-EAA9-401C-909F-21D5659A8F6D}C:\games\world_of_tanks\worldoftanks.exe] => (Allow) C:\games\world_of_tanks\worldoftanks.exe
FirewallRules: [TCP Query User{65B303CF-518E-4091-B20C-25005B28F3A8}C:\users\kslea_000\appdata\local\android\android-studio\bin\studio64.exe] => (Allow) C:\users\kslea_000\appdata\local\android\android-studio\bin\studio64.exe
FirewallRules: [UDP Query User{51E31424-CDBA-4AEF-8E37-C2D85BBA759D}C:\users\kslea_000\appdata\local\android\android-studio\bin\studio64.exe] => (Allow) C:\users\kslea_000\appdata\local\android\android-studio\bin\studio64.exe
FirewallRules: [TCP Query User{77DCB2B3-BF63-48C1-8630-AF07E847E22B}G:\games\world_of_tanks\wotlauncher.exe] => (Allow) G:\games\world_of_tanks\wotlauncher.exe
FirewallRules: [UDP Query User{AF984DF3-AB50-4F30-8B82-5B3D79B0075E}G:\games\world_of_tanks\wotlauncher.exe] => (Allow) G:\games\world_of_tanks\wotlauncher.exe
FirewallRules: [TCP Query User{A88E2A39-4513-4A0A-928F-965FD2959C7F}C:\program files\maple 18\jre\bin\maple.exe] => (Allow) C:\program files\maple 18\jre\bin\maple.exe
FirewallRules: [UDP Query User{0D20C2BB-7A22-40DF-ACA1-C9F4129856F7}C:\program files\maple 18\jre\bin\maple.exe] => (Allow) C:\program files\maple 18\jre\bin\maple.exe
FirewallRules: [TCP Query User{F5F05C63-FBFD-4830-899E-EC36F19C905F}C:\users\kslea_000\appdata\local\temp\rarsfx0\hl.exe] => (Allow) C:\users\kslea_000\appdata\local\temp\rarsfx0\hl.exe
FirewallRules: [UDP Query User{4C606E2C-8BC0-4D33-95B5-4E246C1FCFD3}C:\users\kslea_000\appdata\local\temp\rarsfx0\hl.exe] => (Allow) C:\users\kslea_000\appdata\local\temp\rarsfx0\hl.exe
FirewallRules: [TCP Query User{6A322CE6-1021-47F4-91D3-64F88B620FB4}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{98F3BD6D-BA48-46B8-A844-C915DC0BBD94}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{EA48CA74-CBAF-413E-BB37-2D2E3C2CED8D}C:\program files\maple 18\jre\bin\maple.exe] => (Allow) C:\program files\maple 18\jre\bin\maple.exe
FirewallRules: [UDP Query User{737461A0-2296-4F74-A9B8-81A20C001867}C:\program files\maple 18\jre\bin\maple.exe] => (Allow) C:\program files\maple 18\jre\bin\maple.exe
FirewallRules: [TCP Query User{FEE7F974-AB8B-4F1D-AFCF-D4E8F62825F7}C:\users\kslea_000\desktop\the typing of the dead\tod_e.exe] => (Allow) C:\users\kslea_000\desktop\the typing of the dead\tod_e.exe
FirewallRules: [UDP Query User{9D612F84-9653-4238-8552-271C6E862E0E}C:\users\kslea_000\desktop\the typing of the dead\tod_e.exe] => (Allow) C:\users\kslea_000\desktop\the typing of the dead\tod_e.exe
FirewallRules: [TCP Query User{C7BA858E-365A-4D8D-952C-9DBCC7DC6730}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe
FirewallRules: [UDP Query User{8FAE05E4-0EB2-4253-9089-767814B6A91F}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe
FirewallRules: [TCP Query User{70B5F261-7522-44A0-B341-3AEF620CE301}C:\users\kslea_000\appdata\local\temp\rarsfx0\hl.exe] => (Allow) C:\users\kslea_000\appdata\local\temp\rarsfx0\hl.exe
FirewallRules: [UDP Query User{2D1F8AC7-A5AC-4337-8CFB-116541BC9142}C:\users\kslea_000\appdata\local\temp\rarsfx0\hl.exe] => (Allow) C:\users\kslea_000\appdata\local\temp\rarsfx0\hl.exe
FirewallRules: [TCP Query User{9AF00357-A91A-41B2-9F99-4B46922DF59F}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Allow) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [UDP Query User{7FC93E13-DD97-4130-B868-0D4E48345B38}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Allow) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [TCP Query User{8D59D3AB-EFA6-4BFA-B92D-19BAAEFDDABC}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Allow) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [UDP Query User{8D5B7287-C7A3-4FF6-9E5F-8320AACDD616}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Allow) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [TCP Query User{CC3E00CC-5114-4EC7-A181-7B84EA0BBF04}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Allow) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [UDP Query User{D6C9F823-67E5-464F-8AE3-7A38D6A87F6F}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Allow) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [TCP Query User{A3439941-4DEA-4067-8765-7D41E45069EE}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Allow) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [UDP Query User{163D187C-9F7F-4240-AF4B-357D5D5DC21A}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Allow) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [{8495957F-45CD-4E25-9B83-DE525920B969}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{EF8726B8-A086-4A18-B98E-139911DCF818}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A0AD699F-D4C0-4024-AFC2-739742DF2C0E}] => (Allow) C:\Program Files (x86)\Disconnect\Disconnect Desktop\\openvpn\bin\openvpn.exe
FirewallRules: [{FEFC3CB3-FD58-46F2-8545-7F9C62BC0129}] => (Allow) C:\Program Files (x86)\Disconnect\Disconnect Desktop\\openvpn\bin\openvpnserv.exe
FirewallRules: [TCP Query User{04E32C7A-CF2B-466B-B4FF-5F7D29665960}C:\program files\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{BC6A664A-D7AF-47C9-B71D-52BCA9689209}C:\program files\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{FFC7A103-29BA-4990-8D3C-5F2B42A77979}C:\program files (x86)\jetbrains\pycharm community edition 4.0.4\bin\pycharm.exe] => (Allow) C:\program files (x86)\jetbrains\pycharm community edition 4.0.4\bin\pycharm.exe
FirewallRules: [UDP Query User{10F83FBA-2CE1-43C4-AFD3-99B61A1CE2B2}C:\program files (x86)\jetbrains\pycharm community edition 4.0.4\bin\pycharm.exe] => (Allow) C:\program files (x86)\jetbrains\pycharm community edition 4.0.4\bin\pycharm.exe
FirewallRules: [{80CFAAE1-5E70-4935-AADA-B4A397DFA65D}] => (Allow) C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe
FirewallRules: [{044E39A5-B423-455E-A6B4-8530418F31D6}] => (Allow) C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe
FirewallRules: [{815853BD-B941-4C16-A331-E686CED927E9}] => (Allow) C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe
FirewallRules: [{057E0B49-617A-4B94-A872-B3E24ED71721}] => (Allow) C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe
FirewallRules: [TCP Query User{52667544-7A6A-476E-95D5-16A42AA10F9E}C:\program files (x86)\arduino\java\bin\javaw.exe] => (Allow) C:\program files (x86)\arduino\java\bin\javaw.exe
FirewallRules: [UDP Query User{00C8C921-F403-4047-8833-30904E4DD2FB}C:\program files (x86)\arduino\java\bin\javaw.exe] => (Allow) C:\program files (x86)\arduino\java\bin\javaw.exe
FirewallRules: [TCP Query User{428559AE-0617-44CD-9EAE-173A0D1947C0}C:\program files (x86)\arduino\java\bin\javaw.exe] => (Allow) C:\program files (x86)\arduino\java\bin\javaw.exe
FirewallRules: [UDP Query User{8ECC06D1-F34D-4D84-9A62-B3051982100E}C:\program files (x86)\arduino\java\bin\javaw.exe] => (Allow) C:\program files (x86)\arduino\java\bin\javaw.exe
FirewallRules: [TCP Query User{B05735E6-AA5F-4531-91E9-D38ADCB42A80}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{1045D3CB-A098-4313-A9B2-E742CA705F7D}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{7ACB65E4-40BC-4BF1-BF96-FA80FC45517E}C:\program files (x86)\arduino\java\bin\java.exe] => (Allow) C:\program files (x86)\arduino\java\bin\java.exe
FirewallRules: [UDP Query User{D6AE626E-4DF1-4645-86E7-914E54ED3F36}C:\program files (x86)\arduino\java\bin\java.exe] => (Allow) C:\program files (x86)\arduino\java\bin\java.exe
FirewallRules: [TCP Query User{21F73A69-DACF-4943-A196-60AED26EC06A}C:\eclipse\eclipse\eclipse.exe] => (Allow) C:\eclipse\eclipse\eclipse.exe
FirewallRules: [UDP Query User{6A17B026-3682-4794-9138-DAA52031ABFA}C:\eclipse\eclipse\eclipse.exe] => (Allow) C:\eclipse\eclipse\eclipse.exe
FirewallRules: [{959F3FE8-EA1D-4594-904C-C8F3402DCD19}] => (Allow) C:\Nexon\Library\combatarms\appdata\NMService.exe
FirewallRules: [{172C1746-F79C-4DDE-882B-82F4AA7B3BED}] => (Allow) C:\Nexon\Library\combatarms\appdata\NMService.exe
FirewallRules: [TCP Query User{5A8D8376-C069-4A95-9C07-1F3DF6C66EC4}C:\nexon\library\combatarms\appdata\engine.exe] => (Allow) C:\nexon\library\combatarms\appdata\engine.exe
FirewallRules: [UDP Query User{FB6329CF-4E90-4B80-A89A-7E6C01640FD2}C:\nexon\library\combatarms\appdata\engine.exe] => (Allow) C:\nexon\library\combatarms\appdata\engine.exe
FirewallRules: [TCP Query User{F9E949DF-C463-4343-879E-E24CD7C36AD7}C:\program files\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [UDP Query User{7D19FE5C-EF46-44AF-A4A2-5274676820B7}C:\program files\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [{ACD5F2F5-72EE-4E31-B900-991D0FE79E10}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{DEA0D49B-34D6-448A-8DB3-C4351E2D6A92}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{F6E05C6E-8698-447F-9FD3-5C7E0C9EAE15}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{AE8EDAD5-7CCE-4973-9F59-C3E108B2F443}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [TCP Query User{5C8EE4F3-A648-4DBD-A7D8-F4A8C09B64FC}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{B4AD7E0F-5517-4245-98E7-29EAD3463FDB}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [TCP Query User{80A1B8DC-C7D9-4C49-AAC7-C24DEAC47C29}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{BE702806-DB53-463F-BCC4-EDF8F0245442}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{CD177881-A79C-4EE6-9F5F-04CDEAFCD776}C:\program files (x86)\mattercontrol\mattercontrol.exe] => (Allow) C:\program files (x86)\mattercontrol\mattercontrol.exe
FirewallRules: [UDP Query User{F48628BB-66C3-4C14-BCF1-5BF8D70C55AC}C:\program files (x86)\mattercontrol\mattercontrol.exe] => (Allow) C:\program files (x86)\mattercontrol\mattercontrol.exe
FirewallRules: [TCP Query User{CC8B5302-0E26-4C78-BA9E-767259AE622E}C:\program files (x86)\mattercontrol\mattercontrol.exe] => (Allow) C:\program files (x86)\mattercontrol\mattercontrol.exe
FirewallRules: [UDP Query User{AD20B48C-3ECF-4DCB-A82E-E66259ABCCEC}C:\program files (x86)\mattercontrol\mattercontrol.exe] => (Allow) C:\program files (x86)\mattercontrol\mattercontrol.exe
FirewallRules: [TCP Query User{A600A3AD-99F3-4A7E-820A-D76802631609}C:\eclipse\eclipse\eclipse.exe] => (Allow) C:\eclipse\eclipse\eclipse.exe
FirewallRules: [UDP Query User{ED03617E-AD34-470E-8850-5B91BE723BAF}C:\eclipse\eclipse\eclipse.exe] => (Allow) C:\eclipse\eclipse\eclipse.exe
FirewallRules: [TCP Query User{AF9ABC42-DA99-4E7E-AAFB-ABE5F9396444}C:\program files\java\jdk1.8.0_11\bin\jmc.exe] => (Allow) C:\program files\java\jdk1.8.0_11\bin\jmc.exe
FirewallRules: [UDP Query User{9089CE29-32AE-4C6B-BB23-8D3CAB46CB74}C:\program files\java\jdk1.8.0_11\bin\jmc.exe] => (Allow) C:\program files\java\jdk1.8.0_11\bin\jmc.exe
FirewallRules: [TCP Query User{97F1A9A8-EBA8-4AD5-BDEE-A228B24ED6F2}C:\intel\arduino-1.6.4\java\bin\java.exe] => (Allow) C:\intel\arduino-1.6.4\java\bin\java.exe
FirewallRules: [UDP Query User{BCEA2B63-1402-49B0-96EF-F5F25B6CCF9F}C:\intel\arduino-1.6.4\java\bin\java.exe] => (Allow) C:\intel\arduino-1.6.4\java\bin\java.exe
FirewallRules: [TCP Query User{BAE5023E-3433-4017-B40D-055C9E36C7F6}C:\intel\arduino-1.6.4\java\bin\javaw.exe] => (Allow) C:\intel\arduino-1.6.4\java\bin\javaw.exe
FirewallRules: [UDP Query User{F2B779EE-82DD-4015-ACF0-3528DE77395D}C:\intel\arduino-1.6.4\java\bin\javaw.exe] => (Allow) C:\intel\arduino-1.6.4\java\bin\javaw.exe
FirewallRules: [{E8457264-A925-4E2B-858E-AAD2714A73FC}] => (Block) C:\intel\arduino-1.6.4\java\bin\javaw.exe
FirewallRules: [{057FC270-5514-4D50-A337-CEE3DDC17B8B}] => (Block) C:\intel\arduino-1.6.4\java\bin\javaw.exe
FirewallRules: [TCP Query User{B6842E9A-8864-470F-B0EE-B78C67F07B27}C:\intel\xdk\bin\node.exe] => (Allow) C:\intel\xdk\bin\node.exe
FirewallRules: [UDP Query User{A2A4BEEC-F14E-4DC6-8DF5-958C4E59C4CE}C:\intel\xdk\bin\node.exe] => (Allow) C:\intel\xdk\bin\node.exe
FirewallRules: [TCP Query User{87EFC253-CAC1-45D9-B7FA-1A15E28E524A}C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\node.exe] => (Allow) C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\node.exe
FirewallRules: [UDP Query User{D2269CE4-2AC7-4FA3-88C5-781F162B1CA0}C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\node.exe] => (Allow) C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\node.exe
FirewallRules: [TCP Query User{7A918EEC-950B-496A-836F-FFD89CD98444}C:\program files\java\jre1.8.0_45\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_45\bin\javaw.exe
FirewallRules: [UDP Query User{312FAAB0-B85F-43CC-8B93-FC1252E647A9}C:\program files\java\jre1.8.0_45\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_45\bin\javaw.exe
FirewallRules: [{A4B3FD67-B1BA-48B4-9FCA-6C0D1F30CE9F}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [TCP Query User{6D3487FB-8CF4-463B-B736-0CD35CD5CB11}C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\nw.exe] => (Allow) C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\nw.exe
FirewallRules: [UDP Query User{4C0618EC-8E78-4529-815B-019EA7BD8805}C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\nw.exe] => (Allow) C:\users\kslea_000\appdata\local\intel\xdk iot edition\bin\nw.exe
FirewallRules: [{A5A3C8FB-20AC-4548-99BD-ADE37143C2EE}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [TCP Query User{20B7843A-E5C5-4D91-9F6B-77EBD3BCEE9B}C:\program files (x86)\atmel\atmel studio 6.2\atmelstudio.exe] => (Allow) C:\program files (x86)\atmel\atmel studio 6.2\atmelstudio.exe
FirewallRules: [UDP Query User{C2897BF0-87DD-4C81-AF1C-B436CCEB942E}C:\program files (x86)\atmel\atmel studio 6.2\atmelstudio.exe] => (Allow) C:\program files (x86)\atmel\atmel studio 6.2\atmelstudio.exe
FirewallRules: [{E7DF9DB9-CF86-4410-A588-F95CEE948B18}] => (Block) C:\program files (x86)\atmel\atmel studio 6.2\atmelstudio.exe
FirewallRules: [{1F6EDEFF-4F9C-4FD6-8EB6-4D8B248FF53E}] => (Block) C:\program files (x86)\atmel\atmel studio 6.2\atmelstudio.exe
FirewallRules: [TCP Query User{68732BA7-D59E-4298-ACD9-EA952051AC13}C:\users\kslea_000\documents\processing-2.2.1\java\bin\java.exe] => (Allow) C:\users\kslea_000\documents\processing-2.2.1\java\bin\java.exe
FirewallRules: [UDP Query User{2CCD3095-8F5E-41B8-B26E-62C5775BA6E2}C:\users\kslea_000\documents\processing-2.2.1\java\bin\java.exe] => (Allow) C:\users\kslea_000\documents\processing-2.2.1\java\bin\java.exe
FirewallRules: [{FB21BD01-957F-486C-B5DE-4F6BC992295D}] => (Block) C:\users\kslea_000\documents\processing-2.2.1\java\bin\java.exe
FirewallRules: [{2A34E79A-DE93-4453-BEF7-9F93DE983353}] => (Block) C:\users\kslea_000\documents\processing-2.2.1\java\bin\java.exe
FirewallRules: [TCP Query User{531F5F8D-A905-4245-B024-C18D1B8EA68F}C:\program files\maple 2015\jre\bin\javaw.exe] => (Allow) C:\program files\maple 2015\jre\bin\javaw.exe
FirewallRules: [UDP Query User{9F6E583B-AD0B-462A-AF12-E8E566981994}C:\program files\maple 2015\jre\bin\javaw.exe] => (Allow) C:\program files\maple 2015\jre\bin\javaw.exe
FirewallRules: [{8EDC7EFA-277D-41FA-A8B2-4FCAAB35A8F7}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{090F0279-F2E7-41DB-A18A-CDB175A792C3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7FBB8581-5626-4A5C-ACA5-7D6A4462D776}] => (Allow) C:\Users\kslea_000\AppData\Roaming\Riot Games\League of Legends\prerequisites\null\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{5F3C6DEA-8821-4E66-AD15-65F666D7CBA1}] => (Allow) C:\Users\kslea_000\AppData\Roaming\Riot Games\League of Legends\prerequisites\null\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{D2CFD589-DF9C-45F4-8643-00D6FF36BEAD}] => (Allow) null\Pando Networks\Media Booster\PMB.exe
FirewallRules: [TCP Query User{A62E1D3F-E17A-46D6-93EC-28657AD50179}C:\users\kslea_000\appdata\roaming\riot games\league of legends\prerequisites\null\pando networks\media booster\pmb.exe] => (Allow) C:\users\kslea_000\appdata\roaming\riot games\league of legends\prerequisites\null\pando networks\media booster\pmb.exe
FirewallRules: [UDP Query User{3EA156DC-82CE-499B-8B45-8E821C7BE23E}C:\users\kslea_000\appdata\roaming\riot games\league of legends\prerequisites\null\pando networks\media booster\pmb.exe] => (Allow) C:\users\kslea_000\appdata\roaming\riot games\league of legends\prerequisites\null\pando networks\media booster\pmb.exe
FirewallRules: [TCP Query User{6BF65F2B-9EB8-46B5-8E50-91BA44D10EFF}C:\program files (x86)\android\android-studio\bin\studio64.exe] => (Allow) C:\program files (x86)\android\android-studio\bin\studio64.exe
FirewallRules: [UDP Query User{5EBBAA38-4773-42A6-B5ED-A3D5957F05A3}C:\program files (x86)\android\android-studio\bin\studio64.exe] => (Allow) C:\program files (x86)\android\android-studio\bin\studio64.exe
FirewallRules: [{1F8CAED0-1F8A-4C11-B06A-F150448DA99C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Overcooked\Overcooked.exe
FirewallRules: [{4E83A346-7DE8-4D9F-B4CC-5D23B94FF09D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Overcooked\Overcooked.exe
FirewallRules: [{1EDD6E44-4C5F-49B0-B1A4-0F9223D84133}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\This War of Mine\This War of Mine.exe
FirewallRules: [{35F162DF-2C20-4384-94C5-4BA873D7AEB5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\This War of Mine\This War of Mine.exe
FirewallRules: [{C994271C-A748-45E0-A7EB-FC7B6B9C33F5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\This War of Mine\Storyteller.exe
FirewallRules: [{3BF809EA-A98B-466B-8B16-0816D40FD8E1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\This War of Mine\Storyteller.exe
FirewallRules: [TCP Query User{55319006-B1A6-4ECC-BFB2-02221ACCE527}C:\program files (x86)\jetbrains\pycharm community edition 4.0.4\bin\pycharm.exe] => (Allow) C:\program files (x86)\jetbrains\pycharm community edition 4.0.4\bin\pycharm.exe
FirewallRules: [UDP Query User{2E0FA69E-CC24-4634-BBB6-918A26BFBC8B}C:\program files (x86)\jetbrains\pycharm community edition 4.0.4\bin\pycharm.exe] => (Allow) C:\program files (x86)\jetbrains\pycharm community edition 4.0.4\bin\pycharm.exe
FirewallRules: [TCP Query User{6D2CA772-7A24-4015-9B1A-BCD8BB52FA77}C:\users\kslea_000\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\kslea_000\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{6F30BE30-67BF-45CB-8F52-599491B8569B}C:\users\kslea_000\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\kslea_000\appdata\local\akamai\netsession_win.exe
FirewallRules: [{2ABAB82A-593F-4F8C-927F-89942F23BB59}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{1E8D2129-D36D-489F-BB1E-2B2F3619BECF}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{64BE515C-1425-439D-B720-0D1886E9B4E3}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{A167A7D0-09A8-4BE2-9E6D-9F5EC14A7753}] => (Allow) null\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{D5D6F1DF-226B-4633-B2F4-6604165117F8}] => (Allow) LPort=54925
FirewallRules: [{82A7C4CE-B0DE-4324-87E2-B3A5D6CB2B5C}] => (Allow) LPort=54925
FirewallRules: [TCP Query User{6CF835D7-B6BF-4339-BA8C-4D05BF9C02B7}C:\users\kslea_000\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\kslea_000\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{0542A0C2-C78B-4B1B-AA40-FF12380A042B}C:\users\kslea_000\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\kslea_000\appdata\local\akamai\netsession_win.exe
FirewallRules: [{8085C05C-1C35-481B-86D8-4F46A280192F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\wallpaper_engine\launcher.exe
FirewallRules: [{0602FCDA-5983-41DD-90DB-36A43AF3BA58}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\wallpaper_engine\launcher.exe
FirewallRules: [{29A65B8C-E1A3-4B6A-ACE4-48B36CF6D4EE}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{4D4C7E6F-BE73-4990-A36D-EC8884A4507C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{E135B842-C59E-4495-AF12-A0AB4EDB965B}C:\program files\nodejs\node.exe] => (Allow) C:\program files\nodejs\node.exe
FirewallRules: [UDP Query User{35467442-2D99-47DD-A6C9-FCFE234EDC96}C:\program files\nodejs\node.exe] => (Allow) C:\program files\nodejs\node.exe
FirewallRules: [TCP Query User{9302D50B-AD42-4364-885A-F9AE0C115706}C:\program files\netbeans 8.0.2\bin\netbeans64.exe] => (Allow) C:\program files\netbeans 8.0.2\bin\netbeans64.exe
FirewallRules: [UDP Query User{7D366D7C-F379-4C12-AC74-E725CB4AAFE5}C:\program files\netbeans 8.0.2\bin\netbeans64.exe] => (Allow) C:\program files\netbeans 8.0.2\bin\netbeans64.exe
FirewallRules: [TCP Query User{358DA671-EE70-416B-8904-40862113563E}C:\program files (x86)\battle for wesnoth 1.12.4\wesnothd.exe] => (Block) C:\program files (x86)\battle for wesnoth 1.12.4\wesnothd.exe
FirewallRules: [UDP Query User{95DCCA82-6BD8-4827-B429-3FA076BD01F0}C:\program files (x86)\battle for wesnoth 1.12.4\wesnothd.exe] => (Block) C:\program files (x86)\battle for wesnoth 1.12.4\wesnothd.exe
FirewallRules: [TCP Query User{3A0D1951-C8B6-419B-BC1D-2DE539B95862}C:\program files\java\jre1.8.0_121\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_121\bin\javaw.exe
FirewallRules: [UDP Query User{70DB8CE8-9EFC-4110-A9B9-90F1434FEC0F}C:\program files\java\jre1.8.0_121\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_121\bin\javaw.exe
FirewallRules: [TCP Query User{D99A4BF7-AE1F-495D-B20C-1A77DB6D983B}C:\program files\nodejs\node.exe] => (Allow) C:\program files\nodejs\node.exe
FirewallRules: [UDP Query User{CA8F08B6-952D-4B84-948C-67924448F557}C:\program files\nodejs\node.exe] => (Allow) C:\program files\nodejs\node.exe
FirewallRules: [TCP Query User{28E171FA-7378-4EC3-B62C-418EE17C86F5}C:\program files (x86)\microsoft vs code\code.exe] => (Allow) C:\program files (x86)\microsoft vs code\code.exe
FirewallRules: [UDP Query User{58175B2B-5746-4CC7-9A8B-E0EC4583342D}C:\program files (x86)\microsoft vs code\code.exe] => (Allow) C:\program files (x86)\microsoft vs code\code.exe
FirewallRules: [TCP Query User{D3ABB8EA-E055-4664-B8FA-0CBC867691F9}C:\program files\java\jre1.8.0_144\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_144\bin\javaw.exe
FirewallRules: [UDP Query User{1FAB7189-F65E-4347-955C-C50CCFB89F6A}C:\program files\java\jre1.8.0_144\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_144\bin\javaw.exe
FirewallRules: [{F76B9461-4D7E-4B73-8AF4-C0A689C3049B}] => (Block) C:\program files\java\jre1.8.0_144\bin\javaw.exe
FirewallRules: [{188B3F8F-2231-463B-8D9E-6D98AA6A292A}] => (Block) C:\program files\java\jre1.8.0_144\bin\javaw.exe
FirewallRules: [TCP Query User{5DFE4058-82FD-4FDB-83B8-A81E1831AE41}C:\program files (x86)\microsoft vs code\code.exe] => (Allow) C:\program files (x86)\microsoft vs code\code.exe
FirewallRules: [UDP Query User{DC3B88BD-B337-4CB9-9D94-DB101E535228}C:\program files (x86)\microsoft vs code\code.exe] => (Allow) C:\program files (x86)\microsoft vs code\code.exe
FirewallRules: [TCP Query User{122922FA-8036-4AFE-B7DC-B15C1299C8E1}C:\program files\java\jre1.8.0_151\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_151\bin\javaw.exe
FirewallRules: [UDP Query User{09C2C921-C84D-45E5-9956-82E77534AAF4}C:\program files\java\jre1.8.0_151\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_151\bin\javaw.exe
FirewallRules: [TCP Query User{16B932BB-DB41-416A-82AA-98F597DCAB9E}C:\program files\java\jre1.8.0_151\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_151\bin\javaw.exe
FirewallRules: [UDP Query User{6B630146-B61D-4A2E-B870-6C3C4F9C3506}C:\program files\java\jre1.8.0_151\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_151\bin\javaw.exe
FirewallRules: [{66AEADE2-4618-4BA0-8B76-A29D5D7D2304}] => (Allow) LPort=3306
FirewallRules: [{C8AC782A-994E-4375-B17E-5D2DEDEDD37C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================


==================== Faulty Device Manager Devices =============
 
==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/09/2017 07:43:36 PM) (Source: DbxSvc) (EventID: 320) (User: )
Description: Failed to connect to the driver: (-2147024894) The system cannot find the file specified.

Error: (11/09/2017 07:18:19 PM) (Source: DbxSvc) (EventID: 320) (User: )
Description: Failed to connect to the driver: (-2147024894) The system cannot find the file specified.

Error: (11/09/2017 05:42:40 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15641

Error: (11/09/2017 05:42:40 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15641

Error: (11/09/2017 05:42:40 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (11/09/2017 05:41:32 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Local Hostname tubulerrr.local already in use; will try tubulerrr-2.local instead

Error: (11/09/2017 05:41:32 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: ProbeCount 2; will rename 4 tubulerrr.local. Addr 192.168.0.15

Error: (11/09/2017 05:41:32 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.0.15:5353 16 tubulerrr.local. AAAA 2605:E000:3F48:4F00:0000:0000:0000:0003

Error: (11/09/2017 05:40:23 PM) (Source: DbxSvc) (EventID: 320) (User: )
Description: Failed to connect to the driver: (-2147024894) The system cannot find the file specified.

Error: (11/09/2017 05:33:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 296891


System errors:
=============
Error: (11/09/2017 08:05:41 PM) (Source: DCOM) (EventID: 10016) (User: TUBULERRR)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user TUBULERRR\kslea_000 SID (S-1-5-21-3820140182-2222416168-2024790571-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (11/09/2017 08:00:45 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (11/09/2017 07:59:33 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (11/09/2017 07:52:43 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x0000000000000000, 0x0000000000000002, 0x0000000000000001, 0xfffff8025c2d9a0f). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: e92ae4ad-7c7e-46d9-899f-4991c641ab49.

Error: (11/09/2017 07:48:18 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Delivery Optimization service hung on starting.

Error: (11/09/2017 07:45:46 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (11/09/2017 07:45:46 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (11/09/2017 07:44:08 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The RasMan service depends on the SstpSvc service which failed to start because of the following error:
The operation completed successfully.

Error: (11/09/2017 07:44:06 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The SystemUsageReportSvc_QUEENCREEK service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

Error: (11/09/2017 07:44:06 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the SystemUsageReportSvc_QUEENCREEK service to connect.


CodeIntegrity:
===================================
Date: 2017-09-28 11:11:11.876
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\drivers\SET80B4.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-4200M CPU @ 2.50GHz
Percentage of memory in use: 63%
Total physical RAM: 6056.27 MB
Available physical RAM: 2207.46 MB
Total Virtual: 7016.27 MB
Available Virtual: 2590.09 MB

==================== Drives ================================

Drive c: (Windows8_OS) (Fixed) (Total:892.83 GB) (Free:383.98 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:21.82 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 488F8D18)

Partition: GPT.

==================== End of Addition.txt ============================
 
21:32:05.0654 7388 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
21:32:05.0654 7388 UEFI system
21:32:07.0424 7388 ============================================================
21:32:07.0424 7388 Current date / time: 2017/11/09 21:32:07.0423
21:32:07.0424 7388 SystemInfo:
21:32:07.0425 7388
21:32:07.0425 7388 OS Version: 6.2.9200 ServicePack: 0.0
21:32:07.0425 7388 Product type: Workstation
21:32:07.0425 7388 ComputerName: TUBULERRR
21:32:07.0426 7388 UserName: kslea_000
21:32:07.0426 7388 Windows directory: C:\WINDOWS
21:32:07.0426 7388 System windows directory: C:\WINDOWS
21:32:07.0426 7388 Running under WOW64
21:32:07.0426 7388 Processor architecture: Intel x64
21:32:07.0426 7388 Number of processors: 4
21:32:07.0426 7388 Page size: 0x1000
21:32:07.0426 7388 Boot type: Normal boot
21:32:07.0426 7388 ============================================================
21:32:08.0076 7388 !crdlk
21:32:08.0105 7388 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'A'
21:32:08.0117 7388 ============================================================
21:32:08.0117 7388 \Device\Harddisk0\DR0:
21:32:08.0118 7388 GPT partitions:
21:32:08.0118 7388 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {CB174F5A-F865-414C-8159-24ED70FB69A1}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x1F4000
21:32:08.0118 7388 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {AB61BEC7-4502-4E34-8532-4CD625446839}, Name: EFI system partition, StartLBA 0x1F4800, BlocksNum 0x82000
21:32:08.0118 7388 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {BFBFAFE7-A34F-448A-9A5B-6213EB736C22}, UniqueGUID: {108BA43A-744D-4BE9-9E29-C289109DD547}, Name: Basic data partition, StartLBA 0x276800, BlocksNum 0x1F4000
21:32:08.0118 7388 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {B62E6018-9C4E-4848-BBA4-03CA653FEF94}, Name: Microsoft reserved partition, StartLBA 0x46A800, BlocksNum 0x40000
21:32:08.0118 7388 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {EB13750C-6B9E-4D5F-BFD2-288002268E64}, Name: Basic data partition, StartLBA 0x4AA800, BlocksNum 0x6F9A7800
21:32:08.0118 7388 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {5F955333-805B-46C0-B5BE-2EF3E5BF0DF5}, Name: Basic data partition, StartLBA 0x6FE52000, BlocksNum 0x3200000
21:32:08.0118 7388 \Device\Harddisk0\DR0\Partition7: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {264A8DA3-4EC6-4F14-9B64-760D6562E143}, Name: Basic data partition, StartLBA 0x73052000, BlocksNum 0x16B4800
21:32:08.0118 7388 MBR partitions:
21:32:08.0118 7388 ============================================================
21:32:08.0142 7388 C: <-> \Device\Harddisk0\DR0\Partition5
21:32:08.0184 7388 D: <-> \Device\Harddisk0\DR0\Partition6
21:32:08.0184 7388 ============================================================
21:32:08.0184 7388 Initialize success
21:32:08.0184 7388 ============================================================
21:32:21.0909 3432 ============================================================
21:32:21.0909 3432 Scan started
21:32:21.0909 3432 Mode: Manual;
21:32:21.0909 3432 ============================================================
21:32:22.0609 3432 ================ Scan system memory ========================
21:32:22.0609 3432 System memory - ok
21:32:22.0617 3432 ================ Scan services =============================
21:32:26.0692 3432 1394ohci - ok
21:32:26.0711 3432 3ware - ok
21:32:26.0735 3432 ACPI - ok
21:32:26.0743 3432 AcpiDev - ok
21:32:26.0751 3432 acpiex - ok
21:32:26.0751 3432 acpipagr - ok
21:32:26.0795 3432 [ F5DC5E3D9735389F2332711860A00EF1 ] AcpiPmi C:\WINDOWS\System32\drivers\acpipmi.sys
21:32:26.0795 3432 AcpiPmi - ok
21:32:26.0811 3432 acpitime - ok
21:32:26.0859 3432 [ AF7A18603B0B82DFA5B420456FAF2201 ] ACPIVPC C:\WINDOWS\System32\drivers\AcpiVpc.sys
21:32:26.0859 3432 ACPIVPC - ok
21:32:26.0975 3432 [ EF3FA1EEC533C8B1B12CB3BAEBD0E84F ] AdobeFlashPlayerUpdateSvc C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:32:26.0985 3432 AdobeFlashPlayerUpdateSvc - ok
21:32:27.0043 3432 ADP80XX - ok
21:32:27.0051 3432 AFD - ok
21:32:27.0090 3432 [ 1AD7D3F44B53DEE84E665A071448B400 ] ahcache C:\WINDOWS\system32\DRIVERS\ahcache.sys
21:32:27.0092 3432 ahcache - ok
21:32:27.0132 3432 [ C3144B5B518F9DCEAA87D451111E08F4 ] AJRouter C:\WINDOWS\System32\AJRouter.dll
21:32:27.0132 3432 AJRouter - ok
21:32:27.0172 3432 [ 5E1AA3D60F194F60F08112A6E5A6F3E9 ] ALG C:\WINDOWS\System32\alg.exe
21:32:27.0172 3432 ALG - ok
21:32:27.0192 3432 AmdK8 - ok
21:32:27.0212 3432 AmdPPM - ok
21:32:27.0228 3432 amdsata - ok
21:32:27.0228 3432 amdsbs - ok
21:32:27.0236 3432 amdxata - ok
21:32:27.0268 3432 [ E0DE4879A4EFE87F0A1F393EE2632478 ] AppID C:\WINDOWS\system32\drivers\appid.sys
21:32:27.0268 3432 AppID - ok
21:32:27.0304 3432 [ 1D87C8258679AB936B24F7620D93373B ] AppIDSvc C:\WINDOWS\System32\appidsvc.dll
21:32:27.0304 3432 AppIDSvc - ok
21:32:27.0344 3432 [ 0663D4FCB1A0E3279F5FD5E1EE82CE20 ] Appinfo C:\WINDOWS\System32\appinfo.dll
21:32:27.0344 3432 Appinfo - ok
21:32:27.0394 3432 [ 8CDA6CB0CAB0449DB4626B6170831531 ] applockerfltr C:\WINDOWS\system32\drivers\applockerfltr.sys
21:32:27.0395 3432 applockerfltr - ok
21:32:27.0444 3432 [ 9E3C4B846B88F71F180F21341FB5DB6A ] AppReadiness C:\WINDOWS\system32\AppReadiness.dll
21:32:27.0452 3432 AppReadiness - ok
21:32:27.0552 3432 [ 297211FA91307F4FF67507023B1F7538 ] AppXSvc C:\WINDOWS\system32\appxdeploymentserver.dll
21:32:27.0604 3432 AppXSvc - ok
21:32:27.0636 3432 arcsas - ok
21:32:27.0668 3432 AsyncMac - ok
21:32:27.0694 3432 atapi - ok
21:32:27.0795 3432 [ 835E2C1A3D32492E2B90BD4FE5527CB6 ] athr C:\WINDOWS\System32\drivers\athw8x.sys
21:32:27.0852 3432 athr - ok
21:32:27.0928 3432 [ 36322190763845975E0D001E90687BF2 ] athur C:\WINDOWS\System32\drivers\athurx.sys
21:32:27.0952 3432 athur - ok
21:32:28.0012 3432 AudioEndpointBuilder - ok
21:32:28.0044 3432 Audiosrv - ok
21:32:28.0076 3432 [ 3922CBE6EBE72C73F25879554C273BEB ] AxInstSV C:\WINDOWS\System32\AxInstSV.dll
21:32:28.0076 3432 AxInstSV - ok
21:32:28.0120 3432 b06bdrv - ok
21:32:28.0165 3432 [ 6B7F4904CFB6C4820F342955795EF406 ] bam C:\WINDOWS\system32\drivers\bam.sys
21:32:28.0165 3432 bam - ok
21:32:28.0237 3432 BasicDisplay - ok
21:32:28.0295 3432 BasicRender - ok
21:32:28.0328 3432 bcmfn2 - ok
21:32:28.0360 3432 [ 703F98AD348573170162497076A65F9D ] BDESVC C:\WINDOWS\System32\bdesvc.dll
21:32:28.0360 3432 BDESVC - ok
21:32:28.0396 3432 [ D50A77D0E28FDE7689A84688F07E7478 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
21:32:28.0396 3432 Beep - ok
21:32:28.0432 3432 BFE - ok
21:32:28.0481 3432 [ 39D68A4AA6BCF0AF838A5B0436580910 ] BITS C:\WINDOWS\System32\qmgr.dll
21:32:28.0512 3432 BITS - ok
21:32:28.0644 3432 [ 5AB58C337AC65837FE404462AD6265AB ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
21:32:28.0652 3432 Bonjour Service - ok
21:32:28.0652 3432 bowser - ok
21:32:28.0704 3432 [ BB3C2DF72315079C86FDB4E546571A93 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
21:32:28.0712 3432 BrokerInfrastructure - ok
21:32:28.0752 3432 [ C61BD591052B5478CCD9B0B32EFF8AB4 ] Browser C:\WINDOWS\System32\browser.dll
21:32:28.0760 3432 Browser - ok
21:32:28.0852 3432 [ 0471D5669F18C50E552B2BC0CB15E7B3 ] BrYNSvc C:\Program Files (x86)\Browny02\BrYNSvc.exe
21:32:28.0852 3432 BrYNSvc - ok
21:32:28.0876 3432 [ C6978F7EBA6F37D626482AC6B9390630 ] BTATH_BUS C:\WINDOWS\System32\drivers\btath_bus.sys
21:32:28.0876 3432 BTATH_BUS - ok
21:32:28.0920 3432 [ 16D91F93677738F90263542C59B6FEE1 ] BtFilter C:\WINDOWS\system32\DRIVERS\btfilter.sys
21:32:28.0928 3432 BtFilter - ok
21:32:28.0995 3432 [ 14852686F11838D4F36675F78A71F99A ] BthA2DP C:\WINDOWS\system32\drivers\BthA2DP.sys
21:32:28.0996 3432 BthA2DP - ok
21:32:29.0076 3432 [ B35E4943850E19EDA00FC2176549C076 ] BthAvrcpTg C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
21:32:29.0085 3432 BthAvrcpTg - ok
21:32:29.0122 3432 [ CCB2AAEA0ED2AA59169DA33D5CF6E181 ] BthEnum C:\WINDOWS\System32\drivers\BthEnum.sys
21:32:29.0122 3432 BthEnum - ok
21:32:29.0204 3432 [ 482DEBE90B4D0F26A41F6E6897206451 ] BthHFEnum C:\WINDOWS\System32\drivers\bthhfenum.sys
21:32:29.0204 3432 BthHFEnum - ok
21:32:29.0244 3432 [ 9065BECFBAE77A13AF62FFBBCBF42384 ] bthhfhid C:\WINDOWS\System32\drivers\BthHFHid.sys
21:32:29.0244 3432 bthhfhid - ok
21:32:29.0276 3432 [ 666F57CECA9794A61D7E42997ACD113C ] BthHFSrv C:\WINDOWS\System32\BthHFSrv.dll
21:32:29.0286 3432 BthHFSrv - ok
21:32:29.0344 3432 [ D92A23629703ECD397D27C5A4EFA77F0 ] bthl2cap C:\WINDOWS\system32\DRIVERS\bthl2cap.sys
21:32:29.0344 3432 bthl2cap - ok
21:32:29.0396 3432 [ AEEAB17DDA0DC5A7AC3EE0B4B8E90732 ] BthLEEnum C:\WINDOWS\system32\DRIVERS\Microsoft.Bluetooth.Legacy.LEEnumerator.sys
21:32:29.0404 3432 BthLEEnum - ok
21:32:29.0436 3432 [ 5F64213D78ED4C61EC05B66C38F946E4 ] BTHMODEM C:\WINDOWS\System32\drivers\bthmodem.sys
21:32:29.0444 3432 BTHMODEM - ok
21:32:29.0490 3432 [ 11020BDEB01CC7C9F37D797805125CAC ] BthPan C:\WINDOWS\System32\drivers\bthpan.sys
21:32:29.0491 3432 BthPan - ok
21:32:29.0544 3432 [ DDC440B54F637058488E011664F841F5 ] BTHPORT C:\WINDOWS\system32\DRIVERS\BTHport.sys
21:32:29.0552 3432 BTHPORT - ok
21:32:29.0605 3432 [ 738B9B6E51CB997BEFE9F60830B0EC5A ] bthserv C:\WINDOWS\system32\bthserv.dll
21:32:29.0605 3432 bthserv - ok
21:32:29.0653 3432 [ 6EBCAAED7137CE64073B767683E1DF67 ] BTHUSB C:\WINDOWS\system32\DRIVERS\BTHUSB.sys
21:32:29.0653 3432 BTHUSB - ok
21:32:29.0713 3432 bttflt - ok
21:32:29.0753 3432 buttonconverter - ok
21:32:29.0787 3432 [ 4D6F3452276B52C2AE141240F0D1D147 ] CAD C:\WINDOWS\System32\drivers\CAD.sys
21:32:29.0788 3432 CAD - ok
21:32:29.0837 3432 [ 1C7D8C766915E82B5784837A47D1AB58 ] camsvc C:\WINDOWS\system32\CapabilityAccessManager.dll
21:32:29.0845 3432 camsvc - ok
21:32:29.0861 3432 CapImg - ok
21:32:29.0869 3432 cdfs - ok
21:32:29.0913 3432 [ B90D31DE36DED72F8C5817D194F7D602 ] CDPSvc C:\WINDOWS\System32\CDPSvc.dll
21:32:29.0921 3432 CDPSvc - ok
21:32:29.0994 3432 [ 23FC7049882CE2215B40625F146E8458 ] CDPUserSvc C:\WINDOWS\System32\CDPUserSvc.dll
21:32:29.0997 3432 CDPUserSvc - ok
21:32:30.0061 3432 cdrom - ok
21:32:30.0069 3432 [ 3E321B08C212A75A442627CCFECE6FE7 ] CertPropSvc C:\WINDOWS\System32\certprop.dll
21:32:30.0069 3432 CertPropSvc - ok
21:32:30.0113 3432 [ C58EC27035731337ADD1326880086B16 ] CH341SER_A64 C:\WINDOWS\System32\Drivers\CH341S64.SYS
21:32:30.0121 3432 CH341SER_A64 - ok
21:32:30.0180 3432 cht4iscsi - ok
21:32:30.0232 3432 cht4vbd - ok
21:32:30.0256 3432 [ E57A058B08FAEBE0392E3A1FE938F671 ] circlass C:\WINDOWS\System32\drivers\circlass.sys
21:32:30.0256 3432 circlass - ok
21:32:30.0296 3432 [ 5C518E8598DB9A74F6FF09347446AD8B ] CldFlt C:\WINDOWS\system32\drivers\cldflt.sys
21:32:30.0297 3432 CldFlt - ok
21:32:30.0297 3432 CLFS - ok
21:32:30.0369 3432 [ 5E49B21D23CF0BDABCC4BA749D450716 ] ClipSVC C:\WINDOWS\System32\ClipSVC.dll
21:32:30.0377 3432 ClipSVC - ok
21:32:30.0451 3432 CmBatt - ok
21:32:30.0451 3432 CNG - ok
21:32:30.0495 3432 [ 9F1DA67840B72D06010C00D7565DF563 ] cnghwassist C:\WINDOWS\system32\DRIVERS\cnghwassist.sys
21:32:30.0496 3432 cnghwassist - ok
21:32:30.0593 3432 [ A32120E22EE15A095AB1DA7B01DC8C5C ] CompositeBus C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_dafda767666d2ff6\CompositeBus.sys
21:32:30.0594 3432 CompositeBus - ok
21:32:30.0597 3432 COMSysApp - ok
21:32:30.0597 3432 condrv - ok
21:32:30.0669 3432 [ BA68602A9CECCF8704E7256E3C477363 ] CoreMessagingRegistrar C:\WINDOWS\system32\coremessaging.dll
21:32:30.0677 3432 CoreMessagingRegistrar - ok
21:32:30.0753 3432 [ C17E6193CF8FBB50626C4995E9FE4F29 ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
21:32:30.0761 3432 cphs - ok
21:32:30.0796 3432 CryptSvc - ok
21:32:30.0829 3432 [ 9BB7A7023DAA1B39533619E30051D469 ] dam C:\WINDOWS\system32\drivers\dam.sys
21:32:30.0829 3432 dam - ok
21:32:30.0869 3432 [ 62C2617E1927776851B108717166BBA4 ] DbxSvc C:\WINDOWS\system32\DbxSvc.exe
21:32:30.0869 3432 DbxSvc - ok
21:32:30.0897 3432 DcomLaunch - ok
21:32:30.0913 3432 defragsvc - ok
21:32:30.0977 3432 [ F1BCC17204FAECAEDC66A1C3B0330299 ] DeviceAssociationService C:\WINDOWS\system32\das.dll
21:32:30.0977 3432 DeviceAssociationService - ok
21:32:31.0013 3432 DeviceInstall - ok
21:32:31.0053 3432 [ 21A87E38181405B0C0DF726948885E3F ] DevicesFlowUserSvc C:\WINDOWS\System32\DevicesFlowBroker.dll
21:32:31.0061 3432 DevicesFlowUserSvc - ok
21:32:31.0144 3432 [ 5EEAC9960E82BD17A5FE8E09769A2678 ] DevQueryBroker C:\WINDOWS\system32\DevQueryBroker.dll
21:32:31.0146 3432 DevQueryBroker - ok
21:32:31.0171 3432 Dfsc - ok
21:32:31.0217 3432 [ 73BDD44A6088916964945886F9025409 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
21:32:31.0217 3432 dg_ssudbus - ok
21:32:31.0241 3432 Dhcp - ok
21:32:31.0329 3432 diagnosticshub.standardcollector.service - ok
21:32:31.0353 3432 [ 6589CB8F13ABADAEF52365CE2DE71B0E ] diagsvc C:\WINDOWS\system32\DiagSvc.dll
21:32:31.0361 3432 diagsvc - ok
21:32:31.0397 3432 DiagTrack - ok
21:32:31.0521 3432 [ 91DF13EC831BDCFA36A7A12CD13D66B9 ] Disc Soft Lite Bus Service C:\Program Files (x86)\DAEMON Tools Lite\DiscSoftBusService.exe
21:32:31.0529 3432 Disc Soft Lite Bus Service - ok
21:32:31.0637 3432 [ 89810530F509449C8707B1AD240FCB4E ] Disconnect Desktop Updater C:\Program Files (x86)\Disconnect\Disconnect Desktop\Disconnect Desktop Updater.exe
21:32:31.0637 3432 Disconnect Desktop Updater - ok
21:32:31.0706 3432 Disk - ok
21:32:31.0754 3432 [ F7788F8C7295265DE1FD90446BBECC50 ] DmEnrollmentSvc C:\WINDOWS\system32\Windows.Internal.Management.dll
21:32:31.0762 3432 DmEnrollmentSvc - ok
21:32:31.0822 3432 dmvsc - ok
21:32:31.0846 3432 [ C54ADEBE3A1D6875CE541CFBD23B56A7 ] dmwappushservice C:\WINDOWS\system32\dmwappushsvc.dll
21:32:31.0846 3432 dmwappushservice - ok
21:32:31.0870 3432 Dnscache - ok
21:32:31.0898 3432 [ 242A8F588F025720BFBEFEC3EA6993D6 ] dot3svc C:\WINDOWS\System32\dot3svc.dll
21:32:31.0906 3432 dot3svc - ok
21:32:31.0954 3432 [ 7C8EEBE1410C17968AFF72808430025F ] DPS C:\WINDOWS\system32\dps.dll
21:32:31.0954 3432 DPS - ok
21:32:31.0995 3432 drmkaud - ok
21:32:32.0070 3432 [ 33576C0EAADFA15DDEE5C4C64290E87F ] DSAService C:\Program Files (x86)\Intel Driver Update Utility\DSAService.exe
21:32:32.0070 3432 DSAService - ok
21:32:32.0128 3432 [ 9368462B106F77691EB4B2F262E45FD7 ] DsmSvc C:\WINDOWS\System32\DeviceSetupManager.dll
21:32:32.0131 3432 DsmSvc - ok
21:32:32.0171 3432 [ 0E7FD40652C02D46FCB26B6BE461A493 ] DsSvc C:\WINDOWS\System32\DsSvc.dll
21:32:32.0173 3432 DsSvc - ok
21:32:32.0214 3432 [ 496C3C6BC3D930D0960C9E75AA30F4A7 ] dtlitescsibus C:\WINDOWS\System32\drivers\dtlitescsibus.sys
21:32:32.0215 3432 dtlitescsibus - ok
21:32:32.0257 3432 [ 070494E4942762E7321375AF94B52653 ] DusmSvc C:\WINDOWS\System32\dusmsvc.dll
21:32:32.0265 3432 DusmSvc - ok
21:32:32.0298 3432 DXGKrnl - ok
21:32:32.0314 3432 Eaphost - ok
21:32:32.0354 3432 ebdrv - ok
21:32:32.0370 3432 EFS - ok
21:32:32.0370 3432 EhStorClass - ok
21:32:32.0422 3432 EhStorTcgDrv - ok
21:32:32.0454 3432 [ 664383E71E5CC2175BCAF25FFE714349 ] embeddedmode C:\WINDOWS\System32\embeddedmodesvc.dll
21:32:32.0462 3432 embeddedmode - ok
21:32:32.0496 3432 [ D2349D9837652BF3F737874F2351AE80 ] EntAppSvc C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
21:32:32.0497 3432 EntAppSvc - ok
21:32:32.0545 3432 ErrDev - ok
21:32:32.0697 3432 [ A7E5EFF955B119D187E51EA6190E842B ] ESRV_SVC_QUEENCREEK C:\Program Files\Intel\SUR\QUEENCREEK\esrv_svc.exe
21:32:32.0697 3432 ESRV_SVC_QUEENCREEK - ok
21:32:32.0729 3432 [ 821CEA553C3AA18D21FC6111261FF692 ] ETD C:\WINDOWS\system32\DRIVERS\ETD.sys
21:32:32.0737 3432 ETD - ok
21:32:32.0822 3432 [ 2C101AA0A186C079C4044F1FD0D1E5E5 ] ETDService C:\Program Files\Elantech\ETDService.exe
21:32:32.0822 3432 ETDService - ok
21:32:32.0893 3432 [ BBEA3BCEEE0C7A317C5C830241D7AB71 ] EventSystem C:\WINDOWS\system32\es.dll
21:32:32.0897 3432 EventSystem - ok
21:32:32.0914 3432 exfat - ok
21:32:32.0922 3432 fastfat - ok
21:32:32.0962 3432 [ A2778C297A49D6ED1C7E7C62691EDF04 ] Fax C:\WINDOWS\system32\fxssvc.exe
21:32:32.0970 3432 Fax - ok
21:32:32.0978 3432 fdc - ok
21:32:33.0014 3432 [ D84A7F7A180FABBE9AB06D7541C6BF19 ] fdPHost C:\WINDOWS\system32\fdPHost.dll
21:32:33.0014 3432 fdPHost - ok
21:32:33.0054 3432 [ 4C2AE4D1675B38761B5C805E45246C08 ] FDResPub C:\WINDOWS\system32\fdrespub.dll
21:32:33.0054 3432 FDResPub - ok
21:32:33.0098 3432 [ D59ECE181ABE997FFAD27290F7354149 ] fhsvc C:\WINDOWS\system32\fhsvc.dll
21:32:33.0098 3432 fhsvc - ok
21:32:33.0150 3432 [ 58846DF857D7FFA823360C8C7FDF55DC ] FileCrypt C:\WINDOWS\system32\drivers\filecrypt.sys
21:32:33.0152 3432 FileCrypt - ok
21:32:33.0156 3432 FileInfo - ok
21:32:33.0179 3432 Filetrace - ok
21:32:33.0249 3432 [ 1B04D931B3EFA5FE67FA7D8510722222 ] FlexNet Licensing Service 64 C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
21:32:33.0273 3432 FlexNet Licensing Service 64 - ok
21:32:33.0322 3432 flpydisk - ok
21:32:33.0322 3432 FltMgr - ok
21:32:33.0346 3432 FontCache - ok
21:32:33.0506 3432 FontCache3.0.0.0 - ok
21:32:33.0562 3432 [ 92E872CAF92384E0A22AFF90363C3786 ] FrameServer C:\WINDOWS\system32\FrameServer.dll
21:32:33.0570 3432 FrameServer - ok
21:32:33.0596 3432 FsDepends - ok
21:32:33.0598 3432 Fs_Rec - ok
21:32:33.0630 3432 [ 8EC36B9FD3D25687C3F996200BBB8DED ] FTDIBUS C:\WINDOWS\system32\drivers\ftdibus.sys
21:32:33.0630 3432 FTDIBUS - ok
21:32:33.0662 3432 [ 535AB1F6600D8384145E4A8521194D3F ] FTSER2K C:\WINDOWS\system32\drivers\ftser2k.sys
21:32:33.0662 3432 FTSER2K - ok
21:32:33.0754 3432 [ F97991943FAED43311423BD536266528 ] fussvc C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe
21:32:33.0754 3432 fussvc - ok
21:32:33.0795 3432 fvevol - ok
21:32:33.0846 3432 [ 857FF15D9A575339F6BC9F2B8F14D7EE ] gencounter C:\WINDOWS\System32\drivers\vmgencounter.sys
21:32:33.0846 3432 gencounter - ok
21:32:33.0878 3432 genericusbfn - ok
21:32:33.0896 3432 GPIOClx0101 - ok
21:32:33.0906 3432 gpsvc - ok
21:32:33.0946 3432 [ C91BEFE255FDF97AA647D2C6FC08BC57 ] GpuEnergyDrv C:\WINDOWS\system32\drivers\gpuenergydrv.sys
21:32:33.0946 3432 GpuEnergyDrv - ok
21:32:33.0978 3432 [ C6EE2216D4A4A8F9E6EAC0CA46859FDD ] GraphicsPerfSvc C:\WINDOWS\System32\GraphicsPerfSvc.dll
21:32:33.0987 3432 GraphicsPerfSvc - ok
21:32:34.0063 3432 [ DD7423ABBE2913E70D50E9318AD57EE4 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:32:34.0071 3432 gupdate - ok
21:32:34.0071 3432 [ DD7423ABBE2913E70D50E9318AD57EE4 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:32:34.0071 3432 gupdatem - ok
21:32:34.0126 3432 HDAudBus - ok
21:32:34.0199 3432 HidBatt - ok
21:32:34.0347 3432 [ C7E66B04B5D3A7A4C3045F261BA19754 ] HidBth C:\WINDOWS\System32\drivers\hidbth.sys
21:32:34.0347 3432 HidBth - ok
21:32:34.0371 3432 hidi2c - ok
21:32:34.0414 3432 hidinterrupt - ok
21:32:34.0438 3432 [ B433877528FB31CCDB0F84F2A9C24699 ] HidIr C:\WINDOWS\System32\drivers\hidir.sys
21:32:34.0438 3432 HidIr - ok
21:32:34.0499 3432 hidserv - ok
21:32:34.0531 3432 HidUsb - ok
21:32:34.0579 3432 [ 945CB80FB81D20C3D4F4DD026B77C5E8 ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
21:32:34.0579 3432 HomeGroupListener - ok
21:32:34.0639 3432 [ 584174752C7BA3543833A5271DA4F7F7 ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
21:32:34.0647 3432 HomeGroupProvider - ok
21:32:34.0679 3432 HpSAMD - ok
21:32:34.0755 3432 [ 7E32BB97B5A18FD522D587540DA730B1 ] HPSupportSolutionsFrameworkService C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
21:32:34.0755 3432 HPSupportSolutionsFrameworkService - ok
21:32:34.0815 3432 [ 3092C2C5B7502B07C4D858A9991213AE ] HTTP C:\WINDOWS\system32\drivers\HTTP.sys
21:32:34.0823 3432 HTTP - ok
21:32:34.0871 3432 [ 897721F27214C51B55F04F47D8BA663D ] HvHost C:\WINDOWS\System32\hvhostsvc.dll
21:32:34.0879 3432 HvHost - ok
21:32:34.0915 3432 [ FD22926134FFAFCBD5C5C58B007249FD ] hvservice C:\WINDOWS\system32\drivers\hvservice.sys
21:32:34.0915 3432 hvservice - ok
21:32:34.0947 3432 [ 2674B96BE3736B874DF57DF6D77A4A5D ] HwNClx0101 C:\WINDOWS\system32\Drivers\mshwnclx.sys
21:32:34.0947 3432 HwNClx0101 - ok
21:32:34.0963 3432 hwpolicy - ok
21:32:34.0999 3432 hyperkbd - ok
21:32:35.0047 3432 HyperVideo - ok
21:32:35.0092 3432 i8042prt - ok
21:32:35.0131 3432 iagpio - ok
21:32:35.0131 3432 iai2c - ok
21:32:35.0171 3432 iaLPSS2i_GPIO2 - ok
21:32:35.0194 3432 iaLPSS2i_GPIO2_BXT_P - ok
21:32:35.0199 3432 iaLPSS2i_I2C - ok
21:32:35.0199 3432 iaLPSS2i_I2C_BXT_P - ok
21:32:35.0215 3432 iaLPSSi_GPIO - ok
21:32:35.0223 3432 iaLPSSi_I2C - ok
21:32:35.0279 3432 [ 0324CA31542D1C42E8FF663BA742DE68 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
21:32:35.0279 3432 iaStorA - ok
21:32:35.0315 3432 iaStorAV - ok
21:32:35.0347 3432 [ 5B1DFB39D292B9BB258584349855293E ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
21:32:35.0347 3432 IAStorDataMgrSvc - ok
21:32:35.0371 3432 iaStorV - ok
21:32:35.0415 3432 ibbus - ok
21:32:35.0479 3432 [ FE8E7D7462874ABA0D0CADC65BDD003B ] icssvc C:\WINDOWS\System32\tetheringservice.dll
21:32:35.0489 3432 icssvc - ok
21:32:35.0644 3432 [ 29518D8973FA7F6F7F43F0B37A612281 ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
21:32:35.0755 3432 igfx - ok
21:32:35.0779 3432 [ 16D2096DC8911F0DD731196BBA7CC9FB ] igfxCUIService2.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe
21:32:35.0790 3432 igfxCUIService2.0.0.0 - ok
21:32:35.0807 3432 IKEEXT - ok
21:32:35.0847 3432 [ F7F0111B7C1483784BE322F25BF03E18 ] IndirectKmd C:\WINDOWS\System32\drivers\IndirectKmd.sys
21:32:35.0847 3432 IndirectKmd - ok
21:32:35.0923 3432 [ 55B86C52A85A7BB9E69BF9D35A35150F ] InstallService C:\WINDOWS\system32\InstallService.dll
21:32:35.0939 3432 InstallService - ok
21:32:36.0055 3432 [ 622868E4BAE8FBCD22CB1A5901A2C824 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
21:32:36.0131 3432 IntcAzAudAddService - ok
21:32:36.0207 3432 [ E300D1E37B737ED14F7A08CD5604E5D9 ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
21:32:36.0207 3432 IntcDAud - ok
21:32:36.0239 3432 [ 0DB1E3F6189C628675F855C0EB510419 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
21:32:36.0247 3432 Intel(R) Capability Licensing Service Interface - ok
21:32:36.0271 3432 [ 492AAF2FF66F437F0E796574B116EFC3 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
21:32:36.0279 3432 Intel(R) Capability Licensing Service TCP IP Interface - ok
21:32:36.0315 3432 [ B3FF41FCB17206ABFC9B7DCC5E8E0777 ] IntelHaxm C:\WINDOWS\system32\DRIVERS\IntelHaxm.sys
21:32:36.0315 3432 IntelHaxm - ok
21:32:36.0331 3432 intelide - ok
21:32:36.0379 3432 [ 047C551DF6890B34FD6247E8827A85D4 ] intelpep C:\WINDOWS\system32\drivers\intelpep.sys
21:32:36.0379 3432 intelpep - ok
21:32:36.0439 3432 intelppm - ok
21:32:36.0463 3432 invdimm - ok
21:32:36.0508 3432 [ FBAD6FD9B6B8581E7FF0028CFC123D55 ] iorate C:\WINDOWS\system32\drivers\iorate.sys
21:32:36.0508 3432 iorate - ok
21:32:36.0540 3432 [ B21388DF57C94FF32B65332989553D32 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
21:32:36.0540 3432 IpFilterDriver - ok
21:32:36.0580 3432 [ D914AFBBA94CA191994089B2E5478A28 ] iphlpsvc C:\WINDOWS\System32\iphlpsvc.dll
21:32:36.0596 3432 iphlpsvc - ok
21:32:36.0616 3432 IPMIDRV - ok
21:32:36.0716 3432 [ 6592215840E6BC79D4E1169F95A39BC3 ] IPNAT C:\WINDOWS\system32\drivers\ipnat.sys
21:32:36.0724 3432 IPNAT - ok
21:32:36.0816 3432 [ 944A6D2E1D971806EFFE4BBABF0DBDC7 ] IpOverUsbSvc C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
21:32:36.0816 3432 IpOverUsbSvc - ok
21:32:36.0856 3432 [ B86CEEC2F4EC7A02F894C47B46123861 ] IPT C:\WINDOWS\System32\drivers\ipt.sys
21:32:36.0856 3432 IPT - ok
21:32:36.0900 3432 [ 82ED725BFF56503A8FA1D9F0C4CAE59B ] IpxlatCfgSvc C:\WINDOWS\System32\IpxlatCfg.dll
21:32:36.0908 3432 IpxlatCfgSvc - ok
21:32:36.0924 3432 [ 33C31949AAF411524F9D2D5FC582F8E6 ] irda C:\WINDOWS\system32\drivers\irda.sys
21:32:36.0924 3432 irda - ok
21:32:36.0956 3432 [ 1908DE7D4760AE33DAD7F04F8FF89469 ] IRENUM C:\WINDOWS\system32\drivers\irenum.sys
21:32:36.0956 3432 IRENUM - ok
21:32:36.0999 3432 [ 36A800A9FB641AD73754B054CF47BC0B ] irmon C:\WINDOWS\System32\irmon.dll
21:32:36.0999 3432 irmon - ok
21:32:37.0055 3432 isapnp - ok
21:32:37.0079 3432 iScsiPrt - ok
21:32:37.0126 3432 [ 0442AA226F71C77D4E1DA3FA1E380192 ] isocusb C:\WINDOWS\system32\drivers\isocusb.sys
21:32:37.0129 3432 isocusb - ok
21:32:37.0172 3432 [ 2C04ACF9070282AC9AA837C52CA3C128 ] iwdbus C:\WINDOWS\System32\drivers\iwdbus.sys
21:32:37.0173 3432 iwdbus - ok
21:32:37.0225 3432 [ 52069AEB42D3D0F97CBCA1085EBF55E6 ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
21:32:37.0225 3432 jhi_service - ok
21:32:37.0281 3432 kbdclass - ok
21:32:37.0316 3432 kbdhid - ok
21:32:37.0332 3432 kdnic - ok
21:32:37.0356 3432 KeyIso - ok
21:32:37.0356 3432 KSecDD - ok
21:32:37.0364 3432 KSecPkg - ok
21:32:37.0372 3432 ksthunk - ok
21:32:37.0432 3432 [ DADC7DF3D8B32D5C208914DF7EB36639 ] KtmRm C:\WINDOWS\system32\msdtckrm.dll
21:32:37.0440 3432 KtmRm - ok
21:32:37.0480 3432 [ 4E5EA006CFFB96E0BAFC767D659AAB9A ] L1C C:\WINDOWS\System32\drivers\L1C63x64.sys
21:32:37.0489 3432 L1C - ok
21:32:37.0500 3432 LanmanServer - ok
21:32:37.0508 3432 LanmanWorkstation - ok
21:32:37.0632 3432 [ 20EE2F2ADCF8DBD091E931593F5AC268 ] LBTServ C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
21:32:37.0640 3432 LBTServ - ok
21:32:37.0756 3432 [ 1C079F496D757794605D393335B38C9C ] Lenovo System Agent Service C:\Program Files\Lenovo\iMController\SystemAgentService.exe
21:32:37.0764 3432 Lenovo System Agent Service - ok
21:32:37.0817 3432 [ EAB70270BDDCFEF56FCC7425C2D9883D ] LEqdUsb C:\WINDOWS\system32\DRIVERS\LEqdUsb.Sys
21:32:37.0817 3432 LEqdUsb - ok
21:32:37.0865 3432 [ BC4C98483A0E397A5794275E8596FA9D ] lfsvc C:\WINDOWS\System32\lfsvc.dll
21:32:37.0865 3432 lfsvc - ok
21:32:37.0909 3432 [ 5EBB7C1FC685D45A1D3D8B2B9A656E48 ] LHidEqd C:\WINDOWS\system32\DRIVERS\LHidEqd.Sys
21:32:37.0909 3432 LHidEqd - ok
21:32:37.0957 3432 [ AFDFA4A6B0F7B15AA38E494FD4595741 ] LHidFilt C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
21:32:37.0965 3432 LHidFilt - ok
21:32:38.0017 3432 [ 78FFEAB9F1C70A359E5FF88234975C64 ] LicenseManager C:\WINDOWS\system32\LicenseManagerSvc.dll
21:32:38.0025 3432 LicenseManager - ok
21:32:38.0057 3432 [ 642EB23F889FD6EBC35ED53C393D752B ] lltdio C:\WINDOWS\system32\drivers\lltdio.sys
21:32:38.0065 3432 lltdio - ok
21:32:38.0100 3432 [ 7786A03A2A6076B38B129F5578A90C7C ] lltdsvc C:\WINDOWS\System32\lltdsvc.dll
21:32:38.0100 3432 lltdsvc - ok
21:32:38.0151 3432 lmhosts - ok
21:32:38.0178 3432 [ C3E82B320F34C97F32B8026F4C249BEF ] LMouFilt C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
21:32:38.0180 3432 LMouFilt - ok
21:32:38.0247 3432 [ 30F2881465DA68D22662B27B805C918B ] LSC.Services.SystemService C:\Program Files\Lenovo\Lenovo Solution Center\App\LSC.Services.SystemService.exe
21:32:38.0255 3432 LSC.Services.SystemService - ok
21:32:38.0324 3432 LSI_SAS - ok
21:32:38.0365 3432 LSI_SAS2i - ok
21:32:38.0398 3432 LSI_SAS3i - ok
21:32:38.0416 3432 LSI_SSS - ok
21:32:38.0444 3432 LSM - ok
21:32:38.0476 3432 [ 5206CC1020EFB9AE772DE050F044763B ] luafv C:\WINDOWS\system32\drivers\luafv.sys
21:32:38.0476 3432 luafv - ok
21:32:38.0517 3432 [ 894B01962AA6AEA164D96A0248EFFC8C ] MapsBroker C:\WINDOWS\System32\moshost.dll
21:32:38.0525 3432 MapsBroker - ok
21:32:38.0541 3432 mausbhost - ok
21:32:38.0565 3432 mausbip - ok
21:32:38.0648 3432 [ D8DBCF7C20F3D39AA0037C64118A5FC4 ] McComponentHostService C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe
21:32:38.0648 3432 McComponentHostService - ok
21:32:38.0701 3432 megasas - ok
21:32:38.0741 3432 megasas2i - ok
21:32:38.0765 3432 megasr - ok
21:32:38.0800 3432 [ 926C135CFB0C75B32FB714B5C0C58FAA ] MEIx64 C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys
21:32:38.0801 3432 MEIx64 - ok
21:32:38.0841 3432 [ 12338C8521C0B71167EE265AD1F39366 ] MessagingService C:\WINDOWS\System32\MessagingService.dll
21:32:38.0849 3432 MessagingService - ok
21:32:38.0957 3432 [ 123271BD5237AB991DC5C21FDF8835EB ] Microsoft Office Groove Audit Service C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
21:32:38.0957 3432 Microsoft Office Groove Audit Service - ok
21:32:38.0991 3432 mlx4_bus - ok
21:32:38.0999 3432 MMCSS - ok
21:32:39.0025 3432 [ 5A958DE7ADEB6FC81CE10A07ABC10712 ] Modem C:\WINDOWS\system32\drivers\modem.sys
21:32:39.0025 3432 Modem - ok
21:32:39.0065 3432 [ 8F55A0F11B29CF53FC7516A0C75F894D ] monitor C:\WINDOWS\System32\drivers\monitor.sys
21:32:39.0073 3432 monitor - ok
21:32:39.0110 3432 mouclass - ok
21:32:39.0134 3432 mouhid - ok
21:32:39.0163 3432 mountmgr - ok
21:32:39.0216 3432 [ 98E979807571B3E3378EF65378CF3DE4 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
21:32:39.0218 3432 MozillaMaintenance - ok
21:32:39.0219 3432 Suspicious service (Hidden): MpKsl90967e8f
21:32:39.0309 3432 MpKsl90967e8f ( HiddenService.Multi.Generic ) - warning
21:32:39.0309 3432 MpKsl90967e8f - detected HiddenService.Multi.Generic (1)
21:32:39.0309 3432 Suspicious service (Hidden): MpKsl95e07077
21:32:39.0317 3432 MpKsl95e07077 ( HiddenService.Multi.Generic ) - warning
21:32:39.0317 3432 MpKsl95e07077 - detected HiddenService.Multi.Generic (1)
21:32:39.0341 3432 mpsdrv - ok
21:32:39.0357 3432 MpsSvc - ok
21:32:39.0409 3432 [ 327F27D5BF8C5F11C040B717FE4FFA66 ] MRxDAV C:\WINDOWS\system32\drivers\mrxdav.sys
21:32:39.0417 3432 MRxDAV - ok
21:32:39.0433 3432 mrxsmb - ok
21:32:39.0441 3432 mrxsmb10 - ok
21:32:39.0449 3432 mrxsmb20 - ok
21:32:39.0481 3432 [ 80F06B0AD59A496570C3909970386E57 ] MsBridge C:\WINDOWS\system32\drivers\bridge.sys
21:32:39.0481 3432 MsBridge - ok
21:32:39.0535 3432 [ E9071FCA4368AEC6AAD2B7486B61A8C6 ] MSDTC C:\WINDOWS\System32\msdtc.exe
21:32:39.0541 3432 MSDTC - ok
21:32:39.0551 3432 Msfs - ok
21:32:39.0645 3432 [ 0192BE332749769C7A7916924B4923AA ] msgpiowin32 C:\WINDOWS\System32\drivers\msgpiowin32.sys
21:32:39.0653 3432 msgpiowin32 - ok
21:32:39.0676 3432 mshidkmdf - ok
21:32:39.0713 3432 [ A36D7B0455C778CC4C29ADE5240CFA62 ] mshidumdf C:\WINDOWS\System32\drivers\mshidumdf.sys
21:32:39.0713 3432 mshidumdf - ok
21:32:39.0753 3432 msisadrv - ok
21:32:39.0761 3432 MSiSCSI - ok
21:32:39.0770 3432 msiserver - ok
21:32:39.0781 3432 MSKSSRV - ok
21:32:39.0813 3432 [ 3CC76285E075CD500589FAA82EA867BC ] MsLldp C:\WINDOWS\system32\drivers\mslldp.sys
21:32:39.0813 3432 MsLldp - ok
21:32:39.0821 3432 MSPCLOCK - ok
21:32:39.0821 3432 MSPQM - ok
21:32:39.0829 3432 MsRPC - ok
21:32:39.0876 3432 mssmbios - ok
21:32:39.0881 3432 MSTEE - ok
21:32:39.0913 3432 MTConfig - ok
21:32:39.0921 3432 Mup - ok
21:32:39.0929 3432 mvumis - ok
21:32:39.0981 3432 MySQL57 - ok
21:32:39.0981 3432 NativeWifiP - ok
21:32:40.0029 3432 [ C8C0B0E3147AFB52539B0EF7F85B40D1 ] NaturalAuthentication C:\WINDOWS\System32\NaturalAuth.dll
21:32:40.0045 3432 NaturalAuthentication - ok
21:32:40.0081 3432 [ 4CC8B4F760AFBAC6809C46986346F7FD ] NcaSvc C:\WINDOWS\System32\ncasvc.dll
21:32:40.0082 3432 NcaSvc - ok
21:32:40.0142 3432 [ 4E2BD0FC12B0A3040F6BCE7B6B3B58ED ] NcbService C:\WINDOWS\System32\ncbservice.dll
21:32:40.0148 3432 NcbService - ok
21:32:40.0200 3432 [ ECA9045B21D3DEA15B199C2A902D0931 ] NcdAutoSetup C:\WINDOWS\System32\NcdAutoSetup.dll
21:32:40.0205 3432 NcdAutoSetup - ok
21:32:40.0221 3432 ndfltr - ok
21:32:40.0245 3432 NDIS - ok
21:32:40.0280 3432 [ CE79D10BDFA2F304CB8357D7CB36738B ] NdisCap C:\WINDOWS\system32\drivers\ndiscap.sys
21:32:40.0282 3432 NdisCap - ok
21:32:40.0314 3432 [ 845371AB1E5E41A15D5F8D143544A5E2 ] NdisImPlatform C:\WINDOWS\system32\drivers\NdisImPlatform.sys
21:32:40.0314 3432 NdisImPlatform - ok
21:32:40.0330 3432 NdisTapi - ok
21:32:40.0338 3432 Ndisuio - ok
21:32:40.0362 3432 NdisVirtualBus - ok
21:32:40.0373 3432 NdisWan - ok
21:32:40.0378 3432 ndiswanlegacy - ok
21:32:40.0381 3432 ndproxy - ok
21:32:40.0435 3432 [ 8AF3C23D7CAE89BA301B1C242A995B8C ] Ndu C:\WINDOWS\system32\drivers\Ndu.sys
21:32:40.0443 3432 Ndu - ok
21:32:40.0490 3432 [ 76C4D5C98A808D8C8E0C46280036FAF8 ] Net Driver HPZ12 C:\Windows\System32\HPZinw12.dll
21:32:40.0498 3432 Net Driver HPZ12 - ok
21:32:40.0514 3432 NetAdapterCx - ok
21:32:40.0522 3432 NetBIOS - ok
21:32:40.0530 3432 NetBT - ok
21:32:40.0530 3432 Netlogon - ok
21:32:40.0581 3432 Netman - ok
21:32:40.0629 3432 [ 97DF2FD996CFD135C0E13A801D939265 ] netprofm C:\WINDOWS\System32\netprofmsvc.dll
21:32:40.0637 3432 netprofm - ok
21:32:40.0682 3432 NetSetupSvc - ok
21:32:40.0814 3432 [ DE64DCF58F1238448EE24FD0B50F7E11 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:32:40.0830 3432 NetTcpPortSharing - ok
21:32:40.0890 3432 netvsc - ok
21:32:40.0946 3432 [ 33BFA39C2B4137D0740E5D5A240C7826 ] NgcCtnrSvc C:\WINDOWS\System32\NgcCtnrSvc.dll
21:32:40.0954 3432 NgcCtnrSvc - ok
21:32:41.0006 3432 [ ACB99050E690203BE8CF2FDB6098C686 ] NgcSvc C:\WINDOWS\system32\ngcsvc.dll
21:32:41.0022 3432 NgcSvc - ok
21:32:41.0110 3432 [ 57BECA30181C7948B7D506EC81FD5EEC ] NitroDriverReadSpool9 C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe
21:32:41.0113 3432 NitroDriverReadSpool9 - ok
21:32:41.0130 3432 [ 2EF9F9A28CA7E0B5601ACF3FC7B78965 ] NitroUpdateService C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe
21:32:41.0134 3432 NitroUpdateService - ok
21:32:41.0167 3432 NlaSvc - ok
21:32:41.0232 3432 [ 0E04ABFDF6A48FE6B2BFEF37B858FFE9 ] nlsX86cc C:\windows\SysWOW64\NLSSRV32.EXE
21:32:41.0232 3432 nlsX86cc - ok
21:32:41.0256 3432 Npfs - ok
21:32:41.0306 3432 [ F4E3765FC412D5ED416B019D7B85E225 ] npsvctrig C:\WINDOWS\System32\drivers\npsvctrig.sys
21:32:41.0306 3432 npsvctrig - ok
21:32:41.0338 3432 nsi - ok
21:32:41.0338 3432 nsiproxy - ok
21:32:41.0346 3432 NTFS - ok
21:32:41.0354 3432 Null - ok
21:32:41.0390 3432 nvdimmn - ok
21:32:41.0438 3432 nvraid - ok
21:32:41.0462 3432 nvstor - ok
21:32:41.0582 3432 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
21:32:41.0590 3432 odserv - ok
21:32:41.0679 3432 [ 01585BF5C119939FB69A49B871B633A9 ] OneSyncSvc C:\WINDOWS\System32\APHostService.dll
21:32:41.0682 3432 OneSyncSvc - ok
21:32:41.0846 3432 [ BFAEDDE456C73BB28363D7176BB1820D ] OpenVPNService C:\Program Files (x86)\Disconnect\Disconnect Desktop\openvpn\bin\openvpnserv.exe
21:32:41.0846 3432 OpenVPNService - ok
21:32:41.0898 3432 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:32:41.0898 3432 ose - ok
21:32:41.0982 3432 [ 76379BDF8124612029E4D3975FD92EE6 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:32:41.0982 3432 ose64 - ok
21:32:42.0162 3432 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
21:32:42.0230 3432 osppsvc - ok
21:32:42.0290 3432 [ FAC53608467B67611EEF461A1D04E121 ] p2pimsvc C:\WINDOWS\system32\pnrpsvc.dll
21:32:42.0298 3432 p2pimsvc - ok
21:32:42.0338 3432 [ 26DB6BF55B4416A694096857AD3F9A25 ] p2psvc C:\WINDOWS
 
\system32\p2psvc.dll
21:32:42.0346 3432 p2psvc - ok
21:32:42.0414 3432 Parport - ok
21:32:42.0414 3432 partmgr - ok
21:32:42.0454 3432 [ 3059BB5452BDDE3EA51E056DB47B16E5 ] PcaSvc C:\WINDOWS\System32\pcasvc.dll
21:32:42.0462 3432 PcaSvc - ok
21:32:42.0462 3432 pci - ok
21:32:42.0498 3432 pciide - ok
21:32:42.0538 3432 pcmcia - ok
21:32:42.0546 3432 pcw - ok
21:32:42.0546 3432 pdc - ok
21:32:42.0590 3432 [ 20EA473E6AF7A5DEA70270EEA854BEE5 ] PEAUTH C:\WINDOWS\system32\drivers\peauth.sys
21:32:42.0601 3432 PEAUTH - ok
21:32:42.0645 3432 percsas2i - ok
21:32:42.0671 3432 percsas3i - ok
21:32:42.0781 3432 [ EC1C0A8C0694399153A2A741737EA586 ] PerfHost C:\WINDOWS\SysWow64\perfhost.exe
21:32:42.0782 3432 PerfHost - ok
21:32:42.0882 3432 [ EE41E131A3B177249A045B513B139A2D ] Pharos Systems ComTaskMaster C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe
21:32:42.0882 3432 Pharos Systems ComTaskMaster - ok
21:32:42.0946 3432 [ A7DFFA8356DD90C59C0ACFC67F321B8C ] PhoneSvc C:\WINDOWS\System32\PhoneService.dll
21:32:42.0954 3432 PhoneSvc - ok
21:32:43.0023 3432 [ 15E2B2DAB6BCCDA75D17CAFA63DCF729 ] PimIndexMaintenanceSvc C:\WINDOWS\System32\PimIndexMaintenance.dll
21:32:43.0023 3432 PimIndexMaintenanceSvc - ok
21:32:43.0099 3432 [ 0DE105CAF569F5A743777231DF752B67 ] pla C:\WINDOWS\system32\pla.dll
21:32:43.0134 3432 pla - ok
21:32:43.0163 3432 PlugPlay - ok
21:32:43.0212 3432 pmem - ok
21:32:43.0242 3432 [ D1A4DBB8A29F7FFC78378F47F9EA6B91 ] Pml Driver HPZ12 C:\Windows\System32\HPZipm12.dll
21:32:43.0242 3432 Pml Driver HPZ12 - ok
21:32:43.0291 3432 [ 7E5932AE798DD2EDD8DEB068016D7E92 ] PNPMEM C:\WINDOWS\System32\drivers\pnpmem.sys
21:32:43.0299 3432 PNPMEM - ok
21:32:43.0323 3432 [ E54F81476A85F994B3AC07D8695728E5 ] PNRPAutoReg C:\WINDOWS\system32\pnrpauto.dll
21:32:43.0331 3432 PNRPAutoReg - ok
21:32:43.0355 3432 [ FAC53608467B67611EEF461A1D04E121 ] PNRPsvc C:\WINDOWS\system32\pnrpsvc.dll
21:32:43.0355 3432 PNRPsvc - ok
21:32:43.0378 3432 PolicyAgent - ok
21:32:43.0407 3432 Power - ok
21:32:43.0415 3432 PptpMiniport - ok
21:32:43.0515 3432 [ 3EE7D7D7010DA28FB518FBDB6F57D494 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
21:32:43.0607 3432 PrintNotify - ok
21:32:43.0647 3432 [ 35BED149A249E74CE7BED2FFBB08B95E ] PrintWorkflowUserSvc C:\WINDOWS\System32\PrintWorkflowService.dll
21:32:43.0647 3432 PrintWorkflowUserSvc - ok
21:32:43.0707 3432 Processor - ok
21:32:43.0715 3432 ProfSvc - ok
21:32:43.0747 3432 [ 2C697DA5C9D5CEB1EDF8B2115244747A ] Psched C:\WINDOWS\system32\drivers\pacer.sys
21:32:43.0747 3432 Psched - ok
21:32:43.0806 3432 [ 3ED3608CB3C10B336915C4728901D1F3 ] PushToInstall C:\WINDOWS\system32\PushToInstall.dll
21:32:43.0806 3432 PushToInstall - ok
21:32:43.0846 3432 [ AEEF811001227F5E0B934605BCCCAF16 ] QWAVE C:\WINDOWS\system32\qwave.dll
21:32:43.0854 3432 QWAVE - ok
21:32:43.0898 3432 [ D5DC7C0024434AA97DF8BDACDE8CCA75 ] QWAVEdrv C:\WINDOWS\system32\drivers\qwavedrv.sys
21:32:43.0898 3432 QWAVEdrv - ok
21:32:43.0983 3432 [ 4E033A3D13F2D3611A7DF0A60CE090CB ] RalinkRegistryWriter C:\Program Files (x86)\ALFA\Common\RaRegistry.exe
21:32:43.0991 3432 RalinkRegistryWriter - ok
21:32:44.0015 3432 [ 1222BD405310F8B39D4EC28691E24F7A ] RalinkRegistryWriter64 C:\Program Files (x86)\ALFA\Common\RaRegistry64.exe
21:32:44.0015 3432 RalinkRegistryWriter64 - ok
21:32:44.0048 3432 Ramdisk - ok
21:32:44.0095 3432 [ 2977F7750EA2BECB3E623814D2C18800 ] RaMediaServer C:\Program Files (x86)\ALFA\Common\RaMediaServer.exe
21:32:44.0124 3432 RaMediaServer - ok
21:32:44.0128 3432 RasAcd - ok
21:32:44.0151 3432 RasAgileVpn - ok
21:32:44.0158 3432 RasAuto - ok
21:32:44.0162 3432 Rasl2tp - ok
21:32:44.0178 3432 RasMan - ok
21:32:44.0189 3432 RasPppoe - ok
21:32:44.0193 3432 RasSstp - ok
21:32:44.0198 3432 rdbss - ok
21:32:44.0234 3432 [ FEA5A36D3FB4485DF28AE6DB628565FE ] rdpbus C:\WINDOWS\System32\drivers\rdpbus.sys
21:32:44.0234 3432 rdpbus - ok
21:32:44.0291 3432 [ 0CE3C390080C535DC2628C10E505A7BE ] RDPDR C:\WINDOWS\system32\drivers\rdpdr.sys
21:32:44.0323 3432 RDPDR - ok
21:32:44.0380 3432 [ FF24EDAF6F71D28ED0A7BEE1A117F616 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
21:32:44.0382 3432 RdpVideoMiniport - ok
21:32:44.0423 3432 [ E92E4027F9384311BB11CA0E04FF5AC0 ] rdyboost C:\WINDOWS\system32\drivers\rdyboost.sys
21:32:44.0431 3432 rdyboost - ok
21:32:44.0455 3432 ReFS - ok
21:32:44.0455 3432 ReFSv1 - ok
21:32:44.0515 3432 [ AD79D258D70B2F38A36219613D5C84BB ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
21:32:44.0523 3432 RemoteAccess - ok
21:32:44.0555 3432 [ B758EBBCA86468EC5C4DD25F523CFC54 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
21:32:44.0563 3432 RemoteRegistry - ok
21:32:44.0623 3432 [ 22E8121518D5A6731649683A7B44DC52 ] RetailDemo C:\WINDOWS\system32\RDXService.dll
21:32:44.0631 3432 RetailDemo - ok
21:32:44.0683 3432 [ 8BD465B992D7C4A2975B33CBB47BFE25 ] RFCOMM C:\WINDOWS\System32\drivers\rfcomm.sys
21:32:44.0691 3432 RFCOMM - ok
21:32:44.0747 3432 [ 46F6CFDD9B9BB5587491E4464C062EAF ] rhproxy C:\WINDOWS\System32\drivers\rhproxy.sys
21:32:44.0755 3432 rhproxy - ok
21:32:44.0831 3432 [ FBA61BB4C484A01A655AFB18FF86C417 ] RichVideo64 C:\Program Files\CyberLink\Shared files\RichVideo64.exe
21:32:44.0831 3432 RichVideo64 - ok
21:32:44.0891 3432 [ F44789946F0FB462FDEEC031DA35426F ] RmSvc C:\WINDOWS\System32\RMapi.dll
21:32:44.0891 3432 RmSvc - ok
21:32:44.0923 3432 RpcEptMapper - ok
21:32:44.0963 3432 [ 324DFCB67E77B61C463D13312074DC3E ] RpcLocator C:\WINDOWS\system32\locator.exe
21:32:44.0963 3432 RpcLocator - ok
21:32:44.0972 3432 RpcSs - ok
21:32:45.0005 3432 [ E03381CA16456BD23168A4FA210DB9DE ] rspndr C:\WINDOWS\system32\drivers\rspndr.sys
21:32:45.0007 3432 rspndr - ok
21:32:45.0056 3432 [ 333224D4D25F9BCCA488E08345083E1C ] RTL8187 C:\WINDOWS\System32\drivers\rtl8187.sys
21:32:45.0064 3432 RTL8187 - ok
21:32:45.0111 3432 [ 05E8543E0D8C07535944FC0CB15E0DA0 ] RTSUER C:\WINDOWS\system32\Drivers\RtsUer.sys
21:32:45.0111 3432 RTSUER - ok
21:32:45.0264 3432 [ 993E6A15FD3EAFC280B8EBB396FA31B2 ] rtsuvc C:\WINDOWS\system32\DRIVERS\rtsuvc.sys
21:32:45.0416 3432 rtsuvc - ok
21:32:45.0482 3432 [ 04F486FD82926585A36F90F36E6FE311 ] s3cap C:\WINDOWS\System32\drivers\vms3cap.sys
21:32:45.0483 3432 s3cap - ok
21:32:45.0507 3432 SamSs - ok
21:32:45.0547 3432 sbp2port - ok
21:32:45.0584 3432 [ 8CFD122120A536633E09A73B8D3C500A ] SCardSvr C:\WINDOWS\System32\SCardSvr.dll
21:32:45.0592 3432 SCardSvr - ok
21:32:45.0646 3432 [ 98384E4CF4AF5FB50272252BCB53CBB9 ] ScDeviceEnum C:\WINDOWS\System32\ScDeviceEnum.dll
21:32:45.0652 3432 ScDeviceEnum - ok
21:32:45.0684 3432 [ 17B940A515E11491CB6F7EE5405D46E6 ] scfilter C:\WINDOWS\system32\DRIVERS\scfilter.sys
21:32:45.0684 3432 scfilter - ok
21:32:45.0732 3432 [ DD35B7ADEC669F9C0F02264C171010EB ] Schedule C:\WINDOWS\system32\schedsvc.dll
21:32:45.0748 3432 Schedule - ok
21:32:45.0791 3432 scmbus - ok
21:32:45.0831 3432 [ 3E321B08C212A75A442627CCFECE6FE7 ] SCPolicySvc C:\WINDOWS\System32\certprop.dll
21:32:45.0831 3432 SCPolicySvc - ok
21:32:45.0875 3432 [ AD7189E85A0801DE0507C610963A3CD0 ] ScpVBus C:\WINDOWS\System32\drivers\ScpVBus.sys
21:32:45.0877 3432 ScpVBus - ok
21:32:45.0924 3432 sdbus - ok
21:32:45.0976 3432 [ DDAFE3B7416A7123D3CCC71329895692 ] SDFRd C:\WINDOWS\System32\drivers\SDFRd.sys
21:32:45.0977 3432 SDFRd - ok
21:32:46.0016 3432 [ 7846A7D5091AA33E94B1E596FEDD56FE ] SDRSVC C:\WINDOWS\System32\SDRSVC.dll
21:32:46.0024 3432 SDRSVC - ok
21:32:46.0040 3432 sdstor - ok
21:32:46.0079 3432 [ 3054EFC2C4D7B5BA1A63EC9A0ACCD2CB ] seclogon C:\WINDOWS\system32\seclogon.dll
21:32:46.0084 3432 seclogon - ok
21:32:46.0133 3432 [ 95221238675951EF875CA806966B6E52 ] SecurityHealthService C:\WINDOWS\system32\SecurityHealthService.exe
21:32:46.0141 3432 SecurityHealthService - ok
21:32:46.0185 3432 [ 07F83829E7429E60298440CD1E601A6A ] semav6msr64 C:\WINDOWS\system32\drivers\semav6msr64.sys
21:32:46.0187 3432 semav6msr64 - ok
21:32:46.0236 3432 [ 47B3D55738119D20D66C2A90A4FF5A58 ] SEMgrSvc C:\WINDOWS\system32\SEMgrSvc.dll
21:32:46.0269 3432 SEMgrSvc - ok
21:32:46.0308 3432 [ 838311F91D921E6043FC37EE1C8663FC ] SENS C:\WINDOWS\System32\sens.dll
21:32:46.0316 3432 SENS - ok
21:32:46.0340 3432 Sense - ok
21:32:46.0400 3432 [ F32B8C2436BC1B126E56BEFF3F6794F2 ] SensorDataService C:\WINDOWS\System32\SensorDataService.exe
21:32:46.0440 3432 SensorDataService - ok
21:32:46.0508 3432 [ 7E079137434CCFA79830C4CB8DADE9DD ] SensorService C:\WINDOWS\system32\SensorService.dll
21:32:46.0516 3432 SensorService - ok
21:32:46.0564 3432 [ B77E3E237C0E9E1105D38C66FA4FB55F ] SensorsSimulatorDriver C:\WINDOWS\System32\drivers\WUDFRd.sys
21:32:46.0574 3432 SensorsSimulatorDriver - ok
21:32:46.0608 3432 [ EEF690B6CA64365E644D94151A340430 ] SensrSvc C:\WINDOWS\system32\sensrsvc.dll
21:32:46.0616 3432 SensrSvc - ok
21:32:46.0632 3432 SerCx - ok
21:32:46.0640 3432 SerCx2 - ok
21:32:46.0679 3432 Serenum - ok
21:32:46.0792 3432 Serial - ok
21:32:46.0832 3432 sermouse - ok
21:32:46.0878 3432 [ C5759C278D2E9414E214B19E637E7E4B ] SessionEnv C:\WINDOWS\system32\sessenv.dll
21:32:46.0884 3432 SessionEnv - ok
21:32:46.0924 3432 sfloppy - ok
21:32:46.0980 3432 [ 28F650228E6CE811C6B16DBA4AEC968D ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
21:32:46.0984 3432 SharedAccess - ok
21:32:47.0056 3432 [ 4132E596EA1E636577F4A06B79F5BDE9 ] SharedRealitySvc C:\WINDOWS\System32\SharedRealitySvc.dll
21:32:47.0064 3432 SharedRealitySvc - ok
21:32:47.0125 3432 [ 54331EDFBD25E4E6CCDADFDD0651E9B2 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
21:32:47.0137 3432 ShellHWDetection - ok
21:32:47.0192 3432 [ DE99B0C40B811F6F6A26302C472A153A ] shpamsvc C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll
21:32:47.0200 3432 shpamsvc - ok
21:32:47.0232 3432 [ D74D2ADF4782933E8E194E53B269D088 ] silabenm C:\WINDOWS\system32\DRIVERS\silabenm.sys
21:32:47.0232 3432 silabenm - ok
21:32:47.0278 3432 SiSRaid2 - ok
21:32:47.0293 3432 SiSRaid4 - ok
21:32:47.0349 3432 [ 52F7E8603E888E3DB0A8B3D1804098E9 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
21:32:47.0349 3432 SkypeUpdate - ok
21:32:47.0401 3432 smphost - ok
21:32:47.0433 3432 [ 3858F24BEB5B6509C8CF081CFC6FA45C ] SmsRouter C:\WINDOWS\system32\SmsRouterSvc.dll
21:32:47.0441 3432 SmsRouter - ok
21:32:47.0509 3432 [ F2C62B454A482D85F9B2B4BA0EB57EA0 ] SNMPTRAP C:\WINDOWS\System32\snmptrap.exe
21:32:47.0509 3432 SNMPTRAP - ok
21:32:47.0584 3432 spaceport - ok
21:32:47.0617 3432 [ C471C5C594518A6967E8D7AC63E69E17 ] SpatialGraphFilter C:\WINDOWS\system32\drivers\SpatialGraphFilter.sys
21:32:47.0617 3432 SpatialGraphFilter - ok
21:32:47.0617 3432 SpbCx - ok
21:32:47.0682 3432 [ 529E6847E6D5851B6447D13A7DA17B90 ] spectrum C:\WINDOWS\system32\spectrum.exe
21:32:47.0693 3432 spectrum - ok
21:32:47.0749 3432 [ 5EF8BE20B686346D1C994C6E1BE0133F ] Spooler C:\WINDOWS\System32\spoolsv.exe
21:32:47.0757 3432 Spooler - ok
21:32:47.0857 3432 [ 91410F020BD4A2002ADE4FFED42EB115 ] sppsvc C:\WINDOWS\system32\sppsvc.exe
21:32:47.0965 3432 sppsvc - ok
21:32:48.0049 3432 [ 8FD8EE71D7D639F85805EEE4ADB2AA15 ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
21:32:48.0049 3432 SQLWriter - ok
21:32:48.0077 3432 srv2 - ok
21:32:48.0093 3432 srvnet - ok
21:32:48.0133 3432 [ 3C200B296554EE90A36F1AE73328B833 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
21:32:48.0141 3432 SSDPSRV - ok
21:32:48.0174 3432 SstpSvc - ok
21:32:48.0204 3432 [ 5252D7BC56E5E0ED715AEA8FE173A455 ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
21:32:48.0207 3432 ssudmdm - ok
21:32:48.0301 3432 [ 4A6D36A265347207A9F550D4042D41D4 ] StateRepository C:\WINDOWS\system32\windows.staterepository.dll
21:32:48.0394 3432 StateRepository - ok
21:32:48.0493 3432 [ 03404CCE10E4A207953E954C2AF8D41E ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
21:32:48.0509 3432 Steam Client Service - ok
21:32:48.0533 3432 stexstor - ok
21:32:48.0557 3432 [ B064EA631FD0F7CE055E3CF6F2029562 ] StillCam C:\WINDOWS\system32\DRIVERS\serscan.sys
21:32:48.0557 3432 StillCam - ok
21:32:48.0618 3432 [ 3D8B5131F5A5E5C666E398F0207534E6 ] stisvc C:\WINDOWS\System32\wiaservc.dll
21:32:48.0626 3432 stisvc - ok
21:32:48.0686 3432 storahci - ok
21:32:48.0710 3432 storflt - ok
21:32:48.0726 3432 stornvme - ok
21:32:48.0758 3432 storqosflt - ok
21:32:48.0826 3432 [ A44C14105CD63DF1B22C3FAE21E33EC7 ] StorSvc C:\WINDOWS\system32\storsvc.dll
21:32:48.0842 3432 StorSvc - ok
21:32:48.0880 3432 storufs - ok
21:32:48.0885 3432 storvsc - ok
21:32:48.0894 3432 svsvc - ok
21:32:48.0942 3432 swenum - ok
21:32:48.0950 3432 swprv - ok
21:32:48.0977 3432 [ AC47DF20E5C2F6E88E3054C01C835954 ] Synth3dVsc C:\WINDOWS\System32\drivers\Synth3dVsc.sys
21:32:48.0979 3432 Synth3dVsc - ok
21:32:49.0026 3432 [ 7D290E1DF53AC21E8F49C1A4757C9A90 ] SysMain C:\WINDOWS\system32\sysmain.dll
21:32:49.0042 3432 SysMain - ok
21:32:49.0086 3432 SystemEventsBroker - ok
21:32:49.0163 3432 [ 9D7AED87C79A329BF04275719ADEA0F0 ] SystemUsageReportSvc_QUEENCREEK C:\Program Files\Intel Driver Update Utility\SUR\SurSvc.exe
21:32:49.0173 3432 SystemUsageReportSvc_QUEENCREEK - ok
21:32:49.0210 3432 [ 90242D74C3A4E03875022E859D924C35 ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
21:32:49.0218 3432 TabletInputService - ok
21:32:49.0234 3432 [ 7F5BFF7A547AE4BBF9CB8A80F844206C ] tap0901 C:\WINDOWS\System32\drivers\tap0901.sys
21:32:49.0242 3432 tap0901 - ok
21:32:49.0286 3432 [ B30E91D2D6485076CB48184632068C8F ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
21:32:49.0302 3432 TapiSrv - ok
21:32:49.0326 3432 Tcpip - ok
21:32:49.0326 3432 Tcpip6 - ok
21:32:49.0358 3432 [ 53E1732F597B205C767F2CCBD385B3E3 ] tcpipreg C:\WINDOWS\system32\drivers\tcpipreg.sys
21:32:49.0366 3432 tcpipreg - ok
21:32:49.0366 3432 tdx - ok
21:32:49.0494 3432 [ F6E13889706A231D0F827D384E7E98DF ] Te.Service C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe
21:32:49.0502 3432 Te.Service - ok
21:32:49.0534 3432 [ 37B3595CE87C4AFAFC8DEC7BFCA3A561 ] terminpt C:\WINDOWS\System32\drivers\terminpt.sys
21:32:49.0542 3432 terminpt - ok
21:32:49.0586 3432 [ FDFBF9E7FACF255443EAEBBB09D9B7FF ] TermService C:\WINDOWS\System32\termsrv.dll
21:32:49.0594 3432 TermService - ok
21:32:49.0634 3432 [ 70535AED79CD3F28CC5A889E6CC4C0D4 ] Themes C:\WINDOWS\system32\themeservice.dll
21:32:49.0642 3432 Themes - ok
21:32:49.0694 3432 [ EA497D0D777EC56925B155674C46F523 ] TieringEngineService C:\WINDOWS\system32\TieringEngineService.exe
21:32:49.0702 3432 TieringEngineService - ok
21:32:49.0742 3432 [ 3A2C26BACD4089D1C15E27DFF1B75A39 ] tiledatamodelsvc C:\WINDOWS\system32\tileobjserver.dll
21:32:49.0758 3432 tiledatamodelsvc - ok
21:32:49.0802 3432 [ C201B66A8AE8829B4C10AAB202477628 ] TimeBrokerSvc C:\WINDOWS\System32\TimeBrokerServer.dll
21:32:49.0810 3432 TimeBrokerSvc - ok
21:32:49.0886 3432 [ 653CF5F62F4362003DC62BFF114F3BC2 ] TokenBroker C:\WINDOWS\System32\TokenBroker.dll
21:32:49.0918 3432 TokenBroker - ok
21:32:49.0990 3432 [ F0EC67A5280737765805614DB4B72355 ] Tomcat8 C:\Program Files\Apache Software Foundation\Tomcat 8.5\bin\Tomcat8.exe
21:32:49.0992 3432 Tomcat8 - ok
21:32:50.0022 3432 TPM - ok
21:32:50.0054 3432 [ C910C744B7426416149B17225872E113 ] TrkWks C:\WINDOWS\System32\trkwks.dll
21:32:50.0062 3432 TrkWks - ok
21:32:50.0130 3432 TrustedInstaller - ok
21:32:50.0167 3432 [ F8D480C25AED818B35A4DEF270A98178 ] TsUsbFlt C:\WINDOWS\system32\drivers\tsusbflt.sys
21:32:50.0169 3432 TsUsbFlt - ok
21:32:50.0203 3432 [ D846F2F402784EFA02D3EE23411E6450 ] TsUsbGD C:\WINDOWS\System32\drivers\TsUsbGD.sys
21:32:50.0205 3432 TsUsbGD - ok
21:32:50.0237 3432 [ E9D941EFA0D29E0DBF43619F9BEF079E ] tunnel C:\WINDOWS\System32\drivers\tunnel.sys
21:32:50.0239 3432 tunnel - ok
21:32:50.0271 3432 [ 280CB70949637F92055E7AA292CBE9AE ] tzautoupdate C:\WINDOWS\system32\tzautoupdate.dll
21:32:50.0279 3432 tzautoupdate - ok
21:32:50.0338 3432 UASPStor - ok
21:32:50.0362 3432 [ DC2C8E804EE5F3A3E3BE224DC2786D8E ] UcmCx0101 C:\WINDOWS\system32\Drivers\UcmCx.sys
21:32:50.0362 3432 UcmCx0101 - ok
21:32:50.0402 3432 [ 4E549C7A4B82758F5EB02CD0C3B52683 ] UcmTcpciCx0101 C:\WINDOWS\system32\Drivers\UcmTcpciCx.sys
21:32:50.0410 3432 UcmTcpciCx0101 - ok
21:32:50.0462 3432 [ B9F2F61CEBB67158F4DCADDFD770D8B3 ] UcmUcsi C:\WINDOWS\System32\drivers\UcmUcsi.sys
21:32:50.0462 3432 UcmUcsi - ok
21:32:50.0470 3432 Ucx01000 - ok
21:32:50.0470 3432 UdeCx - ok
21:32:50.0478 3432 udfs - ok
21:32:50.0554 3432 UEFI - ok
21:32:50.0578 3432 [ 6CC6AC23788BFD3FFD3B690DE53B7DBF ] Ufx01000 C:\WINDOWS\system32\drivers\ufx01000.sys
21:32:50.0586 3432 Ufx01000 - ok
21:32:50.0640 3432 UfxChipidea - ok
21:32:50.0655 3432 ufxsynopsys - ok
21:32:50.0711 3432 [ 78855A4E0CDBA12694CED118C3660241 ] UI0Detect C:\WINDOWS\system32\UI0Detect.exe
21:32:50.0719 3432 UI0Detect - ok
21:32:50.0741 3432 umbus - ok
21:32:50.0779 3432 UmPass - ok
21:32:50.0803 3432 [ C085355C037A3F92EB1C5EE70C04E6CC ] UmRdpService C:\WINDOWS\System32\umrdp.dll
21:32:50.0811 3432 UmRdpService - ok
21:32:50.0863 3432 [ A916DBCF41877B83692779FA42E31640 ] UnistoreSvc C:\WINDOWS\System32\unistore.dll
21:32:50.0879 3432 UnistoreSvc - ok
21:32:50.0963 3432 [ 143ADDA7F5DF5FEA154070DFA80C0A54 ] upnphost C:\WINDOWS\System32\upnphost.dll
21:32:50.0971 3432 upnphost - ok
21:32:51.0047 3432 [ A91622515CE23FEEA94FB00E63AF6F62 ] UrsChipidea C:\WINDOWS\System32\drivers\urschipidea.sys
21:32:51.0047 3432 UrsChipidea - ok
21:32:51.0085 3432 [ 50F4832D72BBD2E459A840EDC07DAE75 ] UrsCx01000 C:\WINDOWS\system32\drivers\urscx01000.sys
21:32:51.0087 3432 UrsCx01000 - ok
21:32:51.0147 3432 [ 19F062E7DB43D6EC305FE45EDF234D53 ] UrsSynopsys C:\WINDOWS\System32\drivers\urssynopsys.sys
21:32:51.0149 3432 UrsSynopsys - ok
21:32:51.0195 3432 usbccgp - ok
21:32:51.0231 3432 [ 67C3A589F9108D301E457EF6A24A9029 ] usbcir C:\WINDOWS\System32\drivers\usbcir.sys
21:32:51.0233 3432 usbcir - ok
21:32:51.0263 3432 usbehci - ok
21:32:51.0263 3432 usbhub - ok
21:32:51.0271 3432 USBHUB3 - ok
21:32:51.0287 3432 usbohci - ok
21:32:51.0311 3432 [ A17E8090E6A40394389758381FB25977 ] usbprint C:\WINDOWS\System32\drivers\usbprint.sys
21:32:51.0311 3432 usbprint - ok
21:32:51.0327 3432 usbser - ok
21:32:51.0338 3432 USBSTOR - ok
21:32:51.0342 3432 usbuhci - ok
21:32:51.0346 3432 USBXHCI - ok
21:32:51.0411 3432 [ E3BE5BF63D92E1DF3E291FB8F3AB41FC ] UserDataSvc C:\WINDOWS\System32\userdataservice.dll
21:32:51.0447 3432 UserDataSvc - ok
21:32:51.0487 3432 UserManager - ok
21:32:51.0587 3432 [ A7E5EFF955B119D187E51EA6190E842B ] USER_ESRV_SVC_QUEENCREEK C:\Program Files\Intel\SUR\QUEENCREEK\esrv_svc.exe
21:32:51.0595 3432 USER_ESRV_SVC_QUEENCREEK - ok
21:32:51.0679 3432 [ 1B4BD3E370BE145D8C70CDBF0B0523F3 ] UsoSvc C:\WINDOWS\system32\usocore.dll
21:32:51.0719 3432 UsoSvc - ok
21:32:51.0744 3432 VaultSvc - ok
21:32:51.0827 3432 [ 32583DDC57974DCE56A18E3A8B9F1E74 ] VBoxDrv C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys
21:32:51.0840 3432 VBoxDrv - ok
21:32:51.0862 3432 [ F2FA7B72394A95A9211A20CA8445C1BC ] VBoxNetLwf C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys
21:32:51.0862 3432 VBoxNetLwf - ok
21:32:51.0926 3432 [ 95B03E778D7F0BB14A740AA9688EF773 ] VBoxUSBMon C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys
21:32:51.0926 3432 VBoxUSBMon - ok
21:32:52.0030 3432 vdrvroot - ok
21:32:52.0039 3432 vds - ok
21:32:52.0044 3432 VerifierExt - ok
21:32:52.0079 3432 vhdmp - ok
21:32:52.0079 3432 vhf - ok
21:32:52.0128 3432 vmbus - ok
21:32:52.0165 3432 VMBusHID - ok
21:32:52.0195 3432 [ E647B60AC4BE4BA33E3B237DD20D36E4 ] vmgid C:\WINDOWS\System32\drivers\vmgid.sys
21:32:52.0197 3432 vmgid - ok
21:32:52.0238 3432 [ 06C58C45D7EA3B2C9E3A6CB7D6B82311 ] vmicguestinterface C:\WINDOWS\System32\icsvc.dll
21:32:52.0243 3432 vmicguestinterface - ok
21:32:52.0247 3432 [ 06C58C45D7EA3B2C9E3A6CB7D6B82311 ] vmicheartbeat C:\WINDOWS\System32\icsvc.dll
21:32:52.0247 3432 vmicheartbeat - ok
21:32:52.0255 3432 [ 06C58C45D7EA3B2C9E3A6CB7D6B82311 ] vmickvpexchange C:\WINDOWS\System32\icsvc.dll
21:32:52.0255 3432 vmickvpexchange - ok
21:32:52.0295 3432 [ 7202704600182CDBBB12B4C14D2B1798 ] vmicrdv C:\WINDOWS\System32\icsvcext.dll
21:32:52.0303 3432 vmicrdv - ok
21:32:52.0311 3432 [ 06C58C45D7EA3B2C9E3A6CB7D6B82311 ] vmicshutdown C:\WINDOWS\System32\icsvc.dll
21:32:52.0311 3432 vmicshutdown - ok
21:32:52.0319 3432 [ 06C58C45D7EA3B2C9E3A6CB7D6B82311 ] vmictimesync C:\WINDOWS\System32\icsvc.dll
21:32:52.0319 3432 vmictimesync - ok
21:32:52.0327 3432 [ 06C58C45D7EA3B2C9E3A6CB7D6B82311 ] vmicvmsession C:\WINDOWS\System32\icsvc.dll
21:32:52.0335 3432 vmicvmsession - ok
21:32:52.0341 3432 [ 7202704600182CDBBB12B4C14D2B1798 ] vmicvss C:\WINDOWS\System32\icsvcext.dll
21:32:52.0345 3432 vmicvss - ok
21:32:52.0371 3432 vnvdimm - ok
21:32:52.0418 3432 volmgr - ok
21:32:52.0426 3432 volmgrx - ok
21:32:52.0426 3432 volsnap - ok
21:32:52.0446 3432 volume - ok
21:32:52.0495 3432 [ D37ECF55A84CA338A0430B0D0249ABA6 ] vpci C:\WINDOWS\System32\drivers\vpci.sys
21:32:52.0495 3432 vpci - ok
21:32:52.0547 3432 [ ED1F4BDF68C649C6F79A02502BB6C9BC ] VsEtwService120 C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe
21:32:52.0547 3432 VsEtwService120 - ok
21:32:52.0587 3432 vsmraid - ok
21:32:52.0603 3432 VSS - ok
21:32:52.0679 3432 [ 685DDB31CA2549B2A115E67C9BBD88F7 ] VSStandardCollectorService140 C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe
21:32:52.0679 3432 VSStandardCollectorService140 - ok
21:32:52.0703 3432 VSTXRAID - ok
21:32:52.0703 3432 vwifibus - ok
21:32:52.0719 3432 vwififlt - ok
21:32:52.0719 3432 vwifimp - ok
21:32:52.0741 3432 W32Time - ok
21:32:52.0755 3432 WacomPen - ok
21:32:52.0803 3432 [ FB612E4C3F80A77A64003CF1063CDA4A ] WalletService C:\WINDOWS\system32\WalletService.dll
21:32:52.0811 3432 WalletService - ok
21:32:53.0055 3432 [ 3D2471B3B85F6DF28D7B066DE39143F7 ] Wallpaper Engine Service C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\bin\wallpaperservice32_c.exe
21:32:53.0055 3432 Wallpaper Engine Service - ok
21:32:53.0079 3432 wanarp - ok
21:32:53.0079 3432 wanarpv6 - ok
21:32:53.0123 3432 [ 9176BE83F43DF82B05D39D4BD8CCEC8F ] WarpJITSvc C:\WINDOWS\System32\Windows.WARP.JITService.dll
21:32:53.0131 3432 WarpJITSvc - ok
21:32:53.0150 3432 wbengine - ok
21:32:53.0195 3432 [ EBAABBEC385D9514111C9D4C91E39E92 ] WbioSrvc C:\WINDOWS\System32\wbiosrvc.dll
21:32:53.0213 3432 WbioSrvc - ok
21:32:53.0279 3432 [ 75D9C40DDC0A3C29A0996AFBC600B360 ] wcifs C:\WINDOWS\system32\drivers\wcifs.sys
21:32:53.0279 3432 wcifs - ok
21:32:53.0303 3432 [ 7EAD075BCBAC400FDD39D30C304896EF ] Wcmsvc C:\WINDOWS\System32\wcmsvc.dll
21:32:53.0319 3432 Wcmsvc - ok
21:32:53.0347 3432 wcncsvc - ok
21:32:53.0379 3432 [ C0C9E26C479EF413BF67C87FF077E0A7 ] wcnfs C:\WINDOWS\system32\drivers\wcnfs.sys
21:32:53.0379 3432 wcnfs - ok
21:32:53.0427 3432 [ 5636DABA2DC86DFACC00DDE411ADD9D1 ] WdBoot C:\WINDOWS\system32\drivers\WdBoot.sys
21:32:53.0427 3432 WdBoot - ok
21:32:53.0463 3432 Wdf01000 - ok
21:32:53.0503 3432 [ 52D5CFB2FF554C3C7CDDDB7BD1C39304 ] WdFilter C:\WINDOWS\system32\drivers\WdFilter.sys
21:32:53.0503 3432 WdFilter - ok
21:32:53.0555 3432 [ 1A2C1F84CB9323916A9AAFCDAD638663 ] WdiServiceHost C:\WINDOWS\system32\wdi.dll
21:32:53.0563 3432 WdiServiceHost - ok
21:32:53.0571 3432 [ 1A2C1F84CB9323916A9AAFCDAD638663 ] WdiSystemHost C:\WINDOWS\system32\wdi.dll
21:32:53.0571 3432 WdiSystemHost - ok
21:32:53.0579 3432 wdiwifi - ok
21:32:53.0627 3432 [ 0AC06F578A0FC67D3EF4029F8A816A86 ] WdNisDrv C:\WINDOWS\system32\Drivers\WdNisDrv.sys
21:32:53.0627 3432 WdNisDrv - ok
21:32:53.0671 3432 WdNisSvc - ok
21:32:53.0703 3432 [ 69C2081327D6DAF8F6E82FCF43700B5E ] wdnsfltr C:\WINDOWS\system32\drivers\wdnsfltr.sys
21:32:53.0703 3432 wdnsfltr - ok
21:32:53.0747 3432 [ CFA1D23F4FDDDC4BAF71A929608A948D ] WebClient C:\WINDOWS\System32\webclnt.dll
21:32:53.0755 3432 WebClient - ok
21:32:53.0787 3432 [ 353BB57F8948DD4FBF3AB4F21BB576E1 ] Wecsvc C:\WINDOWS\system32\wecsvc.dll
21:32:53.0795 3432 Wecsvc - ok
21:32:53.0824 3432 [ FFF9C9108B148199A7C1E20166824887 ] WEPHOSTSVC C:\WINDOWS\system32\wephostsvc.dll
21:32:53.0830 3432 WEPHOSTSVC - ok
21:32:53.0871 3432 [ 502C72A9AAED060AC24A42D273950143 ] wercplsupport C:\WINDOWS\System32\wercplsupport.dll
21:32:53.0879 3432 wercplsupport - ok
21:32:53.0911 3432 WerSvc - ok
21:32:53.0979 3432 [ 5B6D8315FEB5E978FF302989BFA9A8D2 ] WFDSConMgrSvc C:\WINDOWS\System32\wfdsconmgrsvc.dll
21:32:53.0987 3432 WFDSConMgrSvc - ok
21:32:54.0040 3432 [ 2EAA82F8F61B8C64FB9BC441DEDD52A6 ] WFPLWFS C:\WINDOWS\system32\drivers\wfplwfs.sys
21:32:54.0043 3432 WFPLWFS - ok
21:32:54.0080 3432 [ 6C4E51EA51768C057D04E53CC1FD9985 ] WiaRpc C:\WINDOWS\System32\wiarpc.dll
21:32:54.0088 3432 WiaRpc - ok
21:32:54.0100 3432 WIMMount - ok
21:32:54.0103 3432 WinDefend - ok
21:32:54.0156 3432 [ 021F17B516D564F9FE88B16058107A62 ] WindowsTrustedRT C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys
21:32:54.0158 3432 WindowsTrustedRT - ok
21:32:54.0227 3432 [ E357B92900181FDC310EB9ADC15A5370 ] WindowsTrustedRTProxy C:\WINDOWS\system32\drivers\WindowsTrustedRTProxy.sys
21:32:54.0227 3432 WindowsTrustedRTProxy - ok
21:32:54.0256 3432 [ 82597A56652EB73A95484ADA65EB532B ] WinDriver6 C:\WINDOWS\system32\drivers\windrvr6.sys
21:32:54.0264 3432 WinDriver6 - ok
21:32:54.0312 3432 WinHttpAutoProxySvc - ok
21:32:54.0348 3432 WinMad - ok
21:32:54.0404 3432 Winmgmt - ok
21:32:54.0434 3432 [ DBC1C0C7486C61E24E329792D3DD75BA ] WinNat C:\WINDOWS\system32\drivers\winnat.sys
21:32:54.0436 3432 WinNat - ok
21:32:54.0504 3432 [ C585B57648F853D530EF2AFE4013E7D5 ] WinRM C:\WINDOWS\system32\WsmSvc.dll
21:32:54.0548 3432 WinRM - ok
21:32:54.0604 3432 [ 567C3D85E0DBEC5FC69D332FE2902FE2 ] WINUSB C:\WINDOWS\System32\drivers\WinUSB.SYS
21:32:54.0604 3432 WINUSB - ok
21:32:54.0648 3432 WinVerbs - ok
21:32:54.0688 3432 wisvc - ok
21:32:54.0712 3432 WlanSvc - ok
21:32:54.0764 3432 [ 98108C9007D21C78677E74A46CBFAE18 ] wlidsvc C:\WINDOWS\system32\wlidsvc.dll
21:32:54.0812 3432 wlidsvc - ok
21:32:54.0880 3432 [ 46C790F950CAEC22E7D6FBAAD5CEBDF4 ] wlpasvc C:\WINDOWS\System32\lpasvc.dll
21:32:54.0904 3432 wlpasvc - ok
21:32:54.0928 3432 WmiAcpi - ok
21:32:54.0948 3432 wmiApSrv - ok
21:32:54.0972 3432 WMPNetworkSvc - ok
21:32:54.0988 3432 [ 7A44ACCC18BBD5CDD7C3471BC4F0ABE6 ] Wof C:\WINDOWS\system32\drivers\Wof.sys
21:32:54.0996 3432 Wof - ok
21:32:55.0056 3432 [ 8AFFCD9A7CA01B2CB050192E70E34A54 ] workfolderssvc C:\WINDOWS\system32\workfolderssvc.dll
21:32:55.0104 3432 workfolderssvc - ok
21:32:55.0156 3432 [ F31BE78C161AB679601AE19D85BCAA4C ] WPDBusEnum C:\WINDOWS\system32\wpdbusenum.dll
21:32:55.0164 3432 WPDBusEnum - ok
21:32:55.0180 3432 [ 8D6E4F10113CCF64623F81374444B025 ] WpdUpFltr C:\WINDOWS\system32\drivers\WpdUpFltr.sys
21:32:55.0188 3432 WpdUpFltr - ok
21:32:55.0300 3432 [ 43D57379F4CECADE7DBC80DEF4AEB9AC ] WpnService C:\WINDOWS\system32\WpnService.dll
21:32:55.0358 3432 WpnService - ok
21:32:55.0416 3432 [ 46938946DD90EE52CB11489807FAE184 ] WpnUserService C:\WINDOWS\System32\WpnUserService.dll
21:32:55.0424 3432 WpnUserService - ok
21:32:55.0448 3432 ws2ifsl - ok
21:32:55.0484 3432 [ 87FF7EDE4E03BDA835365FF3D75AC1CE ] wscsvc C:\WINDOWS\System32\wscsvc.dll
21:32:55.0492 3432 wscsvc - ok
21:32:55.0548 3432 [ A394C473BFA7C1A47D2E1DFEB96E33B7 ] WSDPrintDevice C:\WINDOWS\System32\drivers\WSDPrint.sys
21:32:55.0558 3432 WSDPrintDevice - ok
21:32:55.0600 3432 [ 216F35A194ACA645095A7BEF66B6D2F5 ] WSDScan C:\WINDOWS\system32\DRIVERS\WSDScan.sys
21:32:55.0600 3432 WSDScan - ok
21:32:55.0600 3432 WSearch - ok
21:32:55.0632 3432 [ 72B4E9DF6456C43C42A1419B09486045 ] wsvd C:\WINDOWS\system32\DRIVERS\wsvd.sys
21:32:55.0632 3432 wsvd - ok
21:32:55.0708 3432 [ A76A0DEC3FCC6FFA170132FA449C541C ] wuauserv C:\WINDOWS\system32\wuaueng.dll
21:32:55.0761 3432 wuauserv - ok
21:32:55.0816 3432 [ 245A8EF1E9D1B8FA2C1C7EC453A6A5A3 ] WudfPf C:\WINDOWS\system32\drivers\WudfPf.sys
21:32:55.0824 3432 WudfPf - ok
21:32:55.0868 3432 [ B77E3E237C0E9E1105D38C66FA4FB55F ] WUDFRd C:\WINDOWS\System32\drivers\WUDFRd.sys
21:32:55.0868 3432 WUDFRd - ok
21:32:55.0876 3432 [ B77E3E237C0E9E1105D38C66FA4FB55F ] WUDFWpdFs C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
21:32:55.0876 3432 WUDFWpdFs - ok
21:32:55.0884 3432 [ B77E3E237C0E9E1105D38C66FA4FB55F ] WUDFWpdMtp C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
21:32:55.0884 3432 WUDFWpdMtp - ok
21:32:55.0948 3432 [ AB91BDE8F59AEFCFC6488F4F49E555F2 ] WwanSvc C:\WINDOWS\System32\wwansvc.dll
21:32:55.0984 3432 WwanSvc - ok
21:32:56.0032 3432 [ B5A1C6270815BA6BAB281EB72A977F16 ] xbgm C:\WINDOWS\system32\xbgmsvc.exe
21:32:56.0032 3432 xbgm - ok
21:32:56.0092 3432 [ DDEE5D4FCC0209429DA56B1375AB3B32 ] XblAuthManager C:\WINDOWS\System32\XblAuthManager.dll
21:32:56.0108 3432 XblAuthManager - ok
21:32:56.0184 3432 [ 7CF531B9FFD55F50CB50032BBE6DF9FB ] XblGameSave C:\WINDOWS\System32\XblGameSave.dll
21:32:56.0216 3432 XblGameSave - ok
21:32:56.0284 3432 [ 817EB4C97FA7DDBFE95F339EF3FF9CCD ] xboxgip C:\WINDOWS\System32\drivers\xboxgip.sys
21:32:56.0284 3432 xboxgip - ok
21:32:56.0316 3432 [ CC96C7DA52CB5A344962B5E6495F8ABE ] XboxGipSvc C:\WINDOWS\System32\XboxGipSvc.dll
21:32:56.0316 3432 XboxGipSvc - ok
21:32:56.0368 3432 [ 65D1561339EBD7EFE175C993D9CDC60D ] XboxNetApiSvc C:\WINDOWS\system32\XboxNetApiSvc.dll
21:32:56.0400 3432 XboxNetApiSvc - ok
21:32:56.0440 3432 [ B3A0EA676090FCF62046039C5C941D7F ] xinputhid C:\WINDOWS\System32\drivers\xinputhid.sys
21:32:56.0448 3432 xinputhid - ok
21:32:56.0508 3432 [ 86B8B1F5C1189D68B07666784BE882FE ] ZAtheros Bt and Wlan Coex Agent C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
21:32:56.0516 3432 ZAtheros Bt and Wlan Coex Agent - ok
21:32:56.0516 3432 ================ Scan global ===============================
21:32:56.0600 3432 [Global] - ok
21:32:56.0600 3432 ================ Scan MBR ==================================
21:32:56.0624 3432 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
21:32:56.0669 3432 \Device\Harddisk0\DR0 - ok
21:32:56.0677 3432 ================ Scan VBR ==================================
21:32:56.0693 3432 [ 9585074C263743A8649C945D51CB546A ] \Device\Harddisk0\DR0\Partition1
21:32:56.0693 3432 \Device\Harddisk0\DR0\Partition1 - ok
21:32:56.0701 3432 [ D0C281F365BC6F3AE57CCB32AE59DB3F ] \Device\Harddisk0\DR0\Partition2
21:32:56.0701 3432 \Device\Harddisk0\DR0\Partition2 - ok
21:32:56.0709 3432 [ 6EC0C904A7F856B3CAFD5815A5AE45A7 ] \Device\Harddisk0\DR0\Partition3
21:32:56.0709 3432 \Device\Harddisk0\DR0\Partition3 - ok
21:32:56.0717 3432 [ 2D524F05766D084E9BC1747B63390F77 ] \Device\Harddisk0\DR0\Partition4
21:32:56.0717 3432 \Device\Harddisk0\DR0\Partition4 - ok
21:32:56.0725 3432 [ 5C5A0241156487F85E8BE091A3F43F26 ] \Device\Harddisk0\DR0\Partition5
21:32:56.0725 3432 \Device\Harddisk0\DR0\Partition5 - ok
21:32:56.0749 3432 [ 60C76E365449AD2C84099DE7D8A882D9 ] \Device\Harddisk0\DR0\Partition6
21:32:56.0749 3432 \Device\Harddisk0\DR0\Partition6 - ok
21:32:56.0765 3432 [ 51F4FAA45347D3F1DDB7E6FDD5125399 ] \Device\Harddisk0\DR0\Partition7
21:32:56.0766 3432 \Device\Harddisk0\DR0\Partition7 - ok
21:32:56.0766 3432 ============================================================
21:32:56.0767 3432 Scan finished
21:32:56.0767 3432 ============================================================
21:32:56.0777 10400 Detected object count: 2
21:32:56.0777 10400 Actual detected object count: 2
21:33:49.0360 10400 MpKsl90967e8f ( HiddenService.Multi.Generic ) - skipped by user
21:33:49.0360 10400 MpKsl90967e8f ( HiddenService.Multi.Generic ) - User select action: Skip
21:33:49.0361 10400 MpKsl95e07077 ( HiddenService.Multi.Generic ) - skipped by user
21:33:49.0361 10400 MpKsl95e07077 ( HiddenService.Multi.Generic ) - User select action: Skip
 
Welcome aboard

Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

============================================

Your FRST logs are totally mixed up and impossible for me to read.
Please repost them in correct order.
 
Status
Not open for further replies.
Back