(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-11-20] (IDT, Inc.)
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [41664 2013-11-20] (Hewlett-Packard )
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [18248 2013-05-14] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3486520 2017-07-12] (Dropbox, Inc.)
HKLM-x32\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [4567720 2015-10-28] (Fitbit, Inc.)
HKLM\...\Policies\Explorer: [0] 0
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [4567720 2015-10-28] (Fitbit, Inc.)
Startup: C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Seagate Product Registration.lnk [2017-08-18]
ShortcutTarget: Seagate Product Registration.lnk -> C:\Users\AIRWORX 2\AppData\Roaming\Leadertech\PowerRegister\Seagate Product Registration.exe (Leader Technologies/Seagate)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Tcpip\..\Interfaces\{3b0572ca-8981-41c6-8b49-4de723fbd9b7}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Tcpip\..\Interfaces\{d9ff143d-a6fe-4d5a-b3c0-c2abdb37d13c}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPDSK13/1
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://
www.google.com/
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK13/1
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-02-25] (HP)
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDFViewer\Bin\PlusIEContextMenu.dll [2011-06-30] (Zeon Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-05-24] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: ZeonIEEventHelper Class -> {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} -> C:\Program Files (x86)\Nuance\PDFCreate\Bin\ZeonIEFavClient.dll [2011-03-26] (Zeon Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-24] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-02-25] (HP)
Toolbar: HKLM-x32 - DocuCom PDF - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files (x86)\Nuance\PDFCreate\Bin\ZeonIEFavClient.dll [2011-03-26] (Zeon Corporation)
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1499697116239
DPF: HKLM-x32 {D66F9BB1-7D8E-4A96-9166-20FCC91CBFE9} hxxp://99.7.214.118/FDSH_DVR.CAB
DPF: HKLM-x32 {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} hxxps://secure.logmein.com//activex/ractrl.cab?lmi=3563
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-24] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-29] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-07-26] (Adobe Systems Inc.)
FF Plugin-x32: ZEON/PDF,version=2.0 -> C:\Program Files (x86)\Nuance\PDFViewer\bin\nppdf.dll [2011-07-15] (Zeon Corporation)
Chrome:
=======
CHR DefaultProfile: Profile 10
CHR StartupUrls: Profile 10 -> "hxxps://
www.bleepingcomputer.com/forums/f/22/virus-trojan-spyware-and-malware-removal-logs/","hxxps://
www.google.com/","hxxps://productforums.google.com/forum/#!topic/chrome/KobCsRA5DC4"
CHR Profile: C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-07-28]
CHR Profile: C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 10 [2017-08-26]
CHR Extension: (Google Slides) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 10\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-07-28]
CHR Extension: (Google Docs) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 10\Extensions\aohghmighlieiainnegkcijnfilokake [2017-07-28]
CHR Extension: (Google Drive) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 10\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-07-28]
CHR Extension: (YouTube) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 10\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-07-28]
CHR Extension: (Google Sheets) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 10\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-07-28]
CHR Extension: (Google Docs Offline) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 10\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-07-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 10\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Gmail) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 10\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-07-28]
CHR Extension: (Chrome Media Router) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 10\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-08]
CHR Profile: C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\System Profile [2017-07-28]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeActiveFileMonitor4.0; C:\Program Files (x86)\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe [102400 2005-09-09] () [File not signed]
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
S3 AJRouter; C:\WINDOWS\System32\AJRouter.dll [24576 2017-03-18] (Microsoft Corporation) [File not signed]
S3 ALG; C:\WINDOWS\System32\alg.exe [92672 2017-03-18] (Microsoft Corporation) [File not signed]
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [351944 2015-11-04] (Advanced Micro Devices, Inc.)
R2 AppHostSvc; C:\WINDOWS\system32\inetsrv\apphostsvc.dll [64512 2017-07-14] (Microsoft Corporation) [File not signed]
R2 AppHostSvc; C:\WINDOWS\SysWOW64\inetsrv\apphostsvc.dll [56832 2017-07-14] (Microsoft Corporation) [File not signed]
S3 AppIDSvc; C:\WINDOWS\System32\appidsvc.dll [120320 2017-03-18] (Microsoft Corporation) [File not signed]
R3 Appinfo; C:\WINDOWS\System32\appinfo.dll [138752 2017-03-18] (Microsoft Corporation) [File not signed]
S3 AppReadiness; C:\WINDOWS\system32\AppReadiness.dll [585216 2017-07-14] (Microsoft Corporation) [File not signed]
S3 AppXSvc; C:\WINDOWS\system32\appxdeploymentserver.dll [2804736 2017-07-14] (Microsoft Corporation) [File not signed]
R2 AudioEndpointBuilder; C:\WINDOWS\System32\AudioEndpointBuilder.dll [625152 2017-07-14] (Microsoft Corporation) [File not signed]
R2 Audiosrv; C:\WINDOWS\System32\Audiosrv.dll [1357824 2017-07-14] (Microsoft Corporation) [File not signed]
S3 AxInstSV; C:\WINDOWS\System32\AxInstSV.dll [111616 2017-03-18] (Microsoft Corporation) [File not signed]
S3 BDESVC; C:\WINDOWS\System32\bdesvc.dll [385536 2017-03-18] (Microsoft Corporation) [File not signed]
R2 BFE; C:\WINDOWS\System32\bfe.dll [815616 2017-03-18] (Microsoft Corporation) [File not signed]
S3 BITS; C:\WINDOWS\System32\qmgr.dll [1159680 2017-03-18] (Microsoft Corporation) [File not signed]
R2 BrokerInfrastructure; C:\WINDOWS\System32\bisrv.dll [847872 2017-07-14] (Microsoft Corporation) [File not signed]
S3 Browser; C:\WINDOWS\System32\browser.dll [133120 2017-03-18] (Microsoft Corporation) [File not signed]
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed]
S3 BthHFSrv; C:\WINDOWS\System32\BthHFSrv.dll [431616 2017-03-18] (Microsoft Corporation) [File not signed]
S3 bthserv; C:\WINDOWS\system32\bthserv.dll [154112 2017-03-18] (Microsoft Corporation) [File not signed]
R2 CDPSvc; C:\WINDOWS\System32\CDPSvc.dll [970240 2017-07-14] (Microsoft Corporation) [File not signed]
S2 CDPUserSvc; C:\WINDOWS\System32\CDPUserSvc.dll [524288 2017-03-18] (Microsoft Corporation) [File not signed]
S3 CertPropSvc; C:\WINDOWS\System32\certprop.dll [189952 2017-07-14] (Microsoft Corporation) [File not signed]
R2 CryptSvc; C:\WINDOWS\system32\cryptsvc.dll [94720 2017-03-18] (Microsoft Corporation) [File not signed]
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-08-24] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-08-24] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [49992 2017-07-12] (Dropbox, Inc.)
R2 DcomLaunch; C:\WINDOWS\system32\rpcss.dll [1085440 2017-07-14] (Microsoft Corporation) [File not signed]
S3 defragsvc; C:\WINDOWS\System32\defragsvc.dll [489984 2017-03-18] (Microsoft Corporation) [File not signed]
R2 DeviceAssociationService; C:\WINDOWS\system32\das.dll [455168 2017-03-18] (Microsoft Corporation) [File not signed]
R3 DeviceInstall; C:\WINDOWS\system32\umpnpmgr.dll [114688 2017-03-18] (Microsoft Corporation) [File not signed]
S3 DevicesFlowUserSvc; C:\WINDOWS\System32\DevicesFlowBroker.dll [689152 2017-03-18] (Microsoft Corporation) [File not signed]
S3 DevQueryBroker; C:\WINDOWS\system32\DevQueryBroker.dll [33792 2017-03-18] (Microsoft Corporation) [File not signed]
R2 Dhcp; C:\WINDOWS\system32\dhcpcore.dll [365568 2017-03-18] (Microsoft Corporation) [File not signed]
R2 Dhcp; C:\WINDOWS\SysWOW64\dhcpcore.dll [304128 2017-03-18] (Microsoft Corporation) [File not signed]
S3 diagnosticshub.standardcollector.service; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [86528 2017-03-18] (Microsoft Corporation) [File not signed]
R2 DiagTrack; C:\WINDOWS\system32\diagtrack.dll [2516480 2017-07-14] (Microsoft Corporation) [File not signed]
S3 DmEnrollmentSvc; C:\WINDOWS\system32\Windows.Internal.Management.dll [536064 2017-07-14] (Microsoft Corporation) [File not signed]
S3 DmEnrollmentSvc; C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll [394240 2017-07-14] (Microsoft Corporation) [File not signed]
S3 dmwappushservice; C:\WINDOWS\system32\dmwappushsvc.dll [55296 2017-03-18] (Microsoft Corporation) [File not signed]
R2 Dnscache; C:\WINDOWS\System32\dnsrslvr.dll [282624 2017-03-18] (Microsoft Corporation) [File not signed]
R2 DoSvc; C:\WINDOWS\system32\dosvc.dll [1305088 2017-07-14] (Microsoft Corporation) [File not signed]
S3 dot3svc; C:\WINDOWS\System32\dot3svc.dll [252416 2017-03-18] (Microsoft Corporation) [File not signed]
R2 DPS; C:\WINDOWS\system32\dps.dll [168448 2017-03-18] (Microsoft Corporation) [File not signed]
S3 DsmSvc; C:\WINDOWS\System32\DeviceSetupManager.dll [233984 2017-03-18] (Microsoft Corporation) [File not signed]
S3 DsSvc; C:\WINDOWS\System32\DsSvc.dll [149504 2017-03-18] (Microsoft Corporation) [File not signed]
R2 DusmSvc; C:\WINDOWS\System32\dusmsvc.dll [302592 2017-03-18] (Microsoft Corporation) [File not signed]
S3 EapHost; C:\WINDOWS\System32\eapsvc.dll [108032 2017-03-18] (Microsoft Corporation) [File not signed]
S3 EFS; C:\WINDOWS\system32\efssvc.dll [57344 2017-03-18] (Microsoft Corporation) [File not signed]
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2625368 2017-08-09] (ESET)
S3 embeddedmode; C:\WINDOWS\System32\embeddedmodesvc.dll [149504 2017-07-14] (Microsoft Corporation) [File not signed]
R2 EMET_Service; C:\Program Files (x86)\EMET 5.5\EMET_Service.exe [33464 2016-11-08] (Microsoft Corporation)
S3 EntAppSvc; C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll [301056 2017-07-14] (Microsoft Corporation) [File not signed]
R2 EventLog; C:\WINDOWS\System32\wevtsvc.dll [1737216 2017-03-18] (Microsoft Corporation) [File not signed]
R2 EventSystem; C:\WINDOWS\system32\es.dll [452096 2017-03-18] (Microsoft Corporation) [File not signed]
R2 EventSystem; C:\WINDOWS\SysWOW64\es.dll [331776 2017-03-18] (Microsoft Corporation) [File not signed]
S3 Fax; C:\WINDOWS\system32\fxssvc.exe [637440 2017-03-18] (Microsoft Corporation) [File not signed]
R3 fdPHost; C:\WINDOWS\system32\fdPHost.dll [20992 2017-03-18] (Microsoft Corporation) [File not signed]
R3 FDResPub; C:\WINDOWS\system32\fdrespub.dll [34816 2017-03-18] (Microsoft Corporation) [File not signed]
S3 fhsvc; C:\WINDOWS\system32\fhsvc.dll [121856 2017-03-18] (Microsoft Corporation) [File not signed]
R2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [5906088 2015-10-28] (Fitbit, Inc.)
R2 FontCache; C:\WINDOWS\system32\FntCache.dll [1888256 2017-07-14] (Microsoft Corporation) [File not signed]
S4 FrameServer; C:\WINDOWS\system32\FrameServer.dll [600064 2017-07-14] (Microsoft Corporation) [File not signed]
R2 gpsvc; C:\WINDOWS\System32\gpsvc.dll [1269248 2017-03-18] (Microsoft Corporation) [File not signed]
R3 hidserv; C:\WINDOWS\system32\hidserv.dll [34304 2017-03-18] (Microsoft Corporation) [File not signed]
R3 hidserv; C:\WINDOWS\SysWOW64\hidserv.dll [29696 2017-03-18] (Microsoft Corporation) [File not signed]
S3 HomeGroupListener; C:\WINDOWS\system32\ListSvc.dll [269312 2017-03-18] (Microsoft Corporation) [File not signed]
R3 HomeGroupProvider; C:\WINDOWS\system32\provsvc.dll [463360 2017-03-18] (Microsoft Corporation) [File not signed]
R3 HomeGroupProvider; C:\WINDOWS\SysWOW64\provsvc.dll [396288 2017-03-18] (Microsoft Corporation) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [321896 2017-07-06] (HP Inc.)
S3 icssvc; C:\WINDOWS\System32\tetheringservice.dll [210432 2017-03-18] (Microsoft Corporation) [File not signed]
R2 IKEEXT; C:\WINDOWS\System32\ikeext.dll [934912 2017-03-18] (Microsoft Corporation) [File not signed]
R2 iphlpsvc; C:\WINDOWS\System32\iphlpsvc.dll [996864 2017-03-18] (Microsoft Corporation) [File not signed]
S3 IpxlatCfgSvc; C:\WINDOWS\System32\IpxlatCfg.dll [64000 2017-03-18] (Microsoft Corporation) [File not signed]
S3 irmon; C:\WINDOWS\System32\irmon.dll [24576 2017-03-18] (Microsoft Corporation) [File not signed]
R3 KeyIso; C:\WINDOWS\system32\keyiso.dll [93696 2017-03-18] (Microsoft Corporation) [File not signed]
R3 KeyIso; C:\WINDOWS\SysWOW64\keyiso.dll [69632 2017-03-18] (Microsoft Corporation) [File not signed]
S3 KtmRm; C:\WINDOWS\system32\msdtckrm.dll [368128 2017-03-18] (Microsoft Corporation) [File not signed]
R2 LanmanServer; C:\WINDOWS\system32\srvsvc.dll [303616 2017-03-18] (Microsoft Corporation) [File not signed]
S4 LanmanWorkstation; C:\WINDOWS\System32\wkssvc.dll [272384 2017-03-18] (Microsoft Corporation) [File not signed]
R3 lfsvc; C:\WINDOWS\System32\lfsvc.dll [43520 2017-03-18] (Microsoft Corporation) [File not signed]
R3 LicenseManager; C:\WINDOWS\system32\LicenseManagerSvc.dll [26624 2017-03-18] (Microsoft Corporation) [File not signed]
S3 lltdsvc; C:\WINDOWS\System32\lltdsvc.dll [268800 2017-03-18] (Microsoft Corporation) [File not signed]
R3 lmhosts; C:\WINDOWS\System32\lmhsvc.dll [26112 2017-03-18] (Microsoft Corporation) [File not signed]
R2 LSM; C:\WINDOWS\System32\lsm.dll [706048 2017-03-18] (Microsoft Corporation) [File not signed]
S2 MapsBroker; C:\WINDOWS\System32\moshost.dll [90624 2017-03-18] (Microsoft Corporation) [File not signed]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
S3 MessagingService; C:\WINDOWS\System32\MessagingService.dll [51712 2017-03-18] (Microsoft Corporation) [File not signed]
R2 MpsSvc; C:\WINDOWS\system32\mpssvc.dll [972288 2017-03-18] (Microsoft Corporation) [File not signed]
S3 MSDTC; C:\WINDOWS\System32\msdtc.exe [147456 2017-03-18] (Microsoft Corporation) [File not signed]
R2 MSiSCSI; C:\WINDOWS\system32\iscsiexe.dll [150016 2017-03-18] (Microsoft Corporation) [File not signed]
S3 msiserver; C:\WINDOWS\System32\msiexec.exe [66048 2017-03-18] (Microsoft Corporation) [File not signed]
S3 msiserver; C:\WINDOWS\SysWOW64\msiexec.exe [59392 2017-03-18] (Microsoft Corporation) [File not signed]
S2 MySQL; C:\Program Files (x86)\MySQL\MySQL Server 5.0\my.ini [9027 2017-08-25] () [File not signed]
S3 NaturalAuthentication; C:\WINDOWS\System32\NaturalAuth.dll [723968 2017-03-18] (Microsoft Corporation) [File not signed]
S3 NcaSvc; C:\WINDOWS\System32\ncasvc.dll [167424 2017-03-18] (Microsoft Corporation) [File not signed]
R3 NcbService; C:\WINDOWS\System32\ncbservice.dll [334848 2017-03-18] (Microsoft Corporation) [File not signed]
R3 NcdAutoSetup; C:\WINDOWS\System32\NcdAutoSetup.dll [88064 2017-03-18] (Microsoft Corporation) [File not signed]
S3 Netlogon; C:\WINDOWS\system32\netlogon.dll [777216 2017-03-18] (Microsoft Corporation) [File not signed]
S3 Netlogon; C:\WINDOWS\SysWOW64\netlogon.dll [665600 2017-03-18] (Microsoft Corporation) [File not signed]
S3 Netman; C:\WINDOWS\System32\netman.dll [253440 2017-03-18] (Microsoft Corporation) [File not signed]
R3 netprofm; C:\WINDOWS\System32\netprofmsvc.dll [519168 2017-03-18] (Microsoft Corporation) [File not signed]
S3 NetSetupSvc; C:\WINDOWS\System32\NetSetupSvc.dll [261632 2017-03-18] (Microsoft Corporation) [File not signed]
S3 NgcCtnrSvc; C:\WINDOWS\System32\NgcCtnrSvc.dll [491520 2017-03-18] (Microsoft Corporation) [File not signed]
S3 NgcSvc; C:\WINDOWS\system32\ngcsvc.dll [1046016 2017-07-14] (Microsoft Corporation) [File not signed]
R2 NlaSvc; C:\WINDOWS\System32\nlasvc.dll [365568 2017-03-18] (Microsoft Corporation) [File not signed]
R2 nsi; C:\WINDOWS\system32\nsisvc.dll [30720 2017-03-18] (Microsoft Corporation) [File not signed]
S2 OneSyncSvc; C:\WINDOWS\System32\APHostService.dll [342528 2017-03-18] (Microsoft Corporation) [File not signed]
S3 p2pimsvc; C:\WINDOWS\system32\pnrpsvc.dll [343040 2017-03-18] (Microsoft Corporation) [File not signed]
S4 p2psvc; C:\WINDOWS\system32\p2psvc.dll [421376 2017-03-18] (Microsoft Corporation) [File not signed]
R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [77640 2013-05-14] (Nuance Communications, Inc.)
S3 PerfHost; C:\WINDOWS\SysWow64\perfhost.exe [21504 2017-03-18] (Microsoft Corporation) [File not signed]
S3 PhoneSvc; C:\WINDOWS\System32\PhoneService.dll [772096 2017-03-18] (Microsoft Corporation) [File not signed]
S3 PimIndexMaintenanceSvc; C:\WINDOWS\System32\PimIndexMaintenance.dll [182272 2017-03-18] (Microsoft Corporation) [File not signed]
S3 pla; C:\WINDOWS\system32\pla.dll [1462272 2017-03-18] (Microsoft Corporation) [File not signed]
S3 pla; C:\WINDOWS\SysWOW64\pla.dll [1537536 2017-03-18] (Microsoft Corporation) [File not signed]
R3 PlugPlay; C:\WINDOWS\system32\umpnpmgr.dll [114688 2017-03-18] (Microsoft Corporation) [File not signed]
S3 PNRPAutoReg; C:\WINDOWS\system32\pnrpauto.dll [27136 2017-03-18] (Microsoft Corporation) [File not signed]
S3 PNRPsvc; C:\WINDOWS\system32\pnrpsvc.dll [343040 2017-03-18] (Microsoft Corporation) [File not signed]
R3 PolicyAgent; C:\WINDOWS\System32\ipsecsvc.dll [458240 2017-03-18] (Microsoft Corporation) [File not signed]
R2 Power; C:\WINDOWS\system32\umpo.dll [148480 2017-07-14] (Microsoft Corporation) [File not signed]
S3 PrintNotify; C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll [2899968 2017-03-18] (Microsoft Corporation) [File not signed]
R2 ProfSvc; C:\WINDOWS\system32\profsvc.dll [413696 2017-03-18] (Microsoft Corporation) [File not signed]
S3 QWAVE; C:\WINDOWS\system32\qwave.dll [278016 2017-03-18] (Microsoft Corporation) [File not signed]
S3 QWAVE; C:\WINDOWS\SysWOW64\qwave.dll [239104 2017-03-18] (Microsoft Corporation) [File not signed]
S3 RasAuto; C:\WINDOWS\System32\rasauto.dll [104448 2017-03-18] (Microsoft Corporation) [File not signed]
S3 RasMan; C:\WINDOWS\System32\rasmans.dll [873472 2017-07-14] (Microsoft Corporation) [File not signed]
S4 RemoteAccess; C:\WINDOWS\System32\mprdim.dll [490496 2017-03-18] (Microsoft Corporation) [File not signed]
S4 RemoteAccess; C:\WINDOWS\SysWOW64\mprdim.dll [406528 2017-03-18] (Microsoft Corporation) [File not signed]
S4 RemoteRegistry; C:\WINDOWS\system32\regsvc.dll [154624 2017-03-18] (Microsoft Corporation) [File not signed]
S3 RetailDemo; C:\WINDOWS\system32\RDXService.dll [647168 2017-07-14] (Microsoft Corporation) [File not signed]
S3 RmSvc; C:\WINDOWS\System32\RMapi.dll [152576 2017-03-18] (Microsoft Corporation) [File not signed]
R2 RpcEptMapper; C:\WINDOWS\System32\RpcEpMap.dll [77824 2017-03-18] (Microsoft Corporation) [File not signed]
S3 RpcLocator; C:\WINDOWS\system32\locator.exe [11264 2017-03-18] (Microsoft Corporation) [File not signed]
R2 RpcSs; C:\WINDOWS\system32\rpcss.dll [1085440 2017-07-14] (Microsoft Corporation) [File not signed]
S4 SCardSvr; C:\WINDOWS\System32\SCardSvr.dll [250368 2017-07-14] (Microsoft Corporation) [File not signed]
S3 ScDeviceEnum; C:\WINDOWS\System32\ScDeviceEnum.dll [200192 2017-07-14] (Microsoft Corporation) [File not signed]
R2 Schedule; C:\WINDOWS\system32\schedsvc.dll [877568 2017-03-18] (Microsoft Corporation) [File not signed]
S3 SCPolicySvc; C:\WINDOWS\System32\certprop.dll [189952 2017-07-14] (Microsoft Corporation) [File not signed]
S3 SDRSVC; C:\WINDOWS\System32\SDRSVC.dll [145920 2017-03-18] (Microsoft Corporation) [File not signed]
R3 seclogon; C:\WINDOWS\system32\seclogon.dll [31232 2017-03-18] (Microsoft Corporation) [File not signed]
S3 SEMgrSvc; C:\WINDOWS\system32\SEMgrSvc.dll [1191424 2017-03-18] (Microsoft Corporation) [File not signed]
R2 SENS; C:\WINDOWS\System32\sens.dll [69632 2017-03-18] (Microsoft Corporation) [File not signed]
S3 SensorDataService; C:\WINDOWS\System32\SensorDataService.exe [1284608 2017-03-18] (Microsoft Corporation) [File not signed]
S3 SensorService; C:\WINDOWS\system32\SensorService.dll [548864 2017-07-14] (Microsoft Corporation) [File not signed]
S3 SensrSvc; C:\WINDOWS\system32\sensrsvc.dll [205824 2017-07-14] (Microsoft Corporation) [File not signed]
S3 SessionEnv; C:\WINDOWS\system32\sessenv.dll [385536 2017-03-18] (Microsoft Corporation) [File not signed]
S3 SessionEnv; C:\WINDOWS\SysWOW64\sessenv.dll [337408 2017-03-18] (Microsoft Corporation) [File not signed]
S3 SharedAccess; C:\WINDOWS\System32\ipnathlp.dll [537600 2017-03-18] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\WINDOWS\System32\shsvcs.dll [612864 2017-03-18] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\WINDOWS\SysWOW64\shsvcs.dll [564224 2017-03-18] (Microsoft Corporation) [File not signed]
S4 shpamsvc; C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll [192512 2017-07-14] (Microsoft Corporation) [File not signed]
S3 smphost; C:\WINDOWS\System32\smphost.dll [23552 2017-03-18] (Microsoft Corporation) [File not signed]
S3 smphost; C:\WINDOWS\SysWOW64\smphost.dll [20992 2017-03-18] (Microsoft Corporation) [File not signed]
S3 SmsRouter; C:\WINDOWS\system32\SmsRouterSvc.dll [582656 2017-03-18] (Microsoft Corporation) [File not signed]
S3 SNMPTRAP; C:\WINDOWS\System32\snmptrap.exe [15872 2017-07-14] (Microsoft Corporation) [File not signed]
S3 spectrum; C:\WINDOWS\system32\spectrum.exe [891904 2017-03-18] (Microsoft Corporation) [File not signed]
R2 Spooler; C:\WINDOWS\System32\spoolsv.exe [757760 2017-03-18] (Microsoft Corporation) [File not signed]
R3 SSDPSRV; C:\WINDOWS\System32\ssdpsrv.dll [239616 2017-03-18] (Microsoft Corporation) [File not signed]
S4 SstpSvc; C:\WINDOWS\system32\sstpsvc.dll [208384 2017-03-18] (Microsoft Corporation) [File not signed]
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [339456 2013-11-20] (IDT, Inc.) [File not signed]
R2 stisvc; C:\WINDOWS\System32\wiaservc.dll [634368 2017-03-18] (Microsoft Corporation) [File not signed]
R3 StorSvc; C:\WINDOWS\system32\storsvc.dll [750080 2017-07-14] (Microsoft Corporation) [File not signed]
S3 svsvc; C:\WINDOWS\system32\svsvc.dll [13824 2017-03-18] (Microsoft Corporation) [File not signed]
S3 swprv; C:\WINDOWS\System32\swprv.dll [460800 2017-03-18] (Microsoft Corporation) [File not signed]
R2 SysMain; C:\WINDOWS\system32\sysmain.dll [972800 2017-07-14] (Microsoft Corporation) [File not signed]
R2 SystemEventsBroker; C:\WINDOWS\System32\SystemEventsBrokerServer.dll [292352 2017-03-18] (Microsoft Corporation) [File not signed]
S3 TabletInputService; C:\WINDOWS\System32\TabSvc.dll [147456 2017-03-18] (Microsoft Corporation) [File not signed]
S4 TapiSrv; C:\WINDOWS\System32\tapisrv.dll [306688 2017-03-18] (Microsoft Corporation) [File not signed]
S4 TapiSrv; C:\WINDOWS\SysWOW64\tapisrv.dll [252416 2017-03-18] (Microsoft Corporation) [File not signed]
S4 TermService; C:\WINDOWS\System32\termsrv.dll [992256 2017-03-18] (Microsoft Corporation) [File not signed]
R2 Themes; C:\WINDOWS\system32\themeservice.dll [69632 2017-03-18] (Microsoft Corporation) [File not signed]
S3 TieringEngineService; C:\WINDOWS\system32\TieringEngineService.exe [302592 2017-03-18] (Microsoft Corporation) [File not signed]
R2 tiledatamodelsvc; C:\WINDOWS\system32\tileobjserver.dll [632832 2017-07-14] (Microsoft Corporation) [File not signed]
R3 TimeBrokerSvc; C:\WINDOWS\System32\TimeBrokerServer.dll [165888 2017-03-18] (Microsoft Corporation) [File not signed]
R3 TokenBroker; C:\WINDOWS\System32\TokenBroker.dll [1054208 2017-07-14] (Microsoft Corporation) [File not signed]
R3 TokenBroker; C:\WINDOWS\SysWOW64\TokenBroker.dll [799232 2017-07-14] (Microsoft Corporation) [File not signed]
R2 TrkWks; C:\WINDOWS\System32\trkwks.dll [116736 2017-03-18] (Microsoft Corporation) [File not signed]
S3 TrustedInstaller; C:\WINDOWS\servicing\TrustedInstaller.exe [121344 2017-03-18] (Microsoft Corporation) [File not signed]
S4 tzautoupdate; C:\WINDOWS\system32\tzautoupdate.dll [95744 2017-03-18] (Microsoft Corporation) [File not signed]
S3 UI0Detect; C:\WINDOWS\system32\UI0Detect.exe [43008 2017-03-18] (Microsoft Corporation) [File not signed]
S3 UmRdpService; C:\WINDOWS\System32\umrdp.dll [274944 2017-03-18] (Microsoft Corporation) [File not signed]
S3 UnistoreSvc; C:\WINDOWS\System32\unistore.dll [1177600 2017-07-14] (Microsoft Corporation) [File not signed]
S3 UnistoreSvc; C:\WINDOWS\SysWOW64\unistore.dll [969728 2017-07-14] (Microsoft Corporation) [File not signed]
S3 upnphost; C:\WINDOWS\System32\upnphost.dll [432128 2017-03-18] (Microsoft Corporation) [File not signed]
S3 upnphost; C:\WINDOWS\SysWOW64\upnphost.dll [325120 2017-03-18] (Microsoft Corporation) [File not signed]
S3 UserDataSvc; C:\WINDOWS\System32\userdataservice.dll [1628672 2017-03-18] (Microsoft Corporation) [File not signed]
R2 UserManager; C:\WINDOWS\System32\usermgr.dll [877568 2017-03-18] (Microsoft Corporation) [File not signed]
S3 UsoSvc; C:\WINDOWS\system32\usocore.dll [681984 2017-07-14] (Microsoft Corporation) [File not signed]
R3 VaultSvc; C:\Windows\System32\vaultsvc.dll [346624 2017-03-18] (Microsoft Corporation) [File not signed]
S3 vds; C:\WINDOWS\System32\vds.exe [643072 2017-03-18] (Microsoft Corporation) [File not signed]
S3 vmicguestinterface; C:\WINDOWS\System32\icsvc.dll [283648 2017-03-18] (Microsoft Corporation) [File not signed]
S3 vmicheartbeat; C:\WINDOWS\System32\icsvc.dll [283648 2017-03-18] (Microsoft Corporation) [File not signed]
S3 vmickvpexchange; C:\WINDOWS\System32\icsvc.dll [283648 2017-03-18] (Microsoft Corporation) [File not signed]
S3 vmicrdv; C:\WINDOWS\System32\icsvcext.dll [307712 2017-03-18] (Microsoft Corporation) [File not signed]
S3 vmicshutdown; C:\WINDOWS\System32\icsvc.dll [283648 2017-03-18] (Microsoft Corporation) [File not signed]
S3 vmictimesync; C:\WINDOWS\System32\icsvc.dll [283648 2017-03-18] (Microsoft Corporation) [File not signed]
S3 vmicvmsession; C:\WINDOWS\System32\icsvc.dll [283648 2017-03-18] (Microsoft Corporation) [File not signed]
S3 vmicvss; C:\WINDOWS\System32\icsvcext.dll [307712 2017-03-18] (Microsoft Corporation) [File not signed]
S3 VSS; C:\WINDOWS\system32\vssvc.exe [1550848 2017-03-18] (Microsoft Corporation) [File not signed]
R2 W32Time; C:\WINDOWS\system32\w32time.dll [524288 2017-03-18] (Microsoft Corporation) [File not signed]
S3 w3logsvc; C:\WINDOWS\system32\inetsrv\w3logsvc.dll [82432 2017-07-14] (Microsoft Corporation) [File not signed]
S3 w3logsvc; C:\WINDOWS\SysWOW64\inetsrv\w3logsvc.dll [72192 2017-07-14] (Microsoft Corporation) [File not signed]
S3 WalletService; C:\WINDOWS\system32\WalletService.dll [428032 2017-03-18] (Microsoft Corporation) [File not signed]
S3 WAS; C:\WINDOWS\system32\inetsrv\iisw3adm.dll [559104 2017-07-14] (Microsoft Corporation) [File not signed]
S3 WAS; C:\WINDOWS\SysWOW64\inetsrv\iisw3adm.dll [497664 2017-07-14] (Microsoft Corporation) [File not signed]
S3 wbengine; C:\WINDOWS\system32\wbengine.exe [1528832 2017-03-18] (Microsoft Corporation) [File not signed]
S3 WbioSrvc; C:\WINDOWS\System32\wbiosrvc.dll [942592 2017-07-14] (Microsoft Corporation) [File not signed]
R2 Wcmsvc; C:\WINDOWS\System32\wcmsvc.dll [802816 2017-07-14] (Microsoft Corporation) [File not signed]
R3 wcncsvc; C:\WINDOWS\System32\wcncsvc.dll [463872 2017-03-18] (Microsoft Corporation) [File not signed]
R3 WdiServiceHost; C:\WINDOWS\system32\wdi.dll [97792 2017-03-18] (Microsoft Corporation) [File not signed]
R3 WdiServiceHost; C:\WINDOWS\SysWOW64\wdi.dll [89088 2017-03-18] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\WINDOWS\system32\wdi.dll [97792 2017-03-18] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\WINDOWS\SysWOW64\wdi.dll [89088 2017-03-18] (Microsoft Corporation) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WebClient; C:\WINDOWS\System32\webclnt.dll [224256 2017-03-18] (Microsoft Corporation) [File not signed]
S3 WebClient; C:\WINDOWS\SysWOW64\webclnt.dll [196608 2017-03-18] (Microsoft Corporation) [File not signed]
R2 Wecsvc; C:\WINDOWS\system32\wecsvc.dll [202752 2017-03-18] (Microsoft Corporation) [File not signed]
S3 WEPHOSTSVC; C:\WINDOWS\system32\wephostsvc.dll [27648 2017-03-18] (Microsoft Corporation) [File not signed]
S3 wercplsupport; C:\WINDOWS\System32\wercplsupport.dll [91648 2017-03-18] (Microsoft Corporation) [File not signed]
S3 WerSvc; C:\WINDOWS\System32\WerSvc.dll [176640 2017-03-18] (Microsoft Corporation) [File not signed]
S3 WFDSConMgrSvc; C:\WINDOWS\System32\wfdsconmgrsvc.dll [555008 2017-07-14] (Microsoft Corporation) [File not signed]
S3 WiaRpc; C:\WINDOWS\System32\wiarpc.dll [81920 2017-03-18] (Microsoft Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-07-14] (Microsoft Corporation)
R2 Winmgmt; C:\WINDOWS\system32\wbem\WMIsvc.dll [221696 2017-03-18] (Microsoft Corporation) [File not signed]
S4 WinRM; C:\WINDOWS\system32\WsmSvc.dll [2757120 2017-03-18] (Microsoft Corporation) [File not signed]
S4 WinRM; C:\WINDOWS\SysWOW64\WsmSvc.dll [2354688 2017-03-18] (Microsoft Corporation) [File not signed]
S3 wisvc; C:\WINDOWS\system32\flightsettings.dll [699904 2017-03-18] (Microsoft Corporation) [File not signed]
R2 WlanSvc; C:\WINDOWS\System32\wlansvc.dll [2425856 2017-03-18] (Microsoft Corporation) [File not signed]
R3 wlidsvc; C:\WINDOWS\system32\wlidsvc.dll [2155008 2017-03-18] (Microsoft Corporation) [File not signed]
S3 wlpasvc; C:\WINDOWS\System32\lpasvc.dll [1295360 2017-03-18] (Microsoft Corporation) [File not signed]
S3 wmiApSrv; C:\WINDOWS\system32\wbem\WmiApSrv.exe [199168 2017-03-18] (Microsoft Corporation) [File not signed]
S4 WMPNetworkSvc; C:\Program Files\Windows Media Player\wmpnetwk.exe [1177088 2017-03-17] (Microsoft Corporation) [File not signed]
S3 WPDBusEnum; C:\WINDOWS\system32\wpdbusenum.dll [86016 2017-03-18] (Microsoft Corporation) [File not signed]
R2 WpnService; C:\WINDOWS\system32\WpnService.dll [276480 2017-03-18] (Microsoft Corporation) [File not signed]
S2 WpnUserService; C:\WINDOWS\System32\WpnUserService.dll [72704 2017-03-18] (Microsoft Corporation) [File not signed]
R2 wscsvc; C:\WINDOWS\System32\wscsvc.dll [208896 2017-03-18] (Microsoft Corporation) [File not signed]
R2 WSearch; C:\WINDOWS\system32\SearchIndexer.exe [933376 2017-07-14] (Microsoft Corporation) [File not signed]
R2 WSearch; C:\WINDOWS\SysWOW64\SearchIndexer.exe [797184 2017-07-14] (Microsoft Corporation) [File not signed]
S2 wuauserv; C:\WINDOWS\system32\wuaueng.dll [2444288 2017-07-14] (Microsoft Corporation) [File not signed]
R3 wudfsvc; C:\WINDOWS\System32\WUDFSvc.dll [91648 2017-03-18] (Microsoft Corporation) [File not signed]
S3 WwanSvc; C:\WINDOWS\System32\wwansvc.dll [1396224 2017-07-14] (Microsoft Corporation) [File not signed]
S3 XblAuthManager; C:\WINDOWS\System32\XblAuthManager.dll [1013248 2017-03-18] (Microsoft Corporation) [File not signed]
S4 XblGameSave; C:\WINDOWS\System32\XblGameSave.dll [1135104 2017-03-18] (Microsoft Corporation) [File not signed]
S4 XboxGipSvc; C:\WINDOWS\System32\XboxGipSvc.dll [18944 2017-03-18] (Microsoft Corporation) [File not signed]
S4 XboxNetApiSvc; C:\WINDOWS\system32\XboxNetApiSvc.dll [1067008 2017-07-14] (Microsoft Corporation) [File not signed]