OTL logfile created on: 10/12/2016 23:35:02 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Meliodas-sama\Downloads Professional (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17031) Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy 2,98 Gb Total Physical Memory | 1,74 Gb Available Physical Memory | 58,60% Memory free 4,23 Gb Paging File | 2,70 Gb Available in Paging File | 63,97% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 148,71 Gb Total Space | 104,27 Gb Free Space | 70,12% Space Free | Partition Type: NTFS Computer Name: SHIKAMARU | User Name: Meliodas-sama | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (All) ==========[/color] PRC - [2016/12/10 23:34:04 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Meliodas-sama\Downloads\OTL.exe PRC - [2016/12/07 19:32:39 | 009,080,768 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\avastui.exe PRC - [2016/12/07 19:31:16 | 000,197,128 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2016/12/07 16:35:05 | 000,153,752 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe PRC - [2016/12/01 02:29:43 | 000,941,160 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe PRC - [2016/11/28 15:19:02 | 010,216,688 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\TeamViewer_Service.exe PRC - [2016/11/24 11:34:24 | 000,235,984 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe PRC - [2016/09/21 11:09:08 | 004,088,608 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe PRC - [2016/05/09 07:05:26 | 000,054,800 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\tbaseprovisioning.exe PRC - [2016/05/09 07:05:14 | 000,218,128 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe PRC - [2016/05/09 07:05:12 | 000,502,800 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe PRC - [2014/12/03 03:01:58 | 000,743,688 | ---- | M] (DEVGURU Co., LTD.) -- C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe PRC - [2014/06/24 10:41:42 | 001,738,168 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe PRC - [2014/03/18 09:01:32 | 000,658,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchIndexer.exe PRC - [2014/03/18 09:01:32 | 000,258,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchProtocolHost.exe PRC - [2014/03/18 09:01:32 | 000,164,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchFilterHost.exe PRC - [2014/03/18 09:01:22 | 000,084,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwm.exe PRC - [2014/03/18 09:01:20 | 002,088,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2014/03/18 09:01:19 | 000,517,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SettingSyncHost.exe PRC - [2014/03/18 09:01:18 | 000,672,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SkyDrive.exe PRC - [2014/03/18 09:01:11 | 000,459,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winlogon.exe PRC - [2014/03/18 09:01:06 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dasHost.exe PRC - [2014/03/18 09:01:03 | 000,066,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhostex.exe PRC - [2013/08/22 07:13:54 | 000,034,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\lsass.exe PRC - [2013/08/22 06:30:58 | 000,031,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch] PRC - [2013/08/22 06:30:58 | 000,031,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch] PRC - [2013/08/22 06:30:58 | 000,031,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch] PRC - [2013/08/22 06:30:58 | 000,031,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch] PRC - [2013/08/22 06:30:58 | 000,031,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch] PRC - [2013/08/22 06:30:58 | 000,031,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch] PRC - [2013/08/22 06:30:58 | 000,031,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch] PRC - [2013/08/22 06:30:58 | 000,031,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch] PRC - [2013/08/22 06:30:58 | 000,031,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch] PRC - [2013/08/22 06:30:58 | 000,031,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch] PRC - [2013/08/22 06:21:45 | 000,017,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dllhost.exe PRC - [2013/08/22 03:49:55 | 000,112,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wininit.exe PRC - [2013/08/22 03:18:51 | 000,534,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spoolsv.exe [color=#E56717]========== Modules (All) ==========[/color] MOD - [2016/12/10 23:34:04 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Meliodas-sama\Downloads\OTL.exe MOD - [2016/12/09 18:10:03 | 000,150,584 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\defs\16120901\aswCmnOS.dll MOD - [2016/12/09 18:10:03 | 000,067,408 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\defs\16120901\uiExt.dll MOD - [2016/12/09 18:10:02 | 000,499,632 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\defs\16120901\aswCmnBS.dll MOD - [2016/12/09 18:10:02 | 000,463,248 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\defs\16120901\aswCmnIS.dll MOD - [2016/12/07 19:32:39 | 009,080,768 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\avastui.exe MOD - [2016/12/07 19:32:30 | 004,376,160 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\CommonRes.dll MOD - [2016/12/07 19:32:28 | 001,060,176 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\ashBase.dll MOD - [2016/12/07 19:32:28 | 001,060,176 | ---- | M] (AVAST Software) -- C:\PROGRA~1\AVASTS~1\Avast\ashBase.dll MOD - [2016/12/07 19:32:26 | 000,439,968 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\ashTask.dll MOD - [2016/12/07 19:32:26 | 000,439,968 | ---- | M] (AVAST Software) -- C:\PROGRA~1\AVASTS~1\Avast\ashTask.dll MOD - [2016/12/07 19:32:22 | 003,748,584 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\Aavm4h.dll MOD - [2016/12/07 19:32:22 | 003,748,584 | ---- | M] (AVAST Software) -- C:\PROGRA~1\AVASTS~1\Avast\Aavm4h.dll MOD - [2016/12/07 19:32:19 | 000,456,912 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswProperty.dll MOD - [2016/12/07 19:31:51 | 004,775,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.24210.0_none_a338d8ea2df29efb\mfc140u.dll MOD - [2016/12/07 19:31:50 | 000,921,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\ucrtbase.dll MOD - [2016/12/07 19:31:50 | 000,440,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\msvcp140.dll MOD - [2016/12/07 19:31:50 | 000,083,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\vcruntime140.dll MOD - [2016/12/07 19:31:50 | 000,029,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\api-ms-win-crt-math-l1-1-0.dll MOD - [2016/12/07 19:31:50 | 000,026,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\api-ms-win-crt-multibyte-l1-1-0.dll MOD - [2016/12/07 19:31:50 | 000,024,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\api-ms-win-crt-string-l1-1-0.dll MOD - [2016/12/07 19:31:50 | 000,024,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\api-ms-win-crt-stdio-l1-1-0.dll MOD - [2016/12/07 19:31:50 | 000,023,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\api-ms-win-crt-runtime-l1-1-0.dll MOD - [2016/12/07 19:31:50 | 000,022,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\api-ms-win-crt-convert-l1-1-0.dll MOD - [2016/12/07 19:31:50 | 000,021,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\api-ms-win-crt-time-l1-1-0.dll MOD - [2016/12/07 19:31:50 | 000,020,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\api-ms-win-crt-filesystem-l1-1-0.dll MOD - [2016/12/07 19:31:50 | 000,019,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\api-ms-win-crt-heap-l1-1-0.dll MOD - [2016/12/07 19:31:50 | 000,019,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\api-ms-win-crt-conio-l1-1-0.dll MOD - [2016/12/07 19:31:50 | 000,019,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\api-ms-win-crt-utility-l1-1-0.dll MOD - [2016/12/07 19:31:50 | 000,019,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\api-ms-win-crt-locale-l1-1-0.dll MOD - [2016/12/07 19:31:50 | 000,019,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8\api-ms-win-crt-environment-l1-1-0.dll MOD - [2016/12/07 19:31:43 | 000,217,792 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswJsFlt.dll MOD - [2016/12/07 19:31:38 | 001,354,928 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files\AVAST Software\Avast\LIBEAY32.dll MOD - [2016/12/07 19:31:38 | 000,310,744 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files\AVAST Software\Avast\ssleay32.dll MOD - [2016/12/07 19:31:35 | 048,936,448 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll MOD - [2016/12/07 19:31:26 | 000,921,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\ucrtbase.dll MOD - [2016/12/07 19:31:22 | 000,123,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\log.dll MOD - [2016/12/07 19:31:22 | 000,123,344 | ---- | M] (AVAST Software) -- C:\PROGRA~1\AVASTS~1\Avast\log.dll MOD - [2016/12/07 19:31:21 | 000,482,928 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\ffl2.dll MOD - [2016/12/07 19:31:20 | 000,245,464 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\event_manager.dll MOD - [2016/12/07 19:31:20 | 000,096,816 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\avastIP.dll MOD - [2016/12/07 19:31:20 | 000,096,816 | ---- | M] (AVAST Software) -- C:\PROGRA~1\AVASTS~1\Avast\avastIP.dll MOD - [2016/12/07 19:31:20 | 000,087,024 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\event_manager_rpc.dll MOD - [2016/12/07 19:31:19 | 000,755,176 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswData.dll MOD - [2016/12/07 19:31:19 | 000,597,584 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswSqLt.dll MOD - [2016/12/07 19:31:19 | 000,302,624 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswLog.dll MOD - [2016/12/07 19:31:19 | 000,220,592 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswUtil.dll MOD - [2016/12/07 19:31:19 | 000,111,960 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswRemoteCache.dll MOD - [2016/12/07 19:31:19 | 000,087,480 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswEngLdr.dll MOD - [2016/12/07 19:31:19 | 000,087,480 | ---- | M] (AVAST Software) -- C:\PROGRA~1\AVASTS~1\Avast\aswEngLdr.dll MOD - [2016/12/07 19:31:18 | 000,923,856 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswAux.dll MOD - [2016/12/07 19:31:18 | 000,923,856 | ---- | M] (AVAST Software) -- C:\PROGRA~1\AVASTS~1\Avast\aswAux.dll MOD - [2016/12/07 19:31:18 | 000,832,488 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\ashShell.dll MOD - [2016/12/07 19:31:18 | 000,403,336 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswCmnIS.dll MOD - [2016/12/07 19:31:18 | 000,403,336 | ---- | M] (AVAST Software) -- C:\PROGRA~1\AVASTS~1\Avast\aswCmnIS.dll MOD - [2016/12/07 19:31:18 | 000,379,032 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\ashTaskEx.dll MOD - [2016/12/07 19:31:18 | 000,377,376 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswCmnBS.dll MOD - [2016/12/07 19:31:18 | 000,377,376 | ---- | M] (AVAST Software) -- C:\PROGRA~1\AVASTS~1\Avast\aswCmnBS.dll MOD - [2016/12/07 19:31:18 | 000,142,016 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswCmnOS.dll MOD - [2016/12/07 19:31:18 | 000,142,016 | ---- | M] (AVAST Software) -- C:\PROGRA~1\AVASTS~1\Avast\aswCmnOS.dll MOD - [2016/12/07 19:31:16 | 000,630,952 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\commchannel.dll MOD - [2016/12/07 19:31:16 | 000,630,952 | ---- | M] (AVAST Software) -- C:\PROGRA~1\AVASTS~1\Avast\commchannel.dll MOD - [2016/12/07 19:31:16 | 000,169,064 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll MOD - [2016/12/07 19:31:16 | 000,169,064 | ---- | M] () -- C:\PROGRA~1\AVASTS~1\Avast\JsonRpcServer.dll MOD - [2016/12/07 19:31:14 | 000,333,704 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AavmRpch.dll MOD - [2016/12/07 19:31:14 | 000,333,704 | ---- | M] (AVAST Software) -- C:\PROGRA~1\AVASTS~1\Avast\AavmRpch.dll MOD - [2016/12/07 19:31:13 | 000,435,616 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\1036\UILangRes.dll MOD - [2016/12/07 19:31:13 | 000,113,376 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\1036\Base.dll MOD - [2016/12/07 19:31:05 | 000,271,880 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll MOD - [2016/12/07 19:30:13 | 003,558,256 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\HTMLayout.dll MOD - [2016/12/01 02:29:50 | 000,471,144 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\55.0.2883.75\chrome_watcher.dll MOD - [2016/12/01 02:29:49 | 000,427,624 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\55.0.2883.75\chrome_elf.dll MOD - [2016/12/01 02:29:47 | 046,628,968 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\55.0.2883.75\chrome_child.dll MOD - [2016/12/01 02:29:45 | 040,125,544 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\55.0.2883.75\chrome.dll MOD - [2016/12/01 02:29:43 | 000,941,160 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe MOD - [2016/10/28 09:36:14 | 017,772,736 | ---- | M] () -- C:\Users\Meliodas-sama\AppData\Local\Google\Chrome\User Data\PepperFlash\\pepflashplayer.dll MOD - [2016/09/06 11:00:38 | 005,197,312 | ---- | M] () -- C:\Users\Meliodas-sama\AppData\Local\Google\Chrome\User Data\SwiftShader\\libglesv2.dll MOD - [2016/09/06 11:00:36 | 000,147,456 | ---- | M] () -- C:\Users\Meliodas-sama\AppData\Local\Google\Chrome\User Data\SwiftShader\\libegl.dll MOD - [2014/03/18 09:08:03 | 000,629,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MrmCoreR.dll MOD - [2014/03/18 09:01:32 | 002,643,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll MOD - [2014/03/18 09:01:32 | 001,716,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll MOD - [2014/03/18 09:01:32 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\actxprxy.dll MOD - [2014/03/18 09:01:32 | 000,490,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\advapi32.dll MOD - [2014/03/18 09:01:32 | 000,426,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll MOD - [2014/03/18 09:01:32 | 000,321,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\provsvc.dll MOD - [2014/03/18 09:01:32 | 000,308,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\srchadmin.dll MOD - [2014/03/18 09:01:32 | 000,164,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchFilterHost.exe MOD - [2014/03/18 09:01:32 | 000,061,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\srclient.dll MOD - [2014/03/18 09:01:32 | 000,047,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mssprxy.dll MOD - [2014/03/18 09:01:32 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msshooks.dll MOD - [2014/03/18 09:01:31 | 002,220,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wpc.dll MOD - [2014/03/18 09:01:31 | 000,552,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cscui.dll MOD - [2014/03/18 09:01:29 | 011,745,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll MOD - [2014/03/18 09:01:29 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\ieproxy.dll MOD - [2014/03/18 09:01:29 | 000,222,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\sqmapi.dll MOD - [2014/03/18 09:01:28 | 000,166,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WorkFoldersShell.dll MOD - [2014/03/18 09:01:22 | 012,736,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Windows.UI.Xaml.dll MOD - [2014/03/18 09:01:22 | 003,936,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll MOD - [2014/03/18 09:01:22 | 002,270,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msftedit.dll MOD - [2014/03/18 09:01:22 | 002,071,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll MOD - [2014/03/18 09:01:22 | 001,779,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll MOD - [2014/03/18 09:01:22 | 001,341,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dui70.dll MOD - [2014/03/18 09:01:22 | 001,095,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\werconcpl.dll MOD - [2014/03/18 09:01:22 | 001,092,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\gdi32.dll MOD - [2014/03/18 09:01:22 | 000,422,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wer.dll MOD - [2014/03/18 09:01:22 | 000,406,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll MOD - [2014/03/18 09:01:22 | 000,241,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dcomp.dll MOD - [2014/03/18 09:01:22 | 000,146,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imm32.dll MOD - [2014/03/18 09:01:22 | 000,098,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwmapi.dll MOD - [2014/03/18 09:01:22 | 000,059,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wercplsupport.dll MOD - [2014/03/18 09:01:21 | 001,975,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7\comctl32.dll MOD - [2014/03/18 09:01:21 | 001,370,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\user32.dll MOD - [2014/03/18 09:01:21 | 001,369,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecs.dll MOD - [2014/03/18 09:01:21 | 001,017,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msctf.dll MOD - [2014/03/18 09:01:21 | 000,920,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\UIAutomationCore.dll MOD - [2014/03/18 09:01:21 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winbici.dll MOD - [2014/03/18 09:01:20 | 002,428,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ExplorerFrame.dll MOD - [2014/03/18 09:01:20 | 002,315,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\authui.dll MOD - [2014/03/18 09:01:20 | 002,088,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe MOD - [2014/03/18 09:01:20 | 000,832,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ActionCenter.dll MOD - [2014/03/18 09:01:20 | 000,528,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\comdlg32.dll MOD - [2014/03/18 09:01:20 | 000,193,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\bthprops.cpl MOD - [2014/03/18 09:01:20 | 000,191,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\InputSwitch.dll MOD - [2014/03/18 09:01:20 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\windows.immersiveshell.serviceprovider.dll MOD - [2014/03/18 09:01:20 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\AltTab.dll MOD - [2014/03/18 09:01:19 | 018,682,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\shell32.dll MOD - [2014/03/18 09:01:19 | 002,165,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SyncCenter.dll MOD - [2014/03/18 09:01:19 | 000,644,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntshrui.dll MOD - [2014/03/18 09:01:19 | 000,600,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SettingSyncCore.dll MOD - [2014/03/18 09:01:19 | 000,517,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SettingSyncHost.exe MOD - [2014/03/18 09:01:19 | 000,477,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SHCore.dll MOD - [2014/03/18 09:01:19 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SettingMonitor.dll MOD - [2014/03/18 09:01:19 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SettingSyncPolicy.dll MOD - [2014/03/18 09:01:18 | 011,790,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\twinui.dll MOD - [2014/03/18 09:01:18 | 003,562,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SyncEngine.dll MOD - [2014/03/18 09:01:18 | 001,200,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\propsys.dll MOD - [2014/03/18 09:01:18 | 000,828,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\twinui.appcore.dll MOD - [2014/03/18 09:01:18 | 000,672,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SkyDrive.exe MOD - [2014/03/18 09:01:18 | 000,590,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SkyDriveTelemetry.dll MOD - [2014/03/18 09:01:18 | 000,556,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\twinapi.dll MOD - [2014/03/18 09:01:18 | 000,459,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SettingSync.dll MOD - [2014/03/18 09:01:18 | 000,419,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\twinapi.appcore.dll MOD - [2014/03/18 09:01:18 | 000,288,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\stobject.dll MOD - [2014/03/18 09:01:18 | 000,121,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SkyDriveShell.dll MOD - [2014/03/18 09:01:18 | 000,117,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\thumbcache.dll MOD - [2014/03/18 09:01:17 | 005,834,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Windows.UI.Search.dll MOD - [2014/03/18 09:01:17 | 001,496,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Windows.UI.Immersive.dll MOD - [2014/03/18 09:01:17 | 001,238,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dbghelp.dll MOD - [2014/03/18 09:01:17 | 000,903,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\uxtheme.dll MOD - [2014/03/18 09:01:17 | 000,839,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchFolder.dll MOD - [2014/03/18 09:01:16 | 000,370,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winspool.drv MOD - [2014/03/18 09:01:13 | 000,557,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pnidui.dll MOD - [2014/03/18 09:01:13 | 000,409,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Windows.Networking.Connectivity.dll MOD - [2014/03/18 09:01:13 | 000,229,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wlanapi.dll MOD - [2014/03/18 09:01:13 | 000,214,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SndVolSSO.dll MOD - [2014/03/18 09:01:13 | 000,059,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Windows.Networking.Sockets.PushEnabledApplication.dll MOD - [2014/03/18 09:01:12 | 002,178,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll MOD - [2014/03/18 09:01:12 | 001,789,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll MOD - [2014/03/18 09:01:12 | 001,317,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msxml3.dll MOD - [2014/03/18 09:01:12 | 001,265,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Speech\Common\sapi.dll MOD - [2014/03/18 09:01:12 | 001,143,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll MOD - [2014/03/18 09:01:12 | 000,169,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WSClient.dll MOD - [2014/03/18 09:01:11 | 000,698,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WSShared.dll MOD - [2014/03/18 09:01:11 | 000,553,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll MOD - [2014/03/18 09:01:11 | 000,418,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\StructuredQuery.dll MOD - [2014/03/18 09:01:11 | 000,356,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wlidprov.dll MOD - [2014/03/18 09:01:11 | 000,344,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\schannel.dll MOD - [2014/03/18 09:01:11 | 000,230,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wintrust.dll MOD - [2014/03/18 09:01:11 | 000,148,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\slc.dll MOD - [2014/03/18 09:01:11 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\AuthBroker.dll MOD - [2014/03/18 09:01:11 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sppc.dll MOD - [2014/03/18 09:01:10 | 001,095,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ole32.dll MOD - [2014/03/18 09:01:10 | 001,077,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\webservices.dll MOD - [2014/03/18 09:01:10 | 000,292,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ninput.dll MOD - [2014/03/18 09:01:07 | 000,617,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\apphelp.dll MOD - [2014/03/18 09:01:07 | 000,044,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wldp.dll MOD - [2014/03/18 09:01:07 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winbrand.dll MOD - [2014/03/18 09:01:06 | 001,037,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\kernel32.dll MOD - [2014/03/18 09:01:06 | 000,045,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\AepRoam.dll MOD - [2014/03/18 09:01:05 | 001,767,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\setupapi.dll MOD - [2014/03/18 09:01:05 | 000,479,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wpncore.dll MOD - [2014/03/18 09:01:05 | 000,165,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wpnprv.dll MOD - [2014/03/18 09:01:04 | 000,326,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\AudioSes.dll MOD - [2014/03/18 09:01:04 | 000,296,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MMDevAPI.dll MOD - [2014/03/18 09:01:03 | 001,136,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wscui.cpl MOD - [2014/03/18 09:01:03 | 000,140,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wscapi.dll MOD - [2014/03/18 09:01:03 | 000,109,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wscinterop.dll MOD - [2014/03/18 09:01:03 | 000,066,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhostex.exe MOD - [2014/03/18 09:01:01 | 000,222,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spp.dll MOD - [2014/03/18 09:01:00 | 001,581,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\crypt32.dll MOD - [2014/03/18 09:01:00 | 001,451,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntdll.dll MOD - [2014/03/18 09:01:00 | 001,374,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\combase.dll MOD - [2014/03/18 09:01:00 | 000,863,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\KernelBase.dll MOD - [2014/03/18 09:01:00 | 000,552,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\oleaut32.dll MOD - [2014/03/18 09:01:00 | 000,506,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WinTypes.dll MOD - [2014/03/18 09:01:00 | 000,492,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dnsapi.dll MOD - [2014/03/18 09:01:00 | 000,336,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\bcryptprimitives.dll MOD - [2014/03/18 09:01:00 | 000,256,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wincorlib.dll MOD - [2014/03/18 09:01:00 | 000,251,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\powrprof.dll MOD - [2014/03/18 09:01:00 | 000,134,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sspicli.dll MOD - [2014/03/18 09:01:00 | 000,125,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\bcrypt.dll MOD - [2014/03/18 09:01:00 | 000,089,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ncryptsslp.dll MOD - [2014/03/18 09:01:00 | 000,079,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\bcd.dll MOD - [2014/03/18 09:01:00 | 000,070,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imagehlp.dll MOD - [2014/03/18 09:01:00 | 000,062,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\samlib.dll MOD - [2014/03/18 08:42:18 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cscobj.dll MOD - [2013/08/22 07:13:54 | 000,313,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ws2_32.dll MOD - [2013/08/22 07:13:54 | 000,252,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sechost.dll MOD - [2013/08/22 07:13:54 | 000,030,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptbase.dll MOD - [2013/08/22 07:13:54 | 000,025,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winnsi.dll MOD - [2013/08/22 07:13:54 | 000,019,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\nsi.dll MOD - [2013/08/22 07:13:53 | 000,802,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rpcrt4.dll MOD - [2013/08/22 07:13:53 | 000,780,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msvcrt.dll MOD - [2013/08/22 07:13:53 | 000,051,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\profapi.dll MOD - [2013/08/22 07:13:51 | 000,488,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sxs.dll MOD - [2013/08/22 06:31:41 | 000,123,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\devobj.dll MOD - [2013/08/22 06:31:40 | 000,237,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cfgmgr32.dll MOD - [2013/08/22 06:31:40 | 000,029,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\kernel.appcore.dll MOD - [2013/08/22 06:31:40 | 000,016,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\psapi.dll MOD - [2013/08/22 06:30:48 | 000,308,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wevtapi.dll MOD - [2013/08/22 06:30:36 | 000,082,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mpr.dll MOD - [2013/08/22 06:29:34 | 000,059,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wkscli.dll MOD - [2013/08/22 06:29:31 | 000,108,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\srvcli.dll MOD - [2013/08/22 06:29:31 | 000,094,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\userenv.dll MOD - [2013/08/22 06:29:30 | 000,188,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rsaenh.dll MOD - [2013/08/22 06:29:30 | 000,171,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntasn1.dll MOD - [2013/08/22 06:29:29 | 000,147,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntmarta.dll MOD - [2013/08/22 06:29:29 | 000,113,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll MOD - [2013/08/22 06:29:29 | 000,066,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netapi32.dll MOD - [2013/08/22 06:29:29 | 000,050,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msasn1.dll MOD - [2013/08/22 06:29:29 | 000,036,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netutils.dll MOD - [2013/08/22 06:29:26 | 000,111,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\gpapi.dll MOD - [2013/08/22 06:29:26 | 000,095,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptsp.dll MOD - [2013/08/22 06:29:25 | 000,020,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dsrole.dll MOD - [2013/08/22 06:28:06 | 001,721,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msxml6.dll MOD - [2013/08/22 06:28:06 | 000,175,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\xmllite.dll MOD - [2013/08/22 06:25:38 | 000,025,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\version.dll MOD - [2013/08/22 06:25:37 | 000,263,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\shlwapi.dll MOD - [2013/08/22 06:24:59 | 000,030,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\avrt.dll MOD - [2013/08/22 06:24:57 | 000,103,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxva2.dll MOD - [2013/08/22 06:21:42 | 000,508,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\clbcatq.dll MOD - [2013/08/22 06:20:03 | 000,265,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winsta.dll MOD - [2013/08/22 06:20:02 | 000,050,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wtsapi32.dll MOD - [2013/08/22 06:19:23 | 000,128,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winmm.dll MOD - [2013/08/22 06:19:23 | 000,128,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winmmbase.dll MOD - [2013/08/22 06:19:22 | 000,086,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msacm32.dll MOD - [2013/08/22 06:19:22 | 000,039,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msdmo.dll MOD - [2013/08/22 06:19:12 | 000,018,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ksuser.dll MOD - [2013/08/22 06:17:53 | 000,118,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IPHLPAPI.DLL MOD - [2013/08/22 05:14:43 | 000,638,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\UIRibbonRes.dll MOD - [2013/08/22 05:12:40 | 000,076,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\usp10.dll MOD - [2013/08/22 05:07:58 | 000,535,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_7c55c866aa0c3ff0\comctl32.dll MOD - [2013/08/22 05:07:29 | 000,206,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\shdocvw.dll MOD - [2013/08/22 05:07:04 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SensApi.dll MOD - [2013/08/22 05:06:58 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sfc_os.dll MOD - [2013/08/22 05:06:23 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cscdll.dll MOD - [2013/08/22 05:06:04 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dciman32.dll MOD - [2013/08/22 05:05:53 | 002,012,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\batmeter.dll MOD - [2013/08/22 05:05:51 | 000,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wsock32.dll MOD - [2013/08/22 05:04:34 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msiltcfg.dll MOD - [2013/08/22 05:04:11 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\midimap.dll MOD - [2013/08/22 05:03:33 | 000,395,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msutb.dll MOD - [2013/08/22 05:03:31 | 000,020,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pcacli.dll MOD - [2013/08/22 05:03:14 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IconCodecService.dll MOD - [2013/08/22 05:02:28 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\npmproxy.dll MOD - [2013/08/22 05:01:50 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\linkinfo.dll MOD - [2013/08/22 04:59:13 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msacm32.drv MOD - [2013/08/22 04:58:22 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\qmgrprxy.dll MOD - [2013/08/22 04:58:09 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PlaySndSrv.dll MOD - [2013/08/22 04:58:08 | 000,102,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\chartv.dll MOD - [2013/08/22 04:54:15 | 000,080,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\olepro32.dll MOD - [2013/08/22 04:53:54 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx MOD - [2013/08/22 04:52:26 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Syncreg.dll MOD - [2013/08/22 04:52:00 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MsCtfMonitor.dll MOD - [2013/08/22 04:39:45 | 003,258,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msi.dll MOD - [2013/08/22 04:37:03 | 000,031,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\hcproviders.dll MOD - [2013/08/22 04:32:30 | 000,409,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imapi2.dll MOD - [2013/08/22 04:31:11 | 000,460,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\prnfldr.dll MOD - [2013/08/22 04:27:27 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\EhStorShell.dll MOD - [2013/08/22 04:26:03 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\credui.dll MOD - [2013/08/22 04:19:50 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\apprepapi.dll MOD - [2013/08/22 04:07:01 | 001,664,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\networkexplorer.dll MOD - [2013/08/22 04:06:20 | 000,389,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DXP.dll MOD - [2013/08/22 03:56:01 | 002,378,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\esent.dll MOD - [2013/08/22 03:55:53 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\secur32.dll MOD - [2013/08/22 03:55:43 | 000,012,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dpapi.dll MOD - [2013/08/22 03:55:36 | 000,293,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wldap32.dll MOD - [2013/08/22 03:55:30 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dhcpcsvc6.dll MOD - [2013/08/22 03:55:25 | 000,270,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mswsock.dll MOD - [2013/08/22 03:55:09 | 000,062,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dhcpcsvc.dll MOD - [2013/08/22 03:55:04 | 000,005,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msimg32.dll MOD - [2013/08/22 03:54:52 | 001,497,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll MOD - [2013/08/22 03:54:48 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptnet.dll MOD - [2013/08/22 03:54:44 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\hid.dll MOD - [2013/08/22 03:54:36 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rasadhlp.dll MOD - [2013/08/22 03:54:17 | 000,062,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\samcli.dll MOD - [2013/08/22 03:54:13 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\tbs.dll MOD - [2013/08/22 03:53:48 | 000,100,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\loadperf.dll MOD - [2013/08/22 03:53:48 | 000,028,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\OnDemandConnRouteHelper.dll MOD - [2013/08/22 03:53:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\devrtl.dll MOD - [2013/08/22 03:53:26 | 000,589,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\elslad.dll MOD - [2013/08/22 03:53:05 | 000,028,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wcmapi.dll MOD - [2013/08/22 03:52:25 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cscapi.dll MOD - [2013/08/22 03:52:09 | 000,276,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\BCP47Langs.dll MOD - [2013/08/22 03:51:28 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Windows.Globalization.Fontgroups.dll MOD - [2013/08/22 03:48:53 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\nlaapi.dll MOD - [2013/08/22 03:47:55 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msauserext.dll MOD - [2013/08/22 03:46:53 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ELSCore.dll MOD - [2013/08/22 03:46:42 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wshbth.dll MOD - [2013/08/22 03:46:42 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\keepaliveprovider.dll MOD - [2013/08/22 03:46:39 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\framedynos.dll MOD - [2013/08/22 03:45:46 | 000,262,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wpnapps.dll MOD - [2013/08/22 03:45:37 | 000,053,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vsstrace.dll MOD - [2013/08/22 03:45:23 | 000,528,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WinSync.dll MOD - [2013/08/22 03:44:57 | 000,069,120 | ---- | M] (Microsoft) -- C:\Windows\System32\VaultRoaming.dll MOD - [2013/08/22 03:44:53 | 000,400,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\webio.dll MOD - [2013/08/22 03:44:35 | 003,452,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_47.dll MOD - [2013/08/22 03:44:29 | 000,515,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\FirewallAPI.dll MOD - [2013/08/22 03:44:06 | 000,190,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netprofm.dll MOD - [2013/08/22 03:43:53 | 000,108,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IDStore.dll MOD - [2013/08/22 03:42:31 | 000,280,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\oleacc.dll MOD - [2013/08/22 03:42:11 | 001,352,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.16384_none_dadf89385bc5c7d7\GdiPlus.dll MOD - [2013/08/22 03:41:38 | 000,223,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\UIAnimation.dll MOD - [2013/08/22 03:41:23 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\BluetoothApis.dll MOD - [2013/08/22 03:40:03 | 000,264,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\FWPUCLNT.DLL MOD - [2013/08/22 03:39:44 | 000,345,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PhotoMetadataHandler.dll MOD - [2013/08/22 03:39:08 | 000,589,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winhttp.dll MOD - [2013/08/22 03:38:29 | 000,329,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\es.dll MOD - [2013/08/22 03:38:02 | 000,189,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WSSync.dll MOD - [2013/08/22 03:38:00 | 000,477,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mscms.dll MOD - [2013/08/22 03:36:25 | 000,187,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wdmaud.drv MOD - [2013/08/22 03:33:31 | 000,527,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ddraw.dll MOD - [2013/08/22 03:30:52 | 000,335,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Windows.UI.dll MOD - [2013/08/22 03:29:37 | 000,471,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\duser.dll MOD - [2013/08/22 03:25:20 | 001,117,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vssapi.dll MOD - [2013/08/22 03:22:51 | 000,072,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NetworkStatus.dll MOD - [2013/08/22 03:20:22 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PackageStateRoaming.dll MOD - [2013/08/22 03:18:24 | 000,137,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\shacct.dll MOD - [2013/08/22 03:15:19 | 000,501,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\hgcpl.dll MOD - [2013/08/22 03:12:09 | 000,557,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptui.dll [color=#E56717]========== Services (All) ==========[/color] SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDWSCService) SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDUpdateService) SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDScannerService) SRV - [2016/12/07 19:31:16 | 000,197,128 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2016/12/07 16:35:05 | 000,153,752 | ---- | M] (Google Inc.) [On_Demand | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdatem) SRV - [2016/12/07 16:35:05 | 000,153,752 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate) SRV - [2016/11/28 15:19:02 | 010,216,688 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\TeamViewer_Service.exe -- (TeamViewer) SRV - [2016/09/20 12:54:54 | 000,324,224 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2016/05/09 07:05:26 | 000,054,800 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Windows\System32\tbaseprovisioning.exe -- (tbaseprovisioning) SRV - [2016/05/09 07:05:14 | 000,218,128 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility) SRV - [2014/12/03 03:01:58 | 000,743,688 | ---- | M] (DEVGURU Co., LTD.) [Auto | Running] -- C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe -- (ss_conn_service) SRV - [2014/03/18 09:10:37 | 000,299,008 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\bdesvc.dll -- (BDESVC) SRV - [2014/03/18 09:01:32 | 000,658,432 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\SearchIndexer.exe -- (WSearch) SRV - [2014/03/18 09:01:32 | 000,321,536 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\provsvc.dll -- (HomeGroupProvider) SRV - [2014/03/18 09:01:31 | 000,294,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\pnrpsvc.dll -- (PNRPsvc) SRV - [2014/03/18 09:01:31 | 000,294,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\pnrpsvc.dll -- (p2pimsvc) SRV - [2014/03/18 09:01:29 | 000,108,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService) SRV - [2014/03/18 09:01:28 | 001,210,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\workfolderssvc.dll -- (workfolderssvc) SRV - [2014/03/18 09:01:22 | 000,090,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wersvc.dll -- (WerSvc) SRV - [2014/03/18 09:01:22 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wercplsupport.dll -- (wercplsupport) SRV - [2014/03/18 09:01:21 | 000,613,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsm.dll -- (LSM) SRV - [2014/03/18 09:01:21 | 000,280,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\SessEnv.dll -- (SessionEnv) SRV - [2014/03/18 09:01:20 | 000,406,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AppReadiness.dll -- (AppReadiness) SRV - [2014/03/18 09:01:16 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wiaservc.dll -- (StiSvc) SRV - [2014/03/18 09:01:14 | 000,795,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\iphlpsvc.dll -- (iphlpsvc) SRV - [2014/03/18 09:01:14 | 000,730,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IKEEXT.DLL -- (IKEEXT) SRV - [2014/03/18 09:01:14 | 000,549,888 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\BFE.DLL -- (BFE) SRV - [2014/03/18 09:01:13 | 001,308,160 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wlansvc.dll -- (WlanSvc) SRV - [2014/03/18 09:01:13 | 000,457,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\rasmans.dll -- (RasMan) SRV - [2014/03/18 09:01:13 | 000,380,928 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\ipnathlp.dll -- (SharedAccess) SRV - [2014/03/18 09:01:13 | 000,370,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wcncsvc.dll -- (wcncsvc) SRV - [2014/03/18 09:01:13 | 000,300,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wcmsvc.dll -- (Wcmsvc) SRV - [2014/03/18 09:01:11 | 005,251,224 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\sppsvc.exe -- (sppsvc) SRV - [2014/03/18 09:01:11 | 002,871,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\WSService.dll -- (WSService) SRV - [2014/03/18 09:01:11 | 002,767,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\wuaueng.dll -- (wuauserv) SRV - [2014/03/18 09:01:11 | 001,165,312 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\gpsvc.dll -- (gpsvc) SRV - [2014/03/18 09:01:11 | 000,314,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wbiosrvc.dll -- (WbioSrvc) SRV - [2014/03/18 09:01:11 | 000,088,576 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\appinfo.dll -- (Appinfo) SRV - [2014/03/18 09:01:11 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AxInstSv.dll -- (AxInstSV) SRV - [2014/03/18 09:01:10 | 001,203,200 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wlidsvc.dll -- (wlidsvc) SRV - [2014/03/18 09:01:10 | 000,892,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\sysmain.dll -- (SysMain) SRV - [2014/03/18 09:01:10 | 000,357,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\defragsvc.dll -- (defragsvc) SRV - [2014/03/18 09:01:10 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\GeofenceMonitorService.dll -- (lfsvc) SRV - [2014/03/18 09:01:10 | 000,202,240 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\SystemEventsBrokerServer.dll -- (SystemEventsBroker) SRV - [2014/03/18 09:01:07 | 000,207,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\bisrv.dll -- (BrokerInfrastructure) SRV - [2014/03/18 09:01:07 | 000,160,768 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\aelupsvc.dll -- (AeLookupSvc) SRV - [2014/03/18 09:01:06 | 000,306,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\das.dll -- (DeviceAssociationService) SRV - [2014/03/18 09:01:05 | 000,570,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\vds.exe -- (vds) SRV - [2014/03/18 09:01:04 | 000,969,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\VSSVC.exe -- (VSS) SRV - [2014/03/18 09:01:04 | 000,623,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (Audiosrv) SRV - [2014/03/18 09:01:04 | 000,381,440 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\pcasvc.dll -- (PcaSvc) SRV - [2014/03/18 09:01:04 | 000,353,280 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\swprv.dll -- (swprv) SRV - [2014/03/18 09:01:04 | 000,174,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\AudioEndpointBuilder.dll -- (AudioEndpointBuilder) SRV - [2014/03/18 09:01:03 | 001,131,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AppXDeploymentServer.dll -- (AppXSvc) SRV - [2014/03/18 09:01:03 | 000,980,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\schedsvc.dll -- (Schedule) SRV - [2014/03/18 09:01:03 | 000,098,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wscsvc.dll -- (wscsvc) SRV - [2014/03/18 09:01:01 | 001,294,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wbengine.exe -- (wbengine) SRV - [2014/03/18 09:01:00 | 000,593,408 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (RpcSs) SRV - [2014/03/18 09:01:00 | 000,593,408 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (DcomLaunch) SRV - [2014/03/18 09:01:00 | 000,285,696 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp) SRV - [2014/03/18 09:01:00 | 000,186,880 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dnsrslvr.dll -- (Dnscache) SRV - [2014/03/18 09:01:00 | 000,184,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\profsvc.dll -- (ProfSvc) SRV - [2014/03/18 09:01:00 | 000,089,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\servicing\TrustedInstaller.exe -- (TrustedInstaller) SRV - [2014/03/18 08:42:19 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\appmgmts.dll -- (AppMgmt) SRV - [2014/03/18 08:42:19 | 000,075,104 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\KeyboardFilterSvc.dll -- (MsKeyboardFilter) SRV - [2014/03/18 08:42:17 | 000,642,560 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\cscsvc.dll -- (CscService) SRV - [2014/03/18 08:42:16 | 001,778,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2014/03/18 08:42:15 | 000,239,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\umrdp.dll -- (UmRdpService) SRV - [2014/03/18 08:42:12 | 000,174,080 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2013/08/22 07:13:54 | 000,056,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\RpcEpMap.dll -- (RpcEptMapper) SRV - [2013/08/22 07:13:54 | 000,034,072 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsass.exe -- (SamSs) SRV - [2013/08/22 07:13:54 | 000,021,504 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nsisvc.dll -- (nsi) SRV - [2013/08/22 06:21:45 | 000,017,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dllhost.exe -- (COMSysApp) SRV - [2013/08/22 06:18:20 | 000,278,264 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc) SRV - [2013/08/22 06:18:20 | 000,022,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend) SRV - [2013/08/22 06:17:49 | 002,407,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\spool\drivers\w32x86\3\PrintConfig.dll -- (PrintNotify) SRV - [2013/08/22 05:12:23 | 000,018,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lmhsvc.dll -- (lmhosts) SRV - [2013/08/22 05:12:14 | 000,009,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Locator.exe -- (RpcLocator) SRV - [2013/08/22 05:07:22 | 000,101,888 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\umpnpmgr.dll -- (PlugPlay) SRV - [2013/08/22 05:07:22 | 000,101,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\umpnpmgr.dll -- (DeviceInstall) SRV - [2013/08/22 05:05:54 | 000,029,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\hidserv.dll -- (hidserv) SRV - [2013/08/22 05:03:58 | 000,014,336 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\snmptrap.exe -- (SNMPTRAP) SRV - [2013/08/22 05:03:44 | 000,023,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\seclogon.dll -- (seclogon) SRV - [2013/08/22 05:03:29 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wephostsvc.dll -- (WEPHOSTSVC) SRV - [2013/08/22 05:03:12 | 000,028,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\efssvc.dll -- (EFS) SRV - [2013/08/22 04:58:06 | 000,128,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\TabSvc.dll -- (TabletInputService) SRV - [2013/08/22 04:56:51 | 000,055,808 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\msiexec.exe -- (msiserver) SRV - [2013/08/22 04:56:08 | 000,052,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wiarpc.dll -- (WiaRpc) SRV - [2013/08/22 04:55:59 | 000,093,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\rasauto.dll -- (RasAuto) SRV - [2013/08/22 04:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2013/08/22 04:55:11 | 000,036,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\UI0Detect.exe -- (UI0Detect) SRV - [2013/08/22 04:54:45 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\svsvc.dll -- (svsvc) SRV - [2013/08/22 04:54:39 | 000,075,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\KMSVC.DLL -- (hkmsvc) SRV - [2013/08/22 04:53:37 | 000,140,288 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\SCardSvr.dll -- (SCardSvr) SRV - [2013/08/22 04:50:48 | 000,098,304 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\fhsvc.dll -- (fhsvc) SRV - [2013/08/22 04:47:59 | 000,177,664 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\mprdim.dll -- (RemoteAccess) SRV - [2013/08/22 04:47:58 | 000,198,656 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\WebClnt.dll -- (WebClient) SRV - [2013/08/22 04:47:32 | 000,116,224 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\iscsiexe.dll -- (MSiSCSI) SRV - [2013/08/22 04:41:34 | 000,338,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\QAGENTRT.DLL -- (napagent) SRV - [2013/08/22 04:41:28 | 000,128,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\certprop.dll -- (SCPolicySvc) SRV - [2013/08/22 04:41:28 | 000,128,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\certprop.dll -- (CertPropSvc) SRV - [2013/08/22 04:37:49 | 000,034,304 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\WcsPlugInService.dll -- (WcsPlugInService) SRV - [2013/08/22 04:37:42 | 000,032,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\appidsvc.dll -- (AppIDSvc) SRV - [2013/08/22 04:33:38 | 000,248,320 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\tapisrv.dll -- (TapiSrv) SRV - [2013/08/22 04:30:41 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\lltdsvc.dll -- (lltdsvc) SRV - [2013/08/22 04:18:45 | 001,477,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pla.dll -- (pla) SRV - [2013/08/22 04:15:45 | 000,216,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dot3svc.dll -- (dot3svc) SRV - [2013/08/22 04:10:39 | 000,141,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\NcaSvc.dll -- (NcaSvc) SRV - [2013/08/22 04:07:03 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FXSSVC.exe -- (Fax) SRV - [2013/08/22 04:05:56 | 000,417,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicvss) SRV - [2013/08/22 04:05:56 | 000,417,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmictimesync) SRV - [2013/08/22 04:05:56 | 000,417,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicshutdown) SRV - [2013/08/22 04:05:56 | 000,417,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicrdv) SRV - [2013/08/22 04:05:56 | 000,417,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmickvpexchange) SRV - [2013/08/22 04:05:56 | 000,417,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicheartbeat) SRV - [2013/08/22 04:05:56 | 000,417,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicguestinterface) SRV - [2013/08/22 04:05:38 | 000,801,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\qmgr.dll -- (BITS) SRV - [2013/08/22 03:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\smphost.dll -- (smphost) SRV - [2013/08/22 03:53:20 | 000,116,736 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\regsvc.dll -- (RemoteRegistry) SRV - [2013/08/22 03:53:16 | 000,058,880 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpo.dll -- (Power) SRV - [2013/08/22 03:52:33 | 000,105,472 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\browser.dll -- (Browser) SRV - [2013/08/22 03:52:30 | 001,041,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\FntCache.dll -- (FontCache) SRV - [2013/08/22 03:52:30 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\cryptsvc.dll -- (CryptSvc) SRV - [2013/08/22 03:52:30 | 000,011,264 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wpcsvc.dll -- (WPCSvc) SRV - [2013/08/22 03:51:40 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes) SRV - [2013/08/22 03:50:51 | 000,337,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\w32time.dll -- (W32Time) SRV - [2013/08/22 03:49:34 | 000,105,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ScDeviceEnum.dll -- (ScDeviceEnum) SRV - [2013/08/22 03:49:21 | 000,688,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\netlogon.dll -- (Netlogon) SRV - [2013/08/22 03:48:12 | 000,044,032 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\keyiso.dll -- (KeyIso) SRV - [2013/08/22 03:48:07 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\mmcss.dll -- (THREADORDER) SRV - [2013/08/22 03:48:07 | 000,073,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\mmcss.dll -- (MMCSS) SRV - [2013/08/22 03:47:35 | 000,083,456 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\WUDFSvc.dll -- (wudfsvc) SRV - [2013/08/22 03:47:21 | 000,088,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\trkwks.dll -- (TrkWks) SRV - [2013/08/22 03:47:21 | 000,080,896 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\wdi.dll -- (WdiSystemHost) SRV - [2013/08/22 03:47:21 | 000,080,896 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\wdi.dll -- (WdiServiceHost) SRV - [2013/08/22 03:47:01 | 000,145,408 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dps.dll -- (DPS) SRV - [2013/08/22 03:46:52 | 000,230,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wkssvc.dll -- (LanmanWorkstation) SRV - [2013/08/22 03:46:47 | 000,072,704 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\alg.exe -- (ALG) SRV - [2013/08/22 03:46:38 | 000,054,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\Sens.dll -- (SENS) SRV - [2013/08/22 03:45:36 | 000,173,056 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\TimeBrokerServer.dll -- (TimeBroker) SRV - [2013/08/22 03:44:38 | 000,415,744 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netprofmsvc.dll -- (netprofm) SRV - [2013/08/22 03:44:32 | 000,022,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpauto.dll -- (PNRPAutoReg) SRV - [2013/08/22 03:44:14 | 000,128,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sstpsvc.dll -- (SstpSvc) SRV - [2013/08/22 03:43:51 | 000,174,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wbem\WMIsvc.dll -- (winmgmt) SRV - [2013/08/22 03:43:43 | 000,244,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\srvsvc.dll -- (LanmanServer) SRV - [2013/08/22 03:43:42 | 000,072,704 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\bthserv.dll -- (bthserv) SRV - [2013/08/22 03:43:38 | 000,140,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wbem\WmiApSrv.exe -- (wmiApSrv) SRV - [2013/08/22 03:41:55 | 000,124,928 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\ncbservice.dll -- (NcbService) SRV - [2013/08/22 03:41:18 | 000,029,184 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\FDResPub.dll -- (FDResPub) SRV - [2013/08/22 03:41:13 | 000,256,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\qwave.dll -- (QWAVE) SRV - [2013/08/22 03:41:06 | 001,280,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wevtsvc.dll -- (EventLog) SRV - [2013/08/22 03:40:49 | 000,091,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\eapsvc.dll -- (EapHost) SRV - [2013/08/22 03:39:12 | 000,136,192 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\msdtc.exe -- (MSDTC) SRV - [2013/08/22 03:39:08 | 000,589,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\winhttp.dll -- (WinHttpAutoProxySvc) SRV - [2013/08/22 03:39:05 | 000,196,608 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\vaultsvc.dll -- (VaultSvc) SRV - [2013/08/22 03:38:29 | 000,329,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\es.dll -- (EventSystem) SRV - [2013/08/22 03:37:51 | 000,307,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\msdtckrm.dll -- (KtmRm) SRV - [2013/08/22 03:35:57 | 000,182,272 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\ssdpsrv.dll -- (SSDPSRV) SRV - [2013/08/22 03:35:43 | 002,030,080 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\WsmSvc.dll -- (WinRM) SRV - [2013/08/22 03:34:50 | 000,307,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nlasvc.dll -- (NlaSvc) SRV - [2013/08/22 03:34:26 | 000,312,832 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IPSECSVC.DLL -- (PolicyAgent) SRV - [2013/08/22 03:34:25 | 000,157,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wecsvc.dll -- (Wecsvc) SRV - [2013/08/22 03:31:45 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\DeviceSetupManager.dll -- (DsmSvc) SRV - [2013/08/22 03:28:34 | 000,654,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\MPSSVC.dll -- (MpsSvc) SRV - [2013/08/22 03:27:56 | 000,424,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wwansvc.dll -- (WwanSvc) SRV - [2013/08/22 03:27:04 | 000,564,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (ShellHWDetection) SRV - [2013/08/22 03:22:15 | 000,017,408 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\fdPHost.dll -- (fdPHost) SRV - [2013/08/22 03:21:32 | 000,064,000 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\NcdAutoSetup.dll -- (NcdAutoSetup) SRV - [2013/08/22 03:19:09 | 000,223,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\ListSvc.dll -- (HomeGroupListener) SRV - [2013/08/22 03:18:51 | 000,534,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\spoolsv.exe -- (Spooler) SRV - [2013/08/22 03:17:38 | 000,359,936 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\p2psvc.dll -- (p2psvc) SRV - [2013/08/22 03:16:50 | 000,307,200 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\upnphost.dll -- (upnphost) SRV - [2013/08/22 03:16:41 | 000,202,752 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netman.dll -- (Netman) SRV - [2013/08/22 03:13:53 | 000,862,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\termsrv.dll -- (TermService) SRV - [2013/08/10 01:54:37 | 000,139,856 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing) [color=#E56717]========== Driver Services (All) ==========[/color] DRV - [2016/12/07 19:32:28 | 000,224,752 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswvmm.sys -- (aswVmm) DRV - [2016/12/07 19:32:27 | 000,433,768 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\Drivers\aswsp.sys -- (aswSP) DRV - [2016/12/07 19:32:25 | 000,735,488 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\Drivers\aswsnx.sys -- (aswSnx) DRV - [2016/12/07 19:31:40 | 000,118,664 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\System32\Drivers\aswStm.sys -- (aswStm) DRV - [2016/12/07 19:31:38 | 000,092,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\Drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2016/12/07 19:31:38 | 000,091,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\Drivers\aswRdr2.sys -- (aswRdr) DRV - [2016/12/07 19:31:38 | 000,060,424 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt) DRV - [2016/12/07 19:31:38 | 000,034,008 | ---- | M] (AVAST Software) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\aswHwid.sys -- (aswHwid) DRV - [2016/12/07 19:31:05 | 000,035,096 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\Drivers\aswKbd.sys -- (aswKbd) DRV - [2016/05/09 07:05:08 | 000,183,024 | ---- | M] (Advanced Micro Devices, Inc. ) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\amdpsp.sys -- (amdpsp) DRV - [2016/05/09 07:05:02 | 000,074,992 | ---- | M] (Advanced Micro Devices, Inc. ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\amdkmcsp.sys -- (amdkmcsp) DRV - [2016/05/09 07:05:02 | 000,034,096 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\amdkmpfd.sys -- (amdkmpfd) DRV - [2016/03/24 04:05:44 | 000,029,792 | ---- | M] (HP) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\WirelessButtonDriver86.sys -- (WirelessButtonDriver86) DRV - [2014/12/22 03:40:40 | 003,247,104 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\athwb.sys -- (athr) DRV - [2014/12/03 03:01:58 | 000,184,216 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\ssudmdm.sys -- (ssudmdm) DRV - [2014/12/03 03:01:58 | 000,090,008 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\ssudbus.sys -- (dg_ssudbus) DRV - [2014/03/18 09:01:37 | 000,139,096 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\wof.sys -- (Wof) DRV - [2014/03/18 09:01:32 | 000,502,616 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\fvevol.sys -- (fvevol) DRV - [2014/03/18 09:01:31 | 000,046,000 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\wpcfltr.sys -- (wpcfltr) DRV - [2014/03/18 09:01:22 | 001,326,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\dxgkrnl.sys -- (DXGKrnl) DRV - [2014/03/18 09:01:14 | 000,126,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\ipnat.sys -- (IPNAT) DRV - [2014/03/18 09:01:14 | 000,069,464 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\wfplwfs.sys -- (WFPLWFS) DRV - [2014/03/18 09:01:13 | 000,374,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\nwifi.sys -- (NativeWifiP) DRV - [2014/03/18 09:01:11 | 000,640,000 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\Drivers\PEAuth.sys -- (PEAUTH) DRV - [2014/03/18 09:01:11 | 000,072,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\appid.sys -- (AppID) DRV - [2014/03/18 09:01:10 | 000,122,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\msgpioclx.sys -- (GPIOClx0101) DRV - [2014/03/18 09:01:10 | 000,120,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\SerCx2.sys -- (SerCx2) DRV - [2014/03/18 09:01:07 | 000,063,832 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\System32\Drivers\fileinfo.sys -- (FileInfo) DRV - [2014/03/18 09:01:06 | 000,097,280 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\System32\Drivers\luafv.sys -- (luafv) DRV - [2014/03/18 09:01:05 | 000,198,488 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\rdyboost.sys -- (rdyboost) DRV - [2014/03/18 09:01:01 | 000,735,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\http.sys -- (HTTP) DRV - [2014/03/18 09:01:00 | 001,883,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\tcpip.sys -- (TCPIP6) DRV - [2014/03/18 09:01:00 | 001,883,480 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\tcpip.sys -- (Tcpip) DRV - [2014/03/18 09:01:00 | 001,679,704 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\ntfs.sys -- (Ntfs) DRV - [2014/03/18 09:01:00 | 000,869,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ndis.sys -- (NDIS) DRV - [2014/03/18 09:01:00 | 000,559,616 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\Drivers\srv2.sys -- (srv2) DRV - [2014/03/18 09:01:00 | 000,482,424 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\cng.sys -- (CNG) DRV - [2014/03/18 09:01:00 | 000,336,896 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\System32\Drivers\srv.sys -- (srv) DRV - [2014/03/18 09:01:00 | 000,333,824 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\Drivers\mrxsmb.sys -- (mrxsmb) DRV - [2014/03/18 09:01:00 | 000,309,248 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\System32\Drivers\rdbss.sys -- (rdbss) DRV - [2014/03/18 09:01:00 | 000,271,192 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\System32\Drivers\fltMgr.sys -- (FltMgr) DRV - [2014/03/18 09:01:00 | 000,185,856 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\Drivers\srvnet.sys -- (srvnet) DRV - [2014/03/18 09:01:00 | 000,156,160 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\Drivers\mrxsmb20.sys -- (mrxsmb20) DRV - [2014/03/18 09:01:00 | 000,147,800 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ksecpkg.sys -- (KSecPkg) DRV - [2014/03/18 09:01:00 | 000,142,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\VerifierExt.sys -- (VerifierExt) DRV - [2014/03/18 09:01:00 | 000,101,376 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\System32\Drivers\dfsc.sys -- (Dfsc) DRV - [2014/03/18 09:01:00 | 000,077,656 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ksecdd.sys -- (KSecDD) DRV - [2014/03/18 09:00:59 | 001,015,808 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\bthport.sys -- (BTHPORT) DRV - [2014/03/18 09:00:59 | 000,431,960 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\acpi.sys -- (ACPI) DRV - [2014/03/18 09:00:59 | 000,411,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\vhdmp.sys -- (vhdmp) DRV - [2014/03/18 09:00:59 | 000,376,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\USBHUB3.SYS -- (USBHUB3) DRV - [2014/03/18 09:00:59 | 000,333,656 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\spaceport.sys -- (spaceport) DRV - [2014/03/18 09:00:59 | 000,265,048 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\volsnap.sys -- (volsnap) DRV - [2014/03/18 09:00:59 | 000,261,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\USBXHCI.SYS -- (USBXHCI) DRV - [2014/03/18 09:00:59 | 000,211,800 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\pci.sys -- (pci) DRV - [2014/03/18 09:00:59 | 000,197,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\sdbus.sys -- (sdbus) DRV - [2014/03/18 09:00:59 | 000,186,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\BthLEEnum.sys -- (BthLEEnum) DRV - [2014/03/18 09:00:59 | 000,163,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\UCX01000.SYS -- (UCX01000) DRV - [2014/03/18 09:00:59 | 000,132,096 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\rfcomm.sys -- (RFCOMM) DRV - [2014/03/18 09:00:59 | 000,120,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\USBSTOR.SYS -- (USBSTOR) DRV - [2014/03/18 09:00:59 | 000,104,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\usbccgp.sys -- (usbccgp) DRV - [2014/03/18 09:00:59 | 000,077,144 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\pdc.sys -- (pdc) DRV - [2014/03/18 09:00:59 | 000,064,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\sdstor.sys -- (sdstor) DRV - [2014/03/18 09:00:59 | 000,061,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\BTHUSB.SYS -- (BTHUSB) DRV - [2014/03/18 09:00:59 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\bthmodem.sys -- (BTHMODEM) DRV - [2014/03/18 09:00:59 | 000,047,960 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\stornvme.sys -- (stornvme) DRV - [2014/03/18 09:00:59 | 000,036,696 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\intelpep.sys -- (intelpep) DRV - [2014/03/18 09:00:59 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\BasicRender.sys -- (BasicRender) DRV - [2014/03/18 08:42:20 | 000,019,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\kbldfltr.sys -- (kbldfltr) DRV - [2014/03/18 08:42:19 | 000,023,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV - [2014/03/18 08:42:17 | 000,143,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\rdpdr.sys -- (RDPDR) DRV - [2014/03/18 08:42:15 | 000,439,808 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\csc.sys -- (CSC) DRV - [2014/03/18 08:42:06 | 000,030,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\terminpt.sys -- (terminpt) DRV - [2013/08/22 09:16:23 | 000,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\secdrv.sys -- (secdrv) DRV - [2013/08/22 07:13:54 | 000,455,168 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\afd.sys -- (AFD) DRV - [2013/08/22 07:13:54 | 000,182,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\msrpc.sys -- (MsRPC) DRV - [2013/08/22 07:13:54 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\tdx.sys -- (tdx) DRV - [2013/08/22 07:13:54 | 000,028,160 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\nsiproxy.sys -- (nsiproxy) DRV - [2013/08/22 07:13:53 | 000,614,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\Wdf01000.sys -- (Wdf01000) DRV - [2013/08/22 07:13:53 | 000,081,760 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\mountmgr.sys -- (mountmgr) DRV - [2013/08/22 07:13:53 | 000,068,960 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\partmgr.sys -- (partmgr) DRV - [2013/08/22 07:13:53 | 000,044,544 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\npfs.sys -- (Npfs) DRV - [2013/08/22 07:13:53 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\condrv.sys -- (condrv) DRV - [2013/08/22 07:13:53 | 000,024,928 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\System32\drivers\fs_rec.sys -- (Fs_Rec) DRV - [2013/08/22 07:13:53 | 000,024,064 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\msfs.sys -- (Msfs) DRV - [2013/08/22 07:13:53 | 000,005,120 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\null.sys -- (Null) DRV - [2013/08/22 06:35:21 | 000,053,088 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\Drivers\dam.sys -- (dam) DRV - [2013/08/22 06:35:21 | 000,049,504 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\Drivers\fsdepends.sys -- (FsDepends) DRV - [2013/08/22 06:35:20 | 000,179,552 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\fastfat.sys -- (fastfat) DRV - [2013/08/22 06:35:20 | 000,061,280 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\acpiex.sys -- (acpiex) DRV - [2013/08/22 06:34:53 | 000,098,656 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\pcmcia.sys -- (pcmcia) DRV - [2013/08/22 06:34:53 | 000,054,624 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\System32\Drivers\mup.sys -- (Mup) DRV - [2013/08/22 06:34:52 | 000,133,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\tpm.sys -- (TPM) DRV - [2013/08/22 06:34:52 | 000,032,608 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\mssmbios.sys -- (mssmbios) DRV - [2013/08/22 06:33:33 | 000,141,664 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\nvstor.sys -- (nvstor) DRV - [2013/08/22 06:33:33 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\NV_AGP.SYS -- (nv_agp) DRV - [2013/08/22 06:33:33 | 000,014,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\pciide.sys -- (pciide) DRV - [2013/08/22 06:33:32 | 000,239,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\msiscsi.sys -- (iScsiPrt) DRV - [2013/08/22 06:33:32 | 000,120,160 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\nvraid.sys -- (nvraid) DRV - [2013/08/22 06:33:32 | 000,058,208 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\mvumis.sys -- (mvumis) DRV - [2013/08/22 06:33:32 | 000,015,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\msisadrv.sys -- (msisadrv) DRV - [2013/08/22 06:33:31 | 000,033,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\msgpiowin32.sys -- (msgpiowin32) DRV - [2013/08/22 06:33:30 | 000,079,712 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\lsi_sas2.sys -- (LSI_SAS2) DRV - [2013/08/22 06:33:30 | 000,068,960 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\lsi_sas3.sys -- (LSI_SAS3) DRV - [2013/08/22 06:33:30 | 000,051,552 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\megasas.sys -- (megasas) DRV - [2013/08/22 06:33:30 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\mouclass.sys -- (mouclass) DRV - [2013/08/22 06:33:29 | 000,464,736 | ---- | M] (LSI Corporation, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\megasr.sys -- (megasr) DRV - [2013/08/22 06:33:29 | 000,333,664 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\iaStorV.sys -- (iaStorV) DRV - [2013/08/22 06:33:29 | 000,094,048 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\lsi_sas.sys -- (LSI_SAS) DRV - [2013/08/22 06:33:29 | 000,069,472 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\lsi_sss.sys -- (LSI_SSS) DRV - [2013/08/22 06:33:29 | 000,059,744 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\GAGP30KX.SYS -- (gagp30kx) DRV - [2013/08/22 06:33:29 | 000,056,672 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\HpSAMD.sys -- (HpSAMD) DRV - [2013/08/22 06:33:29 | 000,048,480 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\isapnp.sys -- (isapnp) DRV - [2013/08/22 06:33:29 | 000,045,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\kbdclass.sys -- (kbdclass) DRV - [2013/08/22 06:33:29 | 000,016,736 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\intelide.sys -- (intelide) DRV - [2013/08/22 06:33:26 | 000,215,392 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\amdsbs.sys -- (amdsbs) DRV - [2013/08/22 06:33:26 | 000,101,728 | ---- | M] (PMC-Sierra, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\arcsas.sys -- (arcsas) DRV - [2013/08/22 06:33:26 | 000,086,368 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\3ware.sys -- (3ware) DRV - [2013/08/22 06:33:26 | 000,056,160 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\AGP440.sys -- (agp440) DRV - [2013/08/22 06:33:25 | 000,773,472 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\adp80xx.sys -- (ADP80XX) DRV - [2013/08/22 06:33:25 | 000,100,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv) DRV - [2013/08/22 06:33:25 | 000,072,544 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\amdsata.sys -- (amdsata) DRV - [2013/08/22 06:33:25 | 000,023,392 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\atapi.sys -- (atapi) DRV - [2013/08/22 06:33:24 | 000,073,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\EhStorClass.sys -- (EhStorClass) DRV - [2013/08/22 06:33:24 | 000,056,160 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\AMDAGP.SYS -- (amdagp) DRV - [2013/08/22 06:33:24 | 000,022,880 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\amdxata.sys -- (amdxata) DRV - [2013/08/22 06:33:01 | 000,339,296 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\usbhub.sys -- (usbhub) DRV - [2013/08/22 06:33:01 | 000,276,832 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\VSTXRAID.SYS -- (VSTXRAID) DRV - [2013/08/22 06:33:01 | 000,148,832 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\vsmraid.sys -- (vsmraid) DRV - [2013/08/22 06:33:00 | 000,056,160 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\VIAAGP.SYS -- (viaagp) DRV - [2013/08/22 06:33:00 | 000,018,272 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\viaide.sys -- (viaide) DRV - [2013/08/22 06:32:58 | 000,059,744 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\ULIAGPKX.SYS -- (uliagpkx) DRV - [2013/08/22 06:32:57 | 000,090,976 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\storahci.sys -- (storahci) DRV - [2013/08/22 06:32:57 | 000,079,200 | ---- | M] (Silicon Integrated Systems) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\sisraid4.sys -- (SiSRaid4) DRV - [2013/08/22 06:32:57 | 000,073,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\usbehci.sys -- (usbehci) DRV - [2013/08/22 06:32:57 | 000,059,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\SpbCx.sys -- (SpbCx) DRV - [2013/08/22 06:32:57 | 000,058,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\UAGP35.SYS -- (uagp35) DRV - [2013/08/22 06:32:57 | 000,058,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\SerCx.sys -- (SerCx) DRV - [2013/08/22 06:32:57 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\uaspstor.sys -- (UASPStor) DRV - [2013/08/22 06:32:57 | 000,026,976 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\stexstor.sys -- (stexstor) DRV - [2013/08/22 06:32:57 | 000,013,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\swenum.sys -- (swenum) DRV - [2013/08/22 06:32:56 | 000,054,624 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\SISAGP.SYS -- (sisagp) DRV - [2013/08/22 06:32:56 | 000,041,312 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\sisraid2.sys -- (SiSRaid2) DRV - [2013/08/22 06:32:38 | 000,031,584 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\Drivers\cnghwassist.sys -- (cnghwassist) DRV - [2013/08/22 06:31:48 | 000,029,536 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\Drivers\wimmount.sys -- (WIMMount) DRV - [2013/08/22 06:26:00 | 000,014,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\drmkaud.sys -- (drmkaud) DRV - [2013/08/22 06:25:44 | 000,090,464 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\sbp2port.sys -- (sbp2port) DRV - [2013/08/22 06:25:43 | 000,042,848 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\pcw.sys -- (pcw) DRV - [2013/08/22 06:25:39 | 000,023,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\hwpolicy.sys -- (hwpolicy) DRV - [2013/08/22 06:25:37 | 000,284,000 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\clfs.sys -- (CLFS) DRV - [2013/08/22 06:25:37 | 000,083,808 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\disk.sys -- (disk) DRV - [2013/08/22 06:24:56 | 000,311,136 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\volmgrx.sys -- (volmgrx) DRV - [2013/08/22 06:24:56 | 000,058,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\volmgr.sys -- (volmgr) DRV - [2013/08/22 06:24:56 | 000,023,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\uefi.sys -- (UEFI) DRV - [2013/08/22 06:21:13 | 000,034,656 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\vdrvroot.sys -- (vdrvroot) DRV - [2013/08/22 06:20:49 | 000,093,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\WdNisDrv.sys -- (WdNisDrv) DRV - [2013/08/22 06:20:48 | 000,214,368 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\System32\Drivers\WdFilter.sys -- (WdFilter) DRV - [2013/08/22 06:20:22 | 000,093,248 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\vmbus.sys -- (vmbus) DRV - [2013/08/22 06:20:22 | 000,045,376 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\vmstorfl.sys -- (storflt) DRV - [2013/08/22 06:20:22 | 000,042,304 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\storvsc.sys -- (storvsc) DRV - [2013/08/22 06:17:00 | 000,029,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\WdBoot.sys -- (WdBoot) DRV - [2013/08/22 05:12:02 | 000,006,144 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\beep.sys -- (Beep) DRV - [2013/08/22 05:12:00 | 000,261,120 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\System32\Drivers\udfs.sys -- (udfs) DRV - [2013/08/22 05:11:59 | 000,164,864 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\exfat.sys -- (exfat) DRV - [2013/08/22 05:11:58 | 000,026,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\fdc.sys -- (fdc) DRV - [2013/08/22 05:11:56 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\flpydisk.sys -- (flpydisk) DRV - [2013/08/22 05:11:56 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\serenum.sys -- (Serenum) DRV - [2013/08/22 05:11:55 | 000,073,728 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\System32\Drivers\cdfs.sys -- (cdfs) DRV - [2013/08/22 05:11:52 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\modem.sys -- (Modem) DRV - [2013/08/22 05:11:49 | 000,081,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\parport.sys -- (Parport) DRV - [2013/08/22 05:11:47 | 000,077,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\serial.sys -- (Serial) DRV - [2013/08/22 05:11:47 | 000,008,704 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\Windows\System32\Drivers\parvdm.sys -- (Parvdm) DRV - [2013/08/22 05:11:45 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\wmiacpi.sys -- (WmiAcpi) DRV - [2013/08/22 05:11:40 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\Drivers\ws2ifsl.sys -- (ws2ifsl) DRV - [2013/08/22 05:11:38 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\sermouse.sys -- (sermouse) DRV - [2013/08/22 05:11:38 | 000,013,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\sfloppy.sys -- (sfloppy) DRV - [2013/08/22 05:11:38 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\rasacd.sys -- (RasAcd) DRV - [2013/08/22 05:11:29 | 000,063,488 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\ahcache.sys -- (ahcache) DRV - [2013/08/22 05:11:21 | 000,029,184 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\Drivers\filetrace.sys -- (Filetrace) DRV - [2013/08/22 05:11:09 | 000,021,120 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\CmBatt.sys -- (CmBatt) DRV - [2013/08/22 05:11:06 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\usbuhci.sys -- (usbuhci) DRV - [2013/08/22 05:11:04 | 000,043,520 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\BasicDisplay.sys -- (BasicDisplay) DRV - [2013/08/22 05:11:04 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\qwavedrv.sys -- (QWAVEdrv) DRV - [2013/08/22 05:11:03 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\usbohci.sys -- (usbohci) DRV - [2013/08/22 05:11:02 | 000,008,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mskssrv.sys -- (MSKSSRV) DRV - [2013/08/22 05:11:02 | 000,006,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mspqm.sys -- (MSPQM) DRV - [2013/08/22 05:11:02 | 000,006,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mspclock.sys -- (MSPCLOCK) DRV - [2013/08/22 05:10:59 | 000,082,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\i8042prt.sys -- (i8042prt) DRV - [2013/08/22 05:10:57 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\ndistapi.sys -- (NdisTapi) DRV - [2013/08/22 05:10:49 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\hidir.sys -- (HidIr) DRV - [2013/08/22 05:10:46 | 000,024,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\kbdhid.sys -- (kbdhid) DRV - [2013/08/22 05:10:46 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mouhid.sys -- (mouhid) DRV - [2013/08/22 05:10:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\HyperVideo.sys -- (HyperVideo) DRV - [2013/08/22 05:10:41 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\wacompen.sys -- (WacomPen) DRV - [2013/08/22 05:10:37 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mshidumdf.sys -- (mshidumdf) DRV - [2013/08/22 05:10:36 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mshidkmdf.sys -- (mshidkmdf) DRV - [2013/08/22 05:10:35 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\hidbatt.sys -- (HidBatt) DRV - [2013/08/22 05:10:34 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\vwifibus.sys -- (vwifibus) DRV - [2013/08/22 05:10:32 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\hidusb.sys -- (HidUsb) DRV - [2013/08/22 05:10:30 | 000,040,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\umbus.sys -- (umbus) DRV - [2013/08/22 05:10:30 | 000,009,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\umpass.sys -- (UmPass) DRV - [2013/08/22 05:10:28 | 000,008,704 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\acpitime.sys -- (acpitime) DRV - [2013/08/22 05:10:27 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\IPMIDrv.sys -- (IPMIDRV) DRV - [2013/08/22 05:10:24 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\acpipmi.sys -- (AcpiPmi) DRV - [2013/08/22 05:10:23 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\rdpbus.sys -- (rdpbus) DRV - [2013/08/22 05:10:21 | 000,009,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\acpipagr.sys -- (acpipagr) DRV - [2013/08/22 05:10:19 | 000,037,888 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\System32\Drivers\netbios.sys -- (NetBIOS) DRV - [2013/08/22 05:10:18 | 000,007,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\errdev.sys -- (ErrDev) DRV - [2013/08/22 05:10:15 | 000,080,896 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\Drivers\bowser.sys -- (bowser) DRV - [2013/08/22 05:10:12 | 000,069,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\hdaudbus.sys -- (HDAudBus) DRV - [2013/08/22 05:10:11 | 000,082,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\hidbth.sys -- (HidBth) DRV - [2013/08/22 05:10:09 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\CompositeBus.sys -- (CompositeBus) DRV - [2013/08/22 05:10:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\npsvctrig.sys -- (npsvctrig) DRV - [2013/08/22 05:10:04 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\irenum.sys -- (IRENUM) DRV - [2013/08/22 05:10:01 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg) DRV - [2013/08/22 05:10:00 | 000,088,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\usbcir.sys -- (usbcir) DRV - [2013/08/22 05:09:59 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\kdnic.sys -- (kdnic) DRV - [2013/08/22 05:09:58 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\circlass.sys -- (circlass) DRV - [2013/08/22 05:09:57 | 000,006,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\vms3cap.sys -- (s3cap) DRV - [2013/08/22 05:09:57 | 000,006,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mstee.sys -- (MSTEE) DRV - [2013/08/22 05:09:50 | 000,011,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\vmgencounter.sys -- (gencounter) DRV - [2013/08/22 05:09:45 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ndproxy.sys -- (NDProxy) DRV - [2013/08/22 05:09:44 | 000,035,840 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\scfilter.sys -- (scfilter) DRV - [2013/08/22 05:09:42 | 000,170,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\1394ohci.sys -- (1394ohci) DRV - [2013/08/22 05:09:40 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\vwififlt.sys -- (vwififlt) DRV - [2013/08/22 05:09:40 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\ndiscap.sys -- (NdisCap) DRV - [2013/08/22 05:09:37 | 000,023,808 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BthhfHid.sys -- (bthhfhid) DRV - [2013/08/22 05:09:32 | 000,304,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\HdAudio.sys -- (HdAudAddService) DRV - [2013/08/22 05:09:18 | 000,176,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\usbvideo.sys -- (usbvideo) DRV - [2013/08/22 05:09:15 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\bthhfenum.sys -- (BthHFEnum) DRV - [2013/08/22 05:09:10 | 000,026,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\TsUsbGD.sys -- (TsUsbGD) DRV - [2013/08/22 05:09:10 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\MTConfig.sys -- (MTConfig) DRV - [2013/08/22 05:09:09 | 000,012,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\hyperkbd.sys -- (hyperkbd) DRV - [2013/08/22 05:09:08 | 000,049,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\ndisuio.sys -- (Ndisuio) DRV - [2013/08/22 05:09:05 | 000,124,416 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mrxdav.sys -- (MRxDAV) DRV - [2013/08/22 05:09:03 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2013/08/22 05:09:01 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\hidi2c.sys -- (hidi2c) DRV - [2013/08/22 05:09:01 | 000,018,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\VMBusHID.sys -- (VMBusHID) DRV - [2013/08/22 05:08:47 | 000,102,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\WUDFPf.sys -- (WudfPf) DRV - [2013/08/22 05:08:37 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\dmvsc.sys -- (dmvsc) DRV - [2013/08/22 05:08:36 | 000,187,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\WUDFRd.sys -- (WUDFRd) DRV - [2013/08/22 05:08:29 | 000,040,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\bthenum.sys -- (BthEnum) DRV - [2013/08/22 05:08:26 | 000,218,624 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\netbt.sys -- (NetBT) DRV - [2013/08/22 05:08:18 | 000,072,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\netvsc63.sys -- (netvsc) DRV - [2013/08/22 05:08:17 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\raspppoe.sys -- (RasPppoe) DRV - [2013/08/22 05:08:14 | 000,024,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\monitor.sys -- (monitor) DRV - [2013/08/22 05:08:08 | 000,064,000 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\Drivers\rspndr.sys -- (rspndr) DRV - [2013/08/22 05:08:08 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\usbprint.sys -- (usbprint) DRV - [2013/08/22 05:08:06 | 000,013,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\NdisVirtualBus.sys -- (NdisVirtualBus) DRV - [2013/08/22 05:07:58 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\Drivers\lltdio.sys -- (lltdio) DRV - [2013/08/22 05:07:57 | 000,109,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\NdisImPlatform.sys -- (NdisImPlatform) DRV - [2013/08/22 05:07:55 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mslldp.sys -- (MsLldp) DRV - [2013/08/22 05:07:53 | 000,029,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\vwifimp.sys -- (vwifimp) DRV - [2013/08/22 05:07:46 | 000,227,840 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\System32\Drivers\mrxsmb10.sys -- (mrxsmb10) DRV - [2013/08/22 05:07:45 | 000,167,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\ndiswan.sys -- (NdisWanLegacy) DRV - [2013/08/22 05:07:45 | 000,167,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\ndiswan.sys -- (NdisWan) DRV - [2013/08/22 05:07:45 | 000,095,744 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\bthpan.sys -- (BthPan) DRV - [2013/08/22 05:07:39 | 000,123,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\tunnel.sys -- (tunnel) DRV - [2013/08/22 05:07:39 | 000,037,888 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\Drivers\tcpipreg.sys -- (tcpipreg) DRV - [2013/08/22 05:07:35 | 000,120,832 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\pacer.sys -- (Psched) DRV - [2013/08/22 05:07:35 | 000,054,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\mpsdrv.sys -- (mpsdrv) DRV - [2013/08/22 05:07:33 | 000,098,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\bridge.sys -- (MsBridge) DRV - [2013/08/22 05:07:19 | 000,091,136 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\Drivers\Ndu.sys -- (Ndu) DRV - [2013/08/22 05:07:18 | 000,065,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\ipfltdrv.sys -- (IpFilterDriver) DRV - [2013/08/22 02:59:12 | 000,124,928 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\cdrom.sys -- (cdrom) DRV - [2013/08/22 02:58:53 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\intelppm.sys -- (intelppm) DRV - [2013/08/22 02:58:53 | 000,086,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\amdk8.sys -- (AmdK8) DRV - [2013/08/22 02:58:53 | 000,083,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\viac7.sys -- (ViaC7) DRV - [2013/08/22 02:58:53 | 000,083,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\processr.sys -- (Processor) DRV - [2013/08/22 02:58:53 | 000,083,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\amdppm.sys -- (AmdPPM) DRV - [2013/08/22 02:58:35 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\fxppm.sys -- (FxPPM) DRV - [2013/08/13 00:25:32 | 000,016,088 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\bcmfn2.sys -- (bcmfn2) DRV - [2013/08/10 01:39:44 | 000,524,784 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\iaStorAV.sys -- (iaStorAV) DRV - [2013/07/23 22:18:30 | 000,061,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\iaioi2c.sys -- (iaioi2c) DRV - [2013/07/23 22:18:30 | 000,022,016 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\iaiogpio.sys -- (GPIO) DRV - [2013/06/18 13:23:13 | 000,490,496 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\Rt630x86.sys -- (RTL8168) [color=#E56717]========== Standard Registry (All) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1852234611-3025222955-2826060463-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKU\S-1-5-21-1852234611-3025222955-2826060463-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKU\S-1-5-21-1852234611-3025222955-2826060463-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 IE - HKU\S-1-5-21-1852234611-3025222955-2826060463-1001\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation) IE - HKU\S-1-5-21-1852234611-3025222955-2826060463-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1852234611-3025222955-2826060463-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR IE - HKU\S-1-5-21-1852234611-3025222955-2826060463-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.countryCode: "FR" FF - prefs.js..browser.search.region: "FR" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:50.0.2 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1225195.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.111.2: C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.111.2: C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\sp@avast.com: C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016/12/07 19:31:44 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2016/12/07 19:31:45 | 000,000,000 | ---D | M] [2016/12/07 16:34:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Meliodas-sama\AppData\Roaming\mozilla\Extensions [2016/12/07 16:45:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Meliodas-sama\AppData\Roaming\mozilla\Firefox\Profiles\j9btoglv.default\extensions [color=#E56717]========== Chrome ==========[/color] CHR - Extension: No name found = C:\Users\Meliodas-sama\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\ CHR - Extension: No name found = C:\Users\Meliodas-sama\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\ CHR - Extension: No name found = C:\Users\Meliodas-sama\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\ CHR - Extension: No name found = C:\Users\Meliodas-sama\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\ CHR - Extension: No name found = C:\Users\Meliodas-sama\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\ CHR - Extension: No name found = C:\Users\Meliodas-sama\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\ CHR - Extension: No name found = C:\Users\Meliodas-sama\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\12.0.124_0\ CHR - Extension: No name found = C:\Users\Meliodas-sama\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\\ CHR - Extension: No name found = C:\Users\Meliodas-sama\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\ CHR - Extension: No name found = C:\Users\Meliodas-sama\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\ O1 HOSTS File: ([2013/08/22 07:13:55 | 000,000,824 | ---- | M]) - C:\Windows\System32\Drivers\etc\hosts O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll (Oracle Corporation) O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.) O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Oracle Corporation) O4 - HKU\.DEFAULT..\Run: [SpybotPostWindows10UpgradeReInstall] C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe (Safer-Networking Ltd.) O4 - HKU\S-1-5-18..\Run: [SpybotPostWindows10UpgradeReInstall] C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe (Safer-Networking Ltd.) O4 - HKU\S-1-5-21-1852234611-3025222955-2826060463-1001..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd) O4 - HKU\S-1-5-21-1852234611-3025222955-2826060463-1001..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.) O4 - HKU\S-1-5-21-1852234611-3025222955-2826060463-1001..\Run: [uTorrent] C:\Users\Meliodas-sama\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7 O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\System32\NapiNSP.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\nlaapi.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\winrnr.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Windows\System32\mswsock.dll (Microsoft Corporation) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{698F67B9-4DD8-4FD0-A3B5-49CB1294BFD6}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E57D5D45-FA43-496C-9272-5072B9C8D390}: DhcpNameServer = O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation) O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation) O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll (Microsoft Corporation) O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation) O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation) O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\System32\credssp.dll (Microsoft Corporation) O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2013/08/22 09:16:09 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2016/12/10 00:31:16 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\YYmm [2016/12/10 00:31:16 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\YYebookset [2016/12/10 00:25:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Steam [2016/12/10 00:13:58 | 000,000,000 | ---D | C] -- C:\Program Files\Age of Mythology Extended Edition [2016/12/09 20:57:03 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Local\ElevatedDiagnostics [2016/12/09 20:35:33 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Local\SKIDROW [2016/12/09 20:03:27 | 000,000,000 | ---D | C] -- C:\ProgramData\TweakBit [2016/12/09 19:38:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache [2016/12/09 17:24:22 | 000,000,000 | ---D | C] -- C:\Program Files\R.G. Mechanics [2016/12/09 16:46:35 | 000,000,000 | ---D | C] -- C:\Program Files\StarCraft II [2016/12/09 16:36:14 | 000,184,216 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\System32\drivers\ssudmdm.sys [2016/12/09 16:36:13 | 000,090,008 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\System32\drivers\ssudbus.sys [2016/12/09 16:35:17 | 000,000,000 | ---D | C] -- C:\Program Files\SAMSUNG [2016/12/09 16:31:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Samsung [2016/12/09 16:31:28 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\WinRAR [2016/12/09 13:22:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II [2016/12/08 23:54:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler [2016/12/08 23:54:23 | 000,000,000 | ---D | C] -- C:\Program Files\Defraggler [2016/12/08 21:36:10 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\Documents\StarCraft II [2016/12/08 20:56:17 | 000,000,000 | ---D | C] -- C:\Program Files\Battle.net [2016/12/08 19:17:17 | 000,821,920 | ---- | C] (Safer-Networking Ltd. ) -- C:\Users\Public\Desktop\Post Win10 Spybot-install.exe [2016/12/08 18:34:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 [2016/12/08 18:33:47 | 000,018,968 | ---- | C] (Safer Networking Limited) -- C:\Windows\System32\sdnclean.exe [2016/12/08 18:33:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy [2016/12/08 18:33:27 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy 2 [2016/12/08 18:30:44 | 000,000,000 | ---D | C] -- C:\AdwCleaner [2016/12/08 18:27:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [2016/12/08 18:27:23 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2016/12/08 16:06:09 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\Tracing [2016/12/08 16:06:01 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\Skype [2016/12/07 23:05:54 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Local\Blizzard Entertainment [2016/12/07 23:05:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment [2016/12/07 23:05:34 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Local\Battle.net [2016/12/07 22:45:50 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\Battle.net [2016/12/07 22:45:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Battle.net [2016/12/07 22:20:08 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\uTorrent [2016/12/07 22:09:01 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\Desktop\One Piece (1) [2016/12/07 21:01:24 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\OneDrive [2016/12/07 19:35:47 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Local\CEF [2016/12/07 19:35:44 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Local\Steam [2016/12/07 19:34:32 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\AVAST Software [2016/12/07 19:34:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software [2016/12/07 19:32:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AV [2016/12/07 19:31:55 | 000,735,488 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswsnx.sys [2016/12/07 19:31:55 | 000,433,768 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswsp.sys [2016/12/07 19:31:55 | 000,224,752 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswvmm.sys [2016/12/07 19:31:55 | 000,118,664 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswStm.sys [2016/12/07 19:31:55 | 000,092,256 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2016/12/07 19:31:55 | 000,091,232 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys [2016/12/07 19:31:55 | 000,060,424 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRvrt.sys [2016/12/07 19:31:55 | 000,035,096 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswKbd.sys [2016/12/07 19:31:55 | 000,034,008 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswHwid.sys [2016/12/07 19:31:47 | 000,921,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\ucrtbase.dll [2016/12/07 19:31:47 | 000,319,760 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2016/12/07 19:31:23 | 000,053,208 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2016/12/07 19:30:42 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2016/12/07 19:29:52 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software [2016/12/07 19:29:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth [2016/12/07 19:29:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2016/12/07 19:29:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype [2016/12/07 19:29:19 | 000,000,000 | R--D | C] -- C:\Program Files\Skype [2016/12/07 19:29:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype [2016/12/07 19:29:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2016/12/07 19:28:45 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN [2016/12/07 19:28:21 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\TeamViewer [2016/12/07 19:28:04 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer [2016/12/07 19:27:33 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR [2016/12/07 19:27:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR [2016/12/07 19:27:29 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR [2016/12/07 19:27:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Steam [2016/12/07 19:26:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\Adobe [2016/12/07 19:25:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2016/12/07 19:25:42 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\Sun [2016/12/07 19:25:38 | 000,095,808 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll [2016/12/07 19:25:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java [2016/12/07 19:24:44 | 000,000,000 | ---D | C] -- C:\Program Files\Java [2016/12/07 19:24:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle [2016/12/07 19:19:45 | 000,000,000 | ---D | C] -- C:\Windows\System32\appmgmt [2016/12/07 19:17:23 | 000,257,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEShims.dll [2016/12/07 19:17:23 | 000,000,000 | ---D | C] -- C:\Windows\tbaseregistry [2016/12/07 18:57:20 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Local\Programs [2016/12/07 18:55:47 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Local\Google [2016/12/07 16:45:29 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\Macromedia [2016/12/07 16:42:49 | 000,034,096 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\amdkmpfd.sys [2016/12/07 16:42:47 | 000,000,000 | ---D | C] -- C:\Program Files\AMD [2016/12/07 16:42:16 | 000,000,000 | ---D | C] -- C:\Program Files\HP [2016/12/07 16:39:37 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\AppData\Local\EmieUserList [2016/12/07 16:39:37 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\AppData\Local\EmieSiteList [2016/12/07 16:36:28 | 000,000,000 | ---D | C] -- C:\Program Files\Google [2016/12/07 16:34:45 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\Mozilla [2016/12/07 16:34:45 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Local\Mozilla [2016/12/07 16:30:19 | 000,422,480 | ---- | C] (Secure By Design Inc.) -- C:\Users\Meliodas-sama\Desktop\Ninite Avast Chrome Firefox Google Earth Java 8 Installer.exe [2016/12/07 16:19:37 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2016/12/07 16:19:37 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\Searches [2016/12/07 16:19:37 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2016/12/07 16:19:36 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\Contacts [2016/12/07 16:19:36 | 000,000,000 | -H-D | C] -- C:\Users\Meliodas-sama\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned [2016/12/07 16:19:28 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Local\VirtualStore [2016/12/07 16:19:26 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Local\Packages [2016/12/07 16:19:26 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\Adobe [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\Voisinage réseau [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\Voisinage d'impression [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\AppData\Local\Temporary Internet Files [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\SendTo [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\Recent [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\Modèles [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\Documents\Mes vidéos [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\Documents\Mes images [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\Mes documents [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\Menu Démarrer [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\Documents\Ma musique [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\Local Settings [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\AppData\Local\Historique [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\Cookies [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\Application Data [2016/12/07 16:19:15 | 000,000,000 | -HSD | C] -- C:\Users\Meliodas-sama\AppData\Local\Application Data [2016/12/07 16:19:14 | 000,000,000 | --SD | C] -- C:\Users\Meliodas-sama\AppData\Roaming\Microsoft [2016/12/07 16:19:14 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\Videos [2016/12/07 16:19:14 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [2016/12/07 16:19:14 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\Saved Games [2016/12/07 16:19:14 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\Pictures [2016/12/07 16:19:14 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\Music [2016/12/07 16:19:14 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\Links [2016/12/07 16:19:14 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\Favorites [2016/12/07 16:19:14 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\Downloads [2016/12/07 16:19:14 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\Documents [2016/12/07 16:19:14 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\Desktop [2016/12/07 16:19:14 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2016/12/07 16:19:14 | 000,000,000 | R--D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [2016/12/07 16:19:14 | 000,000,000 | -H-D | C] -- C:\Users\Meliodas-sama\AppData [2016/12/07 16:19:14 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Local\Temp [2016/12/07 16:19:14 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Local\Microsoft [2016/12/07 16:19:14 | 000,000,000 | ---D | C] -- C:\Users\Meliodas-sama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2016/12/07 16:19:13 | 000,000,000 | ---D | C] -- C:\Windows\CSC [2016/12/07 16:19:08 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2016/12/07 16:16:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Modèles [2016/12/07 16:16:37 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Mes vidéos [2016/12/07 16:16:37 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Mes images [2016/12/07 16:16:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Menu Démarrer [2016/12/07 16:16:37 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Ma musique [2016/12/07 16:16:37 | 000,000,000 | -HSD | C] -- C:\Program Files\Fichiers communs [2016/12/07 16:16:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Bureau [2016/12/07 16:14:02 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch [2016/12/07 16:11:08 | 000,000,000 | -HSD | C] -- C:\System Volume Information [2016/12/07 16:10:20 | 000,000,000 | ---D | C] -- C:\Windows\Panther [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2016/12/10 20:45:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2016/12/10 13:02:56 | 000,775,930 | ---- | M] () -- C:\Windows\System32\perfh00C.dat [2016/12/10 13:02:56 | 000,687,180 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2016/12/10 13:02:56 | 000,151,632 | ---- | M] () -- C:\Windows\System32\perfc00C.dat [2016/12/10 13:02:56 | 000,127,812 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2016/12/10 12:57:06 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys [2016/12/10 12:57:06 | 2557,755,392 | -HS- | M] () -- C:\hiberfil.sys [2016/12/10 00:23:28 | 000,000,918 | ---- | M] () -- C:\Users\Public\Desktop\Age of Mythology Extended Edition.lnk [2016/12/09 18:08:30 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2016/12/09 18:08:30 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2016/12/09 17:30:32 | 000,000,854 | ---- | M] () -- C:\Users\Public\Desktop\StarCraft II.lnk [2016/12/09 12:41:34 | 000,001,435 | ---- | M] () -- C:\Users\Meliodas-sama\Desktop\Battle.net Launcher - Raccourci.lnk [2016/12/08 23:54:25 | 000,001,879 | ---- | M] () -- C:\Users\Public\Desktop\Defraggler.lnk [2016/12/08 18:34:10 | 000,002,135 | ---- | M] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk [2016/12/08 18:27:29 | 000,000,981 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2016/12/08 16:04:19 | 000,333,528 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2016/12/07 22:22:45 | 000,002,716 | ---- | M] () -- C:\Users\Meliodas-sama\Desktop\µTorrent.lnk [2016/12/07 19:34:25 | 000,002,095 | ---- | M] () -- C:\Users\Public\Desktop\Avast Antivirus Gratuit.lnk [2016/12/07 19:32:28 | 000,224,752 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswvmm.sys [2016/12/07 19:32:27 | 000,433,768 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswsp.sys [2016/12/07 19:32:25 | 000,735,488 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswsnx.sys [2016/12/07 19:31:40 | 000,118,664 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswStm.sys [2016/12/07 19:31:38 | 000,092,256 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2016/12/07 19:31:38 | 000,091,232 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys [2016/12/07 19:31:38 | 000,060,424 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRvrt.sys [2016/12/07 19:31:38 | 000,034,008 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswHwid.sys [2016/12/07 19:31:26 | 000,921,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\ucrtbase.dll [2016/12/07 19:31:23 | 000,319,760 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2016/12/07 19:31:23 | 000,053,208 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2016/12/07 19:31:05 | 000,035,096 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswKbd.sys [2016/12/07 19:29:49 | 000,002,122 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk [2016/12/07 19:29:27 | 000,002,701 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk [2016/12/07 19:29:07 | 000,001,044 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk [2016/12/07 19:28:20 | 000,001,005 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 12.lnk [2016/12/07 19:27:33 | 000,001,025 | ---- | M] () -- C:\Users\Public\Desktop\WinRAR.lnk [2016/12/07 19:25:25 | 000,095,808 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll [2016/12/07 16:42:49 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_amdpsp_01011.Wdf [2016/12/07 16:38:31 | 000,002,147 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2016/12/07 16:23:52 | 000,422,480 | ---- | M] (Secure By Design Inc.) -- C:\Users\Meliodas-sama\Desktop\Ninite Avast Chrome Firefox Google Earth Java 8 Installer.exe [2016/12/07 16:23:37 | 000,001,456 | ---- | M] () -- C:\Users\Meliodas-sama\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2016/12/07 16:15:50 | 000,000,776 | ---- | M] () -- C:\Windows\System32\license.rtf [color=#E56717]========== Files Created - No Company Name ==========[/color] [2016/12/10 00:23:28 | 000,000,930 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Age of Mythology Extended Edition.lnk [2016/12/10 00:23:28 | 000,000,918 | ---- | C] () -- C:\Users\Public\Desktop\Age of Mythology Extended Edition.lnk [2016/12/09 17:30:32 | 000,000,854 | ---- | C] () -- C:\Users\Public\Desktop\StarCraft II.lnk [2016/12/09 12:41:34 | 000,001,435 | ---- | C] () -- C:\Users\Meliodas-sama\Desktop\Battle.net Launcher - Raccourci.lnk [2016/12/08 23:54:25 | 000,001,879 | ---- | C] () -- C:\Users\Public\Desktop\Defraggler.lnk [2016/12/08 20:45:17 | 000,004,386 | ---- | C] () -- C:\Users\Meliodas-sama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Battle.lnk [2016/12/08 18:34:10 | 000,002,147 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk [2016/12/08 18:34:10 | 000,002,135 | ---- | C] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk [2016/12/08 18:27:28 | 000,000,981 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2016/12/07 22:22:45 | 000,002,716 | ---- | C] () -- C:\Users\Meliodas-sama\Desktop\µTorrent.lnk [2016/12/07 19:34:25 | 000,002,095 | ---- | C] () -- C:\Users\Public\Desktop\Avast Antivirus Gratuit.lnk [2016/12/07 19:29:49 | 000,002,122 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk [2016/12/07 19:29:27 | 000,002,701 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk [2016/12/07 19:29:07 | 000,001,044 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk [2016/12/07 19:28:20 | 000,001,017 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk [2016/12/07 19:28:20 | 000,001,005 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 12.lnk [2016/12/07 19:27:36 | 000,001,025 | ---- | C] () -- C:\Users\Public\Desktop\WinRAR.lnk [2016/12/07 16:42:49 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_amdpsp_01011.Wdf [2016/12/07 16:38:31 | 000,002,159 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [2016/12/07 16:38:31 | 000,002,147 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2016/12/07 16:37:01 | 000,001,096 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2016/12/07 16:37:01 | 000,001,092 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2016/12/07 16:23:37 | 000,001,456 | ---- | C] () -- C:\Users\Meliodas-sama\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2016/12/07 16:19:26 | 000,001,462 | ---- | C] () -- C:\Users\Meliodas-sama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2016/12/07 16:19:14 | 000,000,369 | ---- | C] () -- C:\Users\Meliodas-sama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk [2016/12/07 16:19:14 | 000,000,369 | ---- | C] () -- C:\Users\Meliodas-sama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk [2016/12/07 16:19:14 | 000,000,352 | ---- | C] () -- C:\Users\Meliodas-sama\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk [2016/12/07 16:19:14 | 000,000,334 | ---- | C] () -- C:\Users\Meliodas-sama\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk [2016/12/07 16:16:14 | 2557,755,392 | -HS- | C] () -- C:\hiberfil.sys [2016/12/07 16:13:33 | 268,435,456 | -HS- | C] () -- C:\swapfile.sys [2016/05/09 07:00:02 | 000,001,375 | ---- | C] () -- C:\Windows\System32\tbaseprovisioning.exe.config [color=#E56717]========== ZeroAccess Check ==========[/color] [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2014/03/18 09:01:19 | 018,682,288 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2013/08/22 03:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2013/08/22 03:42:12 | 000,390,144 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2016/12/07 19:34:32 | 000,000,000 | ---D | M] -- C:\Users\Meliodas-sama\AppData\Roaming\AVAST Software [2016/12/07 22:45:50 | 000,000,000 | ---D | M] -- C:\Users\Meliodas-sama\AppData\Roaming\Battle.net [2016/12/07 19:28:21 | 000,000,000 | ---D | M] -- C:\Users\Meliodas-sama\AppData\Roaming\TeamViewer [2016/12/10 00:43:13 | 000,000,000 | ---D | M] -- C:\Users\Meliodas-sama\AppData\Roaming\uTorrent [2016/12/10 00:32:06 | 000,000,000 | ---D | M] -- C:\Users\Meliodas-sama\AppData\Roaming\YYebookset [2016/12/10 00:31:16 | 000,000,000 | ---D | M] -- C:\Users\Meliodas-sama\AppData\Roaming\YYmm [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 220 bytes -> C:\Users\Meliodas-sama\OneDrive:ms-properties < End of report >