OTL logfile created on: 2/4/2016 1:58:36 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop\Computer Cleaning Programs
An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.10586.0)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.50 Gb Total Physical Memory | 2.23 Gb Available Physical Memory | 63.71% Memory free
7.00 Gb Paging File | 5.57 Gb Available in Paging File | 79.58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.35 Gb Total Space | 193.38 Gb Free Space | 83.23% Space Free | Partition Type: NTFS
Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2016/02/04 01:58:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\Computer Cleaning Programs\OTL.exe
PRC - [2016/02/03 03:18:19 | 000,252,232 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.3.29.5\GoogleCrashHandler.exe
PRC - [2016/01/27 11:19:48 | 000,016,384 | ---- | M] () -- C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.122.14020.0_x86__8wekyb3d8bbwe\Microsoft.Photos.exe
PRC - [2016/01/21 22:40:51 | 000,144,384 | ---- | M] () -- C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
PRC - [2016/01/20 22:17:19 | 003,442,368 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_20_0_0_286.exe
PRC - [2016/01/20 22:13:33 | 003,034,624 | ---- | M] () -- C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.49020.0_x86__8wekyb3d8bbwe\Calculator.exe
PRC - [2016/01/08 10:47:10 | 001,433,216 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2016/01/08 10:44:00 | 001,773,696 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2016/01/07 14:15:38 | 000,392,136 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2016/01/04 21:44:14 | 006,082,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
PRC - [2015/12/26 23:39:09 | 007,021,880 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2015/12/26 23:39:01 | 000,226,440 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2015/12/13 23:48:02 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2015/12/07 00:01:37 | 001,351,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
PRC - [2015/10/30 00:45:06 | 001,358,688 | ---- | M] () -- C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
PRC - [2015/10/30 00:45:04 | 004,064,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2015/10/30 00:45:04 | 000,252,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\LockAppHost.exe
PRC - [2015/10/30 00:45:03 | 000,036,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ApplicationFrameHost.exe
PRC - [2015/10/30 00:44:55 | 000,057,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sihost.exe
PRC - [2015/10/30 00:44:46 | 000,073,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RuntimeBroker.exe
PRC - [2015/10/30 00:44:45 | 000,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dasHost.exe
PRC - [2015/10/30 00:44:40 | 000,071,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhostw.exe
PRC - [2015/09/28 08:19:10 | 000,025,800 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
PRC - [2015/04/15 08:44:32 | 000,128,512 | ---- | M] (Motorola Mobility LLC) -- C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
PRC - [2015/01/13 16:40:56 | 000,217,088 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2011/09/02 15:06:38 | 000,065,657 | ---- | M] (Motorola) -- C:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe
========== Modules (No Company Name) ==========
MOD - [2016/01/27 11:19:48 | 012,345,856 | ---- | M] () -- C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.122.14020.0_x86__8wekyb3d8bbwe\Microsoft.Photos.dll
MOD - [2016/01/27 11:19:48 | 000,016,384 | ---- | M] () -- C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.122.14020.0_x86__8wekyb3d8bbwe\Microsoft.Photos.exe
MOD - [2016/01/21 22:40:51 | 022,330,368 | ---- | M] () -- C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
MOD - [2016/01/21 22:40:51 | 000,144,384 | ---- | M] () -- C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
MOD - [2016/01/21 22:40:51 | 000,141,312 | ---- | M] () -- C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
MOD - [2016/01/20 22:17:19 | 017,882,304 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_20_0_0_286.dll
MOD - [2016/01/20 22:13:33 | 003,034,624 | ---- | M] () -- C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.49020.0_x86__8wekyb3d8bbwe\Calculator.exe
MOD - [2016/01/16 00:09:45 | 002,656,768 | ---- | M] () -- C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
MOD - [2016/01/16 00:06:42 | 002,366,464 | ---- | M] () -- C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
MOD - [2016/01/04 20:23:28 | 005,340,672 | ---- | M] () -- C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
MOD - [2016/01/04 20:19:27 | 000,471,552 | ---- | M] () -- C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
MOD - [2015/12/26 23:39:11 | 040,539,648 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2015/12/26 23:39:07 | 000,103,888 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\log.dll
MOD - [2015/12/26 23:39:06 | 000,469,008 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\ffl2.dll
MOD - [2015/12/26 23:39:02 | 000,125,512 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
MOD - [2015/12/15 03:13:05 | 000,169,984 | ---- | M] () -- C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.49020.0_x86__8wekyb3d8bbwe\StoreRatingPromotion.dll
MOD - [2015/12/10 03:01:38 | 000,169,984 | ---- | M] () -- C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.122.14020.0_x86__8wekyb3d8bbwe\StoreRatingPromotion.dll
MOD - [2015/12/08 20:11:07 | 001,859,448 | ---- | M] () -- C:\Windows\System32\CoreUIComponents.dll
MOD - [2015/12/06 23:11:10 | 000,070,656 | ---- | M] () -- C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
MOD - [2015/12/06 22:57:01 | 000,316,416 | ---- | M] () -- C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
MOD - [2015/10/30 00:45:06 | 001,358,688 | ---- | M] () -- C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
========== Services (SafeList) ==========
SRV - [2016/01/20 22:17:20 | 000,269,504 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2016/01/16 00:29:08 | 000,497,664 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2016/01/16 00:27:16 | 000,411,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\SmsRouterSvc.dll -- (SmsRouter)
SRV - [2016/01/16 00:27:03 | 000,238,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV - [2016/01/16 00:19:43 | 001,552,896 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wlidsvc.dll -- (wlidsvc)
SRV - [2016/01/08 10:47:10 | 001,433,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2016/01/08 10:44:00 | 001,773,696 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2016/01/07 14:15:38 | 000,146,888 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2016/01/04 20:41:02 | 000,588,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PhoneService.dll -- (PhoneSvc)
SRV - [2016/01/04 20:35:58 | 000,706,048 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\usermgr.dll -- (UserManager)
SRV - [2015/12/26 23:39:01 | 000,226,440 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2015/12/13 23:48:02 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2015/12/08 20:11:07 | 000,948,224 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\System32\Unistore.dll -- (UnistoreSvc)
SRV - [2015/12/08 20:11:07 | 000,538,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\XblAuthManager.dll -- (XblAuthManager)
SRV - [2015/12/08 20:11:07 | 000,240,128 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\SensorService.dll -- (SensorService)
SRV - [2015/12/08 20:11:07 | 000,131,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\tetheringservice.dll -- (icssvc)
SRV - [2015/12/08 20:11:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\tzautoupdate.dll -- (tzautoupdate)
SRV - [2015/12/08 20:03:59 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\inetsrv\w3logsvc.dll -- (w3logsvc)
SRV - [2015/12/08 20:03:57 | 000,056,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\inetsrv\apphostsvc.dll -- (AppHostSvc)
SRV - [2015/12/08 20:03:49 | 000,504,320 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\inetsrv\iisw3adm.dll -- (WAS)
SRV - [2015/12/08 20:03:49 | 000,504,320 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\inetsrv\iisw3adm.dll -- (W3SVC)
SRV - [2015/12/06 23:12:17 | 000,820,224 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\XboxNetApiSvc.dll -- (XboxNetApiSvc)
SRV - [2015/12/06 23:00:38 | 000,050,688 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\moshost.dll -- (MapsBroker)
SRV - [2015/12/06 22:57:21 | 000,140,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\NetSetupSvc.dll -- (NetSetupSvc)
SRV - [2015/12/06 22:53:08 | 000,484,864 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wcmsvc.dll -- (Wcmsvc)
SRV - [2015/12/02 10:09:28 | 000,235,696 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe -- (McComponentHostService)
SRV - [2015/10/30 01:57:35 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2015/10/30 00:45:46 | 000,783,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\RDXService.dll -- (RetailDemo)
SRV - [2015/10/30 00:45:46 | 000,425,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\WalletService.dll -- (WalletService)
SRV - [2015/10/30 00:45:46 | 000,387,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AppReadiness.dll -- (AppReadiness)
SRV - [2015/10/30 00:45:46 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wiarpc.dll -- (WiaRpc)
SRV - [2015/10/30 00:45:15 | 000,144,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\NcaSvc.dll -- (NcaSvc)
SRV - [2015/10/30 00:45:13 | 001,401,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\workfolderssvc.dll -- (workfolderssvc)
SRV - [2015/10/30 00:45:11 | 000,107,008 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2015/10/30 00:45:07 | 000,900,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\SensorDataService.exe -- (SensorDataService)
SRV - [2015/10/30 00:45:07 | 000,612,352 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsm.dll -- (LSM)
SRV - [2015/10/30 00:45:06 | 000,070,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV - [2015/10/30 00:44:57 | 001,174,368 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\diagtrack.dll -- (DiagTrack)
SRV - [2015/10/30 00:44:57 | 000,294,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\ncbservice.dll -- (NcbService)
SRV - [2015/10/30 00:44:57 | 000,038,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wpnservice.dll -- (WpnService)
SRV - [2015/10/30 00:44:55 | 001,183,744 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\System32\UserDataService.dll -- (UserDataSvc)
SRV - [2015/10/30 00:44:55 | 000,717,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\XblGameSave.dll -- (XblGameSave)
SRV - [2015/10/30 00:44:55 | 000,498,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ngcsvc.dll -- (NgcSvc)
SRV - [2015/10/30 00:44:55 | 000,453,632 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\bisrv.dll -- (BrokerInfrastructure)
SRV - [2015/10/30 00:44:55 | 000,380,928 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\tileobjserver.dll -- (tiledatamodelsvc)
SRV - [2015/10/30 00:44:55 | 000,221,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\NgcCtnrSvc.dll -- (NgcCtnrSvc)
SRV - [2015/10/30 00:44:55 | 000,202,752 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\System32\PimIndexMaintenance.dll -- (PimIndexMaintenanceSvc)
SRV - [2015/10/30 00:44:55 | 000,024,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\DevQueryBroker.dll -- (DevQueryBroker)
SRV - [2015/10/30 00:44:55 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\lfsvc.dll -- (lfsvc)
SRV - [2015/10/30 00:44:55 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\LicenseManagerSvc.dll -- (LicenseManager)
SRV - [2015/10/30 00:44:53 | 002,179,584 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\Windows.StateRepository.dll -- (StateRepository)
SRV - [2015/10/30 00:44:53 | 000,548,536 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\CoreMessaging.dll -- (CoreMessagingRegistrar)
SRV - [2015/10/30 00:44:53 | 000,199,680 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\cdpsvc.dll -- (CDPSvc)
SRV - [2015/10/30 00:44:53 | 000,081,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\embeddedmodesvc.dll -- (embeddedmode)
SRV - [2015/10/30 00:44:53 | 000,019,456 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AJRouter.dll -- (AJRouter)
SRV - [2015/10/30 00:44:51 | 002,885,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\WSService.dll -- (WSService)
SRV - [2015/10/30 00:44:51 | 000,804,352 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dosvc.dll -- (DoSvc)
SRV - [2015/10/30 00:44:51 | 000,251,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\usocore.dll -- (UsoSvc)
SRV - [2015/10/30 00:44:49 | 000,070,656 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\keyiso.dll -- (KeyIso)
SRV - [2015/10/30 00:44:48 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wephostsvc.dll -- (WEPHOSTSVC)
SRV - [2015/10/30 00:44:47 | 000,510,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ClipSVC.dll -- (ClipSVC)
SRV - [2015/10/30 00:44:47 | 000,266,752 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\vaultsvc.dll -- (VaultSvc)
SRV - [2015/10/30 00:44:47 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV - [2015/10/30 00:44:47 | 000,042,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\efssvc.dll -- (EFS)
SRV - [2015/10/30 00:44:46 | 000,026,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe -- (diagnosticshub.standardcollector.service)
SRV - [2015/10/30 00:44:45 | 000,355,328 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\das.dll -- (DeviceAssociationService)
SRV - [2015/10/30 00:44:45 | 000,163,840 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\DeviceSetupManager.dll -- (DsmSvc)
SRV - [2015/10/30 00:44:44 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\smphost.dll -- (smphost)
SRV - [2015/10/30 00:44:43 | 000,272,896 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\System32\APHostService.dll -- (OneSyncSvc)
SRV - [2015/10/30 00:44:43 | 000,256,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\TieringEngineService.exe -- (TieringEngineService)
SRV - [2015/10/30 00:44:43 | 000,156,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dcpsvc.dll -- (DcpSvc)
SRV - [2015/10/30 00:44:43 | 000,099,840 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\fhsvc.dll -- (fhsvc)
SRV - [2015/10/30 00:44:43 | 000,011,264 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\svsvc.dll -- (svsvc)
SRV - [2015/10/30 00:44:42 | 000,116,224 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dssvc.dll -- (DsSvc)
SRV - [2015/10/30 00:44:40 | 001,885,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AppXDeploymentServer.dll -- (AppXSvc)
SRV - [2015/10/30 00:44:40 | 000,261,632 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\EnterpriseAppMgmtSvc.dll -- (EntAppSvc)
SRV - [2015/10/30 00:44:40 | 000,200,192 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Windows.Internal.Management.dll -- (DmEnrollmentSvc)
SRV - [2015/10/30 00:44:40 | 000,047,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dmwappushsvc.dll -- (dmwappushservice)
SRV - [2015/10/30 00:44:38 | 000,044,032 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\System32\MessagingService.dll -- (MessagingService)
SRV - [2015/10/30 00:44:37 | 000,449,024 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netprofmsvc.dll -- (netprofm)
SRV - [2015/10/30 00:44:35 | 000,280,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV - [2015/10/30 00:44:35 | 000,273,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV - [2015/10/30 00:44:35 | 000,118,784 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\TimeBrokerServer.dll -- (TimeBroker)
SRV - [2015/10/30 00:44:35 | 000,023,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2015/10/30 00:44:33 | 000,401,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicvss)
SRV - [2015/10/30 00:44:33 | 000,401,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicvmsession)
SRV - [2015/10/30 00:44:33 | 000,401,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmictimesync)
SRV - [2015/10/30 00:44:33 | 000,401,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicshutdown)
SRV - [2015/10/30 00:44:33 | 000,401,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicrdv)
SRV - [2015/10/30 00:44:33 | 000,401,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmickvpexchange)
SRV - [2015/10/30 00:44:33 | 000,401,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicheartbeat)
SRV - [2015/10/30 00:44:33 | 000,401,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicguestinterface)
SRV - [2015/10/30 00:44:27 | 002,718,208 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\spool\drivers\w32x86\3\PrintConfig.dll -- (PrintNotify)
SRV - [2015/10/30 00:44:25 | 000,252,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\BthHFSrv.dll -- (BthHFSrv)
SRV - [2015/09/28 08:19:10 | 000,025,800 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe -- (HPSupportSolutionsFrameworkService)
SRV - [2015/07/09 12:14:04 | 000,327,296 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2015/04/15 08:44:32 | 000,128,512 | ---- | M] (Motorola Mobility LLC) [Auto | Running] -- C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe -- (Motorola Device Manager)
SRV - [2015/01/13 16:40:56 | 000,217,088 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2011/09/02 15:06:38 | 000,065,657 | ---- | M] (Motorola) [Auto | Running] -- C:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe -- (PST Service)
========== Driver Services (SafeList) ==========
DRV - [2016/01/20 23:46:47 | 000,449,384 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswsp.sys -- (aswSP)
DRV - [2016/01/20 23:46:46 | 000,812,208 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswsnx.sys -- (aswSnx)
DRV - [2015/12/26 23:39:56 | 000,081,168 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2015/12/26 23:39:15 | 000,117,712 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswStm.sys -- (aswStm)
DRV - [2015/12/26 23:39:14 | 000,209,432 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2015/12/26 23:39:14 | 000,049,776 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2015/12/26 23:39:14 | 000,024,016 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswHwid.sys -- (aswHwid)
DRV - [2015/12/26 23:39:13 | 000,081,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr)
DRV - [2015/12/08 20:11:07 | 000,096,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\capimg.sys -- (CapImg)
DRV - [2015/12/08 20:11:07 | 000,076,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sdstor.sys -- (sdstor)
DRV - [2015/12/08 20:03:48 | 000,130,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mqac.sys -- (MQAC)
DRV - [2015/10/30 01:57:54 | 000,023,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2015/10/30 01:57:41 | 000,030,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\terminpt.sys -- (terminpt)
DRV - [2015/10/30 00:45:52 | 000,024,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV - [2015/10/30 00:45:11 | 000,043,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wpcfltr.sys -- (wpcfltr)
DRV - [2015/10/30 00:45:01 | 000,280,920 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\clfs.sys -- (CLFS)
DRV - [2015/10/30 00:45:01 | 000,183,296 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\ahcache.sys -- (ahcache)
DRV - [2015/10/30 00:44:58 | 000,086,552 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\WindowsTrustedRT.sys -- (WindowsTrustedRT)
DRV - [2015/10/30 00:44:57 | 000,159,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VerifierExt.sys -- (VerifierExt)
DRV - [2015/10/30 00:44:57 | 000,088,416 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\wfplwfs.sys -- (WFPLWFS)
DRV - [2015/10/30 00:44:57 | 000,062,464 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\System32\drivers\storqosflt.sys -- (storqosflt)
DRV - [2015/10/30 00:44:57 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\UcmCx.sys -- (UcmCx0101)
DRV - [2015/10/30 00:44:57 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\condrv.sys -- (condrv)
DRV - [2015/10/30 00:44:57 | 000,023,040 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\ioqos.sys -- (IoQos)
DRV - [2015/10/30 00:44:52 | 000,036,864 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\mmcss.sys -- (MMCSS)
DRV - [2015/10/30 00:44:48 | 000,033,112 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\cnghwassist.sys -- (cnghwassist)
DRV - [2015/10/30 00:44:47 | 000,200,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ufx01000.sys -- (Ufx01000)
DRV - [2015/10/30 00:44:47 | 000,060,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SpbCx.sys -- (SpbCx)
DRV - [2015/10/30 00:44:47 | 000,042,840 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\urscx01000.sys -- (UrsCx01000)
DRV - [2015/10/30 00:44:46 | 000,130,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV - [2015/10/30 00:44:46 | 000,121,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SerCx2.sys -- (SerCx2)
DRV - [2015/10/30 00:44:46 | 000,075,104 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\EhStorClass.sys -- (EhStorClass)
DRV - [2015/10/30 00:44:46 | 000,059,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SerCx.sys -- (SerCx)
DRV - [2015/10/30 00:44:46 | 000,009,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mshidumdf.sys -- (mshidumdf)
DRV - [2015/10/30 00:44:44 | 000,007,680 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\gpuenergydrv.sys -- (GpuEnergyDrv)
DRV - [2015/10/30 00:44:43 | 000,054,112 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\dam.sys -- (dam)
DRV - [2015/10/30 00:44:42 | 000,173,408 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\System32\drivers\wof.sys -- (Wof)
DRV - [2015/10/30 00:44:38 | 000,497,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WdiWiFi.sys -- (wdiwifi)
DRV - [2015/10/30 00:44:37 | 000,109,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV - [2015/10/30 00:44:37 | 000,105,472 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\Ndu.sys -- (Ndu)
DRV - [2015/10/30 00:44:37 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\mslldp.sys -- (MsLldp)
DRV - [2015/10/30 00:44:36 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV - [2015/10/30 00:44:35 | 000,246,104 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\WdFilter.sys -- (WdFilter)
DRV - [2015/10/30 00:44:35 | 000,098,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV - [2015/10/30 00:44:35 | 000,037,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WdBoot.sys -- (WdBoot)
DRV - [2015/10/30 00:44:33 | 000,173,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Ucx01000.sys -- (Ucx01000)
DRV - [2015/10/30 00:44:33 | 000,093,024 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\acpiex.sys -- (acpiex)
DRV - [2015/10/30 00:44:33 | 000,083,808 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pdc.sys -- (pdc)
DRV - [2015/10/30 00:44:33 | 000,076,288 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\filecrypt.sys -- (FileCrypt)
DRV - [2015/10/30 00:44:33 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2015/10/30 00:44:33 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Udecx.sys -- (UdeCx)
DRV - [2015/10/30 00:44:33 | 000,024,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vhf.sys -- (vhf)
DRV - [2015/10/30 00:44:29 | 000,036,704 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV - [2015/10/30 00:44:29 | 000,025,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2015/10/30 00:44:29 | 000,021,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\urssynopsys.sys -- (UrsSynopsys)
DRV - [2015/10/30 00:44:29 | 000,021,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\urschipidea.sys -- (UrsChipidea)
DRV - [2015/10/30 00:44:29 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\npsvctrig.sys -- (npsvctrig)
DRV - [2015/10/30 00:44:29 | 000,015,384 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys -- (WindowsTrustedRTProxy)
DRV - [2015/10/30 00:44:28 | 001,038,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\adp80xx.sys -- (ADP80XX)
DRV - [2015/10/30 00:44:28 | 001,035,776 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2015/10/30 00:44:28 | 000,524,632 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\iaStorAV.sys -- (iaStorAV)
DRV - [2015/10/30 00:44:28 | 000,494,080 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rt640x86.sys -- (rt640x86)
DRV - [2015/10/30 00:44:28 | 000,429,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\USBHUB3.SYS -- (USBHUB3)
DRV - [2015/10/30 00:44:28 | 000,427,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\spaceport.sys -- (spaceport)
DRV - [2015/10/30 00:44:28 | 000,287,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\USBXHCI.SYS -- (USBXHCI)
DRV - [2015/10/30 00:44:28 | 000,276,832 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV - [2015/10/30 00:44:28 | 000,200,704 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\xboxgip.sys -- (xboxgip)
DRV - [2015/10/30 00:44:28 | 000,172,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tpm.sys -- (TPM)
DRV - [2015/10/30 00:44:28 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\storahci.sys -- (storahci)
DRV - [2015/10/30 00:44:28 | 000,104,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ufxsynopsys.sys -- (ufxsynopsys)
DRV - [2015/10/30 00:44:28 | 000,088,928 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\lsi_sas2i.sys -- (LSI_SAS2i)
DRV - [2015/10/30 00:44:28 | 000,085,856 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\3ware.sys -- (3ware)
DRV - [2015/10/30 00:44:28 | 000,083,288 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\lsi_sas3i.sys -- (LSI_SAS3i)
DRV - [2015/10/30 00:44:28 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\UfxChipidea.sys -- (UfxChipidea)
DRV - [2015/10/30 00:44:28 | 000,069,472 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\lsi_sss.sys -- (LSI_SSS)
DRV - [2015/10/30 00:44:28 | 000,065,376 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\stornvme.sys -- (stornvme)
DRV - [2015/10/30 00:44:28 | 000,061,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\iaioi2c.sys -- (iaioi2c)
DRV - [2015/10/30 00:44:28 | 000,059,744 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\uaspstor.sys -- (UASPStor)
DRV - [2015/10/30 00:44:28 | 000,058,208 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\mvumis.sys -- (mvumis)
DRV - [2015/10/30 00:44:28 | 000,051,552 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\percsas3i.sys -- (percsas3i)
DRV - [2015/10/30 00:44:28 | 000,051,040 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\percsas2i.sys -- (percsas2i)
DRV - [2015/10/30 00:44:28 | 000,045,568 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV - [2015/10/30 00:44:28 | 000,038,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hidinterrupt.sys -- (hidinterrupt)
DRV - [2015/10/30 00:44:28 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\UcmUcsi.sys -- (UcmUcsi)
DRV - [2015/10/30 00:44:28 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\BasicRender.sys -- (BasicRender)
DRV - [2015/10/30 00:44:28 | 000,027,992 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\storufs.sys -- (storufs)
DRV - [2015/10/30 00:44:28 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\buttonconverter.sys -- (buttonconverter)
DRV - [2015/10/30 00:44:28 | 000,023,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\uefi.sys -- (UEFI)
DRV - [2015/10/30 00:44:28 | 000,022,016 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\iaiogpio.sys -- (GPIO)
DRV - [2015/10/30 00:44:28 | 000,018,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\xinputhid.sys -- (xinputhid)
DRV - [2015/10/30 00:44:28 | 000,017,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\kdnic.sys -- (kdnic)
DRV - [2015/10/30 00:44:28 | 000,017,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\genericusbfn.sys -- (genericusbfn)
DRV - [2015/10/30 00:44:28 | 000,009,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\acpitime.sys -- (acpitime)
DRV - [2015/10/30 00:44:28 | 000,009,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\acpipagr.sys -- (acpipagr)
DRV - [2015/10/30 00:44:28 | 000,008,192 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\bcmfn2.sys -- (bcmfn2)
DRV - [2015/10/30 00:44:28 | 000,008,192 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\bcmfn.sys -- (bcmfn)
DRV - [2015/10/30 00:44:26 | 000,066,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
DRV - [2015/10/30 00:44:25 | 000,552,448 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rtl819xp.sys -- (rtl819xp)
DRV - [2015/10/30 00:44:25 | 000,101,216 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV - [2015/10/30 00:44:25 | 000,079,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2015/10/30 00:44:25 | 000,066,048 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\iai2c.sys -- (iai2c)
DRV - [2015/10/30 00:44:25 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\bthhfenum.sys -- (BthHFEnum)
DRV - [2015/10/30 00:44:25 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV - [2015/10/30 00:44:25 | 000,040,288 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\intelpep.sys -- (intelpep)
DRV - [2015/10/30 00:44:25 | 000,039,776 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2015/10/30 00:44:25 | 000,037,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hidi2c.sys -- (hidi2c)
DRV - [2015/10/30 00:44:25 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV - [2015/10/30 00:44:25 | 000,031,744 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_x86_dd1d60cd48926252\CompositeBus.sys -- (CompositeBus)
DRV - [2015/10/30 00:44:25 | 000,029,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dmvsc.sys -- (dmvsc)
DRV - [2015/10/30 00:44:25 | 000,027,488 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2015/10/30 00:44:25 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BthhfHid.sys -- (bthhfhid)
DRV - [2015/10/30 00:44:25 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2015/10/30 00:44:25 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hyperkbd.sys -- (hyperkbd)
DRV - [2015/10/30 00:44:25 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmgencounter.sys -- (gencounter)
DRV - [2015/10/30 00:44:25 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2015/08/07 05:49:26 | 000,041,584 | ---- | M] (Toshiba Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Thotkey.sys -- (Thotkey)
DRV - [2015/07/25 00:56:24 | 000,035,936 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\TVALZ_O.SYS -- (TVALZ)
DRV - [2015/01/13 17:40:18 | 010,070,016 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2015/01/13 16:20:36 | 000,290,304 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
https://www.google.com/?trackid=sp-006
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
https://www.google.com/search?trackid=sp-006&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://www.google.com/?trackid=sp-006
IE - HKLM\..\SearchScopes,DefaultScope = {E9410C70-B6AE-41FF-AB71-32F4B279EA5F}
IE - HKLM\..\SearchScopes\{2f23ab71-4ac6-41f2-a955-ea576e553146}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}: "URL" =
https://www.google.com/search?trackid=sp-006&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
https://www.google.com/?trackid=sp-006
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
https://www.google.com/search?trackid=sp-006&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://www.google.com/?trackid=sp-006
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8C FD 41 AD EB BF D0 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {E9410C70-B6AE-41FF-AB71-32F4B279EA5F}
IE - HKCU\..\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}: "URL" =
https://www.google.com/search?trackid=sp-006&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 192.168.*.*
========== FireFox ==========
FF - prefs.js..browser.search.countryCode: "US"
FF - prefs.js..browser.search.defaultengine: "Google (avast)"
FF - prefs.js..browser.search.defaultenginename: "Google (avast)"
FF - prefs.js..browser.search.defaultenginename.US: "Default"
FF - prefs.js..browser.search.defaultthis.engineName: "Google (avast)"
FF - prefs.js..browser.search.defaulturl: "
https://www.google.com/search?trackid=sp-006"
FF - prefs.js..browser.search.order.1: "Google (avast)"
FF - prefs.js..browser.search.region: "US"
FF - prefs.js..browser.search.selectedEngine: "Google (avast)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://searchinterneat-a.akamaihd.n...AWAxGFwcFIk0FA18DB0VXfWFoKB8fHGZGIUtbCXIfTkI="
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:43.0.4
FF - prefs.js..keyword.URL: "
https://www.google.com/search?trackid=sp-006"
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_20_0_0_286.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\User\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2015/12/26 23:43:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015/12/26 23:43:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 43.0.4\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 43.0.4\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 43.0.4\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 43.0.4\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2015/08/31 09:00:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Extensions
[2016/01/30 02:00:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\uom3tyqm.default\extensions
[2015/12/13 16:32:34 | 000,009,153 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\uom3tyqm.default\extensions\{9b345654-2e75-4b7c-a218-8f4712ab4fe5}.xpi
[2016/01/16 08:08:07 | 000,002,428 | ---- | M] () -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\uom3tyqm.default\searchplugins\google-avast.xml
[2016/01/01 12:28:54 | 000,000,411 | ---- | M] () -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\uom3tyqm.default\searchplugins\yahoo.xml
[2016/01/17 22:36:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2016/01/07 14:15:39 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ==========
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbldbfalomdbcmadkikldapjpgcfaeia\1.0.5843.26482_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.1_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\11.1.0.210_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\11.1.0.221_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\8.0.0.9098_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljibkigjccbegnbeojkoafejpoiachej\0.1.2_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.2.0_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
O1 HOSTS File: ([2015/12/25 00:51:35 | 000,000,852 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKCU..\Run: [NowUSeeIt Player] "C:\Program Files\NowUSeeItPlayer\NowUSeeItPlayer.exe" /autostart=1 File not found
O4 - HKCU..\Run: [OneDrive] C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DSCAutomationHostEnabled = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: webcompanion.com ([]http in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{135b02f8-71a0-4588-804e-c91f793a0a6b}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{bdc5887f-4f0a-4e48-861f-68d1dede2733}: DhcpNameServer = 192.168.42.129
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O18 - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\WINDOWS\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2016/02/03 23:31:29 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\Computer Cleaning Programs
[2016/02/03 23:26:51 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2016/01/30 16:56:56 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\heater
[2016/01/27 23:22:39 | 006,971,752 | ---- | C] (Microsoft Corp.) -- C:\WINDOWS\System32\Windows.Media.Protection.PlayReady.dll
[2016/01/27 23:22:32 | 005,238,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\windows.storage.dll
[2016/01/27 23:22:31 | 009,918,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\twinui.dll
[2016/01/27 23:22:26 | 018,678,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\edgehtml.dll
[2016/01/27 23:22:23 | 013,018,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Windows.UI.Xaml.dll
[2016/01/27 23:22:22 | 006,297,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mos.dll
[2016/01/27 23:22:20 | 004,759,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d2d1.dll
[2016/01/27 23:22:20 | 000,405,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\AudioSes.dll
[2016/01/27 23:22:19 | 001,552,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wlidsvc.dll
[2016/01/27 23:22:19 | 001,300,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WpcMon.exe
[2016/01/27 23:22:19 | 000,297,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\audiodg.exe
[2016/01/27 23:22:18 | 001,793,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\NetworkMobileSettings.dll
[2016/01/27 23:22:17 | 001,223,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\RecoveryDrive.exe
[2016/01/27 23:22:16 | 005,202,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\BingMaps.dll
[2016/01/27 23:22:16 | 001,944,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\InputService.dll
[2016/01/27 23:22:16 | 000,959,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\aeinv.dll
[2016/01/27 23:22:15 | 001,626,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dwmcore.dll
[2016/01/27 23:22:15 | 000,709,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mfsvr.dll
[2016/01/27 23:22:14 | 002,977,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\win32kfull.sys
[2016/01/27 23:22:14 | 000,238,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\AudioEndpointBuilder.dll
[2016/01/27 23:22:13 | 000,608,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MapsStore.dll
[2016/01/27 23:22:12 | 000,652,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\evr.dll
[2016/01/27 23:22:12 | 000,431,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WWanAPI.dll
[2016/01/27 23:22:12 | 000,350,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CredProvDataModel.dll
[2016/01/27 23:22:11 | 001,542,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\quartz.dll
[2016/01/27 23:22:11 | 000,687,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeeds.dll
[2016/01/27 23:22:11 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\TextInputFramework.dll
[2016/01/27 23:22:10 | 000,398,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\srcore.dll
[2016/01/27 23:22:10 | 000,273,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\SensorsApi.dll
[2016/01/27 23:22:10 | 000,168,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wscapi.dll
[2016/01/27 23:22:09 | 002,050,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcpl.cpl
[2016/01/27 23:22:09 | 000,483,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dxgmms2.sys
[2016/01/27 23:22:09 | 000,411,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\SmsRouterSvc.dll
[2016/01/27 23:22:09 | 000,366,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\AUDIOKSE.dll
[2016/01/27 23:22:08 | 000,335,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\iedkcs32.dll
[2016/01/27 23:22:08 | 000,157,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\SimCfg.dll
[2016/01/27 23:22:07 | 000,599,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\invagent.dll
[2016/01/27 23:22:07 | 000,433,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\devinv.dll
[2016/01/27 23:22:07 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MusUpdateHandlers.dll
[2016/01/27 23:22:07 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ie4uinit.exe
[2016/01/27 23:22:07 | 000,129,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\SimAuth.dll
[2016/01/27 23:22:06 | 000,463,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\enterprisecsps.dll
[2016/01/27 23:22:06 | 000,200,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\DisplayManager.dll
[2016/01/27 23:22:06 | 000,140,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MusNotification.exe
[2016/01/27 23:22:06 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MapsBtSvc.dll
[2016/01/27 23:22:06 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MusNotificationUx.exe
[2016/01/27 23:22:05 | 001,028,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wifinetworkmanager.dll
[2016/01/27 23:22:05 | 000,497,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\StorSvc.dll
[2016/01/27 23:22:03 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\SMSRouter.dll
[2016/01/27 23:22:02 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\pcaui.exe
[2016/01/27 23:22:01 | 000,438,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Windows.Networking.UX.EapRequestHandler.dll
[2016/01/27 23:22:00 | 000,510,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wlidcli.dll
[2016/01/27 23:21:59 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Windows.UI.Core.TextInput.dll
[2016/01/27 23:21:59 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rasautou.exe
[2016/01/27 23:21:58 | 000,335,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\DDDS.dll
[2016/01/27 23:21:58 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\FilterDS.dll
[2016/01/27 23:21:58 | 000,079,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winhttpcom.dll
[2016/01/27 23:21:57 | 000,942,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\reseteng.dll
[2016/01/27 23:21:57 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winbio.dll
[2016/01/27 23:21:57 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sscoreext.dll
[2016/01/27 23:21:57 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rastlsext.dll
[2016/01/27 21:31:07 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\Lights
[2016/01/25 22:37:05 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\trailers
[2016/01/12 18:38:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\PCHEALTH
[2016/01/12 18:08:31 | 005,798,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntoskrnl.exe
[2016/01/12 18:08:29 | 005,660,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Chakra.dll
[2016/01/12 18:08:29 | 002,180,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mfcore.dll
[2016/01/12 18:08:29 | 001,118,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mfnetsrc.dll
[2016/01/12 18:08:28 | 000,701,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mfnetcore.dll
[2016/01/12 18:08:28 | 000,695,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WMADMOD.DLL
[2016/01/12 18:08:28 | 000,233,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\facecredentialprovider.dll
[2016/01/12 18:08:27 | 003,667,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\jscript9.dll
[2016/01/12 18:08:27 | 002,796,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Windows.Media.dll
[2016/01/12 18:08:27 | 000,706,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\usermgr.dll
[2016/01/12 18:08:26 | 001,051,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winload.efi
[2016/01/12 18:08:26 | 000,926,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winload.exe
[2016/01/12 18:08:26 | 000,890,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WMSPDMOD.DLL
[2016/01/12 18:08:26 | 000,703,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WWAHost.exe
[2016/01/12 18:08:26 | 000,641,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\generaltel.dll
[2016/01/12 18:08:25 | 001,696,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WMALFXGFXDSP.dll
[2016/01/12 18:08:25 | 001,137,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\appraiser.dll
[2016/01/12 18:08:25 | 000,588,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\PhoneService.dll
[2016/01/12 18:08:25 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qedit.dll
[2016/01/12 18:08:25 | 000,569,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qdvd.dll
[2016/01/12 18:08:25 | 000,498,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MessagingDataModel2.dll
[2016/01/12 18:08:25 | 000,208,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mftranscode.dll
[2016/01/12 18:08:25 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\DeviceCensus.exe
[2016/01/12 18:08:25 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ProximityCommon.dll
[2016/01/12 18:08:25 | 000,116,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mfps.dll
[2016/01/12 18:08:25 | 000,100,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MP3DMOD.DLL
[2016/01/12 18:08:24 | 001,496,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\aitstatic.exe
[2016/01/12 18:08:24 | 001,070,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WMSPDMOE.DLL
[2016/01/12 18:08:24 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\DscCore.dll
[2016/01/12 18:08:24 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksproxy.ax
[2016/01/12 18:08:24 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\aepic.dll
[2016/01/12 18:08:24 | 000,166,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\UserMgrProxy.dll
[2016/01/12 18:08:24 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\storewuauth.dll
[2016/01/12 18:08:24 | 000,122,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\omadmclient.exe
[2016/01/12 18:08:24 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\RMSRoamingSecurity.dll
[2016/01/12 18:08:24 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\usermgrcli.dll
========== Files - Modified Within 30 Days ==========
[2016/02/04 01:57:19 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2016/02/03 23:38:01 | 000,000,906 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2016/02/03 23:37:26 | 000,000,332 | ---- | M] () -- C:\WINDOWS\tasks\HPCeeScheduleForUser.job
[2016/02/03 23:37:16 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2016/02/03 23:37:12 | 2816,860,160 | -HS- | M] () -- C:\hiberfil.sys
[2016/02/03 23:23:36 | 000,000,910 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2016/02/03 23:17:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2016/02/01 19:00:17 | 000,002,102 | ---- | M] () -- C:\Users\User\Desktop\Google Earth.lnk
[2016/02/01 19:00:16 | 000,000,888 | ---- | M] () -- C:\Users\User\Desktop\My Documents.lnk
[2016/01/29 12:32:02 | 000,001,923 | ---- | M] () -- C:\Users\User\Desktop\Microsoft Excel 2010.lnk
[2016/01/29 12:31:58 | 000,001,927 | ---- | M] () -- C:\Users\User\Desktop\Microsoft Word 2010.lnk
[2016/01/20 23:46:47 | 000,449,384 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswsp.sys
[2016/01/20 23:46:46 | 000,812,208 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswsnx.sys
[2016/01/17 20:31:44 | 000,823,194 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2016/01/17 20:31:44 | 000,166,542 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2016/01/16 08:08:07 | 000,001,097 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2016/01/16 01:35:55 | 000,168,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wscapi.dll
[2016/01/16 01:35:32 | 000,599,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\invagent.dll
[2016/01/16 01:35:14 | 000,959,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\aeinv.dll
[2016/01/16 01:33:28 | 000,433,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\devinv.dll
[2016/01/16 01:20:56 | 000,431,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\WWanAPI.dll
[2016/01/16 01:20:12 | 006,971,752 | ---- | M] (Microsoft Corp.) -- C:\WINDOWS\System32\Windows.Media.Protection.PlayReady.dll
[2016/01/16 01:20:12 | 000,297,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\audiodg.exe
[2016/01/16 01:20:01 | 000,652,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\evr.dll
[2016/01/16 01:20:00 | 000,366,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\AUDIOKSE.dll
[2016/01/16 01:19:59 | 000,709,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mfsvr.dll
[2016/01/16 01:19:58 | 000,405,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\AudioSes.dll
[2016/01/16 01:17:18 | 001,300,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\WpcMon.exe
[2016/01/16 01:16:49 | 005,238,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\windows.storage.dll
[2016/01/16 01:08:49 | 000,483,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dxgmms2.sys
[2016/01/16 00:36:06 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\rastlsext.dll
[2016/01/16 00:35:52 | 000,140,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MusNotification.exe
[2016/01/16 00:35:03 | 013,018,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Windows.UI.Xaml.dll
[2016/01/16 00:34:55 | 000,079,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\winhttpcom.dll
[2016/01/16 00:34:11 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\sscoreext.dll
[2016/01/16 00:33:53 | 000,087,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MapsBtSvc.dll
[2016/01/16 00:32:52 | 000,048,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MusNotificationUx.exe
[2016/01/16 00:32:30 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\pcaui.exe
[2016/01/16 00:31:54 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\rasautou.exe
[2016/01/16 00:31:11 | 000,107,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\FilterDS.dll
[2016/01/16 00:30:34 | 000,325,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MusUpdateHandlers.dll
[2016/01/16 00:30:19 | 000,157,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\SimCfg.dll
[2016/01/16 00:30:18 | 000,093,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\winbio.dll
[2016/01/16 00:29:46 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\SMSRouter.dll
[2016/01/16 00:29:08 | 000,497,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\StorSvc.dll
[2016/01/16 00:29:06 | 000,200,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DisplayManager.dll
[2016/01/16 00:28:57 | 000,335,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DDDS.dll
[2016/01/16 00:28:52 | 000,129,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\SimAuth.dll
[2016/01/16 00:28:49 | 000,186,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ie4uinit.exe
[2016/01/16 00:28:26 | 000,463,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\enterprisecsps.dll
[2016/01/16 00:28:02 | 009,918,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\twinui.dll
[2016/01/16 00:27:16 | 000,411,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\SmsRouterSvc.dll
[2016/01/16 00:27:16 | 000,335,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iedkcs32.dll
[2016/01/16 00:27:03 | 000,398,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\srcore.dll
[2016/01/16 00:27:03 | 000,238,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\AudioEndpointBuilder.dll
[2016/01/16 00:25:50 | 000,438,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Windows.Networking.UX.EapRequestHandler.dll
[2016/01/16 00:25:39 | 000,510,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wlidcli.dll
[2016/01/16 00:24:44 | 000,273,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\SensorsApi.dll
[2016/01/16 00:24:29 | 018,678,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\edgehtml.dll
[2016/01/16 00:24:13 | 000,350,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CredProvDataModel.dll
[2016/01/16 00:23:46 | 000,608,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MapsStore.dll
[2016/01/16 00:23:07 | 002,050,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcpl.cpl
[2016/01/16 00:23:03 | 000,687,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeeds.dll
[2016/01/16 00:22:44 | 001,223,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\RecoveryDrive.exe
[2016/01/16 00:21:51 | 006,297,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mos.dll
[2016/01/16 00:20:40 | 001,944,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\InputService.dll
[2016/01/16 00:20:26 | 001,028,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wifinetworkmanager.dll
[2016/01/16 00:19:43 | 001,552,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wlidsvc.dll
[2016/01/16 00:19:08 | 000,162,816 | ---- | M] () -- C:\WINDOWS\System32\MTF.dll
[2016/01/16 00:19:08 | 000,133,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Windows.UI.Core.TextInput.dll
[2016/01/16 00:19:06 | 000,176,128 | ---- | M] () -- C:\WINDOWS\System32\MTFServer.dll
[2016/01/16 00:19:05 | 000,245,760 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\TextInputFramework.dll
[2016/01/16 00:17:08 | 001,793,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\NetworkMobileSettings.dll
[2016/01/16 00:16:05 | 005,202,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\BingMaps.dll
[2016/01/16 00:15:29 | 004,759,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\d2d1.dll
[2016/01/16 00:14:55 | 002,977,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\win32kfull.sys
[2016/01/16 00:14:51 | 001,626,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dwmcore.dll
[2016/01/16 00:06:14 | 000,942,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\reseteng.dll
========== Files Created - No Company Name ==========
[2016/01/29 12:32:02 | 000,001,923 | ---- | C] () -- C:\Users\User\Desktop\Microsoft Excel 2010.lnk
[2016/01/29 12:31:58 | 000,001,927 | ---- | C] () -- C:\Users\User\Desktop\Microsoft Word 2010.lnk
[2016/01/27 23:22:13 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\MTFServer.dll
[2016/01/27 23:22:13 | 000,162,816 | ---- | C] () -- C:\WINDOWS\System32\MTF.dll
[2015/12/25 18:34:24 | 000,002,888 | ---- | C] () -- C:\WINDOWS\System32\LavasoftTcpServiceOff.ini
[2015/12/25 01:01:28 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2015/12/25 00:33:30 | 000,000,013 | ---- | C] () -- C:\Users\User\.pluto.tv
[2015/12/13 19:22:03 | 000,000,135 | ---- | C] () -- C:\Users\User\AppData\Roaming\WB.CFG
[2015/12/08 20:11:07 | 001,859,448 | ---- | C] () -- C:\WINDOWS\System32\CoreUIComponents.dll
[2015/12/08 17:46:01 | 000,021,316 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2015/12/08 17:24:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2015/12/08 17:22:41 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2015/12/08 17:20:57 | 000,360,504 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2015/11/17 00:30:50 | 000,000,184 | ---- | C] () -- C:\WINDOWS\AutoKMS.ini
[2015/11/17 00:26:59 | 000,000,567 | ---- | C] () -- C:\WINDOWS\System32\Settings.ini
[2015/10/30 00:49:53 | 000,823,194 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2015/10/30 00:49:53 | 000,296,742 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2015/10/30 00:49:53 | 000,166,542 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2015/10/30 00:49:53 | 000,033,362 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2015/10/30 00:48:49 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\NOISE.DAT
[2015/10/30 00:48:48 | 000,215,943 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2015/10/30 00:48:48 | 000,000,389 | ---- | C] () -- C:\WINDOWS\System32\AutoWorkplace.exe.config
[2015/10/30 00:45:11 | 001,520,828 | ---- | C] () -- C:\WINDOWS\System32\WpcNBModel.bin
[2015/10/30 00:45:11 | 000,526,068 | ---- | C] () -- C:\WINDOWS\System32\staticurllist.bin
[2015/10/30 00:45:10 | 000,164,224 | ---- | C] () -- C:\WINDOWS\System32\weretw.dll
[2015/10/30 00:45:06 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2015/10/30 00:45:04 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\BWContextHandler.dll
[2015/10/30 00:45:01 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\GamePanelExternalHook.dll
[2015/10/30 00:44:55 | 000,167,640 | ---- | C] () -- C:\WINDOWS\System32\chs_singlechar_pinyin.dat
[2015/10/30 00:44:55 | 000,149,504 | ---- | C] () -- C:\WINDOWS\System32\ism32k.dll
[2015/10/30 00:44:53 | 000,252,928 | ---- | C] () -- C:\WINDOWS\System32\Windows.Perception.Stub.dll
[2015/10/30 00:44:52 | 004,227,116 | ---- | C] () -- C:\WINDOWS\System32\DefaultHrtfs.bin
[2015/10/30 00:44:52 | 000,293,376 | ---- | C] () -- C:\WINDOWS\System32\HrtfApo.dll
[2015/10/30 00:44:52 | 000,149,044 | ---- | C] () -- C:\WINDOWS\System32\LargeRoom.bin
[2015/10/30 00:44:52 | 000,110,024 | ---- | C] () -- C:\WINDOWS\System32\MediumRoom.bin
[2015/10/30 00:44:52 | 000,069,776 | ---- | C] () -- C:\WINDOWS\System32\SmallRoom.bin
[2015/10/30 00:44:52 | 000,046,908 | ---- | C] () -- C:\WINDOWS\System32\OutdoorAudioEnvironment.bin
[2015/10/30 00:44:48 | 000,170,496 | ---- | C] () -- C:\WINDOWS\System32\EditionUpgradeHelper.dll
[2015/10/30 00:44:48 | 000,022,528 | ---- | C] () -- C:\WINDOWS\System32\efsext.dll
[2015/10/30 00:44:43 | 000,056,119 | ---- | C] () -- C:\WINDOWS\System32\srms.dat
[2015/10/30 00:44:41 | 000,002,269 | ---- | C] () -- C:\WINDOWS\System32\WimBootCompress.ini
[2015/10/30 00:44:40 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\settings.dat
[2015/10/30 00:44:38 | 000,074,752 | ---- | C] () -- C:\WINDOWS\System32\BthpanContextHandler.dll
[2015/10/30 00:44:38 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2015/09/26 08:57:45 | 001,101,824 | ---- | C] () -- C:\ProgramData\TrezaaSetupx30039.msi
[2015/09/25 08:04:04 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\wsusnative32.exe
[2015/09/01 05:52:10 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2015/08/30 20:03:48 | 000,007,625 | ---- | C] () -- C:\Users\User\AppData\Local\Resmon.ResmonCfg
[2015/01/13 16:49:36 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\amdverag.dll
[2015/01/13 16:22:32 | 000,204,952 | ---- | C] () -- C:\WINDOWS\System32\ativvsvl.dat
[2015/01/13 16:22:32 | 000,157,144 | ---- | C] () -- C:\WINDOWS\System32\ativvsva.dat
========== ZeroAccess Check ==========
[2015/12/25 18:35:01 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\windows.storage.dll -- [2016/01/16 01:16:49 | 005,238,360 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2015/10/30 00:44:40 | 000,765,440 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2015/10/30 00:44:39 | 000,409,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report >