Logfile of random's system information tool 1.10 (written by random/random) Run by xxxxxxxxxxxx at 2017-01-26 16:56:00 Microsoft Windows 10 Home System drive C: has 53 GB (41%) free of 128 GB Total RAM: 4072 MB (65% free) ======Listing Processes====== winlogon.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch C:\WINDOWS\system32\svchost.exe -k RPCSS "dwm.exe" C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\system32\atiesrxx.exe C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c49fc898-8b2e-4a15-98f3-5ff9f6d9e2cf -SystemEventPortName:HostProcess-14f69512-3136-49cf-b910-20c0efdaa8d8 -IoCancelEventPortName:HostProcess-8949d008-8f0c-4d72-ab06-1080c57cd88f -NonStateChangingEventPortName:HostProcess-e1d681a5-0581-4036-9c28-15d0344a43af -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:91178d6b-832e-4263-bc1c-b9c2577c14a1 -DeviceGroupId:WpdFsGroup C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\System32\svchost.exe -k NetworkService atieclxx C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted "C:\Windows\system32\FBAgent.exe" "C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe" "C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe" C:\WINDOWS\System32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" C:\WINDOWS\system32\svchost.exe -k apphost C:\WINDOWS\system32\EscSvc64.exe "C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe" dashost.exe {5bc87ed3-bb34-473c-b65916be45b33587} C:\WINDOWS\system32\svchost.exe -k iissvcs "C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe" C:\xampp\mysql\bin\mysqld.exe --defaults-file=c:\xampp\mysql\bin\my.ini mysql C:\WINDOWS\system32\svchost.exe -k appmodel C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k HPZ12 "C:\Program Files\Elantech\ETDService.exe" C:\WINDOWS\SysWoW64\svchost.exe -k hpdevmgmt C:\Windows\System32\svchost.exe -k HPZ12 C:\WINDOWS\system32\mqsvc.exe "C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe" C:\WINDOWS\System32\svchost.exe -k utcsvc "C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe" C:\Windows\system32\svchost.exe -k HPService C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe "C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted "C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE" "C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe" "C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe" "C:\Program Files\Elantech\ETDCtrl.exe" sihost.exe C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E} "C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe" "C:\Program Files\ASUS\P4G\BatteryLife.exe" C:\Windows\System32\RuntimeBroker.exe -Embedding C:\WINDOWS\Explorer.EXE "C:\Program Files\Elantech\ETDCtrlHelper.exe" "C:\Program Files (x86)\ASUS\Splendid\ACMON.exe" C:\Windows\SysWOW64\ACEngSvr.exe -Embedding "C:\Windows\AsScrPro.exe" "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s "C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca C:\WINDOWS\system32\SearchIndexer.exe /Embedding "C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe" "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SF3 "C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" "C:\Program Files\Mouse\Amoumain.exe" "C:\Program Files\Windows Defender\MSASCuiL.exe" "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background "C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe" "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow "C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" "C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" "C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" "C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe" "C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe" "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" C:\WINDOWS\system32\wbem\wmiprvse.exe "C:\Program Files\Windows Defender\\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey 0824BD48-F7C1-08C6-D898-F582B841B830 -Reinvoke KBFiltr.exe "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe" "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" C:\WINDOWS\system32\compattelrunner.exe \??\C:\WINDOWS\system32\conhost.exe 0x4 C:\WINDOWS\system32\CompatTelRunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun -cv:yLVQUmD9kk+9pExZ.1 "C:\Users\Marcoen Jan\Desktop\RSITx64.exe" "C:\Program Files\Windows Defender\\MpCmdRun.exe" SignatureUpdate -ScheduleJob -RestrictPrivileges -Reinvoke "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "C:\Program Files\Windows Defender\\MpCmdRun.exe" SignaturesUpdateService -ScheduleJob -UnmanagedUpdate \??\C:\WINDOWS\system32\conhost.exe 0x4 C:\WINDOWS\system32\wbem\wmiprvse.exe "C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "C:\WINDOWS\system32\SearchFilterHost.exe" 0 644 648 656 8192 652 C:\WINDOWS\System32\svchost.exe -k WerSvcGroup C:\WINDOWS\servicing\TrustedInstaller.exe C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.350_none_43278ee965418581\TiWorker.exe -Embedding "C:\WINDOWS\system32\wuauclt.exe" /RunHandlerComServer "C:\WINDOWS\SoftwareDistribution\Download\Install\AM_Delta.exe" WD /q MpSigStub.exe /program WD /q ======Scheduled tasks folder====== C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe C:\WINDOWS\tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job - C:\Windows\TEMP\{1EEEE507-DFB4-4F6D-BC23-0403EED2A83E}.exe --uninstall=1 C:\WINDOWS\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job - C:\Windows\TEMP\{91BE25D2-2A2C-43B3-BDAF-54BE9EB13FC9}.exe --uninstall=1 C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job - C:\WINDOWS\explorer.exe /NOUACCHECK C:\WINDOWS\tasks\EPSON ET-2550 Series Update {15ABA063-E013-4797-BE32-FB84221538D4}.job - C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSNXE.EXE /EXE:"{15ABA063-E013-4797-BE32-FB84221538D4}" /F:"Update" C:\WINDOWS\tasks\EPSON ET-2550 Series Update {1A89D076-8EBF-4FA7-8C6A-75B910CB72B5}.job - C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSNXE.EXE /EXE:"{1A89D076-8EBF-4FA7-8C6A-75B910CB72B5}" /F:"Update" C:\WINDOWS\tasks\EPSON ET-2550 Series Update {25C751D3-3716-4C75-AA79-1195771845BC}.job - C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSNXE.EXE /EXE:"{25C751D3-3716-4C75-AA79-1195771845BC}" /F:"Update" C:\WINDOWS\tasks\ParetoLogic Registration3.job - C:\WINDOWS\system32\rundll32.exe "C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\UUS3.dll" RunUns C:\WINDOWS\tasks\ParetoLogic Update Version3.job - C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe C:\WINDOWS\tasks\PC Health Advisor Defrag.job - C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe -defrag C:\WINDOWS\tasks\PC Health Advisor.job - C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe -scan =========Mozilla firefox========= ProfilePath - C:\Users\Marcoen Jan\AppData\Roaming\Mozilla\Firefox\Profiles\qfjdedys.default prefs.js - "browser.startup.homepage" - "https://www.malwarebytes.org/restorebrowser/?tpid=ORJ-ST-SPE&o=APN11467&pf=V7&trgb=CR&p2=%5EBED%5EOSJ000%5ECI%5EBE&gct=hp&apn_ptnrs=BED&apn_dtid=%5EOSJ000%5ECI%5EBE&apn_dbr=cr_36.0.1985.143&apn_uid=1F39F658-E027-423B-9B9E-928A2C9264DD&itbv=12.15.5.31&doi=2014-08-17&psv=&pt=tb" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 10 "Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer] "Description"=Adobe Shockwave Player "Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0] "Description"=Picasa3 plugin "Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.121.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.121.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0] "Description"=Office Authorization plug-in for NPAPI browsers "Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] "Description"=Microsoft SharePoint Plug-in for Firefox "Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin] "Description"=This plugin detects and launches Pando Media Booster "Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@zylom.com/ZylomGamesPlayer] "Description"=Zylom Games Player 1.00 "Path"=C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0] "Description"=Office Authorization plug-in for NPAPI browsers "Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL C:\Program Files (x86)\Mozilla Firefox\extensions\ belgiumeid@eid.belgium.be ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-22 473152] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-22 186944] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2016-06-10 3242696] "RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-06-24 1402624] "AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2011-03-21 361984] "WheelMouse"=C:\Program Files\Mouse\Amoumain.exe [2000-01-01 196608] "WindowsDefender"=C:\Program Files\Windows Defender\MSASCuiL.exe [2016-10-02 631808] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"=C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [2014-03-31 4272840] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Uninstall C:\Users\Marcoen Jan\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"=C:\WINDOWS\system32\cmd.exe [2016-07-16 232960] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-02-07 102568] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2015-09-24 40336] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe [2012-06-15 3058304] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2010-08-20 107816] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-06-24 13885696] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-11-04 767176] "ASUSPRP"=C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2012-02-24 3331312] "ASUSWebStorage"=C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [2011-07-29 737104] "SonicMasterTray"=C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [2010-07-10 984400] "ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-12-23 318080] "ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2011-10-25 174720] "HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016] "Wireless Console 3"=C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2011-10-19 2319536] "beid"=C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe /startup [] "Raptr"=C:\Program Files (x86)\Raptr\raptrstub.exe [2015-10-01 56080] "EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2016-01-20 1087184] "SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-12-12 587288] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup FancyStart daemon.lnk - C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DSCAutomationHostEnabled"=2 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=255 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "midimapper"=midimap.dll "msacm.imaadpcm"=imaadp32.acm "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "msacm.msadpcm"=msadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "vidc.i420"=iyuv_32.dll "vidc.iyuv"=iyuv_32.dll "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "vidc.uyvy"=msyuv.dll "vidc.yuy2"=msyuv.dll "vidc.yvu9"=tsbyuv.dll "vidc.yvyu"=msyuv.dll "wavemapper"=msacm32.drv "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv "MSVideo8"=VfWWDM32.dll ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2017-01-26 16:59:59 ----D---- C:\Program Files\trend micro 2017-01-26 16:55:56 ----D---- C:\rsit 2017-01-14 17:38:46 ----A---- C:\WINDOWS\SYSWOW64\shoCE88.tmp 2017-01-13 09:16:26 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2017-01-13 09:16:25 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll 2017-01-13 09:16:22 ----A---- C:\WINDOWS\system32\Windows.Media.dll 2017-01-13 09:16:22 ----A---- C:\WINDOWS\system32\mfcore.dll 2017-01-13 09:16:21 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll 2017-01-13 09:16:21 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll 2017-01-13 09:16:20 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll 2017-01-13 09:16:20 ----A---- C:\WINDOWS\SYSWOW64\InstallAgentUserBroker.exe 2017-01-13 09:16:20 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe 2017-01-13 09:16:20 ----A---- C:\WINDOWS\system32\d2d1.dll 2017-01-13 09:16:19 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.ApplicationData.dll 2017-01-13 09:16:19 ----A---- C:\WINDOWS\system32\mfnetsrc.dll 2017-01-13 09:16:19 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2017-01-13 09:16:18 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll 2017-01-13 09:16:18 ----A---- C:\WINDOWS\system32\aeinv.dll 2017-01-13 09:16:17 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll 2017-01-13 09:16:16 ----A---- C:\WINDOWS\system32\rdpcore.dll 2017-01-13 09:16:16 ----A---- C:\WINDOWS\system32\mfnetcore.dll 2017-01-13 09:16:15 ----A---- C:\WINDOWS\system32\rdpencom.dll 2017-01-13 09:16:15 ----A---- C:\WINDOWS\system32\mstscax.dll 2017-01-13 09:16:15 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll 2017-01-13 09:16:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.CredDialogController.dll 2017-01-13 09:16:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Cred.dll 2017-01-13 09:16:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.BlockedShutdown.dll 2017-01-13 09:16:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.BioFeedback.dll 2017-01-13 09:16:14 ----A---- C:\WINDOWS\system32\D3D12.dll 2017-01-13 09:16:13 ----A---- C:\WINDOWS\SYSWOW64\offlinesam.dll 2017-01-13 09:16:13 ----A---- C:\WINDOWS\system32\wuuhext.dll 2017-01-13 09:16:13 ----A---- C:\WINDOWS\system32\wuaueng.dll 2017-01-13 09:16:13 ----A---- C:\WINDOWS\system32\winlogon.exe 2017-01-13 09:16:13 ----A---- C:\WINDOWS\system32\sppobjs.dll 2017-01-13 09:16:13 ----A---- C:\WINDOWS\system32\samsrv.dll 2017-01-13 09:16:12 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2vdec.dll 2017-01-13 09:16:12 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll 2017-01-13 09:16:12 ----A---- C:\WINDOWS\system32\offlinesam.dll 2017-01-13 09:16:12 ----A---- C:\WINDOWS\system32\lsasrv.dll 2017-01-13 09:16:11 ----A---- C:\WINDOWS\system32\shell32.dll 2017-01-13 09:16:10 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll 2017-01-13 09:16:08 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll 2017-01-13 09:16:08 ----A---- C:\WINDOWS\system32\wuapi.dll 2017-01-13 09:16:08 ----A---- C:\WINDOWS\system32\drivers\cng.sys 2017-01-13 09:16:07 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll 2017-01-13 09:16:07 ----A---- C:\WINDOWS\system32\updatepolicy.dll 2017-01-13 09:16:07 ----A---- C:\WINDOWS\system32\msv1_0.dll 2017-01-13 09:16:07 ----A---- C:\WINDOWS\system32\kerberos.dll 2017-01-13 09:16:07 ----A---- C:\WINDOWS\system32\ImplatSetup.dll 2017-01-13 09:16:06 ----A---- C:\WINDOWS\SYSWOW64\WinSCard.dll 2017-01-13 09:16:06 ----A---- C:\WINDOWS\SYSWOW64\MSVP9DEC.dll 2017-01-13 09:16:06 ----A---- C:\WINDOWS\SYSWOW64\cryptui.dll 2017-01-13 09:16:06 ----A---- C:\WINDOWS\system32\wow64.dll 2017-01-13 09:16:06 ----A---- C:\WINDOWS\system32\WinSCard.dll 2017-01-13 09:16:06 ----A---- C:\WINDOWS\system32\cryptui.dll 2017-01-13 09:16:06 ----A---- C:\WINDOWS\system32\certprop.dll 2017-01-13 09:16:05 ----A---- C:\WINDOWS\system32\ScDeviceEnum.dll 2017-01-13 09:16:04 ----A---- C:\WINDOWS\SYSWOW64\indexeddbserver.dll 2017-01-13 09:16:04 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll 2017-01-13 09:16:04 ----A---- C:\WINDOWS\SYSWOW64\AUDIOKSE.dll 2017-01-13 09:16:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll 2017-01-13 09:16:03 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll 2017-01-13 09:16:03 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll 2017-01-13 09:16:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll 2017-01-13 09:16:00 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll 2017-01-13 09:15:59 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll 2017-01-13 09:15:59 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll 2017-01-13 09:15:59 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll 2017-01-13 09:15:58 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2017-01-13 09:15:57 ----A---- C:\WINDOWS\SYSWOW64\mspaint.exe 2017-01-13 09:15:57 ----A---- C:\WINDOWS\system32\Chakra.dll 2017-01-13 09:15:56 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll 2017-01-13 09:15:56 ----A---- C:\WINDOWS\system32\win32kbase.sys 2017-01-13 09:15:55 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll 2017-01-13 09:15:55 ----A---- C:\WINDOWS\system32\mspaint.exe 2017-01-13 09:15:54 ----A---- C:\WINDOWS\SYSWOW64\winmde.dll 2017-01-13 09:15:54 ----A---- C:\WINDOWS\system32\msmpeg2vdec.dll 2017-01-13 09:15:54 ----A---- C:\WINDOWS\system32\indexeddbserver.dll 2017-01-13 09:15:53 ----A---- C:\WINDOWS\system32\mshtml.dll 2017-01-13 09:15:52 ----A---- C:\WINDOWS\system32\winmde.dll 2017-01-13 09:15:52 ----A---- C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll 2017-01-13 09:15:52 ----A---- C:\WINDOWS\system32\twinui.dll 2017-01-13 09:15:51 ----A---- C:\WINDOWS\system32\edgehtml.dll 2017-01-13 09:15:51 ----A---- C:\WINDOWS\system32\aadcloudap.dll 2017-01-13 09:15:48 ----A---- C:\WINDOWS\system32\aadtb.dll 2017-01-13 09:15:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll 2017-01-13 09:15:45 ----A---- C:\WINDOWS\system32\usocore.dll 2017-01-13 09:15:45 ----A---- C:\WINDOWS\system32\rdpcorets.dll 2017-01-13 09:15:44 ----A---- C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll 2017-01-13 09:15:44 ----A---- C:\WINDOWS\system32\updatehandlers.dll 2017-01-13 09:15:44 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe 2017-01-13 09:15:43 ----A---- C:\WINDOWS\SYSWOW64\remoteaudioendpoint.dll 2017-01-13 09:15:43 ----A---- C:\WINDOWS\SYSWOW64\rdpcore.dll 2017-01-13 09:15:43 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe 2017-01-13 09:15:43 ----A---- C:\WINDOWS\system32\MSVP9DEC.dll 2017-01-13 09:15:42 ----A---- C:\WINDOWS\system32\rdpudd.dll 2017-01-13 09:15:41 ----A---- C:\WINDOWS\SYSWOW64\SyncSettings.dll 2017-01-13 09:15:41 ----A---- C:\WINDOWS\SYSWOW64\rdpencom.dll 2017-01-13 09:15:41 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll 2017-01-13 09:15:41 ----A---- C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll 2017-01-13 09:15:40 ----A---- C:\WINDOWS\SYSWOW64\MSVPXENC.dll 2017-01-13 09:15:40 ----A---- C:\WINDOWS\system32\OneBackupHandler.dll 2017-01-13 09:15:39 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll 2017-01-13 09:15:39 ----A---- C:\WINDOWS\SYSWOW64\CloudBackupSettings.dll 2017-01-13 09:15:39 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll 2017-01-13 09:15:39 ----A---- C:\WINDOWS\system32\win32kfull.sys 2017-01-13 09:15:39 ----A---- C:\WINDOWS\system32\win32k.sys 2017-01-13 09:15:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll 2017-01-13 09:15:38 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll 2017-01-13 09:15:38 ----A---- C:\WINDOWS\system32\SRH.dll 2017-01-13 09:15:37 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll 2017-01-13 09:15:37 ----A---- C:\WINDOWS\system32\SRHInproc.dll 2017-01-13 09:15:36 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll 2017-01-13 09:15:36 ----A---- C:\WINDOWS\system32\dosvc.dll 2017-01-13 09:15:36 ----A---- C:\WINDOWS\system32\domgmt.dll 2017-01-13 09:15:36 ----A---- C:\WINDOWS\system32\AudioSes.dll 2017-01-13 09:15:36 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll 2017-01-13 09:15:36 ----A---- C:\WINDOWS\system32\AudioEng.dll 2017-01-13 09:15:36 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll 2017-01-13 09:15:36 ----A---- C:\WINDOWS\system32\aclui.dll 2017-01-13 09:15:35 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe 2017-01-13 09:15:35 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll 2017-01-13 09:15:35 ----A---- C:\WINDOWS\system32\ClipUp.exe 2017-01-13 09:15:35 ----A---- C:\WINDOWS\system32\audiosrv.dll 2017-01-13 09:15:34 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll 2017-01-13 09:15:34 ----A---- C:\WINDOWS\system32\StoreAgent.dll 2017-01-13 09:15:34 ----A---- C:\WINDOWS\system32\InstallAgentUserBroker.exe 2017-01-13 09:15:34 ----A---- C:\WINDOWS\system32\InstallAgent.exe 2017-01-13 09:15:33 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll 2017-01-13 09:15:33 ----A---- C:\WINDOWS\system32\wbiosrvc.dll 2017-01-13 09:15:33 ----A---- C:\WINDOWS\system32\ie4uinit.exe 2017-01-13 09:15:32 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll 2017-01-13 09:15:32 ----A---- C:\WINDOWS\SYSWOW64\mqmigplugin.dll 2017-01-13 09:15:32 ----A---- C:\WINDOWS\system32\Windows.UI.CredDialogController.dll 2017-01-13 09:15:32 ----A---- C:\WINDOWS\system32\remoteaudioendpoint.dll 2017-01-13 09:15:32 ----A---- C:\WINDOWS\system32\drivers\vhdmp.sys 2017-01-13 09:15:31 ----A---- C:\WINDOWS\system32\mqcmiplugin.dll 2017-01-13 09:15:30 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll 2017-01-13 09:15:30 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll 2017-01-13 09:15:30 ----A---- C:\WINDOWS\system32\SyncSettings.dll 2017-01-13 09:15:30 ----A---- C:\WINDOWS\system32\cloudAP.dll 2017-01-13 09:15:29 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll 2017-01-13 09:15:29 ----A---- C:\WINDOWS\system32\winsrv.dll 2017-01-13 09:15:29 ----A---- C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll 2017-01-13 09:15:29 ----A---- C:\WINDOWS\system32\Windows.UI.BioFeedback.dll 2017-01-13 09:15:29 ----A---- C:\WINDOWS\system32\fhsettingsprovider.dll 2017-01-13 09:15:29 ----A---- C:\WINDOWS\system32\CloudBackupSettings.dll 2017-01-13 09:15:28 ----A---- C:\WINDOWS\system32\securekernel.exe 2017-01-13 09:15:28 ----A---- C:\WINDOWS\system32\fhcfg.dll 2017-01-13 09:15:27 ----A---- C:\WINDOWS\system32\ntoskrnl.exe 2017-01-13 09:15:27 ----A---- C:\WINDOWS\system32\drivers\pci.sys 2017-01-13 09:15:18 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2017-01-13 09:15:17 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys 2017-01-13 09:15:17 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll 2017-01-13 09:15:15 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe 2017-01-13 09:15:15 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll 2017-01-13 09:15:15 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll 2017-01-13 09:15:14 ----A---- C:\WINDOWS\SYSWOW64\d2d1.dll 2017-01-13 09:15:14 ----A---- C:\WINDOWS\system32\LogonController.dll 2017-01-13 09:15:12 ----A---- C:\WINDOWS\system32\ConsoleLogon.dll 2017-01-13 09:15:12 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll 2017-01-13 09:15:11 ----A---- C:\WINDOWS\SYSWOW64\win32k.sys 2017-01-13 09:15:11 ----A---- C:\WINDOWS\system32\MSVPXENC.dll 2017-01-13 09:15:10 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll 2017-01-13 09:15:10 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll 2017-01-13 09:15:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.UI.Logon.ProxyStub.dll 2017-01-13 09:15:09 ----A---- C:\WINDOWS\system32\provengine.dll 2017-01-13 09:15:06 ----A---- C:\WINDOWS\system32\ProvPluginEng.dll 2017-01-13 09:15:06 ----A---- C:\WINDOWS\system32\KnobsCsp.dll 2017-01-13 09:15:06 ----A---- C:\WINDOWS\system32\KnobsCore.dll 2017-01-13 09:15:05 ----A---- C:\WINDOWS\SYSWOW64\D3D12.dll ======List of files/folders modified in the last 1 month====== 2017-01-26 17:08:49 ----D---- C:\WINDOWS\Temp 2017-01-26 17:08:49 ----D---- C:\WINDOWS\Prefetch 2017-01-26 16:59:59 ----RD---- C:\Program Files 2017-01-26 16:39:07 ----A---- C:\WINDOWS\SYSWOW64\log.txt 2017-01-26 16:38:11 ----HD---- C:\ASUS.DAT 2017-01-26 16:36:30 ----D---- C:\WINDOWS\system32\sru 2017-01-26 16:36:05 ----D---- C:\WINDOWS\system32\SleepStudy 2017-01-26 01:28:16 ----RD---- C:\WINDOWS\Microsoft.NET 2017-01-26 01:26:36 ----HD---- C:\Program Files\WindowsApps 2017-01-26 01:26:36 ----D---- C:\WINDOWS\AppReadiness 2017-01-25 16:46:21 ----D---- C:\WINDOWS\Tasks 2017-01-25 15:59:54 ----D---- C:\WINDOWS\System32 2017-01-25 13:56:05 ----SHD---- C:\System Volume Information 2017-01-25 13:39:27 ----D---- C:\WINDOWS\system32\drivers 2017-01-25 13:39:27 ----D---- C:\WINDOWS\fr 2017-01-25 13:39:11 ----D---- C:\WINDOWS\system32\catroot2 2017-01-25 12:21:09 ----D---- C:\Program Files\Enigma Software Group 2017-01-25 10:45:47 ----D---- C:\WINDOWS\system32\WDI 2017-01-25 10:23:23 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service 2017-01-24 22:52:56 ----D---- C:\Training_Analyser_v4.4 2017-01-24 22:41:49 ----RD---- C:\Program Files (x86) 2017-01-24 14:16:46 ----D---- C:\WINDOWS\INF 2017-01-22 17:40:17 ----D---- C:\WINDOWS\LiveKernelReports 2017-01-22 11:06:43 ----D---- C:\ProgramData\Oracle 2017-01-22 11:02:03 ----SHDC---- C:\WINDOWS\Installer 2017-01-22 11:02:03 ----HD---- C:\Config.Msi 2017-01-22 11:02:03 ----D---- C:\Program Files (x86)\Java 2017-01-22 11:02:01 ----D---- C:\WINDOWS\SysWOW64 2017-01-22 11:01:45 ----D---- C:\Program Files (x86)\Common Files 2017-01-22 11:01:17 ----A---- C:\WINDOWS\SYSWOW64\WindowsAccessBridge-32.dll 2017-01-20 16:01:33 ----D---- C:\WINDOWS\system32\config 2017-01-16 16:20:47 ----RD---- C:\WINDOWS\assembly 2017-01-15 16:48:31 ----D---- C:\WINDOWS\rescache 2017-01-15 00:32:26 ----D---- C:\WINDOWS\WinSxS 2017-01-14 17:41:56 ----SHD---- C:\Boot 2017-01-14 17:41:44 ----D---- C:\WINDOWS\system32\DriverStore 2017-01-14 17:38:02 ----D---- C:\WINDOWS\system32\WinBioPlugIns 2017-01-14 17:38:02 ----D---- C:\WINDOWS\system32\wbem 2017-01-14 17:38:02 ----D---- C:\WINDOWS\system32\oobe 2017-01-14 17:38:01 ----D---- C:\WINDOWS\ShellExperiences 2017-01-14 17:38:01 ----D---- C:\WINDOWS\Provisioning 2017-01-14 17:38:00 ----RD---- C:\WINDOWS\ImmersiveControlPanel 2017-01-14 17:38:00 ----D---- C:\Program Files\Internet Explorer 2017-01-14 17:38:00 ----D---- C:\Program Files (x86)\Internet Explorer 2017-01-14 10:53:04 ----D---- C:\WINDOWS\CbsTemp 2017-01-13 09:43:21 ----D---- C:\WINDOWS\system32\MRT 2017-01-13 09:37:51 ----AC---- C:\WINDOWS\system32\MRT.exe 2017-01-04 01:26:28 ----D---- C:\ProgramData\tmp ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-11-19 652344] R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys [2016-11-02 48992] R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536] R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2013-07-29 45856] R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2016-07-16 88576] R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2016-07-16 8192] R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416] R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2016-07-16 70144] R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2016-07-16 48128] R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2016-07-16 78336] R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2016-06-10 21648880] R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2016-06-10 674288] R3 asmthub3;@oem10.inf,%asmthub3_ServiceDescription%;ASMedia USB3 Hub Service; C:\WINDOWS\System32\drivers\asmthub3.sys [2016-05-15 149240] R3 asmtxhci;@oem13.inf,%asmtxhci_ServiceDescription%;ASMEDIA XHCI Service; C:\WINDOWS\System32\drivers\asmtxhci.sys [2016-05-15 443128] R3 AtiHDAudioService;@oem39.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWT6.sys [2015-05-28 102912] R3 ETD;@oem8.inf,%PS2.DeviceDesc%;ELAN Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2016-06-10 525512] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2015-06-24 4504320] R3 kbfiltr;@oem36.inf,%kbfiltr.SvcDesc%;Keyboard Filter; C:\WINDOWS\System32\drivers\kbfiltr.sys [2009-07-20 15416] R3 L1C;@netl1c63x64.inf,%L1C.Service.DispName%;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller; C:\WINDOWS\System32\drivers\L1C63x64.sys [2016-07-16 121344] R3 MEIx64;@oem29.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface; C:\WINDOWS\System32\drivers\HECIx64.sys [2010-10-20 56344] R3 MQAC;@mqutil.dll,-6101; C:\WINDOWS\system32\drivers\mqac.sys [2016-10-02 175616] R3 netr28x;@oem37.inf,%Generic.Service.DispName%;Ralink 802.11n Extensible Wireless Driver; C:\WINDOWS\system32\DRIVERS\netr28x.sys [2015-06-12 2554528] R3 Sftfs;Sftfs; C:\WINDOWS\system32\DRIVERS\Sftfslh.sys [2014-10-08 766632] R3 Sftplay;Sftplay; C:\WINDOWS\system32\DRIVERS\Sftplaylh.sys [2014-10-08 273576] R3 Sftredir;Sftredir; C:\WINDOWS\system32\DRIVERS\Sftredirlh.sys [2014-10-08 29352] R3 Sftvol;Sftvol; C:\WINDOWS\system32\DRIVERS\Sftvollh.sys [2014-10-08 23208] R3 StillCam;@sti.inf,%StillCam.SvcDesc%;Stuurprogramma voor seriële digitale fotocamera; C:\WINDOWS\system32\DRIVERS\serscan.sys [2016-07-16 12800] S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2016-07-16 105824] S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2016-07-16 101216] S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2016-10-05 64352] S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2016-07-16 58720] S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2016-07-16 61792] S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2016-07-16 88416] S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2016-07-16 32096] S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-07-16 18432] S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2016-07-16 15360] S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2016-07-16 9728] S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2016-07-16 38912] S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2016-09-10 118272] S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-07-16 346976] S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-07-16 2104160] S3 dg_ssudbus;@oem30.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2016-09-05 131712] S3 fssfltr;fssfltr; C:\WINDOWS\system32\DRIVERS\fssfltr.sys [2012-09-12 57856] S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2016-07-16 20480] S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2016-07-16 50016] S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2016-10-02 73568] S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2016-07-16 33280] S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2016-07-16 81408] S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-07-16 64512] S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2016-07-16 176384] S3 iaStor;Intel AHCI Controller; C:\WINDOWS\system32\DRIVERS\iaStor.sys [2011-04-26 557848] S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2016-07-16 526176] S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-07-16 35840] S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2016-07-16 120320] S3 libwamf;libwamf; C:\WINDOWS\system32\DRIVERS\libwamf.sys [2016-06-16 15664] S3 libwasys;libwasys; C:\WINDOWS\System32\DRIVERS\libwasys.sys [2016-06-16 28464] S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2016-07-16 842584] S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2016-07-16 108896] S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2016-07-16 90624] S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2016-07-16 928608] S3 Revoflt;Revoflt; C:\WINDOWS\system32\DRIVERS\revoflt.sys [2009-12-30 31800] S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-07-16 123904] S3 ssudmdm;@oem5.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2016-09-05 165504] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-09-14 82128] R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2011-03-04 379520] R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2016-06-10 255472] R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2011-11-21 80512] R2 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [2012-02-04 277120] R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896] R2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] R2 CDPUserSvc_507b2;CDPUserSvc_507b2; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2015-03-18 822496] R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496] R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] R2 EpsonScanSvc;Epson Scanner Service; C:\WINDOWS\system32\EscSvc64.exe [2012-05-16 144560] R2 ETDService;Elan Service; C:\Program Files\Elantech\ETDService.exe [2016-06-10 144072] R2 hpqddsvc;HP CUE DeviceDiscovery-service; C:\WINDOWS\syswow64\svchost.exe [2016-07-16 38792] R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2016-07-16 44496] R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656] R2 MSMQ;@mqutil.dll,-6102; C:\WINDOWS\system32\mqsvc.exe [2016-10-02 26112] R2 mysql;mysql; C:\xampp\mysql\bin\mysqld.exe [2012-07-20 8186368] R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2016-07-16 44496] R2 NetMsmqActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8195; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-16 136360] R2 NetPipeActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-16 136360] R2 OneSyncSvc_507b2;Host synchroniseren_507b2; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2016-07-16 44496] R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2014-10-08 534184] R3 hpqcxs08;hpqcxs08; C:\WINDOWS\syswow64\svchost.exe [2016-07-16 38792] R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2014-10-08 211104] R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S2 Apache2.4;Apache2.4; C:\xampp\apache\bin\httpd.exe [2012-08-18 22016] S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S2 FileZillaServer;FileZillaServer; C:\xampp\filezillaftp\filezillaserver.exe [2012-05-11 632320] S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200] S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496] S2 NetTcpActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-16 136360] S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12 269000] S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-07-16 52920] S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496] S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496] S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496] S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2016-07-16 93184] S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496] S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496] S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696] S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496] S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2014-03-31 1512640] S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200] S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-09 136120] S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496] S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 MessagingService_507b2;MessagingService_507b2; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-07-24 148080] S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496] S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352] S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 PimIndexMaintenanceSvc_507b2;Contact Data_507b2; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496] S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496] S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2016-10-02 1312768] S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496] S4 msvsmon90;Visual Studio 2008 Remote Debugger; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [2007-11-07 4466688] S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496] -----------------EOF-----------------