Summary Operating System Windows 10 Home 64-bit CPU Intel Core i5 6500 @ 3.20GHz 37 °C Skylake 14nm Technology RAM 16.0GB Dual-Channel Unknown (15-15-15-35) Motherboard Gigabyte Technology Co. Ltd. Z170-HD3P-CF (U3E1) 41 °C Graphics S200HQL (1600x900@60Hz) HP 25es (1920x1080@59Hz) HP w19b/w19e (1440x900@60Hz) Intel HD Graphics 530 (Gigabyte) Storage 232GB Samsung SSD 750 EVO 250GB (SSD) 37 °C 931GB Western Digital WDC WD10EZEX-00WN4A0 (SATA) 38 °C Optical Drives ASUS DRW-24B1ST j Audio Realtek High Definition Audio Operating System Windows 10 Home 64-bit Computer type: Desktop Installation Date: 09/30/2016 3:42:28 AM Windows Security Center User Account Control (UAC) Enabled Notify level 0 - Never Notify Windows Update AutoUpdate Not configured Windows Defender Windows Defender Disabled Firewall Firewall Enabled Display Name Kaspersky Total Security Antivirus Kaspersky Total Security Antivirus Enabled Virus Signature Database Up to date Windows Defender Antivirus Disabled Virus Signature Database Up to date .NET Frameworks installed v4.6 Full v4.6 Client v3.5 SP1 v3.0 SP2 v2.0 SP2 Internet Explorer Version 11.576.14393.0 PowerShell Version 5.1.14393.0 Java Java Runtime Environment Path C:\Program Files (x86)\Java\jre1.8.0_111\bin\java.exe Version 8.0 Update 111 Build 14 Environment Variables USERPROFILE C:\Users\Zoe SystemRoot C:\WINDOWS User Variables OneDrive C:\Users\Zoe\OneDrive Path C:\Users\Zoe\AppData\Local\Microsoft\WindowsApps TEMP C:\Users\Zoe\AppData\Local\Temp TMP C:\Users\Zoe\AppData\Local\Temp Machine Variables asl.log Destination=file ComSpec C:\WINDOWS\system32\cmd.exe GTK_BASEPATH C:\Program Files (x86)\GtkSharp\2.12\ NUMBER_OF_PROCESSORS 4 OS Windows_NT Path C:\ProgramData\Oracle\Java\javapath C:\WINDOWS\system32 C:\WINDOWS C:\WINDOWS\System32\Wbem C:\WINDOWS\System32\WindowsPowerShell\v1.0\ C:\Program Files (x86)\GtkSharp\2.12\bin PATHEXT .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC PROCESSOR_ARCHITECTURE AMD64 PROCESSOR_IDENTIFIER Intel64 Family 6 Model 94 Stepping 3, GenuineIntel PROCESSOR_LEVEL 6 PROCESSOR_REVISION 5e03 PSModulePath %ProgramFiles%\WindowsPowerShell\Modules C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules TEMP C:\WINDOWS\TEMP TMP C:\WINDOWS\TEMP USERNAME SYSTEM VS140COMNTOOLS C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\Tools\ windir C:\WINDOWS Power Profile Active power scheme High performance Hibernation Disabled Turn Off Monitor after: (On AC Power) Never Turn Off Hard Disk after: (On AC Power) 5 min Suspend after: (On AC Power) Never Screen saver Disabled Uptime Current Session Current Time 01/09/2017 6:42:57 PM Current Uptime 176,672 sec (2 d, 01 h, 04 m, 32 s) Last Boot Time 01/07/2017 5:38:25 PM Services Running Apple Mobile Device Service Running Application Information Running Background Intelligent Transfer Service Running Background Tasks Infrastructure Service Running Base Filtering Engine Running Bonjour Service Running CDPUserSvc_528fd Running Certificate Propagation Running Client License Service (ClipSVC) Running CNG Key Isolation Running COM+ Event System Running Computer Browser Running Connected Devices Platform Service Running Connected User Experiences and Telemetry Running Contact Data_528fd Running CoreMessaging Running Credential Manager Running Cryptographic Services Running Data Sharing Service Running DbxSvc Running DCOM Server Process Launcher Running Device Association Service Running DHCP Client Running Diagnostic Policy Service Running Diagnostic Service Host Running Diagnostic System Host Running Distributed Link Tracking Client Running DNS Client Running Encrypting File System (EFS) Running Function Discovery Provider Host Running Function Discovery Resource Publication Running Geolocation Service Running Group Policy Client Running HomeGroup Provider Running IKE and AuthIP IPsec Keying Modules Running Intel HD Graphics Control Panel Service Running Intel Rapid Storage Technology Running IP Helper Running iPod Service Running IPsec Policy Agent Running Kaspersky Anti-Virus Service 17.0.0 Running Kaspersky Secure Connection Service 1.0.0 Running Local Session Manager Running Microsoft Account Sign-in Assistant Running Microsoft Office Click-to-Run Service Running Microsoft Software Shadow Copy Provider Running Network Connected Devices Auto-Setup Running Network Connection Broker Running Network Connections Running Network List Service Running Network Location Awareness Running Network Store Interface Service Running NO-IP DUC v4.1.1 Running Peer Name Resolution Protocol Running Peer Networking Identity Manager Running Plug and Play Running Power Running Print Spooler Running Program Compatibility Assistant Service Running Remote Desktop Configuration Running Remote Desktop Services Running Remote Desktop Services UserMode Port Redirector Running Remote Procedure Call (RPC) Running RPC Endpoint Mapper Running Samsung RAPID Mode Service Running Security Accounts Manager Running Security Center Running Server Running Shell Hardware Detection Running SSDP Discovery Running State Repository Service Running Storage Service Running Superfetch Running Sync Host_528fd Running Synergy Running System Event Notification Service Running System Events Broker Running Task Scheduler Running TCP/IP NetBIOS Helper Running TeamViewer 11 Running Themes Running Tile Data model server Running Time Broker Running Update service Running User Data Access_528fd Running User Data Storage_528fd Running User Manager Running User Profile Service Running VNC Server Running Windows Audio Running Windows Audio Endpoint Builder Running Windows Connection Manager Running Windows Driver Foundation - User-mode Driver Framework Running Windows Event Log Running Windows Firewall Running Windows Font Cache Service Running Windows Image Acquisition (WIA) Running Windows License Manager Service Running Windows Management Instrumentation Running Windows Presentation Foundation Font Cache 3.0.0.0 Running Windows Push Notifications System Service Running Windows Search Running WinHTTP Web Proxy Auto-Discovery Service Running Workstation Stopped ActiveX Installer (AxInstSV) Stopped Adobe Flash Player Update Service Stopped AllJoyn Router Service Stopped App Readiness Stopped Application Identity Stopped Application Layer Gateway Service Stopped AppX Deployment Service (AppXSVC) Stopped ASP.NET State Service Stopped Auto Time Zone Updater Stopped BitLocker Drive Encryption Service Stopped Block Level Backup Engine Service Stopped Bluetooth Handsfree Service Stopped Bluetooth Support Service Stopped COM+ System Application Stopped DataCollectionPublishingService Stopped Delivery Optimization Stopped Device Install Service Stopped Device Management Enrollment Service Stopped Device Setup Manager Stopped DevQuery Background Discovery Broker Stopped Distributed Transaction Coordinator Stopped dmwappushsvc Stopped Downloaded Maps Manager Stopped Dropbox Update Service (dbupdate) Stopped Dropbox Update Service (dbupdatem) Stopped Embedded Mode Stopped Enterprise App Management Service Stopped Extensible Authentication Protocol Stopped Fax Stopped File History Service Stopped Google Update Service (gupdate) Stopped Google Update Service (gupdatem) Stopped HomeGroup Listener Stopped Human Interface Device Service Stopped HV Host Service Stopped Hyper-V Data Exchange Service Stopped Hyper-V Guest Service Interface Stopped Hyper-V Guest Shutdown Service Stopped Hyper-V Heartbeat Service Stopped Hyper-V PowerShell Direct Service Stopped Hyper-V Remote Desktop Virtualization Service Stopped Hyper-V Time Synchronization Service Stopped Hyper-V Volume Shadow Copy Requestor Stopped Infrared monitor service Stopped Intel Content Protection HDCP Service Stopped Intel Content Protection HECI Service Stopped Interactive Services Detection Stopped Internet Connection Sharing (ICS) Stopped klvssbrigde64 Stopped KtmRm for Distributed Transaction Coordinator Stopped Link-Layer Topology Discovery Mapper Stopped MessagingService_528fd Stopped Microsoft Diagnostics Hub Standard Collector Service Stopped Microsoft iSCSI Initiator Service Stopped Microsoft Passport Stopped Microsoft Passport Container Stopped Microsoft Storage Spaces SMP Stopped Microsoft Windows SMS Router Service. Stopped Mozilla Maintenance Service Stopped Net.Tcp Port Sharing Service Stopped Netlogon Stopped Network Connectivity Assistant Stopped Network Setup Service Stopped Office Source Engine Stopped Optimize drives Stopped Peer Networking Grouping Stopped Performance Counter DLL Host Stopped Performance Logs & Alerts Stopped Phone Service Stopped PNRP Machine Name Publication Service Stopped Portable Device Enumerator Service Stopped Printer Extensions and Notifications Stopped Problem Reports and Solutions Control Panel Support Stopped Quality Windows Audio Video Experience Stopped Radio Management Service Stopped Remote Access Auto Connection Manager Stopped Remote Access Connection Manager Stopped Remote Procedure Call (RPC) Locator Stopped Remote Registry Stopped Retail Demo Service Stopped Routing and Remote Access Stopped Secondary Logon Stopped Secure Socket Tunneling Protocol Service Stopped Sensor Data Service Stopped Sensor Monitoring Service Stopped Sensor Service Stopped Shared PC Account Manager Stopped Smart Card Stopped Smart Card Device Enumeration Service Stopped Smart Card Removal Policy Stopped SNMP Trap Stopped Software Protection Stopped Spot Verifier Stopped Still Image Acquisition Events Stopped Storage Tiers Management Stopped Telephony Stopped Touch Keyboard and Handwriting Panel Service Stopped Update Orchestrator Service for Windows Update Stopped UPnP Device Host Stopped Virtual Disk Stopped Visual Studio Standard Collector Service Stopped Volume Shadow Copy Stopped WalletService Stopped WebClient Stopped Windows Backup Stopped Windows Biometric Service Stopped Windows Camera Frame Server Stopped Windows Connect Now - Config Registrar Stopped Windows Defender Network Inspection Service Stopped Windows Defender Service Stopped Windows Encryption Provider Host Service Stopped Windows Error Reporting Service Stopped Windows Event Collector Stopped Windows Insider Service Stopped Windows Installer Stopped Windows Media Player Network Sharing Service Stopped Windows Mobile Hotspot Service Stopped Windows Modules Installer Stopped Windows Push Notifications User Service_528fd Stopped Windows Remote Management (WS-Management) Stopped Windows Time Stopped Windows Update Stopped Wired AutoConfig Stopped WLAN AutoConfig Stopped WMI Performance Adapter Stopped Work Folders Stopped WWAN AutoConfig Stopped Xbox Live Auth Manager Stopped Xbox Live Game Save Stopped Xbox Live Networking Service TimeZone TimeZone GMT -6:00 Hours Language English (United States) Location United States Format English (United States) Currency $ Date Format MM/dd/yyyy Time Format h:mm:ss tt Scheduler 01/09/2017 7:13 PM; DropboxUpdateTaskMachineUA 01/09/2017 7:16 PM; GoogleUpdateTaskMachineUA 01/09/2017 7:20 PM; Adobe Flash Player Updater 01/09/2017 7:22 PM; GoogleUpdateTaskUserS-1-5-21-3591470129-1721147500-3194162361-1001UA 01/10/2017 9:20 AM; OneDrive Standalone Update Task v2 01/10/2017 4:05 PM; OneDrive Standalone Update Task 01/10/2017 4:16 PM; GoogleUpdateTaskMachineCore 01/10/2017 6:13 PM; DropboxUpdateTaskMachineCore 01/10/2017 6:22 PM; GoogleUpdateTaskUserS-1-5-21-3591470129-1721147500-3194162361-1001Core 01/13/2017 7:10 AM; Apple Diagnostics SamsungMagician Hotfixes Installed 12/15/2016 Security Update for Adobe Flash Player for Windows 10 Version 1607 (for x64-based Systems) (KB3209498) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 12/15/2016 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB3206632) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 12/15/2016 Windows Malicious Software Removal Tool for Windows 8, 8.1, 10 and Windows Server 2012, 2012 R2, 2016 x64 Edition - December 2016 (KB890830) After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product. 12/10/2016 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB3201845) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 11/09/2016 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB3200970) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 11/09/2016 Security Update for Adobe Flash Player for Windows 10 Version 1607 (for x64-based Systems) (KB3202790) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 11/09/2016 Windows Malicious Software Removal Tool for Windows 8, 8.1, 10 and Windows Server 2012, 2012 R2, 2016 x64 Edition - November 2016 (KB890830) After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product. 11/02/2016 Intel Corporation driver update for Intel(R) HD Graphics 530 This driver was provided by Intel Corporation for support of Intel HD Graphics 530 10/31/2016 Security Update for Adobe Flash Player for Windows 10 Version 1607 (for x64-based Systems) (KB3201860) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 10/31/2016 Update for Windows 10 Version 1607 for x64-based Systems (KB3199986) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 10/31/2016 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB3197954) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 10/20/2016 Update for Windows 10 Version 1607 for x64-based Systems (KB3199209) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 10/14/2016 Security Update for Adobe Flash Player for Windows 10 Version 1607 (for x64-based Systems) (KB3194343) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 10/14/2016 Windows Malicious Software Removal Tool for Windows 8, 8.1, 10 and Windows Server 2012, 2012 R2 x64 Edition - October 2016 (KB890830) After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product. 10/14/2016 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB3194798) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 10/01/2016 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB3194496) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 10/01/2016 Update for Windows 10 Version 1607 for x64-based Systems (KB3176936) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 10/01/2016 Security Update for Adobe Flash Player for Windows 10 Version 1607 for x64-based Systems (KB3188128) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 09/30/2016 Feature update to Windows 10, version 1607 Install the anniversary version of Windows. 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 12/30/1899 Not Installed System Folders Application Data C:\ProgramData Cookies C:\Users\Zoe\AppData\Local\Microsoft\Windows\INetCookies Desktop C:\Users\Zoe\Desktop Documents C:\Users\Public\Documents Fonts C:\WINDOWS\Fonts Global Favorites C:\Users\Zoe\Favorites Internet History C:\Users\Zoe\AppData\Local\Microsoft\Windows\History Local Application Data C:\Users\Zoe\AppData\Local Music C:\Users\Public\Music Path for burning CD C:\Users\Zoe\AppData\Local\Microsoft\Windows\Burn\Burn Physical Desktop C:\Users\Zoe\Desktop Pictures C:\Users\Public\Pictures Program Files C:\Program Files Public Desktop C:\Users\Public\Desktop Start Menu C:\ProgramData\Microsoft\Windows\Start Menu Start Menu Programs C:\ProgramData\Microsoft\Windows\Start Menu\Programs Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Templates C:\ProgramData\Microsoft\Windows\Templates Temporary Internet Files C:\Users\Zoe\AppData\Local\Microsoft\Windows\Temporary Internet Files User Favorites C:\Users\Zoe\Favorites Videos C:\Users\Public\Videos Windows Directory C:\WINDOWS Windows/System C:\WINDOWS\system32 Process List AppleIEDAV.exe Process ID 8548 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe Memory Usage 14 MB Peak Memory Usage 15 MB AppleMobileDeviceService.exe Process ID 2772 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe Memory Usage 5.65 MB Peak Memory Usage 15 MB ApplePhotoStreams.exe Process ID 7452 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe Memory Usage 8.06 MB Peak Memory Usage 41 MB ApplicationFrameHost.exe Process ID 6016 User Zoe Domain ZOENEW Path C:\Windows\System32\ApplicationFrameHost.exe Memory Usage 15 MB Peak Memory Usage 25 MB APSDaemon.exe Process ID 9916 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe Memory Usage 6.55 MB Peak Memory Usage 18 MB audiodg.exe Process ID 12548 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\audiodg.exe Memory Usage 17 MB Peak Memory Usage 28 MB AutoHotkey.exe Process ID 12892 User Zoe Domain ZOENEW Path C:\Program Files\AutoHotkey\AutoHotkey.exe Memory Usage 8.81 MB Peak Memory Usage 9.77 MB avp.exe Process ID 2888 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe Memory Usage 166 MB Peak Memory Usage 776 MB avpui.exe Process ID 5024 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avpui.exe Memory Usage 3.98 MB Peak Memory Usage 118 MB chrome.exe Process ID 13292 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 76 MB Peak Memory Usage 97 MB chrome.exe Process ID 8328 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 154 MB Peak Memory Usage 255 MB chrome.exe Process ID 13036 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 52 MB Peak Memory Usage 121 MB chrome.exe Process ID 10332 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 203 MB Peak Memory Usage 875 MB chrome.exe Process ID 11692 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 52 MB Peak Memory Usage 54 MB chrome.exe Process ID 7776 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 2.31 MB Peak Memory Usage 11 MB chrome.exe Process ID 13160 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 31 MB Peak Memory Usage 61 MB chrome.exe Process ID 1484 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 352 MB Peak Memory Usage 718 MB chrome.exe Process ID 7832 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 2.31 MB Peak Memory Usage 12 MB chrome.exe Process ID 7716 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 322 MB Peak Memory Usage 542 MB chrome.exe Process ID 10556 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 107 MB Peak Memory Usage 200 MB chrome.exe Process ID 7924 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 140 MB Peak Memory Usage 277 MB chrome.exe Process ID 11456 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 54 MB Peak Memory Usage 88 MB chrome.exe Process ID 4932 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 124 MB Peak Memory Usage 155 MB chrome.exe Process ID 12316 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 307 MB Peak Memory Usage 467 MB chrome.exe Process ID 12624 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 180 MB Peak Memory Usage 248 MB chrome.exe Process ID 14600 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Memory Usage 174 MB Peak Memory Usage 200 MB cmd.exe Process ID 11612 User Zoe Domain ZOENEW Path C:\Windows\System32\cmd.exe Memory Usage 2.55 MB Peak Memory Usage 2.73 MB conhost.exe Process ID 792 User Zoe Domain ZOENEW Path C:\Windows\System32\conhost.exe Memory Usage 6.93 MB Peak Memory Usage 11 MB csrss.exe Process ID 680 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\csrss.exe Memory Usage 1.66 MB Peak Memory Usage 4.69 MB csrss.exe Process ID 788 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\csrss.exe Memory Usage 9.74 MB Peak Memory Usage 41 MB dasHost.exe Process ID 2536 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\dasHost.exe Memory Usage 8.82 MB Peak Memory Usage 17 MB DbxSvc.exe Process ID 2780 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\DbxSvc.exe Memory Usage 848 KB Peak Memory Usage 6.24 MB dllhost.exe Process ID 9788 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\dllhost.exe Memory Usage 5.63 MB Peak Memory Usage 5.63 MB dllhost.exe Process ID 2980 User Zoe Domain ZOENEW Path C:\Windows\System32\dllhost.exe Memory Usage 9.02 MB Peak Memory Usage 11 MB dllhost.exe Process ID 1200 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\dllhost.exe Memory Usage 6.01 MB Peak Memory Usage 6.01 MB Dropbox.exe Process ID 10372 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Dropbox\Client\Dropbox.exe Memory Usage 53 MB Peak Memory Usage 141 MB DropboxUpdate.exe Process ID 4912 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Memory Usage 1.76 MB Peak Memory Usage 9.20 MB ducservice.exe Process ID 972 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\No-IP\ducservice.exe Memory Usage 12 MB Peak Memory Usage 22 MB dwm.exe Process ID 1044 User DWM-1 Domain Window Manager Path C:\Windows\System32\dwm.exe Memory Usage 49 MB Peak Memory Usage 126 MB explorer.exe Process ID 5512 User Zoe Domain ZOENEW Path C:\Windows\explorer.exe Memory Usage 98 MB Peak Memory Usage 152 MB GoogleCrashHandler.exe Process ID 3244 User Zoe Domain ZOENEW Path C:\Users\Zoe\AppData\Local\Google\Update\1.3.32.7\GoogleCrashHandler.exe Memory Usage 1.13 MB Peak Memory Usage 6.48 MB GoogleCrashHandler.exe Process ID 7252 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe Memory Usage 1.27 MB Peak Memory Usage 6.53 MB GoogleCrashHandler64.exe Process ID 2388 User Zoe Domain ZOENEW Path C:\Users\Zoe\AppData\Local\Google\Update\1.3.32.7\GoogleCrashHandler64.exe Memory Usage 1.09 MB Peak Memory Usage 5.97 MB GoogleCrashHandler64.exe Process ID 7260 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe Memory Usage 996 KB Peak Memory Usage 5.94 MB IAStorDataMgrSvc.exe Process ID 1628 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Intel\Intel Rapid Storage Technology\IAStorDataMgrSvc.exe Memory Usage 13 MB Peak Memory Usage 52 MB IAStorIcon.exe Process ID 2976 User Zoe Domain ZOENEW Path C:\Program Files\Intel\Intel Rapid Storage Technology\IAStorIcon.exe Memory Usage 3.29 MB Peak Memory Usage 41 MB iCloudDrive.exe Process ID 10188 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe Memory Usage 6.27 MB Peak Memory Usage 36 MB iCloudServices.exe Process ID 9752 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe Memory Usage 33 MB Peak Memory Usage 103 MB ID.exe Process ID 11228 User Zoe Domain ZOENEW Path C:\Users\Zoe\Desktop\AHK\ID.exe Memory Usage 3.99 MB Peak Memory Usage 10 MB igfxCUIService.exe Process ID 1560 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0745f11ce6fc197c\igfxCUIService.exe Memory Usage 956 KB Peak Memory Usage 8.20 MB igfxEM.exe Process ID 5760 User Zoe Domain ZOENEW Path C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0745f11ce6fc197c\igfxEM.exe Memory Usage 1.87 MB Peak Memory Usage 13 MB iPodService.exe Process ID 9428 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\iPod\bin\iPodService.exe Memory Usage 1.87 MB Peak Memory Usage 8.32 MB ipoint.exe Process ID 4920 User Zoe Domain ZOENEW Path C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe Memory Usage 3.65 MB Peak Memory Usage 15 MB iTunesHelper.exe Process ID 8896 User Zoe Domain ZOENEW Path C:\Program Files\iTunes\iTunesHelper.exe Memory Usage 3.34 MB Peak Memory Usage 17 MB itype.exe Process ID 4828 User Zoe Domain ZOENEW Path C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe Memory Usage 3.75 MB Peak Memory Usage 16 MB jusched.exe Process ID 10628 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe Memory Usage 1.28 MB Peak Memory Usage 7.22 MB kpm.exe Process ID 9232 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 8.0.5\kpm.exe Memory Usage 76 MB Peak Memory Usage 100 MB ksde.exe Process ID 11108 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe Memory Usage 1.56 MB Peak Memory Usage 25 MB ksdeui.exe Process ID 8404 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksdeui.exe Memory Usage 3.55 MB Peak Memory Usage 16 MB lsass.exe Process ID 864 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\lsass.exe Memory Usage 11 MB Peak Memory Usage 20 MB mDNSResponder.exe Process ID 2996 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Bonjour\mDNSResponder.exe Memory Usage 2.62 MB Peak Memory Usage 6.52 MB Memory Compression Process ID 2612 User SYSTEM Domain NT AUTHORITY Memory Usage 432 MB Peak Memory Usage 610 MB Microsoft.Photos.exe Process ID 4988 User Zoe Domain ZOENEW Path C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe Memory Usage 173 MB Peak Memory Usage 209 MB notepad.exe Process ID 7120 User Zoe Domain ZOENEW Path C:\Windows\SysWOW64\notepad.exe Memory Usage 37 MB Peak Memory Usage 44 MB OfficeClickToRun.exe Process ID 2876 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe Memory Usage 17 MB Peak Memory Usage 73 MB OneDrive.exe Process ID 8344 User Zoe Domain ZOENEW Path C:\Users\Zoe\AppData\Local\Microsoft\OneDrive\OneDrive.exe Memory Usage 9.98 MB Peak Memory Usage 30 MB OUTLOOK.EXE Process ID 13220 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Memory Usage 127 MB Peak Memory Usage 173 MB plugin-nm-server.exe Process ID 3824 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 8.0.5\plugin-nm-server.exe Memory Usage 16 MB Peak Memory Usage 42 MB PresentationFontCache.exe Process ID 5092 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe Memory Usage 1.52 MB Peak Memory Usage 19 MB pushbullet_client.exe Process ID 12352 User Zoe Domain ZOENEW Path C:\Users\Zoe\AppData\Local\Pushbullet\bin\pushbullet_client.exe Memory Usage 30 MB Peak Memory Usage 107 MB RuntimeBroker.exe Process ID 5376 User Zoe Domain ZOENEW Path C:\Windows\System32\RuntimeBroker.exe Memory Usage 53 MB Peak Memory Usage 72 MB Samsung Magician.exe Process ID 6248 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe Memory Usage 6.06 MB Peak Memory Usage 43 MB SamsungRapidApp.exe Process ID 8716 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe Memory Usage 848 KB Peak Memory Usage 4.70 MB SamsungRapidSvc.exe Process ID 2844 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\RAPID\SamsungRapidSvc.exe Memory Usage 520 KB Peak Memory Usage 3.02 MB SearchIndexer.exe Process ID 1540 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\SearchIndexer.exe Memory Usage 55 MB Peak Memory Usage 136 MB SearchProtocolHost.exe Process ID 15072 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\SearchProtocolHost.exe Memory Usage 12 MB Peak Memory Usage 12 MB SearchUI.exe Process ID 12280 User Zoe Domain ZOENEW Path C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe Memory Usage 145 MB Peak Memory Usage 180 MB secd.exe Process ID 6928 User Zoe Domain ZOENEW Path C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe Memory Usage 2.18 MB Peak Memory Usage 18 MB services.exe Process ID 856 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\services.exe Memory Usage 5.02 MB Peak Memory Usage 11 MB SettingSyncHost.exe Process ID 7588 User Zoe Domain ZOENEW Path C:\Windows\System32\SettingSyncHost.exe Memory Usage 9.39 MB Peak Memory Usage 51 MB ShellExperienceHost.exe Process ID 6152 User Zoe Domain ZOENEW Path C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Memory Usage 96 MB Peak Memory Usage 99 MB sihost.exe Process ID 5032 User Zoe Domain ZOENEW Path C:\Windows\System32\sihost.exe Memory Usage 21 MB Peak Memory Usage 24 MB SkypeHost.exe Process ID 6768 User Zoe Domain ZOENEW Path C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe Memory Usage 29 MB Peak Memory Usage 81 MB smartscreen.exe Process ID 8096 User Zoe Domain ZOENEW Path C:\Windows\System32\smartscreen.exe Memory Usage 24 MB Peak Memory Usage 27 MB smss.exe Process ID 500 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\smss.exe Memory Usage 376 KB Peak Memory Usage 1.21 MB Speccy64.exe Process ID 15000 User Zoe Domain ZOENEW Path C:\Program Files\Speccy\Speccy64.exe Memory Usage 25 MB Peak Memory Usage 25 MB spoolsv.exe Process ID 1932 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\spoolsv.exe Memory Usage 14 MB Peak Memory Usage 23 MB svchost.exe Process ID 1068 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 15 MB Peak Memory Usage 61 MB svchost.exe Process ID 1152 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 45 MB Peak Memory Usage 273 MB svchost.exe Process ID 1164 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 13 MB Peak Memory Usage 31 MB svchost.exe Process ID 1440 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 20 MB Peak Memory Usage 150 MB svchost.exe Process ID 3632 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 7.12 MB Peak Memory Usage 7.12 MB svchost.exe Process ID 1724 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.67 MB Peak Memory Usage 10 MB svchost.exe Process ID 1804 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.11 MB Peak Memory Usage 7.18 MB svchost.exe Process ID 2232 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.38 MB Peak Memory Usage 12 MB svchost.exe Process ID 2836 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 16 MB Peak Memory Usage 25 MB svchost.exe Process ID 2964 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 14 MB Peak Memory Usage 21 MB svchost.exe Process ID 5040 User Zoe Domain ZOENEW Path C:\Windows\System32\svchost.exe Memory Usage 19 MB Peak Memory Usage 33 MB svchost.exe Process ID 6388 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.06 MB Peak Memory Usage 7.28 MB svchost.exe Process ID 2924 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 9.48 MB Peak Memory Usage 14 MB svchost.exe Process ID 7348 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 7.31 MB Peak Memory Usage 7.33 MB svchost.exe Process ID 1344 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 19 MB Peak Memory Usage 37 MB svchost.exe Process ID 9944 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 6.80 MB Peak Memory Usage 6.85 MB svchost.exe Process ID 964 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 14 MB Peak Memory Usage 24 MB svchost.exe Process ID 712 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 9.45 MB Peak Memory Usage 11 MB svchost.exe Process ID 1056 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 15 MB Peak Memory Usage 22 MB synergyd.exe Process ID 3032 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Synergy\synergyd.exe Memory Usage 1.17 MB Peak Memory Usage 6.02 MB System Process ID 4 Memory Usage 6.39 MB Peak Memory Usage 26 MB System Idle Process Process ID 0 SystemSettings.exe Process ID 5068 User Zoe Domain ZOENEW Path C:\Windows\ImmersiveControlPanel\SystemSettings.exe Memory Usage 444 KB Peak Memory Usage 51 MB taskhostw.exe Process ID 4960 User Zoe Domain ZOENEW Path C:\Windows\System32\taskhostw.exe Memory Usage 14 MB Peak Memory Usage 25 MB TeamViewer.exe Process ID 5580 User Zoe Domain ZOENEW Path C:\Program Files (x86)\TeamViewer\TeamViewer.exe Memory Usage 17 MB Peak Memory Usage 38 MB TeamViewer_Service.exe Process ID 3040 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe Memory Usage 7.60 MB Peak Memory Usage 29 MB tv_w32.exe Process ID 6000 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\TeamViewer\tv_w32.exe Memory Usage 1.32 MB Peak Memory Usage 7.08 MB tv_x64.exe Process ID 6072 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\TeamViewer\tv_x64.exe Memory Usage 1.02 MB Peak Memory Usage 6.93 MB Updater.exe Process ID 3016 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Popcorn Time\Updater.exe Memory Usage 4.97 MB Peak Memory Usage 12 MB vivaldi.exe Process ID 2424 User Zoe Domain ZOENEW Path C:\Users\Zoe\AppData\Local\Vivaldi\Application\vivaldi.exe Memory Usage 119 MB Peak Memory Usage 146 MB vivaldi.exe Process ID 12236 User Zoe Domain ZOENEW Path C:\Users\Zoe\AppData\Local\Vivaldi\Application\vivaldi.exe Memory Usage 6.51 MB Peak Memory Usage 7.05 MB vivaldi.exe Process ID 11688 User Zoe Domain ZOENEW Path C:\Users\Zoe\AppData\Local\Vivaldi\Application\vivaldi.exe Memory Usage 71 MB Peak Memory Usage 102 MB vivaldi.exe Process ID 1420 User Zoe Domain ZOENEW Path C:\Users\Zoe\AppData\Local\Vivaldi\Application\vivaldi.exe Memory Usage 48 MB Peak Memory Usage 65 MB vivaldi.exe Process ID 13716 User Zoe Domain ZOENEW Path C:\Users\Zoe\AppData\Local\Vivaldi\Application\vivaldi.exe Memory Usage 33 MB Peak Memory Usage 36 MB vivaldi.exe Process ID 4220 User Zoe Domain ZOENEW Path C:\Users\Zoe\AppData\Local\Vivaldi\Application\vivaldi.exe Memory Usage 80 MB Peak Memory Usage 99 MB vivaldi.exe Process ID 11860 User Zoe Domain ZOENEW Path C:\Users\Zoe\AppData\Local\Vivaldi\Application\vivaldi.exe Memory Usage 128 MB Peak Memory Usage 235 MB vivaldi.exe Process ID 4300 User Zoe Domain ZOENEW Path C:\Users\Zoe\AppData\Local\Vivaldi\Application\vivaldi.exe Memory Usage 597 MB Peak Memory Usage 706 MB vivaldi.exe Process ID 8268 User Zoe Domain ZOENEW Path C:\Users\Zoe\AppData\Local\Vivaldi\Application\vivaldi.exe Memory Usage 64 MB Peak Memory Usage 77 MB vncagent.exe Process ID 3468 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\RealVNC\VNC Server\vncagent.exe Memory Usage 5.88 MB Peak Memory Usage 50 MB vncserver.exe Process ID 3024 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\RealVNC\VNC Server\vncserver.exe Memory Usage 31 MB Peak Memory Usage 55 MB vncserverui.exe Process ID 6092 User Zoe Domain ZOENEW Path C:\Program Files\RealVNC\VNC Server\vncserverui.exe Memory Usage 10 MB Peak Memory Usage 19 MB wininit.exe Process ID 780 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\wininit.exe Memory Usage 744 KB Peak Memory Usage 5.29 MB winlogon.exe Process ID 368 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\winlogon.exe Memory Usage 992 KB Peak Memory Usage 29 MB WmiPrvSE.exe Process ID 4044 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\wbem\WmiPrvSE.exe Memory Usage 18 MB Peak Memory Usage 33 MB WmiPrvSE.exe Process ID 6464 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\wbem\WmiPrvSE.exe Memory Usage 8.41 MB Peak Memory Usage 8.41 MB WUDFHost.exe Process ID 2484 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\WUDFHost.exe Memory Usage 1.17 MB Peak Memory Usage 10 MB Security Options Accounts: Administrator account status Disabled Accounts: Block Microsoft accounts Not Defined Accounts: Guest account status Disabled Accounts: Limit local account use of blank passwords to console logon only Enabled Accounts: Rename administrator account Administrator Accounts: Rename guest account Guest Audit: Audit the access of global system objects Disabled Audit: Audit the use of Backup and Restore privilege Enabled Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings Not Defined Audit: Shut down system immediately if unable to log security audits Disabled DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax Not Defined DCOM: Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) syntax Not Defined Devices: Allow undock without having to log on Enabled Devices: Allowed to format and eject removable media Not Defined Devices: Prevent users from installing printer drivers Disabled Devices: Restrict CD-ROM access to locally logged-on user only Not Defined Devices: Restrict floppy access to locally logged-on user only Not Defined Domain controller: Allow server operators to schedule tasks Not Defined Domain controller: LDAP server signing requirements Not Defined Domain controller: Refuse machine account password changes Not Defined Domain member: Digitally encrypt or sign secure channel data (always) Enabled Domain member: Digitally encrypt secure channel data (when possible) Enabled Domain member: Digitally sign secure channel data (when possible) Enabled Domain member: Disable machine account password changes Disabled Domain member: Maximum machine account password age 30 days Domain member: Require strong (Windows 2000 or later) session key Enabled Interactive logon: Display user information when the session is locked Not Defined Interactive logon: Do not display last user name Disabled Interactive logon: Do not require CTRL+ALT+DEL Not Defined Interactive logon: Machine account lockout threshold Not Defined Interactive logon: Machine inactivity limit Not Defined Interactive logon: Message text for users attempting to log on Interactive logon: Message title for users attempting to log on Interactive logon: Number of previous logons to cache (in case domain controller is not available) 10 logons Interactive logon: Prompt user to change password before expiration 5 days Interactive logon: Require Domain Controller authentication to unlock workstation Disabled Interactive logon: Require smart card Disabled Interactive logon: Smart card removal behavior No Action Microsoft network client: Digitally sign communications (always) Disabled Microsoft network client: Digitally sign communications (if server agrees) Enabled Microsoft network client: Send unencrypted password to third-party SMB servers Disabled Microsoft network server: Amount of idle time required before suspending session Not Defined Microsoft network server: Attempt S4U2Self to obtain claim information Not Defined Microsoft network server: Digitally sign communications (always) Disabled Microsoft network server: Digitally sign communications (if client agrees) Disabled Microsoft network server: Disconnect clients when logon hours expire Enabled Microsoft network server: Server SPN target name validation level Not Defined Network access: Allow anonymous SID/Name translation Disabled Network access: Do not allow anonymous enumeration of SAM accounts Enabled Network access: Do not allow anonymous enumeration of SAM accounts and shares Disabled Network access: Do not allow storage of passwords and credentials for network authentication Disabled Network access: Let Everyone permissions apply to anonymous users Disabled Network access: Named Pipes that can be accessed anonymously Network access: Remotely accessible registry paths System\CurrentControlSet\Control\ProductOptions,System\CurrentControlSet\Control\Server Applications,Software\Microsoft\Windows NT\CurrentVersion Network access: Remotely accessible registry paths and sub-paths System\CurrentControlSet\Control\Print\Printers,System\CurrentControlSet\Services\Eventlog,Software\Microsoft\OLAP Server,Software\Microsoft\Windows NT\CurrentVersion\Print,Software\Microsoft\Windows NT\CurrentVersion\Windows,System\CurrentControlSet\Control\ContentIndex,System\CurrentControlSet\Control\Terminal Server,System\CurrentControlSet\Control\Terminal Server\UserConfig,System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration,Software\Microsoft\Windows NT\CurrentVersion\Perflib,System\CurrentControlSet\Services\SysmonLog Network access: Restrict anonymous access to Named Pipes and Shares Enabled Network access: Restrict clients allowed to make remote calls to SAM Network access: Shares that can be accessed anonymously Not Defined Network access: Sharing and security model for local accounts Classic - local users authenticate as themselves Network security: Allow Local System to use computer identity for NTLM Not Defined Network security: Allow LocalSystem NULL session fallback Not Defined Network security: Allow PKU2U authentication requests to this computer to use online identities. Not Defined Network security: Configure encryption types allowed for Kerberos Not Defined Network security: Do not store LAN Manager hash value on next password change Enabled Network security: Force logoff when logon hours expire Disabled Network security: LAN Manager authentication level Not Defined Network security: LDAP client signing requirements Negotiate signing Network security: Minimum session security for NTLM SSP based (including secure RPC) clients Require 128-bit encryption Network security: Minimum session security for NTLM SSP based (including secure RPC) servers Require 128-bit encryption Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication Not Defined Network security: Restrict NTLM: Add server exceptions in this domain Not Defined Network security: Restrict NTLM: Audit Incoming NTLM Traffic Not Defined Network security: Restrict NTLM: Audit NTLM authentication in this domain Not Defined Network security: Restrict NTLM: Incoming NTLM traffic Not Defined Network security: Restrict NTLM: NTLM authentication in this domain Not Defined Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers Not Defined Recovery console: Allow automatic administrative logon Not Defined Recovery console: Allow floppy copy and access to all drives and all folders Not Defined Shutdown: Allow system to be shut down without having to log on Enabled Shutdown: Clear virtual memory pagefile Disabled System cryptography: Force strong key protection for user keys stored on the computer Not Defined System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing Disabled System objects: Require case insensitivity for non-Windows subsystems Enabled System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links) Enabled System settings: Optional subsystems System settings: Use Certificate Rules on Windows Executables for Software Restriction Policies Disabled User Account Control: Admin Approval Mode for the Built-in Administrator account Not Defined User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop Disabled User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode Elevate without prompting User Account Control: Behavior of the elevation prompt for standard users Prompt for credentials User Account Control: Detect application installations and prompt for elevation Enabled User Account Control: Only elevate executables that are signed and validated Disabled User Account Control: Only elevate UIAccess applications that are installed in secure locations Enabled User Account Control: Run all administrators in Admin Approval Mode Enabled User Account Control: Switch to the secure desktop when prompting for elevation Disabled User Account Control: Virtualize file and registry write failures to per-user locations Enabled Device Tree ACPI x64-based PC Microsoft ACPI-Compliant System ACPI Fan ACPI Fan ACPI Fan ACPI Fan ACPI Fan ACPI Fixed Feature Button ACPI Power Button ACPI Processor Aggregator ACPI Sleep Button ACPI Thermal Zone ACPI Thermal Zone Intel Core i5-6500 CPU @ 3.20GHz Intel Core i5-6500 CPU @ 3.20GHz Intel Core i5-6500 CPU @ 3.20GHz Intel Core i5-6500 CPU @ 3.20GHz Intel Extreme Tuning Utility Device Driver Intel Power Engine Plug-in Microsoft Windows Management Interface for ACPI Motherboard resources PCI Express Root Complex Intel 100 Series/C230 Series Chipset Family PCI Express Root Port #13 - A11C Intel 100 Series/C230 Series Chipset Family PCI Express Root Port #5 - A114 Intel 100 Series/C230 Series Chipset Family PCI Express Root Port #9 - A118 Intel 100 Series/C230 Series Chipset Family PCI Root Port #17 - A167 Intel 100 Series/C230 Series Chipset Family PMC - A121 Intel 100 Series/C230 Series Chipset Family SMBus - A123 Intel 100 Series/C230 Series Chipset Family Thermal subsystem - A131 Intel Management Engine Interface Microsoft Windows Management Interface for ACPI Motherboard resources Motherboard resources Motherboard resources PCI standard host CPU bridge Intel(R) HD Graphics 530 Generic PnP Monitor HP 25e Display HP w19b/w19e Wide LCD Monitor Intel(R) USB 3.0 eXtensible Host Controller - 1.0 (Microsoft) USB Root Hub (xHCI) USB Input Device HID-compliant mouse USB Input Device HID Keyboard Device USB Composite Device Brother Scanner c1 MFC-L2700DW USB Printing Support Brother Laser Type1 Class Driver Brother MFC-L2700DW series Intel(R) 100 Series/C230 Chipset Family SATA AHCI Controller ASUS DRW-24B1ST j Samsung SSD 750 EVO 250GB WDC WD10EZEX-00WN4A0 Intel(R) 100 Series/C230 Series Chipset Family PCI Root Port #19 - A169 PCI-to-PCI Bridge Intel(R) 100 Series/C230 Series Chipset Family PCI Express Root Port #1 - A110 ASMedia USB 3.1 eXtensible Host Controller - 1.10 (Microsoft) USB Root Hub (xHCI) Intel(R) 100 Series/C230 Series Chipset Family PCI Express Root Port #4 - A113 Realtek PCIe GBE Family Controller #2 Intel(R) 100 Series/C230 Series Chipset Family LPC Controller - A145 Communications Port (COM1) High precision event timer Legacy device Motherboard resources Motherboard resources Motherboard resources Motherboard resources Numeric data processor Programmable interrupt controller System CMOS/real time clock System timer Printer Port (LPT1) Printer Port Logical Interface High Definition Audio Controller Realtek High Definition Audio Microphone (Realtek High Definition Audio) Realtek Digital Output (Realtek High Definition Audio) Speakers (Realtek High Definition Audio) Intel(R) Display Audio HP 25es (Intel Display Audio) HP w19b/w19e (Intel Display Audio) CPU Intel Core i5 6500 Cores 4 Threads 4 Name Intel Core i5 6500 Code Name Skylake Package Socket 1151 LGA Technology 14nm Specification Intel Core i5-6500 CPU @ 3.20GHz Family 6 Extended Family 6 Model E Extended Model 5E Stepping 3 Revision R0 Instructions MMX, SSE, SSE2, SSE3, SSSE3, SSE4.1, SSE4.2, Intel 64, NX, VMX, AES, AVX, AVX2, FMA3 Virtualization Supported, Enabled Hyperthreading Not supported Fan Speed 1674 RPM Stock Core Speed 3200 MHz Stock Bus Speed 100 MHz Average Temperature 37 °C Caches L1 Data Cache Size 4 x 32 KBytes L1 Instructions Cache Size 4 x 32 KBytes L2 Unified Cache Size 4 x 256 KBytes L3 Unified Cache Size 6144 KBytes Cores Core 0 Core Speed 3400.8 MHz Multiplier x 34.0 Temperature 36 °C Threads APIC ID: 0 Core 1 Core Speed 3300.8 MHz Multiplier x 33.0 Temperature 41 °C Threads APIC ID: 2 Core 2 Core Speed 3300.8 MHz Multiplier x 33.0 Temperature 34 °C Threads APIC ID: 4 Core 3 Core Speed 3500.8 MHz Multiplier x 35.0 Temperature 35 °C Threads APIC ID: 6 RAM Memory slots Total memory slots 4 Used memory slots 2 Free memory slots 2 Memory Type Unknown Size 16384 MBytes Channels # Dual CAS# Latency (CL) 15 clocks RAS# to CAS# Delay (tRCD) 15 clocks RAS# Precharge (tRP) 15 clocks Cycle Time (tRAS) 35 clocks Command Rate (CR) 2T Physical Memory Memory Usage 49 % Total Physical 16 GB Available Physical 8.04 GB Total Virtual 17 GB Available Virtual 7.51 GB SPD Number Of SPD Modules 2 Slot #1 Type Unknown Size 8192 MBytes Manufacturer G.Skill Max Bandwidth DDR4-2132 (1066 MHz) Part Number F4-2400C15-8GVR SPD Ext. XMP Timing table JEDEC #1 Frequency 666.7 MHz CAS# Latency 9.0 RAS# To CAS# 9 RAS# Precharge 9 tRAS 22 tRC 31 Voltage 1.200 V JEDEC #2 Frequency 814.8 MHz CAS# Latency 11.0 RAS# To CAS# 11 RAS# Precharge 11 tRAS 27 tRC 38 Voltage 1.200 V JEDEC #3 Frequency 888.9 MHz CAS# Latency 12.0 RAS# To CAS# 12 RAS# Precharge 12 tRAS 29 tRC 42 Voltage 1.200 V JEDEC #4 Frequency 963.0 MHz CAS# Latency 13.0 RAS# To CAS# 13 RAS# Precharge 13 tRAS 31 tRC 45 Voltage 1.200 V JEDEC #5 Frequency 1037.0 MHz CAS# Latency 14.0 RAS# To CAS# 14 RAS# Precharge 14 tRAS 34 tRC 49 Voltage 1.200 V JEDEC #6 Frequency 1066.1 MHz CAS# Latency 15.0 RAS# To CAS# 15 RAS# Precharge 15 tRAS 35 tRC 50 Voltage 1.200 V JEDEC #7 Frequency 1066.1 MHz CAS# Latency 16.0 RAS# To CAS# 15 RAS# Precharge 15 tRAS 35 tRC 50 Voltage 1.200 V JEDEC #8 Frequency 1066.1 MHz CAS# Latency 18.0 RAS# To CAS# 15 RAS# Precharge 15 tRAS 35 tRC 50 Voltage 1.200 V JEDEC #9 Frequency 1066.1 MHz CAS# Latency 19.0 RAS# To CAS# 15 RAS# Precharge 15 tRAS 35 tRC 50 Voltage 1.200 V XMP-2400 Frequency 1200 MHz CAS# Latency 15.0 RAS# To CAS# 15 RAS# Precharge 15 tRAS 35 Voltage 1.200 V Slot #2 Type Unknown Size 8192 MBytes Manufacturer G.Skill Max Bandwidth DDR4-2132 (1066 MHz) Part Number F4-2400C15-8GVR SPD Ext. XMP Timing table JEDEC #1 Frequency 666.7 MHz CAS# Latency 9.0 RAS# To CAS# 9 RAS# Precharge 9 tRAS 22 tRC 31 Voltage 1.200 V JEDEC #2 Frequency 814.8 MHz CAS# Latency 11.0 RAS# To CAS# 11 RAS# Precharge 11 tRAS 27 tRC 38 Voltage 1.200 V JEDEC #3 Frequency 888.9 MHz CAS# Latency 12.0 RAS# To CAS# 12 RAS# Precharge 12 tRAS 29 tRC 42 Voltage 1.200 V JEDEC #4 Frequency 963.0 MHz CAS# Latency 13.0 RAS# To CAS# 13 RAS# Precharge 13 tRAS 31 tRC 45 Voltage 1.200 V JEDEC #5 Frequency 1037.0 MHz CAS# Latency 14.0 RAS# To CAS# 14 RAS# Precharge 14 tRAS 34 tRC 49 Voltage 1.200 V JEDEC #6 Frequency 1066.1 MHz CAS# Latency 15.0 RAS# To CAS# 15 RAS# Precharge 15 tRAS 35 tRC 50 Voltage 1.200 V JEDEC #7 Frequency 1066.1 MHz CAS# Latency 16.0 RAS# To CAS# 15 RAS# Precharge 15 tRAS 35 tRC 50 Voltage 1.200 V JEDEC #8 Frequency 1066.1 MHz CAS# Latency 18.0 RAS# To CAS# 15 RAS# Precharge 15 tRAS 35 tRC 50 Voltage 1.200 V JEDEC #9 Frequency 1066.1 MHz CAS# Latency 19.0 RAS# To CAS# 15 RAS# Precharge 15 tRAS 35 tRC 50 Voltage 1.200 V XMP-2400 Frequency 1200 MHz CAS# Latency 15.0 RAS# To CAS# 15 RAS# Precharge 15 tRAS 35 Voltage 1.200 V Motherboard Manufacturer Gigabyte Technology Co. Ltd. Model Z170-HD3P-CF (U3E1) Version x.x Chipset Vendor Intel Chipset Model Skylake Chipset Revision 07 Southbridge Vendor Intel Southbridge Model Z170 Southbridge Revision 31 System Temperature 41 °C BIOS Brand American Megatrends Inc. Version F5 Date 03/07/2016 Voltage CPU CORE 0.492 V +12V 12.096 V +5V 5.010 V CPU TERMINATION 1.068 V DRAM 1.236 V +3.3V 3.360 V VIN8 1.560 V PCI Data Slot PCI-E Slot Type PCI-E Slot Usage In Use Data lanes x16 Slot Designation J6B2 Characteristics 3.3V, Shared, PME Slot Number 0 Slot PCI-E Slot Type PCI-E Slot Usage In Use Data lanes x1 Slot Designation J6B1 Characteristics 3.3V, Shared, PME Slot Number 1 Slot PCI-E Slot Type PCI-E Slot Usage In Use Data lanes x1 Slot Designation J6D1 Characteristics 3.3V, Shared, PME Slot Number 2 Slot PCI-E Slot Type PCI-E Slot Usage In Use Data lanes x1 Slot Designation J7B1 Characteristics 3.3V, Shared, PME Slot Number 3 Slot PCI-E Slot Type PCI-E Slot Usage In Use Data lanes x1 Slot Designation J8B4 Characteristics 3.3V, Shared, PME Slot Number 4 Graphics Monitor 1 Name S200HQL on Intel HD Graphics 530 Current Resolution 1600x900 pixels Work Resolution 1600x870 pixels State Enabled Multiple displays Extended, Secondary, Enabled Monitor Width 1600 Monitor Height 900 Monitor BPP 32 bits per pixel Monitor Frequency 60 Hz Device \\.\DISPLAY1\Monitor0 Monitor 2 Name HP 25es on Intel HD Graphics 530 Current Resolution 1920x1080 pixels Work Resolution 1920x1050 pixels State Enabled Multiple displays Extended, Primary, Enabled Monitor Width 1920 Monitor Height 1080 Monitor BPP 32 bits per pixel Monitor Frequency 59 Hz Device \\.\DISPLAY2\Monitor0 Monitor 3 Name HP w19b/w19e on Intel HD Graphics 530 Current Resolution 1440x900 pixels Work Resolution 1440x870 pixels State Enabled Multiple displays Extended, Secondary, Enabled Monitor Width 1440 Monitor Height 900 Monitor BPP 32 bits per pixel Monitor Frequency 60 Hz Device \\.\DISPLAY3\Monitor0 Intel HD Graphics 530 Manufacturer Intel Model HD Graphics 530 Device ID 8086-1912 Revision 7 Subvendor Gigabyte (1458) Current Performance Level Level 0 Current GPU Clock 0 MHz Driver version 21.20.16.4534 Count of performance levels : 1 Level 1 - "Perf Level 0" Storage Hard drives Samsung SSD 750 EVO 250GB Manufacturer SAMSUNG Heads 16 Cylinders 30,401 Tracks 7,752,255 Sectors 488,392,065 SATA type SATA-III 6.0Gb/s Device type Fixed ATA Standard ACS2 Serial Number S33SNB0H525966N Firmware Version Number MAT01B6Q LBA Size 48-bit LBA Power On Count 14 times Power On Time 173.3 days Speed Not used (SSD Drive) Features S.M.A.R.T., NCQ, TRIM, SSD Max. Transfer Mode SATA III 6.0Gb/s Used Transfer Mode SATA III 6.0Gb/s Interface SATA Capacity 232 GB Real size 250,059,350,016 bytes RAID Type None S.M.A.R.T Status Good Temperature 37 °C Temperature Range OK (less than 50 °C) S.M.A.R.T attributes 05 Attribute name Reallocated Sectors Count Real value 0 Current 100 Worst 100 Threshold 10 Raw Value 0000000000 Status Good 09 Attribute name Power-On Hours (POH) Real value 173d 8h Current 99 Worst 99 Threshold 0 Raw Value 0000001040 Status Good 0C Attribute name Device Power Cycle Count Real value 14 Current 99 Worst 99 Threshold 0 Raw Value 000000000E Status Good B1 Attribute name Wear Leveling Count Real value 13 Current 97 Worst 97 Threshold 0 Raw Value 000000000D Status Good B3 Attribute name Used Reserved Block Count (Total) Real value 0 Current 100 Worst 100 Threshold 10 Raw Value 0000000000 Status Good B5 Attribute name Program Fail Count (Total) Real value 0 Current 100 Worst 100 Threshold 10 Raw Value 0000000000 Status Good B6 Attribute name Erase Fail Count (Total) Real value 0 Current 100 Worst 100 Threshold 10 Raw Value 0000000000 Status Good B7 Attribute name Runtime Bad Block (Total) Real value 0 Current 100 Worst 100 Threshold 10 Raw Value 0000000000 Status Good BB Attribute name Uncorrectable Error Count Real value 0 Current 100 Worst 100 Threshold 0 Raw Value 0000000000 Status Good BE Attribute name Temperature Exceed Count Real value 37 Current 63 Worst 55 Threshold 0 Raw Value 0000000025 Status Good C3 Attribute name ECC Rate Real value 0 Current 200 Worst 200 Threshold 0 Raw Value 0000000000 Status Good C7 Attribute name CRC Error Count Real value 0 Current 100 Worst 100 Threshold 0 Raw Value 0000000000 Status Good EB Attribute name Power Recovery Count Real value 3 Current 99 Worst 99 Threshold 0 Raw Value 0000000003 Status Good F1 Attribute name Total LBAs Written Real value 6,339,153,078 Current 99 Worst 99 Threshold 0 Raw Value 0079D7CCB6 Status Good Partition 0 Partition ID Disk #0, Partition #0 File System NTFS Volume Serial Number 9A90502A Size 499 MB Used Space 354 MB (70%) Free Space 145 MB (30%) Partition 1 Partition ID Disk #0, Partition #1 Disk Letter C: File System NTFS Volume Serial Number 08933EC4 Size 232 GB Used Space 74 GB (32%) Free Space 157 GB (68%) WDC WD10EZEX-00WN4A0 Manufacturer Western Digital Heads 16 Cylinders 121,601 Tracks 31,008,255 Sectors 1,953,520,065 SATA type SATA-III 6.0Gb/s Device type Fixed ATA Standard ACS3 Serial Number WD-WCC6Y3UHKX7S Firmware Version Number 01.01A01 LBA Size 48-bit LBA Power On Count 4 times Power On Time 66.5 days Speed 7200 RPM Features S.M.A.R.T., NCQ Max. Transfer Mode SATA III 6.0Gb/s Used Transfer Mode SATA III 6.0Gb/s Interface SATA Capacity 931 GB Real size 1,000,204,886,016 bytes RAID Type None S.M.A.R.T Status Good Temperature 38 °C Temperature Range OK (less than 50 °C) S.M.A.R.T attributes 01 Attribute name Read Error Rate Real value 0 Current 200 Worst 200 Threshold 51 Raw Value 0000000000 Status Good 03 Attribute name Spin-Up Time Real value 0 ms Current 100 Worst 253 Threshold 21 Raw Value 0000000000 Status Good 04 Attribute name Start/Stop Count Real value 4 Current 100 Worst 100 Threshold 0 Raw Value 0000000004 Status Good 05 Attribute name Reallocated Sectors Count Real value 0 Current 200 Worst 200 Threshold 140 Raw Value 0000000000 Status Good 07 Attribute name Seek Error Rate Real value 0 Current 200 Worst 200 Threshold 0 Raw Value 0000000000 Status Good 09 Attribute name Power-On Hours (POH) Real value 66d 13h Current 98 Worst 98 Threshold 0 Raw Value 000000063D Status Good 0A Attribute name Spin Retry Count Real value 0 Current 100 Worst 253 Threshold 0 Raw Value 0000000000 Status Good 0B Attribute name Recalibration Retries Real value 0 Current 100 Worst 253 Threshold 0 Raw Value 0000000000 Status Good 0C Attribute name Device Power Cycle Count Real value 4 Current 100 Worst 100 Threshold 0 Raw Value 0000000004 Status Good C0 Attribute name Power-off Retract Count Real value 0 Current 200 Worst 200 Threshold 0 Raw Value 0000000000 Status Good C1 Attribute name Load/Unload Cycle Count Real value 1,149 Current 200 Worst 200 Threshold 0 Raw Value 000000047D Status Good C2 Attribute name Temperature Real value 38 °C Current 105 Worst 103 Threshold 0 Raw Value 0000000026 Status Good C4 Attribute name Reallocation Event Count Real value 0 Current 200 Worst 200 Threshold 0 Raw Value 0000000000 Status Good C5 Attribute name Current Pending Sector Count Real value 0 Current 200 Worst 200 Threshold 0 Raw Value 0000000000 Status Good C6 Attribute name Uncorrectable Sector Count Real value 0 Current 100 Worst 253 Threshold 0 Raw Value 0000000000 Status Good C7 Attribute name UltraDMA CRC Error Count Real value 0 Current 200 Worst 200 Threshold 0 Raw Value 0000000000 Status Good C8 Attribute name Write Error Rate / Multi-Zone Error Rate Real value 0 Current 100 Worst 253 Threshold 0 Raw Value 0000000000 Status Good Partition 0 Partition ID Disk #1, Partition #0 Disk Letter E: File System NTFS Volume Serial Number 9A0676E3 Size 931 GB Used Space 631 MB (0%) Free Space 930 GB (100%) Optical Drives ASUS DRW-24B1ST j Media Type DVD Writer Name ASUS DRW-24B1ST j Availability Running/Full Power Capabilities Random Access, Supports Writing, Supports Removable Media Read capabilities CD-R, CD-RW, CD-ROM, DVD-RAM, DVD-ROM, DVD-R, DVD-RW, DVD+R, DVD+RW, DVD-R DL, DVD+R DL Write capabilities CD-R, CD-RW, DVD-RAM, DVD-R, DVD-RW, DVD+R, DVD+RW, DVD-R DL, DVD+R DL Config Manager Error Code Device is working properly Config Manager User Config FALSE Drive D: Media Loaded FALSE SCSI Bus 5 SCSI Logical Unit 0 SCSI Port 0 SCSI Target Id 0 Status OK Audio Sound Cards Realtek High Definition Audio Intel Display Audio Playback Devices HP w19b/w19e (Intel Display Audio) Realtek Digital Output (Realtek High Definition Audio) Speakers (Realtek High Definition Audio) (default) HP 25es (Intel Display Audio) Recording Device Microphone (Realtek High Definition Audio) Speaker Configuration Speaker type Stereo Peripherals HID Keyboard Device Device Kind Keyboard Device Name HID Keyboard Device Vendor Hewlett-Packard Location USB Input Device Driver Date 6-21-2006 Version 10.0.14393.206 File C:\WINDOWS\system32\DRIVERS\kbdhid.sys File C:\WINDOWS\system32\DRIVERS\kbdclass.sys HID-compliant mouse Device Kind Mouse Device Name HID-compliant mouse Vendor Unknown Location USB Input Device Driver Date 6-21-2006 Version 10.0.14393.0 File C:\WINDOWS\system32\DRIVERS\mouhid.sys File C:\WINDOWS\system32\DRIVERS\mouclass.sys Brother Laser Type1 Class Driver Device Kind Printer Device Name Brother Laser Type1 Class Driver Vendor Brother Location USB Printing Support Driver Date 4-21-2009 Version 10.0.14393.0 Brother Laser Type1 Class Driver Device Kind Printer Device Name Brother Laser Type1 Class Driver Vendor Brother Location Brother MFC-L2700DW series [30055cafe2df] Driver Date 4-21-2009 Version 10.0.14393.0 WSD Scan Device Device Kind Camera/scanner Device Name WSD Scan Device Vendor Unknown Comment Brother MFC-L2700DW series [30055cafe2df] Location http://10.0.0.5:80/WebServices/Device Driver Date 6-21-2006 Version 10.0.14393.0 File C:\WINDOWS\system32\DRIVERS\WSDScan.sys Brother Scanner c1 Device Kind Camera/scanner Device Name Brother Scanner c1 Vendor Brother Industries Ltd Location USB Composite Device Driver Date 6-21-2006 Version 10.0.14393.0 File C:\WINDOWS\system32\BrMf4Wia.dll File C:\WINDOWS\system32\BrUs3Sti.dll File C:\WINDOWS\system32\BrMfJDec.dll File C:\WINDOWS\system32\drivers\usbscan.sys Printers Brother MFC-L2700DW series Printer Port USB001 Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 600 * 600 dpi Monochrome Status Unknown Driver Driver Name Brother Laser Type1 Class Driver (v6.03) Driver Path C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_7b3eed059f4c3e41\Amd64\mxdwdrv.dll Brother MFC-L2700DW series Printer (Default Printer) Printer Port WSD-ba935fd6-3ddf-4f17-b5a8-76d763b283ac.0064 Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 600 * 600 dpi Monochrome Status Unknown Driver Driver Name Brother Laser Type1 Class Driver (v6.03) Driver Path C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_7b3eed059f4c3e41\Amd64\mxdwdrv.dll Fax Printer Port SHRFAX: Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 200 * 200 dpi Monochrome Status Unknown Driver Driver Name Microsoft Shared Fax Driver (v4.00) Driver Path C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSDRV.DLL Microsoft Print to PDF Printer Port PORTPROMPT: Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 600 * 600 dpi Color Status Unknown Driver Driver Name Microsoft Print To PDF (v6.03) Driver Path C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_7b3eed059f4c3e41\Amd64\mxdwdrv.dll Microsoft XPS Document Writer Printer Port PORTPROMPT: Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 600 * 600 dpi Color Status Unknown Driver Driver Name Microsoft XPS Document Writer v4 (v6.03) Driver Path C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_7b3eed059f4c3e41\Amd64\mxdwdrv.dll Send To OneNote 2016 Printer Port nul: Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 600 * 600 dpi Color Status Unknown Driver Driver Name Send to Microsoft OneNote 16 Driver (v6.03) Driver Path C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_7b3eed059f4c3e41\Amd64\mxdwdrv.dll Network You are connected to the internet Connected through Realtek PCIe GBE Family Controller #2 IP Address 10.0.0.14 Subnet mask 255.255.255.0 Gateway server 10.0.0.1 Preferred DNS server 8.8.8.8 Alternate DNS server 8.8.4.4 Alternate DNS server 208.67.222.222 Alternate DNS server 208.67.220.220 DHCP Enabled DHCP server 10.0.0.1 External IP Address 68.226.132.179 Adapter Type Ethernet NetBIOS over TCP/IP Enabled via DHCP NETBIOS Node Type Hybrid node Link Speed 177.4 KBps Computer Name NetBIOS Name ZOENEW DNS Name ZoeNew Membership Part of workgroup Workgroup WORKGROUP Remote Desktop Disabled Console State Active Domain ZOENEW 7A78855482A04FA781DC State Listen WinInet Info LAN Connection Local system uses a local area network to connect to the Internet Local system has RAS to connect to the Internet Wi-Fi Info Wi-Fi not enabled WinHTTPInfo WinHTTPSessionProxyType No proxy Session Proxy Session Proxy Bypass Connect Retries 5 Connect Timeout (ms) 60,000 HTTP Version HTTP 1.1 Max Connects Per 1.0 Servers INFINITE Max Connects Per Servers INFINITE Max HTTP automatic redirects 10 Max HTTP status continue 10 Send Timeout (ms) 30,000 IEProxy Auto Detect Yes IEProxy Auto Config IEProxy IEProxy Bypass Default Proxy Config Access Type No proxy Default Config Proxy Default Config Proxy Bypass Sharing and Discovery Network Discovery Enabled File and Printer Sharing Enabled File and printer sharing service Enabled Simple File Sharing Enabled Administrative Shares Enabled Network access: Sharing and security model for local accounts Classic - local users authenticate as themselves Adapters List Enabled Kaspersky Security Data Escort Adapter Connection Name Ethernet 3 DHCP enabled Yes MAC Address 00-FF-58-EA-12-DF Realtek PCIe GBE Family Controller #2 Connection Name Ethernet 2 NetBIOS over TCPIP Yes DHCP enabled Yes MAC Address 40-8D-5C-51-95-CF IP Address 10.0.0.14 Subnet mask 255.255.255.0 Gateway server 10.0.0.1 DHCP 10.0.0.1 DNS Server 8.8.8.8 8.8.4.4 208.67.222.222 208.67.220.220 8.8.8.8 8.8.4.4 Network Shares No network shares Current TCP Connections AppleMobileDeviceService.exe (2772) Local 127.0.0.1:49677 ESTABLISHED Remote 127.0.0.1:5354 (Querying... ) Local 127.0.0.1:49676 ESTABLISHED Remote 127.0.0.1:5354 (Querying... ) Local 127.0.0.1:27015 ESTABLISHED Remote 127.0.0.1:49905 (Querying... ) Local 127.0.0.1:27015 LISTEN avp.exe (2888) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59406 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59417 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59449 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59450 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59451 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59452 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59327 (Querying... ) Local 127.0.0.1:49705 LISTEN Local 127.0.0.1:49705 ESTABLISHED Remote 127.0.0.1:59390 (Querying... ) Local 127.0.0.1:49706 LISTEN Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:51570 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:57252 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:57600 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:58342 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59067 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59226 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59228 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59234 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59294 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59324 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59325 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59326 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59328 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59335 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59336 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59337 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59349 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59350 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59351 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59352 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59402 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59403 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59404 (Querying... ) Local 127.0.0.1:49706 ESTABLISHED Remote 127.0.0.1:59405 (Querying... ) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (9916) Local 10.0.0.14:50008 ESTABLISHED Remote 17.249.220.11:5223 (Querying... ) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (7452) Local 10.0.0.14:52102 CLOSE-WAIT Remote 17.248.141.79:443 (Querying... ) (HTTPS) Local 10.0.0.14:52103 CLOSE-WAIT Remote 17.248.141.42:443 (Querying... ) (HTTPS) Local 10.0.0.14:52104 CLOSE-WAIT Remote 17.248.141.76:443 (Querying... ) (HTTPS) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe (10188) Local 10.0.0.14:49930 CLOSE-WAIT Remote 17.178.100.82:443 (Querying... ) (HTTPS) Local 10.0.0.14:49931 CLOSE-WAIT Remote 23.45.48.76:443 (Querying... ) (HTTPS) Local 10.0.0.14:49932 CLOSE-WAIT Remote 17.248.141.48:443 (Querying... ) (HTTPS) Local 10.0.0.14:49934 CLOSE-WAIT Remote 17.248.141.73:443 (Querying... ) (HTTPS) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (9752) Local 10.0.0.14:49924 CLOSE-WAIT Remote 17.178.100.82:443 (Querying... ) (HTTPS) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (10372) Local 0.0.0.0:17500 LISTEN Local 10.0.0.14:49964 CLOSE-WAIT Remote 108.160.172.204:443 (Querying... ) (HTTPS) Local 10.0.0.14:50002 CLOSE-WAIT Remote 108.160.172.205:443 (Querying... ) (HTTPS) Local 10.0.0.14:57681 ESTABLISHED Remote 162.125.18.133:443 (Querying... ) (HTTPS) Local 10.0.0.14:58624 CLOSE-WAIT Remote 108.160.172.225:443 (Querying... ) (HTTPS) Local 10.0.0.14:58982 CLOSE-WAIT Remote 54.192.122.29:443 (Querying... ) (HTTPS) Local 127.0.0.1:843 LISTEN Local 127.0.0.1:49989 ESTABLISHED Remote 127.0.0.1:49990 (Querying... ) Local 127.0.0.1:49990 ESTABLISHED Remote 127.0.0.1:49989 (Querying... ) Local 127.0.0.1:49995 ESTABLISHED Remote 127.0.0.1:49996 (Querying... ) Local 127.0.0.1:49996 ESTABLISHED Remote 127.0.0.1:49995 (Querying... ) Local 127.0.0.1:49998 ESTABLISHED Remote 127.0.0.1:49999 (Querying... ) Local 127.0.0.1:49999 ESTABLISHED Remote 127.0.0.1:49998 (Querying... ) Local 127.0.0.1:17600 LISTEN Local 10.0.0.14:59532 ESTABLISHED Remote 52.7.36.215:443 (Querying... ) (HTTPS) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (7716) Local 127.0.0.1:59336 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59337 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59349 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59350 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59351 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59352 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 10.0.0.14:59537 ESTABLISHED Remote 216.58.194.67:443 (Querying... ) (HTTPS) Local 127.0.0.1:59390 ESTABLISHED Remote 127.0.0.1:49705 (Querying... ) Local 127.0.0.1:59402 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 10.0.0.14:52329 ESTABLISHED Remote 173.194.223.188:5228 (Querying... ) Local 127.0.0.1:59403 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59404 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59405 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59406 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59417 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 10.0.0.14:58910 ESTABLISHED Remote 72.21.214.83:443 (Querying... ) (HTTPS) Local 127.0.0.1:59449 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59450 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 10.0.0.14:59020 ESTABLISHED Remote 52.94.224.90:443 (Querying... ) (HTTPS) Local 127.0.0.1:59451 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 10.0.0.14:59278 ESTABLISHED Remote 104.28.14.88:443 (Querying... ) (HTTPS) Local 10.0.0.14:59419 ESTABLISHED Remote 104.16.21.35:443 (Querying... ) (HTTPS) Local 10.0.0.14:59422 ESTABLISHED Remote 104.28.14.88:443 (Querying... ) (HTTPS) Local 10.0.0.14:59473 ESTABLISHED Remote 216.58.194.102:443 (Querying... ) (HTTPS) Local 10.0.0.14:59475 ESTABLISHED Remote 216.58.194.110:443 (Querying... ) (HTTPS) Local 10.0.0.14:59481 ESTABLISHED Remote 216.58.194.108:443 (Querying... ) (HTTPS) Local 10.0.0.14:59482 ESTABLISHED Remote 216.58.194.108:443 (Querying... ) (HTTPS) Local 127.0.0.1:59452 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 10.0.0.14:59527 ESTABLISHED Remote 54.239.29.125:443 (Querying... ) (HTTPS) Local 127.0.0.1:57252 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:51570 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:57600 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:58342 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 10.0.0.14:62533 ESTABLISHED Remote 104.154.164.197:443 (Querying... ) (HTTPS) Local 127.0.0.1:59067 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59226 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59228 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59234 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59294 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59324 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59325 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59326 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59327 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59328 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59335 ESTABLISHED Remote 127.0.0.1:49706 (Querying... ) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 8.0.5\kpm.exe (9232) Local 10.0.0.14:55957 CLOSE-WAIT Remote 8.24.33.224:443 (Querying... ) (HTTPS) Local 10.0.0.14:55958 CLOSE-WAIT Remote 8.24.33.224:443 (Querying... ) (HTTPS) Local 10.0.0.14:49974 ESTABLISHED Remote 212.73.235.16:443 (Querying... ) (HTTPS) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE (13220) Local 10.0.0.14:58968 ESTABLISHED Remote 108.177.10.109:993 (Querying... ) Local 10.0.0.14:59534 ESTABLISHED Remote 108.177.10.109:993 (Querying... ) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (5580) Local 127.0.0.1:49778 ESTABLISHED Remote 127.0.0.1:49777 (Querying... ) Local 127.0.0.1:49777 ESTABLISHED Remote 127.0.0.1:49778 (Querying... ) Local 127.0.0.1:49769 ESTABLISHED Remote 127.0.0.1:5939 (Querying... ) C:\Program Files\iTunes\iTunesHelper.exe (8896) Local 127.0.0.1:49905 ESTABLISHED Remote 127.0.0.1:27015 (Querying... ) C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe (6768) Local 10.0.0.14:52392 CLOSE-WAIT Remote 157.55.56.155:443 (Querying... ) (HTTPS) Local 10.0.0.14:55768 LISTEN C:\Users\Zoe\AppData\Local\Pushbullet\bin\pushbullet_client.exe (12352) Local 10.0.0.14:60174 ESTABLISHED Remote 104.154.164.197:443 (Querying... ) (HTTPS) C:\Users\Zoe\AppData\Local\Vivaldi\Application\vivaldi.exe (2424) Local 10.0.0.14:55954 ESTABLISHED Remote 52.94.224.90:443 (Querying... ) (HTTPS) Local 10.0.0.14:53631 ESTABLISHED Remote 159.203.221.240:80 (Querying... ) (HTTP) Local 10.0.0.14:59511 ESTABLISHED Remote 192.241.145.105:443 (Querying... ) (HTTPS) C:\Windows\explorer.exe (5512) Local 10.0.0.14:49775 ESTABLISHED Remote 65.52.108.197:443 (Querying... ) (HTTPS) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe (12280) Local 10.0.0.14:59491 ESTABLISHED Remote 172.233.67.49:443 (Querying... ) (HTTPS) Local 10.0.0.14:59492 ESTABLISHED Remote 23.4.59.27:80 (Querying... ) (HTTP) Local 10.0.0.14:59490 ESTABLISHED Remote 172.233.67.49:443 (Querying... ) (HTTPS) ksde.exe (11108) Local 10.0.0.14:56518 CLOSE-WAIT Remote 54.230.122.67:443 (Querying... ) (HTTPS) lsass.exe (864) Local 0.0.0.0:49668 LISTEN mDNSResponder.exe (2996) Local 127.0.0.1:5354 LISTEN Local 127.0.0.1:5354 ESTABLISHED Remote 127.0.0.1:49677 (Querying... ) Local 127.0.0.1:5354 ESTABLISHED Remote 127.0.0.1:49676 (Querying... ) services.exe (856) Local 0.0.0.0:49681 LISTEN spoolsv.exe (1932) Local 0.0.0.0:49667 LISTEN svchost.exe (1152) Local 0.0.0.0:49666 LISTEN Local 10.0.0.14:49691 ESTABLISHED Remote 65.52.108.209:443 (Querying... ) (HTTPS) svchost.exe (1164) Local 0.0.0.0:49665 LISTEN svchost.exe (712) Local 0.0.0.0:135 (DCE) LISTEN synergyd.exe (3032) Local 127.0.0.1:24801 LISTEN System Process Local 10.0.0.14:59274 TIME-WAIT Remote 104.20.59.209:443 (Querying... ) (HTTPS) Local 10.0.0.14:59518 TIME-WAIT Remote 23.4.59.27:80 (Querying... ) (HTTP) Local 10.0.0.14:59519 TIME-WAIT Remote 38.113.165.113:443 (Querying... ) (HTTPS) Local 10.0.0.14:59520 TIME-WAIT Remote 23.212.53.221:80 (Querying... ) (HTTP) Local 10.0.0.14:59455 TIME-WAIT Remote 216.58.194.110:443 (Querying... ) (HTTPS) Local 127.0.0.1:59387 TIME-WAIT Remote 127.0.0.1:49705 (Querying... ) Local 10.0.0.14:59510 TIME-WAIT Remote 62.128.100.47:443 (Querying... ) (HTTPS) Local 10.0.0.14:59521 TIME-WAIT Remote 23.4.59.27:80 (Querying... ) (HTTP) Local 10.0.0.14:59522 TIME-WAIT Remote 38.113.165.113:443 (Querying... ) (HTTPS) Local 10.0.0.14:59523 TIME-WAIT Remote 23.4.59.27:80 (Querying... ) (HTTP) Local 10.0.0.14:59524 TIME-WAIT Remote 184.25.63.18:80 (Querying... ) (HTTP) Local 10.0.0.14:59525 TIME-WAIT Remote 23.4.59.27:80 (Querying... ) (HTTP) Local 10.0.0.14:59526 TIME-WAIT Remote 23.4.59.27:80 (Querying... ) (HTTP) Local 10.0.0.14:59531 TIME-WAIT Remote 108.160.172.204:443 (Querying... ) (HTTPS) Local 127.0.0.1:59515 TIME-WAIT Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59139 TIME-WAIT Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59024 TIME-WAIT Remote 127.0.0.1:49706 (Querying... ) Local 127.0.0.1:59536 TIME-WAIT Remote 127.0.0.1:49706 (Querying... ) Local 10.0.0.14:59486 TIME-WAIT Remote 62.128.100.47:443 (Querying... ) (HTTPS) Local 10.0.0.14:59533 TIME-WAIT Remote 45.58.75.129:443 (Querying... ) (HTTPS) Local 127.0.0.1:59388 TIME-WAIT Remote 127.0.0.1:49705 (Querying... ) Local 10.0.0.14:59535 TIME-WAIT Remote 38.113.165.113:443 (Querying... ) (HTTPS) Local 10.0.0.14:59454 TIME-WAIT Remote 104.20.129.30:443 (Querying... ) (HTTPS) Local 10.0.0.14:59496 TIME-WAIT Remote 38.113.165.68:443 (Querying... ) (HTTPS) Local 10.0.0.14:59528 TIME-WAIT Remote 54.239.16.79:443 (Querying... ) (HTTPS) Local 10.0.0.14:59512 TIME-WAIT Remote 64.4.54.253:443 (Querying... ) (HTTPS) Local 10.0.0.14:59513 TIME-WAIT Remote 64.4.54.254:443 (Querying... ) (HTTPS) Local 10.0.0.14:59514 TIME-WAIT Remote 38.113.165.113:443 (Querying... ) (HTTPS) Local 10.0.0.14:59516 TIME-WAIT Remote 23.4.59.27:80 (Querying... ) (HTTP) System Process Local 0.0.0.0:445 (Windows shares) LISTEN Local 0.0.0.0:2869 LISTEN Local 0.0.0.0:5357 LISTEN Local 10.0.0.14:139 (NetBIOS session service) LISTEN Local 0.0.0.0:20807 LISTEN TeamViewer_Service.exe (3040) Local 10.0.0.14:56442 ESTABLISHED Remote 162.220.223.10:5938 (Querying... ) Local 127.0.0.1:5939 LISTEN Local 127.0.0.1:5939 ESTABLISHED Remote 127.0.0.1:49769 (Querying... ) Local 0.0.0.0:5938 LISTEN vncserver.exe (3024) Local 10.0.0.14:50640 ESTABLISHED Remote 212.119.29.133:443 (Querying... ) (HTTPS) wininit.exe (780) Local 0.0.0.0:49664 LISTEN Generated with Speccy v1.30.730