--------------------------------------- Malwarebytes Anti-Rootkit BETA 1.10.3.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 10.0.15063 Windows 10 x64 Account is Administrative Internet Explorer version: 11.726.15063.0 File system is: NTFS Disk drives: A:\ DRIVE_FIXED, C:\ DRIVE_FIXED CPU speed: 3.099000 GHz Memory total: 8525340672, free: 3345088512 Downloaded database version: v2017.12.16.06 Downloaded database version: v2017.11.28.01 ======================================= Initializing... Driver version: 4.3.0.15 ------------ Kernel report ------------ 12/16/2017 21:00:31 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\System32\drivers\ksecdd.sys \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\System32\drivers\FLTMGR.SYS \SystemRoot\System32\drivers\clipsp.sys \SystemRoot\System32\drivers\cmimcext.sys \SystemRoot\System32\drivers\ntosext.sys \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\cng.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\SleepStudyHelper.sys \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\system32\drivers\WindowsTrustedRT.sys \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\system32\drivers\iacvybfi.sys \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\system32\drivers\CEA.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\storahci.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Wof.sys \SystemRoot\System32\Drivers\NTFS.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\drivers\wfplwfs.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\System32\drivers\volume.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\iorate.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\system32\drivers\ruybei.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\system32\drivers\filecrypt.sys \SystemRoot\system32\drivers\tbs.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \??\C:\Windows\system32\drivers\avgtpx64.sys \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\vmbkmclr.sys \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\drivers\vwififlt.sys \SystemRoot\System32\drivers\pacer.sys \SystemRoot\system32\drivers\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\System32\Drivers\SCDEmu.SYS \SystemRoot\system32\DRIVERS\sbwfw.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\drivers\gpuenergydrv.sys \??\C:\Windows\system32\drivers\ElRawDsk.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\drivers\Hamdrv.sys \SystemRoot\System32\drivers\evolve.sys \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys \SystemRoot\System32\drivers\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_c68c1eb90f6d242e\nvlddmkm.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\portcls.sys \SystemRoot\System32\drivers\drmk.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\system32\drivers\ucx01000.sys \SystemRoot\System32\drivers\HECIx64.sys \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\drivers\rt640x64.sys \SystemRoot\System32\drivers\parport.sys \SystemRoot\System32\drivers\serial.sys \SystemRoot\System32\drivers\serenum.sys \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys \SystemRoot\System32\drivers\intelppm.sys \SystemRoot\System32\drivers\ISCTD64.sys \SystemRoot\system32\drivers\nvvad64v.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\nvvhci.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\system32\drivers\LGBusEnum.sys \SystemRoot\system32\drivers\LGJoyXlCore.sys \SystemRoot\System32\drivers\ssdevfactory.sys \SystemRoot\system32\drivers\WmBEnum.sys \SystemRoot\system32\drivers\WmXlCore.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\system32\drivers\xspltspk.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\system32\drivers\nvhda64v.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\system32\drivers\RTKVHD64.sys \SystemRoot\system32\drivers\MBfilt64.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\kbdhid.sys \SystemRoot\system32\DRIVERS\ikbevent.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\system32\drivers\usbaudio.sys \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\system32\DRIVERS\udfs.sys \SystemRoot\system32\DRIVERS\imsevent.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\drivers\BTHUSB.sys \SystemRoot\System32\drivers\bthport.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_storahci.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\drivers\rfcomm.sys \SystemRoot\System32\drivers\BthEnum.sys \SystemRoot\System32\drivers\bthpan.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\win32kfull.sys \SystemRoot\System32\win32kbase.sys \SystemRoot\System32\drivers\dxgmms2.sys \SystemRoot\System32\drivers\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\wcifs.sys \SystemRoot\system32\drivers\storqosflt.sys \SystemRoot\system32\DRIVERS\mfmonitor_x64.sys \SystemRoot\system32\DRIVERS\sbapifs.sys \SystemRoot\system32\DRIVERS\PDFsFilter.sys \SystemRoot\System32\drivers\registry.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\drivers\lltdio.sys \SystemRoot\system32\drivers\mslldp.sys \SystemRoot\system32\drivers\rspndr.sys \SystemRoot\System32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\ndisuio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\System32\drivers\condrv.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \??\C:\WINDOWS\system32\Drivers\WebExaminer64.sys \SystemRoot\System32\DRIVERS\srvnet.sys \??\A:\Programs\Microvirt\MEmuHyperv\MEmuDrv.sys \SystemRoot\system32\drivers\mmcss.sys \??\C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\system32\drivers\peauth.sys \??\C:\WINDOWS\system32\drivers\rzpnk.sys \SystemRoot\System32\drivers\tcpipreg.sys \??\C:\WINDOWS\system32\drivers\rzpmgrk.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\system32\drivers\WmVirHid.sys \SystemRoot\system32\drivers\LGVirHid.sys \SystemRoot\System32\Drivers\mbamswissarmy.sys \SystemRoot\System32\drivers\netr28ux.sys \SystemRoot\System32\drivers\vwifibus.sys \SystemRoot\System32\drivers\vwifimp.sys \SystemRoot\system32\drivers\qwavedrv.sys \??\C:\WINDOWS\system32\drivers\413712EF.sys ----------- End ----------- Done! Scan started Database versions: main: v2017.12.16.06 rootkit: v2017.10.14.01 <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffff8006e780d060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffff8006e779a9f0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffff8006e780d060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffff8006e7622860, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xffff8006e7622d80, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xffff8006e7628060, DeviceName: \Device\0000002e\, DriverName: \Driver\storahci\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... File C:\WINDOWS\SYSTEM32\drivers\iacvybfi.sys will be destroyed Infected: C:\WINDOWS\SYSTEM32\drivers\iacvybfi.sys --> [Rootkit.Agent.PUA] Done! Drive 0 This is a System drive Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: 2BD2C32A Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 716800 Partition is bootable Partition file system is NTFS Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 718848 Numsec = 975128624 Partition is not bootable Partition file system is NTFS Partition 2 type is Other (0x27) Partition is NOT ACTIVE. Partition starts at LBA: 975849472 Numsec = 921600 Partition is not bootable Partition file system is NTFS Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition is not bootable Disk Size: 500107862016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-976753168-976773168)... Done! Physical Sector Size: 512 Drive: 1, DevicePointer: 0xffff8006e780c060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffff8006e77989f0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffff8006e780c060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ DevicePointer: 0xffff8006e7622ad0, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xffff8006e7626060, DeviceName: \Device\0000002f\, DriverName: \Driver\storahci\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 Drive 1 Scanning MBR on drive 1... Inspecting partition table: This drive is a GPT Drive. MBR Signature: 55AA Disk Signature: 0 GPT Protective MBR Partition information: Partition 0 type is EFI-GPT (0xee) Partition is NOT ACTIVE. Partition starts at LBA: 1 Numsec = 4294967295 Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 GPT Partition information: GPT Header Signature 4546492050415254 GPT Header Revision 65536 Size 92 CRC 1522896012 GPT Header CurrentLba = 1 BackupLba 5860533167 GPT Header FirstUsableLba 34 LastUsableLba 5860533134 GPT Header Guid 8932639d-3b34-4593-a124-61e66be8ee9 GPT Header Contains 128 partition entries starting at LBA 2 GPT Header Partition entry size = 128 Backup GPT header Signature 4546492050415254 Backup GPT header Revision 65536 Size 92 CRC 1522896012 Backup GPT header CurrentLba = 5860533167 BackupLba 1 Backup GPT header FirstUsableLba 34 LastUsableLba 5860533134 Backup GPT header Guid 8932639d-3b34-4593-a124-61e66be8ee9 Backup GPT header Contains 128 partition entries starting at LBA 5860533135 Backup GPT header Partition entry size = 128 Partition 0 Type e3c9e316-b5c-4db8-817d-f92df0215ae Partition ID 370b8826-34e8-4ebd-a283-72b7c97761b1 FirstLBA 34 Last LBA 262177 Attributes 0 Partition Name Microsoft reserved partition Partition 1 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7 Partition ID 71e43776-3816-442a-a549-e01487e16b93 FirstLBA 264192 Last LBA 5860532223 Attributes 0 Partition Name Basic data partition Disk Size: 3000592982016 bytes Sector size: 512 bytes Done! File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\apphelp.dll" is sparse (flags = 32768) File "C:\Windows\AppPatch\AcLayers.dll" is sparse (flags = 32768) File "C:\Windows\System32\msvcrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\user32.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\gdi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ucrtbase.dll" is sparse (flags = 32768) File "C:\Windows\System32\shell32.dll" is sparse (flags = 32768) File "C:\Windows\System32\cfgmgr32.dll" is sparse (flags = 32768) File "C:\Windows\System32\SHCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcrt4.dll" is sparse (flags = 32768) File "C:\Windows\System32\sspicli.dll" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sechost.dll" is sparse (flags = 32768) File "C:\Windows\System32\combase.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STORAGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\advapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\shlwapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\KERNEL.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\powrprof.dll" is sparse (flags = 32768) File "C:\Windows\System32\profapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleaut32.dll" is sparse (flags = 32768) File "C:\Windows\System32\setupapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\mpr.dll" is sparse (flags = 32768) File "C:\Windows\System32\winspool.drv" is sparse (flags = 32768) File "C:\Windows\System32\bcrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\sfc_os.dll" is sparse (flags = 32768) File "C:\Windows\System32\imm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\imagehlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ole32.dll" is sparse (flags = 32768) File "C:\Windows\System32\wintrust.dll" is sparse (flags = 32768) File "C:\Windows\System32\msasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\crypt32.dll" is sparse (flags = 32768) File "C:\Windows\System32\psapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\version.dll" is sparse (flags = 32768) File "C:\Windows\System32\wininet.dll" is sparse (flags = 32768) File "C:\Windows\System32\netapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\comdlg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\ws2_32.dll" is sparse (flags = 32768) File "C:\Windows\System32\netutils.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.413_none_55bc94a37c2a2854\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winmm.dll" is sparse (flags = 32768) File "C:\Windows\System32\userenv.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPHLPAPI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINMMBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\rsaenh.dll" is sparse (flags = 32768) File "C:\Windows\System32\uxtheme.dll" is sparse (flags = 32768) File "C:\Windows\System32\msctf.dll" is sparse (flags = 32768) File "C:\Windows\System32\dwmapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkscli.dll" is sparse (flags = 32768) File "C:\Windows\System32\cscapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\iertutil.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\winhttp.dll" is sparse (flags = 32768) File "C:\Windows\System32\mswsock.dll" is sparse (flags = 32768) File "C:\Windows\System32\winnsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\urlmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\msIso.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasadhlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\FWPUCLNT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wtsapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\winsta.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntmarta.dll" is sparse (flags = 32768) File "C:\Windows\System32\clbcatq.dll" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERMGRCLI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\propsys.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STATEREPOSITORY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\STATEREPOSITORY.CORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\mssprxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\coml2.dll" is sparse (flags = 32768) File "C:\Windows\System32\linkinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntshrui.dll" is sparse (flags = 32768) File "C:\Windows\System32\srvcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\smss.exe" is sparse (flags = 32768) File "C:\Windows\System32\csrss.exe" is sparse (flags = 32768) File "C:\Windows\System32\wininit.exe" is sparse (flags = 32768) File "C:\Windows\System32\winlogon.exe" is sparse (flags = 32768) File "C:\Windows\System32\services.exe" is sparse (flags = 32768) File "C:\Windows\System32\lsass.exe" is sparse (flags = 32768) File "C:\Windows\System32\svchost.exe" is sparse (flags = 32768) File "C:\Windows\System32\FONTDRVHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dwm.exe" is sparse (flags = 32768) File "C:\Windows\System32\dasHost.exe" is sparse (flags = 32768) File "C:\Windows\System32\spoolsv.exe" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\webio.dll" is sparse (flags = 32768) File "C:\Windows\System32\schannel.dll" is sparse (flags = 32768) File "C:\Windows\System32\MSKEYPROTECT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ncrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\NCRYPTSSLP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wsock32.dll" is sparse (flags = 32768) File "C:\Windows\System32\msxml3.dll" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dbghelp.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbgcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\NapiNSP.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpnsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlaapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winrnr.dll" is sparse (flags = 32768) File "C:\Windows\System32\wshbth.dll" is sparse (flags = 32768) File "C:\Windows\System32\devobj.dll" is sparse (flags = 32768) File "C:\Windows\System32\sihost.exe" is sparse (flags = 32768) File "C:\Windows\System32\edputil.dll" is sparse (flags = 32768) File "C:\Windows\System32\pcacli.dll" is sparse (flags = 32768) File "C:\Windows\System32\devrtl.dll" is sparse (flags = 32768) File "C:\Windows\System32\TASKHOSTW.EXE" is sparse (flags = 32768) File "C:\Windows\explorer.exe" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\RUNTIMEBROKER.EXE" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8\comctl32.dll" is sparse (flags = 32768) File "C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\tiptsf.dll" is sparse (flags = 32768) File "C:\Windows\System32\pdh.dll" is sparse (flags = 32768) File "C:\Windows\System32\security.dll" is sparse (flags = 32768) File "C:\Windows\System32\secur32.dll" is sparse (flags = 32768) File "C:\Windows\System32\msv1_0.dll" is sparse (flags = 32768) File "C:\Windows\System32\NTLMSHARED.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptdll.dll" is sparse (flags = 32768) File "C:\Windows\System32\perfos.dll" is sparse (flags = 32768) File "C:\Windows\System32\FIREWALLAPI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\fwbase.dll" is sparse (flags = 32768) File "C:\Windows\System32\FWPOLICYIOMGR.DLL" is sparse (flags = 32768) File "C:\Windows\System32\rundll32.exe" is sparse (flags = 32768) Infected: C:\Users\Dillon\AppData\Local\zaihupn\zaihupn.exe --> [Trojan.Clicker] Infected: C:\Users\Dillon\AppData\Local\zaihupn\zaihupn.exe --> [Trojan.Clicker] File "C:\Windows\System32\Wldap32.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STORAGE.SEARCH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\normaliz.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.15063.608_none_9e9d5d4256d15def\GdiPlus.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxgi.dll" is sparse (flags = 32768) File "C:\Windows\System32\conhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\SETTINGSYNCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\ctfmon.exe" is sparse (flags = 32768) File "C:\Windows\System32\Taskmgr.exe" is sparse (flags = 32768) File "C:\Windows\System32\APPLICATIONFRAMEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\notepad.exe" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMSETTINGSBROKER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\usp10.dll" is sparse (flags = 32768) File "C:\Windows\System32\DWrite.dll" is sparse (flags = 32768) File "C:\Windows\System32\fontsub.dll" is sparse (flags = 32768) File "C:\Windows\System32\msimg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleacc.dll" is sparse (flags = 32768) File "C:\Windows\System32\UIAUTOMATIONCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\avrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\MMDevAPI.dll" is sparse (flags = 32768) File "C:\Windows\System32\mscms.dll" is sparse (flags = 32768) File "C:\Windows\System32\DIRECTMANIPULATION.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\d3d11.dll" is sparse (flags = 32768) File "C:\Windows\System32\dcomp.dll" is sparse (flags = 32768) File "C:\Windows\System32\TWINAPI.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\atlthunk.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptnet.dll" is sparse (flags = 32768) File "C:\Windows\System32\Speech\Common\sapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdmo.dll" is sparse (flags = 32768) File "C:\Windows\System32\msacm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\devenum.dll" is sparse (flags = 32768) File "C:\Windows\System32\d3d9.dll" is sparse (flags = 32768) File "C:\Windows\System32\ddraw.dll" is sparse (flags = 32768) File "C:\Windows\System32\dciman32.dll" is sparse (flags = 32768) File "C:\Windows\System32\mf.dll" is sparse (flags = 32768) File "C:\Windows\System32\mfplat.dll" is sparse (flags = 32768) File "C:\Windows\System32\RTWorkQ.dll" is sparse (flags = 32768) File "C:\Windows\System32\mfcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\MFPERFHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ksuser.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWSCODECS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sxs.dll" is sparse (flags = 32768) File "C:\Windows\System32\wpnapps.dll" is sparse (flags = 32768) File "C:\Windows\System32\rmclient.dll" is sparse (flags = 32768) File "C:\Windows\System32\xmllite.dll" is sparse (flags = 32768) File "C:\Windows\System32\msxml6.dll" is sparse (flags = 32768) File "C:\Windows\System32\MSMPEG2VDEC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dxva2.dll" is sparse (flags = 32768) File "C:\Windows\System32\msvproc.dll" is sparse (flags = 32768) File "C:\Windows\System32\opengl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\glu32.dll" is sparse (flags = 32768) File "C:\Windows\System32\dinput8.dll" is sparse (flags = 32768) File "C:\Windows\System32\hid.dll" is sparse (flags = 32768) File "C:\Windows\System32\XINPUT1_4.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wlanapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbemcomn.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdmaud.drv" is sparse (flags = 32768) File "C:\Windows\System32\wbem\fastprox.dll" is sparse (flags = 32768) File "C:\Windows\System32\msacm32.drv" is sparse (flags = 32768) File "C:\Windows\System32\midimap.dll" is sparse (flags = 32768) File "C:\Windows\System32\dsound.dll" is sparse (flags = 32768) File "C:\Windows\System32\THUMBCACHE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\POLICYMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP110_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\twinapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\qwave.dll" is sparse (flags = 32768) File "C:\Windows\System32\traffic.dll" is sparse (flags = 32768) File "C:\Windows\System32\wmiclnt.dll" is sparse (flags = 32768) File "C:\Windows\System32\MFWMAAEC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.UI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wbem\wbemprox.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\wbemsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ICONCODECSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptui.dll" is sparse (flags = 32768) File "C:\Windows\System32\samcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\MFREADWRITE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.APPLICATIONMODEL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COMPPKGSUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTCLIENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MFH264ENC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SndVol.exe" is sparse (flags = 32768) Infected: C:\Users\Dillon\AppData\Local\zaihupn\usrvhcg.exe --> [Adware.Yelloader] Infected: C:\Users\Dillon\AppData\Local\zaihupn\usrvhcg.exe --> [Adware.Yelloader] Infected: C:\Users\Dillon\AppData\Local\zaihupn\usrvhcg.exe --> [Adware.Yelloader] Infected: C:\Users\Dillon\AppData\Local\zaihupn\usrvhcg.exe --> [Adware.Yelloader] Infected: C:\Users\Dillon\AppData\Local\zaihupn\usrvhcg.exe --> [Adware.Yelloader] Infected: C:\Users\Dillon\AppData\Local\zaihupn\usrvhcg.exe --> [Adware.Yelloader] File "C:\Windows\System32\STRUCTUREDQUERY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\cmd.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Program Files (x86)\Windows Mail\wab.exe" is sparse (flags = 32768) File "C:\Windows\System32\credssp.dll" is sparse (flags = 32768) File "C:\Windows\System32\userinit.exe" is sparse (flags = 32768) File "C:\Windows\System32\scecli.dll" is sparse (flags = 32768) File "C:\Windows\System32\drivers\appid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspclock.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpiex.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ndu.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\Locator.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mpsdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\afd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ahcache.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\asyncmac.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rfcomm.sys" is sparse (flags = 32768) File "C:\Windows\System32\alg.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcnfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcifs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srvnet.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHUSB.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bowser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthpan.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthport.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cng.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\clfs.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cldflt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\registry.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mup.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\dllhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\condrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dam.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dfsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dxgkrnl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpip.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORCLASS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPATIALGRAPHFILTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fileinfo.sys" is sparse (flags = 32768) File "C:\Windows\System32\FXSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipfltdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fltMgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PRESENTATIONFONTCACHE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fvevol.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndisuio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasl2tp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\http.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hwpolicy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pacer.sys" is sparse (flags = 32768) File "C:\Windows\SysWOW64\perfhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdFilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\iorate.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\scfilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irda.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UcmCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Udecx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecdd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecpkg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksthunk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\lltdio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\luafv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mstee.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mmcss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mskssrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wimmount.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxdav.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\modem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspqm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mountmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb10.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb20.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ucx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ufx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bridge.sys" is sparse (flags = 32768) File "C:\Windows\System32\VSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\msdtc.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\msiexec.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mslldp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nwifi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndis.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiscap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndistapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiswan.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nsiproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\partmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcw.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\PEAuth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\RDPVIDEOMINIPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\qwavedrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspptp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasacd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\agilevpn.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspppoe.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rassstp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdbss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpdr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdyboost.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rspndr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SpbCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\snmptrap.exe" is sparse (flags = 32768) File "C:\Windows\System32\Spectrum.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\sppsvc.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpipreg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tdx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\terminpt.sys" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\servicing\TRUSTEDINSTALLER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbFlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\udfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBAUDIO.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBXHCI.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\vds.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhf.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgrx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volsnap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwifibus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwififlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwifimp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFRd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wanarp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbengine.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdBoot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Wdf01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdiWiFi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdNisDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wfplwfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiApSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ws2ifsl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WSDPrint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFPf.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\xusb22.sys" is sparse (flags = 32768) File "C:\Windows\System32\AJRouter.dll" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umpnpmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcss.dll" is sparse (flags = 32768) File "C:\Windows\System32\appinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\appidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\AxInstSv.dll" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\AUDIOENDPOINTBUILDER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\audiosrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\RpcEpMap.dll" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bdesvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\BFE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netman.dll" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cdpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\umpo.dll" is sparse (flags = 32768) File "C:\Windows\System32\qmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\ListSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lltdsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\browser.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\profsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bthserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\provsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\das.dll" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\certprop.dll" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ClipSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wscsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WsmSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wersvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wecsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dot3svc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dusmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\fdPHost.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsrslvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\dps.dll" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\eapsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\efssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ENTERPRISEAPPMGMTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FntCache.dll" is sparse (flags = 32768) File "C:\Windows\System32\es.dll" is sparse (flags = 32768) File "C:\Windows\System32\sdrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\srvsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\xbgmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FDResPub.dll" is sparse (flags = 32768) File "C:\Windows\System32\upnphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\fhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\hidserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\HVHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IKEEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\iphlpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\irmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\keyiso.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdtckrm.dll" is sparse (flags = 32768) File "C:\Windows\System32\lfsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lpasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lmhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ipnathlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\lsm.dll" is sparse (flags = 32768) File "C:\Windows\System32\moshost.dll" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MPSSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\iscsiexe.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsisvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ngcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NcaSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netlogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\trkwks.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\icsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pcasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\p2psvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pla.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\icsvcext.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPSECSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\rasauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasmans.dll" is sparse (flags = 32768) File "C:\Windows\System32\mprdim.dll" is sparse (flags = 32768) File "C:\Windows\System32\regsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\RDXSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\RMapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\schedsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SCardSvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\seclogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\sensrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SEMgrSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\Sens.dll" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SessEnv.dll" is sparse (flags = 32768) File "C:\Windows\System32\shsvcs.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\smphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\StorSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\sstpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ssdpsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\wiaservc.dll" is sparse (flags = 32768) File "C:\Windows\System32\svsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\swprv.dll" is sparse (flags = 32768) File "C:\Windows\System32\sysmain.dll" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TabSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\termsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\tapisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TOKENBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umrdp.dll" is sparse (flags = 32768) File "C:\Windows\System32\Unistore.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\usermgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\usocore.dll" is sparse (flags = 32768) File "C:\Windows\System32\vaultsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\w32time.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbiosrvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wwansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WUDFSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcncsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdi.dll" is sparse (flags = 32768) File "C:\Windows\System32\WebClnt.dll" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wiarpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WMIsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wuaueng.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Program Files (x86)\Windows Mail\WinMail.exe" is sparse (flags = 32768) File "C:\Windows\System32\unregmp2.exe" is sparse (flags = 32768) File "C:\Windows\System32\ie4uinit.exe" is sparse (flags = 32768) File "C:\Users\Dillon\AppData\Local\Comms\UnistoreDB\store.vol" is sparse (flags = 32768) Infected: C:\Users\Dillon\AppData\Local\dwbhzuc\download\flashplayer28pp_ka_install.exe --> [Trojan.Injector] Infected: C:\Users\Dillon\Desktop\Folders\Extra Apps\Dragon Ball XenoVerse v1.0 Plus 12 Trainer.exe --> [RiskWare.GameHack.Generic] Scan finished Creating System Restore point... Cleaning up... <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Removal scheduling successful. System shutdown needed. System shutdown occurred =======================================