Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

"Bitmotion-New Tab" added in Chrome (can't get rid of it&#


  • Please log in to reply

#106
tl79

tl79

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 186 posts

did msconfig...turned off all (exc MS) in services and startup:  numbers for system idle and procexp64 were about the same.  Interrupts bounces around at around 1.6 to over 2


  • 0

Advertisements


#107
tl79

tl79

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 186 posts

After disabling and re-enabling services and startup, I have internet and can finally get to geeks to go on the laptop!


  • 0

#108
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

It appears there was a big improvement when you ran without battery.  Not enough but significant.  Does it last very long on battery?

 

Since you have it back on line, make a new FRST scan and post it.


  • 0

#109
tl79

tl79

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 186 posts
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03-07-2017 01
Ran by mel (administrator) on MEL-PC (03-07-2017 15:15:24)
Running from C:\Users\mel\Desktop
Loaded Profiles: mel (Available Profiles: mel)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvLaunch.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-03-23] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3954352 2016-03-30] (Synaptics Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213832 2017-07-02] (AVAST Software)
HKLM-x32\...\Run: [IseUI] => C:\Program Files (x86)\COMODO\Internet Security Essentials\vkise.exe
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2014-06-16] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4513792 2014-05-22] (Brother Industries, Ltd.)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
GroupPolicy: Restriction - Chrome <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.3.254
Tcpip\..\Interfaces\{29154919-1dc2-434c-be91-1bc9b23aa427}: [DhcpNameServer] 192.168.3.254
Tcpip\..\Interfaces\{9eda8ba8-f1ef-4784-84ba-c98324db86dd}: [DhcpNameServer] 192.168.3.254
 
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
 
Edge: 
======
Edge HomeButtonPage: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001 -> hxxp://www.google.com/
 
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Profile: C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default [2017-07-03]
CHR Extension: (Google Slides) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-02-27]
CHR Extension: (Google Docs) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-27]
CHR Extension: (Google Drive) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-02-27]
CHR Extension: (YouTube) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-27]
CHR Extension: (uBlock) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\epcnnfbjfcgphgdmggkamkmgojdagdnn [2017-07-02]
CHR Extension: (Google Sheets) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-02-27]
CHR Extension: (Google Docs Offline) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-02-27]
CHR Extension: (F.B.(FluffBusting)Purity) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmkinhboiljjkhaknpaeaicmdjhagpep [2017-07-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08]
CHR Extension: (Gmail) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-27]
CHR Extension: (Chrome Media Router) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-17]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AESTFilters; C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7430992 2017-07-02] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263312 2017-07-02] (AVAST Software)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2013-09-25] (Brother Industries, Ltd.) [File not signed]
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
S2 STacSV; C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\STacSV64.exe [247808 2010-03-23] (IDT, Inc.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [253960 2016-03-30] (Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-27] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [319984 2017-07-02] (AVAST Software s.r.o.)
R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [198944 2017-07-02] (AVAST Software s.r.o.)
R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [343264 2017-07-02] (AVAST Software s.r.o.)
R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [57704 2017-07-02] (AVAST Software s.r.o.)
S3 aswHdsKe; C:\WINDOWS\system32\drivers\aswHdsKe.sys [85552 2017-02-27] (AVAST Software)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [46984 2017-07-02] (AVAST Software)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [41800 2017-07-02] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [146664 2017-07-02] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [110352 2017-07-02] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [84392 2017-07-02] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1015848 2017-07-02] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [585608 2017-07-02] (AVAST Software)
R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [198768 2017-07-02] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [361336 2017-07-02] (AVAST Software)
R3 BCM43XX; C:\WINDOWS\System32\drivers\bcmwl63al.sys [5170176 2016-07-16] (Broadcom Corporation)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [251848 2017-07-03] (Malwarebytes)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [52400 2016-03-30] (Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [52904 2016-03-30] (Synaptics Incorporated)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-07-03 15:15 - 2017-07-03 15:16 - 00009666 _____ C:\Users\mel\Desktop\FRST.txt
2017-07-03 15:15 - 2017-07-03 15:15 - 00000000 ____D C:\Users\mel\Desktop\FRST-OlderVersion
2017-07-03 11:54 - 2017-07-03 14:28 - 00021232 _____ (Thesycon GmbH) C:\WINDOWS\system32\Drivers\dpclat_driver.sys
2017-07-03 11:53 - 2017-07-03 14:28 - 00000980 _____ C:\Users\mel\Desktop\dpclat.exe - Shortcut.lnk
2017-07-03 11:50 - 2017-07-03 11:50 - 00306928 _____ (Thesycon GmbH) C:\Users\mel\Downloads\dpclat.exe
2017-07-03 09:25 - 2017-07-03 09:25 - 00164748 _____ C:\Users\mel\Desktop\apps removed feb 27 2017.pdf
2017-07-03 09:25 - 2017-07-03 09:25 - 00000000 ____D C:\Users\mel\AppData\LocalLow\Temp
2017-07-02 20:13 - 2017-07-02 20:13 - 00000000 ___SD C:\WINDOWS\UpdateAssistantV2
2017-07-02 19:34 - 2017-06-03 05:50 - 00315744 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-07-02 19:34 - 2017-06-03 05:16 - 00279904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-07-02 19:34 - 2017-06-03 05:11 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-07-02 19:34 - 2017-06-03 05:09 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-07-02 19:34 - 2017-06-03 05:06 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-07-02 19:34 - 2017-06-03 04:59 - 01181024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2017-07-02 19:34 - 2017-06-03 04:59 - 00118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-07-02 19:34 - 2017-06-03 04:58 - 00340832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-07-02 19:34 - 2017-06-03 04:55 - 00780640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-07-02 19:34 - 2017-06-03 04:54 - 00187232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-07-02 19:34 - 2017-06-03 04:52 - 01021784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2017-07-02 19:34 - 2017-06-03 04:52 - 00607072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2017-07-02 19:34 - 2017-06-03 04:52 - 00111968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2017-07-02 19:34 - 2017-06-03 04:50 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-07-02 19:34 - 2017-06-03 04:50 - 00381792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-07-02 19:34 - 2017-06-03 04:49 - 20967840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-07-02 19:34 - 2017-06-03 04:48 - 00857952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2017-07-02 19:34 - 2017-06-03 04:48 - 00148832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2017-07-02 19:34 - 2017-06-03 04:45 - 22220864 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-07-02 19:34 - 2017-06-03 04:44 - 01412640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-07-02 19:34 - 2017-06-03 04:44 - 00545944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-07-02 19:34 - 2017-06-03 04:39 - 05686272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-07-02 19:34 - 2017-06-03 04:39 - 02532192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-07-02 19:34 - 2017-06-03 04:33 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-07-02 19:34 - 2017-06-03 04:32 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-07-02 19:34 - 2017-06-03 04:31 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2017-07-02 19:34 - 2017-06-03 04:31 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-07-02 19:34 - 2017-06-03 04:28 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-07-02 19:34 - 2017-06-03 04:28 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edputil.dll
2017-07-02 19:34 - 2017-06-03 04:26 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-07-02 19:34 - 2017-06-03 04:26 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBrokerUI.dll
2017-07-02 19:34 - 2017-06-03 04:22 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2017-07-02 19:34 - 2017-06-03 04:22 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcorehc.dll
2017-07-02 19:34 - 2017-06-03 04:22 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
2017-07-02 19:34 - 2017-06-03 04:20 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2017-07-02 19:34 - 2017-06-03 04:19 - 01164288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certutil.exe
2017-07-02 19:34 - 2017-06-03 04:16 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2017-07-02 19:34 - 2017-06-03 04:16 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-07-02 19:34 - 2017-06-03 04:15 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-07-02 19:34 - 2017-06-03 04:15 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-07-02 19:34 - 2017-06-03 04:15 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-07-02 19:34 - 2017-06-03 04:14 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-07-02 19:34 - 2017-06-03 04:14 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-07-02 19:34 - 2017-06-03 04:14 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-07-02 19:34 - 2017-06-03 04:12 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdProxy.dll
2017-07-02 19:34 - 2017-06-03 04:08 - 02643968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-07-02 19:34 - 2017-06-03 04:08 - 01221120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2017-07-02 19:34 - 2017-06-03 04:07 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-07-02 19:34 - 2017-06-03 04:07 - 00456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2017-07-02 19:34 - 2017-06-03 04:05 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2017-07-02 19:34 - 2017-06-03 04:05 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hnetcfg.dll
2017-07-02 19:34 - 2017-06-03 04:04 - 02006528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-07-02 19:34 - 2017-06-03 04:04 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-07-02 19:34 - 2017-06-03 04:03 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-07-02 19:34 - 2017-06-03 04:02 - 02997760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-07-02 19:34 - 2017-06-03 03:54 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-07-02 19:34 - 2017-06-03 03:52 - 03403264 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-07-02 19:34 - 2017-06-03 03:51 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2017-07-02 19:34 - 2017-06-03 03:50 - 02538496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-07-02 19:34 - 2017-06-03 03:49 - 00903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-07-02 19:34 - 2017-06-03 03:48 - 01131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-07-02 19:34 - 2017-06-03 03:48 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-07-02 19:34 - 2017-06-03 03:48 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-07-02 19:34 - 2017-06-03 03:40 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-07-02 19:34 - 2017-05-25 00:56 - 00038752 _____ (Microsoft Corporation) C:\WINDOWS\system32\OOBEUpdater.exe
2017-07-02 19:34 - 2017-03-04 01:16 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2017-07-02 19:34 - 2017-03-04 01:16 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2017-07-02 19:34 - 2016-09-06 23:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2017-07-02 19:33 - 2017-06-03 05:50 - 00192856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 01564512 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 01214816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00629088 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00544096 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00334176 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00233824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00136024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00096608 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-07-02 19:33 - 2017-06-03 05:14 - 00034648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-07-02 19:33 - 2017-06-03 05:11 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-07-02 19:33 - 2017-06-03 05:08 - 07783256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-07-02 19:33 - 2017-06-03 05:01 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-07-02 19:33 - 2017-06-03 04:59 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-07-02 19:33 - 2017-06-03 04:53 - 00404824 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-07-02 19:33 - 2017-06-03 04:51 - 02187104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-07-02 19:33 - 2017-06-03 04:51 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-07-02 19:33 - 2017-06-03 04:49 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-07-02 19:33 - 2017-06-03 04:49 - 00509280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-07-02 19:33 - 2017-06-03 04:48 - 01112416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2017-07-02 19:33 - 2017-06-03 04:48 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-07-02 19:33 - 2017-06-03 04:48 - 00989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-07-02 19:33 - 2017-06-03 04:44 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-07-02 19:33 - 2017-06-03 04:40 - 01566552 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-07-02 19:33 - 2017-06-03 04:40 - 00628552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-07-02 19:33 - 2017-06-03 04:39 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-07-02 19:33 - 2017-06-03 04:23 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-07-02 19:33 - 2017-06-03 04:22 - 07217152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-07-02 19:33 - 2017-06-03 04:18 - 22569984 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-07-02 19:33 - 2017-06-03 04:16 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-07-02 19:33 - 2017-06-03 04:15 - 19414016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-07-02 19:33 - 2017-06-03 04:15 - 18364928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-07-02 19:33 - 2017-06-03 04:14 - 00045056 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-07-02 19:33 - 2017-06-03 04:11 - 00353792 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2017-07-02 19:33 - 2017-06-03 04:10 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-07-02 19:33 - 2017-06-03 04:10 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll
2017-07-02 19:33 - 2017-06-03 04:10 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBrokerUI.dll
2017-07-02 19:33 - 2017-06-03 04:09 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2017-07-02 19:33 - 2017-06-03 04:09 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcorehc.dll
2017-07-02 19:33 - 2017-06-03 04:09 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2017-07-02 19:33 - 2017-06-03 04:08 - 12187648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-07-02 19:33 - 2017-06-03 04:08 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-07-02 19:33 - 2017-06-03 04:08 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-07-02 19:33 - 2017-06-03 04:08 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-07-02 19:33 - 2017-06-03 04:07 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\HNetCfgClient.dll
2017-07-02 19:33 - 2017-06-03 04:06 - 03664384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-07-02 19:33 - 2017-06-03 04:06 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2017-07-02 19:33 - 2017-06-03 04:04 - 06042624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-07-02 19:33 - 2017-06-03 04:03 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2017-07-02 19:33 - 2017-06-03 04:01 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2017-07-02 19:33 - 2017-06-03 04:00 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-07-02 19:33 - 2017-06-03 03:58 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll
2017-07-02 19:33 - 2017-06-03 03:56 - 13091840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-07-02 19:33 - 2017-06-03 03:53 - 08125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-07-02 19:33 - 2017-06-03 03:52 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-07-02 19:33 - 2017-06-03 03:52 - 00975872 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-07-02 19:33 - 2017-06-03 03:52 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2017-07-02 19:33 - 2017-06-03 03:51 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\certutil.exe
2017-07-02 19:33 - 2017-06-03 03:50 - 04744704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-07-02 19:33 - 2017-06-03 03:49 - 03615744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-07-02 19:33 - 2017-06-03 03:49 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-07-02 19:33 - 2017-06-03 03:49 - 02475520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-07-02 19:33 - 2017-06-03 03:49 - 02318848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-07-02 19:33 - 2017-06-03 03:49 - 01845248 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-07-02 19:33 - 2017-06-03 03:49 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-07-02 19:33 - 2017-06-03 03:49 - 00351744 _____ (Microsoft Corporation) C:\WINDOWS\system32\hnetcfg.dll
2017-07-02 19:33 - 2017-06-03 03:48 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-07-02 19:33 - 2017-06-03 03:46 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-07-02 19:33 - 2017-06-03 01:08 - 00080078 _____ C:\WINDOWS\system32\normidna.nls
2017-07-02 19:33 - 2017-03-04 01:22 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-07-02 19:33 - 2017-03-04 01:19 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2017-07-02 19:28 - 2017-07-02 19:28 - 00007130 _____ C:\junk.txt
2017-07-02 19:19 - 2017-07-03 10:22 - 00000878 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
2017-07-02 19:19 - 2017-07-03 10:22 - 00000000 ____D C:\ProgramData\TinyWall
2017-07-02 19:19 - 2017-07-03 10:22 - 00000000 ____D C:\Program Files (x86)\TinyWall
2017-07-02 19:05 - 2017-07-02 19:05 - 00000837 _____ C:\Users\Public\Desktop\Speccy.lnk
2017-07-02 19:05 - 2017-07-02 19:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2017-07-02 19:05 - 2017-07-02 19:05 - 00000000 ____D C:\Program Files\Speccy
2017-07-02 19:03 - 2017-07-02 19:04 - 06293184 _____ (Piriform Ltd) C:\Users\mel\Desktop\spsetup130.exe
2017-07-02 18:53 - 2017-07-03 14:27 - 00041800 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2017-07-02 18:51 - 2017-07-02 18:53 - 02724512 _____ (Sysinternals - www.sysinternals.com) C:\Users\mel\Desktop\procexp.exe
2017-07-02 18:45 - 2017-07-02 18:45 - 00000000 _____ C:\WINDOWS\System32\Tasks\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}
2017-07-02 08:06 - 2017-07-03 15:15 - 02436096 _____ (Farbar) C:\Users\mel\Desktop\FRST64.exe
2017-07-02 07:49 - 2017-07-02 07:49 - 00448512 _____ (OldTimer Tools) C:\Users\mel\Downloads\TFC.exe
2017-07-02 07:25 - 2017-07-02 07:25 - 00061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys
2017-07-02 07:24 - 2017-07-02 07:24 - 00400464 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2017-07-02 07:11 - 2017-07-02 07:12 - 00000000 ____D C:\speedy fox
2017-07-02 07:11 - 2017-07-02 07:11 - 00000000 ____D C:\Users\mel\AppData\Roaming\CrystalIdea Software
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-07-03 15:15 - 2015-12-08 12:23 - 00000000 ____D C:\FRST
2017-07-03 15:14 - 2017-02-27 22:16 - 00000000 ____D C:\Users\mel
2017-07-03 14:38 - 2017-02-27 23:37 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-07-03 14:38 - 2017-02-27 22:27 - 00000000 ____D C:\Users\mel\AppData\Local\Packages
2017-07-03 14:37 - 2017-02-27 23:37 - 00000000 ___HD C:\Program Files\WindowsApps
2017-07-03 14:26 - 2017-02-27 22:02 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-07-03 14:12 - 2017-02-27 23:37 - 00000000 ____D C:\WINDOWS\rescache
2017-07-03 12:48 - 2017-05-29 09:06 - 00000000 ____D C:\Users\mel\AppData\Local\ElevatedDiagnostics
2017-07-03 12:39 - 2017-02-27 22:22 - 01330072 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-07-03 12:34 - 2017-02-27 22:03 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-07-03 12:33 - 2017-02-27 23:07 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-07-03 11:49 - 2017-02-27 23:11 - 00000000 ____D C:\ProgramData\TEMP
2017-07-03 11:47 - 2017-02-27 23:17 - 00251848 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-07-03 10:23 - 2017-02-27 23:07 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-07-03 10:21 - 2017-02-27 23:38 - 00004146 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{92C4C726-4C71-4BC2-9477-83D9F5AA6E47}
2017-07-03 09:30 - 2017-02-27 23:37 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-07-03 09:16 - 2017-02-27 23:35 - 00000000 ____D C:\WINDOWS\INF
2017-07-03 07:34 - 2016-02-13 08:20 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-07-03 07:32 - 2017-02-27 22:01 - 00268936 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-07-02 20:13 - 2017-02-27 23:37 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-07-02 20:13 - 2017-02-27 23:37 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-07-02 20:13 - 2017-02-27 23:37 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-07-02 20:00 - 2017-03-02 19:30 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-07-02 19:57 - 2017-03-02 19:28 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-07-02 19:57 - 2017-02-27 23:16 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-07-02 19:55 - 2014-04-28 19:07 - 00000000 ___RD C:\Users\mel\Desktop\UTILITIES
2017-07-02 07:43 - 2017-03-05 18:30 - 00000000 ____D C:\Users\mel\AppData\Local\CrashDumps
2017-07-02 07:35 - 2017-01-23 12:29 - 00000000 ____D C:\DAD 2017
2017-07-02 07:33 - 2017-02-27 22:59 - 00004004 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1488254368
2017-07-02 07:32 - 2017-02-27 22:59 - 00001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-07-02 07:25 - 2017-02-27 22:56 - 00361336 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswvmm.sys
2017-07-02 07:24 - 2017-02-27 22:56 - 00585608 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2017-07-02 07:24 - 2017-02-27 22:56 - 00360792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswvmm.sys.149899832379606
2017-07-02 07:24 - 2017-02-27 22:56 - 00198768 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2017-07-02 07:24 - 2017-02-27 22:56 - 00146664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2017-07-02 07:24 - 2017-02-27 22:56 - 00110352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2017-07-02 07:24 - 2017-02-27 22:56 - 00084392 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2017-07-02 07:24 - 2017-02-27 22:56 - 00046984 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2017-07-02 07:24 - 2017-02-27 22:56 - 00003994 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2017-07-02 07:24 - 2017-02-27 22:52 - 00000000 ____D C:\ProgramData\AVAST Software
2017-07-02 07:23 - 2017-02-27 22:58 - 00041800 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2017-07-02 07:23 - 2017-02-27 22:56 - 01015848 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2017-07-02 07:23 - 2017-02-27 22:56 - 00343264 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys
2017-07-02 07:23 - 2017-02-27 22:56 - 00319984 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2017-07-02 07:23 - 2017-02-27 22:56 - 00198944 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2017-07-02 07:23 - 2017-02-27 22:56 - 00057704 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2017-07-02 07:15 - 2017-05-29 19:02 - 00000000 ____D C:\Program Files (x86)\OSTotoSoft
2017-06-27 20:54 - 2017-02-27 22:48 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-06-27 20:54 - 2017-02-27 22:48 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-06-03 01:36 - 2017-02-27 23:40 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-06-03 01:36 - 2017-02-27 23:40 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
 
==================== Files in the root of some directories =======
 
2017-06-01 15:07 - 2017-06-01 15:07 - 0000017 _____ () C:\Users\mel\AppData\Local\resmon.resmoncfg
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-07-02 20:04
 
==================== End of FRST.txt ============================
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-07-2017 01
Ran by mel (03-07-2017 15:18:04)
Running from C:\Users\mel\Desktop
Windows 10 Home Version 1607 (X64) (2017-02-28 03:26:47)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1930977450-1904899304-3597289394-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1930977450-1904899304-3597289394-503 - Limited - Disabled)
Guest (S-1-5-21-1930977450-1904899304-3597289394-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1930977450-1904899304-3597289394-1002 - Limited - Enabled)
mel (S-1-5-21-1930977450-1904899304-3597289394-1001 - Administrator - Enabled) => C:\Users\mel
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.5.2302 - AVAST Software)
Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.60.18.12 - Broadcom Corporation)
Brother MFL-Pro Suite MFC-L2740DW series (HKLM-x32\...\{F8ECC2FD-CE2B-4ED4-BDCC-90D0D34206FD}) (Version: 1.0.2.0 - Brother Industries, Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
LibreOffice 5.3.0.3 (HKLM\...\{769A4A4C-3EBD-4469-B13B-5083F1C7717F}) (Version: 5.3.0.3 - The Document Foundation)
LSI HDA Modem (HKLM\...\LSI Soft Modem) (Version: 2.1.94 - LSI Corporation)
Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
SafeZone Stable 3.55.2393.609 (HKLM-x32\...\SafeZone 3.55.2393.609) (Version: 3.55.2393.609 - Avast Software) Hidden
Speccy (HKLM\...\Speccy) (Version: 1.30 - Piriform)
SpywareBlaster 5.5 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.5.0 - BrightFort LLC)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.12.98 - Synaptics Incorporated)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\mel\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\mel\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\mel\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll => No File
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ContextMenuHandlers01: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
ContextMenuHandlers03: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
ContextMenuHandlers06: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {1BE5BF59-52DE-4E97-AB08-6AC206337510} - System32\Tasks\SafeZone scheduled Autoupdate 1488254368 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-06-13] (Avast Software)
Task: {27371DC3-A84E-4762-9584-A388400AC5FF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated)
Task: {8037B55F-49A9-4731-BF15-26E1A7BDC233} - System32\Tasks\{31DDBD37-5DB7-4030-8064-10B0CAA806C3} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
Task: {A0F10D3D-5045-4202-B13A-1DF935756E8A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-27] (Google Inc.)
Task: {BDBAF97D-ED50-4F49-927D-5739115BEBBC} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-04-13] (AVAST Software)
Task: {C9410398-AFA3-47E2-9CAC-0CF88EBA4296} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-07-02] (AVAST Software)
Task: {CC5F0275-0DFB-494E-BE69-32A3985E4ABE} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\WINDOWS\system32\MRT.exe [2017-07-02] (Microsoft Corporation)
Task: {F6748E67-7309-440F-B68E-B959A8210AD3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-27] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2017-02-28 09:24 - 2005-04-21 23:36 - 00143360 _____ () C:\WINDOWS\system32\BrSNMP64.dll
2016-07-16 06:42 - 2016-07-16 06:42 - 00231424 ____N () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-07-02 19:33 - 2017-06-03 05:01 - 02681200 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-09-18 16:34 - 2016-09-18 16:34 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-03-14 19:16 - 2017-03-04 01:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-03-14 19:18 - 2017-03-04 01:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-03-14 19:18 - 2017-03-04 01:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-03-14 19:18 - 2017-03-04 01:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-07-02 19:33 - 2017-06-03 03:47 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-07-02 19:33 - 2017-06-03 03:47 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-07-02 19:33 - 2017-06-03 03:51 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2017-03-14 19:18 - 2017-03-04 01:04 - 00114176 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Dss.BackgroundTask.dll
2017-02-28 09:24 - 2009-02-27 17:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2017-07-02 07:23 - 2017-07-02 07:23 - 00170224 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-07-02 07:23 - 2017-07-02 07:23 - 01038952 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll
2017-07-02 07:23 - 2017-07-02 07:23 - 67109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-07-02 07:23 - 2017-07-02 07:23 - 00192664 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
2017-07-02 07:23 - 2017-07-02 07:23 - 00224256 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2017-07-02 07:23 - 2017-07-02 07:23 - 00292920 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-07-02 07:23 - 2017-07-02 07:25 - 02962096 _____ () C:\Program Files\AVAST Software\Avast\aswDataScan.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\WINDOWS\splwow64.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\aclui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ActionCenter.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ActionCenterCPL.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ActivationManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\adsmsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\aitstatic.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\AppCapture.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\AudioEng.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\AUDIOKSE.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\AudioSrvPolicyManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\autoplay.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\BackgroundMediaPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\bcastdvr.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\BcastDVRHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\bcdedit.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\bcrypt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\bdesvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\bdeui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\bdeunlock.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\BitLockerDeviceEncryption.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\biwinrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\BRCOM13A.DLL:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\BthRadioMedia.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\cdd.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\cdpsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\cdpusersvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\chartv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ClipUp.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\CloudStorageWizard.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\cmifw.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\cmintegrator.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\comdlg32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ConsoleLogon.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\credprovs.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\credprovslegacy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\cryptngc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\d3d10warp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\D3D12.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\d3d9.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\dab.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DataExchange.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\devenum.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DeviceCenter.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DeviceEnroller.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DevicePairingFolder.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DeviceReactivation.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\dialserver.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\discan.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Display.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\dmenrollengine.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DolbyDecMFT.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\domgmt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\drvstore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\dsreg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\dsregcmd.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\dwmapi.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\EAMProgressHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\easwrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\EditBufferTestHook.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\EditionUpgradeHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\EditionUpgradeManagerObj.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\EDPCleanup.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\efsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\EncDec.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\energy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\ErrorDetailsUpdate.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\esent.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\esentutl.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\facecredentialprovider.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Family.Authentication.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ffbroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\fhcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\fhsettingsprovider.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\fontext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\FSClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\fveapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\fveapibase.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\fvenotify.exe:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\fveui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\gdi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\GlobCollationHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\hal.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\HttpsDataSource.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\icsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\IdCtrls.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\InputLocaleManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\iscsiwmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\JpMapControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\KnobsCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\KnobsCsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ListSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\lpremove.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\lsm.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\manage-bde.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MapControlCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MapsBtSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MDMAppInstaller.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mdmregistration.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfaudiocnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfksproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfreadwrite.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfsensorgroup.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\microsoft-windows-system-events.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\migisol.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\moshostcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MosStorage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mprapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mprdim.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MrmCoreR.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MSAC3ENC.DLL:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MSAudDecMFT.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\msdtcprx.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\msdtcuiu.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\msinfo32.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MSVidCtl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MSVideoDSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\msvproc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ncsi.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\netplwiz.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nettrace.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NetworkCollectionAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NetworkDesktopSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NetworkUXBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NfcRadioMedia.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ngccredprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NgcCtnr.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NgcCtnrGidsHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nlasvc.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\nltest.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NMAA.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NotificationController.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NPSM.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ntdll.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\offlinesam.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\offreg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\OnDemandConnRouteHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\OneBackupHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\pcasvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\pdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\poqexec.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\powercfg.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\profsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\provengine.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\provops.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ProvPluginEng.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ProvSysprep.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\PsmServiceExtHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\pwrshplugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\qmgr.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\rasapi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ReAgentc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\remoteaudioendpoint.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\RemoteNaturalLanguage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ReportingCSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\RjvMDMConfig.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\RMapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\rshx32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\RTWorkQ.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\samsrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ScDeviceEnum.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sendmail.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Sens.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SensorService.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SessEnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\setupugc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\shdocvw.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\skci.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\smphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SndVolSSO.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sppcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sppnp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sppsvc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sppwinob.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SRH.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SRHInproc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sspicli.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\StorSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SyncCenter.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\taskbarcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\tdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\timedate.cpl:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\TpmTasks.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\TSpkg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\twinui.pcshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\UIAnimation.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\UIAutomationCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\umpoext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\usbmon.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\user32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\VEStoreEventHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\vmrdvcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\VPNv2CSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wbiosrvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wc_storage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\webio.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\weretw.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wevtsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wifitask.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\win32k.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wincorlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.Vpn.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.StateRepository.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.BioFeedback.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.CredDialogController.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wininetlui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WinSCard.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wkssvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wlancfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wmpdxm.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wmpeffects.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wmpshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WordBreakers.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wow64.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WpcRefreshTask.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WpcTok.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wpnprv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wpx.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\ws2_32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wscinterop.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wscsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wsecedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WSManHTTPConfig.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WsmSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\zipfldr.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\aclui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ActionCenterCPL.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ActivationManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\adsmsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\AppCapture.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\AUDIOKSE.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\AuthExt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\autoplay.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\BackgroundMediaPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\bcrypt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\biwinrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\BRLM03A.DLL:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\BRLMW03A.DLL:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\BROSNMP.DLL:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\BRTCPCON.DLL:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\chartv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ClipboardServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\CloudStorageWizard.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\cmifw.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\comctl32.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\comdlg32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\credprovs.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\credprovslegacy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\cryptngc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\cryptui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\d2d1.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d10warp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\D3D12.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d8.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d9.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\DataExchange.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\devenum.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\DolbyDecMFT.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\drvstore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\dtdump.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\dwmapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\EditBufferTestHook.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\efsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ErrorDetailsUpdate.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\esent.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\esentutl.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\FSClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\gdi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\GlobCollationHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\InputLocaleManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\iscsiwmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\JpMapControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\LicenseManagerApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\MapControlCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\MapsBtSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mdmregistration.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfaudiocnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfksproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfreadwrite.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfsensorgroup.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\migisol.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\MosStorage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mprapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mprdim.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\MrmCoreR.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\MSAC3ENC.DLL:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\msinfo32.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\MSVidCtl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\msvproc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\NetworkCollectionAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ngccredprov.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\NMAA.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\NPSM.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ntdll.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ntshrui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\offlinesam.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\offreg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\pdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\poqexec.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\powercfg.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\pwrshplugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\rasapi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\rdpencom.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ReAgentc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\RTWorkQ.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\sendmail.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\SessEnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\smphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\SndVolSSO.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\sppcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\sspicli.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\stobject.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\systemcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\tdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\TempSignedLicenseExchangeTask.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\TSpkg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\UIAnimation.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\UIAutomationCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\user32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\webio.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\weretw.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\win32k.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wincorlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.StateRepository.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wininetlui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\WinSCard.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wlancfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wmpdxm.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wmpeffects.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wmpshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\WordBreakers.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ws2_32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wscinterop.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wsecedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\WWanAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\xolehlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\zipfldr.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\afd.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\ahcache.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\bowser.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\capimg.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\clfs.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\cmimcext.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\crashdmp.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\fastfat.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\fvevol.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\hidclass.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\http.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\iorate.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\kbdhid.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\MegaSas2i.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\modem.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\mrxdav.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\mrxsmb10.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\pci.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\stornvme.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\tpm.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\vpci.sys:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\wcifs.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\winhvr.sys:$CmdTcID [64]
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [252]
AlternateDataStreams: C:\Users\mel\Desktop\Kids-Handprint-Valentine-Ideas-2-web.jpg:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\11780492_10153442721576168_1188463333_n.jpg:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\5-11-16 St Sheet1.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\attachments (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\attachments.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\BTFE_collectionsheet_50.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\ChasingBoxTops.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\ChristmasCard2015.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\flights-of-fancy-two-doves-platinum-edition.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\mel\Downloads\flights-of-fancy-two-doves-platinum-edition.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\Grandpa-80th-Birthday.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\OpenHouse.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\ParentInformationNightSchedule1516Final.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\PreschoolpressJanuary.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\PublicLibrarySchedule20152016.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\question.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\Releaseadcb874e-e7bc-4c12-808b-54c4dd233363_2194889.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\ShirtRecycling.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\ValentinesDay_EN_25 (1).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\ValentinesDay_EN_25 (2).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\ValentinesDay_EN_25.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\Winter_HatsMittens25_English (1).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\Winter_HatsMittens25_English.pdf:$CmdZnID [26]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\1001movie.com -> 1001movie.com
 
There are 6091 more sites.
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2017-02-27 23:38 - 2017-02-27 23:32 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\System32\oobe\info\backgrounds\backgroundDefault.jpg
DNS Servers: 192.168.3.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TCP Query User{F9431CE8-C002-49B1-BA3A-4DE77D470C1A}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{935489F9-1CF6-4571-BD10-C3A927C9B6AF}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [{8C6E7E33-C35A-4A0A-998E-26029A096CA3}] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [{89B05E2F-4970-43B2-9A0D-F1AADDAA3B04}] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe
 
==================== Restore Points =========================
 
12-06-2017 12:19:52 Windows Update
02-07-2017 19:18:25 Installed TinyWall
 
==================== Faulty Device Manager Devices =============
 
Name: IDT High Definition Audio CODEC
Description: IDT High Definition Audio CODEC
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: IDT
Service: STHDA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/03/2017 12:20:34 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mel-PC)
Description: Activation of app Microsoft.SkypeApp_kzf8qxf38zg5c!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (07/03/2017 12:20:34 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mel-PC)
Description: Activation of app Microsoft.SkypeApp_kzf8qxf38zg5c!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (07/02/2017 07:18:38 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (07/02/2017 07:05:45 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
 
Error: (07/02/2017 06:51:06 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mel-PC)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024865 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (07/02/2017 06:51:05 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mel-PC)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (07/02/2017 06:51:05 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mel-PC)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (07/02/2017 06:51:05 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mel-PC)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (07/02/2017 06:45:26 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW.  hr = 0x80070006, The handle is invalid.
.
 
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Error: (07/02/2017 06:43:32 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary SASKUTIL.
 
System Error:
The system cannot find the file specified.
.
 
 
System errors:
=============
Error: (07/03/2017 03:14:02 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/03/2017 12:38:52 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/03/2017 12:22:15 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/03/2017 12:20:39 PM) (Source: DCOM) (EventID: 10010) (User: mel-PC)
Description: The server {D63B10C5-BB46-4990-A94F-E40B9D520160} did not register with DCOM within the required timeout.
 
Error: (07/03/2017 12:20:34 PM) (Source: DCOM) (EventID: 10010) (User: mel-PC)
Description: The server App.AppX85gcbw533amccd2rr8qswxymhfj649t2.mca did not register with DCOM within the required timeout.
 
Error: (07/03/2017 12:20:34 PM) (Source: DCOM) (EventID: 10010) (User: mel-PC)
Description: The server App.AppXxynx4ymh02h359j0hx8qs9hcm20wrw44.mca did not register with DCOM within the required timeout.
 
Error: (07/03/2017 12:20:16 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error: 
Access is denied.
 
Error: (07/03/2017 12:20:16 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error: 
Access is denied.
 
Error: (07/03/2017 12:18:15 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/03/2017 12:17:09 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: The aswbIDSAgent service did not shut down properly after receiving a preshutdown control.
 
 
CodeIntegrity:
===================================
  Date: 2017-07-02 07:34:09.507
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-07-02 07:33:35.394
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-07-02 07:33:24.189
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-07-02 07:33:23.695
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-05-29 11:33:14.170
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-05-29 11:23:57.472
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-05-29 11:23:43.848
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-05-29 10:12:53.315
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-05-29 10:12:33.247
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-05-29 09:46:34.694
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
Processor: Pentium® Dual-Core CPU T4300 @ 2.10GHz
Percentage of memory in use: 31%
Total physical RAM: 3999.18 MB
Available physical RAM: 2727.15 MB
Total Virtual: 4703.18 MB
Available Virtual: 3441.29 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:219.15 GB) (Free:187.15 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (RECOVERY) (Fixed) (Total:12.72 GB) (Free:2.11 GB) NTFS ==>[system with boot components (obtained from drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 232.9 GB) (Disk ID: 2169E425)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=219.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=836 MB) - (Type=27)
Partition 4: (Not Active) - (Size=12.7 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

  • 0

#110
tl79

tl79

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 186 posts

The battery probably lasts for 2-3 hours at best, depending on what's being run.


  • 0

#111
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

You might want to order a new battery.  I've found several on Amazon at really good prices with good reviews.

 

Comodo did not completely uninstall
 
Download the attached fixlist.txt to the same location as FRST
 
 
Run FRST and press Fix
A fix log will be generated please post that 
 
 
Run FRST again as before.  Make sure Addition.txt is checked and hit Scan.  Post both logs.
 

 

 

 

 


  • 0

#112
tl79

tl79

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 186 posts

Can you give me a specific recommendation on a battery or Amazon link to consider?  I'm pretty sure we bought the battery we're using now from Amazon relatively recently.


  • 0

#113
tl79

tl79

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 186 posts

Here's the fixlog:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 03-07-2017 01
Ran by mel (03-07-2017 15:59:13) Run:2
Running from C:\Users\mel\Desktop
Loaded Profiles: mel (Available Profiles: mel)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CloseProcesses:
HKLM-x32\...\Run: [IseUI] => C:\Program Files (x86)\COMODO\Internet Security Essentials\vkise.exe
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
GroupPolicy: Restriction - Chrome <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\mel\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\mel\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\mel\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll => No File
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
AlternateDataStreams: C:\WINDOWS\splwow64.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\aclui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ActionCenter.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ActionCenterCPL.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ActivationManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\adsmsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\aitstatic.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\AppCapture.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\AudioEng.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\AUDIOKSE.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\AudioSrvPolicyManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\autoplay.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\BackgroundMediaPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\bcastdvr.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\BcastDVRHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\bcdedit.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\bcrypt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\bdesvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\bdeui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\bdeunlock.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\BitLockerDeviceEncryption.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\biwinrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\BRCOM13A.DLL:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\BthRadioMedia.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\cdd.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\cdpsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\cdpusersvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\chartv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ClipUp.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\CloudStorageWizard.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\cmifw.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\cmintegrator.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\comdlg32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ConsoleLogon.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\credprovs.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\credprovslegacy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\cryptngc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\d3d10warp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\D3D12.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\d3d9.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\dab.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DataExchange.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\devenum.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DeviceCenter.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DeviceEnroller.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DevicePairingFolder.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DeviceReactivation.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\dialserver.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\discan.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Display.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\dmenrollengine.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DolbyDecMFT.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\domgmt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\drvstore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\dsreg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\dsregcmd.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\dwmapi.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\EAMProgressHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\easwrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\EditBufferTestHook.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\EditionUpgradeHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\EditionUpgradeManagerObj.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\EDPCleanup.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\efsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\EncDec.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\energy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\ErrorDetailsUpdate.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\esent.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\esentutl.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\facecredentialprovider.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Family.Authentication.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ffbroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\fhcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\fhsettingsprovider.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\fontext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\FSClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\fveapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\fveapibase.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\fvenotify.exe:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\fveui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\gdi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\GlobCollationHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\hal.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\HttpsDataSource.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\icsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\IdCtrls.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\InputLocaleManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\iscsiwmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\JpMapControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\KnobsCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\KnobsCsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ListSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\lpremove.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\lsm.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\manage-bde.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MapControlCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MapsBtSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MDMAppInstaller.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mdmregistration.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfaudiocnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfksproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfreadwrite.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfsensorgroup.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\microsoft-windows-system-events.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\migisol.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\moshostcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MosStorage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mprapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mprdim.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MrmCoreR.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MSAC3ENC.DLL:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MSAudDecMFT.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\msdtcprx.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\msdtcuiu.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\msinfo32.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MSVidCtl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MSVideoDSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\msvproc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ncsi.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\netplwiz.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nettrace.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NetworkCollectionAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NetworkDesktopSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NetworkUXBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NfcRadioMedia.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ngccredprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NgcCtnr.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NgcCtnrGidsHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nlasvc.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\nltest.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NMAA.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NotificationController.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NPSM.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ntdll.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\offlinesam.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\offreg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\OnDemandConnRouteHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\OneBackupHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\pcasvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\pdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\poqexec.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\powercfg.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\profsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\provengine.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\provops.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ProvPluginEng.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ProvSysprep.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\PsmServiceExtHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\pwrshplugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\qmgr.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\rasapi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ReAgentc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\remoteaudioendpoint.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\RemoteNaturalLanguage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ReportingCSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\RjvMDMConfig.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\RMapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\rshx32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\RTWorkQ.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\samsrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ScDeviceEnum.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sendmail.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Sens.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SensorService.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SessEnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\setupugc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\shdocvw.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\skci.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\smphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SndVolSSO.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sppcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sppnp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sppsvc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sppwinob.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SRH.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SRHInproc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sspicli.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\StorSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SyncCenter.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\taskbarcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\tdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\timedate.cpl:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\TpmTasks.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\TSpkg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\twinui.pcshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\UIAnimation.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\UIAutomationCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\umpoext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\usbmon.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\user32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\VEStoreEventHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\vmrdvcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\VPNv2CSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wbiosrvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wc_storage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\webio.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\weretw.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wevtsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wifitask.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\win32k.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wincorlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.Vpn.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.StateRepository.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.BioFeedback.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.CredDialogController.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wininetlui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WinSCard.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wkssvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wlancfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wmpdxm.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wmpeffects.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wmpshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WordBreakers.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wow64.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WpcRefreshTask.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WpcTok.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wpnprv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wpx.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\ws2_32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wscinterop.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wscsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wsecedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WSManHTTPConfig.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WsmSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\zipfldr.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\aclui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ActionCenterCPL.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ActivationManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\adsmsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\AppCapture.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\AUDIOKSE.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\AuthExt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\autoplay.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\BackgroundMediaPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\bcrypt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\biwinrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\BRLM03A.DLL:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\BRLMW03A.DLL:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\BROSNMP.DLL:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\BRTCPCON.DLL:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\chartv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ClipboardServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\CloudStorageWizard.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\cmifw.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\comctl32.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\comdlg32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\credprovs.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\credprovslegacy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\cryptngc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\cryptui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\d2d1.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d10warp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\D3D12.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d8.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d9.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\DataExchange.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\devenum.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\DolbyDecMFT.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\drvstore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\dtdump.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\dwmapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\EditBufferTestHook.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\efsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ErrorDetailsUpdate.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\esent.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\esentutl.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\FSClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\gdi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\GlobCollationHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\InputLocaleManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\iscsiwmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\JpMapControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\LicenseManagerApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\MapControlCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\MapsBtSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mdmregistration.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfaudiocnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfksproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfreadwrite.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfsensorgroup.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\migisol.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\MosStorage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mprapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mprdim.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\MrmCoreR.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\MSAC3ENC.DLL:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\msinfo32.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\MSVidCtl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\msvproc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\NetworkCollectionAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ngccredprov.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\NMAA.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\NPSM.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ntdll.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ntshrui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\offlinesam.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\offreg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\pdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\poqexec.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\powercfg.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\pwrshplugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\rasapi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\rdpencom.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ReAgentc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\RTWorkQ.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\sendmail.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\SessEnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\smphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\SndVolSSO.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\sppcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\sspicli.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\stobject.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\systemcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\tdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\TempSignedLicenseExchangeTask.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\TSpkg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\UIAnimation.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\UIAutomationCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\user32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\webio.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\weretw.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\win32k.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wincorlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.StateRepository.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wininetlui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\WinSCard.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wlancfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wmpdxm.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wmpeffects.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wmpshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\WordBreakers.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ws2_32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wscinterop.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wsecedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\WWanAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\xolehlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\zipfldr.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\afd.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\ahcache.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\bowser.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\capimg.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\clfs.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\cmimcext.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\crashdmp.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\fastfat.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\fvevol.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\hidclass.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\http.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\iorate.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\kbdhid.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\MegaSas2i.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\modem.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\mrxdav.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\mrxsmb10.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\pci.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\stornvme.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\tpm.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\vpci.sys:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\wcifs.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\winhvr.sys:$CmdTcID [64]
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [252]
AlternateDataStreams: C:\Users\mel\Desktop\Kids-Handprint-Valentine-Ideas-2-web.jpg:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\11780492_10153442721576168_1188463333_n.jpg:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\5-11-16 St Sheet1.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\attachments (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\attachments.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\BTFE_collectionsheet_50.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\ChasingBoxTops.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\ChristmasCard2015.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\flights-of-fancy-two-doves-platinum-edition.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\mel\Downloads\flights-of-fancy-two-doves-platinum-edition.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\Grandpa-80th-Birthday.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\OpenHouse.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\ParentInformationNightSchedule1516Final.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\PreschoolpressJanuary.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\PublicLibrarySchedule20152016.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\question.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\Releaseadcb874e-e7bc-4c12-808b-54c4dd233363_2194889.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\ShirtRecycling.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\ValentinesDay_EN_25 (1).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\ValentinesDay_EN_25 (2).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\ValentinesDay_EN_25.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\Winter_HatsMittens25_English (1).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\mel\Downloads\Winter_HatsMittens25_English.pdf:$CmdZnID [26]
C:\Windows\System32\GroupPolicy
C:\Windows\System32\GroupPolicyUsers
C:\Windows\SysWOW64\GroupPolicy
C:\Windows\SysWOW64\GroupPolicyUsers
CMD: gpupdate /force
EmptyTemp:
CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i"
 
 
 
 
*****************
 
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\IseUI => value removed successfully
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION => restored successfully
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKU\S-1-5-21-1930977450-1904899304-3597289394-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E} => key removed successfully
HKU\S-1-5-21-1930977450-1904899304-3597289394-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C} => key removed successfully
HKU\S-1-5-21-1930977450-1904899304-3597289394-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E} => key removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => key removed successfully
HKLM\Software\Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => key not found. 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => key removed successfully
HKLM\Software\Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282} => key not found. 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => key removed successfully
HKLM\Software\Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30} => key not found. 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => key removed successfully
HKLM\Software\Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => key not found. 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => key removed successfully
HKLM\Software\Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => key not found. 
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => key removed successfully
HKLM\Software\Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => key not found. 
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => key removed successfully
HKLM\Software\Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282} => key not found. 
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => key removed successfully
HKLM\Software\Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30} => key not found. 
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => key removed successfully
HKLM\Software\Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => key not found. 
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => key removed successfully
HKLM\Software\Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => key not found. 
C:\WINDOWS\splwow64.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\aclui.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ActionCenter.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ActionCenterCPL.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ActivationManager.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\adsmsext.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\aitstatic.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\AppCapture.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\AudioEng.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\AUDIOKSE.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\AudioSrvPolicyManager.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\autoplay.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\BackgroundMediaPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\bcastdvr.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\BcastDVRHelper.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\bcdedit.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\bcrypt.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\bdesvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\bdeui.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\bdeunlock.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\BitLockerDeviceEncryption.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\biwinrt.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\BRCOM13A.DLL => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\BthRadioMedia.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\cdd.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\cdpsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\cdpusersvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\chartv.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ClipUp.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\CloudStorageWizard.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\cmifw.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\cmintegrator.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\comdlg32.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ConsoleLogon.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\credprovs.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\credprovslegacy.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\cryptngc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\d3d10warp.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\D3D12.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\d3d9.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\dab.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\DataExchange.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\devenum.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\DeviceCenter.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\DeviceEnroller.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\DevicePairingFolder.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\DeviceReactivation.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\dialserver.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\discan.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Display.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\dmenrollengine.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\DolbyDecMFT.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\domgmt.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\drvstore.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\dsreg.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\dsregcmd.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\dwmapi.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\EAMProgressHandler.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\easwrt.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\EditBufferTestHook.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\EditionUpgradeHelper.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\EditionUpgradeManagerObj.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\EDPCleanup.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\efsext.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\EncDec.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\energy.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ErrorDetailsUpdate.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\esent.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\esentutl.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\facecredentialprovider.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Family.Authentication.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ffbroker.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\fhcpl.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\fhsettingsprovider.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\fontext.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\FSClient.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\fveapi.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\fveapibase.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\fvenotify.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\fveui.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\gdi32.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\GlobCollationHost.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\hal.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\HttpsDataSource.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\icsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\IdCtrls.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\InputLocaleManager.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\iscsiwmi.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\JpMapControl.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\KnobsCore.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\KnobsCsp.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ListSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\lpremove.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\lsm.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\manage-bde.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\MapControlCore.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\MapsBtSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\MDMAppInstaller.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\mdmregistration.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\mfaudiocnv.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\mfksproxy.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\mfreadwrite.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\mfsensorgroup.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\microsoft-windows-system-events.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\migisol.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\moshostcore.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\MosStorage.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\mprapi.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\mprdim.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\MrmCoreR.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\MSAC3ENC.DLL => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\MSAudDecMFT.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\msdtcprx.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\msdtcuiu.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\msinfo32.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\MSVidCtl.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\MSVideoDSP.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\msvproc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ncsi.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\netplwiz.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\nettrace.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\NetworkCollectionAgent.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\NetworkDesktopSettings.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\NetworkUXBroker.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\NfcRadioMedia.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ngccredprov.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\NgcCtnr.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\NgcCtnrGidsHandler.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\nlasvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\nltest.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\NMAA.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\NotificationController.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\NPSM.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ntdll.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\offlinesam.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\offreg.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\OnDemandConnRouteHelper.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\OneBackupHandler.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\pcasvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\pdh.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\poqexec.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\powercfg.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\profsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\provengine.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\provops.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ProvPluginEng.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ProvSysprep.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\PsmServiceExtHost.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\pwrshplugin.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\qmgr.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\rasapi32.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ReAgentc.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\remoteaudioendpoint.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\RemoteNaturalLanguage.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ReportingCSP.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\RjvMDMConfig.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\RMapi.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\rshx32.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\RTWorkQ.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\samsrv.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ScDeviceEnum.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\sendmail.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Sens.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\SensorService.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\SessEnv.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\setupugc.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\shdocvw.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\skci.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\smphost.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\SndVolSSO.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\sppcext.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\sppnp.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\sppsvc.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\sppwinob.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\SRH.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\SRHInproc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\sspicli.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\StorSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\SyncCenter.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\taskbarcpl.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\tdh.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\timedate.cpl => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\TpmTasks.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\TSpkg.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\twinui.pcshell.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\UIAnimation.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\UIAutomationCore.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\umpoext.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\usbmon.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\user32.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\VEStoreEventHandlers.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\vmrdvcore.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\VPNv2CSP.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wbiosrvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wc_storage.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\webio.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\weretw.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wevtsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wifitask.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\win32k.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wincorlib.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Windows.Networking.Vpn.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Windows.StateRepository.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Windows.UI.BioFeedback.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Windows.UI.CredDialogController.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wininetlui.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\WinSCard.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wkssvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wlancfg.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wmpdxm.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wmpeffects.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wmpshell.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\WordBreakers.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wow64.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\WpcRefreshTask.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\WpcTok.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wpnprv.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wpx.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\ws2_32.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wscinterop.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wscsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\wsecedit.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\WSManHTTPConfig.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\WsmSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\zipfldr.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\aclui.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\ActionCenterCPL.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\ActivationManager.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\adsmsext.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\AppCapture.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\AUDIOKSE.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\AuthExt.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\autoplay.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\BackgroundMediaPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\bcrypt.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\biwinrt.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\BRLM03A.DLL => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\BRLMW03A.DLL => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\BROSNMP.DLL => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\BRTCPCON.DLL => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\chartv.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\ClipboardServer.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\CloudStorageWizard.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\cmifw.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\comctl32.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\comdlg32.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\credprovs.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\credprovslegacy.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\cryptngc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\cryptui.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\d2d1.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\d3d10warp.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\D3D12.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\d3d8.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\d3d9.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\DataExchange.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\devenum.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\DolbyDecMFT.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\drvstore.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\dtdump.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\dwmapi.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\EditBufferTestHook.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\efsext.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\ErrorDetailsUpdate.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\esent.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\esentutl.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\FSClient.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\gdi32.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\GlobCollationHost.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\InputLocaleManager.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\iscsiwmi.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\JpMapControl.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\LicenseManagerApi.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\MapControlCore.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\MapsBtSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\mdmregistration.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\mfaudiocnv.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\mfksproxy.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\mfreadwrite.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\mfsensorgroup.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\migisol.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\MosStorage.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\mprapi.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\mprdim.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\MrmCoreR.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\MSAC3ENC.DLL => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\msinfo32.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\MSVidCtl.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\msvproc.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\NetworkCollectionAgent.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\ngccredprov.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\NMAA.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\NPSM.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\ntdll.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\ntshrui.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\offlinesam.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\offreg.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\pdh.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\poqexec.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\powercfg.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\pwrshplugin.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\rasapi32.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\rdpencom.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\ReAgentc.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\RTWorkQ.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\sendmail.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\SessEnv.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\smphost.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\SndVolSSO.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\sppcext.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\sspicli.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\stobject.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\systemcpl.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\tdh.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\TempSignedLicenseExchangeTask.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\TSpkg.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\UIAnimation.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\UIAutomationCore.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\user32.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\webio.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\weretw.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\win32k.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\wincorlib.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\Windows.StateRepository.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\wininetlui.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\WinSCard.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\wlancfg.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\wmpdxm.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\wmpeffects.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\wmpshell.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\WordBreakers.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\ws2_32.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\wscinterop.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\wsecedit.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\WWanAPI.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\xolehlp.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\SysWOW64\zipfldr.dll => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\afd.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\ahcache.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\bowser.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\capimg.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\clfs.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\cmimcext.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\crashdmp.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\fastfat.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\fvevol.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\hidclass.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\http.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\iorate.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\kbdhid.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\MegaSas2i.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\modem.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\mrxdav.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\mrxsmb10.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\pci.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\stornvme.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\tpm.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\vpci.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\wcifs.sys => ":$CmdTcID" ADS removed successfully.
C:\WINDOWS\system32\Drivers\winhvr.sys => ":$CmdTcID" ADS removed successfully.
C:\ProgramData\TEMP => ":5C321E34" ADS removed successfully.
C:\Users\mel\Desktop\Kids-Handprint-Valentine-Ideas-2-web.jpg => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\11780492_10153442721576168_1188463333_n.jpg => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\5-11-16 St Sheet1.pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\attachments (1).zip => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\attachments.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\BTFE_collectionsheet_50.pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\ChasingBoxTops.pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\ChristmasCard2015.doc => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\flights-of-fancy-two-doves-platinum-edition.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\mel\Downloads\flights-of-fancy-two-doves-platinum-edition.exe => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\Grandpa-80th-Birthday.docx => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\OpenHouse.docx => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\ParentInformationNightSchedule1516Final.docx => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\PreschoolpressJanuary.doc => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\PublicLibrarySchedule20152016.docx => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\question.pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\Releaseadcb874e-e7bc-4c12-808b-54c4dd233363_2194889.pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\ShirtRecycling.docx => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\ValentinesDay_EN_25 (1).pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\ValentinesDay_EN_25 (2).pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\ValentinesDay_EN_25.pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\Winter_HatsMittens25_English (1).pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\mel\Downloads\Winter_HatsMittens25_English.pdf => ":$CmdZnID" ADS removed successfully.
C:\Windows\System32\GroupPolicy => moved successfully
C:\Windows\System32\GroupPolicyUsers => moved successfully
C:\Windows\SysWOW64\GroupPolicy => moved successfully
C:\Windows\SysWOW64\GroupPolicyUsers => moved successfully
 
========= gpupdate /force =========
 
Updating policy...
 
 
 
Computer Policy update has completed successfully.
 
User Policy update has completed successfully.
 
 
 
 
========= End of CMD: =========
 
 
========= FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i" =========
 
Failed to clear log Microsoft-Windows-LiveId/Analytic. Access is denied.
Failed to clear log Microsoft-Windows-LiveId/Operational. Access is denied.
Failed to clear log Microsoft-Windows-USBVideo/Analytic. The instance name passed was not recognized as valid by a WMI data provider.
 
========= End of CMD: =========
 
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 14778787 B
Java, Flash, Steam htmlcache => 291 B
Windows/system/drivers => 3338 B
Edge => 0 B
Chrome => 86661821 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 4922 B
NetworkService => 1296 B
mel => 181497507 B
DefaultAppPool => 0 B
 
RecycleBin => 0 B
EmptyTemp: => 269.8 MB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 16:07:46 ====

  • 0

#114
tl79

tl79

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 186 posts

Results of FRST scan:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03-07-2017 01
Ran by mel (administrator) on MEL-PC (03-07-2017 16:29:20)
Running from C:\Users\mel\Desktop
Loaded Profiles: mel (Available Profiles: mel)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-03-23] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3954352 2016-03-30] (Synaptics Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213832 2017-07-02] (AVAST Software)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2014-06-16] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4513792 2014-05-22] (Brother Industries, Ltd.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.3.254
Tcpip\..\Interfaces\{29154919-1dc2-434c-be91-1bc9b23aa427}: [DhcpNameServer] 192.168.3.254
Tcpip\..\Interfaces\{9eda8ba8-f1ef-4784-84ba-c98324db86dd}: [DhcpNameServer] 192.168.3.254
 
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
 
Edge: 
======
Edge HomeButtonPage: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001 -> hxxp://www.google.com/
 
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Profile: C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default [2017-07-03]
CHR Extension: (Google Slides) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-02-27]
CHR Extension: (Google Docs) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-27]
CHR Extension: (Google Drive) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-02-27]
CHR Extension: (YouTube) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-27]
CHR Extension: (uBlock) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\epcnnfbjfcgphgdmggkamkmgojdagdnn [2017-07-02]
CHR Extension: (Google Sheets) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-02-27]
CHR Extension: (Google Docs Offline) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-02-27]
CHR Extension: (F.B.(FluffBusting)Purity) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmkinhboiljjkhaknpaeaicmdjhagpep [2017-07-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08]
CHR Extension: (Gmail) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-27]
CHR Extension: (Chrome Media Router) - C:\Users\mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-17]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AESTFilters; C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7430992 2017-07-02] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263312 2017-07-02] (AVAST Software)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2013-09-25] (Brother Industries, Ltd.) [File not signed]
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
S2 STacSV; C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\STacSV64.exe [247808 2010-03-23] (IDT, Inc.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [253960 2016-03-30] (Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-27] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [319984 2017-07-02] (AVAST Software s.r.o.)
R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [198944 2017-07-02] (AVAST Software s.r.o.)
R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [343264 2017-07-02] (AVAST Software s.r.o.)
R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [57704 2017-07-02] (AVAST Software s.r.o.)
S3 aswHdsKe; C:\WINDOWS\system32\drivers\aswHdsKe.sys [85552 2017-02-27] (AVAST Software)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [46984 2017-07-02] (AVAST Software)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [41800 2017-07-02] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [146664 2017-07-02] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [110352 2017-07-02] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [84392 2017-07-02] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1015848 2017-07-02] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [585608 2017-07-02] (AVAST Software)
R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [198768 2017-07-02] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [361336 2017-07-02] (AVAST Software)
R3 BCM43XX; C:\WINDOWS\System32\drivers\bcmwl63al.sys [5170176 2016-07-16] (Broadcom Corporation)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [251848 2017-07-03] (Malwarebytes)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [52400 2016-03-30] (Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [52904 2016-03-30] (Synaptics Incorporated)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-07-03 16:29 - 2017-07-03 16:30 - 00009377 _____ C:\Users\mel\Desktop\FRST.txt
2017-07-03 15:27 - 2017-07-03 15:27 - 00000000 ____D C:\Users\mel\AppData\Roaming\Macromedia
2017-07-03 15:15 - 2017-07-03 15:15 - 00000000 ____D C:\Users\mel\Desktop\FRST-OlderVersion
2017-07-03 11:54 - 2017-07-03 15:30 - 00021232 _____ (Thesycon GmbH) C:\WINDOWS\system32\Drivers\dpclat_driver.sys
2017-07-03 11:53 - 2017-07-03 15:30 - 00000980 _____ C:\Users\mel\Desktop\dpclat.exe - Shortcut.lnk
2017-07-03 11:50 - 2017-07-03 11:50 - 00306928 _____ (Thesycon GmbH) C:\Users\mel\Downloads\dpclat.exe
2017-07-03 09:25 - 2017-07-03 16:07 - 00000000 ____D C:\Users\mel\AppData\LocalLow\Temp
2017-07-03 09:25 - 2017-07-03 09:25 - 00164748 _____ C:\Users\mel\Desktop\apps removed feb 27 2017.pdf
2017-07-02 20:13 - 2017-07-02 20:13 - 00000000 ___SD C:\WINDOWS\UpdateAssistantV2
2017-07-02 19:34 - 2017-06-03 05:50 - 00315744 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-07-02 19:34 - 2017-06-03 05:16 - 00279904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-07-02 19:34 - 2017-06-03 05:11 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-07-02 19:34 - 2017-06-03 05:09 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-07-02 19:34 - 2017-06-03 05:06 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-07-02 19:34 - 2017-06-03 04:59 - 01181024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2017-07-02 19:34 - 2017-06-03 04:59 - 00118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-07-02 19:34 - 2017-06-03 04:58 - 00340832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-07-02 19:34 - 2017-06-03 04:55 - 00780640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-07-02 19:34 - 2017-06-03 04:54 - 00187232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-07-02 19:34 - 2017-06-03 04:52 - 01021784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2017-07-02 19:34 - 2017-06-03 04:52 - 00607072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2017-07-02 19:34 - 2017-06-03 04:52 - 00111968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2017-07-02 19:34 - 2017-06-03 04:50 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-07-02 19:34 - 2017-06-03 04:50 - 00381792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-07-02 19:34 - 2017-06-03 04:49 - 20967840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-07-02 19:34 - 2017-06-03 04:48 - 00857952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2017-07-02 19:34 - 2017-06-03 04:48 - 00148832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2017-07-02 19:34 - 2017-06-03 04:45 - 22220864 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-07-02 19:34 - 2017-06-03 04:44 - 01412640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-07-02 19:34 - 2017-06-03 04:44 - 00545944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-07-02 19:34 - 2017-06-03 04:39 - 05686272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-07-02 19:34 - 2017-06-03 04:39 - 02532192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-07-02 19:34 - 2017-06-03 04:33 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-07-02 19:34 - 2017-06-03 04:32 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-07-02 19:34 - 2017-06-03 04:31 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2017-07-02 19:34 - 2017-06-03 04:31 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-07-02 19:34 - 2017-06-03 04:28 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-07-02 19:34 - 2017-06-03 04:28 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edputil.dll
2017-07-02 19:34 - 2017-06-03 04:26 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-07-02 19:34 - 2017-06-03 04:26 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBrokerUI.dll
2017-07-02 19:34 - 2017-06-03 04:22 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2017-07-02 19:34 - 2017-06-03 04:22 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcorehc.dll
2017-07-02 19:34 - 2017-06-03 04:22 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
2017-07-02 19:34 - 2017-06-03 04:20 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2017-07-02 19:34 - 2017-06-03 04:19 - 01164288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certutil.exe
2017-07-02 19:34 - 2017-06-03 04:16 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2017-07-02 19:34 - 2017-06-03 04:16 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-07-02 19:34 - 2017-06-03 04:15 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-07-02 19:34 - 2017-06-03 04:15 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-07-02 19:34 - 2017-06-03 04:15 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-07-02 19:34 - 2017-06-03 04:14 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-07-02 19:34 - 2017-06-03 04:14 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-07-02 19:34 - 2017-06-03 04:14 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-07-02 19:34 - 2017-06-03 04:12 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdProxy.dll
2017-07-02 19:34 - 2017-06-03 04:08 - 02643968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-07-02 19:34 - 2017-06-03 04:08 - 01221120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2017-07-02 19:34 - 2017-06-03 04:07 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-07-02 19:34 - 2017-06-03 04:07 - 00456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2017-07-02 19:34 - 2017-06-03 04:05 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2017-07-02 19:34 - 2017-06-03 04:05 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hnetcfg.dll
2017-07-02 19:34 - 2017-06-03 04:04 - 02006528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-07-02 19:34 - 2017-06-03 04:04 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-07-02 19:34 - 2017-06-03 04:03 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-07-02 19:34 - 2017-06-03 04:02 - 02997760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-07-02 19:34 - 2017-06-03 03:54 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-07-02 19:34 - 2017-06-03 03:52 - 03403264 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-07-02 19:34 - 2017-06-03 03:51 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2017-07-02 19:34 - 2017-06-03 03:50 - 02538496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-07-02 19:34 - 2017-06-03 03:49 - 00903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-07-02 19:34 - 2017-06-03 03:48 - 01131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-07-02 19:34 - 2017-06-03 03:48 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-07-02 19:34 - 2017-06-03 03:48 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-07-02 19:34 - 2017-06-03 03:40 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-07-02 19:34 - 2017-05-25 00:56 - 00038752 _____ (Microsoft Corporation) C:\WINDOWS\system32\OOBEUpdater.exe
2017-07-02 19:34 - 2017-03-04 01:16 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2017-07-02 19:34 - 2017-03-04 01:16 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2017-07-02 19:34 - 2016-09-06 23:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2017-07-02 19:33 - 2017-06-03 05:50 - 00192856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 01564512 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 01214816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00629088 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00544096 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00334176 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00233824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00136024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2017-07-02 19:33 - 2017-06-03 05:14 - 00096608 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-07-02 19:33 - 2017-06-03 05:14 - 00034648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-07-02 19:33 - 2017-06-03 05:11 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-07-02 19:33 - 2017-06-03 05:08 - 07783256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-07-02 19:33 - 2017-06-03 05:01 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-07-02 19:33 - 2017-06-03 04:59 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-07-02 19:33 - 2017-06-03 04:53 - 00404824 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-07-02 19:33 - 2017-06-03 04:51 - 02187104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-07-02 19:33 - 2017-06-03 04:51 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-07-02 19:33 - 2017-06-03 04:49 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-07-02 19:33 - 2017-06-03 04:49 - 00509280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-07-02 19:33 - 2017-06-03 04:48 - 01112416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2017-07-02 19:33 - 2017-06-03 04:48 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-07-02 19:33 - 2017-06-03 04:48 - 00989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-07-02 19:33 - 2017-06-03 04:44 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-07-02 19:33 - 2017-06-03 04:40 - 01566552 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-07-02 19:33 - 2017-06-03 04:40 - 00628552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-07-02 19:33 - 2017-06-03 04:39 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-07-02 19:33 - 2017-06-03 04:23 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-07-02 19:33 - 2017-06-03 04:22 - 07217152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-07-02 19:33 - 2017-06-03 04:18 - 22569984 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-07-02 19:33 - 2017-06-03 04:16 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-07-02 19:33 - 2017-06-03 04:15 - 19414016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-07-02 19:33 - 2017-06-03 04:15 - 18364928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-07-02 19:33 - 2017-06-03 04:14 - 00045056 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-07-02 19:33 - 2017-06-03 04:11 - 00353792 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2017-07-02 19:33 - 2017-06-03 04:10 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-07-02 19:33 - 2017-06-03 04:10 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll
2017-07-02 19:33 - 2017-06-03 04:10 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBrokerUI.dll
2017-07-02 19:33 - 2017-06-03 04:09 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2017-07-02 19:33 - 2017-06-03 04:09 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcorehc.dll
2017-07-02 19:33 - 2017-06-03 04:09 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2017-07-02 19:33 - 2017-06-03 04:08 - 12187648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-07-02 19:33 - 2017-06-03 04:08 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-07-02 19:33 - 2017-06-03 04:08 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-07-02 19:33 - 2017-06-03 04:08 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-07-02 19:33 - 2017-06-03 04:07 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\HNetCfgClient.dll
2017-07-02 19:33 - 2017-06-03 04:06 - 03664384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-07-02 19:33 - 2017-06-03 04:06 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2017-07-02 19:33 - 2017-06-03 04:04 - 06042624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-07-02 19:33 - 2017-06-03 04:03 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2017-07-02 19:33 - 2017-06-03 04:01 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2017-07-02 19:33 - 2017-06-03 04:00 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-07-02 19:33 - 2017-06-03 03:58 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll
2017-07-02 19:33 - 2017-06-03 03:56 - 13091840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-07-02 19:33 - 2017-06-03 03:53 - 08125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-07-02 19:33 - 2017-06-03 03:52 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-07-02 19:33 - 2017-06-03 03:52 - 00975872 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-07-02 19:33 - 2017-06-03 03:52 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2017-07-02 19:33 - 2017-06-03 03:51 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\certutil.exe
2017-07-02 19:33 - 2017-06-03 03:50 - 04744704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-07-02 19:33 - 2017-06-03 03:49 - 03615744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-07-02 19:33 - 2017-06-03 03:49 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-07-02 19:33 - 2017-06-03 03:49 - 02475520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-07-02 19:33 - 2017-06-03 03:49 - 02318848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-07-02 19:33 - 2017-06-03 03:49 - 01845248 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-07-02 19:33 - 2017-06-03 03:49 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-07-02 19:33 - 2017-06-03 03:49 - 00351744 _____ (Microsoft Corporation) C:\WINDOWS\system32\hnetcfg.dll
2017-07-02 19:33 - 2017-06-03 03:48 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-07-02 19:33 - 2017-06-03 03:46 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-07-02 19:33 - 2017-06-03 01:08 - 00080078 _____ C:\WINDOWS\system32\normidna.nls
2017-07-02 19:33 - 2017-03-04 01:22 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-07-02 19:33 - 2017-03-04 01:19 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2017-07-02 19:28 - 2017-07-02 19:28 - 00007130 _____ C:\junk.txt
2017-07-02 19:19 - 2017-07-03 10:22 - 00000878 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
2017-07-02 19:19 - 2017-07-03 10:22 - 00000000 ____D C:\ProgramData\TinyWall
2017-07-02 19:19 - 2017-07-03 10:22 - 00000000 ____D C:\Program Files (x86)\TinyWall
2017-07-02 19:05 - 2017-07-02 19:05 - 00000837 _____ C:\Users\Public\Desktop\Speccy.lnk
2017-07-02 19:05 - 2017-07-02 19:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2017-07-02 19:05 - 2017-07-02 19:05 - 00000000 ____D C:\Program Files\Speccy
2017-07-02 19:03 - 2017-07-02 19:04 - 06293184 _____ (Piriform Ltd) C:\Users\mel\Desktop\spsetup130.exe
2017-07-02 18:53 - 2017-07-03 14:27 - 00041800 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2017-07-02 18:51 - 2017-07-02 18:53 - 02724512 _____ (Sysinternals - www.sysinternals.com) C:\Users\mel\Desktop\procexp.exe
2017-07-02 18:45 - 2017-07-02 18:45 - 00000000 _____ C:\WINDOWS\System32\Tasks\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}
2017-07-02 08:06 - 2017-07-03 15:15 - 02436096 _____ (Farbar) C:\Users\mel\Desktop\FRST64.exe
2017-07-02 07:25 - 2017-07-02 07:25 - 00061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys
2017-07-02 07:24 - 2017-07-02 07:24 - 00400464 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2017-07-02 07:11 - 2017-07-02 07:12 - 00000000 ____D C:\speedy fox
2017-07-02 07:11 - 2017-07-02 07:11 - 00000000 ____D C:\Users\mel\AppData\Roaming\CrystalIdea Software
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-07-03 16:29 - 2015-12-08 12:23 - 00000000 ____D C:\FRST
2017-07-03 16:25 - 2017-02-27 22:02 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-07-03 16:15 - 2017-02-27 22:22 - 01349618 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-07-03 16:09 - 2017-02-27 22:03 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-07-03 16:08 - 2017-02-27 23:07 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-07-03 16:03 - 2017-02-27 23:11 - 00000008 __RSH C:\ProgramData\ntuser.pol
2017-07-03 15:31 - 2017-02-27 22:16 - 00000000 ____D C:\Users\mel
2017-07-03 15:24 - 2014-04-28 19:07 - 00000000 ___RD C:\Users\mel\Desktop\UTILITIES
2017-07-03 14:38 - 2017-02-27 23:37 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-07-03 14:38 - 2017-02-27 22:27 - 00000000 ____D C:\Users\mel\AppData\Local\Packages
2017-07-03 14:37 - 2017-02-27 23:37 - 00000000 ___HD C:\Program Files\WindowsApps
2017-07-03 14:12 - 2017-02-27 23:37 - 00000000 ____D C:\WINDOWS\rescache
2017-07-03 12:48 - 2017-05-29 09:06 - 00000000 ____D C:\Users\mel\AppData\Local\ElevatedDiagnostics
2017-07-03 11:49 - 2017-02-27 23:11 - 00000000 ____D C:\ProgramData\TEMP
2017-07-03 11:47 - 2017-02-27 23:17 - 00251848 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-07-03 10:23 - 2017-02-27 23:07 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-07-03 10:21 - 2017-02-27 23:38 - 00004146 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{92C4C726-4C71-4BC2-9477-83D9F5AA6E47}
2017-07-03 09:30 - 2017-02-27 23:37 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-07-03 09:16 - 2017-02-27 23:35 - 00000000 ____D C:\WINDOWS\INF
2017-07-03 07:34 - 2016-02-13 08:20 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-07-03 07:32 - 2017-02-27 22:01 - 00268936 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-07-02 20:13 - 2017-02-27 23:37 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-07-02 20:13 - 2017-02-27 23:37 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-07-02 20:13 - 2017-02-27 23:37 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-07-02 20:00 - 2017-03-02 19:30 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-07-02 19:57 - 2017-03-02 19:28 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-07-02 19:57 - 2017-02-27 23:16 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-07-02 07:43 - 2017-03-05 18:30 - 00000000 ____D C:\Users\mel\AppData\Local\CrashDumps
2017-07-02 07:35 - 2017-01-23 12:29 - 00000000 ____D C:\DAD 2017
2017-07-02 07:33 - 2017-02-27 22:59 - 00004004 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1488254368
2017-07-02 07:32 - 2017-02-27 22:59 - 00001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-07-02 07:25 - 2017-02-27 22:56 - 00361336 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswvmm.sys
2017-07-02 07:24 - 2017-02-27 22:56 - 00585608 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2017-07-02 07:24 - 2017-02-27 22:56 - 00360792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswvmm.sys.149899832379606
2017-07-02 07:24 - 2017-02-27 22:56 - 00198768 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2017-07-02 07:24 - 2017-02-27 22:56 - 00146664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2017-07-02 07:24 - 2017-02-27 22:56 - 00110352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2017-07-02 07:24 - 2017-02-27 22:56 - 00084392 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2017-07-02 07:24 - 2017-02-27 22:56 - 00046984 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2017-07-02 07:24 - 2017-02-27 22:56 - 00003994 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2017-07-02 07:24 - 2017-02-27 22:52 - 00000000 ____D C:\ProgramData\AVAST Software
2017-07-02 07:23 - 2017-02-27 22:58 - 00041800 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2017-07-02 07:23 - 2017-02-27 22:56 - 01015848 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2017-07-02 07:23 - 2017-02-27 22:56 - 00343264 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys
2017-07-02 07:23 - 2017-02-27 22:56 - 00319984 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2017-07-02 07:23 - 2017-02-27 22:56 - 00198944 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2017-07-02 07:23 - 2017-02-27 22:56 - 00057704 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2017-07-02 07:15 - 2017-05-29 19:02 - 00000000 ____D C:\Program Files (x86)\OSTotoSoft
2017-06-27 20:54 - 2017-02-27 22:48 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-06-27 20:54 - 2017-02-27 22:48 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-06-03 01:36 - 2017-02-27 23:40 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-06-03 01:36 - 2017-02-27 23:40 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
 
==================== Files in the root of some directories =======
 
2017-06-01 15:07 - 2017-06-01 15:07 - 0000017 _____ () C:\Users\mel\AppData\Local\resmon.resmoncfg
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-07-02 20:04
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-07-2017 01
Ran by mel (03-07-2017 16:30:50)
Running from C:\Users\mel\Desktop
Windows 10 Home Version 1607 (X64) (2017-02-28 03:26:47)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1930977450-1904899304-3597289394-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1930977450-1904899304-3597289394-503 - Limited - Disabled)
Guest (S-1-5-21-1930977450-1904899304-3597289394-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1930977450-1904899304-3597289394-1002 - Limited - Enabled)
mel (S-1-5-21-1930977450-1904899304-3597289394-1001 - Administrator - Enabled) => C:\Users\mel
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.5.2302 - AVAST Software)
Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.60.18.12 - Broadcom Corporation)
Brother MFL-Pro Suite MFC-L2740DW series (HKLM-x32\...\{F8ECC2FD-CE2B-4ED4-BDCC-90D0D34206FD}) (Version: 1.0.2.0 - Brother Industries, Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
LibreOffice 5.3.0.3 (HKLM\...\{769A4A4C-3EBD-4469-B13B-5083F1C7717F}) (Version: 5.3.0.3 - The Document Foundation)
LSI HDA Modem (HKLM\...\LSI Soft Modem) (Version: 2.1.94 - LSI Corporation)
Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
SafeZone Stable 3.55.2393.609 (HKLM-x32\...\SafeZone 3.55.2393.609) (Version: 3.55.2393.609 - Avast Software) Hidden
Speccy (HKLM\...\Speccy) (Version: 1.30 - Piriform)
SpywareBlaster 5.5 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.5.0 - BrightFort LLC)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.12.98 - Synaptics Incorporated)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
ContextMenuHandlers01: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
ContextMenuHandlers03: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
ContextMenuHandlers06: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {1BE5BF59-52DE-4E97-AB08-6AC206337510} - System32\Tasks\SafeZone scheduled Autoupdate 1488254368 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-06-13] (Avast Software)
Task: {27371DC3-A84E-4762-9584-A388400AC5FF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated)
Task: {8037B55F-49A9-4731-BF15-26E1A7BDC233} - System32\Tasks\{31DDBD37-5DB7-4030-8064-10B0CAA806C3} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
Task: {A0F10D3D-5045-4202-B13A-1DF935756E8A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-27] (Google Inc.)
Task: {BDBAF97D-ED50-4F49-927D-5739115BEBBC} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-04-13] (AVAST Software)
Task: {C9410398-AFA3-47E2-9CAC-0CF88EBA4296} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-07-02] (AVAST Software)
Task: {F6748E67-7309-440F-B68E-B959A8210AD3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-27] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-07-16 06:42 - 2016-07-16 06:42 - 00231424 ____N () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-07-02 19:33 - 2017-06-03 05:01 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2017-02-28 09:24 - 2005-04-21 23:36 - 00143360 _____ () C:\WINDOWS\system32\BrSNMP64.dll
2016-09-18 16:34 - 2016-09-18 16:34 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-03-14 19:16 - 2017-03-04 01:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-03-14 19:18 - 2017-03-04 01:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-03-14 19:18 - 2017-03-04 01:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-03-14 19:18 - 2017-03-04 01:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-07-02 19:33 - 2017-06-03 03:47 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-07-02 19:33 - 2017-06-03 03:47 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-07-02 19:33 - 2017-06-03 03:51 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2017-07-02 07:23 - 2017-07-02 07:23 - 00170224 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-07-02 07:23 - 2017-07-02 07:23 - 01038952 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll
2017-07-02 07:23 - 2017-07-02 07:23 - 67109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-07-02 07:23 - 2017-07-02 07:23 - 00192664 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
2017-07-02 07:23 - 2017-07-02 07:23 - 00224256 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2017-07-02 07:23 - 2017-07-02 07:23 - 00292920 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-07-02 07:23 - 2017-07-02 07:25 - 02962096 _____ () C:\Program Files\AVAST Software\Avast\aswDataScan.dll
2017-07-02 07:23 - 2017-07-02 07:23 - 00689272 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2017-02-28 09:24 - 2009-02-27 17:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\...\1001movie.com -> 1001movie.com
 
There are 6091 more sites.
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2017-02-27 23:38 - 2017-02-27 23:32 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1930977450-1904899304-3597289394-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\System32\oobe\info\backgrounds\backgroundDefault.jpg
DNS Servers: 192.168.3.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TCP Query User{F9431CE8-C002-49B1-BA3A-4DE77D470C1A}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{935489F9-1CF6-4571-BD10-C3A927C9B6AF}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [{8C6E7E33-C35A-4A0A-998E-26029A096CA3}] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [{89B05E2F-4970-43B2-9A0D-F1AADDAA3B04}] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe
 
==================== Restore Points =========================
 
12-06-2017 12:19:52 Windows Update
02-07-2017 19:18:25 Installed TinyWall
 
==================== Faulty Device Manager Devices =============
 
Name: IDT High Definition Audio CODEC
Description: IDT High Definition Audio CODEC
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: IDT
Service: STHDA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
 
System errors:
=============
Error: (07/03/2017 04:09:26 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/03/2017 04:08:12 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll
 
Error: (07/03/2017 04:08:12 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll
 
Error: (07/03/2017 04:08:03 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll
 
 
==================== Memory info =========================== 
 
Processor: Pentium® Dual-Core CPU T4300 @ 2.10GHz
Percentage of memory in use: 32%
Total physical RAM: 3999.18 MB
Available physical RAM: 2716.34 MB
Total Virtual: 4703.18 MB
Available Virtual: 3507.58 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:219.15 GB) (Free:187.32 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (RECOVERY) (Fixed) (Total:12.72 GB) (Free:2.11 GB) NTFS ==>[system with boot components (obtained from drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 232.9 GB) (Disk ID: 2169E425)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=219.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=836 MB) - (Type=27)
Partition 4: (Not Active) - (Size=12.7 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

  • 0

#115
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

I missed one

 

Task: {8037B55F-49A9-4731-BF15-26E1A7BDC233} - System32\Tasks\{31DDBD37-5DB7-4030-8064-10B0CAA806C3} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe

 

Search for

 

task scheduler

 

hit Enter

 

Click on Task Scheduler Library

 

In the pane to the right find

 

8037B55F-49A9-4731-BF15-26E1A7BDC233

or

31DDBD37-5DB7-4030-8064-10B0CAA806C3

 

right click on it and Delete or Disable

 

Close Task Scheduler

 

Give me the make & model number of the laptop and I will look for a battery.

 

 

In the Search box type:  dxdiag 
 
wait for it to find it.  Right click on dxdiag.exe and Run As Admin.
Since  you have a 64 bit system then click on Run 64 bit DxDiag.
Once it finishes (green line in bottom left goes away)
 
Save All Information.  Point it at your desktop and it should save it as dxdiag.txt.
 
Exit
 
Double click on dxdiag.txt and copy and paste the text into a reply.

  • 0

Advertisements


#116
tl79

tl79

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 186 posts

Laptop is HP dv6-1334US

 

Dxdiag.txt:

 

------------------
System Information
------------------
      Time of this report: 7/3/2017, 17:02:08
             Machine name: MEL-PC
               Machine Id: {8D47C707-0E3B-4556-9361-36A90307EFE1}
         Operating System: Windows 10 Home 64-bit (10.0, Build 14393) (14393.rs1_release.170602-2252)
                 Language: English (Regional Setting: English)
      System Manufacturer: Hewlett-Packard
             System Model: HP Pavilion dv6 Notebook PC
                     BIOS: Default System BIOS
                Processor: Pentium® Dual-Core CPU       T4300  @ 2.10GHz (2 CPUs), ~2.1GHz
                   Memory: 4096MB RAM
      Available OS Memory: 4000MB RAM
                Page File: 1740MB used, 2962MB available
              Windows Dir: C:\WINDOWS
          DirectX Version: DirectX 12
      DX Setup Parameters: Not found
         User DPI Setting: Using System DPI
       System DPI Setting: 96 DPI (100 percent)
          DWM DPI Scaling: Disabled
                 Miracast: Not Available
Microsoft Graphics Hybrid: Not Supported
           DxDiag Version: 10.00.14393.0000 64bit Unicode
 
------------
DxDiag Notes
------------
      Display Tab 1: No problems found.
        Sound Tab 1: No sound card was found.  If one is expected, you should install a sound driver provided by the hardware manufacturer.
          Input Tab: No problems found.
 
--------------------
DirectX Debug Levels
--------------------
Direct3D:    0/4 (retail)
DirectDraw:  0/4 (retail)
DirectInput: 0/5 (retail)
DirectMusic: 0/5 (retail)
DirectPlay:  0/9 (retail)
DirectSound: 0/5 (retail)
DirectShow:  0/6 (retail)
 
---------------
Display Devices
---------------
          Card name: Mobile Intel® 4 Series Express Chipset Family (Microsoft Corporation - WDDM 1.1)
       Manufacturer: Intel Corporation
          Chip type: Mobile Intel® 4 Series Express Chipset Family
           DAC type: Internal
        Device Type: Full Device
         Device Key: Enum\PCI\VEN_8086&DEV_2A42&SUBSYS_3627103C&REV_07
      Device Status: 0180200A [DN_DRIVER_LOADED|DN_STARTED|DN_DISABLEABLE|DN_NT_ENUMERATOR|DN_NT_DRIVER] 
Device Problem Code: No Problem
Driver Problem Code: Unknown
     Display Memory: 1695 MB
   Dedicated Memory: 64 MB
      Shared Memory: 1631 MB
       Current Mode: 1366 x 768 (32 bit) (60Hz)
       Monitor Name: Generic PnP Monitor
      Monitor Model: LP156WH2-TLQ1
         Monitor Id: LGD021B
        Native Mode: 1366 x 768(p) (59.636Hz)
        Output Type: Internal
        Driver Name: igdumd64.dll,igd10umd64.dll
Driver File Version: 8.15.0010.2702 (English)
     Driver Version: 8.15.10.2702
        DDI Version: 10
     Feature Levels: 10_0,9_1
       Driver Model: WDDM 1.1
Graphics Preemption: DMA
 Compute Preemption: DMA
           Miracast: Not Supported
Hybrid Graphics GPU: Not Applicable
     Power P-states: Not Applicable
  Driver Attributes: Final Retail
   Driver Date/Size: 3/10/2013 7:00:00 PM, 6593816 bytes
        WHQL Logo'd: n/a
    WHQL Date Stamp: n/a
  Device Identifier: {D7B78E66-6902-11CF-0279-2D16A7C2C535}
          Vendor ID: 0x8086
          Device ID: 0x2A42
          SubSys ID: 0x3627103C
        Revision ID: 0x0007
 Driver Strong Name: oem26.inf:5f63e5348ad1f097:iCNT0:8.15.10.2702:pci\ven_8086&dev_2a42
     Rank Of Driver: 00EC2001
        Video Accel: ModeMPEG2_A ModeMPEG2_C ModeWMV9_B ModeWMV9_C ModeVC1_B ModeVC1_C 
        DXVA2 Modes: DXVA2_ModeMPEG2_VLD  DXVA2_ModeMPEG2_IDCT  DXVA2_ModeMPEG2_MOCOMP  DXVA2_ModeWMV9_MoComp  DXVA2_ModeWMV9_IDCT  DXVA2_ModeVC1_MoComp  DXVA2_ModeVC1_IDCT  
   Deinterlace Caps: {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
                     {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
                     {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
                     {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
                     {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
                     {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
                     {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
                     {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
       D3D9 Overlay: Supported
            DXVA-HD: Supported
       DDraw Status: Enabled
         D3D Status: Enabled
         AGP Status: Enabled
           MPO Caps: Not Supported
        MPO Stretch: Not Supported
    MPO Media Hints: Not Supported
        MPO Formats: Not Supported
 
-------------
Sound Devices
-------------
            Description: 
 Default Sound Playback: No
 Default Voice Playback: No
            Hardware ID: 
        Manufacturer ID: 
             Product ID: 
                   Type: 
            Driver Name: 
         Driver Version: 
      Driver Attributes: 
            WHQL Logo'd: 
          Date and Size: 
            Other Files: 
        Driver Provider: 
         HW Accel Level: Emulation Only
              Cap Flags: 0x0
    Min/Max Sample Rate: 0, 0
Static/Strm HW Mix Bufs: 0, 0
 Static/Strm HW 3D Bufs: 0, 0
              HW Memory: 0
       Voice Management: No
 EAX™ 2.0 Listen/Src: No, No
   I3DL2™ Listen/Src: No, No
Sensaura™ ZoomFX™: No
 
---------------------
Sound Capture Devices
---------------------
---------------------
Video Capture Devices
Number of Devices: 1
---------------------
           FriendlyName: HP Webcam
               Location: n/a
           SymbolicLink: \\?\usb#vid_0408&pid_03f1&mi_00#6&295051be&0&0000#{e5323777-f976-4f5b-9b55-b94699c46e44}\global
           Manufacturer: Microsoft
             HardwareID: USB\VID_0408&PID_03F1&REV_0104&MI_00,USB\VID_0408&PID_03F1&MI_00
             DriverDesc: USB Video Device
         DriverProvider: Microsoft
          DriverVersion: 10.0.14393.82
      DriverDateEnglish: 6/21/2006 00:00:00
    DriverDateLocalized: 6/21/2006 12:00:00 AM
                Service: usbvideo
                  Class: Image
          DevNodeStatus: 180200A[DN_DRIVER_LOADED|DN_STARTED|DN_DISABLEABLE|DN_NT_ENUMERATOR|DN_NT_DRIVER]
            ContainerId: {00000000-0000-0000-FFFF-FFFFFFFFFFFF}
            ProblemCode: No Problem
  BusReportedDeviceDesc: HP Webcam
                 Parent: USB\VID_0408&PID_03F1\5&1950ad25&0&4
      DriverProblemDesc: n/a
           UpperFilters: n/a
           LowerFilters: n/a
                  Stack: \Driver\ksthunk,\Driver\usbvideo,\Driver\usbccgp
      ContainerCategory: Imaging
 
-------------------
DirectInput Devices
-------------------
      Device Name: Mouse
         Attached: 1
    Controller ID: n/a
Vendor/Product ID: n/a
        FF Driver: n/a
 
      Device Name: Keyboard
         Attached: 1
    Controller ID: n/a
Vendor/Product ID: n/a
        FF Driver: n/a
 
      Device Name: Microsoft eHome Infrared Transceiver
         Attached: 1
    Controller ID: 0x0
Vendor/Product ID: 0x045E, 0x006D
        FF Driver: n/a
 
      Device Name: Microsoft eHome Infrared Transceiver
         Attached: 1
    Controller ID: 0x0
Vendor/Product ID: 0x045E, 0x006D
        FF Driver: n/a
 
      Device Name: Microsoft eHome Infrared Transceiver
         Attached: 1
    Controller ID: 0x0
Vendor/Product ID: 0x045E, 0x006D
        FF Driver: n/a
 
      Device Name: Microsoft eHome Infrared Transceiver
         Attached: 1
    Controller ID: 0x0
Vendor/Product ID: 0x045E, 0x006D
        FF Driver: n/a
 
Poll w/ Interrupt: No
 
-----------
USB Devices
-----------
 
----------------
Gameport Devices
----------------
 
------------
PS/2 Devices
------------
+ Microsoft eHome Remote Control Keyboard keys
| Vendor/Product ID: 0x045E, 0x0000
| Matching Device ID: HID\IrDeviceV2&Col05
| Service: kbdhid
| Driver: kbdhid.sys, 9/30/2016 19:51:41, 39424 bytes
| Driver: kbdclass.sys, 7/16/2016 06:41:54, 62304 bytes
+ Microsoft eHome MCIR Keyboard
| Vendor/Product ID: 0x045E, 0x0000
| Matching Device ID: HID\IrDeviceV2&Col06
| Service: kbdhid
| Driver: kbdhid.sys, 9/30/2016 19:51:41, 39424 bytes
| Driver: kbdclass.sys, 7/16/2016 06:41:54, 62304 bytes
+ Microsoft eHome MCIR 109 Keyboard
| Vendor/Product ID: 0x045E, 0x0000
| Matching Device ID: HID\IrDeviceV2&Col07
| Service: kbdhid
| Driver: kbdhid.sys, 9/30/2016 19:51:41, 39424 bytes
| Driver: kbdclass.sys, 7/16/2016 06:41:54, 62304 bytes
+ Standard 101/102-Key or Microsoft Natural PS/2 Keyboard with HP QLB
| Matching Device ID: *PNP0303
| Upper Filters: HpqKbFiltr
| Service: i8042prt
| Driver: HpqKbFiltr.sys, 4/29/2009 10:48:32, 18432 bytes
| Driver: i8042prt.sys, 7/16/2016 06:41:54, 114176 bytes
| Driver: kbdclass.sys, 7/16/2016 06:41:54, 62304 bytes
| Driver: wdfcoinstaller01005.dll, 11/2/2006 09:04:56, 1919968 bytes
+ HID-compliant mouse
| Vendor/Product ID: 0x045E, 0x0000
| Matching Device ID: HID_DEVICE_SYSTEM_MOUSE
| Service: mouhid
| Driver: mouhid.sys, 7/16/2016 06:41:54, 32256 bytes
| Driver: mouclass.sys, 7/16/2016 06:41:54, 59232 bytes
+ Synaptics PS/2 Port TouchPad
| Matching Device ID: acpi\syn1e04
| Upper Filters: SynTP
| Service: i8042prt
| Driver: SynTP.sys, 3/30/2016 23:24:42, 622784 bytes
| Driver: Smb_driver_Intel_Aux.sys, 3/30/2016 23:24:42, 52904 bytes
| Driver: Smb_driver_AMDASF_Aux.sys, 3/30/2016 23:24:42, 52400 bytes
| Driver: SynTPAPI.dll, 3/30/2016 23:24:42, 274968 bytes
| Driver: SynCOM.dll, 3/30/2016 23:24:42, 772104 bytes
| Driver: SynTPRes.dll, 3/30/2016 23:24:46, 19204632 bytes
| Driver: SynTPCpl.dll, 3/30/2016 23:24:44, 3929784 bytes
| Driver: SynCntxt.rtf, 9/2/2015 14:52:16, 12645898 bytes
| Driver: SynZMetr.exe, 3/30/2016 23:24:44, 1896640 bytes
| Driver: SynMood.exe, 3/30/2016 23:24:44, 1919672 bytes
| Driver: SynTPEnh.exe, 3/30/2016 23:24:44, 3954352 bytes
| Driver: Tutorial.exe, 3/30/2016 23:24:44, 1907904 bytes
| Driver: InstNT.exe, 3/30/2016 23:24:42, 314560 bytes
| Driver: SynISDLL.dll, 3/30/2016 23:24:42, 349352 bytes
| Driver: SynUnst.ini, 9/2/2015 14:52:38, 1652424 bytes
| Driver: SynRemoveUserSettings.dat, 9/2/2015 14:52:26, 1315 bytes
| Driver: SynTPHelper.exe, 3/30/2016 23:24:46, 218816 bytes
| Driver: SynTPEnhService.exe, 3/30/2016 23:24:44, 253960 bytes
| Driver: SynReflash.exe, 3/30/2016 23:24:42, 1345720 bytes
| Driver: SynPivotRotate.mpg, 4/10/2009 02:04:14, 770663 bytes
| Driver: SynChiralRotate.mpg, 9/17/2008 22:13:08, 382277 bytes
| Driver: SynFlick.mpg, 9/3/2008 20:27:28, 737975 bytes
| Driver: SynPinch.mpg, 9/3/2008 20:27:28, 286463 bytes
| Driver: SynMomentum.mpg, 9/3/2008 20:27:28, 246230 bytes
| Driver: SynLinearVHScroll.mpg, 9/3/2008 20:27:28, 929103 bytes
| Driver: SynChiralVHScroll.mpg, 9/3/2008 20:27:28, 1620778 bytes
| Driver: SynTwoFingerVHScroll.mpg, 3/16/2009 18:44:00, 746464 bytes
| Driver: SynPivotRotate_ChiralRotate.mpg, 4/10/2009 02:04:14, 1142810 bytes
| Driver: SynThreeFingerFlick.mpg, 3/16/2009 18:44:00, 633621 bytes
| Driver: SynThreeFingersDown.mpg, 3/16/2009 18:44:00, 215907 bytes
| Driver: SynTwistRotate.mpg, 3/4/2011 00:28:40, 1826816 bytes
| Driver: SynChiralTwistRotate.mpg, 3/8/2011 00:39:22, 2998272 bytes
| Driver: StaticImg.html, 12/18/2009 18:23:12, 968 bytes
| Driver: StaticImg.png, 12/14/2009 20:49:44, 107143 bytes
| Driver: SynSysDetect.js, 9/2/2015 14:52:26, 1481 bytes
| Driver: Syn2FingerScrolling.wmv, 9/2/2015 14:52:06, 650659 bytes
| Driver: Syn3FingerFlick.wmv, 9/2/2015 14:52:08, 774019 bytes
| Driver: Syn4FingerFlick.wmv, 2/25/2011 01:10:40, 795115 bytes
| Driver: Syn4FFlickVNB.wmv, 9/2/2015 14:52:10, 381040 bytes
| Driver: SynSmartSense.wmv, 9/2/2015 14:52:26, 370121 bytes
| Driver: SynSmartSenseNB.wmv, 9/2/2015 14:52:26, 670555 bytes
| Driver: Syn4FingerFlickUpDown.wmv, 9/2/2015 14:52:10, 1264895 bytes
| Driver: Syn4FingerFlickUpDownNB.wmv, 9/2/2015 14:52:10, 711685 bytes
| Driver: Syn4FingerFlickLeftRight.wmv, 9/2/2015 14:52:10, 1201694 bytes
| Driver: Syn4FingerFlickLeftRightNB.wmv, 9/2/2015 14:52:10, 711655 bytes
| Driver: Syn3FingerPress.wmv, 9/2/2015 14:52:08, 149361 bytes
| Driver: SynEdgeMotion.wmv, 9/2/2015 14:52:18, 790425 bytes
| Driver: SynLinearScrolling.wmv, 9/2/2015 14:52:20, 486299 bytes
| Driver: SynMomentum.wmv, 9/2/2015 14:52:22, 231541 bytes
| Driver: SynMomentumScrolling.wmv, 9/2/2015 14:52:22, 1513885 bytes
| Driver: SynPinchZoom.wmv, 9/2/2015 14:52:24, 361085 bytes
| Driver: SynBlackScreen.wmv, 9/2/2015 14:52:10, 14729 bytes
| Driver: SynPivotRotate.wmv, 9/2/2015 14:52:24, 609629 bytes
| Driver: SynTwistRotate.wmv, 9/2/2015 14:52:36, 535667 bytes
| Driver: SynCoverGesture.wmv, 9/2/2015 14:52:18, 633185 bytes
| Driver: SynChiralRotate.wmv, 9/2/2015 14:52:12, 321969 bytes
| Driver: SynChiralScrolling.wmv, 9/2/2015 14:52:12, 1776645 bytes
| Driver: SynCoastingScrolling.wmv, 9/2/2015 14:52:16, 880823 bytes
| Driver: SynPointing.wmv, 9/2/2015 14:52:26, 89721 bytes
| Driver: SynPalmCheck.wmv, 9/2/2015 14:52:24, 278039 bytes
| Driver: SynSensitivity.wmv, 9/2/2015 14:52:26, 183903 bytes
| Driver: SynWindowConstrained.wmv, 9/2/2015 14:52:38, 250401 bytes
| Driver: SynSlowMotion.wmv, 9/2/2015 14:52:26, 255951 bytes
| Driver: SynConstrainedMotion.wmv, 9/2/2015 14:52:16, 1174655 bytes
| Driver: SynTapping.wmv, 9/2/2015 14:52:28, 67389 bytes
| Driver: SynButtons.wmv, 9/2/2015 14:52:10, 190451 bytes
| Driver: SynTouchStykSelect.wmv, 9/2/2015 14:52:28, 84183 bytes
| Driver: SynTouchStykButton.wmv, 9/2/2015 14:52:28, 95259 bytes
| Driver: SynTouchStykSensitivity.wmv, 9/2/2015 14:52:28, 183909 bytes
| Driver: SynEdgeMotionDragging.wmv, 9/2/2015 14:52:18, 174015 bytes
| Driver: SynEdgeMotionFixedSpeed.wmv, 9/2/2015 14:52:18, 174015 bytes
| Driver: SynEdgeMotionPointing.wmv, 9/2/2015 14:52:18, 157579 bytes
| Driver: SynEdgeMotionPressure.wmv, 9/2/2015 14:52:18, 67539 bytes
| Driver: SynNoButtons.wmv, 9/2/2015 14:52:24, 28715 bytes
| Driver: SynTapZones.wmv, 9/2/2015 14:52:28, 215105 bytes
| Driver: SynLinearHScrolling.wmv, 9/2/2015 14:52:20, 527389 bytes
| Driver: Syn2FingerHScrolling.wmv, 9/2/2015 14:52:04, 626005 bytes
| Driver: SynTapHoldToDrag.wmv, 9/2/2015 14:52:26, 62001 bytes
| Driver: SynTapLockingDrag.wmv, 9/2/2015 14:52:26, 95259 bytes
| Driver: Syn1FingerClickNB.wmv, 9/2/2015 14:52:04, 141143 bytes
| Driver: Syn1FingerClickDrag.wmv, 9/2/2015 14:52:04, 338125 bytes
| Driver: Syn2FingerClickDrag.wmv, 9/2/2015 14:52:04, 471371 bytes
| Driver: Syn2FingerFlickNB.wmv, 9/2/2015 14:52:04, 675403 bytes
| Driver: Syn2FingerFlickLR.wmv, 9/2/2015 14:52:04, 502795 bytes
| Driver: Syn2FingerHScrollingNB.wmv, 9/2/2015 14:52:04, 617787 bytes
| Driver: Syn2FingerScrollingNB.wmv, 9/2/2015 14:52:06, 634223 bytes
| Driver: Syn3FingerFlickNB.wmv, 9/2/2015 14:52:08, 749365 bytes
| Driver: Syn3FingerPressNB.wmv, 9/2/2015 14:52:08, 141143 bytes
| Driver: Syn4FingerFlickNB.wmv, 9/2/2015 14:52:10, 723930 bytes
| Driver: SynButtonsNB.wmv, 9/2/2015 14:52:12, 182233 bytes
| Driver: SynChiralRotateNB.wmv, 9/2/2015 14:52:12, 356580 bytes
| Driver: SynChiralScrollingNB.wmv, 9/2/2015 14:52:12, 2805670 bytes
| Driver: SynCoastingScrollingNB.wmv, 9/2/2015 14:52:16, 1532130 bytes
| Driver: SynCoverGestureNB.wmv, 9/2/2015 14:52:18, 633185 bytes
| Driver: SynEdgeMotionDraggingNB.wmv, 9/2/2015 14:52:18, 172875 bytes
| Driver: SynEdgeMotionFixedSpeedNB.wmv, 9/2/2015 14:52:18, 185120 bytes
| Driver: SynEdgeMotionPointingNB.wmv, 9/2/2015 14:52:18, 160630 bytes
| Driver: SynEdgeMotionPressureNB.wmv, 9/2/2015 14:52:18, 142023 bytes
| Driver: SynLinearHScrollingNB.wmv, 9/2/2015 14:52:20, 919820 bytes
| Driver: SynMomentumScrollingNB.wmv, 9/2/2015 14:52:22, 928929 bytes
| Driver: SynPinchZoomNB.wmv, 9/2/2015 14:52:24, 834947 bytes
| Driver: SynPivotRotateNB.wmv, 9/2/2015 14:52:24, 535667 bytes
| Driver: SynTapHoldToDragNB.wmv, 9/2/2015 14:52:26, 130279 bytes
| Driver: SynTapLockingDragNB.wmv, 9/2/2015 14:52:26, 212515 bytes
| Driver: SynTwistRotateNB.wmv, 9/2/2015 14:52:36, 821920 bytes
| Driver: SynPointingNB.wmv, 9/2/2015 14:52:26, 177285 bytes
| Driver: Syn2FingerMomentumVHScrolling.wmv, 11/11/2010 22:15:02, 895723 bytes
| Driver: Syn2FingerMomentumVHScrollingNB.wmv, 9/2/2015 14:52:06, 1645313 bytes
| Driver: Syn2FingerMomentumVScrolling_win8.wmv, 9/2/2015 14:52:06, 597933 bytes
| Driver: Syn2FingerMomentumVScrollingNB_win8.wmv, 9/2/2015 14:52:06, 586882 bytes
| Driver: Syn2FingerMomentumHScrolling_win8.wmv, 9/2/2015 14:52:04, 575831 bytes
| Driver: Syn2FingerMomentumHScrollingNB_win8.wmv, 9/2/2015 14:52:04, 1079005 bytes
| Driver: Syn2FingerVHCoasting.wmv, 9/2/2015 14:52:08, 1794763 bytes
| Driver: Syn2FingerVHCoastingNB.wmv, 9/2/2015 14:52:08, 2266890 bytes
| Driver: Syn2FingerVCoasting_win8.wmv, 9/2/2015 14:52:08, 919145 bytes
| Driver: Syn2FingerHCoasting_win8.wmv, 9/2/2015 14:52:04, 1003421 bytes
| Driver: Syn2FingerVCoastingNB_win8.wmv, 9/2/2015 14:52:06, 1311690 bytes
| Driver: Syn2FingerHCoastingNB_win8.wmv, 9/2/2015 14:52:04, 1397405 bytes
| Driver: SynMomentumVHScrolling.wmv, 9/2/2015 14:52:22, 1408837 bytes
| Driver: SynMomentumVHScrollingNB.wmv, 9/2/2015 14:52:22, 1774529 bytes
| Driver: SynVHCoasting.wmv, 9/2/2015 14:52:38, 1955445 bytes
| Driver: Syn2FingerHScrolling_win8.wmv, 9/2/2015 14:52:04, 432126 bytes
| Driver: Syn2FingerHScrollingNB_win8.wmv, 9/2/2015 14:52:04, 968800 bytes
| Driver: SynChiralScrolling_win8.wmv, 9/2/2015 14:52:12, 819031 bytes
| Driver: SynChiralScrollingNB_win8.wmv, 9/2/2015 14:52:12, 2805670 bytes
| Driver: SynLinearHScrolling_win8.wmv, 9/2/2015 14:52:20, 376913 bytes
| Driver: SynLinearHScrollingNB_win8.wmv, 9/2/2015 14:52:20, 919820 bytes
| Driver: SynLinearScrolling_win8.wmv, 9/2/2015 14:52:20, 354811 bytes
| Driver: SynLinearScrollingNB_win8.wmv, 9/2/2015 14:52:20, 797370 bytes
| Driver: SynPivotRotate_win8.wmv, 9/2/2015 14:52:26, 498534 bytes
| Driver: SynPivotRotateNB_win8.wmv, 9/2/2015 14:52:24, 870900 bytes
| Driver: SynTwistRotate_win8.wmv, 9/2/2015 14:52:36, 421135 bytes
| Driver: SynTwistRotateNB_win8.wmv, 9/2/2015 14:52:36, 821920 bytes
| Driver: SynEdgePulls.wmv, 9/2/2015 14:52:18, 1247447 bytes
| Driver: Syn4FingerFlick_win8.wmv, 9/2/2015 14:52:10, 598023 bytes
| Driver: Syn4FingerFlickNB_win8.wmv, 9/2/2015 14:52:10, 564870 bytes
| Driver: Syn2FingerScrolling.html, 9/2/2015 14:52:06, 3216 bytes
| Driver: Syn2FingerFlick.html, 9/2/2015 14:52:04, 3212 bytes
| Driver: Syn3FingerFlick.html, 9/2/2015 14:52:08, 3212 bytes
| Driver: Syn4FingerFlick.html, 9/2/2015 14:52:10, 3212 bytes
| Driver: Syn4FingerFlickUpDown.html, 9/2/2015 14:52:10, 3218 bytes
| Driver: Syn4FingerFlickLeftRight.html, 9/2/2015 14:52:10, 3221 bytes
| Driver: Syn3FingerPress.html, 9/2/2015 14:52:08, 3212 bytes
| Driver: SynEdgeMotion.html, 9/2/2015 14:52:18, 3210 bytes
| Driver: SynMomentum.html, 9/2/2015 14:52:20, 3208 bytes
| Driver: SynPinchZoom.html, 9/2/2015 14:52:24, 3209 bytes
| Driver: SynRotating.html, 9/2/2015 14:52:26, 3208 bytes
| Driver: SynTwistRotate.html, 9/2/2015 14:52:36, 3211 bytes
| Driver: SynCoverGesture.html, 9/2/2015 14:52:18, 3212 bytes
| Driver: SynAccessibility.html, 9/2/2015 14:52:10, 3221 bytes
| Driver: SynSmartSense.html, 9/2/2015 14:52:26, 3210 bytes
| Driver: SynButtons.html, 9/2/2015 14:52:10, 3207 bytes
| Driver: SynClicking.html, 9/2/2015 14:52:14, 3208 bytes
| Driver: SynMultiFingerGestures.html, 9/2/2015 14:52:24, 3182 bytes
| Driver: SynPalmCheck.html, 9/2/2015 14:52:24, 3209 bytes
| Driver: SynPointing.html, 9/2/2015 14:52:26, 3208 bytes
| Driver: SynScrolling.html, 9/2/2015 14:52:26, 3209 bytes
| Driver: SynSensitivity.html, 9/2/2015 14:52:26, 3211 bytes
| Driver: SynTapping.html, 9/2/2015 14:52:26, 3207 bytes
| Driver: SynTouchStykButton.html, 9/2/2015 14:52:28, 3215 bytes
| Driver: SynTouchStykSelect.html, 9/2/2015 14:52:28, 3215 bytes
| Driver: SynTouchStykSensitivity.html, 9/2/2015 14:52:28, 3220 bytes
| Driver: SynScrollingVertical.html, 9/2/2015 14:52:26, 3217 bytes
| Driver: SynScrollingHorizontal.html, 9/2/2015 14:52:26, 3219 bytes
| Driver: SynScrollingChiral.html, 9/2/2015 14:52:26, 3215 bytes
| Driver: SynLockingDrags.html, 9/2/2015 14:52:20, 3212 bytes
| Driver: SynEdgePulls.html, 9/2/2015 14:52:18, 3162 bytes
| Driver: Syn2FingerScrolling_win8.wmv, 9/2/2015 14:52:06, 398973 bytes
| Driver: Syn2FingerScrollingNB_win8.wmv, 9/2/2015 14:52:06, 940613 bytes
| Driver: SynTappingNB.wmv, 9/2/2015 14:52:28, 118535 bytes
| Driver: Syn2FingerRightClickNB.wmv, 9/2/2015 14:52:06, 177253 bytes
| Driver: SynVHCoastingNB.wmv, 9/2/2015 14:52:38, 1821565 bytes
| Driver: SynEdgePullsNB.wmv, 9/2/2015 14:52:20, 517951 bytes
| Driver: SynPalmCheckNB.wmv, 9/2/2015 14:52:24, 670557 bytes
| Driver: SynLinearScrollingNB.wmv, 9/2/2015 14:52:20, 797370 bytes
| Driver: SynSensitivityNB.wmv, 9/2/2015 14:52:26, 400455 bytes
| Driver: SynMomentumNB.wmv, 9/2/2015 14:52:22, 319815 bytes
| Driver: SynTapZonesNB.wmv, 9/2/2015 14:52:28, 258590 bytes
| Driver: SynTapZonesNB_win8.wmv, 9/2/2015 14:52:28, 258590 bytes
| Driver: SynEdgeMotionNB.wmv, 9/2/2015 14:52:18, 1360700 bytes
| Driver: SynSlowMotionNB.wmv, 9/2/2015 14:52:26, 517951 bytes
| Driver: SynConstrainedMotionNB.wmv, 9/2/2015 14:52:16, 623675 bytes
| Driver: SynWindowConstrainedNB.wmv, 9/2/2015 14:52:38, 588401 bytes
| Driver: Syn3FHSlide.wmv, 9/2/2015 14:52:08, 243720 bytes
| Driver: Syn3FHSlideNB.wmv, 9/2/2015 14:52:08, 202757 bytes
| Driver: Syn3FTapActionCenter.wmv, 9/2/2015 14:52:08, 108227 bytes
| Driver: Syn3FTapActionCenterNB.wmv, 9/2/2015 14:52:08, 105076 bytes
| Driver: Syn3FTapCortana.wmv, 9/2/2015 14:52:08, 111378 bytes
| Driver: Syn3FTapCortanaNB.wmv, 9/2/2015 14:52:08, 108227 bytes
| Driver: Syn4FTapActionCenter.wmv, 9/2/2015 14:52:10, 111378 bytes
| Driver: Syn4FTapActionCenterNB.wmv, 9/2/2015 14:52:10, 108227 bytes
| Driver: Syn4FTapCortana.wmv, 9/2/2015 14:52:10, 114529 bytes
| Driver: Syn4FTapCortanaNB.wmv, 9/2/2015 14:52:10, 111378 bytes
| Driver: Syn3FClickActionCenterNB.wmv, 9/2/2015 14:52:08, 139737 bytes
| Driver: Syn3FClickCortanaNB.wmv, 9/2/2015 14:52:08, 149190 bytes
| Driver: Syn4FClickActionCenterNB.wmv, 9/2/2015 14:52:08, 158643 bytes
| Driver: Syn4FClickCortanaNB.wmv, 9/2/2015 14:52:10, 164945 bytes
| Driver: Syn3FVSlide.wmv, 9/2/2015 14:52:08, 476954 bytes
| Driver: Syn3FVSlideNB.wmv, 9/2/2015 14:52:08, 372971 bytes
| Driver: dpinst.exe, 3/30/2016 23:24:42, 1065656 bytes
| Driver: SynSmbDrv.ini, 9/2/2015 14:52:26, 6087 bytes
| Driver: SynLinearVScroll.mpg, 9/3/2008 20:27:28, 518694 bytes
| Driver: SynWingGesture.wmv, 9/2/2015 14:52:38, 305841 bytes
| Driver: SynWingGesture.html, 9/2/2015 14:52:38, 3164 bytes
| Driver: Syn2FingerTappingNB.wmv, 9/2/2015 14:52:06, 101711 bytes
| Driver: Syn2FingerTapping.html, 9/2/2015 14:52:06, 3214 bytes
| Driver: Syn3FingerTapping.html, 9/2/2015 14:52:08, 3214 bytes
| Driver: Syn4FingerTapping.html, 9/2/2015 14:52:10, 3214 bytes
| Driver: Ckp2FingerScrolling.mpg, 7/3/2009 00:56:20, 382935 bytes
| Driver: Ckp3FingerDown.mpg, 7/3/2009 00:56:20, 153456 bytes
| Driver: Ckp3FingerFlick.mpg, 7/3/2009 00:56:20, 569095 bytes
| Driver: CkpChiralMotion.mpg, 7/3/2009 00:56:20, 420858 bytes
| Driver: CkpClickDrag.mpg, 7/3/2009 00:56:20, 271447 bytes
| Driver: CkpLinearScroll.mpg, 7/3/2009 00:56:20, 427998 bytes
| Driver: CkpLRClick.mpg, 7/3/2009 00:56:20, 284073 bytes
| Driver: CkpMomentum.mpg, 7/3/2009 00:56:20, 328085 bytes
| Driver: CkpPinch.mpg, 7/3/2009 00:56:20, 309339 bytes
| Driver: CkpPivotRotate.mpg, 7/3/2009 00:56:20, 605893 bytes
| Driver: CkpPivotRotate2.mpg, 9/26/2009 02:46:08, 779912 bytes
| Driver: CkpTouchpadDisable.mpg, 7/3/2009 00:56:20, 293736 bytes
| Driver: SynCom.dll, 3/30/2016 23:24:42, 430256 bytes
| Driver: mouclass.sys, 7/16/2016 06:41:54, 59232 bytes
| Driver: i8042prt.sys, 7/16/2016 06:41:54, 114176 bytes
| Driver: SynTPCo31-1.dll, 3/30/2016 23:24:42, 267440 bytes
| Driver: WdfCoInstaller01011.dll, 3/30/2016 23:24:44, 1814912 bytes
 
------------------------
Disk & DVD/CD-ROM Drives
------------------------
      Drive: C:
 Free Space: 191.8 GB
Total Space: 224.4 GB
File System: NTFS
      Model: TOSHIBA MK2555GSX
 
      Drive: D:
 Free Space: 2.2 GB
Total Space: 13.0 GB
File System: NTFS
      Model: TOSHIBA MK2555GSX
 
      Drive: E:
      Model: hp DVDRAM GT20L
     Driver: c:\windows\system32\drivers\cdrom.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:53, 173056 bytes
 
--------------
System Devices
--------------
     Name: Intel® ICH9 Family USB Universal Host Controller - 2936
Device ID: PCI\VEN_8086&DEV_2936&SUBSYS_3627103C&REV_03\3&B1BFB68&0&EA
   Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 35328 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 455520 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 501088 bytes
 
     Name: Intel® ICH9 Family USB Universal Host Controller - 2937
Device ID: PCI\VEN_8086&DEV_2937&SUBSYS_3627103C&REV_03\3&B1BFB68&0&D0
   Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 35328 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 455520 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 501088 bytes
 
     Name: PCI-to-PCI Bridge
Device ID: PCI\VEN_8086&DEV_2940&SUBSYS_3627103C&REV_03\3&B1BFB68&0&E0
   Driver: C:\WINDOWS\system32\DRIVERS\pci.sys, 10.00.14393.0594 (English), 1/11/2017 14:47:07, 335712 bytes
 
     Name: Intel® ICH9 Family USB Universal Host Controller - 2938
Device ID: PCI\VEN_8086&DEV_2938&SUBSYS_3627103C&REV_03\3&B1BFB68&0&D1
   Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 35328 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 455520 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 501088 bytes
 
     Name: Intel® ICH9 Family USB Universal Host Controller - 2939
Device ID: PCI\VEN_8086&DEV_2939&SUBSYS_3627103C&REV_03\3&B1BFB68&0&EB
   Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 35328 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 455520 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 501088 bytes
 
     Name: PCI-to-PCI Bridge
Device ID: PCI\VEN_8086&DEV_2942&SUBSYS_3627103C&REV_03\3&B1BFB68&0&E1
   Driver: C:\WINDOWS\system32\DRIVERS\pci.sys, 10.00.14393.0594 (English), 1/11/2017 14:47:07, 335712 bytes
 
     Name: PCI-to-PCI Bridge
Device ID: PCI\VEN_8086&DEV_2946&SUBSYS_3627103C&REV_03\3&B1BFB68&0&E3
   Driver: C:\WINDOWS\system32\DRIVERS\pci.sys, 10.00.14393.0594 (English), 1/11/2017 14:47:07, 335712 bytes
 
     Name: LPC Controller
Device ID: PCI\VEN_8086&DEV_2919&SUBSYS_3627103C&REV_03\3&B1BFB68&0&F8
   Driver: C:\WINDOWS\system32\DRIVERS\msisadrv.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:53, 18784 bytes
 
     Name: PCI-to-PCI Bridge
Device ID: PCI\VEN_8086&DEV_2948&SUBSYS_3627103C&REV_03\3&B1BFB68&0&E4
   Driver: C:\WINDOWS\system32\DRIVERS\pci.sys, 10.00.14393.0594 (English), 1/11/2017 14:47:07, 335712 bytes
 
     Name: CPU to DRAM Controller
Device ID: PCI\VEN_8086&DEV_2A40&SUBSYS_3627103C&REV_07\3&B1BFB68&0&00
   Driver: n/a
 
     Name: Intel® ICH9 Family USB2 Enhanced Host Controller - 293A
Device ID: PCI\VEN_8086&DEV_293A&SUBSYS_3627103C&REV_03\3&B1BFB68&0&EF
   Driver: C:\WINDOWS\system32\drivers\usbehci.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 96096 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 455520 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 501088 bytes
 
     Name: Mobile Intel® 4 Series Express Chipset Family (Microsoft Corporation - WDDM 1.1)
Device ID: PCI\VEN_8086&DEV_2A42&SUBSYS_3627103C&REV_07\3&B1BFB68&0&10
   Driver: C:\WINDOWS\system32\DRIVERS\igdkmd64.sys, 8.15.0010.2702 (English), 3/23/2012 18:13:28, 10627744 bytes
   Driver: C:\WINDOWS\system32\igdumd64.dll, 8.15.0010.2702 (English), 3/11/2013 15:49:02, 6593816 bytes
   Driver: C:\WINDOWS\system32\igd10umd64.dll, 8.15.0010.2702 (English), 3/11/2013 15:48:50, 4755784 bytes
   Driver: C:\WINDOWS\system32\igkrng500.bin, 3/23/2012 18:13:08, 982240 bytes
   Driver: C:\WINDOWS\system32\igcompkrng500.bin, 3/23/2012 18:13:08, 439308 bytes
   Driver: C:\WINDOWS\system32\igfcg500m.bin, 3/23/2012 18:13:08, 92356 bytes
   Driver: C:\WINDOWS\SysWow64\igkrng500.bin, 3/23/2012 18:13:08, 982240 bytes
   Driver: C:\WINDOWS\SysWow64\igcompkrng500.bin, 3/23/2012 18:13:08, 439308 bytes
   Driver: C:\WINDOWS\SysWow64\igfcg500m.bin, 3/23/2012 18:13:08, 92356 bytes
   Driver: C:\WINDOWS\system32\iglhxs64.vp, 3/23/2012 18:41:58, 5424 bytes
   Driver: C:\WINDOWS\system32\iglhxo64.vp, 3/23/2012 17:54:38, 60015 bytes
   Driver: C:\WINDOWS\system32\iglhxc64.vp, 3/23/2012 17:54:38, 60226 bytes
   Driver: C:\WINDOWS\system32\iglhxg64.vp, 3/23/2012 17:54:38, 60254 bytes
   Driver: C:\WINDOWS\system32\iglhxa64.vp, 3/23/2012 17:54:38, 1090 bytes
   Driver: C:\WINDOWS\system32\iglhxa64.cpa, 3/23/2012 17:54:38, 1991936 bytes
   Driver: C:\WINDOWS\system32\iglhcp64.dll, 1.05.0002.0001 (English), 3/23/2012 22:47:02, 188416 bytes
   Driver: C:\WINDOWS\system32\iglhsip64.dll, 1.05.0002.0001 (English), 3/23/2012 22:47:02, 206336 bytes
   Driver: C:\WINDOWS\SysWow64\igdumd32.dll, 8.15.0010.2702 (English), 3/11/2013 15:48:56, 4931384 bytes
   Driver: C:\WINDOWS\SysWow64\igd10umd32.dll, 8.15.0010.2702 (English), 3/11/2013 15:48:44, 4370016 bytes
   Driver: C:\WINDOWS\SysWow64\iglhcp32.dll, 1.05.0002.0001 (English), 3/23/2012 22:47:02, 147456 bytes
   Driver: C:\WINDOWS\SysWow64\iglhsip32.dll, 1.05.0002.0001 (English), 3/23/2012 22:47:02, 208896 bytes
 
     Name: Intel® ICH9 Family USB2 Enhanced Host Controller - 293C
Device ID: PCI\VEN_8086&DEV_293C&SUBSYS_3627103C&REV_03\3&B1BFB68&0&D7
   Driver: C:\WINDOWS\system32\drivers\usbehci.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 96096 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 455520 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 501088 bytes
 
     Name: Synaptics SMBus Driver
Device ID: PCI\VEN_8086&DEV_2930&SUBSYS_3627103C&REV_03\3&B1BFB68&0&FB
   Driver: C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys, 19.00.0012.0098 (English), 3/30/2016 23:24:42, 52904 bytes
   Driver: C:\Program Files\Synaptics\SynTP\SynSmbDrv.ini, 9/2/2015 14:52:26, 6087 bytes
   Driver: C:\WINDOWS\system32\WdfCoInstaller01011.dll, 1.11.9200.16384 (English), 3/30/2016 23:24:44, 1814912 bytes
 
     Name: Mobile Intel® 4 Series Express Chipset Family (Microsoft Corporation - WDDM 1.1)
Device ID: PCI\VEN_8086&DEV_2A43&SUBSYS_3627103C&REV_07\3&B1BFB68&0&11
   Driver: C:\WINDOWS\system32\DRIVERS\igdkmd64.sys, 8.15.0010.2702 (English), 3/23/2012 18:13:28, 10627744 bytes
   Driver: C:\WINDOWS\system32\igdumd64.dll, 8.15.0010.2702 (English), 3/11/2013 15:49:02, 6593816 bytes
   Driver: C:\WINDOWS\system32\igd10umd64.dll, 8.15.0010.2702 (English), 3/11/2013 15:48:50, 4755784 bytes
   Driver: C:\WINDOWS\system32\igkrng500.bin, 3/23/2012 18:13:08, 982240 bytes
   Driver: C:\WINDOWS\system32\igcompkrng500.bin, 3/23/2012 18:13:08, 439308 bytes
   Driver: C:\WINDOWS\system32\igfcg500m.bin, 3/23/2012 18:13:08, 92356 bytes
   Driver: C:\WINDOWS\SysWow64\igkrng500.bin, 3/23/2012 18:13:08, 982240 bytes
   Driver: C:\WINDOWS\SysWow64\igcompkrng500.bin, 3/23/2012 18:13:08, 439308 bytes
   Driver: C:\WINDOWS\SysWow64\igfcg500m.bin, 3/23/2012 18:13:08, 92356 bytes
   Driver: C:\WINDOWS\system32\iglhxs64.vp, 3/23/2012 18:41:58, 5424 bytes
   Driver: C:\WINDOWS\system32\iglhxo64.vp, 3/23/2012 17:54:38, 60015 bytes
   Driver: C:\WINDOWS\system32\iglhxc64.vp, 3/23/2012 17:54:38, 60226 bytes
   Driver: C:\WINDOWS\system32\iglhxg64.vp, 3/23/2012 17:54:38, 60254 bytes
   Driver: C:\WINDOWS\system32\iglhxa64.vp, 3/23/2012 17:54:38, 1090 bytes
   Driver: C:\WINDOWS\system32\iglhxa64.cpa, 3/23/2012 17:54:38, 1991936 bytes
   Driver: C:\WINDOWS\system32\iglhcp64.dll, 1.05.0002.0001 (English), 3/23/2012 22:47:02, 188416 bytes
   Driver: C:\WINDOWS\system32\iglhsip64.dll, 1.05.0002.0001 (English), 3/23/2012 22:47:02, 206336 bytes
   Driver: C:\WINDOWS\SysWow64\igdumd32.dll, 8.15.0010.2702 (English), 3/11/2013 15:48:56, 4931384 bytes
   Driver: C:\WINDOWS\SysWow64\igd10umd32.dll, 8.15.0010.2702 (English), 3/11/2013 15:48:44, 4370016 bytes
   Driver: C:\WINDOWS\SysWow64\iglhcp32.dll, 1.05.0002.0001 (English), 3/23/2012 22:47:02, 147456 bytes
   Driver: C:\WINDOWS\SysWow64\iglhsip32.dll, 1.05.0002.0001 (English), 3/23/2012 22:47:02, 208896 bytes
 
     Name: PCI-to-PCI Bridge
Device ID: PCI\VEN_8086&DEV_2448&SUBSYS_3627103C&REV_93\3&B1BFB68&0&F0
   Driver: C:\WINDOWS\system32\DRIVERS\pci.sys, 10.00.14393.0594 (English), 1/11/2017 14:47:07, 335712 bytes
 
     Name: High Definition Audio Controller
Device ID: PCI\VEN_8086&DEV_293E&SUBSYS_3627103C&REV_03\3&B1BFB68&0&D8
   Driver: C:\WINDOWS\system32\DRIVERS\hdaudbus.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:52, 83456 bytes
   Driver: C:\WINDOWS\system32\DRIVERS\drmk.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:52, 97280 bytes
   Driver: C:\WINDOWS\system32\DRIVERS\portcls.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:52, 366592 bytes
 
     Name: Intel® ICH9M/M-E Family 4 Port SATA AHCI Controller - 2929
Device ID: PCI\VEN_8086&DEV_2929&SUBSYS_3627103C&REV_03\3&B1BFB68&0&FA
   Driver: C:\WINDOWS\system32\DRIVERS\storahci.sys, 10.00.14393.0953 (English), 3/4/2017 02:08:59, 130912 bytes
 
     Name: Thermal Control Device
Device ID: PCI\VEN_8086&DEV_2932&SUBSYS_3627103C&REV_03\3&B1BFB68&0&FE
   Driver: n/a
 
     Name: Broadcom 802.11g Network Adapter
Device ID: PCI\VEN_14E4&DEV_4315&SUBSYS_1507103C&REV_01\4&170D466B&0&00E0
   Driver: C:\WINDOWS\system32\DRIVERS\BCMWL63AL.SYS, 5.100.0245.0200 (English), 7/16/2016 06:41:50, 5170176 bytes
 
     Name: Intel® ICH9 Family USB Universal Host Controller - 2934
Device ID: PCI\VEN_8086&DEV_2934&SUBSYS_3627103C&REV_03\3&B1BFB68&0&E8
   Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 35328 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 455520 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 501088 bytes
 
     Name: PCI-to-PCI Bridge
Device ID: PCI\VEN_8086&DEV_294A&SUBSYS_3627103C&REV_03\3&B1BFB68&0&E5
   Driver: C:\WINDOWS\system32\DRIVERS\pci.sys, 10.00.14393.0594 (English), 1/11/2017 14:47:07, 335712 bytes
 
     Name: Intel® ICH9 Family USB Universal Host Controller - 2935
Device ID: PCI\VEN_8086&DEV_2935&SUBSYS_3627103C&REV_03\3&B1BFB68&0&E9
   Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 35328 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 455520 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.14393.0000 (English), 7/16/2016 06:41:55, 501088 bytes
 
------------------
DirectShow Filters
------------------
 
DirectShow Filters:
WMAudio Decoder DMO,0x00800800,1,1,WMADMOD.DLL,10.00.14393.0000
WMAPro over S/PDIF DMO,0x00600800,1,1,WMADMOD.DLL,10.00.14393.0000
WMSpeech Decoder DMO,0x00600800,1,1,WMSPDMOD.DLL,10.00.14393.0000
MP3 Decoder DMO,0x00600800,1,1,mp3dmod.dll,10.00.14393.0000
Mpeg4s Decoder DMO,0x00800001,1,1,mp4sdecd.dll,10.00.14393.0000
WMV Screen decoder DMO,0x00600800,1,1,wmvsdecd.dll,10.00.14393.0000
WMVideo Decoder DMO,0x00800001,1,1,wmvdecod.dll,10.00.14393.0953
Mpeg43 Decoder DMO,0x00800001,1,1,mp43decd.dll,10.00.14393.0000
Mpeg4 Decoder DMO,0x00800001,1,1,mpg4decd.dll,10.00.14393.0000
DV Muxer,0x00400000,0,0,qdv.dll,10.00.14393.0000
Color Space Converter,0x00400001,1,1,quartz.dll,10.00.14393.1066
WM ASF Reader,0x00400000,0,0,qasf.dll,12.00.14393.0000
AVI Splitter,0x00600000,1,1,quartz.dll,10.00.14393.1066
VGA 16 Color Ditherer,0x00400000,1,1,quartz.dll,10.00.14393.1066
SBE2MediaTypeProfile,0x00200000,0,0,sbe.dll,10.00.14393.1066
Microsoft DTV-DVD Video Decoder,0x005fffff,2,4,msmpeg2vdec.dll,10.00.14393.0953
AC3 Parser Filter,0x00600000,1,1,mpg2splt.ax,10.00.14393.0000
StreamBufferSink,0x00200000,0,0,sbe.dll,10.00.14393.1066
MJPEG Decompressor,0x00600000,1,1,quartz.dll,10.00.14393.1066
MPEG-I Stream Splitter,0x00600000,1,2,quartz.dll,10.00.14393.1066
SAMI (CC) Parser,0x00400000,1,1,quartz.dll,10.00.14393.1066
VBI Codec,0x00600000,1,4,VBICodec.ax,10.00.14393.0000
MPEG-2 Splitter,0x005fffff,1,0,mpg2splt.ax,10.00.14393.0000
Closed Captions Analysis Filter,0x00200000,2,5,cca.dll,10.00.14393.0000
SBE2FileScan,0x00200000,0,0,sbe.dll,10.00.14393.1066
Microsoft MPEG-2 Video Encoder,0x00200000,1,1,msmpeg2enc.dll,10.00.14393.0000
Internal Script Command Renderer,0x00800001,1,0,quartz.dll,10.00.14393.1066
MPEG Audio Decoder,0x03680001,1,1,quartz.dll,10.00.14393.1066
DV Splitter,0x00600000,1,2,qdv.dll,10.00.14393.0000
Video Mixing Renderer 9,0x00200000,1,0,quartz.dll,10.00.14393.1066
Microsoft MPEG-2 Encoder,0x00200000,2,1,msmpeg2enc.dll,10.00.14393.0000
ACM Wrapper,0x00600000,1,1,quartz.dll,10.00.14393.1066
Video Renderer,0x00800001,1,0,quartz.dll,10.00.14393.1066
MPEG-2 Video Stream Analyzer,0x00200000,0,0,sbe.dll,10.00.14393.1066
Line 21 Decoder,0x00600000,1,1,,
Video Port Manager,0x00600000,2,1,quartz.dll,10.00.14393.1066
Video Renderer,0x00400000,1,0,quartz.dll,10.00.14393.1066
VPS Decoder,0x00200000,0,0,WSTPager.ax,10.00.14393.0000
WM ASF Writer,0x00400000,0,0,qasf.dll,12.00.14393.0000
VBI Surface Allocator,0x00600000,1,1,vbisurf.ax,
File writer,0x00200000,1,0,qcap.dll,10.00.14393.0000
DVD Navigator,0x00200000,0,3,qdvd.dll,10.00.14393.0000
Overlay Mixer2,0x00200000,1,1,,
Microsoft MPEG-2 Audio Encoder,0x00200000,1,1,msmpeg2enc.dll,10.00.14393.0000
WST Pager,0x00200000,1,1,WSTPager.ax,10.00.14393.0000
MPEG-2 Demultiplexer,0x00600000,1,1,mpg2splt.ax,10.00.14393.0000
DV Video Decoder,0x00800000,1,1,qdv.dll,10.00.14393.0000
SampleGrabber,0x00200000,1,1,qedit.dll,10.00.14393.1066
Null Renderer,0x00200000,1,0,qedit.dll,10.00.14393.1066
MPEG-2 Sections and Tables,0x005fffff,1,0,Mpeg2Data.ax,10.00.14393.0000
Microsoft AC3 Encoder,0x00200000,1,1,msac3enc.dll,10.00.14393.0206
StreamBufferSource,0x00200000,0,0,sbe.dll,10.00.14393.1066
Smart Tee,0x00200000,1,2,qcap.dll,10.00.14393.0000
Overlay Mixer,0x00200000,0,0,,
AVI Decompressor,0x00600000,1,1,quartz.dll,10.00.14393.1066
AVI/WAV File Source,0x00400000,0,2,quartz.dll,10.00.14393.1066
Wave Parser,0x00400000,1,1,quartz.dll,10.00.14393.1066
MIDI Parser,0x00400000,1,1,quartz.dll,10.00.14393.1066
Multi-file Parser,0x00400000,1,1,quartz.dll,10.00.14393.1066
File stream renderer,0x00400000,1,1,quartz.dll,10.00.14393.1066
Microsoft DTV-DVD Audio Decoder,0x005fffff,1,1,msmpeg2adec.dll,10.00.14393.0000
StreamBufferSink2,0x00200000,0,0,sbe.dll,10.00.14393.1066
AVI Mux,0x00200000,1,0,qcap.dll,10.00.14393.0000
Line 21 Decoder 2,0x00600002,1,1,quartz.dll,10.00.14393.1066
File Source (Async.),0x00400000,0,1,quartz.dll,10.00.14393.1066
File Source (URL),0x00400000,0,1,quartz.dll,10.00.14393.1066
Infinite Pin Tee Filter,0x00200000,1,1,qcap.dll,10.00.14393.0000
Enhanced Video Renderer,0x00200000,1,0,evr.dll,10.00.14393.0953
BDA MPEG2 Transport Information Filter,0x00200000,2,0,psisrndr.ax,10.00.14393.0000
MPEG Video Decoder,0x40000001,1,1,quartz.dll,10.00.14393.1066
 
WDM Streaming Tee/Splitter Devices:
Tee/Sink-to-Sink Converter,0x00200000,1,1,ksproxy.ax,10.00.14393.0000
 
Video Compressors:
WMVideo8 Encoder DMO,0x00600800,1,1,wmvxencd.dll,10.00.14393.0000
WMVideo9 Encoder DMO,0x00600800,1,1,wmvencod.dll,10.00.14393.0000
MSScreen 9 encoder DMO,0x00600800,1,1,wmvsencd.dll,10.00.14393.0000
DV Video Encoder,0x00200000,0,0,qdv.dll,10.00.14393.0000
MJPEG Compressor,0x00200000,0,0,quartz.dll,10.00.14393.1066
 
Audio Compressors:
WM Speech Encoder DMO,0x00600800,1,1,WMSPDMOE.DLL,10.00.14393.0000
WMAudio Encoder DMO,0x00600800,1,1,WMADMOE.DLL,10.00.14393.0000
IMA ADPCM,0x00200000,1,1,quartz.dll,10.00.14393.1066
PCM,0x00200000,1,1,quartz.dll,10.00.14393.1066
Microsoft ADPCM,0x00200000,1,1,quartz.dll,10.00.14393.1066
GSM 6.10,0x00200000,1,1,quartz.dll,10.00.14393.1066
CCITT A-Law,0x00200000,1,1,quartz.dll,10.00.14393.1066
CCITT u-Law,0x00200000,1,1,quartz.dll,10.00.14393.1066
MPEG Layer-3,0x00200000,1,1,quartz.dll,10.00.14393.1066
 
PBDA CP Filters:
PBDA DTFilter,0x00600000,1,1,CPFilters.dll,10.00.14393.1358
PBDA ETFilter,0x00200000,0,0,CPFilters.dll,10.00.14393.1358
PBDA PTFilter,0x00200000,0,0,CPFilters.dll,10.00.14393.1358
 
Midi Renderers:
Default MidiOut Device,0x00800000,1,0,quartz.dll,10.00.14393.1066
Microsoft GS Wavetable Synth,0x00200000,1,0,quartz.dll,10.00.14393.1066
 
WDM Streaming Capture Devices:
HP Webcam,0x00200000,1,2,ksproxy.ax,10.00.14393.0000
 
BDA Network Providers:
Microsoft ATSC Network Provider,0x00200000,0,1,MSDvbNP.ax,10.00.14393.0000
Microsoft DVBC Network Provider,0x00200000,0,1,MSDvbNP.ax,10.00.14393.0000
Microsoft DVBS Network Provider,0x00200000,0,1,MSDvbNP.ax,10.00.14393.0000
Microsoft DVBT Network Provider,0x00200000,0,1,MSDvbNP.ax,10.00.14393.0000
Microsoft Network Provider,0x00200000,0,1,MSNP.ax,10.00.14393.0000
 
Video Capture Sources:
HP Webcam,0x00200000,1,2,ksproxy.ax,10.00.14393.0000
 
Multi-Instance Capable VBI Codecs:
VBI Codec,0x00600000,1,4,VBICodec.ax,10.00.14393.0000
 
BDA Transport Information Renderers:
BDA MPEG2 Transport Information Filter,0x00600000,2,0,psisrndr.ax,10.00.14393.0000
MPEG-2 Sections and Tables,0x00600000,1,0,Mpeg2Data.ax,10.00.14393.0000
 
BDA CP/CA Filters:
Decrypt/Tag,0x00600000,1,1,EncDec.dll,10.00.14393.0351
Encrypt/Tag,0x00200000,0,0,EncDec.dll,10.00.14393.0351
PTFilter,0x00200000,0,0,EncDec.dll,10.00.14393.0351
XDS Codec,0x00200000,0,0,EncDec.dll,10.00.14393.0351
 
WDM Streaming Communication Transforms:
Tee/Sink-to-Sink Converter,0x00200000,1,1,ksproxy.ax,10.00.14393.0000
 
Audio Renderers:
Default DirectSound Device,0x00800000,1,0,quartz.dll,10.00.14393.1066
Default WaveOut Device,0x00200000,1,0,quartz.dll,10.00.14393.1066
 
 
----------------------------
Preferred DirectShow Filters
----------------------------
 
[HKEY_LOCAL_MACHINE\Software\Microsoft\DirectShow\Preferred]
 
<media subtype GUID>, [<filter friendly name>, ]<filter CLSID>
 
MEDIASUBTYPE_MPEG1Payload, MPEG Video Decoder, CLSID_CMpegVideoCodec
MEDIASUBTYPE_MPEG1Packet, MPEG Video Decoder, CLSID_CMpegVideoCodec
MEDIASUBTYPE_DVD_LPCM_AUDIO, Microsoft DTV-DVD Audio Decoder, CLSID_CMPEG2AudDecoderDS
MEDIASUBTYPE_MPEG2_AUDIO, Microsoft DTV-DVD Audio Decoder, CLSID_CMPEG2AudDecoderDS
MEDIASUBTYPE_MPEG2_VIDEO, Microsoft DTV-DVD Video Decoder, CLSID_CMPEG2VidDecoderDS
{78766964-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
{7634706D-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
MEDIASUBTYPE_mp4s, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
{6C737664-0000-0010-8000-00AA00389B71}, DV Video Decoder, CLSID_DVVideoCodec
{64737664-0000-0010-8000-00AA00389B71}, DV Video Decoder, CLSID_DVVideoCodec
{64697678-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
{64687664-0000-0010-8000-00AA00389B71}, DV Video Decoder, CLSID_DVVideoCodec
{58564944-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
{5634504D-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
MEDIASUBTYPE_MP4S, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
MEDIASUBTYPE_WMVR, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_WMVP, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_MJPG, MJPEG Decompressor, CLSID_MjpegDec
{44495658-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
MEDIASUBTYPE_WMVA, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_mpg4, Mpeg4 Decoder DMO, CLSID_CMpeg4DecMediaObject
MEDIASUBTYPE_MPG4, Mpeg4 Decoder DMO, CLSID_CMpeg4DecMediaObject
MEDIASUBTYPE_h264, Microsoft DTV-DVD Video Decoder, CLSID_CMPEG2VidDecoderDS
MEDIASUBTYPE_H264, Microsoft DTV-DVD Video Decoder, CLSID_CMPEG2VidDecoderDS
MEDIASUBTYPE_WMV3, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_mp43, Mpeg43 Decoder DMO, CLSID_CMpeg43DecMediaObject
MEDIASUBTYPE_MP43, Mpeg43 Decoder DMO, CLSID_CMpeg43DecMediaObject
MEDIASUBTYPE_m4s2, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
MEDIASUBTYPE_WMV2, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_MSS2, WMV Screen decoder DMO, CLSID_CMSSCDecMediaObject
MEDIASUBTYPE_M4S2, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
MEDIASUBTYPE_WVP2, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_mp42, Mpeg4 Decoder DMO, CLSID_CMpeg4DecMediaObject
MEDIASUBTYPE_MP42, Mpeg4 Decoder DMO, CLSID_CMpeg4DecMediaObject
MEDIASUBTYPE_WMV1, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_MSS1, WMV Screen decoder DMO, CLSID_CMSSCDecMediaObject
MEDIASUBTYPE_WVC1, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_AVC1, Microsoft DTV-DVD Video Decoder, CLSID_CMPEG2VidDecoderDS
{20637664-0000-0010-8000-00AA00389B71}, DV Video Decoder, CLSID_DVVideoCodec
MEDIASUBTYPE_MPEG_LOAS, Microsoft DTV-DVD Audio Decoder, CLSID_CMPEG2AudDecoderDS
MEDIASUBTYPE_MPEG_ADTS_AAC, Microsoft DTV-DVD Audio Decoder, CLSID_CMPEG2AudDecoderDS
MEDIASUBTYPE_WMAUDIO_LOSSLESS, WMAudio Decoder DMO, CLSID_CWMADecMediaObject
MEDIASUBTYPE_WMAUDIO3, WMAudio Decoder DMO, CLSID_CWMADecMediaObject
WMMEDIASUBTYPE_WMAudioV8, WMAudio Decoder DMO, CLSID_CWMADecMediaObject
MEDIASUBTYPE_MSAUDIO1, WMAudio Decoder DMO, CLSID_CWMADecMediaObject
MEDIASUBTYPE_RAW_AAC1, Microsoft DTV-DVD Audio Decoder, CLSID_CMPEG2AudDecoderDS
WMMEDIASUBTYPE_MP3, MP3 Decoder DMO, CLSID_CMP3DecMediaObject
MEDIASUBTYPE_MPEG1AudioPayload, MPEG Audio Decoder, CLSID_CMpegAudioCodec
WMMEDIASUBTYPE_WMSP2, WMSpeech Decoder DMO, CLSID_CWMSPDecMediaObject
WMMEDIASUBTYPE_WMSP1, WMSpeech Decoder DMO, CLSID_CWMSPDecMediaObject
 
 
---------------------------
Media Foundation Transforms
---------------------------
 
[HKEY_LOCAL_MACHINE\Software\Classes\MediaFoundation\Transforms]
 
<category>:
  <transform friendly name>, <transform CLSID>, <flags>, [<merit>, ]<file name>, <file version>
 
Video Decoders:
  Microsoft MPEG Video Decoder MFT, {2D709E52-123F-49B5-9CBC-9AF5CDE28FB9}, 0x1, msmpeg2vdec.dll, 10.00.14393.0953
  DV Decoder MFT, {404A6DE5-D4D6-4260-9BC7-5A6CBD882432}, 0x1, mfdvdec.dll, 10.00.14393.0000
  Microsoft H265 Video Decoder MFT, {420A51A3-D605-430C-B4FC-45274FA6C562}, 0x1, hevcdecoder.dll, 10.00.14393.0953
  Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT, 0x1, mp4sdecd.dll, 10.00.14393.0000
  Microsoft H264 Video Decoder MFT, CLSID_CMSH264DecoderMFT, 0x1, msmpeg2vdec.dll, 10.00.14393.0953
  WMV Screen decoder MFT, CLSID_CMSSCDecMediaObject, 0x1, wmvsdecd.dll, 10.00.14393.0000
  WMVideo Decoder MFT, CLSID_CWMVDecMediaObject, 0x1, wmvdecod.dll, 10.00.14393.0953
  MJPEG Decoder MFT, {CB17E772-E1CC-4633-8450-5617AF577905}, 0x1, mfmjpegdec.dll, 10.00.14393.1066
  Mpeg43 Decoder MFT, CLSID_CMpeg43DecMediaObject, 0x1, mp43decd.dll, 10.00.14393.0000
  Microsoft WebM MF VP8 Decoder Transform, {E3AAF548-C9A4-4C6E-234D-5ADA374B0000}, 0x1, MSVP9DEC.dll, 10.00.14393.1066
  Mpeg4 Decoder MFT, CLSID_CMpeg4DecMediaObject, 0x1, mpg4decd.dll, 10.00.14393.0000
Video Encoders:
  H264 Encoder MFT, {6CA50344-051A-4DED-9779-A43305165E35}, 0x1, mfh264enc.dll, 10.00.14393.0000
  WMVideo8 Encoder MFT, CLSID_CWMVXEncMediaObject, 0x1, wmvxencd.dll, 10.00.14393.0000
  Microsoft MF VPX Encoder Transform, {AEB6C755-2546-4881-82CC-E15AE5EBFF3D}, 0x1, MSVPXENC.dll, 10.00.14393.0953
  H263 Encoder MFT, {BC47FCFE-98A0-4F27-BB07-698AF24F2B38}, 0x1, mfh263enc.dll, 10.00.14393.0000
  WMVideo9 Encoder MFT, CLSID_CWMV9EncMediaObject, 0x1, wmvencod.dll, 10.00.14393.0000
  Microsoft MPEG-2 Video Encoder MFT, {E6335F02-80B7-4DC4-ADFA-DFE7210D20D5}, 0x2, msmpeg2enc.dll, 10.00.14393.0000
  H265 Encoder MFT, {F2F84074-8BCA-40BD-9159-E880F673DD3B}, 0x1, mfh265enc.dll, 10.00.14393.0000
Video Effects:
  Frame Rate Converter, CLSID_CFrameRateConvertDmo, 0x1, mfvdsp.dll, 10.00.14393.0000
  Resizer MFT, CLSID_CResizerDMO, 0x1, vidreszr.dll, 10.00.14393.0000
  VideoStabilization MFT, {51571744-7FE4-4FF2-A498-2DC34FF74F1B}, 0x1, MSVideoDSP.dll, 10.00.14393.0206
  Color Control, CLSID_CColorControlDmo, 0x1, mfvdsp.dll, 10.00.14393.0000
  Color Converter MFT, CLSID_CColorConvertDMO, 0x1, colorcnv.dll, 10.00.14393.0000
Video Processor:
  Microsoft Video Processor MFT, {88753B26-5B24-49BD-B2E7-0C445C78C982}, 0x1, msvproc.dll, 10.00.14393.0351
Audio Decoders:
  Microsoft Dolby Digital Plus Decoder MFT, {177C0AFE-900B-48D4-9E4C-57ADD250B3D4}, 0x1, DolbyDecMFT.dll, 10.00.14393.0351
  MS AMRNB Decoder MFT, {265011AE-5481-4F77-A295-ABB6FFE8D63E}, 0x1, MSAMRNBDecoder.dll, 10.00.14393.0000
  WMAudio Decoder MFT, CLSID_CWMADecMediaObject, 0x1, WMADMOD.DLL, 10.00.14393.0000
  Microsoft AAC Audio Decoder MFT, CLSID_CMSAACDecMFT, 0x1, MSAudDecMFT.dll, 10.00.14393.0206
  A-law Wrapper MFT, {36CB6E0C-78C1-42B2-9943-846262F31786}, 0x1, mfcore.dll, 10.00.14393.1198
  GSM ACM Wrapper MFT, {4A76B469-7B66-4DD4-BA2D-DDF244C766DC}, 0x1, mfcore.dll, 10.00.14393.1198
  WMAPro over S/PDIF MFT, CLSID_CWMAudioSpdTxDMO, 0x1, WMADMOD.DLL, 10.00.14393.0000
  Microsoft Opus Audio Decoder MFT, {63E17C10-2D43-4C42-8FE3-8D8B63E46A6A}, 0x1, MSOpusDecoder.dll, 10.00.14393.0000
  Microsoft FLAC Audio Decoder MFT, {6B0B3E6B-A2C5-4514-8055-AFE8A95242D9}, 0x1, MSFlacDecoder.dll, 10.00.14393.0000
  Microsoft MPEG Audio Decoder MFT, {70707B39-B2CA-4015-ABEA-F8447D22D88B}, 0x1, MSAudDecMFT.dll, 10.00.14393.0206
  WMSpeech Decoder DMO, CLSID_CWMSPDecMediaObject, 0x1, WMSPDMOD.DLL, 10.00.14393.0000
  G711 Wrapper MFT, {92B66080-5E2D-449E-90C4-C41F268E5514}, 0x1, mfcore.dll, 10.00.14393.1198
  IMA ADPCM ACM Wrapper MFT, {A16E1BFF-A80D-48AD-AECD-A35C005685FE}, 0x1, mfcore.dll, 10.00.14393.1198
  MP3 Decoder MFT, CLSID_CMP3DecMediaObject, 0x1, mp3dmod.dll, 10.00.14393.0000
  Microsoft ALAC Audio Decoder MFT, {C0CD7D12-31FC-4BBC-B363-7322EE3E1879}, 0x1, MSAlacDecoder.dll, 10.00.14393.0000
  ADPCM ACM Wrapper MFT, {CA34FE0A-5722-43AD-AF23-05F7650257DD}, 0x1, mfcore.dll, 10.00.14393.1198
  Dolby TrueHD IEC-61937 converter MFT, {CF5EEEDF-0E92-4B3B-A161-BD0FFE545E4B}, 0x1, mfaudiocnv.dll, 10.00.14393.0479
  DTS IEC-61937 converter MFT, {D035E24C-C877-42D7-A795-2A8A339B472F}, 0x1, mfaudiocnv.dll, 10.00.14393.0479
Audio Encoders:
  LPCM DVD-Audio MFT, {068A8476-9229-4CC0-9D49-2FC699DCD30A}, 0x1, mfaudiocnv.dll, 10.00.14393.0479
  MP3 Encoder ACM Wrapper MFT, {11103421-354C-4CCA-A7A3-1AFF9A5B6701}, 0x1, mfcore.dll, 10.00.14393.1198
  Microsoft FLAC Audio Encoder MFT, {128509E9-C44E-45DC-95E9-C255B8F466A6}, 0x1, MSFlacEncoder.dll, 10.00.14393.0000
  WM Speech Encoder DMO, CLSID_CWMSPEncMediaObject2, 0x1, WMSPDMOE.DLL, 10.00.14393.0000
  MS AMRNB Encoder MFT, {2FAE8AFE-04A3-423A-A814-85DB454712B0}, 0x1, MSAMRNBEncoder.dll, 10.00.14393.0000
  Microsoft MPEG-2 Audio Encoder MFT, {46A4DD5C-73F8-4304-94DF-308F760974F4}, 0x1, msmpeg2enc.dll, 10.00.14393.0000
  WMAudio Encoder MFT, CLSID_CWMAEncMediaObject, 0x1, WMADMOE.DLL, 10.00.14393.0000
  Microsoft AAC Audio Encoder MFT, {93AF0C51-2275-45D2-A35B-F2BA21CAED00}, 0x1, mfAACEnc.dll, 10.00.14393.0000
  Microsoft ALAC Audio Encoder MFT, {9AB6A28C-748E-4B6A-BFFF-CC443B8E8FB4}, 0x1, MSAlacEncoder.dll, 10.00.14393.0000
  Microsoft Dolby Digital Encoder MFT, {AC3315C9-F481-45D7-826C-0B406C1F64B8}, 0x1, msac3enc.dll, 10.00.14393.0206
Audio Effects:
  AEC, CLSID_CWMAudioAEC, 0x1, mfwmaaec.dll, 10.00.14393.0000
  Resampler MFT, CLSID_CResamplerMediaObject, 0x1, resampledmo.dll, 10.00.14393.0000
Multiplexers:
  Microsoft MPEG2 Multiplexer MFT, {AB300F71-01AB-46D2-AB6C-64906CB03258}, 0x2, mfmpeg2srcsnk.dll, 10.00.14393.1198
Others:
  Microsoft H264 Video Remux (MPEG2TSToMP4) MFT, {05A47EBB-8BF0-4CBF-AD2F-3B71D75866F5}, 0x1, msmpeg2vdec.dll, 10.00.14393.0953
 
 
--------------------------------------------
Media Foundation Enabled Hardware Categories
--------------------------------------------
 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Media Foundation\HardwareMFT]
 
 
 
-------------------------------------
Media Foundation Byte Stream Handlers
-------------------------------------
 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Media Foundation\ByteStreamHandlers]
[HKEY_LOCAL_MACHINE\Software\Classes\MediaFoundation\MediaSources\Preferred]
 
<file ext. or MIME type>, <handler CLSID>, <brief description>[, Preferred]
 
.3g2, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.3gp, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.3gp2, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.3gpp, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.aac, {926F41F7-003E-4382-9E84-9E953BE10562}, ADTS Byte Stream Handler, Preferred
.ac3, {46031BA1-083F-47D9-8369-23C92BDAB2FF}, AC-3 Byte Stream Handler, Preferred
.adt, {926F41F7-003E-4382-9E84-9E953BE10562}, ADTS Byte Stream Handler, Preferred
.adts, {926F41F7-003E-4382-9E84-9E953BE10562}, ADTS Byte Stream Handler, Preferred
.am?, {EFE6208A-0A2C-49FA-8A01-3768B559B6DA}, MF AMRNB Media Source ByteStreamHandler
.amr, {EFE6208A-0A2C-49FA-8A01-3768B559B6DA}, MF AMRNB Media Source ByteStreamHandler, Preferred
.asf, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
.avi, {7AFA253E-F823-42F6-A5D9-714BDE467412}, AVI Byte Stream Handler, Preferred
.dvr-ms, {65964407-A5D8-4060-85B0-1CCD63F768E2}, dvr-ms Byte Stream Handler, Preferred
.dvr-ms, {A8721937-E2FB-4D7A-A9EE-4EB08C890B6E}, MF SBE Source ByteStreamHandler
.ec3, {46031BA1-083F-47D9-8369-23C92BDAB2FF}, AC-3 Byte Stream Handler, Preferred
.flac, {0E41CFB8-0506-40F4-A516-77CC23642D91}, MF FLAC Media Source ByteStreamHandler, Preferred
.m2t, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.m2ts, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.m4a, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.m4v, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.mk3d, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, MKV Byte Stream Handler, Preferred
.mka, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, MKV Byte Stream Handler, Preferred
.mks, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, MKV Byte Stream Handler, Preferred
.mkv, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, MKV Byte Stream Handler, Preferred
.mod, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.mov, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.mp2v, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.mp3, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
.mp4, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.mp4v, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.mpa, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
.mpeg, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.mpg, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.mts, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.nsc, {B084785C-DDE0-4D30-8CA8-05A373E185BE}, NSC Byte Stream Handler, Preferred
.sami, {7A56C4CB-D678-4188-85A8-BA2EF68FA10D}, SAMI Byte Stream Handler, Preferred
.smi, {7A56C4CB-D678-4188-85A8-BA2EF68FA10D}, SAMI Byte Stream Handler, Preferred
.tod, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.ts, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.tts, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.uvu, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.vob, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.wav, {42C9B9F5-16FC-47EF-AF22-DA05F7C842E3}, WAV Byte Stream Handler, Preferred
.wm, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
.wma, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
.wmv, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
.wtv, {65964407-A5D8-4060-85B0-1CCD63F768E2}, WTV Byte Stream Handler, Preferred
audio/3gpp, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
audio/3gpp2, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
audio/aac, {926F41F7-003E-4382-9E84-9E953BE10562}, ADTS Byte Stream Handler, Preferred
audio/aacp, {926F41F7-003E-4382-9E84-9E953BE10562}, ADTS Byte Stream Handler, Preferred
audio/eac3, {46031BA1-083F-47D9-8369-23C92BDAB2FF}, AC-3 Byte Stream Handler, Preferred
audio/L16, {3FFB3B8C-EB99-472B-8902-E1C1B05F07CF}, LPCM Byte Stream Handler, Preferred
audio/mp3, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
audio/mp4, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
audio/MP4A-LATM, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
audio/mpa, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
audio/mpeg, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
audio/mpeg3, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
audio/vnd.dlna.adts, {926F41F7-003E-4382-9E84-9E953BE10562}, ADTS Byte Stream Handler, Preferred
audio/vnd.dolby.dd-raw, {46031BA1-083F-47D9-8369-23C92BDAB2FF}, AC-3 Byte Stream Handler, Preferred
audio/wav, {42C9B9F5-16FC-47EF-AF22-DA05F7C842E3}, WAV Byte Stream Handler, Preferred
audio/x-aac, {926F41F7-003E-4382-9E84-9E953BE10562}, ADTS Byte Stream Handler, Preferred
audio/x-m4a, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
audio/x-matroska, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, MKV Byte Stream Handler, Preferred
audio/x-mp3, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
audio/x-mpeg, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
audio/x-ms-wma, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
audio/x-wav, {42C9B9F5-16FC-47EF-AF22-DA05F7C842E3}, WAV Byte Stream Handler, Preferred
video/3gpp, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
video/3gpp2, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
video/avi, {7AFA253E-F823-42F6-A5D9-714BDE467412}, AVI Byte Stream Handler, Preferred
video/mp4, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
video/mpeg, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
video/msvideo, {7AFA253E-F823-42F6-A5D9-714BDE467412}, AVI Byte Stream Handler, Preferred
video/vnd.dece.mp4, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
video/vnd.dlna.mpeg-tts, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
video/x-m4v, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
video/x-matroska, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, MKV Byte Stream Handler, Preferred
video/x-ms-asf, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
video/x-ms-wm, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
video/x-ms-wmv, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
video/x-msvideo, {7AFA253E-F823-42F6-A5D9-714BDE467412}, AVI Byte Stream Handler, Preferred
 
 
--------------------------------
Media Foundation Scheme Handlers
--------------------------------
 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Media Foundation\SchemeHandlers]
[HKEY_LOCAL_MACHINE\Software\Classes\MediaFoundation\MediaSources\Preferred]
 
<URL type>, <handler CLSID>, <brief description>[, Preferred]
 
file:, {477EC299-1421-4BDD-971F-7CCB933F21AD}, File Scheme Handler, Preferred
http:, {44CB442B-9DA9-49DF-B3FD-023777B16E50}, Http Scheme Handler
http:, {9EC4B4F9-3029-45AD-947B-344DE2A249E2}, Urlmon Scheme Handler
http:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
httpd:, {44CB442B-9DA9-49DF-B3FD-023777B16E50}, Http Scheme Handler, Preferred
httpnd:, {2EEEED04-0908-4CDB-AF8F-AC5B768A34C9}, Drm Scheme Handler, Preferred
https:, {37A61C8B-7F8E-4D08-B12B-248D73E9AB4F}, Secure Http Scheme Handler, Preferred
httpsd:, {37A61C8B-7F8E-4D08-B12B-248D73E9AB4F}, Secure Http Scheme Handler, Preferred
httpt:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
httpu:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
mcast:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
mcrecv:, {FA6D33D4-9405-4BA5-9983-12604AC8E77A}, Miracast Sink Scheme Handler, Preferred
mms:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
ms-appdata:, {CFC81939-3886-4ACF-9692-DA58037AE716}, MsAppData Scheme Handler, Preferred
ms-appx-web:, {8DB0224B-3D65-4F6F-8E12-BEB4B78B8974}, MsAppxWeb Scheme Handler, Preferred
ms-appx:, {8DB0224B-3D65-4F6F-8E12-BEB4B78B8974}, MsAppx Scheme Handler, Preferred
ms-winsoundevent:, {F79A6BF9-7415-4CF3-AE10-4559509ABC3C}, Sound Event Scheme Handler, Preferred
rtsp:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
rtspt:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
rtspu:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
sdp:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
 
 
-------------------------------------
Preferred Media Foundation Transforms
-------------------------------------
 
[HKEY_LOCAL_MACHINE\Software\Classes\MediaFoundation\Transforms\Preferred]
 
<media subtype GUID>, [<transform friendly name>, ]<transform CLSID>
 
{EB27CEC4-163E-4CA3-8B74-8E25F91B517E}, Dolby TrueHD IEC-61937 converter MFT, {CF5EEEDF-0E92-4B3B-A161-BD0FFE545E4B}
{E06D802C-DB46-11CF-B4D1-00805F6CBBEA}, Microsoft Dolby Digital Plus Decoder MFT, {177C0AFE-900B-48D4-9E4C-57ADD250B3D4}
MFVideoFormat_MPEG2, Microsoft MPEG Video Decoder MFT, {2D709E52-123F-49B5-9CBC-9AF5CDE28FB9}
MEDIASUBTYPE_DOLBY_DDPLUS, Microsoft Dolby Digital Plus Decoder MFT, {177C0AFE-900B-48D4-9E4C-57ADD250B3D4}
{A2E58EB7-0FA9-48BB-A40C-FA0E156D0645}, DTS IEC-61937 converter MFT, {D035E24C-C877-42D7-A795-2A8A339B472F}
{7634706D-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT
{73616D72-767A-494D-B478-F29D25DC9037}, MS AMRNB Decoder MFT, {265011AE-5481-4F77-A295-ABB6FFE8D63E}
MEDIASUBTYPE_mp4s, Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT
MFVideoFormat_DVSL, DV Decoder MFT, {404A6DE5-D4D6-4260-9BC7-5A6CBD882432}
MFVideoFormat_DVSD, DV Decoder MFT, {404A6DE5-D4D6-4260-9BC7-5A6CBD882432}
MFVideoFormat_DVHD, DV Decoder MFT, {404A6DE5-D4D6-4260-9BC7-5A6CBD882432}
MFVideoFormat_MP4V, Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT
{53564548-0000-0010-8000-00AA00389B71}, Microsoft H265 Video Decoder MFT, {420A51A3-D605-430C-B4FC-45274FA6C562}
MFVideoFormat_MP4S, Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT
{53314356-0000-0010-8000-00AA00389B71}, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_WMVR, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_WMVP, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
MFVideoFormat_MJPG, MJPEG Decoder MFT, {CB17E772-E1CC-4633-8450-5617AF577905}
{43564548-0000-0010-8000-00AA00389B71}, Microsoft H265 Video Decoder MFT, {420A51A3-D605-430C-B4FC-45274FA6C562}
MEDIASUBTYPE_WMVA, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
{3F40F4F0-5622-4FF8-B6D8-A17A584BEE5E}, Microsoft H264 Video Decoder MFT, CLSID_CMSH264DecoderMFT
MEDIASUBTYPE_mpg4, Mpeg4 Decoder MFT, CLSID_CMpeg4DecMediaObject
MEDIASUBTYPE_MPG4, Mpeg4 Decoder MFT, CLSID_CMpeg4DecMediaObject
MFVideoFormat_H264, Microsoft H264 Video Decoder MFT, CLSID_CMSH264DecoderMFT
MFVideoFormat_WMV3, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
{33363248-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT
MEDIASUBTYPE_mp43, Mpeg43 Decoder MFT, CLSID_CMpeg43DecMediaObject
MFVideoFormat_MP43, Mpeg43 Decoder MFT, CLSID_CMpeg43DecMediaObject
MEDIASUBTYPE_m4s2, Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT
MFVideoFormat_WMV2, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
MFVideoFormat_MSS2, WMV Screen decoder MFT, CLSID_CMSSCDecMediaObject
MFVideoFormat_M4S2, Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT
MEDIASUBTYPE_WVP2, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_mp42, Mpeg4 Decoder MFT, CLSID_CMpeg4DecMediaObject
MEDIASUBTYPE_MP42, Mpeg4 Decoder MFT, CLSID_CMpeg4DecMediaObject
MFVideoFormat_WMV1, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
MFVideoFormat_MSS1, WMV Screen decoder MFT, CLSID_CMSSCDecMediaObject
MFVideoFormat_MPG1, Microsoft MPEG Video Decoder MFT, {2D709E52-123F-49B5-9CBC-9AF5CDE28FB9}
MFVideoFormat_WVC1, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
{30395056-0000-0010-8000-00AA00389B71}, Microsoft WebM MF VP8 Decoder Transform, {E3AAF548-C9A4-4C6E-234D-5ADA374B0000}
{30385056-0000-0010-8000-00AA00389B71}, Microsoft WebM MF VP8 Decoder Transform, {E3AAF548-C9A4-4C6E-234D-5ADA374B0000}
MFVideoFormat_DVC, DV Decoder MFT, {404A6DE5-D4D6-4260-9BC7-5A6CBD882432}
{0000F1AC-0000-0010-8000-00AA00389B71}, Microsoft FLAC Audio Decoder MFT, {6B0B3E6B-A2C5-4514-8055-AFE8A95242D9}
{00007361-0000-0010-8000-00AA00389B71}, MS AMRNB Decoder MFT, {265011AE-5481-4F77-A295-ABB6FFE8D63E}
{0000704F-0000-0010-8000-00AA00389B71}, Microsoft Opus Audio Decoder MFT, {63E17C10-2D43-4C42-8FE3-8D8B63E46A6A}
{00006C61-0000-0010-8000-00AA00389B71}, Microsoft ALAC Audio Decoder MFT, {C0CD7D12-31FC-4BBC-B363-7322EE3E1879}
{00002001-0000-0010-8000-00AA00389B71}, DTS IEC-61937 converter MFT, {D035E24C-C877-42D7-A795-2A8A339B472F}
{00002000-0000-0010-8000-00AA00389B71}, Microsoft Dolby Digital Plus Decoder MFT, {177C0AFE-900B-48D4-9E4C-57ADD250B3D4}
MFAudioFormat_AAC, Microsoft AAC Audio Decoder MFT, CLSID_CMSAACDecMFT
{00001600-0000-0100-0800-000aa00389b71}, Microsoft AAC Audio Decoder MFT, CLSID_CMSAACDecMFT
MFAudioFormat_WMAudio_Lossless, WMAudio Decoder MFT, CLSID_CWMADecMediaObject
MFAudioFormat_WMAudioV9, WMAudio Decoder MFT, CLSID_CWMADecMediaObject
MFAudioFormat_WMAudioV8, WMAudio Decoder MFT, CLSID_CWMADecMediaObject
MEDIASUBTYPE_MSAUDIO1, WMAudio Decoder MFT, CLSID_CWMADecMediaObject
MEDIASUBTYPE_RAW_AAC1, Microsoft AAC Audio Decoder MFT, CLSID_CMSAACDecMFT
MFAudioFormat_MP3, MP3 Decoder MFT, CLSID_CMP3DecMediaObject
MFAudioFormat_MPEG, Microsoft MPEG Audio Decoder MFT, {70707B39-B2CA-4015-ABEA-F8447D22D88B}
{00000031-0000-0010-8000-00AA00389B71}, GSM ACM Wrapper MFT, {4A76B469-7B66-4DD4-BA2D-DDF244C766DC}
{00000011-0000-0010-8000-00AA00389B71}, IMA ADPCM ACM Wrapper MFT, {A16E1BFF-A80D-48AD-AECD-A35C005685FE}
WMMEDIASUBTYPE_WMSP2, WMSpeech Decoder DMO, CLSID_CWMSPDecMediaObject
MFAudioFormat_MSP1, WMSpeech Decoder DMO, CLSID_CWMSPDecMediaObject
KSDATAFORMAT_SUBTYPE_MULAW, G711 Wrapper MFT, {92B66080-5E2D-449E-90C4-C41F268E5514}
{00000006-0000-0010-8000-00AA00389B71}, A-law Wrapper MFT, {36CB6E0C-78C1-42B2-9943-846262F31786}
KSDATAFORMAT_SUBTYPE_ADPCM, ADPCM ACM Wrapper MFT, {CA34FE0A-5722-43AD-AF23-05F7650257DD}
 
 
-------------------------------------
Disabled Media Foundation Transforms
-------------------------------------
 
[HKEY_LOCAL_MACHINE\Software\Classes\MediaFoundation\Transforms\DoNotUse]
 
<transform CLSID>
 
 
 
------------------------
Disabled Media Sources
------------------------
 
[HKEY_LOCAL_MACHINE\Software\Classes\MediaFoundation\MediaSources\DoNotUse]
 
<media source CLSID>
 
 
---------------
EVR Power Information
---------------
Current Setting: {5C67A112-A4C9-483F-B4A7-1D473BECAFDC} (Quality) 
  Quality Flags: 2576
    Enabled:
    Force throttling
    Allow half deinterlace
    Allow scaling
    Decode Power Usage: 100
  Balanced Flags: 1424
    Enabled:
    Force throttling
    Allow batching
    Force half deinterlace
    Force scaling
    Decode Power Usage: 50
  PowerFlags: 1424
    Enabled:
    Force throttling
    Allow batching
    Force half deinterlace
    Force scaling
    Decode Power Usage: 0
 
---------------
Diagnostics
---------------
 
Windows Error Reporting:
+++ WER0 +++:
No Data
+++ WER1 +++:
No Data
+++ WER2 +++:
No Data
+++ WER3 +++:
No Data
+++ WER4 +++:
No Data
+++ WER5 +++:
No Data
+++ WER6 +++:
No Data
+++ WER7 +++:
No Data
+++ WER8 +++:
No Data
+++ WER9 +++:
No Data

  • 0

#117
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Do you know which battery you bought?

 

Apparently these only have  about 5 hrs battery life when new.  They make a 12 cell battery with more capacity but it's a bit larger and heavier than the original.

 

Did you forget to reenable the sound driver?

When you were disabling drivers did you disable the webcam?  The Broadcom Network Driver?

 

Appears this was an upgrade from Win 7 so no support from HP.

 

 

Let's look at your event logs

 

 

 
1. Please download the Event Viewer Tool by Vino Rosso
and save it to your Desktop:
2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:
 
* System
4. Under 'Select type to list', select:
* Error
* Warning
 
 
Then use the 'Number of events' as follows:
 
 
1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.
 
 
Please post the Output log in your next reply then repeat but select Application.  (Each time you run VEW it overwrites the log so copy the first one to a Reply or rename it before running it a second time.)

  • 0

#118
tl79

tl79

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 186 posts

Battery was a 6-cell generic 10.8v 5200mAh.

 

Sound is back on.  

 

Where do I find webcam and broadcom network driver?


  • 0

#119
tl79

tl79

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 186 posts
Vino's Event Viewer v01c run on Windows 7 in English
Report run at 03/07/2017 6:07:23 PM
 
Note: All dates below are in the format dd/mm/yyyy
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 03/07/2017 10:52:36 PM
Type: Error Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}  and APPID  {F72671A9-012C-4725-9D2F-2A4D32D65169}  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Log: 'System' Date/Time: 03/07/2017 9:09:26 PM
Type: Error Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}  and APPID  {F72671A9-012C-4725-9D2F-2A4D32D65169}  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Log: 'System' Date/Time: 03/07/2017 9:08:12 PM
Type: Error Category: 0
Event: 10003 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN Extensibility Module has stopped unexpectedly.  Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll 
 
Log: 'System' Date/Time: 03/07/2017 9:08:12 PM
Type: Error Category: 0
Event: 10003 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN Extensibility Module has stopped unexpectedly.  Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll 
 
Log: 'System' Date/Time: 03/07/2017 9:08:03 PM
Type: Error Category: 0
Event: 10003 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN Extensibility Module has stopped unexpectedly.  Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 03/07/2017 10:52:37 PM
Type: Warning Category: 0
Event: 1 Source: RTL8167
Realtek PCIe FE Family Controller is disconnected from network.
 
Log: 'System' Date/Time: 03/07/2017 10:52:36 PM
Type: Warning Category: 1014
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name wpad timed out after none of the configured DNS servers responded.
 
Log: 'System' Date/Time: 03/07/2017 9:31:33 PM
Type: Warning Category: 0
Event: 4 Source: Microsoft-Windows-FilterManager
File System Filter 'wcifs' (Version 10.0, ?2016?-?09?-?15T11:42:03.000000000Z) failed to attach to volume '\Device\HarddiskVolumeShadowCopy3'.  The filter returned a non-standard final status of 0xC000000D.  This filter and/or its supporting applications should handle this condition.  If this condition persists, contact the vendor.
 
Log: 'System' Date/Time: 03/07/2017 9:09:24 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571for more information.
 
Log: 'System' Date/Time: 03/07/2017 9:09:10 PM
Type: Warning Category: 0
Event: 1 Source: RTL8167
Realtek PCIe FE Family Controller is disconnected from network.

  • 0

#120
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Look under Network Adapters and Imaging Devices


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP