--------------------------------------- Malwarebytes Anti-Rootkit BETA 1.09.4.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 10.0.15063 Windows 10 x64 Account is Administrative Internet Explorer version: 11.296.15063.0 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 3.500000 GHz Memory total: 8588013568, free: 6122586112 Downloaded database version: v2017.05.17.06 Downloaded database version: v2017.05.15.01 ======================================= Initializing... Driver version: 0.3.0.4 ------------ Kernel report ------------ 05/17/2017 19:15:42 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_AuthenticAMD.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\System32\drivers\ksecdd.sys \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\System32\drivers\FLTMGR.SYS \SystemRoot\System32\drivers\clipsp.sys \SystemRoot\System32\drivers\cmimcext.sys \SystemRoot\System32\drivers\ntosext.sys \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\cng.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\SleepStudyHelper.sys \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\system32\drivers\WindowsTrustedRT.sys \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\system32\drivers\ndistpr64.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\system32\drivers\NDIS.SYS \SystemRoot\system32\drivers\TDI.SYS \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\system32\drivers\CEA.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\pciide.sys \SystemRoot\System32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\atapi.sys \SystemRoot\System32\drivers\ataport.SYS \SystemRoot\System32\drivers\storahci.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Wof.sys \SystemRoot\System32\Drivers\NTFS.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\drivers\wfplwfs.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\System32\drivers\volume.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\iorate.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\system32\drivers\filecrypt.sys \SystemRoot\system32\drivers\tbs.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\vmbkmclr.sys \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\drivers\vwififlt.sys \SystemRoot\System32\drivers\pacer.sys \SystemRoot\system32\drivers\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\drivers\gpuenergydrv.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\SysWow64\drivers\AsIO.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys \SystemRoot\System32\drivers\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \SystemRoot\System32\drivers\amdppm.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\portcls.sys \SystemRoot\System32\drivers\drmk.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\rt640x64.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\system32\drivers\ucx01000.sys \SystemRoot\System32\drivers\usbohci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\serial.sys \SystemRoot\System32\drivers\serenum.sys \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\system32\drivers\AtihdWT6.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\system32\DRIVERS\HdAudio.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\win32kfull.sys \SystemRoot\System32\win32kbase.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_storahci.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\drivers\dxgmms2.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\kbdhid.sys \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\wcifs.sys \SystemRoot\system32\drivers\storqosflt.sys \SystemRoot\System32\drivers\registry.sys \SystemRoot\system32\drivers\rspndr.sys \SystemRoot\system32\drivers\lltdio.sys \SystemRoot\System32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\mslldp.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\system32\drivers\mmcss.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\drivers\condrv.sys \SystemRoot\System32\drivers\monitor.sys \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys ----------- End ----------- Done! Scan started Database versions: main: v2017.05.17.06 rootkit: v2017.04.02.01 <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffc68f8d5ff060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffc68f8d5759f0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffc68f8d5ff060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffffc68f8bb78060, DeviceName: \Device\00000027\, DriverName: \Driver\storahci\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... File C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys will be destroyed Infected: C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys --> [Rootkit.Agent.PUA] Done! Drive 0 This is a System drive Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: DD0E7A7A Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 716800 Partition is bootable Partition file system is NTFS Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 718848 Numsec = 1951879168 Partition is not bootable Partition file system is NTFS Partition 2 type is Other (0x27) Partition is NOT ACTIVE. Partition starts at LBA: 1952598016 Numsec = 921600 Partition is not bootable Partition file system is NTFS Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition is not bootable Disk Size: 1000204886016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1953505168-1953525168)... Done! File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\apphelp.dll" is sparse (flags = 32768) File "C:\Windows\AppPatch\AcLayers.dll" is sparse (flags = 32768) File "C:\Windows\System32\msvcrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\user32.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\gdi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ucrtbase.dll" is sparse (flags = 32768) File "C:\Windows\System32\shell32.dll" is sparse (flags = 32768) File "C:\Windows\System32\cfgmgr32.dll" is sparse (flags = 32768) File "C:\Windows\System32\SHCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcrt4.dll" is sparse (flags = 32768) File "C:\Windows\System32\sspicli.dll" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sechost.dll" is sparse (flags = 32768) File "C:\Windows\System32\combase.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STORAGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\advapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\shlwapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\KERNEL.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\powrprof.dll" is sparse (flags = 32768) File "C:\Windows\System32\profapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleaut32.dll" is sparse (flags = 32768) File "C:\Windows\System32\setupapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\mpr.dll" is sparse (flags = 32768) File "C:\Windows\System32\winspool.drv" is sparse (flags = 32768) File "C:\Windows\System32\bcrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\sfc_os.dll" is sparse (flags = 32768) File "C:\Windows\System32\imm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\imagehlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ole32.dll" is sparse (flags = 32768) File "C:\Windows\System32\version.dll" is sparse (flags = 32768) File "C:\Windows\System32\wintrust.dll" is sparse (flags = 32768) File "C:\Windows\System32\msasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\crypt32.dll" is sparse (flags = 32768) File "C:\Windows\System32\psapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wininet.dll" is sparse (flags = 32768) File "C:\Windows\System32\netapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\ws2_32.dll" is sparse (flags = 32768) File "C:\Windows\System32\comdlg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\userenv.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.0_none_8b4e86125c6fbfec\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winmm.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINMMBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netutils.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\rsaenh.dll" is sparse (flags = 32768) File "C:\Windows\System32\uxtheme.dll" is sparse (flags = 32768) File "C:\Windows\System32\msctf.dll" is sparse (flags = 32768) File "C:\Windows\System32\dwmapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkscli.dll" is sparse (flags = 32768) File "C:\Windows\System32\cscapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\iertutil.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPHLPAPI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\winhttp.dll" is sparse (flags = 32768) File "C:\Windows\System32\mswsock.dll" is sparse (flags = 32768) File "C:\Windows\System32\winnsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\urlmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\msIso.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasadhlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\FWPUCLNT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\srvcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntmarta.dll" is sparse (flags = 32768) File "C:\Windows\System32\clbcatq.dll" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERMGRCLI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wtsapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winsta.dll" is sparse (flags = 32768) File "C:\Windows\System32\propsys.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STATEREPOSITORY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\STATEREPOSITORY.CORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\mssprxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\coml2.dll" is sparse (flags = 32768) File "C:\Windows\System32\linkinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntshrui.dll" is sparse (flags = 32768) File "C:\Windows\System32\smss.exe" is sparse (flags = 32768) File "C:\Windows\System32\csrss.exe" is sparse (flags = 32768) File "C:\Windows\System32\wininit.exe" is sparse (flags = 32768) File "C:\Windows\System32\services.exe" is sparse (flags = 32768) File "C:\Windows\System32\lsass.exe" is sparse (flags = 32768) File "C:\Windows\System32\winlogon.exe" is sparse (flags = 32768) File "C:\Windows\System32\svchost.exe" is sparse (flags = 32768) File "C:\Windows\System32\FONTDRVHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dwm.exe" is sparse (flags = 32768) File "C:\Windows\System32\spoolsv.exe" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\msimg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\mfc42.dll" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\dataup\dataup.exe --> [Adware.Yelloader] Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Dataup --> [Adware.Yelloader] File "C:\Windows\System32\sxs.dll" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\d3d9.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\wbemprox.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbemcomn.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\wbemsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\fastprox.dll" is sparse (flags = 32768) File "C:\Windows\System32\MMDevAPI.dll" is sparse (flags = 32768) File "C:\Windows\System32\devobj.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdmaud.drv" is sparse (flags = 32768) File "C:\Windows\System32\ksuser.dll" is sparse (flags = 32768) File "C:\Windows\System32\avrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\msacm32.drv" is sparse (flags = 32768) File "C:\Windows\System32\msacm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\midimap.dll" is sparse (flags = 32768) File "C:\Windows\System32\devenum.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdmo.dll" is sparse (flags = 32768) File "C:\Windows\System32\netprofm.dll" is sparse (flags = 32768) File "C:\Windows\System32\npmproxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\NapiNSP.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpnsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlaapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winrnr.dll" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dasHost.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Media Player\wmpnetwk.exe" is sparse (flags = 32768) File "C:\Windows\System32\gpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptnet.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiPrvSE.exe" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\sihost.exe" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\explorer.exe" is sparse (flags = 32768) File "C:\Windows\System32\TASKHOSTW.EXE" is sparse (flags = 32768) Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] File "C:\Windows\System32\Wldap32.dll" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\System32\RUNTIMEBROKER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\BACKGROUNDTASKHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMSETTINGSBROKER.EXE" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MSASCuiL.exe" is sparse (flags = 32768) File "C:\Windows\System32\wsock32.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.15063.0_none_d802f55807fa1ec7\GdiPlus.dll" is sparse (flags = 32768) File "C:\Windows\System32\wer.dll" is sparse (flags = 32768) File "C:\Windows\System32\xmllite.dll" is sparse (flags = 32768) File "C:\Windows\System32\cabinet.dll" is sparse (flags = 32768) File "C:\Windows\System32\Faultrep.dll" is sparse (flags = 32768) File "C:\Windows\System32\secur32.dll" is sparse (flags = 32768) File "C:\Windows\System32\loadperf.dll" is sparse (flags = 32768) File "C:\Windows\System32\pdh.dll" is sparse (flags = 32768) File "C:\Windows\System32\ncrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbghelp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbgcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\mlang.dll" is sparse (flags = 32768) File "C:\Windows\System32\msxml6.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\taskschd.dll" is sparse (flags = 32768) File "C:\Windows\System32\TWINAPI.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\Wpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidprov.dll" is sparse (flags = 32768) File "C:\Windows\System32\samcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleacc.dll" is sparse (flags = 32768) File "C:\Windows\System32\usp10.dll" is sparse (flags = 32768) File "C:\Windows\System32\DWrite.dll" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\d3d11.dll" is sparse (flags = 32768) File "C:\Windows\System32\dcomp.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxgi.dll" is sparse (flags = 32768) File "C:\Windows\System32\mscms.dll" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\msi.dll" is sparse (flags = 32768) File "C:\Windows\System32\cmd.exe" is sparse (flags = 32768) File "C:\Windows\System32\conhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\System32\credssp.dll" is sparse (flags = 32768) File "C:\Windows\System32\userinit.exe" is sparse (flags = 32768) File "C:\Windows\System32\scecli.dll" is sparse (flags = 32768) File "C:\Windows\System32\msv1_0.dll" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\appid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspclock.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpiex.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\Locator.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mpsdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\afd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ahcache.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\asyncmac.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv.sys" is sparse (flags = 32768) File "C:\Windows\System32\alg.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcifs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcnfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\luafv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bowser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cng.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\clfs.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cldflt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\registry.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mup.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\dllhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\condrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dam.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dfsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dxgkrnl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpip.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORCLASS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPATIALGRAPHFILTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fileinfo.sys" is sparse (flags = 32768) File "C:\Windows\System32\FXSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipfltdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fltMgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PRESENTATIONFONTCACHE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fvevol.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndisuio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFRd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wanarp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbengine.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\http.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hwpolicy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pacer.sys" is sparse (flags = 32768) File "C:\Windows\SysWOW64\perfhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\iorate.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\scfilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdFilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irda.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecdd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecpkg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksthunk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\lltdio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwififlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mstee.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mmcss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mskssrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MsMpEng.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wimmount.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxdav.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\modem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspqm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mountmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasl2tp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb10.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb20.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ucx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ufx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bridge.sys" is sparse (flags = 32768) File "C:\Windows\System32\msdtc.exe" is sparse (flags = 32768) File "C:\Windows\System32\VSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\msiexec.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mslldp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nwifi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndis.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiscap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndistapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiswan.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ndu.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwifibus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nsiproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdiWiFi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\vds.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\partmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcw.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\PEAuth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\RDPVIDEOMINIPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\qwavedrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspptp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasacd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\agilevpn.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspppoe.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rassstp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdbss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpdr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdyboost.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rspndr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SpbCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\snmptrap.exe" is sparse (flags = 32768) File "C:\Windows\System32\Spectrum.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Wdf01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\sppsvc.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srvnet.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgrx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpipreg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tdx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\terminpt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\servicing\TRUSTEDINSTALLER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbFlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UcmCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Udecx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\udfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBXHCI.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhf.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volsnap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdBoot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdNisDrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\NisSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wfplwfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiApSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ws2ifsl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFPf.sys" is sparse (flags = 32768) File "C:\Windows\System32\AJRouter.dll" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umpnpmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcss.dll" is sparse (flags = 32768) File "C:\Windows\System32\appinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\appidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\AxInstSv.dll" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\AUDIOENDPOINTBUILDER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\audiosrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\RpcEpMap.dll" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bdesvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\BFE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netman.dll" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cdpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\umpo.dll" is sparse (flags = 32768) File "C:\Windows\System32\qmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\ListSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lltdsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\browser.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\profsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bthserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\provsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\das.dll" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\certprop.dll" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ClipSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wscsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WsmSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wersvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wecsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dot3svc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dusmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\fdPHost.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsrslvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\dps.dll" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\eapsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\efssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ENTERPRISEAPPMGMTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FntCache.dll" is sparse (flags = 32768) File "C:\Windows\System32\es.dll" is sparse (flags = 32768) File "C:\Windows\System32\sdrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\srvsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\xbgmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FDResPub.dll" is sparse (flags = 32768) File "C:\Windows\System32\upnphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\fhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\hidserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\HVHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IKEEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\iphlpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\irmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\keyiso.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdtckrm.dll" is sparse (flags = 32768) File "C:\Windows\System32\lfsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lpasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lmhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ipnathlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\lsm.dll" is sparse (flags = 32768) File "C:\Windows\System32\moshost.dll" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MPSSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\iscsiexe.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsisvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ngcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NcaSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netlogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\trkwks.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\icsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pcasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\p2psvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pla.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\icsvcext.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPSECSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\qwave.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasmans.dll" is sparse (flags = 32768) File "C:\Windows\System32\mprdim.dll" is sparse (flags = 32768) File "C:\Windows\System32\regsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\RDXSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\RMapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\schedsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SCardSvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\seclogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\sensrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SEMgrSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\Sens.dll" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SessEnv.dll" is sparse (flags = 32768) File "C:\Windows\System32\shsvcs.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\smphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\StorSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\sstpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ssdpsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\wiaservc.dll" is sparse (flags = 32768) File "C:\Windows\System32\svsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\swprv.dll" is sparse (flags = 32768) File "C:\Windows\System32\sysmain.dll" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TabSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\termsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\tapisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TOKENBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umrdp.dll" is sparse (flags = 32768) File "C:\Windows\System32\Unistore.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\usermgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\usocore.dll" is sparse (flags = 32768) File "C:\Windows\System32\vaultsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\w32time.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbiosrvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wwansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WUDFSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcncsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdi.dll" is sparse (flags = 32768) File "C:\Windows\System32\WebClnt.dll" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wiarpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WMIsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wuaueng.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Program Files\Windows Mail\WinMail.exe" is sparse (flags = 32768) File "C:\Windows\System32\unregmp2.exe" is sparse (flags = 32768) File "C:\Windows\System32\ie4uinit.exe" is sparse (flags = 32768) File "C:\Users\steff\AppData\Local\Comms\UnistoreDB\store.vol" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\winscr\winscr.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\tnifv\qdcomsvc.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\uhiba\ct.exe --> [Adware.Yelloader] File "C:\Windows\System32\config\systemprofile\AppData\Local\DataSharing\Storage\DSTokenDB2.dat" is sparse (flags = 32768) --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.09.4.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 10.0.15063 Windows 10 x64 Account is Administrative Internet Explorer version: 11.296.15063.0 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 3.500000 GHz Memory total: 8588013568, free: 6267609088 ======================================= Initializing... Driver version: 0.3.0.4 ------------ Kernel report ------------ 05/17/2017 19:32:20 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_AuthenticAMD.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\System32\drivers\ksecdd.sys \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\System32\drivers\FLTMGR.SYS \SystemRoot\System32\drivers\clipsp.sys \SystemRoot\System32\drivers\cmimcext.sys \SystemRoot\System32\drivers\ntosext.sys \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\cng.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\SleepStudyHelper.sys \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\system32\drivers\WindowsTrustedRT.sys \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\system32\drivers\ndistpr64.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\system32\drivers\NDIS.SYS \SystemRoot\system32\drivers\TDI.SYS \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\system32\drivers\CEA.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\pciide.sys \SystemRoot\System32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\atapi.sys \SystemRoot\System32\drivers\ataport.SYS \SystemRoot\System32\drivers\storahci.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Wof.sys \SystemRoot\System32\Drivers\NTFS.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\drivers\wfplwfs.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\System32\drivers\volume.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\iorate.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\system32\drivers\filecrypt.sys \SystemRoot\system32\drivers\tbs.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\vmbkmclr.sys \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\drivers\vwififlt.sys \SystemRoot\System32\drivers\pacer.sys \SystemRoot\system32\drivers\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\drivers\gpuenergydrv.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\SysWow64\drivers\AsIO.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys \SystemRoot\System32\drivers\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \SystemRoot\System32\drivers\amdppm.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\portcls.sys \SystemRoot\System32\drivers\drmk.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\rt640x64.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\system32\drivers\ucx01000.sys \SystemRoot\System32\drivers\usbohci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\serial.sys \SystemRoot\System32\drivers\serenum.sys \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\system32\drivers\AtihdWT6.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\system32\DRIVERS\HdAudio.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\kbdhid.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_storahci.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\win32kfull.sys \SystemRoot\System32\win32kbase.sys \SystemRoot\System32\drivers\dxgmms2.sys \SystemRoot\System32\drivers\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\wcifs.sys \SystemRoot\system32\drivers\storqosflt.sys \SystemRoot\System32\drivers\registry.sys \SystemRoot\system32\drivers\mslldp.sys \SystemRoot\system32\drivers\lltdio.sys \SystemRoot\system32\drivers\rspndr.sys \SystemRoot\System32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\system32\drivers\mmcss.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\drivers\condrv.sys \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys ----------- End ----------- Done! Scan started Database versions: main: v2017.05.17.06 rootkit: v2017.04.02.01 <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffff928c53a0f060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffff928c5398a9f0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffff928c53a0f060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffff928c51fb43c0, DeviceName: \Device\00000027\, DriverName: \Driver\storahci\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... File C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys will be destroyed Infected: C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys --> [Rootkit.Agent.PUA] Done! Drive 0 This is a System drive Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: DD0E7A7A Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 716800 Partition is bootable Partition file system is NTFS Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 718848 Numsec = 1951879168 Partition is not bootable Partition file system is NTFS Partition 2 type is Other (0x27) Partition is NOT ACTIVE. Partition starts at LBA: 1952598016 Numsec = 921600 Partition is not bootable Partition file system is NTFS Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition is not bootable Disk Size: 1000204886016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1953505168-1953525168)... Done! File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\apphelp.dll" is sparse (flags = 32768) File "C:\Windows\AppPatch\AcLayers.dll" is sparse (flags = 32768) File "C:\Windows\System32\msvcrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\user32.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\gdi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ucrtbase.dll" is sparse (flags = 32768) File "C:\Windows\System32\shell32.dll" is sparse (flags = 32768) File "C:\Windows\System32\cfgmgr32.dll" is sparse (flags = 32768) File "C:\Windows\System32\SHCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcrt4.dll" is sparse (flags = 32768) File "C:\Windows\System32\sspicli.dll" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sechost.dll" is sparse (flags = 32768) File "C:\Windows\System32\combase.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STORAGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\advapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\shlwapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\KERNEL.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\powrprof.dll" is sparse (flags = 32768) File "C:\Windows\System32\profapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleaut32.dll" is sparse (flags = 32768) File "C:\Windows\System32\setupapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\mpr.dll" is sparse (flags = 32768) File "C:\Windows\System32\winspool.drv" is sparse (flags = 32768) File "C:\Windows\System32\bcrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\sfc_os.dll" is sparse (flags = 32768) File "C:\Windows\System32\imm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\imagehlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ole32.dll" is sparse (flags = 32768) File "C:\Windows\System32\version.dll" is sparse (flags = 32768) File "C:\Windows\System32\wintrust.dll" is sparse (flags = 32768) File "C:\Windows\System32\msasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\crypt32.dll" is sparse (flags = 32768) File "C:\Windows\System32\psapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wininet.dll" is sparse (flags = 32768) File "C:\Windows\System32\netapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\userenv.dll" is sparse (flags = 32768) File "C:\Windows\System32\ws2_32.dll" is sparse (flags = 32768) File "C:\Windows\System32\comdlg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\netutils.dll" is sparse (flags = 32768) File "C:\Windows\System32\winmm.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.0_none_8b4e86125c6fbfec\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINMMBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\rsaenh.dll" is sparse (flags = 32768) File "C:\Windows\System32\uxtheme.dll" is sparse (flags = 32768) File "C:\Windows\System32\msctf.dll" is sparse (flags = 32768) File "C:\Windows\System32\dwmapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkscli.dll" is sparse (flags = 32768) File "C:\Windows\System32\cscapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\iertutil.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPHLPAPI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\winhttp.dll" is sparse (flags = 32768) File "C:\Windows\System32\mswsock.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winnsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\urlmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\msIso.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasadhlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\FWPUCLNT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ntmarta.dll" is sparse (flags = 32768) File "C:\Windows\System32\clbcatq.dll" is sparse (flags = 32768) File "C:\Windows\System32\propsys.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STATEREPOSITORY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\STATEREPOSITORY.CORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\coml2.dll" is sparse (flags = 32768) File "C:\Windows\System32\mssprxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\linkinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntshrui.dll" is sparse (flags = 32768) File "C:\Windows\System32\srvcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERMGRCLI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\wtsapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winsta.dll" is sparse (flags = 32768) File "C:\Windows\System32\smss.exe" is sparse (flags = 32768) File "C:\Windows\System32\csrss.exe" is sparse (flags = 32768) File "C:\Windows\System32\wininit.exe" is sparse (flags = 32768) File "C:\Windows\System32\services.exe" is sparse (flags = 32768) File "C:\Windows\System32\lsass.exe" is sparse (flags = 32768) File "C:\Windows\System32\winlogon.exe" is sparse (flags = 32768) File "C:\Windows\System32\svchost.exe" is sparse (flags = 32768) File "C:\Windows\System32\FONTDRVHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dwm.exe" is sparse (flags = 32768) File "C:\Windows\System32\spoolsv.exe" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\msimg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\mfc42.dll" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\dataup\dataup.exe --> [Adware.Yelloader] Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Dataup --> [Adware.Yelloader] File "C:\Windows\System32\sxs.dll" is sparse (flags = 32768) File "C:\Windows\System32\d3d9.dll" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\wbemprox.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbemcomn.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\wbemsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\fastprox.dll" is sparse (flags = 32768) File "C:\Windows\System32\MMDevAPI.dll" is sparse (flags = 32768) File "C:\Windows\System32\devobj.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdmaud.drv" is sparse (flags = 32768) File "C:\Windows\System32\avrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\ksuser.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\msacm32.drv" is sparse (flags = 32768) File "C:\Windows\System32\msacm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\midimap.dll" is sparse (flags = 32768) File "C:\Windows\System32\devenum.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdmo.dll" is sparse (flags = 32768) File "C:\Windows\System32\netprofm.dll" is sparse (flags = 32768) File "C:\Windows\System32\npmproxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\NapiNSP.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpnsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlaapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winrnr.dll" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dasHost.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Media Player\wmpnetwk.exe" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiPrvSE.exe" is sparse (flags = 32768) File "C:\Windows\System32\sihost.exe" is sparse (flags = 32768) File "C:\Windows\explorer.exe" is sparse (flags = 32768) Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] File "C:\Windows\System32\Wldap32.dll" is sparse (flags = 32768) File "C:\Windows\System32\TASKHOSTW.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\System32\RUNTIMEBROKER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\BACKGROUNDTASKHOST.EXE" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MSASCuiL.exe" is sparse (flags = 32768) File "C:\Windows\System32\wsock32.dll" is sparse (flags = 32768) File "C:\Windows\System32\xmllite.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.15063.0_none_d802f55807fa1ec7\GdiPlus.dll" is sparse (flags = 32768) File "C:\Windows\System32\wer.dll" is sparse (flags = 32768) File "C:\Windows\System32\cabinet.dll" is sparse (flags = 32768) File "C:\Windows\System32\Faultrep.dll" is sparse (flags = 32768) File "C:\Windows\System32\secur32.dll" is sparse (flags = 32768) File "C:\Windows\System32\loadperf.dll" is sparse (flags = 32768) File "C:\Windows\System32\pdh.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbghelp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ncrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbgcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\mlang.dll" is sparse (flags = 32768) File "C:\Windows\System32\msxml6.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\taskschd.dll" is sparse (flags = 32768) File "C:\Windows\System32\TWINAPI.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\Wpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidprov.dll" is sparse (flags = 32768) File "C:\Windows\System32\samcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\usp10.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleacc.dll" is sparse (flags = 32768) File "C:\Windows\System32\DWrite.dll" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\d3d11.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxgi.dll" is sparse (flags = 32768) File "C:\Windows\System32\dcomp.dll" is sparse (flags = 32768) File "C:\Windows\System32\mscms.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptnet.dll" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETWORKEXPLORER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETWORKEXPLORER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\msi.dll" is sparse (flags = 32768) File "C:\Windows\System32\cmd.exe" is sparse (flags = 32768) File "C:\Windows\System32\conhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\sppsvc.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\System32\credssp.dll" is sparse (flags = 32768) File "C:\Windows\System32\userinit.exe" is sparse (flags = 32768) File "C:\Windows\System32\scecli.dll" is sparse (flags = 32768) File "C:\Windows\System32\msv1_0.dll" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\appid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspclock.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpiex.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\Locator.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mpsdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\afd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ahcache.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\asyncmac.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv.sys" is sparse (flags = 32768) File "C:\Windows\System32\alg.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcifs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcnfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\luafv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bowser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cng.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\clfs.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cldflt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\registry.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mup.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\dllhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\condrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dam.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dfsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dxgkrnl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpip.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORCLASS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPATIALGRAPHFILTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fileinfo.sys" is sparse (flags = 32768) File "C:\Windows\System32\FXSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipfltdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fltMgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PRESENTATIONFONTCACHE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fvevol.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndisuio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFRd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wanarp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbengine.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\http.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hwpolicy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pacer.sys" is sparse (flags = 32768) File "C:\Windows\SysWOW64\perfhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\iorate.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\scfilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdFilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irda.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecdd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecpkg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksthunk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\lltdio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwififlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mstee.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mmcss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mskssrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MsMpEng.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wimmount.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxdav.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\modem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspqm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mountmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasl2tp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb10.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb20.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ucx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ufx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bridge.sys" is sparse (flags = 32768) File "C:\Windows\System32\msdtc.exe" is sparse (flags = 32768) File "C:\Windows\System32\VSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\msiexec.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mslldp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nwifi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndis.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiscap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndistapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiswan.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ndu.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwifibus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nsiproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdiWiFi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\vds.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\partmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcw.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\PEAuth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\RDPVIDEOMINIPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\qwavedrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspptp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasacd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\agilevpn.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspppoe.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rassstp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdbss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpdr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdyboost.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rspndr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SpbCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\snmptrap.exe" is sparse (flags = 32768) File "C:\Windows\System32\Spectrum.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Wdf01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srvnet.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgrx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpipreg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tdx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\terminpt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\servicing\TRUSTEDINSTALLER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbFlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UcmCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Udecx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\udfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBXHCI.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhf.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volsnap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdBoot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdNisDrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\NisSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wfplwfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiApSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ws2ifsl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFPf.sys" is sparse (flags = 32768) File "C:\Windows\System32\AJRouter.dll" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umpnpmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcss.dll" is sparse (flags = 32768) File "C:\Windows\System32\appinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\appidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\AxInstSv.dll" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\AUDIOENDPOINTBUILDER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\audiosrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\RpcEpMap.dll" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bdesvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\BFE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netman.dll" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cdpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\umpo.dll" is sparse (flags = 32768) File "C:\Windows\System32\qmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\ListSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lltdsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\browser.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\profsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bthserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\provsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\das.dll" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\certprop.dll" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ClipSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wscsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WsmSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wersvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wecsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dot3svc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dusmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\fdPHost.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsrslvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\dps.dll" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\eapsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\efssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ENTERPRISEAPPMGMTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FntCache.dll" is sparse (flags = 32768) File "C:\Windows\System32\es.dll" is sparse (flags = 32768) File "C:\Windows\System32\sdrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\srvsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\xbgmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FDResPub.dll" is sparse (flags = 32768) File "C:\Windows\System32\upnphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\fhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\hidserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\HVHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IKEEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\iphlpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\irmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\keyiso.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdtckrm.dll" is sparse (flags = 32768) File "C:\Windows\System32\lfsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lpasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lmhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ipnathlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\lsm.dll" is sparse (flags = 32768) File "C:\Windows\System32\moshost.dll" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MPSSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\iscsiexe.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsisvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ngcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NcaSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netlogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\trkwks.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\icsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pcasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\p2psvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pla.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\icsvcext.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPSECSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\qwave.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasmans.dll" is sparse (flags = 32768) File "C:\Windows\System32\mprdim.dll" is sparse (flags = 32768) File "C:\Windows\System32\regsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\RDXSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\RMapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\schedsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SCardSvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\seclogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\sensrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SEMgrSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\Sens.dll" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SessEnv.dll" is sparse (flags = 32768) File "C:\Windows\System32\shsvcs.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\smphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\StorSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\sstpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ssdpsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\wiaservc.dll" is sparse (flags = 32768) File "C:\Windows\System32\svsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\swprv.dll" is sparse (flags = 32768) File "C:\Windows\System32\sysmain.dll" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TabSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\termsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\tapisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TOKENBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umrdp.dll" is sparse (flags = 32768) File "C:\Windows\System32\Unistore.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\usermgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\usocore.dll" is sparse (flags = 32768) File "C:\Windows\System32\vaultsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\w32time.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbiosrvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wwansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WUDFSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcncsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdi.dll" is sparse (flags = 32768) File "C:\Windows\System32\WebClnt.dll" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wiarpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WMIsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wuaueng.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Program Files\Windows Mail\WinMail.exe" is sparse (flags = 32768) File "C:\Windows\System32\unregmp2.exe" is sparse (flags = 32768) File "C:\Windows\System32\ie4uinit.exe" is sparse (flags = 32768) File "C:\Users\steff\AppData\Local\Comms\UnistoreDB\store.vol" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\winscr\winscr.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\tnifv\qdcomsvc.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\uhiba\ct.exe --> [Adware.Yelloader] File "C:\Windows\System32\config\systemprofile\AppData\Local\DataSharing\Storage\DSTokenDB2.dat" is sparse (flags = 32768) --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.09.4.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 10.0.15063 Windows 10 x64 Account is Administrative Internet Explorer version: 11.296.15063.0 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 3.500000 GHz Memory total: 8588013568, free: 6980857856 ======================================= Initializing... Driver version: 0.3.0.4 ------------ Kernel report ------------ 05/17/2017 19:50:55 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_AuthenticAMD.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\System32\drivers\ksecdd.sys \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\System32\drivers\FLTMGR.SYS \SystemRoot\System32\drivers\clipsp.sys \SystemRoot\System32\drivers\cmimcext.sys \SystemRoot\System32\drivers\ntosext.sys \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\cng.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\SleepStudyHelper.sys \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\system32\drivers\WindowsTrustedRT.sys \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\system32\drivers\ndistpr64.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\system32\drivers\NDIS.SYS \SystemRoot\system32\drivers\TDI.SYS \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\system32\drivers\CEA.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\pciide.sys \SystemRoot\System32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\atapi.sys \SystemRoot\System32\drivers\ataport.SYS \SystemRoot\System32\drivers\storahci.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Wof.sys \SystemRoot\System32\Drivers\NTFS.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\drivers\wfplwfs.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\System32\drivers\volume.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\iorate.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\system32\drivers\filecrypt.sys \SystemRoot\system32\drivers\tbs.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\vmbkmclr.sys \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\drivers\vwififlt.sys \SystemRoot\System32\drivers\pacer.sys \SystemRoot\system32\drivers\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\drivers\gpuenergydrv.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\SysWow64\drivers\AsIO.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys \SystemRoot\System32\drivers\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \SystemRoot\System32\drivers\amdppm.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\portcls.sys \SystemRoot\System32\drivers\drmk.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\rt640x64.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\system32\drivers\ucx01000.sys \SystemRoot\System32\drivers\usbohci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\serial.sys \SystemRoot\System32\drivers\serenum.sys \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\system32\drivers\AtihdWT6.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\system32\DRIVERS\HdAudio.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\kbdhid.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_storahci.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\win32kfull.sys \SystemRoot\System32\win32kbase.sys \SystemRoot\System32\drivers\dxgmms2.sys \SystemRoot\System32\drivers\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\wcifs.sys \SystemRoot\system32\drivers\storqosflt.sys \SystemRoot\System32\drivers\registry.sys \SystemRoot\system32\drivers\lltdio.sys \SystemRoot\system32\drivers\mslldp.sys \SystemRoot\system32\drivers\rspndr.sys \SystemRoot\System32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\system32\drivers\mmcss.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\drivers\condrv.sys \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys ----------- End ----------- Done! Scan started Database versions: main: v2017.05.17.06 rootkit: v2017.04.02.01 <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffb80b2a90a060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffb80b2a77d9f0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffb80b2a90a060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffffb80b28d76060, DeviceName: \Device\00000027\, DriverName: \Driver\storahci\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... File C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys will be destroyed Infected: C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys --> [Rootkit.Agent.PUA] Done! Drive 0 This is a System drive Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: DD0E7A7A Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 716800 Partition is bootable Partition file system is NTFS Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 718848 Numsec = 1951879168 Partition is not bootable Partition file system is NTFS Partition 2 type is Other (0x27) Partition is NOT ACTIVE. Partition starts at LBA: 1952598016 Numsec = 921600 Partition is not bootable Partition file system is NTFS Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition is not bootable Disk Size: 1000204886016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1953505168-1953525168)... Done! File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\apphelp.dll" is sparse (flags = 32768) File "C:\Windows\AppPatch\AcLayers.dll" is sparse (flags = 32768) File "C:\Windows\System32\msvcrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\user32.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\gdi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ucrtbase.dll" is sparse (flags = 32768) File "C:\Windows\System32\shell32.dll" is sparse (flags = 32768) File "C:\Windows\System32\cfgmgr32.dll" is sparse (flags = 32768) File "C:\Windows\System32\SHCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcrt4.dll" is sparse (flags = 32768) File "C:\Windows\System32\sspicli.dll" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sechost.dll" is sparse (flags = 32768) File "C:\Windows\System32\combase.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STORAGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\advapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\shlwapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\KERNEL.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\powrprof.dll" is sparse (flags = 32768) File "C:\Windows\System32\profapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleaut32.dll" is sparse (flags = 32768) File "C:\Windows\System32\setupapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\mpr.dll" is sparse (flags = 32768) File "C:\Windows\System32\winspool.drv" is sparse (flags = 32768) File "C:\Windows\System32\bcrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\sfc_os.dll" is sparse (flags = 32768) File "C:\Windows\System32\imm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\imagehlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ole32.dll" is sparse (flags = 32768) File "C:\Windows\System32\version.dll" is sparse (flags = 32768) File "C:\Windows\System32\wintrust.dll" is sparse (flags = 32768) File "C:\Windows\System32\msasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\crypt32.dll" is sparse (flags = 32768) File "C:\Windows\System32\psapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wininet.dll" is sparse (flags = 32768) File "C:\Windows\System32\netapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\ws2_32.dll" is sparse (flags = 32768) File "C:\Windows\System32\userenv.dll" is sparse (flags = 32768) File "C:\Windows\System32\comdlg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\netutils.dll" is sparse (flags = 32768) File "C:\Windows\System32\winmm.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.0_none_8b4e86125c6fbfec\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINMMBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\rsaenh.dll" is sparse (flags = 32768) File "C:\Windows\System32\uxtheme.dll" is sparse (flags = 32768) File "C:\Windows\System32\msctf.dll" is sparse (flags = 32768) File "C:\Windows\System32\dwmapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkscli.dll" is sparse (flags = 32768) File "C:\Windows\System32\cscapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\iertutil.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPHLPAPI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\winhttp.dll" is sparse (flags = 32768) File "C:\Windows\System32\mswsock.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winnsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\urlmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\msIso.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasadhlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\FWPUCLNT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ntmarta.dll" is sparse (flags = 32768) File "C:\Windows\System32\clbcatq.dll" is sparse (flags = 32768) File "C:\Windows\System32\propsys.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STATEREPOSITORY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\STATEREPOSITORY.CORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\mssprxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\coml2.dll" is sparse (flags = 32768) File "C:\Windows\System32\linkinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntshrui.dll" is sparse (flags = 32768) File "C:\Windows\System32\srvcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERMGRCLI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\wtsapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winsta.dll" is sparse (flags = 32768) File "C:\Windows\System32\smss.exe" is sparse (flags = 32768) File "C:\Windows\System32\csrss.exe" is sparse (flags = 32768) File "C:\Windows\System32\wininit.exe" is sparse (flags = 32768) File "C:\Windows\System32\services.exe" is sparse (flags = 32768) File "C:\Windows\System32\lsass.exe" is sparse (flags = 32768) File "C:\Windows\System32\winlogon.exe" is sparse (flags = 32768) File "C:\Windows\System32\FONTDRVHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\svchost.exe" is sparse (flags = 32768) File "C:\Windows\System32\dwm.exe" is sparse (flags = 32768) File "C:\Windows\System32\spoolsv.exe" is sparse (flags = 32768) File "C:\Windows\System32\msimg32.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\mfc42.dll" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\dataup\dataup.exe --> [Adware.Yelloader] Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Dataup --> [Adware.Yelloader] File "C:\Windows\System32\sxs.dll" is sparse (flags = 32768) File "C:\Windows\System32\d3d9.dll" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\wbemprox.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbemcomn.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\wbemsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\fastprox.dll" is sparse (flags = 32768) File "C:\Windows\System32\MMDevAPI.dll" is sparse (flags = 32768) File "C:\Windows\System32\devobj.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdmaud.drv" is sparse (flags = 32768) File "C:\Windows\System32\ksuser.dll" is sparse (flags = 32768) File "C:\Windows\System32\avrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\msacm32.drv" is sparse (flags = 32768) File "C:\Windows\System32\msacm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\midimap.dll" is sparse (flags = 32768) File "C:\Windows\System32\devenum.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdmo.dll" is sparse (flags = 32768) File "C:\Windows\System32\netprofm.dll" is sparse (flags = 32768) File "C:\Windows\System32\npmproxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\NapiNSP.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpnsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlaapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winrnr.dll" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dasHost.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Media Player\wmpnetwk.exe" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiPrvSE.exe" is sparse (flags = 32768) File "C:\Windows\System32\sihost.exe" is sparse (flags = 32768) File "C:\Windows\explorer.exe" is sparse (flags = 32768) File "C:\Windows\System32\TASKHOSTW.EXE" is sparse (flags = 32768) Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] File "C:\Windows\System32\Wldap32.dll" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\System32\RUNTIMEBROKER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\BACKGROUNDTASKHOST.EXE" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MSASCuiL.exe" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\wsock32.dll" is sparse (flags = 32768) File "C:\Windows\System32\xmllite.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.15063.0_none_d802f55807fa1ec7\GdiPlus.dll" is sparse (flags = 32768) File "C:\Windows\System32\wer.dll" is sparse (flags = 32768) File "C:\Windows\System32\cabinet.dll" is sparse (flags = 32768) File "C:\Windows\System32\Faultrep.dll" is sparse (flags = 32768) File "C:\Windows\System32\secur32.dll" is sparse (flags = 32768) File "C:\Windows\System32\loadperf.dll" is sparse (flags = 32768) File "C:\Windows\System32\pdh.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbghelp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ncrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbgcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\mlang.dll" is sparse (flags = 32768) File "C:\Windows\System32\msxml6.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\taskschd.dll" is sparse (flags = 32768) File "C:\Windows\System32\TWINAPI.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\Wpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidprov.dll" is sparse (flags = 32768) File "C:\Windows\System32\samcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\opengl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\glu32.dll" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\d3d11.dll" is sparse (flags = 32768) File "C:\Windows\System32\dcomp.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxgi.dll" is sparse (flags = 32768) File "C:\Windows\System32\DWrite.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlanapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\dinput8.dll" is sparse (flags = 32768) File "C:\Windows\System32\hid.dll" is sparse (flags = 32768) File "C:\Windows\System32\dsound.dll" is sparse (flags = 32768) File "C:\Windows\System32\XINPUT1_4.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XINPUT1_4.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.UI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.UI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONECOREUAPCOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONECOREUAPCOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPRESOLVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\slc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ELSCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\BCP47LANGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sppc.dll" is sparse (flags = 32768) File "C:\Windows\System32\MrmCoreR.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONECORECOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONECORECOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\POLICYMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP110_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\gpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptnet.dll" is sparse (flags = 32768) File "C:\Windows\System32\webio.dll" is sparse (flags = 32768) File "C:\Windows\System32\regsvr32.exe" is sparse (flags = 32768) File "C:\Windows\System32\oleacc.dll" is sparse (flags = 32768) File "C:\Windows\System32\usp10.dll" is sparse (flags = 32768) File "C:\Windows\System32\mscms.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETWORKEXPLORER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETWORKEXPLORER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\msi.dll" is sparse (flags = 32768) File "C:\Windows\System32\credui.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptui.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxva2.dll" is sparse (flags = 32768) File "C:\Windows\System32\fontsub.dll" is sparse (flags = 32768) File "C:\Windows\System32\fontsub.dll" is sparse (flags = 32768) File "C:\Windows\System32\cmd.exe" is sparse (flags = 32768) File "C:\Windows\System32\conhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\System32\dllhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\sppsvc.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\System32\credssp.dll" is sparse (flags = 32768) File "C:\Windows\System32\userinit.exe" is sparse (flags = 32768) File "C:\Windows\System32\scecli.dll" is sparse (flags = 32768) File "C:\Windows\System32\msv1_0.dll" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\appid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspclock.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpiex.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\Locator.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mpsdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\afd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ahcache.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\asyncmac.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv.sys" is sparse (flags = 32768) File "C:\Windows\System32\alg.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcifs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcnfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\luafv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bowser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cng.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\clfs.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cldflt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\registry.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mup.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\condrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dam.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dfsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dxgkrnl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpip.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORCLASS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPATIALGRAPHFILTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fileinfo.sys" is sparse (flags = 32768) File "C:\Windows\System32\FXSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipfltdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fltMgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PRESENTATIONFONTCACHE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fvevol.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndisuio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFRd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wanarp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbengine.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\http.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hwpolicy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pacer.sys" is sparse (flags = 32768) File "C:\Windows\SysWOW64\perfhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\iorate.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\scfilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdFilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irda.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecdd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecpkg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksthunk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\lltdio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwififlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mstee.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mmcss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mskssrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MsMpEng.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wimmount.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxdav.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\modem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspqm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mountmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasl2tp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb10.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb20.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ucx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ufx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bridge.sys" is sparse (flags = 32768) File "C:\Windows\System32\msdtc.exe" is sparse (flags = 32768) File "C:\Windows\System32\VSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\msiexec.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mslldp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nwifi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndis.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiscap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndistapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiswan.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ndu.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwifibus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nsiproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdiWiFi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\vds.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\partmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcw.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\PEAuth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\RDPVIDEOMINIPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\qwavedrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspptp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasacd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\agilevpn.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspppoe.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rassstp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdbss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpdr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdyboost.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rspndr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SpbCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\snmptrap.exe" is sparse (flags = 32768) File "C:\Windows\System32\Spectrum.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Wdf01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srvnet.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgrx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpipreg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tdx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\terminpt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\servicing\TRUSTEDINSTALLER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbFlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UcmCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Udecx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\udfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBXHCI.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhf.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volsnap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdBoot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdNisDrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\NisSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wfplwfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiApSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ws2ifsl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFPf.sys" is sparse (flags = 32768) File "C:\Windows\System32\AJRouter.dll" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umpnpmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcss.dll" is sparse (flags = 32768) File "C:\Windows\System32\appinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\appidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\AxInstSv.dll" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\AUDIOENDPOINTBUILDER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\audiosrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\RpcEpMap.dll" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bdesvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\BFE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netman.dll" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cdpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\umpo.dll" is sparse (flags = 32768) File "C:\Windows\System32\qmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\ListSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lltdsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\browser.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\profsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bthserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\provsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\das.dll" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\certprop.dll" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ClipSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wscsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WsmSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wersvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wecsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dot3svc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dusmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\fdPHost.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsrslvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\dps.dll" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\eapsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\efssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ENTERPRISEAPPMGMTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FntCache.dll" is sparse (flags = 32768) File "C:\Windows\System32\es.dll" is sparse (flags = 32768) File "C:\Windows\System32\sdrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\srvsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\xbgmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FDResPub.dll" is sparse (flags = 32768) File "C:\Windows\System32\upnphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\fhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\hidserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\HVHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IKEEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\iphlpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\irmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\keyiso.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdtckrm.dll" is sparse (flags = 32768) File "C:\Windows\System32\lfsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lpasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lmhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ipnathlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\lsm.dll" is sparse (flags = 32768) File "C:\Windows\System32\moshost.dll" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MPSSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\iscsiexe.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsisvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ngcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NcaSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netlogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\trkwks.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\icsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pcasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\p2psvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pla.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\icsvcext.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPSECSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\qwave.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasmans.dll" is sparse (flags = 32768) File "C:\Windows\System32\mprdim.dll" is sparse (flags = 32768) File "C:\Windows\System32\regsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\RDXSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\RMapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\schedsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SCardSvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\seclogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\sensrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SEMgrSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\Sens.dll" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SessEnv.dll" is sparse (flags = 32768) File "C:\Windows\System32\shsvcs.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\smphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\StorSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\sstpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ssdpsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\wiaservc.dll" is sparse (flags = 32768) File "C:\Windows\System32\svsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\swprv.dll" is sparse (flags = 32768) File "C:\Windows\System32\sysmain.dll" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TabSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\termsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\tapisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TOKENBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umrdp.dll" is sparse (flags = 32768) File "C:\Windows\System32\Unistore.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\usermgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\usocore.dll" is sparse (flags = 32768) File "C:\Windows\System32\vaultsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\w32time.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbiosrvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wwansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WUDFSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcncsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdi.dll" is sparse (flags = 32768) File "C:\Windows\System32\WebClnt.dll" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wiarpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WMIsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wuaueng.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Program Files\Windows Mail\WinMail.exe" is sparse (flags = 32768) File "C:\Windows\System32\unregmp2.exe" is sparse (flags = 32768) File "C:\Windows\System32\ie4uinit.exe" is sparse (flags = 32768) File "C:\Users\steff\AppData\Local\Comms\UnistoreDB\store.vol" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\winscr\winscr.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\tnifv\qdcomsvc.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\uhiba\ct.exe --> [Adware.Yelloader] File "C:\Windows\System32\config\systemprofile\AppData\Local\DataSharing\Storage\DSTokenDB2.dat" is sparse (flags = 32768) --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.09.4.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 10.0.15063 Windows 10 x64 Account is Administrative Internet Explorer version: 11.296.15063.0 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 3.500000 GHz Memory total: 8588013568, free: 6547849216 ======================================= Initializing... Driver version: 0.3.0.4 ------------ Kernel report ------------ 05/17/2017 20:13:00 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_AuthenticAMD.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\System32\drivers\ksecdd.sys \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\System32\drivers\FLTMGR.SYS \SystemRoot\System32\drivers\clipsp.sys \SystemRoot\System32\drivers\cmimcext.sys \SystemRoot\System32\drivers\ntosext.sys \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\cng.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\SleepStudyHelper.sys \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\system32\drivers\WindowsTrustedRT.sys \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\system32\drivers\ndistpr64.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\system32\drivers\NDIS.SYS \SystemRoot\system32\drivers\TDI.SYS \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\system32\drivers\CEA.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\pciide.sys \SystemRoot\System32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\atapi.sys \SystemRoot\System32\drivers\ataport.SYS \SystemRoot\System32\drivers\storahci.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Wof.sys \SystemRoot\System32\Drivers\NTFS.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\drivers\wfplwfs.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\System32\drivers\volume.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\iorate.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\system32\drivers\filecrypt.sys \SystemRoot\system32\drivers\tbs.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\vmbkmclr.sys \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\drivers\vwififlt.sys \SystemRoot\System32\drivers\pacer.sys \SystemRoot\system32\drivers\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\drivers\gpuenergydrv.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\SysWow64\drivers\AsIO.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys \SystemRoot\System32\drivers\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \SystemRoot\System32\drivers\amdppm.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\portcls.sys \SystemRoot\System32\drivers\drmk.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\rt640x64.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\system32\drivers\ucx01000.sys \SystemRoot\System32\drivers\usbohci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\serial.sys \SystemRoot\System32\drivers\serenum.sys \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\system32\drivers\AtihdWT6.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\system32\DRIVERS\HdAudio.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\kbdhid.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\win32kfull.sys \SystemRoot\System32\win32kbase.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_storahci.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\drivers\dxgmms2.sys \SystemRoot\System32\drivers\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\wcifs.sys \SystemRoot\system32\drivers\storqosflt.sys \SystemRoot\System32\drivers\registry.sys \SystemRoot\system32\drivers\lltdio.sys \SystemRoot\system32\drivers\mslldp.sys \SystemRoot\system32\drivers\rspndr.sys \SystemRoot\System32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\drivers\mmcss.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\System32\drivers\condrv.sys \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys ----------- End ----------- Done! Scan started Database versions: main: v2017.05.17.06 rootkit: v2017.04.02.01 <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffc88e8344f060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffc88e8337e9f0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffc88e8344f060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffffc88e80de5060, DeviceName: \Device\00000027\, DriverName: \Driver\storahci\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... File C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys will be destroyed Infected: C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys --> [Rootkit.Agent.PUA] Done! Drive 0 This is a System drive Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: DD0E7A7A Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 716800 Partition is bootable Partition file system is NTFS Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 718848 Numsec = 1951879168 Partition is not bootable Partition file system is NTFS Partition 2 type is Other (0x27) Partition is NOT ACTIVE. Partition starts at LBA: 1952598016 Numsec = 921600 Partition is not bootable Partition file system is NTFS Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition is not bootable Disk Size: 1000204886016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1953505168-1953525168)... Done! File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\apphelp.dll" is sparse (flags = 32768) File "C:\Windows\AppPatch\AcLayers.dll" is sparse (flags = 32768) File "C:\Windows\System32\msvcrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\user32.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\gdi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ucrtbase.dll" is sparse (flags = 32768) File "C:\Windows\System32\shell32.dll" is sparse (flags = 32768) File "C:\Windows\System32\cfgmgr32.dll" is sparse (flags = 32768) File "C:\Windows\System32\SHCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcrt4.dll" is sparse (flags = 32768) File "C:\Windows\System32\sspicli.dll" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sechost.dll" is sparse (flags = 32768) File "C:\Windows\System32\combase.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STORAGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\advapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\shlwapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\KERNEL.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\powrprof.dll" is sparse (flags = 32768) File "C:\Windows\System32\profapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleaut32.dll" is sparse (flags = 32768) File "C:\Windows\System32\setupapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\mpr.dll" is sparse (flags = 32768) File "C:\Windows\System32\winspool.drv" is sparse (flags = 32768) File "C:\Windows\System32\bcrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\sfc_os.dll" is sparse (flags = 32768) File "C:\Windows\System32\imm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\imagehlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ole32.dll" is sparse (flags = 32768) File "C:\Windows\System32\version.dll" is sparse (flags = 32768) File "C:\Windows\System32\wintrust.dll" is sparse (flags = 32768) File "C:\Windows\System32\msasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\crypt32.dll" is sparse (flags = 32768) File "C:\Windows\System32\psapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wininet.dll" is sparse (flags = 32768) File "C:\Windows\System32\netapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\userenv.dll" is sparse (flags = 32768) File "C:\Windows\System32\ws2_32.dll" is sparse (flags = 32768) File "C:\Windows\System32\netutils.dll" is sparse (flags = 32768) File "C:\Windows\System32\comdlg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winmm.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.0_none_8b4e86125c6fbfec\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINMMBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\rsaenh.dll" is sparse (flags = 32768) File "C:\Windows\System32\uxtheme.dll" is sparse (flags = 32768) File "C:\Windows\System32\msctf.dll" is sparse (flags = 32768) File "C:\Windows\System32\dwmapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkscli.dll" is sparse (flags = 32768) File "C:\Windows\System32\cscapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\iertutil.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPHLPAPI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\winhttp.dll" is sparse (flags = 32768) File "C:\Windows\System32\mswsock.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winnsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\urlmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\msIso.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasadhlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\FWPUCLNT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ntmarta.dll" is sparse (flags = 32768) File "C:\Windows\System32\clbcatq.dll" is sparse (flags = 32768) File "C:\Windows\System32\propsys.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STATEREPOSITORY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\STATEREPOSITORY.CORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\coml2.dll" is sparse (flags = 32768) File "C:\Windows\System32\mssprxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\linkinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntshrui.dll" is sparse (flags = 32768) File "C:\Windows\System32\srvcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERMGRCLI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\wtsapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winsta.dll" is sparse (flags = 32768) File "C:\Windows\System32\smss.exe" is sparse (flags = 32768) File "C:\Windows\System32\csrss.exe" is sparse (flags = 32768) File "C:\Windows\System32\wininit.exe" is sparse (flags = 32768) File "C:\Windows\System32\services.exe" is sparse (flags = 32768) File "C:\Windows\System32\lsass.exe" is sparse (flags = 32768) File "C:\Windows\System32\winlogon.exe" is sparse (flags = 32768) File "C:\Windows\System32\svchost.exe" is sparse (flags = 32768) File "C:\Windows\System32\FONTDRVHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dwm.exe" is sparse (flags = 32768) File "C:\Windows\System32\spoolsv.exe" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\dataup\dataup.exe --> [Adware.Yelloader] Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Dataup --> [Adware.Yelloader] File "C:\Windows\System32\sxs.dll" is sparse (flags = 32768) File "C:\Windows\System32\mfc42.dll" is sparse (flags = 32768) File "C:\Windows\System32\msxml3.dll" is sparse (flags = 32768) File "C:\Windows\System32\msimg32.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\d3d9.dll" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\wbemprox.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbemcomn.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\wbemsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\fastprox.dll" is sparse (flags = 32768) File "C:\Windows\System32\MMDevAPI.dll" is sparse (flags = 32768) File "C:\Windows\System32\devobj.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdmaud.drv" is sparse (flags = 32768) File "C:\Windows\System32\ksuser.dll" is sparse (flags = 32768) File "C:\Windows\System32\avrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\msacm32.drv" is sparse (flags = 32768) File "C:\Windows\System32\msacm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\midimap.dll" is sparse (flags = 32768) File "C:\Windows\System32\devenum.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdmo.dll" is sparse (flags = 32768) File "C:\Windows\System32\netprofm.dll" is sparse (flags = 32768) File "C:\Windows\System32\npmproxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\NapiNSP.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpnsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlaapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winrnr.dll" is sparse (flags = 32768) File "C:\Windows\System32\dasHost.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Media Player\wmpnetwk.exe" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiPrvSE.exe" is sparse (flags = 32768) File "C:\Windows\System32\sihost.exe" is sparse (flags = 32768) File "C:\Windows\explorer.exe" is sparse (flags = 32768) File "C:\Windows\System32\TASKHOSTW.EXE" is sparse (flags = 32768) Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] File "C:\Windows\System32\Wldap32.dll" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\System32\RUNTIMEBROKER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\BACKGROUNDTASKHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MSASCuiL.exe" is sparse (flags = 32768) File "C:\Windows\System32\wsock32.dll" is sparse (flags = 32768) File "C:\Windows\System32\xmllite.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.15063.0_none_d802f55807fa1ec7\GdiPlus.dll" is sparse (flags = 32768) File "C:\Windows\System32\wer.dll" is sparse (flags = 32768) File "C:\Windows\System32\cabinet.dll" is sparse (flags = 32768) File "C:\Windows\System32\Faultrep.dll" is sparse (flags = 32768) File "C:\Windows\System32\secur32.dll" is sparse (flags = 32768) File "C:\Windows\System32\loadperf.dll" is sparse (flags = 32768) File "C:\Windows\System32\pdh.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbghelp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ncrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbgcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\mlang.dll" is sparse (flags = 32768) File "C:\Windows\System32\msxml6.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\taskschd.dll" is sparse (flags = 32768) File "C:\Windows\System32\TWINAPI.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\Wpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidprov.dll" is sparse (flags = 32768) File "C:\Windows\System32\samcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\opengl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\glu32.dll" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\d3d11.dll" is sparse (flags = 32768) File "C:\Windows\System32\dcomp.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxgi.dll" is sparse (flags = 32768) File "C:\Windows\System32\DWrite.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlanapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\dinput8.dll" is sparse (flags = 32768) File "C:\Windows\System32\hid.dll" is sparse (flags = 32768) File "C:\Windows\System32\XINPUT1_4.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XINPUT1_4.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dsound.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.UI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.UI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONECOREUAPCOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONECOREUAPCOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPRESOLVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ELSCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\BCP47LANGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\slc.dll" is sparse (flags = 32768) File "C:\Windows\System32\MrmCoreR.dll" is sparse (flags = 32768) File "C:\Windows\System32\sppc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONECORECOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONECORECOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\POLICYMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP110_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\gpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptnet.dll" is sparse (flags = 32768) File "C:\Windows\System32\usp10.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleacc.dll" is sparse (flags = 32768) File "C:\Windows\System32\mscms.dll" is sparse (flags = 32768) File "C:\Windows\System32\msi.dll" is sparse (flags = 32768) File "C:\Windows\System32\credui.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptui.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxva2.dll" is sparse (flags = 32768) File "C:\Windows\System32\fontsub.dll" is sparse (flags = 32768) File "C:\Windows\System32\fontsub.dll" is sparse (flags = 32768) File "C:\Windows\System32\cmd.exe" is sparse (flags = 32768) File "C:\Windows\System32\conhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\System32\credssp.dll" is sparse (flags = 32768) File "C:\Windows\System32\userinit.exe" is sparse (flags = 32768) File "C:\Windows\System32\scecli.dll" is sparse (flags = 32768) File "C:\Windows\System32\msv1_0.dll" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\appid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspclock.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpiex.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\Locator.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mpsdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\afd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ahcache.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\asyncmac.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv.sys" is sparse (flags = 32768) File "C:\Windows\System32\alg.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcifs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcnfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\luafv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bowser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cng.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\clfs.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cldflt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\registry.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mup.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\dllhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\condrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dam.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dfsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dxgkrnl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpip.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORCLASS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPATIALGRAPHFILTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fileinfo.sys" is sparse (flags = 32768) File "C:\Windows\System32\FXSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipfltdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fltMgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PRESENTATIONFONTCACHE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fvevol.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndisuio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFRd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wanarp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbengine.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\http.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hwpolicy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pacer.sys" is sparse (flags = 32768) File "C:\Windows\SysWOW64\perfhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\iorate.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\scfilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdFilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irda.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecdd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecpkg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksthunk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\lltdio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwififlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mstee.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mmcss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mskssrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MsMpEng.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wimmount.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxdav.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\modem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspqm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mountmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasl2tp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb10.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb20.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ucx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ufx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bridge.sys" is sparse (flags = 32768) File "C:\Windows\System32\msdtc.exe" is sparse (flags = 32768) File "C:\Windows\System32\VSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\msiexec.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mslldp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nwifi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndis.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiscap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndistapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiswan.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ndu.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwifibus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nsiproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdiWiFi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\vds.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\partmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcw.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\PEAuth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\RDPVIDEOMINIPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\qwavedrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspptp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasacd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\agilevpn.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspppoe.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rassstp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdbss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpdr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdyboost.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rspndr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SpbCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\snmptrap.exe" is sparse (flags = 32768) File "C:\Windows\System32\Spectrum.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Wdf01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\sppsvc.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srvnet.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgrx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpipreg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tdx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\terminpt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\servicing\TRUSTEDINSTALLER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbFlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UcmCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Udecx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\udfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBXHCI.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhf.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volsnap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdBoot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdNisDrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\NisSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wfplwfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiApSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ws2ifsl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFPf.sys" is sparse (flags = 32768) File "C:\Windows\System32\AJRouter.dll" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umpnpmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcss.dll" is sparse (flags = 32768) File "C:\Windows\System32\appinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\appidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\AxInstSv.dll" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\AUDIOENDPOINTBUILDER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\audiosrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\RpcEpMap.dll" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bdesvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\BFE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netman.dll" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cdpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\umpo.dll" is sparse (flags = 32768) File "C:\Windows\System32\qmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\ListSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lltdsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\browser.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\profsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bthserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\provsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\das.dll" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\certprop.dll" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ClipSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wscsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WsmSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wersvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wecsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dot3svc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dusmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\fdPHost.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsrslvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\dps.dll" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\eapsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\efssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ENTERPRISEAPPMGMTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FntCache.dll" is sparse (flags = 32768) File "C:\Windows\System32\es.dll" is sparse (flags = 32768) File "C:\Windows\System32\sdrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\srvsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\xbgmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FDResPub.dll" is sparse (flags = 32768) File "C:\Windows\System32\upnphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\fhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\hidserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\HVHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IKEEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\iphlpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\irmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\keyiso.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdtckrm.dll" is sparse (flags = 32768) File "C:\Windows\System32\lfsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lpasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lmhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ipnathlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\lsm.dll" is sparse (flags = 32768) File "C:\Windows\System32\moshost.dll" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MPSSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\iscsiexe.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsisvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ngcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NcaSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netlogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\trkwks.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\icsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pcasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\p2psvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pla.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\icsvcext.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPSECSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\qwave.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasmans.dll" is sparse (flags = 32768) File "C:\Windows\System32\mprdim.dll" is sparse (flags = 32768) File "C:\Windows\System32\regsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\RDXSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\RMapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\schedsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SCardSvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\seclogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\sensrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SEMgrSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\Sens.dll" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SessEnv.dll" is sparse (flags = 32768) File "C:\Windows\System32\shsvcs.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\smphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\StorSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\sstpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ssdpsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\wiaservc.dll" is sparse (flags = 32768) File "C:\Windows\System32\svsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\swprv.dll" is sparse (flags = 32768) File "C:\Windows\System32\sysmain.dll" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TabSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\termsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\tapisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TOKENBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umrdp.dll" is sparse (flags = 32768) File "C:\Windows\System32\Unistore.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\usermgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\usocore.dll" is sparse (flags = 32768) File "C:\Windows\System32\vaultsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\w32time.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbiosrvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wwansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WUDFSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcncsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdi.dll" is sparse (flags = 32768) File "C:\Windows\System32\WebClnt.dll" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wiarpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WMIsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wuaueng.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Program Files\Windows Mail\WinMail.exe" is sparse (flags = 32768) File "C:\Windows\System32\unregmp2.exe" is sparse (flags = 32768) File "C:\Windows\System32\ie4uinit.exe" is sparse (flags = 32768) File "C:\Users\steff\AppData\Local\Comms\UnistoreDB\store.vol" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\winscr\winscr.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\tnifv\qdcomsvc.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\uhiba\ct.exe --> [Adware.Yelloader] File "C:\Windows\System32\config\systemprofile\AppData\Local\DataSharing\Storage\DSTokenDB2.dat" is sparse (flags = 32768) --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.09.4.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 10.0.15063 Windows 10 x64 Account is Administrative Internet Explorer version: 11.296.15063.0 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 3.500000 GHz Memory total: 8588013568, free: 6726651904 ======================================= Initializing... Driver version: 0.3.0.4 ------------ Kernel report ------------ 05/17/2017 20:37:07 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_AuthenticAMD.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\System32\drivers\ksecdd.sys \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\System32\drivers\FLTMGR.SYS \SystemRoot\System32\drivers\clipsp.sys \SystemRoot\System32\drivers\cmimcext.sys \SystemRoot\System32\drivers\ntosext.sys \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\cng.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\SleepStudyHelper.sys \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\system32\drivers\WindowsTrustedRT.sys \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\system32\drivers\ndistpr64.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\system32\drivers\NDIS.SYS \SystemRoot\system32\drivers\TDI.SYS \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\system32\drivers\CEA.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\pciide.sys \SystemRoot\System32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\atapi.sys \SystemRoot\System32\drivers\ataport.SYS \SystemRoot\System32\drivers\storahci.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Wof.sys \SystemRoot\System32\Drivers\NTFS.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\drivers\wfplwfs.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\System32\drivers\volume.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\iorate.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\system32\drivers\filecrypt.sys \SystemRoot\system32\drivers\tbs.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\vmbkmclr.sys \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\drivers\vwififlt.sys \SystemRoot\System32\drivers\pacer.sys \SystemRoot\system32\drivers\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\drivers\gpuenergydrv.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\SysWow64\drivers\AsIO.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys \SystemRoot\System32\drivers\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \SystemRoot\System32\drivers\amdppm.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\portcls.sys \SystemRoot\System32\drivers\drmk.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\rt640x64.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\system32\drivers\ucx01000.sys \SystemRoot\System32\drivers\usbohci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\serial.sys \SystemRoot\System32\drivers\serenum.sys \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\system32\drivers\AtihdWT6.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\system32\DRIVERS\HdAudio.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\kbdhid.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\win32kfull.sys \SystemRoot\System32\win32kbase.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_storahci.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\drivers\dxgmms2.sys \SystemRoot\System32\drivers\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\wcifs.sys \SystemRoot\system32\drivers\storqosflt.sys \SystemRoot\System32\drivers\registry.sys \SystemRoot\system32\drivers\mslldp.sys \SystemRoot\system32\drivers\rspndr.sys \SystemRoot\system32\drivers\lltdio.sys \SystemRoot\System32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\system32\drivers\mmcss.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\System32\drivers\condrv.sys \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys ----------- End ----------- Done! Scan started Database versions: main: v2017.05.17.06 rootkit: v2017.04.02.01 <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffcf0299e59060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffcf0299dc59f0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffcf0299e59060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffffcf0298361060, DeviceName: \Device\00000027\, DriverName: \Driver\storahci\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... File C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys will be destroyed Infected: C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys --> [Rootkit.Agent.PUA] Done! Drive 0 This is a System drive Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: DD0E7A7A Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 716800 Partition is bootable Partition file system is NTFS Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 718848 Numsec = 1951879168 Partition is not bootable Partition file system is NTFS Partition 2 type is Other (0x27) Partition is NOT ACTIVE. Partition starts at LBA: 1952598016 Numsec = 921600 Partition is not bootable Partition file system is NTFS Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition is not bootable Disk Size: 1000204886016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1953505168-1953525168)... Done! File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\apphelp.dll" is sparse (flags = 32768) File "C:\Windows\AppPatch\AcLayers.dll" is sparse (flags = 32768) File "C:\Windows\System32\msvcrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\user32.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\gdi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ucrtbase.dll" is sparse (flags = 32768) File "C:\Windows\System32\shell32.dll" is sparse (flags = 32768) File "C:\Windows\System32\cfgmgr32.dll" is sparse (flags = 32768) File "C:\Windows\System32\SHCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcrt4.dll" is sparse (flags = 32768) File "C:\Windows\System32\sspicli.dll" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sechost.dll" is sparse (flags = 32768) File "C:\Windows\System32\combase.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STORAGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\advapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\shlwapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\KERNEL.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\powrprof.dll" is sparse (flags = 32768) File "C:\Windows\System32\profapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleaut32.dll" is sparse (flags = 32768) File "C:\Windows\System32\setupapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\mpr.dll" is sparse (flags = 32768) File "C:\Windows\System32\winspool.drv" is sparse (flags = 32768) File "C:\Windows\System32\bcrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\sfc_os.dll" is sparse (flags = 32768) File "C:\Windows\System32\imm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\imagehlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ole32.dll" is sparse (flags = 32768) File "C:\Windows\System32\version.dll" is sparse (flags = 32768) File "C:\Windows\System32\wintrust.dll" is sparse (flags = 32768) File "C:\Windows\System32\msasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\crypt32.dll" is sparse (flags = 32768) File "C:\Windows\System32\psapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\comdlg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\netapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\ws2_32.dll" is sparse (flags = 32768) File "C:\Windows\System32\wininet.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.0_none_8b4e86125c6fbfec\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\userenv.dll" is sparse (flags = 32768) File "C:\Windows\System32\winmm.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINMMBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netutils.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\rsaenh.dll" is sparse (flags = 32768) File "C:\Windows\System32\uxtheme.dll" is sparse (flags = 32768) File "C:\Windows\System32\msctf.dll" is sparse (flags = 32768) File "C:\Windows\System32\dwmapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkscli.dll" is sparse (flags = 32768) File "C:\Windows\System32\cscapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\iertutil.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPHLPAPI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\winhttp.dll" is sparse (flags = 32768) File "C:\Windows\System32\mswsock.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winnsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\urlmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\msIso.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasadhlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\FWPUCLNT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ntmarta.dll" is sparse (flags = 32768) File "C:\Windows\System32\clbcatq.dll" is sparse (flags = 32768) File "C:\Windows\System32\propsys.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STATEREPOSITORY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\STATEREPOSITORY.CORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\coml2.dll" is sparse (flags = 32768) File "C:\Windows\System32\mssprxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\linkinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntshrui.dll" is sparse (flags = 32768) File "C:\Windows\System32\srvcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERMGRCLI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wtsapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winsta.dll" is sparse (flags = 32768) File "C:\Windows\System32\smss.exe" is sparse (flags = 32768) File "C:\Windows\System32\csrss.exe" is sparse (flags = 32768) File "C:\Windows\System32\wininit.exe" is sparse (flags = 32768) File "C:\Windows\System32\services.exe" is sparse (flags = 32768) File "C:\Windows\System32\lsass.exe" is sparse (flags = 32768) File "C:\Windows\System32\winlogon.exe" is sparse (flags = 32768) File "C:\Windows\System32\svchost.exe" is sparse (flags = 32768) File "C:\Windows\System32\FONTDRVHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dwm.exe" is sparse (flags = 32768) File "C:\Windows\System32\spoolsv.exe" is sparse (flags = 32768) File "C:\Windows\System32\msimg32.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\mfc42.dll" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\dataup\dataup.exe --> [Adware.Yelloader] Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Dataup --> [Adware.Yelloader] File "C:\Windows\System32\sxs.dll" is sparse (flags = 32768) File "C:\Windows\System32\msxml3.dll" is sparse (flags = 32768) File "C:\Windows\System32\dasHost.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Media Player\wmpnetwk.exe" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiPrvSE.exe" is sparse (flags = 32768) File "C:\Windows\System32\sihost.exe" is sparse (flags = 32768) File "C:\Windows\explorer.exe" is sparse (flags = 32768) Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] File "C:\Windows\System32\Wldap32.dll" is sparse (flags = 32768) File "C:\Windows\System32\TASKHOSTW.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\System32\RUNTIMEBROKER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\BACKGROUNDTASKHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MSASCuiL.exe" is sparse (flags = 32768) File "C:\Windows\System32\wsock32.dll" is sparse (flags = 32768) File "C:\Windows\System32\xmllite.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.15063.0_none_d802f55807fa1ec7\GdiPlus.dll" is sparse (flags = 32768) File "C:\Windows\System32\wer.dll" is sparse (flags = 32768) File "C:\Windows\System32\cabinet.dll" is sparse (flags = 32768) File "C:\Windows\System32\Faultrep.dll" is sparse (flags = 32768) File "C:\Windows\System32\secur32.dll" is sparse (flags = 32768) File "C:\Windows\System32\loadperf.dll" is sparse (flags = 32768) File "C:\Windows\System32\pdh.dll" is sparse (flags = 32768) File "C:\Windows\System32\ncrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbghelp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbgcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\mlang.dll" is sparse (flags = 32768) File "C:\Windows\System32\msxml6.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\taskschd.dll" is sparse (flags = 32768) File "C:\Windows\System32\TWINAPI.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\Wpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidprov.dll" is sparse (flags = 32768) File "C:\Windows\System32\samcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleacc.dll" is sparse (flags = 32768) File "C:\Windows\System32\usp10.dll" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\DWrite.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlaapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\avrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\MMDevAPI.dll" is sparse (flags = 32768) File "C:\Windows\System32\devobj.dll" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\d3d11.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxgi.dll" is sparse (flags = 32768) File "C:\Windows\System32\dcomp.dll" is sparse (flags = 32768) File "C:\Windows\System32\mscms.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptnet.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETWORKEXPLORER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETWORKEXPLORER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\msi.dll" is sparse (flags = 32768) File "C:\Windows\System32\d3d9.dll" is sparse (flags = 32768) File "C:\Windows\System32\NapiNSP.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpnsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\winrnr.dll" is sparse (flags = 32768) File "C:\Windows\System32\cmd.exe" is sparse (flags = 32768) File "C:\Windows\System32\conhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\rundll32.exe" is sparse (flags = 32768) --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.09.4.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 10.0.15063 Windows 10 x64 Account is Administrative Internet Explorer version: 11.296.15063.0 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 3.500000 GHz Memory total: 8588013568, free: 6259609600 Downloaded database version: v2017.05.18.01 Initializing... ====================== Driver version: 0.3.0.4 ------------ Kernel report ------------ 05/17/2017 20:49:13 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_AuthenticAMD.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\System32\drivers\ksecdd.sys \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\System32\drivers\FLTMGR.SYS \SystemRoot\System32\drivers\clipsp.sys \SystemRoot\System32\drivers\cmimcext.sys \SystemRoot\System32\drivers\ntosext.sys \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\cng.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\SleepStudyHelper.sys \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\system32\drivers\WindowsTrustedRT.sys \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\system32\drivers\ndistpr64.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\system32\drivers\NDIS.SYS \SystemRoot\system32\drivers\TDI.SYS \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\system32\drivers\CEA.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\pciide.sys \SystemRoot\System32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\atapi.sys \SystemRoot\System32\drivers\ataport.SYS \SystemRoot\System32\drivers\storahci.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Wof.sys \SystemRoot\System32\Drivers\NTFS.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\drivers\wfplwfs.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\System32\drivers\volume.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\iorate.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\system32\drivers\filecrypt.sys \SystemRoot\system32\drivers\tbs.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\vmbkmclr.sys \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\drivers\vwififlt.sys \SystemRoot\System32\drivers\pacer.sys \SystemRoot\system32\drivers\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\drivers\gpuenergydrv.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\SysWow64\drivers\AsIO.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys \SystemRoot\System32\drivers\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \SystemRoot\System32\drivers\amdppm.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\portcls.sys \SystemRoot\System32\drivers\drmk.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\rt640x64.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\system32\drivers\ucx01000.sys \SystemRoot\System32\drivers\usbohci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\serial.sys \SystemRoot\System32\drivers\serenum.sys \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\system32\drivers\AtihdWT6.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\system32\DRIVERS\HdAudio.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\kbdhid.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_storahci.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\win32kfull.sys \SystemRoot\System32\win32kbase.sys \SystemRoot\System32\drivers\dxgmms2.sys \SystemRoot\System32\drivers\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\wcifs.sys \SystemRoot\system32\drivers\storqosflt.sys \SystemRoot\System32\drivers\registry.sys \SystemRoot\system32\drivers\lltdio.sys \SystemRoot\system32\drivers\mslldp.sys \SystemRoot\system32\drivers\rspndr.sys \SystemRoot\System32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\system32\drivers\mmcss.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\System32\drivers\condrv.sys \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys ----------- End ----------- Done! Scan started Database versions: main: v2017.05.18.01 rootkit: v2017.04.02.01 <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffbd001bc0b060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffbd001bbe59f0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffbd001bc0b060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffffbd001b9ca060, DeviceName: \Device\00000027\, DriverName: \Driver\storahci\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... File C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys will be destroyed Infected: C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys --> [Rootkit.Agent.PUA] Done! Drive 0 This is a System drive Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: DD0E7A7A Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 716800 Partition is bootable Partition file system is NTFS Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 718848 Numsec = 1951879168 Partition is not bootable Partition file system is NTFS Partition 2 type is Other (0x27) Partition is NOT ACTIVE. Partition starts at LBA: 1952598016 Numsec = 921600 Partition is not bootable Partition file system is NTFS Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition is not bootable Disk Size: 1000204886016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1953505168-1953525168)... Done! File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\apphelp.dll" is sparse (flags = 32768) File "C:\Windows\AppPatch\AcLayers.dll" is sparse (flags = 32768) File "C:\Windows\System32\msvcrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\user32.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\gdi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ucrtbase.dll" is sparse (flags = 32768) File "C:\Windows\System32\shell32.dll" is sparse (flags = 32768) File "C:\Windows\System32\cfgmgr32.dll" is sparse (flags = 32768) File "C:\Windows\System32\SHCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcrt4.dll" is sparse (flags = 32768) File "C:\Windows\System32\sspicli.dll" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sechost.dll" is sparse (flags = 32768) File "C:\Windows\System32\combase.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STORAGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\advapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\shlwapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\KERNEL.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\powrprof.dll" is sparse (flags = 32768) File "C:\Windows\System32\profapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleaut32.dll" is sparse (flags = 32768) File "C:\Windows\System32\setupapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\mpr.dll" is sparse (flags = 32768) File "C:\Windows\System32\winspool.drv" is sparse (flags = 32768) File "C:\Windows\System32\bcrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\sfc_os.dll" is sparse (flags = 32768) File "C:\Windows\System32\imm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\imagehlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ole32.dll" is sparse (flags = 32768) File "C:\Windows\System32\version.dll" is sparse (flags = 32768) File "C:\Windows\System32\wintrust.dll" is sparse (flags = 32768) File "C:\Windows\System32\msasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\crypt32.dll" is sparse (flags = 32768) File "C:\Windows\System32\psapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wininet.dll" is sparse (flags = 32768) File "C:\Windows\System32\netapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\userenv.dll" is sparse (flags = 32768) File "C:\Windows\System32\ws2_32.dll" is sparse (flags = 32768) File "C:\Windows\System32\netutils.dll" is sparse (flags = 32768) File "C:\Windows\System32\comdlg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winmm.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.0_none_8b4e86125c6fbfec\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINMMBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\rsaenh.dll" is sparse (flags = 32768) File "C:\Windows\System32\uxtheme.dll" is sparse (flags = 32768) File "C:\Windows\System32\msctf.dll" is sparse (flags = 32768) File "C:\Windows\System32\dwmapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkscli.dll" is sparse (flags = 32768) File "C:\Windows\System32\cscapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\iertutil.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPHLPAPI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\winhttp.dll" is sparse (flags = 32768) File "C:\Windows\System32\mswsock.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winnsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\urlmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\msIso.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasadhlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\FWPUCLNT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ntmarta.dll" is sparse (flags = 32768) File "C:\Windows\System32\clbcatq.dll" is sparse (flags = 32768) File "C:\Windows\System32\propsys.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STATEREPOSITORY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\STATEREPOSITORY.CORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\coml2.dll" is sparse (flags = 32768) File "C:\Windows\System32\mssprxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\linkinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntshrui.dll" is sparse (flags = 32768) File "C:\Windows\System32\srvcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERMGRCLI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wtsapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winsta.dll" is sparse (flags = 32768) File "C:\Windows\System32\smss.exe" is sparse (flags = 32768) File "C:\Windows\System32\csrss.exe" is sparse (flags = 32768) File "C:\Windows\System32\wininit.exe" is sparse (flags = 32768) File "C:\Windows\System32\services.exe" is sparse (flags = 32768) File "C:\Windows\System32\lsass.exe" is sparse (flags = 32768) File "C:\Windows\System32\winlogon.exe" is sparse (flags = 32768) File "C:\Windows\System32\FONTDRVHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\svchost.exe" is sparse (flags = 32768) File "C:\Windows\System32\dwm.exe" is sparse (flags = 32768) File "C:\Windows\System32\spoolsv.exe" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\dataup\dataup.exe --> [Adware.Yelloader] Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Dataup --> [Adware.Yelloader] File "C:\Windows\System32\sxs.dll" is sparse (flags = 32768) File "C:\Windows\System32\mfc42.dll" is sparse (flags = 32768) File "C:\Windows\System32\msimg32.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dasHost.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Media Player\wmpnetwk.exe" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiPrvSE.exe" is sparse (flags = 32768) File "C:\Windows\System32\sihost.exe" is sparse (flags = 32768) File "C:\Windows\explorer.exe" is sparse (flags = 32768) File "C:\Windows\System32\TASKHOSTW.EXE" is sparse (flags = 32768) Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] File "C:\Windows\System32\Wldap32.dll" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcsvc.dll" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\System32\RUNTIMEBROKER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MSASCuiL.exe" is sparse (flags = 32768) File "C:\Windows\System32\wsock32.dll" is sparse (flags = 32768) File "C:\Windows\System32\xmllite.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.15063.0_none_d802f55807fa1ec7\GdiPlus.dll" is sparse (flags = 32768) File "C:\Windows\System32\wer.dll" is sparse (flags = 32768) File "C:\Windows\System32\cabinet.dll" is sparse (flags = 32768) File "C:\Windows\System32\Faultrep.dll" is sparse (flags = 32768) File "C:\Windows\System32\secur32.dll" is sparse (flags = 32768) File "C:\Windows\System32\loadperf.dll" is sparse (flags = 32768) File "C:\Windows\System32\pdh.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbghelp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ncrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbgcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\mlang.dll" is sparse (flags = 32768) File "C:\Windows\System32\msxml6.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\taskschd.dll" is sparse (flags = 32768) File "C:\Windows\System32\TWINAPI.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\Wpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidprov.dll" is sparse (flags = 32768) File "C:\Windows\System32\samcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\regsvr32.exe" is sparse (flags = 32768) File "C:\Windows\System32\usp10.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleacc.dll" is sparse (flags = 32768) File "C:\Windows\System32\DWrite.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlaapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\avrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\MMDevAPI.dll" is sparse (flags = 32768) File "C:\Windows\System32\devobj.dll" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\d3d11.dll" is sparse (flags = 32768) File "C:\Windows\System32\dcomp.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxgi.dll" is sparse (flags = 32768) File "C:\Windows\System32\mscms.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptnet.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETWORKEXPLORER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETWORKEXPLORER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\d3d9.dll" is sparse (flags = 32768) File "C:\Windows\System32\msi.dll" is sparse (flags = 32768) File "C:\Windows\System32\dpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\edputil.dll" is sparse (flags = 32768) File "C:\Windows\System32\NapiNSP.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpnsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\winrnr.dll" is sparse (flags = 32768) File "C:\Windows\System32\dllhost.exe" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe --> [Adware.Yelloader] File "C:\Windows\System32\zipfldr.dll" is sparse (flags = 32768) File "C:\Windows\System32\DIRECTMANIPULATION.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DIRECTMANIPULATION.DLL" is sparse (flags = 32768) File "C:\Windows\System32\devenum.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdmo.dll" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\winscr\winscr.exe --> [Adware.Yelloader] File "C:\Windows\System32\opengl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\glu32.dll" is sparse (flags = 32768) File "C:\Windows\System32\cmd.exe" is sparse (flags = 32768) File "C:\Windows\System32\conhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\schannel.dll" is sparse (flags = 32768) File "C:\Windows\System32\MSKEYPROTECT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSKEYPROTECT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCRYPTSSLP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCRYPTSSLP.DLL" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ctfmon.exe" is sparse (flags = 32768) File "C:\Windows\System32\MSCTFMONITOR.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSCTFMONITOR.DLL" is sparse (flags = 32768) File "C:\Windows\System32\msutb.dll" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\System32\credssp.dll" is sparse (flags = 32768) File "C:\Windows\System32\userinit.exe" is sparse (flags = 32768) File "C:\Windows\System32\scecli.dll" is sparse (flags = 32768) File "C:\Windows\System32\msv1_0.dll" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\appid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspclock.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpiex.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\Locator.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mpsdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\afd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ahcache.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\asyncmac.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv.sys" is sparse (flags = 32768) File "C:\Windows\System32\alg.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcifs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcnfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\luafv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bowser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cng.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\clfs.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cldflt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\registry.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mup.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\condrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dam.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dfsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dxgkrnl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpip.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORCLASS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPATIALGRAPHFILTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fileinfo.sys" is sparse (flags = 32768) File "C:\Windows\System32\FXSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipfltdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fltMgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PRESENTATIONFONTCACHE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fvevol.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndisuio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFRd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wanarp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbengine.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\http.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hwpolicy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pacer.sys" is sparse (flags = 32768) File "C:\Windows\SysWOW64\perfhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\iorate.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\scfilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdFilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irda.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecdd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecpkg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksthunk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\lltdio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwififlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mstee.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mmcss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mskssrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MsMpEng.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wimmount.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxdav.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\modem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspqm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mountmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasl2tp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb10.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb20.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ucx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ufx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bridge.sys" is sparse (flags = 32768) File "C:\Windows\System32\msdtc.exe" is sparse (flags = 32768) File "C:\Windows\System32\VSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\msiexec.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mslldp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nwifi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndis.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiscap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndistapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiswan.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ndu.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwifibus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nsiproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdiWiFi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\vds.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\partmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcw.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\PEAuth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\RDPVIDEOMINIPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\qwavedrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspptp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasacd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\agilevpn.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspppoe.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rassstp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdbss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpdr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdyboost.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rspndr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SpbCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\snmptrap.exe" is sparse (flags = 32768) File "C:\Windows\System32\Spectrum.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Wdf01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\sppsvc.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srvnet.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgrx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpipreg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tdx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\terminpt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\servicing\TRUSTEDINSTALLER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbFlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UcmCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Udecx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\udfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBXHCI.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhf.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volsnap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdBoot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdNisDrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\NisSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wfplwfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiApSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ws2ifsl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFPf.sys" is sparse (flags = 32768) File "C:\Windows\System32\AJRouter.dll" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umpnpmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcss.dll" is sparse (flags = 32768) File "C:\Windows\System32\appinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\appidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\AxInstSv.dll" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\AUDIOENDPOINTBUILDER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\audiosrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\RpcEpMap.dll" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bdesvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\BFE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netman.dll" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cdpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\umpo.dll" is sparse (flags = 32768) File "C:\Windows\System32\qmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\ListSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lltdsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\browser.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\profsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bthserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\provsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\das.dll" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\certprop.dll" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ClipSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wscsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WsmSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wersvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wecsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dot3svc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dusmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\fdPHost.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsrslvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\dps.dll" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\eapsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\efssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ENTERPRISEAPPMGMTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FntCache.dll" is sparse (flags = 32768) File "C:\Windows\System32\es.dll" is sparse (flags = 32768) File "C:\Windows\System32\sdrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\srvsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\xbgmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FDResPub.dll" is sparse (flags = 32768) File "C:\Windows\System32\upnphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\fhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\hidserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\HVHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IKEEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\iphlpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\irmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\keyiso.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdtckrm.dll" is sparse (flags = 32768) File "C:\Windows\System32\lfsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lpasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lmhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ipnathlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\lsm.dll" is sparse (flags = 32768) File "C:\Windows\System32\moshost.dll" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MPSSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\iscsiexe.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsisvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ngcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NcaSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netlogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\trkwks.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\icsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pcasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\p2psvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pla.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\icsvcext.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPSECSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\qwave.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasmans.dll" is sparse (flags = 32768) File "C:\Windows\System32\mprdim.dll" is sparse (flags = 32768) File "C:\Windows\System32\regsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\RDXSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\RMapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\schedsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SCardSvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\seclogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\sensrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SEMgrSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\Sens.dll" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SessEnv.dll" is sparse (flags = 32768) File "C:\Windows\System32\shsvcs.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\smphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\StorSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\sstpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ssdpsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\wiaservc.dll" is sparse (flags = 32768) File "C:\Windows\System32\svsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\swprv.dll" is sparse (flags = 32768) File "C:\Windows\System32\sysmain.dll" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TabSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\termsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\tapisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TOKENBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umrdp.dll" is sparse (flags = 32768) File "C:\Windows\System32\Unistore.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\usermgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\usocore.dll" is sparse (flags = 32768) File "C:\Windows\System32\vaultsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\w32time.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbiosrvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wwansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WUDFSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcncsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdi.dll" is sparse (flags = 32768) File "C:\Windows\System32\WebClnt.dll" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wiarpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WMIsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wuaueng.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Program Files\Windows Mail\WinMail.exe" is sparse (flags = 32768) File "C:\Windows\System32\unregmp2.exe" is sparse (flags = 32768) File "C:\Windows\System32\ie4uinit.exe" is sparse (flags = 32768) File "C:\Users\steff\AppData\Local\Comms\UnistoreDB\store.vol" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\tnifv\qdcomsvc.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\uhiba\ct.exe --> [Adware.Yelloader] File "C:\Windows\System32\config\systemprofile\AppData\Local\DataSharing\Storage\DSTokenDB2.dat" is sparse (flags = 32768) --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.09.4.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 10.0.15063 Windows 10 x64 Account is Administrative Internet Explorer version: 11.296.15063.0 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 3.500000 GHz Memory total: 8588013568, free: 5966360576 Downloaded database version: v2017.05.18.02 Initializing... ====================== Driver version: 0.3.0.4 ------------ Kernel report ------------ 05/17/2017 21:07:53 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_AuthenticAMD.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\System32\drivers\ksecdd.sys \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\System32\drivers\FLTMGR.SYS \SystemRoot\System32\drivers\clipsp.sys \SystemRoot\System32\drivers\cmimcext.sys \SystemRoot\System32\drivers\ntosext.sys \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\cng.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\SleepStudyHelper.sys \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\system32\drivers\WindowsTrustedRT.sys \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\system32\drivers\ndistpr64.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\system32\drivers\NDIS.SYS \SystemRoot\system32\drivers\TDI.SYS \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\system32\drivers\CEA.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\pciide.sys \SystemRoot\System32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\atapi.sys \SystemRoot\System32\drivers\ataport.SYS \SystemRoot\System32\drivers\storahci.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Wof.sys \SystemRoot\System32\Drivers\NTFS.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\drivers\wfplwfs.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\System32\drivers\volume.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\iorate.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\system32\drivers\filecrypt.sys \SystemRoot\system32\drivers\tbs.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\vmbkmclr.sys \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\drivers\vwififlt.sys \SystemRoot\System32\drivers\pacer.sys \SystemRoot\system32\drivers\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\drivers\gpuenergydrv.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\SysWow64\drivers\AsIO.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys \SystemRoot\System32\drivers\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \SystemRoot\System32\drivers\amdppm.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\portcls.sys \SystemRoot\System32\drivers\drmk.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\rt640x64.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\system32\drivers\ucx01000.sys \SystemRoot\System32\drivers\usbohci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\serial.sys \SystemRoot\System32\drivers\serenum.sys \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\system32\drivers\AtihdWT6.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\system32\DRIVERS\HdAudio.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\kbdhid.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_storahci.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\win32kfull.sys \SystemRoot\System32\win32kbase.sys \SystemRoot\System32\drivers\dxgmms2.sys \SystemRoot\System32\drivers\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\wcifs.sys \SystemRoot\system32\drivers\storqosflt.sys \SystemRoot\System32\drivers\registry.sys \SystemRoot\system32\drivers\lltdio.sys \SystemRoot\system32\drivers\mslldp.sys \SystemRoot\system32\drivers\rspndr.sys \SystemRoot\System32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\system32\drivers\mmcss.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\System32\drivers\condrv.sys \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys ----------- End ----------- Done! Scan started Database versions: main: v2017.05.18.02 rootkit: v2017.04.02.01 <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffd5032a1c4060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffd503268611e0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffd5032a1c4060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffffd5032877b060, DeviceName: \Device\00000027\, DriverName: \Driver\storahci\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... File C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys will be destroyed Infected: C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys --> [Rootkit.Agent.PUA] Done! Drive 0 This is a System drive Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: DD0E7A7A Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 716800 Partition is bootable Partition file system is NTFS Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 718848 Numsec = 1951879168 Partition is not bootable Partition file system is NTFS Partition 2 type is Other (0x27) Partition is NOT ACTIVE. Partition starts at LBA: 1952598016 Numsec = 921600 Partition is not bootable Partition file system is NTFS Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition is not bootable Disk Size: 1000204886016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1953505168-1953525168)... Done! File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\apphelp.dll" is sparse (flags = 32768) File "C:\Windows\AppPatch\AcLayers.dll" is sparse (flags = 32768) File "C:\Windows\System32\msvcrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\user32.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\gdi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ucrtbase.dll" is sparse (flags = 32768) File "C:\Windows\System32\shell32.dll" is sparse (flags = 32768) File "C:\Windows\System32\cfgmgr32.dll" is sparse (flags = 32768) File "C:\Windows\System32\SHCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcrt4.dll" is sparse (flags = 32768) File "C:\Windows\System32\sspicli.dll" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sechost.dll" is sparse (flags = 32768) File "C:\Windows\System32\combase.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STORAGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\advapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\shlwapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\KERNEL.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\powrprof.dll" is sparse (flags = 32768) File "C:\Windows\System32\profapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleaut32.dll" is sparse (flags = 32768) File "C:\Windows\System32\setupapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\mpr.dll" is sparse (flags = 32768) File "C:\Windows\System32\winspool.drv" is sparse (flags = 32768) File "C:\Windows\System32\bcrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\sfc_os.dll" is sparse (flags = 32768) File "C:\Windows\System32\imm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\imagehlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ole32.dll" is sparse (flags = 32768) File "C:\Windows\System32\version.dll" is sparse (flags = 32768) File "C:\Windows\System32\wintrust.dll" is sparse (flags = 32768) File "C:\Windows\System32\msasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\crypt32.dll" is sparse (flags = 32768) File "C:\Windows\System32\psapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wininet.dll" is sparse (flags = 32768) File "C:\Windows\System32\netapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\userenv.dll" is sparse (flags = 32768) File "C:\Windows\System32\netutils.dll" is sparse (flags = 32768) File "C:\Windows\System32\comdlg32.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.0_none_8b4e86125c6fbfec\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winmm.dll" is sparse (flags = 32768) File "C:\Windows\System32\ws2_32.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINMMBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\rsaenh.dll" is sparse (flags = 32768) File "C:\Windows\System32\uxtheme.dll" is sparse (flags = 32768) File "C:\Windows\System32\msctf.dll" is sparse (flags = 32768) File "C:\Windows\System32\dwmapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkscli.dll" is sparse (flags = 32768) File "C:\Windows\System32\cscapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\iertutil.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPHLPAPI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\winhttp.dll" is sparse (flags = 32768) File "C:\Windows\System32\mswsock.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winnsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\urlmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\msIso.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasadhlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\FWPUCLNT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ntmarta.dll" is sparse (flags = 32768) File "C:\Windows\System32\clbcatq.dll" is sparse (flags = 32768) File "C:\Windows\System32\propsys.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STATEREPOSITORY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\STATEREPOSITORY.CORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\coml2.dll" is sparse (flags = 32768) File "C:\Windows\System32\mssprxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\linkinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntshrui.dll" is sparse (flags = 32768) File "C:\Windows\System32\srvcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERMGRCLI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\wtsapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winsta.dll" is sparse (flags = 32768) File "C:\Windows\System32\smss.exe" is sparse (flags = 32768) File "C:\Windows\System32\csrss.exe" is sparse (flags = 32768) File "C:\Windows\System32\wininit.exe" is sparse (flags = 32768) File "C:\Windows\System32\services.exe" is sparse (flags = 32768) File "C:\Windows\System32\lsass.exe" is sparse (flags = 32768) File "C:\Windows\System32\winlogon.exe" is sparse (flags = 32768) File "C:\Windows\System32\svchost.exe" is sparse (flags = 32768) File "C:\Windows\System32\FONTDRVHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dwm.exe" is sparse (flags = 32768) File "C:\Windows\System32\spoolsv.exe" is sparse (flags = 32768) File "C:\Windows\System32\msimg32.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\mfc42.dll" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\dataup\dataup.exe --> [Adware.Yelloader] Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Dataup --> [Adware.Yelloader] File "C:\Windows\System32\sxs.dll" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dasHost.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Media Player\wmpnetwk.exe" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiPrvSE.exe" is sparse (flags = 32768) File "C:\Windows\System32\sihost.exe" is sparse (flags = 32768) File "C:\Windows\explorer.exe" is sparse (flags = 32768) Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] File "C:\Windows\System32\Wldap32.dll" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\TASKHOSTW.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\System32\RUNTIMEBROKER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MSASCuiL.exe" is sparse (flags = 32768) File "C:\Windows\System32\wsock32.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.15063.0_none_d802f55807fa1ec7\GdiPlus.dll" is sparse (flags = 32768) File "C:\Windows\System32\xmllite.dll" is sparse (flags = 32768) File "C:\Windows\System32\wer.dll" is sparse (flags = 32768) File "C:\Windows\System32\Faultrep.dll" is sparse (flags = 32768) File "C:\Windows\System32\secur32.dll" is sparse (flags = 32768) File "C:\Windows\System32\cabinet.dll" is sparse (flags = 32768) File "C:\Windows\System32\pdh.dll" is sparse (flags = 32768) File "C:\Windows\System32\loadperf.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbghelp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ncrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbgcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\mlang.dll" is sparse (flags = 32768) File "C:\Windows\System32\msxml6.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\taskschd.dll" is sparse (flags = 32768) File "C:\Windows\System32\TWINAPI.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\Wpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidprov.dll" is sparse (flags = 32768) File "C:\Windows\System32\samcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\opengl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\glu32.dll" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\d3d11.dll" is sparse (flags = 32768) File "C:\Windows\System32\dcomp.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxgi.dll" is sparse (flags = 32768) File "C:\Windows\System32\DWrite.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlanapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\dinput8.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\wbemprox.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbemcomn.dll" is sparse (flags = 32768) File "C:\Windows\System32\hid.dll" is sparse (flags = 32768) File "C:\Windows\System32\devobj.dll" is sparse (flags = 32768) File "C:\Windows\System32\MMDevAPI.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\wbemsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\XINPUT1_4.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XINPUT1_4.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wbem\fastprox.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdmaud.drv" is sparse (flags = 32768) File "C:\Windows\System32\avrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\ksuser.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\msacm32.drv" is sparse (flags = 32768) File "C:\Windows\System32\msacm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\midimap.dll" is sparse (flags = 32768) File "C:\Windows\System32\dsound.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.UI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.UI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NapiNSP.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpnsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlaapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winrnr.dll" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\gpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptnet.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONECOREUAPCOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONECOREUAPCOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPRESOLVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MrmCoreR.dll" is sparse (flags = 32768) File "C:\Windows\System32\BCP47LANGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ELSCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\slc.dll" is sparse (flags = 32768) File "C:\Windows\System32\sppc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONECORECOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONECORECOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\POLICYMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP110_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\oleacc.dll" is sparse (flags = 32768) File "C:\Windows\System32\usp10.dll" is sparse (flags = 32768) File "C:\Windows\System32\mscms.dll" is sparse (flags = 32768) File "C:\Windows\System32\d3d9.dll" is sparse (flags = 32768) File "C:\Windows\System32\msi.dll" is sparse (flags = 32768) File "C:\Windows\System32\dpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\edputil.dll" is sparse (flags = 32768) File "C:\Windows\System32\credui.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptui.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxva2.dll" is sparse (flags = 32768) File "C:\Windows\System32\fontsub.dll" is sparse (flags = 32768) File "C:\Windows\System32\fontsub.dll" is sparse (flags = 32768) File "C:\Windows\System32\dllhost.exe" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe --> [Adware.Yelloader] File "C:\Windows\System32\DIRECTMANIPULATION.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DIRECTMANIPULATION.DLL" is sparse (flags = 32768) File "C:\Windows\System32\webio.dll" is sparse (flags = 32768) File "C:\Windows\System32\devenum.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdmo.dll" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSAPI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSAPI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSNATIVEAPI.V2.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSNATIVEAPI.V2.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSUTILSV2.DLL" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\winscr\winscr.exe --> [Adware.Yelloader] File "C:\Windows\System32\schannel.dll" is sparse (flags = 32768) File "C:\Windows\System32\MSKEYPROTECT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSKEYPROTECT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCRYPTSSLP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCRYPTSSLP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ctfmon.exe" is sparse (flags = 32768) File "C:\Windows\System32\MSCTFMONITOR.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSCTFMONITOR.DLL" is sparse (flags = 32768) File "C:\Windows\System32\msutb.dll" is sparse (flags = 32768) File "C:\Windows\System32\cmd.exe" is sparse (flags = 32768) File "C:\Windows\System32\conhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\System32\credssp.dll" is sparse (flags = 32768) File "C:\Windows\System32\userinit.exe" is sparse (flags = 32768) File "C:\Windows\System32\scecli.dll" is sparse (flags = 32768) File "C:\Windows\System32\msv1_0.dll" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\appid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspclock.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpiex.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\Locator.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mpsdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\afd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ahcache.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\asyncmac.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv.sys" is sparse (flags = 32768) File "C:\Windows\System32\alg.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcifs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcnfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\luafv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bowser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cng.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\clfs.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cldflt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\registry.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mup.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\condrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dam.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dfsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dxgkrnl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpip.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORCLASS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPATIALGRAPHFILTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fileinfo.sys" is sparse (flags = 32768) File "C:\Windows\System32\FXSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipfltdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fltMgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PRESENTATIONFONTCACHE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fvevol.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndisuio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFRd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wanarp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbengine.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\http.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hwpolicy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pacer.sys" is sparse (flags = 32768) File "C:\Windows\SysWOW64\perfhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\iorate.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\scfilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdFilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irda.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecdd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecpkg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksthunk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\lltdio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwififlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mstee.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mmcss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mskssrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MsMpEng.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wimmount.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxdav.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\modem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspqm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mountmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasl2tp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb10.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb20.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ucx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ufx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bridge.sys" is sparse (flags = 32768) File "C:\Windows\System32\msdtc.exe" is sparse (flags = 32768) File "C:\Windows\System32\VSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\msiexec.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mslldp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nwifi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndis.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiscap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndistapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiswan.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ndu.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwifibus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nsiproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdiWiFi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\vds.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\partmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcw.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\PEAuth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\RDPVIDEOMINIPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\qwavedrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspptp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasacd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\agilevpn.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspppoe.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rassstp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdbss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpdr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdyboost.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rspndr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SpbCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\snmptrap.exe" is sparse (flags = 32768) File "C:\Windows\System32\Spectrum.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Wdf01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\sppsvc.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srvnet.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgrx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpipreg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tdx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\terminpt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\servicing\TRUSTEDINSTALLER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbFlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UcmCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Udecx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\udfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBXHCI.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhf.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volsnap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdBoot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdNisDrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\NisSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wfplwfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiApSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ws2ifsl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFPf.sys" is sparse (flags = 32768) File "C:\Windows\System32\AJRouter.dll" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umpnpmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcss.dll" is sparse (flags = 32768) File "C:\Windows\System32\appinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\appidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\AxInstSv.dll" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\AUDIOENDPOINTBUILDER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\audiosrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\RpcEpMap.dll" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bdesvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\BFE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netman.dll" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cdpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\umpo.dll" is sparse (flags = 32768) File "C:\Windows\System32\qmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\ListSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lltdsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\browser.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\profsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bthserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\provsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\das.dll" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\certprop.dll" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ClipSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wscsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WsmSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wersvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wecsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dot3svc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dusmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\fdPHost.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsrslvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\dps.dll" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\eapsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\efssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ENTERPRISEAPPMGMTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FntCache.dll" is sparse (flags = 32768) File "C:\Windows\System32\es.dll" is sparse (flags = 32768) File "C:\Windows\System32\sdrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\srvsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\xbgmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FDResPub.dll" is sparse (flags = 32768) File "C:\Windows\System32\upnphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\fhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\hidserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\HVHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IKEEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\iphlpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\irmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\keyiso.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdtckrm.dll" is sparse (flags = 32768) File "C:\Windows\System32\lfsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lpasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lmhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ipnathlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\lsm.dll" is sparse (flags = 32768) File "C:\Windows\System32\moshost.dll" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MPSSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\iscsiexe.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsisvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ngcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NcaSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netlogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\trkwks.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\icsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pcasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\p2psvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pla.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\icsvcext.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPSECSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\qwave.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasmans.dll" is sparse (flags = 32768) File "C:\Windows\System32\mprdim.dll" is sparse (flags = 32768) File "C:\Windows\System32\regsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\RDXSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\RMapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\schedsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SCardSvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\seclogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\sensrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SEMgrSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\Sens.dll" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SessEnv.dll" is sparse (flags = 32768) File "C:\Windows\System32\shsvcs.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\smphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\StorSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\sstpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ssdpsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\wiaservc.dll" is sparse (flags = 32768) File "C:\Windows\System32\svsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\swprv.dll" is sparse (flags = 32768) File "C:\Windows\System32\sysmain.dll" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TabSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\termsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\tapisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TOKENBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umrdp.dll" is sparse (flags = 32768) File "C:\Windows\System32\Unistore.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\usermgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\usocore.dll" is sparse (flags = 32768) File "C:\Windows\System32\vaultsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\w32time.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbiosrvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wwansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WUDFSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcncsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdi.dll" is sparse (flags = 32768) File "C:\Windows\System32\WebClnt.dll" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wiarpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WMIsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wuaueng.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Program Files\Windows Mail\WinMail.exe" is sparse (flags = 32768) File "C:\Windows\System32\unregmp2.exe" is sparse (flags = 32768) File "C:\Windows\System32\ie4uinit.exe" is sparse (flags = 32768) File "C:\Users\steff\AppData\Local\Comms\UnistoreDB\store.vol" is sparse (flags = 32768) --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.09.4.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 10.0.15063 Windows 10 x64 Account is Administrative Internet Explorer version: 11.296.15063.0 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 3.500000 GHz Memory total: 8588013568, free: 6391410688 Downloaded database version: v2017.05.18.03 Downloaded database version: v2017.05.18.12 Canceled update Downloaded database version: v2017.05.18.03 Downloaded database version: v2017.05.18.04 Downloaded database version: v2017.05.18.05 Downloaded database version: v2017.05.18.06 Downloaded database version: v2017.05.18.07 Downloaded database version: v2017.05.18.08 Downloaded database version: v2017.05.18.09 Downloaded database version: v2017.05.18.10 Downloaded database version: v2017.05.18.11 Downloaded database version: v2017.05.18.12 ======================================= Initializing... Driver version: 0.3.0.4 ------------ Kernel report ------------ 05/18/2017 19:05:57 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_AuthenticAMD.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\System32\drivers\ksecdd.sys \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\System32\drivers\FLTMGR.SYS \SystemRoot\System32\drivers\clipsp.sys \SystemRoot\System32\drivers\cmimcext.sys \SystemRoot\System32\drivers\ntosext.sys \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\cng.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\SleepStudyHelper.sys \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\system32\drivers\WindowsTrustedRT.sys \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\system32\drivers\ndistpr64.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\system32\drivers\NDIS.SYS \SystemRoot\system32\drivers\TDI.SYS \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\system32\drivers\CEA.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\pciide.sys \SystemRoot\System32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\atapi.sys \SystemRoot\System32\drivers\ataport.SYS \SystemRoot\System32\drivers\storahci.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Wof.sys \SystemRoot\System32\Drivers\NTFS.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\drivers\wfplwfs.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\System32\drivers\volume.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\iorate.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\system32\drivers\filecrypt.sys \SystemRoot\system32\drivers\tbs.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\vmbkmclr.sys \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\drivers\vwififlt.sys \SystemRoot\System32\drivers\pacer.sys \SystemRoot\system32\drivers\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\drivers\gpuenergydrv.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\SysWow64\drivers\AsIO.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys \SystemRoot\System32\drivers\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \SystemRoot\System32\drivers\amdppm.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\portcls.sys \SystemRoot\System32\drivers\drmk.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\rt640x64.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\system32\drivers\ucx01000.sys \SystemRoot\System32\drivers\usbohci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\serial.sys \SystemRoot\System32\drivers\serenum.sys \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\system32\drivers\AtihdWT6.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\system32\DRIVERS\HdAudio.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\kbdhid.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_storahci.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\win32kfull.sys \SystemRoot\System32\win32kbase.sys \SystemRoot\System32\drivers\dxgmms2.sys \SystemRoot\System32\drivers\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\wcifs.sys \SystemRoot\system32\drivers\storqosflt.sys \SystemRoot\System32\drivers\registry.sys \SystemRoot\system32\drivers\lltdio.sys \SystemRoot\system32\drivers\mslldp.sys \SystemRoot\system32\drivers\rspndr.sys \SystemRoot\System32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\system32\drivers\mmcss.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\System32\drivers\condrv.sys \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys ----------- End ----------- Done! Scan started Database versions: main: v2017.05.18.12 rootkit: v2017.04.02.01 <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffff8e838b564060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffff8e838b3d88f0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffff8e838b564060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffff8e838b1f3060, DeviceName: \Device\00000027\, DriverName: \Driver\storahci\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... File C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys will be destroyed Infected: C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys --> [Rootkit.Agent.PUA] Done! Drive 0 This is a System drive Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: DD0E7A7A Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 716800 Partition is bootable Partition file system is NTFS Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 718848 Numsec = 1951879168 Partition is not bootable Partition file system is NTFS Partition 2 type is Other (0x27) Partition is NOT ACTIVE. Partition starts at LBA: 1952598016 Numsec = 921600 Partition is not bootable Partition file system is NTFS Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition is not bootable Disk Size: 1000204886016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1953505168-1953525168)... Done! File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\apphelp.dll" is sparse (flags = 32768) File "C:\Windows\AppPatch\AcLayers.dll" is sparse (flags = 32768) File "C:\Windows\System32\msvcrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\user32.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\gdi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ucrtbase.dll" is sparse (flags = 32768) File "C:\Windows\System32\shell32.dll" is sparse (flags = 32768) File "C:\Windows\System32\cfgmgr32.dll" is sparse (flags = 32768) File "C:\Windows\System32\SHCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcrt4.dll" is sparse (flags = 32768) File "C:\Windows\System32\sspicli.dll" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sechost.dll" is sparse (flags = 32768) File "C:\Windows\System32\combase.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STORAGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\advapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\shlwapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\KERNEL.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\powrprof.dll" is sparse (flags = 32768) File "C:\Windows\System32\profapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleaut32.dll" is sparse (flags = 32768) File "C:\Windows\System32\setupapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\mpr.dll" is sparse (flags = 32768) File "C:\Windows\System32\winspool.drv" is sparse (flags = 32768) File "C:\Windows\System32\bcrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\sfc_os.dll" is sparse (flags = 32768) File "C:\Windows\System32\imm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\imagehlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ole32.dll" is sparse (flags = 32768) File "C:\Windows\System32\wintrust.dll" is sparse (flags = 32768) File "C:\Windows\System32\version.dll" is sparse (flags = 32768) File "C:\Windows\System32\msasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\crypt32.dll" is sparse (flags = 32768) File "C:\Windows\System32\psapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wininet.dll" is sparse (flags = 32768) File "C:\Windows\System32\netapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\userenv.dll" is sparse (flags = 32768) File "C:\Windows\System32\comdlg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\ws2_32.dll" is sparse (flags = 32768) File "C:\Windows\System32\netutils.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.0_none_8b4e86125c6fbfec\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winmm.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINMMBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\rsaenh.dll" is sparse (flags = 32768) File "C:\Windows\System32\uxtheme.dll" is sparse (flags = 32768) File "C:\Windows\System32\msctf.dll" is sparse (flags = 32768) File "C:\Windows\System32\dwmapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkscli.dll" is sparse (flags = 32768) File "C:\Windows\System32\cscapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\iertutil.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPHLPAPI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\winhttp.dll" is sparse (flags = 32768) File "C:\Windows\System32\mswsock.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winnsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\urlmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\msIso.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasadhlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\FWPUCLNT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\srvcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntmarta.dll" is sparse (flags = 32768) File "C:\Windows\System32\clbcatq.dll" is sparse (flags = 32768) File "C:\Windows\System32\propsys.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STATEREPOSITORY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\STATEREPOSITORY.CORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\coml2.dll" is sparse (flags = 32768) File "C:\Windows\System32\mssprxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\linkinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntshrui.dll" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERMGRCLI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wtsapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winsta.dll" is sparse (flags = 32768) File "C:\Windows\System32\smss.exe" is sparse (flags = 32768) File "C:\Windows\System32\csrss.exe" is sparse (flags = 32768) File "C:\Windows\System32\wininit.exe" is sparse (flags = 32768) File "C:\Windows\System32\services.exe" is sparse (flags = 32768) File "C:\Windows\System32\lsass.exe" is sparse (flags = 32768) File "C:\Windows\System32\winlogon.exe" is sparse (flags = 32768) File "C:\Windows\System32\FONTDRVHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\svchost.exe" is sparse (flags = 32768) File "C:\Windows\System32\dwm.exe" is sparse (flags = 32768) File "C:\Windows\System32\spoolsv.exe" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\msimg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\mfc42.dll" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\dataup\dataup.exe --> [Adware.Yelloader] Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Dataup --> [Adware.Yelloader] File "C:\Windows\System32\sxs.dll" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dasHost.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Media Player\wmpnetwk.exe" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiPrvSE.exe" is sparse (flags = 32768) File "C:\Windows\System32\sihost.exe" is sparse (flags = 32768) File "C:\Windows\explorer.exe" is sparse (flags = 32768) File "C:\Windows\System32\TASKHOSTW.EXE" is sparse (flags = 32768) Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] File "C:\Windows\System32\Wldap32.dll" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\System32\RUNTIMEBROKER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MSASCuiL.exe" is sparse (flags = 32768) File "C:\Windows\System32\wsock32.dll" is sparse (flags = 32768) File "C:\Windows\System32\xmllite.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.15063.0_none_d802f55807fa1ec7\GdiPlus.dll" is sparse (flags = 32768) File "C:\Windows\System32\wer.dll" is sparse (flags = 32768) File "C:\Windows\System32\Faultrep.dll" is sparse (flags = 32768) File "C:\Windows\System32\secur32.dll" is sparse (flags = 32768) File "C:\Windows\System32\cabinet.dll" is sparse (flags = 32768) File "C:\Windows\System32\loadperf.dll" is sparse (flags = 32768) File "C:\Windows\System32\pdh.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbghelp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ncrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbgcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\mlang.dll" is sparse (flags = 32768) File "C:\Windows\System32\msxml6.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\taskschd.dll" is sparse (flags = 32768) File "C:\Windows\System32\TWINAPI.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\Wpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidprov.dll" is sparse (flags = 32768) File "C:\Windows\System32\samcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\opengl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\glu32.dll" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\d3d11.dll" is sparse (flags = 32768) File "C:\Windows\System32\dcomp.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxgi.dll" is sparse (flags = 32768) File "C:\Windows\System32\DWrite.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleacc.dll" is sparse (flags = 32768) File "C:\Windows\System32\usp10.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlaapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\avrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\MMDevAPI.dll" is sparse (flags = 32768) File "C:\Windows\System32\devobj.dll" is sparse (flags = 32768) File "C:\Windows\System32\mscms.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptnet.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETWORKEXPLORER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETWORKEXPLORER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\d3d9.dll" is sparse (flags = 32768) File "C:\Windows\System32\NapiNSP.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpnsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\winrnr.dll" is sparse (flags = 32768) File "C:\Windows\System32\msi.dll" is sparse (flags = 32768) File "C:\Windows\System32\dpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\edputil.dll" is sparse (flags = 32768) File "C:\Windows\System32\credui.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptui.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxva2.dll" is sparse (flags = 32768) File "C:\Windows\System32\fontsub.dll" is sparse (flags = 32768) File "C:\Windows\System32\fontsub.dll" is sparse (flags = 32768) File "C:\Windows\System32\dllhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WMIADAP.exe" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe --> [Adware.Yelloader] Infected: HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|svcvmx --> [Adware.Yelloader] File "C:\Windows\System32\INSTALLAGENT.EXE" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe --> [Adware.Yelloader] File "C:\Windows\System32\DIRECTMANIPULATION.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DIRECTMANIPULATION.DLL" is sparse (flags = 32768) File "C:\Windows\System32\devenum.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdmo.dll" is sparse (flags = 32768) File "C:\Windows\System32\INSTALLAGENTUSERBROKER.EXE" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ctfmon.exe" is sparse (flags = 32768) File "C:\Windows\System32\MSCTFMONITOR.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSCTFMONITOR.DLL" is sparse (flags = 32768) File "C:\Windows\System32\msutb.dll" is sparse (flags = 32768) File "C:\Windows\System32\cmd.exe" is sparse (flags = 32768) File "C:\Windows\System32\conhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\schannel.dll" is sparse (flags = 32768) File "C:\Windows\System32\MSKEYPROTECT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSKEYPROTECT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\webio.dll" is sparse (flags = 32768) File "C:\Windows\System32\NCRYPTSSLP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCRYPTSSLP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COMPATTELRUNNER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\COMPATTELRUNNER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\MSFEEDSSYNC.EXE" is sparse (flags = 32768) File "C:\Windows\System32\MSFEEDSSYNC.EXE" is sparse (flags = 32768) File "C:\Windows\System32\sppsvc.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\System32\credssp.dll" is sparse (flags = 32768) File "C:\Windows\System32\userinit.exe" is sparse (flags = 32768) File "C:\Windows\System32\scecli.dll" is sparse (flags = 32768) File "C:\Windows\System32\msv1_0.dll" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\appid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspclock.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpiex.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\Locator.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mpsdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\afd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ahcache.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\asyncmac.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv.sys" is sparse (flags = 32768) File "C:\Windows\System32\alg.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcifs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcnfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\luafv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bowser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cng.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\clfs.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cldflt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\registry.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mup.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\condrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dam.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dfsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dxgkrnl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpip.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORCLASS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPATIALGRAPHFILTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fileinfo.sys" is sparse (flags = 32768) File "C:\Windows\System32\FXSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipfltdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fltMgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PRESENTATIONFONTCACHE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fvevol.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndisuio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFRd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wanarp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbengine.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\http.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hwpolicy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pacer.sys" is sparse (flags = 32768) File "C:\Windows\SysWOW64\perfhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\iorate.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\scfilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdFilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irda.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecdd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecpkg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksthunk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\lltdio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwififlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mstee.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mmcss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mskssrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MsMpEng.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wimmount.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxdav.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\modem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspqm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mountmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasl2tp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb10.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb20.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ucx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ufx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bridge.sys" is sparse (flags = 32768) File "C:\Windows\System32\msdtc.exe" is sparse (flags = 32768) File "C:\Windows\System32\VSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\msiexec.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mslldp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nwifi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndis.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiscap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndistapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiswan.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ndu.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwifibus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nsiproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdiWiFi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\vds.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\partmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcw.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\PEAuth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\RDPVIDEOMINIPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\qwavedrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspptp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasacd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\agilevpn.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspppoe.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rassstp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdbss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpdr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdyboost.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rspndr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SpbCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\snmptrap.exe" is sparse (flags = 32768) File "C:\Windows\System32\Spectrum.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Wdf01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srvnet.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgrx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpipreg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tdx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\terminpt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\servicing\TRUSTEDINSTALLER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbFlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UcmCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Udecx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\udfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBXHCI.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhf.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volsnap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdBoot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdNisDrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\NisSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wfplwfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiApSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ws2ifsl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFPf.sys" is sparse (flags = 32768) File "C:\Windows\System32\AJRouter.dll" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umpnpmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcss.dll" is sparse (flags = 32768) File "C:\Windows\System32\appinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\appidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\AxInstSv.dll" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\AUDIOENDPOINTBUILDER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\audiosrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\RpcEpMap.dll" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bdesvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\BFE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netman.dll" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cdpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\umpo.dll" is sparse (flags = 32768) File "C:\Windows\System32\qmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\ListSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lltdsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\browser.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\profsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bthserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\provsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\das.dll" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\certprop.dll" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ClipSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wscsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WsmSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wersvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wecsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dot3svc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dusmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\fdPHost.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsrslvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\dps.dll" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\eapsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\efssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ENTERPRISEAPPMGMTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FntCache.dll" is sparse (flags = 32768) File "C:\Windows\System32\es.dll" is sparse (flags = 32768) File "C:\Windows\System32\sdrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\srvsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\xbgmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FDResPub.dll" is sparse (flags = 32768) File "C:\Windows\System32\upnphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\fhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\hidserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\HVHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IKEEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\iphlpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\irmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\keyiso.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdtckrm.dll" is sparse (flags = 32768) File "C:\Windows\System32\lfsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lpasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lmhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ipnathlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\lsm.dll" is sparse (flags = 32768) File "C:\Windows\System32\moshost.dll" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MPSSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\iscsiexe.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsisvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ngcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NcaSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netlogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\trkwks.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\icsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pcasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\p2psvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pla.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\icsvcext.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPSECSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\qwave.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasmans.dll" is sparse (flags = 32768) File "C:\Windows\System32\mprdim.dll" is sparse (flags = 32768) File "C:\Windows\System32\regsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\RDXSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\RMapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\schedsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SCardSvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\seclogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\sensrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SEMgrSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\Sens.dll" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SessEnv.dll" is sparse (flags = 32768) File "C:\Windows\System32\shsvcs.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\smphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\StorSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\sstpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ssdpsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\wiaservc.dll" is sparse (flags = 32768) File "C:\Windows\System32\svsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\swprv.dll" is sparse (flags = 32768) File "C:\Windows\System32\sysmain.dll" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TabSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\termsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\tapisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TOKENBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umrdp.dll" is sparse (flags = 32768) File "C:\Windows\System32\Unistore.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\usermgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\usocore.dll" is sparse (flags = 32768) File "C:\Windows\System32\vaultsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\w32time.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbiosrvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wwansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WUDFSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcncsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdi.dll" is sparse (flags = 32768) File "C:\Windows\System32\WebClnt.dll" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wiarpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WMIsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wuaueng.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Program Files\Windows Mail\WinMail.exe" is sparse (flags = 32768) File "C:\Windows\System32\unregmp2.exe" is sparse (flags = 32768) File "C:\Windows\System32\ie4uinit.exe" is sparse (flags = 32768) Infected: C:\$Recycle.Bin\S-1-5-21-2892662990-3918576701-1327745688-1002\$RVU2D3I.exe --> [Adware.Yelloader] --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.09.4.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 10.0.15063 Windows 10 x64 Account is Administrative Internet Explorer version: 11.296.15063.0 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 3.500000 GHz Memory total: 8588013568, free: 5839446016 ======================================= Initializing... Driver version: 0.3.0.4 ------------ Kernel report ------------ 05/18/2017 19:15:45 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_AuthenticAMD.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\System32\drivers\ksecdd.sys \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\System32\drivers\FLTMGR.SYS \SystemRoot\System32\drivers\clipsp.sys \SystemRoot\System32\drivers\cmimcext.sys \SystemRoot\System32\drivers\ntosext.sys \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\cng.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\SleepStudyHelper.sys \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\system32\drivers\WindowsTrustedRT.sys \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\system32\drivers\ndistpr64.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\system32\drivers\NDIS.SYS \SystemRoot\system32\drivers\TDI.SYS \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\system32\drivers\CEA.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\pciide.sys \SystemRoot\System32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\atapi.sys \SystemRoot\System32\drivers\ataport.SYS \SystemRoot\System32\drivers\storahci.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Wof.sys \SystemRoot\System32\Drivers\NTFS.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\drivers\wfplwfs.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\System32\drivers\volume.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\iorate.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\system32\drivers\filecrypt.sys \SystemRoot\system32\drivers\tbs.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\vmbkmclr.sys \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\drivers\vwififlt.sys \SystemRoot\System32\drivers\pacer.sys \SystemRoot\system32\drivers\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\drivers\gpuenergydrv.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\SysWow64\drivers\AsIO.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys \SystemRoot\System32\drivers\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \SystemRoot\System32\drivers\amdppm.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\portcls.sys \SystemRoot\System32\drivers\drmk.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\rt640x64.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\system32\drivers\ucx01000.sys \SystemRoot\System32\drivers\usbohci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\serial.sys \SystemRoot\System32\drivers\serenum.sys \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\system32\drivers\AtihdWT6.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\system32\DRIVERS\HdAudio.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\kbdhid.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\win32kfull.sys \SystemRoot\System32\win32kbase.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_storahci.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\drivers\dxgmms2.sys \SystemRoot\System32\drivers\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\wcifs.sys \SystemRoot\system32\drivers\storqosflt.sys \SystemRoot\System32\drivers\registry.sys \SystemRoot\system32\drivers\lltdio.sys \SystemRoot\system32\drivers\mslldp.sys \SystemRoot\System32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\rspndr.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\system32\drivers\mmcss.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\System32\drivers\condrv.sys \SystemRoot\system32\drivers\ndisuio.sys \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys ----------- End ----------- Done! Scan started Database versions: main: v2017.05.18.12 rootkit: v2017.04.02.01 <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffa38bbb0e7060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffa38bbaf999f0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffa38bbb0e7060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffffa38bbad76060, DeviceName: \Device\00000027\, DriverName: \Driver\storahci\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... File C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys will be destroyed Infected: C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys --> [Rootkit.Agent.PUA] Done! Drive 0 This is a System drive Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: DD0E7A7A Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 716800 Partition is bootable Partition file system is NTFS Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 718848 Numsec = 1951879168 Partition is not bootable Partition file system is NTFS Partition 2 type is Other (0x27) Partition is NOT ACTIVE. Partition starts at LBA: 1952598016 Numsec = 921600 Partition is not bootable Partition file system is NTFS Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition is not bootable Disk Size: 1000204886016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1953505168-1953525168)... Done! File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\apphelp.dll" is sparse (flags = 32768) File "C:\Windows\AppPatch\AcLayers.dll" is sparse (flags = 32768) File "C:\Windows\System32\msvcrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\user32.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\gdi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ucrtbase.dll" is sparse (flags = 32768) File "C:\Windows\System32\shell32.dll" is sparse (flags = 32768) File "C:\Windows\System32\cfgmgr32.dll" is sparse (flags = 32768) File "C:\Windows\System32\SHCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcrt4.dll" is sparse (flags = 32768) File "C:\Windows\System32\sspicli.dll" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sechost.dll" is sparse (flags = 32768) File "C:\Windows\System32\combase.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STORAGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\advapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\shlwapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\KERNEL.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\powrprof.dll" is sparse (flags = 32768) File "C:\Windows\System32\profapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleaut32.dll" is sparse (flags = 32768) File "C:\Windows\System32\setupapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\mpr.dll" is sparse (flags = 32768) File "C:\Windows\System32\winspool.drv" is sparse (flags = 32768) File "C:\Windows\System32\bcrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\sfc_os.dll" is sparse (flags = 32768) File "C:\Windows\System32\imm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\imagehlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ole32.dll" is sparse (flags = 32768) File "C:\Windows\System32\wintrust.dll" is sparse (flags = 32768) File "C:\Windows\System32\version.dll" is sparse (flags = 32768) File "C:\Windows\System32\msasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\crypt32.dll" is sparse (flags = 32768) File "C:\Windows\System32\psapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wininet.dll" is sparse (flags = 32768) File "C:\Windows\System32\netapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\ws2_32.dll" is sparse (flags = 32768) File "C:\Windows\System32\userenv.dll" is sparse (flags = 32768) File "C:\Windows\System32\netutils.dll" is sparse (flags = 32768) File "C:\Windows\System32\comdlg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winmm.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.0_none_8b4e86125c6fbfec\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINMMBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\rsaenh.dll" is sparse (flags = 32768) File "C:\Windows\System32\uxtheme.dll" is sparse (flags = 32768) File "C:\Windows\System32\msctf.dll" is sparse (flags = 32768) File "C:\Windows\System32\dwmapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkscli.dll" is sparse (flags = 32768) File "C:\Windows\System32\cscapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\iertutil.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPHLPAPI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\winhttp.dll" is sparse (flags = 32768) File "C:\Windows\System32\mswsock.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winnsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\urlmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\msIso.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasadhlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\FWPUCLNT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ntmarta.dll" is sparse (flags = 32768) File "C:\Windows\System32\clbcatq.dll" is sparse (flags = 32768) File "C:\Windows\System32\propsys.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STATEREPOSITORY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\STATEREPOSITORY.CORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\coml2.dll" is sparse (flags = 32768) File "C:\Windows\System32\mssprxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\linkinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntshrui.dll" is sparse (flags = 32768) File "C:\Windows\System32\srvcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERMGRCLI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\wtsapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winsta.dll" is sparse (flags = 32768) File "C:\Windows\System32\smss.exe" is sparse (flags = 32768) File "C:\Windows\System32\csrss.exe" is sparse (flags = 32768) File "C:\Windows\System32\wininit.exe" is sparse (flags = 32768) File "C:\Windows\System32\services.exe" is sparse (flags = 32768) File "C:\Windows\System32\lsass.exe" is sparse (flags = 32768) File "C:\Windows\System32\winlogon.exe" is sparse (flags = 32768) File "C:\Windows\System32\FONTDRVHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\svchost.exe" is sparse (flags = 32768) File "C:\Windows\System32\dwm.exe" is sparse (flags = 32768) File "C:\Windows\System32\spoolsv.exe" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\msimg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\mfc42.dll" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\dataup\dataup.exe --> [Adware.Yelloader] Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Dataup --> [Adware.Yelloader] File "C:\Windows\System32\sxs.dll" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dasHost.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Media Player\wmpnetwk.exe" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiPrvSE.exe" is sparse (flags = 32768) File "C:\Windows\System32\sihost.exe" is sparse (flags = 32768) File "C:\Windows\explorer.exe" is sparse (flags = 32768) File "C:\Windows\System32\TASKHOSTW.EXE" is sparse (flags = 32768) Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] Infected: c:\windows\system32\tprdpw32.exe --> [Rootkit.Agent.PUA] File "C:\Windows\System32\Wldap32.dll" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\System32\RUNTIMEBROKER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dllhost.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MSASCuiL.exe" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\wsock32.dll" is sparse (flags = 32768) File "C:\Windows\System32\xmllite.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.15063.0_none_d802f55807fa1ec7\GdiPlus.dll" is sparse (flags = 32768) File "C:\Windows\System32\wer.dll" is sparse (flags = 32768) File "C:\Windows\System32\cabinet.dll" is sparse (flags = 32768) File "C:\Windows\System32\Faultrep.dll" is sparse (flags = 32768) File "C:\Windows\System32\secur32.dll" is sparse (flags = 32768) File "C:\Windows\System32\loadperf.dll" is sparse (flags = 32768) File "C:\Windows\System32\pdh.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbghelp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ncrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbgcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\mlang.dll" is sparse (flags = 32768) File "C:\Windows\System32\msxml6.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\taskschd.dll" is sparse (flags = 32768) File "C:\Windows\System32\TWINAPI.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\Wpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidprov.dll" is sparse (flags = 32768) File "C:\Windows\System32\samcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\NapiNSP.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpnsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlaapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winrnr.dll" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\opengl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\glu32.dll" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dcomp.dll" is sparse (flags = 32768) File "C:\Windows\System32\d3d11.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxgi.dll" is sparse (flags = 32768) File "C:\Windows\System32\DWrite.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlanapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\dinput8.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\wbemprox.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbemcomn.dll" is sparse (flags = 32768) File "C:\Windows\System32\hid.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\wbemsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\devobj.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\fastprox.dll" is sparse (flags = 32768) File "C:\Windows\System32\MMDevAPI.dll" is sparse (flags = 32768) File "C:\Windows\System32\XINPUT1_4.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XINPUT1_4.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wdmaud.drv" is sparse (flags = 32768) File "C:\Windows\System32\avrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\ksuser.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\msacm32.drv" is sparse (flags = 32768) File "C:\Windows\System32\msacm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\midimap.dll" is sparse (flags = 32768) File "C:\Windows\System32\dsound.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.UI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.UI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\gpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptnet.dll" is sparse (flags = 32768) File "C:\Windows\System32\webio.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONECOREUAPCOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONECOREUAPCOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPRESOLVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\slc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ELSCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\MrmCoreR.dll" is sparse (flags = 32768) File "C:\Windows\System32\BCP47LANGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sppc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONECORECOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONECORECOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\POLICYMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP110_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\oleacc.dll" is sparse (flags = 32768) File "C:\Windows\System32\usp10.dll" is sparse (flags = 32768) File "C:\Windows\System32\mscms.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETWORKEXPLORER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETWORKEXPLORER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\msi.dll" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe --> [Adware.Yelloader] Infected: HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|svcvmx --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe --> [Adware.Yelloader] File "C:\Windows\System32\dpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\d3d9.dll" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe --> [Adware.Yelloader] File "C:\Windows\System32\DIRECTMANIPULATION.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DIRECTMANIPULATION.DLL" is sparse (flags = 32768) File "C:\Windows\System32\devenum.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdmo.dll" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ctfmon.exe" is sparse (flags = 32768) File "C:\Windows\System32\MSCTFMONITOR.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSCTFMONITOR.DLL" is sparse (flags = 32768) File "C:\Windows\System32\msutb.dll" is sparse (flags = 32768) File "C:\Windows\System32\mmc.exe" is sparse (flags = 32768) File "C:\Windows\System32\credui.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptui.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxva2.dll" is sparse (flags = 32768) File "C:\Windows\System32\fontsub.dll" is sparse (flags = 32768) File "C:\Windows\System32\fontsub.dll" is sparse (flags = 32768) File "C:\Windows\System32\SETTINGSYNCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\servicing\TRUSTEDINSTALLER.EXE" is sparse (flags = 32768) File "C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.15063.0_none_1a733a82001933cc\TiWorker.exe" is sparse (flags = 32768) File "C:\Windows\System32\cmd.exe" is sparse (flags = 32768) File "C:\Windows\System32\conhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\System32\credssp.dll" is sparse (flags = 32768) File "C:\Windows\System32\userinit.exe" is sparse (flags = 32768) File "C:\Windows\System32\scecli.dll" is sparse (flags = 32768) File "C:\Windows\System32\msv1_0.dll" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\appid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspclock.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpiex.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\Locator.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mpsdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\afd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ahcache.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\asyncmac.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv.sys" is sparse (flags = 32768) File "C:\Windows\System32\alg.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcifs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcnfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\luafv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bowser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cng.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\clfs.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cldflt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\registry.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mup.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\condrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dam.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dfsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dxgkrnl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpip.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORCLASS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPATIALGRAPHFILTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fileinfo.sys" is sparse (flags = 32768) File "C:\Windows\System32\FXSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipfltdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fltMgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PRESENTATIONFONTCACHE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fvevol.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndisuio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFRd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wanarp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbengine.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\http.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hwpolicy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pacer.sys" is sparse (flags = 32768) File "C:\Windows\SysWOW64\perfhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\iorate.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\scfilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdFilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irda.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecdd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecpkg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksthunk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\lltdio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwififlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mstee.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mmcss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mskssrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MsMpEng.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wimmount.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxdav.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\modem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspqm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mountmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasl2tp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb10.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb20.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ucx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ufx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bridge.sys" is sparse (flags = 32768) File "C:\Windows\System32\msdtc.exe" is sparse (flags = 32768) File "C:\Windows\System32\VSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\msiexec.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mslldp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nwifi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndis.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiscap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndistapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiswan.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ndu.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwifibus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nsiproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdiWiFi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\vds.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\partmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcw.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\PEAuth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\RDPVIDEOMINIPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\qwavedrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspptp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasacd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\agilevpn.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspppoe.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rassstp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdbss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpdr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdyboost.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rspndr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SpbCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\snmptrap.exe" is sparse (flags = 32768) File "C:\Windows\System32\Spectrum.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Wdf01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\sppsvc.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srvnet.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgrx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpipreg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tdx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\terminpt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbFlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UcmCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Udecx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\udfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBXHCI.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhf.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volsnap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdBoot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdNisDrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\NisSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wfplwfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiApSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ws2ifsl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFPf.sys" is sparse (flags = 32768) File "C:\Windows\System32\AJRouter.dll" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umpnpmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcss.dll" is sparse (flags = 32768) File "C:\Windows\System32\appinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\appidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\AxInstSv.dll" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\AUDIOENDPOINTBUILDER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\audiosrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\RpcEpMap.dll" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bdesvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\BFE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netman.dll" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cdpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\umpo.dll" is sparse (flags = 32768) File "C:\Windows\System32\qmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\ListSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lltdsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\browser.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\profsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bthserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\provsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\das.dll" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\certprop.dll" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ClipSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wscsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WsmSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wersvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wecsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dot3svc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dusmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\fdPHost.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsrslvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\dps.dll" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\eapsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\efssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ENTERPRISEAPPMGMTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FntCache.dll" is sparse (flags = 32768) File "C:\Windows\System32\es.dll" is sparse (flags = 32768) File "C:\Windows\System32\sdrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\srvsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\xbgmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FDResPub.dll" is sparse (flags = 32768) File "C:\Windows\System32\upnphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\fhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\hidserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\HVHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IKEEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\iphlpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\irmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\keyiso.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdtckrm.dll" is sparse (flags = 32768) File "C:\Windows\System32\lfsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lpasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lmhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ipnathlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\lsm.dll" is sparse (flags = 32768) File "C:\Windows\System32\moshost.dll" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MPSSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\iscsiexe.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsisvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ngcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NcaSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netlogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\trkwks.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\icsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pcasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\p2psvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pla.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\icsvcext.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPSECSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\qwave.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasmans.dll" is sparse (flags = 32768) File "C:\Windows\System32\mprdim.dll" is sparse (flags = 32768) File "C:\Windows\System32\regsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\RDXSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\RMapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\schedsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SCardSvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\seclogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\sensrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SEMgrSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\Sens.dll" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SessEnv.dll" is sparse (flags = 32768) File "C:\Windows\System32\shsvcs.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\smphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\StorSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\sstpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ssdpsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\wiaservc.dll" is sparse (flags = 32768) File "C:\Windows\System32\svsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\swprv.dll" is sparse (flags = 32768) File "C:\Windows\System32\sysmain.dll" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TabSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\termsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\tapisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TOKENBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umrdp.dll" is sparse (flags = 32768) File "C:\Windows\System32\Unistore.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\usermgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\usocore.dll" is sparse (flags = 32768) File "C:\Windows\System32\vaultsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\w32time.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbiosrvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wwansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WUDFSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcncsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdi.dll" is sparse (flags = 32768) File "C:\Windows\System32\WebClnt.dll" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wiarpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WMIsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wuaueng.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Program Files\Windows Mail\WinMail.exe" is sparse (flags = 32768) File "C:\Windows\System32\unregmp2.exe" is sparse (flags = 32768) File "C:\Windows\System32\ie4uinit.exe" is sparse (flags = 32768) Infected: C:\$Recycle.Bin\S-1-5-21-2892662990-3918576701-1327745688-1002\$RVU2D3I.exe --> [Adware.Yelloader] File "C:\Users\steff\AppData\Local\Comms\UnistoreDB\store.vol" is sparse (flags = 32768) Infected: C:\Users\steff\AppData\Local\tnifv\qdcomsvc.exe --> [Adware.Yelloader] Infected: C:\Users\steff\AppData\Local\uhiba\ct.exe --> [Adware.Yelloader] File "C:\Windows\System32\config\systemprofile\AppData\Local\DataSharing\Storage\DSTokenDB2.dat" is sparse (flags = 32768) Infected: HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|cpx --> [Trojan.Clicker] Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\drmkpro64 --> [Rootkit.Agent.PUA] Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\DATAUP|ImagePath --> [Trojan.Clicker] Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\Dataup --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000165 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Cookies --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Cookies-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\data_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\data_1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\data_2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\data_3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\data_4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000001 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000002 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000003 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000004 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000005 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000006 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000007 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000008 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000009 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00000a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00000b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00000c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00000e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00000f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000010 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000011 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000012 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000013 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000014 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000015 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000016 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000017 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000018 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000019 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00001a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00001b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00001c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00001d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00001e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00001f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000020 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000022 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000023 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000024 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000025 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000026 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000027 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000028 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000029 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00002a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00002b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00002c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00002d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00002e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00002f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000030 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000031 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000032 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000033 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000034 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000036 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000037 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000038 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000039 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00003a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00003b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00003c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00003d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00003e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00003f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000040 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000041 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000042 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000043 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000044 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000045 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000046 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000047 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000048 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00004a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00004b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00004c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00004d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00004e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000050 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000051 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000052 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000053 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000054 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000055 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000056 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000057 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000058 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000059 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00005a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00005b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00005c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00005e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00005f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000060 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000061 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000062 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000063 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000064 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000065 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000066 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000067 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000068 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000069 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00006a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00006b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00006c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00006d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00006e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00006f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000070 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00000d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000021 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000035 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000049 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00005d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000071 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000085 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000099 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000ad --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000c2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000d6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000ea --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000100 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000114 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000128 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00013d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000151 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000072 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000073 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000074 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000075 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000076 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000077 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000078 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000079 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00007a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00007b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00007c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00007d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00007e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00007f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000080 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000081 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000082 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000083 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000084 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000086 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000087 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000088 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000089 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00008a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00008b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00008c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00008d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00008e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00008f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000090 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000091 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000092 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000093 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000094 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000095 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000096 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000097 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000098 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00009a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00009b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00009c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00009d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00009e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00009f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000a0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000a1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000a2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000a3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000a4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000a5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000a6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000a7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000a8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000a9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000aa --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000ab --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000ac --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000ae --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000af --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000b1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000b2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000b3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000b4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000b5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000b6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000b7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000b8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000b9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000ba --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000bb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000bc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000bd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000be --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000bf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000c0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000c1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000c3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000c4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000c5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000c6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000c7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000c8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000c9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000ca --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000cb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000cc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000cd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000ce --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000cf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000d0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000d1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000d2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000d3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000d4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000d5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000d7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000d8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000d9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000da --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000db --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000dc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000dd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000de --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000df --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000e0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000e1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000e2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000e3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000e4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000e5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000e6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000e7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000e8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000e9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000ec --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000ed --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000ee --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000ef --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000f0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000f1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000f2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000f4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000f5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000f6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000f7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000f8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000f9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000fa --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000fb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000fc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000fd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000fe --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0000ff --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000101 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000102 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000103 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000104 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000105 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000106 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000107 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000108 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000109 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00010a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00010b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00010c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00010d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00010e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00010f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000111 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000112 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000113 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000115 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000116 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000117 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000118 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000119 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00011a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00011b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00011c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00011d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00011e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00011f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000120 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000121 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000122 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000123 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000124 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000125 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000126 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000127 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000129 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00012a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00012c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00012d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00012e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00012f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000130 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000131 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000132 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000133 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000134 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000135 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000136 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000137 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000138 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000139 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00013a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00013b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00013c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00013e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00013f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000140 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000141 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000142 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000143 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000144 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000145 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000146 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000147 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000148 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000149 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00014a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00014b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00014c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00014d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00014e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00014f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000150 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000152 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000153 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000154 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000155 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000156 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000157 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000158 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000159 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00015a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00015b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00015c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00015d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00015e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00015f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000160 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000161 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000162 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000163 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000164 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000166 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000167 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000168 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000169 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00016a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00016b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00016d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00016e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00016f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000170 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000171 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000172 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000173 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000174 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000175 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000176 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000177 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000178 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00017a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00017b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00017c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00017d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00017e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00017f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000180 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000181 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000182 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000183 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000184 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000185 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000186 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000187 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000189 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00018a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00018b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00018c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00018e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00018f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000190 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000191 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000192 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000193 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000194 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000195 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000196 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000197 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000198 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000199 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00019b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00019c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00019d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00019e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00019f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001a0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001a1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001a3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001a4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001a5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001a6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001a7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001a8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001a9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001aa --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001ab --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001ac --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001ad --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001ae --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001af --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001b0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001b1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001b2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001b3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001b4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001b5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001b7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001b8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001b9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001ba --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001bb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001bc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001bd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001be --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001bf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001c0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001c1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001c2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001c3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001c4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001c5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001c6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001c7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001c8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001c9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001cb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001cc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001cd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001ce --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001cf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001d0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001d1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001d2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001d3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001d4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001d5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001d6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001d7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001d8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001d9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001da --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001db --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001dc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001dd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001df --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001e0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001e1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001e2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001e3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001e4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001e5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001e6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001e7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001e8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001e9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001ea --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001eb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001ec --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001ed --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001ee --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001ef --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001f0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001f1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001f3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001f4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001f5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001f6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001f7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001f8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001f9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001fa --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001fb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001fc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001fd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001fe --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001ff --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000200 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000201 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000202 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000203 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000204 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000205 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000207 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000208 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000209 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00020a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00020b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00020c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00020d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00020f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000210 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000211 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000212 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000213 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000214 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000215 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000216 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000217 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000218 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000219 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00021a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00021c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00021d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00021e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00021f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000220 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000221 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000222 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000223 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000224 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000225 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000226 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000227 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000228 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000229 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00022a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00022b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00022c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00022d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00022e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000230 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000231 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000232 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000233 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000234 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000235 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000236 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000237 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000238 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000239 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00023a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00023b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00023d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00023e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00023f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000240 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000241 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000242 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000243 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000245 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000246 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000247 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000248 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000249 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00024a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00024b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00024c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00024d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00024e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000250 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000251 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000252 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000253 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000254 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000255 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000256 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000257 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000258 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00025a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00025b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00025c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00025d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00025e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00025f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000260 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000261 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000262 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000263 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000264 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000265 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000266 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000267 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000269 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00026a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00026b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00026c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00026d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00026f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000270 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000271 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000272 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000273 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000274 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000275 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000276 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000277 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000278 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000279 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00027a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00027b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00027c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00027d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00027e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00027f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000280 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000281 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000283 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000285 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000286 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000287 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000288 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000289 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00028a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00028b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00028c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00028d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00028e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00028f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000290 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000291 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000292 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000293 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000294 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000295 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000297 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000298 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000299 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00029a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00029b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00029c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00029d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00029e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00029f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002a0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002a1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002a2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002a3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002a4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002a5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002a6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002a7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002a8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002a9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002ab --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002ac --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002ad --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002ae --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002af --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002b0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002b1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002b2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002b3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002b4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002b5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002b6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002b7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002b8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002b9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002ba --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002bb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002bc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002bd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002bf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002c0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002c1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002c2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002c3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002c4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002c5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002c6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002c7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002c8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002c9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002ca --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002cb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002cc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002cd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002ce --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002cf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002d0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002d1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002d3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002d4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002d5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002d6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002d7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002d8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002da --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002db --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002dc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002dd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002de --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002df --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002e0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002e1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002e3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002e4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002e5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002e6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002e7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000179 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00018d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001a2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001b6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001ca --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001de --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0001f2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000206 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00021b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00022f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000244 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000259 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00026e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000282 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000296 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002aa --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002be --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002d2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002e8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002fd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000311 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000325 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000339 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00034d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002e9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002ea --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002eb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002ec --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002ed --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002ee --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002ef --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002f0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002f1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002f2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002f3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002f4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002f5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002f6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002f7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002f8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002fa --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002fb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002fc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002fe --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_0002ff --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000300 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000301 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000302 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000303 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000304 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000305 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000306 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000307 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000308 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000309 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00030a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00030b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00030c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00030d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00030e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00030f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000310 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000312 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000313 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000314 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000315 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000316 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000317 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000318 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000319 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00031a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00031b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00031c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00031d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00031e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00031f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000320 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000321 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000322 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000323 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000324 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000326 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000327 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000328 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000329 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00032a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00032b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00032c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00032d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00032e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00032f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000330 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000331 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000332 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000333 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000334 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000335 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000336 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000337 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000338 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00033a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00033b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00033c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00033d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00033e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00033f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000340 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000341 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000342 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000343 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000344 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000345 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000346 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000347 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000348 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000349 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00034a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00034b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00034c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00034e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00034f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000350 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000351 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000352 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000353 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000354 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000355 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000356 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000357 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000358 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_000359 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00035a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00035b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00035c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00035d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\f_00035e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\index --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\QuotaManager --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\QuotaManager-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Visited Links --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\databases --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\databases\Databases.db --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\databases\Databases.db-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\GPUCache --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\GPUCache\data_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\GPUCache\data_1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\GPUCache\data_2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\GPUCache\data_3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\GPUCache\index --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\IndexedDB --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\IndexedDB\http_thedailymeal.com_0.indexeddb.leveldb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\IndexedDB\http_thedailymeal.com_0.indexeddb.leveldb\000003.log --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\IndexedDB\http_thedailymeal.com_0.indexeddb.leveldb\CURRENT --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\IndexedDB\http_thedailymeal.com_0.indexeddb.leveldb\LOCK --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\IndexedDB\http_thedailymeal.com_0.indexeddb.leveldb\LOG --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\IndexedDB\http_thedailymeal.com_0.indexeddb.leveldb\MANIFEST-000001 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\https_www.hayneedle.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_nordic.businessinsider.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\https_assets.bounceexchange.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\https_assets.bounceexchange.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\https_ec-ns.sascdn.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\https_ec-ns.sascdn.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\https_www.hayneedle.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_nordic.businessinsider.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_thedailymeal.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_thedailymeal.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_widgets.outbrain.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_widgets.outbrain.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_www.bhg.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_www.bhg.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_www.brides.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_www.brides.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_www.businessinsider.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_www.businessinsider.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_www.cbssports.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_www.cbssports.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_www.foodnetwork.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_www.foodnetwork.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_davedameshek.nfl.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Local Storage\http_davedameshek.nfl.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache\FWQL6KHG --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\anyclip-inread.s3.amazonaws.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\anyclip-inread.s3.amazonaws.com\analytics.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\anyclip-inread.s3.amazonaws.com\#com.junkbyte --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\anyclip-inread.s3.amazonaws.com\#com.junkbyte\Console --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\anyclip-inread.s3.amazonaws.com\ac# --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\cdn.stickyadstv.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\eereader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\efreader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\efreader.com\analytics.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\egreader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com\##1578D57EFAC6D57F --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com\##1578D57EFAC6D57F\00000001.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com\support --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com\support\flashplayer --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com\support\flashplayer\sys --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com\support\flashplayer\sys\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com\support\flashplayer\sys\#cdn.stickyadstv.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com\support\flashplayer\sys\#cdn.stickyadstv.com\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com\support\flashplayer\sys\#eereader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com\support\flashplayer\sys\#eereader.com\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com\support\flashplayer\sys\#efreader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com\support\flashplayer\sys\#efreader.com\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com\support\flashplayer\sys\#egreader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data615\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2PGPKC9G\macromedia.com\support\flashplayer\sys\#egreader.com\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000165 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Cookies --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Cookies-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\data_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\data_1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\data_2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\data_3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000001 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000002 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000003 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000004 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000005 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000006 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000007 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000008 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000009 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00000a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00000b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00000c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00000e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00000f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000010 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000011 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000012 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000013 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000014 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000015 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000016 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000017 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000018 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000019 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00001a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00001b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00001c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00001d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00001e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00001f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000020 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000022 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000023 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000024 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000025 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000026 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000027 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000028 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00002a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00002b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00002d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00002e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00002f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000030 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000031 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000032 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000033 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000034 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000035 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000036 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000038 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000039 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00003a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00003b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00003c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00003d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00003e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00003f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000040 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000041 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000042 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000043 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000044 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000045 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000046 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000047 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000048 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000049 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00004a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00004d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00004e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00004f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000050 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000052 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000053 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000054 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000055 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000056 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000057 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000058 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000059 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00005a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00005b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00005c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00005d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00005e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00005f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000061 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000062 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000063 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000064 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000065 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000066 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000067 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000068 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000069 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00006a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00006b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00006c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00006d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00006e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00006f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000070 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000071 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000072 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000073 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00000d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000021 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000037 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00004b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000060 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000074 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000088 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00009c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000b0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000c4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000d8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000ec --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000100 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000114 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000128 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00013c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000151 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000179 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00018e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001a2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001b6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001cb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001df --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001f3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000208 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00021d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000231 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000246 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00025a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00026e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000282 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000296 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002aa --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002be --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000075 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000076 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000077 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000078 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000079 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00007a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00007b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00007c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00007d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00007e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00007f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000080 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000081 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000082 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000083 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000084 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000085 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000086 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000087 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000089 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00008a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00008b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00008c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00008d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00008e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00008f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000090 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000091 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000092 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000093 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000094 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000095 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000096 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000097 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000098 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000099 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00009b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00009d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00009e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00009f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000a0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000a1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000a2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000a3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000a4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000a5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000a6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000a7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000a8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000a9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000aa --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000ab --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000ac --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000ad --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000ae --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000af --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000b1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000b2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000b3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000b4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000b5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000b6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000b7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000b8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000b9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000ba --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000bb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000bc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000bd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000be --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000bf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000c0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000c1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000c2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000c3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000c5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000c6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000c7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000c8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000c9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000ca --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000cb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000cc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000cd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000ce --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000cf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000d0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000d1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000d2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000d3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000d4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000d5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000d6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000d7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000d9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000da --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000db --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000dc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000dd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000de --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000df --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000e0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000e1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000e2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000e3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000e4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000e5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000e6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000e7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000e8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000e9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000ea --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000eb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000ed --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000ee --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000ef --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000f0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000f1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000f2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000f3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000f4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000f5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000f6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000f7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000f8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000f9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000fa --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000fb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000fc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000fd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000fe --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0000ff --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000101 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000102 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000103 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000104 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000105 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000106 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000107 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000108 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000109 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00010a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00010b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00010c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00010d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00010e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00010f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000110 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000111 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000112 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000113 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000115 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000116 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000117 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000118 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000119 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00011a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00011b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00011c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00011d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00011e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00011f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000120 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000121 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000122 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000123 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000124 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000125 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000126 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000127 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000129 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00012a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00012b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00012c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00012d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00012e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00012f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000130 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000131 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000132 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000133 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000134 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000135 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000136 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000137 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000138 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000139 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00013a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00013b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00013d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00013e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00013f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000140 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000141 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000142 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000143 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000144 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000145 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000146 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000147 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000148 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000149 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00014a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00014b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00014d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00014e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00014f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000150 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000152 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000153 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000154 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000155 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000156 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000157 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000158 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000159 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00015a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00015b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00015c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00015d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00015e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00015f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000160 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000161 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000162 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000163 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000164 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000166 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000167 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000168 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000169 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00016a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00016b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00016c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00016d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00016e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00016f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000170 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000171 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000172 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000173 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000174 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000175 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000176 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000177 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000178 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00017a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00017b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00017c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00017d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00017e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00017f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000180 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000181 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000182 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000183 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000185 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000186 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000187 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000188 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000189 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00018a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00018b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00018c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00018d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00018f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000190 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000191 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000192 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000193 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000194 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000195 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000196 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000197 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000198 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000199 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00019a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00019b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00019c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00019d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00019e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00019f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001a0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001a1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001a3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001a4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001a5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001a6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001a7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001a8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001a9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001aa --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001ab --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001ac --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001ad --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001ae --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001af --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001b0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001b1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001b2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001b3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001b4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001b5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001b7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001b8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001b9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001ba --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001bb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001bc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001bd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001be --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001bf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001c0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001c1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001c2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001c3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001c5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001c6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001c7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001c8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001c9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001ca --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001cc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001cd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001ce --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001cf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001d0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001d1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001d2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001d3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001d4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001d5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001d6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001d7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001d8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001d9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001da --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001db --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001dc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001dd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001de --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001e0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001e1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001e2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001e3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001e4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001e5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001e6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001e7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001e8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001e9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001ea --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001eb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001ec --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001ed --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001ee --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001ef --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001f0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001f1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001f2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001f4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001f5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001f6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001f7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001f8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001f9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001fa --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001fc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001fd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001fe --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0001ff --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000200 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000201 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000202 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000203 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000204 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000205 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000206 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000207 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000209 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00020a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00020b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00020c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00020d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00020e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00020f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000210 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000211 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000212 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000213 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000214 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000215 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000216 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000217 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000218 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000219 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00021b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00021c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00021e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00021f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000220 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000221 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000222 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000223 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000224 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000225 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000226 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000227 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000228 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000229 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00022a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00022b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00022c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00022d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00022e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00022f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000230 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000232 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000233 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000234 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000235 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000236 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000237 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000238 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000239 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00023a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00023b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00023c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00023d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00023e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00023f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000240 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000241 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000242 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000244 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000245 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000247 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000248 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000249 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00024a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00024b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00024c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00024d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00024e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00024f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000250 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000251 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000252 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000253 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000254 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000255 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000256 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000257 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000258 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000259 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00025b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00025c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00025d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00025e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00025f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000260 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000261 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000262 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000263 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000264 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000265 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000266 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000267 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000268 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000269 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00026a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00026b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00026c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00026d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00026f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000270 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000271 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000272 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000273 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000274 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000275 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000276 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000277 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000278 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000279 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00027a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00027b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00027c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00027d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00027e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00027f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000280 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000281 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000283 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000284 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000285 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000286 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000287 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000288 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000289 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00028a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00028b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00028c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00028d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00028e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00028f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000290 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000291 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000292 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000293 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000294 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000295 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000297 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000298 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_000299 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00029a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00029b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00029c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00029d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00029e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_00029f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002a0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002a1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002a2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002a3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002a4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002a5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002a6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002a7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002a8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002a9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002ab --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002ac --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002ad --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002ae --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002af --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002b0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002b1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002b2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002b3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002b4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002b5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002b6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002b7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002b8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002b9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002ba --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002bb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002bc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002bd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002bf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002c0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002c1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002c2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002c3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002c4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002c5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002c6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002c7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\f_0002c8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\index --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\QuotaManager --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\QuotaManager-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Visited Links --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\databases --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\databases\Databases.db --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\databases\Databases.db-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\File System --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\File System\Origins --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\File System\Origins\000003.log --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\File System\Origins\CURRENT --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\File System\Origins\LOCK --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\File System\Origins\LOG --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\File System\Origins\LOG.old --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\File System\Origins\MANIFEST-000001 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\File System\Origins\lost --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\GPUCache --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\GPUCache\data_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\GPUCache\data_1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\GPUCache\data_2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\GPUCache\data_3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\GPUCache\index --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\IndexedDB --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\IndexedDB\http_www.bhg.com_0.indexeddb.leveldb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\IndexedDB\http_www.cbssports.com_0.indexeddb.leveldb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\IndexedDB\http_www.cbssports.com_0.indexeddb.leveldb\000003.log --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\IndexedDB\http_www.cbssports.com_0.indexeddb.leveldb\CURRENT --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\IndexedDB\http_www.cbssports.com_0.indexeddb.leveldb\LOCK --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\IndexedDB\http_www.cbssports.com_0.indexeddb.leveldb\LOG --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\IndexedDB\http_www.cbssports.com_0.indexeddb.leveldb\MANIFEST-000001 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage\http_nordic.businessinsider.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage\https_connexity.net_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage\https_connexity.net_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage\https_www.baublebar.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage\https_www.baublebar.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage\http_connexity.net_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage\http_connexity.net_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage\http_nordic.businessinsider.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage\http_www.cbssports.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage\http_www.cbssports.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage\http_www.cleveland.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage\http_www.cleveland.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage\http_www.thedailymeal.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Local Storage\http_www.thedailymeal.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash --> [Trojan.Clicker.D] Infected: c:\users\steff\appdata\local\llssoft\winvmx\data620\pepper data\shockwave flash\ba65.tmp --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache\SVA6WKF4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\cdn.stickyadstv.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\eereader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\efreader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\efreader.com\analytics.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\egreader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\egreader.com\analytics.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\macromedia.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\macromedia.com\support --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\macromedia.com\support\flashplayer --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\macromedia.com\support\flashplayer\sys --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\macromedia.com\support\flashplayer\sys\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\macromedia.com\support\flashplayer\sys\#cdn.stickyadstv.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\macromedia.com\support\flashplayer\sys\#cdn.stickyadstv.com\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\macromedia.com\support\flashplayer\sys\#eereader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\macromedia.com\support\flashplayer\sys\#eereader.com\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\macromedia.com\support\flashplayer\sys\#efreader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\macromedia.com\support\flashplayer\sys\#efreader.com\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\macromedia.com\support\flashplayer\sys\#egreader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\S4P9JFG6\macromedia.com\support\flashplayer\sys\#egreader.com\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\index.txt --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\144fdc892a97841f_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\3923af569b95a3c6_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\44e589ca97cf69be_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\46f556466553775b_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\51f05b2604265081_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\558e37ddc568293c_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\55c5f5dd17c01bf1_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\5ec33bf0416553fa_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\65ded0d84e1bd09b_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\65fec101408cdb96_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\6b36556450681407_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\72a41e260e5376dd_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\73563decb6a35f91_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\752c1e258c3ea6a4_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\a3e06d46d263bad8_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\b2f24be3c0bcce07_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\b3ebdfe43ee98270_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\cdc73a73fdc0d3ff_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\d671d06f365a0733_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\da5ff4d792841963_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\e0bfeb5252e99f2f_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\e60001417621e601_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\index --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\index-dir --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data620\Service Worker\CacheStorage\a7bd85f230905f977f12b33025deac9e59c97c45\74F7BEC5-4633-4EDC-A4E5-0C70D6F7140C\index-dir\the-real-index --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Cookies --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Cookies-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\data_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\data_1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\data_2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\data_3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000001 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000003 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000004 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000005 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000006 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000007 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000008 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000009 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00000a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00000b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00000c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00000e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00000f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000010 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000011 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000012 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000013 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000014 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000015 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000016 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000017 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000018 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000019 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00001a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00001b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00001c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00001d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00001e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00001f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000020 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000022 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000023 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000024 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000025 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000026 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000027 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000028 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000029 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00002a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00002b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00002c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00002d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00002e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00002f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000030 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000031 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000032 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000033 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000034 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000036 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000037 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000038 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000039 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00003a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00003b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00003c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00003d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00003e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00003f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000040 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000041 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000042 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000043 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000044 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000045 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000046 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000047 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000048 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00004a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00004b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00004c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00004d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00004e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00004f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000050 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000051 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000052 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000053 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000054 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000055 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000056 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000057 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000058 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00005a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00005b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00005c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00005e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00005f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000060 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000061 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000062 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000063 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000064 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000065 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000066 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000067 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000068 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000069 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00006a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00006b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00006c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00006d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00006e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00006f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000070 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00000d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000021 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000035 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000049 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00005d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000071 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000085 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000099 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000ad --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000c1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000d5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000e9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000fd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000111 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000125 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000139 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00014d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000161 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000176 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00018a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00019e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001b3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001c8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000072 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000073 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000074 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000075 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000076 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000077 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000078 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000079 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00007a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00007b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00007c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00007d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00007f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000080 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000081 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000082 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000083 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000084 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000086 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000087 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000088 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000089 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00008a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00008b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00008c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00008d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00008e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00008f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000090 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000091 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000092 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000093 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000094 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000095 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000096 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000097 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000098 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00009a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00009b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00009c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00009d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00009e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00009f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000a0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000a1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000a2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000a3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000a4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000a5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000a6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000a7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000a8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000a9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000aa --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000ab --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000ac --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000ae --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000af --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000b0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000b1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000b2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000b3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000b4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000b5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000b6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000b7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000b8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000b9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000ba --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000bb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000bc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000bd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000be --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000bf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000c0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000c2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000c3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000c4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000c5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000c6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000c7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000c8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000c9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000ca --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000cb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000cc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000cd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000ce --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000cf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000d0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000d1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000d2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000d3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000d4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000d6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000d7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000d8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000d9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000da --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000db --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000dc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000dd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000de --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000df --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000e0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000e1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000e2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000e3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000e4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000e5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000e6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000e7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000e8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000ea --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000eb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000ec --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000ed --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000ee --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000ef --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000f0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000f1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000f2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000f3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000f4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000f5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000f6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000f7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000f8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000f9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000fa --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000fb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000fc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000fe --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0000ff --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000100 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000101 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000102 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000104 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000105 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000106 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000107 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000108 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000109 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00010a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00010b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00010c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00010d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00010e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00010f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000110 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000112 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000113 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000114 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000115 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000116 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000117 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000118 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000119 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00011a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00011b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00011c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00011d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00011e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00011f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000120 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000121 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000122 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000123 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000124 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000126 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000127 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000128 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000129 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00012a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00012b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00012c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00012d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00012e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00012f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000130 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000131 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000132 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000133 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000134 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000135 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000136 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000137 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000138 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00013a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00013b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00013c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00013d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00013e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00013f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000140 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000141 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000142 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000143 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000144 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000145 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000146 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000147 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000148 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000149 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00014a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00014b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00014c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00014e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00014f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000150 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000151 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000152 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000153 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000154 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000155 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000156 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000157 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000158 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00015a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00015b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00015c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00015d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00015e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00015f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000160 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000162 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000163 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000164 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000165 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000166 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000167 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000168 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000169 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00016a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00016b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00016c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00016d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00016e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00016f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000170 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000171 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000172 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000174 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000175 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000177 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000178 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000179 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00017a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00017b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00017c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00017d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00017e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00017f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000180 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000181 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000182 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000183 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000184 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000185 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000186 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000187 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000188 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000189 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00018b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00018c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00018d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00018e --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00018f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000190 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000191 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000192 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000193 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000194 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000195 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000196 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000197 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000198 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_000199 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00019a --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00019b --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00019c --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00019d --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_00019f --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001a0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001a1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001a2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001a3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001a4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001a5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001a6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001a7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001a9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001aa --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001ab --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001ac --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001ad --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001ae --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001af --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001b0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001b1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001b2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001b4 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001b5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001b6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001b7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001b8 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001b9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001ba --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001bb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001bc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001bd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001be --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001bf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001c0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001c1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001c2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001c3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001c5 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001c6 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001c7 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001c9 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001ca --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001cb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001cc --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001cd --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001ce --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001cf --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001d0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\f_0001d1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\index --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\QuotaManager --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\QuotaManager-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Visited Links --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\databases --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\databases\Databases.db --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\databases\Databases.db-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\000 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\000\t --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\000\t\.usage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\000\t\Paths --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\000\t\Paths\000003.log --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\000\t\Paths\CURRENT --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\000\t\Paths\LOCK --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\000\t\Paths\LOG --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\000\t\Paths\MANIFEST-000001 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\Origins --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\Origins\000003.log --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\Origins\CURRENT --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\Origins\LOCK --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\Origins\LOG --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\Origins\LOG.old --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\File System\Origins\MANIFEST-000001 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\GPUCache --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\GPUCache\data_0 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\GPUCache\data_1 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\GPUCache\data_2 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\GPUCache\data_3 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\GPUCache\index --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\IndexedDB --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\IndexedDB\http_nanatsu-no-taizai.wikia.com_0.indexeddb.leveldb --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\IndexedDB\http_nanatsu-no-taizai.wikia.com_0.indexeddb.leveldb\000003.log --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\IndexedDB\http_nanatsu-no-taizai.wikia.com_0.indexeddb.leveldb\CURRENT --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\IndexedDB\http_nanatsu-no-taizai.wikia.com_0.indexeddb.leveldb\LOCK --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\IndexedDB\http_nanatsu-no-taizai.wikia.com_0.indexeddb.leveldb\LOG --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\IndexedDB\http_nanatsu-no-taizai.wikia.com_0.indexeddb.leveldb\MANIFEST-000001 --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage\https_ec-ns.sascdn.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage\https_ec-ns.sascdn.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage\https_www.shoes.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage\https_www.shoes.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage\http_cdn.krxd.net_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage\http_cdn.krxd.net_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage\http_nanatsu-no-taizai.wikia.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage\http_nanatsu-no-taizai.wikia.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage\http_nordic.businessinsider.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage\http_nordic.businessinsider.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage\http_www.businessinsider.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage\http_www.businessinsider.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage\http_www.tmz.com_0.localstorage --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Local Storage\http_www.tmz.com_0.localstorage-journal --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\D8C8.tmp --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\FA8A.tmp --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache\EEYDCPWM --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\anyclip-inread.s3.amazonaws.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\anyclip-inread.s3.amazonaws.com\analytics.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\anyclip-inread.s3.amazonaws.com\#com.junkbyte --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\anyclip-inread.s3.amazonaws.com\#com.junkbyte\Console --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\anyclip-inread.s3.amazonaws.com\ac# --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\cdn.stickyadstv.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\eereader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\efreader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\egreader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com\##1578D57EFAC6D57F --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com\##1578D57EFAC6D57F\00000001.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com\support --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com\support\flashplayer --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com\support\flashplayer\sys --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com\support\flashplayer\sys\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com\support\flashplayer\sys\#cdn.stickyadstv.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com\support\flashplayer\sys\#cdn.stickyadstv.com\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com\support\flashplayer\sys\#eereader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com\support\flashplayer\sys\#eereader.com\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com\support\flashplayer\sys\#efreader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com\support\flashplayer\sys\#efreader.com\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com\support\flashplayer\sys\#egreader.com --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\data678\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\C6LEAPNB\macromedia.com\support\flashplayer\sys\#egreader.com\settings.sol --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\llssoft\winvmx\dump --> [Trojan.Clicker.D] Infected: C:\Users\steff\AppData\Local\ntuserlitelist --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\dataup --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\dataup\dataup.ini --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\dataup\help_dll.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\dataup\NTSVC.ocx --> [Trojan.Clicker] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E7BC34A3-BA86-11CF-84B1-CBC2DA68BF6C} --> [Trojan.Clicker] Infected: HKLM\SOFTWARE\CLASSES\TYPELIB\{E7BC34A0-BA86-11CF-84B1-CBC2DA68BF6C} --> [Trojan.Clicker] Infected: HKLM\SOFTWARE\CLASSES\INTERFACE\{E7BC34A1-BA86-11CF-84B1-CBC2DA68BF6C} --> [Trojan.Clicker] Infected: HKLM\SOFTWARE\CLASSES\INTERFACE\{E7BC34A2-BA86-11CF-84B1-CBC2DA68BF6C} --> [Trojan.Clicker] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E7BC34A1-BA86-11CF-84B1-CBC2DA68BF6C} --> [Trojan.Clicker] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E7BC34A2-BA86-11CF-84B1-CBC2DA68BF6C} --> [Trojan.Clicker] Infected: HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{E7BC34A1-BA86-11CF-84B1-CBC2DA68BF6C} --> [Trojan.Clicker] Infected: HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{E7BC34A2-BA86-11CF-84B1-CBC2DA68BF6C} --> [Trojan.Clicker] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E7BC34A0-BA86-11CF-84B1-CBC2DA68BF6C} --> [Trojan.Clicker] Infected: HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{E7BC34A0-BA86-11CF-84B1-CBC2DA68BF6C} --> [Trojan.Clicker] Infected: HKLM\SOFTWARE\CLASSES\NTService.Control.1 --> [Trojan.Clicker] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\NTService.Control.1 --> [Trojan.Clicker] Infected: HKLM\SOFTWARE\CLASSES\WOW6432NODE\NTService.Control.1 --> [Trojan.Clicker] Infected: HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E7BC34A3-BA86-11CF-84B1-CBC2DA68BF6C} --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\regtool --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\regtool\regtool.exe --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\cef.pak --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\cef_100_percent.pak --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\cef_200_percent.pak --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\cef_extensions.pak --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\d3dcompiler_47.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\d3dcompiler_47.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\dbghelp.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\dbghelp.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\dbghelp.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\dbghelp.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\dbghelp.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\dbghelp.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\dbghelp.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\debug.log --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\icudtl.dat --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\libcef.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\libcef.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\libcef.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\libcef.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\libcef.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\libcef.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\libEGL.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\libEGL.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\libGLESv2.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\libGLESv2.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\natives_blob.bin --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\pepflashplayer.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\pepflashplayer.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\snapshot_blob.bin --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\svcvmx.log --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\widevinecdm.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\widevinecdmadapter.dll --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\locales --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\locales\en-US.pak --> [Trojan.Clicker] Infected: C:\Users\steff\AppData\Local\ntuserlitelist\svcvmx\locales\zh-CN.pak --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\dataup --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\dataup\dataup.exe --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\dataup\dataup.ini --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\dataup\help_dll.dll --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\dataup\NTSVC.ocx --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\regtool --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\regtool\regtool.exe --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\cef.pak --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\cef_100_percent.pak --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\cef_200_percent.pak --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\cef_extensions.pak --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\d3dcompiler_47.dll --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\dbghelp.dll --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\icudtl.dat --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\libcef.dll --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\libEGL.dll --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\libGLESv2.dll --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\natives_blob.bin --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\pepflashplayer.dll --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\snapshot_blob.bin --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\svcvmx.exe --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\vmxclient.exe --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\widevinecdm.dll --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\widevinecdmadapter.dll --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\locales --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\locales\en-US.pak --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\svcvmx\locales\zh-CN.pak --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\winscr --> [Trojan.Clicker] Infected: C:\Program Files (x86)\ntuserlitelist\winscr\winscr.exe --> [Trojan.Clicker] Infected: C:\ProgramData\Microleaves --> [Adware.OnlineIO] Infected: C:\Users\steff\AppData\Roaming\Microleaves --> [Adware.OnlineIO] Infected: C:\Users\steff\AppData\Roaming\Microleaves\Online Application Installer --> [Adware.OnlineIO] Infected: C:\Users\steff\AppData\Roaming\Microleaves\Online Application Installer\prerequisites --> [Adware.OnlineIO] Infected: C:\Windows\TEMPcoral.vbs --> [Trojan.SpamBot] Scan finished Creating System Restore point... Cleaning up... <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Removal scheduling successful. System shutdown needed. System shutdown occurred ======================================= --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.09.4.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 10.0.15063 Windows 10 x64 Account is Administrative Internet Explorer version: 11.296.15063.0 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 3.500000 GHz Memory total: 8588013568, free: 7001579520 Downloaded database version: v2017.05.19.01 ======================================= Initializing... ------------ Kernel report ------------ 05/18/2017 19:47:13 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_AuthenticAMD.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\System32\drivers\ksecdd.sys \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\System32\drivers\FLTMGR.SYS \SystemRoot\System32\drivers\clipsp.sys \SystemRoot\System32\drivers\cmimcext.sys \SystemRoot\System32\drivers\ntosext.sys \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\cng.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\SleepStudyHelper.sys \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\system32\drivers\WindowsTrustedRT.sys \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys \SystemRoot\system32\drivers\CLASSPNP.SYS \SystemRoot\System32\drivers\pcw.sys \SystemRoot\system32\drivers\ndistpr64.sys \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\system32\drivers\CEA.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\pciide.sys \SystemRoot\System32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\atapi.sys \SystemRoot\System32\drivers\ataport.SYS \SystemRoot\System32\drivers\storahci.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Wof.sys \SystemRoot\System32\Drivers\NTFS.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\drivers\wfplwfs.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\System32\drivers\volume.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\iorate.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\system32\drivers\filecrypt.sys \SystemRoot\system32\drivers\tbs.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\vmbkmclr.sys \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\drivers\vwififlt.sys \SystemRoot\System32\drivers\pacer.sys \SystemRoot\system32\drivers\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\drivers\gpuenergydrv.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\SysWow64\drivers\AsIO.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys \SystemRoot\System32\drivers\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \SystemRoot\System32\drivers\amdppm.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys \SystemRoot\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\portcls.sys \SystemRoot\System32\drivers\drmk.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\rt640x64.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\system32\drivers\ucx01000.sys \SystemRoot\System32\drivers\usbohci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\serial.sys \SystemRoot\System32\drivers\serenum.sys \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\system32\drivers\AtihdWT6.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\system32\DRIVERS\HdAudio.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\kbdhid.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\win32kfull.sys \SystemRoot\System32\win32kbase.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_storahci.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\drivers\dxgmms2.sys \SystemRoot\System32\drivers\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\wcifs.sys \SystemRoot\system32\drivers\storqosflt.sys \SystemRoot\System32\drivers\registry.sys \SystemRoot\system32\drivers\lltdio.sys \SystemRoot\system32\drivers\mslldp.sys \SystemRoot\system32\drivers\rspndr.sys \SystemRoot\System32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\system32\drivers\mmcss.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\System32\drivers\tcpipreg.sys \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys \SystemRoot\System32\drivers\condrv.sys ----------- End ----------- Done! Scan started Database versions: main: v2017.05.19.01 rootkit: v2017.04.02.01 <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffab08b43ef060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffab08b43259f0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffab08b43ef060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffffab08b4128060, DeviceName: \Device\00000027\, DriverName: \Driver\storahci\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... Done! Drive 0 This is a System drive Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: DD0E7A7A Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 716800 Partition is bootable Partition file system is NTFS Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 718848 Numsec = 1951879168 Partition is not bootable Partition file system is NTFS Partition 2 type is Other (0x27) Partition is NOT ACTIVE. Partition starts at LBA: 1952598016 Numsec = 921600 Partition is not bootable Partition file system is NTFS Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition is not bootable Disk Size: 1000204886016 bytes Sector size: 512 bytes Done! File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\apphelp.dll" is sparse (flags = 32768) File "C:\Windows\AppPatch\AcLayers.dll" is sparse (flags = 32768) File "C:\Windows\System32\msvcrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\user32.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768) File "C:\Windows\System32\gdi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ucrtbase.dll" is sparse (flags = 32768) File "C:\Windows\System32\shell32.dll" is sparse (flags = 32768) File "C:\Windows\System32\cfgmgr32.dll" is sparse (flags = 32768) File "C:\Windows\System32\SHCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcrt4.dll" is sparse (flags = 32768) File "C:\Windows\System32\sspicli.dll" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sechost.dll" is sparse (flags = 32768) File "C:\Windows\System32\combase.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STORAGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\advapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\shlwapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\KERNEL.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\powrprof.dll" is sparse (flags = 32768) File "C:\Windows\System32\profapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleaut32.dll" is sparse (flags = 32768) File "C:\Windows\System32\setupapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\mpr.dll" is sparse (flags = 32768) File "C:\Windows\System32\winspool.drv" is sparse (flags = 32768) File "C:\Windows\System32\bcrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\sfc_os.dll" is sparse (flags = 32768) File "C:\Windows\System32\imm32.dll" is sparse (flags = 32768) File "C:\Windows\System32\imagehlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ole32.dll" is sparse (flags = 32768) File "C:\Windows\System32\version.dll" is sparse (flags = 32768) File "C:\Windows\System32\wintrust.dll" is sparse (flags = 32768) File "C:\Windows\System32\msasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\crypt32.dll" is sparse (flags = 32768) File "C:\Windows\System32\psapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wininet.dll" is sparse (flags = 32768) File "C:\Windows\System32\netapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\userenv.dll" is sparse (flags = 32768) File "C:\Windows\System32\ws2_32.dll" is sparse (flags = 32768) File "C:\Windows\System32\netutils.dll" is sparse (flags = 32768) File "C:\Windows\System32\comdlg32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winmm.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.0_none_8b4e86125c6fbfec\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINMMBASE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\rsaenh.dll" is sparse (flags = 32768) File "C:\Windows\System32\uxtheme.dll" is sparse (flags = 32768) File "C:\Windows\System32\msctf.dll" is sparse (flags = 32768) File "C:\Windows\System32\dwmapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkscli.dll" is sparse (flags = 32768) File "C:\Windows\System32\cscapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\iertutil.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONDEMANDCONNROUTEHELPER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPHLPAPI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\winhttp.dll" is sparse (flags = 32768) File "C:\Windows\System32\mswsock.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\winnsi.dll" is sparse (flags = 32768) File "C:\Windows\System32\urlmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\msIso.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasadhlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\FWPUCLNT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ntmarta.dll" is sparse (flags = 32768) File "C:\Windows\System32\clbcatq.dll" is sparse (flags = 32768) File "C:\Windows\System32\propsys.dll" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERMGRCLI.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wtsapi32.dll" is sparse (flags = 32768) File "C:\Windows\System32\winsta.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.STATEREPOSITORY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\STATEREPOSITORY.CORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\mssprxy.dll" is sparse (flags = 32768) File "C:\Windows\System32\coml2.dll" is sparse (flags = 32768) File "C:\Windows\System32\linkinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntshrui.dll" is sparse (flags = 32768) File "C:\Windows\System32\srvcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\smss.exe" is sparse (flags = 32768) File "C:\Windows\System32\csrss.exe" is sparse (flags = 32768) File "C:\Windows\System32\wininit.exe" is sparse (flags = 32768) File "C:\Windows\System32\services.exe" is sparse (flags = 32768) File "C:\Windows\System32\lsass.exe" is sparse (flags = 32768) File "C:\Windows\System32\winlogon.exe" is sparse (flags = 32768) File "C:\Windows\System32\svchost.exe" is sparse (flags = 32768) File "C:\Windows\System32\FONTDRVHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dwm.exe" is sparse (flags = 32768) File "C:\Windows\System32\spoolsv.exe" is sparse (flags = 32768) File "C:\Windows\System32\msimg32.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f\comctl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\mfc42.dll" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dasHost.exe" is sparse (flags = 32768) File "C:\Program Files\Windows Media Player\wmpnetwk.exe" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiPrvSE.exe" is sparse (flags = 32768) File "C:\Windows\System32\sihost.exe" is sparse (flags = 32768) File "C:\Windows\explorer.exe" is sparse (flags = 32768) File "C:\Windows\System32\TASKHOSTW.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768) File "C:\Windows\System32\RUNTIMEBROKER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SMARTSCREEN.EXE" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768) File "C:\Windows\System32\BACKGROUNDTASKHOST.EXE" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MSASCuiL.exe" is sparse (flags = 32768) File "C:\Windows\System32\opengl32.dll" is sparse (flags = 32768) File "C:\Windows\System32\glu32.dll" is sparse (flags = 32768) File "C:\Windows\System32\sxs.dll" is sparse (flags = 32768) File "C:\Windows\System32\wsock32.dll" is sparse (flags = 32768) File "C:\Windows\System32\xmllite.dll" is sparse (flags = 32768) File "C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.15063.0_none_d802f55807fa1ec7\GdiPlus.dll" is sparse (flags = 32768) File "C:\Windows\System32\wer.dll" is sparse (flags = 32768) File "C:\Windows\System32\cabinet.dll" is sparse (flags = 32768) File "C:\Windows\System32\Faultrep.dll" is sparse (flags = 32768) File "C:\Windows\System32\secur32.dll" is sparse (flags = 32768) File "C:\Windows\System32\loadperf.dll" is sparse (flags = 32768) File "C:\Windows\System32\pdh.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbghelp.dll" is sparse (flags = 32768) File "C:\Windows\System32\ncrypt.dll" is sparse (flags = 32768) File "C:\Windows\System32\dbgcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\ntasn1.dll" is sparse (flags = 32768) File "C:\Windows\System32\mlang.dll" is sparse (flags = 32768) File "C:\Windows\System32\msxml6.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768) File "C:\Windows\System32\taskschd.dll" is sparse (flags = 32768) File "C:\Windows\System32\TWINAPI.APPCORE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FAMILYSAFETYEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\Wpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidprov.dll" is sparse (flags = 32768) File "C:\Windows\System32\samcli.dll" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\d3d11.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxgi.dll" is sparse (flags = 32768) File "C:\Windows\System32\dcomp.dll" is sparse (flags = 32768) File "C:\Windows\System32\DWrite.dll" is sparse (flags = 32768) File "C:\Windows\System32\oleacc.dll" is sparse (flags = 32768) File "C:\Windows\System32\usp10.dll" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlaapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768) File "C:\Windows\System32\avrt.dll" is sparse (flags = 32768) File "C:\Windows\System32\MMDevAPI.dll" is sparse (flags = 32768) File "C:\Windows\System32\devobj.dll" is sparse (flags = 32768) File "C:\Windows\System32\mscms.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptnet.dll" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768) File "C:\Windows\System32\msi.dll" is sparse (flags = 32768) File "C:\Windows\System32\d3d9.dll" is sparse (flags = 32768) File "C:\Windows\System32\credui.dll" is sparse (flags = 32768) File "C:\Windows\System32\cryptui.dll" is sparse (flags = 32768) File "C:\Windows\System32\dxva2.dll" is sparse (flags = 32768) File "C:\Windows\System32\fontsub.dll" is sparse (flags = 32768) File "C:\Windows\System32\fontsub.dll" is sparse (flags = 32768) File "C:\Windows\System32\NapiNSP.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpnsp.dll" is sparse (flags = 32768) File "C:\Windows\System32\winrnr.dll" is sparse (flags = 32768) File "C:\Windows\System32\cmd.exe" is sparse (flags = 32768) File "C:\Windows\System32\conhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\rundll32.exe" is sparse (flags = 32768) File "C:\Windows\System32\APPRESOLVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ELSCore.dll" is sparse (flags = 32768) File "C:\Windows\System32\slc.dll" is sparse (flags = 32768) File "C:\Windows\System32\BCP47LANGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\sppc.dll" is sparse (flags = 32768) File "C:\Windows\System32\MrmCoreR.dll" is sparse (flags = 32768) File "C:\Windows\System32\DLNASHEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DLNASHEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PLAYTODEVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PLAYTODEVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVDISPITEMPROVIDER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wpdshext.dll" is sparse (flags = 32768) File "C:\Windows\System32\ONECOREUAPCOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ONECOREUAPCOMMONPROXYSTUB.DLL" is sparse (flags = 32768) File "C:\Windows\System32\POLICYMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MSVCP110_WIN.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\dllhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\sppsvc.exe" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\SysWOW64\ONEDRIVESETUP.EXE" is sparse (flags = 32768) File "C:\Windows\System32\credssp.dll" is sparse (flags = 32768) File "C:\Windows\System32\userinit.exe" is sparse (flags = 32768) File "C:\Windows\System32\scecli.dll" is sparse (flags = 32768) File "C:\Windows\System32\msv1_0.dll" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\appid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspclock.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpiex.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipmi.sys" is sparse (flags = 32768) File "C:\Windows\System32\Locator.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mpsdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\afd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ahcache.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BthhfHid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\asyncmac.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv.sys" is sparse (flags = 32768) File "C:\Windows\System32\alg.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICRENDER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srv2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcifs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wcnfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UCMTCPCICX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\luafv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BASICDISPLAY.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bthmodem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bowser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHAVRCPTG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\BTHHFENUM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cng.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\clfs.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\circlass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\cldflt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\registry.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mup.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\CNGHWASSIST.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\condrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dam.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dfsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\dxgkrnl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpip.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORCLASS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPATIALGRAPHFILTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fileinfo.sys" is sparse (flags = 32768) File "C:\Windows\System32\FXSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILECRYPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipfltdrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fltMgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768) File "C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PRESENTATIONFONTCACHE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\fvevol.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMGENCOUNTER.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndisuio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFRd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wanarp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\GPUENERGYDRV.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wfplwfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbengine.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\http.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmgid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hwpolicy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pacer.sys" is sparse (flags = 32768) File "C:\Windows\SysWOW64\perfhost.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WPDUPFLTR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\INDIRECTKMD.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\iorate.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\scfilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdFilter.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ipnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\irda.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecdd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksecpkg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ksthunk.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\lltdio.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwififlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mstee.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mmcss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mskssrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\MsMpEng.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wimmount.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxdav.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\modem.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mspqm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mountmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasl2tp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb10.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mrxsmb20.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ucx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ufx01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\bridge.sys" is sparse (flags = 32768) File "C:\Windows\System32\msdtc.exe" is sparse (flags = 32768) File "C:\Windows\System32\VSSVC.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSGPIOWIN32.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MSHIDUMDF.SYS" is sparse (flags = 32768) File "C:\Windows\System32\msiexec.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mslldp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nwifi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbios.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndis.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiscap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndistapi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ndiswan.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Ndu.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vwifibus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\netbt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\nsiproxy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdiWiFi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768) File "C:\Windows\System32\vds.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\partmgr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcw.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pdc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\PEAuth.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\RDPVIDEOMINIPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\qwavedrv.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspptp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rasacd.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\agilevpn.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\raspppoe.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rassstp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdbss.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdpdr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rdyboost.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\rspndr.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vms3cap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\swenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\SENSORDATASERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SpbCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SerCx2.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\URSCX01000.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768) File "C:\Windows\System32\snmptrap.exe" is sparse (flags = 32768) File "C:\Windows\System32\Spectrum.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Wdf01000.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\srvnet.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volmgrx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tcpipreg.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tdx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\terminpt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\System32\TIERINGENGINESERVICE.EXE" is sparse (flags = 32768) File "C:\Windows\servicing\TRUSTEDINSTALLER.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbFlt.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\TsUsbGD.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\UcmCx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\Udecx.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\udfs.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\uefi.sys" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\UI0DETECT.EXE" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\umbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbcir.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBXHCI.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbprint.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vhf.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volsnap.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vpci.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdBoot.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WdNisDrv.sys" is sparse (flags = 32768) File "C:\Program Files\Windows Defender\NisSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WINDOWSTRUSTEDRT.SYS" is sparse (flags = 32768) File "C:\Windows\System32\drivers\winnat.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WmiApSrv.exe" is sparse (flags = 32768) File "C:\Windows\System32\drivers\ws2ifsl.sys" is sparse (flags = 32768) File "C:\Windows\System32\drivers\WUDFPf.sys" is sparse (flags = 32768) File "C:\Windows\System32\AJRouter.dll" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umpnpmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\rpcss.dll" is sparse (flags = 32768) File "C:\Windows\System32\appinfo.dll" is sparse (flags = 32768) File "C:\Windows\System32\appidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\AxInstSv.dll" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\AUDIOENDPOINTBUILDER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\audiosrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\RpcEpMap.dll" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\dssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bdesvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\BFE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netman.dll" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESETUPMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cdpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\umpo.dll" is sparse (flags = 32768) File "C:\Windows\System32\qmgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\ListSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lltdsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\dhcpcore.dll" is sparse (flags = 32768) File "C:\Windows\System32\browser.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\BthHFSrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\profsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\bthserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\provsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\das.dll" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\LICENSEMANAGERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\certprop.dll" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DMWAPPUSHSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ClipSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXGIPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\cryptsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wscsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WsmSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wersvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wecsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wkssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dot3svc.dll" is sparse (flags = 32768) File "C:\Windows\System32\dusmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\fdPHost.dll" is sparse (flags = 32768) File "C:\Windows\System32\dnsrslvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\dps.dll" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\eapsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\efssvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\EMBEDDEDMODESVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\ENTERPRISEAPPMGMTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FntCache.dll" is sparse (flags = 32768) File "C:\Windows\System32\es.dll" is sparse (flags = 32768) File "C:\Windows\System32\sdrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\srvsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\xbgmsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FDResPub.dll" is sparse (flags = 32768) File "C:\Windows\System32\upnphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\fhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\gpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\hidserv.dll" is sparse (flags = 32768) File "C:\Windows\System32\HVHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IKEEXT.DLL" is sparse (flags = 32768) File "C:\Windows\System32\iphlpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\IPXLATCFG.DLL" is sparse (flags = 32768) File "C:\Windows\System32\irmon.dll" is sparse (flags = 32768) File "C:\Windows\System32\keyiso.dll" is sparse (flags = 32768) File "C:\Windows\System32\msdtckrm.dll" is sparse (flags = 32768) File "C:\Windows\System32\lfsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lpasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\lmhsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ipnathlp.dll" is sparse (flags = 32768) File "C:\Windows\System32\lsm.dll" is sparse (flags = 32768) File "C:\Windows\System32\moshost.dll" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MESSAGINGSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\MPSSVC.dll" is sparse (flags = 32768) File "C:\Windows\System32\iscsiexe.dll" is sparse (flags = 32768) File "C:\Windows\System32\nsisvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\nlasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ngcsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NcaSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCDAUTOSETUP.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\netlogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\trkwks.dll" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\icsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pcasvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\p2psvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\PIMINDEXMAINTENANCE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\pla.dll" is sparse (flags = 32768) File "C:\Windows\System32\pnrpauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\icsvcext.dll" is sparse (flags = 32768) File "C:\Windows\System32\IPSECSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\qwave.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasauto.dll" is sparse (flags = 32768) File "C:\Windows\System32\rasmans.dll" is sparse (flags = 32768) File "C:\Windows\System32\mprdim.dll" is sparse (flags = 32768) File "C:\Windows\System32\regsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\RDXSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\RMapi.dll" is sparse (flags = 32768) File "C:\Windows\System32\schedsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SCardSvr.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\seclogon.dll" is sparse (flags = 32768) File "C:\Windows\System32\sensrsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\SEMgrSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\Sens.dll" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SessEnv.dll" is sparse (flags = 32768) File "C:\Windows\System32\shsvcs.dll" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TILEOBJSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\smphost.dll" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\StorSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\sstpsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\ssdpsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\wiaservc.dll" is sparse (flags = 32768) File "C:\Windows\System32\svsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\swprv.dll" is sparse (flags = 32768) File "C:\Windows\System32\sysmain.dll" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TabSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\termsrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\tapisrv.dll" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\THEMESERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TOKENBROKER.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\umrdp.dll" is sparse (flags = 32768) File "C:\Windows\System32\Unistore.dll" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\usermgr.dll" is sparse (flags = 32768) File "C:\Windows\System32\usocore.dll" is sparse (flags = 32768) File "C:\Windows\System32\vaultsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\w32time.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbiosrvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wwansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\WUDFSvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlidsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wlansvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wcncsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wdi.dll" is sparse (flags = 32768) File "C:\Windows\System32\WebClnt.dll" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WEPHOSTSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WFDSCONMGRSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wiarpc.dll" is sparse (flags = 32768) File "C:\Windows\System32\wbem\WMIsvc.dll" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\WPNUSERSERVICE.DLL" is sparse (flags = 32768) File "C:\Windows\System32\wuaueng.dll" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Windows\System32\XBOXNETAPISVC.DLL" is sparse (flags = 32768) File "C:\Program Files\Windows Mail\WinMail.exe" is sparse (flags = 32768) File "C:\Windows\System32\unregmp2.exe" is sparse (flags = 32768) File "C:\Windows\System32\ie4uinit.exe" is sparse (flags = 32768) File "C:\Users\steff\AppData\Local\Comms\UnistoreDB\store.vol" is sparse (flags = 32768) File "C:\Windows\System32\config\systemprofile\AppData\Local\DataSharing\Storage\DSTokenDB2.dat" is sparse (flags = 32768) Scan finished ======================================= Removal queue found; removal started Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-1-718848-i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-2-1952598016-i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam... Removal finished