Internet Explorer not working properly

Hello! Some links don't work in websites when I click on them and not all things appear in websites when I browse to website. Chrome shows the missing things that Internet Explorer doesn't.


Also when browsing to different websites I get an invalid certificate errors.


Please help.



Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-07-2017
Ran by family (administrator) on FAMILY-PC (05-07-2017 12:49:57)
Running from C:\Users\family\Desktop
Loaded Profiles: family (Available Profiles: family)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Control Panel Client\nvcplui.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(CMedia) C:\Program Files\ASUS Xonar Essence STX Audio\Customapp\AsusAudioCenter.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_26_0_0_131_ActiveX.exe
(CrossWire Bible Society) C:\Program Files (x86)\CrossWire\The SWORD Project\sword.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
GroupPolicyScripts: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{2354B7A9-E94C-43D0-B33E-A9C5CE00E8A2}: [DhcpNameServer]

Internet Explorer:
HKU\S-1-5-21-3923717162-344275592-1238881661-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com.au/
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-05-05] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-05] (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08] (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)

FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_148.dll [2017-04-23] ()
FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-05] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-05] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll [2017-04-23] ()
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version= -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2009-11-10] (Yahoo! Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)

CHR Profile: C:\Users\family\AppData\Local\Google\Chrome\User Data\Default [2017-07-05]
CHR Extension: (Google Docs) - C:\Users\family\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-04-21]
CHR Extension: (Google Sheets) - C:\Users\family\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-04-21]
CHR Extension: (Google Docs Offline) - C:\Users\family\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-04-21]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 LVSrvLauncher; C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe [173344 2007-02-06] (Logitech Inc.)
S4 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [452152 2017-04-20] (NVIDIA Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2725376 2011-03-10] (C-Media Inc)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-05-14] ()
R0 mv64xx; C:\Windows\System32\DRIVERS\mv64xx.sys [322088 2009-01-29] (Marvell Semiconductor, Inc.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-05 12:49 - 2017-07-05 12:49 - 00000000 ____D C:\Users\family\Desktop\FRST-OlderVersion
2017-07-04 12:55 - 2017-07-04 12:56 - 00000834 _____ C:\Users\family\Documents\Mine2.xml
2017-07-04 12:50 - 2017-07-04 12:50 - 00000834 _____ C:\Users\family\Documents\as.xml
2017-07-04 12:38 - 2017-07-04 12:39 - 00110740 _____ C:\Users\family\Downloads\pizza2_11249772.jar
2017-07-04 12:13 - 2017-07-04 12:13 - 00000000 ____D C:\Program Files (x86)\Launch4j
2017-07-03 23:39 - 2017-07-04 00:28 - 00000000 ____D C:\Users\family\AppData\Roaming\Paltalk
2017-07-03 23:39 - 2017-07-03 23:39 - 00000000 ____D C:\Users\family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Paltalk Messenger
2017-07-03 23:39 - 2017-07-03 23:39 - 00000000 ____D C:\Program Files (x86)\Paltalk Messenger
2017-07-02 16:55 - 2017-07-02 16:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Messenger
2017-07-02 11:31 - 2017-07-02 11:31 - 00000000 ____D C:\Users\family\AppData\Roaming\Yahoo!
2017-07-02 11:31 - 2017-07-02 11:31 - 00000000 ____D C:\Users\family\AppData\Local\Yahoo
2017-07-02 11:30 - 2017-07-02 11:30 - 00000000 ____D C:\ProgramData\Yahoo!
2017-06-29 14:53 - 2017-06-29 14:53 - 00000000 ____D C:\Users\family\AppData\Roaming\Yahoo Messenger
2017-06-27 22:25 - 2017-06-29 14:53 - 00000000 ____D C:\Users\family\AppData\Local\yahoomessenger
2017-06-27 22:25 - 2017-06-27 22:25 - 00000000 ____D C:\Users\family\AppData\Local\SquirrelTemp
2017-06-27 22:24 - 2017-06-27 22:24 - 00749404 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-06-27 22:22 - 2017-07-02 11:30 - 00000000 ____D C:\Program Files (x86)\Yahoo!
2017-06-26 15:15 - 2017-06-29 15:48 - 00000000 ____D C:\Users\family\AppData\Roaming\Skype
2017-06-26 15:15 - 2017-06-26 15:15 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-06-26 15:15 - 2017-06-26 15:15 - 00000000 ____D C:\ProgramData\Skype
2017-06-26 15:15 - 2017-06-26 15:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-06-23 17:39 - 2017-06-23 17:40 - 07649280 _____ C:\Program Files (x86)\GUTD0D6.tmp
2017-06-23 17:39 - 2017-06-23 17:39 - 00000000 ____D C:\Program Files (x86)\GUMD0D5.tmp
2017-06-23 12:22 - 2017-06-23 12:22 - 00000000 ____D C:\ProgramData\Emsisoft
2017-06-23 12:21 - 2017-06-23 17:34 - 00000000 ____D C:\EEK
2017-06-22 14:36 - 2017-06-24 00:01 - 00000000 ____D C:\Program Files\Google
2017-06-22 14:35 - 2017-06-22 14:35 - 00000000 ____D C:\Users\family\AppData\Local\CEF
2017-06-22 14:31 - 2017-06-23 17:37 - 00000000 ____D C:\ProgramData\AVAST Software
2017-06-21 12:35 - 2017-06-21 12:35 - 04110280 _____ C:\Users\family\Desktop\AdwCleaner.exe
2017-06-21 12:28 - 2017-06-21 12:28 - 00001879 _____ C:\Users\family\Desktop\JRT.txt
2017-06-21 12:19 - 2017-06-21 12:19 - 01663672 _____ (Malwarebytes) C:\Users\family\Desktop\JRT.exe
2017-06-21 11:54 - 2017-06-21 11:55 - 00008011 _____ C:\Users\family\Desktop\Fixlog.txt
2017-06-20 16:44 - 2017-06-20 16:44 - 00023659 _____ C:\Users\family\Desktop\Addition.txt
2017-06-20 16:43 - 2017-07-05 12:50 - 00006232 _____ C:\Users\family\Desktop\FRST.txt
2017-06-20 16:43 - 2017-07-05 12:49 - 00000000 ____D C:\FRST
2017-06-20 16:40 - 2017-07-05 12:49 - 02436608 _____ (Farbar) C:\Users\family\Desktop\FRST64.exe
2017-06-19 20:13 - 2017-06-19 20:13 - 00002064 _____ C:\Users\Public\Desktop\Logitech QuickCam.lnk
2017-06-19 20:13 - 2017-06-19 20:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2017-06-19 20:13 - 2017-06-19 20:13 - 00000000 ____D C:\ProgramData\Logitech
2017-06-19 20:13 - 2017-06-19 20:13 - 00000000 ____D C:\ProgramData\Logishrd
2017-06-19 20:04 - 2017-06-19 20:04 - 00220628 _____ C:\Windows\ntbtlog.txt
2017-06-19 19:55 - 2017-06-25 09:59 - 00000000 ____D C:\Windows\system32\appmgmt
2017-06-18 23:13 - 2017-06-18 23:13 - 00295721 _____ C:\Users\family\Downloads\repository.thgiliwt-1.0.3.zip
2017-06-09 17:14 - 2017-06-09 17:14 - 00121522 _____ C:\Users\family\Desktop\submission.jar
2017-06-08 22:39 - 2017-06-08 22:39 - 00000000 ____D C:\Users\family\AppData\Local\Barbary Software

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-05 11:16 - 2017-04-27 10:12 - 00000000 ____D C:\ProgramData\boost_interprocess
2017-07-05 10:55 - 2017-05-17 23:19 - 00000000 ____D C:\Users\family\AppData\Local\PokerStars
2017-07-05 09:38 - 2009-07-14 15:13 - 00716598 _____ C:\Windows\system32\PerfStringBackup.INI
2017-07-05 09:38 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\inf
2017-07-05 09:34 - 2009-07-14 15:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-07-05 00:18 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\system32\NDF
2017-07-05 00:13 - 2017-04-17 01:45 - 00000000 ____D C:\Users\family\AppData\Local\ElevatedDiagnostics
2017-07-04 17:10 - 2017-05-10 20:35 - 00000000 ____D C:\Users\family\AppData\Local\CrashDumps
2017-07-04 16:10 - 2017-04-21 00:19 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
2017-07-04 16:09 - 2017-04-21 00:19 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-07-04 16:08 - 2017-04-26 14:50 - 00000978 _____ C:\Users\family\AppData\Local\7F68A003.il
2017-07-04 16:08 - 2017-04-26 14:50 - 00000280 _____ C:\Users\family\AppData\Local\IndexIE_7F68A003.il
2017-07-04 12:13 - 2017-05-25 00:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Launch4j
2017-07-03 00:21 - 2017-04-17 02:00 - 00000000 ____D C:\Users\family\AppData\Local\QuickPar
2017-07-01 16:16 - 2017-05-05 12:35 - 00000000 ____D C:\Users\family\Documents\NetBeansProjects
2017-07-01 00:55 - 2017-05-17 23:19 - 00000000 ____D C:\Program Files (x86)\PokerStars
2017-06-29 15:14 - 2017-04-23 11:37 - 00007605 _____ C:\Users\family\AppData\Local\Resmon.ResmonCfg
2017-06-29 11:52 - 2017-04-17 22:31 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-06-29 11:52 - 2017-04-17 22:31 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-06-25 10:21 - 2017-04-16 09:10 - 00000000 ____D C:\Users\family\AppData\Local\Adobe
2017-06-25 10:14 - 2017-04-23 09:23 - 00803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-06-25 10:14 - 2017-04-23 09:23 - 00144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-06-25 10:13 - 2017-04-23 09:23 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-06-25 10:13 - 2017-04-23 09:23 - 00000000 ____D C:\Windows\system32\Macromed
2017-06-25 09:50 - 2017-05-04 09:54 - 00000000 ____D C:\ProgramData\Package Cache
2017-06-25 00:03 - 2009-07-14 14:45 - 00015696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-06-25 00:03 - 2009-07-14 14:45 - 00015696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-06-24 01:41 - 2017-05-25 19:49 - 00000000 ____D C:\Users\family\AppData\LocalLow\Temp
2017-06-24 00:01 - 2017-04-17 22:30 - 00000000 ____D C:\Program Files (x86)\Google
2017-06-23 17:40 - 2017-04-17 22:30 - 00000000 ____D C:\Users\family\AppData\Local\Google
2017-06-23 12:08 - 2009-07-14 13:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2017-06-21 12:43 - 2017-04-21 00:01 - 00000000 ____D C:\AdwCleaner
2017-06-19 20:13 - 2017-04-17 22:36 - 00000000 ____D C:\Program Files\Common Files\LogiShrd
2017-06-19 20:13 - 2017-04-17 22:35 - 00000000 ____D C:\Program Files (x86)\Logitech
2017-06-15 00:59 - 2017-04-17 09:20 - 00000000 ____D C:\Users\family\AppData\Roaming\Azureus
2017-06-15 00:59 - 2017-04-17 09:20 - 00000000 ____D C:\Program Files (x86)\Vuze
2017-06-14 14:36 - 2017-04-15 15:13 - 00000000 ____D C:\Windows\system32\SPReview
2017-06-08 09:16 - 2009-07-14 15:08 - 00032548 _____ C:\Windows\Tasks\SCHEDLGU.TXT

==================== Files in the root of some directories =======

2017-06-23 17:39 - 2017-06-23 17:40 - 7649280 _____ () C:\Program Files (x86)\GUTD0D6.tmp
2017-05-12 18:21 - 2017-06-03 14:24 - 0000600 _____ () C:\Users\family\AppData\Roaming\winscp.rnd
2017-04-26 14:50 - 2017-07-04 16:08 - 0000978 _____ () C:\Users\family\AppData\Local\7F68A003.il
2017-04-26 14:50 - 2017-07-04 16:08 - 0000280 _____ () C:\Users\family\AppData\Local\IndexIE_7F68A003.il
2017-05-12 18:21 - 2017-05-12 18:21 - 0000600 _____ () C:\Users\family\AppData\Local\PUTTY.RND
2017-04-23 11:37 - 2017-06-29 15:14 - 0007605 _____ () C:\Users\family\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-07-02 00:54

==================== End of FRST.txt ============================



Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-07-2017
Ran by family (05-07-2017 12:50:22)
Running from C:\Users\family\Desktop
Windows 7 Professional Service Pack 1 (X64) (2017-04-15 02:19:03)
Boot Mode: Normal

==================== Accounts: =============================

Administrator (S-1-5-21-3923717162-344275592-1238881661-500 - Administrator - Disabled)
family (S-1-5-21-3923717162-344275592-1238881661-1000 - Administrator - Enabled) => C:\Users\family
Guest (S-1-5-21-3923717162-344275592-1238881661-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: - Adobe Systems Incorporated)
Adobe Flash Player 26 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated)
Adobe Reader 9.5.5 (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-A95000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 381.89 - NVIDIA Corporation) Hidden
ASUS Xonar Essence STX Audio Driver (HKLM\...\C-Media Oxygen HD Audio Driver) (Version:  - )
BlueJ (HKLM-x32\...\{7D66971C-652B-4065-A6B1-B3EE313C254B}) (Version: 3.1.7 - BlueJ Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: - Google Inc.) Hidden
Java 8 Update 131 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180131F0}) (Version: 8.0.1310.11 - Oracle Corporation)
Java SE Development Kit 8 Update 131 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180131}) (Version: 8.0.1310.11 - Oracle Corporation)
Launch4j 3.8 (HKLM-x32\...\Launch4j) (Version: 3.8 - Grzegorz Kowal)
Logitech QuickCam (HKLM\...\{192E85C6-2B8A-4217-AD30-ECA5CE19DB23}) (Version: 10.51.2029 - Logitech Inc.)
Logitech® Camera Driver (HKLM-x32\...\QcDrv) (Version:  - )
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
MPC-HC 1.7.10 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.10 - MPC-HC Team)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NetBeans IDE 8.2 (HKLM\...\nbi-nb-base- (Version: 8.2 - NetBeans.org)
NewsLeecher v3.9 Final (HKLM-x32\...\NewsLeecher_is1) (Version:  - )
NVIDIA Graphics Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NvTelemetry (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry) (Version: - NVIDIA Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Paltalk Messenger  11.7 (HKLM-x32\...\Paltalk Messenger) (Version: 11.7.639.17814 - AVM Software Inc.)
PokerStars (HKLM-x32\...\PokerStars) (Version:  - PokerStars)
QuickPar 0.9 (HKLM-x32\...\QuickPar) (Version: 0.9 - Peter B. Clements)
Skype™ 7.37 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.37.103 - Skype Technologies S.A.)
The SWORD Project (HKLM-x32\...\The SWORD Project) (Version: 1.5.9 - The Crosswire Bible Society)
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version:  - Elaborate Bytes)
Vuze (HKLM-x32\...\8461-7759-5462-8226) (Version: 4.5 - Vuze Inc.)
Winamp (HKLM-x32\...\Winamp) (Version: 5.63  - Nullsoft, Inc)
WinRAR 5.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
WinSCP 4.3.2 (HKLM-x32\...\winscp3_is1) (Version: 4.3.2 - Martin Prikryl)
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version:  - Yahoo! Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers01: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-15] (Elaborate Bytes AG)
ContextMenuHandlers01: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-08-27] (Alexander Roshal)
ContextMenuHandlers01: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>  -> No File
ContextMenuHandlers01: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} =>  -> No File
ContextMenuHandlers02: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-15] (Elaborate Bytes AG)
ContextMenuHandlers03: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} =>  -> No File
ContextMenuHandlers04: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} =>  -> No File
ContextMenuHandlers05: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2014-07-03] (NVIDIA Corporation)
ContextMenuHandlers05: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} =>  -> No File
ContextMenuHandlers06: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-08-27] (Alexander Roshal)
ContextMenuHandlers06: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>  -> No File
ContextMenuHandlers06: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} =>  -> No File

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {B7F1DEBC-C07C-4D87-B179-DF25CF821828} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-04-17] (Google Inc.)
Task: {DA9193C1-C921-41AA-AD09-3869AD04CE4C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-04-17] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2017-04-16 00:47 - 2014-07-03 04:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-04-16 01:37 - 2011-04-19 14:56 - 00143360 ____N () C:\Program Files\ASUS Xonar Essence STX Audio\Customapp\VmixP8.dll
2006-10-26 13:56 - 2006-10-26 13:56 - 00757008 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

There are 7933 more sites.

IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-3923717162-344275592-1238881661-1000\...\123simsen.com -> www.123simsen.com

There are 7936 more sites.

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 12:34 - 2017-04-21 01:10 - 00454351 ____R C:\Windows\system32\Drivers\etc\hosts www.007guard.com 007guard.com 008i.com www.008k.com 008k.com www.00hq.com 00hq.com 010402.com www.032439.com 032439.com www.0scan.com 0scan.com 1000gratisproben.com www.1000gratisproben.com 1001namen.com www.1001namen.com 100888290cs.com www.100888290cs.com www.100sexlinks.com 100sexlinks.com 10sek.com www.10sek.com www.1-2005-search.com 1-2005-search.com 123fporn.info www.123fporn.info www.123haustiereundmehr.com 123haustiereundmehr.com 123moviedownload.com www.123moviedownload.com

There are 15592 more lines.

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3923717162-344275592-1238881661-1000\Control Panel\Desktop\\Wallpaper ->
DNS Servers: -
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: LVSrvLauncher => 2
MSCONFIG\Services: NVDisplay.ContainerLocalSystem => 2
MSCONFIG\Services: nvsvc => 2
MSCONFIG\Services: NvTelemetryContainer => 2
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: Cmaudio8788 => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.dll,CMICtrlWnd
MSCONFIG\startupreg: Cmaudio8788GX => C:\Windows\syswow64\HsMgr.exe Envoke
MSCONFIG\startupreg: Cmaudio8788GX64 => C:\Windows\system\HsMgr64.exe Envoke
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: LogitechCommunicationsManager => "C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
MSCONFIG\startupreg: LogitechQuickCamRibbon => "C:\Program Files (x86)\Logitech\QuickCam10\QuickCam10.exe" /hide
MSCONFIG\startupreg: Messenger (Yahoo!) => "C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: Yahoo Messenger Updater => "C:\Users\family\AppData\Roaming\Yahoo Messenger\YMUpdater\YMUpdater.exe"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [TCP Query User{F5BE2AA9-9B78-451C-B2CE-50766396843A}C:\program files (x86)\google\chrome\application\chrome.exe] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{26337FB3-857D-4853-9DF8-B29AAD12ECF7}C:\program files (x86)\google\chrome\application\chrome.exe] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [{19BE65CA-8192-4EDC-9225-AE68991234D8}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{3CF1339C-4828-4D23-A0AD-1318042FBC36}] => (Allow) %SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
FirewallRules: [{5BC0BC7D-BF3C-4219-9C20-475478C8E718}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{18FE7F00-466B-4F8A-92A4-95A7C5856AAC}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{8E9CD088-3113-495C-8CF6-5C7D981AE408}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe

==================== Restore Points =========================

ATTENTION: System Restore is disabled

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
Error: (07/05/2017 09:34:21 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Windows license activation failed. Error 0x00000000.

Error: (07/05/2017 09:34:21 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:

Error: (07/05/2017 09:28:23 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Windows license activation failed. Error 0x00000000.

Error: (07/05/2017 09:28:23 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:

Error: (07/04/2017 10:59:06 PM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Windows license activation failed. Error 0x00000000.

Error: (07/04/2017 10:59:06 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:

Error: (07/04/2017 05:23:07 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.18639 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1330

Start Time: 01d2f496410cdd29

Termination Time: 46

Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Report Id:

Error: (07/04/2017 05:10:47 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18639, time stamp: 0x58d6bb0d
Faulting module name: Flash32_26_0_0_131.ocx, version:, time stamp: 0x5941bb71
Exception code: 0x40000015
Fault offset: 0x007f2941
Faulting process id: 0x154c
Faulting application start time: 0x01d2f493bc6f37da
Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Faulting module path: C:\Windows\SysWOW64\Macromed\Flash\Flash32_26_0_0_131.ocx
Report Id: e671a267-6087-11e7-b311-485b3917444d

Error: (07/04/2017 05:04:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18639, time stamp: 0x58d6bb0d
Faulting module name: jscript9.dll, version: 11.0.9600.18639, time stamp: 0x58d6bfcf
Exception code: 0xc0000005
Fault offset: 0x000adf1f
Faulting process id: 0x9d4
Faulting application start time: 0x01d2f49307376791
Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Faulting module path: C:\Windows\SysWOW64\jscript9.dll
Report Id: f9a84e62-6086-11e7-b311-485b3917444d

Error: (07/04/2017 04:59:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18639, time stamp: 0x58d6bb0d
Faulting module name: Flash32_26_0_0_131.ocx, version:, time stamp: 0x5941bb71
Exception code: 0xc0000005
Fault offset: 0x007f9de0
Faulting process id: 0x7ec
Faulting application start time: 0x01d2f491d9f69976
Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Faulting module path: C:\Windows\SysWOW64\Macromed\Flash\Flash32_26_0_0_131.ocx
Report Id: 43439271-6086-11e7-b311-485b3917444d

System errors:
Error: (07/05/2017 09:34:16 AM) (Source: Ntfs) (EventID: 137) (User: )
Description: The default transaction resource manager on volume G: encountered a non-retryable error and could not start.  The data contains the error code.

Error: (07/05/2017 09:34:16 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (07/05/2017 09:34:14 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (07/05/2017 09:34:11 AM) (Source: volmgr) (EventID: 46) (User: )
Description: Crash dump initialization failed!

Error: (07/05/2017 09:29:47 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Diagnostic System Host service hung on starting.

Error: (07/05/2017 09:29:45 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Diagnostic Service Host service hung on starting.

Error: (07/05/2017 09:28:18 AM) (Source: Ntfs) (EventID: 137) (User: )
Description: The default transaction resource manager on volume G: encountered a non-retryable error and could not start.  The data contains the error code.

Error: (07/05/2017 09:28:18 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (07/05/2017 09:28:16 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (07/05/2017 09:28:13 AM) (Source: volmgr) (EventID: 46) (User: )
Description: Crash dump initialization failed!

==================== Memory info ===========================

Processor: Intel® Core™ i7 CPU 975 @ 3.33GHz
Percentage of memory in use: 55%
Total physical RAM: 6135.11 MB
Available physical RAM: 2720.52 MB
Total Virtual: 6133.29 MB
Available Virtual: 1726.79 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:219.87 GB) (Free:186.87 GB) NTFS
Drive d: () (Fixed) (Total:199.22 GB) (Free:29.55 GB) NTFS
Drive f: () (Fixed) (Total:931.51 GB) (Free:7.19 GB) NTFS
Drive g: (Local Disk) (Fixed) (Total:1863.01 GB) (Free:53.43 GB) NTFS

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: D4AEE926)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: A5A370FC)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

Disk: 2 (MBR Code: Windows 7 or 8) (Size: 419.2 GB) (Disk ID: 34352478)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=219.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=199.2 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Error: (07/05/2017 09:34:16 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.



1. Double-click My Computer, and then right-click the hard disk that you want to check. C:
2. Click Properties, and then click Tools.
3. Under Error-checking, click Check Now. A dialog box that shows the Check disk options is displayed,
4. Check both boxes and then click Start.
You will receive the following message:
The disk check could not be performed because the disk check utility needs exclusive access to some Windows files on the disk. These files can be accessed by restarting Windows. Do you want to schedule the disk check to occur the next time you restart the computer?
Click Yes to schedule the disk check, but don't restart yet.
Right click on (My) Computer and select Manage (Continue) Then the Event Viewer. Next select Windows Logs.  Right click on System and Clear Log, Clear. Repeat for Application. Reboot. The disk check will run and will probably take an hour or more to finish.
Repeat the disk check for D:, F:, &  G:  It shouldn't need to reboot for them.
Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator.  Then type (with an Enter after each line).
sfc /scannow
(SPACE after sfc.  This will check your critical system files. Does this finish without complaint?  IF it says it couldn't fix everything then:
Copy the next two lines:
findstr  /c:"[SR]"  \windows\logs\cbs\cbs.log  >  \windows\logs\cbs\junk.txt 
notepad \windows\logs\cbs\junk.txt 
Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator, Continue.  Right click and Paste or Edit then Paste and the copied line should appear.
Hit Enter if notepad does not open.  Copy and paste the text from notepad into a reply.  Close notepad.  Close the Command Window.
1. Please download the Event Viewer Tool by Vino Rosso
and save it to your Desktop:
2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:
* System
4. Under 'Select type to list', select:
* Error
* Warning
Then use the 'Number of events' as follows:
1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.
Please post the Output log in your next reply then repeat but select Application. (Each time you run VEW it overwrites the log so copy the first one to a Reply or rename it before running it a second time.)

I completed error checking for C:, D:, F: and G:.


I completed the sfc /scannow. It finished without complaint.


Here are the output logs of the Event Viewer Tool:


Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 10/07/2017 1:20:29 PM

Note: All dates below are in the format dd/mm/yyyy

'System' Log - Critical Type
Log: 'System' Date/Time: 09/07/2017 11:12:34 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.

Log: 'System' Date/Time: 09/07/2017 10:00:35 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.

Log: 'System' Date/Time: 09/07/2017 4:34:18 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.

'System' Log - Error Type
Log: 'System' Date/Time: 10/07/2017 3:09:23 AM
Type: Error Category: 0
Event: 1 Source: VDS Basic Provider
Unexpected failure. Error code: 490@01010004

Log: 'System' Date/Time: 10/07/2017 1:21:12 AM
Type: Error Category: 0
Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 10/07/2017 1:21:10 AM
Type: Error Category: 0
Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 10/07/2017 1:21:09 AM
Type: Error Category: 0
Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 10/07/2017 1:05:34 AM
Type: Error Category: 0
Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 10/07/2017 1:05:32 AM
Type: Error Category: 0
Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 10/07/2017 12:22:22 AM
Type: Error Category: 0
Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 10/07/2017 12:22:18 AM
Type: Error Category: 0
Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 09/07/2017 11:50:16 PM
Type: Error Category: 0
Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 09/07/2017 11:33:47 PM
Type: Error Category: 0
Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 09/07/2017 11:21:56 PM
Type: Error Category: 0
Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 09/07/2017 11:21:54 PM
Type: Error Category: 0
Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 09/07/2017 11:21:48 PM
Type: Error Category: 0
Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 09/07/2017 11:21:47 PM
Type: Error Category: 0
Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 09/07/2017 11:21:45 PM
Type: Error Category: 0
Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 09/07/2017 11:21:06 PM
Type: Error Category: 0
Event: 7034 Source: Service Control Manager
The NVIDIA Display Driver Service service terminated unexpectedly.  It has done this 1 time(s).

Log: 'System' Date/Time: 09/07/2017 11:17:19 PM
Type: Error Category: 0
Event: 7023 Source: Service Control Manager
The Diagnostic System Host service terminated with the following error:  The requested control is not valid for this service.

Log: 'System' Date/Time: 09/07/2017 11:17:19 PM
Type: Error Category: 0
Event: 7023 Source: Service Control Manager
The Diagnostic Service Host service terminated with the following error:  The requested control is not valid for this service.

Log: 'System' Date/Time: 09/07/2017 11:15:29 PM
Type: Error Category: 0
Event: 7032 Source: Service Control Manager
The Service Control Manager tried to take a corrective action (Reboot the machine) after the unexpected termination of the Power service, but this action failed with the following error:  A system shutdown has already been scheduled.

Log: 'System' Date/Time: 09/07/2017 11:15:29 PM
Type: Error Category: 0
Event: 7032 Source: Service Control Manager
The Service Control Manager tried to take a corrective action (Reboot the machine) after the unexpected termination of the DCOM Server Process Launcher service, but this action failed with the following error:  A system shutdown has already been scheduled.

'System' Log - Warning Type
Log: 'System' Date/Time: 09/07/2017 3:59:06 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name www.bing.com timed out after none of the configured DNS servers responded.

Log: 'System' Date/Time: 09/07/2017 3:49:38 PM
Type: Warning Category: 3
Event: 2004 Source: Microsoft-Windows-Resource-Exhaustion-Detector
Windows successfully diagnosed a low virtual memory condition. The following programs consumed the most virtual memory: dllhost.exe (1884) consumed 5309304832 bytes, svchost.exe (968) consumed 125730816 bytes, and svchost.exe (1152) consumed 53555200 bytes.

Log: 'System' Date/Time: 09/07/2017 10:19:39 AM
Type: Warning Category: 3
Event: 2004 Source: Microsoft-Windows-Resource-Exhaustion-Detector
Windows successfully diagnosed a low virtual memory condition. The following programs consumed the most virtual memory: dllhost.exe (2328) consumed 5456744448 bytes, svchost.exe (976) consumed 130187264 bytes, and svchost.exe (2652) consumed 53432320 bytes.

Log: 'System' Date/Time: 09/07/2017 10:14:39 AM
Type: Warning Category: 3
Event: 2004 Source: Microsoft-Windows-Resource-Exhaustion-Detector
Windows successfully diagnosed a low virtual memory condition. The following programs consumed the most virtual memory: dllhost.exe (2328) consumed 5456744448 bytes, svchost.exe (976) consumed 130134016 bytes, and svchost.exe (2652) consumed 53432320 bytes.

Log: 'System' Date/Time: 09/07/2017 10:09:39 AM
Type: Warning Category: 3
Event: 2004 Source: Microsoft-Windows-Resource-Exhaustion-Detector
Windows successfully diagnosed a low virtual memory condition. The following programs consumed the most virtual memory: dllhost.exe (2328) consumed 5456863232 bytes, svchost.exe (976) consumed 130134016 bytes, and svchost.exe (2652) consumed 53497856 bytes.

Log: 'System' Date/Time: 09/07/2017 10:04:39 AM
Type: Warning Category: 3
Event: 2004 Source: Microsoft-Windows-Resource-Exhaustion-Detector
Windows successfully diagnosed a low virtual memory condition. The following programs consumed the most virtual memory: dllhost.exe (2328) consumed 5235695616 bytes, svchost.exe (976) consumed 125542400 bytes, and svchost.exe (2652) consumed 53547008 bytes.

Log: 'System' Date/Time: 09/07/2017 9:57:15 AM
Type: Warning Category: 3
Event: 2004 Source: Microsoft-Windows-Resource-Exhaustion-Detector
Windows successfully diagnosed a low virtual memory condition. The following programs consumed the most virtual memory: dllhost.exe (2516) consumed 5237616640 bytes, svchost.exe (972) consumed 124497920 bytes, and svchost.exe (2824) consumed 53387264 bytes.

Log: 'System' Date/Time: 09/07/2017 9:51:04 AM
Type: Warning Category: 2
Event: 136 Source: Ntfs
The default transaction resource manager on volume G: encountered an error while starting and its metadata was reset.  The data contains the error code.

Log: 'System' Date/Time: 09/07/2017 4:29:46 AM
Type: Warning Category: 3
Event: 2004 Source: Microsoft-Windows-Resource-Exhaustion-Detector
Windows successfully diagnosed a low virtual memory condition. The following programs consumed the most virtual memory: dllhost.exe (2264) consumed 4930801664 bytes, svchost.exe (1012) consumed 143921152 bytes, and iexplore.exe (3016) consumed 129372160 bytes.



Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 10/07/2017 1:29:57 PM

Note: All dates below are in the format dd/mm/yyyy

'Application' Log - Critical Type
'Application' Log - Error Type
Log: 'Application' Date/Time: 09/07/2017 11:17:19 PM
Type: Error Category: 0
Event: 4103 Source: Microsoft-Windows-Winlogon
Windows license activation failed. Error 0x00000000.

Log: 'Application' Date/Time: 09/07/2017 11:17:19 PM
Type: Error Category: 0
Event: 8198 Source: Microsoft-Windows-Security-SPP
License Activation (slui.exe) failed with the following error code: 0x80070422

Log: 'Application' Date/Time: 09/07/2017 11:12:48 PM
Type: Error Category: 0
Event: 4103 Source: Microsoft-Windows-Winlogon
Windows license activation failed. Error 0x00000000.

Log: 'Application' Date/Time: 09/07/2017 11:12:48 PM
Type: Error Category: 0
Event: 8198 Source: Microsoft-Windows-Security-SPP
License Activation (slui.exe) failed with the following error code: 0x80070422

Log: 'Application' Date/Time: 09/07/2017 3:49:44 PM
Type: Error Category: 0
Event: 9020 Source: Desktop Window Manager
The Desktop Window Manager has encountered a fatal error (0x8007000e)

Log: 'Application' Date/Time: 09/07/2017 3:45:23 PM
Type: Error Category: 0
Event: 4103 Source: Microsoft-Windows-Winlogon
Windows license activation failed. Error 0x00000000.

Log: 'Application' Date/Time: 09/07/2017 3:45:23 PM
Type: Error Category: 0
Event: 8198 Source: Microsoft-Windows-Security-SPP
License Activation (slui.exe) failed with the following error code: 0x80070422

Log: 'Application' Date/Time: 09/07/2017 10:00:43 AM
Type: Error Category: 0
Event: 4103 Source: Microsoft-Windows-Winlogon
Windows license activation failed. Error 0x00000000.

Log: 'Application' Date/Time: 09/07/2017 10:00:43 AM
Type: Error Category: 0
Event: 8198 Source: Microsoft-Windows-Security-SPP
License Activation (slui.exe) failed with the following error code: 0x80070422

Log: 'Application' Date/Time: 09/07/2017 9:53:19 AM
Type: Error Category: 0
Event: 4103 Source: Microsoft-Windows-Winlogon
Windows license activation failed. Error 0x00000000.

Log: 'Application' Date/Time: 09/07/2017 9:53:19 AM
Type: Error Category: 0
Event: 8198 Source: Microsoft-Windows-Security-SPP
License Activation (slui.exe) failed with the following error code: 0x80070422

Log: 'Application' Date/Time: 09/07/2017 5:11:03 AM
Type: Error Category: 0
Event: 4103 Source: Microsoft-Windows-Winlogon
Windows license activation failed. Error 0x00000000.

Log: 'Application' Date/Time: 09/07/2017 5:11:03 AM
Type: Error Category: 0
Event: 8198 Source: Microsoft-Windows-Security-SPP
License Activation (slui.exe) failed with the following error code: 0x80070422

Log: 'Application' Date/Time: 09/07/2017 4:34:26 AM
Type: Error Category: 0
Event: 4103 Source: Microsoft-Windows-Winlogon
Windows license activation failed. Error 0x00000000.

Log: 'Application' Date/Time: 09/07/2017 4:34:26 AM
Type: Error Category: 0
Event: 8198 Source: Microsoft-Windows-Security-SPP
License Activation (slui.exe) failed with the following error code: 0x80070422

Log: 'Application' Date/Time: 09/07/2017 4:30:48 AM
Type: Error Category: 0
Event: 9020 Source: Desktop Window Manager
The Desktop Window Manager has encountered a fatal error (0x80070008)

Log: 'Application' Date/Time: 09/07/2017 4:07:02 AM
Type: Error Category: 0
Event: 4103 Source: Microsoft-Windows-Winlogon
Windows license activation failed. Error 0x00000000.

Log: 'Application' Date/Time: 09/07/2017 4:07:02 AM
Type: Error Category: 0
Event: 8198 Source: Microsoft-Windows-Security-SPP
License Activation (slui.exe) failed with the following error code: 0x80070422

'Application' Log - Warning Type
Log: 'Application' Date/Time: 09/07/2017 11:17:19 PM
Type: Warning Category: 0
Event: 4105 Source: Microsoft-Windows-Winlogon
Windows is in Notification period.

Log: 'Application' Date/Time: 09/07/2017 11:12:47 PM
Type: Warning Category: 0
Event: 4105 Source: Microsoft-Windows-Winlogon
Windows is in Notification period.

Log: 'Application' Date/Time: 09/07/2017 3:45:22 PM
Type: Warning Category: 0
Event: 4105 Source: Microsoft-Windows-Winlogon
Windows is in Notification period.

Log: 'Application' Date/Time: 09/07/2017 10:00:43 AM
Type: Warning Category: 0
Event: 4105 Source: Microsoft-Windows-Winlogon
Windows is in Notification period.

Log: 'Application' Date/Time: 09/07/2017 9:53:19 AM
Type: Warning Category: 0
Event: 4105 Source: Microsoft-Windows-Winlogon
Windows is in Notification period.

Log: 'Application' Date/Time: 09/07/2017 5:11:03 AM
Type: Warning Category: 0
Event: 4105 Source: Microsoft-Windows-Winlogon
Windows is in Notification period.

Log: 'Application' Date/Time: 09/07/2017 4:34:26 AM
Type: Warning Category: 0
Event: 4105 Source: Microsoft-Windows-Winlogon
Windows is in Notification period.

Log: 'Application' Date/Time: 09/07/2017 4:30:12 AM
Type: Warning Category: 0
Event: 4006 Source: Microsoft-Windows-Winlogon
The Windows logon process has failed to spawn a user application. Application name: taskmgr.exe. Command line parameters: taskmgr.exe /2 .

Log: 'Application' Date/Time: 09/07/2017 4:07:02 AM
Type: Warning Category: 0
Event: 4105 Source: Microsoft-Windows-Winlogon
Windows is in Notification period.

Still getting:


Event: 7 Source: Disk
The device, \Device\Harddisk1\DR1, has a bad block.

Log: 'System' Date/Time: 10/07/2017 1:21:10 AM
Type: Error Category: 0


We need to figure out for sure which drive it is talking about.  Windows does not make it easy.  The only way I know for sure is to download WinObj.exe




Save it then Right click and Run As Admin.


Click on the arrow in front of Device


You should see several subentries that start with Harddisk


Click on each Harddisk1 and look in the right pane to see if you see Harddisk1\DR1.  (if you don't see it try the other Harddrive subentries)  Note the Harddisk volume numbers listed.


Now click on Global?? in the left pane.  In the right pane click on the SymLink column header


Scroll down looking in the SymLink column until you find the \Device\HarddiskVolume#'s that you noted earlier.  Look in the first column and there should be a C: or D: or what have you associated with one or more of the HardiskVolume#'s that you noted earlier.


These are the drive letters associated with the error.  Repeat the disk check for those drives.

  • 0



    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts



\Device\Harddisk1\DR1 is F: hard drive.


I repeated the disk check and found no problems. I have attached the screenshot of the result.


Attached Thumbnails

  • FDrive.jpg

  • 0



    Malware Expert

  • Expert
  • 24,708 posts
  • MVP

OK.  As long as it is not the C: drive.  


Log: 'Application' Date/Time: 09/07/2017 11:17:19 PM
Type: Error Category: 0
Event: 4103 Source: Microsoft-Windows-Winlogon
Windows license activation failed. Error 0x00000000.
Log: 'Application' Date/Time: 09/07/2017 11:17:19 PM



Are you getting a notice that Windows has not been activated?  This needs to be fixed.   
Get Process Explorer
Save it to your desktop then run it (Vista or Win7+ - right click and Run As Administrator).  
View, Select Column, check Verified Signer, OK
Options, Verify Image Signatures
Click twice on the CPU column header  to sort things by CPU usage with the big hitters at the top.  
Wait a full minute then:
File, Save As, Save.  Note the file name.   Open the file  on your desktop and copy and paste the text to a reply.
Copy the next 2 lines:
TASKLIST /SVC  > \junk.txt
notepad \junk.txt
Open an Elevated Command Prompt:
Win 7: Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator
Right click and Paste (or Edit then Paste) and the copied lines should appear.
Hit Enter if notepad does not open.  Copy and paste the text from notepad into a reply. 
Get the free version of Speccy:
http://www.filehippo...download_speccy (Look in the upper right for the Download
Latest Version button  - Do NOT press the large Start Download button on the upper left!)  
Download, Save and Install it.  Tell it you do not need CCLEANER.    Run Speccy.  When it finishes (the little icon in the bottom left will stop moving), 
File, Save as Text File,  (to your desktop) note the name it gives. OK.  Open the file in notepad and delete the line that gives the serial number of your Operating System.  
(It will be near the top,  10-20  lines down.) Save the file.  Attach the file to your next post.  Attaching the log is the best option as it is too big for the forum.  Attaching is a multi step process.
First click on More Reply Options
Then scroll down to where you see
Choose File and click on it.  Point it at the file and hit Open.
Now click on Attach this file.

Process CPU Private Bytes Working Set PID Description Company Name Verified Signer

System Idle Process 98.60 0 K 24 K 0

iexplore.exe 0.79 108,448 K 122,684 K 2252 Internet Explorer Microsoft Corporation (Verified) Microsoft Corporation

procexp64.exe 0.48 29,424 K 47,720 K 2788 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation

Interrupts 0.06 0 K 0 K n/a Hardware Interrupts and DPCs

dwm.exe 0.03 29,964 K 30,116 K 1840 Desktop Window Manager Microsoft Corporation (Verified) Microsoft Windows

System 0.01 124 K 304 K 4

csrss.exe 0.01 3,400 K 9,476 K 552 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows

explorer.exe < 0.01 65,768 K 91,720 K 1920 Windows Explorer Microsoft Corporation (Verified) Microsoft Windows

svchost.exe < 0.01 24,612 K 24,528 K 1100 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows

iexplore.exe < 0.01 172,612 K 189,896 K 2008 Internet Explorer Microsoft Corporation (Verified) Microsoft Corporation

iexplore.exe < 0.01 23,752 K 45,456 K 2888 Internet Explorer Microsoft Corporation (Verified) Microsoft Corporation

taskhost.exe < 0.01 21,940 K 25,368 K 1744 Host Process for Windows Tasks Microsoft Corporation (Verified) Microsoft Windows

svchost.exe < 0.01 22,512 K 33,232 K 328 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows

iexplore.exe < 0.01 63,972 K 72,252 K 2536 Internet Explorer Microsoft Corporation (Verified) Microsoft Corporation

nvvsvc.exe < 0.01 7,036 K 15,496 K 1196 NVIDIA Driver Helper Service, Version 340.52 NVIDIA Corporation (Verified) NVIDIA Corporation

iexplore.exe < 0.01 60,220 K 72,176 K 2812 Internet Explorer Microsoft Corporation (Verified) Microsoft Corporation

svchost.exe < 0.01 100,612 K 107,328 K 1004 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows

WmiPrvSE.exe 3,568 K 7,568 K 2732 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows

winlogon.exe 3,820 K 8,356 K 736 Windows Logon Application Microsoft Corporation (Verified) Microsoft Windows

wininit.exe 2,212 K 5,244 K 528 Windows Start-Up Application Microsoft Corporation (Verified) Microsoft Windows

VCDDaemon.exe 1,860 K 6,280 K 1788 Virtual CloneDrive Daemon Elaborate Bytes AG (Verified) Elaborate Bytes AG

svchost.exe 7,520 K 13,264 K 152 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows

svchost.exe 8,844 K 12,960 K 1372 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows

svchost.exe 5,120 K 9,000 K 872 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows

svchost.exe 5,660 K 10,928 K 760 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows

svchost.exe 16,316 K 17,440 K 964 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows

svchost.exe 5,204 K 8,644 K 1432 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows

svchost.exe 2,452 K 6,200 K 2380 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows

svchost.exe 52,084 K 9,448 K 2744 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows

sppsvc.exe 15,604 K 17,072 K 948 Microsoft Software Protection Platform Service Microsoft Corporation (Verified) Microsoft Windows

spoolsv.exe 7,352 K 12,856 K 1344 Spooler SubSystem App Microsoft Corporation (Verified) Microsoft Windows

smss.exe 732 K 1,436 K 276 Windows Session Manager Microsoft Corporation (Verified) Microsoft Windows

services.exe 6,440 K 10,248 K 584 Services and Controller app Microsoft Corporation (Verified) Microsoft Windows

procexp.exe 2,468 K 7,572 K 1240 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation

nvxdsync.exe 11,024 K 23,028 K 1188 NVIDIA User Experience Driver Component NVIDIA Corporation (Verified) NVIDIA Corporation

nvvsvc.exe 3,700 K 8,728 K 832 NVIDIA Driver Helper Service, Version 340.52 NVIDIA Corporation (Verified) NVIDIA Corporation

lsm.exe 2,916 K 4,724 K 612 Local Session Manager Service Microsoft Corporation (Verified) Microsoft Windows

lsass.exe 7,088 K 13,872 K 604 Local Security Authority Process Microsoft Corporation (Verified) Microsoft Windows

FlashUtil64_26_0_0_131_ActiveX.exe 5,236 K 11,092 K 2284 Adobe® Flash® Player Installer/Uninstaller 26.0 r0 Adobe Systems Incorporated (Verified) Adobe Systems Incorporated

csrss.exe 2,468 K 4,528 K 436 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows

audiodg.exe 14,916 K 16,064 K 2228 Windows Audio Device Graph Isolation Microsoft Corporation (Verified) Microsoft Windows



Image Name                     PID Services                                   
========================= ======== ============================================
System Idle Process              0 N/A                                        
System                           4 N/A                                        
smss.exe                       276 N/A                                        
csrss.exe                      436 N/A                                        
wininit.exe                    528 N/A                                        
csrss.exe                      552 N/A                                        
services.exe                   584 N/A                                        
lsass.exe                      604 SamSs                                      
lsm.exe                        612 N/A                                        
winlogon.exe                   736 N/A                                        
svchost.exe                    760 DcomLaunch, PlugPlay, Power                
nvvsvc.exe                     832 nvsvc                                      
svchost.exe                    872 RpcEptMapper, RpcSs                        
svchost.exe                    964 AudioSrv, Dhcp, eventlog, lmhosts, wscsvc  
svchost.exe                   1004 AudioEndpointBuilder, Netman, PcaSvc,      
                                   SysMain, UxSms, wudfsvc                    
svchost.exe                    152 EventSystem, FontCache, netprofm, nsi,     
svchost.exe                    328 Appinfo, gpsvc, IKEEXT, MMCSS, ProfSvc,    
                                   Schedule, SENS, Themes, Winmgmt, wuauserv  
svchost.exe                   1100 CryptSvc, Dnscache, NlaSvc                 
nvxdsync.exe                  1188 N/A                                        
nvvsvc.exe                    1196 N/A                                        
spoolsv.exe                   1344 Spooler                                    
svchost.exe                   1372 BFE, DPS, MpsSvc                           
svchost.exe                   1432 DiagTrack                                  
taskhost.exe                  1744 N/A                                        
dwm.exe                       1840 N/A                                        
explorer.exe                  1920 N/A                                        
VCDDaemon.exe                 1788 N/A                                        
svchost.exe                   2380 PolicyAgent                                
svchost.exe                   2744 WinDefend                                  
iexplore.exe                  2888 N/A                                        
iexplore.exe                  2008 N/A                                        
iexplore.exe                  2252 N/A                                        
iexplore.exe                  2536 N/A                                        
iexplore.exe                  2812 N/A                                        
WmiPrvSE.exe                  2732 N/A                                        
audiodg.exe                   2228 N/A                                        
FlashUtil64_26_0_0_131_Ac     2284 N/A                                        
procexp.exe                   1240 N/A                                        
procexp64.exe                 2788 N/A                                        
wordpad.exe                   2996 N/A                                        
MsSpellCheckingFacility.e      880 N/A                                        
taskhost.exe                  2632 N/A                                        
cmd.exe                        864 N/A                                        
conhost.exe                   1292 N/A                                        
tasklist.exe                  2616 N/A                                        
WmiPrvSE.exe                  1236 N/A                                        

  Operating System
   Windows 7 Professional 64-bit SP1
   Intel Core i7 Extreme 975 @ 3.33GHz 50 °C
   Bloomfield 45nm Technology
   6.00GB Triple-Channel DDR3 @ 668MHz (9-9-9-24)
   CM811 (1600x1200@75Hz)
   512MB NVIDIA GeForce 8400 GS (EVGA) 48 °C
   1535MB NVIDIA GeForce GTX 480 (EVGA) 78 °C
   ForceWare version: 340.52
   SLI Disabled
  Optical Drives
   ASUS Xonar Essence STX Audio Device
Operating System
 Windows 7 Professional 64-bit SP1
 Computer type: Desktop
 Installation Date: 15/04/2017 12:19:03 PM
  Windows Security Center
    Account Control (UAC) Enabled
   Notify level 2 - Default
   Firewall Disabled
   Antivirus Disabled
  Windows Update
   AutoUpdate Disabled
  Windows Defender
   Windows Defender Enabled
  .NET Frameworks installed
   v3.5 SP1
   v3.0 SP2
   v2.0 SP2
  Internet Explorer
   Version 11.0.9600.18638
   Version 2.0
    Java Runtime Environment
     Path C:\Program Files\Java\jdk1.8.0_131\bin\java.exe
     Version 8.0
     Update 131
     Build 11
    Java Runtime Environment
     Path C:\Program Files\Java\jre1.8.0_131\bin\java.exe
     Version 8.0
     Update 131
     Build 11
  Environment Variables
   SystemRoot C:\Windows
     TEMP C:\ s\ \AppData\Local\Temp
     TMP C:\ s\ \AppData\Local\Temp
    Machine Variables
     ComSpec C:\Windows\system32\cmd.exe
     OS Windows_NT
     Path C:\ProgramData\Oracle\Java\javapath
     C:\Program Files (x86)\Skype\Phone\
     PROCESSOR_IDENTIFIER Intel64 6 Model 26 Stepping 5, GenuineIntel
     PSModulePath C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
     TEMP C:\Windows\TEMP
     TMP C:\Windows\TEMP
     windir C:\Windows
  Power Profile
   Active power scheme Balanced
   Hibernation Enabled
   Turn Off Monitor after: (On AC Power) Never
   Turn Off Hard Disk after: (On AC Power) Never
   Suspend after: (On AC Power) 180 min
   Screen saver Disabled
    Current Session
     Current Time 14/07/2017 12:16:49 AM
     Current Uptime 2,027 sec (0 d, 00 h, 33 m, 47 s)
     Last Boot Time 13/07/2017 11:43:02 PM
   Running Application Information
   Running Base Filtering Engine
   Running COM+ Event System
   Running Cryptographic Services
   Running DCOM Server Process Launcher
   Running Desktop Window Manager Session Manager
   Running DHCP Client
   Running Diagnostic Policy Service
   Running Diagnostic Service Host
   Running Diagnostics Tracking Service
   Running DNS Client
   Running Group Policy Client
   Running IKE and AuthIP IPsec Keying Modules
   Running IPsec Policy Agent
   Running Multimedia Class Scheduler
   Running Network Connections
   Running Network List Service
   Running Network Location Awareness
   Running Network Store Interface Service
   Running NVIDIA Display Driver Service
   Running Peer Name Resolution Protocol
   Running Peer Networking Identity Manager
   Running Plug and Play
   Running Power
   Running Print Spooler
   Running Program Compatibility Assistant Service
   Running Remote Procedure Call (RPC)
   Running RPC Endpoint Mapper
   Running Security Accounts Manager
   Running Security Center
   Running Superfetch
   Running System Event Notification Service
   Running Task Scheduler
   Running TCP/IP NetBIOS Helper
   Running Themes
   Running  Profile Service
   Running Windows Audio
   Running Windows Audio Endpoint Builder
   Running Windows Defender
   Running Windows Driver Foundation - -mode Driver Framework
   Running Windows Event Log
   Running Windows Firewall
   Running Windows Font Cache Service
   Running Windows Management Instrumentation
   Running Windows Update
   Running WMI Performance Adapter
   Stopped ActiveX Installer (AxInstSV)
   Stopped Adaptive Brightness
   Stopped Application Experience
   Stopped Application Identity
   Stopped Application Layer Gateway Service
   Stopped Application Management
   Stopped Background Intelligent Transfer Service
   Stopped BitLocker Drive Encryption Service
   Stopped Block Level Backup Engine Service
   Stopped Bluetooth Support Service
   Stopped BranchCache
   Stopped Certificate Propagation
   Stopped CNG Key Isolation
   Stopped COM+ System Application
   Stopped Computer Browser
   Stopped Credential Manager
   Stopped Diagnostic System Host
   Stopped Disk Defragmenter
   Stopped Distributed Link Tracking Client
   Stopped Distributed Transaction Coordinator
   Stopped Encrypting File System (EFS)
   Stopped Extensible Authentication Protocol
   Stopped Fax
   Stopped Function Discovery Provider Host
   Stopped Function Discovery Resource Publication
   Stopped Google Update Service (gupdate)
   Stopped Google Update Service (gupdatem)
   Stopped Health Key and Certificate Management
   Stopped HomeGroup Listener
   Stopped HomeGroup Provider
   Stopped Human Interface Device Access
   Stopped Interactive Services Detection
   Stopped Internet Connection Sharing (ICS)
   Stopped Internet Explorer ETW Collector Service
   Stopped IP Helper
   Stopped KtmRm for Distributed Transaction Coordinator
   Stopped Link-Layer Topology Discovery Mapper
   Stopped LVSrvLauncher
   Stopped Media Center Extender Service
   Stopped Microsoft .NET Framework NGEN v2.0.50727_X64
   Stopped Microsoft .NET Framework NGEN v2.0.50727_X86
   Stopped Microsoft iSCSI Initiator Service
   Stopped Microsoft Office Diagnostics Service
   Stopped Microsoft Office Groove Audit Service
   Stopped Microsoft Software Shadow Copy Provider
   Stopped Net.Msmq Listener Adapter
   Stopped Net.Pipe Listener Adapter
   Stopped Net.Tcp Listener Adapter
   Stopped Net.Tcp Port Sharing Service
   Stopped Netlogon
   Stopped Network Access Protection Agent
   Stopped NVIDIA Telemetry Container
   Stopped Office Source Engine
   Stopped Offline Files
   Stopped Parental Controls
   Stopped Peer Networking Grouping
   Stopped Performance Counter DLL Host
   Stopped Performance Logs & Alerts
   Stopped PnP-X IP Bus Enumerator
   Stopped PNRP Machine Name Publication Service
   Stopped Portable Device Enumerator Service
   Stopped Problem Reports and Solutions Control Panel Support
   Stopped Protected Storage
   Stopped Quality Windows Audio Video Experience
   Stopped Remote Access Auto Connection Manager
   Stopped Remote Access Connection Manager
   Stopped Remote Desktop Configuration
   Stopped Remote Desktop Services
   Stopped Remote Desktop Services Mode Port Redirector
   Stopped Remote Procedure Call (RPC) Locator
   Stopped Remote Registry
   Stopped Routing and Remote Access
   Stopped Secondary Logon
   Stopped Secure Socket Tunneling Protocol Service
   Stopped Server
   Stopped Shell Hardware Detection
   Stopped Skype Updater
   Stopped Smart Card
   Stopped Smart Card Removal Policy
   Stopped SNMP Trap
   Stopped Software Protection
   Stopped SPP Notification Service
   Stopped SSDP Discovery
   Stopped Storage Service
   Stopped Tablet PC Input Service
   Stopped Telephony
   Stopped Thread Ordering Server
   Stopped TPM Base Services
   Stopped UPnP Device Host
   Stopped Virtual Disk
   Stopped Volume Shadow Copy
   Stopped WebClient
   Stopped Windows Backup
   Stopped Windows Biometric Service
   Stopped Windows CardSpace
   Stopped Windows Color System
   Stopped Windows Connect Now - Config Registrar
   Stopped Windows Error Reporting Service
   Stopped Windows Event Collector
   Stopped Windows Image Acquisition (WIA)
   Stopped Windows Installer
   Stopped Windows Media Center Receiver Service
   Stopped Windows Media Center Scheduler Service
   Stopped Windows Media Player Network Sharing Service
   Stopped Windows Modules Installer
   Stopped Windows Presentation Foundation Font Cache
   Stopped Windows Remote Management (WS-Management)
   Stopped Windows Search
   Stopped Windows Time
   Stopped WinHTTP Web Proxy Auto-Discovery Service
   Stopped Wired AutoConfig
   Stopped WLAN AutoConfig
   Stopped Workstation
   Stopped WWAN AutoConfig
   TimeZone GMT +10:00 Hours
   Language English (Australia)
   Location Australia
   Format English (Australia)
   Currency $
   Date Format d/MM/yyyy
   Time Format h:mm:ss tt
   14/07/2017 12:19 AM; GoogleUpdateTaskMachineUA
   14/07/2017 10:19 PM; GoogleUpdateTaskMachineCore
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB2984972)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB2705219)
       A security issue has been identified that could allow an unauthenticated
       remote attacker to compromise your system and gain control over
       it. You can help protect your system by installing this update
       from Microsoft. After you install this update, you may have to
       restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB3004375)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB2491683)
       A security issue has been identified that could allow an unauthenticated
       remote attacker to compromise your system and gain control over
       it. You can help protect your system by installing this update
       from Microsoft. After you install this update, you may have to
       restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB2654428)
       A security issue has been identified that could allow an unauthenticated
       remote attacker to compromise your system and gain control over
       it. You can help protect your system by installing this update
       from Microsoft. After you install this update, you may have to
       restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB3004361)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB3108371)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB2813430)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64 (KB3135983)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB2892074)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB2973351)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB2564958)
       A security issue has been identified that could allow an unauthenticated
       remote attacker to compromise your system and gain control over
       it. You can help protect your system by installing this update
       from Microsoft. After you install this update, you may have to
       restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB3045685)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2836943)
       Install this update to resolve issues in Windows. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article for more information.
       After you install this item, you may have to restart your computer.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB2698365)
       A security issue has been identified that could allow an unauthenticated
       remote attacker to compromise your system and gain control over
       it. You can help protect your system by installing this update
       from Microsoft. After you install this update, you may have to
       restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB3031432)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2736422)
       A security issue has been identified that could allow an unauthenticated
       remote attacker to cause the affected application to stop responding.
       You can help protect your system by installing this update from
       Microsoft. After you install this update, you may have to restart
       your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB3156019)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB2862152)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Security Update for Windows 7 for x64-based Systems (KB3035126)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2943357)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB3097989)
       A security issue has been identified in a Microsoft software
       product that could affect your system. You can help protect your
       system by installing this update from Microsoft. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article. After you install
       this update, you may have to restart your system.
      15/04/2017  Windows Update Agent 7.6.7600.320
       The Windows Update Agent enables your computer to search for
       and install updates from an update service. The agent can automatically
       update itself as needed to communicate with the update service
       when Windows searches for new updates.
      15/04/2017  Definition Update for Windows Defender - KB915597 (Definition 1.239.1412.0)
       Install this update to revise the definition files used to detect
       spyware and other potentially unwanted software. Once you have
       installed this item, it cannot be removed.
      15/04/2017  Windows 7 Service Pack 1 for x64-based Systems (KB976932)
       Windows 7 Service Pack 1 is a recommended collection of updates
       and improvements to Windows that are combined into a single installable
       update. The service pack can help make your computer safer and
       more reliable. A typical installation will take about 30 minutes
       to complete, and you will have to restart your computer about
       halfway through the process.
      15/04/2017  Windows 7 Service Pack 1 for x64-based Systems (KB976932)
       Windows 7 Service Pack 1 is a recommended collection of updates
       and improvements to Windows that are combined into a single installable
       update. The service pack can help make your computer safer and
       more reliable. A typical installation will take about 30 minutes
       to complete, and you will have to restart your computer about
       halfway through the process.
      15/04/2017  Update for Windows 7 for x64-based Systems (KB3163589)
       Install this update to resolve issues in Windows. For a complete
       listing of the issues that are included in this update, see the
       associated Microsoft Knowledge Base article for more information.
       After you install this item, you may have to restart your computer.
      15/04/2017  Update Rollup for ActiveX Killbits for Windows 7 for x64-based Systems (KB2562937)
       Security issues have been identified in ActiveX controls that
       could allow an attacker to compromise a system running Microsoft
       Internet Explorer and gain control over it. You can help protect
       your system by installing this update from Microsoft. After you
       install this item, you may have to restart your computer.
      15/04/2017  Windows Update Agent 7.6.7600.256
       The Windows Update Agent enables your computer to search for
       and install updates from an update service. The agent can automatically
       update itself as needed to communicate with the update service
       when Windows searches for new updates.
    Not Installed
  System Folders
   Application Data C:\ProgramData
   Cookies C:\ s\ \AppData\Roaming\Microsoft\Windows\Cookies
   Desktop C:\ s\ \Desktop
   Documents C:\ s\Public\Documents
   Fonts C:\Windows\Fonts
   Global Favorites C:\ s\ \Favorites
   Internet History C:\ s\ \AppData\Local\Microsoft\Windows\History
   Local Application Data C:\ s\ \AppData\Local
   Music C:\ s\Public\Music
   Path for burning CD C:\ s\ \AppData\Local\Microsoft\Windows\Burn\Burn
   Physical Desktop C:\ s\ \Desktop
   Pictures C:\ s\Public\Pictures
   Program Files C:\Program Files
   Public Desktop C:\ s\Public\Desktop
   Start Menu C:\ProgramData\Microsoft\Windows\Start Menu
   Start Menu Programs C:\ProgramData\Microsoft\Windows\Start Menu\Programs
   Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
   Templates C:\ProgramData\Microsoft\Windows\Templates
   Temporary Internet Files C:\ s\ \AppData\Local\Microsoft\Windows\Temporary Internet Files
    Favorites C:\ s\ \Favorites
   Videos C:\ s\Public\Videos
   Windows Directory C:\Windows
   Windows/System C:\Windows\system32
  Process List
     Process ID 2228
     Domain NT AUTHORITY
     Memory Usage 17 MB
     Peak Memory Usage 17 MB
     Process ID 864
     Path C:\Windows\system32\cmd.exe
     Memory Usage 3.58 MB
     Peak Memory Usage 3.59 MB
     Process ID 1292
     Path C:\Windows\system32\conhost.exe
     Memory Usage 6.63 MB
     Peak Memory Usage 6.70 MB
     Process ID 436
     Domain NT AUTHORITY
     Path C:\Windows\system32\csrss.exe
     Memory Usage 4.46 MB
     Peak Memory Usage 8.91 MB
     Process ID 552
     Domain NT AUTHORITY
     Path C:\Windows\system32\csrss.exe
     Memory Usage 9.60 MB
     Peak Memory Usage 18 MB
     Process ID 3388
     Domain NT AUTHORITY
     Path C:\Windows\system32\DllHost.exe
     Memory Usage 6.72 MB
     Peak Memory Usage 6.72 MB
     Process ID 3440
     Domain NT AUTHORITY
     Path C:\Windows\system32\DllHost.exe
     Memory Usage 5.88 MB
     Peak Memory Usage 5.88 MB
     Process ID 1840
     Path C:\Windows\system32\Dwm.exe
     Memory Usage 31 MB
     Peak Memory Usage 46 MB
     Process ID 1920
     Path C:\Windows\Explorer.EXE
     Memory Usage 93 MB
     Peak Memory Usage 100 MB
     Process ID 2284
     Path C:\Windows\system32\Macromed\Flash\FlashUtil64_26_0_0_131_ActiveX.exe
     Memory Usage 11 MB
     Peak Memory Usage 11 MB
     Process ID 2812
     Path C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
     Memory Usage 71 MB
     Peak Memory Usage 71 MB
     Process ID 2252
     Domain  -PC
     Path C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
     Memory Usage 118 MB
     Peak Memory Usage 120 MB
     Process ID 2008
     Domain  -PC
     Path C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
     Memory Usage 196 MB
     Peak Memory Usage 221 MB
     Process ID 2536
     Domain  -PC
     Path C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
     Memory Usage 71 MB
     Peak Memory Usage 71 MB
     Process ID 2888
     Domain  -PC
     Path C:\Program Files\Internet Explorer\iexplore.exe
     Memory Usage 59 MB
     Peak Memory Usage 66 MB
     Process ID 1636
     Domain  -PC
     Path C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
     Memory Usage 244 MB
     Peak Memory Usage 289 MB
     Process ID 604
     Domain NT AUTHORITY
     Path C:\Windows\system32\lsass.exe
     Memory Usage 15 MB
     Peak Memory Usage 15 MB
     Process ID 612
     Domain NT AUTHORITY
     Path C:\Windows\system32\lsm.exe
     Memory Usage 4.67 MB
     Peak Memory Usage 4.67 MB
     Process ID 880
     Domain  -PC
     Path C:\Windows\System32\MsSpellCheckingFacility.exe
     Memory Usage 8.95 MB
     Peak Memory Usage 9.02 MB
     Process ID 2496
     Domain  -PC
     Path C:\Windows\system32\notepad.exe
     Memory Usage 7.50 MB
     Peak Memory Usage 7.77 MB
     Process ID 832
     Domain NT AUTHORITY
     Path C:\Windows\system32\nvvsvc.exe
     Memory Usage 8.57 MB
     Peak Memory Usage 8.58 MB
     Process ID 1196
     Domain NT AUTHORITY
     Path C:\Windows\system32\nvvsvc.exe
     Memory Usage 15 MB
     Peak Memory Usage 15 MB
     Process ID 1188
     Domain NT AUTHORITY
     Path C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
     Memory Usage 23 MB
     Peak Memory Usage 23 MB
     Process ID 1240
     Domain  -PC
     Path C:\ s\ \Desktop\procexp.exe
     Memory Usage 7.39 MB
     Peak Memory Usage 7.41 MB
     Process ID 2788
     Domain  -PC
     Path C:\ s\ \AppData\Local\Temp\procexp64.exe
     Memory Usage 45 MB
     Peak Memory Usage 54 MB
     Process ID 584
     Domain NT AUTHORITY
     Path C:\Windows\system32\services.exe
     Memory Usage 11 MB
     Peak Memory Usage 11 MB
     Process ID 276
     Domain NT AUTHORITY
     Path \SystemRoot\System32\smss.exe
     Memory Usage 1.40 MB
     Peak Memory Usage 1.44 MB
     Process ID 1236
     Domain  -PC
     Path C:\Program Files\Speccy\Speccy64.exe
     Memory Usage 29 MB
     Peak Memory Usage 29 MB
     Process ID 1344
     Domain NT AUTHORITY
     Path C:\Windows\System32\spoolsv.exe
     Memory Usage 13 MB
     Peak Memory Usage 13 MB
     Process ID 760
     Domain NT AUTHORITY
     Path C:\Windows\system32\svchost.exe
     Memory Usage 11 MB
     Peak Memory Usage 11 MB
     Process ID 964
     Domain NT AUTHORITY
     Path C:\Windows\System32\svchost.exe
     Memory Usage 18 MB
     Peak Memory Usage 18 MB
     Process ID 1004
     Domain NT AUTHORITY
     Path C:\Windows\System32\svchost.exe
     Memory Usage 111 MB
     Peak Memory Usage 111 MB
     Process ID 152
     Domain NT AUTHORITY
     Path C:\Windows\system32\svchost.exe
     Memory Usage 14 MB
     Peak Memory Usage 14 MB
     Process ID 328
     Domain NT AUTHORITY
     Path C:\Windows\system32\svchost.exe
     Memory Usage 37 MB
     Peak Memory Usage 37 MB
     Process ID 1100
     Domain NT AUTHORITY
     Path C:\Windows\system32\svchost.exe
     Memory Usage 26 MB
     Peak Memory Usage 27 MB
     Process ID 1372
     Domain NT AUTHORITY
     Path C:\Windows\system32\svchost.exe
     Memory Usage 13 MB
     Peak Memory Usage 41 MB
     Process ID 1432
     Domain NT AUTHORITY
     Path C:\Windows\System32\svchost.exe
     Memory Usage 8.46 MB
     Peak Memory Usage 8.46 MB
     Process ID 872
     Domain NT AUTHORITY
     Path C:\Windows\system32\svchost.exe
     Memory Usage 8.87 MB
     Peak Memory Usage 8.93 MB
     Process ID 3344
     Domain NT AUTHORITY
     Path C:\Windows\System32\svchost.exe
     Memory Usage 7.38 MB
     Peak Memory Usage 7.38 MB
     Process ID 2380
     Domain NT AUTHORITY
     Path C:\Windows\system32\svchost.exe
     Memory Usage 6.05 MB
     Peak Memory Usage 6.09 MB
     Process ID 2744
     Domain NT AUTHORITY
     Path C:\Windows\System32\svchost.exe
     Memory Usage 9.27 MB
     Peak Memory Usage 65 MB
     Process ID 4
     Memory Usage 304 KB
     Peak Memory Usage 13 MB
    System Idle Process
     Process ID 0
     Process ID 1744
     Domain  -PC
     Path C:\Windows\system32\taskhost.exe
     Memory Usage 20 MB
     Peak Memory Usage 26 MB
     Process ID 1788
     Domain  -PC
     Path C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
     Memory Usage 6.13 MB
     Peak Memory Usage 6.16 MB
     Process ID 528
     Domain NT AUTHORITY
     Path C:\Windows\system32\wininit.exe
     Memory Usage 5.12 MB
     Peak Memory Usage 5.21 MB
     Process ID 736
     Domain NT AUTHORITY
     Path C:\Windows\system32\winlogon.exe
     Memory Usage 8.20 MB
     Peak Memory Usage 9.48 MB
     Process ID 3812
     Domain NT AUTHORITY
     Path C:\Windows\system32\wbem\WmiApSrv.exe
     Memory Usage 6.89 MB
     Peak Memory Usage 6.89 MB
     Process ID 2732
     Domain NT AUTHORITY
     Path C:\Windows\system32\wbem\wmiprvse.exe
     Memory Usage 26 MB
     Peak Memory Usage 26 MB
     Process ID 3204
     Domain NT AUTHORITY
     Path C:\Windows\system32\wbem\wmiprvse.exe
     Memory Usage 15 MB
     Peak Memory Usage 15 MB
     Process ID 3996
     Domain NT AUTHORITY
     Path C:\Windows\system32\wbem\wmiprvse.exe
     Memory Usage 9.80 MB
     Peak Memory Usage 10 MB
     Process ID 2996
     Domain  -PC
     Path C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
     Memory Usage 30 MB
     Peak Memory Usage 38 MB
  Security Options
   Accounts: Administrator account status Disabled
   Accounts: Guest account status Disabled
   Accounts: Limit local account use of blank passwords to console logon only Enabled
   Accounts: Rename administrator account Administrator
   Accounts: Rename guest account Guest
   Audit: Audit the access of global system objects Disabled
   Audit: Audit the use of Backup and Restore privilege Disabled
   Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings Not Defined
   Audit: Shut down system immediately if unable to log security audits Disabled
   DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax Not Defined
   DCOM: Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) syntax Not Defined
   Devices: Allow undock without having to log on Enabled
   Devices: Allowed to format and eject removable media Not Defined
   Devices: Prevent s from installing printer drivers Disabled
   Devices: Restrict CD-ROM access to locally logged-on only Not Defined
   Devices: Restrict floppy access to locally logged-on only Not Defined
   Domain controller: Allow server operators to schedule tasks Not Defined
   Domain controller: LDAP server signing requirements Not Defined
   Domain controller: Refuse machine account password changes Not Defined
   Domain member: Digitally encrypt or sign secure channel data (always) Enabled
   Domain member: Digitally encrypt secure channel data (when possible) Enabled
   Domain member: Digitally sign secure channel data (when possible) Enabled
   Domain member: Disable machine account password changes Disabled
   Domain member: Maximum machine account password age 30 days
   Domain member: Require strong (Windows 2000 or later) session key Enabled
   Interactive logon: Display information when the session is locked Not Defined
   Interactive logon: Do not display last name Disabled
   Interactive logon: Do not require CTRL+ALT+DEL Not Defined
   Interactive logon: Message text for s attempting to log on
   Interactive logon: Message title for s attempting to log on
   Interactive logon: Number of previous logons to cache (in case domain controller is not available) 10 logons
   Interactive logon: Prompt to change password before expiration 5 days
   Interactive logon: Require Domain Controller authentication to unlock workstation Disabled
   Interactive logon: Require smart card Disabled
   Interactive logon: Smart card removal behavior No Action
   Microsoft network client: Digitally sign communications (always) Disabled
   Microsoft network client: Digitally sign communications (if server agrees) Enabled
   Microsoft network client: Send unencrypted password to third-party SMB servers Disabled
   Microsoft network server: Amount of idle time required before suspending session 15 minutes
   Microsoft network server: Digitally sign communications (always) Disabled
   Microsoft network server: Digitally sign communications (if client agrees) Disabled
   Microsoft network server: Disconnect clients when logon hours expire Enabled
   Microsoft network server: Server SPN target name validation level Not Defined
   Network access: Allow anonymous SID/Name translation Disabled
   Network access: Do not allow anonymous enumeration of SAM accounts Enabled
   Network access: Do not allow anonymous enumeration of SAM accounts and shares Disabled
   Network access: Do not allow storage of passwords and credentials for network authentication Disabled
   Network access: Let Everyone permissions apply to anonymous s Disabled
   Network access: Named Pipes that can be accessed anonymously
   Network access: Remotely accessible registry paths System\CurrentControlSet\Control\ProductOptions,System\CurrentControlSet\Control\Server Applications,Software\Microsoft\Windows NT\CurrentVersion
   Network access: Remotely accessible registry paths and sub-paths System\CurrentControlSet\Control\Print\Printers,System\CurrentControlSet\Services\Eventlog,Software\Microsoft\OLAP Server,Software\Microsoft\Windows NT\CurrentVersion\Print,Software\Microsoft\Windows NT\CurrentVersion\Windows,System\CurrentControlSet\Control\ContentIndex,System\CurrentControlSet\Control\Terminal Server,System\CurrentControlSet\Control\Terminal Server\ Config,System\CurrentControlSet\Control\Terminal Server\Default Configuration,Software\Microsoft\Windows NT\CurrentVersion\Perflib,System\CurrentControlSet\Services\SysmonLog
   Network access: Restrict anonymous access to Named Pipes and Shares Enabled
   Network access: Shares that can be accessed anonymously Not Defined
   Network access: Sharing and security model for local accounts Classic - local s authenticate as themselves
   Network security: Allow Local System to use computer identity for NTLM Not Defined
   Network security: Allow LocalSystem NULL session fallback Not Defined
   Network Security: Allow PKU2U authentication requests to this computer to use online identities Not Defined
   Network security: Configure encryption types allowed for Kerberos Not Defined
   Network security: Do not store LAN Manager hash value on next password change Enabled
   Network security: Force logoff when logon hours expire Disabled
   Network security: LAN Manager authentication level Not Defined
   Network security: LDAP client signing requirements Negotiate signing
   Network security: Minimum session security for NTLM SSP based (including secure RPC) clients Require 128-bit encryption
   Network security: Minimum session security for NTLM SSP based (including secure RPC) servers Require 128-bit encryption
   Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication Not Defined
   Network security: Restrict NTLM: Add server exceptions in this domain Not Defined
   Network security: Restrict NTLM: Audit Incoming NTLM Traffic Not Defined
   Network security: Restrict NTLM: Audit NTLM authentication in this domain Not Defined
   Network security: Restrict NTLM: Incoming NTLM traffic Not Defined
   Network security: Restrict NTLM: NTLM authentication in this domain Not Defined
   Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers Not Defined
   Recovery console: Allow automatic administrative logon Disabled
   Recovery console: Allow floppy copy and access to all drives and all folders Disabled
   Shutdown: Allow system to be shut down without having to log on Enabled
   Shutdown: Clear virtual memory pagefile Disabled
   System cryptography: Force strong key protection for keys stored on the computer Not Defined
   System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing Disabled
   System objects: Require case insensitivity for non-Windows subsystems Enabled
   System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links) Enabled
   System settings: Optional subsystems Posix
   System settings: Use Certificate Rules on Windows Executables for Software Restriction Policies Disabled
    Account Control: Admin Approval Mode for the Built-in Administrator account Disabled
    Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop Disabled
    Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode Prompt for consent for non-Windows binaries
    Account Control: Behavior of the elevation prompt for standard s Prompt for credentials
    Account Control: Detect application installations and prompt for elevation Enabled
    Account Control: Only elevate executables that are signed and validated Disabled
    Account Control: Only elevate UIAccess applications that are installed in secure locations Enabled
    Account Control: Run all administrators in Admin Approval Mode Enabled
    Account Control: Switch to the secure desktop when prompting for elevation Enabled
    Account Control: Virtualize file and registry write failures to per- locations Enabled
  Device Tree
    ACPI x64-based PC
      Microsoft ACPI-Compliant System
       ACPI Fixed Feature Button
       ACPI Power Button
       Intel Core i7 CPU 975 @ 3.33GHz
       Intel Core i7 CPU 975 @ 3.33GHz
       Intel Core i7 CPU 975 @ 3.33GHz
       Intel Core i7 CPU 975 @ 3.33GHz
       Intel Core i7 CPU 975 @ 3.33GHz
       Intel Core i7 CPU 975 @ 3.33GHz
       Intel Core i7 CPU 975 @ 3.33GHz
       Intel Core i7 CPU 975 @ 3.33GHz
       System board
        PCI bus
         Intel 5520/5500/X58 I/O Hub Control Status and RAS Registers - 3423
         Intel 5520/5500/X58 I/O Hub GPIO and Scratch Pad Registers - 3422
         Intel 5520/5500/X58 I/O Hub System Management Registers - 342E
         Intel 5520/5500/X58 I/O Hub Throttle Registers - 3438
         Intel 5520/5500/X58 I/O Hub to ESI Port - 3405
         Intel 82801 PCI Bridge - 244E
         Intel ICH10 PCI Express Root Port 1 - 3A40
         Intel ICH10 SMBus Controller - 3A30
         Microsoft Windows Management Interface for ACPI
         Motherboard resources
         System board
          Intel® 5520/5500/X58 I/O Hub PCI Express Root Port 1 - 3408
            NVIDIA GeForce 8400 GS   
             Generic Non-PnP Monitor
          Intel® 5520/5500/X58 I/O Hub PCI Express Root Port 3 - 340A
            PCI standard PCI-to-PCI bridge
             PCI standard PCI-to-PCI bridge
             PCI standard PCI-to-PCI bridge
              PCI standard PCI-to-PCI bridge
                PCI standard PCI-to-PCI bridge
                 ASUS Xonar Essence STX Audio Device
          Intel® 5520/5500/X58 I/O Hub PCI Express Root Port 7 - 340E
            NVIDIA GeForce GTX 480
             Hitachi CM811
            High Definition Audio Controller
             High Definition Audio Device
             High Definition Audio Device
             High Definition Audio Device
             High Definition Audio Device
          Intel® ICH10 USB Universal Host Controller - 3A37
           USB Root Hub
          Intel® ICH10 USB Universal Host Controller - 3A38
           USB Root Hub
          Intel® ICH10 USB Universal Host Controller - 3A39
           USB Root Hub
          Intel® ICH10 USB Enhanced Host Controller - 3A3C
           USB Root Hub
          High Definition Audio Controller
           High Definition Audio Device
          Intel® ICH10 PCI Express Root Port 2 - 3A42
           Realtek RTL8168C(P)/8111C(P) PCI-E Gigabit Ethernet NIC (NDIS 6.20) #2
          Intel® ICH10 PCI Express Root Port 3 - 3A44
           Realtek RTL8168C(P)/8111C(P) PCI-E Gigabit Ethernet NIC (NDIS 6.20)
          Intel® ICH10 PCI Express Root Port 4 - 3A46
            Standard Dual Channel PCI IDE Controller
             ATA Channel 0
             ATA Channel 1
          Intel® ICH10 PCI Express Root Port 5 - 3A48
            Marvell 64xx/63xx SAS Controller
             Generic SCSI Array Device
             SEAGATE ST3450856SS SCSI Disk Device
          Intel® ICH10 USB Universal Host Controller - 3A34
            USB Root Hub
              USB Composite Device
                USB Input Device
                 HID-compliant mouse
                USB Input Device
                 HID Keyboard Device
                 HID-compliant consumer control device
                 HID-compliant device
                 HID-compliant device
              Logitech USB Camera (Pro 4000)
               Logitech Microphone (Pro 4000)
               Logitech QuickCam Pro 4000
          Intel® ICH10 USB Universal Host Controller - 3A35
           USB Root Hub
          Intel® ICH10 USB Universal Host Controller - 3A36
            USB Root Hub
              USB Printing Support
               HP DeskJet 950C/952C/959C
          Intel® ICH10 USB Enhanced Host Controller - 3A3A
           USB Root Hub
          Intel® ICH10R LPC Interface Controller - 3A16
           ATK0110 ACPI UTILITY
           Direct memory access controller
           High Precision Event Timer
           Intel 82802 Firmware Hub Device
           Motherboard resources
           Motherboard resources
           Motherboard resources
           Motherboard resources
           Numeric data processor
           Programmable interrupt controller
           Standard PS/2 Keyboard
           System CMOS/real time clock
           System speaker
           System timer
          Intel® ICH10 4 port Serial ATA Storage Controller 1 - 3A20
           ATA Channel 0
            ATA Channel 1
             PIONEER BD-RW BDR-205 ATA Device
             WDC WD2002FAEX-007BA0 ATA Device
          Intel® ICH10 2 port Serial ATA Storage Controller 2 - 3A26
           ATA Channel 0
            ATA Channel 1
             WDC WD1003FBYX-01Y7B0 ATA Device
  Intel Core i7 Extreme 975
   Cores 4
   Threads 8
   Name Intel Core i7 Extreme 975
   Code Name Bloomfield
   Package Socket 1366 LGA
   Technology 45nm
   Specification Intel Core i7 CPU 975 @ 3.33GHz
   Extended  6
   Model A
   Extended Model 1A
   Stepping 5
   Revision D0
   Instructions MMX, SSE, SSE2, SSE3, SSSE3, SSE4.1, SSE4.2, Intel 64, NX, VMX
   Virtualization Supported, Enabled
   Hyperthreading Supported, Enabled
   Fan Speed 1721 RPM
   Bus Speed 133.6 MHz
   Rated Bus Speed 3207.0 MHz
   Stock Core Speed 3333 MHz
   Stock Bus Speed 133 MHz
   Average Temperature 50 °C
     L1 Data Cache Size 4 x 32 KBytes
     L1 Instructions Cache Size 4 x 32 KBytes
     L2 Unified Cache Size 4 x 256 KBytes
     L3 Unified Cache Size 8192 KBytes
      Core 0
       Core Speed 1603.5 MHz
       Multiplier x 12.0
       Bus Speed 133.6 MHz
       Rated Bus Speed 3207.0 MHz
       Temperature 51 °C
       Threads APIC ID: 0, 1
      Core 1
       Core Speed 1603.5 MHz
       Multiplier x 12.0
       Bus Speed 133.6 MHz
       Rated Bus Speed 3207.0 MHz
       Temperature 49 °C
       Threads APIC ID: 2, 3
      Core 2
       Core Speed 1603.5 MHz
       Multiplier x 12.0
       Bus Speed 133.6 MHz
       Rated Bus Speed 3207.0 MHz
       Temperature 51 °C
       Threads APIC ID: 4, 5
      Core 3
       Core Speed 1603.5 MHz
       Multiplier x 12.0
       Bus Speed 133.6 MHz
       Rated Bus Speed 3207.0 MHz
       Temperature 49 °C
       Threads APIC ID: 6, 7
  Memory slots
   Total memory slots 6
   Used memory slots 3
   Free memory slots 3
   Type DDR3
   Size 6144 MBytes
   Channels # Triple
   DRAM Frequency 668.1 MHz
   CAS# Latency (CL) 9 clocks
   RAS# to CAS# Delay (tRCD) 9 clocks
   RAS# Precharge (tRP) 9 clocks
   Cycle Time (tRAS) 24 clocks
   Command Rate (CR) 1T
  Physical Memory
   Memory Usage 30 %
   Total Physical 5.99 GB
   Available Physical 4.13 GB
   Total Virtual 15 GB
   Available Virtual 13 GB
   Number Of SPD Modules 3
    Slot #1
     Type DDR3
     Size 2048 MBytes
     Manufacturer G.Skill
     Max Bandwidth PC3-10700H (667 MHz)
     Part Number F3-10666CL7-2GBPK
     SPD Ext. XMP
      Timing table
        JEDEC #1
         Frequency 444.4 MHz
         CAS# Latency 6.0
         RAS# To CAS# 6
         RAS# Precharge 6
         tRAS 16
         tRC 22
         Voltage 1.500 V
        JEDEC #2
         Frequency 518.5 MHz
         CAS# Latency 7.0
         RAS# To CAS# 7
         RAS# Precharge 7
         tRAS 19
         tRC 26
         Voltage 1.500 V
        JEDEC #3
         Frequency 592.6 MHz
         CAS# Latency 8.0
         RAS# To CAS# 8
         RAS# Precharge 8
         tRAS 22
         tRC 30
         Voltage 1.500 V
        JEDEC #4
         Frequency 666.7 MHz
         CAS# Latency 9.0
         RAS# To CAS# 9
         RAS# Precharge 9
         tRAS 24
         tRC 33
         Voltage 1.500 V
         Frequency 666 MHz
         CAS# Latency 7.0
         RAS# To CAS# 7
         RAS# Precharge 7
         tRAS 18
         Voltage 1.500 V
    Slot #2
     Type DDR3
     Size 2048 MBytes
     Manufacturer G.Skill
     Max Bandwidth PC3-10700H (667 MHz)
     Part Number F3-10666CL7-2GBPK
     SPD Ext. XMP
      Timing table
        JEDEC #1
         Frequency 444.4 MHz
         CAS# Latency 6.0
         RAS# To CAS# 6
         RAS# Precharge 6
         tRAS 16
         tRC 22
         Voltage 1.500 V
        JEDEC #2
         Frequency 518.5 MHz
         CAS# Latency 7.0
         RAS# To CAS# 7
         RAS# Precharge 7
         tRAS 19
         tRC 26
         Voltage 1.500 V
        JEDEC #3
         Frequency 592.6 MHz
         CAS# Latency 8.0
         RAS# To CAS# 8
         RAS# Precharge 8
         tRAS 22
         tRC 30
         Voltage 1.500 V
        JEDEC #4
         Frequency 666.7 MHz
         CAS# Latency 9.0
         RAS# To CAS# 9
         RAS# Precharge 9
         tRAS 24
         tRC 33
         Voltage 1.500 V
         Frequency 666 MHz
         CAS# Latency 7.0
         RAS# To CAS# 7
         RAS# Precharge 7
         tRAS 18
         Voltage 1.500 V
    Slot #3
     Type DDR3
     Size 2048 MBytes
     Manufacturer G.Skill
     Max Bandwidth PC3-10700H (667 MHz)
     Part Number F3-10666CL7-2GBPK
     SPD Ext. XMP
      Timing table
        JEDEC #1
         Frequency 444.4 MHz
         CAS# Latency 6.0
         RAS# To CAS# 6
         RAS# Precharge 6
         tRAS 16
         tRC 22
         Voltage 1.500 V
        JEDEC #2
         Frequency 518.5 MHz
         CAS# Latency 7.0
         RAS# To CAS# 7
         RAS# Precharge 7
         tRAS 19
         tRC 26
         Voltage 1.500 V
        JEDEC #3
         Frequency 592.6 MHz
         CAS# Latency 8.0
         RAS# To CAS# 8
         RAS# Precharge 8
         tRAS 22
         tRC 30
         Voltage 1.500 V
        JEDEC #4
         Frequency 666.7 MHz
         CAS# Latency 9.0
         RAS# To CAS# 9
         RAS# Precharge 9
         tRAS 24
         tRC 33
         Voltage 1.500 V
         Frequency 666 MHz
         CAS# Latency 7.0
         RAS# To CAS# 7
         RAS# Precharge 7
         tRAS 18
         Voltage 1.500 V
 Manufacturer ASUSTeK Computer INC.
 Version Rev 1.xx
 Chipset Vendor Intel
 Chipset Model X58
 Chipset Revision 13
 Southbridge Vendor Intel
 Southbridge Model 82801JR (ICH10R)
 Southbridge Revision 00
 System Temperature 47 °C
   Brand American Megatrends Inc.
   Version 0702
   Date 16/03/2010
   CPU CORE 1.208 V
   +3.3V 3.296 V
   +5V 4.896 V
   +12V 11.598 V
   VIN6 0.072 V
  PCI Data
    Slot PCI-E
     Slot Type PCI-E
     Slot Usage Available
     Bus Width 32 bit
     Slot Designation PCIEX16
     Characteristics 3.3V, Shared, PME
     Slot Number 0
    Slot PCI-E
     Slot Type PCI-E
     Slot Usage In Use
     Bus Width 32 bit
     Slot Designation PCIEX8
     Characteristics 3.3V, Shared, PME
     Slot Number 1
    Slot PCI-E
     Slot Type PCI-E
     Slot Usage In Use
     Bus Width 64 bit
     Slot Designation PCIEX16
     Characteristics 3.3V, Shared, PME
     Slot Number 2
    Slot PCI-E
     Slot Type PCI-E
     Slot Usage Available
     Bus Width 32 bit
     Slot Designation PCIEX8
     Characteristics 3.3V, Shared, PME
     Slot Number 3
    Slot PCI-E
     Slot Type PCI-E
     Slot Usage In Use
     Bus Width 32 bit
     Slot Designation PCIEX4_1
     Characteristics 3.3V, Shared, PME
     Slot Number 4
    Slot PCI
     Slot Type PCI
     Slot Usage Available
     Bus Width 32 bit
     Slot Designation PCI1
     Characteristics 3.3V, Shared, PME
     Slot Number 5
   Name CM811 on NVIDIA GeForce GTX 480
   Current Resolution 1600x1200 pixels
   Work Resolution 1600x1170 pixels
   State Enabled, Primary
   Monitor Width 1600
   Monitor Height 1200
   Monitor BPP 32 bits per pixel
   Monitor Frequency 75 Hz
   Device \\.\DISPLAY1\Monitor0
  NVIDIA GeForce 8400 GS
   Manufacturer NVIDIA
   Model GeForce 8400 GS
   GPU G98
   Device ID 10DE-06E4
   Revision A2
   Subvendor EVGA (3842)
   Current Performance Level Level 0
   Technology 65 nm
   Die Size 86 mm²
   Release Date 2008
   DirectX Support 10.0
   DirectX Shader Model 4.0
   OpenGL Support 3.0
   Bus Interface PCI Express x4
   Temperature 48 °C
   SLI Disabled
   Driver version
   BIOS Version
   ROPs 4
   Shaders 16 unified
   Memory Type DDR2
   Memory 512 MB
   Bus Width 32x2 (64 bit)
   Filtering Modes Bilinear, Trilinear, 2x Anisotropic, 4x Anisotropic, 8x Anisotropic, 16x Anisotropic
   Noise Level Quiet
   Max Power Draw 32 Watts
    Count of performance levels : 1
     Level 1 - "Perf Level 0"
  NVIDIA GeForce GTX 480
   Manufacturer NVIDIA
   Model GeForce GTX 480
   GPU GF100
   Revision A4
   Subvendor EVGA (3842)
   Current Performance Level Level 0
   Technology 40 nm
   Die Size 526 mm²
   Release Date Mar 26, 2010
   DirectX Support 11.0
   OpenGL Support 5.0
   Bus Interface PCI Express x16
   Temperature 78 °C
   SLI Disabled
   Driver version
   BIOS Version 70.00.1a.00.80
   ROPs 48
   Shaders 480 unified
   Memory Type GDDR5
   Physical Memory 1535 MB
   Virtual Memory 1536 MB
   Bus Width 64x6 (384 bit)
   Filtering Modes 16x Anisotropic
    Count of performance levels : 1
     Level 1 - "Perf Level 0"
  Hard drives
     Form Factor TB/3.5-inch (new format)
     Business Unit/Brand Desktop/WD Caviar
     Heads 16
     Cylinders 243,201
     Tracks 62,016,255
     Sectors 3,907,024,065
     SATA type SATA-III 6.0Gb/s
     Device type Fixed
     ATA Standard ATA8-ACS
     LBA Size 48-bit LBA
     Power On Count 5912 times
     Power On Time 729.8 days
     Features S.M.A.R.T., NCQ
     Max. Transfer Mode SATA III 6.0Gb/s
     Used Transfer Mode SATA II 3.0Gb/s
     Interface SATA
     Capacity 1863 GB
     Real size 2,000,398,934,016 bytes
     RAID Type None
       Status Good
       Temperature 44 °C
       Temperature Range OK (less than 50 °C)
        S.M.A.R.T attributes
           Attribute name Read Error Rate
           Real value 0
           Current 195
           Worst 192
           Threshold 51
           Raw Value 00000027FB
           Status Good
           Attribute name Spin-Up Time
           Real value 8483 ms
           Current 253
           Worst 253
           Threshold 21
           Raw Value 0000002123
           Status Good
           Attribute name Start/Stop Count
           Real value 7,083
           Current 93
           Worst 93
           Threshold 0
           Raw Value 0000001BAB
           Status Good
           Attribute name Reallocated Sectors Count
           Real value 0
           Current 200
           Worst 200
           Threshold 140
           Raw Value 0000000000
           Status Good
           Attribute name Seek Error Rate
           Real value 0
           Current 100
           Worst 253
           Threshold 0
           Raw Value 0000000000
           Status Good
           Attribute name Power-On Hours (POH)
           Real value 729d 18h
           Current 77
           Worst 77
           Threshold 0
           Raw Value 000000446A
           Status Good
           Attribute name Spin Retry Count
           Real value 0
           Current 100
           Worst 100
           Threshold 0
           Raw Value 0000000000
           Status Good
           Attribute name Recalibration Retries
           Real value 0
           Current 100
           Worst 100
           Threshold 0
           Raw Value 0000000000
           Status Good
           Attribute name Device Power Cycle Count
           Real value 5,912
           Current 95
           Worst 95
           Threshold 0
           Raw Value 0000001718
           Status Good
           Attribute name Power-off Retract Count
           Real value 2,402
           Current 197
           Worst 197
           Threshold 0
           Raw Value 0000000962
           Status Good
           Attribute name Load/Unload Cycle Count
           Real value 4,680
           Current 199
           Worst 199
           Threshold 0
           Raw Value 0000001248
           Status Good
           Attribute name Temperature
           Real value 44 °C
           Current 108
           Worst 91
           Threshold 0
           Raw Value 000000002C
           Status Good
           Attribute name Reallocation Event Count
           Real value 0
           Current 200
           Worst 200
           Threshold 0
           Raw Value 0000000000
           Status Good
           Attribute name Current Pending Sector Count
           Real value 0
           Current 200
           Worst 200
           Threshold 0
           Raw Value 0000000000
           Status Good
           Attribute name Uncorrectable Sector Count
           Real value 1
           Current 200
           Worst 200
           Threshold 0
           Raw Value 0000000001
           Status Good
           Attribute name UltraDMA CRC Error Count
           Real value 0
           Current 200
           Worst 200
           Threshold 0
           Raw Value 0000000000
           Status Good
           Attribute name Write Error Rate / Multi-Zone Error Rate
           Real value 1
           Current 200
           Worst 200
           Threshold 0
           Raw Value 0000000001
           Status Good
      Partition 0
       Partition ID Disk #0, Partition #0
       Disk Letter G:
       File System NTFS
       Size 1863 GB
       Used Space 1806 GB (96%)
       Free Space 56 GB (4%)
    WDC WD1003FBYX-01Y7B0 ATA Device
     Manufacturer Western Digital
     Form Factor TB/3.5-inch (new format)
     Business Unit/Brand Enterprise/WD RE3; WD RE2 (3-platter)
     Heads 16
     Cylinders 121,601
     Tracks 31,008,255
     Sectors 1,953,520,065
     SATA type SATA-II 3.0Gb/s
     Device type Fixed
     ATA Standard ATA8-ACS
     Firmware Version Number 01.01V01
     LBA Size 48-bit LBA
     Power On Count 7630 times
     Power On Time 1025.8 days
     Speed 7200 RPM
     Features S.M.A.R.T., APM, AAM, NCQ
     Max. Transfer Mode SATA II 3.0Gb/s
     Used Transfer Mode SATA II 3.0Gb/s
     Interface SATA
     Capacity 931 GB
     Real size 1,000,204,886,016 bytes
     RAID Type None
       Status Good
       Temperature 43 °C
       Temperature Range OK (less than 50 °C)
        S.M.A.R.T attributes
           Attribute name Read Error Rate
           Real value 0
           Current 197
           Worst 197
           Threshold 51
           Raw Value 0000001FAD
           Status Good
           Attribute name Spin-Up Time
           Real value 4200 ms
           Current 176
           Worst 171
           Threshold 21
           Raw Value 0000001068
           Status Good
           Attribute name Start/Stop Count
           Real value 9,887
           Current 91
           Worst 91
           Threshold 0
           Raw Value 000000269F
           Status Good
           Attribute name Reallocated Sectors Count
           Real value 0
           Current 200
           Worst 200
           Threshold 140
           Raw Value 0000000000
           Status Good
           Attribute name Seek Error Rate
           Real value 0
           Current 200
           Worst 200
           Threshold 0
           Raw Value 0000000000
           Status Good
           Attribute name Power-On Hours (POH)
           Real value 1025d 19h
           Current 67
           Worst 67
           Threshold 0
           Raw Value 000000602B
           Status Good
           Attribute name Spin Retry Count
           Real value 0
           Current 100
           Worst 100
           Threshold 0
           Raw Value 0000000000
           Status Good
           Attribute name Recalibration Retries
           Real value 0
           Current 100
           Worst 100
           Threshold 0
           Raw Value 0000000000
           Status Good
           Attribute name Device Power Cycle Count
           Real value 7,630
           Current 93
           Worst 93
           Threshold 0
           Raw Value 0000001DCE
           Status Good
           Attribute name Power-off Retract Count
           Real value 2,993
           Current 197
           Worst 197
           Threshold 0
           Raw Value 0000000BB1
           Status Good
           Attribute name Load/Unload Cycle Count
           Real value 6,893
           Current 198
           Worst 198
           Threshold 0
           Raw Value 0000001AED
           Status Good
           Attribute name Temperature
           Real value 43 °C
           Current 104
           Worst 85
           Threshold 0
           Raw Value 000000002B
           Status Good
           Attribute name Reallocation Event Count
           Real value 0
           Current 200
           Worst 200
           Threshold 0
           Raw Value 0000000000
           Status Good
           Attribute name Current Pending Sector Count
           Real value 12
           Current 200
           Worst 200
           Threshold 0
           Raw Value 000000000C
           Status Good
           Attribute name Uncorrectable Sector Count
           Real value 3
           Current 200
           Worst 200
           Threshold 0
           Raw Value 0000000003
           Status Good
           Attribute name UltraDMA CRC Error Count
           Real value 0
           Current 200
           Worst 200
           Threshold 0
           Raw Value 0000000000
           Status Good
           Attribute name Write Error Rate / Multi-Zone Error Rate
           Real value 834
           Current 196
           Worst 195
           Threshold 0
           Raw Value 0000000342
           Status Good
      Partition 0
       Partition ID Disk #1, Partition #0
       Disk Letter F:
       File System NTFS
       Volume Serial Number CC04EDE0
       Size 931 GB
       Used Space 922 GB (99%)
       Free Space 9.22 GB (1%)
    SEAGATE ST3450856SS SCSI Disk Device
     Interface RAID
     Capacity 419 GB
     Real size 450,098,159,616 bytes
     RAID Type Software RAID
       S.M.A.R.T not supported
      Partition 0
       Partition ID Disk #2, Partition #0
       File System NTFS
       Volume Serial Number F444C326
       Size 99 MB
       Used Space 29.7 MB (29%)
       Free Space 70 MB (71%)
      Partition 1
       Partition ID Disk #2, Partition #1
       Disk Letter C:
       File System NTFS
       Volume Serial Number D04EC916
       Size 219 GB
       Used Space 41 GB (18%)
       Free Space 178 GB (82%)
      Partition 2
       Partition ID Disk #2, Partition #2
       Disk Letter D:
       File System NTFS
       Volume Serial Number E2CB44CF
       Size 199 GB
       Used Space 169 GB (85%)
       Free Space 29.6 GB (15%)
Optical Drives
  PIONEER BD-RW   BDR-205 ATA Device
   Media Type BD Writer
   Name PIONEER BD-RW BDR-205 ATA Device
   Availability Running/Full Power
   Capabilities Random Access, Supports Writing, Supports Removable Media
   Write capabilities CD-R, CD-RW, DVD-RAM, DVD-R, DVD-RW, DVD+R, DVD+RW, DVD-R DL, DVD+R DL, BD-R, BD-RE
   Config Manager Error Code Device is working properly
   Config Manager Config FALSE
   Drive E:
   Media Loaded FALSE
   SCSI Bus 1
   SCSI Logical Unit 0
   SCSI Port 3
   SCSI Target Id 0
   Status OK
   Media Type BD Reader
   Availability Running/Full Power
   Capabilities Random Access, Supports Removable Media
   Read capabilities CD-R, CD-RW, CD-ROM, DVD-RAM, DVD-ROM, DVD-R, HD DVD-ROM, BD-ROM
   Config Manager Error Code Device is working properly
   Config Manager Config FALSE
   Drive H:
   Media Loaded FALSE
   SCSI Bus 0
   SCSI Logical Unit 0
   SCSI Port 7
   SCSI Target Id 0
   Status OK
  Sound Cards
   High Definition Audio Device
   High Definition Audio Device
   High Definition Audio Device
   ASUS Xonar Essence STX Audio Device
   High Definition Audio Device
   High Definition Audio Device
   Logitech Microphone (Pro 4000)
  Playback Device
   Speakers (ASUS Xonar Essence STX Audio Device)
  Recording Devices
   Stereo Mix (ASUS Xonar Essence STX Audio Device)
   Wave (ASUS Xonar Essence STX Audio Device)
   Microphone (2- Logitech Microphone (Pro 4000)) (default)
  Standard PS/2 Keyboard
   Device Kind Keyboard
   Device Name Standard PS/2 Keyboard
   Vendor (Standard keyboards)
   Location plugged into keyboard port
     Date 6-21-2006
     Version 6.1.7601.17514
     File C:\Windows\system32\DRIVERS\i8042prt.sys
     File C:\Windows\system32\DRIVERS\kbdclass.sys
  HID Keyboard Device
   Device Kind Keyboard
   Device Name HID Keyboard Device
   Vendor Logitech
   Location USB Input Device
     Date 6-21-2006
     Version 6.1.7601.17514
     File C:\Windows\system32\DRIVERS\kbdhid.sys
     File C:\Windows\system32\DRIVERS\kbdclass.sys
  HID-compliant mouse
   Device Kind Mouse
   Device Name HID-compliant mouse
   Vendor Logitech
   Location USB Input Device
     Date 6-21-2006
     Version 6.1.7600.16385
     File C:\Windows\system32\DRIVERS\mouhid.sys
     File C:\Windows\system32\DRIVERS\mouclass.sys
  HP DeskJet 950C/952C/959C
   Device Kind Printer
   Device Name HP DeskJet 950C/952C/959C
   Vendor HP
   Location USB Printing Support
     Date 6-21-2006
     Version 6.1.7233.0
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\HPFDJ50.INI
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\HPFUD50.DLL
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\HPFUI50.DLL
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\HPFIMG50.DLL
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\HPF900AL.DLL
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\HPFDJ950.GPD
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\HPFDJ95X.GPD
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\HPFDJ97X.GPD
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\HPFNAM50.GPD
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\UNIDRV.DLL
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\UNIRES.DLL
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\UNIDRVUI.DLL
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\STDNAMES.GPD
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\STDDTYPE.GDL
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\STDSCHEM.GDL
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\STDSCHMX.GDL
     File C:\Windows\system32\spool\DRIVERS\x64\{9945EDAA-5DCC-417F-A2BB-0DD2913B61F2}\UNIDRV.HLP
  Logitech QuickCam Pro 4000
   Device Kind Camera/scanner
   Device Name Logitech QuickCam Pro 4000
   Vendor Logitech
   Location 0000.001d.0000.
     Date 2-3-2007
     File C:\Program Files\Common Files\logishrd\WUApp64.exe
     File C:\Windows\system32\drivers\CamDrL64.sys
     File C:\Windows\syswow64\CamExL20.dll
     File C:\Windows\syswow64\msvcr71.dll
     File C:\Windows\system32\lvcod64.dll
     File C:\Windows\syswow64\lvcodec2.dll
     File C:\Windows\system32\LVUI64.dll
     File C:\Windows\system32\LVUIRC64.dll
     File C:\Windows\syswow64\LVUI2.dll
     File C:\Windows\syswow64\LVUI2RC.dll
     File C:\Windows\system32\CamExL64.ax
     File C:\Windows\syswow64\CamExL20.ax
     File C:\Windows\system32\drivers\LVUSBS64.sys
     File C:\Windows\system32\lvco1051.dll
     File C:\Windows\system32\lvcoin64.ini
     File C:\Windows\system32\Repository.reg
  Logitech Microphone (Pro 4000)
   Device Kind Audio device
   Device Name Logitech Microphone (Pro 4000)
   Vendor Logitech
   Location 0000.001d.0000.
     Date 2-3-2007
     File C:\Program Files\Common Files\logishrd\WUApp64.exe
     File C:\Windows\system32\drivers\LVUSBS64.sys
     File C:\Windows\system32\drivers\drmk.sys
     File C:\Windows\system32\drivers\portcls.sys
     File C:\Windows\system32\drivers\USBAUDIO.sys
     File C:\Windows\system32\lvco1051.dll
     File C:\Windows\system32\lvcoin64.ini
     File C:\Windows\system32\Repository.reg
     Printer Port SHRFAX:
     Print Processor winprint
     Availability Always
     Priority 1
     Duplex None
     Print Quality 200 * 200 dpi Monochrome
     Status Unknown
       Driver Name Microsoft Shared Fax Driver (v4.00)
       Driver Path C:\Windows\system32\spool\DRIVERS\x64\3\FXSDRV.DLL
    HP DeskJet 950C/952C/959C (Default Printer)
     Printer Port USB001
     Print Processor winprint
     Availability Always
     Priority 1
     Duplex None
     Print Quality 300 * 300 dpi Color
     Status Unknown
       Driver Name HP DeskJet 950C/952C/959C (v6.00)
       Driver Path C:\Windows\system32\spool\DRIVERS\x64\3\UNIDRV.DLL
    Microsoft XPS Document Writer
     Printer Port XPSPort:
     Print Processor winprint
     Availability Always
     Priority 1
     Duplex None
     Print Quality 600 * 600 dpi Color
     Status Unknown
       Driver Name Microsoft XPS Document Writer (v6.00)
       Driver Path C:\Windows\system32\spool\DRIVERS\x64\3\mxdwdrv.dll
 You are connected to the internet
 Connected through Realtek RTL8168C(P)/8111C(P) PCI-E Gigabit Ethernet NIC (NDIS 6.20) #2
 IP Address
 Subnet mask
 Gateway server
 DHCP Enabled
 DHCP server
 Adapter Type Ethernet
 NetBIOS over TCP/IP Enabled via DHCP
 NETBIOS Node Type Hybrid node
 Link Speed 0 Bps
  Computer Name
   NetBIOS Name
   DNS Name  -PC
   Membership Stand-alone
  Remote Desktop
     State Active
     Domain  -PC
  WinInet Info
   LAN Connection
   Local system uses a local area network to connect to the Internet
   Local system has RAS to connect to the Internet
  Wi-Fi Info
   Wi-Fi not enabled
   WinHTTPSessionProxyType No proxy
   Session Proxy
   Session Proxy Bypass
   Connect Retries 5
   Connect Timeout (ms) 60,000
   HTTP Version HTTP 1.1
   Max Connects Per 1.0 Servers INFINITE
   Max Connects Per Servers INFINITE
   Max HTTP automatic redirects 10
   Max HTTP status continue 10
   Send Timeout (ms) 30,000
   IEProxy Auto Detect No
   IEProxy Auto Config
   IEProxy Bypass
   Default Proxy Config Access Type No proxy
   Default Config Proxy
   Default Config Proxy Bypass
  Sharing and Discovery
   Network Discovery Disabled
   File and Printer Sharing Disabled
   File and printer sharing service Disabled
   Simple File Sharing Enabled
   Administrative Shares Enabled
   Network access: Sharing and security model for local accounts Classic - local s authenticate as themselves
  Adapters List
      Realtek RTL8168C(P)/8111C(P) PCI-E Gigabit Ethernet NIC (NDIS 6.20)
       Connection Name Local Area Connection
       DHCP enabled Yes
      Realtek RTL8168C(P)/8111C(P) PCI-E Gigabit Ethernet NIC (NDIS 6.20) #2
       Connection Name Local Area Connection 2
       NetBIOS over TCPIP Yes
       DHCP enabled Yes
       IP Address
       Subnet mask
       Gateway server
  Network Shares
   No network shares
  Current TCP Connections
    C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (1636)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local LAST-ACK Remote (Querying... ) (HTTP)
     Local LAST-ACK Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
    C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (2008)
     Local LAST-ACK Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTP)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
     Local ESTABLISHED Remote (Querying... ) (HTTPS)
    C:\Program Files\Internet Explorer\iexplore.exe (2888)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
     Local CLOSE-WAIT Remote (Querying... ) (HTTP)
    lsass.exe (604)
     Local LISTEN
    services.exe (584)
     Local LISTEN
    svchost.exe (2380)
     Local LISTEN
    svchost.exe (328)
     Local LISTEN
    svchost.exe (872)
     Local (DCE) LISTEN
    svchost.exe (964)
     Local LISTEN
    System Process
     Local TIME-WAIT Remote (Querying... ) (HTTP)
     Local TIME-WAIT Remote (Querying... ) (HTTP)
     Local TIME-WAIT Remote (Querying... ) (HTTP)
     Local TIME-WAIT Remote (Querying... ) (HTTP)
     Local TIME-WAIT Remote (Querying... ) (HTTP)
     Local TIME-WAIT Remote (Querying... ) (HTTP)
     Local TIME-WAIT Remote (Querying... ) (HTTP)
    System Process
     Local (NetBIOS session service) LISTEN
    wininit.exe (528)
     Local LISTEN
Generated with Speccy v1.31.732

Edited by cloud789, 13 July 2017 - 09:35 PM.

  • 0



    Malware Expert

  • Expert
  • 24,708 posts
  • MVP

Process explorer looks very good.  Speccy shows F:\ has some problems so you might want to clone it and change it out in the near future.


Otherwise it looks normal.  


You have some out of memory errors so run Process Explorer then click once or twice on Working Set column header to sort things using the most memory at the top.  Note what is at the top and the value.  Does it change over time?  We are looking for something that creeps up slowly.

  • 0



    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts

There are still issues with Internet Explorer, some things and links are not shown on some websites, while on Chrome it's ok. I will let you know about Process Explorer.

  • 0



    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts

Process Explorer doesn't change over time.


My Computer response is slow. When I try to open Chrome nothing seems to happen and after 30 seconds Chrome opens. Internet Explorer also has issues showing everything on some websites.

  • 0



    Malware Expert

  • Expert
  • 24,708 posts
  • MVP
Download and run Speedy Fox.
Close Chrome/Firefox/Skpe. Hit Optimize. 
How long does it take to open Chrome now?
Does speedy fox complain about having problems accessing any of the files?

  • 0



    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts

Still the same.

Speedyfox does not complain.

Now Internet Explorer looks messed up on the top. The address bar looks like there are two address bars overlapping each other, looks very strange. There is definitely something wrong with files on this computer.

  • 0



    Malware Expert

  • Expert
  • 24,708 posts
  • MVP

Does IE work in Safe Mode with Networking?


(Reboot and when you see the maker's logo, hear a beep or it talks about F8, start tapping the F8 key slowly.  Keep tapping until the Safe Mode Menu appears and choose Safe Mode with Networking.  Login with your usual login.)

  • 0

