Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL logfile created on: 16.08.2017 13:39:28 - Run 1
- OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Janusz Rambo\Downloads
- 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
- Internet Explorer (Version = 9.11.15063.0)
- Locale: 00000415 | Country: Polska | Language: PLK | Date Format: dd.MM.yyyy
- 7,94 Gb Total Physical Memory | 4,44 Gb Available Physical Memory | 55,85% Memory free
- 13,80 Gb Paging File | 10,12 Gb Available in Paging File | 73,32% Paging File free
- Paging file location(s): c:\pagefile.sys 6000 6000 [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
- Drive C: | 118,69 Gb Total Space | 21,56 Gb Free Space | 18,16% Space Free | Partition Type: NTFS
- Drive D: | 450,00 Mb Total Space | 88,82 Mb Free Space | 19,74% Space Free | Partition Type: NTFS
- Drive E: | 100,00 Mb Total Space | 59,36 Mb Free Space | 59,37% Space Free | Partition Type: NTFS
- Drive F: | 298,09 Gb Total Space | 28,66 Gb Free Space | 9,61% Space Free | Partition Type: NTFS
- Drive G: | 97,56 Gb Total Space | 24,67 Gb Free Space | 25,29% Space Free | Partition Type: NTFS
- Drive H: | 135,23 Gb Total Space | 55,05 Gb Free Space | 40,71% Space Free | Partition Type: NTFS
- Computer Name: DESKTOP-AKUUNPE | User Name: Janusz Rambo | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
- Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - File not found --
- PRC - [2017.08.16 13:36:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Janusz Rambo\Downloads\OTL.exe
- PRC - [2017.07.26 19:09:20 | 000,449,984 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
- PRC - [2017.07.26 19:09:13 | 000,462,784 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
- PRC - [2017.07.26 19:09:09 | 015,554,496 | ---- | M] (Node.js) -- C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
- PRC - [2017.07.07 08:57:25 | 000,626,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\fontdrvhost.exe
- PRC - [2017.06.27 22:54:13 | 000,462,968 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
- PRC - [2017.06.16 10:58:16 | 000,895,688 | ---- | M] (FreeDownloadManager.org) -- F:\Program Files\FreeDownloadManager.ORG\Free Download Manager\winwfpmonitor.exe
- PRC - [2017.05.18 09:02:02 | 002,246,256 | ---- | M] (Adobe Systems, Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
- PRC - [2017.04.14 17:23:12 | 002,353,616 | ---- | M] (SecureMix LLC) -- C:\Program Files (x86)\GlassWire\GWIdlMon.exe
- PRC - [2017.04.14 17:23:08 | 004,427,728 | ---- | M] (SecureMix LLC) -- C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
- PRC - [2017.04.14 17:23:00 | 005,775,824 | ---- | M] (SecureMix LLC) -- C:\Program Files (x86)\GlassWire\GlassWire.exe
- PRC - [2016.10.12 17:28:18 | 000,744,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
- PRC - [2016.07.28 23:33:46 | 001,269,208 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
- PRC - [2016.05.27 15:23:57 | 000,419,288 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AsusFanControlService\1.08.15\AsusFanControlService.exe
- PRC - [2016.04.18 08:33:38 | 000,963,536 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AAHM\1.00.23\aaHMSvc.exe
- PRC - [2016.02.01 17:35:26 | 001,056,256 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNoticeMonitor.exe
- PRC - [2015.11.11 10:55:04 | 001,460,176 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe
- PRC - [2015.09.17 04:58:24 | 000,936,728 | ---- | M] () -- C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
- PRC - [2014.05.28 14:33:12 | 003,646,264 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe
- PRC - [2013.01.02 17:11:16 | 000,171,632 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2017.07.26 19:09:12 | 001,040,320 | ---- | M] () -- C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
- MOD - [2017.07.26 15:40:31 | 002,466,240 | ---- | M] () -- \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node
- MOD - [2017.07.26 15:40:31 | 001,255,032 | ---- | M] () -- \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSDKAPINode_SP1.node
- MOD - [2017.07.26 15:40:31 | 000,594,880 | ---- | M] () -- \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node
- MOD - [2017.07.26 15:40:31 | 000,523,712 | ---- | M] () -- \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvBackendAPINode.node
- MOD - [2017.07.26 15:40:31 | 000,494,016 | ---- | M] () -- \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node
- MOD - [2017.07.26 15:40:31 | 000,463,992 | ---- | M] () -- \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameStreamAPINode.node
- MOD - [2017.07.26 15:40:31 | 000,394,688 | ---- | M] () -- \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node
- MOD - [2017.07.26 15:40:31 | 000,390,264 | ---- | M] () -- \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvUtil.node
- MOD - [2017.07.26 15:40:31 | 000,386,680 | ---- | M] () -- \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node
- MOD - [2017.07.26 15:40:31 | 000,364,664 | ---- | M] () -- \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node
- MOD - [2017.04.14 17:22:56 | 000,178,128 | ---- | M] () -- C:\Program Files (x86)\GlassWire\EasyHook32.dll
- MOD - [2016.07.28 23:33:46 | 001,269,208 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
- MOD - [2016.05.04 21:46:14 | 000,786,416 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll
- MOD - [2016.04.20 23:52:36 | 000,838,616 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4TurboVEVOAction.dll
- MOD - [2016.04.20 23:52:28 | 000,828,376 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4FanAction.dll
- MOD - [2016.04.20 23:52:18 | 000,878,040 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4EpuAction.dll
- MOD - [2016.03.07 21:42:34 | 000,082,432 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\IccHelper.dll
- MOD - [2016.02.01 17:35:26 | 001,056,256 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNoticeMonitor.exe
- MOD - [2015.11.11 10:55:04 | 001,460,176 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe
- MOD - [2015.09.10 16:06:04 | 000,237,568 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzULIB.dll
- MOD - [2015.08.14 11:23:04 | 000,621,056 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\UIImprovmentHelper.dll
- MOD - [2014.02.24 17:49:28 | 000,208,896 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\ImageHelper.dll
- MOD - [2013.11.20 10:10:22 | 000,662,016 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\aaHMLib.dll
- MOD - [2013.07.02 10:40:08 | 000,253,952 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\pngio.dll
- [color=#E56717]========== Services (SafeList) ==========[/color]
- SRV:[b]64bit:[/b] - [2017.07.26 19:09:15 | 000,512,960 | ---- | M] (NVIDIA Corporation) [On_Demand | Stopped] -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -- (NvContainerNetworkService)
- SRV:[b]64bit:[/b] - [2017.07.26 19:09:15 | 000,512,960 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -- (NvContainerLocalSystem)
- SRV:[b]64bit:[/b] - [2017.07.07 09:20:19 | 000,923,040 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\CoreMessaging.dll -- (CoreMessagingRegistrar)
- SRV:[b]64bit:[/b] - [2017.07.07 09:13:19 | 000,872,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ClipSVC.dll -- (ClipSVC)
- SRV:[b]64bit:[/b] - [2017.07.07 09:13:07 | 000,336,320 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SecurityHealthService.exe -- (SecurityHealthService)
- SRV:[b]64bit:[/b] - [2017.07.07 08:18:36 | 000,548,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SensorService.dll -- (SensorService)
- SRV:[b]64bit:[/b] - [2017.07.07 08:17:02 | 000,536,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Windows.Internal.Management.dll -- (DmEnrollmentSvc)
- SRV:[b]64bit:[/b] - [2017.07.07 08:12:06 | 001,305,088 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dosvc.dll -- (DoSvc)
- SRV:[b]64bit:[/b] - [2017.06.27 22:54:13 | 000,462,968 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe -- (NVDisplay.ContainerLocalSystem)
- SRV:[b]64bit:[/b] - [2017.06.20 08:01:21 | 000,102,816 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
- SRV:[b]64bit:[/b] - [2017.06.20 07:11:29 | 000,200,192 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
- SRV:[b]64bit:[/b] - [2017.06.20 07:09:41 | 000,555,008 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WFDSConMgrSvc.dll -- (WFDSConMgrSvc)
- SRV:[b]64bit:[/b] - [2017.06.20 07:07:09 | 000,632,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\tileobjserver.dll -- (tiledatamodelsvc)
- SRV:[b]64bit:[/b] - [2017.06.20 07:06:00 | 000,847,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
- SRV:[b]64bit:[/b] - [2017.06.20 07:05:53 | 000,585,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
- SRV:[b]64bit:[/b] - [2017.06.20 07:04:35 | 001,177,600 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\Unistore.dll -- (UnistoreSvc)
- SRV:[b]64bit:[/b] - [2017.06.20 07:04:22 | 000,802,816 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
- SRV:[b]64bit:[/b] - [2017.06.20 07:02:54 | 000,681,984 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\usocore.dll -- (UsoSvc)
- SRV:[b]64bit:[/b] - [2017.06.20 07:02:40 | 002,804,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
- SRV:[b]64bit:[/b] - [2017.06.20 06:58:49 | 000,625,152 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
- SRV:[b]64bit:[/b] - [2017.06.20 06:56:18 | 000,600,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FrameServer.dll -- (FrameServer)
- SRV:[b]64bit:[/b] - [2017.06.03 10:58:32 | 001,046,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ngcsvc.dll -- (NgcSvc)
- SRV:[b]64bit:[/b] - [2017.06.03 10:58:21 | 002,516,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
- SRV:[b]64bit:[/b] - [2017.05.20 08:06:05 | 000,192,512 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\Windows.SharedPC.AccountManager.dll -- (shpamsvc)
- SRV:[b]64bit:[/b] - [2017.05.20 08:01:49 | 000,149,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\embeddedmodesvc.dll -- (embeddedmode)
- SRV:[b]64bit:[/b] - [2017.05.20 08:01:35 | 000,970,240 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cdpsvc.dll -- (CDPSvc)
- SRV:[b]64bit:[/b] - [2017.05.20 08:00:27 | 001,067,008 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XboxNetApiSvc.dll -- (XboxNetApiSvc)
- SRV:[b]64bit:[/b] - [2017.04.28 01:58:36 | 001,054,208 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TokenBroker.dll -- (TokenBroker)
- SRV:[b]64bit:[/b] - [2017.04.14 01:37:14 | 000,301,056 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\EnterpriseAppMgmtSvc.dll -- (EntAppSvc)
- SRV:[b]64bit:[/b] - [2017.04.14 01:29:46 | 000,647,168 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\RDXService.dll -- (RetailDemo)
- SRV:[b]64bit:[/b] - [2017.03.18 22:59:53 | 000,428,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WalletService.dll -- (WalletService)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:33 | 000,706,048 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:32 | 000,689,152 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\DevicesFlowBroker.dll -- (DevicesFlowUserSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:29 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:24 | 000,081,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:22 | 000,086,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe -- (diagnosticshub.standardcollector.service)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:21 | 002,155,008 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:21 | 001,135,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XblGameSave.dll -- (XblGameSave)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:21 | 000,777,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:21 | 000,582,656 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SmsRouterSvc.dll -- (SmsRouter)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:21 | 000,334,848 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:21 | 000,093,696 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:21 | 000,047,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\svchost.exe -- (WpnUserService_33cc201)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:21 | 000,047,664 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (UserDataSvc_33cc201)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:21 | 000,047,664 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (UnistoreSvc_33cc201)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:21 | 000,047,664 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (PimIndexMaintenanceSvc_33cc201)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:21 | 000,047,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\svchost.exe -- (OneSyncSvc_33cc201)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:21 | 000,047,664 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (MessagingService_33cc201)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:21 | 000,047,664 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (DevicesFlowUserSvc_33cc201)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:21 | 000,047,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\svchost.exe -- (CDPUserSvc_33cc201)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:18 | 000,055,296 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dmwappushsvc.dll -- (dmwappushservice)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:17 | 001,191,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SEMgrSvc.dll -- (SEMgrSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:17 | 000,772,096 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\PhoneService.dll -- (PhoneSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:17 | 000,152,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\RMapi.dll -- (RmSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:16 | 001,013,248 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XblAuthManager.dll -- (XblAuthManager)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:16 | 000,524,288 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\cdpusersvc.dll -- (CDPUserSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:16 | 000,342,528 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\APHostService.dll -- (OneSyncSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:16 | 000,072,704 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\WpnUserService.dll -- (WpnUserService)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:13 | 000,276,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wpnservice.dll -- (WpnService)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:12 | 000,149,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dssvc.dll -- (DsSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:10 | 001,628,672 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\UserDataService.dll -- (UserDataSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:10 | 001,295,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lpasvc.dll -- (wlpasvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:10 | 001,284,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SensorDataService.exe -- (SensorDataService)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:10 | 000,302,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dusmsvc.dll -- (DusmSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:10 | 000,057,344 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:09 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\moshost.dll -- (MapsBroker)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:09 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AJRouter.dll -- (AJRouter)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:07 | 000,233,984 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:07 | 000,210,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tetheringservice.dll -- (icssvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:07 | 000,182,272 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\PimIndexMaintenance.dll -- (PimIndexMaintenanceSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:04 | 000,301,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\xbgmsvc.dll -- (xbgm)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:04 | 000,043,520 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lfsvc.dll -- (lfsvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:04 | 000,033,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DevQueryBroker.dll -- (DevQueryBroker)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:04 | 000,026,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\LicenseManagerSvc.dll -- (LicenseManager)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:04 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\xboxgipsvc.dll -- (XboxGipSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:01 | 000,723,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NaturalAuth.dll -- (NaturalAuthentication)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:01 | 000,064,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ipxlatcfg.dll -- (IpxlatCfgSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:01 | 000,023,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
- SRV:[b]64bit:[/b] - [2017.03.18 22:58:00 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NgcCtnrSvc.dll -- (NgcCtnrSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:58 | 000,877,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\usermgr.dll -- (UserManager)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:58 | 000,519,168 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:58 | 000,165,888 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBrokerSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:58 | 000,095,744 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\tzautoupdate.dll -- (tzautoupdate)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:54 | 000,346,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:54 | 000,292,352 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:54 | 000,059,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\hvhostsvc.dll -- (HvHost)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:47 | 000,699,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FlightSettings.dll -- (wisvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:47 | 000,261,632 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NetSetupSvc.dll -- (NetSetupSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:46 | 005,302,456 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\Windows.StateRepository.dll -- (StateRepository)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:46 | 000,455,168 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:24 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:16 | 000,121,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:16 | 000,013,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:15 | 000,302,592 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\TieringEngineService.exe -- (TieringEngineService)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:05 | 000,891,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Spectrum.exe -- (spectrum)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:03 | 000,167,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:57:00 | 000,051,712 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\MessagingService.dll -- (MessagingService)
- SRV:[b]64bit:[/b] - [2017.03.18 22:56:56 | 001,832,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:56:44 | 000,342,264 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
- SRV:[b]64bit:[/b] - [2017.03.18 22:56:44 | 000,307,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvcext.dll -- (vmicvss)
- SRV:[b]64bit:[/b] - [2017.03.18 22:56:44 | 000,307,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvcext.dll -- (vmicrdv)
- SRV:[b]64bit:[/b] - [2017.03.18 22:56:44 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvmsession)
- SRV:[b]64bit:[/b] - [2017.03.18 22:56:44 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
- SRV:[b]64bit:[/b] - [2017.03.18 22:56:44 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
- SRV:[b]64bit:[/b] - [2017.03.18 22:56:44 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
- SRV:[b]64bit:[/b] - [2017.03.18 22:56:44 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
- SRV:[b]64bit:[/b] - [2017.03.18 22:56:44 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
- SRV:[b]64bit:[/b] - [2017.03.18 22:56:20 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
- SRV:[b]64bit:[/b] - [2017.03.18 22:56:19 | 000,431,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\BthHFSrv.dll -- (BthHFSrv)
- SRV - [2017.07.28 15:19:42 | 000,487,488 | ---- | M] (GOG.com) [On_Demand | Stopped] -- C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe -- (GalaxyClientService)
- SRV - [2017.07.26 20:07:01 | 008,163,392 | ---- | M] (GOG.com) [On_Demand | Stopped] -- C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe -- (GalaxyCommunication)
- SRV - [2017.07.26 19:09:20 | 000,449,984 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe -- (NvTelemetryContainer)
- SRV - [2017.07.07 08:23:46 | 000,583,160 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\CoreMessaging.dll -- (CoreMessagingRegistrar)
- SRV - [2017.07.07 08:04:29 | 000,394,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Windows.Internal.Management.dll -- (DmEnrollmentSvc)
- SRV - [2017.07.01 13:47:29 | 000,175,560 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
- SRV - [2017.06.20 06:39:05 | 000,969,728 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\Unistore.dll -- (UnistoreSvc)
- SRV - [2017.05.28 11:19:24 | 000,271,864 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
- SRV - [2017.05.18 09:02:02 | 002,246,256 | ---- | M] (Adobe Systems, Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe -- (AGSService)
- SRV - [2017.04.28 02:40:07 | 000,799,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\TokenBroker.dll -- (TokenBroker)
- SRV - [2017.04.16 16:35:33 | 000,026,112 | ---- | M] () [Auto | Running] -- C:\Windows\KMS-R@1n.exe -- (KMS-R@1n)
- SRV - [2017.04.14 17:23:08 | 004,427,728 | ---- | M] (SecureMix LLC) [Auto | Running] -- C:\Program Files (x86)\GlassWire\GWCtlSrv.exe -- (GlassWire)
- SRV - [2017.03.18 22:58:47 | 004,212,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\Windows.StateRepository.dll -- (StateRepository)
- SRV - [2017.03.18 22:58:46 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
- SRV - [2017.03.18 22:56:20 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
- SRV - [2017.02.16 13:49:00 | 006,498,816 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\ADATA\SSD ToolBox\ToolBoxSvc.exe -- (ADATA ToolBox Service)
- SRV - [2016.10.12 17:28:18 | 000,744,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe -- (AdobeUpdateService)
- SRV - [2016.07.23 01:36:30 | 000,837,312 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
- SRV - [2016.05.27 15:23:57 | 000,419,288 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- C:\Program Files (x86)\ASUS\AsusFanControlService\1.08.15\AsusFanControlService.exe -- (AsusFanControlService)
- SRV - [2016.04.18 08:33:38 | 000,963,536 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- C:\Program Files (x86)\ASUS\AAHM\1.00.23\aaHMSvc.exe -- (asHmComSvc)
- SRV - [2015.09.17 04:58:24 | 000,936,728 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe -- (asComSvc)
- SRV - [2013.01.02 17:11:16 | 000,171,632 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe -- (ICCS)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV:[b]64bit:[/b] - [2017.08.16 13:36:53 | 000,055,232 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hitmanpro37.sys -- (hitmanpro37)
- DRV:[b]64bit:[/b] - [2017.07.26 19:09:23 | 000,057,792 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvhci.sys -- (nvvhci)
- DRV:[b]64bit:[/b] - [2017.07.26 19:09:22 | 000,048,064 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
- DRV:[b]64bit:[/b] - [2017.07.26 19:08:47 | 000,030,144 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
- DRV:[b]64bit:[/b] - [2017.07.07 09:24:00 | 000,117,664 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
- DRV:[b]64bit:[/b] - [2017.07.07 09:20:52 | 000,382,368 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
- DRV:[b]64bit:[/b] - [2017.07.07 09:13:20 | 000,554,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
- DRV:[b]64bit:[/b] - [2017.06.28 17:00:36 | 015,625,336 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\nv_dispi.inf_amd64_2386fda73b467ac8\nvlddmkm.sys -- (nvlddmkm)
- DRV:[b]64bit:[/b] - [2017.06.28 00:39:35 | 000,218,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
- DRV:[b]64bit:[/b] - [2017.06.20 08:00:36 | 000,142,752 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\wcifs.sys -- (wcifs)
- DRV:[b]64bit:[/b] - [2017.06.20 07:07:09 | 000,757,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdiWiFi.sys -- (wdiwifi)
- DRV:[b]64bit:[/b] - [2017.06.03 12:00:17 | 000,219,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
- DRV:[b]64bit:[/b] - [2017.06.03 11:11:56 | 000,035,840 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
- DRV:[b]64bit:[/b] - [2017.05.20 09:07:32 | 000,287,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
- DRV:[b]64bit:[/b] - [2017.05.20 08:59:08 | 000,112,544 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
- DRV:[b]64bit:[/b] - [2017.05.20 08:54:43 | 000,144,288 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
- DRV:[b]64bit:[/b] - [2017.05.20 08:07:38 | 000,277,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xboxgip.sys -- (xboxgip)
- DRV:[b]64bit:[/b] - [2017.04.28 02:59:04 | 000,388,000 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
- DRV:[b]64bit:[/b] - [2017.04.19 08:18:19 | 000,118,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc.sys -- (netvsc)
- DRV:[b]64bit:[/b] - [2017.03.20 06:01:31 | 000,037,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
- DRV:[b]64bit:[/b] - [2017.03.20 06:01:27 | 000,040,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpatialGraphFilter.sys -- (SpatialGraphFilter)
- DRV:[b]64bit:[/b] - [2017.03.20 06:01:24 | 000,030,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
- DRV:[b]64bit:[/b] - [2017.03.18 22:59:50 | 000,030,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
- DRV:[b]64bit:[/b] - [2017.03.18 22:58:33 | 000,079,872 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\storqosflt.sys -- (storqosflt)
- DRV:[b]64bit:[/b] - [2017.03.18 22:58:18 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\gpuenergydrv.sys -- (GpuEnergyDrv)
- DRV:[b]64bit:[/b] - [2017.03.18 22:58:16 | 000,127,488 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
- DRV:[b]64bit:[/b] - [2017.03.18 22:58:04 | 000,263,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ufx01000.sys -- (Ufx01000)
- DRV:[b]64bit:[/b] - [2017.03.18 22:58:04 | 000,179,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmTcpciCx.sys -- (UcmTcpciCx0101)
- DRV:[b]64bit:[/b] - [2017.03.18 22:58:04 | 000,104,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmCx.sys -- (UcmCx0101)
- DRV:[b]64bit:[/b] - [2017.03.18 22:58:04 | 000,070,232 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\WindowsTrustedRT.sys -- (WindowsTrustedRT)
- DRV:[b]64bit:[/b] - [2017.03.18 22:58:04 | 000,059,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urscx01000.sys -- (UrsCx01000)
- DRV:[b]64bit:[/b] - [2017.03.18 22:58:04 | 000,036,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IndirectKmd.sys -- (IndirectKmd)
- DRV:[b]64bit:[/b] - [2017.03.18 22:58:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\applockerfltr.sys -- (applockerfltr)
- DRV:[b]64bit:[/b] - [2017.03.18 22:58:01 | 000,217,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winnat.sys -- (WinNat)
- DRV:[b]64bit:[/b] - [2017.03.18 22:58:01 | 000,012,288 | ---- | M] (Microsoft Corporation) [File_System | Auto | Stopped] -- C:\Windows\SysNative\drivers\cldflt.sys -- (CldFlt)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:58 | 000,154,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:58 | 000,083,456 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:58 | 000,074,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hvservice.sys -- (hvservice)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:58 | 000,039,840 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\cnghwassist.sys -- (cnghwassist)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:58 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:57 | 000,075,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:57 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\registry.sys -- (clreg)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:54 | 000,208,288 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\wof.sys -- (Wof)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:54 | 000,169,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:54 | 000,128,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:53 | 000,164,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:53 | 000,072,192 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wcnfs.sys -- (wcnfs)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:47 | 000,080,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:39 | 001,735,584 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\refs.sys -- (ReFS)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:39 | 000,936,864 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\refsv1.sys -- (ReFSv1)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:39 | 000,239,616 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:39 | 000,215,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:39 | 000,033,688 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:38 | 000,056,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:38 | 000,049,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iorate.sys -- (iorate)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:35 | 000,122,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NetAdapterCx.sys -- (NetAdapterCx)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:24 | 000,088,992 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:05 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mmcss.sys -- (MMCSS)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:03 | 000,120,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\irda.sys -- (irda)
- DRV:[b]64bit:[/b] - [2017.03.18 22:57:00 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:44 | 000,294,816 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:44 | 000,121,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:44 | 000,044,632 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:41 | 000,213,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Ucx01000.sys -- (Ucx01000)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:41 | 000,127,392 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:41 | 000,061,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:41 | 000,054,272 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\filecrypt.sys -- (FileCrypt)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:41 | 000,045,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Udecx.sys -- (UdeCx)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:41 | 000,035,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vhf.sys -- (vhf)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:35 | 000,094,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:35 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:35 | 000,051,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmUcsi.sys -- (UcmUcsi)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:35 | 000,051,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidinterrupt.sys -- (hidinterrupt)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:35 | 000,039,424 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\buttonconverter.sys -- (buttonconverter)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:35 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:35 | 000,018,520 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\WindowsTrustedRTProxy.sys -- (WindowsTrustedRTProxy)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:34 | 000,138,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ufxsynopsys.sys -- (ufxsynopsys)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:34 | 000,098,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UfxChipidea.sys -- (UfxChipidea)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:34 | 000,049,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:34 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xinputhid.sys -- (xinputhid)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:34 | 000,029,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urschipidea.sys -- (UrsChipidea)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:34 | 000,028,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urssynopsys.sys -- (UrsSynopsys)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:34 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:34 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\genericusbfn.sys -- (genericusbfn)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:28 | 000,168,448 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_I2C_BXT_P.sys -- (iaLPSS2i_I2C_BXT_P)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:28 | 000,165,376 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_I2C.sys -- (iaLPSS2i_I2C)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:28 | 000,085,504 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_GPIO2_BXT_P.sys -- (iaLPSS2i_GPIO2_BXT_P)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:28 | 000,081,408 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iai2c.sys -- (iai2c)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:28 | 000,074,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:28 | 000,070,656 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_GPIO2.sys -- (iaLPSS2i_GPIO2)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:28 | 000,064,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:28 | 000,053,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CAD.sys -- (CAD)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:28 | 000,047,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:28 | 000,035,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:28 | 000,033,280 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iagpio.sys -- (iagpio)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:28 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:28 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:28 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgid.sys -- (vmgid)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,673,184 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,604,160 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rt640x64.sys -- (rt640x64)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,587,168 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,405,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mausbhost.sys -- (mausbhost)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,101,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pmem.sys -- (pmem)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,095,648 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,091,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\scmbus.sys -- (scmbus)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,080,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvdimmn.sys -- (nvdimmn)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,078,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,071,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,051,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mausbip.sys -- (mausbip)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,036,760 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storufs.sys -- (storufs)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,031,128 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SDFRd.sys -- (SDFRd)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,029,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,016,288 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volume.sys -- (volume)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:26 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 002,104,224 | ---- | M] (Chelsio Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cht4vx64.sys -- (cht4vbd)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 001,135,512 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,842,656 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mlx4_bus.sys -- (mlx4_bus)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,526,240 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ibbus.sys -- (ibbus)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,347,032 | ---- | M] (Chelsio Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cht4sx64.sys -- (cht4iscsi)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,305,568 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,259,488 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,123,808 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2i.sys -- (LSI_SAS2i)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,122,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\capimg.sys -- (CapImg)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,108,960 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndfltr.sys -- (ndfltr)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,107,424 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,103,328 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3i.sys -- (LSI_SAS3i)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,083,352 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,082,848 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,064,920 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winverbs.sys -- (WinVerbs)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,064,416 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,064,416 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\MegaSas2i.sys -- (megasas2i)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,063,904 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,061,848 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\percsas3i.sys -- (percsas3i)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,058,784 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\percsas2i.sys -- (percsas2i)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,032,160 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winmad.sys -- (WinMad)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,031,136 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,027,040 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,020,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AcpiDev.sys -- (AcpiDev)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:25 | 000,009,728 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:23 | 003,419,040 | ---- | M] (QLogic Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:23 | 000,533,920 | ---- | M] (QLogic Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:23 | 000,074,840 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:23 | 000,038,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:19 | 000,119,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:19 | 000,113,152 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:19 | 000,097,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:19 | 000,043,520 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:19 | 000,040,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys -- (CompositeBus)
- DRV:[b]64bit:[/b] - [2017.03.18 22:56:19 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
- DRV:[b]64bit:[/b] - [2016.01.19 22:50:38 | 000,202,032 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TeeDriverW8x64.sys -- (MEIx64)
- DRV:[b]64bit:[/b] - [2015.10.29 21:43:10 | 000,025,928 | ---- | M] (TP Microelectronic) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tpfilter.sys -- (tpfilter)
- DRV:[b]64bit:[/b] - [2015.05.29 06:15:44 | 000,033,152 | ---- | M] (SecureMix LLC) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\gwdrv.sys -- (gwdrv)
- DRV:[b]64bit:[/b] - [2010.04.27 16:57:20 | 000,016,200 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmVirHid.sys -- (WmVirHid)
- DRV:[b]64bit:[/b] - [2010.04.27 16:57:14 | 000,036,936 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmHidLo.sys -- (WmHidLo)
- DRV:[b]64bit:[/b] - [2010.04.27 16:57:12 | 000,026,440 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmBEnum.sys -- (WmBEnum)
- DRV:[b]64bit:[/b] - [2010.04.27 14:03:12 | 000,077,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmXlCore.sys -- (WmXlCore)
- DRV:[b]64bit:[/b] - [2010.04.27 14:02:42 | 000,043,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmFilter.sys -- (WmFilter)
- DRV - [2017.08.16 13:36:54 | 000,044,928 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{203FBFCD-B166-48C7-B89F-4A01EE731F54}\MpKsl1aa9d81d.sys -- (MpKsl1aa9d81d)
- DRV - [2017.07.26 13:10:11 | 000,046,400 | ---- | M] (CPUID) [Kernel | On_Demand | Stopped] -- C:\Users\JANUSZ~1\AppData\Local\Temp\cpuz141\cpuz141_x64.sys -- (cpuz141)
- DRV - [2017.06.28 17:00:36 | 015,625,336 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_2386fda73b467ac8\nvlddmkm.sys -- (nvlddmkm)
- DRV - [2017.03.18 22:56:19 | 000,040,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys -- (CompositeBus)
- DRV - [2016.10.24 12:03:56 | 000,014,024 | ---- | M] () [Kernel | On_Demand | Stopped] -- F:\Program Files (x86)\MSI Afterburner\RTCore64.sys -- (RTCore64)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
- IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
- IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.countryCode: "PL"
- FF - prefs.js..browser.search.region: "PL"
- FF - prefs.js..browser.search.update: false
- FF - prefs.js..extensions.enabledAddons: %7B46551EC9-40F0-4e47-8E18-8E5CF550CFB8%7D:2.0.7
- FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:54.0.1
- FF - user.js - File not found
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll File not found
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.6: f:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
- FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll ()
- FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
- FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 54.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 54.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
- [2017.04.16 16:27:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Janusz Rambo\AppData\Roaming\mozilla\Extensions
- [2017.08.10 16:23:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Janusz Rambo\AppData\Roaming\mozilla\Firefox\Profiles\y1uncvdc.default\extension-data
- [2017.07.26 20:03:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Janusz Rambo\AppData\Roaming\mozilla\Firefox\Profiles\y1uncvdc.default\extensions
- [2017.04.21 06:50:50 | 000,157,498 | ---- | M] () (No name found) -- C:\Users\Janusz Rambo\AppData\Roaming\mozilla\firefox\profiles\y1uncvdc.default\extensions\jid0-GaZOxvWNYcafEsmayJDIG3XXVi8@jetpack.xpi
- [2017.07.26 20:03:20 | 001,728,718 | ---- | M] () (No name found) -- C:\Users\Janusz Rambo\AppData\Roaming\mozilla\firefox\profiles\y1uncvdc.default\extensions\uBlock0@raymondhill.net.xpi
- [2017.04.21 06:50:50 | 000,221,125 | ---- | M] () (No name found) -- C:\Users\Janusz Rambo\AppData\Roaming\mozilla\firefox\profiles\y1uncvdc.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
- [2017.07.26 20:03:16 | 000,008,945 | ---- | M] () (No name found) -- C:\Users\Janusz Rambo\AppData\Roaming\mozilla\firefox\profiles\y1uncvdc.default\features\{5cbaf8f3-c9c4-4f64-af93-71ea49bc58a9}\e10srollout@mozilla.org.xpi
- [2017.07.26 20:03:16 | 000,009,974 | ---- | M] () (No name found) -- C:\Users\Janusz Rambo\AppData\Roaming\mozilla\firefox\profiles\y1uncvdc.default\features\{5cbaf8f3-c9c4-4f64-af93-71ea49bc58a9}\followonsearch@mozilla.com.xpi
- [2017.07.26 20:03:16 | 000,044,954 | ---- | M] () (No name found) -- C:\Users\Janusz Rambo\AppData\Roaming\mozilla\firefox\profiles\y1uncvdc.default\features\{5cbaf8f3-c9c4-4f64-af93-71ea49bc58a9}\shield-recipe-client@mozilla.org.xpi
- [2017.07.01 13:47:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
- [color=#E56717]========== Chrome ==========[/color]
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\2.0.6_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm\1.13.8_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo\4.3.6_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\eplekpmdodlgejgogbojajncdlapamff\4.0.21_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\fihnjjcciajhdojfnbdddfaoknhalnja\2.6.7_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\3.1.17325.1420_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\johjcheghocokbkhacbfbhojoangkpcb\1.5.9_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\kegnjbncdcliihbemealioapbifiaedg\1.2_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\libedajeiljdoodmokbppgapcfbignci\0.0.61_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbpblocgmgfnpjjppndjkmgjaogfceg\0.98.92.2_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mibmplgflabdmnnoncnedjfdpidjblnk\1.45_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkclgpgponpjmpfokoepglboejdobkpl\1.0.2_0\
- CHR - Extension: No name found = C:\Users\Janusz Rambo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6017.605.1.4_0\
- O1 HOSTS File: ([2017.05.28 17:32:02 | 000,000,826 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
- O2:[b]64bit:[/b] - BHO: (no name) - {13D67BB7-DB5F-48AA-884D-7A5D94168509} - No CLSID value found.
- O2 - BHO: (no name) - {13D67BB7-DB5F-48AA-884D-7A5D94168509} - No CLSID value found.
- O4:[b]64bit:[/b] - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
- O4:[b]64bit:[/b] - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
- O4:[b]64bit:[/b] - HKLM..\Run: [SecurityHealth] C:\Program Files\Windows Defender\MSASCuiL.exe (Microsoft Corporation)
- O4:[b]64bit:[/b] - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
- O4:[b]64bit:[/b] - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
- O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
- O4 - HKCU..\Run: [Discord] C:\Users\Janusz Rambo\AppData\Local\Discord\app-0.0.297\Discord.exe (Hammer & Chisel, Inc.)
- O4 - HKCU..\Run: [GlassWire] C:\Program Files (x86)\GlassWire\glasswire.exe (SecureMix LLC)
- O4 - HKCU..\Run: [PeerBlock] f:\Program Files\PeerBlock\peerblock.exe (PeerBlock, LLC)
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DSCAutomationHostEnabled = 2
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
- O13[b]64bit:[/b] - gopher Prefix: missing
- O13 - gopher Prefix: missing
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{31a9ef30-f662-4183-b6d0-44747b26936e}: DhcpNameServer = 192.168.1.1 192.168.1.1
- O18:[b]64bit:[/b] - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
- O18 - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
- O18 - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
- O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O32 - HKLM CDRom: AutoRun - 1
- O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - G:\autoexec.bat -- [ NTFS ]
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
- O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
- O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2017.08.16 13:36:40 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
- [2017.08.16 13:36:33 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
- [2017.08.16 02:00:02 | 000,000,000 | -H-D | C] -- C:\Users\Public\Documents\AdobeGC
- [2017.08.16 00:42:53 | 001,922,496 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvspcap64.dll
- [2017.08.16 00:42:42 | 000,057,792 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvvhci.sys
- [2017.08.16 00:42:42 | 000,048,064 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvvad64v.sys
- [2017.08.14 21:41:21 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\Desktop\rgr
- [2017.08.11 09:33:10 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Roaming\Trimble Connect for SketchUp
- [2017.08.11 08:57:15 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Roaming\SketchUp
- [2017.08.11 08:56:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp 2017
- [2017.08.11 08:56:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Reprise
- [2017.08.11 08:56:19 | 000,000,000 | ---D | C] -- C:\ProgramData\SketchUp
- [2017.08.02 15:35:02 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\CrashRpt
- [2017.07.31 20:37:25 | 000,000,000 | ---D | C] -- C:\ProgramData\360TSBackup
- [2017.07.26 12:20:42 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Recovery
- [2017.07.23 15:27:49 | 000,000,000 | ---D | C] -- C:\The Sims 4
- [2017.07.23 14:46:51 | 000,135,616 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe
- [2017.07.23 14:46:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VulkanRT
- [2017.07.23 14:46:20 | 000,549,312 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nv3dappshext.dll
- [2017.07.23 14:46:20 | 000,069,752 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll
- [2017.07.23 14:41:31 | 035,838,912 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
- [2017.07.23 14:41:31 | 028,953,536 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
- [2017.07.23 14:41:31 | 012,337,296 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll
- [2017.07.23 14:41:31 | 012,132,272 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvptxJitCompiler.dll
- [2017.07.23 14:41:31 | 010,381,664 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll
- [2017.07.23 14:41:31 | 009,982,456 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvptxJitCompiler.dll
- [2017.07.23 14:41:31 | 001,988,216 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6438476.dll
- [2017.07.23 14:41:31 | 001,615,448 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvhdagenco6420103.dll
- [2017.07.23 14:41:31 | 001,597,888 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6438476.dll
- [2017.07.23 14:41:31 | 001,278,528 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvEncMFTH264.dll
- [2017.07.23 14:41:31 | 001,276,992 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvEncMFThevc.dll
- [2017.07.23 14:41:31 | 001,067,128 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvFBC64.dll
- [2017.07.23 14:41:31 | 001,004,664 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvFBC.dll
- [2017.07.23 14:41:31 | 000,996,760 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvEncMFTH264.dll
- [2017.07.23 14:41:31 | 000,995,224 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvEncMFThevc.dll
- [2017.07.23 14:41:31 | 000,972,736 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvIFR64.dll
- [2017.07.23 14:41:31 | 000,924,096 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvIFR.dll
- [2017.07.23 14:41:31 | 000,781,728 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvEncodeAPI64.dll
- [2017.07.23 14:41:31 | 000,689,808 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvfatbinaryLoader.dll
- [2017.07.23 14:41:31 | 000,618,744 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmcumd.dll
- [2017.07.23 14:41:31 | 000,617,416 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvEncodeAPI.dll
- [2017.07.23 14:41:31 | 000,609,728 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvIFROpenGL.dll
- [2017.07.23 14:41:31 | 000,578,056 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvfatbinaryLoader.dll
- [2017.07.23 14:41:31 | 000,499,320 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvIFROpenGL.dll
- [2017.07.23 14:41:31 | 000,218,712 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvhda64v.sys
- [2017.07.23 14:41:31 | 000,045,976 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvhdap64.dll
- [2017.07.23 14:41:30 | 040,239,736 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
- [2017.07.23 14:41:30 | 035,314,296 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
- [2017.07.23 14:41:30 | 013,559,376 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
- [2017.07.23 14:41:30 | 011,501,776 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
- [2017.07.23 14:41:30 | 004,208,984 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll
- [2017.07.23 14:41:30 | 004,163,008 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
- [2017.07.23 14:41:30 | 003,709,952 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
- [2017.07.23 14:41:30 | 003,595,384 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
- [2017.07.23 14:41:30 | 000,725,112 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvDecMFTMjpeg.dll
- [2017.07.23 14:41:30 | 000,584,128 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvDecMFTMjpeg.dll
- [2017.07.21 16:38:41 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsignad28436cdf90b7c9
- [2017.07.21 16:36:48 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsignbee047f3d7abd232
- [2017.07.21 16:09:08 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsign84b2afa0ed05205a
- [2017.07.21 16:06:36 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsign6372fe2fc82d42d4
- [2017.07.21 16:06:36 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsign2e205ddd34c436df
- [2017.07.21 16:05:06 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsign085ca3900f14d3c1
- [2017.07.21 15:56:40 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\Desktop\WKLEJKI
- [2017.07.21 14:36:17 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsignfe59705502dae6b4
- [2017.07.21 14:32:35 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsign6dbd2184a56e1735
- [2017.07.21 14:32:29 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsign4306b5a83199814c
- [2017.07.21 14:32:28 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsignc36f661873011de5
- [2017.07.21 14:31:48 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsignc9709cb659c7c2a1
- [2017.07.21 14:31:21 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsign06d20362a93f24da
- [2017.07.21 14:30:27 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsign295c215382c302f1
- [2017.07.21 14:30:25 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsign2c86eae19116409c
- [2017.07.21 14:30:25 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsign0034b2b253f5bc51
- [2017.07.21 14:26:19 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsign09492c84e0731dd6
- [2017.07.21 14:26:15 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsign7d9ebf7990c68476
- [2017.07.21 14:26:14 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Tempzxpsign3f2151684c00fad1
- [2017.07.21 14:26:06 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Roaming\NVIDIA
- [2017.07.21 14:26:04 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
- [2017.07.21 14:21:15 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\Documents\Adobe
- [2017.07.21 14:20:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
- [2017.07.21 14:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
- [2017.07.21 14:19:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
- [2017.07.21 14:19:35 | 000,000,000 | ---D | C] -- C:\Users\Janusz Rambo\AppData\Local\Adobe
- [2017.07.21 14:19:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
- [2017.07.21 14:19:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
- [2017.07.20 09:30:26 | 000,000,000 | ---D | C] -- C:\ProgramData\360Quarant
- [1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
- [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2017.08.16 13:36:53 | 000,055,232 | ---- | M] () -- C:\Windows\SysNative\drivers\hitmanpro37.sys
- [2017.08.16 13:33:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
- [2017.08.16 07:04:36 | 007,899,960 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
- [2017.08.16 07:04:36 | 003,887,030 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat
- [2017.08.16 07:04:36 | 001,701,628 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
- [2017.08.16 07:04:36 | 001,104,842 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat
- [2017.08.16 07:04:36 | 001,057,254 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
- [2017.08.16 06:57:38 | 016,777,216 | -HS- | M] () -- C:\swapfile.sys
- [2017.08.12 12:50:23 | 025,851,259 | ---- | M] () -- C:\Users\Janusz Rambo\Desktop\jdmbimma.psd
- [2017.08.11 17:13:46 | 000,000,535 | ---- | M] () -- C:\Users\Public\Desktop\Overwatch Test.lnk
- [2017.08.07 15:00:03 | 000,396,174 | ---- | M] () -- C:\Users\Janusz Rambo\Desktop\7313670_orig.jpg
- [2017.08.07 09:04:57 | 001,074,626 | ---- | M] () -- C:\Users\Janusz Rambo\Desktop\087.jpg
- [2017.08.06 16:38:34 | 000,169,971 | ---- | M] () -- C:\Users\Janusz Rambo\Desktop\02_audi_a4_deval_roof_spoiler_02.jpg
- [2017.07.31 20:44:58 | 000,007,594 | ---- | M] () -- C:\Users\Janusz Rambo\AppData\Local\resmon.resmoncfg
- [2017.07.29 15:44:52 | 000,164,043 | ---- | M] () -- C:\Users\Janusz Rambo\Desktop\ultraracing28.jpg
- [2017.07.29 15:37:32 | 000,087,873 | ---- | M] () -- C:\Users\Janusz Rambo\Desktop\img_ur_img01.jpg
- [2017.07.29 15:35:47 | 000,046,747 | ---- | M] () -- C:\Users\Janusz Rambo\Desktop\ultra-racing-8-point-side-bar-proton-wira-1-3-1-5-1-6-1-8-sedan-eddy204-1501-02-eddy204@343.jpg
- [2017.07.29 14:19:12 | 000,447,171 | ---- | M] () -- C:\Users\Janusz Rambo\Desktop\editetk6qrbm.jpg
- [2017.07.29 14:14:33 | 000,023,111 | ---- | M] () -- C:\Users\Janusz Rambo\Desktop\25jb801.jpg
- [2017.07.26 19:09:28 | 001,922,496 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvspcap64.dll
- [2017.07.26 19:09:27 | 001,755,072 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvspbridge64.dll
- [2017.07.26 19:09:27 | 001,505,728 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvspcap.dll
- [2017.07.26 19:09:27 | 001,317,312 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvspbridge.dll
- [2017.07.26 19:09:27 | 000,121,280 | ---- | M] () -- C:\Windows\SysNative\NvRtmpStreamer64.dll
- [2017.07.26 19:09:23 | 000,057,792 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvvhci.sys
- [2017.07.26 19:09:22 | 000,048,064 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvvad64v.sys
- [2017.07.26 19:09:21 | 000,179,136 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvaudcap64v.dll
- [2017.07.26 19:09:21 | 000,146,368 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvaudcap32v.dll
- [2017.07.26 15:40:31 | 000,001,951 | ---- | M] () -- C:\Windows\NvTelemetryContainerRecovery.bat
- [2017.07.26 15:36:56 | 000,001,951 | ---- | M] () -- C:\Windows\NvContainerRecovery.bat
- [2017.07.25 21:35:50 | 000,000,007 | ---- | M] () -- C:\Users\Janusz Rambo\Desktop\Nowy dokument sformatowany.rtf
- [2017.07.25 15:37:54 | 000,192,832 | ---- | M] () -- C:\Users\Janusz Rambo\Desktop\E46o91k.jpg
- [2017.07.23 11:31:45 | 000,001,345 | ---- | M] () -- C:\Users\Janusz Rambo\Desktop\TS4_x64 — skrót .lnk
- [2017.07.22 07:44:47 | 000,227,216 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
- [2017.07.21 14:27:13 | 000,001,099 | ---- | M] () -- C:\Users\Janusz Rambo\Desktop\Adobe Photoshop CC 2017.lnk
- [2017.07.21 14:20:12 | 000,001,300 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
- [2017.07.17 21:00:40 | 001,395,166 | ---- | M] () -- C:\Users\Janusz Rambo\Desktop\goodwood-festivalofspeed-jordanbutters-speedhunters-4301.jpg
- [1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
- [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2017.08.16 13:36:53 | 000,055,232 | ---- | C] () -- C:\Windows\SysNative\drivers\hitmanpro37.sys
- [2017.08.12 12:50:23 | 025,851,259 | ---- | C] () -- C:\Users\Janusz Rambo\Desktop\jdmbimma.psd
- [2017.08.07 15:00:01 | 000,396,174 | ---- | C] () -- C:\Users\Janusz Rambo\Desktop\7313670_orig.jpg
- [2017.08.07 09:04:57 | 001,074,626 | ---- | C] () -- C:\Users\Janusz Rambo\Desktop\087.jpg
- [2017.08.06 16:38:31 | 000,169,971 | ---- | C] () -- C:\Users\Janusz Rambo\Desktop\02_audi_a4_deval_roof_spoiler_02.jpg
- [2017.07.29 15:44:50 | 000,164,043 | ---- | C] () -- C:\Users\Janusz Rambo\Desktop\ultraracing28.jpg
- [2017.07.29 15:37:30 | 000,087,873 | ---- | C] () -- C:\Users\Janusz Rambo\Desktop\img_ur_img01.jpg
- [2017.07.29 15:35:45 | 000,046,747 | ---- | C] () -- C:\Users\Janusz Rambo\Desktop\ultra-racing-8-point-side-bar-proton-wira-1-3-1-5-1-6-1-8-sedan-eddy204-1501-02-eddy204@343.jpg
- [2017.07.29 14:19:11 | 000,447,171 | ---- | C] () -- C:\Users\Janusz Rambo\Desktop\editetk6qrbm.jpg
- [2017.07.29 14:14:31 | 000,023,111 | ---- | C] () -- C:\Users\Janusz Rambo\Desktop\25jb801.jpg
- [2017.07.25 21:35:50 | 000,000,007 | ---- | C] () -- C:\Users\Janusz Rambo\Desktop\Nowy dokument sformatowany.rtf
- [2017.07.25 15:37:47 | 000,192,832 | ---- | C] () -- C:\Users\Janusz Rambo\Desktop\E46o91k.jpg
- [2017.07.23 14:46:35 | 000,536,864 | ---- | C] () -- C:\Windows\SysNative\vulkan-1.dll
- [2017.07.23 14:46:35 | 000,525,600 | ---- | C] () -- C:\Windows\SysWow64\vulkan-1.dll
- [2017.07.23 14:46:35 | 000,254,240 | ---- | C] () -- C:\Windows\SysNative\vulkaninfo.exe
- [2017.07.23 14:46:35 | 000,233,760 | ---- | C] () -- C:\Windows\SysWow64\vulkaninfo.exe
- [2017.07.23 14:41:31 | 000,046,373 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
- [2017.07.23 14:41:30 | 000,000,669 | ---- | C] () -- C:\Windows\SysNative\nv-vk64.json
- [2017.07.23 14:41:30 | 000,000,669 | ---- | C] () -- C:\Windows\SysWow64\nv-vk32.json
- [2017.07.23 11:31:52 | 000,001,345 | ---- | C] () -- C:\Users\Janusz Rambo\Desktop\TS4_x64 — skrót .lnk
- [2017.07.21 14:27:13 | 000,001,099 | ---- | C] () -- C:\Users\Janusz Rambo\Desktop\Adobe Photoshop CC 2017.lnk
- [2017.07.21 14:21:14 | 000,001,099 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017.lnk
- [2017.07.21 14:20:12 | 000,001,312 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
- [2017.07.21 14:20:12 | 000,001,300 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
- [2017.07.21 04:06:32 | 000,227,216 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
- [2017.07.17 21:00:38 | 001,395,166 | ---- | C] () -- C:\Users\Janusz Rambo\Desktop\goodwood-festivalofspeed-jordanbutters-speedhunters-4301.jpg
- [2017.07.04 16:33:31 | 000,001,658 | ---- | C] () -- C:\Users\Janusz Rambo\AppData\Local\recently-used.xbel
- [2017.06.14 07:55:25 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\xboxgipsynthetic.dll
- [2017.05.13 06:28:03 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
- [2017.05.13 06:27:16 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
- [2017.05.12 09:11:04 | 005,191,808 | ---- | C] () -- C:\Windows\PE_File.dll
- [2017.05.12 09:10:33 | 005,135,488 | ---- | C] () -- C:\Windows\PE_Rom.dll
- [2017.05.12 08:56:31 | 000,014,464 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsUpIO.sys
- [2017.04.16 18:00:09 | 000,007,594 | ---- | C] () -- C:\Users\Janusz Rambo\AppData\Local\resmon.resmoncfg
- [2017.04.16 16:47:01 | 000,015,232 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
- [2017.04.16 16:35:33 | 000,026,112 | ---- | C] () -- C:\Windows\KMS-R@1n.exe
- [2017.04.16 16:35:33 | 000,005,120 | ---- | C] () -- C:\Windows\KMS-R@1nHook.exe
- [2017.04.16 16:35:33 | 000,004,096 | ---- | C] () -- C:\Windows\KMS-R@1nHook.dll
- [2017.04.16 16:17:24 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
- [2017.03.18 23:03:42 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
- [2017.03.18 23:03:41 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
- [2017.03.18 22:58:56 | 000,054,272 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
- [2017.03.18 22:58:54 | 000,116,824 | ---- | C] () -- C:\Windows\SysWow64\InputHost.dll
- [2017.03.18 22:58:54 | 000,112,128 | ---- | C] () -- C:\Windows\SysWow64\HeatCore.dll
- [2017.03.18 22:58:54 | 000,086,528 | ---- | C] () -- C:\Windows\SysWow64\WindowsDefaultHeatProcessor.dll
- [2017.03.18 22:58:52 | 003,200,000 | ---- | C] () -- C:\Windows\SysWow64\Windows.UI.Input.Inking.Analysis.dll
- [2017.03.18 22:58:51 | 000,167,640 | ---- | C] () -- C:\Windows\SysWow64\chs_singlechar_pinyin.dat
- [2017.03.18 22:58:48 | 000,002,307 | ---- | C] () -- C:\Windows\SysWow64\WimBootCompress.ini
- [2017.03.18 22:58:42 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
- [2017.03.18 22:58:39 | 000,307,200 | ---- | C] () -- C:\Windows\SysWow64\ssdm.dll
- [2017.03.18 22:58:37 | 001,859,072 | ---- | C] () -- C:\Windows\SysWow64\Windows.Mirage.dll
- [2017.03.18 22:57:47 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
- [2017.03.18 22:57:03 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
- [2017.03.10 23:17:28 | 000,525,600 | ---- | C] () -- C:\Windows\SysWow64\vulkan-1-1-0-42-1.dll
- [2017.03.10 23:17:20 | 000,233,760 | ---- | C] () -- C:\Windows\SysWow64\vulkaninfo-1-1-0-42-1.exe
- [color=#E56717]========== ZeroAccess Check ==========[/color]
- [2017.05.13 08:53:42 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
- [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- "" = C:\Windows\SysNative\windows.storage.dll -- [2017.07.07 09:14:39 | 007,325,584 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- "" = %SystemRoot%\system32\windows.storage.dll -- [2017.07.07 08:31:01 | 005,820,984 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2017.03.18 22:57:58 | 000,961,024 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
- "" = %systemroot%\system32\wbem\fastprox.dll -- [2017.03.18 22:58:50 | 000,770,560 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2017.03.18 22:57:53 | 000,510,464 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Both
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement