'log'
Logfile of random's system information tool 1.10 (written by random/random)
Run by ItsdwaN at 2019-03-05 00:47:19
Microsoft Windows 10 Famille
System drive C: has 867 GB (96%) free of 907 GB
Total RAM: 8106 MB (60% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 00:47:26, on 05/03/2019
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.17763.0001)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe
C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
C:\Users\ItsdwaN\Downloads\RSIT.exe
C:\Program Files (x86)\trend micro\ItsdwaN.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo15.msn.com/?pc=LCTE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo15.msn.com/?pc=LCTE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe"
O4 - HKLM\..\Run: [CLVirtualDrive] "C:\Program Files (x86)\Lenovo\Power2Go\VirtualDrive.exe" /R
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'SERVICE RÉSEAU')
O4 - Global Startup: Avast Cleanup Premium.lnk = C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: @%SystemRoot%\system32\AJRouter.dll,-2 (AJRouter) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - AMD - C:\Windows\System32\DriverStore\FileRepository\u0338124.inf_amd64_b9b08b9409c1138e\B337967\atiesrxx.exe
O23 - Service: @oem25.inf,%HidMonitor.SvcDisp%;Alps SMBus Monitor Service (ApHidMonitorService) - Alps Electric Co., Ltd. - C:\Program Files\Apoint2K\HidMonitorSvc.exe
O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\AppReadiness.dll,-1000 (AppReadiness) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\appxdeploymentserver.dll,-1 (AppXSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (Audiosrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Service %1!s! Update (avast) (avast) - Unknown owner - C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Firewall Service (avast! Firewall) - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Service %1!s! Update (avastm) (avastm) - Unknown owner - C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
O23 - Service: AvastWscReporter - AVAST Software - C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\BcastDVRUserService.dll,-100 (BcastDVRUserService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: BcastDVRUserService_3ee32 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\bdesvc.dll,-100 (BDESVC) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Microsoft.Bluetooth.UserService.dll,-101 (BluetoothUserService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: BluetoothUserService_3ee32 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%windir%\system32\bisrv.dll,-100 (BrokerInfrastructure) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\BTAGService.dll,-101 (BTAGService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\BthAvctpSvc.dll,-101 (BthAvctpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (bthserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\CapabilityAccessManager.dll,-1 (camsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\CaptureService.dll,-100 (CaptureService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: CaptureService_3ee32 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\cbdhsvc.dll,-100 (cbdhsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: cbdhsvc_3ee32 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\cdpsvc.dll,-100 (CDPSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\cdpusersvc.dll,-100 (CDPUserSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: CDPUserSvc_3ee32 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Avast Cleanup Premium (CleanupPSvc) - AVAST Software - C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe
O23 - Service: @%SystemRoot%\system32\ClipSVC.dll,-103 (ClipSVC) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\ConsentUxClient.dll,-100 (ConsentUxUserSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: ConsentUxUserSvc_3ee32 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\coremessaging.dll,-1 (CoreMessagingRegistrar) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @combase.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\das.dll,-100 (DeviceAssociationService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (DeviceInstall) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Windows.Devices.Picker.dll,-1006 (DevicePickerUserSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: DevicePickerUserSvc_3ee32 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\DevicesFlowBroker.dll,-103 (DevicesFlowUserSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: DevicesFlowUserSvc_3ee32 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\DevQueryBroker.dll,-100 (DevQueryBroker) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%systemroot%\system32\DiagSvc.dll,-100 (diagsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\diagtrack.dll,-3001 (DiagTrack) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\Microsoft.Graphics.Display.DisplayEnhancementService.dll,-1000 (DisplayEnhancementService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\Windows.Internal.Management.dll,-100 (DmEnrollmentSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dmwappushsvc.dll,-200 (dmwappushservice) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dosvc.dll,-100 (DoSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\DeviceSetupManager.dll,-1000 (DsmSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dssvc.dll,-10003 (DsSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\dusmsvc.dll,-1 (DusmSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (Eaphost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\embeddedmodesvc.dll,-201 (embeddedmode) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @EnterpriseAppMgmtSvc.dll,-1 (EntAppSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (EventLog) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fhsvc.dll,-101 (fhsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\FrameServer.dll,-100 (FrameServer) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google Inc. - C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.121\elevation_service.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\GraphicsPerfSvc.dll,-100 (GraphicsPerfSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Service Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\hvhostsvc.dll,-100 (HvHost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @oem28.inf,%SERVICE_NAME%;Intel Bluetooth Service (ibtsiva) - Unknown owner - C:\Windows\system32\ibtsiva (file missing)
O23 - Service: @%SystemRoot%\System32\tetheringservice.dll,-4097 (icssvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @oem1.inf,%ImcSvcDisplayName%;System Interface Foundation Service (ImControllerService) - Lenovo Group Ltd. - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service: @%SystemRoot%\system32\InstallService.dll,-200 (InstallService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-500 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%Systemroot%\system32\ipxlatcfg.dll,-500 (IpxlatCfgSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\irmon.dll,-2000 (irmon) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\lfsvc.dll,-1 (lfsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\licensemanagersvc.dll,-200 (LicenseManager) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%windir%\system32\lsm.dll,-1001 (LSM) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\LanguageOverlayServer.dll,-100 (LxpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\moshost.dll,-100 (MapsBroker) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: McAfee CSP Service (mccspsvc) - Unknown owner - C:\Program Files\Common Files\McAfee\CSP\1.5.471.0\McCSPServiceHost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\MessagingService.dll,-100 (MessagingService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: MessagingService_3ee32 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (mpssvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe
O23 - Service: @%systemroot%\system32\NaturalAuth.dll,-100 (NaturalAuthentication) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\ncasvc.dll,-3009 (NcaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\ncbservice.dll,-500 (NcbService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\NcdAutoSetup.dll,-100 (NcdAutoSetup) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\netprofmsvc.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\NetSetupSvc.dll,-3 (NetSetupSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\NgcCtnrSvc.dll,-1 (NgcCtnrSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\APHostRes.dll,-10002 (OneSyncSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: OneSyncSvc_3ee32 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\Windows\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - Unknown owner - C:\Windows\SysWow64\perfhost.exe
O23 - Service: @%SystemRoot%\system32\PhoneserviceRes.dll,-10000 (PhoneSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\UserDataAccessRes.dll,-15001 (PimIndexMaintenanceSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: PimIndexMaintenanceSvc_3ee32 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-200 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll,-1 (PrintNotify) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\PrintWorkflowService.dll,-100 (PrintWorkflowUserSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: PrintWorkflowUserSvc_3ee32 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pushtoinstall.dll,-200 (PushToInstall) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\RDXService.dll,-256 (RetailDemo) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\RMapi.dll,-1001 (RmSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @combase.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\ScDeviceEnum.dll,-100 (ScDeviceEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\Windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SEMgrSvc.dll,-1001 (SEMgrSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\sensorservice.dll,-1000 (SensorService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\sensrsvc.dll,-1000 (SensrSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\Windows\system32\SgrmBroker.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ipnathlp.dll,-106 (SharedAccess) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\SharedRealitySvc.dll,-100 (SharedRealitySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\smphost.dll,-102 (smphost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\SmsRouterSvc.dll,-10001 (SmsRouter) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\Windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\windows.staterepository.dll,-1 (StateRepository) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\StorSvc.dll,-100 (StorSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\svsvc.dll,-101 (svsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%windir%\system32\SystemEventsBrokerServer.dll,-1001 (SystemEventsBroker) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%windir%\system32\TimeBrokerServer.dll,-1001 (TimeBrokerSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\tokenbroker.dll,-100 (TokenBroker) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe
O23 - Service: @%SystemRoot%\system32\umrdp.dll,-1000 (UmRdpService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\UserDataAccessRes.dll,-10003 (UnistoreSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: UnistoreSvc_3ee32 - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Update Agent (UpdateAgentService) - Unknown owner - C:\Program Files\update\UpdateAgent.exe
O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\UserDataAccessRes.dll,-14001 (UserDataSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: UserDataSvc_3ee32 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\usermgr.dll,-100 (UserManager) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\usocore.dll,-101 (UsoSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\vac.dll,-200 (VacSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\icsvc.dll,-801 (vmicguestinterface) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\icsvc.dll,-101 (vmicheartbeat) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\icsvc.dll,-201 (vmickvpexchange) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\icsvcext.dll,-601 (vmicrdv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\icsvc.dll,-301 (vmicshutdown) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\icsvc.dll,-401 (vmictimesync) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\icsvc.dll,-901 (vmicvmsession) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\icsvcext.dll,-501 (vmicvss) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @WaaSMedicSvc.dll,-100 (WaaSMedicSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\WalletService.dll,-1000 (WalletService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\Windows.WARP.JITService.dll,-100 (WarpJITSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wcmsvc.dll,-4097 (Wcmsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wephostsvc.dll,-100 (WEPHOSTSVC) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wfdsconmgrsvc.dll,-9000 (WFDSConMgrSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wiarpc.dll,-2 (WiaRpc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\flightsettings.dll,-103 (wisvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (WlanSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wlidsvc.dll,-100 (wlidsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lpasvc.dll,-1000 (wlpasvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\Windows.Management.Service.dll,-100 (WManSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%systemroot%\system32\workfolderssvc.dll,-102 (workfolderssvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\WpcRefreshTask.dll,-100 (WpcMonSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wpnservice.dll,-1 (WpnService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\WpnUserService.dll,-1 (WpnUserService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: WpnUserService_3ee32 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe
O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\XblAuthManager.dll,-100 (XblAuthManager) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\XblGameSave.dll,-100 (XblGameSave) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\xboxgipsvc.dll,-100 (XboxGipSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\XboxNetApiSvc.dll,-100 (XboxNetApiSvc) - Unknown owner - C:\Windows\system32\svchost.exe
--
End of file - 34620 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer_For_P2G8"=C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe [2014-09-09 110344]
"CLVirtualDrive"=C:\Program Files (x86)\Lenovo\Power2Go\VirtualDrive.exe [2014-09-09 492808]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-06-23 767176]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2019-03-04 259976]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Avast Cleanup Premium.lnk - C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioEndpointBui lder]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioSrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingReg istrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudAddService. Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudBus.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SerCx2.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\usbaudio.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AudioEndpointBui lder]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AudioSrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingReg istrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HdAudAddService. Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HdAudBus.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetSetupSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SerCx2.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\usbaudio.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96C-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"EnableFullTrustStartupTasks"=2
"EnableUwpStartupTasks"=2
"SupportFullTrustStartupTasks"=1
"SupportUwpStartupTasks"=1
"FilterAdministratorToken"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewall policy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewall policy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.cvid"=iccvid.dll
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2019-03-05 07:14:21 ----D---- C:\Users\ItsdwaN\AppData\Roaming\Intel Corporation
2019-03-05 07:13:32 ----D---- C:\Users\ItsdwaN\AppData\Roaming\ATI
2019-03-05 07:11:48 ----D---- C:\ProgramData\Packages
2019-03-05 07:11:30 ----D---- C:\Users\ItsdwaN\AppData\Roaming\Adobe
2019-03-05 07:07:09 ----SD---- C:\Users\ItsdwaN\AppData\Roaming\Microsoft
2019-03-05 07:03:46 ----SHD---- C:\ProgramData\Modèles
2019-03-05 07:03:46 ----SHD---- C:\ProgramData\Menu Démarrer
2019-03-05 07:03:46 ----SHD---- C:\ProgramData\Documents
2019-03-05 07:03:46 ----SHD---- C:\ProgramData\Bureau
2019-03-05 07:03:46 ----SHD---- C:\ProgramData\Application Data
2019-03-05 07:00:53 ----A---- C:\Windows\SysWOW64\PrintConfig.dll
2019-03-05 06:58:00 ----ASH---- C:\hiberfil.sys
2019-03-05 06:43:13 ----D---- C:\Windows\Cnxt
2019-03-05 06:42:05 ----A---- C:\Windows\SysWOW64\SASrv.exe
2019-03-05 06:40:18 ----A---- C:\Windows\SysWOW64\RebootPrompt.exe
2019-03-05 06:40:14 ----D---- C:\ProgramData\Conexant
2019-03-05 06:39:44 ----D---- C:\Intel
2019-03-05 06:39:29 ----D---- C:\Program Files (x86)\Common Files\Intel
2019-03-05 06:39:01 ----D---- C:\ProgramData\USOShared
2019-03-05 06:36:48 ----D---- C:\ProgramData\Lenovo
2019-03-05 06:36:47 ----D---- C:\Program Files (x86)\Lenovo
2019-03-05 06:35:19 ----D---- C:\Windows\ServiceProfiles
2019-03-05 00:47:20 ----D---- C:\Program Files (x86)\trend micro
2019-03-05 00:47:19 ----D---- C:\rsit
2019-03-05 00:02:57 ----D---- C:\Users\ItsdwaN\AppData\Roaming\ZHP
2019-03-04 23:42:11 ----SHD---- C:\Config.Msi
2019-03-04 23:07:59 ----D---- C:\Program Files (x86)\Warcraft III
2019-03-04 23:04:34 ----D---- C:\ProgramData\Blizzard Entertainment
2019-03-04 23:02:33 ----D---- C:\Users\ItsdwaN\AppData\Roaming\Battle.net
2019-03-04 23:00:11 ----D---- C:\Program Files (x86)\Battle.net
2019-03-04 22:59:12 ----D---- C:\Users\ItsdwaN\AppData\Roaming\LSC
2019-03-04 22:54:21 ----D---- C:\ProgramData\Battle.net
2019-03-04 22:48:45 ----D---- C:\Users\ItsdwaN\AppData\Roaming\Intel
2019-03-04 22:38:34 ----D---- C:\Program Files (x86)\AVAST Software
2019-03-04 22:36:43 ----D---- C:\Users\ItsdwaN\AppData\Roaming\AVAST Software
2019-03-04 22:29:55 ----D---- C:\ProgramData\AVAST Software
2019-03-04 22:26:53 ----D---- C:\Program Files (x86)\Google
2019-03-04 18:14:49 ----D---- C:\Windows.old
2019-03-04 18:14:38 ----AS---- C:\Windows\bootstat.dat
2019-03-04 18:09:01 ----D---- C:\Windows\Setup
2019-03-04 18:03:46 ----D---- C:\Windows\SysWOW64\XPSViewer
2019-03-04 18:03:46 ----D---- C:\Windows\SysWOW64\MailContactsCalendarSync
2019-03-04 18:03:46 ----D---- C:\Windows\OCR
2019-03-04 18:03:43 ----D---- C:\Program Files (x86)\Windows Media Player
2019-03-04 18:03:43 ----D---- C:\Program Files (x86)\Reference Assemblies
2019-03-04 18:03:43 ----D---- C:\Program Files (x86)\MSBuild
2019-03-04 18:02:40 ----D---- C:\Windows\SysWOW64\fr
2019-03-04 18:02:40 ----D---- C:\Windows\SysWOW64\drivers\fr-FR
2019-03-04 18:02:33 ----D---- C:\Windows\fr-FR
2019-03-04 18:00:31 ----D---- C:\Windows\SysWOW64\winrm
2019-03-04 18:00:31 ----D---- C:\Windows\SysWOW64\WCN
2019-03-04 18:00:31 ----D---- C:\Windows\SysWOW64\sysprep
2019-03-04 18:00:31 ----D---- C:\Windows\SysWOW64\slmgr
2019-03-04 18:00:31 ----D---- C:\Windows\SysWOW64\Printing_Admin_Scripts
2019-03-04 18:00:30 ----D---- C:\Windows\SysWOW64\en
2019-03-04 18:00:30 ----D---- C:\Windows\SysWOW64\drivers\UMDF
2019-03-04 18:00:30 ----D---- C:\Windows\SysWOW64\drivers\en-US
2019-03-04 18:00:30 ----D---- C:\Windows\SysWOW64\0409
2019-03-04 18:00:26 ----D---- C:\Windows\en-US
2019-03-04 18:00:26 ----D---- C:\Windows\DigitalLocker
2019-03-04 17:58:09 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2019-03-04 17:55:37 ----A---- C:\Windows\SysWOW64\NOISE.DAT
2019-03-04 17:55:37 ----A---- C:\Windows\SysWOW64\msclmd.dll
2019-03-04 17:55:36 ----A---- C:\Windows\SysWOW64\dssec.dat
2019-03-04 17:55:09 ----A---- C:\Windows\fonts\desktop.ini
2019-03-04 17:55:08 ----ASH---- C:\Program Files (x86)\desktop.ini
2019-03-04 17:55:07 ----D---- C:\Windows\Web
2019-03-04 17:55:07 ----D---- C:\Windows\WaaS
2019-03-04 17:55:07 ----D---- C:\Windows\Vss
2019-03-04 17:55:07 ----D---- C:\Windows\twain_32
2019-03-04 17:55:06 ----SD---- C:\Windows\SysWOW64\Nui
2019-03-04 17:55:06 ----SD---- C:\Windows\SysWOW64\F12
2019-03-04 17:55:06 ----SD---- C:\Windows\SysWOW64\DiagSvcs
2019-03-04 17:55:06 ----SD---- C:\Windows\SysWOW64\Configuration
2019-03-04 17:55:06 ----D---- C:\Windows\tracing
2019-03-04 17:55:06 ----D---- C:\Windows\TextInput
2019-03-04 17:55:06 ----D---- C:\Windows\Temp
2019-03-04 17:55:06 ----D---- C:\Windows\TAPI
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\zh-TW
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\zh-CN
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\WinMetadata
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\WindowsPowerShell
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\wbem
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\uk-UA
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\tr-TR
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\th-TH
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\Tasks
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\sv-SE
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\sru
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\sr-Latn-RS
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\sppui
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\spp
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\Speech_OneCore
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\Speech
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\SMI
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\sl-SI
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\sk-SK
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\setup
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\ru-RU
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\ro-RO
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\restore
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\Recovery
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\RasToast
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\ras
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\pt-PT
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\pt-BR
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\pl-PL
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\PerceptionSimulation
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\oobe
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\nl-NL
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\networklist
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\NDF
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\nb-NO
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\MUI
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\Msdtc
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\MSDRM
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\migwiz
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\migration
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\Macromed
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\lv-LV
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\lt-LT
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\LogFiles
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\Licenses
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\ko-KR
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\ja-JP
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\it-IT
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\Ipmi
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\InstallShield
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\InputMethod
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\inetsrv
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\IME
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\icsxml
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\hu-HU
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\hr-HR
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\he-IL
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\GroupPolicyUsers
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\GroupPolicy
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\FxsTmp
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\fr-FR
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\fr-CA
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\fi-FI
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\et-EE
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\es-MX
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\es-ES
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\en-US
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\en-GB
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\el-GR
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\DriverStore
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\drivers
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\downlevel
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\Dism
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\de-DE
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\da-DK
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\cs-CZ
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\config
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\com
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\catroot
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\Bthprops
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\bg-BG
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\ar-SA
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\AppLocker
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64\AdvancedInstallers
2019-03-04 17:55:06 ----D---- C:\Windows\SysWOW64
2019-03-04 17:55:06 ----D---- C:\Windows\SystemResources
2019-03-04 17:55:04 ----SHD---- C:\Windows\Installer
2019-03-04 17:55:04 ----SD---- C:\Windows\Downloaded Program Files
2019-03-04 17:55:04 ----RSD---- C:\Windows\media
2019-03-04 17:55:04 ----RSD---- C:\Windows\Fonts
2019-03-04 17:55:04 ----RD---- C:\Windows\PrintDialog
2019-03-04 17:55:04 ----RD---- C:\Windows\Offline Web Pages
2019-03-04 17:55:04 ----RD---- C:\Windows\ImmersiveControlPanel
2019-03-04 17:55:04 ----HD---- C:\Windows\LanguageOverlayCache
2019-03-04 17:55:04 ----HD---- C:\Windows\ELAMBKUP
2019-03-04 17:55:04 ----D---- C:\Windows\SystemApps
2019-03-04 17:55:04 ----D---- C:\Windows\System
2019-03-04 17:55:04 ----D---- C:\Windows\Speech_OneCore
2019-03-04 17:55:04 ----D---- C:\Windows\Speech
2019-03-04 17:55:04 ----D---- C:\Windows\SKB
2019-03-04 17:55:04 ----D---- C:\Windows\ShellExperiences
2019-03-04 17:55:04 ----D---- C:\Windows\ShellComponents
2019-03-04 17:55:04 ----D---- C:\Windows\ServiceState
2019-03-04 17:55:04 ----D---- C:\Windows\security
2019-03-04 17:55:04 ----D---- C:\Windows\schemas
2019-03-04 17:55:04 ----D---- C:\Windows\SchCache
2019-03-04 17:55:04 ----D---- C:\Windows\Resources
2019-03-04 17:55:04 ----D---- C:\Windows\rescache
2019-03-04 17:55:04 ----D---- C:\Windows\Registration
2019-03-04 17:55:04 ----D---- C:\Windows\Provisioning
2019-03-04 17:55:04 ----D---- C:\Windows\prefetch
2019-03-04 17:55:04 ----D---- C:\Windows\PolicyDefinitions
2019-03-04 17:55:04 ----D---- C:\Windows\PLA
2019-03-04 17:55:04 ----D---- C:\Windows\Performance
2019-03-04 17:55:04 ----D---- C:\Windows\ModemLogs
2019-03-04 17:55:04 ----D---- C:\Windows\Migration
2019-03-04 17:55:04 ----D---- C:\Windows\Logs
2019-03-04 17:55:04 ----D---- C:\Windows\LiveKernelReports
2019-03-04 17:55:04 ----D---- C:\Windows\L2Schemas
2019-03-04 17:55:04 ----D---- C:\Windows\InputMethod
2019-03-04 17:55:04 ----D---- C:\Windows\IME
2019-03-04 17:55:04 ----D---- C:\Windows\IdentityCRL
2019-03-04 17:55:04 ----D---- C:\Windows\Help
2019-03-04 17:55:04 ----D---- C:\Windows\Globalization
2019-03-04 17:55:04 ----D---- C:\Windows\GameBarPresenceWriter
2019-03-04 17:55:04 ----D---- C:\Windows\diagnostics
2019-03-04 17:55:04 ----D---- C:\Windows\debug
2019-03-04 17:55:04 ----D---- C:\Windows\Cursors
2019-03-04 17:55:04 ----D---- C:\Windows\Containers
2019-03-04 17:55:04 ----D---- C:\Windows\Branding
2019-03-04 17:55:04 ----D---- C:\Windows\Boot
2019-03-04 17:55:04 ----D---- C:\Windows\bcastdvr
2019-03-04 17:55:04 ----D---- C:\Windows\AppReadiness
2019-03-04 17:55:03 ----SHD---- C:\Program Files (x86)\Windows Sidebar
2019-03-04 17:55:03 ----SHD---- C:\$Recycle.Bin
2019-03-04 17:55:03 ----SD---- C:\ProgramData\Microsoft
2019-03-04 17:55:03 ----RSD---- C:\Windows\assembly
2019-03-04 17:55:03 ----RD---- C:\Windows\Microsoft.NET
2019-03-04 17:55:03 ----RD---- C:\Program Files (x86)
2019-03-04 17:55:03 ----RD---- C:\Program Files
2019-03-04 17:55:03 ----HD---- C:\ProgramData
2019-03-04 17:55:03 ----D---- C:\Windows\apppatch
2019-03-04 17:55:03 ----D---- C:\Windows\appcompat
2019-03-04 17:55:03 ----D---- C:\Windows\addins
2019-03-04 17:55:03 ----D---- C:\ProgramData\WindowsHolographicDevices
2019-03-04 17:55:03 ----D---- C:\ProgramData\USOPrivate
2019-03-04 17:55:03 ----D---- C:\ProgramData\SoftwareDistribution
2019-03-04 17:55:03 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2019-03-04 17:55:03 ----D---- C:\Program Files (x86)\WindowsPowerShell
2019-03-04 17:55:03 ----D---- C:\Program Files (x86)\Windows Portable Devices
2019-03-04 17:55:03 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2019-03-04 17:55:03 ----D---- C:\Program Files (x86)\windows nt
2019-03-04 17:55:03 ----D---- C:\Program Files (x86)\Windows Multimedia Platform
2019-03-04 17:55:03 ----D---- C:\Program Files (x86)\Windows Mail
2019-03-04 17:55:03 ----D---- C:\Program Files (x86)\Windows Defender
2019-03-04 17:55:03 ----D---- C:\Program Files (x86)\Microsoft.NET
2019-03-04 17:55:03 ----D---- C:\Program Files (x86)\Internet Explorer
2019-03-04 17:55:03 ----D---- C:\Program Files (x86)\Common Files\system
2019-03-04 17:55:03 ----D---- C:\Program Files (x86)\Common Files\Services
2019-03-04 17:55:03 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2019-03-04 17:55:03 ----D---- C:\Program Files (x86)\Common Files
2019-03-04 17:55:03 ----D---- C:\PerfLogs
2019-03-04 17:53:17 ----D---- C:\Windows\INF
2019-03-04 17:46:32 ----D---- C:\Windows\CbsTemp
2019-03-04 17:39:11 ----RD---- C:\Users
2019-03-04 17:39:11 ----D---- C:\Windows\WinSxS
2019-03-04 17:39:11 ----D---- C:\Windows\System32
2019-03-04 17:39:11 ----D---- C:\Windows\servicing
2019-03-04 17:39:11 ----D---- C:\Windows
2019-03-04 17:39:06 ----D---- C:\Windows\Panther
2019-03-04 17:21:16 ----HD---- C:\$SysReset
2019-03-02 16:48:30 ----N---- C:\Windows\SysWOW64\msmpeg2vdec.dll
2019-03-02 16:48:30 ----N---- C:\Windows\SysWOW64\mfsvr.dll
2019-03-02 16:48:30 ----N---- C:\Windows\SysWOW64\mfh264enc.dll
2019-03-02 16:48:30 ----N---- C:\Windows\SysWOW64\DolbyDecMFT.dll
2019-03-02 16:48:29 ----N---- C:\Windows\SysWOW64\mfmp4srcsnk.dll
2019-03-02 16:48:29 ----N---- C:\Windows\SysWOW64\MFMediaEngine.dll
2019-03-02 16:48:29 ----N---- C:\Windows\SysWOW64\mfcore.dll
2019-03-02 16:48:29 ----N---- C:\Windows\SysWOW64\mfasfsrcsnk.dll
2019-03-02 16:48:13 ----N---- C:\Windows\SysWOW64\wsp_health.dll
2019-03-02 16:48:13 ----N---- C:\Windows\SysWOW64\wsp_fs.dll
2019-03-02 16:48:12 ----N---- C:\Windows\SysWOW64\mstscax.dll
2019-03-02 16:48:12 ----N---- C:\Windows\SysWOW64\ieframe.dll
2019-03-02 16:48:04 ----N---- C:\Windows\SysWOW64\mshtml.dll
2019-03-02 16:48:04 ----N---- C:\Windows\SysWOW64\EdgeManager.dll
2019-03-02 16:48:03 ----N---- C:\Windows\SysWOW64\edgehtml.dll
2019-03-02 16:48:02 ----N---- C:\Windows\SysWOW64\webplatstorageserver.dll
2019-03-02 16:48:02 ----N---- C:\Windows\SysWOW64\resutils.dll
2019-03-02 16:48:02 ----N---- C:\Windows\SysWOW64\PlayToManager.dll
2019-03-02 16:48:02 ----N---- C:\Windows\SysWOW64\msrd2x40.dll
2019-03-02 16:48:02 ----N---- C:\Windows\SysWOW64\msi.dll
2019-03-02 16:48:02 ----N---- C:\Windows\SysWOW64\itss.dll
2019-03-02 16:48:02 ----N---- C:\Windows\SysWOW64\clusapi.dll
2019-03-02 16:48:01 ----N---- C:\Windows\SysWOW64\mispace.dll
2019-03-02 16:47:50 ----N---- C:\Windows\SysWOW64\shell32.dll
2019-03-02 16:47:50 ----N---- C:\Windows\SysWOW64\mprddm.dll
2019-03-02 16:47:49 ----N---- C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2019-03-02 16:47:49 ----N---- C:\Windows\SysWOW64\tdh.dll
2019-03-02 16:47:49 ----N---- C:\Windows\SysWOW64\srpapi.dll
2019-03-02 16:47:49 ----N---- C:\Windows\SysWOW64\mcbuilder.exe
2019-03-02 16:47:49 ----N---- C:\Windows\SysWOW64\dwmcore.dll
2019-03-02 16:47:48 ----N---- C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-03-02 16:47:48 ----N---- C:\Windows\SysWOW64\UserDataTimeUtil.dll
2019-03-02 16:47:48 ----N---- C:\Windows\SysWOW64\SndVolSSO.dll
2019-03-02 16:47:48 ----N---- C:\Windows\SysWOW64\cryptngc.dll
2019-03-02 16:47:47 ----N---- C:\Windows\SysWOW64\Windows.Services.TargetedContent.dll
2019-03-02 16:47:47 ----N---- C:\Windows\SysWOW64\rdpserverbase.dll
2019-03-02 16:47:47 ----N---- C:\Windows\SysWOW64\rdpcore.dll
2019-03-02 16:47:47 ----N---- C:\Windows\SysWOW64\rdpbase.dll
2019-03-02 16:47:47 ----N---- C:\Windows\SysWOW64\propsys.dll
2019-03-02 16:47:47 ----N---- C:\Windows\SysWOW64\MapRouter.dll
2019-03-02 16:47:47 ----N---- C:\Windows\SysWOW64\JpMapControl.dll
2019-03-02 16:47:47 ----N---- C:\Windows\SysWOW64\BingOnlineServices.dll
2019-03-02 16:47:47 ----N---- C:\Windows\SysWOW64\AppXDeploymentClient.dll
2019-03-02 16:47:46 ----N---- C:\Windows\SysWOW64\ttdwriter.dll
2019-03-02 16:47:46 ----N---- C:\Windows\SysWOW64\ttdrecordcpu.dll
2019-03-02 16:47:46 ----N---- C:\Windows\SysWOW64\MapGeocoder.dll
2019-03-02 16:47:46 ----N---- C:\Windows\SysWOW64\MapConfiguration.dll
2019-03-02 16:47:46 ----N---- C:\Windows\SysWOW64\InputHost.dll
2019-03-02 16:47:46 ----N---- C:\Windows\SysWOW64\BingMaps.dll
2019-03-02 16:47:45 ----N---- C:\Windows\SysWOW64\wintrust.dll
2019-03-02 16:47:45 ----N---- C:\Windows\SysWOW64\windows.storage.dll
2019-03-02 16:47:45 ----N---- C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll
2019-03-02 16:47:44 ----N---- C:\Windows\SysWOW64\Windows.Devices.Picker.dll
2019-03-02 16:47:44 ----N---- C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2019-03-02 16:47:44 ----N---- C:\Windows\SysWOW64\smartscreenps.dll
2019-03-02 16:47:44 ----N---- C:\Windows\SysWOW64\D3D12.dll
2019-03-02 16:47:44 ----N---- C:\Windows\SysWOW64\d3d10warp.dll
2019-03-02 16:47:44 ----N---- C:\Windows\SysWOW64\cdp.dll
2019-03-02 16:47:43 ----N---- C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll
2019-03-02 16:47:43 ----N---- C:\Windows\SysWOW64\ReAgent.dll
2019-03-02 16:47:42 ----N---- C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2019-03-02 16:47:34 ----N---- C:\Windows\SysWOW64\explorer.exe
2019-03-02 16:47:34 ----N---- C:\Windows\SysWOW64\dsound.dll
2019-03-02 16:47:34 ----N---- C:\Windows\SysWOW64\AudioSes.dll
2019-03-02 16:47:33 ----N---- C:\Windows\SysWOW64\SpatialAudioLicenseSrv.exe
2019-03-02 16:47:33 ----N---- C:\Windows\SysWOW64\CredentialMigrationHandler.dll
2019-03-02 16:47:33 ----N---- C:\Windows\SysWOW64\AudioEng.dll
2019-03-02 16:47:27 ----N---- C:\Windows\SysWOW64\KernelBase.dll
2019-03-02 16:47:20 ----N---- C:\Windows\SysWOW64\pidgenx.dll
2019-03-02 16:46:59 ----N---- C:\Windows\explorer.exe
2019-03-02 16:46:50 ----N---- C:\Windows\SysWOW64\BioCredProv.dll
2019-03-02 16:46:47 ----N---- C:\Windows\SysWOW64\Faultrep.dll
2019-03-02 16:46:45 ----N---- C:\Windows\SysWOW64\wldp.dll
2019-03-02 16:46:45 ----N---- C:\Windows\SysWOW64\ucrtbase.dll
2019-03-02 16:46:45 ----N---- C:\Windows\SysWOW64\tzres.dll
2019-03-02 16:46:45 ----N---- C:\Windows\SysWOW64\aepic.dll
2019-03-02 16:46:43 ----N---- C:\Windows\SysWOW64\winbio.dll
2019-03-02 16:46:43 ----N---- C:\Windows\SysWOW64\win32kfull.sys
2019-03-02 16:46:43 ----N---- C:\Windows\SysWOW64\wimgapi.dll
2019-03-02 16:46:43 ----N---- C:\Windows\SysWOW64\w32tm.exe
2019-03-02 16:46:43 ----N---- C:\Windows\SysWOW64\spacebridge.dll
2019-03-02 16:46:43 ----N---- C:\Windows\SysWOW64\msctf.dll
2019-03-02 16:46:39 ----N---- C:\Windows\SysWOW64\nshwfp.dll
2019-03-01 21:07:10 ----A---- C:\Windows\SysWOW64\igd11dxva32.dll
2019-03-01 21:04:48 ----A---- C:\Windows\SysWOW64\Intel_OpenCL_ICD32.dll
2019-03-01 21:04:46 ----A---- C:\Windows\SysWOW64\IntelOpenCL32.dll
2019-03-01 21:04:45 ----A---- C:\Windows\SysWOW64\IntelCpHeciSvc.exe
2019-03-01 21:04:44 ----A---- C:\Windows\SysWOW64\iglhsip32.dll
2019-03-01 21:04:44 ----A---- C:\Windows\SysWOW64\iglhcp32.dll
2019-03-01 21:04:42 ----A---- C:\Windows\SysWOW64\igfxexps32.dll
2019-03-01 21:04:41 ----A---- C:\Windows\SysWOW64\igfxcmrt32.dll
2019-03-01 21:04:40 ----A---- C:\Windows\SysWOW64\igfxcmjit32.dll
2019-03-01 21:04:40 ----A---- C:\Windows\SysWOW64\igfx11cmrt32.dll
2019-03-01 21:04:39 ----A---- C:\Windows\SysWOW64\igdusc32.dll
2019-03-01 21:04:34 ----A---- C:\Windows\SysWOW64\igdumdim32.dll
2019-03-01 21:04:33 ----A---- C:\Windows\SysWOW64\igdrcl32.dll
2019-03-01 21:04:33 ----A---- C:\Windows\SysWOW64\igdmd32.dll
2019-03-01 21:04:32 ----A---- C:\Windows\SysWOW64\igdmcl32.dll
2019-03-01 21:04:30 ----A---- C:\Windows\SysWOW64\igdfcl32.dll
2019-03-01 21:04:30 ----A---- C:\Windows\SysWOW64\igdde32.dll
2019-03-01 21:04:30 ----A---- C:\Windows\SysWOW64\igdbcl32.dll
2019-03-01 21:04:30 ----A---- C:\Windows\SysWOW64\igdail32.dll
2019-03-01 21:04:29 ----A---- C:\Windows\SysWOW64\igd12umd32.dll
2019-03-01 21:04:24 ----A---- C:\Windows\SysWOW64\igd10iumd32.dll
2019-03-01 21:04:24 ----A---- C:\Windows\SysWOW64\igd10idpp32.dll
2019-03-01 21:04:22 ----A---- C:\Windows\SysWOW64\igc32.dll
2019-03-01 21:04:20 ----A---- C:\Windows\SysWOW64\ig8icd32.dll
2019-03-01 21:04:10 ----A---- C:\Windows\SysWOW64\common_clang32.dll
2019-03-01 14:52:29 ----A---- C:\Windows\SysWOW64\RtCamP.dll
2019-03-01 14:52:29 ----A---- C:\Windows\SysWOW64\RsDecode.dll
2019-03-01 14:51:54 ----A---- C:\Windows\SysWOW64\SynCom.dll
2019-02-22 20:21:31 ----A---- C:\Windows\SysWOW64\ativvsvl.dat
2019-02-22 20:21:31 ----A---- C:\Windows\SysWOW64\ativvsva.dat
2019-02-22 20:20:05 ----A---- C:\Windows\SysWOW64\RapidFireServer.dll
2019-02-22 20:20:05 ----A---- C:\Windows\SysWOW64\Rapidfire.dll
2019-02-22 20:20:05 ----A---- C:\Windows\SysWOW64\mcl32.dll
2019-02-22 20:20:05 ----A---- C:\Windows\SysWOW64\mantleaxl32.dll
2019-02-22 20:20:05 ----A---- C:\Windows\SysWOW64\mantle32.dll
2019-02-22 20:20:05 ----A---- C:\Windows\SysWOW64\GameManager32.dll
2019-02-22 20:20:05 ----A---- C:\Windows\SysWOW64\detoured.dll
2019-02-22 20:19:54 ----A---- C:\Windows\SysWOW64\atisamu32.dll
2019-02-22 20:18:12 ----A---- C:\Windows\SysWOW64\atimpc32.dll
2019-02-22 20:18:12 ----A---- C:\Windows\SysWOW64\atigktxx.dll
2019-02-22 20:18:12 ----A---- C:\Windows\SysWOW64\atidxx32.dll
2019-02-22 20:18:05 ----A---- C:\Windows\SysWOW64\aticfx32.dll
2019-02-22 20:18:00 ----A---- C:\Windows\SysWOW64\atiadlxy.dll
2019-02-22 20:18:00 ----A---- C:\Windows\SysWOW64\atiadlxx.dll
2019-02-22 20:17:49 ----A---- C:\Windows\SysWOW64\amfrt32.dll
2019-02-22 20:17:49 ----A---- C:\Windows\SysWOW64\amf-mft-mjpeg-decoder32.dll
2019-02-22 20:17:48 ----A---- C:\Windows\SysWOW64\OpenCL.dll
2019-02-22 20:17:48 ----A---- C:\Windows\SysWOW64\amdxc32.dll
2019-02-22 20:17:42 ----A---- C:\Windows\SysWOW64\amdpcom32.dll
2019-02-22 20:15:35 ----A---- C:\Windows\SysWOW64\amdmcl32.dll
2019-02-22 20:15:32 ----A---- C:\Windows\SysWOW64\amdlvr32.dll
2019-02-22 20:15:31 ----A---- C:\Windows\SysWOW64\amdhcp32.dll
2019-02-22 20:15:31 ----A---- C:\Windows\SysWOW64\amdgfxinfo32.dll
2019-02-22 20:15:31 ----A---- C:\Windows\SysWOW64\amdave32.dll
2019-02-22 20:15:25 ----A---- C:\Windows\SysWOW64\atieah32.exe
2019-02-22 01:51:23 ----N---- C:\Windows\SysWOW64\xpsrchvw.exe
2019-02-22 01:51:22 ----N---- C:\Windows\SysWOW64\MSFlacDecoder.dll
2019-02-22 01:51:21 ----N---- C:\Windows\SysWOW64\Windows.Media.dll
2019-02-22 01:51:21 ----N---- C:\Windows\SysWOW64\mfreadwrite.dll
2019-02-22 01:51:11 ----N---- C:\Windows\SysWOW64\msjet40.dll
2019-02-22 01:51:11 ----N---- C:\Windows\SysWOW64\AcGenral.dll
2019-02-22 01:51:09 ----N---- C:\Windows\SysWOW64\jscript9.dll
2019-02-22 01:51:07 ----N---- C:\Windows\SysWOW64\msrd3x40.dll
2019-02-22 01:51:07 ----N---- C:\Windows\SysWOW64\Chakra.dll
2019-02-22 01:50:55 ----N---- C:\Windows\SysWOW64\setupcln.dll
2019-02-22 01:50:55 ----N---- C:\Windows\SysWOW64\setupapi.dll
2019-02-22 01:50:55 ----N---- C:\Windows\SysWOW64\rasppp.dll
2019-02-22 01:50:55 ----N---- C:\Windows\SysWOW64\rasman.dll
2019-02-22 01:50:55 ----N---- C:\Windows\SysWOW64\rasapi32.dll
2019-02-22 01:50:46 ----N---- C:\Windows\SysWOW64\wininet.dll
2019-02-22 01:50:46 ----N---- C:\Windows\SysWOW64\mf3216.dll
2019-02-22 01:50:46 ----N---- C:\Windows\SysWOW64\iertutil.dll
2019-02-22 01:50:45 ----N---- C:\Windows\SysWOW64\wincredui.dll
2019-02-22 01:50:45 ----N---- C:\Windows\SysWOW64\uReFS.dll
2019-02-22 01:50:45 ----N---- C:\Windows\SysWOW64\nslookup.exe
2019-02-22 01:50:45 ----N---- C:\Windows\SysWOW64\GdiPlus.dll
2019-02-22 01:50:45 ----N---- C:\Windows\SysWOW64\gdi32full.dll
2019-02-22 01:50:45 ----N---- C:\Windows\SysWOW64\container.dll
2019-02-22 01:50:44 ----N---- C:\Windows\SysWOW64\Windows.StateRepositoryUpgrade.dll
2019-02-22 01:50:44 ----N---- C:\Windows\SysWOW64\Windows.StateRepository.dll
2019-02-22 01:50:44 ----N---- C:\Windows\SysWOW64\apphelp.dll
2019-02-22 01:50:43 ----N---- C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll
2019-02-22 01:50:43 ----N---- C:\Windows\SysWOW64\Windows.Globalization.dll
2019-02-22 01:50:43 ----N---- C:\Windows\SysWOW64\twinapi.appcore.dll
2019-02-22 01:50:43 ----N---- C:\Windows\SysWOW64\TileDataRepository.dll
2019-02-22 01:50:43 ----N---- C:\Windows\SysWOW64\spopk.dll
2019-02-22 01:50:43 ----N---- C:\Windows\SysWOW6