Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Slow Laptop- Windows 10


  • Please log in to reply

#16
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,731 posts
  • MVP

NO you did Latency Monitor OK.  I need a log from Process Explorer:

 

Get Process Explorer

https://live.sysinte...com/procexp.exe

Save it to your desktop then run it (Vista or Win7+ - right click and Run As Administrator).  

View, Select Column, check Verified Signer, OK
Options, Verify Image Signatures


Click twice on the CPU column header  to sort things by CPU usage with the big hitters at the top.  

Wait a full minute then:

File, Save As, Save.  Note the file name.   Open the file  on your desktop and copy and paste the text to a reply.


Copy the next 2 lines:

TASKLIST /SVC  > \junk.txt
notepad \junk.txt

Open an Elevated Command Prompt:
Win 7: Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator
Win 8: http://www.eightforu...indows-8-a.html
win 10: http://www.howtogeek...-in-windows-10/

Right click and Paste (or Edit then Paste) and the copied lines should appear.
Hit Enter if notepad does not open.  Copy and paste the text from notepad into a reply.


 


  • 0

Advertisements


#17
dbrupp

dbrupp

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts

I am so sorry for bombing the process explorer request the first time.  Thank you for re-stating the steps required.  

 

My understanding is that you require Process Explorer & the Elevated cmd prompt with the laptop in airplane mode.  Here they are:

 

Process Explorer:

 

Process CPU Private Bytes Working Set PID Description Company Name Verified Signer
AcrobatNotificationClient.exe Suspended 6,424 K 3,252 K 10032 (Verified) Adobe Systems, Incorporated
AcroCEF.exe 54,288 K 5,048 K 3460 Adobe AcroCEF Adobe Systems Incorporated (Verified) Adobe Inc.
acrotray.exe 1,988 K 7,668 K 10332 AcroTray Adobe Systems Inc. (Verified) Adobe Inc.
AdobeCollabSync.exe 2,784 K 10,952 K 9492 Adobe Collaboration Synchronizer 20.6 Adobe Systems Incorporated (Verified) Adobe Inc.
AGSService.exe 1,636 K 7,592 K 568 Adobe Genuine Software Integrity Service Adobe Systems, Incorporated (Verified) Adobe Inc.
ApplicationFrameHost.exe 5,980 K 10,860 K 3744 Application Frame Host Microsoft Corporation (Verified) Microsoft Windows
armsvc.exe 1,024 K 5,000 K 876 Adobe Acrobat Update Service Adobe Systems (Verified) Adobe Inc.
chrome.exe 1,248 K 3,640 K 5968 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 1,480 K 4,876 K 10840 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 7,344 K 15,916 K 4628 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 68,852 K 41,828 K 14164 Google Chrome Google LLC (Verified) Google LLC
csrss.exe 1,192 K 3,764 K 500 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows Publisher
ctfmon.exe 2,636 K 10,356 K 10980 CTF Loader Microsoft Corporation (Verified) Microsoft Windows
dasHost.exe 652 K 1,872 K 3400 Device Association Framework Provider Host Microsoft Corporation (Verified) Microsoft Windows
dasHost.exe 5,708 K 9,920 K 1900 Device Association Framework Provider Host Microsoft Corporation (Verified) Microsoft Windows
dllhost.exe 4,632 K 11,332 K 6040 COM Surrogate Microsoft Corporation (Verified) Microsoft Windows
dllhost.exe 2,804 K 6,316 K 3840 COM Surrogate Microsoft Corporation (Verified) Microsoft Windows
Dropbox.exe 1,460 K 6,388 K 1144 Dropbox Dropbox, Inc. (Verified) Dropbox, Inc
DropboxUpdate.exe 1,872 K 3,572 K 9712 Dropbox Update Dropbox, Inc. (Verified) Dropbox, Inc
fontdrvhost.exe 1,516 K 2,124 K 752 Usermode Font Driver Host Microsoft Corporation (Verified) Microsoft Windows
fontdrvhost.exe 7,236 K 7,176 K 9052 Usermode Font Driver Host Microsoft Corporation (Verified) Microsoft Windows
HPSupportSolutionsFrameworkService.exe 14,320 K 6,928 K 1588 SolutionsFrameworkService Hewlett-Packard Company (Verified) Hewlett-Packard Company
ibmpmsvc.exe 1,064 K 4,380 K 1456 Lenovo Power Management Service Lenovo. (Verified) LENOVO
Memory Compression 892 K 13,188 K 1548
mqsvc.exe 3,480 K 4,344 K 488 Message Queuing Service Microsoft Corporation (Verified) Microsoft Windows
MusNotifyIcon.exe 2,724 K 3,588 K 5136 MusNotifyIcon.exe Microsoft Corporation (Verified) Microsoft Windows
NisSrv.exe 5,468 K 6,692 K 4412 Microsoft Network Realtime Inspection Service Microsoft Corporation (Verified) Microsoft Windows Publisher
NMSAccessU.exe 896 K 4,320 K 2160 (Verified) Numedia Soft, Inc.
OfficeClickToRun.exe 23,904 K 7,696 K 448 Microsoft Office Click-to-Run (SxS) Microsoft Corporation (Verified) Microsoft Corporation
Registry 0.03 14,020 K 36,952 K 88
RuntimeBroker.exe 3,860 K 7,676 K 10892 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 3,528 K 8,884 K 11556 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 4,352 K 5,144 K 4268 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 5,132 K 5,916 K 6604 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 5,216 K 8,536 K 9808 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 3,004 K 3,948 K 12132 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
ScanToPCActivationApp.exe 2,588 K 5,380 K 13980 ScanToPCActivationApp Hewlett-Packard Co. (Verified) Hewlett Packard
SearchIndexer.exe 34,104 K 8,364 K 5256 Microsoft Windows Search Indexer Microsoft Corporation (Verified) Microsoft Windows
SearchUI.exe Suspended 52,652 K 7,592 K 4780 Search and Cortana application Microsoft Corporation (Verified) Microsoft Windows
SecurityHealthService.exe 3,704 K 7,968 K 8028 Windows Security Health Service Microsoft Corporation (Verified) Microsoft Windows Publisher
SecurityHealthSystray.exe 1,280 K 7,356 K 10156 Windows Security notification icon Microsoft Corporation (Verified) Microsoft Windows
services.exe 3,136 K 6,040 K 636 Services and Controller app Microsoft Corporation (Verified) Microsoft Windows Publisher
SettingSyncHost.exe 5,616 K 5,380 K 13600 Host Process for Setting Synchronization Microsoft Corporation (Verified) Microsoft Windows
ShellExperienceHost.exe Suspended 13,232 K 28,708 K 5928 Windows Shell Experience Host Microsoft Corporation (Verified) Microsoft Windows
sihost.exe 4,924 K 14,140 K 6780 Shell Infrastructure Host Microsoft Corporation (Verified) Microsoft Windows
SkypeBackgroundHost.exe Suspended 1,540 K 2,240 K 13628 Microsoft Skype Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
SkypeBridge.exe 21,932 K 20,796 K 8404 SkypeBridge Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
smss.exe 328 K 572 K 376 Windows Session Manager Microsoft Corporation (Verified) Microsoft Windows Publisher
SMSvcHost.exe 16,652 K 7,268 K 2116 SMSvcHost.exe Microsoft Corporation (Verified) Microsoft Corporation
SMSvcHost.exe 14,972 K 4,592 K 4044 SMSvcHost.exe Microsoft Corporation (Verified) Microsoft Corporation
spoolsv.exe 12,028 K 9,616 K 1980 Spooler SubSystem App Microsoft Corporation (Verified) Microsoft Windows
StartMenuExperienceHost.exe 26,068 K 29,368 K 836 (Verified) Microsoft Windows
svchost.exe 1,316 K 5,288 K 1656 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,440 K 8,048 K 1664 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,004 K 7,308 K 940 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 5,148 K 11,532 K 2404 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,016 K 6,364 K 2556 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,960 K 4,868 K 2764 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,424 K 4,848 K 3272 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 41,756 K 14,536 K 1876 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 5,704 K 6,284 K 8068 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,224 K 5,468 K 1004 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,924 K 7,848 K 7720 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 8,528 K 10,852 K 2024 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,068 K 7,304 K 2076 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4,916 K 8,964 K 1884 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,632 K 7,168 K 1624 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 7,280 K 14,340 K 1784 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 10,584 K 10,544 K 1356 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,396 K 4,072 K 8992 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 5,664 K 11,884 K 920 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 42,016 K 38,528 K 1120 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 7,924 K 13,868 K 8000 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
SynTPHelper.exe 740 K 3,620 K 5664 Synaptics Pointing Device Helper Synaptics Incorporated (Verified) Synaptics Incorporated
SynTPLpr.exe 1,264 K 5,028 K 6052 TouchPad Driver Helper Application Synaptics Incorporated (Verified) Synaptics Incorporated
SystemSettings.exe Suspended 18,948 K 556 K 3896 Settings Microsoft Corporation (Verified) Microsoft Windows
taskhostw.exe 1,260 K 5,868 K 12768 Host Process for Windows Tasks Microsoft Corporation (Verified) Microsoft Windows
unsecapp.exe 1,188 K 5,452 K 3852 Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation (Verified) Microsoft Windows
wininit.exe 1,140 K 5,492 K 572 Windows Start-Up Application Microsoft Corporation (Verified) Microsoft Windows Publisher
winlogon.exe 2,092 K 7,852 K 14020 Windows Logon Application Microsoft Corporation (Verified) Microsoft Windows
WmiPrvSE.exe 2,044 K 7,224 K 13428 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
WmiPrvSE.exe 2,120 K 7,588 K 4492 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
YourPhone.exe Suspended 13,536 K 1,436 K 13172 (No signature was present in the subject)
w3dbsmgr.exe < 0.01 291,064 K 21,044 K 2240 Database Service Manager Pervasive Software Inc. (Verified) Sage Software, Inc.
SkypeApp.exe Suspended 178,072 K 27,032 K 288 SkypeApp Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
svchost.exe < 0.01 66,908 K 45,932 K 1080 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 11,304 K 16,580 K 1296 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
lsass.exe 0.01 5,364 K 12,172 K 644 Local Security Authority Process Microsoft Corporation (Verified) Microsoft Windows Publisher
Dropbox.exe 0.01 2,260 K 9,088 K 13696 Dropbox Dropbox, Inc. (Verified) Dropbox, Inc
chrome.exe 0.01 17,368 K 20,060 K 9412 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 0.01 15,604 K 15,268 K 13904 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 0.01 15,960 K 22,284 K 6588 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 0.01 21,380 K 33,188 K 5436 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 0.01 15,808 K 32,876 K 9656 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 0.02 15,948 K 24,532 K 5504 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 0.02 16,856 K 27,548 K 2648 Google Chrome Google LLC (Verified) Google LLC
WINWORD.EXE 0.02 103,020 K 62,556 K 6004 Microsoft Word Microsoft Corporation (Verified) Microsoft Corporation
chrome.exe 0.02 16,124 K 24,040 K 1348 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 0.02 15,948 K 27,692 K 7748 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 0.02 19,916 K 44,568 K 5392 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 0.02 21,180 K 39,764 K 7460 Google Chrome Google LLC (Verified) Google LLC
udceng.exe 0.02 8,508 K 8,460 K 5888 Universal Document Converter Graphics Engine fCoder Group, Inc. (Verified) fCoder Group, Inc.
chrome.exe 0.02 17,032 K 28,040 K 2868 Google Chrome Google LLC (Verified) Google LLC
QtWebEngineProcess.exe 0.03 33,264 K 24,976 K 9028 Qt Qtwebengineprocess The Qt Company Ltd. (Verified) Dropbox, Inc
QtWebEngineProcess.exe 0.03 31,984 K 9,984 K 11648 Qt Qtwebengineprocess The Qt Company Ltd. (Verified) Dropbox, Inc
chrome.exe 0.03 17,980 K 26,600 K 3884 Google Chrome Google LLC (Verified) Google LLC
CCleaner.exe 0.04 9,800 K 8,548 K 12136 CCleaner Piriform Software Ltd (Verified) Piriform Software Ltd
chrome.exe 0.04 21,284 K 34,408 K 12464 Google Chrome Google LLC (Verified) Google LLC
AGMService.exe 0.05 3,300 K 7,408 K 792 Adobe Genuine Software Service Adobe Systems, Incorporated (Verified) Adobe Inc.
WG111v3.exe 0.05 3,752 K 8,276 K 6080 NetgearCUv2 MFC Application (No signature was present in the subject)
chrome.exe 0.05 25,016 K 47,176 K 816 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 0.06 25,616 K 37,328 K 4316 Google Chrome Google LLC (Verified) Google LLC
svchost.exe 0.06 9,760 K 16,272 K 744 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
chrome.exe 0.06 24,024 K 38,724 K 5292 Google Chrome Google LLC (Verified) Google LLC
CNMNSST2.exe 0.07 2,552 K 8,716 K 9580 Canon IJ Network Scanner Selector EX2 CANON INC. (Verified) Canon Inc.
svchost.exe 0.10 16,468 K 13,648 K 1224 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
AdobeCollabSync.exe 0.16 4,992 K 9,540 K 13328 Adobe Collaboration Synchronizer 20.6 Adobe Systems Incorporated (Verified) Adobe Inc.
explorer.exe 0.18 30,292 K 49,404 K 2576 Windows Explorer Microsoft Corporation (Verified) Microsoft Windows
chrome.exe 0.26 32,424 K 56,780 K 13768 Google Chrome Google LLC (Verified) Google LLC
AcroCEF.exe 0.34 12,268 K 8,964 K 10216 Adobe AcroCEF Adobe Systems Incorporated (Verified) Adobe Inc.
chrome.exe 0.42 55,504 K 46,772 K 9084 Google Chrome Google LLC (Verified) Google LLC
svchost.exe 0.79 3,700 K 8,916 K 10352 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
Dropbox.exe 0.86 259,152 K 71,204 K 8432 Dropbox Dropbox, Inc. (Verified) Dropbox, Inc
csrss.exe 0.95 1,384 K 4,448 K 8232 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows Publisher
System 2.51 72 K 728 K 4
svchost.exe 1.47 37,716 K 19,556 K 1416 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
MsMpEng.exe 1.54 431,744 K 111,068 K 8948 Antimalware Service Executable Microsoft Corporation (Verified) Microsoft Windows Publisher
chrome.exe 1.66 61,156 K 78,724 K 5432 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 1.88 17,052 K 25,692 K 520 Google Chrome Google LLC (Verified) Google LLC
SynTPEnh.exe 2.29 3,968 K 9,188 K 9136 Synaptics TouchPad Enhancements Synaptics Incorporated (Verified) Synaptics Incorporated
dwm.exe 3.09 58,220 K 32,528 K 10232 Desktop Window Manager Microsoft Corporation (Verified) Microsoft Windows
Interrupts 3.13 0 K 0 K n/a Hardware Interrupts and DPCs
chrome.exe 3.36 62,416 K 78,244 K 4516 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 6.74 73,844 K 95,788 K 724 Google Chrome Google LLC (Verified) Google LLC
procexp.exe 14.24 30,816 K 56,376 K 13208 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
System Idle Process 47.82 40 K 4 K 0
 

 

 

________________________________________________________________________________________

Elevated cmd Prompt:

 

 
Image Name                     PID Services                                    
========================= ======== ============================================
System Idle Process              0 N/A                                         
System                           4 N/A                                         
Registry                        88 N/A                                         
smss.exe                       376 N/A                                         
csrss.exe                      500 N/A                                         
wininit.exe                    572 N/A                                         
services.exe                   636 N/A                                         
lsass.exe                      644 KeyIso, SamSs, VaultSvc                     
svchost.exe                    744 BrokerInfrastructure, DcomLaunch, LSM,      
                                   PlugPlay, Power, SystemEventsBroker         
fontdrvhost.exe                752 N/A                                         
svchost.exe                    920 RpcEptMapper, RpcSs                         
svchost.exe                   1080 Appinfo, iphlpsvc, LanmanServer, lfsvc,     
                                   ProfSvc, Schedule, SENS, ShellHWDetection,  
                                   Themes, TokenBroker, UserManager, UsoSvc,   
                                   winmgmt, WpnService, wuauserv               
svchost.exe                   1120 AudioEndpointBuilder,                       
                                   DeviceAssociationService,                   
                                   DisplayEnhancementService, NcbService,      
                                   PcaSvc, StorSvc, SysMain,                   
                                   TabletInputService, TrkWks, WdiSystemHost   
svchost.exe                   1224 Dhcp, EventLog, TimeBrokerSvc,              
                                   WinHttpAutoProxySvc                         
svchost.exe                   1296 BthAvctpSvc, CDPSvc, DispBrokerDesktopSvc,  
                                   EventSystem, FontCache, LicenseManager,     
                                   netprofm, nsi, SstpSvc, WdiServiceHost,     
                                   WebClient                                   
svchost.exe                   1416 CryptSvc, Dnscache, LanmanWorkstation,      
                                   NlaSvc, tapisrv                             
ibmpmsvc.exe                  1456 IBMPMSVC                                    
Memory Compression            1548 N/A                                         
svchost.exe                   1624 Audiosrv                                    
svchost.exe                   1656 DusmSvc                                     
svchost.exe                   1664 Wcmsvc                                      
svchost.exe                   1784 camsvc, StateRepository                     
svchost.exe                   1884 Wlansvc                                     
spoolsv.exe                   1980 Spooler                                     
svchost.exe                   2024 BFE, mpssvc                                 
AGMService.exe                 792 AGMService                                  
AGSService.exe                 568 AGSService                                  
armsvc.exe                     876 AdobeARMservice                             
svchost.exe                    940 AppHostSvc                                  
svchost.exe                   1356 CoreMessagingRegistrar, DPS                 
HPSupportSolutionsFramewo     1588 HPSupportSolutionsFrameworkService          
mqsvc.exe                      488 MSMQ                                        
OfficeClickToRun.exe           448 ClickToRunSvc                               
dasHost.exe                   1900 N/A                                         
svchost.exe                   2076 W3SVC, WAS                                  
SMSvcHost.exe                 2116 NetPipeActivator, NetTcpActivator,          
                                   NetTcpPortSharing                           
NMSAccessU.exe                2160 NMSAccess                                   
w3dbsmgr.exe                  2240 psqlWGE                                     
svchost.exe                   2404 StiSvc                                      
svchost.exe                   2556 RasMan                                      
svchost.exe                   2764 SSDPSRV                                     
svchost.exe                   3272 PolicyAgent                                 
dasHost.exe                   3400 N/A                                         
unsecapp.exe                  3852 N/A                                         
SMSvcHost.exe                 4044 NetMsmqActivator                            
dllhost.exe                   3840 N/A                                         
SearchIndexer.exe             5256 WSearch                                     
SecurityHealthService.exe     8028 SecurityHealthService                       
svchost.exe                   7720 wscsvc                                      
MsMpEng.exe                   8948 WinDefend                                   
NisSrv.exe                    4412 WdNisSvc                                    
svchost.exe                   8992 WbioSrvc                                    
svchost.exe                   1004 RmSvc                                       
svchost.exe                   8068 InstallService                              
svchost.exe                   1876 AppXSvc                                     
svchost.exe                  10352 DoSvc                                       
csrss.exe                     8232 N/A                                         
winlogon.exe                 14020 N/A                                         
dwm.exe                      10232 N/A                                         
fontdrvhost.exe               9052 N/A                                         
sihost.exe                    6780 N/A                                         
svchost.exe                   8000 CDPUserSvc_1197e5e, OneSyncSvc_1197e5e,     
                                   WpnUserService_1197e5e                      
taskhostw.exe                12768 N/A                                         
ctfmon.exe                   10980 N/A                                         
explorer.exe                  2576 N/A                                         
StartMenuExperienceHost.e      836 N/A                                         
RuntimeBroker.exe             6604 N/A                                         
SearchUI.exe                  4780 N/A                                         
RuntimeBroker.exe             4268 N/A                                         
SkypeBackgroundHost.exe      13628 N/A                                         
SkypeApp.exe                   288 N/A                                         
YourPhone.exe                13172 N/A                                         
RuntimeBroker.exe            12132 N/A                                         
RuntimeBroker.exe            10892 N/A                                         
SecurityHealthSystray.exe    10156 N/A                                         
acrotray.exe                 10332 N/A                                         
SynTPEnh.exe                  9136 N/A                                         
CNMNSST2.exe                  9580 N/A                                         
DropboxUpdate.exe             9712 N/A                                         
SynTPLpr.exe                  6052 N/A                                         
ScanToPCActivationApp.exe    13980 N/A                                         
SynTPHelper.exe               5664 N/A                                         
AdobeCollabSync.exe           9492 N/A                                         
AdobeCollabSync.exe          13328 N/A                                         
CCleaner.exe                 12136 N/A                                         
WG111v3.exe                   6080 N/A                                         
Dropbox.exe                   8432 N/A                                         
Dropbox.exe                   1144 N/A                                         
Dropbox.exe                  13696 N/A                                         
RuntimeBroker.exe             9808 N/A                                         
AcrobatNotificationClient    10032 N/A                                         
QtWebEngineProcess.exe        9028 N/A                                         
ShellExperienceHost.exe       5928 N/A                                         
RuntimeBroker.exe            11556 N/A                                         
dllhost.exe                   6040 N/A                                         
AcroCEF.exe                  10216 N/A                                         
AcroCEF.exe                   3460 N/A                                         
QtWebEngineProcess.exe       11648 N/A                                         
SettingSyncHost.exe          13600 N/A                                         
MusNotifyIcon.exe             5136 N/A                                         
SkypeBridge.exe               8404 N/A                                         
ApplicationFrameHost.exe      3744 N/A                                         
chrome.exe                    4516 N/A                                         
chrome.exe                    5968 N/A                                         
chrome.exe                   10840 N/A                                         
chrome.exe                   14164 N/A                                         
chrome.exe                     520 N/A                                         
chrome.exe                    5436 N/A                                         
chrome.exe                    9084 N/A                                         
chrome.exe                   13904 N/A                                         
chrome.exe                    6588 N/A                                         
chrome.exe                    9412 N/A                                         
chrome.exe                    4628 N/A                                         
WmiPrvSE.exe                  4492 N/A                                         
WmiPrvSE.exe                 13428 N/A                                         
chrome.exe                   10116 N/A                                         
chrome.exe                    9200 N/A                                         
smartscreen.exe               8712 N/A                                         
powershell.exe                2376 N/A                                         
conhost.exe                   1740 N/A                                         
tasklist.exe                  1544 N/A                                         
WmiPrvSE.exe                  8300 N/A                                         
 

  • 0

#18
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,731 posts
  • MVP

Go into Settings, Update & Security and Check for Updates.  If you have any please install them and reboot when done.

 

Could you close Chrome and give me a new Process Explorer log with Wireless disabled?


  • 0

#19
dbrupp

dbrupp

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts

Hello Again!

 

The system updates completed and the laptop has been rebooted.

 

I turned off the wi-fi and here are the logs.

 

Proc Expl:

 

Process CPU Private Bytes Working Set PID Description Company Name Verified Signer
AcrobatNotificationClient.exe Suspended 6,484 K 2,156 K 7996 (Verified) Adobe Systems, Incorporated
acrotray.exe 2,008 K 8,500 K 6204 AcroTray Adobe Systems Inc. (Verified) Adobe Inc.
AdobeCollabSync.exe 2,892 K 11,436 K 6644 Adobe Collaboration Synchronizer 20.6 Adobe Systems Incorporated (Verified) Adobe Inc.
AGSService.exe 1,648 K 7,872 K 996 Adobe Genuine Software Integrity Service Adobe Systems, Incorporated (Verified) Adobe Inc.
ApplicationFrameHost.exe 10,120 K 23,560 K 6444 Application Frame Host Microsoft Corporation (Verified) Microsoft Windows
armsvc.exe 1,020 K 5,312 K 1804 Adobe Acrobat Update Service Adobe Systems (Verified) Adobe Inc.
csrss.exe 1,112 K 3,840 K 496 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows Publisher
ctfmon.exe 2,600 K 10,224 K 5132 CTF Loader Microsoft Corporation (Verified) Microsoft Windows
dasHost.exe 652 K 3,344 K 3944 Device Association Framework Provider Host Microsoft Corporation (Verified) Microsoft Windows
dasHost.exe 5,780 K 14,332 K 2456 Device Association Framework Provider Host Microsoft Corporation (Verified) Microsoft Windows
dllhost.exe 2,580 K 8,788 K 4484 COM Surrogate Microsoft Corporation (Verified) Microsoft Windows
dllhost.exe 3,284 K 10,656 K 4216 COM Surrogate Microsoft Corporation (Verified) Microsoft Windows
Dropbox.exe 1,440 K 6,732 K 7480 Dropbox Dropbox, Inc. (Verified) Dropbox, Inc
DropboxUpdate.exe 1,860 K 3,844 K 6368 Dropbox Update Dropbox, Inc. (Verified) Dropbox, Inc
fontdrvhost.exe 1,268 K 2,364 K 820 Usermode Font Driver Host Microsoft Corporation (Verified) Microsoft Windows
fontdrvhost.exe 6,696 K 9,312 K 832 Usermode Font Driver Host Microsoft Corporation (Verified) Microsoft Windows
HPSupportSolutionsFrameworkService.exe 14,360 K 11,232 K 2092 SolutionsFrameworkService Hewlett-Packard Company (Verified) Hewlett-Packard Company
ibmpmsvc.exe 1,020 K 4,216 K 1572 Lenovo Power Management Service Lenovo. (Verified) LENOVO
lsass.exe 4,544 K 11,120 K 640 Local Security Authority Process Microsoft Corporation (Verified) Microsoft Windows Publisher
Memory Compression 636 K 96,296 K 1652
mqsvc.exe 3,460 K 9,352 K 2336 Message Queuing Service Microsoft Corporation (Verified) Microsoft Windows
NisSrv.exe 4,300 K 8,140 K 4536 Microsoft Network Realtime Inspection Service Microsoft Corporation (Verified) Microsoft Windows Publisher
NMSAccessU.exe 896 K 4,524 K 2156 (Verified) Numedia Soft, Inc.
OfficeClickToRun.exe 10,408 K 20,600 K 2076 Microsoft Office Click-to-Run (SxS) Microsoft Corporation (Verified) Microsoft Corporation
Registry 14,208 K 27,976 K 88
RuntimeBroker.exe 2,192 K 11,244 K 6156 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 1,820 K 7,964 K 5440 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 3,828 K 14,196 K 4784 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 2,212 K 13,080 K 7628 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 5,108 K 18,784 K 6040 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 2,120 K 9,168 K 4384 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
ScanToPCActivationApp.exe 2,412 K 11,068 K 6552 ScanToPCActivationApp Hewlett-Packard Co. (Verified) Hewlett Packard
SearchFilterHost.exe 1,484 K 6,168 K 2872 Microsoft Windows Search Filter Host Microsoft Corporation (Verified) Microsoft Windows
SearchIndexer.exe 26,924 K 30,224 K 5608 Microsoft Windows Search Indexer Microsoft Corporation (Verified) Microsoft Windows
SearchProtocolHost.exe 1,836 K 8,592 K 9616 Microsoft Windows Search Protocol Host Microsoft Corporation (Verified) Microsoft Windows
SearchUI.exe Suspended 42,140 K 56,900 K 7852 Search and Cortana application Microsoft Corporation (Verified) Microsoft Windows
SecurityHealthService.exe 3,304 K 13,224 K 2304 Windows Security Health Service Microsoft Corporation (Verified) Microsoft Windows Publisher
SecurityHealthSystray.exe 1,312 K 7,612 K 2284 Windows Security notification icon Microsoft Corporation (Verified) Microsoft Windows
services.exe 3,188 K 6,188 K 632 Services and Controller app Microsoft Corporation (Verified) Microsoft Windows Publisher
SettingSyncHost.exe 2,440 K 5,216 K 560 Host Process for Setting Synchronization Microsoft Corporation (Verified) Microsoft Windows
ShellExperienceHost.exe Suspended 11,884 K 38,252 K 9632 Windows Shell Experience Host Microsoft Corporation (Verified) Microsoft Windows
sihost.exe 4,508 K 18,628 K 4816 Shell Infrastructure Host Microsoft Corporation (Verified) Microsoft Windows
SkypeApp.exe Suspended 534,684 K 28,312 K 4004 SkypeApp Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
SkypeBackgroundHost.exe Suspended 1,540 K 6,712 K 4024 Microsoft Skype Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
smartscreen.exe 7,508 K 20,020 K 3848 Windows Defender SmartScreen Microsoft Corporation (Verified) Microsoft Windows
smss.exe 320 K 816 K 372 Windows Session Manager Microsoft Corporation (Verified) Microsoft Windows Publisher
SMSvcHost.exe 16,616 K 9,504 K 2164 SMSvcHost.exe Microsoft Corporation (Verified) Microsoft Corporation
SMSvcHost.exe 15,024 K 8,096 K 4068 SMSvcHost.exe Microsoft Corporation (Verified) Microsoft Corporation
spoolsv.exe 10,252 K 24,936 K 660 Spooler SubSystem App Microsoft Corporation (Verified) Microsoft Windows
StartMenuExperienceHost.exe 16,032 K 49,916 K 5956 (Verified) Microsoft Windows
svchost.exe 1,452 K 5,328 K 1860 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,032 K 7,376 K 1244 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,016 K 9,924 K 2644 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 5,032 K 16,452 K 4064 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,748 K 8,092 K 5432 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,564 K 8,236 K 1876 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,952 K 8,048 K 7660 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,436 K 6,020 K 3548 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4,592 K 12,972 K 2256 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,128 K 7,564 K 9780 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,072 K 7,532 K 2212 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,284 K 10,180 K 5968 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,504 K 11,252 K 1744 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4,684 K 11,860 K 1888 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,968 K 6,424 K 3140 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 8,692 K 17,108 K 1140 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4,988 K 14,872 K 328 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 8,772 K 15,292 K 976 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 8,456 K 30,356 K 4836 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 38,196 K 48,228 K 1164 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 9,720 K 27,320 K 1340 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 15,528 K 21,836 K 1180 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 7,716 K 17,688 K 1484 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
SynTPHelper.exe 736 K 3,740 K 6972 Synaptics Pointing Device Helper Synaptics Incorporated (Verified) Synaptics Incorporated
SynTPLpr.exe 1,256 K 5,288 K 6784 TouchPad Driver Helper Application Synaptics Incorporated (Verified) Synaptics Incorporated
SystemSettings.exe Suspended 16,632 K 1,188 K 2720 Settings Microsoft Corporation (Verified) Microsoft Windows
taskhostw.exe 5,568 K 14,068 K 7152 Host Process for Windows Tasks Microsoft Corporation (Verified) Microsoft Windows
taskhostw.exe 1,212 K 5,816 K 4892 Host Process for Windows Tasks Microsoft Corporation (Verified) Microsoft Windows
unsecapp.exe 1,136 K 6,660 K 1156 Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation (Verified) Microsoft Windows
w3dbsmgr.exe 284,924 K 13,932 K 2268 Database Service Manager Pervasive Software Inc. (Verified) Sage Software, Inc.
WG111v3.exe 3,400 K 10,964 K 6980 NetgearCUv2 MFC Application (No signature was present in the subject)
wininit.exe 1,096 K 5,200 K 568 Windows Start-Up Application Microsoft Corporation (Verified) Microsoft Windows Publisher
winlogon.exe 2,140 K 7,792 K 716 Windows Logon Application Microsoft Corporation (Verified) Microsoft Windows
WinStore.App.exe Suspended 14,104 K 968 K 8040 Store Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
WmiPrvSE.exe 2,268 K 7,264 K 9888 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
WmiPrvSE.exe 2,188 K 8,408 K 8780 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
WmiPrvSE.exe 2,136 K 7,596 K 8932 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
YourPhone.exe Suspended 11,736 K 24,796 K 5200 (No signature was present in the subject)
svchost.exe < 0.01 40,524 K 65,728 K 1108 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
Dropbox.exe 0.01 2,488 K 9,772 K 7532 Dropbox Dropbox, Inc. (Verified) Dropbox, Inc
svchost.exe 0.01 4,460 K 9,764 K 928 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 0.03 8,048 K 22,904 K 812 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
QtWebEngineProcess.exe 0.04 33,872 K 51,112 K 1944 Qt Qtwebengineprocess The Qt Company Ltd. (Verified) Dropbox, Inc
AGMService.exe 0.05 3,816 K 12,116 K 1812 Adobe Genuine Software Service Adobe Systems, Incorporated (Verified) Adobe Inc.
CCleaner.exe 0.06 9,220 K 25,824 K 6916 CCleaner Piriform Software Ltd (Verified) Piriform Software Ltd
QtWebEngineProcess.exe 0.09 32,228 K 40,524 K 6268 Qt Qtwebengineprocess The Qt Company Ltd. (Verified) Dropbox, Inc
CNMNSST2.exe 0.11 2,432 K 8,848 K 6324 Canon IJ Network Scanner Selector EX2 CANON INC. (Verified) Canon Inc.
HPNetworkCommunicator.exe 0.36 2,224 K 8,984 K 4048 HPNetworkCommunicator Hewlett-Packard Co. (Verified) Hewlett Packard
AdobeCollabSync.exe 0.58 5,252 K 14,924 K 6744 Adobe Collaboration Synchronizer 20.6 Adobe Systems Incorporated (Verified) Adobe Inc.
explorer.exe 0.61 31,476 K 81,220 K 5288 Windows Explorer Microsoft Corporation (Verified) Microsoft Windows
Dropbox.exe 0.81 260,592 K 172,928 K 7044 Dropbox Dropbox, Inc. (Verified) Dropbox, Inc
csrss.exe 1.80 1,360 K 4,292 K 588 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows Publisher
MsMpEng.exe 2.87 138,612 K 118,412 K 2572 Antimalware Service Executable Microsoft Corporation (Verified) Microsoft Windows Publisher
SynTPEnh.exe 3.05 4,288 K 13,000 K 6276 Synaptics TouchPad Enhancements Synaptics Incorporated (Verified) Synaptics Incorporated
System 3.10 72 K 1,856 K 4
Interrupts 3.12 0 K 0 K n/a Hardware Interrupts and DPCs
dwm.exe 7.41 56,220 K 42,912 K 1016 Desktop Window Manager Microsoft Corporation (Verified) Microsoft Windows
procexp.exe 28.40 28,896 K 53,424 K 8468 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
System Idle Process 31.04 40 K 4 K 0
 
 
Elevated CMD prompt:
 
 
Image Name                     PID Services                                    
========================= ======== ============================================
System Idle Process              0 N/A                                         
System                           4 N/A                                         
Registry                        88 N/A                                         
smss.exe                       372 N/A                                         
csrss.exe                      496 N/A                                         
wininit.exe                    568 N/A                                         
csrss.exe                      588 N/A                                         
services.exe                   632 N/A                                         
lsass.exe                      640 KeyIso, SamSs, VaultSvc                     
winlogon.exe                   716 N/A                                         
svchost.exe                    812 BrokerInfrastructure, DcomLaunch, LSM,      
                                   PlugPlay, Power, SystemEventsBroker         
fontdrvhost.exe                820 N/A                                         
fontdrvhost.exe                832 N/A                                         
svchost.exe                    928 RpcEptMapper, RpcSs                         
dwm.exe                       1016 N/A                                         
svchost.exe                   1108 Appinfo, gpsvc, iphlpsvc, LanmanServer,     
                                   lfsvc, ProfSvc, Schedule, SENS,             
                                   ShellHWDetection, Themes, TokenBroker,      
                                   UserManager, UsoSvc, winmgmt, wlidsvc,      
                                   WpnService                                  
svchost.exe                   1140 CoreMessagingRegistrar, DPS                 
svchost.exe                   1164 AudioEndpointBuilder,                       
                                   DeviceAssociationService,                   
                                   DisplayEnhancementService, NcbService,      
                                   PcaSvc, StorSvc, SysMain,                   
                                   TabletInputService, TrkWks, WdiSystemHost   
svchost.exe                   1180 Dhcp, EventLog, TimeBrokerSvc,              
                                   WinHttpAutoProxySvc                         
svchost.exe                   1340 CDPSvc, DispBrokerDesktopSvc, EventSystem,  
                                   FontCache, LicenseManager, netprofm, nsi,   
                                   SstpSvc, WdiServiceHost                     
svchost.exe                   1484 CryptSvc, Dnscache, LanmanWorkstation,      
                                   NlaSvc, tapisrv                             
ibmpmsvc.exe                  1572 IBMPMSVC                                    
Memory Compression            1652 N/A                                         
svchost.exe                   1744 Audiosrv                                    
svchost.exe                   1860 DusmSvc                                     
svchost.exe                   1876 Wcmsvc                                      
svchost.exe                   1888 camsvc, StateRepository                     
svchost.exe                    328 Wlansvc                                     
spoolsv.exe                    660 Spooler                                     
svchost.exe                    976 BFE, mpssvc                                 
armsvc.exe                    1804 AdobeARMservice                             
AGMService.exe                1812 AGMService                                  
AGSService.exe                 996 AGSService                                  
svchost.exe                   1244 AppHostSvc                                  
OfficeClickToRun.exe          2076 ClickToRunSvc                               
HPSupportSolutionsFramewo     2092 HPSupportSolutionsFrameworkService          
NMSAccessU.exe                2156 NMSAccess                                   
SMSvcHost.exe                 2164 NetPipeActivator, NetTcpActivator,          
                                   NetTcpPortSharing                           
svchost.exe                   2212 W3SVC, WAS                                  
svchost.exe                   2256 StiSvc                                      
w3dbsmgr.exe                  2268 psqlWGE                                     
mqsvc.exe                     2336 MSMQ                                        
dasHost.exe                   2456 N/A                                         
MsMpEng.exe                   2572 WinDefend                                   
svchost.exe                   2644 RasMan                                      
svchost.exe                   3140 SSDPSRV                                     
svchost.exe                   3548 PolicyAgent                                 
dasHost.exe                   3944 N/A                                         
SMSvcHost.exe                 4068 NetMsmqActivator                            
unsecapp.exe                  1156 N/A                                         
dllhost.exe                   4484 N/A                                         
NisSrv.exe                    4536 WdNisSvc                                    
sihost.exe                    4816 N/A                                         
svchost.exe                   4836 CDPUserSvc_48a59, OneSyncSvc_48a59,         
                                   WpnUserService_48a59                        
taskhostw.exe                 4892 N/A                                         
ctfmon.exe                    5132 N/A                                         
explorer.exe                  5288 N/A                                         
SearchIndexer.exe             5608 WSearch                                     
StartMenuExperienceHost.e     5956 N/A                                         
RuntimeBroker.exe             6040 N/A                                         
RuntimeBroker.exe             4384 N/A                                         
SkypeApp.exe                  4004 N/A                                         
SkypeBackgroundHost.exe       4024 N/A                                         
YourPhone.exe                 5200 N/A                                         
SecurityHealthSystray.exe     2284 N/A                                         
SecurityHealthService.exe     2304 SecurityHealthService                       
RuntimeBroker.exe             6156 N/A                                         
acrotray.exe                  6204 N/A                                         
SynTPEnh.exe                  6276 N/A                                         
CNMNSST2.exe                  6324 N/A                                         
DropboxUpdate.exe             6368 N/A                                         
ScanToPCActivationApp.exe     6552 N/A                                         
AdobeCollabSync.exe           6644 N/A                                         
AdobeCollabSync.exe           6744 N/A                                         
SynTPLpr.exe                  6784 N/A                                         
CCleaner.exe                  6916 N/A                                         
SynTPHelper.exe               6972 N/A                                         
WG111v3.exe                   6980 N/A                                         
Dropbox.exe                   7044 N/A                                         
Dropbox.exe                   7480 N/A                                         
Dropbox.exe                   7532 N/A                                         
RuntimeBroker.exe             7628 N/A                                         
svchost.exe                   7660 wscsvc                                      
SearchUI.exe                  7852 N/A                                         
QtWebEngineProcess.exe        1944 N/A                                         
AcrobatNotificationClient     7996 N/A                                         
QtWebEngineProcess.exe        6268 N/A                                         
WinStore.App.exe              8040 N/A                                         
ApplicationFrameHost.exe      6444 N/A                                         
RuntimeBroker.exe             5440 N/A                                         
SystemSettings.exe            2720 N/A                                         
svchost.exe                   5968 WbioSrvc                                    
taskhostw.exe                 7152 N/A                                         
svchost.exe                   4064 InstallService                              
smartscreen.exe               3848 N/A                                         
SettingSyncHost.exe            560 N/A                                         
svchost.exe                   5432 ClipSVC                                     
dllhost.exe                   4216 N/A                                         
WmiPrvSE.exe                  8932 N/A                                         
WmiPrvSE.exe                  9888 N/A                                         
ShellExperienceHost.exe       9632 N/A                                         
RuntimeBroker.exe             4784 N/A                                         
svchost.exe                   9780 RmSvc                                       
SearchProtocolHost.exe        9616 N/A                                         
powershell.exe                7768 N/A                                         
conhost.exe                   8612 N/A                                         
tasklist.exe                 10140 N/A                                         
WmiPrvSE.exe                  1828 N/A                                         
 

 


  • 0

#20
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,731 posts
  • MVP

Right click on the clock and select Task Manager (More Details) Startup tab.  Find SynTPEnh and disable.

 

Search for

programs

then hit Enter

 

Find the following programs, click on them and Uninstall:

 

CCleaner

HP Support Solutions Framework

Any printer software for Printers you no longer have.

Any of the following that you do not use:

Acrobat Notification Client -> C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r [2019-01-08] (Adobe Systems Incorporated)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.165.800.0_x86__kgqvnymyfvs32 [2020-04-02] (king.com)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_110.1.671.0_x86__v10z8vjag6ke6 [2020-02-05] (HP Inc.)
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_4.27.32.0_x86__k1h2ywk1493x8 [2019-03-26] (LENOVO INC.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-17] (Microsoft Corporation) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.36.20714.0_x86__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.1224.0_x86__8wekyb3d8bbwe [2020-01-31] (Microsoft Studios) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.36.20714.0_x86__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.36.20714.0_x86__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x86__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x86__8wekyb3d8bbwe [2020-01-12] (Microsoft Corporation)
Reader Notification Client -> C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r [2019-01-08] (Adobe Systems Incorporated)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0 [2020-04-01] (Spotify AB) [Startup Task]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2018-09-10] (Twitter Inc.)
WindowsDVDPlayer -> C:\Program Files\WindowsApps\Microsoft.WindowsDVDPlayer_3.6.13291.0_x86__8wekyb3d8bbwe [2016-05-24] (Microsoft Corporation)

 

 

Make sure your PC is set to High Performance.  Windows makes it hard to do that but there is a way:

https://tunecomp.net...-power-options/

 

Reboot when done and run a new Process Explorer log.   Make sure you wait 5 minutes after a reboot and then wait at least a minute after bringing up Process Explorer before making the log.


  • 0

#21
dbrupp

dbrupp

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts

Hello,

 

Thank you for all of your help.  I have to admit, I got a little weepy uninstalling CCleaner, but I'm over it  :D  Here are the logs with Wi-Fi turned on and airplane mode Off.

 

ProcExpl:

 

Process CPU Private Bytes Working Set PID Description Company Name Verified Signer
AcrobatNotificationClient.exe Suspended 6,592 K 17,064 K 6228 (Verified) Adobe Systems, Incorporated
acrotray.exe 2,012 K 8,900 K 1504 AcroTray Adobe Systems Inc. (Verified) Adobe Inc.
AdobeCollabSync.exe 2,588 K 11,600 K 6216 Adobe Collaboration Synchronizer 20.6 Adobe Systems Incorporated (Verified) Adobe Inc.
AGSService.exe 1,712 K 8,260 K 2136 Adobe Genuine Software Integrity Service Adobe Systems, Incorporated (Verified) Adobe Inc.
ApplicationFrameHost.exe 10,868 K 24,800 K 6800 Application Frame Host Microsoft Corporation (Verified) Microsoft Windows
armsvc.exe 1,068 K 5,484 K 2120 Adobe Acrobat Update Service Adobe Systems (Verified) Adobe Inc.
audiodg.exe 5,916 K 9,228 K 7248 Windows Audio Device Graph Isolation Microsoft Corporation (Verified) Microsoft Windows
csrss.exe 1,104 K 4,152 K 504 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows Publisher
ctfmon.exe 2,564 K 10,688 K 4516 CTF Loader Microsoft Corporation (Verified) Microsoft Windows
dasHost.exe 720 K 3,444 K 3796 Device Association Framework Provider Host Microsoft Corporation (Verified) Microsoft Windows
dasHost.exe 4,812 K 14,156 K 2400 Device Association Framework Provider Host Microsoft Corporation (Verified) Microsoft Windows
dllhost.exe 2,692 K 9,184 K 4700 COM Surrogate Microsoft Corporation (Verified) Microsoft Windows
dllhost.exe 4,872 K 12,588 K 6036 COM Surrogate Microsoft Corporation (Verified) Microsoft Windows
Dropbox.exe 1,460 K 6,952 K 6864 Dropbox Dropbox, Inc. (Verified) Dropbox, Inc
DropboxUpdate.exe 1,888 K 2,088 K 6160 Dropbox Update Dropbox, Inc. (Verified) Dropbox, Inc
fontdrvhost.exe 1,260 K 2,856 K 844 Usermode Font Driver Host Microsoft Corporation (Verified) Microsoft Windows
fontdrvhost.exe 7,904 K 14,048 K 840 Usermode Font Driver Host Microsoft Corporation (Verified) Microsoft Windows
ibmpmsvc.exe 1,012 K 4,640 K 1588 Lenovo Power Management Service Lenovo. (Verified) LENOVO
Memory Compression 200 K 13,332 K 1672
mqsvc.exe 3,520 K 10,272 K 2260 Message Queuing Service Microsoft Corporation (Verified) Microsoft Windows
NMSAccessU.exe 892 K 4,696 K 2344 (Verified) Numedia Soft, Inc.
OfficeClickToRun.exe 9,184 K 20,528 K 2268 Microsoft Office Click-to-Run (SxS) Microsoft Corporation (Verified) Microsoft Corporation
Registry 9,708 K 24,620 K 88
RuntimeBroker.exe 3,988 K 11,576 K 7736 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 2,200 K 11,784 K 4676 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 3,060 K 16,284 K 1112 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 5,504 K 19,788 K 5484 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 6,072 K 19,528 K 4432 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
ScanToPCActivationApp.exe 2,676 K 12,708 K 6188 ScanToPCActivationApp Hewlett-Packard Co. (Verified) Hewlett Packard
SearchIndexer.exe 29,700 K 31,280 K 5096 Microsoft Windows Search Indexer Microsoft Corporation (Verified) Microsoft Windows
SearchUI.exe Suspended 52,504 K 57,392 K 5716 Search and Cortana application Microsoft Corporation (Verified) Microsoft Windows
SecurityHealthSystray.exe 1,332 K 7,740 K 5296 Windows Security notification icon Microsoft Corporation (Verified) Microsoft Windows
sihost.exe 4,428 K 18,804 K 4224 Shell Infrastructure Host Microsoft Corporation (Verified) Microsoft Windows
smartscreen.exe 7,256 K 19,656 K 8160 Windows Defender SmartScreen Microsoft Corporation (Verified) Microsoft Windows
smss.exe 360 K 900 K 376 Windows Session Manager Microsoft Corporation (Verified) Microsoft Windows Publisher
SMSvcHost.exe 16,588 K 10,704 K 2368 SMSvcHost.exe Microsoft Corporation (Verified) Microsoft Corporation
SMSvcHost.exe 14,980 K 8,896 K 3448 SMSvcHost.exe Microsoft Corporation (Verified) Microsoft Corporation
StartMenuExperienceHost.exe 15,644 K 40,772 K 5348 (Verified) Microsoft Windows
svchost.exe 968 K 4,656 K 2376 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,212 K 6,788 K 2948 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,476 K 6,200 K 3368 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,996 K 9,932 K 2820 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 7,412 K 12,504 K 4056 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,056 K 8,716 K 2156 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,036 K 8,680 K 2240 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,564 K 11,260 K 1768 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4,812 K 12,388 K 1944 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,336 K 5,524 K 1808 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,940 K 8,464 K 8088 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,384 K 10,264 K 6280 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 8,196 K 31,800 K 4244 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 5,476 K 13,348 K 1152 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 42,660 K 67,556 K 1104 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,472 K 8,104 K 1816 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 17,328 K 24,128 K 1196 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4,656 K 13,548 K 2028 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
SystemSettings.exe Suspended 17,812 K 17,120 K 4264 Settings Microsoft Corporation (Verified) Microsoft Windows
taskhostw.exe 1,184 K 6,020 K 4316 Host Process for Windows Tasks Microsoft Corporation (Verified) Microsoft Windows
unsecapp.exe 1,152 K 6,680 K 2320 Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation (Verified) Microsoft Windows
w3dbsmgr.exe 284,972 K 36,040 K 2356 Database Service Manager Pervasive Software Inc. (Verified) Sage Software, Inc.
wininit.exe 1,128 K 5,512 K 576 Windows Start-Up Application Microsoft Corporation (Verified) Microsoft Windows Publisher
winlogon.exe 2,184 K 8,000 K 768 Windows Logon Application Microsoft Corporation (Verified) Microsoft Windows
WinStore.App.exe Suspended 16,340 K 6,096 K 3004 Store Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
WmiPrvSE.exe 1,784 K 7,000 K 7244 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
WmiPrvSE.exe 2,136 K 7,568 K 6208 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
YourPhone.exe Suspended 11,680 K 23,656 K 5276 (No signature was present in the subject)
spoolsv.exe < 0.01 10,320 K 26,988 K 600 Spooler SubSystem App Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 0.01 7,916 K 18,220 K 1496 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 0.01 5,180 K 14,336 K 2408 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
lsass.exe 0.01 4,456 K 11,912 K 648 Local Security Authority Process Microsoft Corporation (Verified) Microsoft Windows Publisher
Dropbox.exe 0.01 2,216 K 9,884 K 6904 Dropbox Dropbox, Inc. (Verified) Dropbox, Inc
svchost.exe 0.01 8,180 K 15,136 K 856 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
services.exe 0.02 3,028 K 6,480 K 640 Services and Controller app Microsoft Corporation (Verified) Microsoft Windows Publisher
QtWebEngineProcess.exe 0.02 32,284 K 53,064 K 4388 Qt Qtwebengineprocess The Qt Company Ltd. (Verified) Dropbox, Inc
SecurityHealthService.exe 0.03 3,360 K 13,444 K 3836 Windows Security Health Service Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 0.04 4,344 K 9,716 K 932 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
AGMService.exe 0.04 3,412 K 11,820 K 2128 Adobe Genuine Software Service Adobe Systems, Incorporated (Verified) Adobe Inc.
QtWebEngineProcess.exe 0.04 31,752 K 50,836 K 2800 Qt Qtwebengineprocess The Qt Company Ltd. (Verified) Dropbox, Inc
WG111v3.exe 0.06 3,636 K 12,848 K 6312 NetgearCUv2 MFC Application (No signature was present in the subject)
svchost.exe 0.09 7,812 K 22,420 K 820 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
NisSrv.exe 0.11 4,660 K 8,760 K 5920 Microsoft Network Realtime Inspection Service Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 0.24 8,852 K 21,192 K 1348 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
AdobeCollabSync.exe 0.38 4,392 K 15,196 K 6252 Adobe Collaboration Synchronizer 20.6 Adobe Systems Incorporated (Verified) Adobe Inc.
explorer.exe 0.38 30,776 K 71,140 K 4712 Windows Explorer Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 0.57 32,820 K 45,692 K 1188 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
Dropbox.exe 0.79 261,520 K 281,724 K 6504 Dropbox Dropbox, Inc. (Verified) Dropbox, Inc
csrss.exe 1.06 1,384 K 4,364 K 596 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows Publisher
CNMNSST2.exe 1.22 2,160 K 8,964 K 5596 Canon IJ Network Scanner Selector EX2 CANON INC. (Verified) Canon Inc.
System 1.49 64 K 372 K 4
MsMpEng.exe 1.58 129,772 K 122,340 K 2568 Antimalware Service Executable Microsoft Corporation (Verified) Microsoft Windows Publisher
Interrupts 2.24 0 K 0 K n/a Hardware Interrupts and DPCs
dwm.exe 4.46 51,296 K 37,752 K 1024 Desktop Window Manager Microsoft Corporation (Verified) Microsoft Windows
procexp.exe 24.00 29,184 K 54,372 K 4104 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
System Idle Process 60.65 40 K 4 K 0
 
 
Elevated Cmd:
 
 
Image Name                     PID Services                                    
========================= ======== ============================================
System Idle Process              0 N/A                                         
System                           4 N/A                                         
Registry                        88 N/A                                         
smss.exe                       376 N/A                                         
csrss.exe                      504 N/A                                         
wininit.exe                    576 N/A                                         
csrss.exe                      596 N/A                                         
services.exe                   640 N/A                                         
lsass.exe                      648 KeyIso, SamSs, VaultSvc                     
winlogon.exe                   768 N/A                                         
svchost.exe                    820 BrokerInfrastructure, DcomLaunch, LSM,      
                                   PlugPlay, Power, SystemEventsBroker         
fontdrvhost.exe                840 N/A                                         
fontdrvhost.exe                844 N/A                                         
svchost.exe                    932 RpcEptMapper, RpcSs                         
dwm.exe                       1024 N/A                                         
svchost.exe                   1104 Appinfo, Browser, gpsvc, iphlpsvc,          
                                   LanmanServer, lfsvc, ProfSvc, Schedule,     
                                   SENS, ShellHWDetection, Themes,             
                                   TokenBroker, UserManager, UsoSvc, winmgmt,  
                                   wlidsvc, WpnService, wuauserv               
svchost.exe                   1152 CoreMessagingRegistrar, DPS                 
svchost.exe                   1188 AudioEndpointBuilder,                       
                                   DeviceAssociationService,                   
                                   DisplayEnhancementService, NcbService,      
                                   NgcSvc, PcaSvc, StorSvc, SysMain,           
                                   TabletInputService, TrkWks, WdiSystemHost   
svchost.exe                   1196 Dhcp, EventLog, lmhosts, NgcCtnrSvc,        
                                   TimeBrokerSvc, WinHttpAutoProxySvc          
svchost.exe                   1348 CDPSvc, DispBrokerDesktopSvc, EventSystem,  
                                   FontCache, LicenseManager, netprofm, nsi,   
                                   SstpSvc, WdiServiceHost                     
svchost.exe                   1496 CryptSvc, Dnscache, LanmanWorkstation,      
                                   NlaSvc, tapisrv                             
ibmpmsvc.exe                  1588 IBMPMSVC                                    
Memory Compression            1672 N/A                                         
svchost.exe                   1768 Audiosrv                                    
svchost.exe                   1808 DusmSvc                                     
svchost.exe                   1816 Wcmsvc                                      
svchost.exe                   1944 camsvc, StateRepository                     
svchost.exe                   2028 Wlansvc                                     
spoolsv.exe                    600 Spooler                                     
svchost.exe                    856 BFE, mpssvc                                 
armsvc.exe                    2120 AdobeARMservice                             
AGMService.exe                2128 AGMService                                  
AGSService.exe                2136 AGSService                                  
svchost.exe                   2156 AppHostSvc                                  
svchost.exe                   2240 W3SVC, WAS                                  
mqsvc.exe                     2260 MSMQ                                        
OfficeClickToRun.exe          2268 ClickToRunSvc                               
NMSAccessU.exe                2344 NMSAccess                                   
w3dbsmgr.exe                  2356 psqlWGE                                     
SMSvcHost.exe                 2368 NetPipeActivator, NetTcpActivator,          
                                   NetTcpPortSharing                           
svchost.exe                   2376 Pml Driver HPZ12                            
dasHost.exe                   2400 N/A                                         
svchost.exe                   2408 StiSvc                                      
MsMpEng.exe                   2568 WinDefend                                   
svchost.exe                   2820 RasMan                                      
svchost.exe                   2948 SSDPSRV                                     
svchost.exe                   3368 PolicyAgent                                 
dasHost.exe                   3796 N/A                                         
svchost.exe                   4056 AppXSvc                                     
SMSvcHost.exe                 3448 NetMsmqActivator                            
unsecapp.exe                  2320 N/A                                         
sihost.exe                    4224 N/A                                         
svchost.exe                   4244 CDPUserSvc_41323, OneSyncSvc_41323,         
                                   WpnUserService_41323                        
taskhostw.exe                 4316 N/A                                         
ctfmon.exe                    4516 N/A                                         
dllhost.exe                   4700 N/A                                         
explorer.exe                  4712 N/A                                         
SearchIndexer.exe             5096 WSearch                                     
StartMenuExperienceHost.e     5348 N/A                                         
RuntimeBroker.exe             5484 N/A                                         
SearchUI.exe                  5716 N/A                                         
NisSrv.exe                    5920 WdNisSvc                                    
dllhost.exe                   6036 N/A                                         
RuntimeBroker.exe             4432 N/A                                         
YourPhone.exe                 5276 N/A                                         
SecurityHealthSystray.exe     5296 N/A                                         
RuntimeBroker.exe             4676 N/A                                         
RuntimeBroker.exe             1112 N/A                                         
SecurityHealthService.exe     3836 SecurityHealthService                       
acrotray.exe                  1504 N/A                                         
CNMNSST2.exe                  5596 N/A                                         
DropboxUpdate.exe             6160 N/A                                         
ScanToPCActivationApp.exe     6188 N/A                                         
AdobeCollabSync.exe           6216 N/A                                         
AdobeCollabSync.exe           6252 N/A                                         
WG111v3.exe                   6312 N/A                                         
Dropbox.exe                   6504 N/A                                         
Dropbox.exe                   6864 N/A                                         
Dropbox.exe                   6904 N/A                                         
QtWebEngineProcess.exe        4388 N/A                                         
QtWebEngineProcess.exe        2800 N/A                                         
AcrobatNotificationClient     6228 N/A                                         
svchost.exe                   8088 wscsvc                                      
WinStore.App.exe              3004 N/A                                         
ApplicationFrameHost.exe      6800 N/A                                         
RuntimeBroker.exe             7736 N/A                                         
smartscreen.exe               8160 N/A                                         
SystemSettings.exe            4264 N/A                                         
svchost.exe                   6280 WbioSrvc                                    
audiodg.exe                   7248 N/A                                         
WmiPrvSE.exe                  6208 N/A                                         
WmiPrvSE.exe                  7244 N/A                                         
SearchProtocolHost.exe        5616 N/A                                         
SearchFilterHost.exe          7916 N/A                                         
powershell.exe                7348 N/A                                         
conhost.exe                    908 N/A                                         
HPNetworkCommunicator.exe      112 N/A                                         
tasklist.exe                   780 N/A                                         
WmiPrvSE.exe                  1084 N/A   
 
 
All the best!!                                
 

 


  • 0

#22
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,731 posts
  • MVP

Sorry for the delay.  Took a day off to do nothing.

 

Search for

 

services.msc

 

hit Enter

 

This should bring up the Services Window.

 

Scroll down to SysMain

 

Right click on it and select Properties then change the Startup Type: to Disabled then Apply OK.

 

Search for

dxdiag

hit Enter

Once it finishes (green line in bottom left goes away)

Save All Information.  Point it at your desktop and it should save it as dxdiag.txt.

Exit

Double click on dxdiag.txt and copy and paste the text into a reply.

 

Search for

device manager

hit Enter

 

Click on the arrow in front of Mouse.  If you see the touchpad there right click on it and select Properties then look on the Drivers tab for the date & version number.  Note it down.

then click on the Details tab.  
Change Property to Hardware IDs.  Click on the top one then right click and copy.  Paste that into a reply along with the date and version number.


  • 0

#23
dbrupp

dbrupp

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts

Hello,

 

Take all the time you need.  A day to do nothing and refresh your internal batteries is totally warranted.

 

Here you go.....

 

DxDiag Log:

 

------------------
System Information
------------------
      Time of this report: 4/25/2020, 14:24:55
             Machine name: CHRISSY-PC
               Machine Id: {326DAC05-EC37-4E2C-B508-7FBB36163622}
         Operating System: Windows 10 Home 32-bit (10.0, Build 18363) (18362.19h1_release.190318-1202)
                 Language: English (Regional Setting: English)
      System Manufacturer: LENOVO
             System Model: 7439W6R
                     BIOS: Ver 1.00PARTTBL( (type: BIOS)
                Processor: Intel® Core™2 Duo CPU     P8600  @ 2.40GHz (2 CPUs), ~2.4GHz
                   Memory: 2048MB RAM
      Available OS Memory: 1944MB RAM
                Page File: 2322MB used, 2181MB available
              Windows Dir: C:\WINDOWS
          DirectX Version: DirectX 12
      DX Setup Parameters: Not found
         User DPI Setting: 96 DPI (100 percent)
       System DPI Setting: 96 DPI (100 percent)
          DWM DPI Scaling: Disabled
                 Miracast: Not Available
Microsoft Graphics Hybrid: Not Supported
 DirectX Database Version: Unknown
           DxDiag Version: 10.00.18362.0387 32bit Unicode
 
------------
DxDiag Notes
------------
      Display Tab 1: No problems found.
        Sound Tab 1: No problems found.
          Input Tab: No problems found.
 
--------------------
DirectX Debug Levels
--------------------
Direct3D:    0/4 (retail)
DirectDraw:  0/4 (retail)
DirectInput: 0/5 (retail)
DirectMusic: 0/5 (retail)
DirectPlay:  0/9 (retail)
DirectSound: 0/5 (retail)
DirectShow:  0/6 (retail)
 
---------------
Display Devices
---------------
           Card name: Mobile Intel® 4 Series Express Chipset Family (Microsoft Corporation - WDDM 1.1)
        Manufacturer: Intel Corporation
           Chip type: Mobile Intel® 4 Series Express Chipset Family
            DAC type: Internal
         Device Type: Full Device (POST)
          Device Key: Enum\PCI\VEN_8086&DEV_2A42&SUBSYS_20E417AA&REV_07
       Device Status: 0180200A [DN_DRIVER_LOADED|DN_STARTED|DN_DISABLEABLE|DN_NT_ENUMERATOR|DN_NT_DRIVER] 
 Device Problem Code: No Problem
 Driver Problem Code: Unknown
      Display Memory: 1036 MB
    Dedicated Memory: 64 MB
       Shared Memory: 972 MB
        Current Mode: 1280 x 800 (32 bit) (60Hz)
         HDR Support: Not Supported
    Display Topology: Internal
 Display Color Space: DXGI_COLOR_SPACE_RGB_FULL_G22_NONE_P709
     Color Primaries: Red(0.589844,0.339844), Green(0.320313,0.540039), Blue(0.155273,0.139648), White Point(0.313477,0.329102)
   Display Luminance: Min Luminance = 0.500000, Max Luminance = 270.000000, MaxFullFrameLuminance = 270.000000
        Monitor Name: LCD 1280x800
       Monitor Model: unknown
          Monitor Id: LEN4035
         Native Mode: 1280 x 800(p) (59.999Hz)
         Output Type: Internal
Monitor Capabilities: HDR Not Supported
Display Pixel Format: DISPLAYCONFIG_PIXELFORMAT_32BPP
      Advanced Color: Not Supported
         Driver Name: igdumd32.dll,igd10umd32.dll,igd10umd32.dll
 Driver File Version: 8.15.0010.2702 (English)
      Driver Version: 8.15.10.2702
         DDI Version: 10
      Feature Levels: 10_0,9_1
        Driver Model: WDDM 1.1
 Graphics Preemption: DMA
  Compute Preemption: DMA
            Miracast: Not Supported
      Detachable GPU: No
 Hybrid Graphics GPU: Not Applicable
      Power P-states: Not Applicable
      Virtualization: Not Supported
          Block List: No Blocks
  Catalog Attributes: N/A
   Driver Attributes: Final Retail
    Driver Date/Size: 3/10/2013 8:00:00 PM, 4931384 bytes
         WHQL Logo'd: Yes
     WHQL Date Stamp: Unknown
   Device Identifier: {D7B78E66-6902-11CF-947E-EE00A7C2C535}
           Vendor ID: 0x8086
           Device ID: 0x2A42
           SubSys ID: 0x20E417AA
         Revision ID: 0x0007
  Driver Strong Name: oem13.inf:5f63e5348ad1f097:iCNT0:8.15.10.2702:pci\ven_8086&dev_2a42
      Rank Of Driver: 00EC2001
         Video Accel: ModeMPEG2_A ModeMPEG2_C ModeWMV9_B ModeWMV9_C ModeVC1_B ModeVC1_C 
         DXVA2 Modes: DXVA2_ModeMPEG2_VLD  DXVA2_ModeMPEG2_IDCT  DXVA2_ModeMPEG2_MOCOMP  DXVA2_ModeWMV9_MoComp  DXVA2_ModeWMV9_IDCT  DXVA2_ModeVC1_MoComp  DXVA2_ModeVC1_IDCT  
   Deinterlace Caps: {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
                     {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
                     {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
                     {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
                     {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
                     {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
                     {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
                     {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering 
                     {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch 
                     {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend 
        D3D9 Overlay: Supported
             DXVA-HD: Supported
        DDraw Status: Enabled
          D3D Status: Enabled
          AGP Status: Enabled
       MPO MaxPlanes: 1
            MPO Caps: Not Supported
         MPO Stretch: Not Supported
     MPO Media Hints: Not Supported
         MPO Formats: Not Supported
    PanelFitter Caps: Not Supported
 PanelFitter Stretch: Not Supported
 
-------------
Sound Devices
-------------
            Description: Speakers (High Definition Audio Device)
 Default Sound Playback: Yes
 Default Voice Playback: Yes
            Hardware ID: HDAUDIO\FUNC_01&VEN_14F1&DEV_5051&SUBSYS_17AA211C&REV_1000
        Manufacturer ID: 1
             Product ID: 65535
                   Type: WDM
            Driver Name: HdAudio.sys
         Driver Version: 10.00.18362.0356 (English)
      Driver Attributes: Final Retail
            WHQL Logo'd: Yes
          Date and Size: 9/4/2019 12:00:00 AM, 357376 bytes
            Other Files: 
        Driver Provider: Microsoft
         HW Accel Level: Basic
              Cap Flags: 0xF1F
    Min/Max Sample Rate: 100, 200000
Static/Strm HW Mix Bufs: 1, 0
 Static/Strm HW 3D Bufs: 0, 0
              HW Memory: 0
       Voice Management: No
 EAX™ 2.0 Listen/Src: No, No
   I3DL2™ Listen/Src: No, No
Sensaura™ ZoomFX™: No
 
---------------------
Sound Capture Devices
---------------------
            Description: Microphone (High Definition Audio Device)
  Default Sound Capture: Yes
  Default Voice Capture: Yes
            Driver Name: HdAudio.sys
         Driver Version: 10.00.18362.0356 (English)
      Driver Attributes: Final Retail
          Date and Size: 9/12/2019 11:03:42, 357376 bytes
              Cap Flags: 0x1
           Format Flags: 0xFFFFF
 
---------------------
Video Capture Devices
Number of Devices: 0
---------------------
-------------------
DirectInput Devices
-------------------
      Device Name: Mouse
         Attached: 1
    Controller ID: n/a
Vendor/Product ID: n/a
        FF Driver: n/a
 
      Device Name: Keyboard
         Attached: 1
    Controller ID: n/a
Vendor/Product ID: n/a
        FF Driver: n/a
 
Poll w/ Interrupt: No
 
-----------
USB Devices
-----------
 
----------------
Gameport Devices
----------------
 
------------
PS/2 Devices
------------
+ Standard PS/2 Keyboard
| Matching Device ID: *PNP0303
| Service: i8042prt
| Driver: i8042prt.sys, 3/18/2019 22:39:29, 99328 bytes
| Driver: kbdclass.sys, 3/18/2019 22:39:29, 51000 bytes
+ ThinkPad UltraNav Pointing Device
| Matching Device ID: acpi\ibm0057
| Upper Filters: SynTP
| Service: i8042prt
| Driver: SynTP.sys, 4/24/2013 01:23:06, 347888 bytes
| Driver: SynTPAPI.dll, 4/24/2013 01:23:04, 175856 bytes
| Driver: SynCOM.dll, 4/24/2013 01:23:04, 540400 bytes
| Driver: syndata.bin, 4/24/2013 01:23:02, 1048576 bytes
| Driver: SynTPRes.dll, 4/24/2013 01:23:02, 11783920 bytes
| Driver: SynTPCpl.dll, 4/24/2013 01:23:02, 1330928 bytes
| Driver: SynCntxt.rtf, 4/24/2013 01:23:04, 5527332 bytes
| Driver: SynZMetr.exe, 4/24/2013 01:23:04, 253680 bytes
| Driver: SynMood.exe, 4/24/2013 01:23:04, 245488 bytes
| Driver: SynTPEnh.exe, 4/24/2013 01:23:04, 2379504 bytes
| Driver: SynTPCOM.dll, 4/24/2013 01:23:02, 114416 bytes
| Driver: Tutorial.exe, 4/24/2013 01:23:04, 339696 bytes
| Driver: InstNT.exe, 4/24/2013 01:23:02, 171760 bytes
| Driver: SynISDLL.dll, 4/24/2013 01:23:02, 241392 bytes
| Driver: SynUnst.ini, 4/24/2013 01:23:06, 866677 bytes
| Driver: SynTPHelper.exe, 4/24/2013 01:23:04, 110320 bytes
| Driver: SynTPLpr.exe, 4/24/2013 01:23:04, 134896 bytes
| Driver: TP4table.dat, 4/24/2013 01:23:02, 7887 bytes
| Driver: TP4Sc_JP.htm, 4/24/2013 01:23:06, 12801 bytes
| Driver: TP4Sc_GR.htm, 4/24/2013 01:23:04, 14792 bytes
| Driver: TP4Sc_IT.htm, 4/24/2013 01:23:02, 14300 bytes
| Driver: TP4Sc_SP.htm, 4/24/2013 01:23:06, 13687 bytes
| Driver: TP4Sc_FR.htm, 4/24/2013 01:23:02, 13545 bytes
| Driver: TP4Sc_FI.htm, 4/24/2013 01:23:02, 15345 bytes
| Driver: TP4Sc_NL.htm, 4/24/2013 01:23:04, 13896 bytes
| Driver: TP4Sc_NO.htm, 4/24/2013 01:23:04, 12976 bytes
| Driver: TP4Sc_DK.htm, 4/24/2013 01:23:02, 13551 bytes
| Driver: TP4Sc_SE.htm, 4/24/2013 01:23:02, 12834 bytes
| Driver: TP4Sc_CH.htm, 4/24/2013 01:23:04, 11254 bytes
| Driver: TP4Sc_TW.htm, 4/24/2013 01:23:06, 11070 bytes
| Driver: TP4Sc_TZ.htm, 4/24/2013 01:23:04, 11070 bytes
| Driver: TP4Sc_RU.htm, 4/24/2013 01:23:04, 18621 bytes
| Driver: TP4Sc_BR.htm, 4/24/2013 01:23:04, 14657 bytes
| Driver: TP4Scrol.htm, 4/24/2013 01:23:04, 13233 bytes
| Driver: TP4Sc_JP-win8.htm, 4/24/2013 01:23:04, 13331 bytes
| Driver: TP4Sc_GR-win8.htm, 4/24/2013 01:23:04, 15322 bytes
| Driver: TP4Sc_IT-win8.htm, 4/24/2013 01:23:04, 14830 bytes
| Driver: TP4Sc_SP-win8.htm, 4/24/2013 01:23:02, 14220 bytes
| Driver: TP4Sc_FR-win8.htm, 4/24/2013 01:23:02, 14075 bytes
| Driver: TP4Sc_FI-win8.htm, 4/24/2013 01:23:04, 15868 bytes
| Driver: TP4Sc_NL-win8.htm, 4/24/2013 01:23:02, 14426 bytes
| Driver: TP4Sc_NO-win8.htm, 4/24/2013 01:23:04, 13506 bytes
| Driver: TP4Sc_DK-win8.htm, 4/24/2013 01:23:04, 14081 bytes
| Driver: TP4Sc_SE-win8.htm, 4/24/2013 01:23:04, 13364 bytes
| Driver: TP4Sc_CH-win8.htm, 4/24/2013 01:23:04, 11784 bytes
| Driver: TP4Sc_TW-win8.htm, 4/24/2013 01:23:04, 11603 bytes
| Driver: TP4Sc_TZ-win8.htm, 4/24/2013 01:23:04, 11596 bytes
| Driver: TP4Sc_RU-win8.htm, 4/24/2013 01:23:04, 19151 bytes
| Driver: TP4Sc_BR-win8.htm, 4/24/2013 01:23:06, 15187 bytes
| Driver: TP4Scrol-win8.htm, 4/24/2013 01:23:04, 13763 bytes
| Driver: TP4-A123.GIF, 4/24/2013 01:23:02, 43499 bytes
| Driver: TP4-ASR.GIF, 4/24/2013 01:23:04, 120911 bytes
| Driver: TP4-HEAD.GIF, 4/24/2013 01:23:04, 22797 bytes
| Driver: TP4-I.JPG, 4/24/2013 01:23:04, 894 bytes
| Driver: TP4-IMG.JPG, 4/24/2013 01:23:04, 756 bytes
| Driver: TP4-ISR.JPG, 4/24/2013 01:23:04, 753 bytes
| Driver: TP4-MG.GIF, 4/24/2013 01:23:04, 26890 bytes
| Driver: TP4-NOTE.GIF, 4/24/2013 01:23:02, 201 bytes
| Driver: TP4-SC.GIF, 4/24/2013 01:23:04, 73657 bytes
| Driver: TP4SCROL.CSS, 4/24/2013 01:23:02, 5537 bytes
| Driver: SynPinchZoom.wmv, 4/24/2013 01:23:04, 426019 bytes
| Driver: SynMomentum.wmv, 4/24/2013 01:23:02, 146439 bytes
| Driver: SynLinearScrolling.wmv, 4/24/2013 01:23:04, 258289 bytes
| Driver: SynLinearHScrolling.wmv, 4/24/2013 01:23:02, 224713 bytes
| Driver: SynChiralScrolling.wmv, 4/24/2013 01:23:04, 783933 bytes
| Driver: SynChiralHScrolling.wmv, 4/24/2013 01:23:04, 526657 bytes
| Driver: Syn2FingerScrolling.wmv, 4/24/2013 01:23:04, 336563 bytes
| Driver: Syn2FingerScrollingNB_win8.wmv, 4/24/2013 01:23:02, 796911 bytes
| Driver: Syn2FingerHScrolling.wmv, 4/24/2013 01:23:04, 291805 bytes
| Driver: Syn2FingerHScrollingNB_win8.wmv, 4/24/2013 01:23:02, 376913 bytes
| Driver: Syn3FingerFlick.wmv, 4/24/2013 01:23:02, 571445 bytes
| Driver: Syn3FingerPress.wmv, 4/24/2013 01:23:02, 112893 bytes
| Driver: SynTwistRotate.wmv, 4/24/2013 01:23:04, 437231 bytes
| Driver: SynChiralRotate.wmv, 4/24/2013 01:23:04, 191197 bytes
| Driver: SynPivotRotate.wmv, 4/24/2013 01:23:04, 481959 bytes
| Driver: SynCoverGesture.wmv, 4/24/2013 01:23:04, 146469 bytes
| Driver: Syn4FingerFlick.wmv, 4/24/2013 01:23:02, 795115 bytes
| Driver: Syn4FingerFlick_win8.wmv, 4/24/2013 01:23:04, 598023 bytes
| Driver: mouclass.sys, 3/18/2019 22:39:29, 48440 bytes
| Driver: i8042prt.sys, 3/18/2019 22:39:29, 99328 bytes
| Driver: SynTPCo14.dll, 4/24/2013 01:23:04, 143088 bytes
| Driver: WdfCoInstaller01009.dll, 4/24/2013 01:23:04, 1461992 bytes
 
------------------------
Disk & DVD/CD-ROM Drives
------------------------
      Drive: C:
 Free Space: 62.8 GB
Total Space: 151.9 GB
File System: NTFS
      Model: FUJITSU MHZ2160BJ G1
 
      Drive: D:
      Model: HL-DT-ST DVDRAM GT30N
     Driver: C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS, 10.00.18362.0001 (English), 3/18/2019 22:39:26, 125952 bytes
 
--------------
System Devices
--------------
     Name: PCI Express Root Port
Device ID: PCI\VEN_8086&DEV_2940&SUBSYS_20F317AA&REV_03\3&E89B380&0&E0
   Driver: C:\WINDOWS\system32\DRIVERS\pci.sys, 10.00.18362.0752 (English), 4/18/2020 15:34:57, 325136 bytes
 
     Name: Intel® ICH9 Family USB Universal Host Controller - 2935
Device ID: PCI\VEN_8086&DEV_2935&SUBSYS_20F017AA&REV_03\3&E89B380&0&E9
   Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 24576 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 381240 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 384824 bytes
 
     Name: Intel® ICH9 Family USB Universal Host Controller - 2936
Device ID: PCI\VEN_8086&DEV_2936&SUBSYS_20F017AA&REV_03\3&E89B380&0&EA
   Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 24576 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 381240 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 384824 bytes
 
     Name: Mobile Intel® 4 Series Express Chipset Family (Microsoft Corporation - WDDM 1.1)
Device ID: PCI\VEN_8086&DEV_2A42&SUBSYS_20E417AA&REV_07\3&E89B380&0&10
   Driver: C:\WINDOWS\system32\DRIVERS\igdkmd32.sys, 8.15.0010.2702 (English), 3/23/2012 18:09:38, 9036288 bytes
   Driver: C:\WINDOWS\system32\igdumd32.dll, 8.15.0010.2702 (English), 3/11/2013 15:49:34, 4931384 bytes
   Driver: C:\WINDOWS\system32\igkrng500.bin, 3/23/2012 18:08:56, 982240 bytes
   Driver: C:\WINDOWS\system32\igcompkrng500.bin, 3/23/2012 18:08:56, 439308 bytes
   Driver: C:\WINDOWS\system32\igfcg500m.bin, 3/23/2012 18:08:56, 92356 bytes
   Driver: C:\WINDOWS\system32\iglhxs32.vp, 3/23/2012 18:41:54, 51684 bytes
   Driver: C:\WINDOWS\system32\iglhxo32.vp, 3/23/2012 17:54:38, 60015 bytes
   Driver: C:\WINDOWS\system32\iglhxc32.vp, 3/23/2012 17:54:38, 60226 bytes
   Driver: C:\WINDOWS\system32\iglhxg32.vp, 3/23/2012 17:54:38, 60254 bytes
   Driver: C:\WINDOWS\system32\iglhxa32.vp, 3/23/2012 17:54:38, 1090 bytes
   Driver: C:\WINDOWS\system32\iglhxa32.cpa, 3/23/2012 17:54:38, 1921265 bytes
   Driver: C:\WINDOWS\system32\iglhcp32.dll, 1.05.0002.0001 (English), 3/23/2012 22:47:04, 147456 bytes
   Driver: C:\WINDOWS\system32\iglhsip32.dll, 1.05.0002.0001 (English), 3/23/2012 22:47:04, 208896 bytes
   Driver: C:\WINDOWS\system32\igd10umd32.dll, 8.15.0010.2702 (English), 3/11/2013 15:49:28, 4370016 bytes
 
     Name: High Definition Audio Controller
Device ID: PCI\VEN_8086&DEV_293E&SUBSYS_20F217AA&REV_03\3&E89B380&0&D8
   Driver: C:\WINDOWS\system32\DRIVERS\hdaudbus.sys, 10.00.18362.0693 (English), 3/14/2020 11:21:49, 92160 bytes
   Driver: C:\WINDOWS\system32\DRIVERS\drmk.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:23, 70144 bytes
   Driver: C:\WINDOWS\system32\DRIVERS\portcls.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:23, 279552 bytes
 
     Name: PCI Express Root Port
Device ID: PCI\VEN_8086&DEV_2942&SUBSYS_20F317AA&REV_03\3&E89B380&0&E1
   Driver: C:\WINDOWS\system32\DRIVERS\pci.sys, 10.00.18362.0752 (English), 4/18/2020 15:34:57, 325136 bytes
 
     Name: Intel® ICH9 Family USB Universal Host Controller - 2937
Device ID: PCI\VEN_8086&DEV_2937&SUBSYS_20F017AA&REV_03\3&E89B380&0&D0
   Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 24576 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 381240 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 384824 bytes
 
     Name: Mobile Intel® 4 Series Express Chipset Family (Microsoft Corporation - WDDM 1.1)
Device ID: PCI\VEN_8086&DEV_2A43&SUBSYS_20E417AA&REV_07\3&E89B380&0&11
   Driver: C:\WINDOWS\system32\DRIVERS\igdkmd32.sys, 8.15.0010.2702 (English), 3/23/2012 18:09:38, 9036288 bytes
   Driver: C:\WINDOWS\system32\igdumd32.dll, 8.15.0010.2702 (English), 3/11/2013 15:49:34, 4931384 bytes
   Driver: C:\WINDOWS\system32\igkrng500.bin, 3/23/2012 18:08:56, 982240 bytes
   Driver: C:\WINDOWS\system32\igcompkrng500.bin, 3/23/2012 18:08:56, 439308 bytes
   Driver: C:\WINDOWS\system32\igfcg500m.bin, 3/23/2012 18:08:56, 92356 bytes
   Driver: C:\WINDOWS\system32\iglhxs32.vp, 3/23/2012 18:41:54, 51684 bytes
   Driver: C:\WINDOWS\system32\iglhxo32.vp, 3/23/2012 17:54:38, 60015 bytes
   Driver: C:\WINDOWS\system32\iglhxc32.vp, 3/23/2012 17:54:38, 60226 bytes
   Driver: C:\WINDOWS\system32\iglhxg32.vp, 3/23/2012 17:54:38, 60254 bytes
   Driver: C:\WINDOWS\system32\iglhxa32.vp, 3/23/2012 17:54:38, 1090 bytes
   Driver: C:\WINDOWS\system32\iglhxa32.cpa, 3/23/2012 17:54:38, 1921265 bytes
   Driver: C:\WINDOWS\system32\iglhcp32.dll, 1.05.0002.0001 (English), 3/23/2012 22:47:04, 147456 bytes
   Driver: C:\WINDOWS\system32\iglhsip32.dll, 1.05.0002.0001 (English), 3/23/2012 22:47:04, 208896 bytes
   Driver: C:\WINDOWS\system32\igd10umd32.dll, 8.15.0010.2702 (English), 3/11/2013 15:49:28, 4370016 bytes
 
     Name: Intel® ICH9 Family USB Universal Host Controller - 2938
Device ID: PCI\VEN_8086&DEV_2938&SUBSYS_20F017AA&REV_03\3&E89B380&0&D1
   Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 24576 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 381240 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 384824 bytes
 
     Name: Intel® ICH9 Family USB Universal Host Controller - 2939
Device ID: PCI\VEN_8086&DEV_2939&SUBSYS_20F017AA&REV_03\3&E89B380&0&D2
   Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 24576 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 381240 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 384824 bytes
 
     Name: Intel® ICH9 Family USB2 Enhanced Host Controller - 293A
Device ID: PCI\VEN_8086&DEV_293A&SUBSYS_20F117AA&REV_03\3&E89B380&0&EF
   Driver: C:\WINDOWS\system32\drivers\usbehci.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 73016 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 381240 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 384824 bytes
 
     Name: PCI Express Root Port
Device ID: PCI\VEN_8086&DEV_2946&SUBSYS_20F317AA&REV_03\3&E89B380&0&E3
   Driver: C:\WINDOWS\system32\DRIVERS\pci.sys, 10.00.18362.0752 (English), 4/18/2020 15:34:57, 325136 bytes
 
     Name: PCI-to-PCI Bridge
Device ID: PCI\VEN_8086&DEV_2448&SUBSYS_20F417AA&REV_93\3&E89B380&0&F0
   Driver: C:\WINDOWS\system32\DRIVERS\pci.sys, 10.00.18362.0752 (English), 4/18/2020 15:34:57, 325136 bytes
 
     Name: Intel® ICH9 Family USB2 Enhanced Host Controller - 293C
Device ID: PCI\VEN_8086&DEV_293C&SUBSYS_20F117AA&REV_03\3&E89B380&0&D7
   Driver: C:\WINDOWS\system32\drivers\usbehci.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 73016 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 381240 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 384824 bytes
 
     Name: Synaptics SMBus Driver
Device ID: PCI\VEN_8086&DEV_2930&SUBSYS_20F917AA&REV_03\3&E89B380&0&FB
   Driver: C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys, 16.02.0019.0007 (English), 4/24/2013 01:23:02, 38640 bytes
   Driver: C:\Program Files\Synaptics\SynTP\SmbDrv.ini, 4/24/2013 01:23:04, 5525 bytes
   Driver: C:\WINDOWS\system32\WdfCoInstaller01009.dll, 1.09.7600.16385 (English), 4/24/2013 01:23:04, 1461992 bytes
 
     Name: PCI Express Root Port
Device ID: PCI\VEN_8086&DEV_2948&SUBSYS_20F317AA&REV_03\3&E89B380&0&E4
   Driver: C:\WINDOWS\system32\DRIVERS\pci.sys, 10.00.18362.0752 (English), 4/18/2020 15:34:57, 325136 bytes
 
     Name: Intel® Management Engine Interface
Device ID: PCI\VEN_8086&DEV_2A44&SUBSYS_20E617AA&REV_07\3&E89B380&0&18
   Driver: C:\WINDOWS\system32\DRIVERS\HECI.sys, 4.02.0000.1008 (English), 6/23/2009 15:49:58, 40832 bytes
 
     Name: Intel® 82567LM Gigabit Network Connection
Device ID: PCI\VEN_8086&DEV_10F5&SUBSYS_20EE17AA&REV_03\3&E89B380&0&C8
   Driver: C:\WINDOWS\system32\DRIVERS\e1y6032.sys, 10.01.0010.0000 (English), 3/18/2019 22:39:24, 217600 bytes
 
     Name: CPU to DRAM Controller
Device ID: PCI\VEN_8086&DEV_2A40&SUBSYS_20E017AA&REV_07\3&E89B380&0&00
   Driver: n/a
 
     Name: LPC Controller
Device ID: PCI\VEN_8086&DEV_2917&SUBSYS_20F517AA&REV_03\3&E89B380&0&F8
   Driver: C:\WINDOWS\system32\DRIVERS\msisadrv.sys, 10.00.18362.0267 (English), 8/20/2019 22:48:39, 16696 bytes
 
     Name: Intel® WiFi Link 5100 AGN
Device ID: PCI\VEN_8086&DEV_4237&SUBSYS_12118086&REV_00\001E65FFFF3A6A1E00
   Driver: C:\WINDOWS\system32\DRIVERS\NETwNs32.sys, 14.03.0002.0001 (English), 5/2/2013 07:16:40, 7530736 bytes
   Driver: C:\WINDOWS\system32\NETwNc32.dll, 14.00.0000.0008 (English), 5/2/2013 07:16:38, 690928 bytes
   Driver: C:\WINDOWS\system32\NETwNr32.dll, 14.00.0000.0008 (English), 5/2/2013 07:16:40, 2767600 bytes
 
     Name: Ricoh R/RL/5C476(II) or Compatible CardBus Controller
Device ID: PCI\VEN_1180&DEV_0476&SUBSYS_20C617AA&REV_BA\4&132DB2BD&0&00F0
   Driver: C:\WINDOWS\system32\DRIVERS\pcmcia.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:21, 98320 bytes
   Driver: C:\WINDOWS\system32\DRIVERS\pci.sys, 10.00.18362.0752 (English), 4/18/2020 15:34:57, 325136 bytes
 
     Name: Standard SATA AHCI Controller
Device ID: PCI\VEN_8086&DEV_2929&SUBSYS_20F817AA&REV_03\3&E89B380&0&FA
   Driver: C:\WINDOWS\system32\DRIVERS\storahci.sys, 10.00.18362.0693 (English), 3/14/2020 11:21:50, 144400 bytes
 
     Name: Ricoh 1394 OHCI Compliant Host Controller
Device ID: PCI\VEN_1180&DEV_0832&SUBSYS_20C717AA&REV_04\4&132DB2BD&0&01F0
   Driver: C:\WINDOWS\system32\DRIVERS\1394ohci.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:26, 190464 bytes
 
     Name: Intel® ICH9 Family USB Universal Host Controller - 2934
Device ID: PCI\VEN_8086&DEV_2934&SUBSYS_20F017AA&REV_03\3&E89B380&0&E8
   Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 24576 bytes
   Driver: C:\WINDOWS\system32\drivers\usbport.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 381240 bytes
   Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 10.00.18362.0001 (English), 3/18/2019 22:39:29, 384824 bytes
 
------------------
DirectShow Filters
------------------
 
DirectShow Filters:
WMAudio Decoder DMO,0x00800800,1,1,WMADMOD.DLL,10.00.18362.0145
WMAPro over S/PDIF DMO,0x00600800,1,1,WMADMOD.DLL,10.00.18362.0145
WMSpeech Decoder DMO,0x00600800,1,1,WMSPDMOD.DLL,10.00.18362.0001
MP3 Decoder DMO,0x00600800,1,1,mp3dmod.dll,10.00.18362.0001
Mpeg4s Decoder DMO,0x00800001,1,1,mp4sdecd.dll,10.00.18362.0001
WMV Screen decoder DMO,0x00600800,1,1,wmvsdecd.dll,10.00.18362.0001
WMVideo Decoder DMO,0x00800001,1,1,wmvdecod.dll,10.00.18362.0001
Mpeg43 Decoder DMO,0x00800001,1,1,mp43decd.dll,10.00.18362.0001
Mpeg4 Decoder DMO,0x00800001,1,1,mpg4decd.dll,10.00.18362.0001
LEAD DVD Playlist Parser,0x00600000,1,2,,
ffdshow Video Decoder,0xff800001,2,1,ffdshow.ax,1.00.0007.3064
Pixela mpeg system multiplexer,0x00200000,2,1,PixPsMux.ax,1.01.0004.0000
ffdshow raw video filter,0x00200000,2,1,ffdshow.ax,1.00.0007.3064
ffdshow Audio Decoder,0x3fffffff,1,1,ffdshow.ax,1.00.0007.3064
DV Muxer,0x00400000,0,0,qdv.dll,10.00.18362.0001
Color Space Converter,0x00400001,1,1,quartz.dll,10.00.18362.0001
WM ASF Reader,0x00400000,0,0,qasf.dll,12.00.18362.0001
PIXELA MPEG2 Video Decoder(IMX),0x00200001,1,1,ImMpvDec.ax,1.01.0003.0002
AVI Splitter,0x00600000,1,1,quartz.dll,10.00.18362.0001
VGA 16 Color Ditherer,0x00400000,1,1,quartz.dll,10.00.18362.0001
SBE2MediaTypeProfile,0x00200000,0,0,sbe.dll,10.00.18362.0001
Microsoft DTV-DVD Video Decoder,0x005fffff,2,4,msmpeg2vdec.dll,10.00.18362.0693
AC3 Parser Filter,0x00600000,1,1,mpg2splt.ax,10.00.18362.0001
StreamBufferSink,0x00200000,0,0,sbe.dll,10.00.18362.0001
MJPEG Decompressor,0x00600000,1,1,quartz.dll,10.00.18362.0001
MPEG-I Stream Splitter,0x00600000,1,2,quartz.dll,10.00.18362.0001
SAMI (CC) Parser,0x00400000,1,1,quartz.dll,10.00.18362.0001
VBI Codec,0x00600000,1,4,VBICodec.ax,10.00.18362.0001
MPC - MPEG-2 Video Decoder (Gabest),0x00500001,1,1,Mpeg2DecFilter.ax,1.03.1264.0000
MPEG-2 Splitter,0x005fffff,1,0,mpg2splt.ax,10.00.18362.0001
Closed Captions Analysis Filter,0x00200000,2,5,cca.dll,10.00.18362.0001
SBE2FileScan,0x00200000,0,0,sbe.dll,10.00.18362.0001
Microsoft MPEG-2 Video Encoder,0x00200000,1,1,msmpeg2enc.dll,10.00.18362.0001
MPC - FLV Splitter (Gabest),0x00600000,1,1,FLVSplitter.ax,1.03.1264.0000
Internal Script Command Renderer,0x00800001,1,0,quartz.dll,10.00.18362.0001
MPEG Audio Decoder,0x03680001,1,1,quartz.dll,10.00.18362.0001
WavPack Audio Decoder,0x00600000,1,1,WavPackDSDecoder.ax,1.01.0000.0484
DV Splitter,0x00600000,1,2,qdv.dll,10.00.18362.0001
Video Mixing Renderer 9,0x00200000,1,0,quartz.dll,10.00.18362.0001
PIXELA MPEG2-Splitter(IMX),0x00400000,1,2,ImxPsSpl.ax,1.00.0005.0026
Haali Media Splitter,0x00800001,0,1,splitter.ax,1.09.0042.0001
Haali Media Splitter (AR),0x00400000,1,1,splitter.ax,1.09.0042.0001
Microsoft MPEG-2 Encoder,0x00200000,2,1,msmpeg2enc.dll,10.00.18362.0001
Xvid MPEG-4 Video Decoder,0x00800000,1,1,,
ACM Wrapper,0x00600000,1,1,quartz.dll,10.00.18362.0001
Video Renderer,0x00800001,1,0,quartz.dll,10.00.18362.0001
PIXELA MPEG2 Video Decoder(IMX-DES),0x00200001,1,1,ImMpvDec_des.ax,1.01.0003.0004
MPEG-2 Video Stream Analyzer,0x00200000,0,0,sbe.dll,10.00.18362.0001
Line 21 Decoder,0x00600000,1,1,qdvd.dll,10.00.18362.0001
Video Port Manager,0x00600000,2,1,quartz.dll,10.00.18362.0001
Video Renderer,0x00400000,1,0,quartz.dll,10.00.18362.0001
Haali Video Renderer,0x00200000,1,0,dxr.dll,
VPS Decoder,0x00200000,0,0,WSTPager.ax,10.00.18362.0001
WM ASF Writer,0x00400000,0,0,qasf.dll,12.00.18362.0001
VBI Surface Allocator,0x00600000,1,1,vbisurf.ax,
File writer,0x00200000,1,0,qcap.dll,10.00.18362.0001
Pixela Audio format convert Filter,0x00200000,1,1,aufconpx.ax,1.00.0001.0007
PIXELA DVDCam Source Filter (IMx),0x00200000,0,1,PxDVDFilter.ax,1.00.0000.0002
Haali Simple Media Splitter,0x00200000,0,1,splitter.ax,1.09.0042.0001
DirectVobSub,0x00200000,2,1,VSFilter.dll,1.03.1264.0000
PiXELA AC-3 Decoder,0x00200001,1,1,px_ac3dec.ax,1.00.0000.0006
DirectVobSub (auto-loading version),0x00800002,2,1,VSFilter.dll,1.03.1264.0000
DVD Navigator,0x00200000,0,3,qdvd.dll,10.00.18362.0001
Overlay Mixer2,0x00200000,1,1,qdvd.dll,10.00.18362.0001
Haali Matroska Muxer,0x00200000,1,0,splitter.ax,1.09.0042.0001
AVI Draw,0x00600064,9,1,quartz.dll,10.00.18362.0001
Microsoft MPEG-2 Audio Encoder,0x00200000,1,1,msmpeg2enc.dll,10.00.18362.0001
Pixela Audio format convert Filter (IMX-DES),0x00200001,1,1,ImxAudFmtCnvt_des.ax,1.00.0001.0010
WST Pager,0x00200000,1,1,WSTPager.ax,10.00.18362.0001
MPEG-2 Demultiplexer,0x00600000,1,1,mpg2splt.ax,10.00.18362.0001
DV Video Decoder,0x00800000,1,1,qdv.dll,10.00.18362.0001
ffdshow Audio Processor,0x00200000,1,1,ffdshow.ax,1.00.0007.3064
Pixela MPEG2 Video Encoder,0x00200000,1,1,PxMpegVidEnc.ax,1.00.0000.0006
SampleGrabber,0x00200000,1,1,qedit.dll,10.00.18362.0001
Null Renderer,0x00200000,1,0,qedit.dll,10.00.18362.0001
MPEG-2 Sections and Tables,0x005fffff,1,0,Mpeg2Data.ax,10.00.18362.0001
Microsoft AC3 Encoder,0x00200000,1,1,msac3enc.dll,10.00.18362.0001
MPC - FLV Source (Gabest),0x00600000,0,0,FLVSplitter.ax,1.03.1264.0000
StreamBufferSource,0x00200000,0,0,sbe.dll,10.00.18362.0001
Smart Tee,0x00200000,1,2,qcap.dll,10.00.18362.0001
Overlay Mixer,0x00200000,0,0,qdvd.dll,10.00.18362.0001
AVI Decompressor,0x00600000,1,1,quartz.dll,10.00.18362.0001
AVI/WAV File Source,0x00400000,0,2,quartz.dll,10.00.18362.0001
Wave Parser,0x00400000,1,1,quartz.dll,10.00.18362.0001
MIDI Parser,0x00400000,1,1,quartz.dll,10.00.18362.0001
Multi-file Parser,0x00400000,1,1,quartz.dll,10.00.18362.0001
File stream renderer,0x00400000,1,1,quartz.dll,10.00.18362.0001
Dump,0x00200000,1,0,PixeDump.ax,1.00.0000.0000
WavPack Audio Splitter,0x00600000,1,1,WavPackDSSplitter.ax,1.01.0000.0323
ffdshow subtitles filter,0x00200000,2,1,ffdshow.ax,1.00.0007.3064
Microsoft DTV-DVD Audio Decoder,0x005fffff,1,1,msmpeg2adec.dll,10.00.18362.0001
StreamBufferSink2,0x00200000,0,0,sbe.dll,10.00.18362.0001
AVI Mux,0x00200000,1,0,qcap.dll,10.00.18362.0001
LEAD Video Resize Filter (2.0),0x00200000,1,1,,
LEAD DVD Writer (2.0),0x00200000,1,0,,
LEAD MPEG2 Multiplexer (2.0),0x00200000,0,0,,
LEAD MPEG Audio Encoder (2.0),0x00200000,1,1,,
LEAD MPEG2 Encoder (3.0),0x00200000,1,1,,
Line 21 Decoder 2,0x00600002,1,1,quartz.dll,10.00.18362.0001
File Source (Async.),0x00400000,0,1,quartz.dll,10.00.18362.0001
File Source (URL),0x00400000,0,1,quartz.dll,10.00.18362.0001
Haali Video Sink,0x00200000,1,0,splitter.ax,1.09.0042.0001
Infinite Pin Tee Filter,0x00200000,1,1,qcap.dll,10.00.18362.0001
Enhanced Video Renderer,0x00200000,1,0,evr.dll,10.00.18362.0001
BDA MPEG2 Transport Information Filter,0x00200000,2,0,psisrndr.ax,10.00.18362.0001
MPEG Video Decoder,0x40000001,1,1,quartz.dll,10.00.18362.0001
 
WDM Streaming Tee/Splitter Devices:
Tee/Sink-to-Sink Converter,0x00200000,1,1,ksproxy.ax,10.00.18362.0001
 
Video Compressors:
WMVideo8 Encoder DMO,0x00600800,1,1,wmvxencd.dll,10.00.18362.0001
WMVideo9 Encoder DMO,0x00600800,1,1,wmvencod.dll,10.00.18362.0001
MSScreen 9 encoder DMO,0x00600800,1,1,wmvsencd.dll,10.00.18362.0001
DV Video Encoder,0x00200000,0,0,qdv.dll,10.00.18362.0001
ffdshow video encoder,0x00100000,1,1,ffdshow.ax,1.00.0007.3064
LEAD MPEG2 Encoder (3.0),0x00200000,1,1,,
MJPEG Compressor,0x00200000,0,0,quartz.dll,10.00.18362.0001
Cinepak Codec by Radius,0x00200000,1,1,qcap.dll,10.00.18362.0001
Intel IYUV codec,0x00200000,1,1,qcap.dll,10.00.18362.0001
Intel IYUV codec,0x00200000,1,1,qcap.dll,10.00.18362.0001
Microsoft RLE,0x00200000,1,1,qcap.dll,10.00.18362.0001
Microsoft Video 1,0x00200000,1,1,qcap.dll,10.00.18362.0001
 
Audio Compressors:
WM Speech Encoder DMO,0x00600800,1,1,WMSPDMOE.DLL,10.00.18362.0145
WMAudio Encoder DMO,0x00600800,1,1,WMADMOE.DLL,10.00.18362.0145
LEAD MPEG Audio Encoder (2.0),0x00200000,1,1,,
IMA ADPCM,0x00200000,1,1,quartz.dll,10.00.18362.0001
PCM,0x00200000,1,1,quartz.dll,10.00.18362.0001
Microsoft ADPCM,0x00200000,1,1,quartz.dll,10.00.18362.0001
GSM 6.10,0x00200000,1,1,quartz.dll,10.00.18362.0001
CCITT A-Law,0x00200000,1,1,quartz.dll,10.00.18362.0001
CCITT u-Law,0x00200000,1,1,quartz.dll,10.00.18362.0001
MPEG Layer-3,0x00200000,1,1,quartz.dll,10.00.18362.0001
 
Audio Capture Sources:
Microphone (High Definition Audio Device),0x00200000,0,0,qcap.dll,10.00.18362.0001
 
PBDA CP Filters:
PBDA DTFilter,0x00600000,1,1,CPFilters.dll,10.00.18362.0752
PBDA ETFilter,0x00200000,0,0,CPFilters.dll,10.00.18362.0752
PBDA PTFilter,0x00200000,0,0,CPFilters.dll,10.00.18362.0752
 
Midi Renderers:
Default MidiOut Device,0x00800000,1,0,quartz.dll,10.00.18362.0001
Microsoft GS Wavetable Synth,0x00200000,1,0,quartz.dll,10.00.18362.0001
 
WDM Streaming Capture Devices:
HD Audio Microphone 2,0x00200000,1,1,ksproxy.ax,10.00.18362.0001
 
WDM Streaming Rendering Devices:
HD Audio Speaker,0x00200000,1,1,ksproxy.ax,10.00.18362.0001
 
BDA Network Providers:
Microsoft ATSC Network Provider,0x00200000,0,1,MSDvbNP.ax,10.00.18362.0001
Microsoft DVBC Network Provider,0x00200000,0,1,MSDvbNP.ax,10.00.18362.0001
Microsoft DVBS Network Provider,0x00200000,0,1,MSDvbNP.ax,10.00.18362.0001
Microsoft DVBT Network Provider,0x00200000,0,1,MSDvbNP.ax,10.00.18362.0001
Microsoft Network Provider,0x00200000,0,1,MSNP.ax,10.00.18362.0001
 
Multi-Instance Capable VBI Codecs:
VBI Codec,0x00600000,1,4,VBICodec.ax,10.00.18362.0001
 
BDA Transport Information Renderers:
BDA MPEG2 Transport Information Filter,0x00600000,2,0,psisrndr.ax,10.00.18362.0001
MPEG-2 Sections and Tables,0x00600000,1,0,Mpeg2Data.ax,10.00.18362.0001
 
BDA CP/CA Filters:
Decrypt/Tag,0x00600000,1,1,msvidctl.dll,6.05.18362.0001
Encrypt/Tag,0x00200000,0,0,,
PTFilter,0x00200000,0,0,,
XDS Codec,0x00200000,0,0,,
 
WDM Streaming Communication Transforms:
Tee/Sink-to-Sink Converter,0x00200000,1,1,ksproxy.ax,10.00.18362.0001
 
Audio Renderers:
Speakers (High Definition Audio Device),0x00200000,1,0,quartz.dll,10.00.18362.0001
Default DirectSound Device,0x00800000,1,0,quartz.dll,10.00.18362.0001
Default WaveOut Device,0x00200000,1,0,quartz.dll,10.00.18362.0001
DirectSound: Speakers (High Definition Audio Device),0x00200000,1,0,quartz.dll,10.00.18362.0001
 
LTMM Video Processors:
LEAD Video Resize Filter (2.0),0x00200000,0,0,,
 
 
----------------------------
Preferred DirectShow Filters
----------------------------
 
[HKEY_LOCAL_MACHINE\Software\Microsoft\DirectShow\Preferred]
 
<media subtype GUID>, [<filter friendly name>, ]<filter CLSID>
 
MEDIASUBTYPE_DVD_LPCM_AUDIO, Microsoft DTV-DVD Audio Decoder, CLSID_CMPEG2AudDecoderDS
MEDIASUBTYPE_MPEG2_AUDIO, Microsoft DTV-DVD Audio Decoder, CLSID_CMPEG2AudDecoderDS
MEDIASUBTYPE_MPEG2_VIDEO, Microsoft DTV-DVD Video Decoder, CLSID_CMPEG2VidDecoderDS
{78766964-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
{7634706D-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
MEDIASUBTYPE_mp4s, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
{64697678-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
{58564944-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
{5634504D-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
MEDIASUBTYPE_MP4S, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
MEDIASUBTYPE_WMVR, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_WMVP, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
{44495658-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
MEDIASUBTYPE_WMVA, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_mpg4, Mpeg4 Decoder DMO, CLSID_CMpeg4DecMediaObject
MEDIASUBTYPE_MPG4, Mpeg4 Decoder DMO, CLSID_CMpeg4DecMediaObject
MEDIASUBTYPE_h264, Microsoft DTV-DVD Video Decoder, CLSID_CMPEG2VidDecoderDS
MEDIASUBTYPE_H264, Microsoft DTV-DVD Video Decoder, CLSID_CMPEG2VidDecoderDS
MEDIASUBTYPE_WMV3, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_mp43, Mpeg43 Decoder DMO, CLSID_CMpeg43DecMediaObject
MEDIASUBTYPE_MP43, Mpeg43 Decoder DMO, CLSID_CMpeg43DecMediaObject
MEDIASUBTYPE_m4s2, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
MEDIASUBTYPE_WMV2, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_MSS2, WMV Screen decoder DMO, CLSID_CMSSCDecMediaObject
MEDIASUBTYPE_M4S2, Mpeg4s Decoder DMO, CLSID_CMpeg4sDecMediaObject
MEDIASUBTYPE_WVP2, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_mp42, Mpeg4 Decoder DMO, CLSID_CMpeg4DecMediaObject
MEDIASUBTYPE_MP42, Mpeg4 Decoder DMO, CLSID_CMpeg4DecMediaObject
MEDIASUBTYPE_WMV1, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_MSS1, WMV Screen decoder DMO, CLSID_CMSSCDecMediaObject
MEDIASUBTYPE_WVC1, WMVideo Decoder DMO, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_AVC1, Microsoft DTV-DVD Video Decoder, CLSID_CMPEG2VidDecoderDS
MEDIASUBTYPE_MPEG_LOAS, Microsoft DTV-DVD Audio Decoder, CLSID_CMPEG2AudDecoderDS
MEDIASUBTYPE_MPEG_ADTS_AAC, Microsoft DTV-DVD Audio Decoder, CLSID_CMPEG2AudDecoderDS
MEDIASUBTYPE_WMAUDIO_LOSSLESS, WMAudio Decoder DMO, CLSID_CWMADecMediaObject
MEDIASUBTYPE_WMAUDIO3, WMAudio Decoder DMO, CLSID_CWMADecMediaObject
WMMEDIASUBTYPE_WMAudioV8, WMAudio Decoder DMO, CLSID_CWMADecMediaObject
MEDIASUBTYPE_MSAUDIO1, WMAudio Decoder DMO, CLSID_CWMADecMediaObject
MEDIASUBTYPE_RAW_AAC1, Microsoft DTV-DVD Audio Decoder, CLSID_CMPEG2AudDecoderDS
WMMEDIASUBTYPE_MP3, MP3 Decoder DMO, CLSID_CMP3DecMediaObject
MEDIASUBTYPE_MPEG1Payload, MPEG Video Decoder, CLSID_CMpegVideoCodec
MEDIASUBTYPE_MPEG1Packet, MPEG Video Decoder, CLSID_CMpegVideoCodec
{6C737664-0000-0010-8000-00AA00389B71}, DV Video Decoder, CLSID_DVVideoCodec
{64737664-0000-0010-8000-00AA00389B71}, DV Video Decoder, CLSID_DVVideoCodec
{64687664-0000-0010-8000-00AA00389B71}, DV Video Decoder, CLSID_DVVideoCodec
MEDIASUBTYPE_MJPG, MJPEG Decompressor, CLSID_MjpegDec
{20637664-0000-0010-8000-00AA00389B71}, DV Video Decoder, CLSID_DVVideoCodec
MEDIASUBTYPE_MPEG1AudioPayload, MPEG Audio Decoder, CLSID_CMpegAudioCodec
WMMEDIASUBTYPE_WMSP2, WMSpeech Decoder DMO, CLSID_CWMSPDecMediaObject
WMMEDIASUBTYPE_WMSP1, WMSpeech Decoder DMO, CLSID_CWMSPDecMediaObject
 
 
---------------------------
Media Foundation File Versions
---------------------------
 
  mfcore.dll, 10.00.18362.0657
  mfreadwrite.dll, 10.00.18362.0719
  mfcaptureengine.dll, 10.00.18362.0001
  mfsensorgroup.dll, 10.00.18362.0628
  windows.media.dll, 10.00.18362.0145
  frameserver.dll, 10.00.18362.0628
  fsclient.dll, 10.00.18362.0628
 
 
---------------------------
Media Foundation Transforms
---------------------------
 
[HKEY_LOCAL_MACHINE\Software\Classes\MediaFoundation\Transforms]
 
<category>:
  <transform friendly name>, <transform CLSID>, <flags>, [<merit>, ]<file name>, <file version>
 
Video Decoders:
  Microsoft MPEG Video Decoder MFT, {2D709E52-123F-49B5-9CBC-9AF5CDE28FB9}, 0x1, msmpeg2vdec.dll, 10.00.18362.0693
  DV Decoder MFT, {404A6DE5-D4D6-4260-9BC7-5A6CBD882432}, 0x1, mfdvdec.dll, 10.00.18362.0001
  Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT, 0x1, mp4sdecd.dll, 10.00.18362.0001
  Microsoft H264 Video Decoder MFT, CLSID_CMSH264DecoderMFT, 0x1, msmpeg2vdec.dll, 10.00.18362.0693
  WMV Screen decoder MFT, CLSID_CMSSCDecMediaObject, 0x1, wmvsdecd.dll, 10.00.18362.0001
  WMVideo Decoder MFT, CLSID_CWMVDecMediaObject, 0x1, wmvdecod.dll, 10.00.18362.0001
  MJPEG Decoder MFT, {CB17E772-E1CC-4633-8450-5617AF577905}, 0x1, mfmjpegdec.dll, 10.00.18362.0001
  Mpeg43 Decoder MFT, CLSID_CMpeg43DecMediaObject, 0x1, mp43decd.dll, 10.00.18362.0001
  Mpeg4 Decoder MFT, CLSID_CMpeg4DecMediaObject, 0x1, mpg4decd.dll, 10.00.18362.0001
  WebpImageExtension
  HEIFImageExtension
  VP9VideoExtensionDecoder
Video Encoders:
  H264 Encoder MFT, {6CA50344-051A-4DED-9779-A43305165E35}, 0x1, mfh264enc.dll, 10.00.18362.0001
  WMVideo8 Encoder MFT, CLSID_CWMVXEncMediaObject, 0x1, wmvxencd.dll, 10.00.18362.0001
  H263 Encoder MFT, {BC47FCFE-98A0-4F27-BB07-698AF24F2B38}, 0x1, mfh263enc.dll, 10.00.18362.0001
  WMVideo9 Encoder MFT, CLSID_CWMV9EncMediaObject, 0x1, wmvencod.dll, 10.00.18362.0001
  Microsoft MPEG-2 Video Encoder MFT, {E6335F02-80B7-4DC4-ADFA-DFE7210D20D5}, 0x2, msmpeg2enc.dll, 10.00.18362.0001
  HEIFImageExtension
  VP9VideoExtensionEncoder
Video Effects:
  Frame Rate Converter, CLSID_CFrameRateConvertDmo, 0x1, mfvdsp.dll, 10.00.18362.0001
  Resizer MFT, CLSID_CResizerDMO, 0x1, vidreszr.dll, 10.00.18362.0001
  VideoStabilization MFT, {51571744-7FE4-4FF2-A498-2DC34FF74F1B}, 0x1, MSVideoDSP.dll, 10.00.18362.0001
  Color Control, CLSID_CColorControlDmo, 0x1, mfvdsp.dll, 10.00.18362.0001
  Color Converter MFT, CLSID_CColorConvertDMO, 0x1, colorcnv.dll, 10.00.18362.0001
Video Processor:
  Microsoft Video Processor MFT, {88753B26-5B24-49BD-B2E7-0C445C78C982}, 0x1, msvproc.dll, 10.00.18362.0387
Audio Decoders:
  Microsoft Dolby Digital Plus Decoder MFT, {177C0AFE-900B-48D4-9E4C-57ADD250B3D4}, 0x1, DolbyDecMFT.dll, 10.00.18362.0719
  MS AMRNB Decoder MFT, {265011AE-5481-4F77-A295-ABB6FFE8D63E}, 0x1, MSAMRNBDecoder.dll, 10.00.18362.0001
  WMAudio Decoder MFT, CLSID_CWMADecMediaObject, 0x1, WMADMOD.DLL, 10.00.18362.0145
  Microsoft AAC Audio Decoder MFT, CLSID_CMSAACDecMFT, 0x1, MSAudDecMFT.dll, 10.00.18362.0001
  A-law Wrapper MFT, {36CB6E0C-78C1-42B2-9943-846262F31786}, 0x1, mfcore.dll, 10.00.18362.0657
  GSM ACM Wrapper MFT, {4A76B469-7B66-4DD4-BA2D-DDF244C766DC}, 0x1, mfcore.dll, 10.00.18362.0657
  WMAPro over S/PDIF MFT, CLSID_CWMAudioSpdTxDMO, 0x1, WMADMOD.DLL, 10.00.18362.0145
  Microsoft Opus Audio Decoder MFT, {63E17C10-2D43-4C42-8FE3-8D8B63E46A6A}, 0x1, MSOpusDecoder.dll, 10.00.18362.0001
  Microsoft FLAC Audio Decoder MFT, {6B0B3E6B-A2C5-4514-8055-AFE8A95242D9}, 0x1, MSFlacDecoder.dll, 10.00.18362.0778
  Microsoft MPEG Audio Decoder MFT, {70707B39-B2CA-4015-ABEA-F8447D22D88B}, 0x1, MSAudDecMFT.dll, 10.00.18362.0001
  WMSpeech Decoder DMO, CLSID_CWMSPDecMediaObject, 0x1, WMSPDMOD.DLL, 10.00.18362.0001
  G711 Wrapper MFT, {92B66080-5E2D-449E-90C4-C41F268E5514}, 0x1, mfcore.dll, 10.00.18362.0657
  IMA ADPCM ACM Wrapper MFT, {A16E1BFF-A80D-48AD-AECD-A35C005685FE}, 0x1, mfcore.dll, 10.00.18362.0657
  MP3 Decoder MFT, CLSID_CMP3DecMediaObject, 0x1, mp3dmod.dll, 10.00.18362.0001
  Microsoft ALAC Audio Decoder MFT, {C0CD7D12-31FC-4BBC-B363-7322EE3E1879}, 0x1, MSAlacDecoder.dll, 10.00.18362.0001
  ADPCM ACM Wrapper MFT, {CA34FE0A-5722-43AD-AF23-05F7650257DD}, 0x1, mfcore.dll, 10.00.18362.0657
  Dolby TrueHD IEC-61937 converter MFT, {CF5EEEDF-0E92-4B3B-A161-BD0FFE545E4B}, 0x1, mfaudiocnv.dll, 10.00.18362.0001
  DTS IEC-61937 converter MFT, {D035E24C-C877-42D7-A795-2A8A339B472F}, 0x1, mfaudiocnv.dll, 10.00.18362.0001
Audio Encoders:
  LPCM DVD-Audio MFT, {068A8476-9229-4CC0-9D49-2FC699DCD30A}, 0x1, mfaudiocnv.dll, 10.00.18362.0001
  MP3 Encoder ACM Wrapper MFT, {11103421-354C-4CCA-A7A3-1AFF9A5B6701}, 0x1, mfcore.dll, 10.00.18362.0657
  Microsoft FLAC Audio Encoder MFT, {128509E9-C44E-45DC-95E9-C255B8F466A6}, 0x1, MSFlacEncoder.dll, 10.00.18362.0719
  WM Speech Encoder DMO, CLSID_CWMSPEncMediaObject2, 0x1, WMSPDMOE.DLL, 10.00.18362.0145
  MS AMRNB Encoder MFT, {2FAE8AFE-04A3-423A-A814-85DB454712B0}, 0x1, MSAMRNBEncoder.dll, 10.00.18362.0001
  Microsoft MPEG-2 Audio Encoder MFT, {46A4DD5C-73F8-4304-94DF-308F760974F4}, 0x1, msmpeg2enc.dll, 10.00.18362.0001
  WMAudio Encoder MFT, CLSID_CWMAEncMediaObject, 0x1, WMADMOE.DLL, 10.00.18362.0145
  Microsoft AAC Audio Encoder MFT, {93AF0C51-2275-45D2-A35B-F2BA21CAED00}, 0x1, mfAACEnc.dll, 10.00.18362.0001
  Microsoft ALAC Audio Encoder MFT, {9AB6A28C-748E-4B6A-BFFF-CC443B8E8FB4}, 0x1, MSAlacEncoder.dll, 10.00.18362.0001
  Microsoft Dolby Digital Encoder MFT, {AC3315C9-F481-45D7-826C-0B406C1F64B8}, 0x1, msac3enc.dll, 10.00.18362.0001
Audio Effects:
  AEC, CLSID_CWMAudioAEC, 0x1, mfwmaaec.dll, 10.00.18362.0001
  Resampler MFT, CLSID_CResamplerMediaObject, 0x1, resampledmo.dll, 10.00.18362.0001
Multiplexers:
  Microsoft MPEG2 Multiplexer MFT, {AB300F71-01AB-46D2-AB6C-64906CB03258}, 0x2, mfmpeg2srcsnk.dll, 10.00.18362.0778
Others:
  Microsoft H264 Video Remux (MPEG2TSToMP4) MFT, {05A47EBB-8BF0-4CBF-AD2F-3B71D75866F5}, 0x1, msmpeg2vdec.dll, 10.00.18362.0693
 
 
--------------------------------------------
Media Foundation Enabled Hardware Categories
--------------------------------------------
 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Media Foundation\HardwareMFT]
 
EnableDecoders = 0
EnableEncoders = 1
EnableVideoProcessors = 1
 
 
-------------------------------------
Media Foundation Byte Stream Handlers
-------------------------------------
 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Media Foundation\ByteStreamHandlers]
[HKEY_LOCAL_MACHINE\Software\Classes\MediaFoundation\MediaSources\Preferred]
 
<file ext. or MIME type>, <handler CLSID>, <brief description>[, Preferred]
 
.3g2, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.3gp, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.3gp2, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.3gpp, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.aac, {926F41F7-003E-4382-9E84-9E953BE10562}, ADTS Byte Stream Handler, Preferred
.ac3, {46031BA1-083F-47D9-8369-23C92BDAB2FF}, AC-3 Byte Stream Handler, Preferred
.adt, {926F41F7-003E-4382-9E84-9E953BE10562}, ADTS Byte Stream Handler, Preferred
.adts, {926F41F7-003E-4382-9E84-9E953BE10562}, ADTS Byte Stream Handler, Preferred
.am?, {EFE6208A-0A2C-49FA-8A01-3768B559B6DA}, MF AMRNB Media Source ByteStreamHandler
.amr, {EFE6208A-0A2C-49FA-8A01-3768B559B6DA}, MF AMRNB Media Source ByteStreamHandler, Preferred
.asf, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
.avi, {7AFA253E-F823-42F6-A5D9-714BDE467412}, AVI Byte Stream Handler, Preferred
.dvr-ms, {A8721937-E2FB-4D7A-A9EE-4EB08C890B6E}, MF SBE Source ByteStreamHandler
.dvr-ms, {65964407-A5D8-4060-85B0-1CCD63F768E2}, dvr-ms Byte Stream Handler, Preferred
.ec3, {46031BA1-083F-47D9-8369-23C92BDAB2FF}, AC-3 Byte Stream Handler, Preferred
.flac, {0E41CFB8-0506-40F4-A516-77CC23642D91}, MF FLAC Media Source ByteStreamHandler, Preferred
.m2t, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.m2ts, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.m4a, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.m4v, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.mk3d, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, MKV Byte Stream Handler, Preferred
.mka, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, MKV Byte Stream Handler, Preferred
.mks, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, MKV Byte Stream Handler, Preferred
.mkv, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, MKV Byte Stream Handler, Preferred
.mod, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.mov, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.mp2v, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.mp3, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
.mp4, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.mp4v, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.mpa, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
.mpeg, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.mpg, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.mts, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.nsc, {B084785C-DDE0-4D30-8CA8-05A373E185BE}, NSC Byte Stream Handler, Preferred
.sami, {7A56C4CB-D678-4188-85A8-BA2EF68FA10D}, SAMI Byte Stream Handler, Preferred
.smi, {7A56C4CB-D678-4188-85A8-BA2EF68FA10D}, SAMI Byte Stream Handler, Preferred
.tod, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.ts, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.tts, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.uvu, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
.vob, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
.wav, {42C9B9F5-16FC-47EF-AF22-DA05F7C842E3}, WAV Byte Stream Handler, Preferred
.weba, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, WEBM Byte Stream Handler, Preferred
.webm, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, WEBM Byte Stream Handler, Preferred
.wm, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
.wma, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
.wmv, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
.wtv, {65964407-A5D8-4060-85B0-1CCD63F768E2}, WTV Byte Stream Handler, Preferred
audio/3gpp, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
audio/3gpp2, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
audio/aac, {926F41F7-003E-4382-9E84-9E953BE10562}, ADTS Byte Stream Handler, Preferred
audio/aacp, {926F41F7-003E-4382-9E84-9E953BE10562}, ADTS Byte Stream Handler, Preferred
audio/eac3, {46031BA1-083F-47D9-8369-23C92BDAB2FF}, AC-3 Byte Stream Handler, Preferred
audio/flac, {0E41CFB8-0506-40F4-A516-77CC23642D91}, MF FLAC Media Source ByteStreamHandler, Preferred
audio/L16, {3FFB3B8C-EB99-472B-8902-E1C1B05F07CF}, LPCM Byte Stream Handler, Preferred
audio/mp3, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
audio/mp4, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
audio/MP4A-LATM, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
audio/mpa, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
audio/mpeg, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
audio/mpeg3, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
audio/vnd.dlna.adts, {926F41F7-003E-4382-9E84-9E953BE10562}, ADTS Byte Stream Handler, Preferred
audio/vnd.dolby.dd-raw, {46031BA1-083F-47D9-8369-23C92BDAB2FF}, AC-3 Byte Stream Handler, Preferred
audio/wav, {42C9B9F5-16FC-47EF-AF22-DA05F7C842E3}, WAV Byte Stream Handler, Preferred
audio/webm, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, WEBM Byte Stream Handler, Preferred
audio/x-aac, {926F41F7-003E-4382-9E84-9E953BE10562}, ADTS Byte Stream Handler, Preferred
audio/x-flac, {0E41CFB8-0506-40F4-A516-77CC23642D91}, MF FLAC Media Source ByteStreamHandler, Preferred
audio/x-m4a, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
audio/x-matroska, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, MKV Byte Stream Handler, Preferred
audio/x-mp3, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
audio/x-mpeg, {A82E50BA-8E92-41EB-9DF2-433F50EC2993}, MP3 Byte Stream Handler, Preferred
audio/x-ms-wma, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
audio/x-wav, {42C9B9F5-16FC-47EF-AF22-DA05F7C842E3}, WAV Byte Stream Handler, Preferred
video/3gpp, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
video/3gpp2, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
video/avi, {7AFA253E-F823-42F6-A5D9-714BDE467412}, AVI Byte Stream Handler, Preferred
video/mp4, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
video/mpeg, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
video/msvideo, {7AFA253E-F823-42F6-A5D9-714BDE467412}, AVI Byte Stream Handler, Preferred
video/vnd.dece.mp4, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
video/vnd.dlna.mpeg-tts, {40871C59-AB40-471F-8DC3-1F259D862479}, MPEG2 Byte Stream Handler, Preferred
video/webm, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, WEBM Byte Stream Handler, Preferred
video/x-m4v, {271C3902-6095-4C45-A22F-20091816EE9E}, MPEG4 Byte Stream Handler, Preferred
video/x-matroska, {1F9A2C18-D89E-463E-B4F4-BB90152ACC64}, MKV Byte Stream Handler, Preferred
video/x-ms-asf, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
video/x-ms-wm, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
video/x-ms-wmv, {41457294-644C-4298-A28A-BD69F2C0CF3B}, ASF Byte Stream Handler, Preferred
video/x-msvideo, {7AFA253E-F823-42F6-A5D9-714BDE467412}, AVI Byte Stream Handler, Preferred
 
 
--------------------------------
Media Foundation Scheme Handlers
--------------------------------
 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Media Foundation\SchemeHandlers]
[HKEY_LOCAL_MACHINE\Software\Classes\MediaFoundation\MediaSources\Preferred]
 
<URL type>, <handler CLSID>, <brief description>[, Preferred]
 
file:, {477EC299-1421-4BDD-971F-7CCB933F21AD}, File Scheme Handler, Preferred
http:, {44CB442B-9DA9-49DF-B3FD-023777B16E50}, Http Scheme Handler
http:, {9EC4B4F9-3029-45AD-947B-344DE2A249E2}, Urlmon Scheme Handler
http:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
httpd:, {44CB442B-9DA9-49DF-B3FD-023777B16E50}, Http Scheme Handler, Preferred
https:, {37A61C8B-7F8E-4D08-B12B-248D73E9AB4F}, Secure Http Scheme Handler, Preferred
httpsd:, {37A61C8B-7F8E-4D08-B12B-248D73E9AB4F}, Secure Http Scheme Handler, Preferred
httpt:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
httpu:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
mcast:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
mcrecv:, {FA6D33D4-9405-4BA5-9983-12604AC8E77A}, Miracast Sink Scheme Handler, Preferred
mms:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
ms-appdata:, {CFC81939-3886-4ACF-9692-DA58037AE716}, MsAppData Scheme Handler, Preferred
ms-appx-web:, {8DB0224B-3D65-4F6F-8E12-BEB4B78B8974}, MsAppxWeb Scheme Handler, Preferred
ms-appx:, {8DB0224B-3D65-4F6F-8E12-BEB4B78B8974}, MsAppx Scheme Handler, Preferred
ms-winsoundevent:, {F79A6BF9-7415-4CF3-AE10-4559509ABC3C}, Sound Event Scheme Handler, Preferred
rtsp:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
rtsps:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
rtspt:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
rtspu:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
sdp:, {E9F4EBAB-D97B-463E-A2B1-C54EE3F9414D}, Net Scheme Handler, Preferred
 
 
-------------------------------------
Preferred Media Foundation Transforms
-------------------------------------
 
[HKEY_LOCAL_MACHINE\Software\Classes\MediaFoundation\Transforms\Preferred]
 
<media subtype GUID>, [<transform friendly name>, ]<transform CLSID>
 
{EB27CEC4-163E-4CA3-8B74-8E25F91B517E}, Dolby TrueHD IEC-61937 converter MFT, {CF5EEEDF-0E92-4B3B-A161-BD0FFE545E4B}
{E06D802C-DB46-11CF-B4D1-00805F6CBBEA}, Microsoft Dolby Digital Plus Decoder MFT, {177C0AFE-900B-48D4-9E4C-57ADD250B3D4}
MFVideoFormat_MPEG2, Microsoft MPEG Video Decoder MFT, {2D709E52-123F-49B5-9CBC-9AF5CDE28FB9}
MEDIASUBTYPE_DOLBY_DDPLUS, Microsoft Dolby Digital Plus Decoder MFT, {177C0AFE-900B-48D4-9E4C-57ADD250B3D4}
{A61AC364-AD0E-4744-89FF-213CE0DF8804}, DTS IEC-61937 converter MFT, {D035E24C-C877-42D7-A795-2A8A339B472F}
{A2E58EB7-0FA9-48BB-A40C-FA0E156D0645}, DTS IEC-61937 converter MFT, {D035E24C-C877-42D7-A795-2A8A339B472F}
{7634706D-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT
{73616D72-767A-494D-B478-F29D25DC9037}, MS AMRNB Decoder MFT, {265011AE-5481-4F77-A295-ABB6FFE8D63E}
MEDIASUBTYPE_mp4s, Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT
MFVideoFormat_DVSL, DV Decoder MFT, {404A6DE5-D4D6-4260-9BC7-5A6CBD882432}
MFVideoFormat_DVSD, DV Decoder MFT, {404A6DE5-D4D6-4260-9BC7-5A6CBD882432}
MFVideoFormat_DVHD, DV Decoder MFT, {404A6DE5-D4D6-4260-9BC7-5A6CBD882432}
{63616C61-0000-0010-8000-00AA00389B71}, Microsoft ALAC Audio Decoder MFT, {C0CD7D12-31FC-4BBC-B363-7322EE3E1879}
MFVideoFormat_MP4V, Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT
MFVideoFormat_MP4S, Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT
{53314356-0000-0010-8000-00AA00389B71}, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_WMVR, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_WMVP, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
MFVideoFormat_MJPG, MJPEG Decoder MFT, {CB17E772-E1CC-4633-8450-5617AF577905}
MEDIASUBTYPE_WMVA, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
{3F40F4F0-5622-4FF8-B6D8-A17A584BEE5E}, Microsoft H264 Video Decoder MFT, CLSID_CMSH264DecoderMFT
MEDIASUBTYPE_mpg4, Mpeg4 Decoder MFT, CLSID_CMpeg4DecMediaObject
MEDIASUBTYPE_MPG4, Mpeg4 Decoder MFT, CLSID_CMpeg4DecMediaObject
MFVideoFormat_H264, Microsoft H264 Video Decoder MFT, CLSID_CMSH264DecoderMFT
MFVideoFormat_WMV3, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
{33363248-0000-0010-8000-00AA00389B71}, Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT
MEDIASUBTYPE_mp43, Mpeg43 Decoder MFT, CLSID_CMpeg43DecMediaObject
MFVideoFormat_MP43, Mpeg43 Decoder MFT, CLSID_CMpeg43DecMediaObject
MEDIASUBTYPE_m4s2, Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT
MFVideoFormat_WMV2, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
MFVideoFormat_MSS2, WMV Screen decoder MFT, CLSID_CMSSCDecMediaObject
MFVideoFormat_M4S2, Mpeg4s Decoder MFT, CLSID_CMpeg4sDecMFT
MEDIASUBTYPE_WVP2, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
MEDIASUBTYPE_mp42, Mpeg4 Decoder MFT, CLSID_CMpeg4DecMediaObject
MEDIASUBTYPE_MP42, Mpeg4 Decoder MFT, CLSID_CMpeg4DecMediaObject
MFVideoFormat_WMV1, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
MFVideoFormat_MSS1, WMV Screen decoder MFT, CLSID_CMSSCDecMediaObject
MFVideoFormat_MPG1, Microsoft MPEG Video Decoder MFT, {2D709E52-123F-49B5-9CBC-9AF5CDE28FB9}
MFVideoFormat_WVC1, WMVideo Decoder MFT, CLSID_CWMVDecMediaObject
MFVideoFormat_DVC, DV Decoder MFT, {404A6DE5-D4D6-4260-9BC7-5A6CBD882432}
{0000F1AC-0000-0010-8000-00AA00389B71}, Microsoft FLAC Audio Decoder MFT, {6B0B3E6B-A2C5-4514-8055-AFE8A95242D9}
{00007361-0000-0010-8000-00AA00389B71}, MS AMRNB Decoder MFT, {265011AE-5481-4F77-A295-ABB6FFE8D63E}
{0000704F-0000-0010-8000-00AA00389B71}, Microsoft Opus Audio Decoder MFT, {63E17C10-2D43-4C42-8FE3-8D8B63E46A6A}
{00006C61-0000-0010-8000-00AA00389B71}, Microsoft ALAC Audio Decoder MFT, {C0CD7D12-31FC-4BBC-B363-7322EE3E1879}
{00002001-0000-0010-8000-00AA00389B71}, DTS IEC-61937 converter MFT, {D035E24C-C877-42D7-A795-2A8A339B472F}
{00002000-0000-0010-8000-00AA00389B71}, Microsoft Dolby Digital Plus Decoder MFT, {177C0AFE-900B-48D4-9E4C-57ADD250B3D4}
MFAudioFormat_AAC, Microsoft AAC Audio Decoder MFT, CLSID_CMSAACDecMFT
MFAudioFormat_ADTS, Microsoft AAC Audio Decoder MFT, CLSID_CMSAACDecMFT
MFAudioFormat_WMAudio_Lossless, WMAudio Decoder MFT, CLSID_CWMADecMediaObject
MFAudioFormat_WMAudioV9, WMAudio Decoder MFT, CLSID_CWMADecMediaObject
MFAudioFormat_WMAudioV8, WMAudio Decoder MFT, CLSID_CWMADecMediaObject
MEDIASUBTYPE_MSAUDIO1, WMAudio Decoder MFT, CLSID_CWMADecMediaObject
MEDIASUBTYPE_RAW_AAC1, Microsoft AAC Audio Decoder MFT, CLSID_CMSAACDecMFT
MFAudioFormat_MP3, MP3 Decoder MFT, CLSID_CMP3DecMediaObject
MFAudioFormat_MPEG, Microsoft MPEG Audio Decoder MFT, {70707B39-B2CA-4015-ABEA-F8447D22D88B}
{00000031-0000-0010-8000-00AA00389B71}, GSM ACM Wrapper MFT, {4A76B469-7B66-4DD4-BA2D-DDF244C766DC}
{00000011-0000-0010-8000-00AA00389B71}, IMA ADPCM ACM Wrapper MFT, {A16E1BFF-A80D-48AD-AECD-A35C005685FE}
KSDATAFORMAT_SUBTYPE_MULAW, G711 Wrapper MFT, {92B66080-5E2D-449E-90C4-C41F268E5514}
{00000006-0000-0010-8000-00AA00389B71}, A-law Wrapper MFT, {36CB6E0C-78C1-42B2-9943-846262F31786}
KSDATAFORMAT_SUBTYPE_ADPCM, ADPCM ACM Wrapper MFT, {CA34FE0A-5722-43AD-AF23-05F7650257DD}
WMMEDIASUBTYPE_WMSP2, WMSpeech Decoder DMO, CLSID_CWMSPDecMediaObject
MFAudioFormat_MSP1, WMSpeech Decoder DMO, CLSID_CWMSPDecMediaObject
 
 
-------------------------------------
Disabled Media Foundation Transforms
-------------------------------------
 
[HKEY_LOCAL_MACHINE\Software\Classes\MediaFoundation\Transforms\DoNotUse]
 
<transform CLSID>
 
 
 
------------------------
Disabled Media Sources
------------------------
 
[HKEY_LOCAL_MACHINE\Software\Classes\MediaFoundation\MediaSources\DoNotUse]
 
<media source CLSID>
 
 
---------------
EVR Power Information
---------------
Current Setting: {5C67A112-A4C9-483F-B4A7-1D473BECAFDC} (Quality) 
  Quality Flags: 2576
    Enabled:
    Force throttling
    Allow half deinterlace
    Allow scaling
    Decode Power Usage: 100
  Balanced Flags: 1424
    Enabled:
    Force throttling
    Allow batching
    Force half deinterlace
    Force scaling
    Decode Power Usage: 50
  PowerFlags: 1424
    Enabled:
    Force throttling
    Allow batching
    Force half deinterlace
    Force scaling
    Decode Power Usage: 0
 
---------------
Diagnostics
---------------
 
Windows Error Reporting:
+++ WER0 +++:
Fault bucket 2114285026178507385, type 1
Event Name: APPCRASH
Response: Not available
Cab Id: 0
 
Problem signature:
P1: Acrobat.exe
P2: 20.6.20042.43423
P3: 5e616ad0
P4: StackHash_1bba
P5: 10.0.18362.778
P6: 7d3954ae
P7: c0000374
P8: PCH_CC_FROM_ntdll+0x000916D0
P9: 
P10: 
 
 
+++ WER1 +++:
Fault bucket 2202411671516552478, type 5
Event Name: RADAR_PRE_LEAK_32
Response: Not available
Cab Id: 0
 
Problem signature:
P1: Dropbox.exe
P2: 95.4.441.0
P3: 10.0.18363.2.0.0
P4: 
P5: 
P6: 
P7: 
P8: 
P9: 
P10: 
 
 
+++ WER2 +++:
Fault bucket 1387317350027558027, type 1
Event Name: APPCRASH
Response: Not available
Cab Id: 0
 
Problem signature:
P1: Acrobat.exe
P2: 20.6.20042.43423
P3: 5e616ad0
P4: StackHash_791f
P5: 10.0.18362.778
P6: 7d3954ae
P7: c0000374
P8: PCH_B0_FROM_ntdll+0x000916D0
P9: 
P10: 
 
 
+++ WER3 +++:
Fault bucket 1693298195570881273, type 5
Event Name: AppHangB1
Response: Not available
Cab Id: 0
 
Problem signature:
P1: Acrobat.exe
P2: 20.6.20042.43423
P3: 5e616ad0
P4: 5445
P5: 134217728
P6: 
P7: 
P8: 
P9: 
P10: 
 
 
+++ WER4 +++:
Fault bucket 2015380023614861603, type 5
Event Name: RADAR_PRE_LEAK_32
Response: Not available
Cab Id: 0
 
Problem signature:
P1: SkypeApp.exe
P2: 8.56.0.102
P3: 10.0.18363.2.0.0
P4: 
P5: 
P6: 
P7: 
P8: 
P9: 
P10: 
 
 
+++ WER5 +++:
Fault bucket 1874080943878130843, type 5
Event Name: StoreAgentDownloadFailure1
Response: Not available
Cab Id: 0
 
Problem signature:
P1: Update;ScanForUpdates
P2: 8024001e
P3: 18363
P4: 778
P5: Windows.Desktop
P6: S
P7: 
P8: 
P9: 
P10: 
 
 
+++ WER6 +++:
Fault bucket 1264324649728591026, type 5
Event Name: MoAppHang
Response: Not available
Cab Id: 0
 
Problem signature:
P1: windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy
P2: praid:microsoft.windows.immersivecontrolpanel
P3: 10.0.18362.628
P4: 613246bc
P5: 59b3
P6: 2097152
P7: 
P8: 
P9: 
P10: 
 
 
+++ WER7 +++:
Fault bucket 1795529642229312388, type 5
Event Name: MoAppHang
Response: Not available
Cab Id: 0
 
Problem signature:
P1: Microsoft.Windows.ShellExperienceHost_10.0.18362.449_neutral_neutral_cw5n1h2txyewy
P2: praid:App
P3: 10.0.18362.752
P4: 5e707dfb
P5: 1536
P6: 2097152
P7: 
P8: 
P9: 
P10: 
 
 
+++ WER8 +++:
Fault bucket 1874080943878130843, type 5
Event Name: StoreAgentDownloadFailure1
Response: Not available
Cab Id: 0
 
Problem signature:
P1: Update;ScanForUpdates
P2: 8024001e
P3: 18363
P4: 778
P5: Windows.Desktop
P6: S
P7: 
P8: 
P9: 
P10: 
 
 
+++ WER9 +++:
Fault bucket , type 0
Event Name: StoreAgentDownloadFailure1
Response: Not available
Cab Id: 0
 
Problem signature:
P1: Update;ScanForUpdates
P2: 8024001e
P3: 18363
P4: 778
P5: Windows.Desktop
P6: S
P7: 
P8: 
P9: 
P10: 
 
 

 

 

Hardware ID:  ACPI\VEN_IBM&DEV_0057

Driver Date:  4/17/2013
Version:  16.2.19.7

  • 0

#24
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,731 posts
  • MVP

The high interrupts (in process explorer)  is probably caused by an old driver.  I would really like to update the graphics and touchpad drivers but there just aren't any newer than what you have.  (The graphics driver hasn't been updated since XP.  The touchpad is a bit newer probably Win 8 vintage but no luck finding anything newer.

 

Can I see a new process explorer log.  Please make sure you let it settle for a minute before running it.  I don't need the junk file again.

 

DxDiag says it has seen crashes from Acrobat,Skype & Dropbox but it appears you have the latest versions so not much we can do about them.

 

I think it's time for a new FRST scan.  Note we are having problems with Smart Screen and Windows Defender eating the FRST.exe file when it tries to update.  Apparently a false positive.  You may have to pause Windows Defender or exclude the folder where it lives:

https://www.windowsc...antivirus-scans

 

For Smart Screen you can turn it off for a while:

 

Settings, Update & Security, App & Browser Control, Check Apps & Files, set to Off then reboot.

 

Let's check your hard drive to see if it is up to speed:

HD Tune

https://www.lifewire...-review-2624561


Actual download is at:


http://www.hdtune.co.../hdtune_255.exe


Download, Save, right click and Run As Admin.  Run the Benchmark test and report your min, max & average transfer times.  Ideally the graph would be flat or slightly tilted to the right.  On a bad drive you will see sharp drops.  The fewer programs running at the same time the better.  Pause your anti-virus.


 


  • 0

#25
dbrupp

dbrupp

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts

Thanks for your investigation.

 

Here are the logs that you requested.

 

1. Process Explore:

 

Process CPU Private Bytes Working Set PID Description Company Name Verified Signer
AcrobatNotificationClient.exe Suspended 6,520 K 19,556 K 7968 (Verified) Adobe Systems, Incorporated
acrotray.exe 2,000 K 8,876 K 1692 AcroTray Adobe Systems Inc. (Verified) Adobe Inc.
AdobeCollabSync.exe 2,600 K 11,592 K 5112 Adobe Collaboration Synchronizer 20.6 Adobe Systems Incorporated (Verified) Adobe Inc.
AGSService.exe 1,688 K 9,308 K 2132 Adobe Genuine Software Integrity Service Adobe Systems, Incorporated (Verified) Adobe Inc.
armsvc.exe 1,092 K 5,600 K 2096 Adobe Acrobat Update Service Adobe Systems (Verified) Adobe Inc.
backgroundTaskHost.exe 49,200 K 18,504 K 6368 Background Task Host Microsoft Corporation (Verified) Microsoft Windows
backgroundTaskHost.exe 3,300 K 16,008 K 7672 Background Task Host Microsoft Corporation (Verified) Microsoft Windows
backgroundTaskHost.exe 7,064 K 18,860 K 7312 Background Task Host Microsoft Corporation (Verified) Microsoft Windows
csrss.exe 1,136 K 4,480 K 504 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows Publisher
ctfmon.exe 2,572 K 11,840 K 4260 CTF Loader Microsoft Corporation (Verified) Microsoft Windows
dasHost.exe 736 K 3,636 K 4760 Device Association Framework Provider Host Microsoft Corporation (Verified) Microsoft Windows
dasHost.exe 4,268 K 14,100 K 2304 Device Association Framework Provider Host Microsoft Corporation (Verified) Microsoft Windows
dllhost.exe 2,512 K 9,320 K 5268 COM Surrogate Microsoft Corporation (Verified) Microsoft Windows
dllhost.exe 4,492 K 12,012 K 5908 COM Surrogate Microsoft Corporation (Verified) Microsoft Windows
Dropbox.exe 1,468 K 6,980 K 2212 Dropbox Dropbox, Inc. (Verified) Dropbox, Inc
Dropbox.exe 2,476 K 9,992 K 844 Dropbox Dropbox, Inc. (Verified) Dropbox, Inc
DropboxUpdate.exe 1,864 K 2,084 K 1148 Dropbox Update Dropbox, Inc. (Verified) Dropbox, Inc
fontdrvhost.exe 1,200 K 2,908 K 820 Usermode Font Driver Host Microsoft Corporation (Verified) Microsoft Windows
fontdrvhost.exe 7,936 K 14,128 K 816 Usermode Font Driver Host Microsoft Corporation (Verified) Microsoft Windows
GoogleCrashHandler.exe 1,076 K 2,296 K 6704 Google Crash Handler Google LLC (Verified) Google LLC
ibmpmsvc.exe 1,016 K 4,728 K 1428 Lenovo Power Management Service Lenovo. (Verified) LENOVO
mqsvc.exe 3,524 K 11,424 K 2268 Message Queuing Service Microsoft Corporation (Verified) Microsoft Windows
NisSrv.exe 4,112 K 8,760 K 5980 Microsoft Network Realtime Inspection Service Microsoft Corporation (Verified) Microsoft Windows Publisher
NMSAccessU.exe 912 K 4,768 K 2336 (Verified) Numedia Soft, Inc.
OfficeC2RClient.exe 3,532 K 10,512 K 6548 Microsoft Office Click-to-Run Client Microsoft Corporation (Verified) Microsoft Corporation
OfficeClickToRun.exe 9,860 K 27,568 K 2204 Microsoft Office Click-to-Run (SxS) Microsoft Corporation (Verified) Microsoft Corporation
Registry 9,100 K 72,240 K 88
RuntimeBroker.exe 5,756 K 20,612 K 5432 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 2,236 K 11,836 K 1036 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 3,144 K 16,324 K 4192 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
ScanToPCActivationApp.exe 2,664 K 12,740 K 2352 ScanToPCActivationApp Hewlett-Packard Co. (Verified) Hewlett Packard
SearchProtocolHost.exe 2,040 K 11,404 K 6100 Microsoft Windows Search Protocol Host Microsoft Corporation (Verified) Microsoft Windows
SearchUI.exe Suspended 52,276 K 63,376 K 5680 Search and Cortana application Microsoft Corporation (Verified) Microsoft Windows
SecurityHealthService.exe 3,008 K 12,744 K 2240 Windows Security Health Service Microsoft Corporation (Verified) Microsoft Windows Publisher
SecurityHealthSystray.exe 1,364 K 7,760 K 5064 Windows Security notification icon Microsoft Corporation (Verified) Microsoft Windows
SettingSyncHost.exe 2,292 K 5,628 K 4656 Host Process for Setting Synchronization Microsoft Corporation (Verified) Microsoft Windows
sihost.exe 4,276 K 19,836 K 152 Shell Infrastructure Host Microsoft Corporation (Verified) Microsoft Windows
smss.exe 352 K 696 K 372 Windows Session Manager Microsoft Corporation (Verified) Microsoft Windows Publisher
SMSvcHost.exe 16,588 K 19,512 K 2328 SMSvcHost.exe Microsoft Corporation (Verified) Microsoft Corporation
SMSvcHost.exe 15,056 K 13,940 K 3800 SMSvcHost.exe Microsoft Corporation (Verified) Microsoft Corporation
StartMenuExperienceHost.exe 15,528 K 52,120 K 5280 (Verified) Microsoft Windows
svchost.exe 920 K 4,872 K 2360 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,452 K 6,524 K 3412 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,212 K 7,100 K 3332 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,052 K 9,760 K 2192 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,976 K 11,992 K 2872 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,292 K 5,832 K 1804 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,136 K 8,592 K 7992 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,016 K 9,756 K 2284 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4,632 K 12,216 K 2480 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,456 K 12,068 K 1756 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 6,308 K 13,552 K 1948 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 17,388 K 26,192 K 1252 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 25,200 K 15,308 K 1136 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 8,156 K 16,624 K 1400 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 8,340 K 41,280 K 732 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
taskhostw.exe 1,204 K 6,136 K 720 Host Process for Windows Tasks Microsoft Corporation (Verified) Microsoft Windows
unsecapp.exe 1,172 K 6,740 K 3468 Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation (Verified) Microsoft Windows
w3dbsmgr.exe 284,996 K 41,972 K 2372 Database Service Manager Pervasive Software Inc. (Verified) Sage Software, Inc.
wermgr.exe 1,196 K 3,332 K 7456 Windows Problem Reporting Microsoft Corporation (Verified) Microsoft Windows
WG111v3.exe 3,772 K 13,712 K 4132 NetgearCUv2 MFC Application (No signature was present in the subject)
wininit.exe 1,136 K 5,804 K 576 Windows Start-Up Application Microsoft Corporation (Verified) Microsoft Windows Publisher
winlogon.exe 2,184 K 10,292 K 768 Windows Logon Application Microsoft Corporation (Verified) Microsoft Windows
WmiPrvSE.exe 2,096 K 7,228 K 6888 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
WmiPrvSE.exe 1,944 K 7,420 K 4580 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
svchost.exe < 0.01 4,384 K 14,848 K 2404 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
spoolsv.exe < 0.01 10,988 K 27,160 K 988 Spooler SubSystem App Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 0.01 6,212 K 17,040 K 1156 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
QtWebEngineProcess.exe 0.01 32,704 K 52,116 K 1420 Qt Qtwebengineprocess The Qt Company Ltd. (Verified) Dropbox, Inc
RuntimeBroker.exe 0.01 6,080 K 19,656 K 5868 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 0.01 4,164 K 9,856 K 936 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 0.01 22,844 K 51,216 K 1120 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
YourPhone.exe 0.01 11,676 K 30,356 K 4200 (No signature was present in the subject)
AGMService.exe 0.01 3,400 K 12,480 K 2108 Adobe Genuine Software Service Adobe Systems, Incorporated (Verified) Adobe Inc.
svchost.exe 0.01 2,592 K 8,956 K 1812 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
SearchIndexer.exe 0.02 27,108 K 28,392 K 4812 Microsoft Windows Search Indexer Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 0.03 4,700 K 16,180 K 64 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 0.03 8,484 K 23,192 K 1468 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
CNMNSST2.exe 0.03 2,012 K 8,676 K 848 Canon IJ Network Scanner Selector EX2 CANON INC. (Verified) Canon Inc.
svchost.exe 0.04 8,236 K 24,580 K 832 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
SearchFilterHost.exe 0.05 1,136 K 6,072 K 7756 Microsoft Windows Search Filter Host Microsoft Corporation (Verified) Microsoft Windows
lsass.exe 0.08 4,324 K 13,260 K 648 Local Security Authority Process Microsoft Corporation (Verified) Microsoft Windows Publisher
AdobeCollabSync.exe 0.13 4,556 K 15,528 K 4820 Adobe Collaboration Synchronizer 20.6 Adobe Systems Incorporated (Verified) Adobe Inc.
svchost.exe 0.15 7,216 K 19,336 K 1652 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
csrss.exe 0.21 1,320 K 4,544 K 596 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows Publisher
explorer.exe 0.27 29,964 K 84,292 K 4512 Windows Explorer Microsoft Corporation (Verified) Microsoft Windows
services.exe 0.34 2,972 K 6,564 K 640 Services and Controller app Microsoft Corporation (Verified) Microsoft Windows Publisher
g2mupdate.exe 0.55 6,692 K 14,976 K 5628 GoToMeeting LogMeIn, Inc. (Verified) LogMeIn, Inc.
System 0.66 72 K 180 K 4
dwm.exe 0.77 50,644 K 43,436 K 1012 Desktop Window Manager Microsoft Corporation (Verified) Microsoft Windows
Interrupts 1.96 0 K 0 K n/a Hardware Interrupts and DPCs
MsMpEng.exe 3.43 134,752 K 140,088 K 2624 Antimalware Service Executable Microsoft Corporation (Verified) Microsoft Windows Publisher
QtWebEngineProcess.exe 6.59 32,728 K 52,716 K 3892 Qt Qtwebengineprocess The Qt Company Ltd. (Verified) Dropbox, Inc
procexp.exe 14.53 28,824 K 53,592 K 8044 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
System Idle Process 27.70 40 K 4 K 0
Dropbox.exe 43.03 252,776 K 284,664 K 5368 Dropbox Dropbox, Inc. (Verified) Dropbox, Inc
 

 

2.  FRST;

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-04-2020
Ran by Chrissy (administrator) on CHRISSY-PC (LENOVO 7439W6R) (26-04-2020 17:33:56)
Running from C:\Users\Chrissy\Desktop
Loaded Profiles: Chrissy (Available Profiles: Chrissy & DefaultAppPool)
Platform: Microsoft Windows 10 Home Version 1909 18363.778 (X86) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
(Adobe Inc. -> Adobe Systems Inc.) C:\Program Files\Adobe\Acrobat DC\Acrobat\acrotray.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(Adobe Inc. -> Adobe Systems) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Canon Inc. -> CANON INC.) C:\Program Files\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Users\Chrissy\AppData\Local\Dropbox\Update\DropboxUpdate.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\Dropbox.exe <3>
(Dropbox, Inc -> The Qt Company Ltd.) C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\95.4.441\QtWebEngineProcess.exe <2>
(Hewlett Packard -> Hewlett-Packard Co.) C:\Program Files\Hp\HP Officejet Pro 8500 A910\Bin\ScanToPCActivationApp.exe
(LENOVO -> Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2004.6-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2004.6-0\NisSrv.exe
(Numedia Soft, Inc. -> ) C:\Program Files\CDBurnerXP\NMSAccessU.exe
(Sage Software, Inc. -> Pervasive Software Inc.) C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [PeachtreePrefetcher.exe] => C:\Program Files\Sage\Peachtree\PeachtreePrefetcher.exe [30576 2012-10-22] (Sage Software, Inc. -> Sage Software, Inc.)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3022416 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [Acrobat Assistant 8.0] => C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrotray.exe [5314096 2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2379504 2013-04-24] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [IJNetworkScannerSelectorEX2] => C:\Program Files\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe [270912 2015-06-17] (Canon Inc. -> CANON INC.)
HKU\S-1-5-21-2695042837-3831575686-1124767896-1000\...\Run: [Dropbox Update] => C:\Users\Chrissy\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-06] (Dropbox, Inc -> Dropbox, Inc.)
HKU\S-1-5-21-2695042837-3831575686-1124767896-1000\...\Run: [HP Officejet Pro 8500 A910 (NET)] => C:\Program Files\Hp\HP Officejet Pro 8500 A910\Bin\ScanToPCActivationApp.exe [1837672 2012-10-17] (Hewlett Packard -> Hewlett-Packard Co.)
HKU\S-1-5-21-2695042837-3831575686-1124767896-1000\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [5557296 2020-03-05] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-2695042837-3831575686-1124767896-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [134656 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\81.0.4044.122\Installer\chrmstp.exe [2020-04-24] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] -> 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk [2013-02-03]
ShortcutTarget: NETGEAR WG111v3 Smart Wizard.lnk -> C:\Program Files\NETGEAR\WG111v3\WG111v3.exe () [File not signed]
Startup: C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2020-03-20]
ShortcutTarget: Dropbox.lnk -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
Startup: C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet Pro 8500 A910 (Network).lnk [2016-05-20]
ShortcutAndArgument: Monitor Ink Alerts - HP Officejet Pro 8500 A910 (Network).lnk -> C:\Windows\system32\RunDll32.exe => "C:\Program Files\HP\HP Officejet Pro 8500 A910\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN0BIBM07J;CONNECTION=NW;MONITOR=1;
GroupPolicy\User: Restriction ? <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {019B1734-9A1F-44C9-80A1-BF0F6F3D5D51} - System32\Tasks\G2MUpdateTask-S-1-5-21-2695042837-3831575686-1124767896-1000 => C:\Users\Chrissy\AppData\Local\GoToMeeting\10996\g2mupdate.exe [29736 2018-11-05] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {04B5251C-8D64-4910-BED8-99D2AB52ED25} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [18936600 2020-04-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {17EC1FE7-D867-49CF-9751-7C4EF3DD3F00} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2004.6-0\MpCmdRun.exe [418768 2020-04-21] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3F468508-9C3B-4EC3-A812-8900D6A3738A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2004.6-0\MpCmdRun.exe [418768 2020-04-21] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {41044F75-AA49-41A2-86D1-8CDDC895E884} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [18936600 2020-04-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {57D2D5AB-A981-42C5-9C07-526A75391A32} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2004.6-0\MpCmdRun.exe [418768 2020-04-21] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7AE05DD8-A634-4483-AAA2-113909AA4BA7} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [115448 2020-04-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {A4485799-C4F3-4606-BA99-6DB42FD496F6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2004.6-0\MpCmdRun.exe [418768 2020-04-21] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {A76D933D-AC92-4D21-972D-B7A37FAB4A46} - System32\Tasks\0 => c:\program files\internet explorer\iexplore.exe 
Task: {AEC6F720-D19B-4CDE-8D25-22BC11215A84} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [144200 2015-08-30] (Google Inc -> Google Inc.)
Task: {BA7A9B7A-2B62-4F71-B97F-AE3C34A79257} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [115448 2020-04-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {BF97CB34-3029-48F7-BDBB-FB952D720991} - System32\Tasks\SidebarExecute => C:\Program Files\Windows Sidebar\sidebar.exe
Task: {CDBE7605-8F60-4F79-AEC2-1F1ABC779DFF} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
Task: {D989BDBD-BC6A-4B4C-A09E-88DCF1546107} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [269504 2016-05-13] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {DB67E9E2-7A43-4A62-8197-69383BDC3814} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {E20C0141-41C2-49C4-8D18-2DE08E6BB110} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {E79B2998-8F63-451A-A56D-26EDC0A5098A} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47C2-B62A-B7C4CED925CB}
Task: {E7AF8EDD-83B0-4AF7-B146-38DE487DED64} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [144200 2015-08-30] (Google Inc -> Google Inc.)
Task: {E9241184-65A8-4D90-BEB5-0DC9664DD6AA} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E}
Task: {F908A273-E82E-4629-853A-92F40A7AAEE2} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3022416 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{072620ba-7083-4d9e-b4b6-9da50f9d0f8b}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{29ea32ab-d579-422f-9305-96d856445e85}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{6fb389c2-2b28-481d-8e9e-4bd3eb9a80d3}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{b8632072-9b1e-40ac-9bb9-9b4b1783b2de}: [DhcpNameServer] 75.75.75.75 75.75.76.76
 
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000 -> {180780f0-b348-4b44-8210-94a8f3ee15b2} URL = hxxp://search.comcast.net/search/?cat=Web&con=toolbar&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000 -> {3FC5EC2D-7212-4C6B-99E8-393ADDB9FBC3} URL = hxxp://www.mysearchresults.com/search?&c=4200&t=11&q={searchTerms}
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2018-12-04] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2018-12-04] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2018-12-04] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Toolbar: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-04-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-04-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-04-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-04-15] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2019-05-02]
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2011-06-10] (Adobe Systems, Inc.) [File not signed]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-04-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default [2020-04-26]
CHR NewTab: Default ->  Not-active:"chrome-extension://mallpejgeafdahhflmliiahjdpgbegpk/ntp1.html"
CHR Extension: (Docs) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Google Drive) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Google Search) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Adobe Acrobat) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2020-03-04]
CHR Extension: (Google Docs Offline) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-04-23]
CHR Extension: (Xfinity) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\hemjgdpngmhbimofcicjfhibkdbigdmb [2014-02-25]
CHR Extension: (FromDocToPDF) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mallpejgeafdahhflmliiahjdpgbegpk [2019-12-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-07]
CHR Extension: (Gmail) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-30]
CHR Extension: (Chrome Media Router) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-09]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM\...\Chrome\Extension: [hemjgdpngmhbimofcicjfhibkdbigdmb] - C:\ProgramData\comcastModemRelease\shortcuts\chrome\xfinity.crx [2013-02-08]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeARMservice; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [88648 2020-02-25] (Adobe Inc. -> Adobe Systems)
R2 AGMService; C:\Program Files\Common Files\Adobe\AdobeGCClient\AGMService.exe [3374160 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [3103824 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [7596920 2020-04-10] (Microsoft Corporation -> Microsoft Corporation)
R2 NMSAccess; C:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2010-03-05] (Numedia Soft, Inc. -> )
S3 Peachtree SmartPosting 2012; C:\Program Files\Sage\Peachtree\SmartPostingService2012.exe [44400 2012-10-22] (Sage Software, Inc. -> Sage Software, Inc.)
R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [52736 2009-06-22] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard)
R2 psqlWGE; C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe [435528 2011-04-07] (Sage Software, Inc. -> Pervasive Software Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2004.6-0\NisSrv.exe [2303144 2020-04-21] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2004.6-0\MsMpEng.exe [85760 2020-04-21] (Microsoft Windows Publisher -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [28824 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 cpudrv; C:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2011-06-02] (Intel® Graphics DSS -> )
S3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [132520 2015-03-10] (BoiseTest -> Windows ® Win 7 DDK provider)
S3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [17320 2015-03-10] (BoiseTest -> Windows ® Win 7 DDK provider)
S3 dot4usb; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [37800 2015-03-10] (BoiseTest -> Microsoft Corporation)
R3 Eplpdx02; C:\WINDOWS\system32\Drivers\EPLPDX02.SYS [70084 2001-08-10] (MK Systems CO., LTD.) [File not signed]
S3 NETw5s32; C:\WINDOWS\System32\DRIVERS\NETw5s32.sys [6114816 2009-09-15] (Intel Corporation) [File not signed]
R3 NETwNs32; C:\WINDOWS\System32\drivers\NETwNs32.sys [7530736 2013-05-02] (Intel Corporation-Mobile Wireless Group -> Intel Corporation)
S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL32.sys [24832 2015-07-13] (Daniel Terhell -> Resplendence Software Projects Sp.)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [38640 2013-04-24] (Synaptics Incorporated -> Synaptics Incorporated)
R3 SrvHsfHDA; C:\WINDOWS\system32\DRIVERS\VSTAZL3.SYS [207360 2019-03-18] (Microsoft Windows -> Conexant Systems, Inc.)
R3 SrvHsfV92; C:\WINDOWS\system32\DRIVERS\VSTDPV3.SYS [980992 2019-03-18] (Microsoft Windows -> Conexant Systems, Inc.)
R3 SrvHsfWinac; C:\WINDOWS\system32\DRIVERS\VSTCNXT3.SYS [661504 2019-03-18] (Microsoft Windows -> Conexant Systems, Inc.)
S3 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [7168 2009-11-12] () [File not signed]
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [37984 2020-04-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [305592 2020-04-21] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [46000 2020-04-21] (Microsoft Windows -> Microsoft Corporation)
S3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [207360 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
U3 idsvc; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ===================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-04-26 17:33 - 2020-04-26 17:36 - 000021201 _____ C:\Users\Chrissy\Desktop\FRST.txt
2020-04-26 17:33 - 2020-04-26 17:33 - 000011229 _____ C:\Users\Chrissy\Desktop\Registry.txt
2020-04-26 17:04 - 2020-04-26 17:04 - 000000976 _____ C:\Users\Chrissy\Desktop\HD Tune.lnk
2020-04-26 17:04 - 2020-04-26 17:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune
2020-04-26 17:04 - 2020-04-26 17:04 - 000000000 ____D C:\Program Files\HD Tune
2020-04-26 17:03 - 2020-04-26 17:03 - 000642632 _____ (EFD Software ) C:\Users\Chrissy\Downloads\hdtune_255.exe
2020-04-26 16:59 - 2020-04-26 16:59 - 002011136 _____ (Farbar) C:\Users\Chrissy\Desktop\FRST.exe
2020-04-26 08:55 - 2020-04-26 08:55 - 000428390 _____ C:\Users\Chrissy\Desktop\UI Online - Doc_20200426085419.pdf
2020-04-26 08:54 - 2020-04-26 08:54 - 000428390 _____ C:\Users\Chrissy\Downloads\UI Online - Doc_20200426085419.pdf
2020-04-18 15:37 - 2020-04-18 15:37 - 001870408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2020-04-18 15:37 - 2020-04-18 15:37 - 001013000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-04-18 15:37 - 2020-04-18 15:37 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2020-04-18 15:37 - 2020-04-18 15:37 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2020-04-18 15:37 - 2020-04-18 15:37 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbadmin.exe
2020-04-18 15:37 - 2020-04-18 15:37 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 019850240 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 018027520 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 007070736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 007017472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 006523048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 005910016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 003512320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 002999808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 002978816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 002865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 002799104 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 002536448 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSAT.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 002234680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-04-18 15:36 - 2020-04-18 15:36 - 002078096 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 001659736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 001616704 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 001477112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 001429312 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 001394544 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-04-18 15:36 - 2020-04-18 15:36 - 001310720 _____ (Microsoft Corporation) C:\WINDOWS\system32\msjet40.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 001298432 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 001264640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 001247024 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 001077424 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 001066496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000880952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2020-04-18 15:36 - 2020-04-18 15:36 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000798720 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000768528 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000766464 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000692736 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000686080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000673464 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 000665088 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000660480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2020-04-18 15:36 - 2020-04-18 15:36 - 000647680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000636696 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000531456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000525312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000462864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-04-18 15:36 - 2020-04-18 15:36 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2020-04-18 15:36 - 2020-04-18 15:36 - 000427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 000415760 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000397624 _____ (Microsoft Corporation) C:\WINDOWS\system32\halmacpi.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000397624 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000392208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000381440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 000361784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2020-04-18 15:36 - 2020-04-18 15:36 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrd3x40.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\msexcl40.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\system32\es.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000331064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2020-04-18 15:36 - 2020-04-18 15:36 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\msltus40.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000220984 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000190048 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoncli.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasrad.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageComponentsInstaller.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000136504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2020-04-18 15:36 - 2020-04-18 15:36 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000102248 _____ (Microsoft Corporation) C:\WINDOWS\system32\smss.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasacct.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumapi.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000043008 _____ C:\WINDOWS\system32\runexehelper.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 000040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\iaspolcy.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000031544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hwpolicy.sys
2020-04-18 15:36 - 2020-04-18 15:36 - 000031248 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ias.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsunattend.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe
2020-04-18 15:36 - 2020-04-18 15:36 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2020-04-18 15:36 - 2020-04-18 15:36 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2020-04-18 15:35 - 2020-04-18 15:36 - 000138768 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 014818816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 004867944 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 004755968 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 003742544 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 002800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-04-18 15:35 - 2020-04-18 15:35 - 002760720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-04-18 15:35 - 2020-04-18 15:35 - 002711864 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 002377216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 002058240 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-04-18 15:35 - 2020-04-18 15:35 - 001916744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001587712 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001541120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001539688 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001498112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001484384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001473848 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001469440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001452544 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001368576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001368576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001245184 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001154656 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001150464 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 001139712 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001055376 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 001009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000993280 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000899688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000865280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000802304 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000785920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000785920 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000729600 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000689680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-04-18 15:35 - 2020-04-18 15:35 - 000673704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000632832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000627000 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000612864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000607544 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000587264 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000538160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000537912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2020-04-18 15:35 - 2020-04-18 15:35 - 000526352 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000507152 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000506232 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000491008 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000487784 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000478720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000406480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000402528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000393728 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000375720 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000374584 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000344376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-04-18 15:35 - 2020-04-18 15:35 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-04-18 15:35 - 2020-04-18 15:35 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.th.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000290304 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000268008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000265528 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcApi.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2020-04-18 15:35 - 2020-04-18 15:35 - 000195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000185952 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000134416 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingUI.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000123952 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000105592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcDecoderHost.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000096000 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000094976 _____ (Microsoft Corporation) C:\WINDOWS\system32\changepk.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000072808 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\keepaliveprovider.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000061240 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000050544 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudNotifications.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.Common.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000042792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeResultsUI.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2020-04-18 15:35 - 2020-04-18 15:35 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxssrv.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcProxyStubs.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprtPS.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.ps.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbservicetrigger.dll
2020-04-18 15:35 - 2020-04-18 15:35 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll
2020-04-18 15:34 - 2020-04-18 15:35 - 000136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2020-04-18 15:34 - 2020-04-18 15:34 - 001401344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2020-04-18 15:34 - 2020-04-18 15:34 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2020-04-18 15:34 - 2020-04-18 15:34 - 000325136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2020-04-18 15:34 - 2020-04-18 15:34 - 000235320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2020-04-18 15:34 - 2020-04-18 15:34 - 000158736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2020-04-18 15:34 - 2020-04-18 15:34 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2020-04-18 15:34 - 2020-04-18 15:34 - 000066872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2020-04-18 15:34 - 2020-04-18 15:34 - 000047416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2020-04-18 15:34 - 2020-04-18 15:34 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys
2020-04-18 15:34 - 2020-04-18 15:34 - 000020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\flpydisk.sys
2020-04-18 15:34 - 2020-04-18 15:34 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sfloppy.sys
2020-04-18 15:08 - 2020-03-16 23:57 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-04-18 14:58 - 2020-04-18 14:58 - 000000000 ____D C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2020-04-16 20:08 - 2020-04-18 14:20 - 000001047 _____ C:\Users\Chrissy\Desktop\LatencyMon.lnk
2020-04-16 20:08 - 2020-04-16 20:08 - 000001035 _____ C:\Users\Chrissy\Desktop\In Depth Latency Tests.lnk
2020-04-16 20:08 - 2020-04-16 20:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LatencyMon
2020-04-16 20:08 - 2020-04-16 20:08 - 000000000 ____D C:\Program Files\LatencyMon
2020-04-16 20:08 - 2015-07-13 11:16 - 000024832 _____ (Resplendence Software Projects Sp.) C:\WINDOWS\system32\Drivers\rspLLL32.sys
2020-04-16 20:06 - 2020-04-16 20:07 - 002323432 _____ (Resplendence Software Projects Sp. ) C:\Users\Chrissy\Downloads\LatencyMon.exe
2020-04-15 22:36 - 2020-04-15 22:43 - 000002886 _____ C:\Users\Chrissy\Desktop\OOSU10.ini
2020-04-15 22:20 - 2020-04-15 22:20 - 000002458 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2020-04-15 22:20 - 2020-04-15 22:20 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2020-04-15 22:20 - 2020-04-15 22:20 - 000002421 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2020-04-15 22:20 - 2020-04-15 22:20 - 000002420 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2020-04-15 22:20 - 2020-04-15 22:20 - 000002414 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2020-04-15 22:20 - 2020-04-15 22:20 - 000002408 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2020-04-15 22:20 - 2020-04-15 22:20 - 000002400 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2020-04-15 22:20 - 2020-04-15 22:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2020-04-15 22:18 - 2020-04-15 22:18 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2020-04-15 21:38 - 2020-04-15 21:38 - 000000000 ____D C:\Program Files\Microsoft Office 15
2020-04-13 20:16 - 2020-04-13 20:16 - 001030520 _____ (O&O Software GmbH) C:\Users\Chrissy\Desktop\OOSU10.exe
2020-04-13 20:14 - 2020-04-13 20:14 - 002798456 _____ (Sysinternals - www.sysinternals.com) C:\Users\Chrissy\Desktop\procexp.exe
2020-04-10 15:23 - 2020-03-14 11:21 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthA2dp.sys
2020-04-09 14:57 - 2020-04-09 14:58 - 002868054 _____ C:\Users\Chrissy\Downloads\941.pdf
2020-04-09 14:43 - 2020-04-09 14:43 - 000606391 _____ C:\Users\Chrissy\Desktop\Q 3 941.pdf
2020-04-09 14:42 - 2020-04-09 14:42 - 000608855 _____ C:\Users\Chrissy\Desktop\Q 3 941 II.pdf
2020-04-09 10:09 - 2020-04-09 10:52 - 000000026 _____ C:\WINDOWS\AatrixForms.INI
2020-04-09 10:09 - 2020-04-09 10:09 - 000000000 ____D C:\Users\Chrissy\AppData\Roaming\Aatrix Software
2020-04-09 10:09 - 2020-04-09 10:09 - 000000000 ____D C:\Users\Chrissy\AppData\Local\Aatrix Software
2020-04-08 20:06 - 2020-04-08 20:06 - 000000045 _____ C:\WINDOWS\system32\initdebug.nfo
2020-04-07 20:07 - 2020-04-23 21:31 - 000018798 _____ C:\junk.txt
2020-04-07 19:54 - 2020-04-26 17:30 - 000030048 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2020-04-06 14:00 - 2020-04-06 14:01 - 000078168 _____ (Zoom Video Communications, Inc.) C:\Users\Chrissy\Downloads\Zoom_ca54e9ef2f18a90a.exe
2020-04-05 19:05 - 2020-04-26 17:35 - 000000000 ____D C:\FRST
2020-04-05 16:23 - 2020-04-05 16:23 - 000000000 ____D C:\WINDOWS\Panther
2020-04-05 15:10 - 2020-04-05 15:10 - 000000267 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
2020-04-05 14:28 - 2020-04-05 14:28 - 000000000 ____D C:\ProgramData\Intel
2020-04-04 19:37 - 2020-04-04 19:39 - 001993489 _____ C:\Users\Chrissy\Documents\Savannah Sousa 2020-21.pdf
2020-04-04 19:31 - 2020-04-04 19:33 - 002313479 _____ C:\Users\Chrissy\Documents\Griffin Sousa 2019-20.pdf
2020-04-04 19:23 - 2020-04-04 19:26 - 003259887 _____ C:\Users\Chrissy\Documents\Savannah Sousa 2019-20.pdf
2020-04-03 10:46 - 2020-04-03 10:46 - 000428390 _____ C:\Users\Chrissy\Downloads\UI Online - Doc_20200403104628.pdf
2020-04-03 08:35 - 2020-04-03 08:35 - 000255320 _____ (Asurvio, LP) C:\Users\Chrissy\Downloads\DSOne.exe
2020-04-03 07:55 - 2020-04-03 07:55 - 000007605 _____ C:\Users\Chrissy\AppData\Local\Resmon.ResmonCfg
2020-04-02 19:08 - 2020-04-05 15:11 - 000000000 ____D C:\ProgramData\Lenovo
2020-04-02 19:08 - 2020-04-05 15:10 - 000000000 ____D C:\WINDOWS\system32\Tasks\TVT
2020-04-02 19:05 - 2020-04-05 15:11 - 000000000 ____D C:\WINDOWS\system32\Tasks\Lenovo
2020-04-02 19:02 - 2020-04-05 15:12 - 000000000 ____D C:\WINDOWS\TempInst
2020-04-02 15:13 - 2020-04-02 15:13 - 000004987 _____ C:\Users\Chrissy\Downloads\Dynamic Email List - Parent & Child Classes (2019-2020).xlsx
2020-04-02 15:11 - 2020-04-02 15:11 - 000004346 _____ C:\Users\Chrissy\Downloads\Dynamic Email List - Transitional Preschool (2019-20).xlsx
2020-04-02 15:06 - 2020-04-02 15:08 - 000010235 _____ C:\Users\Chrissy\Downloads\Dynamic Email List - Preschool (2019-20).xlsx
2020-04-02 14:58 - 2020-04-02 15:00 - 000009429 _____ C:\Users\Chrissy\Downloads\Dynamic Email List - Multi-Track Kindergarten (2019-20).xlsx
2020-04-02 14:56 - 2020-04-02 14:56 - 000004915 _____ C:\Users\Chrissy\Downloads\Dynamic Email List - Summer 2020.xlsx
2020-04-02 14:47 - 2020-04-02 14:47 - 000086093 _____ C:\Users\Chrissy\Downloads\members_export_8e7b28e9c4.zip
2020-04-02 14:32 - 2020-04-02 14:33 - 000002158 _____ C:\Users\Chrissy\Downloads\members_export_5e4b740e45.zip
2020-04-01 20:11 - 2020-04-01 20:11 - 005747077 _____ C:\Users\Chrissy\Documents\Dependents.pdf
2020-04-01 19:35 - 2020-04-01 19:35 - 000546775 _____ C:\Users\Chrissy\Downloads\UI Online - Doc_20200401193509.pdf
2020-04-01 19:35 - 2020-04-01 19:35 - 000546775 _____ C:\Users\Chrissy\Downloads\UI Online - Doc_20200401193500.pdf
2020-04-01 19:25 - 2020-04-01 19:25 - 000546772 _____ C:\Users\Chrissy\Downloads\UI Online - Doc_20200401192522.pdf
2020-04-01 19:24 - 2020-04-01 19:24 - 000024058 _____ C:\Users\Chrissy\Downloads\UI Online - Doc_20200401192406.pdf
2020-04-01 19:20 - 2020-04-01 19:20 - 000546772 _____ C:\Users\Chrissy\Downloads\UI Online - Doc_20200401192043.pdf
2020-03-31 20:37 - 2020-03-31 20:37 - 000024058 _____ C:\Users\Chrissy\Downloads\UI Online - Doc_20200331203718.pdf
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-04-26 17:36 - 2019-03-18 22:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-04-26 17:35 - 2019-08-20 20:01 - 000004162 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{B76945DF-72EF-4988-9332-2D50101B113A}
2020-04-26 17:31 - 2019-10-01 19:40 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2020-04-26 17:31 - 2019-10-01 19:40 - 000000000 ___HD C:\ProgramData\Documents\AdobeGCData
2020-04-26 17:26 - 2019-08-20 20:01 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-04-26 17:25 - 2019-03-18 22:35 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2020-04-26 16:51 - 2018-06-28 13:38 - 000000000 ____D C:\Users\Chrissy\AppData\Local\Adobe
2020-04-25 14:11 - 2019-03-18 22:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-04-24 20:18 - 2019-08-20 19:24 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-04-24 14:00 - 2012-12-29 09:16 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-04-24 13:57 - 2013-08-29 09:20 - 000000000 ___RD C:\Users\Chrissy\Dropbox
2020-04-23 21:01 - 2019-03-18 22:46 - 000000000 ___HD C:\Program Files\WindowsApps
2020-04-23 20:59 - 2018-01-14 23:59 - 000000000 ____D C:\Users\Chrissy\AppData\Local\Packages
2020-04-23 20:26 - 2012-06-13 18:29 - 000000000 ____D C:\Users\Chrissy\AppData\Local\VirtualStore
2020-04-21 19:13 - 2018-02-24 21:56 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-04-20 09:00 - 2019-08-20 19:49 - 000950252 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-04-20 09:00 - 2019-03-18 22:44 - 000000000 ____D C:\WINDOWS\INF
2020-04-20 08:52 - 2019-08-20 19:24 - 000493968 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-04-19 20:54 - 2019-03-18 22:46 - 000000000 ____D C:\WINDOWS\SystemResources
2020-04-19 20:54 - 2019-03-18 22:46 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-04-19 20:54 - 2019-03-18 22:46 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-04-19 20:54 - 2019-03-18 22:46 - 000000000 ____D C:\WINDOWS\Provisioning
2020-04-19 20:54 - 2019-03-18 22:46 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-04-19 09:20 - 2019-03-18 22:35 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-04-18 15:02 - 2012-10-02 19:52 - 000000000 ____D C:\Users\Chrissy\AppData\Roaming\Dropbox
2020-04-15 22:31 - 2019-08-20 20:01 - 000002418 _____ C:\WINDOWS\system32\Tasks\0
2020-04-15 22:26 - 2016-07-22 10:27 - 000000000 ____D C:\Users\Chrissy\AppData\Local\ElevatedDiagnostics
2020-04-15 22:19 - 2019-03-18 22:46 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2020-04-15 22:19 - 2012-06-16 21:34 - 000000000 ____D C:\Program Files\Microsoft Office
2020-04-15 21:37 - 2019-08-20 20:01 - 000003374 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2695042837-3831575686-1124767896-1000
2020-04-15 21:37 - 2019-08-20 19:36 - 000002421 _____ C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-04-15 21:37 - 2016-05-22 12:17 - 000000000 ___RD C:\Users\Chrissy\OneDrive
2020-04-13 20:08 - 2018-02-08 12:07 - 000000000 ____D C:\Users\Chrissy\AppData\Local\PlaceholderTileLogoFolder
2020-04-13 09:12 - 2019-08-20 19:36 - 000000000 ____D C:\Users\Chrissy
2020-04-08 20:27 - 2013-07-05 15:34 - 000000000 ____D C:\Program Files\Java
2020-04-08 20:22 - 2014-03-09 21:33 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2020-04-05 19:57 - 2019-05-28 20:36 - 000000000 ____D C:\Users\Chrissy\AppData\Local\D3DSCache
2020-04-05 15:11 - 2019-01-08 11:14 - 000000000 ____D C:\ProgramData\Package Cache
2020-04-05 15:11 - 2013-02-28 09:04 - 000000000 ____D C:\Program Files\Intel
2020-04-02 19:35 - 2020-01-30 10:05 - 000609128 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-04-02 13:35 - 2012-06-19 20:44 - 000000000 ____D C:\Users\Chrissy\AppData\Local\CutePDF Writer
 
==================== Files in the root of some directories ========
 
2013-05-14 13:55 - 2013-05-14 13:55 - 000033193 _____ () C:\Users\Chrissy\AppData\Roaming\UserTile.png
2017-12-14 16:33 - 2017-12-14 16:33 - 000004096 ____H () C:\Users\Chrissy\AppData\Local\keyfile3.drm
2019-01-08 11:09 - 2019-01-08 11:09 - 000000615 _____ () C:\Users\Chrissy\AppData\Local\oobelibMkey.log
2020-04-03 07:55 - 2020-04-03 07:55 - 000007605 _____ () C:\Users\Chrissy\AppData\Local\Resmon.ResmonCfg
2015-01-05 16:50 - 2015-01-05 16:50 - 000000000 _____ () C:\Users\Chrissy\AppData\Local\{F2E88783-AFFE-446F-B21E-F98399405CA3}
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 
3. FRST_Addition:
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 26-04-2020
Ran by Chrissy (26-04-2020 17:39:07)
Running from C:\Users\Chrissy\Desktop
Microsoft Windows 10 Home Version 1909 18363.778 (X86) (2019-08-21 00:03:14)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2695042837-3831575686-1124767896-500 - Administrator - Disabled)
Chrissy (S-1-5-21-2695042837-3831575686-1124767896-1000 - Administrator - Enabled) => C:\Users\Chrissy
DefaultAccount (S-1-5-21-2695042837-3831575686-1124767896-503 - Limited - Disabled)
Guest (S-1-5-21-2695042837-3831575686-1124767896-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2695042837-3831575686-1124767896-1002 - Limited - Enabled)
WDAGUtilityAccount (S-1-5-21-2695042837-3831575686-1124767896-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 4.65 (HKLM\...\7-Zip) (Version:  - )
Adobe Acrobat DC (HKLM\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Adobe Acrobat Reader DC (HKLM\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Adobe AIR (HKLM\...\Adobe AIR) (Version: 2.7.0.19530 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM\...\Adobe Shockwave Player) (Version: 11.6.0.626 - Adobe Systems, Inc.)
Canon IJ Network Scanner Selector EX2 (HKLM\...\Canon_IJ_Network_Scanner_Selector_EX2) (Version: 2.0.0.19 - Canon Inc.)
Canon IJ Scan Utility (HKLM\...\Canon_IJ_Scan_Utility) (Version: 1.2.0.18 - Canon Inc.)
Canon MB2700 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MB2700_series) (Version: 1.02 - Canon Inc.)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.3.1.2101 - CDBurnerXP)
Cisco WebEx Meetings (HKLM\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Combined Community Codec Pack 2009-09-09 (HKLM\...\Combined Community Codec Pack_is1) (Version: 2009.09.09.0 - CCCP Project)
Crystal Reports 2008 Runtime SP1 (HKLM\...\{C484CC8D-03CF-4022-89C4-DB4F02E8A15B}) (Version: 12.1.0.882 - Business Objects)
CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version:  - )
Dot4 (HKLM\...\{FF359AAB-AA6A-449F-B75F-21201CD86495}) (Version: 1.0.0.0 - HP)
Dropbox (HKU\S-1-5-21-2695042837-3831575686-1124767896-1000\...\Dropbox) (Version: 95.4.441 - Dropbox, Inc.)
EPSON Printer Software (HKLM\...\EPSON Printer and Utilities) (Version:  - )
Google Chrome (HKLM\...\Google Chrome) (Version: 81.0.4044.122 - Google LLC)
Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Google Update Helper (HKLM\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
GoTo Opener (HKLM\...\{665DF231-32BE-46BA-ABD2-B0D69F8314FF}) (Version: 1.0.494 - LogMeIn, Inc.)
GoToMeeting 8.41.0.12127 (HKU\S-1-5-21-2695042837-3831575686-1124767896-1000\...\GoToMeeting) (Version: 8.41.0.12127 - LogMeIn, Inc.)
HD Tune 2.55 (HKLM\...\HD Tune_is1) (Version:  - EFD Software)
HP Officejet Pro 8500 A910 Basic Device Software (HKLM\...\{14BEBF02-A501-4A68-ABEB-286CCB28AE9F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
ImageMixer3 (HKLM\...\{AB19A235-66D4-47F7-9904-BAF84ED25BB6}) (Version: 3.00.005 - PIXELA)
Juniper Networks Host Checker (HKU\S-1-5-21-2695042837-3831575686-1124767896-1000\...\Neoteris_Host_Checker) (Version: 7.4.0.31481 - Juniper Networks)
Juniper Networks, Inc. Setup Client (HKU\S-1-5-21-2695042837-3831575686-1124767896-1000\...\Juniper_Setup_Client) (Version: 7.4.11.47145 - Juniper Networks, Inc.)
Juniper Networks, Inc. Setup Client Activex Control (HKLM\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks, Inc.)
Juniper Terminal Services Client (HKU\S-1-5-21-2695042837-3831575686-1124767896-1000\...\Juniper_Term_Services) (Version: 7.4.0.31481 - Juniper Networks)
LatencyMon 6.71 (HKLM\...\LatencyMon_is1) (Version:  - Resplendence Software Projects Sp.)
Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.10.15 - Lenovo)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.12624.20466 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2695042837-3831575686-1124767896-1000\...\OneDriveSetup.exe) (Version: 19.232.1124.0012 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (HKLM\...\{7e9fae12-5bbf-47fb-b944-09c49e75c061}) (Version: 14.15.26706.0 - Microsoft Corporation)
MyLiveChat (HKU\S-1-5-21-2695042837-3831575686-1124767896-1000\...\4435c09f5cdefce5) (Version: 1.0.2.51 - MyLiveChat)
NETGEAR WG111v3 wireless USB 2.0 adapter (HKLM\...\{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}) (Version: 1.01.10 - NETGEAR) Hidden
NETGEAR WG111v3 wireless USB 2.0 adapter (HKLM\...\InstallShield_{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}) (Version: 1.01.10 - NETGEAR)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.12624.20442 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-0000-0000000FF1CE}) (Version: 16.0.12624.20466 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.12624.20442 - Microsoft Corporation) Hidden
Peachtree Accounting 2012 (HKLM\...\{B4FDAA4D-37BD-4DF4-8531-B4F7ABC74E62}) (Version: 19.00.00 - Sage Software, Inc.) Hidden
Peachtree Accounting 2012 (HKLM\...\InstallShield_{B4FDAA4D-37BD-4DF4-8531-B4F7ABC74E62}) (Version: 19.00.00 - Sage Software, Inc.)
Peachtree Signature Ready Forms (HKLM\...\{BA1EF4A7-AB67-492B-9C7D-4AEE43F5A3C6}) (Version: 6.14.24 - Sage Software SB, Inc.) Hidden
Pervasive PSQL v10 SP2 Workgroup (32-bit) (HKLM\...\{0A3238D7-AB32-1010-B717-F3E3F18B4A8C}) (Version: 10.20.034 - Pervasive Software) Hidden
Pervasive PSQL v10 SP2 Workgroup (32-bit) (HKLM\...\Pervasive PSQL v10 SP2 Workgroup (32-bit)) (Version: 10.10.126 - Pervasive Software)
PHOTOfunSTUDIO -viewer- (HKLM\...\{9A9DBEBC-C800-4776-A970-D76D6AA405B1}) (Version: 1.00.000 - )
Sage Integration Services (HKLM\...\Integration Services) (Version: 2.2.2240 - Sage Technology)
swMSM (HKLM\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
System Requirements Lab for Intel (HKLM\...\{C7CA731B-BF9A-46D9-92CF-8A8737AE9240}) (Version: 4.5.13.0 - Husdawg, LLC)
ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.19.7 - )
Universal Document Converter Server Edition (HKLM\...\Universal Document Converter_is1) (Version: 5.5 - fCoder Group, Inc.)
Visual Studio Tools for the Office system 3.0 Runtime (HKLM\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version:  - Microsoft Corporation)
Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation)
Windows 10 Update and Privacy Settings (HKLM\...\{542CC2C2-ABAF-4604-8723-DA296AF74540}) (Version: 1.0.14.0 - Microsoft Corporation)
 
Packages:
=========
Acrobat Notification Client -> C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r [2019-01-08] (Adobe Systems Incorporated)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_110.1.728.0_x86__v10z8vjag6ke6 [2020-04-18] (HP Inc.)
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_4.27.32.0_x86__k1h2ywk1493x8 [2019-03-26] (LENOVO INC.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-17] (Microsoft Corporation) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.36.20714.0_x86__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x86__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x86__8wekyb3d8bbwe [2020-01-12] (Microsoft Corporation)
Reader Notification Client -> C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r [2019-01-08] (Adobe Systems Incorporated)
WindowsDVDPlayer -> C:\Program Files\WindowsApps\Microsoft.WindowsDVDPlayer_3.6.13291.0_x86__8wekyb3d8bbwe [2016-05-24] (Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-E4A4737B4AD9} -> [Creative Cloud Files] => C:\Users\Chrissy\Creative Cloud Files [2019-01-08 12:13]
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\Chrissy\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Chrissy\AppData\Local\GoToMeeting\12127\G2MOutlookAddin.dll (LogMeIn, Inc. -> LogMeIn, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\Chrissy\AppData\Local\Dropbox\Update\1.3.295.1\DropboxUpdateOnDemand.exe (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\Chrissy\AppData\Local\Dropbox\Update\1.3.295.1\DropboxUpdateOnDemand.exe (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{A659F7AF-C6B4-40FD-BF17-35CED2DA8C8B}\InprocServer32 -> C:\Users\Chrissy\AppData\Local\Dropbox\Update\1.3.295.1\psuser.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\Chrissy\AppData\Local\Dropbox\Update\1.3.295.1\DropboxUpdateOnDemand.exe (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\Chrissy\AppData\Local\Dropbox\Update\1.3.295.1\DropboxUpdateOnDemand.exe (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => C:\Users\Chrissy\Dropbox [2013-08-29 09:20]
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1B} -> [dropbox-NamespaceExtensionRole.Business] => 0
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{E7A37920-253C-4FF1-B169-298A7CE6CAA9}\localserver32 -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2695042837-3831575686-1124767896-1000_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\Chrissy\AppData\Local\Dropbox\Update\1.3.295.1\psuser.dll (Dropbox, Inc -> Dropbox, Inc.)
ShellExecuteHooks: No Name - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} -  -> No File
ShellIconOverlayIdentifiers: [   AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files\Common Files\Adobe\CoreSyncExtension\CoreSync_x86.dll [2018-03-05] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [   AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files\Common Files\Adobe\CoreSyncExtension\CoreSync_x86.dll [2018-03-05] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [   AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files\Common Files\Adobe\CoreSyncExtension\CoreSync_x86.dll [2018-03-05] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2009-02-03] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files\Common Files\Adobe\CoreSyncExtension\CoreSync_x86.dll [2018-03-05] (Adobe Systems Incorporated -> )
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim.dll [2019-12-02] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2009-02-03] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} =>  -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files\Common Files\Adobe\CoreSyncExtension\CoreSync_x86.dll [2018-03-05] (Adobe Systems Incorporated -> )
ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim.dll [2019-12-02] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1_S-1-5-21-2695042837-3831575686-1124767896-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers4_S-1-5-21-2695042837-3831575686-1124767896-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers5_S-1-5-21-2695042837-3831575686-1124767896-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
 
==================== Codecs (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Drivers32: [vidc.ffds] => C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll [85504 2009-08-31] () [File not signed]
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\"::
WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate]
Shortcut: C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.co
 
==================== Loaded Modules (Whitelisted) =============
 
2008-12-29 18:13 - 2008-12-29 18:13 - 000204800 _____ () [File not signed] C:\Program Files\NETGEAR\WG111v3\KJLog.dll
2009-03-04 10:52 - 2009-03-04 10:52 - 000372736 _____ () [File not signed] C:\Program Files\NETGEAR\WG111v3\WlanDll.dll
2020-02-22 16:22 - 2015-09-15 17:07 - 000318464 _____ (CANON INC) [File not signed] C:\Program Files\Canon\IJ Network Scanner Selector EX2\scchmpm.dll
2020-02-22 16:22 - 2015-09-01 19:11 - 000194560 _____ (CANON INC.) [File not signed] C:\Program Files\Canon\IJ Network Scanner Selector EX2\cnmpu2.dll
2020-02-22 16:22 - 2015-06-17 17:03 - 000008192 _____ (CANON INC.) [File not signed] C:\Program Files\Canon\IJ Network Scanner Selector EX2\CNS2_ENU.DLL
2020-02-22 16:22 - 2015-06-17 17:00 - 000104960 _____ (CANON INC.) [File not signed] C:\Program Files\Canon\IJ Network Scanner Selector EX2\CNS2_IMG.dll
2020-02-22 16:22 - 2015-05-26 10:44 - 000141312 _____ (CANON INC.) [File not signed] C:\Program Files\Canon\IJ Network Scanner Selector EX2\cnwidsd.dll
2009-02-03 03:09 - 2009-02-03 03:09 - 000069632 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2000-09-13 06:00 - 2000-09-13 06:00 - 000032768 _____ (MK Systems CO.,LTD.) [File not signed] C:\WINDOWS\System32\Eplplx02.dll
2002-06-21 06:04 - 2002-06-21 06:04 - 000079872 _____ (MK Systems CO.,LTD.) [File not signed] C:\WINDOWS\System32\Eplpmx02.DLL
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer trusted/restricted ==========
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:04 - 2009-06-10 17:39 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\Pervasive Software\PSQL\bin\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-2695042837-3831575686-1124767896-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
HKLM\...\StartupApproved\Run: => "SynTPEnh"
HKU\S-1-5-21-2695042837-3831575686-1124767896-1000\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2695042837-3831575686-1124767896-1000\...\StartupApproved\Run: => "SUPERAntiSpyware"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{1BAB5892-140F-448E-920D-980B907CDA14}] => (Allow) LPort=1583
FirewallRules: [{CEC8D2C1-73EC-4176-B212-86CB84605F07}] => (Allow) LPort=3351
FirewallRules: [{B40B6A1F-6E56-46D5-87A8-3164F2822D18}] => (Allow) C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe (Sage Software, Inc. -> Pervasive Software Inc.)
FirewallRules: [{D5403EC3-5302-42CD-9751-1AA5B7BD530A}] => (Allow) C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe (Sage Software, Inc. -> Pervasive Software Inc.)
FirewallRules: [{19A9C98F-E89D-4695-BA16-9E8CDF9F3B5D}] => (Allow) C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
FirewallRules: [{BDA28771-F93B-49A8-BB37-C6111EDEB4D0}] => (Allow) C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
FirewallRules: [{F03EAF5E-9ED5-464D-877F-2B7651EB52C9}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{FBBB15BA-FC5E-48C7-B479-FC66CE912062}C:\users\chrissy\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\chrissy\appdata\roaming\dropbox\bin\dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
FirewallRules: [UDP Query User{488A720B-0B63-484E-8041-DB4316130A24}C:\users\chrissy\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\chrissy\appdata\roaming\dropbox\bin\dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
FirewallRules: [{A6FFDB5E-895B-4F4F-AF06-1599D39FB79D}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8500 A910\bin\FaxApplications.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [{61D242F6-5AFA-41A5-800A-6563F7A1AD6C}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8500 A910\bin\DigitalWizards.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [{74C50345-F115-45F2-9410-D8B966F7E59F}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8500 A910\bin\SendAFax.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [{C70921FE-350A-4959-B15E-6323B6FAA85F}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\DeviceSetup.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [{BF853CAC-7579-42C7-92AF-7DA1CD7B0B6C}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\HPNetworkCommunicator.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [{30D8FD6B-0D55-4237-9756-AEF39C802444}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\HPNetworkCommunicatorCom.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [{2605F714-6057-4C3A-9116-EDF3CC34258D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.130.658.0_x86__zpdnekdrzrea0\Spotify.exe No File
FirewallRules: [{08960DC2-8B52-4B6C-BAF6-4A4CE7D7A7FB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.130.658.0_x86__zpdnekdrzrea0\Spotify.exe No File
FirewallRules: [{B765CE57-9899-47F6-8F85-BC92C15D0B45}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.130.658.0_x86__zpdnekdrzrea0\Spotify.exe No File
FirewallRules: [{26BE53EC-75F4-4595-B581-4001516A7490}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.130.658.0_x86__zpdnekdrzrea0\Spotify.exe No File
FirewallRules: [{14B96270-9E63-4098-9958-1D01850DA1F7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.130.658.0_x86__zpdnekdrzrea0\Spotify.exe No File
FirewallRules: [{343065C6-048C-4904-8F1E-D337AC1D425D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.130.658.0_x86__zpdnekdrzrea0\Spotify.exe No File
FirewallRules: [{56CF1D03-3E9F-4C93-ADD3-1D1ED9E538A8}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.130.658.0_x86__zpdnekdrzrea0\Spotify.exe No File
FirewallRules: [{61EDE857-5691-4A53-92F8-6DB9FDECE9CD}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.130.658.0_x86__zpdnekdrzrea0\Spotify.exe No File
FirewallRules: [{BCE39A34-8893-44D6-9A6B-A267B8203A67}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{005D690E-DBC9-4D7E-82F7-225FA6AEC166}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
 
==================== Restore Points =========================
 
15-04-2020 22:38:28 O&O ShutUp10
23-04-2020 20:30:11 GeeksB4Uninstall
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (04/26/2020 05:28:22 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: Chrissy-PC)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
 
Error: (04/26/2020 05:23:05 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: Chrissy-PC)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
 
Error: (04/26/2020 04:51:43 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: Chrissy-PC)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
 
Error: (04/26/2020 08:43:26 AM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: Chrissy-PC)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
 
Error: (04/25/2020 02:07:15 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: Chrissy-PC)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
 
Error: (04/24/2020 08:20:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Acrobat.exe, version: 20.6.20042.43423, time stamp: 0x5e616ad0
Faulting module name: ntdll.dll, version: 10.0.18362.778, time stamp: 0x7d3954ae
Exception code: 0xc0000374
Fault offset: 0x000efe8d
Faulting process id: 0x2d28
Faulting application start time: 0x01d61a970c9368c2
Faulting application path: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 239e68f9-3b43-4a97-8a10-f97b2cd5fbef
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (04/24/2020 01:55:55 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: Chrissy-PC)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
 
Error: (04/23/2020 09:19:42 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: Chrissy-PC)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
 
 
System errors:
=============
Error: (04/26/2020 05:31:21 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Update Orchestrator Service service hung on starting.
 
Error: (04/23/2020 09:17:14 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Update Orchestrator Service service terminated with the following error: 
%%2147942419 = The media is write protected.
 
Error: (04/23/2020 09:17:13 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {B91D5831-B1BD-4608-8198-D72E155020F7} did not register with DCOM within the required timeout.
 
Error: (04/23/2020 09:16:34 PM) (Source: DCOM) (EventID: 10010) (User: Chrissy-PC)
Description: The server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} did not register with DCOM within the required timeout.
 
Error: (04/23/2020 09:16:34 PM) (Source: DCOM) (EventID: 10010) (User: Chrissy-PC)
Description: The server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} did not register with DCOM within the required timeout.
 
Error: (04/23/2020 09:15:21 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Update Orchestrator Service service hung on starting.
 
Error: (04/23/2020 08:54:57 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073cff: 9NCBCSZSJRSB-SpotifyAB.SpotifyMusic.
 
Error: (04/21/2020 07:18:24 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
 
 
Windows Defender:
===================================
Date: 2020-04-15 22:21:50.976
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: Trojan:Win32/Wacatac.C!ml
ID: 2147749372
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Chrissy\Desktop\FRST.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: System
Process Name: Unknown
Security intelligence Version: AV: 1.313.1607.0, AS: 1.313.1607.0, NIS: 1.313.1607.0
Engine Version: AM: 1.1.16900.4, NIS: 1.1.16900.4
 
Date: 2020-04-15 20:54:46.880
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: Program:Win32/Wacapew.C!ml
ID: 265744
Severity: Medium
Category: Potentially Unwanted Software
Path: file:_C:\Users\Chrissy\Desktop\FRST.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.313.1456.0, AS: 1.313.1456.0, NIS: 1.313.1456.0
Engine Version: AM: 1.1.16900.4, NIS: 1.1.16900.4
 
Date: 2020-04-13 20:52:51.122
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: Program:Win32/Wacapew.C!ml
ID: 265744
Severity: Medium
Category: Potentially Unwanted Software
Path: file:_C:\Users\Chrissy\Desktop\FRST.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.313.1456.0, AS: 1.313.1456.0, NIS: 1.313.1456.0
Engine Version: AM: 1.1.16900.4, NIS: 1.1.16900.4
 
Date: 2020-04-13 20:10:01.260
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: Program:Win32/Wacapew.C!ml
ID: 265744
Severity: Medium
Category: Potentially Unwanted Software
Path: file:_C:\Users\Chrissy\Desktop\FRST.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: System
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.313.1456.0, AS: 1.313.1456.0, NIS: 1.313.1456.0
Engine Version: AM: 1.1.16900.4, NIS: 1.1.16900.4
 
Date: 2020-04-13 20:09:35.495
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: Program:Win32/Wacapew.C!ml
ID: 265744
Severity: Medium
Category: Potentially Unwanted Software
Path: file:_C:\Users\Chrissy\Desktop\FRST.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: System
Process Name: Unknown
Security intelligence Version: AV: 1.313.1456.0, AS: 1.313.1456.0, NIS: 1.313.1456.0
Engine Version: AM: 1.1.16900.4, NIS: 1.1.16900.4
 
Date: 2020-04-23 20:50:34.031
Description: 
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.313.2035.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.16900.4
Error code: 0x80070102
Error description: The wait operation timed out. 
 
Date: 2020-04-19 09:16:22.137
Description: 
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.313.1607.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.16900.4
Error code: 0x80072ee7
Error description: The server name or address could not be resolved 
 
Date: 2020-04-19 09:16:22.136
Description: 
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.313.1607.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiSpyware
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.16900.4
Error code: 0x80072ee7
Error description: The server name or address could not be resolved 
 
Date: 2020-04-19 09:16:22.135
Description: 
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.313.1607.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.16900.4
Error code: 0x80072ee7
Error description: The server name or address could not be resolved 
 
Date: 2020-04-19 09:16:21.995
Description: 
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.313.1607.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.16900.4
Error code: 0x80072ee7
Error description: The server name or address could not be resolved 
 
CodeIntegrity:
===================================
 
Date: 2020-04-26 17:28:23.420
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.
 
Date: 2020-04-26 17:21:45.658
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.
 
Date: 2020-04-23 21:19:42.923
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.
 
Date: 2020-04-23 21:12:34.193
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.
 
Date: 2020-04-20 09:17:04.372
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.
 
Date: 2020-04-20 08:53:09.898
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.
 
Date: 2020-04-19 10:30:15.326
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.stdformat.dll that did not meet the Microsoft signing level requirements.
 
Date: 2020-04-19 10:30:15.228
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll that did not meet the Microsoft signing level requirements.
 
==================== Memory info =========================== 
 
BIOS: LENOVO 7UET79WW (3.09 ) 10/13/2009
Motherboard: LENOVO 7439W6R
Processor: Intel® Core™2 Duo CPU P8600 @ 2.40GHz
Percentage of memory in use: 96%
Total physical RAM: 1944.02 MB
Available physical RAM: 58.95 MB
Total Virtual: 4504.02 MB
Available Virtual: 2433.7 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:148.35 GB) (Free:61.2 GB) NTFS
 
\\?\Volume{73b17344-af71-11e1-a62f-806e6f6e6963}\ (System) (Fixed) (Total:0.2 GB) (Free:0.15 GB) NTFS
\\?\Volume{8d91f07f-0000-0000-0000-402325000000}\ () (Fixed) (Total:0.5 GB) (Free:0.15 GB) NTFS
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 149.1 GB) (Disk ID: 8D91F07F)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=148.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=510 MB) - (Type=27)
 
==================== End of Addition.txt =======================

 

 
4.  HD Tune: FUJITSU MHZ2160BJ G1 Benchmark
 
Transfer Rate Minimum : 25.3 MB/sec
Transfer Rate Maximum : 67.7 MB/sec
Transfer Rate Average : 54.2 MB/sec
Access Time           : 17.1 ms
Burst Rate            : 64.0 MB/sec
CPU Usage             : 3.7%
 

  • 0

Advertisements


#26
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,731 posts
  • MVP

Process Explorer says Dropbox is eating most of the CPU.  I'm not a dropbox user so have no idea what is going on but I found this article which might help:

 

https://help.dropbox.../high-cpu-usage

You are showing this error:

 

Error: (04/26/2020 05:31:21 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Update Orchestrator Service service hung on starting.

 

 
Search for:
services.msc
hit Enter
find Update Orchestrator and see if it has started.  If not try to Start it.  What error do you get?  Right click on it and verify that it has Startup Type: Automatic (Delayed Start)
This is part of Windows Update so you might need to run the Windows Update Troubleshooter again as we did earlier.
 
I see an error from Adobe Acrobat.  I assume you need it so I would uninstall it and download a new copy from adobe.com (Remember to wait and uncheck the optional software they always try to sucker you into downloading before you press the download button)
 
Remember going in to Event Viewer and then into Applications & Services logs?  If you have some time it would not hurt to go through each individual log and DISABLE logging for any which have logging enabled.  You can also Clear Log, Clear when you find one that is enabled.  That will free up a small amount of disk space and keep the logging from wasting CPU time.
 
HDTune also has an Error Scan tab.  Click on it and press Start and see if the drive has any bad spots.
 
Just so you can see the difference between hard drives.  The first one is from my C: drive which is a Samsung EVO 1 TB SSD.  The second is from my second drive which is a high quality 3 GB Western Digital Black drive of the older type.  Both are operating at SATA 3 speed which is 4 times better than the SATA 1 that your PC runs at but you can see the SSD is twice as fast as the mechanical. 
 
 
 
 
hdtune.jpg
 
Annotation 2020-04-26 224612.jpg
 
I would urge you to look into getting either a good quality SSD or at least a new drive.  Perhaps you can find a good used drive where the owner replaced it with an SSD. 
 

 

 


  • 0

#27
dbrupp

dbrupp

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts

Hello,

Thank you for investigating the logs and errors.

 

The laptop is running so much better and I'm so grateful to you.  I will be removing Dropbox from this laptop as my wife was a little scared that something is going to crash and she will be without her laptop.  As soon as she gets the new one up and running I will remove dropbox.  The only thing she will need this laptop for is for her Peachtree accounting software.  It's an older version that was loaded via a disc.   The newer version is a cloud version that requires a monthly subscription; so, hopefully I'll find a way to move her licensed software from her current laptop to the new one....Anyhow, that's not your problem and I apologize for the rambling on....

 

Per your request, I checked and found Update Orchestrator was started with Startup Type: Automatic (Delayed Start).    There were no error messages.

 

I was able to remove  Adobe Acrobat DC from this laptop and will install it on a different one.

 

I looked back in the thread, because I couldn't remember how to disable logging in Event Viewer, but I was able to search for "Event Viewer" and find Applications & Services logs & was able to Clear Log for those enabled items.

 

HD Tune looked good...no errors. Attached is a screenshot.

 

Thanks for the information about the new drive or SSD.

 

Stay safe and have a fantastic rest of your week.

 

Attached Thumbnails

  • Error_Scan.jpg

  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP