Logfile of random's system information tool 1.10 (written by random/random) Run by thoma at 2016-10-18 08:54:09 Microsoft Windows 10 Pro System drive C: has 324 GB (73%) free of 441 GB Total RAM: 16276 MB (65% free) ======Listing Processes====== C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch C:\WINDOWS\system32\svchost.exe -k RPCSS winlogon.exe "dwm.exe" C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted C:\WINDOWS\System32\svchost.exe -k NetworkService C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\system32\svchost.exe -k LocalService "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0bde0038-aece-424a-8dc7-b3ba09984ba4 -SystemEventPortName:HostProcess-2882dba8-dd0d-4d07-a9f8-a67bad26bd13 -IoCancelEventPortName:HostProcess-5bfa2cde-9e07-4ecb-8c76-520c3f326386 -NonStateChangingEventPortName:HostProcess-8fb894c0-5708-48fe-aa1f-50d279c76b7e -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:2e3f5b11-e0d7-4c49-bbf8-353f50707647 -DeviceGroupId:WudfDefaultDevicePool C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork "C:\Program Files\Bitdefender\Bitdefender 2016\vsserv.exe" /service C:\WINDOWS\system32\svchost.exe -k netsvcs dashost.exe {9e6196a8-7361-45b9-830061409da239d3} C:\WINDOWS\system32\igfxCUIService.exe C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted C:\WINDOWS\system32\WLANExt.exe 2787712113312 \??\C:\WINDOWS\system32\conhost.exe 0x4 C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe" C:\WINDOWS\System32\spoolsv.exe C:\WINDOWS\System32\svchost.exe -k utcsvc "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" "C:\Program Files\Elantech\ETDService.exe" "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service C:\WINDOWS\system32\DbxSvc.exe "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" "C:\Program Files\Bitdefender Agent\ProductAgentService.exe" "C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe" C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\svchost.exe -k appmodel "C:\Program Files\Bitdefender\Bitdefender 2016\updatesrv.exe" /service "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" C:\WINDOWS\system32\CxAudMsg64.exe C:\WINDOWS\SysWoW64\SAsrv.exe C:\WINDOWS\system32\BtwRSupportService.exe "C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe" C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted "C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn\sqlceip.exe" -Service SQLEXPRESS "C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS "C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS01\MSSQL\Binn\sqlceip.exe" -Service SQLEXPRESS01 C:\WINDOWS\System32\vds.exe "C:\Program Files\Elantech\ETDCtrl.exe" sihost.exe "C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe" C:\WINDOWS\Explorer.EXE "C:\Program Files\Elantech\ETDCtrlHelper.exe" "C:\Program Files\Elantech\ETDIntelligent.exe" C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E} "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c C:\Windows\System32\RuntimeBroker.exe -Embedding igfxEM.exe igfxHK.exe C:\WINDOWS\system32\SearchIndexer.exe /Embedding "C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca C:\WINDOWS\system32\SettingSyncHost.exe -Embedding "C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe" "C:\Windows\RTFTrack.exe" "C:\Users\thoma\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow "C:\Program Files (x86)\MySQL\MySQL Notifier 1.1\MySQLNotifier.exe" "C:\Program Files (x86)\Citrix\ICA Client\SelfServicePlugin\SelfServicePlugin.exe" "C:\Program Files\FreeFileSync\RealTimeSync.exe" "C:\Program Files\FreeFileSync\Bin\RealTimeSync_x64.exe" "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized "fontdrvhost.exe" "C:\Program Files (x86)\Citrix\ICA Client\Receiver\Receiver.exe" -autoupdate -startplugins -disableshowcontrolpanel "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" "C:\WINDOWS\SysWOW64\RunDll32.exe" "C:\Program Files\Lenovo\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook C:\WINDOWS\system32\wbem\wmiprvse.exe "C:\Program Files\Bitdefender\Bitdefender 2016\bdagent.exe" "C:\Program Files (x86)\Lenovo\GDCAgentSetupRed\GDCAgent.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe" "C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxag.exe " "C:\Program Files\Bitdefender\Bitdefender 2016\Antispam32\bdwtxapps.exe" "C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe" --defaults-file="C:\ProgramData\MySQL\MySQL Server 5.7\my.ini" MySQL57 "C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe" "C:\Program Files (x86)\Citrix\AuthManager\AuthManSvr.exe" -Embedding C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding C:\WINDOWS\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85} C:\WINDOWS\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} C:\Windows\System32\SystemSettingsBroker.exe -Embedding C:\Windows\System32\DataExchangeHost.exe -Embedding taskhostw.exe "C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe" -Embedding "C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe" "C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js \??\C:\WINDOWS\system32\conhost.exe 0x4 "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -a -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -l 3 -c "C:\WINDOWS\system32\nvvsvc.exe" C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe -first "C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca "C:\Program Files (x86)\Snipaste\Snipaste.exe" "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc C:\Windows\System32\smartscreen.exe -Embedding C:\WINDOWS\system32\AUDIODG.EXE 0x41c C:\WINDOWS\servicing\TrustedInstaller.exe C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.82_none_5be7b69702339d1d\TiWorker.exe -Embedding C:\WINDOWS\System32\svchost.exe -k swprv "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXe9cvj1thv1hmcw0cs98xm3r97tyzy2xs.mca "C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE" "C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-2326612360-2477090070-2315343964-1001165_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-2326612360-2477090070-2315343964-1001165 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1" "C:\WINDOWS\system32\SearchFilterHost.exe" 0 644 648 656 8192 652 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "http://track.pc-helpforum.be/wf/click?upn=dTZOOcibKXP-2BXYr5iDSB7F3q6K2otMpIxWmS0waM1E6yduuiw1vmd-2B6l4DIRUCJWDHE92vRItnDchLGJqzmDKA-3D-3D_-2BPe06-2FbvfIwPZYvDYsJeB4sKDhXHWUjZaPG9BkxbYaccAH13tOC4OcYz4G2uG7zVXFHeDcSNHrat55oxMO6O8aOjCFIghB-2BkWdUkNOu2iFVTpHO3msTpUTr3ZPvFjkEoCJX1y6PdXZMyN0CdWJJM-2FDpZ1nYLR6q8nzGz4KZYCoDG8t-2BA1owhF-2FOyL3xywGyUmbOIksarjHAbynTfYZqFGCHF064w4ukPhXVW-2Fxh6VXE-3D" "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\thoma\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=54.0.2840.59 --handshake-handle=0x18c "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --enable-features="AutomaticTabDiscarding \\.\pipe\chrome.nativeMessaging.out.f01fd3072612f85c \??\C:\WINDOWS\system32\conhost.exe 0x4 "C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxcr.exe" --parent-window=0 chrome-extension://dhhejlifdlcgcmogbggeomfodgklfaem/ "C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe166_ Global\UsGthrCtrlFltPipeMssGthrPipe166 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features="AutomaticTabDiscarding