This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Probably virus. Help needed.

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Nothing horrible yet, but tried to download something and now Windows Defender isn't working right. 

 

Help! 

 

 

[external image: xlK5Hdb.png]Farbar Recovery Scan Tool (FRST) Scan
  • Please download Farbar Recovery Scan Tool (x32) or Farbar Recovery Scan Tool (x64) and save the file to your Desktop.
  • Note: Download and run the version compatible with your system (32 or 64-bit). Download both if you're unsure; only one will run.
  • Right-Click FRST.exe / FRST64.exe and select [external image: AVOiBNU.jpg]Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06.01.2019
Ran by [removed] (administrator) on LISAS-DESKTOP (06-01-2019 13:02:36)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 10 Home Version 1803 17134.472 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\DriverStore\FileRepository̵076.inf_amd64_f8c797ab08b9d461\B334840\atiesrxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ICEpower) C:\Windows\System32\ICEsoundService64.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(Microsoft Corporation) C:\Program Files\rempl\sedsvc.exe
(TOSHIBA CORPORATION) C:\Windows\System32\lsihrkzsvc.exe
(AMD) C:\Windows\System32\DriverStore\FileRepository̵076.inf_amd64_f8c797ab08b9d461\B334840\atieclxx.exe
() C:\Program Files (x86)\Characterised\subsisting.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amddvr.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
() C:\Program Files (x86)\PhotoScape\PhotoScape.exe
(Microsoft Corporation) C:\Users\Lisa Viger\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\FileCoAuth.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(BitTorrent Inc.) C:\Users\Lisa Viger\AppData\Roaming\BitTorrent\BitTorrent.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(BitTorrent Inc.) C:\Users\Lisa Viger\AppData\Roaming\BitTorrent\updates\7.10.4_44847\bittorrentie.exe
(BitTorrent Inc.) C:\Users\Lisa Viger\AppData\Roaming\BitTorrent\updates\7.10.4_44847\bittorrentie.exe
() C:\Program Files (x86)\minstrelsy\cringing.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
() C:\Program Files (x86)\Characterised\subsisting.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
() C:\Program Files (x86)\twisty\Winds.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
() C:\Users\Lisa Viger\AppData\Local\tiskhnu\tiskhnu.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
() C:\Program Files (x86)\Moslem\Rathman.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chromeDeregulation.exe
() C:\Users\Lisa Viger\AppData\Local\tiskhnu\sccwtzr.exe
() C:\Users\Lisa Viger\AppData\Local\tiskhnu\sccwtzr.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.464_none_eaf315ac1d6e512f\TiWorker.exe
() C:\Users\Lisa Viger\AppData\Local\tiskhnu\sccwtzr.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
() C:\Users\Lisa Viger\AppData\Local\tiskhnu\sccwtzr.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Corporation)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9279432 2018-09-21] (Realtek Semiconductor)
HKLM\…\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [5822056 2018-11-12] (Paramount Software UK Ltd)
HKLM\…\Run: [Westboro] => C:\Program Files (x86)\Moslem\Rathman.exe [12800 2019-01-05] ()
HKLM\…\Run: [Blot] => C:\Program Files (x86)\twisty\Winds.exe [12800 2019-01-05] ()
HKLM\…\Run: [Powers] => C:\Program Files (x86)\Remunerated\Rathman.exe [12800 2019-01-05] ()
HKLM-x32\…\Run: [Demain] => C:\Program Files (x86)\Moslem\Rathman.exe [12800 2019-01-05] ()
HKLM-x32\…\Run: [Tuthill] => C:\Program Files (x86)\twisty\Winds.exe [12800 2019-01-05] ()
HKLM-x32\…\Run: [Thrombolysis] => C:\Program Files (x86)\Remunerated\Rathman.exe [12800 2019-01-05] ()
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\Run: [BitTorrent] => C:\Users\Lisa Viger\AppData\Roaming\BitTorrent\BitTorrent.exe [1746368 2018-12-09] (BitTorrent Inc.)
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\Run: [sfciwu] => rundll32.exe "C:\Users\Lisa Viger\AppData\Local\sfciwu.dll",sfciwu <==== ATTENTION
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\Run: [Kiker] => C:\Program Files (x86)\Moslem\Rathman.exe [12800 2019-01-05] ()
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\Run: [Per] => C:\Program Files (x86)\twisty\Winds.exe [12800 2019-01-05] ()
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\Run: [Gasca] => C:\Program Files (x86)\Remunerated\Rathman.exe [12800 2019-01-05] ()
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\Run: [Kolker] => C:\Program Files (x86)\Moslem\Rathman.exe [12800 2019-01-05] ()
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\Run: [Craven] => C:\Program Files (x86)\twisty\Winds.exe [12800 2019-01-05] ()
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\Run: [Independence] => C:\Program Files (x86)\Remunerated\Rathman.exe [12800 2019-01-05] ()
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\Run: [cringing] => C:\Program Files (x86)\minstrelsy\cringing.exe [49502 2019-01-05] ()
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\Run: [emphasise] => C:\Program Files (x86)\Moslem\Rathman.exe [12800 2019-01-05] ()
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\Run: [WinResSync] => C:\Windows\system32\regsvr32.exe /s "C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs" <==== ATTENTION
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\Run: [Blogger] => C:\ProgramData\Blogger\Blogger.exe [1098752 2019-01-05] ()
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\Run: [GoogleChromeAutoLaunch_28B6DDC3CEFF48A5F4263F10EABF3C1D] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" –no-startup-window /prefetch:5
HKU\S-1-5-18\…\Run: [WinResSync] => C:\Windows\system32\regsvr32.exe /s "C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs" <==== ATTENTION
HKU\S-1-5-18\…\RunOnce: [WinResSync] => C:\Windows\system32\regsvr32.exe /s "C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs" <==== ATTENTION
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\Installer\chrmstp.exe [2018-12-12] (Google Inc.)
Startup: C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\napped.lnk [2019-01-05]
ShortcutTarget: napped.lnk -> C:\Program Files (x86)\Moslem\Rathman.exe ()
Startup: C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\nappednapped.lnk [2019-01-05]
ShortcutTarget: nappednapped.lnk -> C:\Program Files (x86)\twisty\Winds.exe ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.254.254
Tcpip\..\Interfaces\{48fdd0f5-e0a9-4e62-8c6a-9505a564d59f}: [DhcpNameServer] 192.168.254.254 [removed]
Tcpip\..\Interfaces\{a04f85f7-7778-4593-8d05-0b84626fa75a}: [DhcpNameServer] 192.168.254.254
 
Internet Explorer:
==================
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://oem17win10.msn.com/?pc=NMTE
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://oem17win10.msn.com/?pc=NMTE
 
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default [2019-01-06]
CHR Extension: (Slides) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-11-15]
CHR Extension: (Docs) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-11-15]
CHR Extension: (Google Drive) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-11-15]
CHR Extension: (YouTube) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-11-15]
CHR Extension: (Sheets) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-11-15]
CHR Extension: (VideoCast (VLC/Chromecast)) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\gclhodkofgoighinmongpkpncdpalejb [2018-12-06]
CHR Extension: (Google Docs Offline) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-11-15]
CHR Extension: (Tailwind Publisher) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkbhgdhhefdphpikedbinecandoigdel [2018-12-06]
CHR Extension: (Pinterest Save Button) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2018-12-10]
CHR Extension: (Viraltag) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgalnfddmdhldmolecmlopbabjbngoka [2018-12-29]
CHR Extension: (Grammarly for Chrome) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2018-12-06]
CHR Extension: (Tag Assistant (by Google)) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\kejbdjndbnbjgmefkgdddjlbokphdefk [2018-12-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-11-15]
CHR Extension: (Gmail) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-11-15]
CHR Extension: (Chrome Media Router) - C:\Users\Lisa Viger\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-07]
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
HKLM\SYSTEM\CurrentControlSet\Services\hacvbgn <==== ATTENTION (Rootkit!)
 
R2 AMD External Events Utility; C:\Windows\System32\DriverStore\FileRepository̵076.inf_amd64_f8c797ab08b9d461\B334840\atiesrxx.exe [508000 2018-10-25] (AMD)
S2 AUEPLauncher; C:\Program Files\AMD\Performance Profile Client\AUEPLauncher.exe [43008 2018-10-20] (AMD) [File not signed]
R2 ibtsiva; C:\Windows\system32\ibtsiva.exe [541896 2018-07-06] (Intel Corporation)
R2 ICEsoundService; C:\Windows\system32\ICEsoundService64.exe [799656 2018-09-21] (ICEpower)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [5665664 2018-11-12] (Paramount Software UK Ltd)
S4 ssh-agent; C:\Windows\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\NisSrv.exe [3880120 2018-12-10] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MsMpEng.exe [114208 2018-12-10] (Microsoft Corporation)
S3 Futuremark SystemInfo Service; "C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe" [X]
S4 windowsmanagementservice; windowsmanagementservice [X] <==== ATTENTION
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 amdgpio2; C:\Windows\System32\drivers\amdgpio2.sys [34696 2017-10-09] (Advanced Micro Devices, Inc)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [67576 2018-10-25] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\Windows\System32\DriverStore\FileRepository̵076.inf_amd64_f8c797ab08b9d461\B334840\atikmdag.sys [47503976 2018-10-25] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\System32\DriverStore\FileRepository̵076.inf_amd64_f8c797ab08b9d461\B334840\atikmpag.sys [589920 2018-10-25] (Advanced Micro Devices, Inc.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [102384 2018-10-25] (Advanced Micro Devices, Inc.)
R3 AMDPCIDev; C:\Windows\System32\drivers\AMDPCIDev.sys [31592 2018-04-25] (Advanced Micro Devices)
R0 amdpsp; C:\Windows\System32\drivers\amdpsp.sys [137104 2017-11-07] (Advanced Micro Devices, Inc. )
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [141848 2018-07-06] (Intel Corporation)
S3 Netwtw04; C:\Windows\System32\drivers\Netwtw04.sys [7689728 2018-04-11] (Intel Corporation)
R3 Netwtw06; C:\Windows\system32\DRIVERS\Netwtw06.sys [8822768 2018-08-07] (Intel Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [604160 2018-04-11] (Realtek )
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [46680 2018-12-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [330936 2018-12-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [62136 2018-12-10] (Microsoft Corporation)
S0 dtvbrz; System32\drivers\wmslapvh.sys [X]
U3 eehhhk; system32\drivers\xxaaae.sys [X]
R1 zbckxrmo; \??\C:\Users\LISAVI~1\AppData\Local\Temp\nvkoazlb.sys [X] <==== ATTENTION
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-01-06 13:02 - 2019-01-06 13:02 - 000020484 _____ C:\Users\Lisa Viger\Downloads\FRST.txt
2019-01-06 13:01 - 2019-01-06 13:02 - 000000000 ____D C:\FRST
2019-01-06 13:01 - 2019-01-06 13:01 - 000000000 ____D C:\Users\Lisa Viger\Downloads\FRST-OlderVersion
2019-01-06 11:39 - 2019-01-06 13:01 - 002425856 _____ (Farbar) C:\Users\Lisa Viger\Downloads\FRST64.exe
2019-01-06 11:01 - 2019-01-06 11:01 - 000000000 ____D C:\Users\Lisa Viger\AppData\LocalLow\BitTorrent
2019-01-05 21:27 - 2019-01-05 21:27 - 000000000 ____D C:\Users\Lisa Viger\AppData\Local\Meltytech
2019-01-05 21:16 - 2019-01-05 21:16 - 000001711 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shotcut.lnk
2019-01-05 21:16 - 2019-01-05 21:16 - 000000000 ____D C:\Program Files\Shotcut
2019-01-05 21:13 - 2019-01-05 21:15 - 202220376 _____ C:\Users\Lisa Viger\Downloads\shotcut-win64-181223.exe
2019-01-05 20:55 - 2019-01-06 13:00 - 000000000 ____D C:\Users\Lisa Viger\AppData\Local\wdsimog
2019-01-05 20:55 - 2019-01-05 20:55 - 000000000 ____D C:\Users\Lisa Viger\AppData\Local\CEF
2019-01-05 20:55 - 2019-01-05 20:55 - 000000000 ____D C:\ProgramData\Blogger
2019-01-05 20:55 - 2019-01-05 20:55 - 000000000 ____D C:\ProgramData\Bler
2019-01-05 20:51 - 2019-01-06 13:02 - 000000000 ____D C:\Users\Lisa Viger\AppData\Local\tiskhnu
2019-01-05 20:51 - 2019-01-05 20:51 - 000000000 ____D C:\Users\Lisa Viger\AppData\Local\niesztw
2019-01-05 20:50 - 2019-01-06 13:00 - 000000001 _____ C:\575datdo4a5sbry
2019-01-05 20:50 - 2019-01-05 20:54 - 000000000 ____D C:\Windows\system32\dwaivbo
2019-01-05 20:50 - 2019-01-05 20:50 - 002930176 _____ (TOSHIBA CORPORATION) C:\Windows\system32\lsihrkzsvc.exe
2019-01-05 20:50 - 2019-01-05 20:50 - 000000000 ____D C:\Windows\SysWOW64\dwaivbo
2019-01-05 20:50 - 2019-01-05 20:50 - 000000000 ____D C:\Users\Lisa Viger\AppData\Roaming\Macromedia
2019-01-05 20:49 - 2019-01-05 21:01 - 000000000 ____D C:\Program Files (x86)\s5
2019-01-05 20:49 - 2019-01-05 20:51 - 000000000 ____D C:\ProgramData\Uded
2019-01-05 20:49 - 2019-01-05 20:49 - 000016384 _____ C:\Users\Lisa Viger\AppData\Local\sfciwu.dll
2019-01-05 20:49 - 2019-01-05 20:49 - 000004126 _____ C:\Windows\System32\Tasks\chording unwisely harewood
2019-01-05 20:49 - 2019-01-05 20:49 - 000004110 _____ C:\Windows\System32\Tasks\ecliptic journaling
2019-01-05 20:49 - 2019-01-05 20:49 - 000004100 _____ C:\Windows\System32\Tasks\nashville_asian
2019-01-05 20:49 - 2019-01-05 20:49 - 000004096 _____ C:\Windows\System32\Tasks\talky-counterpart
2019-01-05 20:49 - 2019-01-05 20:49 - 000004092 _____ C:\Windows\System32\Tasks\turret
2019-01-05 20:49 - 2019-01-05 20:49 - 000004090 _____ C:\Windows\System32\Tasks\kyi_crh
2019-01-05 20:49 - 2019-01-05 20:49 - 000004090 _____ C:\Windows\System32\Tasks\amp
2019-01-05 20:49 - 2019-01-05 20:49 - 000004076 _____ C:\Windows\System32\Tasks\tawil
2019-01-05 20:49 - 2019-01-05 20:49 - 000004034 _____ C:\Windows\System32\Tasks\chording unwisely harewoodchording unwisely harewood
2019-01-05 20:49 - 2019-01-05 20:49 - 000004004 _____ C:\Windows\System32\Tasks\ecliptic journalingecliptic journaling
2019-01-05 20:49 - 2019-01-05 20:49 - 000003986 _____ C:\Windows\System32\Tasks\talky-counterparttalky-counterpart
2019-01-05 20:49 - 2019-01-05 20:49 - 000003986 _____ C:\Windows\System32\Tasks\nashville_asiannashville_asian
2019-01-05 20:49 - 2019-01-05 20:49 - 000003960 _____ C:\Windows\System32\Tasks\turretturret
2019-01-05 20:49 - 2019-01-05 20:49 - 000003960 _____ C:\Windows\System32\Tasks\kyi_crhkyi_crh
2019-01-05 20:49 - 2019-01-05 20:49 - 000003954 _____ C:\Windows\System32\Tasks\ampamp
2019-01-05 20:49 - 2019-01-05 20:49 - 000003942 _____ C:\Windows\System32\Tasks\tawiltawil
2019-01-05 20:49 - 2019-01-05 20:49 - 000000939 _____ C:\Users\Lisa Viger\Desktop\s5.lnk
2019-01-05 20:49 - 2019-01-05 20:49 - 000000012 _____ C:\Windows\b89085897
2019-01-05 20:49 - 2019-01-05 20:49 - 000000000 ___HD C:\Program Files (x86)\Remunerated
2019-01-05 20:49 - 2019-01-05 20:49 - 000000000 ___HD C:\Program Files (x86)\minstrelsy
2019-01-05 20:49 - 2019-01-05 20:49 - 000000000 ____D C:\Users\Lisa Viger\AppData\Roaming\et
2019-01-05 20:49 - 2019-01-05 20:49 - 000000000 ____D C:\ProgramData\Foge
2019-01-05 20:49 - 2019-01-05 20:49 - 000000000 ____D C:\ProgramData\1546739382
2019-01-05 20:49 - 2019-01-05 20:49 - 000000000 ____D C:\Program Files (x86)\twisty
2019-01-05 20:49 - 2019-01-05 20:49 - 000000000 ____D C:\Program Files (x86)\petitioner
2019-01-05 20:49 - 2019-01-05 20:49 - 000000000 ____D C:\Program Files (x86)\Moslem
2019-01-05 20:49 - 2019-01-05 20:49 - 000000000 ____D C:\Program Files (x86)\Characterised
2019-01-05 14:51 - 2019-01-05 14:51 - 000012800 _____ C:\Windows\guttural.exe
2019-01-05 14:51 - 2019-01-05 14:51 - 000012800 _____ C:\Users\Lisa Viger\AppData\Local\Winds.exe
2019-01-05 14:51 - 2019-01-05 14:51 - 000012800 _____ C:\Users\Lisa Viger\AppData\Local\Rathman.exe
2019-01-04 11:23 - 2019-01-04 11:23 - 000405921 _____ C:\Users\Lisa Viger\Downloads\floral_flower.zip
2019-01-04 11:23 - 2019-01-04 11:23 - 000140675 _____ C:\Users\Lisa Viger\Downloads\floral_capitals.zip
2019-01-04 11:23 - 2019-01-04 11:23 - 000104997 _____ C:\Users\Lisa Viger\Downloads\florality.zip
2019-01-04 11:23 - 2019-01-04 11:23 - 000064181 _____ C:\Users\Lisa Viger\Downloads\lsleaves.zip
2019-01-04 11:23 - 2019-01-04 11:23 - 000021507 _____ C:\Users\Lisa Viger\Downloads\wmleaves1.zip
2019-01-04 11:22 - 2019-01-04 11:22 - 000393148 _____ C:\Users\Lisa Viger\Downloads\floral.zip
2019-01-04 11:22 - 2019-01-04 11:22 - 000125978 _____ C:\Users\Lisa Viger\Downloads\cf_plants_and_flowers.zip
2019-01-04 11:22 - 2019-01-04 11:22 - 000037302 _____ C:\Users\Lisa Viger\Downloads\plants.zip
2019-01-04 11:22 - 2019-01-04 11:22 - 000031646 _____ C:\Users\Lisa Viger\Downloads\planttype.zip
2019-01-04 11:22 - 2019-01-04 11:22 - 000023253 _____ C:\Users\Lisa Viger\Downloads\florals_2.zip
2019-01-04 10:31 - 2019-01-04 10:31 - 000000000 ____D C:\Users\Lisa Viger\Documents\Add-in Express
2019-01-04 10:30 - 2019-01-04 10:30 - 000289321 _____ C:\Users\Lisa Viger\Downloads\kg_tangled_up_in_you.zip
2019-01-04 10:30 - 2019-01-04 10:30 - 000163778 _____ C:\Users\Lisa Viger\Downloads\kg_no_regrets.zip
2019-01-04 10:30 - 2019-01-04 10:30 - 000027878 _____ C:\Users\Lisa Viger\Downloads\kg_only_human.zip
2019-01-04 10:29 - 2019-01-04 10:29 - 000425506 _____ C:\Users\Lisa Viger\Downloads\kg_all_of_me.zip
2019-01-04 10:29 - 2019-01-04 10:29 - 000054864 _____ C:\Users\Lisa Viger\Downloads\kg_only_hope.zip
2019-01-04 10:29 - 2019-01-04 10:29 - 000054125 _____ C:\Users\Lisa Viger\Downloads\janda_flower_doodles.zip
2019-01-04 10:29 - 2019-01-04 10:29 - 000039727 _____ C:\Users\Lisa Viger\Downloads\kg_neatly_printed.zip
2019-01-04 10:29 - 2019-01-04 10:29 - 000025796 _____ C:\Users\Lisa Viger\Downloads\stars_from_our_eyes.zip
2019-01-04 10:29 - 2019-01-04 10:29 - 000025791 _____ C:\Users\Lisa Viger\Downloads\the_only_exception.zip
2019-01-04 10:29 - 2019-01-04 10:29 - 000023080 _____ C:\Users\Lisa Viger\Downloads\kg_one_more_night.zip
2019-01-04 10:28 - 2019-01-04 10:28 - 000276515 _____ C:\Users\Lisa Viger\Downloads\kg_flavor_and_frames_three.zip
2019-01-04 10:28 - 2019-01-04 10:28 - 000090050 _____ C:\Users\Lisa Viger\Downloads\kg_hard_candy.zip
2019-01-04 10:28 - 2019-01-04 10:28 - 000035780 _____ C:\Users\Lisa Viger\Downloads\kg_all_things_new.zip
2019-01-04 10:27 - 2019-01-04 10:28 - 000027118 _____ C:\Users\Lisa Viger\Downloads\kg_always_a_good_time.zip
2019-01-04 10:27 - 2019-01-04 10:27 - 000118098 _____ C:\Users\Lisa Viger\Downloads\sign_of_love.zip
2019-01-04 10:27 - 2019-01-04 10:27 - 000016254 _____ C:\Users\Lisa Viger\Downloads\lovelique.zip
2019-01-04 10:25 - 2019-01-04 10:25 - 000096993 _____ C:\Users\Lisa Viger\Downloads\funplay.zip
2019-01-04 10:24 - 2019-01-04 10:24 - 000016387 _____ C:\Users\Lisa Viger\Downloads\varsity_2 (1).zip
2019-01-04 10:23 - 2019-01-04 10:23 - 000207461 _____ C:\Users\Lisa Viger\Downloads\sunset_boulevard (1).zip
2019-01-04 10:21 - 2019-01-04 10:21 - 000065099 _____ C:\Users\Lisa Viger\Downloads\no_added_sugar.zip
2019-01-04 10:21 - 2019-01-04 10:21 - 000019493 _____ C:\Users\Lisa Viger\Downloads\quick.zip
2019-01-04 10:21 - 2019-01-04 10:21 - 000006215 _____ C:\Users\Lisa Viger\Downloads\telegrafico.zip
2019-01-04 10:16 - 2019-01-04 10:16 - 000870198 _____ C:\Users\Lisa Viger\Downloads\odin_rounded.zip
2019-01-04 10:16 - 2019-01-04 10:16 - 000662207 _____ C:\Users\Lisa Viger\Downloads\coyote.zip
2019-01-04 10:16 - 2019-01-04 10:16 - 000027676 _____ C:\Users\Lisa Viger\Downloads\marbre_sans.zip
2019-01-04 10:15 - 2019-01-04 10:15 - 006220267 _____ C:\Users\Lisa Viger\Downloads\moon_get (1).zip
2019-01-04 10:15 - 2019-01-04 10:15 - 001727049 _____ C:\Users\Lisa Viger\Downloads\baron_neue.zip
2019-01-04 10:15 - 2019-01-04 10:15 - 000014496 _____ C:\Users\Lisa Viger\Downloads\the_next_font.zip
2019-01-04 10:14 - 2019-01-04 10:14 - 000071649 _____ C:\Users\Lisa Viger\Downloads\couture (1).zip
2019-01-04 10:14 - 2019-01-04 10:14 - 000021086 _____ C:\Users\Lisa Viger\Downloads\kiona_2.zip
2019-01-04 10:14 - 2019-01-04 10:14 - 000010469 _____ C:\Users\Lisa Viger\Downloads\modern_sans.zip
2019-01-04 10:14 - 2019-01-04 10:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2019-01-04 10:14 - 2019-01-04 10:14 - 000000000 ____D C:\Program Files\7-Zip
2019-01-04 10:13 - 2019-01-04 10:14 - 005240073 _____ C:\Users\Lisa Viger\Downloads\tourmaline (1).zip
2019-01-04 10:13 - 2019-01-04 10:13 - 003004388 _____ C:\Users\Lisa Viger\Downloads\cocogoose (1).zip
2019-01-04 10:13 - 2019-01-04 10:13 - 000272154 _____ C:\Users\Lisa Viger\Downloads\aliens_and_cows (1).zip
2019-01-04 10:13 - 2019-01-04 10:13 - 000201702 _____ C:\Users\Lisa Viger\Downloads\comfortaa.zip
2019-01-04 10:13 - 2019-01-04 10:13 - 000053262 _____ C:\Users\Lisa Viger\Downloads\bebas_neue.zip
2019-01-04 10:13 - 2019-01-04 10:13 - 000026118 _____ C:\Users\Lisa Viger\Downloads\code (1).zip
2019-01-04 10:13 - 2019-01-04 10:13 - 000016374 _____ C:\Users\Lisa Viger\Downloads\the_bold_font.zip
2019-01-04 10:12 - 2019-01-04 10:13 - 001443680 _____ (Igor Pavlov) C:\Users\Lisa Viger\Downloads\7z1806-x64.exe
2019-01-04 10:11 - 2019-01-04 10:11 - 000435280 _____ C:\Users\Lisa Viger\Downloads\courier_polski_1941.zip
2019-01-04 10:11 - 2019-01-04 10:11 - 000144173 _____ C:\Users\Lisa Viger\Downloads\zai_royal_vogue_typewriter_1929.zip
2019-01-04 10:11 - 2019-01-04 10:11 - 000026497 _____ C:\Users\Lisa Viger\Downloads\teletype_1945_1985.zip
2019-01-04 10:10 - 2019-01-04 10:10 - 000367160 _____ C:\Users\Lisa Viger\Downloads\am_type1.zip
2019-01-04 10:10 - 2019-01-04 10:10 - 000250846 _____ C:\Users\Lisa Viger\Downloads\lucky_typewriter.zip
2019-01-04 10:10 - 2019-01-04 10:10 - 000201185 _____ C:\Users\Lisa Viger\Downloads\zai_olivetti_underwood_studio_21_typewriter.zip
2019-01-04 10:10 - 2019-01-04 10:10 - 000045044 _____ C:\Users\Lisa Viger\Downloads\f25_executive.zip
2019-01-04 10:09 - 2019-01-04 10:09 - 001435574 _____ C:\Users\Lisa Viger\Downloads\jmh_typewriter (1).zip
2019-01-04 10:09 - 2019-01-04 10:09 - 000254075 _____ C:\Users\Lisa Viger\Downloads\tox_typewriter.zip
2019-01-04 10:09 - 2019-01-04 10:09 - 000189677 _____ C:\Users\Lisa Viger\Downloads\linowrite.zip
2019-01-04 10:09 - 2019-01-04 10:09 - 000077285 _____ C:\Users\Lisa Viger\Downloads\typoslab_irregular.zip
2019-01-04 10:09 - 2019-01-04 10:09 - 000023590 _____ C:\Users\Lisa Viger\Downloads\atypewriterforme.zip
2018-12-19 21:28 - 2018-12-14 07:24 - 001364992 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvruserservice.dll
2018-12-19 21:28 - 2018-12-14 02:29 - 006567472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-12-19 21:28 - 2018-12-14 02:29 - 001130760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvproc.dll
2018-12-19 21:28 - 2018-12-14 02:25 - 001035256 _____ (Microsoft Corporation) C:\Windows\system32\ApplyTrustOffline.exe
2018-12-19 21:28 - 2018-12-14 02:23 - 001221432 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2018-12-19 21:28 - 2018-12-14 02:23 - 001029944 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2018-12-19 21:28 - 2018-12-14 02:23 - 000566568 _____ (Microsoft Corporation) C:\Windows\system32\tcblaunch.exe
2018-12-19 21:28 - 2018-12-14 02:23 - 000134968 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll
2018-12-19 21:28 - 2018-12-14 02:23 - 000076088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvservice.sys
2018-12-19 21:28 - 2018-12-14 02:22 - 009084216 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-12-19 21:28 - 2018-12-14 02:22 - 007520104 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2018-12-19 21:28 - 2018-12-14 02:21 - 001457240 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-12-19 21:28 - 2018-12-14 02:21 - 001257672 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-12-19 21:28 - 2018-12-14 02:21 - 001140480 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-12-19 21:28 - 2018-12-14 02:21 - 001098064 _____ (Microsoft Corporation) C:\Windows\system32\msvproc.dll
2018-12-19 21:28 - 2018-12-14 02:21 - 000982912 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2018-12-19 21:28 - 2018-12-14 02:13 - 005775872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2018-12-19 21:28 - 2018-12-14 02:12 - 005307392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2018-12-19 21:28 - 2018-12-14 02:10 - 001295360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVPXENC.dll
2018-12-19 21:28 - 2018-12-14 02:07 - 000669696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-12-19 21:28 - 2018-12-14 01:55 - 003396608 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2018-12-19 21:28 - 2018-12-14 01:55 - 000209408 _____ (Microsoft Corporation) C:\Windows\system32\AppXApplicabilityBlob.dll
2018-12-19 21:28 - 2018-12-14 01:54 - 006032384 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2018-12-19 21:28 - 2018-12-14 01:54 - 001307648 _____ (Microsoft Corporation) C:\Windows\system32\MSVPXENC.dll
2018-12-19 21:28 - 2018-12-14 01:54 - 000154112 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2018-12-19 21:28 - 2018-12-14 01:53 - 007573504 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2018-12-19 21:28 - 2018-12-14 01:52 - 002173440 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2018-12-19 21:28 - 2018-12-14 01:52 - 001826816 _____ (Microsoft Corporation) C:\Windows\system32\Windows.CloudStore.dll
2018-12-19 21:28 - 2018-12-14 01:51 - 001551360 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2018-12-19 21:28 - 2018-12-14 01:50 - 000776192 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-12-19 21:28 - 2018-12-14 00:34 - 000001312 _____ C:\Windows\system32\tcbres.wim
2018-12-14 10:37 - 2018-12-14 10:38 - 019583300 _____ C:\Users\Lisa Viger\Downloads\LQN.0035.004.pdf
2018-12-14 10:37 - 2018-12-14 10:38 - 019583300 _____ C:\Users\Lisa Viger\Downloads\LQN.0035.004 (2).pdf
2018-12-14 10:37 - 2018-12-14 10:38 - 019583300 _____ C:\Users\Lisa Viger\Downloads\LQN.0035.004 (1).pdf
2018-12-12 13:34 - 2018-12-12 13:34 - 000000000 ____D C:\Program Files\Windows Movie Maker 6.0
2018-12-12 13:31 - 2018-12-12 13:31 - 010776181 _____ C:\Users\Lisa Viger\Downloads\Windows Movie Maker 6.0.rar
2018-12-12 13:28 - 2018-12-12 13:28 - 000000000 ____D C:\Users\Lisa Viger\AppData\Local\DBG
2018-12-12 13:24 - 2010-05-01 13:05 - 000000000 ____D C:\Users\Lisa Viger\Documents\Windows Movie Maker 6.0
2018-12-12 13:23 - 2010-05-01 13:05 - 000000000 ____D C:\Users\Lisa Viger\Downloads\Windows Movie Maker 6.0
2018-12-12 13:21 - 2018-12-12 13:21 - 000000000 ____D C:\ProgramData\UniqueId
2018-12-12 10:28 - 2018-12-08 07:47 - 001048712 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2018-12-12 10:28 - 2018-12-08 07:47 - 000645320 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-12-12 10:28 - 2018-12-08 07:46 - 000549760 _____ (Microsoft Corporation) C:\Windows\system32\AppResolver.dll
2018-12-12 10:28 - 2018-12-08 07:42 - 004527800 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2018-12-12 10:28 - 2018-12-08 07:42 - 001634944 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
2018-12-12 10:28 - 2018-12-08 07:42 - 001616824 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2018-12-12 10:28 - 2018-12-08 07:41 - 002394960 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2018-12-12 10:28 - 2018-12-08 07:41 - 000481880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-12-12 10:28 - 2018-12-08 07:40 - 001454648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
2018-12-12 10:28 - 2018-12-08 07:39 - 000444416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppResolver.dll
2018-12-12 10:28 - 2018-12-08 07:29 - 013572608 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2018-12-12 10:28 - 2018-12-08 07:29 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\iemigplugin.dll
2018-12-12 10:28 - 2018-12-08 07:28 - 012710400 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-12-12 10:28 - 2018-12-08 07:28 - 006586880 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2018-12-12 10:28 - 2018-12-08 07:28 - 004708864 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll
2018-12-12 10:28 - 2018-12-08 07:27 - 005657600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2018-12-12 10:28 - 2018-12-08 07:27 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storqosflt.sys
2018-12-12 10:28 - 2018-12-08 07:27 - 000068608 _____ (Microsoft Corporation) C:\Windows\system32\fdBth.dll
2018-12-12 10:28 - 2018-12-08 07:27 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdBth.dll
2018-12-12 10:28 - 2018-12-08 07:25 - 012500992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2018-12-12 10:28 - 2018-12-08 07:25 - 011902976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-12-12 10:28 - 2018-12-08 07:23 - 003649024 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2018-12-12 10:28 - 2018-12-08 07:23 - 002892288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2018-12-12 10:28 - 2018-12-08 07:23 - 001856512 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2018-12-12 10:28 - 2018-12-08 07:23 - 001661440 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2018-12-12 10:28 - 2018-12-08 07:23 - 000503296 _____ (Microsoft Corporation) C:\Windows\system32\sppcext.dll
2018-12-12 10:28 - 2018-12-08 07:23 - 000471040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AcSpecfc.dll
2018-12-12 10:28 - 2018-12-08 07:22 - 001586176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2018-12-12 10:28 - 2018-12-08 07:22 - 001469952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2018-12-12 10:28 - 2018-12-08 07:22 - 000577024 _____ (Microsoft Corporation) C:\Windows\system32\SppExtComObj.Exe
2018-12-12 10:28 - 2018-12-08 03:12 - 000272408 _____ (Microsoft Corporation) C:\Windows\system32\SgrmEnclave.dll
2018-12-12 10:28 - 2018-12-08 03:12 - 000269336 _____ (Microsoft Corporation) C:\Windows\system32\SgrmEnclave_secure.dll
2018-12-12 10:28 - 2018-12-08 03:12 - 000092688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bindflt.sys
2018-12-12 10:28 - 2018-12-08 03:07 - 005625352 _____ (Microsoft Corporation) C:\Windows\system32\StartTileData.dll
2018-12-12 10:28 - 2018-12-08 03:07 - 001328632 _____ (Microsoft Corporation) C:\Windows\system32\wpx.dll
2018-12-12 10:28 - 2018-12-08 03:07 - 001063416 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2018-12-12 10:28 - 2018-12-08 03:06 - 001017168 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll
2018-12-12 10:28 - 2018-12-08 03:06 - 000777512 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2018-12-12 10:28 - 2018-12-08 03:06 - 000709936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2018-12-12 10:28 - 2018-12-08 03:06 - 000491416 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2018-12-12 10:28 - 2018-12-08 03:06 - 000433168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2018-12-12 10:28 - 2018-12-08 03:06 - 000249088 _____ (Microsoft Corporation) C:\Windows\system32\weretw.dll
2018-12-12 10:28 - 2018-12-08 03:05 - 007436216 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2018-12-12 10:28 - 2018-12-08 03:05 - 002822656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2018-12-12 10:28 - 2018-12-08 03:05 - 002463384 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2018-12-12 10:28 - 2018-12-08 03:05 - 001935008 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2018-12-12 10:28 - 2018-12-08 03:05 - 001209888 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2018-12-12 10:28 - 2018-12-08 03:05 - 001018880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ClipSp.sys
2018-12-12 10:28 - 2018-12-08 03:05 - 000793592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2018-12-12 10:28 - 2018-12-08 03:05 - 000706040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2018-12-12 10:28 - 2018-12-08 03:05 - 000594224 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2018-12-12 10:28 - 2018-12-08 03:05 - 000421176 _____ (Microsoft Corporation) C:\Windows\system32\xbgmengine.dll
2018-12-12 10:28 - 2018-12-08 03:05 - 000413920 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2018-12-12 10:28 - 2018-12-08 03:05 - 000171008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-12-12 10:28 - 2018-12-08 03:05 - 000130312 _____ (Microsoft Corporation) C:\Windows\system32\rmclient.dll
2018-12-12 10:28 - 2018-12-08 03:05 - 000086016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fileinfo.sys
2018-12-12 10:28 - 2018-12-08 03:04 - 004404720 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2018-12-12 10:28 - 2018-12-08 03:04 - 002590296 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2018-12-12 10:28 - 2018-12-08 03:04 - 002371296 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2018-12-12 10:28 - 2018-12-08 03:04 - 001943328 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-12-12 10:28 - 2018-12-08 03:04 - 001188512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-12-12 10:28 - 2018-12-08 03:04 - 001150312 _____ (Microsoft Corporation) C:\Windows\system32\MSVP9DEC.dll
2018-12-12 10:28 - 2018-12-08 03:04 - 000885760 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2018-12-12 10:28 - 2018-12-08 03:04 - 000604984 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe
2018-12-12 10:28 - 2018-12-08 03:04 - 000527160 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-12-12 10:28 - 2018-12-08 03:04 - 000416024 _____ (Microsoft Corporation) C:\Windows\system32\MSAudDecMFT.dll
2018-12-12 10:28 - 2018-12-08 03:04 - 000413176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2018-12-12 10:28 - 2018-12-08 03:04 - 000375608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2018-12-12 10:28 - 2018-12-08 03:04 - 000335672 _____ (Microsoft Corporation) C:\Windows\system32\moshostcore.dll
2018-12-12 10:28 - 2018-12-08 03:04 - 000268280 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll
2018-12-12 10:28 - 2018-12-08 03:04 - 000260800 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2018-12-12 10:28 - 2018-12-08 03:04 - 000158624 _____ (Microsoft Corporation) C:\Windows\system32\vertdll.dll
2018-12-12 10:28 - 2018-12-08 03:04 - 000128824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tm.sys
2018-12-12 10:28 - 2018-12-08 03:04 - 000058168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\iorate.sys
2018-12-12 10:28 - 2018-12-08 03:04 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\browser_broker.exe
2018-12-12 10:28 - 2018-12-08 02:49 - 025855488 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2018-12-12 10:28 - 2018-12-08 02:47 - 000861744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll
2018-12-12 10:28 - 2018-12-08 02:47 - 000785760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-12-12 10:28 - 2018-12-08 02:46 - 002331480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2018-12-12 10:28 - 2018-12-08 02:46 - 001989040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2018-12-12 10:28 - 2018-12-08 02:46 - 001397104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVP9DEC.dll
2018-12-12 10:28 - 2018-12-08 02:46 - 000665224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2018-12-12 10:28 - 2018-12-08 02:46 - 000457056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2018-12-12 10:28 - 2018-12-08 02:46 - 000101192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rmclient.dll
2018-12-12 10:28 - 2018-12-08 02:45 - 006043496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2018-12-12 10:28 - 2018-12-08 02:45 - 004789952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2018-12-12 10:28 - 2018-12-08 02:45 - 002307240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2018-12-12 10:28 - 2018-12-08 02:45 - 001805656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2018-12-12 10:28 - 2018-12-08 02:45 - 001620472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-12-12 10:28 - 2018-12-08 02:45 - 001379816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2018-12-12 10:28 - 2018-12-08 02:45 - 001011872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2018-12-12 10:28 - 2018-12-08 02:45 - 000567256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2018-12-12 10:28 - 2018-12-08 02:45 - 000356864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2018-12-12 10:28 - 2018-12-08 02:45 - 000129296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2018-12-12 10:28 - 2018-12-08 02:42 - 022715392 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-12-12 10:28 - 2018-12-08 02:42 - 009084928 _____ (Microsoft Corporation) C:\Windows\system32\BingMaps.dll
2018-12-12 10:28 - 2018-12-08 02:41 - 007057408 _____ (Microsoft Corporation) C:\Windows\system32\mos.dll
2018-12-12 10:28 - 2018-12-08 02:40 - 004710912 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
2018-12-12 10:28 - 2018-12-08 02:40 - 004384768 _____ (Microsoft Corporation) C:\Windows\system32\EdgeContent.dll
2018-12-12 10:28 - 2018-12-08 02:39 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\wpnsruprov.dll
2018-12-12 10:28 - 2018-12-08 02:38 - 022016000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2018-12-12 10:28 - 2018-12-08 02:38 - 003392000 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2018-12-12 10:28 - 2018-12-08 02:38 - 002739200 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2018-12-12 10:28 - 2018-12-08 02:38 - 000419328 _____ (Microsoft Corporation) C:\Windows\system32\eeprov.dll
2018-12-12 10:28 - 2018-12-08 02:38 - 000310272 _____ (Microsoft Corporation) C:\Windows\system32\wc_storage.dll
2018-12-12 10:28 - 2018-12-08 02:38 - 000132608 _____ (Microsoft Corporation) C:\Windows\system32\DataUsageLiveTileTask.exe
2018-12-12 10:28 - 2018-12-08 02:38 - 000085504 _____ (Microsoft Corporation) C:\Windows\system32\LocationFrameworkInternalPS.dll
2018-12-12 10:28 - 2018-12-08 02:38 - 000083456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wcnfs.sys
2018-12-12 10:28 - 2018-12-08 02:38 - 000055296 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2018-12-12 10:28 - 2018-12-08 02:37 - 002825728 _____ (Microsoft Corporation) C:\Windows\system32\MapGeocoder.dll
2018-12-12 10:28 - 2018-12-08 02:37 - 000395776 _____ (Microsoft Corporation) C:\Windows\system32\Search.ProtocolHandler.MAPI2.dll
2018-12-12 10:28 - 2018-12-08 02:37 - 000386048 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.Diagnostics.dll
2018-12-12 10:28 - 2018-12-08 02:37 - 000358912 _____ (Microsoft Corporation) C:\Windows\system32\DataUsageHandlers.dll
2018-12-12 10:28 - 2018-12-08 02:37 - 000184320 _____ (Microsoft Corporation) C:\Windows\system32\bthserv.dll
2018-12-12 10:28 - 2018-12-08 02:37 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\appsruprov.dll
2018-12-12 10:28 - 2018-12-08 02:37 - 000157696 _____ (Microsoft Corporation) C:\Windows\system32\energyprov.dll
2018-12-12 10:28 - 2018-12-08 02:37 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthenum.sys
2018-12-12 10:28 - 2018-12-08 02:37 - 000099328 _____ (Microsoft Corporation) C:\Windows\system32\utcutil.dll
2018-12-12 10:28 - 2018-12-08 02:37 - 000079872 _____ (Microsoft Corporation) C:\Windows\system32\offreg.dll
2018-12-12 10:28 - 2018-12-08 02:36 - 003381248 _____ (Microsoft Corporation) C:\Windows\system32\MapRouter.dll
2018-12-12 10:28 - 2018-12-08 02:36 - 003090432 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2018-12-12 10:28 - 2018-12-08 02:36 - 002364928 _____ (Microsoft Corporation) C:\Windows\system32\OpcServices.dll
2018-12-12 10:28 - 2018-12-08 02:36 - 001768448 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2018-12-12 10:28 - 2018-12-08 02:36 - 000894464 _____ (Microsoft Corporation) C:\Windows\system32\webplatstorageserver.dll
2018-12-12 10:28 - 2018-12-08 02:36 - 000566784 _____ (Microsoft Corporation) C:\Windows\system32\daxexec.dll
2018-12-12 10:28 - 2018-12-08 02:36 - 000462336 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2018-12-12 10:28 - 2018-12-08 02:36 - 000356352 _____ (Microsoft Corporation) C:\Windows\system32\dusmsvc.dll
2018-12-12 10:28 - 2018-12-08 02:36 - 000227328 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2018-12-12 10:28 - 2018-12-08 02:36 - 000153600 _____ (Microsoft Corporation) C:\Windows\system32\RMapi.dll
2018-12-12 10:28 - 2018-12-08 02:36 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mmcss.sys
2018-12-12 10:28 - 2018-12-08 02:35 - 002126336 _____ (Microsoft Corporation) C:\Windows\system32\LocationFramework.dll
2018-12-12 10:28 - 2018-12-08 02:35 - 001708544 _____ (Microsoft Corporation) C:\Windows\system32\MSPhotography.dll
2018-12-12 10:28 - 2018-12-08 02:35 - 000808448 _____ (Microsoft Corporation) C:\Windows\system32\EdgeManager.dll
2018-12-12 10:28 - 2018-12-08 02:35 - 000623104 _____ (Microsoft Corporation) C:\Windows\system32\PsmServiceExtHost.dll
2018-12-12 10:28 - 2018-12-08 02:34 - 001535488 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-12-12 10:28 - 2018-12-08 02:34 - 001023488 _____ (Microsoft Corporation) C:\Windows\system32\ShareHost.dll
2018-12-12 10:28 - 2018-12-08 02:34 - 000884224 _____ (Microsoft Corporation) C:\Windows\system32\NMAA.dll
2018-12-12 10:28 - 2018-12-08 02:34 - 000693248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Connectivity.dll
2018-12-12 10:28 - 2018-12-08 02:34 - 000684544 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2018-12-12 10:28 - 2018-12-08 02:34 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\defragsvc.dll
2018-12-12 10:28 - 2018-12-08 02:33 - 019405312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-12-12 10:28 - 2018-12-08 02:33 - 002904064 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2018-12-12 10:28 - 2018-12-08 02:33 - 001457152 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2018-12-12 10:28 - 2018-12-08 02:33 - 001264640 _____ (Microsoft Corporation) C:\Windows\system32\JpMapControl.dll
2018-12-12 10:28 - 2018-12-08 02:33 - 001058304 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2018-12-12 10:28 - 2018-12-08 02:33 - 000949248 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2018-12-12 10:28 - 2018-12-08 02:33 - 000823296 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2018-12-12 10:28 - 2018-12-08 02:33 - 000176640 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2018-12-12 10:28 - 2018-12-08 02:32 - 001097728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2018-12-12 10:28 - 2018-12-08 02:32 - 001032704 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
2018-12-12 10:28 - 2018-12-08 02:32 - 000895488 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll
2018-12-12 10:28 - 2018-12-08 02:32 - 000796672 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2018-12-12 10:28 - 2018-12-08 02:32 - 000542208 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-12-12 10:28 - 2018-12-08 02:32 - 000406528 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2018-12-12 10:28 - 2018-12-08 02:30 - 006647296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingMaps.dll
2018-12-12 10:28 - 2018-12-08 02:30 - 002966528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdp.dll
2018-12-12 10:28 - 2018-12-08 02:30 - 000074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dtdump.exe
2018-12-12 10:28 - 2018-12-08 02:29 - 005883904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
2018-12-12 10:28 - 2018-12-08 02:29 - 002700288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2018-12-12 10:28 - 2018-12-08 02:29 - 000311296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.Diagnostics.dll
2018-12-12 10:28 - 2018-12-08 02:29 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
2018-12-12 10:28 - 2018-12-08 02:28 - 002258944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2018-12-12 10:28 - 2018-12-08 02:28 - 001361408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSPhotography.dll
2018-12-12 10:28 - 2018-12-08 02:28 - 000391680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\daxexec.dll
2018-12-12 10:28 - 2018-12-08 02:28 - 000288768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2018-12-12 10:28 - 2018-12-08 02:27 - 002449408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapRouter.dll
2018-12-12 10:28 - 2018-12-08 02:27 - 001986560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapGeocoder.dll
2018-12-12 10:28 - 2018-12-08 02:27 - 000608768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EdgeManager.dll
2018-12-12 10:28 - 2018-12-08 02:27 - 000578560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webplatstorageserver.dll
2018-12-12 10:28 - 2018-12-08 02:27 - 000555008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll
2018-12-12 10:28 - 2018-12-08 02:27 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\offreg.dll
2018-12-12 10:28 - 2018-12-08 02:26 - 001348096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpcServices.dll
2018-12-12 10:28 - 2018-12-08 02:26 - 000848384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ShareHost.dll
2018-12-12 10:28 - 2018-12-08 02:25 - 000978944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JpMapControl.dll
2018-12-12 10:28 - 2018-12-08 02:25 - 000856576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2018-12-12 10:28 - 2018-12-08 02:25 - 000729088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NMAA.dll
2018-12-12 10:28 - 2018-12-08 02:25 - 000702464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2018-12-12 10:28 - 2018-12-08 02:25 - 000145408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2018-12-12 10:28 - 2018-12-08 02:24 - 000795648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2018-12-12 10:28 - 2018-12-08 02:24 - 000735744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2018-12-12 10:28 - 2018-12-08 02:24 - 000533504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-12-12 10:28 - 2018-12-08 02:24 - 000345088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2018-12-12 10:28 - 2018-11-09 01:15 - 021388752 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2018-12-12 10:28 - 2018-11-09 01:00 - 000177664 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2018-12-12 10:28 - 2018-11-09 00:59 - 008623616 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2018-12-12 10:28 - 2018-11-09 00:58 - 000244736 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2018-12-12 10:28 - 2018-11-09 00:57 - 000208896 _____ (Microsoft Corporation) C:\Windows\system32\sensrsvc.dll
2018-12-12 10:28 - 2018-11-09 00:56 - 000392192 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-12-12 10:28 - 2018-11-09 00:56 - 000381952 _____ (Microsoft Corporation) C:\Windows\system32\ninput.dll
2018-12-12 10:28 - 2018-11-09 00:56 - 000103936 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSoftwareInstallationClient.dll
2018-12-12 10:28 - 2018-11-09 00:55 - 001254400 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.Handlers.dll
2018-12-12 10:28 - 2018-11-09 00:55 - 000878592 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2018-12-12 10:28 - 2018-11-09 00:54 - 001535488 _____ (Microsoft Corporation) C:\Windows\system32\wbengine.exe
2018-12-12 10:28 - 2018-11-09 00:32 - 020383832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2018-12-12 10:28 - 2018-11-09 00:22 - 000138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2018-12-12 10:28 - 2018-11-09 00:20 - 007987712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2018-12-12 10:28 - 2018-11-09 00:19 - 000181248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2018-12-12 10:28 - 2018-11-09 00:18 - 000344576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-12-12 10:28 - 2018-11-09 00:18 - 000320512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ninput.dll
2018-12-12 10:28 - 2018-11-09 00:17 - 000704000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2018-12-12 10:28 - 2018-11-08 21:56 - 001213472 _____ (Microsoft Corporation) C:\Windows\system32\ClipUp.exe
2018-12-12 10:28 - 2018-11-08 21:49 - 000723416 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2018-12-12 10:28 - 2018-11-08 21:49 - 000565048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2018-12-12 10:28 - 2018-11-08 21:49 - 000368656 _____ (Microsoft Corporation) C:\Windows\system32\thumbcache.dll
2018-12-12 10:28 - 2018-11-08 21:48 - 003179760 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2018-12-12 10:28 - 2018-11-08 21:48 - 002719736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2018-12-12 10:28 - 2018-11-08 21:48 - 001613288 _____ (Microsoft Corporation) C:\Windows\system32\D3D12.dll
2018-12-12 10:28 - 2018-11-08 21:48 - 000899920 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2018-12-12 10:28 - 2018-11-08 21:48 - 000766704 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2018-12-12 10:28 - 2018-11-08 21:48 - 000745472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2018-12-12 10:28 - 2018-11-08 21:48 - 000375296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2018-12-12 10:28 - 2018-11-08 21:47 - 002765344 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-12-12 10:28 - 2018-11-08 21:47 - 002571128 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-12-12 10:28 - 2018-11-08 21:47 - 002062392 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll
2018-12-12 10:28 - 2018-11-08 21:47 - 001285432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2018-12-12 10:28 - 2018-11-08 21:47 - 000930616 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2018-12-12 10:28 - 2018-11-08 21:47 - 000537912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2018-12-12 10:28 - 2018-11-08 21:22 - 000185344 _____ (Microsoft Corporation) C:\Windows\system32\InstallServiceTasks.dll
2018-12-12 10:28 - 2018-11-08 21:22 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\winhttpcom.dll
2018-12-12 10:28 - 2018-11-08 21:21 - 004866560 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-12-12 10:28 - 2018-11-08 21:21 - 001627136 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2018-12-12 10:28 - 2018-11-08 21:21 - 000119808 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTimeUtil.dll
2018-12-12 10:28 - 2018-11-08 21:21 - 000112128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthhfenum.sys
2018-12-12 10:28 - 2018-11-08 21:21 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-12-12 10:28 - 2018-11-08 21:20 - 000530432 _____ (Microsoft Corporation) C:\Windows\system32\MapConfiguration.dll
2018-12-12 10:28 - 2018-11-08 21:20 - 000399872 _____ (Microsoft Corporation) C:\Windows\system32\BthAvctpSvc.dll
2018-12-12 10:28 - 2018-11-08 21:20 - 000200704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthA2DP.sys
2018-12-12 10:28 - 2018-11-08 21:20 - 000193536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiswan.sys
2018-12-12 10:28 - 2018-11-08 21:20 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\tzautoupdate.dll
2018-12-12 10:28 - 2018-11-08 21:19 - 002368512 _____ (Microsoft Corporation) C:\Windows\system32\WebRuntimeManager.dll
2018-12-12 10:28 - 2018-11-08 21:19 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-12-12 10:28 - 2018-11-08 21:19 - 000304128 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll
2018-12-12 10:28 - 2018-11-08 21:18 - 003320320 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2018-12-12 10:28 - 2018-11-08 21:18 - 001487360 _____ (Microsoft Corporation) C:\Windows\system32\InstallService.dll
2018-12-12 10:28 - 2018-11-08 21:18 - 000573952 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2018-12-12 10:28 - 2018-11-08 21:18 - 000514048 _____ (Microsoft Corporation) C:\Windows\system32\BTAGService.dll
2018-12-12 10:28 - 2018-11-08 21:18 - 000300032 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2018-12-12 10:28 - 2018-11-08 21:17 - 002584576 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2018-12-12 10:28 - 2018-11-08 21:17 - 001069568 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll
2018-12-12 10:28 - 2018-11-08 21:16 - 004939776 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-12-12 10:28 - 2018-11-08 21:16 - 002224640 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2018-12-12 10:28 - 2018-11-08 21:16 - 001364992 _____ (Microsoft Corporation) C:\Windows\system32\lpasvc.dll
2018-12-12 10:28 - 2018-11-08 21:16 - 001225216 _____ (Microsoft Corporation) C:\Windows\system32\MapsStore.dll
2018-12-12 10:28 - 2018-11-08 21:16 - 000308736 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseAppMgmtSvc.dll
2018-12-12 10:28 - 2018-11-08 21:15 - 000943616 _____ (Microsoft Corporation) C:\Windows\system32\BingOnlineServices.dll
2018-12-12 10:28 - 2018-11-08 21:15 - 000933888 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2018-12-12 10:28 - 2018-11-08 21:15 - 000884224 _____ (Microsoft Corporation) C:\Windows\system32\MapControlCore.dll
2018-12-12 10:28 - 2018-11-08 21:15 - 000505344 _____ (Microsoft Corporation) C:\Windows\system32\edgeIso.dll
2018-12-12 10:28 - 2018-11-08 21:07 - 002417976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2018-12-12 10:28 - 2018-11-08 21:07 - 001299704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3D12.dll
2018-12-12 10:28 - 2018-11-08 20:48 - 000550728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2018-12-12 10:28 - 2018-11-08 20:47 - 000295224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\thumbcache.dll
2018-12-12 10:28 - 2018-11-08 20:46 - 002253184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-12-12 10:28 - 2018-11-08 20:46 - 002161008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll
2018-12-12 10:28 - 2018-11-08 20:46 - 001980776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-12-12 10:28 - 2018-11-08 20:46 - 000829960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2018-12-12 10:28 - 2018-11-08 20:46 - 000721024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2018-12-12 10:28 - 2018-11-08 20:46 - 000573504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2018-12-12 10:28 - 2018-11-08 20:31 - 000094720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTimeUtil.dll
2018-12-12 10:28 - 2018-11-08 20:31 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2018-12-12 10:28 - 2018-11-08 20:30 - 000142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallServiceTasks.dll
2018-12-12 10:28 - 2018-11-08 20:30 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttpcom.dll
2018-12-12 10:28 - 2018-11-08 20:29 - 003711488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-12-12 10:28 - 2018-11-08 20:29 - 000561152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-12-12 10:28 - 2018-11-08 20:29 - 000392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapConfiguration.dll
2018-12-12 10:28 - 2018-11-08 20:29 - 000331264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgeIso.dll
2018-12-12 10:28 - 2018-11-08 20:28 - 002900992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2018-12-12 10:28 - 2018-11-08 20:27 - 000463872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2018-12-12 10:28 - 2018-11-08 20:26 - 004514816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-12-12 10:28 - 2018-11-08 20:26 - 001110528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallService.dll
2018-12-12 10:28 - 2018-11-08 20:26 - 000873472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2018-12-12 10:28 - 2018-11-08 20:26 - 000251904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msIso.dll
2018-12-12 10:28 - 2018-11-08 20:25 - 000713216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingOnlineServices.dll
2018-12-12 10:28 - 2018-11-08 20:25 - 000705024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapControlCore.dll
2018-12-12 08:15 - 2018-12-12 08:15 - 000000000 ____D C:\Program Files\Reference Assemblies
2018-12-12 08:15 - 2018-12-12 08:15 - 000000000 ____D C:\Program Files\MSBuild
2018-12-12 08:15 - 2018-12-12 08:15 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2018-12-12 08:15 - 2018-12-12 08:15 - 000000000 ____D C:\Program Files (x86)\MSBuild
2018-12-12 08:15 - 2018-03-05 16:07 - 000778936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationNative_v0300.dll
2018-12-12 08:15 - 2018-03-05 16:07 - 000103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2018-12-12 08:15 - 2018-03-05 16:07 - 000035456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2018-12-12 08:15 - 2018-02-14 16:21 - 001166520 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll
2018-12-12 08:15 - 2018-02-14 16:21 - 000124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2018-12-12 08:15 - 2018-02-14 16:21 - 000035456 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2018-12-12 08:13 - 2018-12-12 08:13 - 001242312 _____ (Microsoft Corporation) C:\Users\Lisa Viger\Downloads\wlsetup-web.exe
2018-12-09 15:17 - 2018-12-09 15:27 - 000000000 ____D C:\Users\Lisa Viger\Downloads\Water For Elephants (2011)
2018-12-09 15:09 - 2019-01-06 13:02 - 000000000 ____D C:\Users\Lisa Viger\AppData\Roaming\BitTorrent
2018-12-09 15:09 - 2018-12-09 15:09 - 000000921 _____ C:\Users\Lisa Viger\Desktop\BitTorrent.lnk
2018-12-09 15:09 - 2018-12-09 15:09 - 000000901 _____ C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk
2018-12-09 15:08 - 2018-12-09 15:08 - 002685544 _____ (BitTorrent Inc.) C:\Users\Lisa Viger\Downloads\BitTorrent.exe
2018-12-08 16:54 - 2018-12-08 16:54 - 002009344 _____ C:\Users\Lisa Viger\Downloads\shorelines_script (1).zip
2018-12-08 16:32 - 2018-12-08 16:32 - 000092206 _____ C:\Users\Lisa Viger\Downloads\mermaid.zip
2018-12-08 16:32 - 2018-12-08 16:32 - 000051870 _____ C:\Users\Lisa Viger\Downloads\timeless.zip
2018-12-08 16:32 - 2018-12-08 16:32 - 000018406 _____ C:\Users\Lisa Viger\Downloads\nouvelle_vague.zip
2018-12-08 16:32 - 2018-12-08 16:32 - 000009420 _____ C:\Users\Lisa Viger\Downloads\edition.zip
2018-12-08 16:30 - 2018-12-08 16:30 - 000170424 _____ C:\Users\Lisa Viger\Downloads\dingfleur.zip
2018-12-08 16:30 - 2018-12-08 16:30 - 000107247 _____ C:\Users\Lisa Viger\Downloads\art_nouveau_flowers.zip
2018-12-08 16:30 - 2018-12-08 16:30 - 000086656 _____ C:\Users\Lisa Viger\Downloads\wmtrees1.zip
2018-12-08 16:29 - 2018-12-08 16:29 - 000668455 _____ C:\Users\Lisa Viger\Downloads\menina_graciosa_ornaments.zip
2018-12-08 16:29 - 2018-12-08 16:29 - 000195917 _____ C:\Users\Lisa Viger\Downloads\trees_tfb.zip
2018-12-08 16:29 - 2018-12-08 16:29 - 000023440 _____ C:\Users\Lisa Viger\Downloads\flower_ornaments.zip
2018-12-08 16:29 - 2018-12-08 16:29 - 000016056 _____ C:\Users\Lisa Viger\Downloads\leafs.zip
2018-12-08 16:28 - 2018-12-08 16:28 - 005240073 _____ C:\Users\Lisa Viger\Downloads\tourmaline.zip
2018-12-08 16:28 - 2018-12-08 16:28 - 000071649 _____ C:\Users\Lisa Viger\Downloads\couture.zip
2018-12-08 16:28 - 2018-12-08 16:28 - 000024825 _____ C:\Users\Lisa Viger\Downloads\another_typewriter.zip
2018-12-08 16:27 - 2018-12-08 16:27 - 005628516 _____ C:\Users\Lisa Viger\Downloads\shink.zip
2018-12-08 16:27 - 2018-12-08 16:27 - 001435574 _____ C:\Users\Lisa Viger\Downloads\jmh_typewriter.zip
2018-12-08 16:27 - 2018-12-08 16:27 - 000428635 _____ C:\Users\Lisa Viger\Downloads\quicksand.zip
2018-12-08 16:27 - 2018-12-08 16:27 - 000163194 _____ C:\Users\Lisa Viger\Downloads\made_canvas.zip
2018-12-08 16:27 - 2018-12-08 16:27 - 000047623 _____ C:\Users\Lisa Viger\Downloads\i_love_christmas.zip
2018-12-08 16:26 - 2018-12-08 16:26 - 004450421 _____ C:\Users\Lisa Viger\Downloads\yessy.zip
2018-12-08 16:26 - 2018-12-08 16:26 - 000989291 _____ C:\Users\Lisa Viger\Downloads\traveling_typewriter.zip
2018-12-08 16:26 - 2018-12-08 16:26 - 000516140 _____ C:\Users\Lisa Viger\Downloads\magnolia_sky.zip
2018-12-08 16:26 - 2018-12-08 16:26 - 000214102 _____ C:\Users\Lisa Viger\Downloads\mf_i_love_glitter.zip
2018-12-08 16:26 - 2018-12-08 16:26 - 000098099 _____ C:\Users\Lisa Viger\Downloads\adelard.zip
2018-12-08 16:26 - 2018-12-08 16:26 - 000085977 _____ C:\Users\Lisa Viger\Downloads\xmas_tfb_christmas.zip
2018-12-08 16:26 - 2018-12-08 16:26 - 000058520 _____ C:\Users\Lisa Viger\Downloads\everything_calligraphy.zip
2018-12-08 16:26 - 2018-12-08 16:26 - 000050801 _____ C:\Users\Lisa Viger\Downloads\watermelon_script.zip
2018-12-08 16:26 - 2018-12-08 16:26 - 000037696 _____ C:\Users\Lisa Viger\Downloads\shocking_headline.zip
2018-12-08 16:26 - 2018-12-08 16:26 - 000010869 _____ C:\Users\Lisa Viger\Downloads\freshman.zip
2018-12-08 16:25 - 2018-12-08 16:25 - 003004388 _____ C:\Users\Lisa Viger\Downloads\cocogoose.zip
2018-12-08 16:25 - 2018-12-08 16:25 - 000272154 _____ C:\Users\Lisa Viger\Downloads\aliens_and_cows.zip
2018-12-08 16:25 - 2018-12-08 16:25 - 000210123 _____ C:\Users\Lisa Viger\Downloads\keep_calm.zip
2018-12-08 16:25 - 2018-12-08 16:25 - 000204132 _____ C:\Users\Lisa Viger\Downloads\nattalia.zip
2018-12-08 16:25 - 2018-12-08 16:25 - 000068078 _____ C:\Users\Lisa Viger\Downloads\geo_sans_light.zip
2018-12-08 16:25 - 2018-12-08 16:25 - 000026645 _____ C:\Users\Lisa Viger\Downloads\another_flight.zip
2018-12-08 16:25 - 2018-12-08 16:25 - 000026118 _____ C:\Users\Lisa Viger\Downloads\code.zip
2018-12-08 16:25 - 2018-12-08 16:25 - 000024256 _____ C:\Users\Lisa Viger\Downloads\oh_darling.zip
2018-12-08 16:25 - 2018-12-08 16:25 - 000021476 _____ C:\Users\Lisa Viger\Downloads\loves.zip
2018-12-08 16:25 - 2018-12-08 16:25 - 000019487 _____ C:\Users\Lisa Viger\Downloads\sunshine_2.zip
2018-12-08 16:25 - 2018-12-08 16:25 - 000013500 _____ C:\Users\Lisa Viger\Downloads\the_skinny.zip
2018-12-08 16:24 - 2018-12-08 16:24 - 002009344 _____ C:\Users\Lisa Viger\Downloads\shorelines_script.zip
2018-12-08 16:24 - 2018-12-08 16:24 - 000404226 _____ C:\Users\Lisa Viger\Downloads\sweet_hipster.zip
2018-12-08 16:24 - 2018-12-08 16:24 - 000210692 _____ C:\Users\Lisa Viger\Downloads\champagne_limousines.zip
2018-12-08 16:24 - 2018-12-08 16:24 - 000207461 _____ C:\Users\Lisa Viger\Downloads\sunset_boulevard.zip
2018-12-08 16:24 - 2018-12-08 16:24 - 000136224 _____ C:\Users\Lisa Viger\Downloads\caviar_dreams.zip
2018-12-08 16:24 - 2018-12-08 16:24 - 000043002 _____ C:\Users\Lisa Viger\Downloads\bettalia.zip
2018-12-08 16:24 - 2018-12-08 16:24 - 000032911 _____ C:\Users\Lisa Viger\Downloads\bignoodletitling.zip
2018-12-08 16:24 - 2018-12-08 16:24 - 000016387 _____ C:\Users\Lisa Viger\Downloads\varsity_2.zip
2018-12-08 16:24 - 2018-12-08 16:24 - 000010856 _____ C:\Users\Lisa Viger\Downloads\vogue.zip
2018-12-08 16:23 - 2018-12-08 16:23 - 003642215 _____ C:\Users\Lisa Viger\Downloads\magic.zip
2018-12-08 16:23 - 2018-12-08 16:23 - 000360792 _____ C:\Users\Lisa Viger\Downloads\lemon_milk.zip
2018-12-08 16:23 - 2018-12-08 16:23 - 000063185 _____ C:\Users\Lisa Viger\Downloads\le_bal_des_cochons.zip
2018-12-08 16:23 - 2018-12-08 16:23 - 000056953 _____ C:\Users\Lisa Viger\Downloads\boulevard_2.zip
2018-12-08 16:23 - 2018-12-08 16:23 - 000033511 _____ C:\Users\Lisa Viger\Downloads\valentine_2.zip
2018-12-08 16:23 - 2018-12-08 16:23 - 000029864 _____ C:\Users\Lisa Viger\Downloads\little_betty.zip
2018-12-08 16:22 - 2018-12-08 16:22 - 000325886 _____ C:\Users\Lisa Viger\Downloads\tell_me_a_secret.zip
2018-12-08 16:22 - 2018-12-08 16:22 - 000131167 _____ C:\Users\Lisa Viger\Downloads\conjecture.zip
2018-12-08 16:21 - 2018-12-08 16:21 - 000476615 _____ C:\Users\Lisa Viger\Downloads\nenuphar_of_venus.zip
2018-12-08 16:21 - 2018-12-08 16:21 - 000461655 _____ C:\Users\Lisa Viger\Downloads\dancing_on_the_grass.zip
2018-12-08 16:21 - 2018-12-08 16:21 - 000110654 _____ C:\Users\Lisa Viger\Downloads\mougatine.zip
2018-12-08 16:21 - 2018-12-08 16:21 - 000033071 _____ C:\Users\Lisa Viger\Downloads\estrela_fulguria_1748.zip
2018-12-08 16:21 - 2018-12-08 16:21 - 000016840 _____ C:\Users\Lisa Viger\Downloads\the_curious_incident.zip
2018-12-08 16:20 - 2018-12-08 16:20 - 000505784 _____ C:\Users\Lisa Viger\Downloads\eglantine2.zip
2018-12-08 16:20 - 2018-12-08 16:20 - 000477328 _____ C:\Users\Lisa Viger\Downloads\eternal_call.zip
2018-12-08 16:20 - 2018-12-08 16:20 - 000301239 _____ C:\Users\Lisa Viger\Downloads\onedaybeforerain.zip
2018-12-08 16:20 - 2018-12-08 16:20 - 000118850 _____ C:\Users\Lisa Viger\Downloads\jack_and_the_beanstalk.zip
2018-12-08 16:20 - 2018-12-08 16:20 - 000110059 _____ C:\Users\Lisa Viger\Downloads\the_fabulous_orchestra.zip
2018-12-08 16:20 - 2018-12-08 16:20 - 000063368 _____ C:\Users\Lisa Viger\Downloads\lantre_du_caniche.zip
2018-12-08 16:20 - 2018-12-08 16:20 - 000047986 _____ C:\Users\Lisa Viger\Downloads\fabulous_vikings.zip
2018-12-08 16:20 - 2018-12-08 16:20 - 000020794 _____ C:\Users\Lisa Viger\Downloads\dragons_and_chickens.zip
2018-12-08 16:19 - 2018-12-08 16:19 - 000746892 _____ C:\Users\Lisa Viger\Downloads\helene_queen_k.zip
2018-12-08 16:19 - 2018-12-08 16:19 - 000274578 _____ C:\Users\Lisa Viger\Downloads\marguerite.zip
2018-12-08 16:19 - 2018-12-08 16:19 - 000193527 _____ C:\Users\Lisa Viger\Downloads\arabia.zip
2018-12-08 16:19 - 2018-12-08 16:19 - 000036382 _____ C:\Users\Lisa Viger\Downloads\mathilde_castleland.zip
2018-12-08 16:19 - 2018-12-08 16:19 - 000028156 _____ C:\Users\Lisa Viger\Downloads\band_of_reality.zip
2018-12-08 16:18 - 2018-12-08 16:18 - 000563288 _____ C:\Users\Lisa Viger\Downloads\diane_de_france.zip
2018-12-08 16:18 - 2018-12-08 16:18 - 000205825 _____ C:\Users\Lisa Viger\Downloads\mademoiselle_catherine.zip
2018-12-08 16:18 - 2018-12-08 16:18 - 000147241 _____ C:\Users\Lisa Viger\Downloads\from_this_moment.zip
2018-12-08 16:18 - 2018-12-08 16:18 - 000089904 _____ C:\Users\Lisa Viger\Downloads\ornamind.zip
2018-12-08 16:18 - 2018-12-08 16:18 - 000070472 _____ C:\Users\Lisa Viger\Downloads\there_can_only_be_one_beaver_im_it.zip
2018-12-08 16:18 - 2018-12-08 16:18 - 000056654 _____ C:\Users\Lisa Viger\Downloads\it_was_a_good_day.zip
2018-12-08 16:18 - 2018-12-08 16:18 - 000036812 _____ C:\Users\Lisa Viger\Downloads\alicia_on_the_enchanted_highlands.zip
2018-12-08 16:18 - 2018-12-08 16:18 - 000029814 _____ C:\Users\Lisa Viger\Downloads\the_golden_flower.zip
2018-12-08 16:18 - 2018-12-08 16:18 - 000028567 _____ C:\Users\Lisa Viger\Downloads\the_constellation_of_heracles.zip
2018-12-08 16:18 - 2018-12-08 16:18 - 000024871 _____ C:\Users\Lisa Viger\Downloads\angelique_ma_douce_colombe.zip
2018-12-08 16:17 - 2018-12-08 16:17 - 000434582 _____ C:\Users\Lisa Viger\Downloads\magnolia.zip
2018-12-08 16:17 - 2018-12-08 16:17 - 000342193 _____ C:\Users\Lisa Viger\Downloads\moonlights_on_the_beach.zip
2018-12-08 16:17 - 2018-12-08 16:17 - 000062237 _____ C:\Users\Lisa Viger\Downloads\mademoiselle_camille.zip
2018-12-08 16:17 - 2018-12-08 16:17 - 000024122 _____ C:\Users\Lisa Viger\Downloads\chocolatines.zip
2018-12-08 16:17 - 2018-12-08 16:17 - 000019368 _____ C:\Users\Lisa Viger\Downloads\stardust_adventure.zip
2018-12-08 16:17 - 2018-12-08 16:17 - 000016793 _____ C:\Users\Lisa Viger\Downloads\dragon_is_coming.zip
2018-12-08 16:16 - 2018-12-08 16:16 - 001189970 _____ C:\Users\Lisa Viger\Downloads\chicago_moonshine.zip
2018-12-08 16:16 - 2018-12-08 16:16 - 000881613 _____ C:\Users\Lisa Viger\Downloads\haunted_moon.zip
2018-12-08 16:16 - 2018-12-08 16:16 - 000202673 _____ C:\Users\Lisa Viger\Downloads\full_moon_on_mars.zip
2018-12-08 16:16 - 2018-12-08 16:16 - 000176189 _____ C:\Users\Lisa Viger\Downloads\dk_moonlight_serenade.zip
2018-12-08 16:16 - 2018-12-08 16:16 - 000111551 _____ C:\Users\Lisa Viger\Downloads\daylight_moonlight.zip
2018-12-08 16:16 - 2018-12-08 16:16 - 000107992 _____ C:\Users\Lisa Viger\Downloads\october_moon.zip
2018-12-08 16:16 - 2018-12-08 16:16 - 000089464 _____ C:\Users\Lisa Viger\Downloads\sun_and_moon.zip
2018-12-08 16:16 - 2018-12-08 16:16 - 000087752 _____ C:\Users\Lisa Viger\Downloads\queen_of_the_moon.zip
2018-12-08 16:16 - 2018-12-08 16:16 - 000073337 _____ C:\Users\Lisa Viger\Downloads\raspberry_moonshine.zip
2018-12-08 16:16 - 2018-12-08 16:16 - 000067105 _____ C:\Users\Lisa Viger\Downloads\rabbit_on_the_moon.zip
2018-12-08 16:16 - 2018-12-08 16:16 - 000049717 _____ C:\Users\Lisa Viger\Downloads\moontea_family.zip
2018-12-08 16:15 - 2018-12-08 16:15 - 006220267 _____ C:\Users\Lisa Viger\Downloads\moon_get.zip
2018-12-08 16:15 - 2018-12-08 16:15 - 001322875 _____ C:\Users\Lisa Viger\Downloads\moon_flower.zip
2018-12-08 16:15 - 2018-12-08 16:15 - 000416469 _____ C:\Users\Lisa Viger\Downloads\moonchrome.zip
2018-12-08 16:15 - 2018-12-08 16:15 - 000247914 _____ C:\Users\Lisa Viger\Downloads\autumn_moon.zip
2018-12-08 16:15 - 2018-12-08 16:15 - 000083015 _____ C:\Users\Lisa Viger\Downloads\honey_moon.zip
2018-12-08 16:15 - 2018-12-08 16:15 - 000072371 _____ C:\Users\Lisa Viger\Downloads\pixie_moon.zip
2018-12-08 16:15 - 2018-12-08 16:15 - 000031485 _____ C:\Users\Lisa Viger\Downloads\moonlight_2.zip
2018-12-08 16:15 - 2018-12-08 16:15 - 000014456 _____ C:\Users\Lisa Viger\Downloads\moonrise.zip
2018-12-08 16:15 - 2018-12-08 16:15 - 000012492 _____ C:\Users\Lisa Viger\Downloads\rabbitmoon.zip
2018-12-08 16:15 - 2018-12-08 16:15 - 000009855 _____ C:\Users\Lisa Viger\Downloads\moon_phases.zip
2018-12-08 16:14 - 2018-12-08 16:14 - 000847386 _____ C:\Users\Lisa Viger\Downloads\the_perfect_christmas.zip
2018-12-08 15:57 - 2018-12-08 15:57 - 000035583 _____ C:\Users\Lisa Viger\Downloads\fabulous_5 (1).zip
2018-12-08 15:48 - 2018-12-08 15:48 - 000782868 _____ C:\Users\Lisa Viger\Downloads\dust_west_college.zip
2018-12-08 15:48 - 2018-12-08 15:48 - 000671559 _____ C:\Users\Lisa Viger\Downloads\universal_college.zip
2018-12-08 15:48 - 2018-12-08 15:48 - 000626299 _____ C:\Users\Lisa Viger\Downloads\ficticcia_college.zip
2018-12-08 15:48 - 2018-12-08 15:48 - 000293651 _____ C:\Users\Lisa Viger\Downloads\sketch_college.zip
2018-12-08 15:48 - 2018-12-08 15:48 - 000232691 _____ C:\Users\Lisa Viger\Downloads\collegethrash.zip
2018-12-08 15:48 - 2018-12-08 15:48 - 000224231 _____ C:\Users\Lisa Viger\Downloads\fine_college.zip
2018-12-08 15:48 - 2018-12-08 15:48 - 000113967 _____ C:\Users\Lisa Viger\Downloads\mickeys_school.zip
2018-12-08 15:48 - 2018-12-08 15:48 - 000020767 _____ C:\Users\Lisa Viger\Downloads\vintage_college_dept_worn.zip
2018-12-08 15:47 - 2018-12-08 15:47 - 000304718 _____ C:\Users\Lisa Viger\Downloads\colleged.zip
2018-12-08 15:46 - 2018-12-08 15:46 - 000045635 _____ C:\Users\Lisa Viger\Downloads\leisha.zip
2018-12-08 15:46 - 2018-12-08 15:46 - 000035583 _____ C:\Users\Lisa Viger\Downloads\fabulous_5.zip
2018-12-08 15:46 - 2018-12-08 15:46 - 000028970 _____ C:\Users\Lisa Viger\Downloads\memories_2.zip
2018-12-07 21:27 - 2019-01-05 20:50 - 000148816 ____N C:\Windows\system32\Drivers\zaksbdwp.sys
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-01-06 13:00 - 2018-04-11 18:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-01-06 01:11 - 2018-11-15 22:09 - 000000000 ____D C:\Users\Lisa Viger\AppData\Local\PlaceholderTileLogoFolder
2019-01-05 21:27 - 2018-11-15 22:03 - 000000000 ____D C:\Users\Lisa Viger\AppData\Local\D3DSCache
2019-01-05 20:03 - 2018-05-15 11:46 - 000000000 ____D C:\Windows\system32\SleepStudy
2019-01-05 19:22 - 2018-11-15 22:07 - 000002378 _____ C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-01-05 11:25 - 2018-05-15 11:53 - 000838560 _____ C:\Windows\system32\PerfStringBackup.INI
2019-01-05 11:25 - 2018-04-11 18:36 - 000000000 ____D C:\Windows\INF
2019-01-05 11:21 - 2018-05-15 11:47 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-01-05 11:21 - 2018-05-15 11:46 - 000395984 _____ C:\Windows\system32\FNTCACHE.DAT
2019-01-05 00:55 - 2018-10-31 15:43 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2019-01-05 00:55 - 2018-04-11 16:04 - 015466496 _____ C:\Windows\system32\config\HARDWARE
2019-01-05 00:55 - 2018-04-11 16:04 - 000786432 _____ C:\Windows\system32\config\BBI
2019-01-04 21:27 - 2018-11-15 22:07 - 000000000 ___RD C:\Users\Lisa Viger\OneDrive
2019-01-04 08:01 - 2018-04-11 18:38 - 000000000 ____D C:\Windows\AppReadiness
2019-01-03 07:20 - 2018-11-16 22:22 - 000000000 ____D C:\ProgramData\Packages
2019-01-03 07:20 - 2018-04-11 18:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-12-27 23:14 - 2018-11-20 20:19 - 000000000 ____D C:\Users\Lisa Viger\AppData\Local\ElevatedDiagnostics
2018-12-19 23:53 - 2018-04-11 18:38 - 000000000 ____D C:\Windows\TextInput
2018-12-19 23:53 - 2018-04-11 18:38 - 000000000 ____D C:\Windows\bcastdvr
2018-12-19 21:30 - 2018-04-11 18:30 - 000000000 ____D C:\Windows\CbsTemp
2018-12-19 21:22 - 2018-11-15 22:14 - 000003418 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-12-19 21:22 - 2018-11-15 22:14 - 000003294 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-12-16 17:56 - 2018-04-11 18:38 - 000000000 ____D C:\Windows\LiveKernelReports
2018-12-12 20:22 - 2018-11-15 22:24 - 000000000 ____D C:\Users\Lisa Viger\AppData\Roaming\PhotoScape
2018-12-12 17:35 - 2018-11-15 22:05 - 000000000 ___RD C:\Users\Lisa Viger\3D Objects
2018-12-12 17:35 - 2018-05-15 11:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-12-12 17:34 - 2018-04-11 18:38 - 000000000 ___SD C:\Windows\system32\DiagSvcs
2018-12-12 17:34 - 2018-04-11 18:38 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2018-12-12 17:34 - 2018-04-11 18:38 - 000000000 ____D C:\Windows\ShellComponents
2018-12-12 10:32 - 2018-11-16 21:16 - 000000000 ____D C:\Windows\system32\MRT
2018-12-12 10:31 - 2018-11-16 21:16 - 137260640 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-12-10 20:35 - 2018-11-16 06:53 - 000592616 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2018-12-10 20:35 - 2018-05-15 11:47 - 000000000 ____D C:\Windows\system32\Drivers\wd
2018-12-08 14:15 - 2018-11-16 20:45 - 000000000 ____D C:\Program Files\rempl
2018-12-07 07:13 - 2018-10-31 15:49 - 000000000 ____D C:\Windows\Minidump
2018-12-07 07:13 - 2018-04-11 18:38 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
 
==================== Files in the root of some directories =======
 
2019-01-05 14:51 - 2019-01-05 14:51 - 000012800 _____ () C:\Users\Lisa Viger\AppData\Local\Rathman.exe
2019-01-05 20:49 - 2019-01-05 20:49 - 000016384 _____ () C:\Users\Lisa Viger\AppData\Local\sfciwu.dll
2019-01-05 14:51 - 2019-01-05 14:51 - 000012800 _____ () C:\Users\Lisa Viger\AppData\Local\Winds.exe
 
Some files in TEMP:
====================
2019-01-05 01:41 - 2019-01-05 01:41 - 014999840 _____ () C:\Users\Lisa Viger\AppData\Local\Temp\setup.dll
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
C:\Windows\system32\drivers\zaksbdwp.sys -> Access Denied <======= ATTENTION
 
LastRegBack: 2018-05-15 11:46
 
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06.01.2019
Ran by [removed] (06-01-2019 13:03:09)
Running from C:\Users\[removed]\Downloads
Windows 10 Home Version 1803 17134.472 (X64) (2018-11-16 02:58:26)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-833294152-1074476770-1006749115-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-833294152-1074476770-1006749115-503 - Limited - Disabled)
Guest (S-1-5-21-833294152-1074476770-1006749115-501 - Limited - Disabled)
Lisa Viger (S-1-5-21-833294152-1074476770-1006749115-1003 - Administrator - Enabled) => C:\Users\Lisa Viger
WDAGUtilityAccount (S-1-5-21-833294152-1074476770-1006749115-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 18.06 (x64) (HKLM\…\7-Zip) (Version: 18.06 - Igor Pavlov)
AMD Software (HKLM\…\AMD Catalyst Install Manager) (Version: 18.10.2 - Advanced Micro Devices, Inc.)
Balanced (HKLM-x32\…\{EFD0705E-598B-46D4-8D5B-4539431764B8}) (Version: 2.02.0000 - Advanced Micro Devices, Inc.) Hidden
BitTorrent (HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\BitTorrent) (Version: 7.10.4.44847 - BitTorrent Inc.)
BlockAdsPro (HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\BlockAdsPro) (Version: 2.4.36.6 - Soft Corporation)
Branding64 (HKLM\…\{EE2AFCE4-0238-4DE0-A140-1647021627C1}) (Version: 1.00.0001 - Advanced Micro Devices, Inc.) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 71.0.3578.98 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden
Intel(R) Wireless Bluetooth(R) (HKLM-x32\…\{00000070-0200-1033-84C8-B8D95FA3C8C3}) (Version: 20.70.0 - Intel Corporation)
JerkPatrol (HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\JerkPatrol) (Version:  - Alt0C10ud)
Macrium Reflect Free Edition (HKLM\…\{DF104573-C971-434E-BDB4-E05FA85287B8}) (Version: 7.2.3858 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free Edition (HKLM\…\MacriumReflect) (Version: 7.2 - Paramount Software (UK) Ltd.)
Microsoft OneDrive (HKU\S-1-5-21-833294152-1074476770-1006749115-1003\…\OneDriveSetup.exe) (Version: 17.3.6816.0313 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.14.26429 (HKLM-x32\…\{80586c77-db42-44bb-bfc8-7aebbb220c00}) (Version: 14.14.26429.4 - Microsoft Corporation)
OEM Application Profile (HKLM-x32\…\{7F5DCD33-1039-C3B2-9538-B645B65BBA63}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
PhotoScape (HKLM-x32\…\PhotoScape) (Version:  - )
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8522 - Realtek Semiconductor Corp.)
Shotcut (HKLM-x32\…\Shotcut) (Version: 18.12.23 - Meltytech, LLC)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\…\{9CBA860F-7437-4A75-941C-8EF559F2D145}) (Version: 2.52.0.0 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-12-30] (Igor Pavlov)
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2018-10-30] (Paramount Software UK Ltd)
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2018-10-30] (Paramount Software UK Ltd)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-12-30] (Igor Pavlov)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2018-10-20] (Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-12-30] (Igor Pavlov)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {018EA53B-BFAD-4027-9B24-462BDAC69CA9} - System32\Tasks\nashville_asian => C:\Users\Lisa Viger\AppData\Local\Winds.exe [2019-01-05] ()
Task: {0AEF75A1-6A6D-4EE7-82C4-293A0FFAC226} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-11-15] (Google Inc.)
Task: {0BBC7450-51C9-417C-83E5-0F6A03CE70F6} - System32\Tasks\chording unwisely harewoodchording unwisely harewood => C:\Users\Lisa Viger\AppData\Local\Rathman.exe [2019-01-05] ()
Task: {1A48C5EC-7602-4D66-9497-E73F2250415E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-10] (Microsoft Corporation)
Task: {1DF9DF33-BB67-4594-958A-37F3E72701A7} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2018-10-20] (Advanced Micro Devices, Inc.)
Task: {21234088-1523-4A14-A0A3-FDEDDA549498} - System32\Tasks\amp => C:\Program Files (x86)\Characterised\subsisting.exe [2019-01-05] ()
Task: {290FCE76-DA3F-42C1-B1DB-63486892BB04} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-11-15] (Google Inc.)
Task: {4A32EE78-0E42-4E02-BE05-1A9D55D5AAC2} - System32\Tasks\nashville_asiannashville_asian => C:\Users\Lisa Viger\AppData\Local\Winds.exe [2019-01-05] ()
Task: {50867DB9-D3F0-4534-A1D7-B4BE1C5C56C1} - System32\Tasks\turretturret => C:\Program Files (x86)\petitioner\petitioner.exe [2019-01-05] ()
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\Windows\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] ()
Task: {6667C65C-80FC-4897-8A42-7BD49ED9FDD8} - System32\Tasks\tawil => C:\Program Files (x86)\Moslem\Rathman.exe [2019-01-05] ()
Task: {68EEEE42-35CC-443D-8468-B0DD70F74628} - System32\Tasks\ecliptic journaling => C:\Program Files (x86)\Remunerated\Winds.exe [2019-01-05] ()
Task: {741D3925-B092-4589-A974-422909ED05F9} - System32\Tasks\chording unwisely harewood => C:\Users\Lisa Viger\AppData\Local\Rathman.exe [2019-01-05] ()
Task: {83A8DEEC-ED45-4E64-88C4-1FFBF2BA1A25} - System32\Tasks\ampamp => C:\Program Files (x86)\Characterised\subsisting.exe [2019-01-05] ()
Task: {83EDE065-A688-4D33-96E7-0C6B05FF3920} - System32\Tasks\ecliptic journalingecliptic journaling => C:\Program Files (x86)\Remunerated\Winds.exe [2019-01-05] ()
Task: {8D0E0214-0F64-4151-B3E4-C44E56EE3FB1} - System32\Tasks\turret => C:\Program Files (x86)\petitioner\petitioner.exe [2019-01-05] ()
Task: {8EE33902-B5AD-4A0E-BABB-CBF53146DF49} - System32\Tasks\kyi_crhkyi_crh => C:\Program Files (x86)\Remunerated\Rathman.exe [2019-01-05] ()
Task: {992201F5-C210-4EFD-8167-036BBC98F572} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-10] (Microsoft Corporation)
Task: {B06E92E5-A3E8-4919-948C-150F34585E38} - System32\Tasks\talky-counterparttalky-counterpart => C:\Program Files (x86)\twisty\Winds.exe [2019-01-05] ()
Task: {BE8BB364-13A1-4F7B-86D0-5BFC18B4D984} - System32\Tasks\kyi_crh => C:\Program Files (x86)\Remunerated\Rathman.exe [2019-01-05] ()
Task: {DB59FB28-9B67-402B-94D3-A0C4BFA7431C} - System32\Tasks\talky-counterpart => C:\Program Files (x86)\twisty\Winds.exe [2019-01-05] ()
Task: {ED437E70-8D11-4154-B289-9A932993E1EF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-10] (Microsoft Corporation)
Task: {FBDBF595-7771-48C0-A348-707DB212B496} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\dvrcmd.exe [2018-10-20] (Advanced Micro Devices, Inc.)
Task: {FDC58621-43D4-44BE-8831-DECD82AD4429} - System32\Tasks\tawiltawil => C:\Program Files (x86)\Moslem\Rathman.exe [2019-01-05] ()
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2018-08-07 10:53 - 2018-08-07 10:53 - 000192160 _____ () C:\Windows\system32\IntelWifiIhv06.dll
2019-01-05 14:51 - 2019-01-05 14:51 - 000061426 _____ () C:\Program Files (x86)\Characterised\subsisting.exe
2018-04-11 18:34 - 2018-04-11 18:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll
2018-04-11 18:34 - 2018-04-11 18:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-12-12 10:28 - 2018-11-08 21:17 - 002759680 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-06-28 00:15 - 2018-06-28 00:15 - 000014336 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.DLL
2018-06-28 00:15 - 2018-06-28 00:15 - 002552832 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2018-12-19 21:28 - 2018-12-14 01:50 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-12-13 18:02 - 2018-12-13 18:04 - 000182272 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
2018-11-16 21:52 - 2018-11-16 21:54 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\ImagePipelineNative.dll
2018-12-13 18:02 - 2018-12-13 18:04 - 000060416 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\ChakraBridge.dll
2014-09-10 11:26 - 2014-09-10 11:26 - 007406656 _____ () C:\Program Files (x86)\PhotoScape\PhotoScape.exe
2019-01-05 14:51 - 2019-01-05 14:51 - 000049502 _____ () C:\Program Files (x86)\minstrelsy\cringing.exe
2018-12-12 16:21 - 2018-12-12 00:11 - 005237216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libglesv2.dll
2018-12-12 16:21 - 2018-12-12 00:11 - 000117216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libegl.dll
2019-01-05 14:51 - 2019-01-05 14:51 - 000012800 _____ () C:\Program Files (x86)\twisty\Winds.exe
2018-12-10 20:35 - 2018-12-10 20:35 - 034870272 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\Video.UI.exe
2018-12-10 20:35 - 2018-12-10 20:35 - 000292352 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\SharedUI.dll
2018-04-12 04:24 - 2018-04-12 04:24 - 000902656 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\Microsoft.Membership.MeControl.UI.Xaml.dll
2018-12-06 21:17 - 2018-12-06 21:18 - 004202208 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-12-10 20:35 - 2018-12-10 20:35 - 005967872 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\EntCommon.dll
2018-12-10 20:35 - 2018-12-10 20:35 - 009072128 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\EntPlat.dll
2019-01-05 14:51 - 2019-01-05 14:51 - 000012800 _____ () C:\Program Files (x86)\Moslem\Rathman.exe
2019-01-05 20:49 - 2019-01-05 20:49 - 000016384 _____ () C:\Users\Lisa Viger\AppData\Local\sfciwu.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2018-04-11 18:38 - 2019-01-05 20:49 - 000001282 _____ C:\Windows\system32\Drivers\etc\hosts
 
162.222.193.86       aoaomo.tremorhub.com
188.95.50.62       bobomo.tremorhub.com
162.222.193.86       www.howcast.com
162.222.193.86       howcast.com
162.222.193.86       www.ustream.tv
162.222.193.86       ustream.tv
162.222.193.86       www.livestream.com
162.222.193.86       livestream.com
162.222.193.86       www.dailymotion.com
162.222.193.86       dailymotion.com
192.192.3.8       www.virustotal.com
192.192.3.8       virustotal.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.254.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
If an entry is included in the fixlist, it will be removed.
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{AE3C37F8-ED64-4CE0-A57B-04B912DE263A}] => (Allow) C:\Users\Lisa Viger\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc.)
FirewallRules: [{19C2A175-16CE-44EC-ACBF-5CBAFB7A3B3B}] => (Allow) C:\Users\Lisa Viger\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc.)
FirewallRules: [{0CCEF7C7-0317-4859-B0C9-58B116B10B4C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe No File
FirewallRules: [{2323D239-ACC4-4772-8036-715C5CF68230}] => (Allow) C:\Windows\system32\rundll32.exe (Microsoft Corporation)
FirewallRules: [{F9791372-ACE4-4BA8-A2E8-EFE8342A9E5C}] => (Allow) C:\Program Files (x86)\Moslem\Rathman.exe ()
FirewallRules: [{AF625959-D1B3-454A-BFC3-0BB425A47470}] => (Allow) C:\Program Files (x86)\Remunerated\Rathman.exe ()
FirewallRules: [{7CB7D730-3E5C-4F58-9872-D763D1C588D0}] => (Allow) C:\Program Files (x86)\twisty\Winds.exe ()
FirewallRules: [{7BC13C4D-5C45-4319-932C-2382709A9035}] => (Allow) C:\Program Files (x86)\Remunerated\Winds.exe ()
 
==================== Restore Points =========================
 
ATTENTION: System Restore is disabled
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (01/06/2019 11:00:39 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AUEPMaster.exe, version: 1840.7.1.1019, time stamp: 0x5bca97eb
Faulting module name: AUEPMaster.exe, version: 1840.7.1.1019, time stamp: 0x5bca97eb
Exception code: 0xc0000005
Fault offset: 0x000000000002826d
Faulting process id: 0x1e90
Faulting application start time: 0x01d4a513029327cf
Faulting application path: C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
Faulting module path: C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
Report Id: 0dd810d5-a0a1-4385-9db2-d1be49074826
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (01/02/2019 01:22:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 71.0.3578.98, time stamp: 0x5c0f4450
Faulting module name: KERNELBASE.dll, version: 10.0.17134.441, time stamp: 0x428de48c
Exception code: 0xe0000008
Fault offset: 0x000000000003a388
Faulting process id: 0x24a0
Faulting application start time: 0x01d4a2c37aaf3aa9
Faulting application path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: 5099717b-0b88-460c-a5d8-69905c5d2ab7
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (01/02/2019 06:29:04 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AUEPMaster.exe, version: 1840.7.1.1019, time stamp: 0x5bca97eb
Faulting module name: AUEPMaster.exe, version: 1840.7.1.1019, time stamp: 0x5bca97eb
Exception code: 0xc0000005
Fault offset: 0x000000000002826d
Faulting process id: 0x534
Faulting application start time: 0x01d4a21ef3d0a16f
Faulting application path: C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
Faulting module path: C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
Report Id: 29a279e1-106d-4fc3-9c2f-362f65610861
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (12/16/2018 05:56:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AUEPMaster.exe, version: 1840.7.1.1019, time stamp: 0x5bca97eb
Faulting module name: AUEPMaster.exe, version: 1840.7.1.1019, time stamp: 0x5bca97eb
Exception code: 0xc0000005
Fault offset: 0x000000000002826d
Faulting process id: 0x1b8
Faulting application start time: 0x01d493a0f820468f
Faulting application path: C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
Faulting module path: C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
Report Id: 4bc61faf-79c9-482b-8741-0f69de59a31e
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (12/12/2018 01:38:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MOVIEMK.exe, version: 6.0.6000.16386, time stamp: 0x4549b5b6
Faulting module name: PipeTran.dll, version: 6.1.7068.0, time stamp: 0x49c59b27
Exception code: 0xc0000005
Fault offset: 0x000207c6
Faulting process id: 0x3b4
Faulting application start time: 0x01d49249d19a6977
Faulting application path: C:\Program Files\Windows Movie Maker 6.0\MOVIEMK.exe
Faulting module path: C:\Program Files\Windows Movie Maker 6.0\PipeTran.dll
Report Id: 35b1cd1a-6f11-4350-afc1-a398c7527dfb
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (12/12/2018 01:37:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MOVIEMK.exe, version: 6.0.6000.16386, time stamp: 0x4549b5b6
Faulting module name: PipeTran.dll, version: 6.1.7068.0, time stamp: 0x49c59b27
Exception code: 0xc0000005
Fault offset: 0x000207c6
Faulting process id: 0x3a84
Faulting application start time: 0x01d49249aa077810
Faulting application path: C:\Program Files\Windows Movie Maker 6.0\MOVIEMK.exe
Faulting module path: C:\Program Files\Windows Movie Maker 6.0\PipeTran.dll
Report Id: 761fd079-503b-4d0d-a599-58751be6a89a
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (12/12/2018 01:28:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MOVIEMK.exe, version: 6.0.6000.16386, time stamp: 0x4549b5b6
Faulting module name: PipeTran.dll, version: 6.1.7068.0, time stamp: 0x49c59b27
Exception code: 0xc0000005
Fault offset: 0x000207c6
Faulting process id: 0x3950
Faulting application start time: 0x01d4924847f17a71
Faulting application path: C:\Users\Lisa Viger\Downloads\Windows Movie Maker 6.0\MOVIEMK.exe
Faulting module path: C:\Users\Lisa Viger\Downloads\Windows Movie Maker 6.0\PipeTran.dll
Report Id: 0957fe8d-0c3b-4445-9800-fa931197a65f
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (12/11/2018 01:11:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_BTAGService, version: 10.0.17134.1, time stamp: 0xa38b9ab2
Faulting module name: KERNELBASE.dll, version: 10.0.17134.407, time stamp: 0x99042cc0
Exception code: 0xe06d7363
Fault offset: 0x000000000003a388
Faulting process id: 0x157c
Faulting application start time: 0x01d4917cf431335f
Faulting application path: C:\Windows\system32\svchost.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: eb98b487-cffa-4095-b6c0-6dbe386d8ec0
Faulting package full name: 
Faulting package-relative application ID:
 
 
System errors:
=============
Error: (01/06/2019 12:37:40 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.
 
Error: (01/06/2019 12:37:40 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.
 
Error: (01/06/2019 12:37:40 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.
 
Error: (01/06/2019 12:37:40 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.
 
Error: (01/06/2019 12:37:40 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.
 
Error: (01/06/2019 12:37:40 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.
 
Error: (01/06/2019 12:37:40 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.
 
Error: (01/06/2019 12:37:40 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.
 
 
Windows Defender:
===================================
Date: 2019-01-05 21:13:52.722
Description: 
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {0930D434-625C-4295-9203-AC108754852B}
Scan Type: Antimalware
Scan Parameters: Full Scan
 
Date: 2019-01-05 21:00:35.700
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name;=Trojan:Win32/Skeeyah.A!rfn&threatid;=2147694182&enterprise;=0
Name: Trojan:Win32/Skeeyah.A!rfn
ID: 2147694182
Severity: Severe
Category: Trojan
Path: chromeinstall:_HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GOOGLE CHROME; file:_C:\Program Files (x86)\Google\Chrome\Application\chrome.exe; file:_C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk; file:_C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk; file:_C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk; file:_C:\Users\Public\Desktop\Google Chrome.lnk; regkey:_HKCU@S-1-5-21-833294152-1074476770-1006749115-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\GoogleChromeAutoLaunch_28B6DDC3CEFF48A5F4263F10EABF3C1D; runkey:_HKCU@S-1-5-21-833294152-1074476770-1006749115-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\GoogleChromeAutoLaunch_28B6DDC3CEFF48A5F4263F10EABF3C1D; startup:_C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: User
Process Name: Unknown
Signature Version: AV: 1.283.2305.0, AS: 1.283.2305.0, NIS: 0.0.0.0
Engine Version: AM: 1.1.15500.2, NIS: 0.0.0.0
 
Date: 2019-01-05 21:00:35.698
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name;=Trojan:Win32/SquareNet&threatid;=2147727752&enterprise;=0
Name: Trojan:Win32/SquareNet
ID: 2147727752
Severity: Severe
Category: Trojan
Path: file:_C:\Program Files (x86)\s5\u.exe; regkey:_HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\s5m; uninstall:_HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\s5m
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: User
Process Name: Unknown
Signature Version: AV: 1.283.2305.0, AS: 1.283.2305.0, NIS: 0.0.0.0
Engine Version: AM: 1.1.15500.2, NIS: 0.0.0.0
 
Date: 2019-01-05 20:26:13.947
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name;=Trojan:Win32/Fuery.B!cl&threatid;=2147718514&enterprise;=0
Name: Trojan:Win32/Fuery.B!cl
ID: 2147718514
Severity: Severe
Category: Trojan
Path: file:_I:\MOVIES\Windows Movie Maker 8.5.3 (For Windows All 7. 8. 10)\Windows Movie Maker 8.5.3 (For Windows All 7. 8. 10).exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Signature Version: AV: 1.283.2305.0, AS: 1.283.2305.0, NIS: 1.283.2305.0
Engine Version: AM: 1.1.15500.2, NIS: 1.1.15500.2
 
Date: 2019-01-05 20:25:53.320
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name;=Trojan:Win32/Fuery.B!cl&threatid;=2147718514&enterprise;=0
Name: Trojan:Win32/Fuery.B!cl
ID: 2147718514
Severity: Severe
Category: Trojan
Path: file:_I:\MOVIES\Windows Movie Maker 8.5.3 (For Windows All 7. 8. 10)\Windows Movie Maker 8.5.3 (For Windows All 7. 8. 10).exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Signature Version: AV: 1.283.2305.0, AS: 1.283.2305.0, NIS: 1.283.2305.0
Engine Version: AM: 1.1.15500.2, NIS: 1.1.15500.2
 
Date: 2018-11-20 20:18:32.718
Description: 
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.281.408.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.15400.5
Error code: 0x8024402c
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 
 
CodeIntegrity:
===================================
 
Date: 2019-01-05 21:04:24.251
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\dllhost.exe) attempted to load \Device\HarddiskVolume6\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs that did not meet the Microsoft signing level requirements.
 
Date: 2019-01-05 20:50:55.820
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume6\Windows\System32\lsihrkzsvc.exe that did not meet the Unchecked signing level requirements.
 
Date: 2019-01-05 20:50:55.810
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume6\Windows\System32\lsihrkzsvc.exe that did not meet the Unchecked signing level requirements.
 
Date: 2019-01-05 20:50:55.798
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume6\Windows\System32\lsihrkzsvc.exe that did not meet the Unchecked signing level requirements.
 
Date: 2019-01-05 20:49:54.472
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume6\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs that did not meet the Microsoft signing level requirements.
 
Date: 2019-01-05 20:49:50.360
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\dllhost.exe) attempted to load \Device\HarddiskVolume6\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs that did not meet the Microsoft signing level requirements.
 
Date: 2019-01-05 20:49:50.233
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\RuntimeBroker.exe) attempted to load \Device\HarddiskVolume6\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs that did not meet the Microsoft signing level requirements.
 
Date: 2019-01-05 20:49:50.211
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume6\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs that did not meet the Microsoft signing level requirements.
 
==================== Memory info =========================== 
 
Processor: AMD Ryzen 3 2200G with Radeon Vega Graphics 
Percentage of memory in use: 49%
Total physical RAM: 16316.26 MB
Available physical RAM: 8257.34 MB
Total Virtual: 18748.26 MB
Available Virtual: 7103.27 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:223.02 GB) (Free:182.14 GB) NTFS
Drive d: (SD) (Removable) (Total:29.71 GB) (Free:3.03 GB) FAT32
Drive h: (New Volume) (Fixed) (Total:1863 GB) (Free:1850.08 GB) NTFS
Drive i: (Seagate Backup Plus Drive) (Fixed) (Total:4657.4 GB) (Free:2082.13 GB) NTFS
 
\\?\Volume{e116be19-363f-4834-a012-f079c5d9b88e}\ (Recovery) (Fixed) (Total:0.44 GB) (Free:0.08 GB) NTFS
\\?\Volume{a82ba7d8-f8b3-4815-8f9b-b63a7e1b767d}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Protective MBR) (Size: 1863 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
========================================================
Disk: 1 (Size: 223.6 GB) (Disk ID: B5B2DF75)
 
Partition: GPT.
 
========================================================
Disk: 2 (MBR Code: Windows 7/8/10) (Size: 4657.5 GB) (Disk ID: 9FBC85AD)
 
Partition: GPT.
 
========================================================
Disk: 3 (Protective MBR) (Size: 29.7 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==================== End of Addition.txt ============================
There is quite the damage here.

I'm going to try and attempt to help but it wont be easy.


~~

Follow the instructions in the thread below. Make sure to download the MBAR version linked in it. Let me know if you're not able to launch it and run a scan.

https://forums.malwarebytes.com/topic/198907-requested-resource-is-in-use-error-unable-to-start-malwarebytes/

If you manage to run a scan, delete everything it finds, and then copy/paste the content of the mbar-log-DATE-(TIME).txt log that is located in the MBAR folder here after.


~~~~~~~~~~~~~~~~~~~~~~~~~

[external image: iO3R662.png]Farbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.
  • Right-click on the FRST executable and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Copy/paste the following inside the text area:
    Start::
    CMD: bcdedit.exe /set {bootmgr} displaybootmenu yes
    CMD: bcdedit.exe /set {default} recoveryenabled yes
    End::
    
  • Click on the Fix button
    [external image: NYA5Cbr.png]
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad
  • Copy and paste its content in your next reply
Fix result of Farbar Recovery Scan Tool (x64) Version: 06.01.2019
Ran by [removed] (07-01-2019 09:11:31) Run:1
Running from C:\Users\[removed]\Downloads
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CMD: bcdedit.exe /set {bootmgr} displaybootmenu yes
CMD: bcdedit.exe /set {default} recoveryenabled yes
 
*****************
 
 
========= bcdedit.exe /set {bootmgr} displaybootmenu yes =========
 
The operation completed successfully.
 
========= End of CMD: =========
 
 
========= bcdedit.exe /set {default} recoveryenabled yes =========
 
The operation completed successfully.
 
========= End of CMD: =========
 
 
==== End of Fixlog 09:11:31 ====
It's important to see what was removed to see how to move forward.

If need be run it again and take notice if it shows/tells you were the log will be placed.

Upon completion of the scan or after the reboot, two files named mbar-log.txt and system-log.txt will be created

I think this is it … 

 

 

Malwarebytes Anti-Rootkit BETA 1.10.3.1001
www.malwarebytes.org
 
Database version:
  main:    v2019.01.07.03
  rootkit: v2019.01.07.03
 
Windows 10 x64 NTFS
Internet Explorer 11.472.17134.0
Lisa Viger :: LISAS-DESKTOP [administrator]
 
1/7/2019 8:49:15 AM
mbar-log-2019-01-07 (08-49-15).txt
 
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 175343
Time elapsed: 5 minute(s), 10 second(s)
 
Memory Processes Detected: 1
C:\Program Files (x86)\minstrelsy\cringing.exe (Adware.DotDo.Generic) -> 14024 -> Delete on reboot. [e3acc439a026f442f2acd62620e16799]
 
Memory Modules Detected: 1
C:\Users\Lisa Viger\AppData\Local\sfciwu.dll (Trojan.ProxyAgent) -> Delete on reboot. [bad5ad50e6e0290d6a2f8fc9946f9a66]
 
Registry Keys Detected: 1
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINDOWSMANAGEMENTSERVICE (Trojan.Yelloader) -> Delete on reboot. [d7b8d42955718ea8b901707a0af68080]
 
Registry Values Detected: 9
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|sfciwu (Trojan.ProxyAgent) -> Data: rundll32.exe "C:\Users\Lisa Viger\AppData\Local\sfciwu.dll",sfciwu -> Delete on reboot. [bad5ad50e6e0290d6a2f8fc9946f9a66]
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|cringing (Adware.DotDo.Generic) -> Data: "C:\Program Files (x86)\minstrelsy\cringing.exe" azawjwazawjwazawjwazawj.azawjjazawjrazawjhazawj.azawjpazawjwazawj/azawjy2s0s1s9s0azawjsl1sl0y5ysazawjhtml0LF8scazawjyQUIlpIwnTazawjhLg0 -> Delete on reboot. [e3acc439a026f442f2acd62620e16799]
HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WinResSync (Trojan.Injector) -> Data: C:\Windows\system32\regsvr32.exe /s "C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs" -> Delete on reboot. [0a85bd40477f3105c815946f60a39c64]
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WinResSync (Trojan.Injector) -> Data: C:\Windows\system32\regsvr32.exe /s "C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs" -> Delete on reboot. [0a85bd40477f3105c815946f60a39c64]
HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|WinResSync (Trojan.Injector) -> Data: C:\Windows\system32\regsvr32.exe /s "C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs" -> Delete on reboot. [0a85bd40477f3105c815946f60a39c64]
HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WinResSync (Trojan.Injector) -> Data: C:\Windows\system32\regsvr32.exe /s "C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs" -> Delete on reboot. [0a85bd40477f3105c815946f60a39c64]
HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|WinResSync (Trojan.Injector) -> Data: C:\Windows\system32\regsvr32.exe /s "C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs" -> Delete on reboot. [0a85bd40477f3105c815946f60a39c64]
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Blogger (Trojan.Agent) -> Data: C:\ProgramData\Blogger\Blogger.exe -> Delete on reboot. [ace311ec5670e353c5b582b91fe1e11f]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINDOWSMANAGEMENTSERVICE|ImagePath (Trojan.Yelloader) -> Data: windowsmanagementservice -> Delete on reboot. [d7b8d42955718ea8b901707a0af68080]
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 3
C:\ProgramData\1546739382 (Trojan.Yelloader.Gen) -> Delete on reboot. [d6b98776c2041e1845d60237a0608b75]
C:\ProgramData\Blogger (Trojan.Agent) -> Delete on reboot. [ace311ec5670e353c5b582b91fe1e11f]
C:\Users\Lisa Viger\AppData\Local\Temp\1546739382 (Trojan.Yelloader) -> Delete on reboot. [573822db12b48aac0175a4de39c71ae6]
 
Files Detected: 20
C:\Users\Lisa Viger\AppData\Local\sfciwu.dll (Trojan.ProxyAgent) -> Delete on reboot. [bad5ad50e6e0290d6a2f8fc9946f9a66]
C:\Program Files (x86)\minstrelsy\cringing.exe (Adware.DotDo.Generic) -> Delete on reboot. [e3acc439a026f442f2acd62620e16799]
C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs (Trojan.Injector) -> Delete on reboot. [0a85bd40477f3105c815946f60a39c64]
C:\Users\Lisa Viger\AppData\Local\Temp\1546739382\s5m_install_325.exe (Trojan.Clicker) -> Delete on reboot. [503f30cd9531e056f6ce41a062a0fd03]
C:\Users\Lisa Viger\AppData\Local\Temp\1546739382\setup0904.exe (Adware.Clicker) -> Delete on reboot. [602fc934fbcbde58a6e0a349fe0355ab]
C:\Windows\guttural.exe (Adware.DotDo.Generic.TskLnk) -> Delete on reboot. [7a150af34d793afc75bb2ff29a68b749]
C:\ProgramData\1546739382\s9.zip.download (Trojan.Yelloader.Gen) -> Delete on reboot. [d6b98776c2041e1845d60237a0608b75]
C:\ProgramData\Blogger\Blogger.exe (Trojan.Agent) -> Delete on reboot. [ace311ec5670e353c5b582b91fe1e11f]
C:\Users\Lisa Viger\AppData\Local\Temp\1546739382\s5m_install_325.zip (Trojan.Yelloader) -> Delete on reboot. [573822db12b48aac0175a4de39c71ae6]
C:\Users\Lisa Viger\AppData\Local\Temp\1546739382\setup0904.zip (Trojan.Yelloader) -> Delete on reboot. [573822db12b48aac0175a4de39c71ae6]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (162.222.193.86       aoaomo.tremorhub.com) Good: () -> Replace on reboot. [eea185781aacff373b8dfba5986b02fe]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: ( file used by Microsoft TCP/IP for W) Good: () -> Replace on reboot. [414e27d665618ea8f8d0a6face35669a]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (9 Microsoft Corp.
#
# This is ) Good: () -> Replace on reboot. [6629c13c675fc373ecdcbfe138cbe818]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (-2009 Microsoft Corp.
#
# This is) Good: () -> Replace on reboot. [a3ec13eaf0d63cfa84441b856c977f81]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (09 Microsoft Corp.
#
# This i) Good: () -> Replace on reboot. [226d57a6666047ef9830118f748f19e7]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (3-2009 Microsoft Corp.
#
# This is a ) Good: () -> Replace on reboot. [b1de837a1da9fd39c2069a06966d639d]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (icrosoft Corp.
#
# This is a samp) Good: () -> Replace on reboot. [6e21d8251bab63d312b6d0d061a2d828]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (09 Microsoft Corp.
#
# This is a sampl) Good: () -> Replace on reboot. [820d5e9fe9dd2d0910b8ced27a89eb15]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (crosoft Corp.
#
# This is a sample) Good: () -> Replace on reboot. [78177a833393af873e8a267a5ea5e61a]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (188.95.50.62       bobomo.tremorhub.com) Good: () -> Replace on reboot. [d5baec110db9ea4ce4e63a66d42fa15f]
 
Physical Sectors Detected: 0
(No malicious items detected)
 
(end)

And this … 

 

—————————————
Malwarebytes Anti-Rootkit BETA 1.10.3.1001
 
© Malwarebytes Corporation 2011-2012
 
OS version: 10.0.9200 Windows 10 x64
 
Account is Administrative
 
Internet Explorer version: 11.472.17134.0
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, H:\ DRIVE_FIXED, I:\ DRIVE_FIXED
CPU speed: 3.493000 GHz
Memory total: 17108836352, free: 9844064256
 
Downloaded database version: v2019.01.07.03
Downloaded database version: v2019.01.07.03
Downloaded database version: v2018.01.20.01
=======================================
Initializing…
Driver version: 4.3.0.15
———— Kernel report ————
     01/07/2019 08:49:11
———— Loaded modules ———–
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kd.dll
\SystemRoot\system32\mcupdate_AuthenticAMD.dll
\SystemRoot\System32\drivers\msrpc.sys
\SystemRoot\System32\drivers\ksecdd.sys
\SystemRoot\System32\drivers\werkernel.sys
\SystemRoot\System32\drivers\CLFS.SYS
\SystemRoot\System32\drivers\tm.sys
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\System32\drivers\FLTMGR.SYS
\SystemRoot\System32\drivers\clipsp.sys
\SystemRoot\System32\drivers\cmimcext.sys
\SystemRoot\System32\drivers\ntosext.sys
\SystemRoot\system32\CI.dll
\SystemRoot\System32\drivers\cng.sys
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\WppRecorder.sys
\SystemRoot\system32\drivers\SleepStudyHelper.sys
\SystemRoot\System32\Drivers\acpiex.sys
\SystemRoot\system32\drivers\SgrmAgent.sys
\SystemRoot\System32\drivers\ACPI.sys
\SystemRoot\System32\drivers\WMILIB.SYS
\SystemRoot\System32\drivers\intelpep.sys
\SystemRoot\system32\drivers\WindowsTrustedRT.sys
\SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\drivers\msisadrv.sys
\SystemRoot\System32\drivers\pci.sys
\SystemRoot\System32\drivers\vdrvroot.sys
\SystemRoot\system32\drivers\pdc.sys
\SystemRoot\system32\drivers\CEA.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\System32\drivers\spaceport.sys
\SystemRoot\System32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\System32\drivers\storahci.sys
\SystemRoot\System32\drivers\storport.sys
\SystemRoot\System32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Wof.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\amdpsp.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\System32\drivers\wfplwfs.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\System32\drivers\amdkmpfd.sys
\SystemRoot\System32\drivers\volume.sys
\SystemRoot\System32\drivers\volsnap.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\system32\drivers\iorate.sys
\SystemRoot\System32\drivers\disk.sys
\SystemRoot\System32\drivers\CLASSPNP.SYS
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\drivers\cdrom.sys
\SystemRoot\system32\drivers\filecrypt.sys
\SystemRoot\system32\drivers\tbs.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\drivers\vmbkmclr.sys
\SystemRoot\System32\drivers\BasicDisplay.sys
\SystemRoot\System32\drivers\BasicRender.sys
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afunix.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\drivers\vwififlt.sys
\SystemRoot\System32\drivers\pacer.sys
\SystemRoot\system32\drivers\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\System32\drivers\npsvctrig.sys
\SystemRoot\System32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\gpuenergydrv.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\system32\drivers\bam.sys
\SystemRoot\system32\DRIVERS\ahcache.sys
\SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_bcb89b3386563bd7\CompositeBus.sys
\SystemRoot\System32\drivers\kdnic.sys
\SystemRoot\System32\drivers\umbus.sys
\SystemRoot\System32\DriverStore\FileRepository̵076.inf_amd64_f8c797ab08b9d461\B334840\atikmpag.sys
\SystemRoot\System32\DriverStore\FileRepository̵076.inf_amd64_f8c797ab08b9d461\B334840\atikmdag.sys
\SystemRoot\System32\drivers\HDAudBus.sys
\SystemRoot\System32\drivers\portcls.sys
\SystemRoot\System32\drivers\drmk.sys
\SystemRoot\System32\drivers\ks.sys
\SystemRoot\System32\drivers\USBXHCI.SYS
\SystemRoot\system32\drivers\ucx01000.sys
\SystemRoot\System32\drivers\rt640x64.sys
\SystemRoot\system32\DRIVERS\Netwtw06.sys
\SystemRoot\system32\DRIVERS\wdiwifi.sys
\SystemRoot\System32\drivers\vwifibus.sys
\SystemRoot\System32\drivers\AMDPCIDev.sys
\SystemRoot\System32\drivers\serial.sys
\SystemRoot\System32\drivers\serenum.sys
\SystemRoot\System32\drivers\amdppm.sys
\SystemRoot\System32\drivers\amdgpio2.sys
\SystemRoot\System32\Drivers\msgpioclx.sys
\SystemRoot\System32\drivers\wmiacpi.sys
\SystemRoot\System32\drivers\UEFI.sys
\SystemRoot\System32\drivers\NdisVirtualBus.sys
\SystemRoot\System32\DriverStore\FileRepository\swenum.inf_amd64_ea7b19c04e7a8136\swenum.sys
\SystemRoot\System32\drivers\rdpbus.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\System32\drivers\UsbHub3.sys
\SystemRoot\System32\drivers\USBD.SYS
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\System32\drivers\usbccgp.sys
\SystemRoot\System32\drivers\hidusb.sys
\SystemRoot\System32\drivers\HIDCLASS.SYS
\SystemRoot\System32\drivers\HIDPARSE.SYS
\SystemRoot\System32\drivers\kbdhid.sys
\SystemRoot\System32\drivers\kbdclass.sys
\SystemRoot\System32\drivers\mouhid.sys
\SystemRoot\System32\drivers\mouclass.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\win32kfull.sys
\SystemRoot\System32\win32kbase.sys
\SystemRoot\System32\drivers\uaspstor.sys
\SystemRoot\system32\DRIVERS\ibtusb.sys
\SystemRoot\System32\drivers\BTHUSB.sys
\SystemRoot\System32\drivers\bthport.sys
\SystemRoot\System32\drivers\dxgmms2.sys
\SystemRoot\System32\drivers\USBSTOR.SYS
\SystemRoot\System32\drivers\monitor.sys
\SystemRoot\system32\DRIVERS\Microsoft.Bluetooth.Legacy.LEEnumerator.sys
\SystemRoot\System32\drivers\rfcomm.sys
\SystemRoot\System32\drivers\BthEnum.sys
\SystemRoot\System32\drivers\bthpan.sys
\SystemRoot\system32\drivers\BthA2DP.sys
\SystemRoot\system32\drivers\btampm.sys
\SystemRoot\system32\DRIVERS\Microsoft.Bluetooth.AvrcpTransport.sys
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\drivers\wcifs.sys
\SystemRoot\System32\drivers\bthhfenum.sys
\SystemRoot\System32\drivers\BthHfAud.sys
\SystemRoot\system32\DRIVERS\WUDFRd.sys
\SystemRoot\System32\drivers\WpdUpFltr.sys
\SystemRoot\system32\drivers\cldflt.sys
\SystemRoot\system32\drivers\storqosflt.sys
\SystemRoot\System32\Drivers\dump_diskdump.sys
\SystemRoot\System32\Drivers\dump_storahci.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\drivers\lltdio.sys
\SystemRoot\system32\drivers\mslldp.sys
\SystemRoot\system32\drivers\rspndr.sys
\SystemRoot\System32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\ndisuio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\System32\drivers\condrv.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\System32\drivers\vwifimp.sys
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\system32\drivers\mmcss.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\drivers\Ndu.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\drivers\rassstp.sys
\SystemRoot\System32\DRIVERS\NDProxy.sys
\SystemRoot\System32\drivers\AgileVpn.sys
\SystemRoot\System32\drivers\rasl2tp.sys
\SystemRoot\System32\drivers\raspptp.sys
\SystemRoot\System32\drivers\raspppoe.sys
\SystemRoot\System32\DRIVERS\ndistapi.sys
\SystemRoot\System32\drivers\ndiswan.sys
\??\C:\Users\LISAVI~1\AppData\Local\Temp\nvkoazlb.sys
\SystemRoot\System32\drivers\zaksbdwp.sys
\SystemRoot\system32\drivers\hkkknn.sys
\SystemRoot\system32\drivers\xxaaae.sys
\SystemRoot\System32\drivers\rdpvideominiport.sys
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\AtihdWT6.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\7212C7B3.sys
———– End ———–
Done!
Module: \??\C:\Windows\System32\drivers\zaksbdwp.sys could not be loadedModule: \??\C:\Windows\System32\drivers\zaksbdwp.sys could not be loaded
Scan started
Database versions:
  main:    v2019.01.07.03
  rootkit: v2019.01.07.03
 
<<<2>>>
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xffffac82585fd060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffac82584c59d0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffac82585fd060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
DevicePointer: 0xffffac8258586060, DeviceName: \Device\00000028\, DriverName: \Driver\storahci\
———— End ———-
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers…
File user open failed: C:\WINDOWS\SYSTEM32\drivers\zaksbdwp.sys (0x00000005)
File kernel read failed: C:\WINDOWS\SYSTEM32\drivers\zaksbdwp.sys
Done!
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffac82585fe060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffac82584c69d0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffac82585fe060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffac8258588060, DeviceName: \Device\00000027\, DriverName: \Driver\storahci\
———— End ———-
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 0
Scanning MBR on drive 0…
Inspecting partition table:
This drive is a GPT Drive.
MBR Signature: 55AA
Disk Signature: 0
 
GPT Protective MBR Partition information:
 
    Partition 0 type is EFI-GPT (0xee)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 1  Numsec = 4294967295
 
    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
GPT Partition information:
 
    GPT Header Signature 4546492050415254
    GPT Header Revision 65536 Size 92 CRC 2546263203
    GPT Header CurrentLba = 1 BackupLba 3907029167
    GPT Header FirstUsableLba 34  LastUsableLba 3907029134
    GPT Header Guid ad83e2b9-dbd6-4051-b6e5-af5a9fabe597
    GPT Header Contains 128 partition entries starting at LBA 2
    GPT Header Partition entry size = 128
 
    Backup GPT header Signature 4546492050415254
    Backup GPT header Revision 65536 Size 92 CRC 2546263203
    Backup GPT header CurrentLba = 3907029167 BackupLba 1
    Backup GPT header FirstUsableLba 34  LastUsableLba 3907029134
    Backup GPT header Guid ad83e2b9-dbd6-4051-b6e5-af5a9fabe597
    Backup GPT header Contains 128 partition entries starting at LBA 3907029135
    Backup GPT header Partition entry size = 128
 
    Partition 0 Type e3c9e316-b5c-4db8-817d-f92df0215ae
    Partition ID cd2ad597-3703-4c0e-ac36-2e16595e37b
    FirstLBA 34  Last LBA 32767
    Attributes 0
    Partition Name         Microsoft reserved partition
 
    Partition 1 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
    Partition ID 24eb1111-25ae-47a2-b9b8-f37b195edd5b
    FirstLBA 32768  Last LBA 3907026943
    Attributes 0
    Partition Name                 Basic data partition
 
Disk Size: 2000398934016 bytes
Sector size: 512 bytes
 
Done!
Drive 1
This is a System drive
Scanning MBR on drive 1…
Inspecting partition table:
This drive is a GPT Drive.
MBR Signature: 55AA
Disk Signature: B5B2DF75
 
GPT Protective MBR Partition information:
 
    Partition 0 type is EFI-GPT (0xee)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 1  Numsec = 4294967295
 
    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
GPT Partition information:
 
    GPT Header Signature 4546492050415254
    GPT Header Revision 65536 Size 92 CRC 1297587749
    GPT Header CurrentLba = 1 BackupLba 468877311
    GPT Header FirstUsableLba 34  LastUsableLba 468877278
    GPT Header Guid 7cb143b7-bbc0-4fda-995d-a12fdd3be731
    GPT Header Contains 128 partition entries starting at LBA 2
    GPT Header Partition entry size = 128
 
    Backup GPT header Signature 4546492050415254
    Backup GPT header Revision 65536 Size 92 CRC 1297587749
    Backup GPT header CurrentLba = 468877311 BackupLba 1
    Backup GPT header FirstUsableLba 34  LastUsableLba 468877278
    Backup GPT header Guid 7cb143b7-bbc0-4fda-995d-a12fdd3be731
    Backup GPT header Contains 128 partition entries starting at LBA 468877279
    Backup GPT header Partition entry size = 128
 
    Partition 0 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
    Partition ID e116be19-363f-4834-a012-f079c5d9b88e
    FirstLBA 2048  Last LBA 923647
    Attributes 1
    Partition Name                 Basic data partition
 
    Partition 1 Type c12a7328-f81f-11d2-ba4b-0a0c93ec93b
    Partition ID a82ba7d8-f8b3-4815-8f9b-b63a7e1b767d
    FirstLBA 923648  Last LBA 1128447
    Attributes 0
    Partition Name                 EFI system partition
 
    GPT Partition 1 is bootable
    Partition 2 Type e3c9e316-b5c-4db8-817d-f92df0215ae
    Partition ID 26110d42-f035-4a70-918c-dd358b64bdb4
    FirstLBA 1128448  Last LBA 1161215
    Attributes 0
    Partition Name         Microsoft reserved partition
 
    Partition 3 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
    Partition ID 5597a24a-2fee-4713-93bd-873ee9a1c347
    FirstLBA 1161216  Last LBA 468875263
    Attributes 0
    Partition Name                 Basic data partition
 
Disk Size: 240065183744 bytes
Sector size: 512 bytes
 
Done!
Physical Sector Size: 512
Drive: 2, DevicePointer: 0xffffac825982b060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffac825982d9d0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffac825982b060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
DevicePointer: 0xffffac8258fe0060, DeviceName: \Device\00000046\, DriverName: \Driver\UASPStor\
———— End ———-
Alternate DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 2
Scanning MBR on drive 2…
Inspecting partition table:
This drive is a GPT Drive.
MBR Signature: 55AA
Disk Signature: 9FBC85AD
 
GPT Protective MBR Partition information:
 
    Partition 0 type is EFI-GPT (0xee)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 1  Numsec = 4294967295
 
    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
GPT Partition information:
 
    GPT Header Signature 4546492050415254
    GPT Header Revision 65536 Size 92 CRC 57565777
    GPT Header CurrentLba = 1 BackupLba 9767541166
    GPT Header FirstUsableLba 34  LastUsableLba 9767541133
    GPT Header Guid 3db421eb-e695-4ecc-bff8-6e6f62e1290
    GPT Header Contains 128 partition entries starting at LBA 2
    GPT Header Partition entry size = 128
 
    Backup GPT header Signature 4546492050415254
    Backup GPT header Revision 65536 Size 92 CRC 57565777
    Backup GPT header CurrentLba = 9767541166 BackupLba 1
    Backup GPT header FirstUsableLba 34  LastUsableLba 9767541133
    Backup GPT header Guid 3db421eb-e695-4ecc-bff8-6e6f62e1290
    Backup GPT header Contains 128 partition entries starting at LBA 9767541134
    Backup GPT header Partition entry size = 128
 
    Partition 0 Type e3c9e316-b5c-4db8-817d-f92df0215ae
    Partition ID 5287c07a-5252-4d04-bbe6-907d4e61e481
    FirstLBA 34  Last LBA 262177
    Attributes 0
    Partition Name         Microsoft reserved partition
 
    Partition 1 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
    Partition ID 6a8742c5-d4ca-48bb-9e94-9a22e392ce17
    FirstLBA 264192  Last LBA 9767540735
    Attributes 0
    Partition Name                 Basic data partition
 
Disk Size: 5000981077504 bytes
Sector size: 512 bytes
 
Done!
Physical Sector Size: 512
Drive: 3, DevicePointer: 0xffffac8258cf0060, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffac8258cdf9d0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffac8258cf0060, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
DevicePointer: 0xffffac8259520060, DeviceName: \Device\0000004b\, DriverName: \Driver\USBSTOR\
———— End ———-
Alternate DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 3
Scanning MBR on drive 3…
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 0
 
Partition information:
 
    Partition 0 type is Other (0xc)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 8192  Numsec = 62325760
    Partition is not bootable
    Partition file system is FAT32
 
    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable
 
    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable
 
    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable
 
Disk Size: 31914983424 bytes
Sector size: 512 bytes
 
Done!
Physical Sector Size: 0
Drive: 4, DevicePointer: 0xffffac8259599060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffac82595972d0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffac8259599060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\
DevicePointer: 0xffffac8258cf8060, DeviceName: \Device\0000004c\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 5, DevicePointer: 0xffffac8259596060, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffac8259594040, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffac8259596060, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\
DevicePointer: 0xffffac8258cf6b10, DeviceName: \Device\0000004d\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 6, DevicePointer: 0xffffac8259595060, DeviceName: \Device\Harddisk6\DR6\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffac82595949d0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffac8259595060, DeviceName: \Device\Harddisk6\DR6\, DriverName: \Driver\Disk\
DevicePointer: 0xffffac8258cf4060, DeviceName: \Device\0000004e\, DriverName: \Driver\USBSTOR\
———— End ———-
Infected: C:\Users\Lisa Viger\AppData\Local\sfciwu.dll –> [Trojan.ProxyAgent]
Infected: HKU\S-1-5-21-833294152-1074476770-1006749115-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|sfciwu –> [Trojan.ProxyAgent]
Infected: C:\Users\Lisa Viger\AppData\Local\sfciwu.dll –> [Trojan.ProxyAgent]
Infected: C:\Program Files (x86)\minstrelsy\cringing.exe –> [Adware.DotDo.Generic]
Infected: HKU\S-1-5-21-833294152-1074476770-1006749115-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|cringing –> [Adware.DotDo.Generic]
Infected: C:\Program Files (x86)\minstrelsy\cringing.exe –> [Adware.DotDo.Generic]
Infected: C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs –> [Trojan.Injector]
Infected: HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WinResSync –> [Trojan.Injector]
Infected: HKU\S-1-5-21-833294152-1074476770-1006749115-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WinResSync –> [Trojan.Injector]
Infected: HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|WinResSync –> [Trojan.Injector]
Infected: HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WinResSync –> [Trojan.Injector]
Infected: HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|WinResSync –> [Trojan.Injector]
File "C:\Users\Lisa Viger\AppData\Local\D3DSCache\45a5e5b635b28e7a\52264C4C-172F-41B9-91B8-7F0C3B1E9021_VEN_1002&DEV_67DF&SUBSYS_C570&REV_EF.val" is compressed (flags = 1)
File "C:\Users\Lisa Viger\AppData\Local\D3DSCache\643ef9f3b699fd42\52264C4C-172F-41B9-91B8-7F0C3B1E9021_VEN_1002&DEV_67DF&SUBSYS_C570&REV_EF.val" is compressed (flags = 1)
File "C:\Users\Lisa Viger\AppData\Local\D3DSCache\d1045fa42060dcaf\52264C4C-172F-41B9-91B8-7F0C3B1E9021_VEN_1002&DEV_67DF&SUBSYS_C570&REV_EF.val" is compressed (flags = 1)
Infected: C:\Users\Lisa Viger\AppData\Local\Temp\1546739382\s5m_install_325.exe –> [Trojan.Clicker]
Infected: C:\Users\Lisa Viger\AppData\Local\Temp\1546739382\setup0904.exe –> [Adware.Clicker]
File "C:\Windows\System32\config\systemprofile\AppData\Local\DataSharing\Storage\DSTokenDB2.dat" is sparse (flags = 32768)
Infected: C:\Windows\guttural.exe –> [Adware.DotDo.Generic.TskLnk]
Infected: C:\ProgramData\1546739382\s9.zip.download –> [Trojan.Yelloader.Gen]
Infected: C:\ProgramData\1546739382 –> [Trojan.Yelloader.Gen]
Infected: C:\ProgramData\Blogger\Blogger.exe –> [Trojan.Agent]
Infected: HKU\S-1-5-21-833294152-1074476770-1006749115-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Blogger –> [Trojan.Agent]
Infected: C:\ProgramData\Blogger –> [Trojan.Agent]
Infected: C:\Users\Lisa Viger\AppData\Local\Temp\1546739382\s5m_install_325.zip –> [Trojan.Yelloader]
Infected: C:\Users\Lisa Viger\AppData\Local\Temp\1546739382 –> [Trojan.Yelloader]
Infected: C:\Users\Lisa Viger\AppData\Local\Temp\1546739382\setup0904.zip –> [Trojan.Yelloader]
Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINDOWSMANAGEMENTSERVICE|ImagePath –> [Trojan.Yelloader]
Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINDOWSMANAGEMENTSERVICE –> [Trojan.Yelloader]
Infected: C:\Windows\System32\drivers\etc\hosts –> [Hijack.Host]
Infected: C:\Windows\System32\drivers\etc\hosts –> [Hijack.Host]
Infected: C:\Windows\System32\drivers\etc\hosts –> [Hijack.Host]
Infected: C:\Windows\System32\drivers\etc\hosts –> [Hijack.Host]
Infected: C:\Windows\System32\drivers\etc\hosts –> [Hijack.Host]
Infected: C:\Windows\System32\drivers\etc\hosts –> [Hijack.Host]
Infected: C:\Windows\System32\drivers\etc\hosts –> [Hijack.Host]
Infected: C:\Windows\System32\drivers\etc\hosts –> [Hijack.Host]
Infected: C:\Windows\System32\drivers\etc\hosts –> [Hijack.Host]
Infected: C:\Windows\System32\drivers\etc\hosts –> [Hijack.Host]
Scan finished
Creating System Restore point…
Could not create restore point…
Cleaning up…
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================
 
 
—————————————
Malwarebytes Anti-Rootkit BETA 1.10.3.1001
 
© Malwarebytes Corporation 2011-2012
 
OS version: 10.0.9200 Windows 10 x64
 
Account is Administrative
 
Internet Explorer version: 11.472.17134.0
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, H:\ DRIVE_FIXED, I:\ DRIVE_FIXED
CPU speed: 3.493000 GHz
Memory total: 17108836352, free: 8730619904
 
=======================================
Please download the Malwarebytes Anti-Malware setup file to your Desktop.

OR from this location Here
  • Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme.
  • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
  • After the installation IS complete let it update if it asks.
  • Under SETTINGS…..PROTECTION tick Scan for rootkits and make sure AUTOMATIC QUARANTINE is on.
  • Then go to the Dashboard and click on SCAN NOW
  • If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
    Upon completion of the scan (or after the reboot), click the Reports tab.
    Double-click the Scan Log.
    At the bottom click Export and choose Text file.

    Save the file to your desktop and include its content in your next reply.

    You can access the logs by going in the "Reports" tab, clicking on the latest "Scan" entry (the one with detections), then clicking on the "Export" button in the bottom-left corner and select "Copy to clipboard". After that, all you have to do is paste it here
  • Then click on POST
  • Exit Malwarebytes
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


[external image: RQKuhw1.png]RogueKiller
  • Download the right version of RogueKiller for your Windows version (32 or 64-bit)
  • Once done, move the executable file to your Desktop, right-click on it and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
  • Wait for the scan to complete
  • On completion, the results will be displayed
  • Check every single entry (threat found), and click on the Remove Selected button
  • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
  • This will open the report in Notepad. Copy/paste its content in your next reply
***
Next
I'd like to see a fresh Farbar Recovery Scan Tool logs
  • Right-Click FRST.exe / FRST64.exe and select [external image: AVOiBNU.jpg]Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.

    please post these 4 logs when finished.
Malwarebytes Anti-Rootkit BETA 1.10.3.1001
www.malwarebytes.org
 
Database version:
  main:    v2019.01.07.03
  rootkit: v2019.01.07.03
 
Windows 10 x64 NTFS
Internet Explorer 11.472.17134.0
Lisa Viger :: LISAS-DESKTOP [administrator]
 
1/7/2019 8:49:15 AM
mbar-log-2019-01-07 (08-49-15).txt
 
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 175343
Time elapsed: 5 minute(s), 10 second(s)
 
Memory Processes Detected: 1
C:\Program Files (x86)\minstrelsy\cringing.exe (Adware.DotDo.Generic) -> 14024 -> Delete on reboot. [e3acc439a026f442f2acd62620e16799]
 
Memory Modules Detected: 1
C:\Users\Lisa Viger\AppData\Local\sfciwu.dll (Trojan.ProxyAgent) -> Delete on reboot. [bad5ad50e6e0290d6a2f8fc9946f9a66]
 
Registry Keys Detected: 1
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINDOWSMANAGEMENTSERVICE (Trojan.Yelloader) -> Delete on reboot. [d7b8d42955718ea8b901707a0af68080]
 
Registry Values Detected: 9
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|sfciwu (Trojan.ProxyAgent) -> Data: rundll32.exe "C:\Users\Lisa Viger\AppData\Local\sfciwu.dll",sfciwu -> Delete on reboot. [bad5ad50e6e0290d6a2f8fc9946f9a66]
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|cringing (Adware.DotDo.Generic) -> Data: "C:\Program Files (x86)\minstrelsy\cringing.exe" azawjwazawjwazawjwazawj.azawjjazawjrazawjhazawj.azawjpazawjwazawj/azawjy2s0s1s9s0azawjsl1sl0y5ysazawjhtml0LF8scazawjyQUIlpIwnTazawjhLg0 -> Delete on reboot. [e3acc439a026f442f2acd62620e16799]
HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WinResSync (Trojan.Injector) -> Data: C:\Windows\system32\regsvr32.exe /s "C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs" -> Delete on reboot. [0a85bd40477f3105c815946f60a39c64]
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WinResSync (Trojan.Injector) -> Data: C:\Windows\system32\regsvr32.exe /s "C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs" -> Delete on reboot. [0a85bd40477f3105c815946f60a39c64]
HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|WinResSync (Trojan.Injector) -> Data: C:\Windows\system32\regsvr32.exe /s "C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs" -> Delete on reboot. [0a85bd40477f3105c815946f60a39c64]
HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WinResSync (Trojan.Injector) -> Data: C:\Windows\system32\regsvr32.exe /s "C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs" -> Delete on reboot. [0a85bd40477f3105c815946f60a39c64]
HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|WinResSync (Trojan.Injector) -> Data: C:\Windows\system32\regsvr32.exe /s "C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs" -> Delete on reboot. [0a85bd40477f3105c815946f60a39c64]
HKU\S-1-5-21-833294152-1074476770-1006749115-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Blogger (Trojan.Agent) -> Data: C:\ProgramData\Blogger\Blogger.exe -> Delete on reboot. [ace311ec5670e353c5b582b91fe1e11f]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINDOWSMANAGEMENTSERVICE|ImagePath (Trojan.Yelloader) -> Data: windowsmanagementservice -> Delete on reboot. [d7b8d42955718ea8b901707a0af68080]
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 3
C:\ProgramData\1546739382 (Trojan.Yelloader.Gen) -> Delete on reboot. [d6b98776c2041e1845d60237a0608b75]
C:\ProgramData\Blogger (Trojan.Agent) -> Delete on reboot. [ace311ec5670e353c5b582b91fe1e11f]
C:\Users\Lisa Viger\AppData\Local\Temp\1546739382 (Trojan.Yelloader) -> Delete on reboot. [573822db12b48aac0175a4de39c71ae6]
 
Files Detected: 20
C:\Users\Lisa Viger\AppData\Local\sfciwu.dll (Trojan.ProxyAgent) -> Delete on reboot. [bad5ad50e6e0290d6a2f8fc9946f9a66]
C:\Program Files (x86)\minstrelsy\cringing.exe (Adware.DotDo.Generic) -> Delete on reboot. [e3acc439a026f442f2acd62620e16799]
C:\Users\Lisa Viger\AppData\Roaming\Microsoft\Protect\d65561-c2a2f1-61c12560-d5fec0-d1a0.rs (Trojan.Injector) -> Delete on reboot. [0a85bd40477f3105c815946f60a39c64]
C:\Users\Lisa Viger\AppData\Local\Temp\1546739382\s5m_install_325.exe (Trojan.Clicker) -> Delete on reboot. [503f30cd9531e056f6ce41a062a0fd03]
C:\Users\Lisa Viger\AppData\Local\Temp\1546739382\setup0904.exe (Adware.Clicker) -> Delete on reboot. [602fc934fbcbde58a6e0a349fe0355ab]
C:\Windows\guttural.exe (Adware.DotDo.Generic.TskLnk) -> Delete on reboot. [7a150af34d793afc75bb2ff29a68b749]
C:\ProgramData\1546739382\s9.zip.download (Trojan.Yelloader.Gen) -> Delete on reboot. [d6b98776c2041e1845d60237a0608b75]
C:\ProgramData\Blogger\Blogger.exe (Trojan.Agent) -> Delete on reboot. [ace311ec5670e353c5b582b91fe1e11f]
C:\Users\Lisa Viger\AppData\Local\Temp\1546739382\s5m_install_325.zip (Trojan.Yelloader) -> Delete on reboot. [573822db12b48aac0175a4de39c71ae6]
C:\Users\Lisa Viger\AppData\Local\Temp\1546739382\setup0904.zip (Trojan.Yelloader) -> Delete on reboot. [573822db12b48aac0175a4de39c71ae6]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (162.222.193.86       aoaomo.tremorhub.com) Good: () -> Replace on reboot. [eea185781aacff373b8dfba5986b02fe]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: ( file used by Microsoft TCP/IP for W) Good: () -> Replace on reboot. [414e27d665618ea8f8d0a6face35669a]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (9 Microsoft Corp.
#
# This is ) Good: () -> Replace on reboot. [6629c13c675fc373ecdcbfe138cbe818]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (-2009 Microsoft Corp.
#
# This is) Good: () -> Replace on reboot. [a3ec13eaf0d63cfa84441b856c977f81]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (09 Microsoft Corp.
#
# This i) Good: () -> Replace on reboot. [226d57a6666047ef9830118f748f19e7]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (3-2009 Microsoft Corp.
#
# This is a ) Good: () -> Replace on reboot. [b1de837a1da9fd39c2069a06966d639d]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (icrosoft Corp.
#
# This is a samp) Good: () -> Replace on reboot. [6e21d8251bab63d312b6d0d061a2d828]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (09 Microsoft Corp.
#
# This is a sampl) Good: () -> Replace on reboot. [820d5e9fe9dd2d0910b8ced27a89eb15]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (crosoft Corp.
#
# This is a sample) Good: () -> Replace on reboot. [78177a833393af873e8a267a5ea5e61a]
C:\Windows\System32\drivers\etc\hosts (Hijack.Host) -> Bad: (188.95.50.62       bobomo.tremorhub.com) Good: () -> Replace on reboot. [d5baec110db9ea4ce4e63a66d42fa15f]
 
Physical Sectors Detected: 0
(No malicious items detected)
 
(end)
RogueKiller Anti-Malware V13.0.21.0 (x64) [Jan  7 2019] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.17134) 64 bits
Started in : Normal mode
User : Lisa Viger [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Standard Scan, Delete – Date : 2019/01/08 07:47:35 (Duration : 00:05:11)
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[Bad.Extension (Malicious)] lsihrkzsvc.exe – %SystemRoot%\System32\lsihrkzsvc.exe -> Killed [DrvNtTerm]
[Suspicious.Path (Potentially Malicious)] tiskhnu.exe – %localappdata%\tiskhnu\tiskhnu.exe -> Killed [TermThr]
[Suspicious.Path (Potentially Malicious)] sccwtzr.exe – %localappdata%\tiskhnu\sccwtzr.exe -> 
[Suspicious.Path (Potentially Malicious)] sccwtzr.exe – %localappdata%\tiskhnu\sccwtzr.exe -> 
[Suspicious.Path (Potentially Malicious)] sccwtzr.exe – %localappdata%\tiskhnu\sccwtzr.exe -> 
[Suspicious.Path (Potentially Malicious)] sccwtzr.exe – %localappdata%\tiskhnu\sccwtzr.exe -> 
[Suspicious.Path (Potentially Malicious)] sccwtzr.exe – %localappdata%\tiskhnu\sccwtzr.exe -> 
[Suspicious.Path (Potentially Malicious)] zbckxrmo – %SystemDrive%\Users\LISAVI~1\AppData\Local\Temp\nvkoazlb.sys -> Stopped
[Suspicious.Path (Potentially Malicious)] \chording unwisely harewood – C:\Users\Lisa Viger\AppData\Local\Rathman.exe (azawjwazawjwazawjwazawj.azawjjazawjrazawjhazawj.azawjpazawjwazawj/azawjy2s0s1s9s0azawjsl1sl0y5ysazawjhtml0LF8scazawjyQUIlpIwnTazawjhLg0) -> Deleted
[Suspicious.Path (Potentially Malicious)] \chording unwisely harewoodchording unwisely harewood – C:\Users\Lisa Viger\AppData\Local\Rathman.exe (azawjwazawjwazawjwazawj.azawjjazawjrazawjhazawj.azawjpazawjwazawj/azawjy2s0s1s9s0azawjsl1sl0y5ysazawjhtml0LF8scazawjyQUIlpIwnTazawjhLg0) -> Deleted
[Suspicious.Path (Potentially Malicious)] \nashville_asian – C:\Users\Lisa Viger\AppData\Local\Winds.exe (azawjwazawjwazawjwazawj.azawjjazawjrazawjhazawj.azawjpazawjwazawj/azawjy2s0s1s9s0azawjsl1sl0y5ysazawjhtml0LF8scazawjyQUIlpIwnTazawjhLg0) -> Deleted
[Suspicious.Path (Potentially Malicious)] \nashville_asiannashville_asian – C:\Users\Lisa Viger\AppData\Local\Winds.exe (azawjwazawjwazawjwazawj.azawjjazawjrazawjhazawj.azawjpazawjwazawj/azawjy2s0s1s9s0azawjsl1sl0y5ysazawjhtml0LF8scazawjyQUIlpIwnTazawjhLg0) -> Deleted
[PUP.Gen1 (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\xs –  -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zbckxrmo – [%SystemDrive%\Users\LISAVI~1\AppData\Local\Temp\nvkoazlb.sys] -> Deleted

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI