Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-11-2021 Ran by marcyandmatt (administrator) on MARCYANDMATT (28-11-2021 21:57:14) Running from C:\Users\Kitchen PC\Desktop Loaded Profiles: marcyandmatt Platform: Microsoft Windows 10 Home Version 21H1 19043.1348 (X64) Language: English (United States) Default browser: Chrome Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe <4> (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe (Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\EpicWebHelper.exe <2> (Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <14> (Microsoft Corporation -> Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDAppHost.exe (Microsoft Corporation -> Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDExtHost.exe (Microsoft Corporation -> Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDRuntimeHost.exe (Microsoft Corporation -> Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDSurrogateHost.exe (Microsoft Corporation -> Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe <2> (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_253e24b785ea60ca\Display.NvContainer\NVDisplay.Container.exe <2> (Samsung Electronics Co., Ltd. -> Samsung Electronics) C:\ProgramData\Samsung Apps\Portable SSD\SamsungPortableSSDMon.exe (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7> (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [134936 2021-10-04] (Avast Software s.r.o. -> AVAST Software) HKLM-x32\...\Run: [BingDesktop] => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2369240 2015-10-20] (Microsoft Corporation -> Microsoft Corp.) HKLM-x32\...\Run: [REDRAGON M711 Gaming Mouse] => C:\Program Files (x86)\REDRAGON M711 Gaming Mouse\hid.exe [965120 2019-03-25] () [File not signed] HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-323964869-3011789935-2468043319-1000\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [33529824 2021-11-17] (Epic Games Inc. -> Epic Games, Inc.) HKU\S-1-5-21-323964869-3011789935-2468043319-1000\...\Run: [HP ENVY 5540 series (NET)] => C:\Program Files\HP\HP ENVY 5540 series\Bin\ScanToPCActivationApp.exe [3770504 2017-03-27] (Hewlett Packard -> HP Inc.) HKLM\...\Windows x64\Print Processors\hpfpp70v: C:\Windows\System32\spool\prtprocs\x64\hpfpp70v.dll [248320 2009-04-16] (Hewlett-Packard Corporation) [File not signed] HKLM\...\Windows x64\Print Processors\hpzpplhn: C:\Windows\System32\spool\prtprocs\x64\hpzpplhn.dll [99840 2008-05-07] (Hewlett-Packard Corporation) [File not signed] HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [53656 2010-10-25] (Adobe Systems, Incorporated -> Adobe Systems Inc) HKLM\...\Print\Monitors\HP CE11 Status Monitor: C:\Windows\system32\hpinkstsCE11LM.dll [393352 2017-03-19] (Hewlett Packard -> HP Inc.) HKLM\...\Print\Monitors\hpf3l70v.dll: C:\Windows\system32\hpf3l70v.dll [136704 2009-04-16] (Hewlett-Packard Company) [File not signed] HKLM\...\Print\Monitors\PCL hpz3llhn: C:\Windows\system32\hpz3llhn.dll [34816 2008-05-07] (Hewlett-Packard Company) [File not signed] HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\96.0.4664.45\Installer\chrmstp.exe [2021-11-19] (Google LLC -> Google LLC) HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> "C:\Program Files (x86)\AVAST Software\Browser\Application\86.1.6960.198\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] -> HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {09F66E8E-9F66-43CB-ADE6-83CF970DDC10} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) (No File) Task: {15E4A690-A6D4-4421-A45F-63AFE737E532} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe -PvrRecoveryTask (No File) Task: {18DF3753-78B7-4FC3-9D71-2BEB462702DC} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1562376 2021-08-16] (Adobe Inc. -> Adobe Inc.) Task: {25E9B3AB-16B0-42C4-AE47-527E6C0D8375} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {27BB8114-A96C-4EE2-A3F1-41606BF9A7F8} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe /RestartRecording (No File) Task: {2D268147-9A45-4E5A-BDFE-C7314F5089CB} - \Microsoft\Windows\Setup\gwx\rundetector -> No File <==== ATTENTION Task: {2F1D79DD-EF31-4521-84D9-5E5B16334318} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {3532DA2F-BD4F-400F-A2B3-1843DA603006} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) (No File) Task: {450B94F7-3123-4C47-89AC-63E69AAE9EAC} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION Task: {45DC1F49-359A-4E05-9EC0-E3FC1052C113} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316} Task: {470FAF02-F985-4F8F-B4FB-0E994C8E96C5} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe /PBDADiscovery (No File) Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47C2-B62A-B7C4CED925CB} Task: {4A4C3CC9-3381-4520-A58C-76767825D7B9} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe /OCURActivate (No File) Task: {4FAEEF82-E64B-4D2A-B2CC-B7F33137CDE7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {5103ED3B-BE22-4C0D-9BE2-7425186AD8C4} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe /DoActivateWindowsSearch (No File) Task: {593BE672-3D5E-4AEB-86D6-26D232CE92B4} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A} Task: {5D1C52D8-6C86-444F-8C17-DF7EA613FD8E} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe /DoConfigureInternetTimeService (No File) Task: {617F01F5-DD3F-48B2-9E9D-757C3A3E34B4} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe /DoReindexSearchRoot (No File) Task: {64A7A34F-1F69-49B7-B92A-AF2CA22E1F38} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe -MediaCenterRecoveryTask (No File) Task: {670936F4-6FDA-496A-A0B6-A691BE75E542} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {73F52A01-4331-48E7-A1C1-ED1F27D3A927} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2016-05-13] (Google Inc -> Google Inc.) Task: {8238DA5C-04A2-4F7D-A63C-F8B40D82D799} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-16] (Piriform Software Ltd -> Piriform Ltd) Task: {83BC47FA-B153-4096-B80E-78676D663CBB} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe -PvrSchedule (No File) Task: {865DBC54-E8B3-4BA4-B71D-7CCD1B6DBB8B} - System32\Tasks\Samsung_PSSD_Registration => C:\ProgramData\Samsung Apps\Portable SSD\SamsungPortableSSDMon.exe [497752 2021-11-06] (Samsung Electronics Co., Ltd. -> Samsung Electronics) Task: {93A8F4C8-2A39-4BE5-B9BD-39EFC26E4EF2} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe -pscn 0 (No File) Task: {A069E548-4EE0-479E-A7CC-BCE756521ADF} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969} Task: {A1E615EF-633A-4C79-81E1-CAB74FC7C3D9} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1} Task: {A420A222-ACAC-4D89-980F-7D9B47B38CA1} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs (No File) Task: {AFC5FE57-81B9-4C25-BAD9-AEC7F5844D41} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-16] (Piriform Software Ltd -> Piriform Software Ltd) Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371} Task: {B46A18B7-661B-4B02-BA02-CF812A9945C0} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1} Task: {B80D8339-9C1D-402B-BD1F-453402D7EDCA} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe -ObjectStoreRecoveryTask (No File) Task: {B8796AE0-90FD-43E5-B555-5ECB3929FE16} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) (No File) Task: {BE2BABA2-A596-4F21-9C60-5A744E1AF8D6} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [4974872 2021-11-17] (Avast Software s.r.o. -> AVAST Software) Task: {BEB54045-7B75-4522-9266-FDF47C5C9E4B} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61} Task: {BEBCF221-111B-416C-8DF5-F0A098796A93} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe /DRMInit (No File) Task: {CFA9EF1F-9846-46C8-A757-D88E3BC3FB05} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1790184 2021-04-29] (Avast Software s.r.o. -> Avast Software) Task: {D33448E1-CADF-4340-AA19-AE6F7F3A337B} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {D3A5BFBF-79F9-4EF5-8C4A-BA2BE99D6B59} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery (No File) Task: {D5BE3CE4-4683-42E2-B82C-37DFBE43C083} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery (No File) Task: {D7BA15AD-BCEC-48BC-BEB8-50EAB2FBBFD5} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E} Task: {DFA72E33-E607-4CAE-8ABE-F7EA6F8C62CB} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) (No File) Task: {E35D1A64-D942-47F1-958F-BBAB1CFD4B12} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe $(Arg0) (No File) Task: {E38610CF-75D9-4F64-94ED-AEB193BE52BF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2016-05-13] (Google Inc -> Google Inc.) Task: {E5491616-7385-42A6-A25F-455BB414C697} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) (No File) Task: {FBF27397-2298-4250-9918-0506423498C4} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe -SqlLiteRecoveryTask (No File) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76 Tcpip\..\Interfaces\{cb725f84-7279-4851-b4d4-f3f37e21d841}: [DhcpNameServer] 75.75.75.75 75.75.76.76 Tcpip\..\Interfaces\{CDB24927-9B46-4C22-B91E-09C04B037F3A}: [DhcpNameServer] 192.168.1.1 Edge: ======= Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found] Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found] Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found] Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found] Edge DefaultProfile: Default Edge Profile: C:\Users\Kitchen PC\AppData\Local\Microsoft\Edge\User Data\Default [2021-11-01] FireFox: ======== FF ProfilePath: C:\Users\Kitchen PC\AppData\Roaming\Mozilla\Firefox\Profiles\h4ql1auo.default-1422069087404 [2021-08-24] FF Homepage: Mozilla\Firefox\Profiles\h4ql1auo.default-1422069087404 -> hxxps://www.miniclip.com/games/8-ball-pool-multiplayer/en/ FF Extension: (Avast SafePrice | Comparison, deals, coupons) - C:\Users\Kitchen PC\AppData\Roaming\Mozilla\Firefox\Profiles\h4ql1auo.default-1422069087404\Extensions\sp@avast.com.xpi [2021-11-28] FF Extension: (Avast Online Security) - C:\Users\Kitchen PC\AppData\Roaming\Mozilla\Firefox\Profiles\h4ql1auo.default-1422069087404\Extensions\wrc@avast.com.xpi [2018-07-08] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2017-06-22] [Legacy] [not signed] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll [2017-03-14] (Adobe Systems Incorporated -> ) FF Plugin: @java.com/DTPlugin,version=11.92.2 -> C:\Program Files\Java\jre1.8.0_92\bin\dtplugin\npDeployJava1.dll [2016-06-29] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.92.2 -> C:\Program Files\Java\jre1.8.0_92\bin\plugin2\npjp2.dll [2016-06-29] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll [2017-03-14] (Adobe Systems Incorporated -> ) FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-06-29] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-06-29] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-10-05] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR DefaultProfile: Profile 1 CHR Profile: C:\Users\Kitchen PC\AppData\Local\Google\Chrome\User Data\Default [2017-06-16] CHR HomePage: Default -> hxxp://www.google.com/ CHR StartupUrls: Default -> "hxxps://mail.google.com/mail/u/0/#inbox" CHR Profile: C:\Users\Kitchen PC\AppData\Local\Google\Chrome\User Data\Guest Profile [2021-08-24] CHR Profile: C:\Users\Kitchen PC\AppData\Local\Google\Chrome\User Data\Profile 1 [2021-11-28] CHR Notifications: Profile 1 -> hxxps://calendar.google.com; hxxps://captchamodern.top; hxxps://drive.google.com; hxxps://mail.google.com; hxxps://matrix-news.org; hxxps://skillshare.pissedconsumer.com; hxxps://www.ae.com; hxxps://www.facebook.com CHR HomePage: Profile 1 -> hxxp://www.google.com/ CHR StartupUrls: Profile 1 -> "hxxp://google.com/" CHR Extension: (Google Drive) - C:\Users\Kitchen PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-24] CHR Extension: (YouTube) - C:\Users\Kitchen PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-27] CHR Extension: (Google Docs Offline) - C:\Users\Kitchen PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-10-19] CHR Extension: (Avast Online Security & Privacy) - C:\Users\Kitchen PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2021-10-27] CHR Extension: (Google Play Music) - C:\Users\Kitchen PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg [2016-09-27] CHR Extension: (Chrome Web Store Payments) - C:\Users\Kitchen PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-28] CHR Extension: (Gmail) - C:\Users\Kitchen PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22] CHR Profile: C:\Users\Kitchen PC\AppData\Local\Google\Chrome\User Data\System Profile [2021-09-29] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-08-16] (Adobe Inc. -> Adobe Inc.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-04-03] (Apple Inc. -> Apple Inc.) S2 AsusUpdateCheck; C:\WINDOWS\System32\AsusUpdateCheck.exe [768408 2021-11-12] (ASUSTeK Computer Inc. -> ) R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [8323664 2021-10-04] (Avast Software s.r.o. -> AVAST Software) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [630040 2021-10-04] (Avast Software s.r.o. -> AVAST Software) R2 avast! Tools; C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe [377624 2021-10-04] (Avast Software s.r.o. -> AVAST Software) R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [56912 2021-06-02] (Avast Software s.r.o. -> AVAST Software) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8901968 2021-02-24] (BattlEye Innovations e.K. -> ) S2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173784 2015-10-20] (Microsoft Corporation -> Microsoft Corp.) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [774272 2018-03-09] (EasyAntiCheat Oy -> EasyAntiCheat Ltd) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes Corporation -> Malwarebytes) S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2009-05-14] (Hewlett-Packard) [File not signed] S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2009-05-14] (Hewlett-Packard) [File not signed] S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_253e24b785ea60ca\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_253e24b785ea60ca\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [35704 2021-11-17] (Avast Software s.r.o. -> AVAST Software) R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [222112 2021-11-17] (Avast Software s.r.o. -> AVAST Software) R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [367632 2021-11-18] (Avast Software s.r.o. -> AVAST Software) R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [250392 2021-11-17] (Avast Software s.r.o. -> AVAST Software) R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [99344 2021-11-17] (Avast Software s.r.o. -> AVAST Software) R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [21936 2021-10-04] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software) R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [41344 2021-11-17] (Avast Software s.r.o. -> AVAST Software) R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [184648 2021-11-17] (Avast Software s.r.o. -> AVAST Software) R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [538976 2021-11-17] (Avast Software s.r.o. -> AVAST Software) R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [107848 2021-11-17] (Avast Software s.r.o. -> AVAST Software) R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [82904 2021-11-17] (Avast Software s.r.o. -> AVAST Software) R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [852216 2021-11-17] (Avast Software s.r.o. -> AVAST Software) R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [557648 2021-11-17] (Avast Software s.r.o. -> AVAST Software) R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [215392 2021-10-04] (Avast Software s.r.o. -> AVAST Software) R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [317696 2021-11-17] (Avast Software s.r.o. -> AVAST Software) S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [25480 2019-03-11] (CHENGDU YIWO Tech Development Co., Ltd. -> ) R0 EPMVolFl; C:\WINDOWS\System32\drivers\EPMVolFl.sys [21384 2019-04-12] (CHENGDU YIWO Tech Development Co., Ltd. -> Windows (R) Codename Longhorn DDK provider) S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [14728 2018-12-10] (CHENGDU YIWO Tech Development Co., Ltd. -> ) R2 speedfan; C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation) U3 idsvc; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2021-11-28 21:57 - 2021-11-28 21:57 - 000026943 _____ C:\Users\Kitchen PC\Desktop\FRST.txt 2021-11-28 21:56 - 2021-11-28 21:56 - 000000000 ____D C:\Users\Kitchen PC\Desktop\FRST-OlderVersion 2021-11-28 21:55 - 2021-11-28 21:56 - 002311680 _____ (Farbar) C:\Users\Kitchen PC\Desktop\FRST64.exe 2021-11-24 14:08 - 2021-11-24 14:08 - 000003567 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (36).pdf 2021-11-24 14:08 - 2021-11-24 14:08 - 000003565 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (35).pdf 2021-11-24 14:08 - 2021-11-24 14:08 - 000003565 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (34).pdf 2021-11-24 14:07 - 2021-11-24 14:07 - 000003743 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (32).pdf 2021-11-24 14:07 - 2021-11-24 14:07 - 000003569 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (33).pdf 2021-11-24 14:06 - 2021-11-24 14:06 - 000003567 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (31).pdf 2021-11-24 14:06 - 2021-11-24 14:06 - 000003565 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (30).pdf 2021-11-24 14:06 - 2021-11-24 14:06 - 000003565 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (29).pdf 2021-11-24 14:05 - 2021-11-24 14:05 - 000003743 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (27).pdf 2021-11-24 14:05 - 2021-11-24 14:05 - 000003569 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (28).pdf 2021-11-19 21:34 - 2021-11-20 12:08 - 000000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2021-11-18 13:40 - 2021-11-18 13:40 - 000017903 _____ C:\Users\Kitchen PC\Desktop\SCRIPS_MasterOrderForm_Christmas21.xlsx 2021-11-18 13:37 - 2021-11-18 13:37 - 000003727 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (26).pdf 2021-11-18 13:34 - 2021-11-18 13:34 - 000003537 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (25).pdf 2021-11-18 13:28 - 2021-11-18 13:28 - 000003727 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (24).pdf 2021-11-18 13:27 - 2021-11-18 13:27 - 000003554 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (23).pdf 2021-11-18 13:26 - 2021-11-18 13:26 - 000003537 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (22).pdf 2021-11-17 15:11 - 2021-11-17 15:11 - 000340248 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2021-11-17 15:11 - 2021-11-17 15:11 - 000214384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswf88d4373c80d4236.tmp 2021-11-11 15:49 - 2021-11-11 15:49 - 000003734 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (21).pdf 2021-11-11 15:47 - 2021-11-11 15:47 - 000003981 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (20).pdf 2021-11-11 15:47 - 2021-11-11 15:47 - 000003543 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (18).pdf 2021-11-11 15:47 - 2021-11-11 15:47 - 000003538 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (19).pdf 2021-11-11 15:46 - 2021-11-11 15:46 - 000003734 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (17).pdf 2021-11-10 11:30 - 2021-11-10 11:30 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe 2021-11-10 11:30 - 2021-11-10 11:30 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe 2021-11-10 11:30 - 2021-11-10 11:30 - 000011363 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2021-11-10 11:29 - 2021-11-10 11:29 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe 2021-11-10 11:25 - 2021-11-10 11:25 - 000000000 ___HD C:\$WinREAgent 2021-11-06 12:16 - 2021-11-28 21:46 - 000002484 _____ C:\WINDOWS\system32\Tasks\Samsung_PSSD_Registration 2021-11-06 12:16 - 2021-11-06 12:16 - 000000000 ____D C:\ProgramData\Samsung Apps 2021-11-04 10:47 - 2021-11-04 10:47 - 000003733 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (15).pdf 2021-11-04 10:47 - 2021-11-04 10:47 - 000003551 _____ C:\Users\Kitchen PC\Downloads\FamilyOrderDetail_Pro (16).pdf 2021-11-01 20:54 - 2021-11-01 20:54 - 000001146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk 2021-11-01 20:54 - 2021-11-01 20:54 - 000000000 ____D C:\Program Files\PCHealthCheck ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2021-11-28 21:57 - 2019-12-07 03:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2021-11-28 21:57 - 2018-07-08 17:27 - 000000000 ____D C:\FRST 2021-11-28 21:52 - 2016-05-14 06:29 - 000000000 ____D C:\Program Files (x86)\Steam 2021-11-28 21:46 - 2020-08-28 23:35 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task 2021-11-28 21:46 - 2020-08-28 23:35 - 000003408 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2021-11-28 21:46 - 2020-08-28 23:35 - 000003348 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2021-11-28 21:46 - 2020-08-28 23:35 - 000003194 _____ C:\WINDOWS\system32\Tasks\CCleaner Update 2021-11-28 21:46 - 2020-08-28 23:35 - 000003184 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2021-11-28 21:46 - 2020-08-28 23:35 - 000003124 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2021-11-28 21:46 - 2020-08-28 23:35 - 000002292 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC 2021-11-28 21:46 - 2020-08-28 23:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software 2021-11-28 21:46 - 2017-03-14 20:26 - 000000000 ____D C:\Users\Kitchen PC\AppData\LocalLow\Mozilla 2021-11-28 20:08 - 2016-05-13 20:48 - 000000000 ____D C:\Program Files (x86)\Google 2021-11-28 19:35 - 2017-03-04 07:04 - 000000000 ____D C:\Users\Kitchen PC\AppData\Local\CrashDumps 2021-11-28 13:38 - 2020-02-01 09:57 - 000000000 ____D C:\ProgramData\Mozilla 2021-11-28 12:18 - 2020-08-28 23:28 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2021-11-28 00:11 - 2016-05-14 01:03 - 000000000 ____D C:\ProgramData\NVIDIA 2021-11-25 21:10 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2021-11-25 09:23 - 2020-08-21 08:25 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2021-11-25 09:23 - 2020-08-21 08:25 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2021-11-25 09:23 - 2019-12-07 03:14 - 000000000 ___HD C:\Program Files\WindowsApps 2021-11-23 07:54 - 2020-08-28 23:37 - 000934986 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2021-11-23 07:54 - 2019-12-07 03:13 - 000000000 ____D C:\WINDOWS\INF 2021-11-19 12:09 - 2016-05-13 20:49 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2021-11-19 06:42 - 2019-11-17 17:48 - 000000000 ____D C:\ProgramData\Packages 2021-11-18 07:37 - 2019-01-18 07:11 - 000367632 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys 2021-11-17 19:06 - 2016-06-08 11:08 - 000000000 ____D C:\Users\Kitchen PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox 2021-11-17 15:11 - 2020-10-27 11:06 - 000184648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2021-11-17 15:11 - 2020-08-28 23:35 - 000003990 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update 2021-11-17 15:11 - 2020-04-20 17:14 - 000538976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNetHub.sys 2021-11-17 15:11 - 2019-12-07 03:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2021-11-17 15:11 - 2019-01-17 09:59 - 000250392 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsh.sys 2021-11-17 15:11 - 2019-01-17 09:59 - 000099344 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniv.sys 2021-11-17 15:11 - 2019-01-17 09:59 - 000035704 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArDisk.sys 2021-11-17 15:11 - 2018-10-22 09:03 - 000041344 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2021-11-17 15:11 - 2017-11-22 06:43 - 000222112 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys 2021-11-17 15:11 - 2016-05-13 20:51 - 000852216 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2021-11-17 15:11 - 2016-05-13 20:51 - 000557648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2021-11-17 15:11 - 2016-05-13 20:51 - 000317696 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys 2021-11-17 15:11 - 2016-05-13 20:51 - 000107848 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2021-11-17 15:11 - 2016-05-13 20:51 - 000082904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2021-11-16 17:06 - 2018-12-22 10:38 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2021-11-12 09:08 - 2020-08-28 23:35 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2021-11-12 09:08 - 2020-08-28 23:28 - 000008192 ___SH C:\DumpStack.log.tmp 2021-11-12 09:08 - 2019-12-16 03:52 - 000807280 _____ C:\WINDOWS\system32\wpbbin.exe 2021-11-12 09:08 - 2019-12-16 03:52 - 000768408 _____ C:\WINDOWS\system32\AsusUpdateCheck.exe 2021-11-12 09:08 - 2016-05-13 20:50 - 000000000 ____D C:\ProgramData\AVAST Software 2021-11-11 22:29 - 2019-12-07 03:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2021-11-11 22:28 - 2019-12-07 03:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2021-11-11 22:28 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SystemResources 2021-11-11 22:28 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2021-11-11 22:28 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2021-11-10 11:30 - 2019-12-07 03:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2021-11-10 11:24 - 2016-05-13 23:21 - 000000000 ____D C:\WINDOWS\system32\MRT 2021-11-10 11:22 - 2016-05-13 23:20 - 141529560 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2021-11-01 21:37 - 2020-08-28 23:28 - 000448688 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2021-11-01 21:36 - 2019-12-07 03:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2021-11-01 21:36 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2021-11-01 21:36 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2021-11-01 21:36 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\setup 2021-11-01 21:36 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\Dism 2021-11-01 21:36 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\ShellExperiences 2021-11-01 21:36 - 2019-12-07 03:03 - 000000000 ____D C:\WINDOWS\servicing 2021-11-01 06:52 - 2019-12-07 03:14 - 000000000 ___RD C:\WINDOWS\PrintDialog 2021-11-01 06:52 - 2019-11-17 17:34 - 000000000 ____D C:\Users\Kitchen PC\AppData\Local\Packages ==================== Files in the root of some directories ======== 2017-10-15 10:39 - 2017-10-15 10:39 - 000007605 _____ () C:\Users\Kitchen PC\AppData\Local\Resmon.ResmonCfg 2018-06-18 21:53 - 2018-06-18 21:53 - 000000000 _____ () C:\Users\Kitchen PC\AppData\Local\{7F0636D0-E8DD-40CB-BC76-60C8CD111A6C} ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ========================