Upgraded friends PC last week from Windows 7 to Windows 10 and installed Bitdefender, since he has been using it "Bitdefender showing infected web page detected when browsing with firefox" message is coming up all the time. Got it back from him today the information in Bitdefender is
We blocked this dangerous page for your protection: https://polinaryapp....dd84a1d2a730.jsThreat name: JS:Adware.Lnkr.A Dangerous pages attempt to install software that can harm the device, gather personal information or operate without your consent.
We blocked this dangerous page for your protection: https://toolsmagick....9d09bdba7f1b.jsThreat name: JS:Adware.Lnkr.A Dangerous pages attempt to install software that can harm the device, gather personal information or operate without your consent.
There were 2 extensions in Firefox SAML-tracer and another called App something which I removed and since then I have had no more notifications from bitdefender. Just looking for some advice to make sure system is ok. Scan results are posted below, thanks.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-02-2020 02
Ran by Eddie (administrator) on EDDIEDELL (Dell Inc. Vostro 270) (11-02-2020 18:08:06)
Running from C:\Users\Eddie\Desktop
Loaded Profiles: Eddie (Available Profiles: Eddie)
Platform: Windows 10 Pro Version 1909 18363.628 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\DiscoverySrv.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Device Management\DevMgmtService.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdtrackersnmh.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdwtxag.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [DBRMTray] => C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation) [File not signed]
HKLM\...\Run: [flvga_tray64] => C:\Windows\system32\flvga_tray.exe [419328 2015-12-07] () [File not signed]
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3933496 2012-09-20] (Logitech -> Logitech, Inc.)
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\Run: [VideoGuardMonitor] => C:\Users\Eddie\AppData\Local\Cisco\VideoGuardPlayer\VideoGuardMonitor\CiscoVideoGuardMonitor.exe [2345736 2017-11-02] (Cisco Video Technologies Israel Ltd. -> Cisco)
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\Run: [EPSON SX410 Series] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIFCE.EXE [223232 2008-10-02] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.130\Installer\chrmstp.exe [2020-01-22] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01495D74-89D8-4B56-9A66-6CB0E27EF3B9} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {053D1D96-34A1-43DB-A08C-42013752D3E2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-01] (Google Inc -> Google Inc.)
Task: {0ACED679-9CB3-4827-A46A-2BCC4D55023D} - \Microsoft\Windows\Setup\EOSNotify2 -> No File <==== ATTENTION
Task: {0E9B0B5C-9FF3-4A29-8479-0868A68DD87B} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {20547455-08F6-4781-81F0-355BF009032E} - System32\Tasks\Bitdefender AgentTask_AD394AE64E874073B10A89FEEC305A3C => C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe [525120 2019-12-06] (Bitdefender SRL -> Bitdefender)
Task: {24093C7A-BB64-4A0F-967B-30A04900E47E} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4f47-879B-29A80C355D61}
Task: {2956E29D-A64D-413D-B892-F5AA2AC347BB} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {3999671B-80BF-4CDF-A95C-93FD2F0FE480} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {3B12223C-54DE-4CFC-8307-4A1D915AF6A3} - System32\Tasks\Microsoft\Windows\End Of Support\Notify1 => C:\WINDOWS\system32\sipnotify.exe
Task: {3CBC40D7-5079-4162-B3CF-8BB086B1F88F} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47c2-B62A-B7C4CED925CB}
Task: {49072A42-1C33-4821-800D-28DD295D6786} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {4952B2DA-0911-4A59-84B7-70CE6138225C} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
Task: {4FF356D2-FE47-4920-B00B-3E8B260DCA26} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {528B6446-B6F7-44E3-AA71-6203798B4E57} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {53C82D5D-CAA2-4928-AD01-FD5CA9402E42} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {54C24529-FE0D-45F3-921C-72B199731A29} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {5681C43E-9E0F-4FBB-AF45-8126839219E0} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [490808 2019-11-27] (Bitdefender SRL -> Bitdefender)
Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A}
Task: {63882D74-4B0D-4654-86EE-D96AE3948093} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6563DB5C-54FD-4007-98A3-1F779956369C} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {67C59A98-0975-4C0D-BC85-5E23C19BED38} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe
Task: {6A73D90C-B17C-4761-8357-1A346F1A3327} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {74B79B52-5FD9-4C14-BAB0-205B4C4DD9F9} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {7999A0A7-D11A-45C6-BDD2-8E903177FB5A} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {834A60BA-2D0F-4377-BE69-8C0777570D5A} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
Task: {92BE7943-78D8-4C4B-883D-3B2AAF434323} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {ACDC58CF-A087-48C0-A33C-1903B2116D07} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43da-BFD7-FBEEA2180A1E}
Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40b4-8963-D3C761B18371}
Task: {B1450FE1-82E8-40F1-8F3F-5749E0F9E20E} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {BA7F3875-7416-4EF5-B045-A03824D3AFA2} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {C1913C94-0842-490C-B755-F95332E09ABA} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {C35DD040-7390-40B7-B2DE-4D2574A463EB} - System32\Tasks\Microsoft\Windows\End Of Support\Notify2 => C:\WINDOWS\system32\sipnotify.exe
Task: {C92F3B8C-9131-4D30-8E74-934DCB76B59F} - \Microsoft\Windows\Setup\EOSNotify -> No File <==== ATTENTION
Task: {CE4EEC05-AE50-4266-B124-7496745958B2} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D2ACE0C1-E609-4CDD-AE28-98BEE54A0267} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1873288 2019-09-18] (AVAST Software s.r.o. -> AVAST Software)
Task: {DA5EBFDD-F0C4-44BB-802B-EC827B4A9BF5} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DA9D1E83-01AA-4187-BDB9-6D13247DE477} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E0024056-A3C8-4FB2-88B3-77B17119DC8B} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {E0AA4134-CDC5-47C0-AFAF-C7CDC34DBC40} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-01] (Google Inc -> Google Inc.)
Task: {EE53A167-6087-475B-A68D-3CDDED69B013} - \Microsoft\Windows\Setup\UpgradeTriggers\UpgradeReminderTask -> No File <==== ATTENTION
Task: {F218EEF0-1004-40A5-A322-21D0A63B9A31} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDfE067B1}
Task: {FFD0BCF8-7926-4344-A2B0-908C275D350D} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.132.1
Tcpip\..\Interfaces\{7059D287-A263-4A16-854D-FFC987708542}: [DhcpNameServer] 192.168.132.1
Tcpip\..\Interfaces\{8C412334-6E80-4EC8-9F2B-E48E60423A89}: [DhcpNameServer] 194.168.4.100 194.168.8.100
Tcpip\..\Interfaces\{CCEB5E90-4E48-420A-A652-21003662E153}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.co.uk/
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www1.euro.dell.com/content/default.aspx?c=uk&l=en&s=gen
BHO: Bitdefender Trackers Blocking -> {159ff5d5-55f1-4d2f-b706-767a55f77abb} -> C:\Program Files\Bitdefender\Bitdefender Security\bdtbie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
BHO: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
BHO-x32: Bitdefender Trackers Blocking -> {159ff5d5-55f1-4d2f-b706-767a55f77abb} -> C:\Program Files\Bitdefender\Bitdefender Security\antispam32\bdtbie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
BHO-x32: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
Toolbar: HKLM - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
Toolbar: HKLM-x32 - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
FireFox:
========
FF DefaultProfile: g6p9p80w.default
FF ProfilePath: C:\Users\Eddie\AppData\Roaming\Mozilla\Firefox\Profiles\g6p9p80w.default [2020-02-11]
FF NewTab: Mozilla\Firefox\Profiles\g6p9p80w.default -> about:home
FF Notifications: Mozilla\Firefox\Profiles\g6p9p80w.default -> hxxps://mail.virginmedia.com; hxxp://mail.virginmedia.com; hxxps://www.bingotastic.com; hxxps://www.youtube.com; hxxps://www.facebook.com; hxxps://www.ebay.co.uk; hxxps://www.epson.co.uk; hxxps://0.nextyourcontent.com; hxxps://1.nextyourcontent.com; hxxps://2.nextyourcontent.com
FF NewTabOverride: Mozilla\Firefox\Profiles\g6p9p80w.default -> Disabled: [email protected]
FF Extension: (No Name) - C:\Users\Eddie\AppData\Roaming\Mozilla\Firefox\Profiles\g6p9p80w.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-10-22]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi
FF Extension: (Bitdefender Wallet) - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi [2019-12-06]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbef.xpi
FF Extension: (Bitdefender Anti-tracker) - C:\Program Files\Bitdefender\Bitdefender Security\bdtbef.xpi [2019-11-01]
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext
FF Extension: (Bitdefender Antispam Toolbar) - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext [2020-01-08] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbef.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\bd_js_config.js [2020-02-02] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\bd_config.cfg [2020-02-02] <==== ATTENTION
Chrome:
=======
CHR Profile: C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default [2020-02-02]
CHR HomePage: Default -> hxxp://www.google.com
CHR Extension: (Slides) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-12-18]
CHR Extension: (Docs) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-13]
CHR Extension: (Google Drive) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-03]
CHR Extension: (YouTube) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-03]
CHR Extension: (Sheets) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-12-13]
CHR Extension: (Bitdefender Wallet) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\gannpgaobkkhmpomoijebaigcapoeebl [2020-02-02]
CHR Extension: (Google Docs Offline) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-02-02]
CHR Extension: (Bitdefender Anti-tracker) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\khndhdhbebhaddchcgnalcjlaekbbeof [2020-02-02]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-02-02]
CHR Extension: (Gmail) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-06-10]
CHR Extension: (Chrome Media Router) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-02-02]
CHR HKLM-x32\...\Chrome\Extension: [gannpgaobkkhmpomoijebaigcapoeebl]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
CHR HKLM-x32\...\Chrome\Extension: [khndhdhbebhaddchcgnalcjlaekbbeof]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 BDAuxSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [803576 2019-12-06] (Bitdefender SRL -> Bitdefender)
R2 BDProtSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [803576 2019-12-06] (Bitdefender SRL -> Bitdefender)
R2 bdredline; C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe [2195344 2018-03-22] (Bitdefender SRL -> Bitdefender)
R2 DevMgmtService; C:\Program Files\Bitdefender\Bitdefender Device Management\DevMgmtService.exe [119368 2019-12-06] (Bitdefender SRL -> Bitdefender)
S4 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE [163840 2007-12-17] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
S4 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE [126464 2007-01-11] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
S4 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [328608 2015-07-30] (Intel Corporation - pGFX -> Intel Corporation)
S2 MBAMInstallerService; C:\Users\Eddie\AppData\Local\Temp\MBAMInstallerService.exe [5225688 2020-02-11] (Malwarebytes Inc -> Malwarebytes) <==== ATTENTION
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1329240 2020-01-15] (Bitdefender SRL -> Bitdefender)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5796168 2020-01-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe [151656 2019-12-06] (Bitdefender SRL -> Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [803576 2019-12-06] (Bitdefender SRL -> Bitdefender)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2020-01-29] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2020-01-29] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 avast; "C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /svc [X]
S3 avastm; "C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /medsvc [X]
S3 McComponentHostService; "C:\Program Files\McAfee Security Scan\3.11.561\McCHSvc.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 atc; C:\WINDOWS\System32\DRIVERS\atc.sys [1693368 2019-09-23] (Bitdefender SRL -> Bitdefender S.R.L. Bucharest, ROMANIA)
S3 athur; C:\WINDOWS\System32\DRIVERS\athurx.sys [1847296 2010-01-05] (Microsoft Windows Hardware Compatibility Publisher -> Atheros Communications, Inc.)
R2 BdDci; C:\WINDOWS\system32\DRIVERS\bddci.sys [739264 2019-07-29] (Bitdefender SRL -> Bitdefender)
S0 bdelam; C:\WINDOWS\System32\drivers\bdelam.sys [22960 2019-03-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Bitdefender)
R0 bdprivmon; C:\WINDOWS\System32\DRIVERS\bdprivmon.sys [46056 2019-06-21] (Bitdefender SRL -> © Bitdefender SRL)
R1 BDVEDISK; C:\WINDOWS\system32\DRIVERS\bdvedisk.sys [96448 2018-04-27] (Bitdefender SRL -> BitDefender)
R0 Gemma; C:\WINDOWS\System32\DRIVERS\gemma.sys [564112 2019-11-07] (Bitdefender SRL -> BitDefender S.R.L. Bucharest, ROMANIA)
R0 gzflt; C:\WINDOWS\System32\DRIVERS\gzflt.sys [188384 2018-11-28] (Bitdefender SRL -> BitDefender LLC)
R2 Ignis; C:\WINDOWS\system32\DRIVERS\ignis.sys [196392 2019-07-04] (Bitdefender SRL -> Bitdefender)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [216544 2020-01-07] (Malwarebytes Inc -> Malwarebytes)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [662528 2019-03-19] (Microsoft Windows -> Realtek )
R0 trufos; C:\WINDOWS\System32\DRIVERS\trufos.sys [610640 2019-01-14] (Bitdefender SRL -> Bitdefender)
U5 vwifimp; C:\Windows\System32\Drivers\vwifimp.sys [50176 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45664 2020-01-29] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [355760 2020-01-29] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2020-01-29] (Microsoft Windows -> Microsoft Corporation)
U3 idsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-02-11 18:08 - 2020-02-11 18:09 - 000022976 _____ C:\Users\Eddie\Desktop\FRST.txt
2020-02-11 18:05 - 2020-02-11 18:05 - 002279424 _____ (Farbar) C:\Users\Eddie\Desktop\FRST64.exe
2020-02-02 20:22 - 2020-02-02 20:22 - 000000080 ___SH C:\bootTel.dat
2020-02-02 10:21 - 2020-02-02 10:21 - 000157636 _____ C:\ProgramData\dm.update.1580638881.bdinstall.v2.bin
2020-02-02 10:21 - 2020-02-02 10:21 - 000036233 _____ C:\ProgramData\dm.uninstall.1580638890.bdinstall.bin
2020-02-02 10:20 - 2020-02-02 10:20 - 000000000 ____D C:\ProgramData\Bitdefender Device Management
2020-02-02 10:19 - 2020-02-02 10:19 - 000817888 _____ C:\ProgramData\cl.1580638097.bdinstall.v2.bin
2020-02-02 10:19 - 2020-02-02 10:19 - 000102260 _____ C:\ProgramData\cl.kit.1580638087.bdinstall.v2.bin
2020-02-02 10:19 - 2020-02-02 10:19 - 000003420 _____ C:\WINDOWS\system32\Tasks\Bitdefender AgentTask_AD394AE64E874073B10A89FEEC305A3C
2020-02-02 10:18 - 2020-02-02 10:18 - 000000000 ____D C:\ProgramData\Gemma
2020-02-02 10:18 - 2020-02-02 10:18 - 000000000 ____D C:\ProgramData\Atc
2020-02-02 10:17 - 2020-02-02 10:17 - 000002431 _____ C:\Users\Public\Desktop\Bitdefender VPN.lnk
2020-02-02 10:17 - 2020-02-02 10:17 - 000002431 _____ C:\ProgramData\Desktop\Bitdefender VPN.lnk
2020-02-02 10:17 - 2020-02-02 10:17 - 000002344 _____ C:\Users\Public\Desktop\Bitdefender.lnk
2020-02-02 10:17 - 2020-02-02 10:17 - 000002344 _____ C:\ProgramData\Desktop\Bitdefender.lnk
2020-02-02 10:17 - 2020-02-02 10:17 - 000000000 ____D C:\WINDOWS\system32\elambkup
2020-02-02 10:17 - 2020-02-02 10:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender Security
2020-02-02 10:17 - 2020-02-02 10:17 - 000000000 ____D C:\ProgramData\BDLogging
2020-02-02 10:17 - 2019-03-21 00:12 - 000022960 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bdelam.sys
2020-02-02 10:16 - 2019-11-07 08:49 - 000564112 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\gemma.sys
2020-02-02 10:16 - 2019-09-23 08:43 - 001693368 _____ (Bitdefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\atc.sys
2020-02-02 10:16 - 2019-07-29 15:32 - 000739264 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bddci.sys
2020-02-02 10:16 - 2019-06-21 07:30 - 000046056 _____ (© Bitdefender SRL) C:\WINDOWS\system32\Drivers\bdprivmon.sys
2020-02-02 10:16 - 2018-04-27 07:45 - 000096448 _____ (BitDefender) C:\WINDOWS\system32\Drivers\bdvedisk.sys
2020-02-02 10:15 - 2020-02-02 10:43 - 000000000 ____D C:\ProgramData\Bitdefender
2020-02-02 10:15 - 2020-02-02 10:21 - 000000000 ____D C:\Program Files\Bitdefender
2020-02-02 10:15 - 2020-02-02 10:20 - 000000000 ____D C:\Users\Eddie\AppData\Roaming\Bitdefender
2020-02-02 10:15 - 2019-07-04 11:15 - 000196392 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\ignis.sys
2020-02-02 10:15 - 2019-01-14 16:25 - 000610640 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\trufos.sys
2020-02-02 10:15 - 2018-11-28 05:45 - 000188384 _____ (BitDefender LLC) C:\WINDOWS\system32\Drivers\gzflt.sys
2020-02-02 10:08 - 2020-02-02 10:15 - 000000000 ____D C:\Program Files\Common Files\Bitdefender
2020-02-02 10:08 - 2020-02-02 10:08 - 000003802 _____ C:\WINDOWS\system32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
2020-02-02 10:06 - 2020-02-02 10:20 - 000000000 ____D C:\Program Files\Bitdefender Agent
2020-02-02 10:06 - 2020-02-02 10:06 - 000113524 _____ C:\ProgramData\agent.1580637970.bdinstall.v2.bin
2020-02-02 10:06 - 2020-02-02 10:06 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2020-02-02 10:05 - 2020-02-02 10:05 - 012422992 _____ C:\Users\Eddie\Downloads\bitdefender_windows_d19acce7-90aa-4746-a6ad-21b2e4307aa2.exe
2020-01-31 17:47 - 2020-01-31 17:47 - 000000000 ____D C:\Users\Eddie\AppData\Local\PeerDistRepub
2020-01-31 17:10 - 2020-01-31 17:27 - 000000000 ____D C:\Users\Eddie\AppData\Local\D3DSCache
2020-01-31 16:35 - 2020-01-31 16:35 - 000000000 ____D C:\WINDOWS\system32\appmgmt
2020-01-30 00:39 - 2020-01-30 00:39 - 000000000 ____D C:\Program Files\Common Files\SpeechEngines
2020-01-30 00:38 - 2020-01-30 00:38 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2020-01-30 00:37 - 2020-01-30 00:37 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2020-01-30 00:35 - 2020-01-30 00:35 - 003365376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\WINDOWS\system32\msmq
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\WINDOWS\system32\BestPractices
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\Program Files\Reference Assemblies
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\Program Files\MSBuild
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\Program Files (x86)\MSBuild
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\inetpub
2020-01-30 00:33 - 2019-03-02 01:31 - 001166488 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2020-01-30 00:33 - 2019-03-02 01:31 - 000124568 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2020-01-30 00:33 - 2019-03-02 01:31 - 000035592 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2020-01-30 00:33 - 2019-02-06 02:41 - 000778912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2020-01-30 00:33 - 2019-02-06 02:41 - 000103072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2020-01-30 00:33 - 2019-02-06 02:41 - 000035592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2020-01-30 00:32 - 2019-03-19 03:21 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2020-01-30 00:32 - 2019-03-19 03:20 - 004470272 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2020-01-30 00:32 - 2019-03-19 03:16 - 000903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2020-01-30 00:32 - 2019-03-19 02:15 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2020-01-30 00:32 - 2019-03-19 02:09 - 000568320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2020-01-30 00:32 - 2019-03-02 01:33 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2020-01-30 00:32 - 2018-08-09 22:53 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2020-01-29 21:13 - 2020-01-29 21:13 - 000000144 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2020-01-29 20:25 - 2020-01-29 20:25 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 022635008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 019812864 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 018026496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 009926968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 007754240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 007600656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 007259648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 006516648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 006435840 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 006285312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 006083832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 005914112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 005764664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 005112320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 004856832 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 004348616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 003967888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 003819008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 003550208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 003372440 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 003243080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002988552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 002801152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 002773776 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002766088 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002703872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002584008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002493928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002314952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002260176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002225160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002084576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002032128 _____ C:\WINDOWS\system32\rdpnano.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001916744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001858560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001835128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-01-29 20:25 - 2020-01-29 20:25 - 001743672 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001726480 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001693184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001610752 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001541632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 001512320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 001489064 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001417760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001412096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001399304 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 001394168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001372160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-01-29 20:25 - 2020-01-29 20:25 - 001300280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 001283592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2020-01-29 20:25 - 2020-01-29 20:25 - 001283584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001182232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 001170960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001154448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001151816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001105776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001097216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001083392 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001073168 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 001051448 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001000960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000974336 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000928120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000913408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000892488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000891736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000890368 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000875144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000828216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000824848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000805376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000788992 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000768488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000749568 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000747320 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000704512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000679160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000673080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000661816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000637440 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000617784 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000598528 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000587064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000568120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000545432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000518184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000510768 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000500736 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2020-01-29 20:25 - 2020-01-29 20:25 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2020-01-29 20:25 - 2020-01-29 20:25 - 000476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000467648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000465208 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000453432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000444928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000441072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2020-01-29 20:25 - 2020-01-29 20:25 - 000416056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\DispBroker.Desktop.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000404912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000399360 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000384000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000375504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000366416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000345088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000324616 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000311096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000300392 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\msutb.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000259984 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoncli.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000248064 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofm.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2020-01-29 20:25 - 2020-01-29 20:25 - 000221200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msutb.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\regapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000193592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000190464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\regapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000190256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logoncli.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2020-01-29 20:25 - 2020-01-29 20:25 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000174392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppvVemgr.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000153912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppvVfs.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatialAudioLicenseSrv.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000143160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000138040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppVStrm.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetDriverInstall.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000107832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairingExperienceMEM.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000106808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000099712 _____ (Microsoft Corporation) C:\WINDOWS\system32\FsIso.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\compstui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000093704 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000089328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSystray.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000084496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetDriverInstall.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedsbs.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000072816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\findnetprinters.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\printui.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000063288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\printui.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000059221 _____ C:\WINDOWS\system32\srms.dat
2020-01-29 20:25 - 2020-01-29 20:25 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\findnetprinters.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\npmproxy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000042512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcicda.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmproxy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mciwave.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mciseq.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000021304 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000019768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmsprep.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedssync.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedssync.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-01-29 20:24 - 2020-01-29 20:24 - 007905208 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 006231200 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 006167552 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 004615376 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 004470784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 004005888 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 003729408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 003703296 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 003591184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 003110400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 002284544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 002125904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 002071552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001942016 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001841152 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001748480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 001413912 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 001083904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001027000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000874512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000737280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000732200 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000716288 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000642008 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000637968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000589592 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000536064 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000459896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000437776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000415808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000350720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SpeechPrivacy.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000296760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000194064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\tssrvlic.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AppExecutionAlias.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_BackgroundApps.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationControlCSP.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000117264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000089912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000088352 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\LSCSHostPolicy.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcicda.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000047208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mciwave.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mciseq.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\lstelemetry.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindflt.dll
2020-01-29 20:05 - 2020-01-31 17:27 - 000000000 __SHD C:\Users\Eddie\IntelGraphicsProfiles
2020-01-29 20:05 - 2020-01-29 20:05 - 000000451 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2020-01-29 17:36 - 2020-02-03 11:40 - 000000000 ____D C:\Users\Eddie\AppData\Local\PlaceholderTileLogoFolder
2020-01-29 17:22 - 2020-01-29 17:23 - 000000000 ____D C:\Users\Eddie\AppData\Local\Comms
2020-01-29 17:21 - 2020-01-29 19:01 - 000000000 ____D C:\ProgramData\Packages
2020-01-29 17:20 - 2020-02-10 17:21 - 000003368 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3631865646-3207491450-1134192123-1000
2020-01-29 17:20 - 2020-02-10 17:21 - 000000000 ___RD C:\Users\Eddie\OneDrive
2020-01-29 17:17 - 2020-01-29 17:17 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2020-01-29 17:16 - 2020-01-29 17:16 - 000001450 _____ C:\Users\Eddie\Desktop\Microsoft Edge.lnk
2020-01-29 17:04 - 2020-01-29 17:04 - 000000000 ___HD C:\Users\Eddie\MicrosoftEdgeBackups
2020-01-29 17:04 - 2020-01-29 17:04 - 000000000 ____D C:\Users\Eddie\AppData\Local\MicrosoftEdge
2020-01-29 17:03 - 2020-01-29 21:13 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-01-29 17:03 - 2020-01-29 21:13 - 000000000 ___RD C:\Users\Eddie\3D Objects
2020-01-29 17:03 - 2020-01-29 17:55 - 000000000 ____D C:\Users\Eddie\AppData\Local\Publishers
2020-01-29 17:02 - 2020-01-31 16:47 - 000000000 ____D C:\Users\Eddie\AppData\Local\Packages
2020-01-29 17:02 - 2020-01-29 17:03 - 000000000 ____D C:\Users\Eddie\AppData\Local\ConnectedDevicesPlatform
2020-01-29 17:02 - 2020-01-29 17:02 - 000000020 ___SH C:\Users\Eddie\ntuser.ini
2020-01-29 17:00 - 2020-02-05 11:12 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-01-29 17:00 - 2020-02-05 11:12 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-01-29 17:00 - 2020-02-02 20:22 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-01-29 17:00 - 2020-01-29 19:04 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-01-29 17:00 - 2020-01-29 17:01 - 000003486 _____ C:\WINDOWS\system32\Tasks\AvastUpdateTaskMachineUA
2020-01-29 17:00 - 2020-01-29 17:00 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2020-01-29 17:00 - 2020-01-29 17:00 - 000007623 _____ C:\WINDOWS\diagerr.xml
2020-01-29 17:00 - 2020-01-29 17:00 - 000003358 _____ C:\WINDOWS\system32\Tasks\AvastUpdateTaskMachineCore
2020-01-29 17:00 - 2020-01-29 17:00 - 000000000 ____D C:\WINDOWS\system32\Tasks\WPD
2020-01-29 17:00 - 2020-01-29 17:00 - 000000000 ____D C:\WINDOWS\system32\Tasks\Games
2020-01-29 17:00 - 2020-01-29 17:00 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2020-01-29 17:00 - 2016-05-19 13:27 - 000003184 _____ C:\WINDOWS\system32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2020-01-29 16:53 - 2020-02-10 17:21 - 000002410 _____ C:\Users\Eddie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-01-29 16:53 - 2020-02-02 20:17 - 000000000 ____D C:\Users\Eddie
2020-01-29 16:52 - 2020-01-29 21:16 - 000936048 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-01-29 16:49 - 2020-01-09 21:24 - 002874368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2020-01-29 16:48 - 2020-01-29 16:48 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2020-01-29 16:45 - 2020-02-11 18:00 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-01-29 16:45 - 2020-01-29 21:12 - 000413136 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-01-29 15:33 - 2020-02-10 12:56 - 000000000 ___DC C:\WINDOWS\Panther
2020-01-29 15:19 - 2020-01-29 15:33 - 000000000 ____D C:\ESD
2020-01-29 15:17 - 2020-01-29 15:17 - 000000000 ___HD C:\$Windows.~WS
2020-01-29 15:15 - 2020-01-29 15:15 - 000030165 _____ C:\WINDOWS\system32\servers.def.lkg
2020-01-29 15:15 - 2020-01-29 15:15 - 000030165 _____ C:\WINDOWS\system32\servers.def
2020-01-29 15:15 - 2020-01-29 15:15 - 000004451 _____ C:\WINDOWS\system32\uat64.vpx
2020-01-29 15:15 - 2020-01-29 15:15 - 000003333 _____ C:\WINDOWS\system32\servers.def.vpx
2020-01-29 15:15 - 2020-01-29 15:15 - 000000602 _____ C:\WINDOWS\system32\prod-pgm.vpx
2020-01-29 15:15 - 2020-01-29 15:15 - 000000540 _____ C:\WINDOWS\system32\.tmp
2020-01-29 15:15 - 2020-01-29 15:15 - 000000341 _____ C:\WINDOWS\system32\prod-vps.vpx
2020-01-29 15:13 - 2020-01-29 15:13 - 019255000 _____ (Microsoft Corporation) C:\Users\Eddie\Downloads\MediaCreationTool1909.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-02-11 18:08 - 2017-03-08 14:43 - 000000000 ____D C:\FRST
2020-02-11 14:39 - 2019-03-19 04:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-02-11 14:29 - 2016-11-18 15:24 - 000000000 ____D C:\Users\Eddie\AppData\LocalLow\Mozilla
2020-02-11 14:27 - 2016-05-08 12:28 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2020-02-11 14:27 - 2014-02-13 14:01 - 000001165 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-02-11 14:27 - 2014-02-13 14:01 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-02-09 22:09 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-02-08 16:00 - 2019-03-19 04:37 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-02-02 20:54 - 2019-03-19 04:50 - 000000000 ____D C:\WINDOWS\INF
2020-02-02 20:17 - 2019-03-19 04:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-02-02 10:27 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-02-02 10:27 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-02-02 10:27 - 2017-03-12 10:39 - 000000000 ____D C:\Program Files (x86)\Adobe
2020-01-31 17:41 - 2016-05-26 15:42 - 000007619 _____ C:\Users\Eddie\AppData\Local\resmon.resmoncfg
2020-01-31 17:09 - 2019-03-19 04:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-01-31 16:34 - 2018-05-16 09:02 - 000000000 ____D C:\Users\Eddie\AppData\Local\AVAST Software
2020-01-31 16:34 - 2017-03-10 14:51 - 000000000 ____D C:\ProgramData\AVAST Software
2020-01-31 15:50 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\appcompat
2020-01-30 00:44 - 2019-09-16 12:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2020-01-30 00:44 - 2019-03-19 04:56 - 000000000 ____D C:\WINDOWS\Setup
2020-01-30 00:44 - 2019-03-19 04:52 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2020-01-30 00:44 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-01-30 00:44 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\NDF
2020-01-30 00:44 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-01-30 00:44 - 2019-03-19 04:49 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2020-01-30 00:44 - 2016-12-27 18:56 - 000000000 __SHD C:\WINDOWS\SysWOW64\AI_RecycleBin
2020-01-30 00:44 - 2016-05-24 03:43 - 000000000 ____D C:\WINDOWS\system32\configBackup
2020-01-30 00:44 - 2014-08-06 19:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson Software
2020-01-30 00:44 - 2014-07-10 13:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 6.0 Sprint
2020-01-30 00:44 - 2014-07-10 13:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2020-01-30 00:44 - 2014-07-10 12:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2020-01-30 00:44 - 2014-03-25 20:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2020-01-30 00:44 - 2013-10-31 11:58 - 000000000 ____D C:\Program Files (x86)\Intel
2020-01-30 00:44 - 2013-10-31 10:02 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2020-01-30 00:44 - 2010-11-21 07:17 - 000000000 ____D C:\WINDOWS\ShellNew
2020-01-30 00:44 - 2009-07-14 03:20 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2020-01-30 00:44 - 2009-07-14 03:20 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2020-01-30 00:41 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2020-01-30 00:41 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\IME
2020-01-30 00:39 - 2019-03-19 04:52 - 000000000 __SHD C:\Program Files\Windows Sidebar
2020-01-30 00:39 - 2019-03-19 04:52 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
2020-01-30 00:39 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\schemas
2020-01-30 00:39 - 2014-02-13 16:48 - 000000000 ____D C:\Program Files\Microsoft Games
2020-01-30 00:39 - 2013-10-31 11:59 - 000000000 ____D C:\Program Files\CONEXANT
2020-01-30 00:39 - 2009-07-14 05:32 - 000000000 ____D C:\Program Files\DVD Maker
2020-01-30 00:34 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2020-01-30 00:34 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2020-01-30 00:33 - 2020-01-09 21:26 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2020-01-30 00:33 - 2020-01-09 21:26 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2020-01-30 00:33 - 2020-01-09 21:26 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngkeyhelper.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2020-01-30 00:33 - 2020-01-09 21:25 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2020-01-30 00:33 - 2019-03-19 05:00 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2020-01-30 00:33 - 2019-03-19 05:00 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2020-01-30 00:33 - 2019-03-19 05:00 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2020-01-30 00:33 - 2019-03-19 05:00 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2020-01-30 00:33 - 2019-03-19 05:00 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2020-01-30 00:33 - 2019-03-19 04:58 - 001401344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000783872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000304640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2020-01-30 00:33 - 2019-03-19 04:58 - 000230912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2020-01-30 00:33 - 2019-03-19 04:58 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2020-01-30 00:33 - 2019-03-19 04:58 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2020-01-30 00:33 - 2019-03-19 04:58 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2020-01-30 00:33 - 2019-03-19 04:58 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2020-01-30 00:33 - 2019-03-19 04:58 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2020-01-30 00:33 - 2019-03-19 04:58 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2020-01-30 00:33 - 2019-03-19 04:58 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2020-01-30 00:33 - 2019-03-19 04:57 - 000134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2020-01-30 00:33 - 2019-03-19 04:57 - 000128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\et-EE
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\es-MX
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SystemResources
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-01-29 19:04 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files\Windows Defender
2020-01-29 19:01 - 2019-03-19 04:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-01-29 17:53 - 2013-10-31 10:03 - 000000000 ____D C:\Program Files\Intel
2020-01-29 17:50 - 2019-03-19 04:37 - 000000000 ____D C:\WINDOWS\servicing
2020-01-29 17:42 - 2010-11-21 03:27 - 000748816 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-01-29 17:40 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2020-01-29 17:40 - 2019-03-19 04:52 - 000000000 ____D C:\ProgramData\USOPrivate
2020-01-29 17:22 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\ServiceState
2020-01-29 17:11 - 2019-03-19 06:22 - 000000000 ____D C:\WINDOWS\OCR
2020-01-29 17:02 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\spool
2020-01-29 17:00 - 2019-03-19 04:52 - 000000000 __RHD C:\Users\Public\Libraries
2020-01-29 16:59 - 2017-04-01 13:22 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-01-29 16:59 - 2017-04-01 13:22 - 000002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-01-29 16:59 - 2017-04-01 13:22 - 000002262 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-01-29 16:54 - 2018-04-15 13:37 - 000000000 ____D C:\Users\Eddie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sky
2020-01-29 16:52 - 2011-02-10 14:33 - 000892382 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2020-01-29 16:50 - 2019-03-19 04:52 - 000000000 ___RD C:\WINDOWS\PrintDialog
2020-01-29 16:17 - 2009-07-14 04:45 - 000021312 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-01-29 16:17 - 2009-07-14 04:45 - 000021312 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-01-15 21:52 - 2014-02-13 15:34 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-01-15 21:48 - 2014-02-13 15:34 - 120202352 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories ========
2014-10-29 16:15 - 2014-10-29 16:15 - 000004096 ____H () C:\Users\Eddie\AppData\Local\keyfile3.drm
2016-05-26 15:42 - 2020-01-31 17:41 - 000007619 _____ () C:\Users\Eddie\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-02-2020 02
Ran by Eddie (11-02-2020 18:11:18)
Running from C:\Users\Eddie\Desktop
Windows 10 Pro Version 1909 18363.628 (X64) (2020-01-29 17:02:07)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3631865646-3207491450-1134192123-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3631865646-3207491450-1134192123-503 - Limited - Disabled)
Eddie (S-1-5-21-3631865646-3207491450-1134192123-1000 - Administrator - Enabled) => C:\Users\Eddie
Guest (S-1-5-21-3631865646-3207491450-1134192123-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3631865646-3207491450-1134192123-1002 - Limited - Enabled)
WDAGUtilityAccount (S-1-5-21-3631865646-3207491450-1134192123-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Bitdefender Antivirus (Enabled - Up to date) {0E17DB7D-A20F-62CE-B95B-17DB0CDFE318}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Enabled) {362C5A58-E860-6396-9204-BEEEF20CA463}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
ABBYY FineReader 6.0 Sprint (HKLM-x32\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1395.4512 - ABBYY Software House)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 24.0.1.161 - Bitdefender)
Bitdefender Device Management (HKLM\...\Bitdefender Device Management) (Version: 24.0.14.86 - Bitdefender)
Bitdefender Total Security (HKLM\...\Bitdefender) (Version: 24.0.14.85 - Bitdefender)
Cisco VideoGuard Player (HKLM-x32\...\{30e4813e-2a86-4e4f-82ea-23df71ca8ffb}) (Version: 10.1.1.6570 - Cisco Systems, Inc)
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Epson Easy Photo Print 2 (HKLM-x32\...\{87C2248A-C7DD-49ED-9BCD-B312A9D0819E}) (Version: 2.1.0.0 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - )
Epson Stylus SX210_SX410_TX210_TX410 Manual (HKLM-x32\...\Epson Stylus SX210_SX410_TX210_TX410 User’s Guide) (Version: - )
EPSON SX410 Series Printer Uninstall (HKLM\...\EPSON SX410 Series) (Version: - SEIKO EPSON Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 79.0.3945.130 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.441 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.123 - Google Inc.) Hidden
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.0.1351 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.220 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{6199B534-A1B6-46ED-873B-97B0ECF8F81E}) (Version: 1.23.216.0 - Intel Corporation)
Malwarebytes version 4.0.4.49 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.0.4.49 - Malwarebytes)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\OneDriveSetup.exe) (Version: 19.232.1124.0005 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 73.0 (x64 en-US) (HKLM\...\Mozilla Firefox 73.0 (x64 en-US)) (Version: 73.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 73.0.0.7342 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Sky Go 1.5.16.0 (HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\com.bskyb.skygoplayer_is1) (Version: 1.5.16.0 - Sky)
Sky Go Desktop (HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\2508210495.go.sky.com) (Version: - go.sky.com)
Sky Sports 6.0.1 (only current user) (HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\805733bb-91da-567d-b881-06034d21d33f) (Version: 6.0.1 - )
Thin2000 USB Display Adapter (HKLM\...\{BA661C83-7D34-4DF8-A31F-2139C1D72B1C}) (Version: 1.1.316.0 - Fresco Logic)
TP-LINK Wireless Client Utility (HKLM-x32\...\{7A2A107B-9695-423F-9462-8F17C178BD35}) (Version: 7.0 - TP-LINK)
Packages:
=========
Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_1.29.4.0_x86__kgqvnymyfvs32 [2020-01-29] (king.com)
Farm Heroes Saga -> C:\Program Files\WindowsApps\king.com.FarmHeroesSaga_5.30.9.0_x86__kgqvnymyfvs32 [2020-01-29] (king.com)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-01-29] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-01-29] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.5.12061.0_x64__8wekyb3d8bbwe [2020-01-29] (Microsoft Studios) [MS Ad]
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3631865646-3207491450-1134192123-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation - pGFX -> Intel Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2015-07-30] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\Eddie\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.co
==================== Loaded Modules (Whitelisted) =============
2014-02-13 13:49 - 2008-11-12 03:00 - 000118784 _____ (SEIKO EPSON CORPORATION) [File not signed] C:\WINDOWS\System32\E_ILMFIE.DLL
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer trusted/restricted ==========
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 02:34 - 2020-02-11 17:19 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Dell\Win7 LtBlue 1920x1200.jpg
DNS Servers: 192.168.132.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: AVP16.0.0 => 2
MSCONFIG\Services: cphs => 3
MSCONFIG\Services: EPSON_EB_RPCV4_01 => 2
MSCONFIG\Services: EPSON_PM_RPCV4_01 => 2
MSCONFIG\Services: GoogleChromeElevationService => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: IAStorDataMgrSvc => 2
MSCONFIG\Services: igfxCUIService1.0.0.0 => 2
MSCONFIG\Services: Intel® Capability Licensing Service Interface => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: MBAMInstallerService => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: UNS => 2
MSCONFIG\Services: vssbrigde64 => 3
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: DBRMTray => C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe
MSCONFIG\startupreg: EPSON SX410 Series => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFCE.EXE /FU "C:\Windows\TEMP\E_SB404.tmp" /EF "HKCU"
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IAStorIcon => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" 60
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: IMSS => "C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe"
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: USB3MON => "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "DBRMTray"
HKLM\...\StartupApproved\Run: => "flvga_tray64"
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\StartupApproved\Run: => "VideoGuardMonitor"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{066457EA-5F85-453E-B42B-1932DDB50E04}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{69E72D19-F49C-4A13-990A-0C8D88CC12F8}C:\users\eddie\appdata\roaming\sky\sky go\sky go.exe] => (Block) C:\users\eddie\appdata\roaming\sky\sky go\sky go.exe (Sky UK Limited -> Sky UK)
FirewallRules: [TCP Query User{742691DA-D506-47DA-A1FD-D736B34F0B7B}C:\users\eddie\appdata\roaming\sky\sky go\sky go.exe] => (Block) C:\users\eddie\appdata\roaming\sky\sky go\sky go.exe (Sky UK Limited -> Sky UK)
FirewallRules: [{50E4E72F-6D4C-454E-B7C9-2516355F068C}] => (Allow) LPort=53
FirewallRules: [{8780A08B-79DF-49D6-92CC-08ACF7E935BF}] => (Allow) LPort=53
FirewallRules: [{F7ABF902-A19E-4514-A9E1-AC3EEFECC7B3}] => (Allow) LPort=68
FirewallRules: [{2CA0D1DA-1161-45DF-AAA6-34B705B2D7BF}] => (Allow) LPort=67
FirewallRules: [{9B633C90-3460-47A4-875D-80B09EA0E462}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RTLDHCP.exe No File
FirewallRules: [{5DC8B8B7-D95F-4370-AB76-84457A612EE0}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RTLDHCP.exe No File
FirewallRules: [{61C25B7E-A460-403B-AE0C-36F3976788A5}] => (Allow) LPort=53
FirewallRules: [{F053692C-CE7B-4213-9DA2-5B5AE9FCBFC6}] => (Allow) LPort=1542
FirewallRules: [{A641E685-FBDA-4457-B76A-F693DDFB306A}] => (Allow) LPort=1542
FirewallRules: [{DCAD6A22-D1D5-4C9A-882C-0EC3F69CA2ED}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe No File
FirewallRules: [{AEF1CD72-353D-4232-9533-7C169C1658D8}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe No File
FirewallRules: [{C3895048-7F66-4ED2-B368-03D40A184BA9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{79A9EB39-E084-4A2E-81D1-1519ED7022E2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{6ADB7F32-8035-4E9D-8F13-8A0D35A450E3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{259FBEE8-38E4-4B2D-880C-7DDA44A60B3F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{529B52EC-1C0F-4449-8B2A-30B76E57F48A}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe No File
FirewallRules: [TCP Query User{58FD11C6-2A37-4D57-87A6-BDCBF04C94FB}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe No File
FirewallRules: [{741EA72A-428C-464E-8EDE-FA3CE458D6B5}] => (Allow) C:\Program Files (x86)\EpsonNet\EpsonNet Setup\tool09\ENEasyApp.exe No File
FirewallRules: [{7D497B30-B5B9-4B2E-BE52-80A1B31BA62E}] => (Allow) C:\Program Files (x86)\EpsonNet\EpsonNet Setup\tool09\ENEasyApp.exe No File
==================== Restore Points =========================
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (02/11/2020 03:56:10 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (10612,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (02/11/2020 02:45:49 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (9932,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (02/11/2020 02:34:51 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4484,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (02/11/2020 02:12:34 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (2852,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (02/11/2020 02:05:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: RuntimeBroker.exe, version: 10.0.18362.1, time stamp: 0x4539d5a0
Faulting module name: SettingsEnvironment.Desktop.dll, version: 10.0.18362.387, time stamp: 0x10b406e4
Exception code: 0xc0000005
Fault offset: 0x000000000002b605
Faulting process id: 0x5c4
Faulting application start time: 0x01d5e0ddce6a459c
Faulting application path: C:\Windows\System32\RuntimeBroker.exe
Faulting module path: C:\WINDOWS\SYSTEM32\SettingsEnvironment.Desktop.dll
Report Id: cff7b944-3141-486d-9c01-c0b1a6317903
Faulting package full name: Microsoft.Windows.Cortana_1.13.0.18362_neutral_neutral_cw5n1h2txyewy
Faulting package-relative application ID: runtimebroker07f4358a809ac99a64a67c1
Error: (02/11/2020 02:03:30 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (7744,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (02/11/2020 01:23:51 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (10712,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (02/10/2020 08:26:08 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (10856,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
System errors:
=============
Error: (02/05/2020 06:48:33 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (02/05/2020 06:48:31 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (02/02/2020 08:50:28 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (02/02/2020 08:50:26 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (02/02/2020 08:24:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The %1!s! Update Service (avast) service failed to start due to the following error:
The system cannot find the file specified.
Error: (02/02/2020 07:39:41 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume C:.
A corruption was found in a file system index structure. The file reference number is 0xe000000032ce2. The name of the file is "\Program Files\Common Files\Bitdefender\Bitdefender Threat Scanner\Antivirus_59987_003\Plugins". The corrupted index attribute is ":$I30:$INDEX_ALLOCATION".
Error: (02/02/2020 07:39:41 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (02/02/2020 07:39:28 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Windows Defender:
===================================
Date: 2020-02-01 21:06:31.640
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {9E18AF29-209C-4498-9519-1AED9B807900}
Scan Type: Antimalware
Scan Parameters: Quick Scan
CodeIntegrity:
===================================
Date: 2020-02-01 21:24:16.746
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Date: 2020-02-01 21:24:16.718
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.
Date: 2020-02-01 21:24:16.573
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Date: 2020-02-01 21:24:16.522
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.
Date: 2020-02-01 21:24:14.269
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.
Date: 2020-02-01 21:24:11.986
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.
Date: 2020-02-01 21:13:33.030
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Date: 2020-02-01 21:13:32.992
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.
==================== Memory info ===========================
BIOS: Dell Inc. A09 02/01/2013
Motherboard: Dell Inc. 084J0R
Processor: Intel® Pentium® CPU G2020 @ 2.90GHz
Percentage of memory in use: 80%
Total physical RAM: 3967.54 MB
Available physical RAM: 756.13 MB
Total Virtual: 7935.54 MB
Available Virtual: 3515.01 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:456.5 GB) (Free:413.45 GB) NTFS
\\?\Volume{9d80cf44-4223-11e3-adbc-806e6f6e6963}\ (RECOVERY) (Fixed) (Total:9.22 GB) (Free:4.07 GB) NTFS
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 2566B9A3)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=9.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=456.5 GB) - (Type=07 NTFS)
==================== End of Addition.txt =======================