Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Bitdefender showing infected web page detected when browsing with fire


  • Please log in to reply

#1
bytesize

bytesize

    Member

  • Member
  • PipPip
  • 96 posts

Upgraded friends PC last week from Windows 7 to Windows 10 and installed Bitdefender, since he has been using it "Bitdefender showing infected web page detected when browsing with firefox" message is coming up all the time. Got it back from him today the information in Bitdefender is

 

We blocked this dangerous page for your protection: https://polinaryapp....dd84a1d2a730.jsThreat name: JS:Adware.Lnkr.A Dangerous pages attempt to install software that can harm the device, gather personal information or operate without your consent.

 

We blocked this dangerous page for your protection: https://toolsmagick....9d09bdba7f1b.jsThreat name: JS:Adware.Lnkr.A Dangerous pages attempt to install software that can harm the device, gather personal information or operate without your consent.

 

There were 2 extensions in Firefox SAML-tracer and another called App something which I removed and since then I have had no more notifications from bitdefender. Just looking for some advice to make sure system is ok. Scan results are posted below, thanks.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-02-2020 02
Ran by Eddie (administrator) on EDDIEDELL (Dell Inc. Vostro 270) (11-02-2020 18:08:06)
Running from C:\Users\Eddie\Desktop
Loaded Profiles: Eddie (Available Profiles: Eddie)
Platform: Windows 10 Pro Version 1909 18363.628 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\DiscoverySrv.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Device Management\DevMgmtService.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdtrackersnmh.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdwtxag.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [DBRMTray] => C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation) [File not signed]
HKLM\...\Run: [flvga_tray64] => C:\Windows\system32\flvga_tray.exe [419328 2015-12-07] () [File not signed]
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3933496 2012-09-20] (Logitech -> Logitech, Inc.)
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\Run: [VideoGuardMonitor] => C:\Users\Eddie\AppData\Local\Cisco\VideoGuardPlayer\VideoGuardMonitor\CiscoVideoGuardMonitor.exe [2345736 2017-11-02] (Cisco Video Technologies Israel Ltd. -> Cisco)
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\Run: [EPSON SX410 Series] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIFCE.EXE [223232 2008-10-02] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.130\Installer\chrmstp.exe [2020-01-22] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {01495D74-89D8-4B56-9A66-6CB0E27EF3B9} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {053D1D96-34A1-43DB-A08C-42013752D3E2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-01] (Google Inc -> Google Inc.)
Task: {0ACED679-9CB3-4827-A46A-2BCC4D55023D} - \Microsoft\Windows\Setup\EOSNotify2 -> No File <==== ATTENTION
Task: {0E9B0B5C-9FF3-4A29-8479-0868A68DD87B} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {20547455-08F6-4781-81F0-355BF009032E} - System32\Tasks\Bitdefender AgentTask_AD394AE64E874073B10A89FEEC305A3C => C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe [525120 2019-12-06] (Bitdefender SRL -> Bitdefender)
Task: {24093C7A-BB64-4A0F-967B-30A04900E47E} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4f47-879B-29A80C355D61}
Task: {2956E29D-A64D-413D-B892-F5AA2AC347BB} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {3999671B-80BF-4CDF-A95C-93FD2F0FE480} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {3B12223C-54DE-4CFC-8307-4A1D915AF6A3} - System32\Tasks\Microsoft\Windows\End Of Support\Notify1 => C:\WINDOWS\system32\sipnotify.exe
Task: {3CBC40D7-5079-4162-B3CF-8BB086B1F88F} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47c2-B62A-B7C4CED925CB}
Task: {49072A42-1C33-4821-800D-28DD295D6786} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {4952B2DA-0911-4A59-84B7-70CE6138225C} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
Task: {4FF356D2-FE47-4920-B00B-3E8B260DCA26} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {528B6446-B6F7-44E3-AA71-6203798B4E57} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {53C82D5D-CAA2-4928-AD01-FD5CA9402E42} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {54C24529-FE0D-45F3-921C-72B199731A29} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {5681C43E-9E0F-4FBB-AF45-8126839219E0} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [490808 2019-11-27] (Bitdefender SRL -> Bitdefender)
Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A}
Task: {63882D74-4B0D-4654-86EE-D96AE3948093} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6563DB5C-54FD-4007-98A3-1F779956369C} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {67C59A98-0975-4C0D-BC85-5E23C19BED38} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe
Task: {6A73D90C-B17C-4761-8357-1A346F1A3327} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {74B79B52-5FD9-4C14-BAB0-205B4C4DD9F9} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {7999A0A7-D11A-45C6-BDD2-8E903177FB5A} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {834A60BA-2D0F-4377-BE69-8C0777570D5A} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
Task: {92BE7943-78D8-4C4B-883D-3B2AAF434323} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {ACDC58CF-A087-48C0-A33C-1903B2116D07} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43da-BFD7-FBEEA2180A1E}
Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40b4-8963-D3C761B18371}
Task: {B1450FE1-82E8-40F1-8F3F-5749E0F9E20E} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {BA7F3875-7416-4EF5-B045-A03824D3AFA2} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {C1913C94-0842-490C-B755-F95332E09ABA} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {C35DD040-7390-40B7-B2DE-4D2574A463EB} - System32\Tasks\Microsoft\Windows\End Of Support\Notify2 => C:\WINDOWS\system32\sipnotify.exe
Task: {C92F3B8C-9131-4D30-8E74-934DCB76B59F} - \Microsoft\Windows\Setup\EOSNotify -> No File <==== ATTENTION
Task: {CE4EEC05-AE50-4266-B124-7496745958B2} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D2ACE0C1-E609-4CDD-AE28-98BEE54A0267} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1873288 2019-09-18] (AVAST Software s.r.o. -> AVAST Software)
Task: {DA5EBFDD-F0C4-44BB-802B-EC827B4A9BF5} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DA9D1E83-01AA-4187-BDB9-6D13247DE477} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E0024056-A3C8-4FB2-88B3-77B17119DC8B} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {E0AA4134-CDC5-47C0-AFAF-C7CDC34DBC40} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-01] (Google Inc -> Google Inc.)
Task: {EE53A167-6087-475B-A68D-3CDDED69B013} - \Microsoft\Windows\Setup\UpgradeTriggers\UpgradeReminderTask -> No File <==== ATTENTION
Task: {F218EEF0-1004-40A5-A322-21D0A63B9A31} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDfE067B1}
Task: {FFD0BCF8-7926-4344-A2B0-908C275D350D} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.132.1
Tcpip\..\Interfaces\{7059D287-A263-4A16-854D-FFC987708542}: [DhcpNameServer] 192.168.132.1
Tcpip\..\Interfaces\{8C412334-6E80-4EC8-9F2B-E48E60423A89}: [DhcpNameServer] 194.168.4.100 194.168.8.100
Tcpip\..\Interfaces\{CCEB5E90-4E48-420A-A652-21003662E153}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.co.uk/
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www1.euro.dell.com/content/default.aspx?c=uk&l=en&s=gen
BHO: Bitdefender Trackers Blocking -> {159ff5d5-55f1-4d2f-b706-767a55f77abb} -> C:\Program Files\Bitdefender\Bitdefender Security\bdtbie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
BHO: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
BHO-x32: Bitdefender Trackers Blocking -> {159ff5d5-55f1-4d2f-b706-767a55f77abb} -> C:\Program Files\Bitdefender\Bitdefender Security\antispam32\bdtbie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
BHO-x32: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
Toolbar: HKLM - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
Toolbar: HKLM-x32 - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)

FireFox:
========
FF DefaultProfile: g6p9p80w.default
FF ProfilePath: C:\Users\Eddie\AppData\Roaming\Mozilla\Firefox\Profiles\g6p9p80w.default [2020-02-11]
FF NewTab: Mozilla\Firefox\Profiles\g6p9p80w.default -> about:home
FF Notifications: Mozilla\Firefox\Profiles\g6p9p80w.default -> hxxps://mail.virginmedia.com; hxxp://mail.virginmedia.com; hxxps://www.bingotastic.com; hxxps://www.youtube.com; hxxps://www.facebook.com; hxxps://www.ebay.co.uk; hxxps://www.epson.co.uk; hxxps://0.nextyourcontent.com; hxxps://1.nextyourcontent.com; hxxps://2.nextyourcontent.com
FF NewTabOverride: Mozilla\Firefox\Profiles\g6p9p80w.default -> Disabled: [email protected]
FF Extension: (No Name) - C:\Users\Eddie\AppData\Roaming\Mozilla\Firefox\Profiles\g6p9p80w.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-10-22]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi
FF Extension: (Bitdefender Wallet) - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi [2019-12-06]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbef.xpi
FF Extension: (Bitdefender Anti-tracker) - C:\Program Files\Bitdefender\Bitdefender Security\bdtbef.xpi [2019-11-01]
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext
FF Extension: (Bitdefender Antispam Toolbar) - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext [2020-01-08] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbef.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\bd_js_config.js [2020-02-02] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\bd_config.cfg [2020-02-02] <==== ATTENTION

Chrome:
=======
CHR Profile: C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default [2020-02-02]
CHR HomePage: Default -> hxxp://www.google.com
CHR Extension: (Slides) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-12-18]
CHR Extension: (Docs) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-13]
CHR Extension: (Google Drive) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-03]
CHR Extension: (YouTube) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-03]
CHR Extension: (Sheets) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-12-13]
CHR Extension: (Bitdefender Wallet) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\gannpgaobkkhmpomoijebaigcapoeebl [2020-02-02]
CHR Extension: (Google Docs Offline) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-02-02]
CHR Extension: (Bitdefender Anti-tracker) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\khndhdhbebhaddchcgnalcjlaekbbeof [2020-02-02]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-02-02]
CHR Extension: (Gmail) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-06-10]
CHR Extension: (Chrome Media Router) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-02-02]
CHR HKLM-x32\...\Chrome\Extension: [gannpgaobkkhmpomoijebaigcapoeebl]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
CHR HKLM-x32\...\Chrome\Extension: [khndhdhbebhaddchcgnalcjlaekbbeof]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 BDAuxSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [803576 2019-12-06] (Bitdefender SRL -> Bitdefender)
R2 BDProtSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [803576 2019-12-06] (Bitdefender SRL -> Bitdefender)
R2 bdredline; C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe [2195344 2018-03-22] (Bitdefender SRL -> Bitdefender)
R2 DevMgmtService; C:\Program Files\Bitdefender\Bitdefender Device Management\DevMgmtService.exe [119368 2019-12-06] (Bitdefender SRL -> Bitdefender)
S4 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE [163840 2007-12-17] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
S4 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE [126464 2007-01-11] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
S4 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [328608 2015-07-30] (Intel Corporation - pGFX -> Intel Corporation)
S2 MBAMInstallerService; C:\Users\Eddie\AppData\Local\Temp\MBAMInstallerService.exe [5225688 2020-02-11] (Malwarebytes Inc -> Malwarebytes) <==== ATTENTION
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1329240 2020-01-15] (Bitdefender SRL -> Bitdefender)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5796168 2020-01-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe [151656 2019-12-06] (Bitdefender SRL -> Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [803576 2019-12-06] (Bitdefender SRL -> Bitdefender)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2020-01-29] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2020-01-29] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 avast; "C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /svc [X]
S3 avastm; "C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /medsvc [X]
S3 McComponentHostService; "C:\Program Files\McAfee Security Scan\3.11.561\McCHSvc.exe" [X]

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 atc; C:\WINDOWS\System32\DRIVERS\atc.sys [1693368 2019-09-23] (Bitdefender SRL -> Bitdefender S.R.L. Bucharest, ROMANIA)
S3 athur; C:\WINDOWS\System32\DRIVERS\athurx.sys [1847296 2010-01-05] (Microsoft Windows Hardware Compatibility Publisher -> Atheros Communications, Inc.)
R2 BdDci; C:\WINDOWS\system32\DRIVERS\bddci.sys [739264 2019-07-29] (Bitdefender SRL -> Bitdefender)
S0 bdelam; C:\WINDOWS\System32\drivers\bdelam.sys [22960 2019-03-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Bitdefender)
R0 bdprivmon; C:\WINDOWS\System32\DRIVERS\bdprivmon.sys [46056 2019-06-21] (Bitdefender SRL -> © Bitdefender SRL)
R1 BDVEDISK; C:\WINDOWS\system32\DRIVERS\bdvedisk.sys [96448 2018-04-27] (Bitdefender SRL -> BitDefender)
R0 Gemma; C:\WINDOWS\System32\DRIVERS\gemma.sys [564112 2019-11-07] (Bitdefender SRL -> BitDefender S.R.L. Bucharest, ROMANIA)
R0 gzflt; C:\WINDOWS\System32\DRIVERS\gzflt.sys [188384 2018-11-28] (Bitdefender SRL -> BitDefender LLC)
R2 Ignis; C:\WINDOWS\system32\DRIVERS\ignis.sys [196392 2019-07-04] (Bitdefender SRL -> Bitdefender)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [216544 2020-01-07] (Malwarebytes Inc -> Malwarebytes)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [662528 2019-03-19] (Microsoft Windows -> Realtek )
R0 trufos; C:\WINDOWS\System32\DRIVERS\trufos.sys [610640 2019-01-14] (Bitdefender SRL -> Bitdefender)
U5 vwifimp; C:\Windows\System32\Drivers\vwifimp.sys [50176 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45664 2020-01-29] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [355760 2020-01-29] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2020-01-29] (Microsoft Windows -> Microsoft Corporation)
U3 idsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-02-11 18:08 - 2020-02-11 18:09 - 000022976 _____ C:\Users\Eddie\Desktop\FRST.txt
2020-02-11 18:05 - 2020-02-11 18:05 - 002279424 _____ (Farbar) C:\Users\Eddie\Desktop\FRST64.exe
2020-02-02 20:22 - 2020-02-02 20:22 - 000000080 ___SH C:\bootTel.dat
2020-02-02 10:21 - 2020-02-02 10:21 - 000157636 _____ C:\ProgramData\dm.update.1580638881.bdinstall.v2.bin
2020-02-02 10:21 - 2020-02-02 10:21 - 000036233 _____ C:\ProgramData\dm.uninstall.1580638890.bdinstall.bin
2020-02-02 10:20 - 2020-02-02 10:20 - 000000000 ____D C:\ProgramData\Bitdefender Device Management
2020-02-02 10:19 - 2020-02-02 10:19 - 000817888 _____ C:\ProgramData\cl.1580638097.bdinstall.v2.bin
2020-02-02 10:19 - 2020-02-02 10:19 - 000102260 _____ C:\ProgramData\cl.kit.1580638087.bdinstall.v2.bin
2020-02-02 10:19 - 2020-02-02 10:19 - 000003420 _____ C:\WINDOWS\system32\Tasks\Bitdefender AgentTask_AD394AE64E874073B10A89FEEC305A3C
2020-02-02 10:18 - 2020-02-02 10:18 - 000000000 ____D C:\ProgramData\Gemma
2020-02-02 10:18 - 2020-02-02 10:18 - 000000000 ____D C:\ProgramData\Atc
2020-02-02 10:17 - 2020-02-02 10:17 - 000002431 _____ C:\Users\Public\Desktop\Bitdefender VPN.lnk
2020-02-02 10:17 - 2020-02-02 10:17 - 000002431 _____ C:\ProgramData\Desktop\Bitdefender VPN.lnk
2020-02-02 10:17 - 2020-02-02 10:17 - 000002344 _____ C:\Users\Public\Desktop\Bitdefender.lnk
2020-02-02 10:17 - 2020-02-02 10:17 - 000002344 _____ C:\ProgramData\Desktop\Bitdefender.lnk
2020-02-02 10:17 - 2020-02-02 10:17 - 000000000 ____D C:\WINDOWS\system32\elambkup
2020-02-02 10:17 - 2020-02-02 10:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender Security
2020-02-02 10:17 - 2020-02-02 10:17 - 000000000 ____D C:\ProgramData\BDLogging
2020-02-02 10:17 - 2019-03-21 00:12 - 000022960 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bdelam.sys
2020-02-02 10:16 - 2019-11-07 08:49 - 000564112 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\gemma.sys
2020-02-02 10:16 - 2019-09-23 08:43 - 001693368 _____ (Bitdefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\atc.sys
2020-02-02 10:16 - 2019-07-29 15:32 - 000739264 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bddci.sys
2020-02-02 10:16 - 2019-06-21 07:30 - 000046056 _____ (© Bitdefender SRL) C:\WINDOWS\system32\Drivers\bdprivmon.sys
2020-02-02 10:16 - 2018-04-27 07:45 - 000096448 _____ (BitDefender) C:\WINDOWS\system32\Drivers\bdvedisk.sys
2020-02-02 10:15 - 2020-02-02 10:43 - 000000000 ____D C:\ProgramData\Bitdefender
2020-02-02 10:15 - 2020-02-02 10:21 - 000000000 ____D C:\Program Files\Bitdefender
2020-02-02 10:15 - 2020-02-02 10:20 - 000000000 ____D C:\Users\Eddie\AppData\Roaming\Bitdefender
2020-02-02 10:15 - 2019-07-04 11:15 - 000196392 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\ignis.sys
2020-02-02 10:15 - 2019-01-14 16:25 - 000610640 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\trufos.sys
2020-02-02 10:15 - 2018-11-28 05:45 - 000188384 _____ (BitDefender LLC) C:\WINDOWS\system32\Drivers\gzflt.sys
2020-02-02 10:08 - 2020-02-02 10:15 - 000000000 ____D C:\Program Files\Common Files\Bitdefender
2020-02-02 10:08 - 2020-02-02 10:08 - 000003802 _____ C:\WINDOWS\system32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
2020-02-02 10:06 - 2020-02-02 10:20 - 000000000 ____D C:\Program Files\Bitdefender Agent
2020-02-02 10:06 - 2020-02-02 10:06 - 000113524 _____ C:\ProgramData\agent.1580637970.bdinstall.v2.bin
2020-02-02 10:06 - 2020-02-02 10:06 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2020-02-02 10:05 - 2020-02-02 10:05 - 012422992 _____ C:\Users\Eddie\Downloads\bitdefender_windows_d19acce7-90aa-4746-a6ad-21b2e4307aa2.exe
2020-01-31 17:47 - 2020-01-31 17:47 - 000000000 ____D C:\Users\Eddie\AppData\Local\PeerDistRepub
2020-01-31 17:10 - 2020-01-31 17:27 - 000000000 ____D C:\Users\Eddie\AppData\Local\D3DSCache
2020-01-31 16:35 - 2020-01-31 16:35 - 000000000 ____D C:\WINDOWS\system32\appmgmt
2020-01-30 00:39 - 2020-01-30 00:39 - 000000000 ____D C:\Program Files\Common Files\SpeechEngines
2020-01-30 00:38 - 2020-01-30 00:38 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2020-01-30 00:37 - 2020-01-30 00:37 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2020-01-30 00:35 - 2020-01-30 00:35 - 003365376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\WINDOWS\system32\msmq
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\WINDOWS\system32\BestPractices
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\Program Files\Reference Assemblies
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\Program Files\MSBuild
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\Program Files (x86)\MSBuild
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\inetpub
2020-01-30 00:33 - 2019-03-02 01:31 - 001166488 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2020-01-30 00:33 - 2019-03-02 01:31 - 000124568 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2020-01-30 00:33 - 2019-03-02 01:31 - 000035592 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2020-01-30 00:33 - 2019-02-06 02:41 - 000778912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2020-01-30 00:33 - 2019-02-06 02:41 - 000103072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2020-01-30 00:33 - 2019-02-06 02:41 - 000035592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2020-01-30 00:32 - 2019-03-19 03:21 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2020-01-30 00:32 - 2019-03-19 03:20 - 004470272 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2020-01-30 00:32 - 2019-03-19 03:16 - 000903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2020-01-30 00:32 - 2019-03-19 02:15 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2020-01-30 00:32 - 2019-03-19 02:09 - 000568320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2020-01-30 00:32 - 2019-03-02 01:33 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2020-01-30 00:32 - 2018-08-09 22:53 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2020-01-29 21:13 - 2020-01-29 21:13 - 000000144 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2020-01-29 20:25 - 2020-01-29 20:25 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 022635008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 019812864 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 018026496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 009926968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 007754240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 007600656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 007259648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 006516648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 006435840 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 006285312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 006083832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 005914112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 005764664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 005112320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 004856832 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 004348616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 003967888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 003819008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 003550208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 003372440 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 003243080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002988552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 002801152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 002773776 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002766088 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002703872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002584008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002493928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002314952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002260176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002225160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002084576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002032128 _____ C:\WINDOWS\system32\rdpnano.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001916744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001858560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001835128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-01-29 20:25 - 2020-01-29 20:25 - 001743672 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001726480 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001693184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001610752 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001541632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 001512320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 001489064 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001417760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001412096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001399304 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 001394168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001372160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-01-29 20:25 - 2020-01-29 20:25 - 001300280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 001283592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2020-01-29 20:25 - 2020-01-29 20:25 - 001283584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001182232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 001170960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001154448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001151816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001105776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001097216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001083392 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001073168 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 001051448 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001000960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000974336 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000928120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000913408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000892488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000891736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000890368 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000875144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000828216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000824848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000805376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000788992 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000768488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000749568 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000747320 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000704512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000679160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000673080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000661816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000637440 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000617784 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000598528 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000587064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000568120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000545432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000518184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000510768 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000500736 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2020-01-29 20:25 - 2020-01-29 20:25 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2020-01-29 20:25 - 2020-01-29 20:25 - 000476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000467648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000465208 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000453432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000444928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000441072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2020-01-29 20:25 - 2020-01-29 20:25 - 000416056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\DispBroker.Desktop.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000404912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000399360 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000384000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000375504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000366416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000345088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000324616 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000311096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000300392 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\msutb.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000259984 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoncli.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000248064 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofm.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2020-01-29 20:25 - 2020-01-29 20:25 - 000221200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msutb.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\regapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000193592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000190464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\regapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000190256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logoncli.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2020-01-29 20:25 - 2020-01-29 20:25 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000174392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppvVemgr.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000153912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppvVfs.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatialAudioLicenseSrv.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000143160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000138040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppVStrm.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetDriverInstall.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000107832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairingExperienceMEM.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000106808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000099712 _____ (Microsoft Corporation) C:\WINDOWS\system32\FsIso.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\compstui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000093704 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000089328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSystray.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000084496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetDriverInstall.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedsbs.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000072816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\findnetprinters.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\printui.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000063288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\printui.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000059221 _____ C:\WINDOWS\system32\srms.dat
2020-01-29 20:25 - 2020-01-29 20:25 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\findnetprinters.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\npmproxy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000042512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcicda.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmproxy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mciwave.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mciseq.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000021304 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000019768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmsprep.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedssync.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedssync.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-01-29 20:24 - 2020-01-29 20:24 - 007905208 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 006231200 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 006167552 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 004615376 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 004470784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 004005888 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 003729408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 003703296 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 003591184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 003110400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 002284544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 002125904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 002071552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001942016 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001841152 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001748480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 001413912 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 001083904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001027000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000874512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000737280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000732200 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000716288 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000642008 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000637968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000589592 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000536064 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000459896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000437776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000415808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000350720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SpeechPrivacy.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000296760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000194064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\tssrvlic.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AppExecutionAlias.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_BackgroundApps.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationControlCSP.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000117264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000089912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000088352 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\LSCSHostPolicy.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcicda.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000047208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mciwave.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mciseq.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\lstelemetry.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindflt.dll
2020-01-29 20:05 - 2020-01-31 17:27 - 000000000 __SHD C:\Users\Eddie\IntelGraphicsProfiles
2020-01-29 20:05 - 2020-01-29 20:05 - 000000451 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2020-01-29 17:36 - 2020-02-03 11:40 - 000000000 ____D C:\Users\Eddie\AppData\Local\PlaceholderTileLogoFolder
2020-01-29 17:22 - 2020-01-29 17:23 - 000000000 ____D C:\Users\Eddie\AppData\Local\Comms
2020-01-29 17:21 - 2020-01-29 19:01 - 000000000 ____D C:\ProgramData\Packages
2020-01-29 17:20 - 2020-02-10 17:21 - 000003368 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3631865646-3207491450-1134192123-1000
2020-01-29 17:20 - 2020-02-10 17:21 - 000000000 ___RD C:\Users\Eddie\OneDrive
2020-01-29 17:17 - 2020-01-29 17:17 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2020-01-29 17:16 - 2020-01-29 17:16 - 000001450 _____ C:\Users\Eddie\Desktop\Microsoft Edge.lnk
2020-01-29 17:04 - 2020-01-29 17:04 - 000000000 ___HD C:\Users\Eddie\MicrosoftEdgeBackups
2020-01-29 17:04 - 2020-01-29 17:04 - 000000000 ____D C:\Users\Eddie\AppData\Local\MicrosoftEdge
2020-01-29 17:03 - 2020-01-29 21:13 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-01-29 17:03 - 2020-01-29 21:13 - 000000000 ___RD C:\Users\Eddie\3D Objects
2020-01-29 17:03 - 2020-01-29 17:55 - 000000000 ____D C:\Users\Eddie\AppData\Local\Publishers
2020-01-29 17:02 - 2020-01-31 16:47 - 000000000 ____D C:\Users\Eddie\AppData\Local\Packages
2020-01-29 17:02 - 2020-01-29 17:03 - 000000000 ____D C:\Users\Eddie\AppData\Local\ConnectedDevicesPlatform
2020-01-29 17:02 - 2020-01-29 17:02 - 000000020 ___SH C:\Users\Eddie\ntuser.ini
2020-01-29 17:00 - 2020-02-05 11:12 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-01-29 17:00 - 2020-02-05 11:12 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-01-29 17:00 - 2020-02-02 20:22 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-01-29 17:00 - 2020-01-29 19:04 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-01-29 17:00 - 2020-01-29 17:01 - 000003486 _____ C:\WINDOWS\system32\Tasks\AvastUpdateTaskMachineUA
2020-01-29 17:00 - 2020-01-29 17:00 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2020-01-29 17:00 - 2020-01-29 17:00 - 000007623 _____ C:\WINDOWS\diagerr.xml
2020-01-29 17:00 - 2020-01-29 17:00 - 000003358 _____ C:\WINDOWS\system32\Tasks\AvastUpdateTaskMachineCore
2020-01-29 17:00 - 2020-01-29 17:00 - 000000000 ____D C:\WINDOWS\system32\Tasks\WPD
2020-01-29 17:00 - 2020-01-29 17:00 - 000000000 ____D C:\WINDOWS\system32\Tasks\Games
2020-01-29 17:00 - 2020-01-29 17:00 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2020-01-29 17:00 - 2016-05-19 13:27 - 000003184 _____ C:\WINDOWS\system32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2020-01-29 16:53 - 2020-02-10 17:21 - 000002410 _____ C:\Users\Eddie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-01-29 16:53 - 2020-02-02 20:17 - 000000000 ____D C:\Users\Eddie
2020-01-29 16:52 - 2020-01-29 21:16 - 000936048 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-01-29 16:49 - 2020-01-09 21:24 - 002874368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2020-01-29 16:48 - 2020-01-29 16:48 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2020-01-29 16:45 - 2020-02-11 18:00 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-01-29 16:45 - 2020-01-29 21:12 - 000413136 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-01-29 15:33 - 2020-02-10 12:56 - 000000000 ___DC C:\WINDOWS\Panther
2020-01-29 15:19 - 2020-01-29 15:33 - 000000000 ____D C:\ESD
2020-01-29 15:17 - 2020-01-29 15:17 - 000000000 ___HD C:\$Windows.~WS
2020-01-29 15:15 - 2020-01-29 15:15 - 000030165 _____ C:\WINDOWS\system32\servers.def.lkg
2020-01-29 15:15 - 2020-01-29 15:15 - 000030165 _____ C:\WINDOWS\system32\servers.def
2020-01-29 15:15 - 2020-01-29 15:15 - 000004451 _____ C:\WINDOWS\system32\uat64.vpx
2020-01-29 15:15 - 2020-01-29 15:15 - 000003333 _____ C:\WINDOWS\system32\servers.def.vpx
2020-01-29 15:15 - 2020-01-29 15:15 - 000000602 _____ C:\WINDOWS\system32\prod-pgm.vpx
2020-01-29 15:15 - 2020-01-29 15:15 - 000000540 _____ C:\WINDOWS\system32\.tmp
2020-01-29 15:15 - 2020-01-29 15:15 - 000000341 _____ C:\WINDOWS\system32\prod-vps.vpx
2020-01-29 15:13 - 2020-01-29 15:13 - 019255000 _____ (Microsoft Corporation) C:\Users\Eddie\Downloads\MediaCreationTool1909.exe

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-02-11 18:08 - 2017-03-08 14:43 - 000000000 ____D C:\FRST
2020-02-11 14:39 - 2019-03-19 04:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-02-11 14:29 - 2016-11-18 15:24 - 000000000 ____D C:\Users\Eddie\AppData\LocalLow\Mozilla
2020-02-11 14:27 - 2016-05-08 12:28 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2020-02-11 14:27 - 2014-02-13 14:01 - 000001165 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-02-11 14:27 - 2014-02-13 14:01 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-02-09 22:09 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-02-08 16:00 - 2019-03-19 04:37 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-02-02 20:54 - 2019-03-19 04:50 - 000000000 ____D C:\WINDOWS\INF
2020-02-02 20:17 - 2019-03-19 04:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-02-02 10:27 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-02-02 10:27 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-02-02 10:27 - 2017-03-12 10:39 - 000000000 ____D C:\Program Files (x86)\Adobe
2020-01-31 17:41 - 2016-05-26 15:42 - 000007619 _____ C:\Users\Eddie\AppData\Local\resmon.resmoncfg
2020-01-31 17:09 - 2019-03-19 04:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-01-31 16:34 - 2018-05-16 09:02 - 000000000 ____D C:\Users\Eddie\AppData\Local\AVAST Software
2020-01-31 16:34 - 2017-03-10 14:51 - 000000000 ____D C:\ProgramData\AVAST Software
2020-01-31 15:50 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\appcompat
2020-01-30 00:44 - 2019-09-16 12:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2020-01-30 00:44 - 2019-03-19 04:56 - 000000000 ____D C:\WINDOWS\Setup
2020-01-30 00:44 - 2019-03-19 04:52 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2020-01-30 00:44 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-01-30 00:44 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\NDF
2020-01-30 00:44 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-01-30 00:44 - 2019-03-19 04:49 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2020-01-30 00:44 - 2016-12-27 18:56 - 000000000 __SHD C:\WINDOWS\SysWOW64\AI_RecycleBin
2020-01-30 00:44 - 2016-05-24 03:43 - 000000000 ____D C:\WINDOWS\system32\configBackup
2020-01-30 00:44 - 2014-08-06 19:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson Software
2020-01-30 00:44 - 2014-07-10 13:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 6.0 Sprint
2020-01-30 00:44 - 2014-07-10 13:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2020-01-30 00:44 - 2014-07-10 12:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2020-01-30 00:44 - 2014-03-25 20:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2020-01-30 00:44 - 2013-10-31 11:58 - 000000000 ____D C:\Program Files (x86)\Intel
2020-01-30 00:44 - 2013-10-31 10:02 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2020-01-30 00:44 - 2010-11-21 07:17 - 000000000 ____D C:\WINDOWS\ShellNew
2020-01-30 00:44 - 2009-07-14 03:20 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2020-01-30 00:44 - 2009-07-14 03:20 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2020-01-30 00:41 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2020-01-30 00:41 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\IME
2020-01-30 00:39 - 2019-03-19 04:52 - 000000000 __SHD C:\Program Files\Windows Sidebar
2020-01-30 00:39 - 2019-03-19 04:52 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
2020-01-30 00:39 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\schemas
2020-01-30 00:39 - 2014-02-13 16:48 - 000000000 ____D C:\Program Files\Microsoft Games
2020-01-30 00:39 - 2013-10-31 11:59 - 000000000 ____D C:\Program Files\CONEXANT
2020-01-30 00:39 - 2009-07-14 05:32 - 000000000 ____D C:\Program Files\DVD Maker
2020-01-30 00:34 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2020-01-30 00:34 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2020-01-30 00:33 - 2020-01-09 21:26 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2020-01-30 00:33 - 2020-01-09 21:26 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2020-01-30 00:33 - 2020-01-09 21:26 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngkeyhelper.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2020-01-30 00:33 - 2020-01-09 21:25 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2020-01-30 00:33 - 2019-03-19 05:00 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2020-01-30 00:33 - 2019-03-19 05:00 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2020-01-30 00:33 - 2019-03-19 05:00 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2020-01-30 00:33 - 2019-03-19 05:00 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2020-01-30 00:33 - 2019-03-19 05:00 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2020-01-30 00:33 - 2019-03-19 04:58 - 001401344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000783872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000304640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2020-01-30 00:33 - 2019-03-19 04:58 - 000230912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2020-01-30 00:33 - 2019-03-19 04:58 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2020-01-30 00:33 - 2019-03-19 04:58 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2020-01-30 00:33 - 2019-03-19 04:58 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2020-01-30 00:33 - 2019-03-19 04:58 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2020-01-30 00:33 - 2019-03-19 04:58 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2020-01-30 00:33 - 2019-03-19 04:58 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2020-01-30 00:33 - 2019-03-19 04:58 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2020-01-30 00:33 - 2019-03-19 04:57 - 000134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2020-01-30 00:33 - 2019-03-19 04:57 - 000128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\et-EE
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\es-MX
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SystemResources
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-01-29 19:04 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files\Windows Defender
2020-01-29 19:01 - 2019-03-19 04:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-01-29 17:53 - 2013-10-31 10:03 - 000000000 ____D C:\Program Files\Intel
2020-01-29 17:50 - 2019-03-19 04:37 - 000000000 ____D C:\WINDOWS\servicing
2020-01-29 17:42 - 2010-11-21 03:27 - 000748816 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-01-29 17:40 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2020-01-29 17:40 - 2019-03-19 04:52 - 000000000 ____D C:\ProgramData\USOPrivate
2020-01-29 17:22 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\ServiceState
2020-01-29 17:11 - 2019-03-19 06:22 - 000000000 ____D C:\WINDOWS\OCR
2020-01-29 17:02 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\spool
2020-01-29 17:00 - 2019-03-19 04:52 - 000000000 __RHD C:\Users\Public\Libraries
2020-01-29 16:59 - 2017-04-01 13:22 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-01-29 16:59 - 2017-04-01 13:22 - 000002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-01-29 16:59 - 2017-04-01 13:22 - 000002262 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-01-29 16:54 - 2018-04-15 13:37 - 000000000 ____D C:\Users\Eddie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sky
2020-01-29 16:52 - 2011-02-10 14:33 - 000892382 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2020-01-29 16:50 - 2019-03-19 04:52 - 000000000 ___RD C:\WINDOWS\PrintDialog
2020-01-29 16:17 - 2009-07-14 04:45 - 000021312 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-01-29 16:17 - 2009-07-14 04:45 - 000021312 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-01-15 21:52 - 2014-02-13 15:34 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-01-15 21:48 - 2014-02-13 15:34 - 120202352 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

==================== Files in the root of some directories ========

2014-10-29 16:15 - 2014-10-29 16:15 - 000004096 ____H () C:\Users\Eddie\AppData\Local\keyfile3.drm
2016-05-26 15:42 - 2020-01-31 17:41 - 000007619 _____ () C:\Users\Eddie\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-02-2020 02
Ran by Eddie (11-02-2020 18:11:18)
Running from C:\Users\Eddie\Desktop
Windows 10 Pro Version 1909 18363.628 (X64) (2020-01-29 17:02:07)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3631865646-3207491450-1134192123-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3631865646-3207491450-1134192123-503 - Limited - Disabled)
Eddie (S-1-5-21-3631865646-3207491450-1134192123-1000 - Administrator - Enabled) => C:\Users\Eddie
Guest (S-1-5-21-3631865646-3207491450-1134192123-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3631865646-3207491450-1134192123-1002 - Limited - Enabled)
WDAGUtilityAccount (S-1-5-21-3631865646-3207491450-1134192123-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Bitdefender Antivirus (Enabled - Up to date) {0E17DB7D-A20F-62CE-B95B-17DB0CDFE318}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Enabled) {362C5A58-E860-6396-9204-BEEEF20CA463}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

ABBYY FineReader 6.0 Sprint (HKLM-x32\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1395.4512 - ABBYY Software House)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 24.0.1.161 - Bitdefender)
Bitdefender Device Management (HKLM\...\Bitdefender Device Management) (Version: 24.0.14.86 - Bitdefender)
Bitdefender Total Security (HKLM\...\Bitdefender) (Version: 24.0.14.85 - Bitdefender)
Cisco VideoGuard Player (HKLM-x32\...\{30e4813e-2a86-4e4f-82ea-23df71ca8ffb}) (Version: 10.1.1.6570 - Cisco Systems, Inc)
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Epson Easy Photo Print 2 (HKLM-x32\...\{87C2248A-C7DD-49ED-9BCD-B312A9D0819E}) (Version: 2.1.0.0 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )
Epson Stylus SX210_SX410_TX210_TX410 Manual (HKLM-x32\...\Epson Stylus SX210_SX410_TX210_TX410 User’s Guide) (Version:  - )
EPSON SX410 Series Printer Uninstall (HKLM\...\EPSON SX410 Series) (Version:  - SEIKO EPSON Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 79.0.3945.130 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.441 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.123 - Google Inc.) Hidden
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.0.1351 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.220 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{6199B534-A1B6-46ED-873B-97B0ECF8F81E}) (Version: 1.23.216.0 - Intel Corporation)
Malwarebytes version 4.0.4.49 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.0.4.49 - Malwarebytes)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\OneDriveSetup.exe) (Version: 19.232.1124.0005 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 73.0 (x64 en-US) (HKLM\...\Mozilla Firefox 73.0 (x64 en-US)) (Version: 73.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 73.0.0.7342 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Sky Go 1.5.16.0 (HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\com.bskyb.skygoplayer_is1) (Version: 1.5.16.0 - Sky)
Sky Go Desktop (HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\2508210495.go.sky.com) (Version:  - go.sky.com)
Sky Sports 6.0.1 (only current user) (HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\805733bb-91da-567d-b881-06034d21d33f) (Version: 6.0.1 - )
Thin2000 USB Display Adapter (HKLM\...\{BA661C83-7D34-4DF8-A31F-2139C1D72B1C}) (Version: 1.1.316.0 - Fresco Logic)
TP-LINK Wireless Client Utility (HKLM-x32\...\{7A2A107B-9695-423F-9462-8F17C178BD35}) (Version: 7.0 - TP-LINK)

Packages:
=========
Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_1.29.4.0_x86__kgqvnymyfvs32 [2020-01-29] (king.com)
Farm Heroes Saga -> C:\Program Files\WindowsApps\king.com.FarmHeroesSaga_5.30.9.0_x86__kgqvnymyfvs32 [2020-01-29] (king.com)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-01-29] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-01-29] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.5.12061.0_x64__8wekyb3d8bbwe [2020-01-29] (Microsoft Studios) [MS Ad]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3631865646-3207491450-1134192123-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation - pGFX -> Intel Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2015-07-30] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Eddie\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.co

==================== Loaded Modules (Whitelisted) =============

2014-02-13 13:49 - 2008-11-12 03:00 - 000118784 _____ (SEIKO EPSON CORPORATION) [File not signed] C:\WINDOWS\System32\E_ILMFIE.DLL

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 02:34 - 2020-02-11 17:19 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Dell\Win7 LtBlue 1920x1200.jpg
DNS Servers: 192.168.132.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: AVP16.0.0 => 2
MSCONFIG\Services: cphs => 3
MSCONFIG\Services: EPSON_EB_RPCV4_01 => 2
MSCONFIG\Services: EPSON_PM_RPCV4_01 => 2
MSCONFIG\Services: GoogleChromeElevationService => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: IAStorDataMgrSvc => 2
MSCONFIG\Services: igfxCUIService1.0.0.0 => 2
MSCONFIG\Services: Intel® Capability Licensing Service Interface => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: MBAMInstallerService => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: UNS => 2
MSCONFIG\Services: vssbrigde64 => 3
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: DBRMTray => C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe
MSCONFIG\startupreg: EPSON SX410 Series => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFCE.EXE /FU "C:\Windows\TEMP\E_SB404.tmp" /EF "HKCU"
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IAStorIcon => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" 60
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: IMSS => "C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe"
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: USB3MON => "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "DBRMTray"
HKLM\...\StartupApproved\Run: => "flvga_tray64"
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\StartupApproved\Run: => "VideoGuardMonitor"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{066457EA-5F85-453E-B42B-1932DDB50E04}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{69E72D19-F49C-4A13-990A-0C8D88CC12F8}C:\users\eddie\appdata\roaming\sky\sky go\sky go.exe] => (Block) C:\users\eddie\appdata\roaming\sky\sky go\sky go.exe (Sky UK Limited -> Sky UK)
FirewallRules: [TCP Query User{742691DA-D506-47DA-A1FD-D736B34F0B7B}C:\users\eddie\appdata\roaming\sky\sky go\sky go.exe] => (Block) C:\users\eddie\appdata\roaming\sky\sky go\sky go.exe (Sky UK Limited -> Sky UK)
FirewallRules: [{50E4E72F-6D4C-454E-B7C9-2516355F068C}] => (Allow) LPort=53
FirewallRules: [{8780A08B-79DF-49D6-92CC-08ACF7E935BF}] => (Allow) LPort=53
FirewallRules: [{F7ABF902-A19E-4514-A9E1-AC3EEFECC7B3}] => (Allow) LPort=68
FirewallRules: [{2CA0D1DA-1161-45DF-AAA6-34B705B2D7BF}] => (Allow) LPort=67
FirewallRules: [{9B633C90-3460-47A4-875D-80B09EA0E462}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RTLDHCP.exe No File
FirewallRules: [{5DC8B8B7-D95F-4370-AB76-84457A612EE0}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RTLDHCP.exe No File
FirewallRules: [{61C25B7E-A460-403B-AE0C-36F3976788A5}] => (Allow) LPort=53
FirewallRules: [{F053692C-CE7B-4213-9DA2-5B5AE9FCBFC6}] => (Allow) LPort=1542
FirewallRules: [{A641E685-FBDA-4457-B76A-F693DDFB306A}] => (Allow) LPort=1542
FirewallRules: [{DCAD6A22-D1D5-4C9A-882C-0EC3F69CA2ED}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe No File
FirewallRules: [{AEF1CD72-353D-4232-9533-7C169C1658D8}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe No File
FirewallRules: [{C3895048-7F66-4ED2-B368-03D40A184BA9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{79A9EB39-E084-4A2E-81D1-1519ED7022E2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{6ADB7F32-8035-4E9D-8F13-8A0D35A450E3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{259FBEE8-38E4-4B2D-880C-7DDA44A60B3F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{529B52EC-1C0F-4449-8B2A-30B76E57F48A}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe No File
FirewallRules: [TCP Query User{58FD11C6-2A37-4D57-87A6-BDCBF04C94FB}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe No File
FirewallRules: [{741EA72A-428C-464E-8EDE-FA3CE458D6B5}] => (Allow) C:\Program Files (x86)\EpsonNet\EpsonNet Setup\tool09\ENEasyApp.exe No File
FirewallRules: [{7D497B30-B5B9-4B2E-BE52-80A1B31BA62E}] => (Allow) C:\Program Files (x86)\EpsonNet\EpsonNet Setup\tool09\ENEasyApp.exe No File

==================== Restore Points =========================


==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (02/11/2020 03:56:10 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (10612,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (02/11/2020 02:45:49 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (9932,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (02/11/2020 02:34:51 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4484,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (02/11/2020 02:12:34 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (2852,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (02/11/2020 02:05:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: RuntimeBroker.exe, version: 10.0.18362.1, time stamp: 0x4539d5a0
Faulting module name: SettingsEnvironment.Desktop.dll, version: 10.0.18362.387, time stamp: 0x10b406e4
Exception code: 0xc0000005
Fault offset: 0x000000000002b605
Faulting process id: 0x5c4
Faulting application start time: 0x01d5e0ddce6a459c
Faulting application path: C:\Windows\System32\RuntimeBroker.exe
Faulting module path: C:\WINDOWS\SYSTEM32\SettingsEnvironment.Desktop.dll
Report Id: cff7b944-3141-486d-9c01-c0b1a6317903
Faulting package full name: Microsoft.Windows.Cortana_1.13.0.18362_neutral_neutral_cw5n1h2txyewy
Faulting package-relative application ID: runtimebroker07f4358a809ac99a64a67c1

Error: (02/11/2020 02:03:30 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (7744,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (02/11/2020 01:23:51 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (10712,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (02/10/2020 08:26:08 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (10856,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.


System errors:
=============
Error: (02/05/2020 06:48:33 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (02/05/2020 06:48:31 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (02/02/2020 08:50:28 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (02/02/2020 08:50:26 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (02/02/2020 08:24:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The %1!s! Update Service (avast) service failed to start due to the following error:
The system cannot find the file specified.

Error: (02/02/2020 07:39:41 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume C:.

A corruption was found in a file system index structure.  The file reference number is 0xe000000032ce2.  The name of the file is "\Program Files\Common Files\Bitdefender\Bitdefender Threat Scanner\Antivirus_59987_003\Plugins".  The corrupted index attribute is ":$I30:$INDEX_ALLOCATION".

Error: (02/02/2020 07:39:41 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (02/02/2020 07:39:28 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.


Windows Defender:
===================================
Date: 2020-02-01 21:06:31.640
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {9E18AF29-209C-4498-9519-1AED9B807900}
Scan Type: Antimalware
Scan Parameters: Quick Scan

CodeIntegrity:
===================================

Date: 2020-02-01 21:24:16.746
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2020-02-01 21:24:16.718
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2020-02-01 21:24:16.573
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2020-02-01 21:24:16.522
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2020-02-01 21:24:14.269
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2020-02-01 21:24:11.986
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2020-02-01 21:13:33.030
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2020-02-01 21:13:32.992
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

==================== Memory info ===========================

BIOS: Dell Inc. A09 02/01/2013
Motherboard: Dell Inc. 084J0R
Processor: Intel® Pentium® CPU G2020 @ 2.90GHz
Percentage of memory in use: 80%
Total physical RAM: 3967.54 MB
Available physical RAM: 756.13 MB
Total Virtual: 7935.54 MB
Available Virtual: 3515.01 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:456.5 GB) (Free:413.45 GB) NTFS

\\?\Volume{9d80cf44-4223-11e3-adbc-806e6f6e6963}\ (RECOVERY) (Fixed) (Total:9.22 GB) (Free:4.07 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 2566B9A3)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=9.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=456.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt =======================


  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP
Error: (02/02/2020 07:39:41 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume C:.

A corruption was found in a file system index structure.  The file reference number is 0xe000000032ce2.  The name of the file is "\Program Files\Common Files\Bitdefender\Bitdefender Threat Scanner\Antivirus_59987_003\Plugins".  The corrupted index attribute is ":$I30:$INDEX_ALLOCATION".

 

 

Harddrive is sick.  Have you run

chkdsk  /r  C:

since the error showed up?  It will probably require you to reboot so it can run.  Must be run from an Elevated Command Prompt.

Open an Elevated Command Prompt:
Win 7: Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator
Win 8: http://www.eightforu...indows-8-a.html
win 10: http://www.howtogeek...-in-windows-10/


Since the error references BitDefender it would be wise to repair or reinstall BitDefender afterwards.

 

It is my understanding that Win 10 no longer supports Media Center so all of the tasks that reference Media Center are just wasting CPU time. 

If that is the case then you can just disable the tasks:

 

Search for

task scheduler

hit Enter

Click on the arrow in front of Task Scheduler Library then

Click on the arrow in front of Microsoft

Click on the arrow in front of Windows

scroll down to Media Center and click on it then look in the pane to the right.

Right click on each task and Disable.

 

We can clear up some of the errors in your logs with a Fixlist:

 

Download the attached fixlist.txt to the same location as FRST

Attached File  fixlist.txt   4.48KB   206 downloads

Run FRST and press Fix
A fix log will be generated please post that

Reboot if the fix doesn't reboot it for you

Run FRST again as before.  Make sure Addition.txt is checked and hit Scan.  Post both logs.

 

Get Process Explorer

https://live.sysinte...com/procexp.exe

Save it to your desktop then run it (Vista or Win7+ - right click and Run As Administrator).  

View, Select Column, check Verified Signer, OK
Options, Verify Image Signatures


Click twice on the CPU column header  to sort things by CPU usage with the big hitters at the top.  

Wait a full minute then:

File, Save As, Save.  Note the file name.   Open the file  on your desktop and copy and paste the text to a reply.
 

Copy the next 2 lines:

TASKLIST /SVC  > \junk.txt
notepad \junk.txt

Open an Elevated Command Prompt:
Win 7: Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator
Win 8: http://www.eightforu...indows-8-a.html
win 10: http://www.howtogeek...-in-windows-10/

Right click and Paste (or Edit then Paste) and the copied lines should appear.
Hit Enter if notepad does not open.  Copy and paste the text from notepad into a reply.


Get the free version of Speccy:

http://www.filehippo...ownload_speccy/ 

(Look in the upper right for the Download
Latest Version button  - Do NOT press the large Start Download button on the upper left!)  
Download, Save and Install it.  Tell it you do not need CCLEANER.    Run Speccy.  When it finishes (the little icon in the bottom left will stop moving),
File, Save as Text File,  (to your desktop) note the name it gives. OK.  Open the file in notepad and delete the line that gives the serial number of your Operating System.  
(It will be near the top,  10-20  lines down.) Save the file.  Attach the file to your next post.  Attaching the log is the best option as it is too big for the forum.  Attaching is a multi step process.

First click on More Reply Options
Then scroll down to where you see
Choose File and click on it.  Point it at the file and hit Open.
Now click on Attach this file.



Multiple Replies are OK.  Best to post your logs as you get them.
 

 



 

 

 

 


  • 0

#3
bytesize

bytesize

    Member

  • Topic Starter
  • Member
  • PipPip
  • 96 posts

Hi RKinner

 

ran chkdsk through the night, unistalled BD then reinstalled it as requested. Started Task Scheduler to disable Media Center stuff and an error box popped up, clicked the OK button and another error boxed appeared couldn't get any further. It appears that Task Scheduler is corrupted in some way.

 

Ran FRST with the FIXLIST provided log file attached:

 

 

Thanks

 

 

Attached Files


  • 0

#4
bytesize

bytesize

    Member

  • Topic Starter
  • Member
  • PipPip
  • 96 posts

Here are the files from FRST scan

Attached Files


  • 0

#5
bytesize

bytesize

    Member

  • Topic Starter
  • Member
  • PipPip
  • 96 posts

Here is Sys Internals output

 

Process    CPU    Private Bytes    Working Set    PID    Description    Company Name    Verified Signer
System Idle Process    88.60    60 K    8 K    0            
procexp64.exe    4.61    31,108 K    62,304 K    2896    Sysinternals Process Explorer    Sysinternals - www.sysinternals.com    (Verified) Microsoft Corporation
dwm.exe    1.64    38,004 K    30,400 K    820    Desktop Window Manager    Microsoft Corporation    (Verified) Microsoft Windows
firefox.exe    1.46    188,264 K    225,412 K    4224    Firefox    Mozilla Corporation    (Verified) Mozilla Corporation
firefox.exe    0.90    51,532 K    54,296 K    7876    Firefox    Mozilla Corporation    (Verified) Mozilla Corporation
Interrupts    0.75    0 K    0 K    n/a    Hardware Interrupts and DPCs        
firefox.exe    0.65    171,952 K    233,184 K    6644    Firefox    Mozilla Corporation    (Verified) Mozilla Corporation
System    0.47    204 K    3,260 K    4            
csrss.exe    0.34    2,408 K    2,932 K    664    Client Server Runtime Process    Microsoft Corporation    (Verified) Microsoft Windows Publisher
explorer.exe    0.19    41,004 K    66,260 K    6752    Windows Explorer    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe    0.11    4,340 K    8,160 K    3440    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
bdservicehost.exe    0.10    531,704 K    310,556 K    1652    bdservicehost    Bitdefender    (Verified) Bitdefender SRL
svchost.exe    0.10    3,740 K    5,696 K    4216    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
DevMgmtService.exe    0.03    11,968 K    10,436 K    1900    Bitdefender Device Management Service    Bitdefender    (Verified) Bitdefender SRL
BdVpnService.exe    0.02    34,164 K    10,124 K    1976    Bitdefender Vpn Service    Bitdefender    (Verified) Bitdefender SRL
bdagent.exe    0.01    29,084 K    15,688 K    4268    Bitdefender agent    Bitdefender    (Verified) Bitdefender SRL
svchost.exe    0.01    5,672 K    8,068 K    272    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe    < 0.01    8,924 K    12,080 K    984    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
firefox.exe    < 0.01    27,828 K    54,376 K    6884    Firefox    Mozilla Corporation    (Verified) Mozilla Corporation
smartscreen.exe    < 0.01    10,892 K    26,464 K    1468    Windows Defender SmartScreen    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe    < 0.01    66,252 K    64,224 K    2436    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
bdservicehost.exe    < 0.01    34,184 K    26,964 K    1860    bdservicehost    Bitdefender    (Verified) Bitdefender SRL
firefox.exe    < 0.01    217,104 K    146,624 K    6948    Firefox    Mozilla Corporation    (Verified) Mozilla Corporation
svchost.exe    < 0.01    3,308 K    2,596 K    4592    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
WUDFHost.exe        1,928 K    1,620 K    1740    Windows Driver Foundation - User-mode Driver Framework Host Process    Microsoft Corporation    (Verified) Microsoft Windows
WmiPrvSE.exe        3,772 K    9,292 K    5020    WMI Provider Host    Microsoft Corporation    (Verified) Microsoft Windows
winlogon.exe        2,796 K    3,016 K    752    Windows Logon Application    Microsoft Corporation    (Verified) Microsoft Windows
wininit.exe        1,396 K    1,412 K    648    Windows Start-Up Application    Microsoft Corporation    (Verified) Microsoft Windows Publisher
updatesrv.exe        10,260 K    8,168 K    4080    Bitdefender Update Service    Bitdefender    (Verified) Bitdefender SRL
taskhostw.exe        5,492 K    7,860 K    6184    Host Process for Windows Tasks    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe        2,600 K    4,276 K    2188    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        5,088 K    10,216 K    1720    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        3,904 K    3,452 K    1728    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,424 K    1,840 K    1140    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,324 K    3,624 K    2504    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,108 K    3,140 K    512    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        20,152 K    20,796 K    3672    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        7,156 K    11,128 K    3736    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        3,764 K    1,476 K    3848    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,748 K    3,708 K    2816    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        5,140 K    6,700 K    6084    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        3,908 K    9,304 K    3592    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        4,724 K    2,180 K    3244    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,992 K    3,092 K    6980    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,504 K    3,824 K    1476    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,724 K    3,416 K    1772    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        3,956 K    2,656 K    6600    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,744 K    6,044 K    6196    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        3,668 K    6,036 K    6524    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        4,096 K    2,712 K    1524    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        3,520 K    2,640 K    3916    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,780 K    1,552 K    6344    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,992 K    2,276 K    3432    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,060 K    2,120 K    1564    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,972 K    3,832 K    2416    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        13,240 K    21,500 K    3640    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        4,176 K    9,504 K    3824    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        5,112 K    12,612 K    6368    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,400 K    1,584 K    5716    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,132 K    1,844 K    5040    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,724 K    1,344 K    4996    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,656 K    2,364 K    4976    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,764 K    3,440 K    644    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        3,360 K    2,336 K    3456    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,208 K    3,892 K    2428    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        4,012 K    1,992 K    3568    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        4,492 K    6,200 K    4056    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,624 K    1,300 K    3976    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,932 K    1,428 K    3988    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,384 K    1,376 K    3604    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,636 K    1,704 K    3704    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        10,428 K    7,480 K    3424    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,312 K    1,080 K    4068    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,268 K    868 K    4048    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,284 K    2,604 K    3320    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,368 K    2,256 K    3132    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,632 K    1,884 K    3124    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,980 K    6,324 K    3004    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        13,336 K    9,580 K    1408    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,284 K    2,096 K    2364    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,792 K    2,180 K    2692    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,296 K    1,508 K    2456    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,740 K    3,168 K    2724    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        5,696 K    7,796 K    1284    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,828 K    1,608 K    2544    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,388 K    3,064 K    1120    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,784 K    2,304 K    1092    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,724 K    2,196 K    1052    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,448 K    1,216 K    1320    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,604 K    5,836 K    1328    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        1,572 K    1,552 K    1368    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        968 K    1,088 K    900    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        5,328 K    12,060 K    6776    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        4,308 K    2,552 K    1812    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,896 K    828 K    7056    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,772 K    6,616 K    7312    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
svchost.exe        2,892 K    6,508 K    4872    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
StartMenuExperienceHost.exe        22,264 K    24,932 K    3468            (Verified) Microsoft Windows
spoolsv.exe        5,208 K    2,720 K    3392    Spooler SubSystem App    Microsoft Corporation    (Verified) Microsoft Windows
SMSvcHost.exe        24,772 K    1,028 K    5316    SMSvcHost.exe    Microsoft Corporation    (Verified) Microsoft Corporation
SMSvcHost.exe        27,472 K    2,032 K    3900    SMSvcHost.exe    Microsoft Corporation    (Verified) Microsoft Corporation
smss.exe        1,292 K    376 K    476    Windows Session Manager    Microsoft Corporation    (Verified) Microsoft Windows Publisher
sihost.exe        4,844 K    7,232 K    1152    Shell Infrastructure Host    Microsoft Corporation    (Verified) Microsoft Windows
SgrmBroker.exe        3,256 K    3,912 K    1360    System Guard Runtime Monitor Broker Service    Microsoft Corporation    (Verified) Microsoft Windows Publisher
services.exe        4,872 K    5,212 K    716    Services and Controller app    Microsoft Corporation    (Verified) Microsoft Windows Publisher
SecurityHealthService.exe        2,760 K    5,900 K    5872    Windows Security Health Service    Microsoft Corporation    (Verified) Microsoft Windows Publisher
SearchUI.exe    Suspended    83,104 K    1,308 K    3636    Search and Cortana application    Microsoft Corporation    (Verified) Microsoft Windows
SearchIndexer.exe        20,400 K    17,132 K    4092    Microsoft Windows Search Indexer    Microsoft Corporation    (Verified) Microsoft Windows
RuntimeBroker.exe        3,972 K    4,072 K    7260    Runtime Broker    Microsoft Corporation    (Verified) Microsoft Windows
RuntimeBroker.exe        4,676 K    5,700 K    7828    Runtime Broker    Microsoft Corporation    (Verified) Microsoft Windows
RuntimeBroker.exe        3,568 K    3,004 K    6004    Runtime Broker    Microsoft Corporation    (Verified) Microsoft Windows
Registry        8,452 K    23,288 K    88            
ProductAgentService.exe        5,760 K    5,572 K    3960    Bitdefender Agent    Bitdefender    (Verified) Bitdefender SRL
procexp.exe        5,140 K    10,988 K    5556    Sysinternals Process Explorer    Sysinternals - www.sysinternals.com    (Verified) Microsoft Corporation
mqsvc.exe        4,060 K    2,364 K    3776    Message Queuing Service    Microsoft Corporation    (Verified) Microsoft Windows
Memory Compression        492 K    151,944 K    2564            
lsass.exe        6,300 K    9,100 K    792    Local Security Authority Process    Microsoft Corporation    (Verified) Microsoft Windows Publisher
GoogleUpdate.exe        2,256 K    304 K    6152    Google Installer    Google Inc.    (Verified) Google Inc
fontdrvhost.exe        3,468 K    3,520 K    916    Usermode Font Driver Host    Microsoft Corporation    (Verified) Microsoft Windows
fontdrvhost.exe        1,428 K    1,184 K    908    Usermode Font Driver Host    Microsoft Corporation    (Verified) Microsoft Windows
firefox.exe        27,900 K    49,652 K    5496    Firefox    Mozilla Corporation    (Verified) Mozilla Corporation
dllhost.exe        1,372 K    3,152 K    4552    COM Surrogate    Microsoft Corporation    (Verified) Microsoft Windows
DiscoverySrv.exe        2,616 K    2,764 K    6516    DiscoverySrv    Bitdefender    (Verified) Bitdefender SRL
dasHost.exe        1,252 K    1,276 K    4228    Device Association Framework Provider Host    Microsoft Corporation    (Verified) Microsoft Windows
ctfmon.exe        3,500 K    6,608 K    6416    CTF Loader    Microsoft Corporation    (Verified) Microsoft Windows
csrss.exe        1,844 K    2,168 K    576    Client Server Runtime Process    Microsoft Corporation    (Verified) Microsoft Windows Publisher
conhost.exe        6,644 K    6,644 K    1560    Console Window Host    Microsoft Corporation    (Verified) Microsoft Windows
BdVpnApp.exe        4,596 K    3,140 K    8132    Bitdefender Vpn App    Bitdefender    (Verified) Bitdefender SRL
bdtrackersnmh.exe        6,968 K    11,336 K    8052    trackers blocker host    Bitdefender    (Verified) Bitdefender SRL
bdservicehost.exe        8,812 K    6,500 K    3580    bdservicehost    Bitdefender    (Verified) Bitdefender SRL
bdredline.exe        3,632 K    3,168 K    2740    Bitdefender redline update    Bitdefender    (Verified) Bitdefender SRL
audiodg.exe        7,488 K    12,092 K    1272    Windows Audio Device Graph Isolation     Microsoft Corporation    (Verified) Microsoft Windows


 


  • 0

#6
bytesize

bytesize

    Member

  • Topic Starter
  • Member
  • PipPip
  • 96 posts

Output text file created by TASKLIST /SVC  > \junk.txt
notepad \junk.txt

 

Image Name                     PID Services                                    
========================= ======== ============================================
System Idle Process              0 N/A                                         
System                           4 N/A                                         
Registry                        88 N/A                                         
smss.exe                       476 N/A                                         
csrss.exe                      576 N/A                                         
wininit.exe                    648 N/A                                         
csrss.exe                      664 N/A                                         
services.exe                   716 N/A                                         
winlogon.exe                   752 N/A                                         
lsass.exe                      792 KeyIso, SamSs, VaultSvc                     
svchost.exe                    900 PlugPlay                                    
fontdrvhost.exe                908 N/A                                         
fontdrvhost.exe                916 N/A                                         
svchost.exe                    984 BrokerInfrastructure, DcomLaunch, Power,    
                                   SystemEventsBroker                          
svchost.exe                    272 RpcEptMapper, RpcSs                         
svchost.exe                    512 LSM                                         
dwm.exe                        820 N/A                                         
svchost.exe                   1052 lmhosts                                     
svchost.exe                   1092 TimeBrokerSvc                               
svchost.exe                   1120 NcbService                                  
svchost.exe                   1140 CoreMessagingRegistrar                      
svchost.exe                   1284 Schedule                                    
svchost.exe                   1320 DispBrokerDesktopSvc                        
svchost.exe                   1328 ProfSvc                                     
svchost.exe                   1368 hidserv                                     
svchost.exe                   1408 EventLog                                    
svchost.exe                   1476 UserManager                                 
svchost.exe                   1524 nsi                                         
svchost.exe                   1564 Dhcp                                        
bdservicehost.exe             1652 VSSERV                                      
svchost.exe                   1728 NlaSvc                                      
WUDFHost.exe                  1740 N/A                                         
svchost.exe                   1772 Dnscache                                    
bdservicehost.exe             1860 BDAuxSrv                                    
DevMgmtService.exe            1900 DevMgmtService                              
BdVpnService.exe              1976 BdVpnService                                
svchost.exe                   2188 netprofm                                    
svchost.exe                   2364 SEMgrSvc                                    
svchost.exe                   2416 EventSystem                                 
svchost.exe                   2428 CscService                                  
svchost.exe                   2436 SysMain                                     
svchost.exe                   2456 Themes                                      
svchost.exe                   2504 LanmanServer                                
svchost.exe                   2544 SENS                                        
Memory Compression            2564 N/A                                         
svchost.exe                   2692 AudioEndpointBuilder                        
svchost.exe                   2724 FontCache                                   
svchost.exe                   2816 WinHttpAutoProxySvc                         
svchost.exe                   3004 Audiosrv                                    
svchost.exe                   1720 StateRepository                             
svchost.exe                   3124 DusmSvc                                     
svchost.exe                   3132 Wcmsvc                                      
svchost.exe                   3244 WlanSvc                                     
svchost.exe                   3320 ShellHWDetection                            
spoolsv.exe                   3392 Spooler                                     
svchost.exe                   3424 BFE, mpssvc                                 
svchost.exe                   3432 LanmanWorkstation                           
svchost.exe                   3568 AppHostSvc                                  
bdservicehost.exe             3580 BDProtSrv                                   
svchost.exe                   3592 CryptSvc                                    
svchost.exe                   3604 DeviceAssociationService                    
svchost.exe                   3640 DiagTrack                                   
svchost.exe                   3672 DPS                                         
svchost.exe                   3704 IKEEXT                                      
svchost.exe                   3736 Winmgmt                                     
mqsvc.exe                     3776 MSMQ                                        
svchost.exe                   3848 WAS                                         
SMSvcHost.exe                 3900 NetPipeActivator, NetTcpActivator,          
                                   NetTcpPortSharing                           
ProductAgentService.exe       3960 ProductAgentService                         
svchost.exe                   3976 SstpSvc                                     
svchost.exe                   3988 stisvc                                      
svchost.exe                   4048 TrkWks                                      
svchost.exe                   4056 WpnService                                  
svchost.exe                   4068 WdiServiceHost                              
updatesrv.exe                 4080 UPDATESRV                                   
SearchIndexer.exe             4092 WSearch                                     
svchost.exe                   3456 iphlpsvc                                    
dasHost.exe                   4228 N/A                                         
svchost.exe                   4592 RasMan                                      
svchost.exe                   4976 Browser                                     
svchost.exe                   4996 PolicyAgent                                 
svchost.exe                   5040 SSDPSRV                                     
SMSvcHost.exe                 5316 NetMsmqActivator                            
svchost.exe                   5716 upnphost                                    
sihost.exe                    1152 N/A                                         
svchost.exe                   3916 CDPUserSvc_40602                            
svchost.exe                   6084 WpnUserService_40602                        
GoogleUpdate.exe              6152 N/A                                         
taskhostw.exe                 6184 N/A                                         
svchost.exe                   6196 TokenBroker                                 
svchost.exe                   6344 TabletInputService                          
ctfmon.exe                    6416 N/A                                         
DiscoverySrv.exe              6516 N/A                                         
svchost.exe                   6524 PcaSvc                                      
svchost.exe                   6600 CDPSvc                                      
explorer.exe                  6752 N/A                                         
svchost.exe                   6980 cbdhsvc_40602                               
StartMenuExperienceHost.e     3468 N/A                                         
dllhost.exe                   4552 N/A                                         
RuntimeBroker.exe             6004 N/A                                         
SearchUI.exe                  3636 N/A                                         
RuntimeBroker.exe             7260 N/A                                         
RuntimeBroker.exe             7828 N/A                                         
BdVpnApp.exe                  8132 N/A                                         
bdagent.exe                   4268 N/A                                         
bdredline.exe                 2740 bdredline                                   
svchost.exe                   3440 DoSvc                                       
svchost.exe                   4216 StorSvc                                     
SgrmBroker.exe                1360 SgrmBroker                                  
svchost.exe                   6776 UsoSvc                                      
svchost.exe                   1812 OneSyncSvc_40602                            
svchost.exe                    644 wscsvc                                      
SecurityHealthService.exe     5872 SecurityHealthService                       
svchost.exe                   7056 SDRSVC                                      
svchost.exe                   6368 InstallService                              
firefox.exe                   6644 N/A                                         
firefox.exe                   7876 N/A                                         
firefox.exe                   4224 N/A                                         
firefox.exe                   6948 N/A                                         
bdtrackersnmh.exe             8052 N/A                                         
conhost.exe                   1560 N/A                                         
firefox.exe                   6884 N/A                                         
svchost.exe                   7312 Appinfo                                     
svchost.exe                   4872 WdiSystemHost                               
firefox.exe                   5496 N/A                                         
WmiPrvSE.exe                  5020 N/A                                         
smartscreen.exe               8124 N/A                                         
notepad.exe                   1760 N/A                                         
WindowsInternal.Composabl     2732 N/A                                         
dllhost.exe                   4616 N/A                                         
RuntimeBroker.exe             5836 N/A                                         
audiodg.exe                   2788 N/A                                         
cmd.exe                        484 N/A                                         
conhost.exe                   3876 N/A                                         
tasklist.exe                  4664 N/A                                         
WmiPrvSE.exe                  2760 N/A                                         

 


  • 0

#7
bytesize

bytesize

    Member

  • Topic Starter
  • Member
  • PipPip
  • 96 posts

Speccy txt file

 

 I await further instructions thankyou for your help

Attached Files


  • 0

#8
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP
C5
                                            Attribute name    Current Pending Sector Count
                                            Real value    1
                                            Current    200
                                            Worst    200
                                            Threshold    0
                                            Raw Value    0000000001
                                            Status    Good

 

 

Looks like you have one sector on the hard drive that has failed but has been replaced with a spare sector yet.  Might be the cause of the corruption error.  You might want to run Western Digital's Data Lifeguard's Extended test to make sure the drive is healthy. 

https://support.wdc....spx?p=3&lang=en

(Will take hours so let it run overnight)

 

Process Explorer and the junk file look clean.

 

Let's just remove all of the media center tasks with a fixlist.

 

Download the attached fixlist.txt to the same location as FRST

Attached File  fixlist.txt   8.5KB   167 downloads

Run FRST and press Fix
A fix log will be generated please post that

Reboot if the fix doesn't reboot it for you

Run FRST again as before.  Make sure Addition.txt is checked and hit Scan.  Post both logs.


 

 

 

 

 


  • 0

#9
bytesize

bytesize

    Member

  • Topic Starter
  • Member
  • PipPip
  • 96 posts

Ran the HDD utility and it found bad sector said it could repair but might lose data, clicked repair, then it said it couldn't repair it. Have a spare 500Gb Seagate HDD that i could use to replace, it only runs at 5900rpm, could clone existing HDD on to that?

 

Here are the FRST logs

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 12-02-2020
Ran by Eddie (14-02-2020 10:12:43) Run:2
Running from C:\Users\Eddie\Desktop
Loaded Profiles: Eddie (Available Profiles: Eddie)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Task: {0E9B0B5C-9FF3-4A29-8479-0868A68DD87B} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {2956E29D-A64D-413D-B892-F5AA2AC347BB} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {3999671B-80BF-4CDF-A95C-93FD2F0FE480} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {3CBC40D7-5079-4162-B3CF-8BB086B1F88F} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {49072A42-1C33-4821-800D-28DD295D6786} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {4FF356D2-FE47-4920-B00B-3E8B260DCA26} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {528B6446-B6F7-44E3-AA71-6203798B4E57} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {53C82D5D-CAA2-4928-AD01-FD5CA9402E42} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {54C24529-FE0D-45F3-921C-72B199731A29} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {63882D74-4B0D-4654-86EE-D96AE3948093} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6563DB5C-54FD-4007-98A3-1F779956369C} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {6A73D90C-B17C-4761-8357-1A346F1A3327} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {74B79B52-5FD9-4C14-BAB0-205B4C4DD9F9} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {7999A0A7-D11A-45C6-BDD2-8E903177FB5A} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {834A60BA-2D0F-4377-BE69-8C0777570D5A} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
Task: {92BE7943-78D8-4C4B-883D-3B2AAF434323} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {ACDC58CF-A087-48C0-A33C-1903B2116D07} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43da-BFD7-FBEEA2180A1E}
Task: {B1450FE1-82E8-40F1-8F3F-5749E0F9E20E} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {BA7F3875-7416-4EF5-B045-A03824D3AFA2} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {C1913C94-0842-490C-B755-F95332E09ABA} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {CE4EEC05-AE50-4266-B124-7496745958B2} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D2ACE0C1-E609-4CDD-AE28-98BEE54A0267} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1873288 2019-09-18] (AVAST Software s.r.o. -> AVAST Software)
Task: {DA5EBFDD-F0C4-44BB-802B-EC827B4A9BF5} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DA9D1E83-01AA-4187-BDB9-6D13247DE477} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {FFD0BCF8-7926-4344-A2B0-908C275D350D} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
FirewallRules: [{741EA72A-428C-464E-8EDE-FA3CE458D6B5}] => (Allow) C:\Program Files (x86)\EpsonNet\EpsonNet Setup\tool09\ENEasyApp.exe No File
FirewallRules: [{7D497B30-B5B9-4B2E-BE52-80A1B31BA62E}] => (Allow) C:\Program Files (x86)\EpsonNet\EpsonNet Setup\tool09\ENEasyApp.exe No File
File: C:\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
CMD: mkdir C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer
CMD: mkdir C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database
CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i"
Reboot:


*****************

"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0E9B0B5C-9FF3-4A29-8479-0868A68DD87B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0E9B0B5C-9FF3-4A29-8479-0868A68DD87B}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrScheduleTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2956E29D-A64D-413D-B892-F5AA2AC347BB}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2956E29D-A64D-413D-B892-F5AA2AC347BB}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ReindexSearchRoot" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3999671B-80BF-4CDF-A95C-93FD2F0FE480}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3999671B-80BF-4CDF-A95C-93FD2F0FE480}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrRecoveryTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3CBC40D7-5079-4162-B3CF-8BB086B1F88F}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3CBC40D7-5079-4162-B3CF-8BB086B1F88F}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ActivateWindowsSearch" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{49072A42-1C33-4821-800D-28DD295D6786}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{49072A42-1C33-4821-800D-28DD295D6786}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\UpdateRecordPath" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4FF356D2-FE47-4920-B00B-3E8B260DCA26}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4FF356D2-FE47-4920-B00B-3E8B260DCA26}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\OCURDiscovery" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{528B6446-B6F7-44E3-AA71-6203798B4E57}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{528B6446-B6F7-44E3-AA71-6203798B4E57}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PeriodicScanRetry" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{53C82D5D-CAA2-4928-AD01-FD5CA9402E42}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{53C82D5D-CAA2-4928-AD01-FD5CA9402E42}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\SqlLiteRecoveryTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{54C24529-FE0D-45F3-921C-72B199731A29}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{54C24529-FE0D-45F3-921C-72B199731A29}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW2" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{63882D74-4B0D-4654-86EE-D96AE3948093}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{63882D74-4B0D-4654-86EE-D96AE3948093}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\OCURActivate" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6563DB5C-54FD-4007-98A3-1F779956369C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6563DB5C-54FD-4007-98A3-1F779956369C}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\MediaCenterRecoveryTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A73D90C-B17C-4761-8357-1A346F1A3327}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A73D90C-B17C-4761-8357-1A346F1A3327}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\mcupdate => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{74B79B52-5FD9-4C14-BAB0-205B4C4DD9F9}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{74B79B52-5FD9-4C14-BAB0-205B4C4DD9F9}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\InstallPlayReady" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7999A0A7-D11A-45C6-BDD2-8E903177FB5A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7999A0A7-D11A-45C6-BDD2-8E903177FB5A}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SideShow\SystemDataProviders" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{834A60BA-2D0F-4377-BE69-8C0777570D5A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{834A60BA-2D0F-4377-BE69-8C0777570D5A}" => removed successfully
C:\WINDOWS\System32\Tasks\AvastUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AvastUpdateTaskMachineCore" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{92BE7943-78D8-4C4B-883D-3B2AAF434323}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{92BE7943-78D8-4C4B-883D-3B2AAF434323}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{ACDC58CF-A087-48C0-A33C-1903B2116D07}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ACDC58CF-A087-48C0-A33C-1903B2116D07}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\MobilePC\HotStart => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MobilePC\HotStart" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B1450FE1-82E8-40F1-8F3F-5749E0F9E20E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B1450FE1-82E8-40F1-8F3F-5749E0F9E20E}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW1" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BA7F3875-7416-4EF5-B045-A03824D3AFA2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BA7F3875-7416-4EF5-B045-A03824D3AFA2}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\RegisterSearch" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C1913C94-0842-490C-B755-F95332E09ABA}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C1913C94-0842-490C-B755-F95332E09ABA}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ConfigureInternetTimeService" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CE4EEC05-AE50-4266-B124-7496745958B2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE4EEC05-AE50-4266-B124-7496745958B2}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscovery" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{D2ACE0C1-E609-4CDD-AE28-98BEE54A0267}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D2ACE0C1-E609-4CDD-AE28-98BEE54A0267}" => removed successfully
C:\WINDOWS\System32\Tasks\Avast Software\Overseer => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software\Overseer" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DA5EBFDD-F0C4-44BB-802B-EC827B4A9BF5}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA5EBFDD-F0C4-44BB-802B-EC827B4A9BF5}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\DispatchRecoveryTasks" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DA9D1E83-01AA-4187-BDB9-6D13247DE477}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA9D1E83-01AA-4187-BDB9-6D13247DE477}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ehDRMInit" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{FFD0BCF8-7926-4344-A2B0-908C275D350D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FFD0BCF8-7926-4344-A2B0-908C275D350D}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\RecordingRestart" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{741EA72A-428C-464E-8EDE-FA3CE458D6B5}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7D497B30-B5B9-4B2E-BE52-80A1B31BA62E}" => removed successfully

========================= File: C:\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll ========================

C:\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
File not signed
MD5: E1EEB7E26AB04075EECC7275239B20B3
Creation and modification date: 2020-01-29 16:54 - 2020-01-29 16:54
Size: 000016384
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name:
Original Name:
Product: Microsoft® Visual Studio .NET
Description:
File Version: 7.00.9466
Product Version: 7.00.9466
Copyright: © Microsoft Corporation.  All rights reserved.
VirusTotal: 0

====== End of File: ======


========= mkdir C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer =========


========= End of CMD: =========


========= mkdir C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database =========


========= End of CMD: =========


========= FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i" =========

Failed to clear log Microsoft-Windows-LiveId/Analytic.
Access is denied.
Failed to clear log Microsoft-Windows-LiveId/Operational.
Access is denied.

========= End of CMD: =========



The system needed a reboot.

==== End of Fixlog 10:13:37 ====

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-02-2020
Ran by Eddie (14-02-2020 10:26:22)
Running from C:\Users\Eddie\Desktop
Windows 10 Pro Version 1909 18363.657 (X64) (2020-01-29 17:02:07)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3631865646-3207491450-1134192123-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3631865646-3207491450-1134192123-503 - Limited - Disabled)
Eddie (S-1-5-21-3631865646-3207491450-1134192123-1000 - Administrator - Enabled) => C:\Users\Eddie
Guest (S-1-5-21-3631865646-3207491450-1134192123-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3631865646-3207491450-1134192123-1002 - Limited - Enabled)
WDAGUtilityAccount (S-1-5-21-3631865646-3207491450-1134192123-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Bitdefender Antivirus (Enabled - Up to date) {0E17DB7D-A20F-62CE-B95B-17DB0CDFE318}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Enabled) {362C5A58-E860-6396-9204-BEEEF20CA463}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

ABBYY FineReader 6.0 Sprint (HKLM-x32\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1395.4512 - ABBYY Software House)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 24.0.1.161 - Bitdefender)
Bitdefender Device Management (HKLM\...\Bitdefender Device Management) (Version: 24.0.14.86 - Bitdefender)
Bitdefender Total Security (HKLM\...\Bitdefender) (Version: 24.0.14.85 - Bitdefender)
Bitdefender VPN (HKLM\...\Bitdefender VPN) (Version: 24.0.2.693 - Bitdefender)
Cisco VideoGuard Player (HKLM-x32\...\{30e4813e-2a86-4e4f-82ea-23df71ca8ffb}) (Version: 10.1.1.6570 - Cisco Systems, Inc)
Data Lifeguard Diagnostic version 1.36 (HKLM-x32\...\{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1) (Version:  - Western Digital Corporation)
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Epson Easy Photo Print 2 (HKLM-x32\...\{87C2248A-C7DD-49ED-9BCD-B312A9D0819E}) (Version: 2.1.0.0 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )
Epson Stylus SX210_SX410_TX210_TX410 Manual (HKLM-x32\...\Epson Stylus SX210_SX410_TX210_TX410 User’s Guide) (Version:  - )
EPSON SX410 Series Printer Uninstall (HKLM\...\EPSON SX410 Series) (Version:  - SEIKO EPSON Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 79.0.3945.130 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.441 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.123 - Google Inc.) Hidden
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.0.1351 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.220 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{6199B534-A1B6-46ED-873B-97B0ECF8F81E}) (Version: 1.23.216.0 - Intel Corporation)
Malwarebytes version 4.0.4.49 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.0.4.49 - Malwarebytes)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\OneDriveSetup.exe) (Version: 19.232.1124.0005 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 73.0 (x64 en-US) (HKLM\...\Mozilla Firefox 73.0 (x64 en-US)) (Version: 73.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 73.0.0.7342 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Sky Go 1.5.16.0 (HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\com.bskyb.skygoplayer_is1) (Version: 1.5.16.0 - Sky)
Sky Go Desktop (HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\2508210495.go.sky.com) (Version:  - go.sky.com)
Sky Sports 6.0.1 (only current user) (HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\805733bb-91da-567d-b881-06034d21d33f) (Version: 6.0.1 - )
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
Thin2000 USB Display Adapter (HKLM\...\{BA661C83-7D34-4DF8-A31F-2139C1D72B1C}) (Version: 1.1.316.0 - Fresco Logic)
TP-LINK Wireless Client Utility (HKLM-x32\...\{7A2A107B-9695-423F-9462-8F17C178BD35}) (Version: 7.0 - TP-LINK)

Packages:
=========
Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_1.30.3.0_x86__kgqvnymyfvs32 [2020-02-14] (king.com)
Farm Heroes Saga -> C:\Program Files\WindowsApps\king.com.FarmHeroesSaga_5.31.8.0_x86__kgqvnymyfvs32 [2020-02-14] (king.com)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-01-29] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-01-29] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.5.12061.0_x64__8wekyb3d8bbwe [2020-01-29] (Microsoft Studios) [MS Ad]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3631865646-3207491450-1134192123-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation - pGFX -> Intel Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2015-07-30] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Eddie\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.co

==================== Loaded Modules (Whitelisted) =============

2014-02-13 13:49 - 2008-11-12 03:00 - 000118784 _____ (SEIKO EPSON CORPORATION) [File not signed] C:\WINDOWS\System32\E_ILMFIE.DLL

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 02:34 - 2020-02-14 10:19 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Dell\Win7 LtBlue 1920x1200.jpg
DNS Servers: 192.168.132.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: cphs => 3
MSCONFIG\Services: EPSON_EB_RPCV4_01 => 2
MSCONFIG\Services: EPSON_PM_RPCV4_01 => 2
MSCONFIG\Services: GoogleChromeElevationService => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: IAStorDataMgrSvc => 2
MSCONFIG\Services: igfxCUIService1.0.0.0 => 2
MSCONFIG\Services: Intel® Capability Licensing Service Interface => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: MBAMInstallerService => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: UNS => 2
MSCONFIG\Services: vssbrigde64 => 3
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: DBRMTray => C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe
MSCONFIG\startupreg: EPSON SX410 Series => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFCE.EXE /FU "C:\Windows\TEMP\E_SB404.tmp" /EF "HKCU"
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IAStorIcon => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" 60
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: IMSS => "C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe"
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: USB3MON => "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "DBRMTray"
HKLM\...\StartupApproved\Run: => "flvga_tray64"
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\StartupApproved\Run: => "VideoGuardMonitor"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{066457EA-5F85-453E-B42B-1932DDB50E04}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{69E72D19-F49C-4A13-990A-0C8D88CC12F8}C:\users\eddie\appdata\roaming\sky\sky go\sky go.exe] => (Block) C:\users\eddie\appdata\roaming\sky\sky go\sky go.exe (Sky UK Limited -> Sky UK)
FirewallRules: [TCP Query User{742691DA-D506-47DA-A1FD-D736B34F0B7B}C:\users\eddie\appdata\roaming\sky\sky go\sky go.exe] => (Block) C:\users\eddie\appdata\roaming\sky\sky go\sky go.exe (Sky UK Limited -> Sky UK)
FirewallRules: [{50E4E72F-6D4C-454E-B7C9-2516355F068C}] => (Allow) LPort=53
FirewallRules: [{8780A08B-79DF-49D6-92CC-08ACF7E935BF}] => (Allow) LPort=53
FirewallRules: [{F7ABF902-A19E-4514-A9E1-AC3EEFECC7B3}] => (Allow) LPort=68
FirewallRules: [{2CA0D1DA-1161-45DF-AAA6-34B705B2D7BF}] => (Allow) LPort=67
FirewallRules: [{9B633C90-3460-47A4-875D-80B09EA0E462}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RTLDHCP.exe No File
FirewallRules: [{5DC8B8B7-D95F-4370-AB76-84457A612EE0}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RTLDHCP.exe No File
FirewallRules: [{61C25B7E-A460-403B-AE0C-36F3976788A5}] => (Allow) LPort=53
FirewallRules: [{F053692C-CE7B-4213-9DA2-5B5AE9FCBFC6}] => (Allow) LPort=1542
FirewallRules: [{A641E685-FBDA-4457-B76A-F693DDFB306A}] => (Allow) LPort=1542
FirewallRules: [{DCAD6A22-D1D5-4C9A-882C-0EC3F69CA2ED}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe No File
FirewallRules: [{AEF1CD72-353D-4232-9533-7C169C1658D8}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe No File
FirewallRules: [{C3895048-7F66-4ED2-B368-03D40A184BA9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{79A9EB39-E084-4A2E-81D1-1519ED7022E2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{6ADB7F32-8035-4E9D-8F13-8A0D35A450E3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{259FBEE8-38E4-4B2D-880C-7DDA44A60B3F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{529B52EC-1C0F-4449-8B2A-30B76E57F48A}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe No File
FirewallRules: [TCP Query User{58FD11C6-2A37-4D57-87A6-BDCBF04C94FB}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe No File

==================== Restore Points =========================

13-02-2020 09:17:34 Windows Modules Installer

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================

System errors:
=============

==================== Memory info ===========================

BIOS: Dell Inc. A09 02/01/2013
Motherboard: Dell Inc. 084J0R
Processor: Intel® Pentium® CPU G2020 @ 2.90GHz
Percentage of memory in use: 54%
Total physical RAM: 3967.54 MB
Available physical RAM: 1789.06 MB
Total Virtual: 7935.54 MB
Available Virtual: 5569.18 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:456.5 GB) (Free:403.99 GB) NTFS

\\?\Volume{9d80cf44-4223-11e3-adbc-806e6f6e6963}\ (RECOVERY) (Fixed) (Total:9.22 GB) (Free:4.07 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 2566B9A3)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=9.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=456.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt =======================

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-02-2020
Ran by Eddie (administrator) on EDDIEDELL (Dell Inc. Vostro 270) (14-02-2020 10:22:35)
Running from C:\Users\Eddie\Desktop
Loaded Profiles: Eddie (Available Profiles: Eddie)
Platform: Windows 10 Pro Version 1909 18363.657 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\DiscoverySrv.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Device Management\DevMgmtService.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnApp.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnService.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\usocoreworker.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [DBRMTray] => C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation) [File not signed]
HKLM\...\Run: [flvga_tray64] => C:\Windows\system32\flvga_tray.exe [419328 2015-12-07] () [File not signed]
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3933496 2012-09-20] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [BdVpnApp] => C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnApp.exe [456088 2019-10-13] (Bitdefender SRL -> Bitdefender)
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\Run: [VideoGuardMonitor] => C:\Users\Eddie\AppData\Local\Cisco\VideoGuardPlayer\VideoGuardMonitor\CiscoVideoGuardMonitor.exe [2345736 2017-11-02] (Cisco Video Technologies Israel Ltd. -> Cisco)
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\...\Run: [EPSON SX410 Series] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIFCE.EXE [223232 2008-10-02] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.130\Installer\chrmstp.exe [2020-01-22] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {053D1D96-34A1-43DB-A08C-42013752D3E2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-01] (Google Inc -> Google Inc.)
Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47c2-B62A-B7C4CED925CB}
Task: {5681C43E-9E0F-4FBB-AF45-8126839219E0} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [490808 2019-11-27] (Bitdefender SRL -> Bitdefender)
Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A}
Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40b4-8963-D3C761B18371}
Task: {C2B62A8D-6C26-466B-895F-C83C6BDFBB8E} - System32\Tasks\Bitdefender AgentTask_AD394AE64E874073B10A89FEEC305A3C => C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe [525120 2019-12-06] (Bitdefender SRL -> Bitdefender)
Task: {E0AA4134-CDC5-47C0-AFAF-C7CDC34DBC40} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-01] (Google Inc -> Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.132.1
Tcpip\..\Interfaces\{7059D287-A263-4A16-854D-FFC987708542}: [DhcpNameServer] 192.168.132.1
Tcpip\..\Interfaces\{8C412334-6E80-4EC8-9F2B-E48E60423A89}: [DhcpNameServer] 194.168.4.100 194.168.8.100
Tcpip\..\Interfaces\{CCEB5E90-4E48-420A-A652-21003662E153}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.co.uk/
HKU\S-1-5-21-3631865646-3207491450-1134192123-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www1.euro.dell.com/content/default.aspx?c=uk&l=en&s=gen
BHO: Bitdefender Trackers Blocking -> {159ff5d5-55f1-4d2f-b706-767a55f77abb} -> C:\Program Files\Bitdefender\Bitdefender Security\bdtbie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
BHO: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
BHO-x32: Bitdefender Trackers Blocking -> {159ff5d5-55f1-4d2f-b706-767a55f77abb} -> C:\Program Files\Bitdefender\Bitdefender Security\antispam32\bdtbie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
BHO-x32: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
Toolbar: HKLM - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)
Toolbar: HKLM-x32 - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2019-12-06] (Bitdefender SRL -> Bitdefender)

FireFox:
========
FF DefaultProfile: g6p9p80w.default
FF ProfilePath: C:\Users\Eddie\AppData\Roaming\Mozilla\Firefox\Profiles\g6p9p80w.default [2020-02-14]
FF NewTab: Mozilla\Firefox\Profiles\g6p9p80w.default -> about:home
FF Notifications: Mozilla\Firefox\Profiles\g6p9p80w.default -> hxxps://mail.virginmedia.com; hxxp://mail.virginmedia.com; hxxps://www.bingotastic.com; hxxps://www.youtube.com; hxxps://www.facebook.com; hxxps://www.ebay.co.uk; hxxps://www.epson.co.uk; hxxps://0.nextyourcontent.com; hxxps://1.nextyourcontent.com; hxxps://2.nextyourcontent.com
FF NewTabOverride: Mozilla\Firefox\Profiles\g6p9p80w.default -> Disabled: [email protected]
FF Extension: (No Name) - C:\Users\Eddie\AppData\Roaming\Mozilla\Firefox\Profiles\g6p9p80w.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2020-02-13]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi
FF Extension: (Bitdefender Wallet) - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi [2019-12-06]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbef.xpi
FF Extension: (Bitdefender Anti-tracker) - C:\Program Files\Bitdefender\Bitdefender Security\bdtbef.xpi [2019-11-01]
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext
FF Extension: (Bitdefender Antispam Toolbar) - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext [2020-01-08] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbef.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\bd_js_config.js [2020-02-13] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\bd_config.cfg [2020-02-13] <==== ATTENTION

Chrome:
=======
CHR Profile: C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default [2020-02-02]
CHR HomePage: Default -> hxxp://www.google.com
CHR Extension: (Slides) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-12-18]
CHR Extension: (Docs) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-13]
CHR Extension: (Google Drive) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-03]
CHR Extension: (YouTube) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-03]
CHR Extension: (Sheets) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-12-13]
CHR Extension: (Bitdefender Wallet) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\gannpgaobkkhmpomoijebaigcapoeebl [2020-02-02]
CHR Extension: (Google Docs Offline) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-02-02]
CHR Extension: (Bitdefender Anti-tracker) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\khndhdhbebhaddchcgnalcjlaekbbeof [2020-02-02]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-02-02]
CHR Extension: (Gmail) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-06-10]
CHR Extension: (Chrome Media Router) - C:\Users\Eddie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-02-02]
CHR HKLM-x32\...\Chrome\Extension: [gannpgaobkkhmpomoijebaigcapoeebl]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
CHR HKLM-x32\...\Chrome\Extension: [khndhdhbebhaddchcgnalcjlaekbbeof]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AfVpnService; C:\Program Files\Bitdefender\Bitdefender VPN\vpnservice.exe [322432 2019-06-04] (AnchorFree Inc -> AnchorFree Inc.)
R2 BDAuxSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [803576 2019-12-06] (Bitdefender SRL -> Bitdefender)
R2 BDProtSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [803576 2019-12-06] (Bitdefender SRL -> Bitdefender)
R2 bdredline; C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe [2195344 2018-03-22] (Bitdefender SRL -> Bitdefender)
R2 BdVpnService; C:\Program Files\Bitdefender\Bitdefender VPN\bdvpnservice.exe [471120 2019-10-13] (Bitdefender SRL -> Bitdefender)
R2 DevMgmtService; C:\Program Files\Bitdefender\Bitdefender Device Management\DevMgmtService.exe [119368 2019-12-06] (Bitdefender SRL -> Bitdefender)
S4 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE [163840 2007-12-17] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
S4 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE [126464 2007-01-11] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
S4 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [328608 2015-07-30] (Intel Corporation - pGFX -> Intel Corporation)
S2 MBAMInstallerService; C:\Users\Eddie\AppData\Local\Temp\MBAMInstallerService.exe [5225688 2020-02-11] (Malwarebytes Inc -> Malwarebytes) <==== ATTENTION
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1329240 2020-01-15] (Bitdefender SRL -> Bitdefender)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5796168 2020-01-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe [151656 2019-12-06] (Bitdefender SRL -> Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [803576 2019-12-06] (Bitdefender SRL -> Bitdefender)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2020-01-29] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2020-01-29] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 aftap0901; C:\WINDOWS\System32\drivers\aftap0901.sys [48624 2018-06-15] (AnchorFree Inc -> The OpenVPN Project)
R1 atc; C:\WINDOWS\System32\DRIVERS\atc.sys [1693368 2019-09-23] (Bitdefender SRL -> Bitdefender S.R.L. Bucharest, ROMANIA)
S3 athur; C:\WINDOWS\System32\DRIVERS\athurx.sys [1847296 2010-01-05] (Microsoft Windows Hardware Compatibility Publisher -> Atheros Communications, Inc.)
R2 BdDci; C:\WINDOWS\system32\DRIVERS\bddci.sys [739264 2019-07-29] (Bitdefender SRL -> Bitdefender)
S0 bdelam; C:\WINDOWS\System32\drivers\bdelam.sys [22960 2019-03-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Bitdefender)
R0 bdprivmon; C:\WINDOWS\System32\DRIVERS\bdprivmon.sys [46056 2019-06-21] (Bitdefender SRL -> © Bitdefender SRL)
R1 BDVEDISK; C:\WINDOWS\system32\DRIVERS\bdvedisk.sys [96448 2018-04-27] (Bitdefender SRL -> BitDefender)
R0 Gemma; C:\WINDOWS\System32\DRIVERS\gemma.sys [564112 2019-11-07] (Bitdefender SRL -> BitDefender S.R.L. Bucharest, ROMANIA)
R0 gzflt; C:\WINDOWS\System32\DRIVERS\gzflt.sys [188384 2018-11-28] (Bitdefender SRL -> BitDefender LLC)
R2 Ignis; C:\WINDOWS\system32\DRIVERS\ignis.sys [196392 2019-07-04] (Bitdefender SRL -> Bitdefender)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [216544 2020-01-07] (Malwarebytes Inc -> Malwarebytes)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [662528 2019-03-19] (Microsoft Windows -> Realtek )
R0 trufos; C:\WINDOWS\System32\DRIVERS\trufos.sys [610640 2019-01-14] (Bitdefender SRL -> Bitdefender)
U5 vwifimp; C:\Windows\System32\Drivers\vwifimp.sys [50176 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45664 2020-01-29] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [355760 2020-01-29] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2020-01-29] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-02-14 10:22 - 2020-02-14 10:24 - 000017283 _____ C:\Users\Eddie\Desktop\FRST.txt
2020-02-14 00:07 - 2020-02-14 00:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital Corporation
2020-02-14 00:07 - 2020-02-14 00:07 - 000000000 ____D C:\Program Files (x86)\Western Digital Corporation
2020-02-14 00:06 - 2020-02-14 00:07 - 000571159 _____ C:\Users\Eddie\Downloads\WinDlg_v1_36.zip
2020-02-13 12:43 - 2020-02-13 12:43 - 000000839 _____ C:\Users\Public\Desktop\Speccy.lnk
2020-02-13 12:43 - 2020-02-13 12:43 - 000000839 _____ C:\ProgramData\Desktop\Speccy.lnk
2020-02-13 12:43 - 2020-02-13 12:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2020-02-13 12:43 - 2020-02-13 12:43 - 000000000 ____D C:\Program Files\Speccy
2020-02-13 12:42 - 2020-02-13 12:43 - 006889184 _____ (Piriform Ltd) C:\Users\Eddie\Downloads\spsetup132.exe
2020-02-13 12:33 - 2020-02-13 12:33 - 000011342 _____ C:\junk.txt
2020-02-13 12:26 - 2020-02-13 12:26 - 000036192 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2020-02-13 12:25 - 2020-02-13 12:25 - 002798456 _____ (Sysinternals - www.sysinternals.com) C:\Users\Eddie\Desktop\procexp.exe
2020-02-13 10:49 - 2020-02-14 10:13 - 000019383 _____ C:\Users\Eddie\Desktop\Fixlog.txt
2020-02-13 10:49 - 2020-02-13 10:49 - 000000000 ____D C:\Users\Eddie\Desktop\FRST-OlderVersion
2020-02-13 09:54 - 2020-02-13 09:54 - 000073886 _____ C:\ProgramData\vpn.1581587617.bdinstall.bin
2020-02-13 09:53 - 2020-02-13 09:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender VPN
2020-02-13 09:53 - 2020-02-13 09:53 - 000000000 ____D C:\ProgramData\Bitdefender VPN
2020-02-13 09:53 - 2018-06-15 09:26 - 000048624 _____ (The OpenVPN Project) C:\WINDOWS\system32\Drivers\aftap0901.sys
2020-02-13 09:52 - 2020-02-13 09:52 - 000814764 _____ C:\ProgramData\cl.1581587183.bdinstall.v2.bin
2020-02-13 09:52 - 2020-02-13 09:52 - 000138752 _____ C:\ProgramData\dm.1581587556.bdinstall.v2.bin
2020-02-13 09:52 - 2020-02-13 09:52 - 000102260 _____ C:\ProgramData\cl.kit.1581587172.bdinstall.v2.bin
2020-02-13 09:52 - 2020-02-13 09:52 - 000003420 _____ C:\WINDOWS\system32\Tasks\Bitdefender AgentTask_AD394AE64E874073B10A89FEEC305A3C
2020-02-13 09:49 - 2020-02-13 09:53 - 000002197 _____ C:\Users\Public\Desktop\Bitdefender VPN.lnk
2020-02-13 09:49 - 2020-02-13 09:53 - 000002197 _____ C:\ProgramData\Desktop\Bitdefender VPN.lnk
2020-02-13 09:49 - 2020-02-13 09:49 - 000002344 _____ C:\Users\Public\Desktop\Bitdefender.lnk
2020-02-13 09:49 - 2020-02-13 09:49 - 000002344 _____ C:\ProgramData\Desktop\Bitdefender.lnk
2020-02-13 09:49 - 2020-02-13 09:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender Security
2020-02-13 09:49 - 2019-03-21 00:12 - 000022960 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bdelam.sys
2020-02-13 09:48 - 2019-11-07 08:49 - 000564112 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\gemma.sys
2020-02-13 09:48 - 2019-09-23 08:43 - 001693368 _____ (Bitdefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\atc.sys
2020-02-13 09:48 - 2019-07-29 15:32 - 000739264 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bddci.sys
2020-02-13 09:48 - 2019-06-21 07:30 - 000046056 _____ (© Bitdefender SRL) C:\WINDOWS\system32\Drivers\bdprivmon.sys
2020-02-13 09:48 - 2018-04-27 07:45 - 000096448 _____ (BitDefender) C:\WINDOWS\system32\Drivers\bdvedisk.sys
2020-02-13 09:47 - 2020-02-13 09:53 - 000000000 ____D C:\Program Files\Bitdefender
2020-02-13 09:47 - 2019-07-04 11:15 - 000196392 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\ignis.sys
2020-02-13 09:47 - 2019-01-14 16:25 - 000610640 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\trufos.sys
2020-02-13 09:47 - 2018-11-28 05:45 - 000188384 _____ (BitDefender LLC) C:\WINDOWS\system32\Drivers\gzflt.sys
2020-02-13 09:46 - 2020-02-13 09:47 - 000000000 ____D C:\Program Files\Common Files\Bitdefender
2020-02-13 09:41 - 2020-02-13 09:41 - 000000000 ____D C:\ProgramData\ssh
2020-02-13 09:36 - 2020-02-13 09:36 - 025900032 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 022635008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 019850240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 019813376 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 018026496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 008013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 007754752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 007600448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 007017472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 006519752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 006284800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 005912064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 005502464 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 005041664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 004856832 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 004575232 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 004470272 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 004308480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 004129416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 003820032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 003525592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 003484672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 003365376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 002861568 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 002800128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-02-13 09:36 - 2020-02-13 09:36 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2020-02-13 09:36 - 2020-02-13 09:36 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2020-02-13 09:36 - 2020-02-13 09:36 - 002703872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 002561536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 002493720 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 002314952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 002305536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 002230232 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001687040 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001664696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001664680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001610240 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001562424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001541632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 001540096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001482040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2020-02-13 09:36 - 2020-02-13 09:36 - 001398584 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001284096 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001273856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001272360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001260544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpsharercom.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001218120 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 001216000 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001213752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001195008 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001098720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001080832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 001077264 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 001060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000996352 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000904504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000857088 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2020-02-13 09:36 - 2020-02-13 09:36 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000784384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000774664 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 000705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000685056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000679368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000670720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000629760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000597816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000542288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000537608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000486400 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000453432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 000450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000422912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000422008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000405632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000400696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2020-02-13 09:36 - 2020-02-13 09:36 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 000335448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-02-13 09:36 - 2020-02-13 09:36 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpviewerax.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000309248 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapisrv.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000274464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BCP47Langs.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000270848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpviewerax.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFMCP.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapisrv.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\srrstr.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2020-02-13 09:36 - 2020-02-13 09:36 - 000214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdsdwmdr.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 000194560 _____ (Microsoft Corporation) C:\WINDOWS\system32\recdisc.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 000193800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2020-02-13 09:36 - 2020-02-13 09:36 - 000186880 _____ (Microsoft Corp.) C:\WINDOWS\system32\Defrag.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000158208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Winlangdb.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000152064 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWSD.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000150536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdrsvc.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000133464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BCP47mrm.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000126976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWSD.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdSSDP.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\dfrgui.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 000097080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\globinputhost.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000093496 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dfrgui.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 000089328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdSSDP.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000084496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2020-02-13 09:36 - 2020-02-13 09:36 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\keyiso.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtutils.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\SrTasks.exe
2020-02-13 09:36 - 2020-02-13 09:36 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtutils.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguageProfileCallback.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Websocket.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000032056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys
2020-02-13 09:36 - 2020-02-13 09:36 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000021520 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000020944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2020-02-13 09:36 - 2020-02-13 09:36 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsunattend.exe
2020-02-13 09:35 - 2020-02-13 09:36 - 009929016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-02-13 09:35 - 2020-02-13 09:35 - 017787904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 004562896 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-02-13 09:35 - 2020-02-13 09:35 - 004005888 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 003969536 _____ (Microsoft Corporation) C:\WINDOWS\system32\tellib.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 003792384 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 003728896 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-02-13 09:35 - 2020-02-13 09:35 - 003703296 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 003590968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-02-13 09:35 - 2020-02-13 09:35 - 003263488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 002870272 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 002714624 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-02-13 09:35 - 2020-02-13 09:35 - 001999960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 001830200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 001743680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 001655880 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 001505592 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 001481216 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpsharercom.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-02-13 09:35 - 2020-02-13 09:35 - 001149928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-02-13 09:35 - 2020-02-13 09:35 - 001084216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 001026792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 001009664 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000875448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-02-13 09:35 - 2020-02-13 09:35 - 000851968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2020-02-13 09:35 - 2020-02-13 09:35 - 000804872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2020-02-13 09:35 - 2020-02-13 09:35 - 000782848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000758800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000678928 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2020-02-13 09:35 - 2020-02-13 09:35 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-02-13 09:35 - 2020-02-13 09:35 - 000535552 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000518456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2020-02-13 09:35 - 2020-02-13 09:35 - 000516648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2020-02-13 09:35 - 2020-02-13 09:35 - 000490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000467952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-02-13 09:35 - 2020-02-13 09:35 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2020-02-13 09:35 - 2020-02-13 09:35 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000369504 _____ (Microsoft Corporation) C:\WINDOWS\system32\BCP47Langs.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000247856 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2020-02-13 09:35 - 2020-02-13 09:35 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Winlangdb.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000220984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2020-02-13 09:35 - 2020-02-13 09:35 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000186672 _____ (Microsoft Corporation) C:\WINDOWS\system32\BCP47mrm.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000179720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2020-02-13 09:35 - 2020-02-13 09:35 - 000165832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2020-02-13 09:35 - 2020-02-13 09:35 - 000157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000132624 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\globinputhost.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000128528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2020-02-13 09:35 - 2020-02-13 09:35 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000127280 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2020-02-13 09:35 - 2020-02-13 09:35 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\keyiso.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguageProfileCallback.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000058880 _____ C:\WINDOWS\system32\runexehelper.exe
2020-02-13 09:35 - 2020-02-13 09:35 - 000046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Websocket.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2020-02-13 09:35 - 2020-02-13 09:35 - 000037392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2020-02-13 09:35 - 2020-02-13 09:35 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dstokenclean.exe
2020-02-13 09:17 - 2020-01-16 05:07 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-02-13 09:17 - 2020-01-16 04:23 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-02-11 18:05 - 2020-02-13 10:49 - 002279424 _____ (Farbar) C:\Users\Eddie\Desktop\FRST64.exe
2020-02-02 20:22 - 2020-02-02 20:22 - 000000080 ___SH C:\bootTel.dat
2020-02-02 10:20 - 2020-02-02 10:20 - 000000000 ____D C:\ProgramData\Bitdefender Device Management
2020-02-02 10:18 - 2020-02-02 10:18 - 000000000 ____D C:\ProgramData\Gemma
2020-02-02 10:18 - 2020-02-02 10:18 - 000000000 ____D C:\ProgramData\Atc
2020-02-02 10:17 - 2020-02-02 10:17 - 000000000 ____D C:\WINDOWS\system32\elambkup
2020-02-02 10:17 - 2020-02-02 10:17 - 000000000 ____D C:\ProgramData\BDLogging
2020-02-02 10:15 - 2020-02-13 09:52 - 000000000 ____D C:\Users\Eddie\AppData\Roaming\Bitdefender
2020-02-02 10:15 - 2020-02-02 10:43 - 000000000 ____D C:\ProgramData\Bitdefender
2020-02-02 10:08 - 2020-02-02 10:08 - 000003802 _____ C:\WINDOWS\system32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
2020-02-02 10:06 - 2020-02-02 10:20 - 000000000 ____D C:\Program Files\Bitdefender Agent
2020-02-02 10:06 - 2020-02-02 10:06 - 000113524 _____ C:\ProgramData\agent.1580637970.bdinstall.v2.bin
2020-02-02 10:06 - 2020-02-02 10:06 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2020-02-02 10:05 - 2020-02-02 10:05 - 012422992 _____ C:\Users\Eddie\Downloads\bitdefender_windows_d19acce7-90aa-4746-a6ad-21b2e4307aa2.exe
2020-01-31 17:47 - 2020-01-31 17:47 - 000000000 ____D C:\Users\Eddie\AppData\Local\PeerDistRepub
2020-01-31 17:10 - 2020-01-31 17:27 - 000000000 ____D C:\Users\Eddie\AppData\Local\D3DSCache
2020-01-31 16:35 - 2020-01-31 16:35 - 000000000 ____D C:\WINDOWS\system32\appmgmt
2020-01-30 00:39 - 2020-01-30 00:39 - 000000000 ____D C:\Program Files\Common Files\SpeechEngines
2020-01-30 00:38 - 2020-01-30 00:38 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2020-01-30 00:37 - 2020-01-30 00:37 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\WINDOWS\system32\msmq
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\WINDOWS\system32\BestPractices
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\Program Files\Reference Assemblies
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\Program Files\MSBuild
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\Program Files (x86)\MSBuild
2020-01-30 00:34 - 2020-01-30 00:34 - 000000000 ____D C:\inetpub
2020-01-30 00:33 - 2019-03-02 01:31 - 001166488 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2020-01-30 00:33 - 2019-03-02 01:31 - 000124568 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2020-01-30 00:33 - 2019-03-02 01:31 - 000035592 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2020-01-30 00:33 - 2019-02-06 02:41 - 000778912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2020-01-30 00:33 - 2019-02-06 02:41 - 000103072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2020-01-30 00:33 - 2019-02-06 02:41 - 000035592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2020-01-30 00:32 - 2019-03-19 03:21 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2020-01-30 00:32 - 2019-03-19 03:16 - 000903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2020-01-30 00:32 - 2019-03-19 02:15 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2020-01-30 00:32 - 2019-03-19 02:09 - 000568320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2020-01-30 00:32 - 2019-03-02 01:33 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2020-01-30 00:32 - 2018-08-09 22:53 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2020-01-29 21:13 - 2020-01-29 21:13 - 000000144 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2020-01-29 20:25 - 2020-01-29 20:25 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 007259648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 006435840 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 006083832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 005764664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 005112320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 004348616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 003967888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 003550208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 003372440 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 003243080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002988552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 002773776 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002766088 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002584008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002260176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002225160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002084576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 002032128 _____ C:\WINDOWS\system32\rdpnano.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001916744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001858560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001835128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-01-29 20:25 - 2020-01-29 20:25 - 001726480 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001693184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001512320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 001489064 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001417760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001412096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001394168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001372160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-01-29 20:25 - 2020-01-29 20:25 - 001300280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 001283592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2020-01-29 20:25 - 2020-01-29 20:25 - 001182232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 001170960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001154448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001151816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001105776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001097216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001083392 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001051448 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 001000960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000974336 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000928120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000913408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000892488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000891736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000890368 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000828216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000824848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000805376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000788992 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000768488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000749568 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000747320 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000704512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000673080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000661816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000637440 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000617784 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000598528 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000587064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000568120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000545432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000510768 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000500736 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2020-01-29 20:25 - 2020-01-29 20:25 - 000486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2020-01-29 20:25 - 2020-01-29 20:25 - 000476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000465208 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000444928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000441072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2020-01-29 20:25 - 2020-01-29 20:25 - 000416056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\DispBroker.Desktop.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000399360 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000384000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000375504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000366416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000345088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000324616 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000311096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000300392 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\msutb.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000259984 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoncli.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofm.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msutb.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\regapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000190464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\regapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000190256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logoncli.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000174392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppvVemgr.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000153912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppvVfs.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatialAudioLicenseSrv.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000143160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000138040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppVStrm.sys
2020-01-29 20:25 - 2020-01-29 20:25 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetDriverInstall.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000107832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairingExperienceMEM.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000106808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000099712 _____ (Microsoft Corporation) C:\WINDOWS\system32\FsIso.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\compstui.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSystray.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetDriverInstall.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedsbs.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000072816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\findnetprinters.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\printui.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000063288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\printui.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000059221 _____ C:\WINDOWS\system32\srms.dat
2020-01-29 20:25 - 2020-01-29 20:25 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\findnetprinters.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\npmproxy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000042512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcicda.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmproxy.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mciwave.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mciseq.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000019768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmsprep.dll
2020-01-29 20:25 - 2020-01-29 20:25 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedssync.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedssync.exe
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-01-29 20:25 - 2020-01-29 20:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-01-29 20:24 - 2020-01-29 20:24 - 007905208 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 006231200 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 006167552 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 004615376 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 004470784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 003110400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 002284544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 002125904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 002071552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001942016 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001841152 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001748480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001413912 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 001083904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000737280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000732200 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000716288 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000642008 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000637968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000589592 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000459896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000437776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000415808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000350720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SpeechPrivacy.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000296760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000194064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\tssrvlic.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AppExecutionAlias.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_BackgroundApps.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationControlCSP.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000117264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000089912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2020-01-29 20:24 - 2020-01-29 20:24 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000088352 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\LSCSHostPolicy.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcicda.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000047208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2020-01-29 20:24 - 2020-01-29 20:24 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mciwave.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mciseq.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\lstelemetry.dll
2020-01-29 20:24 - 2020-01-29 20:24 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindflt.dll
2020-01-29 20:05 - 2020-01-31 17:27 - 000000000 __SHD C:\Users\Eddie\IntelGraphicsProfiles
2020-01-29 20:05 - 2020-01-29 20:05 - 000000451 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2020-01-29 17:36 - 2020-02-03 11:40 - 000000000 ____D C:\Users\Eddie\AppData\Local\PlaceholderTileLogoFolder
2020-01-29 17:22 - 2020-01-29 17:23 - 000000000 ____D C:\Users\Eddie\AppData\Local\Comms
2020-01-29 17:21 - 2020-01-29 19:01 - 000000000 ____D C:\ProgramData\Packages
2020-01-29 17:20 - 2020-02-10 17:21 - 000003368 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3631865646-3207491450-1134192123-1000
2020-01-29 17:20 - 2020-02-10 17:21 - 000000000 ___RD C:\Users\Eddie\OneDrive
2020-01-29 17:17 - 2020-01-29 17:17 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2020-01-29 17:16 - 2020-01-29 17:16 - 000001450 _____ C:\Users\Eddie\Desktop\Microsoft Edge.lnk
2020-01-29 17:04 - 2020-01-29 17:04 - 000000000 ___HD C:\Users\Eddie\MicrosoftEdgeBackups
2020-01-29 17:04 - 2020-01-29 17:04 - 000000000 ____D C:\Users\Eddie\AppData\Local\MicrosoftEdge
2020-01-29 17:03 - 2020-01-29 21:13 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-01-29 17:03 - 2020-01-29 21:13 - 000000000 ___RD C:\Users\Eddie\3D Objects
2020-01-29 17:03 - 2020-01-29 17:55 - 000000000 ____D C:\Users\Eddie\AppData\Local\Publishers
2020-01-29 17:02 - 2020-01-31 16:47 - 000000000 ____D C:\Users\Eddie\AppData\Local\Packages
2020-01-29 17:02 - 2020-01-29 17:03 - 000000000 ____D C:\Users\Eddie\AppData\Local\ConnectedDevicesPlatform
2020-01-29 17:02 - 2020-01-29 17:02 - 000000020 ___SH C:\Users\Eddie\ntuser.ini
2020-01-29 17:00 - 2020-02-14 10:18 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-01-29 17:00 - 2020-02-14 10:12 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2020-01-29 17:00 - 2020-02-05 11:12 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-01-29 17:00 - 2020-02-05 11:12 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-01-29 17:00 - 2020-01-29 19:04 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-01-29 17:00 - 2020-01-29 17:00 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2020-01-29 17:00 - 2020-01-29 17:00 - 000007623 _____ C:\WINDOWS\diagerr.xml
2020-01-29 17:00 - 2020-01-29 17:00 - 000000000 ____D C:\WINDOWS\system32\Tasks\WPD
2020-01-29 17:00 - 2020-01-29 17:00 - 000000000 ____D C:\WINDOWS\system32\Tasks\Games
2020-01-29 16:53 - 2020-02-10 17:21 - 000002410 _____ C:\Users\Eddie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-01-29 16:53 - 2020-02-02 20:17 - 000000000 ____D C:\Users\Eddie
2020-01-29 16:52 - 2020-02-13 11:25 - 000936112 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-01-29 16:49 - 2020-01-09 21:24 - 002874368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2020-01-29 16:48 - 2020-01-29 16:48 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2020-01-29 16:45 - 2020-02-14 03:18 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-01-29 16:45 - 2020-02-13 09:43 - 000413136 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-01-29 15:33 - 2020-02-10 12:56 - 000000000 ___DC C:\WINDOWS\Panther
2020-01-29 15:19 - 2020-01-29 15:33 - 000000000 ____D C:\ESD
2020-01-29 15:17 - 2020-01-29 15:17 - 000000000 ___HD C:\$Windows.~WS
2020-01-29 15:15 - 2020-01-29 15:15 - 000030165 _____ C:\WINDOWS\system32\servers.def.lkg
2020-01-29 15:15 - 2020-01-29 15:15 - 000030165 _____ C:\WINDOWS\system32\servers.def
2020-01-29 15:15 - 2020-01-29 15:15 - 000004451 _____ C:\WINDOWS\system32\uat64.vpx
2020-01-29 15:15 - 2020-01-29 15:15 - 000003333 _____ C:\WINDOWS\system32\servers.def.vpx
2020-01-29 15:15 - 2020-01-29 15:15 - 000000602 _____ C:\WINDOWS\system32\prod-pgm.vpx
2020-01-29 15:15 - 2020-01-29 15:15 - 000000540 _____ C:\WINDOWS\system32\.tmp
2020-01-29 15:15 - 2020-01-29 15:15 - 000000341 _____ C:\WINDOWS\system32\prod-vps.vpx
2020-01-29 15:13 - 2020-01-29 15:13 - 019255000 _____ (Microsoft Corporation) C:\Users\Eddie\Downloads\MediaCreationTool1909.exe

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-02-14 10:23 - 2017-03-08 14:43 - 000000000 ____D C:\FRST
2020-02-14 10:21 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-02-14 10:20 - 2019-03-19 04:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-02-14 10:20 - 2019-03-19 04:50 - 000000000 ____D C:\WINDOWS\INF
2020-02-14 10:17 - 2019-03-19 04:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-02-14 00:09 - 2016-11-18 15:24 - 000000000 ____D C:\Users\Eddie\AppData\LocalLow\Mozilla
2020-02-14 00:08 - 2019-03-19 04:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-02-14 00:01 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2020-02-14 00:01 - 2019-03-19 04:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-02-13 11:25 - 2014-02-13 15:34 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-02-13 11:23 - 2014-02-13 15:34 - 120407888 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-02-13 09:57 - 2016-05-08 12:28 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2020-02-13 09:41 - 2019-03-19 04:52 - 000000000 ___RD C:\WINDOWS\PrintDialog
2020-02-13 09:41 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2020-02-13 09:41 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-02-13 09:41 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SystemResources
2020-02-13 09:41 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2020-02-13 09:41 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-02-13 09:41 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-02-13 09:41 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-02-13 09:41 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-02-13 09:41 - 2019-03-19 04:37 - 000000000 ____D C:\WINDOWS\servicing
2020-02-13 09:29 - 2019-03-19 04:37 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-02-13 00:22 - 2014-02-13 14:01 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-02-11 14:27 - 2014-02-13 14:01 - 000001165 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-02-03 20:56 - 2019-03-19 04:56 - 000835688 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2020-02-03 20:56 - 2019-03-19 04:56 - 000179608 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2020-02-02 10:27 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-02-02 10:27 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-02-02 10:27 - 2017-03-12 10:39 - 000000000 ____D C:\Program Files (x86)\Adobe
2020-01-31 17:41 - 2016-05-26 15:42 - 000007619 _____ C:\Users\Eddie\AppData\Local\resmon.resmoncfg
2020-01-31 16:34 - 2018-05-16 09:02 - 000000000 ____D C:\Users\Eddie\AppData\Local\AVAST Software
2020-01-31 16:34 - 2017-03-10 14:51 - 000000000 ____D C:\ProgramData\AVAST Software
2020-01-31 15:50 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\appcompat
2020-01-30 00:44 - 2019-09-16 12:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2020-01-30 00:44 - 2019-03-19 04:56 - 000000000 ____D C:\WINDOWS\Setup
2020-01-30 00:44 - 2019-03-19 04:52 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2020-01-30 00:44 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\NDF
2020-01-30 00:44 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-01-30 00:44 - 2019-03-19 04:49 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2020-01-30 00:44 - 2016-12-27 18:56 - 000000000 __SHD C:\WINDOWS\SysWOW64\AI_RecycleBin
2020-01-30 00:44 - 2016-05-24 03:43 - 000000000 ____D C:\WINDOWS\system32\configBackup
2020-01-30 00:44 - 2014-08-06 19:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson Software
2020-01-30 00:44 - 2014-07-10 13:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 6.0 Sprint
2020-01-30 00:44 - 2014-07-10 13:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2020-01-30 00:44 - 2014-07-10 12:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2020-01-30 00:44 - 2014-03-25 20:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2020-01-30 00:44 - 2013-10-31 11:58 - 000000000 ____D C:\Program Files (x86)\Intel
2020-01-30 00:44 - 2013-10-31 10:02 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2020-01-30 00:44 - 2010-11-21 07:17 - 000000000 ____D C:\WINDOWS\ShellNew
2020-01-30 00:44 - 2009-07-14 03:20 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2020-01-30 00:44 - 2009-07-14 03:20 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2020-01-30 00:41 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2020-01-30 00:41 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\IME
2020-01-30 00:39 - 2019-03-19 04:52 - 000000000 __SHD C:\Program Files\Windows Sidebar
2020-01-30 00:39 - 2019-03-19 04:52 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
2020-01-30 00:39 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\schemas
2020-01-30 00:39 - 2014-02-13 16:48 - 000000000 ____D C:\Program Files\Microsoft Games
2020-01-30 00:39 - 2013-10-31 11:59 - 000000000 ____D C:\Program Files\CONEXANT
2020-01-30 00:39 - 2009-07-14 05:32 - 000000000 ____D C:\Program Files\DVD Maker
2020-01-30 00:34 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2020-01-30 00:34 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2020-01-30 00:33 - 2020-01-09 21:26 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2020-01-30 00:33 - 2020-01-09 21:26 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2020-01-30 00:33 - 2020-01-09 21:26 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngkeyhelper.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2020-01-30 00:33 - 2020-01-09 21:25 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll
2020-01-30 00:33 - 2020-01-09 21:25 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2020-01-30 00:33 - 2019-03-19 05:00 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2020-01-30 00:33 - 2019-03-19 05:00 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2020-01-30 00:33 - 2019-03-19 05:00 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2020-01-30 00:33 - 2019-03-19 05:00 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2020-01-30 00:33 - 2019-03-19 05:00 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2020-01-30 00:33 - 2019-03-19 05:00 - 000009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2020-01-30 00:33 - 2019-03-19 04:58 - 001401344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000783872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000304640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2020-01-30 00:33 - 2019-03-19 04:58 - 000230912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2020-01-30 00:33 - 2019-03-19 04:58 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2020-01-30 00:33 - 2019-03-19 04:58 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2020-01-30 00:33 - 2019-03-19 04:58 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2020-01-30 00:33 - 2019-03-19 04:58 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2020-01-30 00:33 - 2019-03-19 04:58 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2020-01-30 00:33 - 2019-03-19 04:58 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2020-01-30 00:33 - 2019-03-19 04:58 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2020-01-30 00:33 - 2019-03-19 04:58 - 000009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2020-01-30 00:33 - 2019-03-19 04:57 - 000134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2020-01-30 00:33 - 2019-03-19 04:57 - 000128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\et-EE
2020-01-30 00:33 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\es-MX
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2020-01-29 21:10 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2020-01-29 19:04 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files\Windows Defender
2020-01-29 17:53 - 2013-10-31 10:03 - 000000000 ____D C:\Program Files\Intel
2020-01-29 17:42 - 2010-11-21 03:27 - 000748816 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-01-29 17:40 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2020-01-29 17:40 - 2019-03-19 04:52 - 000000000 ____D C:\ProgramData\USOPrivate
2020-01-29 17:22 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\ServiceState
2020-01-29 17:11 - 2019-03-19 06:22 - 000000000 ____D C:\WINDOWS\OCR
2020-01-29 17:02 - 2019-03-19 04:52 - 000000000 ____D C:\WINDOWS\system32\spool
2020-01-29 17:00 - 2019-03-19 04:52 - 000000000 __RHD C:\Users\Public\Libraries
2020-01-29 16:59 - 2017-04-01 13:22 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-01-29 16:59 - 2017-04-01 13:22 - 000002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-01-29 16:59 - 2017-04-01 13:22 - 000002262 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-01-29 16:54 - 2018-04-15 13:37 - 000000000 ____D C:\Users\Eddie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sky
2020-01-29 16:52 - 2011-02-10 14:33 - 000892382 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2020-01-29 16:17 - 2009-07-14 04:45 - 000021312 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-01-29 16:17 - 2009-07-14 04:45 - 000021312 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

==================== Files in the root of some directories ========

2014-10-29 16:15 - 2014-10-29 16:15 - 000004096 ____H () C:\Users\Eddie\AppData\Local\keyfile3.drm
2016-05-26 15:42 - 2020-01-31 17:41 - 000007619 _____ () C:\Users\Eddie\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

 

Had a look online about info for task scheduler, think its to do with it having missing enteries, would like to fix this, after I am finished here would the Windows 10 forum be able to help with that.

 

Thanks again for all your effort and hard work.


  • 0

#10
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

I'm not a big fan of Seagate myself (I've had bad luck with them failing prematurely and their SMART's always show read errors) but many people like them.  Probably better than having a drive that fails the manufacturer's test tho.  I'd run Seatools's extended test on it just to make sure it's good.

 

Not sure what you mean:

 

Had a look online about info for task scheduler, think its to do with it having missing enteries, would like to fix this, after I am finished here would the Windows 10 forum be able to help with that.

 

 

We have cleaned out all of the tasks that had missing entries as well as the ones that referred to obsolete stuff.  Only thing I wonder about is the ParentalControls stuff.


  • 0

Advertisements


#11
bytesize

bytesize

    Member

  • Topic Starter
  • Member
  • PipPip
  • 96 posts

Hi RKinner

 

still getting these 5 errors when I try and start Task Scheduler, can we use FRST for a fix with these too have posted screenshots below:

 

 

 

 

 

 

 

Attached Thumbnails

  • tasksched1.png
  • tasksched2.png
  • tasksched3.png
  • tasksched4.png
  • tasksched5.png

  • 0

#12
bytesize

bytesize

    Member

  • Topic Starter
  • Member
  • PipPip
  • 96 posts

Found another HDD in some of my old stuff its a WD Caviar SE 250GB but the date on it is 2007, not sure what it was pulled from, will connect it up and run the WD diagnostics on that. Another thing I noticed is I can't seem to uninstall Malwarebytes completely.

 

Thanks


  • 0

#13
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

Last time I saw this kind of error you could go into Task Scheduler and hit OK until the errors stopped then Task Scheduler would work normally.  If that's the case try going into Task Scheduler and navigate to Microsoft\Windows\PerfTrack.  Click on PerfTrack and look in the pane to the right and there should only be one entry for BackgroundConfigSurveyor.  Try right clicking on it and Disable or Delete.  (It's Disabled on mine). If that works go to

 

Microsoft\Windows\RAC and disable or delete RacTrack (not present on mine)

 

Microsoft\Windows\Shell and delete or disable all WindowsParentalControl tasks.  I would also make sure that all FamilyControl tasks are disabled.

Microsoft\Windows\TCPIP and delete or disable all tasks (alternatively right click on TCPIP and Delete Folder

 

Reboot and try Task Scheduler again.  Do you get the same errors.

 

If that doesn't work then you can try to delete the associated task files yourself.  These files are located in

C:\Windows\System32\Tasks\PerfTrack\BackgroundConfigSurveyor

C:\Windows\System32\Tasks\RAC\RACTrack

C:\Windows\System32\Tasks\Shell\WindowsParentalControl... (more than one - delete all)

C:\Windows\System32\Tasks\TCPIP (DELETE FOLDER)

These are hidden system files so you have to tell Windows to let you see them:

http://www.howtogeek...-windows-vista/

 

If this fails we can go into the registry but I hate to do that.  The files are in

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Window\

 

then look for the folder name (PrefTrack) and the task (BackgroundConfigSurveyor) and right click on the task and Delete.  Ignore the warning.

 

Give me a new FRST scan after you finish and I will try to remove MalwareBytes for you.

 

Isn't the original HD 500GB?  Won't the 250GB be too small?

 

 

 


  • 0

#14
bytesize

bytesize

    Member

  • Topic Starter
  • Member
  • PipPip
  • 96 posts

Here is an update tried deleting from within Task Scheduler, only one there was WindowsParentalControlsMigration which I deleted made no difference. Went into

 

C:\Windows\System32\Tasks\ but the tree structure is slightly different found the entries under

 

C:\Windows\System32\Tasks\Microsoft\Windows and they can also be found here too C:\Windows\System32\Tasks_Migrated\Microsoft\Windows

 

Didn't do anything when I found them because they were in a different place to where you said, is the Tasks_Migrated because of the upgrade route.

Should I go ahead and delete from here?

 

Re HDD yes it is smaller, but at the moment he is only using about 60GB and it passed the WD diagnostic test?

 

Thanks


  • 0

#15
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

My win 10 used to be win 8 so I wasn't surprised to see the migrated folder but I looked at my newer laptop and it has it too tho it has never been anything but win 10.  Perhaps they use that folder when they upgrade versions?

 

I would removed the sick files in either or both folders

 

Can you shrink the partitions down so that everything will fit on the smaller drive or does your clonng program do that for you? If you can get it to work it's probably better than what is in there.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP