Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Possible virus or malware

#possible virus #malware

  • Please log in to reply

#16
mckinnik

mckinnik

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts

Okay ... I finally have the results of the second FRST scan. The scan took a very long time to complete

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-08-2020
Ran by mckinnik (administrator) on DESKTOP-GLBDK8Q (SAMSUNG ELECTRONICS CO., LTD. 750QUA) (14-08-2020 20:12:14)
Running from C:\Users\mckin\OneDrive\Desktop
Loaded Profiles: mckinnik
Platform: Windows 10 Home Version 1903 18362.1016 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository̵151.inf_amd64_e5705aeeafa5c2ab\B335002\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository̵151.inf_amd64_e5705aeeafa5c2ab\B335002\atiesrxx.exe
(Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(Cisco Video Technologies Israel Ltd. -> Synamedia) C:\Users\mckin\AppData\Local\Synamedia\VideoGuardPlayer\VideoGuardMonitor\VideoGuardMonitor.exe
(CyberLink Corp. -> CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(Hitachi-LG Data Storage Korea, Inc. -> Hitachi-LG Data Storage, Inc.) C:\Program Files (x86)\ODD Auto Firmware Update\ODDFWUpdate.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13110.41006.0_x64__8wekyb3d8bbwe\commsapps.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13110.41006.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12007.1001.2.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CastSrv.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Qualcomm Atheros -> Windows ® Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\ConsultingMode\ConsultingMode.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\ConsultingMode\ConsultingModeService.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\SamsungSecurity\CmdServer\SamsungSecurityCmdServer.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\SamsungSecurity\CmdServer\SamsungSecurityEventHandler.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\SamsungSecurity\CmdServer\SamsungSecurityLauncher.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\PTPCtrl\PTPCtrl.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\ColorEngine\ColorEngine.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Recovery\BulletService.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung PC Cleaner 2 Service\PCCleaner2Service.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung PC Cleaner 2 Service\PCCleaner2Status.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungSettings\SamsungSettingsExpansionPack.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungSettings\SamsungSettingsExpansionUI.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungSettings\SamsungSettingsExpLauncher.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungUpdate\SUEngine.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungUpdate\SUService.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungUpdate\SUUserModeWorker.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\sService\sServiceAgentLauncherSvc.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\sService\sServiceKeyMonitor.exe
(Samsung Electronics CO., LTD. -> Samsung) C:\Program Files\Samsung\SamsungSettings\WlanAniControl.exe
(Trend Micro, Inc. -> ) C:\Program Files\Trend Micro\TMIDS\tower\PwmTower.exe <3>
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\module\10011\8.1.2009\8.1.2009\TmsaInstance64.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\DiamondRing\DrSDKCaller.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSessionAgent.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtWatchDog.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\TMIDS\PwmSvc.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiSeAgnt.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [Platinum] => C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSessionAgent.exe [1246368 2019-07-29] (Trend Micro, Inc. -> Trend Micro Inc.)
HKLM\...\Run: [Trend Micro Client Framework] => C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [246112 2019-07-29] (Trend Micro, Inc. -> Trend Micro Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [190648 2018-06-27] (CyberLink Corp. -> CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [593080 2018-06-27] (CyberLink Corp. -> CyberLink Corp.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX2] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe [279240 2016-12-09] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [Discord] => C:\ProgramData\SquirrelMachineInstalls\Discord.exe [62625080 2020-07-05] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\Run: [GoogleDriveSync] => "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\Run: [OneDrive] => C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe [1911152 2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\Run: [VideoGuardMonitor] => C:\Users\mckin\AppData\Local\Synamedia\VideoGuardPlayer\VideoGuardMonitor\VideoGuardMonitor.exe [2610920 2019-11-21] (Cisco Video Technologies Israel Ltd. -> Synamedia)
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\Run: [Discord] => C:\Users\mckin\AppData\Local\Discord\app-0.0.306\Discord.exe [90950968 2020-06-09] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\RunOnce: [Application Restart #5] => C:\Program Files\Trend Micro\TMIDS\tower\PwmTower.exe [935840 2018-07-13] (Trend Micro, Inc. -> )
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\RunOnce: [Application Restart #0] => C:\Program Files\Trend Micro\TMIDS\tower\PwmTower.exe [935840 2018-07-13] (Trend Micro, Inc. -> )
HKU\S-1-5-18\...\RunOnce: [Application Restart #0] => C:\Program Files\Samsung\SamsungSettings\WlanAniControl.exe [3379096 2017-06-26] (Samsung Electronics CO., LTD. -> Samsung)
HKU\S-1-5-18\...\RunOnce: [Application Restart #3] => C:\Program Files\Samsung\SamsungSettings\WlanAniControl.exe [3379096 2017-06-26] (Samsung Electronics CO., LTD. -> Samsung)
HKU\S-1-5-18\...\RunOnce: [Application Restart #1] => C:\Program Files\Samsung\SamsungSettings\WlanAniControl.exe [3379096 2017-06-26] (Samsung Electronics CO., LTD. -> Samsung)
HKU\S-1-5-18\...\RunOnce: [Application Restart #2] => C:\Program Files\Samsung\SamsungSettings\WlanAniControl.exe [3379096 2017-06-26] (Samsung Electronics CO., LTD. -> Samsung)
HKU\S-1-5-18\...\RunOnce: [Application Restart #4] => C:\Program Files\Samsung\SamsungSettings\WlanAniControl.exe [3379096 2017-06-26] (Samsung Electronics CO., LTD. -> Samsung)
HKU\S-1-5-18\...\RunOnce: [Application Restart #5] => C:\Program Files\Samsung\SamsungSettings\WlanAniControl.exe [3379096 2017-06-26] (Samsung Electronics CO., LTD. -> Samsung)
HKLM\...\Windows x64\Print Processors\Canon TS6100 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDDP.DLL [482816 2017-12-18] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor TS6100 series: C:\WINDOWS\system32\CNMLMDP.DLL [1302016 2017-12-18] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\84.0.4147.125\Installer\chrmstp.exe [2020-08-10] (Google LLC -> Google LLC)
Startup: C:\Users\mckin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2020-05-16]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\mckin\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook, Inc. -> Facebook)
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {116569F3-7FF4-4C4C-8034-17A7AF2229DB} - System32\Tasks\RtkAudUService64_BG => C:\WINDOWS\System32\RtkAudUService64.exe [956920 2019-12-12] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {16B3C668-E49D-487E-836F-97E0171F6AC4} - System32\Tasks\Samsung\SamsungPCCleaner\SecurityCheck => C:\Program Files\Samsung\Samsung PC Cleaner 2 Service\SecurityAppChecker.exe [4664568 2020-06-02] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {19932E13-FD77-4C47-8E10-CC484B97C15F} - System32\Tasks\SamsungUpdateServiceUpdate => C:\ProgramData\Samsung\SamsungUpdate3\data\SelfUpdate\SUInst.exe
Task: {31E64FB9-A4BC-4EDE-BCA5-8EA843517BAB} - System32\Tasks\SecTimeSync\TimeSyncInit => C:\Windows\SecTimeSync.exe [1629424 2018-06-11] (Samsung Electronics CO., LTD. -> Samsung Electronics CO., LTD.)
Task: {35BFBAB8-D0FF-4353-A11E-EDC7D4F8CC14} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files (x86)\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [2749288 2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {3D7F9E35-CEAF-4BB3-8082-E2537C92936E} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [118624 2020-08-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {49DD80F0-3637-48C9-9259-8B2352B10FF8} - System32\Tasks\Samsung\Settings\SettingsHibernateMonitor => C:\Program Files\Samsung\SamsungSettings\SettingsHibernateMonitor.exe [46488 2017-07-03] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {550E6CD7-C77B-4B65-96F1-C7FE53C50EB8} - System32\Tasks\DPICustomized => C:\ProgramData\Samsung\DPICustomizing\FontCustomizing.exe [24736 2017-11-05] (Samsung Electronics CO., LTD. -> )
Task: {56277C9B-AF4E-4740-B06A-D75A9D64F9C9} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [49032 2018-10-26] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {56D95652-C436-41AB-BDA9-BF26A30FBA3D} - System32\Tasks\PTPFilter => C:\Program Files\PTPCtrl\PTPCtrl.exe [3336864 2018-05-09] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {5D426AB7-E112-4BF2-9CC7-CC26F8B4CF33} - System32\Tasks\Samsung\SamsungSecurity\SecurityAppMoniter => C:\Program Files (x86)\Samsung\SamsungSecurity\SecurityAppChecker.exe [459608 2019-10-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {5ED0E562-B82C-423E-94AD-95A6941F3C08} - System32\Tasks\ColorEngine => C:\Program Files\Samsung\ColorEngine\ColorEngine.exe [571736 2019-05-16] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {68D60D6E-6A3C-47F4-8E72-181C4D04B9A2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-01-03] (Google Inc -> Google Inc.)
Task: {73418FAA-0C7A-4BA8-B589-DF6465E12E8B} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_414_pepper.exe [1471032 2020-08-13] (Adobe Inc. -> Adobe)
Task: {7A085267-4926-43DE-A23B-48A191DDAF27} - System32\Tasks\Samsung\SamsungSecurity\SamsungSecurityPatternLoginMonitor => C:\Program Files (x86)\Samsung\SamsungSecurity\SMessage.exe [500056 2019-10-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {7A3B3FA3-F89A-4F75-84D8-405B28475781} - System32\Tasks\AirSupport Update => C:\Program Files\Trend Micro\AirSupport\Update.exe [4344776 2020-05-17] (Trend Micro, Inc. -> Trend Micro Inc.)
Task: {8DB18245-D4FD-4F4D-8B97-84C19E2E7252} - System32\Tasks\Samsung\SamsungUpdate\UserModeWorker => C:\Program Files\Samsung\SamsungUpdate\SUUserModeWorker.exe [21880 2020-05-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {A7357291-DC9D-4F01-9C8A-1EDB08B9E02F} - System32\Tasks\Samsung\SamsungSecurity\SamsungSecurityPatternLoginAccountMonitor => C:\Program Files (x86)\Samsung\SamsungSecurity\SMessage.exe [500056 2019-10-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {AD48ED6B-F1A0-484B-B625-3FFBA3CD6CEB} - System32\Tasks\ColorSettings => C:\Program Files\Samsung\ColorEngine\SetParam3264.exe [40608 2019-05-16] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {B04C66D3-635E-4EBA-A231-AE83A506A838} - System32\Tasks\ODDAutoFirmwareUpdate => C:\Program Files (x86)\ODD Auto Firmware Update\ODDFWUpdate.exe [1260880 2020-01-24] (Hitachi-LG Data Storage Korea, Inc. -> Hitachi-LG Data Storage, Inc.)
Task: {C5E99885-5966-46C2-A980-8D4E1DB289CD} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1312672 2020-08-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {D8E598ED-640E-4A1A-A2A4-631E756D60D8} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-08-13] (Adobe Inc. -> Adobe)
Task: {EBF74085-AE5E-4E9E-8E3E-E638A93E24F9} - System32\Tasks\Samsung\Recovery8\BulletUserModeWorker => C:\Program Files\Samsung\Recovery\BulletUserModeWorker.exe [317160 2018-06-20] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {EC300D46-8F0B-4BF9-A963-0D8A10334DB3} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [118624 2020-08-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {ECC85EE6-C980-41FE-B76D-4D257BD2FA25} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23819128 2020-07-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {F82E7C73-277F-4A83-966A-AE60D954C660} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23819128 2020-07-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {FA16150C-7C42-4B08-8838-393F037C1721} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-01-03] (Google Inc -> Google Inc.)
Task: {FC00166F-6DEA-4DD7-A6B0-4E1C39A3E89E} - System32\Tasks\Samsung\Wifi Camera\WiFi Camera Agent => C:\Program Files\Samsung\WiFiCamera\WiFiCameraAgent.exe [434904 2018-06-20] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\..\Interfaces\{3f913ad0-69eb-4e37-af61-b835662b816c}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Tcpip\..\Interfaces\{df4a89ed-0624-4f9c-bbe4-534d39895a40}: [DhcpNameServer] 192.168.42.129
 
Internet Explorer:
==================
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung17win10.msn.com/?pc=SMTE
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung17win10.msn.com/?pc=SMTE
SearchScopes: HKU\S-1-5-21-3518604814-232533841-1677687598-1002 -> DefaultScope {C44B1D2B-F169-4ABB-9F54-B4CD5A09252F} URL = 
SearchScopes: HKU\S-1-5-21-3518604814-232533841-1677687598-1002 -> {C44B1D2B-F169-4ABB-9F54-B4CD5A09252F} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2020-01-11] (Microsoft Corporation -> Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2020-04-10] (Trend Micro, Inc. -> Trend Micro Inc.)
BHO: Password Manager BHO -> {782829FB-43A5-4AE0-A14E-590A252E7946} -> C:\Program Files\Trend Micro\TMIDS\bhoDirectPass64.dll [2020-07-06] (Trend Micro, Inc. -> Trend Micro Inc.)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO-x32: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2020-04-10] (Trend Micro, Inc. -> Trend Micro Inc.)
BHO-x32: Password Manager BHO -> {782829FB-43A5-4AE0-A14E-590A252E7946} -> C:\Program Files\Trend Micro\TMIDS\bhoDirectPass32.dll [2020-07-06] (Trend Micro, Inc. -> Trend Micro Inc.)
Toolbar: HKLM - Password Manager ToolBar - {97EE74D2-C351-4ECE-B75A-8CD36FAE3661} - C:\Program Files\Trend Micro\TMIDS\bhoDirectPass64.dll [2020-07-06] (Trend Micro, Inc. -> Trend Micro Inc.)
Toolbar: HKLM - Trend Micro Security Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2020-04-10] (Trend Micro, Inc. -> Trend Micro Inc.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM-x32 - Password Manager ToolBar - {97EE74D2-C351-4ECE-B75A-8CD36FAE3661} - C:\Program Files\Trend Micro\TMIDS\bhoDirectPass32.dll [2020-07-06] (Trend Micro, Inc. -> Trend Micro Inc.)
Toolbar: HKLM-x32 - Trend Micro Security Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2020-04-10] (Trend Micro, Inc. -> Trend Micro Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-08-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-08-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-08-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-08-07] (Microsoft Corporation -> Microsoft Corporation)
Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2020-04-10] (Trend Micro, Inc. -> Trend Micro Inc.)
Handler-x32: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2020-04-10] (Trend Micro, Inc. -> Trend Micro Inc.)
Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ProToolbarIMRatingActiveX.dll [2019-07-29] (Trend Micro, Inc. -> Trend Micro Inc.)
Handler-x32: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll [2019-07-29] (Trend Micro, Inc. -> Trend Micro Inc.)
 
Edge: 
======
DownloadDir: C:\Users\mckin\Downloads
Edge DefaultProfile: Default
Edge Profile: C:\Users\mckin\AppData\Local\Microsoft\Edge\User Data\Default [2020-08-14]
Edge DownloadDir: C:\Users\mckin\Downloads
Edge Extension: (Trend Micro Security for Best Buy) - C:\Users\mckin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\aafppfglogndiagcgpkieicjfkjghbpd [2020-08-14]
 
FireFox:
========
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\[email protected]
FF Extension: (Trend Micro Toolbar) - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\[email protected] [2020-06-17] [UpdateUrl:hxxps://ti-res.trendmicro.com/ti-res/toolbar/FF/prod/updates.json]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\[email protected]
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2019-07-02] (CANON INC.) [File not signed]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-01-11] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-3518604814-232533841-1677687598-1002: @zoom.us/ZoomVideoPlugin -> C:\Users\mckin\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-05-13] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default [2020-08-14]
CHR Notifications: Default -> hxxps://colapamall.com; hxxps://drive.google.com; hxxps://m.headlineswithavoice.com; hxxps://mail.google.com; hxxps://mewe.com; hxxps://outlook.live.com; hxxps://photos.google.com; hxxps://www.facebook.com; hxxps://www.lawenforcementtoday.com; hxxps://www.neonrevolt.com; hxxps://www.spiritualunite.com; hxxps://www.youtube.com
CHR HomePage: Default -> hxxps://www.google.com/
CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxps://duckduckgo.com/"
CHR NewTab: Default ->  Not-active:"chrome-extension://llelondjpcjljnjihdflhpclcpbiaiba/iframe_msn.html"
CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> duckduckgo.com
CHR DefaultNewTabURL: Default -> hxxps://duckduckgo.com/chrome_newtab
CHR DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list
CHR Extension: (Slides) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-01-03]
CHR Extension: (Docs) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-01-03]
CHR Extension: (Google Drive) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-01-03]
CHR Extension: (DuckDuckGo) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2020-08-13]
CHR Extension: (YouTube) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-01-03]
CHR Extension: (ReadingFanatic) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmmbajpcfedaechekcachdldkdfaalbf [2020-06-13]
CHR Extension: (Spell checker and Grammar checker by Scribens) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgkiikdlhmpikkhpiplldicbnicmboc [2020-07-15]
CHR Extension: (Sheets) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-01-03]
CHR Extension: (Trend Micro Password Manager) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fokifklggehlihkifghafpekelcicmgl [2019-07-02]
CHR Extension: (Emojis - Emoji Keyboard) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaoflciahikhligngeccdecgfjngejlh [2020-07-25]
CHR Extension: (Google Docs Offline) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-08-11]
CHR Extension: (Guardio: Antivirus & Malware Removal) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjfpmkejnolcfklaaddjnckanhhgegla [2020-07-09]
CHR Extension: (Google Play Music) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg [2019-01-03]
CHR Extension: (EasyVoice Search) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifabnpjjgbggngmgijikmfjkppdhfpgj [2019-01-07]
CHR Extension: (Grammarly for Chrome) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2020-08-14]
CHR Extension: (Sea Turtle) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgekaffpofmijoelekkemmmelefohain [2019-12-15]
CHR Extension: (MSN New Tab) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\llelondjpcjljnjihdflhpclcpbiaiba [2020-05-25]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2019-05-28]
CHR Extension: (Office) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndjpnladcallmjemlbaebfadecfhkepb [2020-08-07]
CHR Extension: (Wikibuy from Capital One) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nenlahapcbofgnanklpelkaejcehkggg [2020-08-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Trend Micro Toolbar) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohhcpmplhhiiaoiddkfboafbhiknefdf [2020-05-22]
CHR Extension: (Flash Player   ) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooonkoejkmhiacbhhkdgfeemioceapbh [2019-06-12]
CHR Extension: (Amazon Assistant for Chrome) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2020-08-14]
CHR Extension: (mp10search) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfkloachmagkajpnglbknngaimopgkbd [2019-06-12]
CHR Extension: (Gmail) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-03-26]
CHR Extension: (Chrome Media Router) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-07-21]
CHR Profile: C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-05-02]
CHR Profile: C:\Users\mckin\AppData\Local\Google\Chrome\User Data\System Profile [2020-05-17]
CHR HKU\S-1-5-21-3518604814-232533841-1677687598-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [ohhcpmplhhiiaoiddkfboafbhiknefdf]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AdobeFlashPlayerUpdateSvc; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-08-13] (Adobe Inc. -> Adobe)
R2 Amsp; C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe [384032 2019-07-28] (Trend Micro, Inc. -> Trend Micro Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [10566528 2020-07-22] (Microsoft Corporation -> Microsoft Corporation)
R2 ConsultingMode; C:\Program Files (x86)\Samsung\ConsultingMode\ConsultingModeService.exe [951024 2020-05-18] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 FileSyncHelper; C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\FileSyncHelper.exe [2165608 2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [399296 2019-11-28] (Canon Inc. -> )
S3 OneDrive Updater Service; C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\OneDriveUpdaterService.exe [2525040 2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
R2 Platinum Host Service; C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe [1127584 2019-07-29] (Trend Micro, Inc. -> Trend Micro Inc.)
R2 PwmSvc; C:\Program Files\Trend Micro\TMIDS\PwmSvc.exe [2794056 2020-07-06] (Trend Micro, Inc. -> Trend Micro Inc.)
R2 Samsung PC Cleaner 2 Service; C:\Program Files\Samsung\Samsung PC Cleaner 2 Service\PCCleaner2Service.exe [1147136 2020-06-02] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R2 Samsung Settings Expansion Launcher; C:\Program Files\Samsung\SamsungSettings\SamsungSettingsExpLauncher.exe [229232 2020-05-07] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R2 SamsungRecoveryService; C:\Program Files\Samsung\Recovery\BulletService.exe [479464 2018-06-20] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R2 SamsungSecurity Launcher; C:\Program Files (x86)\Samsung\SamsungSecurity\CmdServer\SamsungSecurityLauncher.exe [2014040 2019-10-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R2 SamsungUpdateService; C:\Program Files\Samsung\SamsungUpdate\SUService.exe [377208 2020-05-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R2 sService Agent Launcher; C:\Program Files\Samsung\sService\sServiceAgentLauncherSvc.exe [412880 2017-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 sServiceLoopBack; C:\Program Files\Samsung\sService\sServiceLoopBackSvc.exe [47312 2018-02-08] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 TmWscSvc; C:\Program Files\Trend Micro\Titanium\TmWscSvc\TmWscSvc.exe [406440 2019-11-05] (Trend Micro, Inc. -> Trend Micro Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4098056 2019-03-18] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [113992 2019-03-18] (Microsoft Corporation -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 mxtBootBridge; C:\WINDOWS\System32\drivers\mxtBootBridge.sys [66560 2018-06-26] (Solomon Systech Limited -> Atmel Corporation)
R3 PTPFilter; C:\WINDOWS\System32\drivers\PTPFilter.sys [69440 2018-06-04] (WDKTestCert tguni,131171724190859783 -> Samsung)
S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL64.sys [26368 2015-07-13] (Daniel Terhell -> Resplendence Software Projects Sp.)
R3 SamsungEventController; C:\WINDOWS\System32\drivers\SamsungEventController.sys [41616 2018-05-16] (Samsung Electronics CO., LTD. -> Samsung)
R3 Shci; C:\WINDOWS\System32\drivers\Shci.sys [62448 2018-06-20] (Microsoft Windows Hardware Compatibility Publisher -> Samsung Electronics Co., Ltd.)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167232 2018-12-12] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R0 TMEBC; C:\WINDOWS\System32\DRIVERS\TMEBC64.sys [74760 2019-06-04] (Trend Micro, Inc. -> Trend Micro Inc.)
R2 tmeevw; C:\WINDOWS\system32\DRIVERS\tmeevw.sys [147672 2017-05-10] (Trend Micro, Inc. -> Trend Micro Inc.)
S0 tmel; C:\WINDOWS\System32\DRIVERS\tmel.sys [37552 2019-06-04] (Microsoft Windows Early Launch Anti-malware Publisher -> Trend Micro Inc.)
R1 tmeyes; C:\WINDOWS\system32\DRIVERS\tmeyes.sys [686152 2020-06-07] (Trend Micro, Inc. -> Trend Micro Inc.)
R2 tmnciesc; C:\WINDOWS\system32\DRIVERS\tmnciesc.sys [562296 2018-03-07] (Trend Micro, Inc. -> Trend Micro Inc.)
R1 tmumh; C:\WINDOWS\system32\DRIVERS\TMUMH.sys [160544 2020-03-27] (Trend Micro, Inc. -> Trend Micro Inc.)
R2 tmusa; C:\WINDOWS\system32\DRIVERS\tmusa.sys [137776 2019-05-03] (Trend Micro, Inc. -> Trend Micro Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46472 2019-03-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [333784 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [62432 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
U2 TMAgent; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ===================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-08-14 16:00 - 2020-08-14 16:00 - 000000000 ____D C:\Users\mckin\AppData\Local\inSSIDer
2020-08-14 13:37 - 2020-08-14 16:01 - 000000000 ____D C:\Users\mckin\AppData\Local\MetaGeek
2020-08-14 13:37 - 2020-08-14 16:00 - 000000000 ____D C:\Users\mckin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MetaGeek
2020-08-14 12:50 - 2020-08-14 12:50 - 000000000 ____D C:\Users\mckin\AppData\Local\MetaGeek,_LLC
2020-08-13 11:49 - 2020-08-13 11:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LatencyMon
2020-08-13 11:49 - 2020-08-13 11:49 - 000000000 ____D C:\Program Files\LatencyMon
2020-08-13 11:49 - 2015-07-13 11:16 - 000026368 _____ (Resplendence Software Projects Sp.) C:\WINDOWS\system32\Drivers\rspLLL64.sys
2020-08-13 11:06 - 2020-08-13 11:32 - 000137243 _____ C:\Users\mckin\OneDrive\Documents\DESKTOP-GLBDK8Q.txt
2020-08-13 10:58 - 2020-08-13 10:59 - 000000000 ____D C:\Program Files\Speccy
2020-08-13 10:58 - 2020-08-13 10:58 - 000000837 _____ C:\Users\Public\Desktop\Speccy.lnk
2020-08-13 10:58 - 2020-08-13 10:58 - 000000837 _____ C:\ProgramData\Desktop\Speccy.lnk
2020-08-13 10:58 - 2020-08-13 10:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2020-08-13 09:55 - 2020-08-13 09:55 - 000039372 _____ C:\junk.txt
2020-08-13 09:33 - 2020-08-13 09:33 - 000036408 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2020-08-12 17:44 - 2020-08-12 17:44 - 025903104 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 022642688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 019852288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 019812352 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 018032128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 014820352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 007758848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 007270912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 006526448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 006294528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 006074552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 005946368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 005904896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 005849872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 005767224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 005111296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 005013504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 005003824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 004859904 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 004611072 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 004129408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 003974376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 003822592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 003743056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 003637760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 003516416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002950808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002799104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-08-12 17:44 - 2020-08-12 17:44 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2020-08-12 17:44 - 2020-08-12 17:44 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2020-08-12 17:44 - 2020-08-12 17:44 - 002739200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directml.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002737664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002588688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 002583496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002576896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002422384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 002307584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002259192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 002138280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 002096128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002022400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001870200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001740800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001697792 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001672544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001669344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001654312 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001610240 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001587712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001564160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001420320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001418832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001406464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001397576 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001282872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2020-08-12 17:44 - 2020-08-12 17:44 - 001215488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 001197056 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001151816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001101312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001077048 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 001015296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001012792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001009664 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000995840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000914432 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000897648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000894032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000875520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000782336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000775480 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000738064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 000724480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000718336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000717312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000709120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000702976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BTAGService.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000692224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000690536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000675040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000675024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000673088 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000672256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000671744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaservc.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000671040 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000668672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000666280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 000649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000629760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000593480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000579584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000572200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000568128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000564488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StateRepository.Core.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000535040 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasgcw.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000525824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000495104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxbde40.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000467968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WalletService.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000431104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000405504 _____ (Microsoft Corporation) C:\WINDOWS\system32\DispBroker.Desktop.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000403456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprdim.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000379704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000359496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP4SDECD.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000343408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP4SDECD.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 000339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HrtfApo.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000338944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000330240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-08-12 17:44 - 2020-08-12 17:44 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000309248 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapisrv.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000273744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BCP47Langs.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapisrv.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmWmiPl.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shdocvw.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasplap.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scecli.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000211256 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasplap.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000194048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatializerApo.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000193592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\net1.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtm.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvcext.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrahc.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000165176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtm.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdrsvc.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAuto.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\net1.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Winlangdb.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000133256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BCP47mrm.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000124512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceUpdateAgent.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdSSDP.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\globinputhost.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000090936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000089328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdSSDP.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiarpc.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpkinstall.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManMigrationPlugin.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmRes.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguageProfileCallback.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnpcont.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afunix.sys
2020-08-12 17:44 - 2020-08-12 17:44 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\acwow64.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmprovhost.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnpcont.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryCore.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msisip.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Drivers\afunix.sys
2020-08-12 17:44 - 2020-08-12 17:44 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAgent.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msisip.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiatrace.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmplpxy.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtprio.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtprio.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000006144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000000357 _____ C:\WINDOWS\system32\DrtmAuthKeyDelegate_From_20190529_To_20200303.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000357 _____ C:\WINDOWS\system32\DrtmAuth1KeyDelegate.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-08-12 17:43 - 2020-08-12 17:43 - 017792512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 009932088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 007915864 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 007850784 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 007604584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 007583272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 007297536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 007270728 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 006436864 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 005283776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 004625184 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 004565248 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 004227116 _____ C:\WINDOWS\system32\DefaultHrtfs.bin
2020-08-12 17:43 - 2020-08-12 17:43 - 004005376 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 003806208 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 003727872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 003712000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 003581240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 003368616 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 003141632 _____ (Microsoft Corporation) C:\WINDOWS\system32\directml.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 003084800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002986808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 002808832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002766952 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002717696 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 002698048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 002552120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002523136 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002471936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002289152 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002260312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002136064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002085632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001942528 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001885184 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001756592 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-08-12 17:43 - 2020-08-12 17:43 - 001751040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001743680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001665024 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001660536 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001612800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001540096 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001512848 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 001482568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 001393960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001366144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-08-12 17:43 - 2020-08-12 17:43 - 001338368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001274128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryPS.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001182248 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 001182208 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 001127424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001123344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001072128 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001059328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001055232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001008128 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000937984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000917800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000888352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000875424 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 000867840 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000865280 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000823744 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000822800 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000716312 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000661816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 000624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 000548352 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000534016 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000522688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2020-08-12 17:43 - 2020-08-12 17:43 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\system32\HrtfApo.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000463168 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000461112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000457016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000369304 _____ (Microsoft Corporation) C:\WINDOWS\system32\BCP47Langs.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageOverlayServer.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000335872 _____ (Microsoft Corporation) C:\WINDOWS\system32\RasMediaManager.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000314368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000302080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatializerApo.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000247856 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000220984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000209208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000201544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SIUF.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Winlangdb.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBAUDIO.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 000186472 _____ (Microsoft Corporation) C:\WINDOWS\system32\BCP47mrm.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000179512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAuto.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000152416 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000132408 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\globinputhost.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000104248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManMigrationPlugin.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\keepaliveprovider.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmRes.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguageProfileCallback.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmprovhost.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAgent.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\FaxPrinterInstaller.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbservicetrigger.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmplpxy.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2020-08-12 17:36 - 2020-08-12 17:37 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-08-12 17:36 - 2020-08-12 17:37 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-07-20 13:08 - 2020-07-20 13:08 - 000913656 _____ C:\Users\mckin\OneDrive\Documents\IMG_20200720_0002.pdf
2020-07-20 12:58 - 2020-07-20 12:59 - 000246820 _____ C:\Users\mckin\OneDrive\Documents\IMG_20200720_0001.pdf
2020-07-18 20:05 - 2020-07-18 20:05 - 000104451 _____ C:\Users\mckin\OneDrive\Documents\FRST.txt
2020-07-18 10:16 - 2020-07-18 20:05 - 000046189 _____ C:\Users\mckin\OneDrive\Documents\Addition.txt
2020-07-18 09:59 - 2020-08-14 20:17 - 000000000 ____D C:\FRST
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-08-14 20:26 - 2018-08-31 09:22 - 000000512 _____ C:\Users\Public\amdsfhdcd.bin
2020-08-14 20:25 - 2019-01-04 12:09 - 000000000 ____D C:\Users\mckin\AppData\Local\DP_Tower_3.7
2020-08-14 20:22 - 2019-03-18 21:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-08-14 20:06 - 2019-01-03 13:40 - 000000000 ___RD C:\Users\mckin\OneDrive
2020-08-14 19:58 - 2019-06-21 15:57 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-08-14 16:00 - 2019-04-29 10:38 - 000000000 ____D C:\Users\mckin\AppData\Local\SquirrelTemp
2020-08-14 14:17 - 2019-06-21 16:05 - 000004166 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{82C98F3A-F861-4825-865D-F4A99D1C2801}
2020-08-14 12:55 - 2019-01-04 12:09 - 000000000 ____D C:\ProgramData\TMDP_Log
2020-08-14 12:38 - 2018-09-18 18:19 - 000000000 ____D C:\Users\mckin\AppData\Local\Packages
2020-08-14 12:36 - 2019-03-18 21:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-08-14 12:36 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-08-14 12:26 - 2019-01-03 13:58 - 000000000 ____D C:\Users\mckin\AppData\Local\ElevatedDiagnostics
2020-08-14 10:30 - 2019-06-21 16:06 - 000840852 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-08-14 10:30 - 2019-03-18 21:50 - 000000000 ____D C:\WINDOWS\INF
2020-08-14 10:28 - 2019-03-18 21:37 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-08-14 10:25 - 2019-06-21 16:05 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-08-14 10:25 - 2019-03-18 21:37 - 001310720 _____ C:\WINDOWS\system32\config\BBI
2020-08-14 10:18 - 2019-03-18 21:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-08-14 08:20 - 2019-06-21 16:05 - 000000000 ____D C:\WINDOWS\system32\Tasks\Samsung
2020-08-13 23:14 - 2020-02-13 09:10 - 000000000 ____D C:\ProgramData\CanonIJPLM
2020-08-13 15:38 - 2019-06-21 16:05 - 000004564 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2020-08-13 15:38 - 2019-03-18 21:56 - 000842296 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2020-08-13 15:38 - 2019-03-18 21:56 - 000175160 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2020-08-13 15:36 - 2020-07-14 11:36 - 004510264 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2020-08-13 15:36 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-08-13 15:36 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-08-13 08:21 - 2018-09-18 18:19 - 000000000 ___RD C:\Users\mckin\3D Objects
2020-08-13 08:21 - 2018-09-01 01:18 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-08-13 08:20 - 2019-09-13 12:07 - 000000000 ____D C:\Program Files (x86)\Microsoft OneDrive
2020-08-13 08:20 - 2019-06-21 15:57 - 000447536 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\SystemResources
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\system32\setup
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\Provisioning
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-08-13 08:20 - 2019-03-18 21:37 - 000000000 ____D C:\WINDOWS\servicing
2020-08-12 21:00 - 2019-01-04 14:26 - 000000010 _____ C:\Users\mckin\AppData\Local\sponge.last.runtime.cache
2020-08-12 18:41 - 2020-06-23 21:17 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-08-12 18:41 - 2020-06-23 21:17 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2020-08-12 18:41 - 2020-06-23 21:17 - 000002276 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2020-08-12 12:29 - 2019-09-13 12:07 - 000003206 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2020-08-12 12:29 - 2019-09-13 12:07 - 000002174 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-08-11 12:47 - 2020-01-30 20:06 - 000000000 ____D C:\Users\mckin\AppData\Roaming\Messenger
2020-08-11 12:33 - 2019-01-04 11:46 - 000000000 ____D C:\ProgramData\Trend Micro
2020-08-11 12:29 - 2020-01-22 18:50 - 000000000 ____D C:\Users\mckin\AppData\Local\CrashDumps
2020-08-10 15:15 - 2019-01-03 20:26 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-08-08 18:31 - 2019-01-09 22:45 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2020-08-07 16:48 - 2018-04-11 16:38 - 000000359 _____ C:\WINDOWS\win.ini
2020-07-17 09:03 - 2020-07-05 11:30 - 000000000 ____D C:\Users\mckin\AppData\Roaming\discord
 
==================== Files in the root of some directories ========
 
2019-01-04 11:51 - 2020-01-22 11:27 - 000000036 _____ () C:\Users\mckin\AppData\Local\housecall.guid.cache
2019-01-04 14:26 - 2020-08-12 21:00 - 000000010 _____ () C:\Users\mckin\AppData\Local\sponge.last.runtime.cache
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-08-2020
Ran by mckinnik (administrator) on DESKTOP-GLBDK8Q (SAMSUNG ELECTRONICS CO., LTD. 750QUA) (14-08-2020 20:12:14)
Running from C:\Users\mckin\OneDrive\Desktop
Loaded Profiles: mckinnik
Platform: Windows 10 Home Version 1903 18362.1016 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository̵151.inf_amd64_e5705aeeafa5c2ab\B335002\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository̵151.inf_amd64_e5705aeeafa5c2ab\B335002\atiesrxx.exe
(Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(Cisco Video Technologies Israel Ltd. -> Synamedia) C:\Users\mckin\AppData\Local\Synamedia\VideoGuardPlayer\VideoGuardMonitor\VideoGuardMonitor.exe
(CyberLink Corp. -> CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(Hitachi-LG Data Storage Korea, Inc. -> Hitachi-LG Data Storage, Inc.) C:\Program Files (x86)\ODD Auto Firmware Update\ODDFWUpdate.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13110.41006.0_x64__8wekyb3d8bbwe\commsapps.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13110.41006.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12007.1001.2.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CastSrv.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Qualcomm Atheros -> Windows ® Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\ConsultingMode\ConsultingMode.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\ConsultingMode\ConsultingModeService.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\SamsungSecurity\CmdServer\SamsungSecurityCmdServer.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\SamsungSecurity\CmdServer\SamsungSecurityEventHandler.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\SamsungSecurity\CmdServer\SamsungSecurityLauncher.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\PTPCtrl\PTPCtrl.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\ColorEngine\ColorEngine.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Recovery\BulletService.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung PC Cleaner 2 Service\PCCleaner2Service.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung PC Cleaner 2 Service\PCCleaner2Status.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungSettings\SamsungSettingsExpansionPack.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungSettings\SamsungSettingsExpansionUI.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungSettings\SamsungSettingsExpLauncher.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungUpdate\SUEngine.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungUpdate\SUService.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungUpdate\SUUserModeWorker.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\sService\sServiceAgentLauncherSvc.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\sService\sServiceKeyMonitor.exe
(Samsung Electronics CO., LTD. -> Samsung) C:\Program Files\Samsung\SamsungSettings\WlanAniControl.exe
(Trend Micro, Inc. -> ) C:\Program Files\Trend Micro\TMIDS\tower\PwmTower.exe <3>
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\module\10011\8.1.2009\8.1.2009\TmsaInstance64.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\DiamondRing\DrSDKCaller.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSessionAgent.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtWatchDog.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\TMIDS\PwmSvc.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiSeAgnt.exe
(Trend Micro, Inc. -> Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [Platinum] => C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSessionAgent.exe [1246368 2019-07-29] (Trend Micro, Inc. -> Trend Micro Inc.)
HKLM\...\Run: [Trend Micro Client Framework] => C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [246112 2019-07-29] (Trend Micro, Inc. -> Trend Micro Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [190648 2018-06-27] (CyberLink Corp. -> CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [593080 2018-06-27] (CyberLink Corp. -> CyberLink Corp.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX2] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe [279240 2016-12-09] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [Discord] => C:\ProgramData\SquirrelMachineInstalls\Discord.exe [62625080 2020-07-05] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\Run: [GoogleDriveSync] => "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\Run: [OneDrive] => C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe [1911152 2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\Run: [VideoGuardMonitor] => C:\Users\mckin\AppData\Local\Synamedia\VideoGuardPlayer\VideoGuardMonitor\VideoGuardMonitor.exe [2610920 2019-11-21] (Cisco Video Technologies Israel Ltd. -> Synamedia)
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\Run: [Discord] => C:\Users\mckin\AppData\Local\Discord\app-0.0.306\Discord.exe [90950968 2020-06-09] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\RunOnce: [Application Restart #5] => C:\Program Files\Trend Micro\TMIDS\tower\PwmTower.exe [935840 2018-07-13] (Trend Micro, Inc. -> )
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\RunOnce: [Application Restart #0] => C:\Program Files\Trend Micro\TMIDS\tower\PwmTower.exe [935840 2018-07-13] (Trend Micro, Inc. -> )
HKU\S-1-5-18\...\RunOnce: [Application Restart #0] => C:\Program Files\Samsung\SamsungSettings\WlanAniControl.exe [3379096 2017-06-26] (Samsung Electronics CO., LTD. -> Samsung)
HKU\S-1-5-18\...\RunOnce: [Application Restart #3] => C:\Program Files\Samsung\SamsungSettings\WlanAniControl.exe [3379096 2017-06-26] (Samsung Electronics CO., LTD. -> Samsung)
HKU\S-1-5-18\...\RunOnce: [Application Restart #1] => C:\Program Files\Samsung\SamsungSettings\WlanAniControl.exe [3379096 2017-06-26] (Samsung Electronics CO., LTD. -> Samsung)
HKU\S-1-5-18\...\RunOnce: [Application Restart #2] => C:\Program Files\Samsung\SamsungSettings\WlanAniControl.exe [3379096 2017-06-26] (Samsung Electronics CO., LTD. -> Samsung)
HKU\S-1-5-18\...\RunOnce: [Application Restart #4] => C:\Program Files\Samsung\SamsungSettings\WlanAniControl.exe [3379096 2017-06-26] (Samsung Electronics CO., LTD. -> Samsung)
HKU\S-1-5-18\...\RunOnce: [Application Restart #5] => C:\Program Files\Samsung\SamsungSettings\WlanAniControl.exe [3379096 2017-06-26] (Samsung Electronics CO., LTD. -> Samsung)
HKLM\...\Windows x64\Print Processors\Canon TS6100 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDDP.DLL [482816 2017-12-18] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor TS6100 series: C:\WINDOWS\system32\CNMLMDP.DLL [1302016 2017-12-18] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\84.0.4147.125\Installer\chrmstp.exe [2020-08-10] (Google LLC -> Google LLC)
Startup: C:\Users\mckin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2020-05-16]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\mckin\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook, Inc. -> Facebook)
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {116569F3-7FF4-4C4C-8034-17A7AF2229DB} - System32\Tasks\RtkAudUService64_BG => C:\WINDOWS\System32\RtkAudUService64.exe [956920 2019-12-12] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {16B3C668-E49D-487E-836F-97E0171F6AC4} - System32\Tasks\Samsung\SamsungPCCleaner\SecurityCheck => C:\Program Files\Samsung\Samsung PC Cleaner 2 Service\SecurityAppChecker.exe [4664568 2020-06-02] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {19932E13-FD77-4C47-8E10-CC484B97C15F} - System32\Tasks\SamsungUpdateServiceUpdate => C:\ProgramData\Samsung\SamsungUpdate3\data\SelfUpdate\SUInst.exe
Task: {31E64FB9-A4BC-4EDE-BCA5-8EA843517BAB} - System32\Tasks\SecTimeSync\TimeSyncInit => C:\Windows\SecTimeSync.exe [1629424 2018-06-11] (Samsung Electronics CO., LTD. -> Samsung Electronics CO., LTD.)
Task: {35BFBAB8-D0FF-4353-A11E-EDC7D4F8CC14} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files (x86)\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [2749288 2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {3D7F9E35-CEAF-4BB3-8082-E2537C92936E} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [118624 2020-08-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {49DD80F0-3637-48C9-9259-8B2352B10FF8} - System32\Tasks\Samsung\Settings\SettingsHibernateMonitor => C:\Program Files\Samsung\SamsungSettings\SettingsHibernateMonitor.exe [46488 2017-07-03] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {550E6CD7-C77B-4B65-96F1-C7FE53C50EB8} - System32\Tasks\DPICustomized => C:\ProgramData\Samsung\DPICustomizing\FontCustomizing.exe [24736 2017-11-05] (Samsung Electronics CO., LTD. -> )
Task: {56277C9B-AF4E-4740-B06A-D75A9D64F9C9} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [49032 2018-10-26] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {56D95652-C436-41AB-BDA9-BF26A30FBA3D} - System32\Tasks\PTPFilter => C:\Program Files\PTPCtrl\PTPCtrl.exe [3336864 2018-05-09] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {5D426AB7-E112-4BF2-9CC7-CC26F8B4CF33} - System32\Tasks\Samsung\SamsungSecurity\SecurityAppMoniter => C:\Program Files (x86)\Samsung\SamsungSecurity\SecurityAppChecker.exe [459608 2019-10-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {5ED0E562-B82C-423E-94AD-95A6941F3C08} - System32\Tasks\ColorEngine => C:\Program Files\Samsung\ColorEngine\ColorEngine.exe [571736 2019-05-16] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {68D60D6E-6A3C-47F4-8E72-181C4D04B9A2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-01-03] (Google Inc -> Google Inc.)
Task: {73418FAA-0C7A-4BA8-B589-DF6465E12E8B} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_414_pepper.exe [1471032 2020-08-13] (Adobe Inc. -> Adobe)
Task: {7A085267-4926-43DE-A23B-48A191DDAF27} - System32\Tasks\Samsung\SamsungSecurity\SamsungSecurityPatternLoginMonitor => C:\Program Files (x86)\Samsung\SamsungSecurity\SMessage.exe [500056 2019-10-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {7A3B3FA3-F89A-4F75-84D8-405B28475781} - System32\Tasks\AirSupport Update => C:\Program Files\Trend Micro\AirSupport\Update.exe [4344776 2020-05-17] (Trend Micro, Inc. -> Trend Micro Inc.)
Task: {8DB18245-D4FD-4F4D-8B97-84C19E2E7252} - System32\Tasks\Samsung\SamsungUpdate\UserModeWorker => C:\Program Files\Samsung\SamsungUpdate\SUUserModeWorker.exe [21880 2020-05-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {A7357291-DC9D-4F01-9C8A-1EDB08B9E02F} - System32\Tasks\Samsung\SamsungSecurity\SamsungSecurityPatternLoginAccountMonitor => C:\Program Files (x86)\Samsung\SamsungSecurity\SMessage.exe [500056 2019-10-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {AD48ED6B-F1A0-484B-B625-3FFBA3CD6CEB} - System32\Tasks\ColorSettings => C:\Program Files\Samsung\ColorEngine\SetParam3264.exe [40608 2019-05-16] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {B04C66D3-635E-4EBA-A231-AE83A506A838} - System32\Tasks\ODDAutoFirmwareUpdate => C:\Program Files (x86)\ODD Auto Firmware Update\ODDFWUpdate.exe [1260880 2020-01-24] (Hitachi-LG Data Storage Korea, Inc. -> Hitachi-LG Data Storage, Inc.)
Task: {C5E99885-5966-46C2-A980-8D4E1DB289CD} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1312672 2020-08-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {D8E598ED-640E-4A1A-A2A4-631E756D60D8} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-08-13] (Adobe Inc. -> Adobe)
Task: {EBF74085-AE5E-4E9E-8E3E-E638A93E24F9} - System32\Tasks\Samsung\Recovery8\BulletUserModeWorker => C:\Program Files\Samsung\Recovery\BulletUserModeWorker.exe [317160 2018-06-20] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {EC300D46-8F0B-4BF9-A963-0D8A10334DB3} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [118624 2020-08-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {ECC85EE6-C980-41FE-B76D-4D257BD2FA25} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23819128 2020-07-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {F82E7C73-277F-4A83-966A-AE60D954C660} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23819128 2020-07-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {FA16150C-7C42-4B08-8838-393F037C1721} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-01-03] (Google Inc -> Google Inc.)
Task: {FC00166F-6DEA-4DD7-A6B0-4E1C39A3E89E} - System32\Tasks\Samsung\Wifi Camera\WiFi Camera Agent => C:\Program Files\Samsung\WiFiCamera\WiFiCameraAgent.exe [434904 2018-06-20] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\..\Interfaces\{3f913ad0-69eb-4e37-af61-b835662b816c}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Tcpip\..\Interfaces\{df4a89ed-0624-4f9c-bbe4-534d39895a40}: [DhcpNameServer] 192.168.42.129
 
Internet Explorer:
==================
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung17win10.msn.com/?pc=SMTE
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung17win10.msn.com/?pc=SMTE
SearchScopes: HKU\S-1-5-21-3518604814-232533841-1677687598-1002 -> DefaultScope {C44B1D2B-F169-4ABB-9F54-B4CD5A09252F} URL = 
SearchScopes: HKU\S-1-5-21-3518604814-232533841-1677687598-1002 -> {C44B1D2B-F169-4ABB-9F54-B4CD5A09252F} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2020-01-11] (Microsoft Corporation -> Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2020-04-10] (Trend Micro, Inc. -> Trend Micro Inc.)
BHO: Password Manager BHO -> {782829FB-43A5-4AE0-A14E-590A252E7946} -> C:\Program Files\Trend Micro\TMIDS\bhoDirectPass64.dll [2020-07-06] (Trend Micro, Inc. -> Trend Micro Inc.)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO-x32: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2020-04-10] (Trend Micro, Inc. -> Trend Micro Inc.)
BHO-x32: Password Manager BHO -> {782829FB-43A5-4AE0-A14E-590A252E7946} -> C:\Program Files\Trend Micro\TMIDS\bhoDirectPass32.dll [2020-07-06] (Trend Micro, Inc. -> Trend Micro Inc.)
Toolbar: HKLM - Password Manager ToolBar - {97EE74D2-C351-4ECE-B75A-8CD36FAE3661} - C:\Program Files\Trend Micro\TMIDS\bhoDirectPass64.dll [2020-07-06] (Trend Micro, Inc. -> Trend Micro Inc.)
Toolbar: HKLM - Trend Micro Security Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2020-04-10] (Trend Micro, Inc. -> Trend Micro Inc.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM-x32 - Password Manager ToolBar - {97EE74D2-C351-4ECE-B75A-8CD36FAE3661} - C:\Program Files\Trend Micro\TMIDS\bhoDirectPass32.dll [2020-07-06] (Trend Micro, Inc. -> Trend Micro Inc.)
Toolbar: HKLM-x32 - Trend Micro Security Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2020-04-10] (Trend Micro, Inc. -> Trend Micro Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-08-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-08-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-08-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-08-07] (Microsoft Corporation -> Microsoft Corporation)
Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2020-04-10] (Trend Micro, Inc. -> Trend Micro Inc.)
Handler-x32: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2020-04-10] (Trend Micro, Inc. -> Trend Micro Inc.)
Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ProToolbarIMRatingActiveX.dll [2019-07-29] (Trend Micro, Inc. -> Trend Micro Inc.)
Handler-x32: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll [2019-07-29] (Trend Micro, Inc. -> Trend Micro Inc.)
 
Edge: 
======
DownloadDir: C:\Users\mckin\Downloads
Edge DefaultProfile: Default
Edge Profile: C:\Users\mckin\AppData\Local\Microsoft\Edge\User Data\Default [2020-08-14]
Edge DownloadDir: C:\Users\mckin\Downloads
Edge Extension: (Trend Micro Security for Best Buy) - C:\Users\mckin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\aafppfglogndiagcgpkieicjfkjghbpd [2020-08-14]
 
FireFox:
========
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\[email protected]
FF Extension: (Trend Micro Toolbar) - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\[email protected] [2020-06-17] [UpdateUrl:hxxps://ti-res.trendmicro.com/ti-res/toolbar/FF/prod/updates.json]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\[email protected]
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2019-07-02] (CANON INC.) [File not signed]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-01-11] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-3518604814-232533841-1677687598-1002: @zoom.us/ZoomVideoPlugin -> C:\Users\mckin\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-05-13] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default [2020-08-14]
CHR Notifications: Default -> hxxps://colapamall.com; hxxps://drive.google.com; hxxps://m.headlineswithavoice.com; hxxps://mail.google.com; hxxps://mewe.com; hxxps://outlook.live.com; hxxps://photos.google.com; hxxps://www.facebook.com; hxxps://www.lawenforcementtoday.com; hxxps://www.neonrevolt.com; hxxps://www.spiritualunite.com; hxxps://www.youtube.com
CHR HomePage: Default -> hxxps://www.google.com/
CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxps://duckduckgo.com/"
CHR NewTab: Default ->  Not-active:"chrome-extension://llelondjpcjljnjihdflhpclcpbiaiba/iframe_msn.html"
CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> duckduckgo.com
CHR DefaultNewTabURL: Default -> hxxps://duckduckgo.com/chrome_newtab
CHR DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list
CHR Extension: (Slides) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-01-03]
CHR Extension: (Docs) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-01-03]
CHR Extension: (Google Drive) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-01-03]
CHR Extension: (DuckDuckGo) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2020-08-13]
CHR Extension: (YouTube) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-01-03]
CHR Extension: (ReadingFanatic) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmmbajpcfedaechekcachdldkdfaalbf [2020-06-13]
CHR Extension: (Spell checker and Grammar checker by Scribens) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgkiikdlhmpikkhpiplldicbnicmboc [2020-07-15]
CHR Extension: (Sheets) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-01-03]
CHR Extension: (Trend Micro Password Manager) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fokifklggehlihkifghafpekelcicmgl [2019-07-02]
CHR Extension: (Emojis - Emoji Keyboard) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaoflciahikhligngeccdecgfjngejlh [2020-07-25]
CHR Extension: (Google Docs Offline) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-08-11]
CHR Extension: (Guardio: Antivirus & Malware Removal) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjfpmkejnolcfklaaddjnckanhhgegla [2020-07-09]
CHR Extension: (Google Play Music) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg [2019-01-03]
CHR Extension: (EasyVoice Search) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifabnpjjgbggngmgijikmfjkppdhfpgj [2019-01-07]
CHR Extension: (Grammarly for Chrome) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2020-08-14]
CHR Extension: (Sea Turtle) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgekaffpofmijoelekkemmmelefohain [2019-12-15]
CHR Extension: (MSN New Tab) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\llelondjpcjljnjihdflhpclcpbiaiba [2020-05-25]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2019-05-28]
CHR Extension: (Office) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndjpnladcallmjemlbaebfadecfhkepb [2020-08-07]
CHR Extension: (Wikibuy from Capital One) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nenlahapcbofgnanklpelkaejcehkggg [2020-08-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Trend Micro Toolbar) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohhcpmplhhiiaoiddkfboafbhiknefdf [2020-05-22]
CHR Extension: (Flash Player   ) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooonkoejkmhiacbhhkdgfeemioceapbh [2019-06-12]
CHR Extension: (Amazon Assistant for Chrome) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2020-08-14]
CHR Extension: (mp10search) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfkloachmagkajpnglbknngaimopgkbd [2019-06-12]
CHR Extension: (Gmail) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-03-26]
CHR Extension: (Chrome Media Router) - C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-07-21]
CHR Profile: C:\Users\mckin\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-05-02]
CHR Profile: C:\Users\mckin\AppData\Local\Google\Chrome\User Data\System Profile [2020-05-17]
CHR HKU\S-1-5-21-3518604814-232533841-1677687598-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [ohhcpmplhhiiaoiddkfboafbhiknefdf]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AdobeFlashPlayerUpdateSvc; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-08-13] (Adobe Inc. -> Adobe)
R2 Amsp; C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe [384032 2019-07-28] (Trend Micro, Inc. -> Trend Micro Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [10566528 2020-07-22] (Microsoft Corporation -> Microsoft Corporation)
R2 ConsultingMode; C:\Program Files (x86)\Samsung\ConsultingMode\ConsultingModeService.exe [951024 2020-05-18] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 FileSyncHelper; C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\FileSyncHelper.exe [2165608 2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [399296 2019-11-28] (Canon Inc. -> )
S3 OneDrive Updater Service; C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\OneDriveUpdaterService.exe [2525040 2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
R2 Platinum Host Service; C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe [1127584 2019-07-29] (Trend Micro, Inc. -> Trend Micro Inc.)
R2 PwmSvc; C:\Program Files\Trend Micro\TMIDS\PwmSvc.exe [2794056 2020-07-06] (Trend Micro, Inc. -> Trend Micro Inc.)
R2 Samsung PC Cleaner 2 Service; C:\Program Files\Samsung\Samsung PC Cleaner 2 Service\PCCleaner2Service.exe [1147136 2020-06-02] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R2 Samsung Settings Expansion Launcher; C:\Program Files\Samsung\SamsungSettings\SamsungSettingsExpLauncher.exe [229232 2020-05-07] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R2 SamsungRecoveryService; C:\Program Files\Samsung\Recovery\BulletService.exe [479464 2018-06-20] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R2 SamsungSecurity Launcher; C:\Program Files (x86)\Samsung\SamsungSecurity\CmdServer\SamsungSecurityLauncher.exe [2014040 2019-10-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R2 SamsungUpdateService; C:\Program Files\Samsung\SamsungUpdate\SUService.exe [377208 2020-05-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R2 sService Agent Launcher; C:\Program Files\Samsung\sService\sServiceAgentLauncherSvc.exe [412880 2017-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 sServiceLoopBack; C:\Program Files\Samsung\sService\sServiceLoopBackSvc.exe [47312 2018-02-08] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 TmWscSvc; C:\Program Files\Trend Micro\Titanium\TmWscSvc\TmWscSvc.exe [406440 2019-11-05] (Trend Micro, Inc. -> Trend Micro Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4098056 2019-03-18] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [113992 2019-03-18] (Microsoft Corporation -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 mxtBootBridge; C:\WINDOWS\System32\drivers\mxtBootBridge.sys [66560 2018-06-26] (Solomon Systech Limited -> Atmel Corporation)
R3 PTPFilter; C:\WINDOWS\System32\drivers\PTPFilter.sys [69440 2018-06-04] (WDKTestCert tguni,131171724190859783 -> Samsung)
S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL64.sys [26368 2015-07-13] (Daniel Terhell -> Resplendence Software Projects Sp.)
R3 SamsungEventController; C:\WINDOWS\System32\drivers\SamsungEventController.sys [41616 2018-05-16] (Samsung Electronics CO., LTD. -> Samsung)
R3 Shci; C:\WINDOWS\System32\drivers\Shci.sys [62448 2018-06-20] (Microsoft Windows Hardware Compatibility Publisher -> Samsung Electronics Co., Ltd.)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167232 2018-12-12] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R0 TMEBC; C:\WINDOWS\System32\DRIVERS\TMEBC64.sys [74760 2019-06-04] (Trend Micro, Inc. -> Trend Micro Inc.)
R2 tmeevw; C:\WINDOWS\system32\DRIVERS\tmeevw.sys [147672 2017-05-10] (Trend Micro, Inc. -> Trend Micro Inc.)
S0 tmel; C:\WINDOWS\System32\DRIVERS\tmel.sys [37552 2019-06-04] (Microsoft Windows Early Launch Anti-malware Publisher -> Trend Micro Inc.)
R1 tmeyes; C:\WINDOWS\system32\DRIVERS\tmeyes.sys [686152 2020-06-07] (Trend Micro, Inc. -> Trend Micro Inc.)
R2 tmnciesc; C:\WINDOWS\system32\DRIVERS\tmnciesc.sys [562296 2018-03-07] (Trend Micro, Inc. -> Trend Micro Inc.)
R1 tmumh; C:\WINDOWS\system32\DRIVERS\TMUMH.sys [160544 2020-03-27] (Trend Micro, Inc. -> Trend Micro Inc.)
R2 tmusa; C:\WINDOWS\system32\DRIVERS\tmusa.sys [137776 2019-05-03] (Trend Micro, Inc. -> Trend Micro Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46472 2019-03-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [333784 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [62432 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
U2 TMAgent; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ===================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-08-14 16:00 - 2020-08-14 16:00 - 000000000 ____D C:\Users\mckin\AppData\Local\inSSIDer
2020-08-14 13:37 - 2020-08-14 16:01 - 000000000 ____D C:\Users\mckin\AppData\Local\MetaGeek
2020-08-14 13:37 - 2020-08-14 16:00 - 000000000 ____D C:\Users\mckin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MetaGeek
2020-08-14 12:50 - 2020-08-14 12:50 - 000000000 ____D C:\Users\mckin\AppData\Local\MetaGeek,_LLC
2020-08-13 11:49 - 2020-08-13 11:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LatencyMon
2020-08-13 11:49 - 2020-08-13 11:49 - 000000000 ____D C:\Program Files\LatencyMon
2020-08-13 11:49 - 2015-07-13 11:16 - 000026368 _____ (Resplendence Software Projects Sp.) C:\WINDOWS\system32\Drivers\rspLLL64.sys
2020-08-13 11:06 - 2020-08-13 11:32 - 000137243 _____ C:\Users\mckin\OneDrive\Documents\DESKTOP-GLBDK8Q.txt
2020-08-13 10:58 - 2020-08-13 10:59 - 000000000 ____D C:\Program Files\Speccy
2020-08-13 10:58 - 2020-08-13 10:58 - 000000837 _____ C:\Users\Public\Desktop\Speccy.lnk
2020-08-13 10:58 - 2020-08-13 10:58 - 000000837 _____ C:\ProgramData\Desktop\Speccy.lnk
2020-08-13 10:58 - 2020-08-13 10:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2020-08-13 09:55 - 2020-08-13 09:55 - 000039372 _____ C:\junk.txt
2020-08-13 09:33 - 2020-08-13 09:33 - 000036408 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2020-08-12 17:44 - 2020-08-12 17:44 - 025903104 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 022642688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 019852288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 019812352 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 018032128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 014820352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 007758848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 007270912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 006526448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 006294528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 006074552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 005946368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 005904896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 005849872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 005767224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 005111296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 005013504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 005003824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 004859904 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 004611072 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 004129408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 003974376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 003822592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 003743056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 003637760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 003516416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002950808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002799104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-08-12 17:44 - 2020-08-12 17:44 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2020-08-12 17:44 - 2020-08-12 17:44 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2020-08-12 17:44 - 2020-08-12 17:44 - 002739200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directml.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002737664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002588688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 002583496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002576896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002422384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 002307584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002259192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 002138280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 002096128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 002022400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001870200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001740800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001697792 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001672544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001669344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001654312 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001610240 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001587712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001564160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001420320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001418832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001406464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001397576 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001282872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2020-08-12 17:44 - 2020-08-12 17:44 - 001215488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 001197056 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001151816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001101312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001077048 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 001015296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001012792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 001009664 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000995840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000914432 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000897648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000894032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000875520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000782336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000775480 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000738064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 000724480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000718336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000717312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000709120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000702976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BTAGService.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000692224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000690536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000675040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000675024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000673088 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000672256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000671744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaservc.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000671040 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000668672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000666280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 000649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000629760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000593480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000579584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000572200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000568128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000564488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StateRepository.Core.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000535040 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasgcw.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000525824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000495104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxbde40.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000467968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WalletService.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000431104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000405504 _____ (Microsoft Corporation) C:\WINDOWS\system32\DispBroker.Desktop.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000403456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprdim.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000379704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000359496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP4SDECD.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000343408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP4SDECD.DLL
2020-08-12 17:44 - 2020-08-12 17:44 - 000339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HrtfApo.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000338944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000330240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-08-12 17:44 - 2020-08-12 17:44 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000309248 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapisrv.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000273744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BCP47Langs.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapisrv.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmWmiPl.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shdocvw.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasplap.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scecli.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000211256 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasplap.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000194048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatializerApo.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000193592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\net1.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtm.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvcext.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrahc.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000165176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtm.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdrsvc.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAuto.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\net1.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Winlangdb.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000133256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BCP47mrm.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000124512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceUpdateAgent.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdSSDP.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\globinputhost.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000090936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000089328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdSSDP.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiarpc.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpkinstall.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManMigrationPlugin.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmRes.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguageProfileCallback.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnpcont.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afunix.sys
2020-08-12 17:44 - 2020-08-12 17:44 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\acwow64.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmprovhost.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnpcont.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryCore.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msisip.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Drivers\afunix.sys
2020-08-12 17:44 - 2020-08-12 17:44 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAgent.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msisip.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiatrace.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmplpxy.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtprio.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtprio.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000006144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
2020-08-12 17:44 - 2020-08-12 17:44 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2020-08-12 17:44 - 2020-08-12 17:44 - 000000357 _____ C:\WINDOWS\system32\DrtmAuthKeyDelegate_From_20190529_To_20200303.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000357 _____ C:\WINDOWS\system32\DrtmAuth1KeyDelegate.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-08-12 17:44 - 2020-08-12 17:44 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-08-12 17:43 - 2020-08-12 17:43 - 017792512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 009932088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 007915864 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 007850784 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 007604584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 007583272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 007297536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 007270728 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 006436864 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 005283776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 004625184 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 004565248 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 004227116 _____ C:\WINDOWS\system32\DefaultHrtfs.bin
2020-08-12 17:43 - 2020-08-12 17:43 - 004005376 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 003806208 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 003727872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 003712000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 003581240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 003368616 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 003141632 _____ (Microsoft Corporation) C:\WINDOWS\system32\directml.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 003084800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002986808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 002808832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002766952 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002717696 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 002698048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 002552120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002523136 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002471936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002289152 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002260312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002136064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 002085632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001942528 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001885184 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001756592 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-08-12 17:43 - 2020-08-12 17:43 - 001751040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001743680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001665024 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001660536 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001612800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001540096 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001512848 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 001482568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 001393960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001366144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-08-12 17:43 - 2020-08-12 17:43 - 001338368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001274128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryPS.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001182248 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 001182208 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 001127424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001123344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001072128 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001059328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001055232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 001008128 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000937984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000917800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000888352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000875424 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 000867840 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000865280 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000823744 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000822800 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000716312 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000661816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 000624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 000548352 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000534016 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000522688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2020-08-12 17:43 - 2020-08-12 17:43 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\system32\HrtfApo.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000463168 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000461112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000457016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000369304 _____ (Microsoft Corporation) C:\WINDOWS\system32\BCP47Langs.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageOverlayServer.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000335872 _____ (Microsoft Corporation) C:\WINDOWS\system32\RasMediaManager.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000314368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000302080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatializerApo.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000247856 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000220984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000209208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000201544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SIUF.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Winlangdb.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBAUDIO.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 000186472 _____ (Microsoft Corporation) C:\WINDOWS\system32\BCP47mrm.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000179512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2020-08-12 17:43 - 2020-08-12 17:43 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAuto.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000152416 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000132408 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\globinputhost.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000104248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManMigrationPlugin.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\keepaliveprovider.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmRes.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguageProfileCallback.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmprovhost.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2020-08-12 17:43 - 2020-08-12 17:43 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAgent.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\FaxPrinterInstaller.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbservicetrigger.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmplpxy.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2020-08-12 17:43 - 2020-08-12 17:43 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2020-08-12 17:36 - 2020-08-12 17:37 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-08-12 17:36 - 2020-08-12 17:37 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-07-20 13:08 - 2020-07-20 13:08 - 000913656 _____ C:\Users\mckin\OneDrive\Documents\IMG_20200720_0002.pdf
2020-07-20 12:58 - 2020-07-20 12:59 - 000246820 _____ C:\Users\mckin\OneDrive\Documents\IMG_20200720_0001.pdf
2020-07-18 20:05 - 2020-07-18 20:05 - 000104451 _____ C:\Users\mckin\OneDrive\Documents\FRST.txt
2020-07-18 10:16 - 2020-07-18 20:05 - 000046189 _____ C:\Users\mckin\OneDrive\Documents\Addition.txt
2020-07-18 09:59 - 2020-08-14 20:17 - 000000000 ____D C:\FRST
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-08-14 20:26 - 2018-08-31 09:22 - 000000512 _____ C:\Users\Public\amdsfhdcd.bin
2020-08-14 20:25 - 2019-01-04 12:09 - 000000000 ____D C:\Users\mckin\AppData\Local\DP_Tower_3.7
2020-08-14 20:22 - 2019-03-18 21:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-08-14 20:06 - 2019-01-03 13:40 - 000000000 ___RD C:\Users\mckin\OneDrive
2020-08-14 19:58 - 2019-06-21 15:57 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-08-14 16:00 - 2019-04-29 10:38 - 000000000 ____D C:\Users\mckin\AppData\Local\SquirrelTemp
2020-08-14 14:17 - 2019-06-21 16:05 - 000004166 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{82C98F3A-F861-4825-865D-F4A99D1C2801}
2020-08-14 12:55 - 2019-01-04 12:09 - 000000000 ____D C:\ProgramData\TMDP_Log
2020-08-14 12:38 - 2018-09-18 18:19 - 000000000 ____D C:\Users\mckin\AppData\Local\Packages
2020-08-14 12:36 - 2019-03-18 21:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-08-14 12:36 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-08-14 12:26 - 2019-01-03 13:58 - 000000000 ____D C:\Users\mckin\AppData\Local\ElevatedDiagnostics
2020-08-14 10:30 - 2019-06-21 16:06 - 000840852 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-08-14 10:30 - 2019-03-18 21:50 - 000000000 ____D C:\WINDOWS\INF
2020-08-14 10:28 - 2019-03-18 21:37 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-08-14 10:25 - 2019-06-21 16:05 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-08-14 10:25 - 2019-03-18 21:37 - 001310720 _____ C:\WINDOWS\system32\config\BBI
2020-08-14 10:18 - 2019-03-18 21:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-08-14 08:20 - 2019-06-21 16:05 - 000000000 ____D C:\WINDOWS\system32\Tasks\Samsung
2020-08-13 23:14 - 2020-02-13 09:10 - 000000000 ____D C:\ProgramData\CanonIJPLM
2020-08-13 15:38 - 2019-06-21 16:05 - 000004564 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2020-08-13 15:38 - 2019-03-18 21:56 - 000842296 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2020-08-13 15:38 - 2019-03-18 21:56 - 000175160 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2020-08-13 15:36 - 2020-07-14 11:36 - 004510264 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2020-08-13 15:36 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-08-13 15:36 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-08-13 08:21 - 2018-09-18 18:19 - 000000000 ___RD C:\Users\mckin\3D Objects
2020-08-13 08:21 - 2018-09-01 01:18 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-08-13 08:20 - 2019-09-13 12:07 - 000000000 ____D C:\Program Files (x86)\Microsoft OneDrive
2020-08-13 08:20 - 2019-06-21 15:57 - 000447536 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\SystemResources
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\system32\setup
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\Provisioning
2020-08-13 08:20 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-08-13 08:20 - 2019-03-18 21:37 - 000000000 ____D C:\WINDOWS\servicing
2020-08-12 21:00 - 2019-01-04 14:26 - 000000010 _____ C:\Users\mckin\AppData\Local\sponge.last.runtime.cache
2020-08-12 18:41 - 2020-06-23 21:17 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-08-12 18:41 - 2020-06-23 21:17 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2020-08-12 18:41 - 2020-06-23 21:17 - 000002276 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2020-08-12 12:29 - 2019-09-13 12:07 - 000003206 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2020-08-12 12:29 - 2019-09-13 12:07 - 000002174 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-08-11 12:47 - 2020-01-30 20:06 - 000000000 ____D C:\Users\mckin\AppData\Roaming\Messenger
2020-08-11 12:33 - 2019-01-04 11:46 - 000000000 ____D C:\ProgramData\Trend Micro
2020-08-11 12:29 - 2020-01-22 18:50 - 000000000 ____D C:\Users\mckin\AppData\Local\CrashDumps
2020-08-10 15:15 - 2019-01-03 20:26 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-08-08 18:31 - 2019-01-09 22:45 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2020-08-07 16:48 - 2018-04-11 16:38 - 000000359 _____ C:\WINDOWS\win.ini
2020-07-17 09:03 - 2020-07-05 11:30 - 000000000 ____D C:\Users\mckin\AppData\Roaming\discord
 
==================== Files in the root of some directories ========
 
2019-01-04 11:51 - 2020-01-22 11:27 - 000000036 _____ () C:\Users\mckin\AppData\Local\housecall.guid.cache
2019-01-04 14:26 - 2020-08-12 21:00 - 000000010 _____ () C:\Users\mckin\AppData\Local\sponge.last.runtime.cache
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================

  • 0

Advertisements


#17
mckinnik

mckinnik

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts
I am going back and re-reading all the information presented. There are items on the Latency Monitor results that I'm not sure of how to handle. For instance there is this
 
Your system seems to be having difficulty handling real-time audio and other tasks. You may experience drop outs, clicks or pops due to buffer underruns. One or more DPC routines that belong to a driver running in your system appear to be executing for too long. At least one detected problem appears to be network related. In case you are using a WLAN adapter, try disabling it to get better results. One problem may be related to power management, disable CPU throttling settings in Control Panel and BIOS setup. Check for BIOS updates. 
LatencyMon has been analyzing your system for  0:00:35  (h:mm:ss) on all processors.
 
And this
 
Note: reported execution times may be calculated based on a fixed reported CPU speed. Disable variable speed settings like Intel Speed Step and AMD Cool N Quiet in the BIOS setup for more accurate results.
 
WARNING: the CPU speed that was measured is only a fraction of the CPU speed reported. Your CPUs may be throttled back due to variable speed settings and thermal issues. It is suggested that you run a utility which reports your actual CPU frequency and temperature. 
 
 Unfortunately I have no idea how to do any of these things. Will you be helping me solve these issues or is this something I have to research and deal with myself?

  • 0

#18
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Please post the addition.txt file.  You posted the FRST.txt file twice.  The slowness may be caused by your anti-virus.  FRST looks at a lot of files and each time it does the anti-virus has to approve the file.  Probably run faster if you pause your anti-virus while doing a scan.

 

As for Latency Monitor:

 

The CPU statement appears to a be a bug in the program.  I see it a lot. 

But you can run Why So Slow to make sure:

 

WhySoSlow:

The Download is on

http://www.resplendence.com/downloads

Look under System Monitoring Tools for WhySoSlow 1.51  then click on


Download free home edition

Save the file then right click and Run As Admin.  Follow the prompts. Let it run for a minute (watch the Time Running indication at the bottom) then hit Stop

 

Should look like this.

wss.jpg

 

 

  What is your Average CPU Speed?

Is that more than Latency Monitor claimed?

 

Reported CPU speed:                                   1996 MHz

 

Are there any areas which do not have a green checkmark?

 

Now hit Analyze

Then when a new window appears hit Analyze again.  (The one on the top of the new window) Once the report appears scroll down and see if it complains about anything. 

You can also hit Save.  It will want to save it as WhySoSlowOutput.htm but the forum won't let you attach an htm file so change it to WhySoSlowOutput.txt before you save it then you can attach the file.

 

The DPC problem is real but probably needs a new BIOS update and I'm not sure there is one.  What is the make and model number of your PC?

 

Did you make the changes to Task Scheduler and run OOSU10.exe?  These help a lot with Hard Pagefaults.

 

I may know more after I see the latest Addition.txt file but I suspect you will need to force the Windows Update to 2004.

 

 


  • 0

#19
mckinnik

mckinnik

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts

Oh for crying out loud

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-08-2020
Ran by mckinnik (14-08-2020 20:27:08)
Running from C:\Users\mckin\OneDrive\Desktop
Windows 10 Home Version 1903 18362.1016 (X64) (2019-06-21 23:05:10)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3518604814-232533841-1677687598-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3518604814-232533841-1677687598-503 - Limited - Disabled)
Guest (S-1-5-21-3518604814-232533841-1677687598-501 - Limited - Disabled)
mckinnik (S-1-5-21-3518604814-232533841-1677687598-1002 - Administrator - Enabled) => C:\Users\mckin
WDAGUtilityAccount (S-1-5-21-3518604814-232533841-1677687598-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Trend Micro Internet Security (Enabled - Up to date) {AFEE279F-FAE7-BAEE-3A88-4BF7277B8551}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Trend Micro Internet Security (Enabled - Up to date) {90387C74-1C56-9484-893C-8ADCB2906C3D}
AS: Trend Micro Internet Security (Enabled - Up to date) {2B599D90-3A6C-9B0A-B38C-B1AEC9172680}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.414 - Adobe)
Amazon Kindle (HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\Amazon Kindle) (Version: 1.27.0.56109 - Amazon)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 17.7 - Advanced Micro Devices, Inc.)
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX2 (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX2) (Version: 2.0.5.3 - Canon Inc.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.00.1.51 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.4.0.16 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.2.0 - Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.6.4 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.6.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.8.5 - Canon Inc.)
Canon TS6100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_TS6100_series) (Version: 1.02 - Canon Inc.)
Canon TS6100 series On-screen Manual (HKLM-x32\...\Canon TS6100 series On-screen Manual) (Version: 1.1.0 - Canon Inc.)
ColorEngine (HKLM\...\{0B48E952-494A-408B-8D9D-5F3331F96659}) (Version: 5.0 - Samsung Electronics Co., Ltd.)
Consulting Mode Touchpad Driver (HKLM\...\ConsultingMode TPDriver) (Version: 20.0.0.24 - Samsung Electronics Co., Ltd.)
CyberLink Media Suite 15 (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 15.0 - CyberLink Corp.)
Discord (HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\Discord) (Version: 0.0.306 - Discord Inc.)
Facebook Gameroom 1.23.7426.18586 (HKLM-x32\...\{58E3FB73-8B88-4807-A803-79B5ADA0136F}) (Version: 1.23.7426.18586 - Facebook)
G-Force (HKLM-x32\...\G-Force) (Version: 5.8.3 - SoundSpectrum)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 84.0.4147.125 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Grammarly (HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\GrammarlyForWindows) (Version: 1.5.61 - Grammarly)
inSSIDer (HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\inSSIDer) (Version: 5.2.11 - MetaGeek, LLC)
LatencyMon 6.71 (HKLM\...\LatencyMon_is1) (Version:  - Resplendence Software Projects Sp.)
Media Player 10 (HKLM-x32\...\Media Player 10) (Version: 10.0.0 - CodeTechno)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.13029.20308 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 84.0.522.59 - Microsoft Corporation)
Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.133.5 - )
Microsoft OneDrive (HKLM-x32\...\OneDriveSetup.exe) (Version: 20.134.0705.0008 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.25.28508 (HKLM-x32\...\{6913e92a-b64e-41c9-a5e6-cef39207fe89}) (Version: 14.25.28508.3 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.25.28508 (HKLM-x32\...\{65e650ff-30be-469d-b63a-418d71ea1765}) (Version: 14.25.28508.3 - Microsoft Corporation)
ODD Auto Firmware Update (HKLM-x32\...\{3DD8DB1B-20D0-447C-940A-1306B3931FED}) (Version: 1.0.1807.2501 - Hitachi-LG Data Storage, Inc.)
OEM Application Profile (HKLM-x32\...\{C6D87295-79C5-FB7D-04F1-41EC66F05409}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.13029.20200 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.13029.20200 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.13029.20308 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.13029.20200 - Microsoft Corporation) Hidden
Online Support(S Service) Agent (HKLM\...\{11F387C2-0BE2-489A-A9C1-8FB1FEE475B9}) (Version: 2.2.1 - Samsung Electronics Co., Ltd.)
Printer Registration (HKLM-x32\...\Canon EISRegistration) (Version: 1.5.0 - Canon Inc.)
Qualcomm Atheros 11ac Wireless LAN Installer (HKLM-x32\...\{20CA507E-24AA-4741-87CF-CC1B250790B7}) (Version: 11.0.10487 - Qualcomm)
Qualcomm Atheros Bluetooth Installer (64) (HKLM\...\{628988B4-3FA5-4EA6-BAA3-DA640F6718BD}) (Version: 10.0.0.825 - Qualcomm Atheros)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8673 - Realtek Semiconductor Corp.)
Realtek USB Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{04201224-2B34-4EE7-862B-B7BBF89DB3AB}) (Version: 10.24.326.2018 - Realtek)
Samsung Consulting Mode FN Key Driver (HKLM-x32\...\{3A1164B8-D634-48C2-A638-7EC4F0CC1B73}) (Version: 1.1.31 - Samsung Electronics Co., Ltd.)
Samsung DPI Configuration (HKLM-x32\...\{5370467A-26B3-44BF-B7C5-97687E77B520}) (Version: 1.0 - Samsung Electronics Co., Ltd.)
Samsung PC Cleaner 2 Service (HKLM\...\{EF853EE0-71B9-4487-AB5A-F8ADE89E6E37}) (Version: 2.0.18 - Samsung Electronics Co., Ltd.)
Samsung Recovery Service (HKLM\...\{A942FE64-54BE-4787-A336-C0674F50A118}) (Version: 8.0.31 - Samsung Electronics Co., Ltd.)
Samsung S Service Notification (HKLM\...\{DA145588-7B19-43DD-BC08-90E7E6F60CF2}) (Version: 1.0.3 - Samsung Electronics Co., Ltd.)
Samsung Security (HKLM-x32\...\{4466950A-EE3E-47FD-A7BA-53E0DE343C38}) (Version: 1.00.40 - Samsung Electronics Co., Ltd.)
Samsung Settings Expansion Pack (HKLM\...\{AD77583A-D644-4058-9132-C0D9CA524460}) (Version: 1.0.49 - Samsung Electronics Co., Ltd.)
Samsung Update Service (HKLM\...\{04EC561D-6EC8-457F-B200-3820228179DF}) (Version: 3.0.51 - Samsung Electronics Co., Ltd.)
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
Synamedia VideoGuard Player (HKLM-x32\...\{c04440a1-d5cb-4d2e-9a36-c3b8266b3f7c}) (Version: 13.0 - Synamedia)
Trend Micro Internet Security (HKLM\...\{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}) (Version: 16.0 - Trend Micro Inc.)
Trend Micro Password Manager (HKLM\...\3A0FB4E3-2C0D-4572-A24D-67F1CAABDDP35_is1) (Version: 5.0.0.1134 - Trend Micro Inc.)
Trend Micro Troubleshooting Tool (HKLM\...\{4B83469E-CE4F-45D0-BC34-CCB7BF194477}) (Version: 6.0 - Trend Micro Inc.)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
User Manual (HKLM-x32\...\{815B858E-ED12-495C-B603-37129A7C5832}) (Version: 1.1.00 - Samsung Electronics Co., Ltd.)
Voice Note (HKLM\...\{4BB006D8-F513-4184-956D-1DC334D580A9}) (Version: 1.0.12 - Samsung Electronics Co., Ltd.)
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0-2) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
Wi-Fi Camera (HKLM\...\{EF3E6EB4-DCD9-4EBC-9889-17AF4DDB0A50}) (Version: 1.0 - Samsung Electronics Co., Ltd)
Windows Driver Package - CanvasBio (WUDFRd) Biometric  (04/09/2019 2.1.36.882) (HKLM\...\1658B0FBC6E68B43B8BC17E4C4A550D54DEEFA31) (Version: 04/09/2019 2.1.36.882 - CanvasBio)
Zoom (HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\ZoomUMX) (Version: 5.0 - Zoom Video Communications, Inc.)
 
Packages:
=========
Amazon -> C:\Program Files\WindowsApps\Amazon.com.Amazon_2018.519.2815.0_x64__343d40qqvtj1t [2020-02-19] (Amazon.com)
Amazon Music -> C:\Program Files\WindowsApps\AmazonMobileLLC.AmazonMusic_7.12.0.0_x86__kc6t79cpj4tp0 [2020-06-12] (AMZN Mobile LLC)
Community Showcase Dramatic Skies -> C:\Program Files\WindowsApps\Microsoft.CommunityShowcaseDramaticSkies_1.0.0.0_neutral__8wekyb3d8bbwe [2019-06-22] (Microsoft Corporation)
Cosmic Beauty -> C:\Program Files\WindowsApps\Microsoft.CosmicBeauty_1.0.0.0_neutral__8wekyb3d8bbwe [2019-02-18] (Microsoft Corporation)
Emoji Stickers HD -> C:\Program Files\WindowsApps\22227CandleLight.EmojiStickersHD_1.1.0.1_x86__4f4e294qr27gg [2020-04-26] (ClipinApps) [MS Ad]
Facebook -> C:\Program Files\WindowsApps\Facebook.Facebook_186.2619.19263.0_x86__8xx8rvfyw5nnt [2019-11-12] (Facebook Inc)
Fitbit Coach -> C:\Program Files\WindowsApps\Fitbit.FitbitCoach_4.4.133.0_x64__6mqt6hf9g46tw [2019-01-03] (Fitbit)
Hulu -> C:\Program Files\WindowsApps\HuluLLC.HuluPlus_2.5.5.0_neutral__fphbd361v8tya [2019-11-22] (Hulu.)
Hummingbirds by Desiree Skatvold -> C:\Program Files\WindowsApps\Microsoft.HummingbirdsbyDesireeSkatvold_1.0.0.0_neutral__8wekyb3d8bbwe [2020-02-04] (Microsoft Corporation)
Instagram -> C:\Program Files\WindowsApps\Facebook.InstagramBeta_42.0.2.0_neutral__8xx8rvfyw5nnt [2020-03-04] (Instagram)
Link Sharing -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.1412377A9806A_1.1.39.0_x64__3c1yjt4zspk6g [2020-06-12] (Samsung Electronics Co. Ltd.)
LinkedIn -> C:\Program Files\WindowsApps\7EE7776C.LinkedInforWindows_2.1.7098.0_neutral__w1wdnht996qgy [2019-01-03] (LinkedIn)
Little Artist -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.LittleArtist_1.1.13.0_neutral__3c1yjt4zspk6g [2018-08-31] (Samsung Electronics Co. Ltd.)
Messenger -> C:\Program Files\WindowsApps\FACEBOOK.317180B0BB486_620.8.119.0_x64__8xx8rvfyw5nnt [2020-08-05] (Facebook Inc) [Startup Task]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-09] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-09] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.8042.0_x64__8wekyb3d8bbwe [2020-08-07] (Microsoft Studios) [MS Ad]
MPEG-2 Video Extension -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.22661.0_x64__8wekyb3d8bbwe [2019-09-30] (Microsoft Corporation)
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.97.752.0_x64__mcm4njqhnhss8 [2020-07-16] (Netflix, Inc.)
Online Support(S Service) -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.OnlineSupportSService_2.4.32.0_x64__3c1yjt4zspk6g [2019-11-27] (Samsung Electronics Co. Ltd.)
Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2019-06-22] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-12-08] (Microsoft Corporation)
Phototastic Collage -> C:\Program Files\WindowsApps\ThumbmunkeysLtd.PhototasticCollage_3.20.1.0_x64__nfy108tqq3p12 [2020-07-25] (Thumbmunkeys Ltd)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.9.205.0_x64__dt26b99r8h8gj [2020-01-11] (Realtek Semiconductor Corp)
Samsung Gallery -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.PCGallery_4.1.27.0_x64__3c1yjt4zspk6g [2020-07-14] (Samsung Electronics Co. Ltd.)
Samsung Notes -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCoLtd.SamsungNotes_3.10.382.0_x64__wyx1vj98g3asy [2020-07-01] (Samsung Electronics Co, Ltd.)
Samsung PC Cleaner -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SamsungPCCleaner_2.0.18.0_x64__3c1yjt4zspk6g [2020-06-16] (Samsung Electronics Co. Ltd.)
Samsung Recovery -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SamsungRecovery_8.1.25.0_x64__3c1yjt4zspk6g [2020-07-07] (Samsung Electronics Co. Ltd.)
Samsung Settings -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SamsungSettings_1.0.49.0_x64__3c1yjt4zspk6g [2020-07-16] (Samsung Electronics Co. Ltd.)
Samsung Update -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SamsungUpdate_3.0.55.0_x64__3c1yjt4zspk6g [2020-08-05] (Samsung Electronics Co. Ltd.)
smiling creatures -> C:\Program Files\WindowsApps\Microsoft.smilingcreatures_1.0.0.0_neutral__8wekyb3d8bbwe [2019-11-29] (Microsoft Corporation)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.139.612.0_x86__zpdnekdrzrea0 [2020-08-11] (Spotify AB) [Startup Task]
Studio Plus -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.StudioPlus_3.2.3.0_x64__3c1yjt4zspk6g [2020-06-02] (Samsung Electronics Co. Ltd.)
teamPL -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.873506AC0B4C_2.1.7.0_x64__3c1yjt4zspk6g [2020-06-20] (Samsung Electronics Co. Ltd.)
The Butterfly -> C:\Program Files\WindowsApps\Microsoft.TheButterfly_1.0.0.0_neutral__8wekyb3d8bbwe [2019-02-17] (Microsoft Corporation)
TuneIn Radio -> C:\Program Files\WindowsApps\TuneIn.TuneInRadio_4.0.7.0_x64__6bhtb546zcxnj [2020-07-09] (TuneIn) [MS Ad]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2019-02-27] (Twitter Inc.)
Wi-Fi Transfer -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.Wi-FiTransfer_2.0.26.0_x64__3c1yjt4zspk6g [2019-01-03] (Samsung Electronics Co. Ltd.)
WildTangent Games -> C:\Program Files\WindowsApps\WildTangentGames.63435CFB65F55_2.0.82.0_x64__qt5r5pa5dyg8m [2019-12-22] (WildTangent Games)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3518604814-232533841-1677687598-1002_Classes\CLSID\{e0d836c8-9ae5-4c36-b2ee-4bab5c2a6637}\localserver32 -> C:\Program Files\Samsung\SServiceNotification\SServiceToast.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
ShellIconOverlayIdentifiers: [       OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [       OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [       OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [       OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [       OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [       OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [       OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [      FSOverlayIcon] -> {C0829D19-E5A0-44F5-B56E-D15030C53BB9} => C:\Program Files\Trend Micro\Titanium\plugin\TmOverlayIcon.dll [2019-07-29] (Trend Micro, Inc. -> Trend Micro Inc.)
ShellIconOverlayIdentifiers: [    FSOverlayIcon] -> {C0829D19-E5A0-44F5-B56E-D15030C53BB9} => C:\Program Files\Trend Micro\Titanium\plugin\TmOverlayIcon.dll [2019-07-29] (Trend Micro, Inc. -> Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2018-07-04] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers1: [{48F45200-91E6-11CE-8A4F-0080C81A28D4}] -> {48F45200-91E6-11CE-8A4F-0080C81A28D4} => C:\Program Files\Trend Micro\UniClient\UiFrmwrk\tmdshell.dll [2019-07-29] (Trend Micro, Inc. -> Trend Micro Inc.)
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2018-07-04] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files (x86)\Microsoft OneDrive\20.134.0705.0008\amd64\FileSyncShell64.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2018-10-26] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [{48F45200-91E6-11CE-8A4F-0080C81A28D4}] -> {48F45200-91E6-11CE-8A4F-0080C81A28D4} => C:\Program Files\Trend Micro\UniClient\UiFrmwrk\tmdshell.dll [2019-07-29] (Trend Micro, Inc. -> Trend Micro Inc.)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
==================== Loaded Modules (Whitelisted) =============
 
2018-04-24 22:09 - 2018-04-24 22:09 - 000015360 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\libEGL.DLL
2018-04-24 22:09 - 2018-04-24 22:09 - 002519040 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2019-01-04 12:09 - 2017-01-26 12:35 - 001078272 _____ () [File not signed] C:\Program Files\Trend Micro\TMIDS\tower\ffmpeg.dll
2019-01-04 12:09 - 2017-02-23 01:31 - 000079872 _____ () [File not signed] C:\Program Files\Trend Micro\TMIDS\tower\libegl.dll
2019-01-04 12:09 - 2017-02-23 01:31 - 001922560 _____ () [File not signed] C:\Program Files\Trend Micro\TMIDS\tower\libglesv2.dll
2019-01-04 12:09 - 2017-02-23 01:31 - 004834816 _____ () [File not signed] C:\Program Files\Trend Micro\TMIDS\tower\node.dll
2020-02-13 09:23 - 2016-10-21 16:06 - 000318976 _____ (CANON INC) [File not signed] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\scchmpm.dll
2020-02-13 09:23 - 2016-12-01 09:23 - 000219648 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\cnmpu2.dll
2020-02-13 09:23 - 2016-12-09 11:09 - 000008192 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNS2_ENU.DLL
2020-02-13 09:23 - 2016-12-09 11:09 - 000104960 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNS2_IMG.dll
2020-02-13 09:27 - 2017-07-05 13:43 - 000561152 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\Quick Menu\CCL.dll
2020-02-13 09:27 - 2017-07-05 13:49 - 000593920 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\Quick Menu\CNQMMWRP.dll
2018-02-02 14:52 - 2018-02-02 14:52 - 001809920 _____ (SAMSUNG Electronics CO., LTD.) [File not signed] C:\Program Files (x86)\Samsung\SamsungSecurity\CmdServer\HookDllUSB.DLL
2019-01-04 12:09 - 2017-02-23 01:31 - 068185600 _____ (The NWJS Community) [File not signed] C:\Program Files\Trend Micro\TMIDS\tower\nw.dll
2019-01-04 12:09 - 2017-02-23 01:31 - 000421888 _____ (The NWJS Community) [File not signed] C:\Program Files\Trend Micro\TMIDS\tower\nw_elf.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000032256 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qgif.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000039936 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qicns.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000034304 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qico.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000237056 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qjpeg.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000025600 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qsvg.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000025600 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qtga.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000024064 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qwbmp.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000481792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qwebp.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 001336320 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\platforms\qwindows.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 001136128 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Charts.dll
2018-10-26 16:46 - 2018-10-26 16:46 - 005766144 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Core.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 006045184 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Gui.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000964096 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Network.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 003233792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Qml.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 003406848 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Quick.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000328704 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Svg.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 005523456 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Widgets.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000282624 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WinExtras.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000194560 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Xml.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000049152 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000018432 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\qtgraphicaleffectsplugin.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000018432 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000311296 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000139264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000089600 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2018-04-24 22:09 - 2018-04-24 22:09 - 000018432 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\mckin\Downloads\driveralert2-setup-0008 (1).exe:SmartScreen [7]
AlternateDataStreams: C:\Users\mckin\Downloads\driveralert2-setup-0008.exe:SmartScreen [7]
 
==================== Safe Mode (Whitelisted) ==================
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer trusted/restricted ==========
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\.DEFAULT\...\trendmicro.com -> hxxps://pwm.trendmicro.com
IE trusted site: HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\trendmicro.com -> hxxps://pwm.trendmicro.com
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2018-04-11 16:38 - 2018-04-11 16:36 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
2019-05-14 12:06 - 2019-11-03 18:44 - 000000445 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\mckin\OneDrive\Desktop\Karen Phone July 2020\Resized_20200625_065403_5446.jpeg
DNS Servers: 68.105.28.11 - 68.105.29.11
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
HKLM\...\StartupApproved\Run32: => "Discord"
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\StartupApproved\StartupFolder: => "Facebook Gameroom.lnk"
HKU\S-1-5-21-3518604814-232533841-1677687598-1002\...\StartupApproved\Run: => "Discord"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [UDP Query User{6554C876-B991-4972-92CB-BE84312CBDF1}C:\program files\windowsapps\samsungelectronicsco.ltd.873506ac0b4c_2.1.3.0_x64__3c1yjt4zspk6g\teamplapp\teamplapp.exe] => (Block) C:\program files\windowsapps\samsungelectronicsco.ltd.873506ac0b4c_2.1.3.0_x64__3c1yjt4zspk6g\teamplapp\teamplapp.exe => No File
FirewallRules: [TCP Query User{7FE50A23-3902-44B4-A378-DC24CDB5DE49}C:\program files\windowsapps\samsungelectronicsco.ltd.873506ac0b4c_2.1.3.0_x64__3c1yjt4zspk6g\teamplapp\teamplapp.exe] => (Block) C:\program files\windowsapps\samsungelectronicsco.ltd.873506ac0b4c_2.1.3.0_x64__3c1yjt4zspk6g\teamplapp\teamplapp.exe => No File
FirewallRules: [{96B7C538-2A89-40E4-82C6-29A28CAD1EFA}] => (Allow) C:\MfgDiag\DiagTools\DiagResultCheck\AMTMonitor.exe => No File
FirewallRules: [{E9AD6484-ADD3-4B9E-9939-664FDFED3022}] => (Allow) C:\MfgDiag\DiagTools\DiagResultCheck\AMTMonitor.exe => No File
FirewallRules: [{2259945C-C8D9-435C-865C-F564AF75F1E0}] => (Allow) C:\Program Files\Samsung\WiFiCamera\WiFiCameraAgent.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd)
FirewallRules: [{D28751EF-EFB6-4877-8D1D-9A45213D5875}] => (Allow) C:\Program Files\Samsung\WiFiCamera\WiFiCameraAgent.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd)
FirewallRules: [{CCD88D4A-48B3-478B-88BB-675876766AA4}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe => No File
FirewallRules: [{44771117-3684-48CC-B5CB-2C2F0ED4C124}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe => No File
FirewallRules: [{4DF42555-3310-4005-A07D-9352DC8DC2EC}] => (Allow) C:\Users\mckin\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{7F77F24A-AC53-439D-9179-B4EF8C447CF6}] => (Allow) C:\Users\mckin\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{BE4647DA-D70B-4342-9559-E2469DB80B26}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{D70B709A-226F-48EB-B1D9-F99131CA6A48}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\Kernel\DMS\CLMSServerPDVD14.exe => No File
FirewallRules: [{96FCF8A9-5AC5-4447-8FCC-894F88BFA180}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe => No File
FirewallRules: [{5CB7B2F8-49A7-4F62-880F-60A85266433C}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\Movie\PowerDVDMovie.exe => No File
FirewallRules: [{ABD00314-CE64-4271-8A8D-2234BD9E5C76}] => (Allow) C:\Program Files\WindowsApps\AmazonMobileLLC.AmazonMusic_7.12.0.0_x86__kc6t79cpj4tp0\Amazon Music Helper.exe (Amazon.com Services LLC) [File not signed]
FirewallRules: [{46150459-005A-4BD1-B4EE-2B3EFC0A11A8}] => (Allow) C:\Program Files\WindowsApps\AmazonMobileLLC.AmazonMusic_7.12.0.0_x86__kc6t79cpj4tp0\Amazon Music Helper.exe (Amazon.com Services LLC) [File not signed]
FirewallRules: [{980B5B8A-2D04-4135-9D93-25EB52F8C387}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{F1264B28-07AD-45CD-A752-8341E00F644D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{DC2775E1-8968-4CA5-AEB8-180C74609C9C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{614FE976-B5C0-406E-9D78-5068D5712C49}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{98F67040-6880-4B2F-9C6B-CF0EFA510C3B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C4DE78B1-6A6A-4040-97C9-A1A000D7C3F2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{D985005C-D4E3-4BB3-AD29-2D38FBE7DE78}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.139.612.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{739E5CCD-007E-4C88-9E99-9C2E6BE7D9CF}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.139.612.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{29D41C9B-6173-423D-B5F0-CB9419EE6A80}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.139.612.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{48E87ED8-C7BF-498A-9071-2F2495098C7E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.139.612.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{345E8F31-E1E7-4B67-8F18-C48231C53360}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.139.612.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{DF216396-DF11-4CA5-8D20-1B2666CD9F09}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.139.612.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{04C9B525-A05E-47D8-B5EB-FC238EDD46B6}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.139.612.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{16A5808F-3913-4F17-9382-1250A81B06AC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.139.612.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
 
==================== Restore Points =========================
 
25-07-2020 09:14:40 Scheduled Checkpoint
07-08-2020 11:19:05 Scheduled Checkpoint
11-08-2020 12:36:37 PCCleaner2_Init
14-08-2020 12:49:13 Installed inSSIDer Home
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (08/14/2020 08:04:52 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program FRST64.exe version 12.8.2020.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 3ef4
 
Start Time: 01d6729e892f8a2a
 
Termination Time: 4294967295
 
Application Path: C:\Users\mckin\OneDrive\Desktop\FRST64.exe
 
Report Id: ea9bc76d-1be7-45bd-929f-254a2b056e5c
 
Faulting package full name: 
 
Faulting package-relative application ID: 
 
Hang type: Top level window is idle
 
Error: (08/14/2020 07:38:29 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-GLBDK8Q$ via https://AMD-KeyId-ce...plates/Aik/scepfailed:
 
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-ce3052d29862d1a5303f14651f30a48d414586ae.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Cache-Control: private
Date: Sat, 15 Aug 2020 02:38:29 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: f0903d18-21e5-413a-80c1-15a5ae363a9f
 
Method: GET(578ms)
Stage: GetCACaps
Not found (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
 
Error: (08/14/2020 10:28:33 AM) (Source: Outlook) (EventID: 35) (User: )
Description: Failed to determine if the store is in the crawl scope (error=0x80040150).
 
Error: (08/14/2020 10:28:33 AM) (Source: Outlook) (EventID: 34) (User: )
Description: Failed to get the Crawl Scope Manager with error=0x80040150.
 
Error: (08/14/2020 10:26:08 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-GLBDK8Q$ via https://AMD-KeyId-ce...plates/Aik/scepfailed:
 
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-ce3052d29862d1a5303f14651f30a48d414586ae.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Cache-Control: private
Date: Fri, 14 Aug 2020 17:26:08 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 51b26585-111e-41d9-bcba-7d72be65a1c2
 
Method: GET(1625ms)
Stage: GetCACaps
Not found (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
 
 
System errors:
=============
Error: (08/14/2020 11:42:49 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GLBDK8Q)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.
 
Error: (08/14/2020 10:42:49 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GLBDK8Q)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.
 
Error: (08/14/2020 09:42:12 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GLBDK8Q)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.
 
Error: (08/14/2020 08:43:01 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GLBDK8Q)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.
 
Error: (08/14/2020 08:06:03 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GLBDK8Q)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.
 
Error: (08/14/2020 07:42:58 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GLBDK8Q)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.
 
Error: (08/14/2020 06:42:58 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GLBDK8Q)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.
 
Error: (08/14/2020 05:42:59 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GLBDK8Q)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.
 
 
CodeIntegrity:
===================================
 
Date: 2020-08-14 22:36:43.354
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\TmAMSI\TmAMSIProvider64.dll that did not meet the Windows signing level requirements.
 
Date: 2020-08-14 20:06:03.433
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Trend Micro\Titanium\TmWscSvc\WSCHandler.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2020-08-14 20:06:03.414
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Trend Micro\Titanium\TmWscSvc\WSCHandler.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2020-08-14 20:06:03.395
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\TmAMSI\TmAMSIProvider64.dll that did not meet the Windows signing level requirements.
 
Date: 2020-08-14 19:36:39.869
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\TmAMSI\TmAMSIProvider64.dll that did not meet the Windows signing level requirements.
 
Date: 2020-08-14 17:41:58.125
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Trend Micro\Titanium\TmWscSvc\WSCHandler.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2020-08-14 17:41:58.108
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Trend Micro\Titanium\TmWscSvc\WSCHandler.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2020-08-14 17:41:58.079
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\TmAMSI\TmAMSIProvider64.dll that did not meet the Windows signing level requirements.
 
==================== Memory info =========================== 
 
BIOS: American Megatrends Inc. P03AGV.032.180928.MK 09/28/2018
Motherboard: SAMSUNG ELECTRONICS CO., LTD. NP750QUA-K01US
Processor: AMD Ryzen 5 2500U with Radeon Vega Mobile Gfx 
Percentage of memory in use: 58%
Total physical RAM: 7124.73 MB
Available physical RAM: 2971.75 MB
Total Virtual: 13524.73 MB
Available Virtual: 7793.14 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:104.98 GB) (Free:48.58 GB) NTFS
 
\\?\Volume{cd002f0c-53e1-465f-a508-a28de4924fcf}\ (Windows RE tools) (Fixed) (Total:0.83 GB) (Free:0.44 GB) NTFS
\\?\Volume{6216a8e1-49cb-4111-931f-58d4be76e3f6}\ (SAMSUNG_REC2) (Fixed) (Total:12.16 GB) (Free:1.71 GB) NTFS
\\?\Volume{061a3a5f-c789-49ed-4173-636c65706975}\ (SAMSUNG_REC) (Fixed) (Total:1 GB) (Free:0.45 GB) FAT32
\\?\Volume{e95332c2-2ab8-4ca3-acb3-1e52a5db9457}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.21 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: 26EA9241)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

  • 0

#20
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

It said FRST crashed during the scan so that may explain the long time.

 

I would try to force the Windows Update per the instructions at the bottom of my previous post

http://www.geekstogo...e/#entry2652045

 

This will take several hours and you won't be able to use the PC during that time.


  • 0

#21
mckinnik

mckinnik

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts
Steps I have taken
 
1. Concerning Latency Monitor results
 
_________________________________________________________________________________________________________
CONCLUSION
_________________________________________________________________________________________________________
Your system seems to be having difficulty handling real-time audio and other tasks. You may experience drop outs, clicks or pops due to buffer underruns. One or more DPC routines that belong to a driver running in your system appear to be executing for too long. At least one detected problem appears to be network related. In case you are using a WLAN adapter, try disabling it to get better results. One problem may be related to power management, disable CPU throttling settings in Control Panel and BIOS setup. Check for BIOS updates. 
LatencyMon has been analyzing your system for  0:00:35  (h:mm:ss) on all processors.
 
I have changed my power settings to balanced which has disabled power throttling. So far I have NOT gone into BIOS and attempted to change anything. If this step is necessary I will have to research how to do that. I will be waiting for further advice from you on this
 
2. I did force the Window 10 update and I did turn system restore BACK on. I have no idea how that was disabled.
 
3.Concerning the router issue. I downloaded inssider and saw the two signals. The router is provided by Cox who is our internet provider. I researched how to access our router information online and saw three signals there. 2CA4E, 2CA45F, and one that is our Direct TV.  Four phones, three smart tvs and this laptop were connected to 2CA4E along with Direct TV.  This probably explains the constant buffering and bad signal notices I was getting while watching youtube on Roku tv and dropped Zoom meetings on my phone. I moved two phones and my computer to 2CA45F (channel 48). The other phones belong to roommates and I'll have them move if they complain of buffering. inSSIDer is reporting that I'm running WPA instead of WPA2 but then it shows that I have WPA2. I'm including screenshots for you.
 
4. I ran the fix for CompattelRunner and completed all the tasks.
 
. I am happy to report that since I completed the tasks above things have really improved on my computer, phones and tv streaming.  So far so good.
 

Attached Thumbnails

  • 2020-08-16.png
  • 2020-08-16 (1).png
  • 2020-08-16 (2).png
  • 2020-08-16 (3).png

  • 0

#22
mckinnik

mckinnik

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts

Latency 8162020.jpg Here is the latest Latency Monitor summary and screen shot 

 

 

_________________________________________________________________________________________________________
CONCLUSION
_________________________________________________________________________________________________________
Your system seems to be having difficulty handling real-time audio and other tasks. You may experience drop outs, clicks or pops due to buffer underruns. One or more DPC routines that belong to a driver running in your system appear to be executing for too long. At least one detected problem appears to be network related. In case you are using a WLAN adapter, try disabling it to get better results. One problem may be related to power management, disable CPU throttling settings in Control Panel and BIOS setup. Check for BIOS updates. 
LatencyMon has been analyzing your system for  0:00:21  (h:mm:ss) on all processors.
 
 
_________________________________________________________________________________________________________
SYSTEM INFORMATION
_________________________________________________________________________________________________________
Computer name:                                        DESKTOP-GLBDK8Q
OS version:                                           Windows 10 , 10.0, build: 19041 (x64)
Hardware:                                             750QUA, SAMSUNG ELECTRONICS CO., LTD., NP750QUA-K01US
CPU:                                                  AuthenticAMD AMD Ryzen 5 2500U with Radeon Vega Mobile Gfx 
Logical processors:                                   8
Processor groups:                                     1
RAM:                                                  7124 MB total
 
 
_________________________________________________________________________________________________________
CPU SPEED
_________________________________________________________________________________________________________
Reported CPU speed:                                   1996 MHz
 
Note: reported execution times may be calculated based on a fixed reported CPU speed. Disable variable speed settings like Intel Speed Step and AMD Cool N Quiet in the BIOS setup for more accurate results.
 
WARNING: the CPU speed that was measured is only a fraction of the CPU speed reported. Your CPUs may be throttled back due to variable speed settings and thermal issues. It is suggested that you run a utility which reports your actual CPU frequency and temperature. 
 
 
 
_________________________________________________________________________________________________________
MEASURED INTERRUPT TO USER PROCESS LATENCIES
_________________________________________________________________________________________________________
The interrupt to process latency reflects the measured interval that a usermode process needed to respond to a hardware request from the moment the interrupt service routine started execution. This includes the scheduling and execution of a DPC routine, the signaling of an event and the waking up of a usermode thread from an idle wait state in response to that event.
 
Highest measured interrupt to process latency (µs):   493.0
Average measured interrupt to process latency (µs):   8.955346
 
Highest measured interrupt to DPC latency (µs):       486.60
Average measured interrupt to DPC latency (µs):       3.133019
 
 
_________________________________________________________________________________________________________
 REPORTED ISRs
_________________________________________________________________________________________________________
Interrupt service routines are routines installed by the OS and device drivers that execute in response to a hardware interrupt signal.
 
Highest ISR routine execution time (µs):              67.665331
Driver with highest ISR routine execution time:       ACPI.sys - ACPI Driver for NT, Microsoft Corporation
 
Highest reported total ISR routine time (%):          0.002098
Driver with highest ISR total time:                   ACPI.sys - ACPI Driver for NT, Microsoft Corporation
 
Total time spent in ISRs (%)                          0.002737
 
ISR count (execution time <250 µs):                   325
ISR count (execution time 250-500 µs):                0
ISR count (execution time 500-999 µs):                0
ISR count (execution time 1000-1999 µs):              0
ISR count (execution time 2000-3999 µs):              0
ISR count (execution time >=4000 µs):                 0
 
 
_________________________________________________________________________________________________________
REPORTED DPCs
_________________________________________________________________________________________________________
DPC routines are part of the interrupt servicing dispatch mechanism and disable the possibility for a process to utilize the CPU while it is interrupted until the DPC has finished execution.
 
Highest DPC routine execution time (µs):              1185.731463
Driver with highest DPC routine execution time:       ACPI.sys - ACPI Driver for NT, Microsoft Corporation
 
Highest reported total DPC routine time (%):          0.012970
Driver with highest DPC total execution time:         ndis.sys - Network Driver Interface Specification (NDIS), Microsoft Corporation
 
Total time spent in DPCs (%)                          0.040597
 
DPC count (execution time <250 µs):                   4046
DPC count (execution time 250-500 µs):                0
DPC count (execution time 500-999 µs):                8
DPC count (execution time 1000-1999 µs):              4
DPC count (execution time 2000-3999 µs):              0
DPC count (execution time >=4000 µs):                 0
 
 
_________________________________________________________________________________________________________
 REPORTED HARD PAGEFAULTS
_________________________________________________________________________________________________________
Hard pagefaults are events that get triggered by making use of virtual memory that is not resident in RAM but backed by a memory mapped file on disk. The process of resolving the hard pagefault requires reading in the memory from disk while the process is interrupted and blocked from execution.
 
NOTE: some processes were hit by hard pagefaults. If these were programs producing audio, they are likely to interrupt the audio stream resulting in dropouts, clicks and pops. Check the Processes tab to see which programs were hit.
 
Process with highest pagefault count:                 coreserviceshell.exe
 
Total number of hard pagefaults                       22
Hard pagefault count of hardest hit process:          22
Number of processes hit:                              1
 
 
_________________________________________________________________________________________________________
 PER CPU DATA
_________________________________________________________________________________________________________
CPU 0 Interrupt cycle time (s):                       0.301526
CPU 0 ISR highest execution time (µs):                67.665331
CPU 0 ISR total execution time (s):                   0.004515
CPU 0 ISR count:                                      271
CPU 0 DPC highest execution time (µs):                1185.731463
CPU 0 DPC total execution time (s):                   0.057102
CPU 0 DPC count:                                      3204
_________________________________________________________________________________________________________
CPU 1 Interrupt cycle time (s):                       0.045479
CPU 1 ISR highest execution time (µs):                0.0
CPU 1 ISR total execution time (s):                   0.0
CPU 1 ISR count:                                      0
CPU 1 DPC highest execution time (µs):                43.907816
CPU 1 DPC total execution time (s):                   0.000701
CPU 1 DPC count:                                      94
_________________________________________________________________________________________________________
CPU 2 Interrupt cycle time (s):                       0.053178
CPU 2 ISR highest execution time (µs):                1.773547
CPU 2 ISR total execution time (s):                   0.000004
CPU 2 ISR count:                                      3
CPU 2 DPC highest execution time (µs):                63.356713
CPU 2 DPC total execution time (s):                   0.002151
CPU 2 DPC count:                                      186
_________________________________________________________________________________________________________
CPU 3 Interrupt cycle time (s):                       0.066933
CPU 3 ISR highest execution time (µs):                1.382766
CPU 3 ISR total execution time (s):                   0.000002
CPU 3 ISR count:                                      2
CPU 3 DPC highest execution time (µs):                53.416834
CPU 3 DPC total execution time (s):                   0.002429
CPU 3 DPC count:                                      162
_________________________________________________________________________________________________________
CPU 4 Interrupt cycle time (s):                       0.052110
CPU 4 ISR highest execution time (µs):                3.096192
CPU 4 ISR total execution time (s):                   0.000005
CPU 4 ISR count:                                      3
CPU 4 DPC highest execution time (µs):                91.032064
CPU 4 DPC total execution time (s):                   0.002490
CPU 4 DPC count:                                      182
_________________________________________________________________________________________________________
CPU 5 Interrupt cycle time (s):                       0.041325
CPU 5 ISR highest execution time (µs):                0.0
CPU 5 ISR total execution time (s):                   0.0
CPU 5 ISR count:                                      0
CPU 5 DPC highest execution time (µs):                39.058116
CPU 5 DPC total execution time (s):                   0.000287
CPU 5 DPC count:                                      36
_________________________________________________________________________________________________________
CPU 6 Interrupt cycle time (s):                       0.058277
CPU 6 ISR highest execution time (µs):                1.683367
CPU 6 ISR total execution time (s):                   0.000007
CPU 6 ISR count:                                      7
CPU 6 DPC highest execution time (µs):                56.753507
CPU 6 DPC total execution time (s):                   0.002092
CPU 6 DPC count:                                      133
_________________________________________________________________________________________________________
CPU 7 Interrupt cycle time (s):                       0.052680
CPU 7 ISR highest execution time (µs):                6.643287
CPU 7 ISR total execution time (s):                   0.000068
CPU 7 ISR count:                                      39
CPU 7 DPC highest execution time (µs):                54.809619
CPU 7 DPC total execution time (s):                   0.001001
CPU 7 DPC count:                                      61
_________________________________________________________________________________________________________
 

  • 0

#23
mckinnik

mckinnik

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts

Hopefully that all went through ok


  • 0

#24
mckinnik

mckinnik

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts

I did make changes to Task Scheduler and run OOSU10.exe and disabled some suggested items


  • 0

#25
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Looks a bit better.  Your latency is less than 1/2 of what it was before.  The Pagefaults are now all from your Trend anti-virus.  Appears to be a bit of a memory hog.  Make sure it is up to date.  You might pause your anti-virus and rerun Latency Monitor and see if that helps.

 

You never said what model number you have.  Latency Monitor says it's a NP750QUA but Samsung support doesn't show any downloads except a User Manual.  Perhaps if you ask the Samsung Update program which is installed on your PC it will offer a new BIOS update.

 

Could I see a new FRST scan?  (Pause your anti-virus while the scan is running)


  • 0

Advertisements


#26
mckinnik

mckinnik

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts

I have not abandoned this project. There has been an illness and death in my family. I should be able to get back to this in a few days.


  • 0

#27
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Sorry to hear that.  Don't worry about delays.  I do not keep track.


  • 0






Similar Topics


Also tagged with one or more of these keywords: #possible virus, #malware

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP