Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Malware infected pc


  • Please log in to reply

#1
LuckyJohn

LuckyJohn

    New Member

  • Member
  • Pip
  • 1 posts

Hi,

 

I was hoping someone could help me out I'm pretty sure my pc is infected I've tried remedying using 6 or 7 different notable anti malware programs. Each program has been able to detect something and remove it. Frequent crashes and performance issues persist even after each antivirus software removed malware and remnants. I'm sure that this happened while torrenting. I've noticed suspicious processes running and using a sizable portion of my resources while gaming. when I open task manager or any other monitoring tool resource utilization seems to settle as my fans rpm will decrease aggressively afterwards. I have attached a copy of Farbar Txt file. 

 

Any help is appreciated,

thanks.

 

                                           ----------------------------------------------------------------------------------------------------------------------------------------------

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-09-2021
Ran by kjeff (administrator) on DESKTOP-UF1CQQ5 (16-09-2021 15:24:16)
Running from G:\
Loaded Profiles: kjeff
Platform: Windows 10 Pro Version 21H1 19043.1202 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Autodesk, Inc. -> Autodesk) C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\11.0.0.4854\AdskLicensingService\AdskLicensingService.exe
(Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Check Point Software Technologies Ltd. -> ) C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\SBACipollaSrvHost.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\EFRService.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\Endpoint Security\Remediation\RemediationService.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\Endpoint Security\Threat Emulation\TESvc.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZANG\AR\AR_Service.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZANG\MgrSvc\ZANG_MgrSvc.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZANG\UI\UI_Main.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies, Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Comodo Security Solutions, Inc. -> COMODO) C:\Program Files (x86)\Comodo\COMODO Secure Shopping\csssrv64.exe
(Comodo Security Solutions, Inc. -> Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(d7xTech, Inc -> d7xTech, Inc.) C:\Users\kjeff\Desktop\KillEmAll Mini.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Emsisoft Ltd -> Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Emsisoft Ltd -> Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Emsisoft Ltd -> Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2start.exe
(Emsisoft Ltd -> Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\CommService.exe
(Emsisoft Ltd -> Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\eppwsc.exe
(IObit CO., LTD -> IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFCore.exe
(IObit CO., LTD -> IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe
(IObit CO., LTD -> IObit) C:\Users\kjeff\AppData\Local\Temp\IMF8_BigUpgrade\IMFBigUpgrade1.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12107.1001.15.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(Nvidia Corporation -> NVIDIA Corporation) C:\Users\kjeff\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmdi.inf_amd64_9413e5ce3f1b6ec6\Display.NvContainer\NVDisplay.Container.exe <2>
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookInst64.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDOnAccess.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(X-Rite Incorporated -> X-Rite Inc.) C:\Program Files (x86)\X-Rite\Devices\Services\xrdd.exe
Failed to access process -> ADPClientService.exe
Failed to access process -> SDUpdate.exe
Failed to access process -> SDUpdate.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [DigidesignMMERefresh] => C:\Program Files\Avid\Pro Tools\MMERefresh.exe
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9277520 2019-07-03] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Sonic Studio 3] => C:\Program Files\ASUSTeKcomputer.Inc\Sonic Suite 3\Foundation\SS3svc32.exe [1234432 2019-10-30] (ASUSTeK COMPUTER INC.) [File not signed]
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [339512 2021-08-04] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [AdAwareTray] => C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.10.158.0\AdAwareTray.exe [4882168 2021-06-23] (Adaware Software (Lavasoft Software Canada Inc.) -> )
HKLM\...\Run: [vdcss] => C:\Program Files (x86)\COMODO\COMODO Secure Shopping\vdcss.exe [10140904 2019-08-21] (Comodo Security Solutions, Inc. -> COMODO)
HKLM\...\Run: [emsisoft anti-malware] => C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [9286160 2021-09-15] (Emsisoft Ltd -> Emsisoft Ltd)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [8091424 2021-09-13] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [668376 2021-05-10] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM-x32\...\Run: [Autodesk Genuine Service ] => C:\ProgramData\Autodesk\Genuine Service\x64\GenuineService.exe [2483552 2021-01-08] (Autodesk, Inc. -> Autodesk)
HKLM-x32\...\Run: [Glorious Core] => C:\Program Files (x86)\Glorious Core\Glorious Core\Glorious Core.exe [93626368 2021-07-23] (GitHub, Inc.) [File not signed]
HKLM-x32\...\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [326152 2021-05-20] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
HKLM-x32\...\Run: [ZANG] => C:\Program Files (x86)\CheckPoint\ZANG\UI\UI_Main.exe [702080 2021-06-08] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [6787856 2019-03-19] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [6932176 2021-08-27] (IObit CO., LTD -> IObit)
HKU\S-1-5-21-881886857-835413342-2016909866-1001\...\Run: [Discord] => C:\Users\kjeff\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-881886857-835413342-2016909866-1001\...\Run: [EpicGamesLauncher] => "E:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent
HKU\S-1-5-21-881886857-835413342-2016909866-1001\...\Run: [Haste] => C:\Program Files\Haste\Haste.exe [5497032 2021-06-21] (Thalonet, Inc. -> Thalonet, Inc. dba Haste)
HKU\S-1-5-21-881886857-835413342-2016909866-1001\...\Run: [CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [144008 2019-11-26] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-881886857-835413342-2016909866-1001\...\Run: [Steam] => E:\Program Files (x86)\Steam\steam.exe [4282600 2021-09-13] (Valve -> Valve Corporation)
HKU\S-1-5-21-881886857-835413342-2016909866-1001\...\Run: [Substance Launcher] => "E:\Program Files\Allegorithmic\Substance Launcher\Substance Launcher.exe"
HKU\S-1-5-21-881886857-835413342-2016909866-1001\...\Run: [YandexDisk2] => C:\Users\kjeff\AppData\Roaming\Yandex\YandexDisk2\3.1.20.3664\YandexDisk2.exe -autostart
HKU\S-1-5-21-881886857-835413342-2016909866-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3145920 2021-08-19] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-881886857-835413342-2016909866-1001\...\Run: [WallpaperEngine] => E:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe [2652832 2021-06-25] (Skutta, Kristjan -> )
HKU\S-1-5-21-881886857-835413342-2016909866-1001\...\Run: [com.squirrel.splice.Splice] => C:\Users\kjeff\AppData\Local\splice\app-3.7.24713\Splice.exe [83318784 2021-09-07] (Splice) [File not signed]
HKU\S-1-5-21-881886857-835413342-2016909866-1001\...\Run: [wtfast Tray] => C:\Program Files (x86)\wtfast\wtfast.exe [7725872 2020-05-15] (WTFast (AAA Internet Publishing Inc.) -> AAA Internet Publishing Inc.)
HKU\S-1-5-21-881886857-835413342-2016909866-1001\...\Run: [1Password] => C:\Users\kjeff\AppData\Local\1Password\app\7\1Password.exe [5282456 2021-09-15] (AgileBits Inc. -> AgileBits Inc.)
HKU\S-1-5-21-881886857-835413342-2016909866-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [11224432 2021-08-19] (Support.com Inc -> SUPERAntiSpyware)
HKU\S-1-5-21-881886857-835413342-2016909866-1001\...\Run: [Opera Browser Assistant] => C:\Users\kjeff\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [4091600 2021-09-13] (Opera Software AS -> Opera Software)
HKU\S-1-5-18\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3519608 2021-07-25] (Razer USA Ltd. -> Razer Inc.)
HKLM\...\Print\Monitors\Win2PDF Port: C:\Windows\system32\win2pdfm7.dll [98320 2020-01-11] (Dane Prairie Systems, LLC -> Dane Prairie Systems, LLC - hxxp://www.win2pdf.com)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\93.0.4577.82\Installer\chrmstp.exe [2021-09-15] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{50968FF7-10C1-4fb3-98B0-CD654D6CB97E}] -> C:\Program Files\WIDCOMM\Bluetooth Software\\BtwCP.dll [2016-02-17] (Broadcom Corporation -> Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AudientAppLauncher Autostart.lnk [2021-08-18]
ShortcutTarget: AudientAppLauncher Autostart.lnk -> C:\Program Files\Audient\USBAudioDriver\W10_x64\AudientAppLauncher.exe (Thesycon Software Solutions GmbH & Co. KG -> Audient)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2021-08-23]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation -> Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Toon Boom Harmony Network Connections.lnk [2021-07-22]
ShortcutTarget: Toon Boom Harmony Network Connections.lnk -> C:\Program Files (x86)\Toon Boom Animation\Toon Boom Harmony 20 Premium\win32\bin\Toon Boom Harmony Network Connections.exe (Toon Boom Animation Inc -> )
Startup: C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2020-06-29]
ShortcutTarget: MEGAsync.lnk -> C:\Users\kjeff\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited -> Mega Limited)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKU\S-1-5-21-881886857-835413342-2016909866-1001\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0FE01E19-25F0-4EBB-97AE-8B9281F59F97} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe [65448 2021-05-31] (Microsoft Corporation -> Microsoft)
Task: {152767CF-78AF-4E5E-8B77-3DC98E7F8745} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-881886857-835413342-2016909866-1001 => C:\Users\kjeff\AppData\Local\MEGAsync\MEGAupdater.exe [1820848 2021-05-12] (Mega Limited -> Mega Limited)
Task: {17721FE1-29E2-49E4-A40A-23F55AFFD42B} - System32\Tasks\CheckPointUpdateTaskMachineCore => C:\Program Files (x86)\CheckPoint\Update\ZoneAlarmUpdate.exe [166200 2021-08-26] (Check Point Software Technologies Ltd. -> CheckPoint Software Technologies Ltd.)
Task: {17DFFA68-2DB3-4C06-AB35-D8EDE4CC3F22} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [680888 2021-09-15] (Mozilla Corporation -> Mozilla Foundation)
Task: {19C3AD9E-C0A7-4429-A758-8AF1CB9AB0C7} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3339120 2021-06-15] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {22AC0833-1E76-4C6D-B039-A5118A5F61A8} - System32\Tasks\ASUS\Ez Update => C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe [1509424 2020-03-31] (ASUSTeK Computer Inc. -> )
Task: {2696C832-D255-42F2-8036-C773908725A3} - System32\Tasks\Opera scheduled assistant Autoupdate 1631745798 => C:\Users\kjeff\AppData\Local\Programs\Opera\launcher.exe [42724048 2021-09-13] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\kjeff\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {30AFB461-159B-49F4-92FF-D45D0B6219F0} - System32\Tasks\Kill JDownloader => C:\Users\kjeff\Documents\Scripts\JDownloader_Kill.bat [32 2021-07-12] () [File not signed]
Task: {3497E6EC-698A-44D0-A876-8E0A885B92C3} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [129808 2021-08-14] (Dropbox, Inc -> Dropbox, Inc.)
Task: {3994F878-8DDC-40ED-B72B-0515EE8279DD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616832 2019-09-04] (Apple Inc. -> Apple Inc.)
Task: {3EC38FF8-A16C-4CA9-9BE1-F611FCBB949D} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [6189624 2020-04-26] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {45595CB1-9FE0-4323-999D-96BE426C5F56} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [129808 2021-08-14] (Dropbox, Inc -> Dropbox, Inc.)
Task: {459B788B-BF19-4C36-993A-63CB8BCE54B3} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [903024 2021-05-04] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {4726D87B-95A3-430A-8A72-785F6E98140A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-04-22] (Google LLC -> Google LLC)
Task: {4907C348-982C-4C08-8286-738EC4216481} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905072 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {504AA91B-0C86-4C5F-9929-82E666C8BE23} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\kjeff\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe
Task: {57FC03B0-8D77-443E-BCEB-E54562553BD5} - System32\Tasks\ASUS\GpuFanHelper => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\GpuFanHelper.exe [4329008 2020-10-12] (ASUSTeK Computer Inc. -> TODO: <Company name>)
Task: {5FC6A88D-373C-4C06-A456-70237795FAB7} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [645488 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {64004491-B976-49E3-8E26-0BE138BBA2B6} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {65DC703C-E00A-488D-B853-6CEFEAAF4A11} - System32\Tasks\IMF_SkipUAC_kjeff => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [6932176 2021-08-27] (IObit CO., LTD -> IObit)
Task: {661124D8-412F-4422-8CE7-B104CDF20CD0} - System32\Tasks\ASUS\ASUS AISuiteIII => C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe [2115632 2020-10-22] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {68F3E5F9-BCFC-41EE-B590-EBFAF4A44657} - System32\Tasks\ASUS\ASUS DIPAwayMode => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe [1469288 2020-10-19] (ASUSTeK Computer Inc. -> )
Task: {6AABE99B-271F-4477-9357-CE0B3D1B5FA3} - System32\Tasks\X-Rite Device Services Software Updater => C:\Program Files (x86)\X-Rite\Devices\Services\XRD Software Update.exe [31656 2019-01-24] (X-Rite Incorporated -> X-Rite Inc.)
Task: {6EF1F50F-8E71-43D8-B3E8-57F8653B8EDF} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-881886857-835413342-2016909866-1001 => C:\Users\kjeff\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {7545A23D-0924-48C4-B10E-807773E3315F} - System32\Tasks\SUPERAntiSpyware Scheduled Task c0c5032c-90cd-4cc3-b268-6bd5debf4856 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [49944 2021-01-09] (SUPERAntiSpyware.com -> SUPERAdBlocker.com) -> "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" /TASK:c0c5032c-90cd-4cc3-b268-6bd5debf4856
Task: {7DE040C3-B31B-4AED-BA74-30CAA3637190} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {80775E9D-0570-4855-865B-C46415177275} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {80C11BF4-FB45-47BD-8961-4F2FE7FF3537} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905072 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {95797D06-DC33-4521-8462-78C13D329555} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [5723640 2019-09-04] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {97621CA9-3683-4E48-B031-74912D85AC0A} - System32\Tasks\WpsUpdateTask_kjeff => C:\Users\kjeff\AppData\Local\Kingsoft\WPS Office\11.2.0.10296\office6\wpsupdate.exe [166600 2021-09-10] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {9D9B959D-0082-4831-8EED-F1CEE1F3D286} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [7177168 2020-04-26] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {B044F3A5-CBC1-4929-BE19-E84EE11DBAD3} - System32\Tasks\SUPERAntiSpyware Scheduled Task 96bbc763-d277-4bed-b479-c904faeb193f => C:\Program Files\SUPERAntiSpyware\SASTask.exe [49944 2021-01-09] (SUPERAntiSpyware.com -> SUPERAdBlocker.com) -> "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" /TASK:96bbc763-d277-4bed-b479-c904faeb193f
Task: {B44AAB59-EB55-4ECE-8BB3-28D4267513DD} - System32\Tasks\SS3svc64Run => C:\Program Files\ASUSTeKcomputer.Inc\Sonic Suite 3\Foundation\x64\SS3svc64.exe [811520 2019-10-30] (ASUSTeK COMPUTER INC.) [File not signed]
Task: {CA609FDE-2647-4B35-BEE5-A359AE6E3CC8} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CB5FC06E-4EF2-49BD-ADB0-9A4C6709499C} - System32\Tasks\WpsExternal_kjeff_20210910203048 => C:\Users\kjeff\AppData\Local\Kingsoft\WPS Office\11.2.0.10296\office6\wpscloudsvr.exe [1057480 2021-09-10] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {CC71B440-3F7D-4EDC-90A8-E768ABA095F6} - System32\Tasks\Safer-Networking\Spybot Anti-Beacon\Refresh Spybot Anti-Beacon immunization => C:\Program Files (x86)\Safer-Networking Ltd\Spybot Anti-Beacon\Spybot3AntiBeacon.exe [9469648 2021-04-29] (Safer-Networking Ltd. -> )
Task: {D3FB4D85-E96C-41D5-8D25-8CADCE78A55F} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\kjeff\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe
Task: {D7688983-F041-43FA-8E2F-FEF271CCB48C} - System32\Tasks\CheckPointUpdateTaskMachineUA => C:\Program Files (x86)\CheckPoint\Update\ZoneAlarmUpdate.exe [166200 2021-08-26] (Check Point Software Technologies Ltd. -> CheckPoint Software Technologies Ltd.)
Task: {DBB1C0FA-FF78-4E00-94C0-B392A92AEF5D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-04-22] (Google LLC -> Google LLC)
Task: {DF77F4F8-696E-4C2A-B084-7D692F88192A} - System32\Tasks\Opera scheduled Autoupdate 1631745780 => C:\Users\kjeff\AppData\Local\Programs\Opera\launcher.exe [42724048 2021-09-13] (Opera Software AS -> Opera Software)
Task: {EDFC1A5B-DD4D-42DD-A5A5-7BB8D8086A17} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [903024 2021-05-04] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {F7124DEC-A127-4A94-83A3-FDC52DA4F083} - System32\Tasks\Sleep => C:\Users\kjeff\Documents\Scripts\Sleep.bat [47 2021-07-12] () [File not signed]
Task: {F9CB6CC0-69C9-4B82-94A0-3097BCAEA1B6} - System32\Tasks\SS3svc32Run => C:\Program Files\ASUSTeKcomputer.Inc\Sonic Suite 3\Foundation\SS3svc32.exe [1234432 2019-10-30] (ASUSTeK COMPUTER INC.) [File not signed]
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 96bbc763-d277-4bed-b479-c904faeb193f.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task c0c5032c-90cd-4cc3-b268-6bd5debf4856.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\WINDOWS\Tasks\X-Rite Device Services Software Updater.job => C:\Program Files (x86)\X-Rite\Devices\Services\XRD Software Update.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Hosts: 0.0.0.1  scinstallcheck.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{0d2d2371-b774-4222-831a-bcf3a8b53e60}: [DhcpNameServer] 192.168.1.254
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
 
Edge: 
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Profile 1
Edge Profile: C:\Users\kjeff\AppData\Local\Microsoft\Edge\User Data\Default [2021-09-15]
Edge Profile: C:\Users\kjeff\AppData\Local\Microsoft\Edge\User Data\Profile 1 [2021-09-16]
Edge DownloadDir: Profile 1 -> H:\
Edge Notifications: Profile 1 -> hxxps://app.chime.aws; hxxps://bangx.org; hxxps://flashymass.com; hxxps://kokotrokot.com; hxxps://linkvertise.com; hxxps://meet.google.com; hxxps://oxford-ms.geebo.com; hxxps://porneq.com; hxxps://suggestive.com; hxxps://time4news.net; hxxps://typiccor.com; hxxps://www.instantcheckmate.com; hxxps://www2.darenjarvis.pro; hxxps://www40.darenjarvis.pro
Edge HomePage: Profile 1 -> hxxp://lenovo17win10.msn.com/?pc=LCTE
Edge Extension: (Click&Clean) - C:\Users\kjeff\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\dacknjoogbepndbemlmljdobinliojbk [2021-06-18]
Edge Extension: (lock) - C:\Users\kjeff\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\dppgmdbiimibapkepcbdbmkaabgiofem [2021-09-15]
Edge Extension: (MetaMask) - C:\Users\kjeff\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\ejbalbakoplchlghecdalmeeeajnimhm [2021-09-05]
Edge Extension: (Download All Images) - C:\Users\kjeff\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\focinmnfmbmhknhdaamhppgdhahnbgif [2021-09-10]
Edge Extension: (Workona Tab Manager) - C:\Users\kjeff\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\gdfnelpciiajgjenlapgkdcjpcfpfpob [2021-07-21]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\kjeff\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-09-15]
Edge Extension: (Download with JDownloader) - C:\Users\kjeff\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\ilonanfdcnaljoedndpfeflllibalflj [2021-07-13]
Edge Extension: (AdBlock — best ad blocker) - C:\Users\kjeff\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2021-09-10]
Edge Profile: C:\Users\kjeff\AppData\Local\Microsoft\Edge\User Data\Profile 2 [2021-09-16]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\kjeff\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-09-15]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
 
FireFox:
========
FF DefaultProfile: myo3bsn6.default
FF ProfilePath: C:\Users\kjeff\AppData\Roaming\Mozilla\Firefox\Profiles\myo3bsn6.default [2021-09-15]
FF Extension: (IObit Surfing Protection & Ads Removal) - C:\Users\kjeff\AppData\Roaming\Mozilla\Firefox\Profiles\myo3bsn6.default\Extensions\[email protected] [2021-01-12]
FF ProfilePath: C:\Users\kjeff\AppData\Roaming\Mozilla\Firefox\Profiles\kxbp2r4e.default-release [2021-09-16]
FF DownloadDir: C:\Users\kjeff\Downloads\teetetease
FF Extension: (IObit Surfing Protection & Ads Removal) - C:\Users\kjeff\AppData\Roaming\Mozilla\Firefox\Profiles\kxbp2r4e.default-release\Extensions\[email protected] [2021-01-12]
FF Extension: (Authenticator) - C:\Users\kjeff\AppData\Roaming\Mozilla\Firefox\Profiles\kxbp2r4e.default-release\Extensions\[email protected] [2021-09-15]
FF Extension: (Open Multiple URLs) - C:\Users\kjeff\AppData\Roaming\Mozilla\Firefox\Profiles\kxbp2r4e.default-release\Extensions\[email protected] [2021-07-20]
FF Extension: (Download with JDownloader) - C:\Users\kjeff\AppData\Roaming\Mozilla\Firefox\Profiles\kxbp2r4e.default-release\Extensions\{03e07985-30b0-4ae0-8b3e-0c7519b9bdf6}.xpi [2021-07-04]
FF Extension: (Locoloader) - C:\Users\kjeff\AppData\Roaming\Mozilla\Firefox\Profiles\kxbp2r4e.default-release\Extensions\{21368c2e-1e43-414c-9c63-e1b87782681f}.xpi [2021-07-07]
FF Extension: (Malwarebytes Browser Guard) - C:\Users\kjeff\AppData\Roaming\Mozilla\Firefox\Profiles\kxbp2r4e.default-release\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2021-09-15]
FF Extension: (Allow Right-Click) - C:\Users\kjeff\AppData\Roaming\Mozilla\Firefox\Profiles\kxbp2r4e.default-release\Extensions\{278b0ae0-da9d-4cc6-be81-5aa7f3202672}.xpi [2021-09-09]
FF Extension: (Absolute Right Click) - C:\Users\kjeff\AppData\Roaming\Mozilla\Firefox\Profiles\kxbp2r4e.default-release\Extensions\{9350bc42-47fb-4598-ae0f-825e3dd9ceba}.xpi [2021-07-07]
FF Extension: (1Password – Password Manager) - C:\Users\kjeff\AppData\Roaming\Mozilla\Firefox\Profiles\kxbp2r4e.default-release\Extensions\{d634138d-c276-4fc8-924b-40a0ea21d284}.xpi [2021-09-15]
FF Plugin-x32: @tools.google.com/CheckPoint Update;version=3 -> C:\Program Files (x86)\CheckPoint\Update\1.3.99.0\npZoneAlarmUpdate3.dll [2021-08-26] (Check Point Software Technologies Ltd. -> CheckPoint Software Technologies Ltd.)
FF Plugin-x32: @tools.google.com/CheckPoint Update;version=9 -> C:\Program Files (x86)\CheckPoint\Update\1.3.99.0\npZoneAlarmUpdate3.dll [2021-08-26] (Check Point Software Technologies Ltd. -> CheckPoint Software Technologies Ltd.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\antibeacon.js [2021-09-16] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files\mozilla firefox\mozilla.cfg [2021-09-16] <==== ATTENTION
 
Chrome: 
=======
CHR DefaultProfile: Profile 2
CHR Profile: C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default [2021-09-15]
CHR Notifications: Default -> hxxps://linkvertise.com
CHR DefaultSearchURL: Default -> hxxps://lookbox.net/search?q={searchTerms}
CHR DefaultSearchKeyword: Default -> lookbox
CHR Extension: (Slides) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-04-22]
CHR Extension: (Docs) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-04-22]
CHR Extension: (Google Drive) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-26]
CHR Extension: (YouTube) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-04-22]
CHR Extension: (Video Downloader Plus) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfejhehdhaaeoiahaojjhmjaihjaodcf [2021-07-07]
CHR Extension: (Image Downloader) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnpniohnfphhjihaiiggeabnkjhpaldj [2021-06-10]
CHR Extension: (Lookbox.net) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\eceiapccglmgpbbocamhfmgfbcollhpk [2020-06-01]
CHR Extension: (Video Downloader professional) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2021-07-07]
CHR Extension: (Sheets) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-04-22]
CHR Extension: (Video Downloader PLUS) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhplmmllnpjjlncfjpbbpjadoeijkogc [2020-06-15]
CHR Extension: (Google Docs Offline) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-07-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-14]
CHR Extension: (Gmail) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-23]
CHR Extension: (Chrome Media Router) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-06-10]
CHR Profile: C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Guest Profile [2021-09-15]
CHR Profile: C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1 [2021-09-16]
CHR Notifications: Profile 1 -> hxxps://bestjavporn.com; hxxps://linkvertise.com; hxxps://www.tubxporn.com
CHR Extension: (Slides) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-04-29]
CHR Extension: (Safe Torrent Scanner) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2021-08-29]
CHR Extension: (Math Wallet) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\afbcbjpbpfadlkmhmclhkeeodmamcflc [2021-08-19]
CHR Extension: (Docs) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2020-04-29]
CHR Extension: (Google Drive) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-12-21]
CHR Extension: (YouTube) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-04-29]
CHR Extension: (Honey) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2021-08-19]
CHR Extension: (Sheets) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-04-29]
CHR Extension: (Binance Wallet) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fhbohimaelbohpjbbldcngcnapndodjp [2021-08-29]
CHR Extension: (ZoneAlarm Web Secure) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\flljooaijgdgaaogmfhakpojmddcjjmj [2021-08-29]
CHR Extension: (Proctorio) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fpmapakogndmenjcfoajifaaonnkpkei [2021-08-19]
CHR Extension: (Google Docs Offline) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-07-05]
CHR Extension: (Video Adblocker for Youtube™ Extension) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hflefjhkfeiaignkclmphmokmmbhbhik [2020-04-29]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-08-29]
CHR Extension: (Custom Engines) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mkacjhofeafagblkflacbogbkdcmeabf [2021-01-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-14]
CHR Extension: (Gmail) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-12-21]
CHR Extension: (Chrome Media Router) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-08-19]
CHR Profile: C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2 [2021-09-16]
CHR Extension: (Slides) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-03-25]
CHR Extension: (Safe Torrent Scanner) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2021-08-29]
CHR Extension: (Docs) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2021-03-25]
CHR Extension: (Google Drive) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-03-25]
CHR Extension: (YouTube) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-03-25]
CHR Extension: (Tampermonkey) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2021-07-07]
CHR Extension: (Sheets) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-03-25]
CHR Extension: (ExpressVPN: VPN proxy for a better internet) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\fgddmllnllkalaagkghckoinaemmogpe [2021-07-07]
CHR Extension: (ZoneAlarm Web Secure) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\flljooaijgdgaaogmfhakpojmddcjjmj [2021-08-29]
CHR Extension: (Google Docs Offline) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-07-07]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-08-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-03-25]
CHR Extension: (Gmail) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-03-25]
CHR Extension: (Chrome Media Router) - C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-08-19]
CHR Profile: C:\Users\kjeff\AppData\Local\Google\Chrome\User Data\System Profile [2021-09-15]
CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]
CHR HKLM-x32\...\Chrome\Extension: [flljooaijgdgaaogmfhakpojmddcjjmj]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
 
Opera: 
=======
OPR Profile: C:\Users\kjeff\AppData\Roaming\Opera Software\Opera Stable [2021-09-15]
OPR Extension: (Rich Hints Agent) - C:\Users\kjeff\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2021-09-15]
OPR Extension: (Amazon Assistant Promotion) - C:\Users\kjeff\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2021-09-15]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2021-01-09] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [11119744 2021-09-15] (Emsisoft Ltd -> Emsisoft Ltd)
S2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1050920 2021-05-10] (Autodesk, Inc. -> Autodesk Inc.)
S2 adawareantivirusservice; C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.10.158.0\AdAwareService.exe [587104 2021-06-23] (Adaware Software (Lavasoft Software Canada Inc.) -> )
R2 AdskLicensingService; C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingService\AdskLicensingService.exe [18673448 2020-11-17] (Autodesk, Inc. -> Autodesk)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [99104 2021-03-16] (Apple Inc. -> Apple Inc.)
R2 AR_Service; C:\Program Files (x86)\CheckPoint\ZANG\AR\AR_Service.exe [23168 2021-06-08] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.00.51\atkexComSvc.exe [442928 2020-10-22] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.25\AsSysCtrlService.exe [1360016 2020-10-12] (ASUSTeK Computer Inc. -> ) [File not signed]
S2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\2.00.94\AsusFanControlService.exe [2073136 2020-10-12] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S2 AsusUpdateCheck; C:\WINDOWS\System32\AsusUpdateCheck.exe [768408 2021-09-16] (ASUSTeK Computer Inc. -> )
S2 Canvas Installer; C:\Program Files (x86)\Dell\Canvas Installer\DCIService.exe [39960 2019-11-04] (Dell Inc -> DELL)
R2 CPEFR; C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\EFRService.exe [3268288 2021-02-25] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
R2 CpSbaCipolla; C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\SBACipollaSrvHost.exe [33984 2021-06-04] (Check Point Software Technologies Ltd. -> )
R2 CpSbaUpdater; C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\SBACipollaSrvHost.exe [33984 2021-06-04] (Check Point Software Technologies Ltd. -> )
R2 csssrv; C:\Program Files (x86)\COMODO\COMODO Secure Shopping\csssrv64.exe [4054248 2019-08-21] (Comodo Security Solutions, Inc. -> COMODO)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [129808 2021-08-14] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [129808 2021-08-14] (Dropbox, Inc -> Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [44328 2021-09-13] (Dropbox, Inc -> Dropbox, Inc.)
S3 Denuvo Anti-Cheat Update Service; C:\Program Files\Denuvo Anti-Cheat\denuvo-anti-cheat-update-service.exe [980184 2020-05-19] (Denuvo GmbH -> Denuvo GmbH)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2253776 2019-06-20] (Comodo Security Solutions, Inc. -> Comodo)
S2 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [9868696 2021-08-18] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803440 2020-11-16] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 EmsiCommService; C:\Program Files\Emsisoft Anti-Malware\CommService.exe [14230080 2021-09-15] (Emsisoft Ltd -> Emsisoft Ltd)
R2 EppWsc; C:\Program Files\Emsisoft Anti-Malware\EppWsc.exe [1545368 2021-09-15] (Emsisoft Ltd -> Emsisoft Ltd)
S2 HasteUEService; C:\Program Files\Haste\UserEdgeService.exe [1597128 2021-06-21] (Thalonet, Inc. -> Thalonet, Inc. (dba Haste))
S2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2405136 2021-08-31] (IObit Information Technology -> IObit)
S2 LightingService; C:\Program Files (x86)\LightingService\LightingService.exe [2109376 2019-07-03] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7785656 2021-09-10] (Malwarebytes Inc -> Malwarebytes)
S2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\3.4.105.0\\McCSPServiceHost.exe [2687856 2020-01-25] (McAfee, LLC. -> McAfee, LLC.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2557144 2021-08-19] (Electronic Arts, Inc. -> Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3475680 2021-08-19] (Electronic Arts, Inc. -> Electronic Arts)
S2 Razer Game Manager Service; C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe [254224 2021-03-21] (Razer USA Ltd. -> Razer Inc)
S2 Razer Synapse Service; C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe [294520 2021-07-25] (Razer USA Ltd. -> Razer Inc.)
R2 RemediationService; C:\Program Files (x86)\CheckPoint\Endpoint Security\Remediation\RemediationService.exe [18168 2020-12-16] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S2 RzActionSvc; C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe [533808 2021-01-29] (Razer USA Ltd. -> Razer Inc.)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2747312 2020-04-26] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4583240 2020-04-26] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [940976 2019-09-04] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5394872 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TESvc; C:\Program Files (x86)\CheckPoint\Endpoint Security\Threat Emulation\TESvc.exe [136896 2021-05-27] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [4575688 2021-05-20] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [147392 2019-04-30] (Microsoft Corporation -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\NisSrv.exe [2772856 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MsMpEng.exe [136640 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 wpscloudsvr; C:\Program Files (x86)\Kingsoft\office6\wpscloudsvr.exe [1058504 2021-08-09] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)
R2 xrdd.exe; C:\Program Files (x86)\X-Rite\Devices\Services\xrdd.exe [91048 2019-01-24] (X-Rite Incorporated -> X-Rite Inc.)
S2 ZA NET ICM Service; C:\Program Files (x86)\CheckPoint\ICM\ICM-Service-NET.exe [42208 2020-03-13] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
R2 ZANG_MgrSvc; C:\Program Files (x86)\CheckPoint\ZANG\MgrSvc\ZANG_MgrSvc.exe [25216 2021-06-08] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
R2 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [129216 2021-05-20] (Check Point Software Technologies Ltd. -> Check Point Software Technologies, Ltd.)
S2 zus; C:\Program Files (x86)\CheckPoint\Update\ZoneAlarmUpdate.exe [166200 2021-08-26] (Check Point Software Technologies Ltd. -> CheckPoint Software Technologies Ltd.)
S3 zusm; C:\Program Files (x86)\CheckPoint\Update\ZoneAlarmUpdate.exe [166200 2021-08-26] (Check Point Software Technologies Ltd. -> CheckPoint Software Technologies Ltd.)
S2 DigiRefresh; C:\Program Files\Avid\Pro Tools\MMERefresh.exe -s [X]
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_9413e5ce3f1b6ec6\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_9413e5ce3f1b6ec6\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
S2 RealtekHubService; C:\Users\kjeff\AppData\Local\Temp\is-KJAP4.tmp\RtHubSSContrl.exe [X] <==== ATTENTION
S2 SafeConnectService; "C:\Program Files (x86)\McAfee\McAfee Safe Connect\SafeConnect.ServiceHost.exe" [X]
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [34112 2019-07-02] (ASUSTeK Computer Inc. -> )
R1 Asusgio2; C:\Windows\system32\drivers\AsIO2.sys [35136 2020-05-25] (ASUSTeK Computer Inc. -> )
R3 audientusbaudio; C:\WINDOWS\System32\drivers\audientusbaudio.sys [381496 2021-07-12] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 audientusbaudioks; C:\WINDOWS\System32\drivers\audientusbaudioks.sys [53816 2021-07-12] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [284672 2021-04-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R1 cmdcss; C:\WINDOWS\system32\drivers\cmdcss.sys [125000 2018-02-28] (Comodo Security Solutions, Inc. -> COMODO)
R2 cpbak; C:\WINDOWS\System32\DRIVERS\cpbak.sys [83248 2020-09-03] (Check Point Software Technologies Ltd. -> Check Point Software Technologies)
R1 CPEPMon; C:\WINDOWS\System32\DRIVERS\CPEPMon.sys [150968 2021-05-30] (Microsoft Windows Hardware Compatibility Publisher -> Check Point Software Technologies)
R1 cposfw; C:\WINDOWS\System32\DRIVERS\cposfw.sys [113976 2021-06-08] (Check Point Software Technologies Ltd. -> Check Point Software Technologies)
S3 Denuvo Anti-Cheat; C:\Program Files\Denuvo Anti-Cheat\denuvo-anti-cheat.sys [1553128 2020-05-19] (Denuvo GmbH -> Denuvo GmbH)
R1 EneIo; C:\Windows\system32\drivers\ene.sys [17624 2019-05-22] (Microsoft Windows Hardware Compatibility Publisher -> )
S0 epelam; C:\WINDOWS\System32\drivers\epelam.sys [23528 2020-02-20] (CheckPointElamTestSign -> Check Point Software Technologies)
R1 epnetflt; C:\WINDOWS\system32\drivers\epnetflt.sys [135984 2020-12-06] (Check Point Software Technologies Ltd. -> Check Point Software Technologies)
R1 epp; C:\Program Files\Emsisoft Anti-Malware\epp.sys [155112 2021-09-15] (Microsoft Windows Hardware Compatibility Publisher -> Emsisoft Ltd)
R0 eppdisk; C:\WINDOWS\System32\drivers\eppdisk.sys [37776 2021-09-15] (Emsisoft Ltd -> Emsisoft Ltd)
S0 EppElam; C:\WINDOWS\System32\drivers\EppElam.sys [16808 2021-09-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Emsisoft Ltd)
R1 eppwfp; C:\Program Files\Emsisoft Anti-Malware\eppwfp.sys [126968 2021-09-15] (Microsoft Windows Hardware Compatibility Publisher -> Emsisoft Ltd)
R1 epregflt; C:\WINDOWS\system32\drivers\epregflt.sys [133416 2020-12-02] (Check Point Software Technologies Ltd. -> Check Point Software Technologies)
R1 GLCKIO2; C:\Windows\system32\drivers\GLCKIO2.sys [29368 2019-04-24] (ASUSTeK Computer Inc. -> )
R3 Imf8HpRegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win10_amd64\ImfHpRegFilter.sys [41848 2019-12-17] (IObit Information Technology -> IObit)
R3 IMFDownProtect; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win10_amd64\IMFDownProtect.sys [40920 2021-07-30] (IObit CO., LTD -> IObit)
R3 IMFForceDelete; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win10_amd64\IMFForceDelete.sys [34192 2019-06-11] (IObit Information Technology -> IObit)
R3 ImfHpFileFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win10_amd64\ImfHpFileFilter.sys [45432 2019-12-17] (IObit Information Technology -> IObit)
S3 ImfObCallback; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win10_amd64\ImfObCallback.sys [33984 2020-03-12] (IObit Information Technology -> IObit)
R3 ImfRealScanner; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win10_amd64\ImfRealScanner.sys [53720 2021-08-13] (IObit CO., LTD -> IObit)
S3 ImfRegistryFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win10_amd64\ImfRegistryFilter.sys [42360 2019-12-17] (IObit Information Technology -> IObit)
R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [34064 2020-10-15] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 ISWKL; C:\Program Files (x86)\CheckPoint\Endpoint Security\Endpoint Common\bin\ISWKL.sys [56184 2020-06-17] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S3 iVCam; C:\WINDOWS\system32\DRIVERS\iVCam.sys [1089512 2020-04-04] (Shanghai Yitu Information Technology Co., Ltd. -> e2eSoft)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [210344 2021-09-10] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2021-09-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-09-11] (Malwarebytes Inc -> Malwarebytes)
R3 MSIO; C:\Program Files\Patriot\Aac_Patriot Viper RGB\msio64.sys [25616 2018-02-12] (MICSYS Technology Co., Ltd. -> )
S3 RtsUpx; C:\WINDOWS\system32\drivers\RtsUpx.sys [18136 2020-07-15] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
S3 RzCommon; C:\WINDOWS\System32\drivers\RzCommon.sys [54632 2021-03-30] (Razer USA Ltd. -> Razer Inc)
S3 RzDev_022b; C:\WINDOWS\System32\drivers\RzDev_022b.sys [55624 2021-01-28] (Razer USA Ltd. -> Razer Inc)
S3 RzDev_0526; C:\WINDOWS\System32\drivers\RzDev_0526.sys [54168 2020-08-24] (Razer USA Ltd. -> Razer Inc)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2021-01-09] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2021-01-09] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SDHookDriver; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookDrv64.sys [82848 2019-07-31] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S0 Spybot3ELAM; C:\WINDOWS\System32\drivers\Spybot3ELAM.sys [19904 2019-06-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Windows ® Win 7 DDK provider)
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [41392 2020-09-22] (McAfee, LLC. -> The OpenVPN Project)
S3 tapprotonvpn; C:\WINDOWS\System32\drivers\tapprotonvpn.sys [49024 2021-05-28] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
R3 Trufos; C:\WINDOWS\System32\DRIVERS\Trufos.sys [641736 2021-04-20] (Bitdefender SRL -> Bitdefender)
U5 UnlockerDriver5; C:\Program Files (x86)\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] (Empty Loop -> )
S3 vmulti; C:\WINDOWS\System32\drivers\vmulti.sys [10752 2018-03-16] (Windows ® Win 7 DDK provider) [File not signed]
R1 Vsdatant; C:\WINDOWS\System32\drivers\vsdatant.sys [461240 2021-05-20] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
U5 vsock; C:\Windows\System32\Drivers\vsock.sys [103224 2019-08-14] (VMware, Inc. -> VMware, Inc.)
S3 WacHidRouterISD; C:\WINDOWS\system32\DRIVERS\wachidrouter_isd.sys [139928 2017-04-28] (Wacom Technology Corporation -> Wacom Technology, Corp.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2021-09-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [433384 2021-09-09] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86264 2021-09-09] (Microsoft Windows -> Microsoft Corporation)
R4 WinDivert1.3; C:\Program Files\Haste\WinDivert64.sys [47560 2021-06-21] (Ars Nova Systems -> Basil)
R2 WinI2C-DDC; C:\WINDOWS\system32\drivers\DDCDrv.sys [20832 2017-06-15] (PC Micro Systems Inc. -> Nicomsoft Ltd.)
R2 WtfEngineDrv; C:\WINDOWS\system32\Drivers\WtfEngineDrv.sys [41704 2020-05-15] (Initeks, OOO -> AAA Internet Publishing, Inc.)
S3 GPU-Z-v2; \??\C:\Users\kjeff\AppData\Local\Temp\GPU-Z-v2.sys [X] <==== ATTENTION
U3 iswSvc; no ImagePath
S3 MpKsla56a9945; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6921F87E-4728-4AE6-88AC-D4DA7DE14995}\MpKslDrv.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Three months (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2021-09-16 15:21 - 2021-09-16 15:21 - 000000000 _____ C:\WINDOWS\cpepmon.mlf
2021-09-16 05:56 - 2021-09-16 05:56 - 000000000 ____D C:\Program Files\ESET
2021-09-16 05:52 - 2021-09-16 05:52 - 000000000 ____D C:\Users\kjeff\Downloads\teetetease
2021-09-16 05:39 - 2021-09-16 05:40 - 008702880 _____ (ESET) C:\Users\kjeff\Downloads\eset_internet_security_live_installer.exe
2021-09-16 05:05 - 2021-09-16 05:05 - 000000000 ____D C:\WINDOWS\SysWOW64\%LOCALAPPDATA%
2021-09-16 05:04 - 2021-09-16 05:04 - 000001702 _____ C:\WINDOWS\system32\.crusader
2021-09-16 00:56 - 2021-09-16 00:56 - 000000733 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\KillEmAll Mini.lnk
2021-09-16 00:55 - 2021-01-27 21:31 - 001044248 _____ (d7xTech, Inc.) C:\Users\kjeff\Desktop\KillEmAll Mini.exe
2021-09-16 00:48 - 2021-09-16 00:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2021-09-16 00:48 - 2021-09-16 00:48 - 000000000 ____D C:\Program Files\HitmanPro
2021-09-16 00:46 - 2021-09-16 05:04 - 000000000 ____D C:\ProgramData\HitmanPro
2021-09-16 00:44 - 2021-09-16 00:44 - 000319274 _____ C:\Users\kjeff\Downloads\KillEmAll_Mini.zip
2021-09-16 00:37 - 2021-09-16 00:37 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Comodo
2021-09-15 23:35 - 2019-08-21 08:02 - 000454616 _____ (COMODO) C:\WINDOWS\system32\cssguard64.dll
2021-09-15 23:35 - 2019-08-21 08:02 - 000341224 _____ (COMODO) C:\WINDOWS\system32\cmdkbdcss64.dll
2021-09-15 23:35 - 2019-08-21 08:02 - 000337856 _____ (COMODO) C:\WINDOWS\SysWOW64\cssguard32.dll
2021-09-15 23:35 - 2019-08-21 08:02 - 000262376 _____ (COMODO) C:\WINDOWS\SysWOW64\cmdkbdcss32.dll
2021-09-15 23:35 - 2018-02-28 08:11 - 000125000 _____ (COMODO) C:\WINDOWS\system32\Drivers\cmdcss.sys
2021-09-15 23:33 - 2021-09-15 23:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2021-09-15 23:33 - 2021-09-15 23:33 - 000000000 ____D C:\Users\kjeff\AppData\Local\Comodo
2021-09-15 23:32 - 2021-09-15 23:34 - 000000000 ____D C:\Program Files (x86)\Comodo
2021-09-15 23:26 - 2021-09-15 23:34 - 000000000 ____D C:\ProgramData\Comodo
2021-09-15 23:26 - 2021-09-15 23:26 - 000000000 ____D C:\ProgramData\Shared Space
2021-09-15 23:20 - 2021-09-15 23:20 - 000000000 ____D C:\Users\kjeff\AppData\LocalLow\iTop Screen Recorder
2021-09-15 23:19 - 2021-09-15 23:19 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\iTop Screenshot
2021-09-15 23:18 - 2021-09-15 23:20 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\iTop Screen Recorder
2021-09-15 23:18 - 2021-09-15 23:20 - 000000000 ____D C:\ProgramData\iTop
2021-09-15 23:18 - 2021-09-15 23:18 - 000002908 _____ C:\WINDOWS\system32\Tasks\IMF_SkipUAC_kjeff
2021-09-15 23:17 - 2021-09-15 23:25 - 000000000 ____D C:\Program Files (x86)\iFun Screen Recorder
2021-09-15 23:16 - 2021-09-16 06:31 - 000000279 _____ C:\Users\kjeff\Desktop\Recycle Bin.lnk
2021-09-15 23:12 - 2021-09-15 23:17 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\IObit
2021-09-15 23:12 - 2021-09-15 23:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2021-09-15 23:12 - 2021-09-15 21:01 - 000037776 _____ (Emsisoft Ltd) C:\WINDOWS\system32\Drivers\eppdisk.sys
2021-09-15 23:12 - 2021-09-15 21:01 - 000016808 _____ (Emsisoft Ltd) C:\WINDOWS\system32\Drivers\EppElam.sys
2021-09-15 23:11 - 2021-09-15 23:17 - 000000000 ____D C:\ProgramData\ProductData
2021-09-15 23:06 - 2021-09-15 23:18 - 000000000 ____D C:\Users\kjeff\AppData\LocalLow\IObit
2021-09-15 23:03 - 2021-09-15 23:03 - 000001246 _____ C:\Users\Public\Desktop\IObit Malware Fighter.lnk
2021-09-15 23:03 - 2021-09-15 23:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
2021-09-15 23:00 - 2021-09-15 23:00 - 000000000 ____D C:\Program Files (x86)\IObit
2021-09-15 22:59 - 2021-09-15 23:18 - 000000000 ____D C:\ProgramData\IObit
2021-09-15 21:51 - 2021-09-16 15:25 - 000000000 ____D C:\FRST
2021-09-15 20:24 - 2021-04-07 22:06 - 000000868 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20210915-202415.backup
2021-09-15 20:22 - 2021-04-07 22:06 - 000000868 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20210915-202220.backup
2021-09-15 20:10 - 2021-09-15 20:10 - 000000000 ___HD C:\$WinREAgent
2021-09-15 20:08 - 2021-09-15 20:09 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-881886857-835413342-2016909866-1001
2021-09-15 20:06 - 2021-09-15 20:09 - 000000000 ____D C:\Users\TEMP
2021-09-15 17:45 - 2021-09-15 17:45 - 000000000 ____D C:\WINDOWS\system32\Tasks\WPD
2021-09-15 17:45 - 2021-09-15 17:45 - 000000000 ____D C:\WINDOWS\system32\Tasks\Lenovo
2021-09-15 17:44 - 2021-09-15 17:44 - 000000000 ____D C:\Safer-Networking Ltd
2021-09-15 17:43 - 2021-09-15 17:47 - 000000000 ____D C:\Users\kjeff\AppData\Local\Safer-Networking Ltd
2021-09-15 17:43 - 2021-09-15 17:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot Anti-Beacon
2021-09-15 17:43 - 2021-09-15 17:43 - 000004464 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1631745798
2021-09-15 17:43 - 2021-09-15 17:43 - 000004210 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1631745780
2021-09-15 17:43 - 2021-09-15 17:43 - 000001399 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
2021-09-15 17:43 - 2021-09-15 17:43 - 000000000 ____D C:\WINDOWS\system32\Tasks\Safer-Networking
2021-09-15 17:43 - 2021-09-15 17:43 - 000000000 ____D C:\Users\kjeff\AppData\Local\Opera Software
2021-09-15 17:43 - 2021-09-15 17:43 - 000000000 ____D C:\Program Files (x86)\Safer-Networking Ltd
2021-09-15 17:42 - 2021-09-16 15:23 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2021-09-15 17:42 - 2021-09-15 17:42 - 000001460 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2021-09-15 17:42 - 2021-09-15 17:42 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Opera Software
2021-09-15 17:42 - 2021-09-15 17:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2021-09-15 17:42 - 2019-06-21 08:34 - 000019904 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\Drivers\Spybot3ELAM.sys
2021-09-15 17:42 - 2018-02-06 19:04 - 000032168 _____ (Safer-Networking Ltd.) C:\WINDOWS\system32\sdnclean64.exe
2021-09-15 17:41 - 2021-09-16 15:23 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2021-09-15 17:34 - 2021-09-15 17:34 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2021-09-15 17:34 - 2021-09-15 17:34 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\adaware
2021-09-15 17:34 - 2021-09-15 17:34 - 000000000 ____D C:\Users\kjeff\AppData\Local\AdAwareDesktop
2021-09-15 17:33 - 2021-09-15 17:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\adaware
2021-09-15 17:33 - 2021-09-15 17:33 - 000000000 ____D C:\Program Files\adaware
2021-09-15 17:30 - 2021-09-15 20:06 - 000000542 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task c0c5032c-90cd-4cc3-b268-6bd5debf4856.job
2021-09-15 17:30 - 2021-09-15 20:06 - 000000542 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 96bbc763-d277-4bed-b479-c904faeb193f.job
2021-09-15 17:30 - 2021-09-15 17:30 - 000003782 _____ C:\WINDOWS\system32\Tasks\SUPERAntiSpyware Scheduled Task 96bbc763-d277-4bed-b479-c904faeb193f
2021-09-15 17:30 - 2021-09-15 17:30 - 000003700 _____ C:\WINDOWS\system32\Tasks\SUPERAntiSpyware Scheduled Task c0c5032c-90cd-4cc3-b268-6bd5debf4856
2021-09-15 17:30 - 2021-09-15 17:30 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\SUPERAntiSpyware.com
2021-09-15 17:30 - 2021-09-15 17:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2021-09-15 17:30 - 2021-09-15 17:30 - 000000000 ____D C:\ProgramData\adaware
2021-09-15 17:29 - 2021-09-15 17:30 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2021-09-15 17:29 - 2021-09-15 17:29 - 000000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2021-09-15 16:41 - 2021-09-15 16:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2021-09-15 02:03 - 2021-09-15 02:03 - 000001361 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1Password.lnk
2021-09-15 02:02 - 2021-09-15 02:02 - 000000000 ____D C:\Users\kjeff\AppData\Local\1Password
2021-09-14 02:57 - 2021-09-14 02:57 - 000000000 ____D C:\Users\kjeff\Documents\Ampeg
2021-09-13 05:58 - 2021-09-13 05:58 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2021-09-13 05:58 - 2021-09-13 05:58 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2021-09-13 05:58 - 2021-09-13 05:58 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2021-09-13 05:58 - 2021-09-13 05:58 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx.sys
2021-09-13 05:58 - 2021-09-13 05:58 - 000044328 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2021-09-13 02:57 - 2021-09-13 02:57 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Goldberg SocialClub Emu Saves
2021-09-13 02:56 - 2021-09-13 02:56 - 000000000 ____D C:\Users\kjeff\Documents\Rockstar Games
2021-09-13 02:56 - 2021-09-13 02:56 - 000000000 ____D C:\Users\kjeff\AppData\Local\Rockstar Games
2021-09-13 02:55 - 2021-09-13 02:55 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\EMPRESS
2021-09-12 07:16 - 2021-09-12 07:16 - 000000745 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Red Dead Redemption 2.lnk
2021-09-12 07:13 - 2021-04-07 22:06 - 000000868 ____R C:\WINDOWS\system32\Drivers\etc\hosts.check
2021-09-12 07:13 - 2021-04-07 22:06 - 000000868 ____R C:\WINDOWS\system32\Drivers\etc\hosts.backup
2021-09-12 07:12 - 2021-09-12 07:13 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2021-09-12 03:35 - 2021-09-12 04:11 - 000000583 _____ C:\Users\Public\Desktop\Red Dead Redemption 2.lnk
2021-09-12 00:25 - 2021-09-12 00:25 - 000000828 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Projects.lnk
2021-09-11 21:16 - 2021-09-11 21:19 - 000262176 _____ C:\Users\kjeff\Downloads\keylabmkII_Firmware_Update_1_2_4_1091.led
2021-09-11 21:16 - 2021-09-11 21:19 - 000000107 _____ C:\Users\kjeff\Downloads\keylabmkII_Firmware_Update_1_2_4_1091.led.confirm
2021-09-11 21:13 - 2021-09-11 21:13 - 000000979 _____ C:\Users\kjeff\Desktop\Piano V2.lnk
2021-09-11 21:10 - 2021-09-11 21:10 - 000001027 _____ C:\Users\kjeff\Desktop\Analog Lab V.lnk
2021-09-11 20:27 - 2021-09-11 21:12 - 000000000 ____D C:\Program Files\Arturia
2021-09-11 20:26 - 2021-09-12 05:56 - 000001334 _____ C:\Users\kjeff\Desktop\MIDI Control Center.lnk
2021-09-11 20:20 - 2021-09-13 06:05 - 000000000 ____D C:\Users\kjeff\Downloads\Arturia
2021-09-11 20:19 - 2021-09-11 21:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Arturia
2021-09-11 20:19 - 2021-09-11 21:02 - 000001382 _____ C:\Users\kjeff\Desktop\Arturia Software Center.lnk
2021-09-11 20:13 - 2021-09-11 20:13 - 000000000 ____D C:\Users\kjeff\Documents\BIAS_PD_BACKUP-8909B942-B5B0-451C-A981-A17EDA6E8226
2021-09-11 20:13 - 2021-09-11 20:13 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Ampeg
2021-09-11 04:23 - 2021-09-16 05:06 - 188743680 _____ C:\WINDOWS\system32\config\SOFTWARE
2021-09-11 02:03 - 2021-09-11 02:03 - 000424307 _____ C:\Users\kjeff\Downloads\SweetwaterInvoice_28826011.pdf
2021-09-11 01:16 - 2021-09-11 01:16 - 000000000 ____D C:\WINDOWS\Panther
2021-09-10 21:07 - 2021-09-10 21:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Line 6
2021-09-10 21:06 - 2021-09-10 21:07 - 000000000 ____D C:\ProgramData\Ampeg
2021-09-10 21:05 - 2021-09-11 20:13 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Line 6
2021-09-10 21:05 - 2021-09-10 21:05 - 000000000 ____D C:\ProgramData\Line 6
2021-09-10 21:00 - 2021-09-11 20:13 - 000000000 ____D C:\Users\kjeff\Documents\BIAS_Pedal
2021-09-10 20:56 - 2021-09-13 01:47 - 000000000 ____D C:\Users\Public\Documents\NI Resources
2021-09-10 20:56 - 2021-09-10 20:56 - 000000000 ____D C:\Users\kjeff\AppData\Local\Native Instruments
2021-09-10 20:56 - 2021-09-10 20:56 - 000000000 ____D C:\Users\kjeff\AppData\Local\Guitar Rig 6
2021-09-10 20:54 - 2021-09-10 20:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments
2021-09-10 20:53 - 2021-09-10 20:56 - 000000000 ___RD C:\Users\kjeff\Documents\Native Instruments
2021-09-10 20:53 - 2021-09-10 20:53 - 000000000 _RSHD C:\Users\Public\Documents\Native Instruments
2021-09-10 20:53 - 2021-09-10 20:53 - 000000000 ___RD C:\Program Files\Native Instruments
2021-09-10 20:53 - 2020-10-06 02:03 - 003578488 _____ () C:\WINDOWS\system32\qtANGLE.dll
2021-09-10 20:45 - 2021-09-11 01:24 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-09-10 20:45 - 2021-09-10 20:45 - 000210344 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2021-09-10 20:45 - 2021-09-10 20:45 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-09-10 20:45 - 2021-09-10 20:44 - 000160176 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2021-09-10 20:45 - 2021-09-10 20:44 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2021-09-10 20:44 - 2021-09-10 20:44 - 000000000 ____D C:\ProgramData\Malwarebytes
2021-09-10 20:38 - 2021-09-10 20:38 - 000000000 ____D C:\Users\kjeff\AppData\Local\AAA_Internet_Publishing_I
2021-09-10 20:37 - 2021-09-10 20:38 - 000000000 ____D C:\Program Files (x86)\wtfast
2021-09-10 20:37 - 2021-09-10 20:37 - 000001048 _____ C:\Users\Public\Desktop\wtfast.lnk
2021-09-10 20:37 - 2021-09-10 20:37 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_WtfEngineDrv_01009.Wdf
2021-09-10 20:37 - 2021-09-10 20:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wtfast
2021-09-10 20:37 - 2020-05-15 11:21 - 000041704 _____ (AAA Internet Publishing, Inc.) C:\WINDOWS\system32\Drivers\WtfEngineDrv.sys
2021-09-10 20:30 - 2021-09-10 20:31 - 000003758 _____ C:\WINDOWS\system32\Tasks\WpsUpdateTask_kjeff
2021-09-10 20:30 - 2021-09-10 20:30 - 000004076 _____ C:\WINDOWS\system32\Tasks\WpsExternal_kjeff_20210910203048
2021-09-10 07:01 - 2021-09-10 07:06 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Blue Cat Audio
2021-09-10 07:01 - 2021-09-10 07:01 - 000000000 ____D C:\Users\kjeff\Documents\Blue Cat Audio
2021-09-10 06:50 - 2021-09-10 06:54 - 000000000 ____D C:\Program Files\Blue Cat Audio
2021-09-10 06:37 - 2021-09-10 06:37 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\PositiveGrid
2021-09-10 06:24 - 2021-09-10 06:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BIAS Amp 2
2021-09-10 06:21 - 2021-09-10 21:00 - 000000000 ___RD C:\Program Files\Common Files\PositiveGrid
2021-09-10 06:21 - 2021-09-10 06:21 - 000000000 ____D C:\Users\kjeff\Documents\PositiveGrid
2021-09-09 04:57 - 2021-09-10 03:11 - 000000924 _____ C:\Users\Public\Desktop\Overwatch.lnk
2021-09-09 04:20 - 2021-09-09 04:20 - 000170496 _____ C:\WINDOWS\system32\DeviceUpdateCenterCsp.dll
2021-09-09 04:19 - 2021-09-09 04:19 - 001313608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-09-09 04:19 - 2021-09-09 04:19 - 000672768 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2021-09-09 04:19 - 2021-09-09 04:19 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-09-09 04:19 - 2021-09-09 04:19 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-09-09 04:19 - 2021-09-09 04:19 - 000011345 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-09-09 04:18 - 2021-09-09 04:18 - 002295296 _____ (Digimarc) C:\WINDOWS\system32\DMRCDecoder.dll
2021-09-09 04:18 - 2021-09-09 04:18 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2021-09-09 04:18 - 2021-09-09 04:18 - 002111488 _____ (Digimarc) C:\WINDOWS\SysWOW64\DMRCDecoder.dll
2021-09-09 04:18 - 2021-09-09 04:18 - 001823304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-09-09 04:18 - 2021-09-09 04:18 - 001393480 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-09-09 04:18 - 2021-09-09 04:18 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2021-09-09 04:18 - 2021-09-09 04:18 - 001163776 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2021-09-09 04:18 - 2021-09-09 04:18 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe
2021-09-09 04:18 - 2021-09-09 04:18 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2021-09-09 04:18 - 2021-09-09 04:18 - 000162816 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2021-09-09 04:18 - 2021-09-09 04:18 - 000098816 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-09-09 03:41 - 2021-09-09 03:45 - 000000000 ___RD C:\Users\kjeff\Documents\DMGAudio
2021-09-09 03:41 - 2021-09-09 03:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DMGAudio
2021-09-09 02:55 - 2021-09-09 02:56 - 000000000 ____D C:\Users\kjeff\Desktop\Cracks
2021-09-09 00:19 - 2021-09-09 03:28 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Xfer
2021-09-09 00:15 - 2021-09-09 02:05 - 000000000 ____D C:\Users\kjeff\Documents\Xfer
2021-09-09 00:15 - 2021-09-09 00:19 - 000000000 ____D C:\Users\kjeff\AppData\Local\Xfer
2021-09-09 00:03 - 2021-09-09 00:04 - 000000000 ____D C:\Users\kjeff\Desktop\Packs
2021-09-08 23:54 - 2021-09-12 00:55 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Maize Sampler Player
2021-09-07 22:27 - 2021-09-07 22:27 - 000000000 ____D C:\Users\kjeff\AppData\LocalLow\Nomada
2021-09-07 05:20 - 2021-08-28 07:25 - 001858664 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2021-09-07 05:20 - 2021-08-28 07:25 - 001858664 _____ C:\WINDOWS\system32\vulkaninfo.exe
2021-09-07 05:20 - 2021-08-28 07:25 - 001474704 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2021-09-07 05:20 - 2021-08-28 07:25 - 001438848 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-09-07 05:20 - 2021-08-28 07:25 - 001438848 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2021-09-07 05:20 - 2021-08-28 07:25 - 001212536 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2021-09-07 05:20 - 2021-08-28 07:25 - 001097856 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2021-09-07 05:20 - 2021-08-28 07:25 - 001097856 _____ C:\WINDOWS\system32\vulkan-1.dll
2021-09-07 05:20 - 2021-08-28 07:25 - 000951936 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2021-09-07 05:20 - 2021-08-28 07:25 - 000951936 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2021-09-07 05:20 - 2021-08-28 07:22 - 001520760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2021-09-07 05:20 - 2021-08-28 07:22 - 001171064 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2021-09-07 05:20 - 2021-08-28 07:22 - 000716920 _____ C:\WINDOWS\system32\nvofapi64.dll
2021-09-07 05:20 - 2021-08-28 07:22 - 000676480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2021-09-07 05:20 - 2021-08-28 07:22 - 000645240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2021-09-07 05:20 - 2021-08-28 07:22 - 000577168 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2021-09-07 05:20 - 2021-08-28 07:22 - 000564344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2021-09-07 05:20 - 2021-08-28 07:21 - 002112128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2021-09-07 05:20 - 2021-08-28 07:21 - 001595536 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2021-09-07 05:20 - 2021-08-28 07:21 - 000919184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2021-09-07 05:20 - 2021-08-28 07:21 - 000706192 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2021-09-07 05:20 - 2021-08-28 07:20 - 008854144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2021-09-07 05:20 - 2021-08-28 07:20 - 007920760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2021-09-07 05:20 - 2021-08-28 07:20 - 005681280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2021-09-07 05:20 - 2021-08-28 07:20 - 004987512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2021-09-07 05:20 - 2021-08-28 07:20 - 002925688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2021-09-07 05:20 - 2021-08-28 07:20 - 000447104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2021-09-07 05:20 - 2021-08-28 07:19 - 000849016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2021-09-07 05:20 - 2021-08-27 11:54 - 000083133 _____ C:\WINDOWS\system32\nvinfo.pb
2021-09-07 03:51 - 2021-09-07 17:12 - 000000000 ____D C:\Users\kjeff\Documents\Splice
2021-09-07 03:48 - 2021-09-16 15:21 - 000000000 ____D C:\Users\kjeff\AppData\Local\SpliceSettings
2021-09-07 03:48 - 2021-09-07 03:49 - 000000000 ____D C:\Users\kjeff\AppData\Local\splice
2021-09-07 03:48 - 2021-09-07 03:48 - 000002215 _____ C:\Users\kjeff\Desktop\Splice.lnk
2021-09-07 03:48 - 2021-09-07 03:48 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Splice
2021-09-07 03:48 - 2021-09-07 03:48 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Splice
2021-09-07 01:44 - 2021-09-07 01:44 - 000001312 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\12M.lnk
2021-09-07 00:31 - 2021-09-07 00:31 - 000000223 _____ C:\Users\kjeff\Desktop\Twelve Minutes.url
2021-09-05 03:36 - 2021-09-05 03:40 - 000000000 ____D C:\Users\kjeff\Desktop\Arturia
2021-09-05 00:26 - 2021-09-12 00:33 - 000000000 ____D C:\Users\kjeff\Documents\Arturia mkii
2021-09-03 21:54 - 2021-09-03 21:59 - 000000000 ____D C:\Users\kjeff\Documents\XLN.Audio.RC-20.Retro.Color.v1.1.1.2.Incl.Patched.and.Keygen-R2R
2021-09-03 05:59 - 2021-09-03 05:59 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Voxengo
2021-08-31 03:52 - 2021-09-11 21:12 - 000000000 ___RD C:\ProgramData\Arturia
2021-08-31 03:52 - 2021-09-11 20:26 - 000000000 _RSHD C:\Program Files (x86)\Arturia
2021-08-31 03:40 - 2021-09-11 22:43 - 000000032 _____ C:\Users\kjeff\AppData\Roaming\msregsvv.dll
2021-08-31 03:40 - 2021-09-11 22:43 - 000000032 _____ C:\ProgramData\autobk.inc
2021-08-31 03:40 - 2021-09-10 04:26 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\IK Multimedia
2021-08-31 03:38 - 2021-09-10 04:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IK Multimedia
2021-08-31 03:37 - 2021-09-10 04:24 - 000000000 ____D C:\Users\kjeff\Documents\IK Multimedia
2021-08-31 03:37 - 2021-09-10 04:19 - 000000000 ____D C:\Program Files\IK Multimedia
2021-08-31 03:37 - 2021-08-31 03:37 - 000000000 ____D C:\Program Files\VstPlugIns
2021-08-31 03:03 - 2021-08-31 03:03 - 000000000 ____D C:\Users\kjeff\Documents\FabFilter
2021-08-31 03:03 - 2021-08-31 03:03 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\FabFilter
2021-08-31 03:01 - 2021-08-31 03:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FabFilter
2021-08-31 03:01 - 2021-08-31 03:01 - 000000000 ____D C:\Program Files (x86)\FabFilter
2021-08-31 02:58 - 2021-08-31 02:58 - 000000000 ____D C:\Program Files\Voxengo
2021-08-31 02:47 - 2021-08-31 02:47 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\UJAM
2021-08-31 02:44 - 2021-08-31 02:44 - 000000000 ____D C:\ProgramData\UJAM
2021-08-31 02:44 - 2021-08-31 02:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UJAM
2021-08-31 02:39 - 2021-08-31 02:39 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Antares
2021-08-31 02:18 - 2021-09-03 05:53 - 000000000 ____D C:\Users\kjeff\Documents\RC-20 Retro Color Logs
2021-08-31 02:18 - 2021-08-31 02:18 - 000000000 ____D C:\Users\kjeff\Documents\RC-20 Retro Color
2021-08-31 02:16 - 2021-09-09 03:45 - 000000000 ____D C:\Program Files\Steinberg
2021-08-31 02:08 - 2021-08-31 02:17 - 000000000 ____D C:\ProgramData\XLN Audio
2021-08-31 02:08 - 2021-08-31 02:08 - 000000000 ____D C:\Users\kjeff\Documents\XLN Online Installer
2021-08-31 02:08 - 2021-08-31 02:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XLN Audio
2021-08-31 02:08 - 2021-08-31 02:08 - 000000000 ____D C:\Program Files\XLN Audio
2021-08-31 00:09 - 2021-08-31 00:09 - 000000000 ____D C:\Program Files\Antares
2021-08-30 07:45 - 2021-08-30 07:45 - 000000000 __SHD C:\ProgramData\win-net
2021-08-30 07:20 - 2021-09-12 00:02 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Eventide
2021-08-30 07:20 - 2021-08-30 07:20 - 000000000 ____D C:\Users\kjeff\AppData\Local\Lethal
2021-08-30 07:09 - 2021-08-30 07:18 - 000000000 ____D C:\Program Files\AbletonPlugins
2021-08-30 06:59 - 2021-08-31 00:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antares
2021-08-30 06:02 - 2021-09-11 21:12 - 000000000 ____D C:\Program Files\Common Files\VST3
2021-08-30 06:02 - 2021-08-30 06:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eventide
2021-08-30 06:01 - 2021-08-30 06:31 - 000000000 ____D C:\Users\kjeff\Documents\Eventide
2021-08-30 04:22 - 2021-08-30 04:22 - 000001254 _____ C:\Users\kjeff\Documents\Adobe After Effects 2020 v17.1.3.41 (x64) Patched - Shortcut.lnk
2021-08-30 04:14 - 2021-09-11 21:12 - 000000000 ____D C:\Program Files\VST_Plugins
2021-08-30 04:11 - 2021-09-10 20:53 - 000000000 ___RD C:\Program Files\Common Files\Native Instruments
2021-08-30 04:11 - 2021-08-30 04:11 - 000000000 __SHD C:\Users\kjeff\AppData\Local\ms-drivers
2021-08-30 04:11 - 2021-08-30 04:11 - 000000000 __SHD C:\Users\kjeff\AppData\Local\icsxml
2021-08-30 04:11 - 2021-08-30 04:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lethal
2021-08-30 04:11 - 2021-08-30 04:11 - 000000000 ____D C:\Program Files\Lethal
2021-08-30 02:37 - 2021-04-07 22:11 - 000284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthA2dp.sys
2021-08-29 07:12 - 2021-08-29 07:12 - 000057085 _____ C:\Users\kjeff\Desktop\Authorize.auz
2021-08-29 07:08 - 2021-08-29 07:08 - 000000000 ____D C:\Users\kjeff\Documents\Ableton
2021-08-29 06:51 - 2021-08-29 06:51 - 000000871 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ableton Live 11 Suite.lnk
2021-08-29 06:09 - 2021-08-29 06:15 - 000000000 ____D C:\Users\kjeff\Desktop\Vip.Soundlab.Trap.Beast.HD.Drums.and.Kontakt
2021-08-29 05:36 - 2021-09-09 00:05 - 000000000 ____D C:\Users\kjeff\Documents\Beatskillz - Synthwave Drums 1.0.0 VSTi x86 x64
2021-08-29 04:30 - 2021-08-29 06:12 - 000000000 ____D C:\Users\kjeff\AppData\Local\BitTorrentHelper
2021-08-29 04:30 - 2021-08-29 04:31 - 000000000 ____D C:\Users\kjeff\AppData\LocalLow\BitTorrent
2021-08-29 04:29 - 2021-08-29 06:10 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\BitTorrent
2021-08-29 04:28 - 2021-08-29 04:28 - 000000000 ____D C:\Users\kjeff\AppData\Local\Adaware
2021-08-29 00:55 - 2021-08-29 00:55 - 000000000 ____D C:\ProgramData\inMusic
2021-08-28 06:37 - 2021-08-28 06:42 - 000000000 ____D C:\Users\kjeff\Documents\Track Session
2021-08-28 03:23 - 2021-08-28 03:23 - 000000722 _____ C:\Users\kjeff\AppData\Roaming\PureRef.ini
2021-08-27 20:27 - 2021-09-11 04:23 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
2021-08-27 17:09 - 2021-08-27 17:10 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Process Hacker 2
2021-08-27 15:51 - 2021-08-29 06:52 - 000000000 ____D C:\ProgramData\Ableton
2021-08-27 15:42 - 2021-08-27 15:42 - 000000000 ____D C:\Users\kjeff\Documents\FeedbackHub
2021-08-27 15:17 - 2021-08-27 15:17 - 000001372 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Misc_Apps - Shortcut.lnk
2021-08-27 15:16 - 2021-08-27 15:17 - 000000000 ____D C:\Program Files\Misc_Apps
2021-08-27 15:07 - 2021-08-27 15:08 - 000000691 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notes.lnk
2021-08-27 15:06 - 2021-09-10 06:04 - 000000000 ____D C:\Users\kjeff\Documents\Notes
2021-08-27 15:06 - 2021-08-27 15:06 - 000001385 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Task Scheduler.lnk
2021-08-27 15:01 - 2021-08-27 15:01 - 000002178 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Canvas Pen.lnk
2021-08-27 14:33 - 2021-08-27 14:33 - 000001044 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z.lnk
2021-08-27 14:33 - 2021-08-27 14:33 - 000000000 ____D C:\Program Files (x86)\GPU-Z
2021-08-27 14:19 - 2021-08-27 14:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Process Hacker 2
2021-08-27 14:19 - 2021-08-27 14:19 - 000000000 ____D C:\Program Files\Process Hacker 2
2021-08-26 05:36 - 2021-08-26 05:36 - 000000279 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recycle Bin.lnk
2021-08-26 05:16 - 2021-09-16 00:41 - 000000000 ___HD C:\SandBlastBackup
2021-08-26 04:57 - 2021-08-26 04:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZoneAlarm
2021-08-26 04:56 - 2020-02-20 19:50 - 000023528 _____ (Check Point Software Technologies) C:\WINDOWS\system32\Drivers\epelam.sys
2021-08-26 04:55 - 2021-08-26 04:55 - 000003462 _____ C:\WINDOWS\system32\Tasks\CheckPointUpdateTaskMachineUA
2021-08-26 04:55 - 2021-08-26 04:55 - 000003338 _____ C:\WINDOWS\system32\Tasks\CheckPointUpdateTaskMachineCore
2021-08-26 04:55 - 2021-08-26 04:55 - 000000000 ____D C:\Users\kjeff\AppData\Local\CheckPoint
2021-08-26 04:39 - 2021-08-26 04:56 - 000000000 ____D C:\Program Files (x86)\CheckPoint
2021-08-26 04:39 - 2021-08-26 04:39 - 000435647 _____ C:\WINDOWS\system32\Drivers\vsconfig.xml
2021-08-26 04:39 - 2021-08-26 04:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point
2021-08-26 04:39 - 2021-08-26 04:39 - 000000000 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts
2021-08-26 04:38 - 2021-08-26 04:57 - 000000000 ____D C:\ProgramData\CheckPoint
2021-08-25 14:43 - 2021-08-25 18:51 - 000003858 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2021-08-25 14:43 - 2021-08-25 18:51 - 000003416 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2021-08-25 01:05 - 2021-08-25 01:05 - 000000000 ____D C:\Users\kjeff\AppData\Local\ESET
2021-08-25 01:04 - 2021-08-25 14:44 - 000000000 ____D C:\KVRT2020_Data
2021-08-25 00:33 - 2021-08-25 00:33 - 000000000 ____D C:\Users\kjeff\AppData\Local\mbam
2021-08-25 00:32 - 2021-08-25 00:32 - 000000000 ____D C:\Program Files\Malwarebytes
2021-08-24 23:24 - 2021-08-24 23:58 - 000000000 ____D C:\ProgramData\regid.1993-06.com.microsoft
2021-08-24 23:24 - 2021-08-24 23:54 - 000000000 ____D C:\Program Files (x86)\Sofware IN LLC
2021-08-24 23:24 - 2021-08-24 23:24 - 000000000 ____D C:\Users\kjeff\AppData\Local\NetSupport
2021-08-24 22:59 - 2021-08-25 00:48 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\qBittorrent
2021-08-24 22:59 - 2021-08-24 22:59 - 000000000 ____D C:\Users\kjeff\AppData\Local\qBittorrent
2021-08-24 21:59 - 2021-08-24 21:59 - 000000000 ____D C:\Users\kjeff\AppData\Local\Melodics
2021-08-24 21:50 - 2021-08-24 21:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Melodics
2021-08-24 21:49 - 2021-08-24 21:50 - 000000000 ____D C:\Program Files\Melodics
2021-08-23 21:12 - 2021-08-23 21:12 - 000000000 ____D C:\Users\kjeff\Documents\Bluetooth Exchange Folder
2021-08-23 21:12 - 2021-08-23 21:12 - 000000000 ____D C:\Users\kjeff\AppData\Local\Broadcom
2021-08-23 21:11 - 2021-08-23 21:11 - 000000000 ____D C:\Program Files\WIDCOMM
2021-08-23 21:11 - 2016-02-17 14:00 - 000213312 _____ (Broadcom Corporation.) C:\WINDOWS\system32\Drivers\btwampfl.sys
2021-08-23 21:11 - 2016-02-17 14:00 - 000186152 _____ (Broadcom Corporation.) C:\WINDOWS\system32\Drivers\bcbtums.sys
2021-08-23 21:11 - 2015-12-16 22:18 - 000049952 _____ (Broadcom Corporation.) C:\WINDOWS\system32\Drivers\btwl2cap.sys
2021-08-23 21:11 - 2015-12-09 18:47 - 000262440 _____ (Broadcom Corporation.) C:\WINDOWS\system32\Drivers\btwavdt.sys
2021-08-23 21:11 - 2015-12-09 18:47 - 000212760 _____ (Broadcom Corporation.) C:\WINDOWS\system32\Drivers\btwaudio.sys
2021-08-23 21:11 - 2015-11-04 14:40 - 000047392 _____ (Broadcom Corporation.) C:\WINDOWS\system32\Drivers\btwrchid.sys
2021-08-23 21:11 - 2015-08-05 12:19 - 000071148 _____ C:\WINDOWS\system32\Drivers\BCM20702A1_001.002.014.1502.1764.hex
2021-08-20 00:34 - 2021-08-20 00:35 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.9
2021-08-20 00:34 - 2021-08-20 00:34 - 000000000 ____D C:\Users\kjeff\AppData\Local\Package Cache
2021-08-18 20:05 - 2021-08-18 20:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2021-08-18 20:04 - 2021-08-18 20:05 - 000000000 ____D C:\Program Files\iTunes
2021-08-18 20:02 - 2021-08-18 20:02 - 000000000 ____D C:\Users\kjeff\AppData\Local\Apple Inc
2021-08-18 20:01 - 2021-08-18 20:01 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Apple Computer
2021-08-18 20:01 - 2021-08-18 20:01 - 000000000 ____D C:\Users\kjeff\AppData\Local\Apple Computer
2021-08-18 20:01 - 2021-08-18 20:01 - 000000000 ____D C:\ProgramData\Apple Computer
2021-08-18 19:57 - 2021-08-18 19:57 - 000002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2021-08-18 19:57 - 2021-08-18 19:57 - 000000000 ____D C:\WINDOWS\system32\Tasks\Apple
2021-08-18 19:57 - 2021-08-18 19:57 - 000000000 ____D C:\Users\kjeff\AppData\Local\Apple
2021-08-18 19:57 - 2021-08-18 19:57 - 000000000 ____D C:\Program Files\Common Files\Apple
2021-08-18 19:57 - 2021-08-18 19:57 - 000000000 ____D C:\Program Files\Bonjour
2021-08-18 19:57 - 2021-08-18 19:57 - 000000000 ____D C:\Program Files (x86)\Bonjour
2021-08-18 19:57 - 2021-08-18 19:57 - 000000000 ____D C:\Program Files (x86)\Apple Software Update
2021-08-18 07:05 - 2021-08-18 07:05 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Audient
2021-08-18 06:59 - 2021-08-18 06:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audient
2021-08-18 06:58 - 2021-07-12 04:10 - 000381496 _____ () C:\WINDOWS\system32\Drivers\audientusbaudio.sys
2021-08-18 06:58 - 2021-07-12 04:10 - 000053816 _____ () C:\WINDOWS\system32\Drivers\audientusbaudioks.sys
2021-08-18 06:14 - 2021-08-18 06:59 - 000000000 ____D C:\Program Files\Audient
2021-08-18 04:58 - 2021-08-18 04:58 - 000000000 ____D C:\WINDOWS\system32\configBak
2021-08-18 04:43 - 2021-08-18 04:43 - 000000000 ____D C:\WINDOWS\system32\config\backup
2021-08-18 04:35 - 2021-08-18 04:35 - 000000000 ____D C:\EFI
2021-08-17 05:55 - 2021-08-18 03:37 - 000011520 _____ C:\WINDOWS\PE_Rom.dll
2021-08-17 05:52 - 2021-08-17 05:52 - 000000000 _____ C:\WINDOWS\SysWOW64\Drivers\1043_ASUSTeK_ROG STRIX B450-F GAMING.alu
2021-08-17 05:45 - 2021-08-27 15:14 - 000000000 ____D C:\ProgramData\SS3
2021-08-17 05:45 - 2021-08-18 02:22 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2021-08-17 05:45 - 2021-08-17 05:45 - 000002463 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sonic Studio 3.lnk
2021-08-17 05:45 - 2021-08-17 05:45 - 000002455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sonic Radar 3.lnk
2021-08-17 05:45 - 2021-08-17 05:45 - 000000000 ____D C:\Program Files\Realtek
2021-08-17 05:45 - 2021-08-17 05:45 - 000000000 ____D C:\Program Files\ASUSTeKcomputer.Inc
2021-08-17 05:45 - 2019-07-03 14:01 - 015218512 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE3.dll
2021-08-17 05:45 - 2019-07-03 14:01 - 003306704 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll
2021-08-17 05:45 - 2019-07-03 14:01 - 002197872 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll
2021-08-17 05:45 - 2019-07-03 14:01 - 001382128 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll
2021-08-17 05:45 - 2019-07-03 14:01 - 001337528 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaeapo64.dll
2021-08-17 05:45 - 2019-07-03 14:01 - 000852024 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tosasfapo64.dll
2021-08-17 05:45 - 2019-07-03 14:01 - 000604688 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaemaxapo64.dll
2021-08-17 05:45 - 2019-07-03 14:01 - 000447072 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\toseaeapo64.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 072520600 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
2021-08-17 05:44 - 2019-07-03 17:00 - 007178360 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 007101632 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 006886992 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2021-08-17 05:44 - 2019-07-03 17:00 - 006270080 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 003676960 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2021-08-17 05:44 - 2019-07-03 17:00 - 003159664 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 002930040 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 001159072 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 001003744 _____ (Nahimic Inc) C:\WINDOWS\system32\NahimicAPONSControl.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 000416400 _____ (Harman) C:\WINDOWS\system32\HMUI.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 000378272 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 000266440 _____ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 000154256 _____ (Harman) C:\WINDOWS\system32\HarmanAudioInterface.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 000122208 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 000118480 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 000105200 _____ C:\WINDOWS\system32\audioLibVc.dll
2021-08-17 05:44 - 2019-07-03 17:00 - 000023584 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 003445632 _____ (DTS, Inc.) C:\WINDOWS\system32\slcnt64.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 003168280 _____ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 001435032 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 001110064 _____ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 000964912 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 000873352 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 000541008 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 000467048 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 000381296 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 000341040 _____ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 000341040 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 000230592 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 000218160 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 000174832 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 000158584 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll
2021-08-17 05:44 - 2019-07-03 14:01 - 000075432 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 006463760 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV3apo.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 005938800 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV2apo.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 005593504 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICAPOlfx.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 005347096 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 003753024 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 003340296 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 003266984 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 002992288 _____ (Audyssey Labs) C:\WINDOWS\system32\AudysseyEfx.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 002444792 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001971472 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001965264 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001788064 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001611064 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyAPOv251gm.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001598504 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001544360 _____ (Dolby Laboratories) C:\WINDOWS\system32\DAX3APOProp.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001516376 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001396840 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001386680 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDHF64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001372496 _____ (Dolby Laboratories) C:\WINDOWS\system32\DAX3APOv251.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001353208 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001294184 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001287704 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyAPOvlldpgm.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001259832 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOvlldp.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001180792 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001078576 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SEHDHF32.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 001061464 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000934848 _____ (ICEpower A/S) C:\WINDOWS\system32\ICEsoundAPO64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000751408 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000734880 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000715752 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000692056 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000511776 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000453168 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000452840 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000448712 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000406560 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2APIPCLL.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000392760 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000367712 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000366224 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\HMAPO.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000360448 _____ (Harman) C:\WINDOWS\system32\HMClariFi.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000343600 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000333112 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000327160 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000327160 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000316080 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000278376 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000261336 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000261304 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000260320 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000231808 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000220280 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000203944 _____ (Harman) C:\WINDOWS\system32\HMHVS.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000192872 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000191040 _____ (Harman) C:\WINDOWS\system32\HMEQ_Voice.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000191040 _____ (Harman) C:\WINDOWS\system32\HMEQ.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000179728 _____ (Harman) C:\WINDOWS\system32\HMLimiter.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000167224 _____ (ASUSTeK COMPUTER INC.) C:\WINDOWS\system32\ATKWMI.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000157232 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000139648 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000116432 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000093792 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000090808 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000090064 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000088208 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
2021-08-17 05:44 - 2019-07-03 14:00 - 000083512 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
2021-08-17 05:44 - 2019-07-03 13:29 - 033399859 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2021-08-17 05:44 - 2019-07-03 13:29 - 005804772 _____ C:\WINDOWS\system32\Drivers\rtvienna.dat
2021-08-17 05:43 - 2020-10-15 13:59 - 000034064 ____N (ASUSTeK Computer Inc.) C:\WINDOWS\system32\Drivers\IOMap64.sys
2021-08-17 05:40 - 2019-07-02 03:58 - 000034112 _____ C:\WINDOWS\SysWOW64\Drivers\AsUpIO.sys
2021-08-17 05:39 - 2021-08-17 05:40 - 000000000 ____D C:\WINDOWS\system32\Tasks\ASUS
2021-08-17 05:30 - 2021-08-17 05:30 - 000003228 _____ C:\WINDOWS\system32\Tasks\SS3svc64Run
2021-08-17 05:28 - 2021-08-17 05:29 - 000000000 ____D C:\AMD
2021-08-17 05:28 - 2021-08-17 05:28 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\AMD
2021-08-17 05:28 - 2021-08-17 05:28 - 000000000 ____D C:\Users\kjeff\AppData\Local\setup
2021-08-17 05:28 - 2021-08-17 05:28 - 000000000 ____D C:\Program Files (x86)\AMD
2021-08-17 05:23 - 2021-08-17 05:23 - 000003220 _____ C:\WINDOWS\system32\Tasks\SS3svc32Run
2021-08-17 05:22 - 2021-08-18 02:22 - 000000000 ____D C:\WINDOWS\system32\RTCOM
2021-08-17 05:22 - 2021-08-17 05:45 - 000000000 ___HD C:\Program Files (x86)\Temp
2021-08-17 05:22 - 2021-08-17 05:45 - 000000000 ____D C:\WINDOWS\system32\DAX3
2021-08-17 05:22 - 2021-08-17 05:45 - 000000000 ____D C:\WINDOWS\system32\DAX2
2021-08-17 05:22 - 2021-08-17 05:45 - 000000000 ____D C:\ProgramData\Audyssey Labs
2021-08-17 05:22 - 2021-08-17 05:22 - 000000000 ____H C:\ProgramData\DP45977C.lfl
2021-08-17 05:22 - 2019-04-15 07:13 - 002856624 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtlExUpd.dll
2021-08-12 04:25 - 2021-08-28 07:18 - 006216336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2021-08-12 02:56 - 2021-08-27 15:10 - 000000000 ____D C:\Program Files (x86)\SpeedFan
2021-08-12 02:56 - 2021-08-12 02:56 - 000000045 _____ C:\WINDOWS\SysWOW64\initdebug.nfo
2021-08-12 02:47 - 2021-08-12 02:47 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2021-08-12 02:47 - 2021-08-12 02:47 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2021-08-10 00:07 - 2021-08-10 00:12 - 000000000 ____D C:\Users\kjeff\Documents\Untitled
2021-08-10 00:06 - 2021-08-10 00:06 - 000000000 ____D C:\Users\kjeff\AppData\Local\Avid
2021-08-10 00:05 - 2021-08-30 04:33 - 000000000 ____D C:\Program Files\Common Files\Avid
2021-08-10 00:05 - 2021-08-10 00:05 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Avid
2021-08-09 23:57 - 2016-04-12 09:12 - 000000000 ____D C:\Program Files\Pro Tools
2021-08-09 15:18 - 2021-08-09 15:18 - 000000000 ____D C:\Program Files (x86)\Kingsoft
2021-08-09 00:25 - 2021-08-09 00:25 - 002607473 _____ (Glorious ) C:\WINDOWS\unins001.exe
2021-08-09 00:25 - 2021-08-09 00:25 - 000022940 _____ C:\WINDOWS\unins001.dat
2021-08-09 00:25 - 2021-08-09 00:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glorious Core
2021-08-09 00:25 - 2021-08-09 00:25 - 000000000 ____D C:\Program Files (x86)\Glorious Core
2021-08-08 20:37 - 2021-08-08 20:37 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
2021-08-04 05:06 - 2021-08-04 05:06 - 000000000 ____D C:\Users\kjeff\AppData\Local\ToastNotificationManagerCompat
2021-08-04 05:05 - 2021-09-10 02:25 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Proton Technologies AG
2021-08-04 05:05 - 2021-09-10 02:25 - 000000000 ____D C:\Program Files (x86)\Proton Technologies
2021-08-02 06:37 - 2021-08-02 06:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PotPlayer
2021-07-23 04:14 - 2021-08-28 07:21 - 000750224 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2021-07-22 01:08 - 2021-07-22 01:08 - 000001990 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HarmonyPremium.lnk
2021-07-22 01:07 - 2021-07-22 01:07 - 000000000 ____D C:\Users\kjeff\AppData\Local\Toon Boom Animation
2021-07-22 01:06 - 2021-07-22 01:06 - 000000000 ____D C:\Users\kjeff\Documents\Toon Boom Harmony Premium Library
2021-07-22 01:05 - 2021-07-22 01:05 - 000000000 ____D C:\ProgramData\FLEXnet
2021-07-22 01:03 - 2021-07-22 01:03 - 000000000 ____D C:\ProgramData\FNP
2021-07-22 00:51 - 2021-09-16 05:04 - 000000000 ____D C:\flexlm
2021-07-22 00:51 - 2021-07-22 01:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Harmony 17 Premium
2021-07-22 00:48 - 2021-07-22 00:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Harmony 20 Premium
2021-07-22 00:47 - 2021-07-22 00:47 - 000000000 ____D C:\Program Files (x86)\Toon Boom Animation
2021-07-22 00:06 - 2021-07-22 01:07 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Toon Boom Animation
2021-07-22 00:06 - 2021-07-22 00:06 - 000000000 ____D C:\Program Files\Common Files\Macrovision Shared
2021-07-21 23:37 - 2021-07-21 23:37 - 000000000 ____D C:\ProgramData\Toon Boom Animation
2021-07-21 23:32 - 2021-07-22 00:47 - 000000000 ____D C:\WINDOWS\Downloaded Installations
2021-07-18 01:54 - 2021-07-18 01:54 - 000001333 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ghostrunner.lnk
2021-07-18 01:45 - 2021-07-18 01:45 - 000004336 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\witcher3.lnk
2021-07-18 01:39 - 2021-07-18 01:39 - 000000000 ____D C:\Users\kjeff\AppData\Local\Pathless
2021-07-18 01:38 - 2021-07-18 01:38 - 000001009 _____ C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pathless.lnk
2021-07-17 23:19 - 2021-09-15 05:12 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Dual Monitor Tools
2021-07-17 23:19 - 2021-07-17 23:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dual Monitor Tools
2021-07-17 23:19 - 2021-07-17 23:19 - 000000000 ____D C:\Program Files (x86)\Dual Monitor Tools
2021-07-17 04:48 - 2021-07-17 04:48 - 000000000 ____D C:\Users\kjeff\AppData\Local\Ghostrunner
2021-07-17 03:45 - 2021-07-17 03:45 - 000000000 ____D C:\Users\kjeff\AppData\Local\Ghostrunner_Demo
2021-07-15 23:59 - 2021-07-15 23:59 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsraLegacy.tlb
2021-07-15 23:59 - 2021-07-15 23:59 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsraLegacy.tlb
2021-07-15 23:59 - 2021-07-15 23:59 - 000006656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rendezvousSession.tlb
2021-07-15 23:59 - 2021-07-15 23:59 - 000006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\rendezvousSession.tlb
2021-07-14 02:36 - 2021-09-02 03:33 - 000000000 ____D C:\Program Files\Sublime Text 3
2021-07-12 04:45 - 2021-07-12 04:45 - 000003208 _____ C:\WINDOWS\system32\Tasks\Kill JDownloader
2021-07-12 04:44 - 2021-07-12 04:44 - 000003164 _____ C:\WINDOWS\system32\Tasks\Sleep
2021-07-12 04:38 - 2021-08-20 00:40 - 000000000 ____D C:\Users\kjeff\Documents\Scripts
2021-07-12 04:04 - 2021-07-12 04:04 - 000000000 __HDL C:\Users\kjeff\Dropbox
2021-07-09 00:14 - 2021-07-09 05:12 - 000000000 ____D C:\ProgramData\Jellyfin
2021-07-09 00:14 - 2021-07-09 00:14 - 000000000 ____D C:\Users\kjeff\AppData\Local\ASP.NET
2021-07-09 00:12 - 2021-07-09 05:12 - 000000000 ____D C:\Program Files\Jellyfin
2021-07-08 23:26 - 2021-07-09 00:16 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\vlc
2021-07-08 23:25 - 2021-07-18 02:04 - 000000000 ____D C:\Program Files\VideoLAN
2021-07-07 02:10 - 2021-07-08 00:35 - 000000000 ____D C:\Users\kjeff\AppData\Local\CocCoc
2021-07-07 02:10 - 2021-07-08 00:35 - 000000000 ____D C:\Program Files (x86)\CocCoc
2021-07-07 02:10 - 2021-07-07 02:14 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\CocCoc
2021-07-07 02:10 - 2021-07-07 02:10 - 000000000 ____D C:\ProgramData\CocCoc
2021-06-28 16:08 - 2021-06-28 16:08 - 000057064 _____ (Python Software Foundation) C:\WINDOWS\pyshellext.amd64.dll
2021-06-28 16:07 - 2021-06-28 16:07 - 000924904 _____ (Python Software Foundation) C:\WINDOWS\pyw.exe
2021-06-28 16:07 - 2021-06-28 16:07 - 000924392 _____ (Python Software Foundation) C:\WINDOWS\py.exe
2021-06-25 03:32 - 2021-06-25 03:32 - 000000000 ____D C:\WINDOWS\Minidump
2021-06-25 01:24 - 2021-06-25 01:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haste
2021-06-24 22:32 - 2021-06-24 22:32 - 002371072 _____ C:\WINDOWS\system32\rdpnano.dll
2021-06-24 22:32 - 2021-06-24 22:32 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2021-06-24 22:32 - 2021-06-24 22:32 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2021-06-24 22:32 - 2021-06-24 22:32 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2021-06-23 02:50 - 2021-06-21 03:43 - 000037664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhdap64.dll
2021-06-23 01:56 - 2021-05-04 02:49 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2021-06-22 04:54 - 2021-06-22 04:54 - 000000000 ____D C:\Program Files\Pixologic
2021-06-18 03:58 - 2021-06-18 03:58 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader
2021-06-18 03:57 - 2021-08-12 00:34 - 000000000 ____D C:\Users\kjeff\AppData\Local\JDownloader 2.0
 
==================== Three months (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2021-09-16 15:26 - 2020-04-28 05:07 - 000000000 ____D C:\Program Files\Emsisoft Anti-Malware
2021-09-16 15:24 - 2020-07-04 19:44 - 000483156 _____ C:\WINDOWS\system32\perfh011.dat
2021-09-16 15:24 - 2020-07-04 19:44 - 000131552 _____ C:\WINDOWS\system32\perfc011.dat
2021-09-16 15:24 - 2020-06-12 13:10 - 001446070 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-09-16 15:24 - 2019-12-07 04:13 - 000000000 ____D C:\WINDOWS\INF
2021-09-16 15:23 - 2020-04-20 10:50 - 000000000 ____D C:\ProgramData\NVIDIA
2021-09-16 15:22 - 2019-12-07 04:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-09-16 15:21 - 2020-04-20 18:35 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\discord
2021-09-16 15:20 - 2020-04-22 00:10 - 000000000 ____D C:\Program Files (x86)\Google
2021-09-16 15:20 - 2020-04-21 23:27 - 000000000 ____D C:\ProgramData\Autodesk
2021-09-16 15:20 - 2020-04-21 04:02 - 000000000 ____D C:\Users\kjeff\AppData\Local\Dropbox
2021-09-16 15:19 - 2020-04-20 18:35 - 000000000 ____D C:\Users\kjeff\AppData\Local\Discord
2021-09-16 15:18 - 2020-04-20 13:57 - 000013868 _____ C:\CosairDram.txt
2021-09-16 15:18 - 2020-04-20 08:44 - 000000000 ____D C:\ProgramData\ASUS
2021-09-16 15:17 - 2020-06-12 13:10 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-09-16 15:17 - 2020-06-12 13:04 - 000008192 ___SH C:\DumpStack.log.tmp
2021-09-16 15:17 - 2020-06-12 13:04 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-09-16 15:17 - 2020-06-02 03:04 - 000008192 _____ C:\WINDOWS\SysWOW64\edb.chk
2021-09-16 15:17 - 2020-04-20 08:44 - 000807280 _____ C:\WINDOWS\system32\wpbbin.exe
2021-09-16 15:17 - 2020-04-20 08:44 - 000768408 _____ C:\WINDOWS\system32\AsusUpdateCheck.exe
2021-09-16 15:16 - 2020-06-12 13:05 - 000000000 ____D C:\Users\kjeff
2021-09-16 11:56 - 2021-05-31 14:43 - 000000000 ____D C:\Users\kjeff\AppData\LocalLow\Mozilla
2021-09-16 10:36 - 2020-09-21 19:16 - 000004164 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{BA26D84C-DDDA-46B7-826F-17EC2056C5B6}
2021-09-16 05:38 - 2019-12-07 04:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-09-16 05:38 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-09-16 05:06 - 2019-12-07 04:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2021-09-16 04:33 - 2019-12-07 04:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2021-09-16 04:17 - 2020-07-29 16:05 - 000000000 ____D C:\Users\kjeff\AppData\Local\Battle.net
2021-09-16 01:17 - 2020-09-20 01:11 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager
2021-09-16 01:13 - 2020-04-20 10:53 - 000000000 ____D C:\ProgramData\Package Cache
2021-09-15 23:13 - 2020-04-28 05:08 - 000000000 ____D C:\ProgramData\Emsisoft
2021-09-15 23:12 - 2019-12-07 04:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-09-15 21:03 - 2020-04-22 00:11 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-09-15 20:56 - 2020-04-20 13:45 - 000000000 ____D C:\Users\kjeff\AppData\Local\D3DSCache
2021-09-15 20:13 - 2021-06-14 02:43 - 000000000 ____D C:\Program Files\Mozilla Firefox
2021-09-15 20:06 - 2020-04-20 08:50 - 000000000 __RHD C:\Users\Public\AccountPictures
2021-09-15 20:06 - 2019-12-07 04:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-09-15 17:44 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-09-15 17:36 - 2021-05-31 14:43 - 000000000 ____D C:\ProgramData\Mozilla
2021-09-15 17:34 - 2021-05-31 14:43 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-09-15 16:41 - 2020-04-21 04:02 - 000000000 ____D C:\Program Files (x86)\Dropbox
2021-09-15 05:12 - 2020-04-20 15:31 - 000000000 ____D C:\Users\kjeff\AppData\Local\CrashDumps
2021-09-13 18:17 - 2020-04-20 11:50 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-09-12 07:17 - 2021-02-01 22:35 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Origin
2021-09-12 03:27 - 2021-02-01 22:35 - 000000000 ____D C:\Users\kjeff\AppData\Local\Origin
2021-09-12 03:27 - 2021-02-01 22:35 - 000000000 ____D C:\ProgramData\Origin
2021-09-12 00:19 - 2020-04-29 19:04 - 000000000 ____D C:\Users\kjeff\AppData\Local\.IdentityService
2021-09-11 02:10 - 2020-07-29 16:04 - 000000000 ____D C:\Program Files (x86)\Battle.net
2021-09-10 06:39 - 2020-07-31 15:45 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Cycling '74
2021-09-10 03:11 - 2020-07-29 16:12 - 000000000 ____D C:\Program Files (x86)\Overwatch
2021-09-10 02:52 - 2020-05-09 00:20 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2021-09-10 02:23 - 2020-04-20 08:52 - 000000000 ____D C:\Users\kjeff\AppData\Local\PlaceholderTileLogoFolder
2021-09-10 02:17 - 2020-04-20 08:50 - 000000000 ____D C:\Users\kjeff\AppData\Local\Packages
2021-09-09 09:20 - 2020-06-12 13:04 - 001139416 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-09-09 09:19 - 2019-12-07 04:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2021-09-09 09:19 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2021-09-09 09:19 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-09-09 09:19 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-09-09 09:19 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-09-09 09:19 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2021-09-09 09:19 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-09-09 09:19 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-09-09 09:19 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2021-09-09 09:19 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-09-09 09:19 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2021-09-09 09:19 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2021-09-09 09:19 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2021-09-09 09:19 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-09-09 09:19 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-09-09 09:19 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\servicing
2021-09-09 04:25 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-09-09 04:02 - 2021-02-21 22:20 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-09-09 02:51 - 2020-04-20 08:44 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-09-09 01:44 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2021-09-09 01:29 - 2021-06-16 00:00 - 000000000 ____D C:\Users\kjeff\Documents\Tablet_presets
2021-09-09 01:15 - 2020-04-21 23:34 - 000000000 ____D C:\Users\kjeff\Documents\maya
2021-09-07 23:27 - 2021-05-02 05:02 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Telegram Desktop
2021-09-07 03:49 - 2020-04-20 18:35 - 000000000 ____D C:\Users\kjeff\AppData\Local\SquirrelTemp
2021-09-05 00:26 - 2021-04-12 22:27 - 000000000 ____D C:\Users\kjeff\AppData\Local\Downloaded Installations
2021-09-01 21:34 - 2021-02-01 22:36 - 000000000 ____D C:\Program Files (x86)\Origin
2021-08-31 02:18 - 2021-05-29 18:34 - 000000000 ____D C:\ProgramData\boost_interprocess
2021-08-30 23:52 - 2020-04-20 10:52 - 000803176 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2021-08-30 07:29 - 2020-04-21 23:26 - 000000000 ____D C:\Users\kjeff\AppData\Local\Autodesk
2021-08-30 05:09 - 2020-06-22 00:17 - 000000000 ____D C:\Program Files\Black Tree Gaming Ltd
2021-08-29 06:58 - 2020-07-31 12:19 - 000000398 __RSH C:\ProgramData\ntuser.pol
2021-08-28 07:18 - 2020-06-02 03:48 - 007280848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2021-08-27 17:30 - 2020-06-07 04:06 - 000000000 ____D C:\Program Files\TouchZoomDesktop
2021-08-27 17:30 - 2020-06-07 04:06 - 000000000 ____D C:\Program Files\TouchMousePointer
2021-08-27 05:07 - 2021-04-07 22:25 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\gnupg
2021-08-27 04:43 - 2020-06-12 13:10 - 000004308 _____ C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-08-27 04:43 - 2020-06-12 13:10 - 000004106 _____ C:\WINDOWS\system32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-08-27 04:43 - 2020-06-12 13:10 - 000003976 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-08-27 04:43 - 2020-06-12 13:10 - 000003940 _____ C:\WINDOWS\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-08-27 04:43 - 2020-06-12 13:10 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-08-27 04:43 - 2020-06-12 13:10 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-08-27 04:43 - 2020-06-12 13:10 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-08-27 04:43 - 2020-06-12 13:10 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-08-27 04:43 - 2020-04-20 08:50 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2021-08-27 04:42 - 2020-06-12 13:10 - 000003894 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-08-27 04:42 - 2020-06-12 13:10 - 000003654 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-08-27 04:42 - 2020-04-20 10:53 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2021-08-27 04:42 - 2020-04-20 08:50 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2021-08-26 06:50 - 2020-10-28 02:07 - 000000000 ____D C:\Program Files (x86)\McAfee
2021-08-25 13:27 - 2020-08-19 00:18 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Unpacker
2021-08-25 01:53 - 2020-07-31 12:24 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Ableton
2021-08-25 01:50 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2021-08-23 22:23 - 2020-07-31 15:45 - 000000000 ____D C:\Users\kjeff\Documents\Max 8
2021-08-23 20:59 - 2020-06-26 17:34 - 000000000 ____D C:\Users\kjeff\AppData\Local\ElevatedDiagnostics
2021-08-20 00:31 - 2020-04-29 19:34 - 000008403 _____ C:\Users\kjeff\.bash_history
2021-08-18 19:57 - 2020-06-04 03:01 - 000000000 ____D C:\ProgramData\Apple
2021-08-18 04:35 - 2019-12-07 04:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2021-08-18 02:28 - 2021-02-05 14:20 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Glorious Core
2021-08-18 00:32 - 2020-06-12 13:10 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-08-18 00:32 - 2020-06-12 13:10 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-08-17 05:44 - 2020-04-20 13:56 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2021-08-17 05:42 - 2020-04-21 04:02 - 000000938 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2021-08-17 05:42 - 2020-04-21 04:02 - 000000934 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2021-08-17 05:41 - 2020-04-20 11:56 - 000000000 ____D C:\Program Files\WinRAR
2021-08-17 05:40 - 2020-04-20 13:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2021-08-17 05:39 - 2020-04-20 08:50 - 000000000 ____D C:\Program Files (x86)\ASUS
2021-08-17 05:20 - 2020-04-20 11:56 - 000000000 ____D C:\Users\kjeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2021-08-17 05:20 - 2020-04-20 11:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2021-08-17 01:22 - 2021-02-21 22:20 - 000740168 _____ (Microsoft Corporation) C:\WINDOWS\system32\sedplugins.dll
2021-08-17 01:22 - 2021-02-21 22:20 - 000486728 _____ (Microsoft Corporation) C:\WINDOWS\system32\QualityUpdateAssistant.dll
 
==================== Files in the root of some directories ========
 
2021-06-14 01:51 - 2021-08-01 23:53 - 000001137 _____ () C:\Users\kjeff\AppData\Roaming\Coolorus 2
2021-08-31 03:40 - 2021-09-11 22:43 - 000000032 _____ () C:\Users\kjeff\AppData\Roaming\msregsvv.dll
2021-08-28 03:23 - 2021-08-28 03:23 - 000000722 _____ () C:\Users\kjeff\AppData\Roaming\PureRef.ini
2021-09-16 00:58 - 2021-09-16 15:23 - 000010962 _____ () C:\Users\kjeff\AppData\Roaming\Safer-Networking.log
2020-05-03 21:44 - 2020-05-04 04:15 - 000000128 _____ () C:\Users\kjeff\AppData\Roaming\winscp.rnd
2020-10-28 02:01 - 2021-04-01 22:15 - 000000615 _____ () C:\Users\kjeff\AppData\Local\oobelibMkey.log
2020-05-03 21:47 - 2020-05-04 04:13 - 000000128 _____ () C:\Users\kjeff\AppData\Local\PUTTY.RND
2020-04-20 22:51 - 2021-07-23 04:11 - 000007597 _____ () C:\Users\kjeff\AppData\Local\resmon.resmoncfg
 
==================== FLock ==============================
 
2021-09-16 00:41 C:\SandBlastBackup
 
==================== SigCheckExt =========================
 
2019-03-18 23:45 - 2019-03-18 23:45 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionMgr.dll
2020-04-20 11:14 - 2020-04-20 11:14 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindflt.dll
2019-03-18 23:44 - 2019-03-18 23:44 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\canonurl.dll
2019-03-18 23:45 - 2019-03-18 23:45 - 000590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\CMFNVSDeviceBridge.dll
2020-07-15 14:03 - 2019-01-25 23:43 - 000145920 _____ (Nicomsoft Ltd.) C:\WINDOWS\system32\DDCHelper.dll
2020-07-15 14:03 - 2019-01-25 23:43 - 000125440 _____ (Nicomsoft Ltd.) C:\WINDOWS\system32\DDCHelperX.dll
2019-03-18 23:43 - 2019-03-18 23:43 - 000759296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyHrtfEnc.dll
2019-03-18 23:43 - 2019-03-18 23:43 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyMATEnc.dll
2020-06-14 17:16 - 2021-07-28 21:30 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2020-04-20 11:14 - 2020-04-28 05:06 - 000006656 _____ C:\WINDOWS\system32\lpcio.dll
2019-03-18 23:43 - 2019-03-18 23:43 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\mitigationscanner.exe
2009-11-09 13:21 - 2009-11-09 13:21 - 000066560 _____ C:\WINDOWS\system32\ntrights.exe
2019-03-18 23:45 - 2019-03-18 23:45 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecureBioSysprep.dll
2020-04-20 08:50 - 2020-06-12 13:11 - 000366592 _____ C:\WINDOWS\system32\syncas.dll
2019-03-18 23:44 - 2019-03-18 23:44 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.internal.shellcommon.ShellPosition.dll
2021-08-17 05:55 - 2021-08-18 03:37 - 000011520 _____ C:\WINDOWS\PE_Rom.dll
2021-08-09 00:25 - 2021-08-09 00:25 - 002607473 _____ (Glorious ) C:\WINDOWS\unins001.exe
2015-03-17 01:34 - 2015-03-17 01:34 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atl71.dll
2019-03-18 23:45 - 2019-03-18 23:45 - 000028160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\canonurl.dll
2020-07-15 14:03 - 2019-01-25 23:43 - 000131584 _____ (Nicomsoft Ltd.) C:\WINDOWS\SysWOW64\DDCHelper.dll
2020-07-15 14:03 - 2019-01-25 23:43 - 000108032 _____ (Nicomsoft Ltd.) C:\WINDOWS\SysWOW64\DDCHelperX.dll
2015-03-17 01:34 - 2015-03-17 01:34 - 001060864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc71.dll
2015-03-17 01:34 - 2015-03-17 01:34 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71CHS.DLL
2015-03-17 01:34 - 2015-03-17 01:34 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71CHT.DLL
2015-03-17 01:34 - 2015-03-17 01:34 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71DEU.DLL
2015-03-17 01:34 - 2015-03-17 01:34 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71ENU.DLL
2015-03-17 01:34 - 2015-03-17 01:34 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71ESP.DLL
2015-03-17 01:34 - 2015-03-17 01:34 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71FRA.DLL
2015-03-17 01:34 - 2015-03-17 01:34 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71ITA.DLL
2015-03-17 01:34 - 2015-03-17 01:34 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71JPN.DLL
2015-03-17 01:34 - 2015-03-17 01:34 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71KOR.DLL
2015-03-17 01:34 - 2015-03-17 01:34 - 001047552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc71u.dll
2015-03-17 01:34 - 2015-03-17 01:34 - 000499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp71.dll
2015-03-17 01:34 - 2015-03-17 01:34 - 000348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr71.dll
2020-06-02 03:21 - 2021-06-13 06:15 - 000001536 _____ C:\WINDOWS\SysWOW64\RtkMsgs.dll
2021-08-31 03:40 - 2021-09-11 22:43 - 000000032 _____ C:\Users\kjeff\AppData\Roaming\msregsvv.dll
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
 
==================== BCD ================================
 
Firmware Boot Manager
---------------------
identifier              {fwbootmgr}
displayorder            {bootmgr}
                        {a5e912f2-ffee-11eb-9630-806e6f6e6963}
                        {f15bab7c-8314-11ea-8171-a85e4552dc8d}
timeout                 1
 
Windows Boot Manager
--------------------
identifier              {bootmgr}
device                  partition=\Device\HarddiskVolume6
path                    \EFI\MICROSOFT\BOOT\BOOTMGFW.EFI
description             Windows Boot Manager
locale                  en-US
inherit                 {globalsettings}
default                 {current}
resumeobject            {48a9c4ca-acf0-11ea-9968-ea0672ac7218}
displayorder            {current}
toolsdisplayorder       {memdiag}
timeout                 30
 
Firmware Application (101fffff)
-------------------------------
identifier              {a5e912f2-ffee-11eb-9630-806e6f6e6963}
device                  partition=C:
path                    \EFI\MICROSOFT\BOOT\BOOTMGFW.EFI
description             Windows Boot Manager
 
Firmware Application (101fffff)
-------------------------------
identifier              {f15bab7c-8314-11ea-8171-a85e4552dc8d}
description             Hard Drive
 
Windows Boot Loader
-------------------
identifier              {current}
device                  partition=C:
path                    \WINDOWS\system32\winload.efi
description             Windows 10
locale                  en-US
inherit                 {bootloadersettings}
recoverysequence        {48a9c4cc-acf0-11ea-9968-ea0672ac7218}
displaymessageoverride  StartupRepair
recoveryenabled         Yes
isolatedcontext         Yes
allowedinmemorysettings 0x15000075
osdevice                partition=C:
systemroot              \WINDOWS
resumeobject            {48a9c4ca-acf0-11ea-9968-ea0672ac7218}
nx                      OptIn
bootmenupolicy          Standard
useplatformclock        No
 
Windows Boot Loader
-------------------
identifier              {48a9c4cc-acf0-11ea-9968-ea0672ac7218}
device                  ramdisk=[\Device\HarddiskVolume5]\Recovery\WindowsRE\Winre.wim,{48a9c4cd-acf0-11ea-9968-ea0672ac7218}
path                    \windows\system32\winload.efi
description             Windows Recovery Environment
locale                  en-US
inherit                 {bootloadersettings}
displaymessage          Recovery
osdevice                ramdisk=[\Device\HarddiskVolume5]\Recovery\WindowsRE\Winre.wim,{48a9c4cd-acf0-11ea-9968-ea0672ac7218}
systemroot              \windows
nx                      OptIn
bootmenupolicy          Standard
winpe                   Yes
 
Resume from Hibernate
---------------------
identifier              {48a9c4ca-acf0-11ea-9968-ea0672ac7218}
device                  partition=C:
path                    \WINDOWS\system32\winresume.efi
description             Windows Resume Application
locale                  en-US
inherit                 {resumeloadersettings}
recoverysequence        {48a9c4cc-acf0-11ea-9968-ea0672ac7218}
recoveryenabled         Yes
isolatedcontext         Yes
allowedinmemorysettings 0x15000075
filedevice              partition=C:
filepath                \hiberfil.sys
bootmenupolicy          Standard
debugoptionenabled      No
 
Windows Memory Tester
---------------------
identifier              {memdiag}
device                  partition=\Device\HarddiskVolume6
path                    \EFI\Microsoft\Boot\memtest.efi
description             Windows Memory Diagnostic
locale                  en-US
inherit                 {globalsettings}
badmemoryaccess         Yes
 
EMS Settings
------------
identifier              {emssettings}
bootems                 No
 
Debugger Settings
-----------------
identifier              {dbgsettings}
debugtype               Local
 
RAM Defects
-----------
identifier              {badmemory}
 
Global Settings
---------------
identifier              {globalsettings}
inherit                 {dbgsettings}
                        {emssettings}
                        {badmemory}
 
Boot Loader Settings
--------------------
identifier              {bootloadersettings}
inherit                 {globalsettings}
                        {hypervisorsettings}
 
Hypervisor Settings
-------------------
identifier              {hypervisorsettings}
hypervisordebugtype     Serial
hypervisordebugport     1
hypervisorbaudrate      115200
 
Resume Loader Settings
----------------------
identifier              {resumeloadersettings}
inherit                 {globalsettings}
 
Device options
--------------
identifier              {48a9c4cd-acf0-11ea-9968-ea0672ac7218}
description             Windows Recovery
ramdisksdidevice        partition=\Device\HarddiskVolume5
ramdisksdipath          \Recovery\WindowsRE\boot.sdi
 
==================== End of FRST.txt ========================

  • 0

Advertisements







Similar Topics

12 user(s) are reading this topic

1 members, 11 guests, 0 anonymous users


    LuckyJohn

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP