Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Dell Inspiron bogged down with I don't know what [Solved]


  • This topic is locked This topic is locked

#1
moondog830

moondog830

    Member

  • Member
  • PipPipPip
  • 804 posts

A lady from church asked if I could take her Dell and clean it. She SAYS she has viruses on it, but I think that's a guess on her part. I have ran the FRST64 file and will post those reports. (The link on the start page for viruses and malware does not take me to the FRST64 file, so I downloaded it from another location and it said that that file was 1100+ days outdated. It also would not update, I think because she has McAffee and I think it's blocking it).

 

Could someone help me help this lady out? Her laptop takes it's time in loading anything.

 

moondog

(my friends call me Mark)

 

FRST

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-04-2017 01 (ATTENTION: ====> FRSTversion is 1618 days old and could be outdated)

Ran by ejbea (administrator) on DESKTOP-2KHI5DN (21-09-2021 11:57:56)
Running from C:\Users\ejbea\OneDrive\Desktop
Loaded Profiles: ejbea (Available Profiles: ejbea)
Platform: Windows 10 Home Version 2004 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument %1)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
Failed to access process -> Registry
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\IntelCpHDCPSvc.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Rivet Networks) C:\Program Files\Rivet Networks\SmartByte\SmartByteNetworkService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(McAfee, LLC) C:\Program Files\Common Files\mcafee\SystemCore\mfemms.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(McAfee, LLC) C:\Program Files\Common Files\mcafee\pef\CORE\PEFService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(McAfee, LLC) C:\Program Files\Common Files\mcafee\modulecore\ModuleCoreService.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\IntelCpHeciSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(McAfee, LLC) C:\Program Files\Common Files\mcafee\mmsshost\MMSSHOST.exe
(McAfee, LLC) C:\Windows\System32\mfevtps.exe
(McAfee, LLC) C:\Program Files\Common Files\mcafee\modulecore\ProtectedModuleHost.exe
(McAfee, LLC) C:\Program Files\mcafee\mfeav\MfeAVSvc.exe
(McAfee, LLC) C:\Program Files\Common Files\mcafee\VSCore_21_4\mcapexe.exe
(McAfee, LLC) C:\Program Files\Common Files\mcafee\modulecore\ModuleCoreService.exe
(McAfee LLC.) C:\Program Files\Common Files\mcafee\amcore\mcshield.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(McAfee, LLC) C:\Program Files\Common Files\mcafee\csp\4.6.104.0\McCSPServiceHost.exe
(Intel Corporation) C:\Program Files\Intel\IntelSGXPSW\bin\x64\Release\aesm_service.exe
(Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Dell Inc.) C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\igfxEM.exe
() C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(McAfee, LLC) C:\Program Files\Common Files\mcafee\modulecore\ModuleCoreService.exe
(McAfee, LLC) C:\Program Files\mcafee\MAT\McPvTray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\SecurityHealthSystray.exe
(Microsoft Corporation) C:\Windows\System32\SecurityHealthService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(CyberLink) C:\Program Files\WindowsApps\DB6EA5DB.Power2GoforDell_11.0.3920.0_x86__mcezb6ze687jp\Power2Go11\CLMLSvc_P2G11.exe
(DELL) C:\Program Files\Rivet Networks\SmartByte\SmartByteTelemetry.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2108.25001.0_x64__8wekyb3d8bbwe\Cortana.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\SgrmBroker.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(McAfee, LLC) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12107.1001.15.0_x64__8wekyb3d8bbwe\WinStore.App.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.1220_none_7e21bc567c7ed16b\TiWorker.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Users\ejbea\AppData\Local\Microsoft\OneDrive\21.170.0822.0002\FileCoAuth.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
() C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe
(McAfee, LLC) C:\Program Files\mcafee\MQS\QcShm.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SecurityHealth] => C:\WINDOWS\system32\SecurityHealthSystray.exe [86016 2019-12-07] (Microsoft Corporation)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [320568 2016-09-20] (Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9269328 2019-01-28] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506384 2019-01-28] (Realtek Semiconductor)
HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [3910656 2017-05-03] (Dell Inc.)
HKLM\...\Run: [DellMobileConnectWelcome] => C:\Program Files\Dell\DellMobileConnectDrivers\DellMobileConnectWStartup.exe [313064 2018-10-05] (Screenovate Technologies Ltd.)
HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [1213736 2018-11-04] (Waves Audio Ltd.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKU\S-1-5-21-3457983286-1419784188-334204780-1001\...\Run: [MicrosoftEdgeAutoLaunch_799699109B40F4658C53434E420CEEDF] => C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe [3325840 2021-09-16] (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.1
Tcpip\..\Interfaces\{589ec2c5-523f-4790-b90c-67d059a82bbe}: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{6daae701-dcd4-4585-aa71-409ea1fd00ff}: [DhcpNameServer] 192.168.0.1 192.168.0.1
 
Internet Explorer:
==================
HKU\S-1-5-21-3457983286-1419784188-334204780-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=620947&OCID=AVRES000&pc=UE00
HKU\S-1-5-21-3457983286-1419784188-334204780-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
BHO: IEToEdge BHO -> {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} -> C:\Program Files (x86)\Microsoft\Edge\Application\93.0.961.52\BHO\ie_to_edge_bho_64.dll [2021-09-16] (Microsoft Corporation)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2021-05-28] (Microsoft Corporation)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2020-07-31] (McAfee, LLC)
BHO-x32: IEToEdge BHO -> {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} -> C:\Program Files (x86)\Microsoft\Edge\Application\93.0.961.52\BHO\ie_to_edge_bho.dll [2021-09-16] (Microsoft Corporation)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2020-07-31] (McAfee, LLC)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-08-26] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-08-26] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-08-26] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-08-26] (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\McAfee\MSC\McSnIePl64.dll [2021-08-22] (McAfee, LLC)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2021-08-22] (McAfee, LLC)
 
Edge: 
======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions [not found]
 
FireFox:
========
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Extension: (No Name) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2020-07-31] [not signed]
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\McAfee\MSKHKLM => not found
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\McAfee\MSK
FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2021-09-09] [not signed]
FF Plugin: @mcafee.com/MSC,version=10 -> C:\Program Files\McAfee\MSC\npMcSnFFPl64.dll [2021-08-22] ()
FF Plugin-x32: @mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\MSC\npMcSnFFPl.dll [2021-08-22] ()
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-05-28] (Microsoft Corporation)
 
Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AarSvc; C:\WINDOWS\System32\AarSvc.dll [475136 2021-06-10] (Microsoft Corporation)
S3 AarSvc; C:\WINDOWS\SysWOW64\AarSvc.dll [362496 2021-06-10] (Microsoft Corporation)
R3 AarSvc_1425db; C:\WINDOWS\system32\svchost.exe [57360 2020-11-22] (Microsoft Corporation)
R3 AarSvc_1425db; C:\WINDOWS\SysWOW64\svchost.exe [47016 2020-11-22] (Microsoft Corporation)
R2 AESMService; c:\Program Files\Intel\IntelSGXPSW\bin\x64\Release\aesm_service.exe [3723400 2016-04-14] (Intel Corporation)
S3 autotimesvc; C:\WINDOWS\System32\autotimesvc.dll [114176 2021-01-13] (Microsoft Corporation)
S3 BcastDVRUserService; C:\WINDOWS\System32\BcastDVRUserService.dll [1384448 2021-02-09] (Microsoft Corporation)
S3 BcastDVRUserService_1425db; C:\WINDOWS\system32\svchost.exe [57360 2020-11-22] (Microsoft Corporation)
S3 BcastDVRUserService_1425db; C:\WINDOWS\SysWOW64\svchost.exe [47016 2020-11-22] (Microsoft Corporation)
S3 BluetoothUserService; C:\WINDOWS\System32\Microsoft.Bluetooth.UserService.dll [500736 2021-01-13] (Microsoft Corporation)
S3 BluetoothUserService_1425db; C:\WINDOWS\system32\svchost.exe [57360 2020-11-22] (Microsoft Corporation)
S3 BluetoothUserService_1425db; C:\WINDOWS\SysWOW64\svchost.exe [47016 2020-11-22] (Microsoft Corporation)
R2 BrokerInfrastructure; C:\WINDOWS\System32\psmsrv.dll [247296 2020-12-09] (Microsoft Corporation)
S3 BTAGService; C:\WINDOWS\System32\BTAGService.dll [1023488 2021-01-13] (Microsoft Corporation)
S3 BTAGService; C:\WINDOWS\SysWOW64\BTAGService.dll [733696 2021-01-13] (Microsoft Corporation)
R3 BthAvctpSvc; C:\WINDOWS\System32\BthAvctpSvc.dll [399872 2021-09-16] (Microsoft Corporation)
R3 camsvc; C:\WINDOWS\system32\CapabilityAccessManager.dll [391168 2021-01-13] (Microsoft Corporation)
S3 CaptureService; C:\WINDOWS\System32\CaptureService.dll [130560 2021-02-09] (Microsoft Corporation)
S3 CaptureService_1425db; C:\WINDOWS\system32\svchost.exe [57360 2020-11-22] (Microsoft Corporation)
S3 CaptureService_1425db; C:\WINDOWS\SysWOW64\svchost.exe [47016 2020-11-22] (Microsoft Corporation)
S3 cbdhsvc; C:\WINDOWS\System32\cbdhsvc.dll [1024000 2021-02-09] (Microsoft Corporation)
R3 cbdhsvc_1425db; C:\WINDOWS\system32\svchost.exe [57360 2020-11-22] (Microsoft Corporation)
R3 cbdhsvc_1425db; C:\WINDOWS\SysWOW64\svchost.exe [47016 2020-11-22] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9166736 2021-08-23] (Microsoft Corporation)
S3 ConsentUxUserSvc; C:\WINDOWS\System32\ConsentUxClient.dll [170496 2021-01-13] (Microsoft Corporation)
S3 ConsentUxUserSvc_1425db; C:\WINDOWS\system32\svchost.exe [57360 2020-11-22] (Microsoft Corporation)
S3 ConsentUxUserSvc_1425db; C:\WINDOWS\SysWOW64\svchost.exe [47016 2020-11-22] (Microsoft Corporation)
R3 cphs; C:\WINDOWS\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\IntelCpHeciSvc.exe [491632 2018-03-21] (Intel Corporation)
R2 cplspcon; C:\WINDOWS\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\IntelCpHDCPSvc.exe [470128 2018-03-21] (Intel Corporation)
S3 CredentialEnrollmentManagerUserSvc; C:\WINDOWS\system32\CredentialEnrollmentManager.exe [382696 2021-09-16] (Microsoft Corporation)
S3 CredentialEnrollmentManagerUserSvc_1425db; C:\WINDOWS\system32\CredentialEnrollmentManager.exe [382696 2021-09-16] (Microsoft Corporation)
R2 Dell SupportAssist Remediation; C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe [293528 2018-10-20] (Dell Inc.)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [35976 2019-04-03] ()
S3 DeviceAssociationBrokerSvc; C:\WINDOWS\System32\deviceaccess.dll [240688 2021-01-13] (Microsoft Corporation)
S3 DeviceAssociationBrokerSvc; C:\WINDOWS\SysWOW64\deviceaccess.dll [188536 2021-01-13] (Microsoft Corporation)
S3 DeviceAssociationBrokerSvc_1425db; C:\WINDOWS\system32\svchost.exe [57360 2020-11-22] (Microsoft Corporation)
S3 DeviceAssociationBrokerSvc_1425db; C:\WINDOWS\SysWOW64\svchost.exe [47016 2020-11-22] (Microsoft Corporation)
S3 DevicePickerUserSvc; C:\WINDOWS\System32\Windows.Devices.Picker.dll [482816 2021-04-16] (Microsoft Corporation)
S3 DevicePickerUserSvc; C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll [342016 2021-04-16] (Microsoft Corporation)
S3 DevicePickerUserSvc_1425db; C:\WINDOWS\system32\svchost.exe [57360 2020-11-22] (Microsoft Corporation)
S3 DevicePickerUserSvc_1425db; C:\WINDOWS\SysWOW64\svchost.exe [47016 2020-11-22] (Microsoft Corporation)
S3 DevicesFlowUserSvc; C:\WINDOWS\System32\DevicesFlowBroker.dll [598016 2021-05-15] (Microsoft Corporation)
S3 DevicesFlowUserSvc_1425db; C:\WINDOWS\system32\svchost.exe [57360 2020-11-22] (Microsoft Corporation)
S3 DevicesFlowUserSvc_1425db; C:\WINDOWS\SysWOW64\svchost.exe [47016 2020-11-22] (Microsoft Corporation)
S3 diagsvc; C:\WINDOWS\system32\DiagSvc.dll [205824 2021-07-13] (Microsoft Corporation)
R2 DispBrokerDesktopSvc; C:\WINDOWS\System32\DispBroker.Desktop.dll [382976 2021-06-10] (Microsoft Corporation)
R3 DisplayEnhancementService; C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll [1192448 2021-04-16] (Microsoft Corporation)
R2 DusmSvc; C:\WINDOWS\System32\dusmsvc.dll [341504 2019-12-07] (Microsoft Corporation)
S2 edgeupdate; C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [224160 2020-07-09] (Microsoft Corporation)
S3 edgeupdatem; C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [224160 2020-07-09] (Microsoft Corporation)
R2 esifsvc; C:\WINDOWS\System32\Intel\DPTF\esif_uf.exe [1705040 2017-11-21] (Intel Corporation)
S3 GraphicsPerfSvc; C:\WINDOWS\System32\GraphicsPerfSvc.dll [106496 2021-01-13] (Microsoft Corporation)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [17976 2016-09-20] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\igfxCUIService.exe [406128 2018-03-21] (Intel Corporation)
R3 InstallService; C:\WINDOWS\system32\InstallService.dll [2438144 2021-08-14] (Microsoft Corporation)
R3 InstallService; C:\WINDOWS\SysWOW64\InstallService.dll [1843712 2021-08-14] (Microsoft Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_75ffca5eec865b4b\lib\SocketHeciServer.exe [856848 2020-04-22] (Intel® Corporation)
S2 Intel® TPM Provisioning Service; C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_75ffca5eec865b4b\lib\TPMProvisioningService.exe [783112 2020-04-22] (Intel® Corporation)
S3 IpxlatCfgSvc; C:\WINDOWS\System32\IpxlatCfg.dll [66048 2019-12-07] (Microsoft Corporation)
R2 jhi_service; C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe [629752 2020-08-16] (Intel Corporation)
S3 LxpSvc; C:\WINDOWS\System32\LanguageOverlayServer.dll [302080 2021-01-13] (Microsoft Corporation)
S2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [949960 2020-08-07] () [File not signed]
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_21_4\McApExe.exe [789752 2021-08-22] (McAfee, LLC)
S3 McAWFwk; c:\Program Files\Common Files\mcafee\actwiz\McAWFwk.exe [455584 2018-07-16] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\4.6.104.0\\McCSPServiceHost.exe [2825792 2021-08-13] (McAfee, LLC)
S3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [652232 2021-05-11] (McAfee, LLC)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [652232 2021-05-11] (McAfee, LLC)
R3 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [652232 2021-05-11] (McAfee, LLC)
S3 MicrosoftEdgeElevationService; C:\Program Files (x86)\Microsoft\Edge\Application\93.0.961.52\elevation_service.exe [1651616 2021-09-16] (Microsoft Corporation)
S3 MixedRealityOpenXRSvc; C:\WINDOWS\System32\MixedRealityRuntime.dll [134768 2021-01-13] (Microsoft Corporation)
S3 MixedRealityOpenXRSvc; C:\WINDOWS\SysWOW64\MixedRealityRuntime.dll [104824 2021-01-13] (Microsoft Corporation)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1671760 2021-08-10] (McAfee, LLC)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [311584 2019-04-22] ()
S3 NaturalAuthentication; C:\WINDOWS\System32\NaturalAuth.dll [454656 2021-01-13] (Microsoft Corporation)
R2 PEFService; C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe [4288832 2021-08-13] (McAfee, LLC)
S3 perceptionsimulation; C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe [106496 2021-01-13] (Microsoft Corporation)
S3 PrintWorkflowUserSvc; C:\WINDOWS\System32\PrintWorkflowService.dll [182272 2021-02-09] (Microsoft Corporation)
S3 PrintWorkflowUserSvc; C:\WINDOWS\SysWOW64\PrintWorkflowService.dll [138752 2021-02-09] (Microsoft Corporation)
S3 PrintWorkflowUserSvc_1425db; C:\WINDOWS\system32\svchost.exe [57360 2020-11-22] (Microsoft Corporation)
S3 PrintWorkflowUserSvc_1425db; C:\WINDOWS\SysWOW64\svchost.exe [47016 2020-11-22] (Microsoft Corporation)
S3 PushToInstall; C:\WINDOWS\system32\PushToInstall.dll [281088 2021-01-13] (Microsoft Corporation)
S2 RNDBWM; C:\Program Files\Rivet Networks\SmartByte\RNDBWMService.exe [64184 2018-12-04] (CloudBees, Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [267768 2019-01-28] (Realtek Semiconductor)
R3 SecurityHealthService; C:\WINDOWS\system32\SecurityHealthService.exe [986032 2021-08-14] (Microsoft Corporation)
S3 SEMgrSvc; C:\WINDOWS\system32\SEMgrSvc.dll [1223680 2021-01-13] (Microsoft Corporation)
R2 SgrmBroker; C:\WINDOWS\system32\SgrmBroker.exe [329504 2020-11-22] (Microsoft Corporation)
S3 SharedRealitySvc; C:\WINDOWS\System32\SharedRealitySvc.dll [307200 2021-01-13] (Microsoft Corporation)
R2 SmartByte Network Service x64; C:\Program Files\Rivet Networks\SmartByte\SmartByteNetworkService.exe [2114248 2018-12-04] (Rivet Networks)
S3 spectrum; C:\WINDOWS\system32\spectrum.exe [877568 2021-08-14] (Microsoft Corporation)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [382976 2021-05-15] ()
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [265640 2018-09-26] (Synaptics Incorporated)
R3 TokenBroker; C:\WINDOWS\System32\TokenBroker.dll [1522688 2021-06-10] (Microsoft Corporation)
R3 TokenBroker; C:\WINDOWS\SysWOW64\TokenBroker.dll [1234944 2021-02-09] (Microsoft Corporation)
S3 TroubleshootingSvc; C:\WINDOWS\system32\MitigationClient.dll [487936 2021-07-13] (Microsoft Corporation)
S4 tzautoupdate; C:\WINDOWS\SysWOW64\tzautoupdate.dll [73728 2021-01-13] (Microsoft Corporation)
S3 UdkUserSvc; C:\WINDOWS\System32\windowsudk.shellcommon.dll [2111488 2021-03-10] (Microsoft Corporation)
S3 UdkUserSvc_1425db; C:\WINDOWS\system32\svchost.exe [57360 2020-11-22] (Microsoft Corporation)
S3 UdkUserSvc_1425db; C:\WINDOWS\SysWOW64\svchost.exe [47016 2020-11-22] (Microsoft Corporation)
S4 uhssvc; C:\Program Files\Microsoft Update Health Tools\uhssvc.exe [351544 2021-08-17] (Microsoft Corporation)
R2 UsoSvc; C:\WINDOWS\system32\usosvc.dll [569856 2021-09-16] (Microsoft Corporation)
S3 VacSvc; C:\WINDOWS\System32\vac.dll [382720 2021-02-09] (Microsoft Corporation)
S3 WaaSMedicSvc; C:\WINDOWS\System32\WaaSMedicSvc.dll [440832 2021-08-14] (Microsoft Corporation)
S3 WarpJITSvc; C:\WINDOWS\System32\Windows.WARP.JITService.dll [65536 2019-12-07] (Microsoft Corporation)
R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [875816 2018-11-04] (Waves Audio Ltd.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\NisSrv.exe [2772856 2021-09-18] (Microsoft Corporation)
S3 WFDSConMgrSvc; C:\WINDOWS\System32\wfdsconmgrsvc.dll [677888 2021-09-16] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MsMpEng.exe [136640 2021-09-18] (Microsoft Corporation)
S3 wisvc; C:\WINDOWS\SysWOW64\flightsettings.dll [752024 2021-07-13] (Microsoft Corporation)
S3 wlpasvc; C:\WINDOWS\System32\lpasvc.dll [1253888 2021-01-13] (Microsoft Corporation)
S3 WManSvc; C:\WINDOWS\system32\Windows.Management.Service.dll [803840 2021-09-16] (Microsoft Corporation)
S3 WpcMonSvc; C:\WINDOWS\System32\WpcDesktopMonSvc.dll [1872384 2021-07-13] (Microsoft Corporation)
S3 XboxGipSvc; C:\WINDOWS\System32\XboxGipSvc.dll [72704 2021-03-10] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [4110624 2019-04-22] (Intel® Corporation)
R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 Acx01000; C:\WINDOWS\System32\drivers\Acx01000.sys [415232 2019-12-07] (Microsoft Corporation)
R1 afunix; C:\WINDOWS\system32\drivers\afunix.sys [41984 2021-07-15] (Microsoft Corporation)
R1 afunix; C:\Windows\SysWOW64\drivers\afunix.sys [29696 2021-07-15] (Microsoft Corporation)
S3 amdgpio2; C:\WINDOWS\System32\drivers\amdgpio2.sys [18432 2019-12-07] (Advanced Micro Devices, Inc)
S3 amdi2c; C:\WINDOWS\System32\drivers\amdi2c.sys [45568 2019-12-07] (Advanced Micro Devices, Inc)
R1 bam; C:\WINDOWS\System32\drivers\bam.sys [78136 2019-12-07] (Microsoft Corporation)
R1 BasicDisplay; C:\WINDOWS\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_65ab9a260dbf7467\BasicDisplay.sys [68608 2021-04-15] (Microsoft Corporation)
R1 BasicRender; C:\WINDOWS\System32\DriverStore\FileRepository\basicrender.inf_amd64_df49c4daa6251397\BasicRender.sys [38912 2021-04-15] (Microsoft Corporation)
R2 bindflt; C:\WINDOWS\system32\drivers\bindflt.sys [148816 2021-07-13] (Microsoft Corporation)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthLEEnum; C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys [106496 2020-11-22] (Microsoft Corporation)
S3 BthMini; C:\WINDOWS\System32\drivers\BTHMINI.sys [45568 2021-09-16] (Microsoft Corporation)
S0 bttflt; C:\WINDOWS\System32\drivers\bttflt.sys [43832 2019-12-07] (Microsoft Corporation)
R3 CAD; C:\WINDOWS\System32\drivers\CAD.sys [66576 2019-12-07] (Microsoft Corporation)
R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [80400 2021-05-19] (McAfee, LLC)
R1 CimFS; C:\Windows\System32\Drivers\CimFS.sys [98816 2021-09-16] ()
R2 CldFlt; C:\WINDOWS\System32\drivers\cldflt.sys [496128 2021-07-15] (Microsoft Corporation)
S3 DDDriver; C:\WINDOWS\System32\drivers\dddriver64Dcsa.sys [35704 2019-10-31] (Dell Inc.)
R2 DpmLiteDrv; c:\Program Files\Dell\QuickSet\DpmLiteDrv64.sys [15080 2014-10-15] (Wistron Corp.)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [69536 2017-11-21] (Intel Corporation)
R3 esif_lf; C:\WINDOWS\System32\drivers\esif_lf.sys [382880 2017-11-21] (Intel Corporation)
S3 genericusbfn; C:\WINDOWS\System32\DriverStore\FileRepository\genericusbfn.inf_amd64_53931f0ae21d6d2c\genericusbfn.sys [23040 2019-12-07] (Microsoft Corporation)
S3 HfAudio; C:\WINDOWS\System32\drivers\HfAudio.sys [91200 2018-10-05] (Screenovate Technologies Ltd.)
R3 HidEventFilter; C:\WINDOWS\System32\DriverStore\FileRepository\hideventfilter.inf_amd64_ca1148cff9a7eea6\HidEventFilter.sys [85664 2019-04-18] (Intel Corporation)
S3 hidspi; C:\WINDOWS\System32\drivers\hidspi.sys [66560 2019-12-07] (Microsoft Corporation)
S4 hvcrash; C:\WINDOWS\System32\drivers\hvcrash.sys [35128 2019-12-07] (Microsoft Corporation)
S3 HwNClx0101; C:\WINDOWS\System32\Drivers\mshwnclx.sys [30208 2019-12-07] (Microsoft Corporation)
S3 iaLPSS2i_GPIO2_BXT_P; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [93184 2019-12-07] (Intel Corporation)
S3 iaLPSS2i_GPIO2_CNL; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_CNL.sys [112128 2019-12-07] (Intel Corporation)
S3 iaLPSS2i_GPIO2_GLK; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_GLK.sys [96256 2019-12-07] (Intel Corporation)
S3 iaLPSS2i_I2C_BXT_P; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [175104 2019-12-07] (Intel Corporation)
S3 iaLPSS2i_I2C_CNL; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_CNL.sys [177152 2019-12-07] (Intel Corporation)
S3 iaLPSS2i_I2C_GLK; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_GLK.sys [177664 2019-12-07] (Intel Corporation)
R3 iaLPSS2_GPIO2; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_skl.inf_amd64_e79b9f98409084db\iaLPSS2_GPIO2.sys [95640 2020-05-02] (Intel Corporation)
R3 iaLPSS2_I2C; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_i2c_skl.inf_amd64_5b7885d62ac7afad\iaLPSS2_I2C.sys [185240 2020-05-02] (Intel Corporation)
S3 iaLPSS2_SPI; C:\WINDOWS\System32\drivers\iaLPSS2_SPI.sys [158368 2017-10-16] (Intel Corporation)
S3 iaLPSS2_UART2; C:\WINDOWS\System32\drivers\iaLPSS2_UART2.sys [310936 2017-10-16] (Intel Corporation)
R0 iaStorAC; C:\WINDOWS\System32\drivers\iaStorAC.sys [1096192 2019-08-12] (Intel Corporation)
S0 iaStorAVC; C:\WINDOWS\System32\drivers\iaStorAVC.sys [884752 2019-12-07] (Intel Corporation)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [136728 2018-05-15] (Intel Corporation)
R3 igfx; C:\WINDOWS\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\igdkmd64.sys [12809648 2018-03-21] (Intel Corporation)
S3 intelpmax; C:\WINDOWS\System32\drivers\intelpmax.sys [30720 2019-12-07] (Microsoft Corporation)
S3 IPT; C:\WINDOWS\System32\drivers\ipt.sys [59704 2019-12-07] (Microsoft Corporation)
S0 ItSas35i; C:\WINDOWS\System32\drivers\ItSas35i.sys [172344 2019-12-07] (Avago Technologies)
S3 mausbhost; C:\WINDOWS\System32\drivers\mausbhost.sys [537608 2019-12-07] (Microsoft Corporation)
S3 mausbip; C:\WINDOWS\System32\drivers\mausbip.sys [64016 2019-12-07] (Microsoft Corporation)
S3 MbbCx; C:\WINDOWS\System32\drivers\MbbCx.sys [391168 2021-07-13] (Microsoft Corporation)
R2 McPvDrv; C:\WINDOWS\system32\drivers\McPvDrv.sys [97696 2021-07-27] (McAfee, LLC)
S0 megasas35i; C:\WINDOWS\System32\drivers\megasas35i.sys [105480 2019-12-07] (Avago Technologies)
R3 MEIx64; C:\WINDOWS\System32\DriverStore\FileRepository\heci.inf_amd64_a54e540558404ee5\x64\TeeDriverW10x64.sys [310656 2021-01-10] (Intel Corporation)
R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [550944 2021-05-19] (McAfee, LLC)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [390664 2021-05-19] (McAfee, LLC)
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [85952 2021-05-19] (McAfee, LLC)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [527368 2021-05-19] (McAfee, LLC)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [1037320 2021-05-19] (McAfee, LLC)
R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [590032 2021-04-16] (McAfee LLC.)
S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [120512 2021-04-16] (McAfee LLC.)
R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [121352 2021-05-19] (McAfee, LLC)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [257552 2021-05-19] (McAfee, LLC)
S3 Microsoft_Bluetooth_AvrcpTransport; C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys [65024 2019-12-07] (Microsoft Corporation)
R3 MsQuic; C:\WINDOWS\System32\drivers\msquic.sys [322376 2020-11-22] (Microsoft Corporation)
S3 NDKPing; C:\WINDOWS\System32\drivers\NDKPing.sys [72720 2019-12-07] (Microsoft Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [208384 2021-09-16] (Microsoft Corporation)
R3 Netwtw04; C:\WINDOWS\system32\DRIVERS\Netwtw04.sys [8728672 2019-05-03] (Intel Corporation)
S0 nvdimm; C:\WINDOWS\System32\drivers\nvdimm.sys [168464 2019-12-07] (Microsoft Corporation)
S3 PktMon; C:\WINDOWS\System32\drivers\PktMon.sys [129872 2021-04-16] (Microsoft Corporation)
S0 pmem; C:\WINDOWS\System32\drivers\pmem.sys [138040 2019-12-07] (Microsoft Corporation)
S3 portcfg; C:\WINDOWS\System32\drivers\portcfg.sys [27136 2019-12-07] (Microsoft Corporation)
S0 Ramdisk; C:\WINDOWS\System32\DRIVERS\ramdisk.sys [42296 2019-12-07] (Microsoft Corporation)
S3 rhproxy; C:\WINDOWS\System32\drivers\rhproxy.sys [115712 2019-12-07] (Microsoft Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [984032 2017-07-25] (Realtek                                            )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [436224 2016-12-15] (Realsil Semiconductor Corporation)
S3 ScrHIDDriver2; C:\WINDOWS\System32\drivers\ScrHIDDriver2.sys [75800 2018-10-05] (Screenovate Technologies Ltd.)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [35128 2019-12-07] (Microsoft Corporation)
R0 SgrmAgent; C:\WINDOWS\System32\drivers\SgrmAgent.sys [88080 2019-12-07] (Microsoft Corporation)
S0 SmartSAMD; C:\WINDOWS\System32\drivers\SmartSAMD.sys [209720 2019-12-07] (Microsemi Corportation)
R3 SmbCoSvc; C:\WINDOWS\system32\DRIVERS\SmbCo10X64.sys [120008 2018-12-04] (Rivet Networks, LLC.)
S3 spaceparser; C:\WINDOWS\System32\drivers\spaceparser.sys [26624 2019-12-07] (Microsoft Corporation)
S3 SpatialGraphFilter; C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [90936 2019-12-07] (Microsoft Corporation)
R3 SynRMIHID; C:\WINDOWS\system32\DRIVERS\SynRMIHID.sys [65960 2018-09-26] (Synaptics Incorporated)
R0 Telemetry; C:\WINDOWS\System32\drivers\IntelTA.sys [26608 2020-11-22] (Microsoft Corporation)
S3 UcmUcsiAcpiClient; C:\WINDOWS\System32\drivers\UcmUcsiAcpiClient.sys [36864 2019-12-07] (Microsoft Corporation)
S3 UcmUcsiCx0101; C:\WINDOWS\System32\Drivers\UcmUcsiCx.sys [113152 2020-11-22] (Microsoft Corporation)
R3 UEFI; C:\WINDOWS\System32\DriverStore\FileRepository\uefi.inf_amd64_c1628ffa62c8e54c\UEFI.sys [34104 2019-12-07] (Microsoft Corporation)
S3 UfxChipidea; C:\WINDOWS\System32\DriverStore\FileRepository\ufxchipidea.inf_amd64_1c78775fffab6a0a\UfxChipidea.sys [110608 2019-12-07] (Microsoft Corporation)
R3 umbus; C:\WINDOWS\System32\DriverStore\FileRepository\umbus.inf_amd64_b78a9c5b6fd62c27\umbus.sys [58368 2019-12-07] (Microsoft Corporation)
S3 UrsChipidea; C:\WINDOWS\System32\DriverStore\FileRepository\urschipidea.inf_amd64_78ad1c14e33df968\urschipidea.sys [32056 2019-12-07] (Microsoft Corporation)
S3 UrsSynopsys; C:\WINDOWS\System32\DriverStore\FileRepository\urssynopsys.inf_amd64_057fa37902020500\urssynopsys.sys [29496 2019-12-07] (Microsoft Corporation)
S3 usbaudio2; C:\WINDOWS\System32\drivers\usbaudio2.sys [260608 2019-12-07] (Microsoft Corporation)
S3 VirtualRender; C:\WINDOWS\System32\DriverStore\FileRepository\vrd.inf_amd64_81fbd405ff2470fc\vrd.sys [11264 2019-12-07] (Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2021-09-18] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [433384 2021-09-18] (Microsoft Corporation)
S3 WdmCompanionFilter; C:\WINDOWS\System32\drivers\WdmCompanionFilter.sys [23560 2019-12-07] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86264 2021-09-18] (Microsoft Corporation)
S3 WinNat; C:\WINDOWS\System32\drivers\winnat.sys [259584 2021-03-10] (Microsoft Corporation)
S3 MpKslbdb8f141; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{11863E0B-8241-4CEF-8BF6-107FA524074A}\MpKslDrv.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
NETSVC: InstallService -> C:\Windows\system32\InstallService.dll (Microsoft Corporation)
NETSVC: PushToInstall -> C:\Windows\system32\PushToInstall.dll (Microsoft Corporation)
NETSVC: TroubleshootingSvc -> C:\Windows\system32\MitigationClient.dll (Microsoft Corporation)
NETSVC: LxpSvc -> C:\Windows\System32\LanguageOverlayServer.dll (Microsoft Corporation)
NETSVC: WManSvc -> C:\Windows\system32\Windows.Management.Service.dll (Microsoft Corporation)
NETSVC: TokenBroker -> C:\Windows\System32\TokenBroker.dll (Microsoft Corporation)
NETSVC: NaturalAuthentication -> C:\Windows\System32\NaturalAuth.dll (Microsoft Corporation)
NETSVC: XboxGipSvc -> C:\Windows\System32\XboxGipSvc.dll (Microsoft Corporation)
NETSVCx32: TokenBroker -> C:\Windows\SysWOW64\TokenBroker.dll (Microsoft Corporation)
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2021-09-21 11:57 - 2021-09-21 11:57 - 00000000 ____D C:\FRST
2021-09-16 13:36 - 2021-09-16 13:36 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2021-09-16 13:36 - 2021-09-16 13:36 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2021-09-16 13:36 - 2021-09-16 13:36 - 00093128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpfve.sys
2021-09-16 13:35 - 2021-09-16 13:36 - 00992768 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2021-09-16 13:35 - 2021-09-16 13:35 - 00817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2021-09-16 13:35 - 2021-09-16 13:35 - 00555008 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2021-09-16 13:35 - 2021-09-16 13:35 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2021-09-16 13:35 - 2021-09-16 13:35 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2021-09-16 13:35 - 2021-09-16 13:35 - 00388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2021-09-16 13:35 - 2021-09-16 13:35 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbadmin.exe
2021-09-16 13:35 - 2021-09-16 13:35 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2021-09-16 13:35 - 2021-09-16 13:35 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConsoleLogon.dll
2021-09-16 13:35 - 2021-09-16 13:35 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2021-09-16 13:35 - 2021-09-16 13:35 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerWizardElev.exe
2021-09-16 13:35 - 2021-09-16 13:35 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe
2021-09-16 13:35 - 2021-09-16 13:35 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeui.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 24272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 19866112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 18767872 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 18082304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 07111168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 06444544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 04807144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 04315136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 03664384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 03567928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 02663424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 02527824 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 02453384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2021-09-16 13:34 - 2021-09-16 13:34 - 02345424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 02137248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2021-09-16 13:34 - 2021-09-16 13:34 - 02122848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 01956552 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 01887776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 01826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 01770576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 01506632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 01352256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 01335656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 01315144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 01301592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 01165392 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 01014896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00980328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00896000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00829952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00710656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PayloadRestrictions.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00676864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00530976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00482304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00452096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-09-16 13:34 - 2021-09-16 13:34 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00382976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00353264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsensorgroup.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FrameServerClient.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BioCredProv.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GameBarPresenceWriter.exe
2021-09-16 13:34 - 2021-09-16 13:34 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Robocopy.exe
2021-09-16 13:34 - 2021-09-16 13:34 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2021-09-16 13:34 - 2021-09-16 13:34 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GameBarPresenceWriter.proxy.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 23448576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 08238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 07776768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 07648256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 06001232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 03298816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 02428752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 02237752 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 01982264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 01721168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 01570640 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 01313608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-09-16 13:32 - 2021-09-16 13:32 - 01296384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 01268048 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 01133056 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 01100800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 01073664 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 01005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00988672 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00977920 _____ (Microsoft Corporation) C:\WINDOWS\system32\PayloadRestrictions.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00902656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00894976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00806216 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00790344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00678200 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00672768 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcIsoCtnr.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00640512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00570368 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-09-16 13:32 - 2021-09-16 13:32 - 00547328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00539648 _____ (Microsoft Corporation) C:\WINDOWS\system32\IESettingSync.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00520704 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00422912 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServerClient.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00416880 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00413680 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00413256 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00362672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00360960 _____ (Microsoft Corporation) C:\WINDOWS\system32\GameBarPresenceWriter.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00307512 _____ (Microsoft Corporation) C:\WINDOWS\system32\computestorage.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00304344 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdsdwmdr.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00220472 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrobj.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Robocopy.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetpp.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupcln.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscript.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscript.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcwutl.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx
2021-09-16 13:32 - 2021-09-16 13:32 - 00118072 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00117584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2021-09-16 13:32 - 2021-09-16 13:32 - 00105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00101312 _____ (Microsoft Corporation) C:\WINDOWS\system32\FsIso.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00095056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2021-09-16 13:32 - 2021-09-16 13:32 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\klist.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetppui.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnpinst.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshcon.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00021328 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dispex.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcwrun.exe
2021-09-16 13:32 - 2021-09-16 13:32 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\GameBarPresenceWriter.proxy.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 00011355 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-09-16 13:31 - 2021-09-16 13:32 - 00582656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\printui.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 08889968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 04493312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 04466160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupapi.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 03824712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2021-09-16 13:31 - 2021-09-16 13:31 - 02637704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 01696696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 01678848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 01618744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 01468928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12Core.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 01452880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 01148928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 01029632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 01013352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00978944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00964776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2021-09-16 13:31 - 2021-09-16 13:31 - 00926560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00896096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00738816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00603984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00586752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00535584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00475448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00452480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00355328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2021-09-16 13:31 - 2021-09-16 13:31 - 00319488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntprint.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00297984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00265216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winsku.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00250368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\newdev.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00244736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pdh.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00232784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtutil.exe
2021-09-16 13:31 - 2021-09-16 13:31 - 00177152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devicengccredprov.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngckeyenum.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00152392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbrand.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvsetup.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00132936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupcl.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\compstui.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00092960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\printui.exe
2021-09-16 13:31 - 2021-09-16 13:31 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntprint.exe
2021-09-16 13:31 - 2021-09-16 13:31 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngclocal.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KeyCredMgr.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\findnetprinters.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mskeyprotect.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edpnotify.exe
2021-09-16 13:31 - 2021-09-16 13:31 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\runonce.exe
2021-09-16 13:31 - 2021-09-16 13:31 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00037688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininitext.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmintegrator.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wowreg32.exe
2021-09-16 13:31 - 2021-09-16 13:31 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dabapi.dll
2021-09-16 13:31 - 2021-09-16 13:31 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchTM.exe
2021-09-16 13:30 - 2021-09-16 13:30 - 07632792 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 06920704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 06360648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 04783616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 04687256 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupapi.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 04419688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2021-09-16 13:30 - 2021-09-16 13:30 - 02844672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 02433024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 02348544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 02111488 _____ (Digimarc) C:\WINDOWS\SysWOW64\DMRCDecoder.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 01963712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 01951744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 01696760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 01660928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 01633104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 01475072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 01333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 01164288 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2021-09-16 13:30 - 2021-09-16 13:30 - 01127424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 01125888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 01066040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00969032 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2021-09-16 13:30 - 2021-09-16 13:30 - 00921600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00878592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00861696 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00858880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00836096 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00820224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00766440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPKsp.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00753592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00725504 _____ (Microsoft Corporation) C:\WINDOWS\system32\printui.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00646472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00640800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00622080 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.ConversationalAgent.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00542864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00516096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00509256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WwaApi.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2021-09-16 13:30 - 2021-09-16 13:30 - 00377344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntprint.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00366672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanui.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadauthhelper.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe
2021-09-16 13:30 - 2021-09-16 13:30 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\newdev.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00322560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00289192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.Ngc.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlancfg.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmWmiPl.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrobj.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2021-09-16 13:30 - 2021-09-16 13:30 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupcln.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
2021-09-16 13:30 - 2021-09-16 13:30 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\L2SecHC.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscript.exe
2021-09-16 13:30 - 2021-09-16 13:30 - 00151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.OneCore.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx
2021-09-16 13:30 - 2021-09-16 13:30 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAuto.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00140976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingMonitor.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleprn.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Credentials.UI.UserConsentVerifier.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spbcd.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\findnetprinters.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManMigrationPlugin.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\printui.exe
2021-09-16 13:30 - 2021-09-16 13:30 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntprint.exe
2021-09-16 13:30 - 2021-09-16 13:30 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmRes.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00061768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GameInput.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmprovhost.exe
2021-09-16 13:30 - 2021-09-16 13:30 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2021-09-16 13:30 - 2021-09-16 13:30 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2021-09-16 13:30 - 2021-09-16 13:30 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dispex.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAgent.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshcon.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemEventsBrokerClient.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsregtask.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wowreg32.exe
2021-09-16 13:30 - 2021-09-16 13:30 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmplpxy.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 00003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCertResources.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 10846544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2021-09-16 13:29 - 2021-09-16 13:29 - 10343136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 05016064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 04629312 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2021-09-16 13:29 - 2021-09-16 13:29 - 03826688 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 03507504 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 02991944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2021-09-16 13:29 - 2021-09-16 13:29 - 02923944 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 02851656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2021-09-16 13:29 - 2021-09-16 13:29 - 02183256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 02024728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 01980760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 01945600 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 01751424 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 01655296 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 01394008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 01383144 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 01340416 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 01257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 01126488 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00943616 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2021-09-16 13:29 - 2021-09-16 13:29 - 00916336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00892928 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00867328 _____ (Microsoft Corporation) C:\WINDOWS\system32\conhost.exe
2021-09-16 13:29 - 2021-09-16 13:29 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2021-09-16 13:29 - 2021-09-16 13:29 - 00786744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00762704 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00746912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2021-09-16 13:29 - 2021-09-16 13:29 - 00714752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00707536 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00655176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2021-09-16 13:29 - 2021-09-16 13:29 - 00649736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00598344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00577872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2021-09-16 13:29 - 2021-09-16 13:29 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2021-09-16 13:29 - 2021-09-16 13:29 - 00529968 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00502600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2021-09-16 13:29 - 2021-09-16 13:29 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrGidsHandler.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2021-09-16 13:29 - 2021-09-16 13:29 - 00456008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2021-09-16 13:29 - 2021-09-16 13:29 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00432856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2021-09-16 13:29 - 2021-09-16 13:29 - 00423760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2021-09-16 13:29 - 2021-09-16 13:29 - 00407368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2021-09-16 13:29 - 2021-09-16 13:29 - 00383784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00350208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00268616 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00265016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2021-09-16 13:29 - 2021-09-16 13:29 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\devicengccredprov.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\NetAdapterCx.sys
2021-09-16 13:29 - 2021-09-16 13:29 - 00180024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2021-09-16 13:29 - 2021-09-16 13:29 - 00152576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00146944 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00142136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2021-09-16 13:29 - 2021-09-16 13:29 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00134992 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00124752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dab.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\spbcd.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngclocal.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\KeyCredMgr.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpnotify.exe
2021-09-16 13:29 - 2021-09-16 13:29 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\runonce.exe
2021-09-16 13:29 - 2021-09-16 13:29 - 00057656 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2021-09-16 13:29 - 2021-09-16 13:29 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagnosticdataquery.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00046392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininitext.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmsgapi.dll
2021-09-16 13:29 - 2021-09-16 13:29 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dabapi.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 06413312 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 03919872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 03589120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 03402240 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 03232056 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 03143168 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 02826240 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 02594640 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 02466816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 02007368 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 02004808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2021-09-16 13:28 - 2021-09-16 13:28 - 01823304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-09-16 13:28 - 2021-09-16 13:28 - 01780736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 01638400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MoUsoCoreWorker.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 01571840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConstraintIndex.Search.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 01556192 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 01413632 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 01393480 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-09-16 13:28 - 2021-09-16 13:28 - 01223576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 01214264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 01213232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 01208832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 01197744 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 01152512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\refsutil.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00876344 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00852280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00813568 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00764728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00672056 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00645112 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00629248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00602424 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00582088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00581944 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00522064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00479544 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\RasMediaManager.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00390144 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00379904 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsku.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00266056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinREAgent.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00214840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2021-09-16 13:28 - 2021-09-16 13:28 - 00214016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00204560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbrand.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAuto.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidpolicyconverter.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00160056 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00152912 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupcl.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00102712 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManMigrationPlugin.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00064016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmRes.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidcertstorecheck.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmprovhost.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00039760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2021-09-16 13:28 - 2021-09-16 13:28 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAgent.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidtel.exe
2021-09-16 13:28 - 2021-09-16 13:28 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\applockerfltr.sys
2021-09-16 13:28 - 2021-09-16 13:28 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmplpxy.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll
2021-09-16 13:28 - 2021-09-16 13:28 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchTM.exe
2021-09-16 13:27 - 2021-09-16 13:28 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 17539584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 08016600 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 07964480 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 06191616 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 05754856 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 04850432 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2021-09-16 13:27 - 2021-09-16 13:27 - 04732928 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 03817984 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2021-09-16 13:27 - 2021-09-16 13:27 - 03814216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2021-09-16 13:27 - 2021-09-16 13:27 - 03750400 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 03182080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 02893824 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2021-09-16 13:27 - 2021-09-16 13:27 - 02653696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 02503520 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 02308096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 02295296 _____ (Digimarc) C:\WINDOWS\system32\DMRCDecoder.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 02260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 02250240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 02077696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01865528 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01862016 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12Core.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01829192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01708056 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01523200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01427456 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01366528 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsf3gip.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01327416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01298992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01273344 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01149704 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPKsp.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01147904 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01101824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01096192 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01092424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2021-09-16 13:27 - 2021-09-16 13:27 - 01040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01015944 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 01012736 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00967168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2021-09-16 13:27 - 2021-09-16 13:27 - 00935424 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00902984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2021-09-16 13:27 - 2021-09-16 13:27 - 00888832 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00856336 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2021-09-16 13:27 - 2021-09-16 13:27 - 00804864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00770144 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2021-09-16 13:27 - 2021-09-16 13:27 - 00739840 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds.exe
2021-09-16 13:27 - 2021-09-16 13:27 - 00713728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFDSConMgrSvc.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00668672 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00635840 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00634368 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00598016 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2021-09-16 13:27 - 2021-09-16 13:27 - 00569344 _____ (Microsoft Corporation) C:\WINDOWS\system32\WwaApi.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2021-09-16 13:27 - 2021-09-16 13:27 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00469496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadauthhelper.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00454992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2021-09-16 13:27 - 2021-09-16 13:27 - 00435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanui.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00383248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00382696 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialEnrollmentManager.exe
2021-09-16 13:27 - 2021-09-16 13:27 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioCredProv.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00326656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlancfg.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00295936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00272384 _____ C:\WINDOWS\system32\TpmTool.exe
2021-09-16 13:27 - 2021-09-16 13:27 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcrecovery.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00248320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtutil.exe
2021-09-16 13:27 - 2021-09-16 13:27 - 00242688 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.OneCore.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\L2SecHC.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00194560 _____ (Microsoft Corporation) C:\WINDOWS\system32\cimfs.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcProCsp.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00166312 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingMonitor.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00162816 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2021-09-16 13:27 - 2021-09-16 13:27 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Credentials.UI.UserConsentVerifier.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2021-09-16 13:27 - 2021-09-16 13:27 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsutil.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00132744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmclient.exe
2021-09-16 13:27 - 2021-09-16 13:27 - 00118096 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds_ps.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00098816 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-09-16 13:27 - 2021-09-16 13:27 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolss.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwififlt.sys
2021-09-16 13:27 - 2021-09-16 13:27 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\keepaliveprovider.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00070968 _____ (Microsoft Corporation) C:\WINDOWS\system32\GameInput.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mskeyprotect.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintIsolationProxy.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2021-09-16 13:27 - 2021-09-16 13:27 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\FaxPrinterInstaller.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerClient.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsldr.exe
2021-09-16 13:27 - 2021-09-16 13:27 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregtask.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbservicetrigger.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CSystemEventsBrokerClient.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 00003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCertResources.dll
2021-09-16 13:26 - 2021-09-16 13:27 - 00823296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys
2021-09-16 13:26 - 2021-09-16 13:26 - 01580544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2021-09-16 13:26 - 2021-09-16 13:26 - 01563136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2021-09-16 13:26 - 2021-09-16 13:26 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2021-09-16 13:26 - 2021-09-16 13:26 - 00781824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2021-09-16 13:26 - 2021-09-16 13:26 - 00715088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2021-09-16 13:26 - 2021-09-16 13:26 - 00648016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2021-09-16 13:26 - 2021-09-16 13:26 - 00490808 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2021-09-16 13:26 - 2021-09-16 13:26 - 00475976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2021-09-16 13:26 - 2021-09-16 13:26 - 00399872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthAvctpSvc.dll
2021-09-16 13:26 - 2021-09-16 13:26 - 00319800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbvideo.sys
2021-09-16 13:26 - 2021-09-16 13:26 - 00248320 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2021-09-16 13:26 - 2021-09-16 13:26 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ManageCI.dll
2021-09-16 13:26 - 2021-09-16 13:26 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBAUDIO.sys
2021-09-16 13:26 - 2021-09-16 13:26 - 00156488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2021-09-16 13:26 - 2021-09-16 13:26 - 00113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2021-09-16 13:26 - 2021-09-16 13:26 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2021-09-16 13:26 - 2021-09-16 13:26 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2021-09-16 13:26 - 2021-09-16 13:26 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2021-09-16 13:26 - 2021-09-16 13:26 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\bfsvc.exe
2021-09-16 13:26 - 2021-09-16 13:26 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2021-09-16 13:26 - 2021-09-16 13:26 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthMini.SYS
2021-09-16 13:26 - 2021-09-16 13:26 - 00022864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\isapnp.sys
2021-09-16 13:26 - 2021-09-16 13:26 - 00020280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msisadrv.sys
2021-09-16 11:32 - 2021-09-16 11:32 - 00000000 ___HD C:\$WinREAgent
2021-09-16 11:29 - 2021-08-09 22:44 - 00495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2021-09-16 11:29 - 2021-08-09 22:36 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2021-08-24 08:54 - 2021-08-24 08:56 - 01485796 _____ C:\WINDOWS\Minidump\082421-46375-01.dmp
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2021-09-21 12:00 - 2019-12-07 04:14 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-09-21 11:53 - 2020-11-22 01:42 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee
2021-09-21 11:53 - 2019-12-07 04:13 - 00000000 ____D C:\WINDOWS\INF
2021-09-21 11:31 - 2020-12-15 16:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2021-09-21 10:25 - 2020-11-22 01:09 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2021-09-19 15:26 - 2019-04-03 16:04 - 00000000 ___RD C:\Users\ejbea\OneDrive
2021-09-19 15:20 - 2020-12-15 17:15 - 00000000 __RSD C:\Users\ejbea\OneDrive\Mobile uploads\Documents\McAfee Vaults
2021-09-19 15:19 - 2019-04-03 15:56 - 00000000 __SHD C:\Users\ejbea\IntelGraphicsProfiles
2021-09-19 15:17 - 2019-12-07 04:03 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2021-09-19 15:14 - 2020-11-22 01:42 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-09-19 15:14 - 2020-11-22 01:09 - 00008192 ___SH C:\DumpStack.log.tmp
2021-09-19 15:14 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\ServiceState
2021-09-18 22:38 - 2019-12-07 04:14 - 00000000 ___HD C:\Program Files\WindowsApps
2021-09-18 22:38 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\AppReadiness
2021-09-18 22:35 - 2020-11-22 01:16 - 00000000 ____D C:\Users\ejbea
2021-09-18 22:34 - 2019-02-08 15:05 - 00000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-09-18 22:25 - 2019-03-30 01:58 - 00803176 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2021-09-17 19:05 - 2020-07-09 16:01 - 00002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-09-17 19:05 - 2020-07-09 16:01 - 00002278 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-09-16 15:13 - 2020-11-22 01:28 - 00797618 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-09-16 15:09 - 2020-11-22 01:09 - 00448408 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-09-16 15:06 - 2019-12-07 04:03 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2021-09-16 15:04 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2021-09-16 15:04 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-09-16 15:04 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-09-16 15:03 - 2019-12-07 04:14 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-09-16 15:03 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\SystemResources
2021-09-16 15:03 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2021-09-16 15:03 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-09-16 15:03 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\system32\oobe
2021-09-16 15:03 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\system32\migwiz
2021-09-16 15:03 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\system32\Dism
2021-09-16 15:03 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\system32\DDFs
2021-09-16 15:03 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\system32\appraiser
2021-09-16 15:03 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\ShellComponents
2021-09-16 15:03 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\Provisioning
2021-09-16 15:03 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\bcastdvr
2021-09-16 15:03 - 2019-12-07 04:03 - 00000000 ____D C:\WINDOWS\servicing
2021-09-16 13:59 - 2019-12-07 04:03 - 00000000 ____D C:\WINDOWS\CbsTemp
2021-09-16 11:26 - 2019-04-03 18:07 - 00000000 ____D C:\WINDOWS\system32\MRT
2021-09-16 11:19 - 2019-04-03 18:07 - 135637312 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-09-15 20:46 - 2020-11-22 01:42 - 00003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3457983286-1419784188-334204780-1001
2021-09-15 20:46 - 2020-11-22 01:16 - 00002381 _____ C:\Users\ejbea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-09-12 23:00 - 2019-04-03 15:56 - 00000000 ____D C:\Users\ejbea\AppData\Local\Packages
2021-09-12 13:01 - 2020-10-01 18:41 - 00000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-09-09 17:30 - 2019-02-08 15:35 - 00000000 ____D C:\Program Files\Common Files\mcafee
2021-09-09 17:27 - 2020-11-22 01:42 - 00003316 _____ C:\WINDOWS\System32\Tasks\McAfeeLogon
2021-09-08 16:58 - 2020-11-22 01:42 - 00003710 _____ C:\WINDOWS\System32\Tasks\McAfee Remediation (Prepare)
2021-09-04 19:05 - 2019-12-07 04:14 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2021-09-04 09:49 - 2019-06-04 22:14 - 00000000 ____D C:\Users\ejbea\AppData\Local\D3DSCache
2021-08-26 19:23 - 2019-06-18 17:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2021-08-24 08:57 - 2021-03-01 21:21 - 00000000 ____D C:\WINDOWS\Minidump
2021-08-24 08:54 - 2019-10-12 18:06 - 801071561 _____ C:\WINDOWS\MEMORY.DMP
 
==================== Files in the root of some directories =======
 
2019-07-04 20:07 - 2020-03-10 10:16 - 0000479 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
 
Some files in TEMP:
====================
2021-08-17 15:51 - 2021-08-17 15:51 - 0015488 _____ () C:\Users\ejbea\AppData\Local\Temp\BullseyeCoverage-x64-ic-6.dll
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
C:\WINDOWS\system32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION
 
==================== End of FRST.txt ============================
 
 
Addition
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-04-2017 01
Ran by ejbea (21-09-2021 12:01:42)
Running from C:\Users\ejbea\OneDrive\Desktop
Windows 10 Home Version 2004 (X64) (2020-11-22 06:44:39)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3457983286-1419784188-334204780-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3457983286-1419784188-334204780-503 - Limited - Disabled)
ejbea (S-1-5-21-3457983286-1419784188-334204780-1001 - Administrator - Enabled) => C:\Users\ejbea
Guest (S-1-5-21-3457983286-1419784188-334204780-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-3457983286-1419784188-334204780-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee VirusScan (Enabled - Up to date) {9D4501E6-72F6-2877-C789-89AF6F535B2C}
AS: McAfee VirusScan (Enabled - Up to date) {4DE344F8-6897-65B4-CED0-82B3AF2591B4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall (Enabled) {A57E80C3-3899-292F-ECD6-209A91801C57}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Dell Mobile Connect Drivers (HKLM\...\{04DF02C6-E3D7-4D26-A44C-6F8A2E218D2C}) (Version: 1.3.6844 - Screenovate Technologies Ltd.)
Dell SupportAssist Remediation (HKLM-x32\...\{f4ee83d8-d901-4c1a-b5a2-288427598fe2}) (Version: 4.1.0.6830 - Dell Inc.)
Dell SupportAssist Remediation (Version: 4.1.0.6830 - Dell Inc.) Hidden
Dell Touchpad (HKLM\...\SynTPDeinstKey) (Version: 19.2.17.70 - Synaptics Incorporated)
Dell Update - SupportAssist Update Plugin (HKLM-x32\...\{286db51f-336c-4d5e-b1e2-3fbc3becd693}) (Version: 4.1.0.6830 - Dell Inc.)
Dell Update - SupportAssist Update Plugin (Version: 4.1.0.6830 - Dell Inc.) Hidden
Dell Update for Windows 10 (HKLM\...\{70E9F8CC-A23E-4C25-B292-C86C1821587C}) (Version: 3.0.1 - Dell, Inc.)
Intel® Chipset Device Software (x32 Version: 10.1.1.38 - Intel® Corporation) Hidden
Intel® Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.3.10207.5567 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1054 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 23.20.16.4973 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.2.0.1020 - Intel Corporation)
Intel® Trusted Connect Service Client x86 (x32 Version: 1.47.866.0 - Intel Corporation) Hidden
Intel® Trusted Connect Services Client (x32 Version: 1.47.866.0 - Intel Corporation) Hidden
Intel® Wireless Bluetooth® (HKLM-x32\...\{00000060-0200-1033-84C8-B8D95FA3C8C3}) (Version: 20.60.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{a914536c-bd41-479c-96aa-dee4a9639c22}) (Version: 21.10.1 - Intel Corporation)
Intel® Software Guard Extensions Platform Software (HKLM\...\{06F94C28-DE1D-485F-AD91-333ACEB3F52D}) (Version: 1.6.100.32677 - Intel Corporation)
Maxx Audio Installer (x64) (Version: 2.7.9669.4 - Waves Audio Ltd.) Hidden
McAfee LiveSafe (HKLM-x32\...\MSC) (Version: 16.0 R37 - McAfee, LLC)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.14326.20238 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 93.0.961.52 - Microsoft Corporation)
Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.151.27 - )
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 93.0.961.52 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3457983286-1419784188-334204780-1001\...\OneDriveSetup.exe) (Version: 21.170.0822.0002 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{7B981965-2FBC-433C-B4B3-E183EE97CD29}) (Version: 2.83.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.14326.20238 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.14326.20238 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.14326.20238 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
QuickSet64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 11.1.40 - Dell Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.31228 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8622 - Realtek Semiconductor Corp.)
SmartByte Drivers and Services (HKLM\...\{01F01829-4C5A-41B0-8198-0BDD02B34C47}) (Version: 2.0.643 - Rivet Networks)
TurboTax 2018 (HKLM-x32\...\TurboTax 2018) (Version: 2018.0 - Intuit, Inc)
TurboTax 2019 (HKLM-x32\...\TurboTax 2019) (Version: 2019.0 - Intuit, Inc)
Vulkan Run Time Libraries 1.0.65.1 (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WebAdvisor by McAfee (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.1.140 - McAfee, LLC)
Zoom (HKU\S-1-5-21-3457983286-1419784188-334204780-1001\...\ZoomUMX) (Version: 5.1 - Zoom Video Communications, Inc.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3457983286-1419784188-334204780-1001_Classes\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InprocServer32 -> C:\Users\ejbea\AppData\Local\Microsoft\OneDrive\21.170.0822.0002\FileCoAuthLib64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3457983286-1419784188-334204780-1001_Classes\CLSID\{a9872fee-5a55-4ecb-9b0f-b06fedcf14d1}\localserver32 -> C:\Program Files\Waves\MaxxAudio\MaxxAudioPro.exe (Waves Audio Ltd)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {008539BF-83F9-4483-9E0A-EEEE6EAC0A08} - System32\Tasks\Microsoft\Windows\Shell\UpdateUserPictureTask
Task: {0641A910-0E57-4016-A931-6E9AED33BBB0} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceWnsFallback
Task: {077333D6-06BA-4EA4-BDF4-1CD1439558F2} - System32\Tasks\Microsoft\Windows\BrokerInfrastructure\BgTaskRegistrationMaintenanceTask
Task: {0CBABB27-6DFC-4155-BAE7-AE919B92FEF2} - System32\Tasks\Microsoft\Windows\DirectX\DXGIAdapterCache => C:\WINDOWS\system32\dxgiadaptercache.exe [2021-04-16] (Microsoft Corporation)
Task: {0CEC0B91-4AE9-4E8A-ACB2-3B4C811F442C} - System32\Tasks\Microsoft\Windows\WaaSMedic\PerformRemediation
Task: {0E2DCCB3-7B11-40CF-B973-90F22732E317} - System32\Tasks\Microsoft\Windows\EDP\EDP Inaccessible Credentials Task
Task: {105D676A-D551-4274-81E7-97AC52E4FD87} - System32\Tasks\Microsoft\Windows\Speech\HeadsetButtonPress => C:\WINDOWS\system32\speech_onecore\common\SpeechRuntime.exe [2021-06-10] (Microsoft Corporation)
Task: {12DF3F8A-9612-48CA-AE38-2818FA70CA73} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2021-09-16] ()
Task: {2A2980C0-E808-4E68-857A-ACF32E20DEA9} - System32\Tasks\Microsoft\Windows\Diagnosis\RecommendedTroubleshootingScanner
Task: {304D2127-E6ED-4C82-B9B3-63B3B54A4D66} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Check And Scan
Task: {34A8D19D-910E-488B-A7B4-01B7A8C9C314} - System32\Tasks\Microsoft\Windows\WwanSvc\OobeDiscovery
Task: {34ADEFE8-89DB-43BC-8C0B-14BB34D69F6D} - System32\Tasks\Microsoft\Windows\BitLocker\BitLocker Encrypt All Drives
Task: {35525E8D-FD60-47BF-8D11-FA4F778C57C3} - System32\Tasks\Microsoft\Windows\Printing\EduPrintProv => C:\WINDOWS\system32\eduprintprov.exe [2019-12-07] (Microsoft Corporation)
Task: {3A36A1B6-E37D-4EDA-8551-E64F71C2280F} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [2021-08-26] (Microsoft Corporation)
Task: {3F2C0611-A707-4EE5-B1C2-510E1C9C381C} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2021-08-26] (Microsoft Corporation)
Task: {3FC4BE91-4A96-48F5-8858-1628CB88EFB5} - System32\Tasks\Microsoft\Windows\Chkdsk\SyspartRepair => C:\WINDOWS\system32\bcdboot.exe [2021-09-16] (Microsoft Corporation)
Task: {421EB07E-45E3-4F51-9E93-15EA2C26858C} - System32\Tasks\Microsoft\Windows\Flighting\FeatureConfig\UsageDataReporting
Task: {44AF7ADA-1C0D-43B1-A063-9E7581F7730B} - System32\Tasks\Microsoft\Windows\InstallService\SmartRetry
Task: {45C19C88-2540-4538-89E6-64CA0C4A968C} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent
Task: {4A0DEFDA-A2B8-4736-88E1-A578E00D9704} - System32\Tasks\Microsoft\Windows\Input\PenSyncDataAvailable
Task: {4BCE6391-0B05-40B4-B642-910B37FB1CE6} - System32\Tasks\Microsoft\Windows\PushToInstall\Registration => Sc.exe start pushtoinstall registration
Task: {4CA61756-72D5-4B5F-B383-893E44C3C111} - System32\Tasks\Microsoft\Windows\Flighting\FeatureConfig\ReconcileFeatures
Task: {4DA488F5-2651-4698-B612-178907141643} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2021-08-23] (Microsoft Corporation)
Task: {4F2030CE-BA8E-4122-B9A8-29AA5858973E} - System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache
Task: {5300D027-704A-42B3-87FB-53C63FB81C6A} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [2021-08-16] (McAfee, LLC)
Task: {55B1C85E-5BEF-4EDB-ADD0-ECEAEF261E7C} - System32\Tasks\Microsoft\Windows\DirectX\DirectXDatabaseUpdater => C:\WINDOWS\system32\directxdatabaseupdater.exe [2021-04-16] (Microsoft Corporation)
Task: {571A0A5E-B60E-4A25-BEFB-ABB3C6BB6B78} - System32\Tasks\Microsoft\Windows\Workplace Join\Device-Sync
Task: {58CCC4DA-C86D-4E3D-8FAF-A7B24D8F3950} - System32\Tasks\Microsoft\Windows\StateRepository\MaintenanceTasks => Rundll32.exe %windir%\system32\Windows.StateRepositoryClient.dll,StateRepositoryDoMaintenanceTasks
Task: {5DBDF6D9-3014-423A-B68E-E0B120525B96} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d6c09861562f5c => C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-07-09] (Microsoft Corporation) <==== ATTENTION
Task: {5E351EE7-F0D4-4F41-A05C-907EB1A33CE8} - System32\Tasks\Microsoft\Windows\WlanSvc\CDSSync
Task: {66A3F618-0C70-4F70-9BBA-735CCDB43A09} - System32\Tasks\Microsoft\Windows\EDP\StorageCardEncryption Task
Task: {74670E62-F3CD-44B5-AE43-03E0FC2DD218} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2021-08-23] (Microsoft Corporation)
Task: {7C1E17E4-F942-4719-ADB5-BA56FCA8C8F8} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore => C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-07-09] (Microsoft Corporation) <==== ATTENTION
Task: {7C4733D2-81D6-4CA3-B30C-E00B496B9857} - System32\Tasks\Microsoft\Windows\Input\TouchpadSyncDataAvailable
Task: {7D24E915-203B-46BB-BAA3-1B7076BC9B72} - System32\Tasks\McAfee\McAfee DAT Built in test => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.0.12.663\mcdatrep.exe [2021-01-07] (McAfee, LLC.)
Task: {8093A7E8-E197-4C98-B6AA-FAB9390C8159} - System32\Tasks\Microsoft\Windows\Application Experience\PcaPatchDbTask => Rundll32.exe %windir%\system32\PcaSvc.dll,PcaPatchSdbTask
Task: {87094343-6C1F-4855-A6B9-305BA74AB761} - System32\Tasks\Microsoft\Windows\BitLocker\BitLocker MDM policy Refresh
Task: {8B4DF5ED-846A-4856-850C-50ABD39BEDDE} - System32\Tasks\SmartByte Telemetry => C:\Program Files\Rivet Networks\SmartByte\SmartByteTelemetry.exe [2018-12-04] (DELL)
Task: {9B29B882-A95C-438B-BF91-E7C31B1D82D1} - System32\Tasks\Microsoft\Windows\InstallService\WakeUpAndContinueUpdates
Task: {A08D6A77-C926-4E78-9ED0-09836E2769AE} - System32\Tasks\Microsoft\Windows\InstallService\ScanForUpdates
Task: {A2FADBDF-6855-42F7-BDFC-F0C510EDA9BC} - System32\Tasks\Microsoft\Windows\InstallService\ScanForUpdatesAsUser
Task: {A499FA48-7057-4AC1-9702-44C6FD924058} - System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\ReconcileLanguageResources
Task: {A60D9ECB-A6F4-4FE1-9BD7-B049487A67E7} - System32\Tasks\Microsoft\Windows\International\Synchronize Language Settings
Task: {A74EF9D1-6D6B-4566-8E25-782430F970E5} - System32\Tasks\Microsoft\Windows\PushToInstall\LoginCheck => Sc.exe start pushtoinstall login
Task: {AEA36979-6D97-4FF9-AC21-B87088C23D3B} - System32\Tasks\Agent Activation Runtime\S-1-5-21-3457983286-1419784188-334204780-1001 => C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe [2021-05-15] ()
Task: {AF73DAAA-53AE-4CC8-8671-BE29D886B057} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceProtectionStateChanged
Task: {BD76146D-5506-4D93-AFD4-C6EFBF677F4F} - System32\Tasks\Microsoft\Windows\Subscription\EnableLicenseAcquisition => C:\WINDOWS\system32\ClipRenew.exe [2019-12-07] (Microsoft Corporation)
Task: {C0D40F39-515D-4FA6-A2A4-5F17794320DF} - System32\Tasks\Microsoft\Windows\Subscription\LicenseAcquisition => C:\WINDOWS\system32\ClipRenew.exe [2019-12-07] (Microsoft Corporation)
Task: {C5D47392-881C-422A-9BF8-E4916B55CD22} - System32\Tasks\Microsoft\Windows\USB\Usb-Notifications
Task: {CAB76809-EDC0-40D2-A888-AD9BEDF4E88A} - System32\Tasks\Microsoft\Windows\UNP\RunUpdateNotificationMgr => C:\WINDOWS\System32\UNP\UpdateNotificationMgr.exe [2021-08-14] (Microsoft Corporation)
Task: {CADF1293-5495-426F-8E37-A30F69274AF4} - System32\Tasks\Microsoft\Windows\Input\LocalUserSyncDataAvailable
Task: {CCA6AD34-8445-4B13-B68E-47223883D621} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineUA => C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-07-09] (Microsoft Corporation) <==== ATTENTION
Task: {D4273156-AC6B-4500-AAF9-7DBB5A0D1988} - System32\Tasks\McAfee\DAD.Execute.Updates => C:\Program Files\Common Files\McAfee\DynamicAppDownloader\DADUpdater.exe [2021-08-12] (McAfee, LLC)
Task: {D7294A9A-3352-49AB-B910-8E199838193E} - System32\Tasks\McAfee\McAfee Idle Detection Task
Task: {D73F81A3-C8FD-405A-B3D5-04A71113FEB1} - System32\Tasks\Microsoft\Windows\Flighting\FeatureConfig\UsageDataFlushing
Task: {DA42085F-11E4-4EE1-A363-1898204812F5} - System32\Tasks\Microsoft\Windows\Input\MouseSyncDataAvailable
Task: {DA5F1CB2-CBEE-4D4B-B0BA-A0654EFEDEF0} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [2021-05-06] (McAfee, LLC)
Task: {DAF79D90-BEF1-4D5D-B5C7-4BD2C4EAEB96} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [2021-08-26] (Microsoft Corporation)
Task: {EC3EFE4E-A2E4-4C66-975C-CA2EFD0D42CD} - System32\Tasks\Microsoft\Windows\InstallService\WakeUpAndScanForUpdates
Task: {F8FEDA28-6261-4385-844A-684E6C988577} - System32\Tasks\Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\ejbea\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__bdaipkelaldmidppbfaafolldkbdenfg\Home _ BVSCU.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) ->  --profile-directory=Default --app-id=bdaipkelaldmidppbfaafolldkbdenfg --app-url=hxxps://www.bvscu.org/
ShortcutWithArgument: C:\Users\ejbea\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) -> --profile-directory=Default
 
==================== Loaded Modules (Whitelisted) ==============
 
2020-11-22 02:35 - 2020-11-22 02:35 - 00064552 _____ () C:\WINDOWS\system32\UMPDC.dll
2020-11-22 02:35 - 2020-11-22 02:35 - 00064552 _____ () c:\windows\system32\UMPDC.dll
2020-11-22 02:35 - 2020-11-22 02:35 - 00064552 _____ () C:\Windows\System32\UMPDC.dll
2020-11-22 02:35 - 2020-11-22 02:35 - 00064552 _____ () C:\WINDOWS\SYSTEM32\UMPDC.dll
2021-06-10 23:11 - 2021-06-10 23:11 - 00657464 _____ () C:\Windows\System32\windowmanagementapi.dll
2021-03-10 15:33 - 2021-03-10 15:33 - 00707016 _____ () C:\WINDOWS\system32\TextShaping.dll
2021-03-10 15:33 - 2021-03-10 15:33 - 00707016 _____ () c:\windows\system32\TextShaping.dll
2020-11-22 02:35 - 2020-11-22 02:35 - 00064552 _____ () C:\WINDOWS\System32\UMPDC.dll
2021-08-26 19:11 - 2021-08-23 09:56 - 01980672 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\MSIX.dll
2019-04-03 08:10 - 2019-04-03 08:10 - 00035976 _____ () C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
2021-09-16 13:27 - 2021-09-16 13:27 - 02260992 _____ () C:\WINDOWS\system32\TextInputMethodFormatter.dll
2019-12-07 04:08 - 2019-12-07 04:08 - 00039424 _____ () C:\Windows\System32\usocoreps.dll
2021-06-10 23:11 - 2021-06-10 23:11 - 00657464 _____ () C:\Windows\System32\WindowManagementAPI.dll
2021-03-10 15:33 - 2021-03-10 15:33 - 00707016 _____ () C:\WINDOWS\SYSTEM32\TextShaping.dll
2020-05-13 12:13 - 2020-05-13 12:13 - 01165824 _____ () C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2108.25001.0_x64__8wekyb3d8bbwe\e_sqlite3.dll
2021-04-01 20:37 - 2021-04-01 20:38 - 00036864 _____ () C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2108.25001.0_x64__8wekyb3d8bbwe\OneSettingsClientForwarder.dll
2021-06-10 23:11 - 2021-06-10 23:11 - 00657464 _____ () C:\WINDOWS\SYSTEM32\WindowManagementAPI.dll
2021-09-03 21:31 - 2021-09-03 21:32 - 00116224 _____ () C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2108.25001.0_x64__8wekyb3d8bbwe\WinRTUtils.dll
2020-12-09 19:37 - 2020-12-09 19:37 - 00073216 _____ () C:\Windows\System32\windows.applicationmodel.conversationalagent.internal.proxystub.dll
2021-07-15 18:57 - 2021-07-15 18:57 - 00622880 _____ () C:\WINDOWS\SYSTEM32\WINBIOPLUGINS\FACEBOOTSTRAPADAPTER.DLL
2021-09-17 19:04 - 2021-09-16 01:48 - 02815888 _____ () C:\Program Files (x86)\Microsoft\Edge\Application\93.0.961.52\ffmpeg.dll
2021-09-17 19:04 - 2021-09-16 01:50 - 06623056 _____ () C:\Program Files (x86)\Microsoft\Edge\Application\93.0.961.52\libglesv2.dll
2021-09-17 19:04 - 2021-09-16 01:50 - 00453968 _____ () C:\Program Files (x86)\Microsoft\Edge\Application\93.0.961.52\libegl.dll
2021-08-14 11:23 - 2021-08-14 11:23 - 00288768 _____ () C:\WINDOWS\System32\Windows.Management.InprocObjects.dll
2021-08-14 11:00 - 2021-08-14 11:01 - 00090624 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_12107.1001.15.0_x64__8wekyb3d8bbwe\WinStore.Preview.dll
2021-03-27 22:34 - 2021-03-27 22:34 - 01418240 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_12107.1001.15.0_x64__8wekyb3d8bbwe\Microsoft.Membership.MeControl.dll
2021-07-31 08:37 - 2021-07-31 08:44 - 00756224 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2021-07-31 08:37 - 2021-07-31 08:44 - 82322944 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2019-05-27 17:28 - 2019-05-27 17:28 - 03707904 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll
2019-04-03 16:47 - 2019-04-03 16:51 - 02523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll
2021-04-12 08:22 - 2021-04-12 08:23 - 00036864 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\OneSettingsClientForwarder.dll
2019-09-26 10:59 - 2019-09-26 11:04 - 00011264 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\RenderingPlugin.dll
2021-07-31 08:37 - 2021-07-31 08:39 - 00104960 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\AppSettingsCppCX.dll
2021-07-31 08:37 - 2021-07-31 08:39 - 01857536 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll
2021-07-31 08:37 - 2021-07-31 08:39 - 00686592 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\AppCoreFramework.Windows.dll
2021-07-31 08:37 - 2021-07-31 08:39 - 06504448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\Lightbox.dll
2021-07-31 08:37 - 2021-07-31 08:39 - 00505856 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\ImageLib.dll
2020-07-16 22:26 - 2020-07-16 22:27 - 01400320 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll
2020-10-05 23:53 - 2020-10-05 23:53 - 00969728 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\OnlineMediaComponent.dll
2021-07-31 08:37 - 2021-07-31 08:45 - 10523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll
2019-05-27 17:28 - 2019-05-27 17:28 - 01014784 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll
2021-01-13 20:00 - 2021-01-13 20:00 - 00095744 _____ () C:\Windows\System32\VirtualMonitorManager.dll
2019-12-07 04:08 - 2019-12-07 04:08 - 00499200 _____ () C:\Windows\ShellExperiences\TileControl.dll
2021-08-14 11:24 - 2021-08-14 11:24 - 02158592 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2021-09-16 13:35 - 2021-09-16 13:35 - 00442368 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\Search.Core.dll
2020-11-22 02:36 - 2020-11-22 02:36 - 00793416 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
2020-08-13 17:06 - 2020-08-13 17:17 - 00634552 _____ () C:\Program Files\WindowsApps\DB6EA5DB.Power2GoforDell_11.0.3920.0_x86__mcezb6ze687jp\Power2Go11\CLMediaLibrary.dll
2017-11-09 03:44 - 2017-11-09 03:44 - 01244304 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioEndpointBuilder => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioSrv => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CBDHSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudAddService.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudBus.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NgcCtnrSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NgcSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SerCx2.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\usbaudio.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318} => ""="Media"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318} => "SafeBootDrivers"="1"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AudioEndpointBuilder => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AudioSrv => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CBDHSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HdAudAddService.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HdAudBus.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MsQuic => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetSetupSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NgcCtnrSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NgcSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SerCx2.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\usbaudio.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96C-E325-11CE-BFC1-08002BE10318} => ""="Media"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96C-E325-11CE-BFC1-08002BE10318} => "SafeBootDrivers"="1"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2018-09-15 02:31 - 2018-09-15 02:31 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3457983286-1419784188-334204780-1001\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [Microsoft-Windows-DeviceManagement-OmaDmClient-TCP-Out] => (Allow) %SystemRoot%\system32\omadmclient.exe
FirewallRules: [Microsoft-Windows-DeviceManagement-deviceenroller-TCP-Out] => (Allow) %SystemRoot%\system32\deviceenroller.exe
FirewallRules: [Microsoft-Windows-DeviceManagement-CertificateInstall-TCP-Out] => (Allow) %SystemRoot%\system32\dmcertinst.exe
FirewallRules: [{C909EBC9-72FD-4AE2-ABD9-AF6AD14CC7E5}] => (Allow) C:\Program Files (x86)\Common Files\McAfee\MMSSHost\MMSSHost.exe
FirewallRules: [{5063EBCB-ABE1-42AB-A083-80AF05CE1048}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe
FirewallRules: [{D83A36C9-79A1-40EB-B4B3-2B46FC066D0A}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{B28F8059-CB4B-40B2-A9C3-27A56B1BDE3F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.11629.20214.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe
FirewallRules: [{89201931-C0C7-4269-8D13-2D10CC494228}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{EE179294-8BE1-48D2-829B-0D208A3ABC0D}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe
FirewallRules: [{008C2730-9A95-4A24-8F94-6D33FC90705E}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{D832794C-2804-4AC3-9A1C-6C4981BD8E14}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{0DF6AE09-D610-435A-B250-F62CFD17A521}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{76FB62CC-CE27-4E18-8A24-CCE2C1D8AB76}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{4B2F5D68-0069-4EB2-98FA-8A01A364A3DE}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{07BB402A-4180-4104-B415-65DACD47B472}] => (Allow) C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.3.9803.0_x64__0vhbc3ng4wbp0\app\DellMobileConnectClient.exe
FirewallRules: [{4A8033E9-B576-4E83-805B-A6496E14239E}] => (Allow) C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.3.9803.0_x64__0vhbc3ng4wbp0\app\DellMobileConnectClient.exe
FirewallRules: [{E1250F2B-4DAF-42E4-88D6-330A3F1F3A04}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
FirewallRules: [{A224DBA5-4E7A-48C3-B08E-B9EFF5329157}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
FirewallRules: [{EF17721C-F271-495B-8942-7BB9128D3DDB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
FirewallRules: [{04B9B98A-720E-449C-B401-045C48635E1B}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
FirewallRules: [{B665FCFF-FAF3-41B8-8D5D-A33E02972549}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{8880C358-2FD4-40F1-A209-CA0ABE4E4D21}] => (Allow) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
FirewallRules: [{6B79E6D0-1443-4BF0-9C14-2F8EAB59166E}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\93.0.961.52\msedgewebview2.exe
 
==================== Restore Points =========================
 
08-09-2021 17:15:32 Scheduled Checkpoint
16-09-2021 11:27:10 Windows Modules Installer
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/21/2021 11:40:10 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program HxOutlook.exe version 16.0.14326.20384 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 2de4
 
Start Time: 01d7af073a28fe29
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20388.0_x64__8wekyb3d8bbwe\HxOutlook.exe
 
Report Id: e22af4fb-8b16-457c-abf8-f3f79752c7f1
 
Faulting package full name: microsoft.windowscommunicationsapps_16005.14326.20388.0_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: microsoft.windowslive.mail
 
Hang type: Quiesce
 
Error: (09/21/2021 10:55:52 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_MapsBroker, version: 10.0.19041.546, time stamp: 0x058e175a
Faulting module name: KERNELBASE.dll, version: 10.0.19041.1202, time stamp: 0xc9db1934
Exception code: 0x8400000e
Fault offset: 0x000000000010be3e
Faulting process id: 0x37b0
Faulting application start time: 0x01d7af010889f60e
Faulting application path: C:\WINDOWS\System32\svchost.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report Id: acf84680-bc1d-419f-98cf-d73e7171372c
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (09/21/2021 10:51:42 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program LockApp.exe version 10.0.19041.844 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 27b4
 
Start Time: 01d7aefa69758767
 
Termination Time: 4294967295
 
Application Path: C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
 
Report Id: 9c219e5e-e895-4f43-805f-d1a67c5fc285
 
Faulting package full name: Microsoft.LockApp_10.0.19041.1023_neutral__cw5n1h2txyewy
 
Faulting package-relative application ID: WindowsDefaultLockScreen
 
Hang type: Cross-process
 
Error: (09/21/2021 10:48:15 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (09/21/2021 10:33:58 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program explorer.exe version 10.0.19041.1202 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 1464
 
Start Time: 01d7ad93ada30389
 
Termination Time: 58
 
Application Path: C:\Windows\explorer.exe
 
Report Id: 300fdb0f-c6f4-495a-9dee-37d023c584d5
 
Faulting package full name: 
 
Faulting package-relative application ID: 
 
Hang type: Unknown
 
Error: (09/21/2021 10:25:11 AM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel® Dynamic Platform and Thermal Framework : ESIF(8.3.10207.5567) TYPE: ERROR MODULE: DPTF TIME 155531945 ms
 
DPTF Build Version:  8.3.10207.5567
DPTF Build Date:  Nov  2 2017 14:28:00
Source File:  ..\..\..\..\Sources\Policies\ConfigTdpPolicy\ConfigTdpPolicy.cpp @ line 155
Executing Function:  ConfigTdpPolicy::onBindDomain
Message:  ConfigTdp not supported.
Participant:  TCPU [0]
Domain:  PKG [0]
Policy:  ConfigTDP Policy [0]
 
Error: (09/21/2021 10:25:11 AM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel® Dynamic Platform and Thermal Framework : ESIF(8.3.10207.5567) TYPE: ERROR MODULE: DPTF TIME 155531936 ms
 
DPTF Build Version:  8.3.10207.5567
DPTF Build Date:  Nov  2 2017 14:28:00
Source File:  ..\..\..\..\Sources\Policies\ConfigTdpPolicy\ConfigTdpPolicy.cpp @ line 342
Executing Function:  ConfigTdpPolicy::synchronizeConfigTdpPlatformSettings
Message:  ConfigTdp not supported.
Policy:  ConfigTDP Policy [0]
 
Error: (09/21/2021 10:06:58 AM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel® Dynamic Platform and Thermal Framework : ESIF(8.3.10207.5567) TYPE: ERROR MODULE: DPTF TIME 154439554 ms
 
DPTF Build Version:  8.3.10207.5567
DPTF Build Date:  Nov  2 2017 14:28:00
Source File:  ..\..\..\..\Sources\Policies\ConfigTdpPolicy\ConfigTdpPolicy.cpp @ line 155
Executing Function:  ConfigTdpPolicy::onBindDomain
Message:  ConfigTdp not supported.
Participant:  TCPU [0]
Domain:  PKG [0]
Policy:  ConfigTDP Policy [0]
 
Error: (09/21/2021 10:06:58 AM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel® Dynamic Platform and Thermal Framework : ESIF(8.3.10207.5567) TYPE: ERROR MODULE: DPTF TIME 154439217 ms
 
DPTF Build Version:  8.3.10207.5567
DPTF Build Date:  Nov  2 2017 14:28:00
Source File:  ..\..\..\..\Sources\Policies\ConfigTdpPolicy\ConfigTdpPolicy.cpp @ line 342
Executing Function:  ConfigTdpPolicy::synchronizeConfigTdpPlatformSettings
Message:  ConfigTdp not supported.
Policy:  ConfigTDP Policy [0]
 
Error: (09/19/2021 06:47:29 PM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel® Dynamic Platform and Thermal Framework : ESIF(8.3.10207.5567) TYPE: ERROR MODULE: DPTF TIME 12863108 ms
 
DPTF Build Version:  8.3.10207.5567
DPTF Build Date:  Nov  2 2017 14:28:00
Source File:  ..\..\..\..\Sources\Policies\ConfigTdpPolicy\ConfigTdpPolicy.cpp @ line 155
Executing Function:  ConfigTdpPolicy::onBindDomain
Message:  ConfigTdp not supported.
Participant:  TCPU [0]
Domain:  PKG [0]
Policy:  ConfigTDP Policy [0]
 
 
System errors:
=============
Error: (09/21/2021 10:59:20 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Rivet Dynamic Bandwidth Management service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (09/21/2021 10:59:20 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Rivet Dynamic Bandwidth Management service to connect.
 
Error: (09/21/2021 10:56:13 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-2KHI5DN)
Description: The server {209500FC-6B45-4693-8871-6296C4843751} did not register with DCOM within the required timeout.
 
Error: (09/21/2021 10:56:00 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Downloaded Maps Manager service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (09/19/2021 03:28:03 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Intel® Management and Security Application Local Management Service service hung on starting.
 
Error: (09/19/2021 03:25:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Intuit Update Service v4 service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (09/19/2021 03:25:52 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Intuit Update Service v4 service to connect.
 
Error: (09/19/2021 03:24:51 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Intel® Rapid Storage Technology service to connect.
 
Error: (09/19/2021 03:16:25 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server Windows.Internal.StateRepository.ApplicationExtension did not register with DCOM within the required timeout.
 
Error: (09/19/2021 03:15:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Rivet Dynamic Bandwidth Management service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
 
CodeIntegrity:
===================================
  Date: 2021-09-21 11:31:47.9120000Z
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Common Files\mcafee\modulecore\ProtectedModuleHost.exe) attempted to load \Device\HarddiskVolume3\Program Files\mcafee.com\agent\WSCLLCGlobalSign.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2021-09-21 11:31:47.8810000Z
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Common Files\mcafee\modulecore\ProtectedModuleHost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\mcafee\platform\core\vtploader.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2021-09-21 11:31:47.8440000Z
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Common Files\mcafee\modulecore\ProtectedModuleHost.exe) attempted to load \Device\HarddiskVolume3\Program Files\mcafee.com\agent\WSCLLCGlobalSign.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2021-09-21 11:31:47.8110000Z
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Common Files\mcafee\modulecore\ProtectedModuleHost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\mcafee\platform\core\vtploader.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2021-09-21 11:31:47.7540000Z
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Common Files\mcafee\modulecore\ProtectedModuleHost.exe) attempted to load \Device\HarddiskVolume3\Program Files\mcafee.com\agent\WSCLLCGlobalSign.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2021-09-21 11:31:47.7190000Z
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Common Files\mcafee\modulecore\ProtectedModuleHost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\mcafee\platform\core\vtploader.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2021-09-21 11:31:47.6510000Z
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Common Files\mcafee\modulecore\ProtectedModuleHost.exe) attempted to load \Device\HarddiskVolume3\Program Files\mcafee.com\agent\WSCLLCGlobalSign.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2021-09-21 11:31:47.6140000Z
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Common Files\mcafee\modulecore\ProtectedModuleHost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\mcafee\platform\core\vtploader.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2021-09-21 11:31:47.5720000Z
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Common Files\mcafee\modulecore\ProtectedModuleHost.exe) attempted to load \Device\HarddiskVolume3\Program Files\mcafee.com\agent\WSCLLCGlobalSign.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2021-09-21 11:31:47.4900000Z
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Common Files\mcafee\modulecore\ProtectedModuleHost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\mcafee\platform\core\vtploader.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i3-7020U CPU @ 2.30GHz
Percentage of memory in use: 81%
Total physical RAM: 3961.88 MB
Available physical RAM: 735.96 MB
Total Virtual: 5625.88 MB
Available Virtual: 1760.99 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:916.28 GB) (Free:845.55 GB) NTFS
Drive d: (ALANJACKSON) (CDROM) (Total:2.84 GB) (Free:0 GB) UDF
Drive e: (TRUDEE) (Removable) (Total:5.58 GB) (Free:3.62 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 6CAC8AAD)
 
Partition: GPT.
 
========================================================
Disk: 1 (Size: 5.6 GB) (Disk ID: E54E1929)
Partition 1: (Active) - (Size=5.6 GB) - (Type=0B)
 
==================== End of Addition.txt ============================

  • 0

Advertisements


#2
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,096 posts

Hi, Mark. 
 
Nice to see you again.

Download Farbar Recovery Scan Tool and save it to your desktop. --> IMPORTANT

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

If your antivirus software detects the tool as malicious, it’s safe to allow FRST to run. It is a false-positive detection.

If English is not your primary language, right click on FRST.exe/FRST64.exe and rename to FRSTEnglish.exe/FRST64English.exe

  • Double-click the FRST icon to run the tool. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
  • Please attach the content of these two logs in your next reply.

(To attach the files, click on the More Reply Options at the bottom right of the reply area, and then choose Attach File)


  • 0

#3
moondog830

moondog830

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 804 posts

Hey Dr M.

    Glad to see you again. Thanks for helping. I didn't mean that I wouldn't run it because of McAffee saying it was malicious. McAffee wouldn't let me finish the download of it, so I had to get it elsewhere. Got the one you told me to download and I get the following message 

 

C:\Program Files\McAfee\WebAdvisor\x64\DownloadScan.dll is either not designed to run on Windows or it contains an error. Try installing the program again using the original installation media or contact your system administrator or the software vendor for support. Error status 0xc000012f. (this happens 4 times while trying to run FRST and then it began to scan) I then ran the same program on my computer and it runs just fine ... so I'm guessing this is a McAfee thing ... I don't know how to turn that p.o.s. off. 

 

FRST

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-09-2021

Ran by ejbea (administrator) on DESKTOP-2KHI5DN (Dell Inc. Inspiron 15-3567) (21-09-2021 15:20:35)
Running from C:\Users\ejbea\OneDrive\Desktop
Loaded Profiles: ejbea
Platform: Windows 10 Home Version 2004 19041.1237 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(CYBERLINK CORPORATION.) C:\Program Files\WindowsApps\DB6EA5DB.Power2GoforDell_11.0.3920.0_x86__mcezb6ze687jp\Power2Go11\CLMLSvc_P2G11.exe
(Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe
(Dell Inc.) [File not signed] C:\Program Files\Dell\QuickSet\quickset.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel® Corporation -> Intel Corporation) C:\Program Files\Intel\IntelSGXPSW\bin\x64\Release\aesm_service.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\igfxCUIService.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\igfxEM.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\IntelCpHDCPSvc.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\IntelCpHeciSvc.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel® Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(McAfee, Inc. -> McAfee LLC.) C:\Program Files\Common Files\mcafee\amcore\mcshield.exe
(McAfee, Inc. -> McAfee, LLC) C:\Program Files\Common Files\mcafee\SystemCore\mfemms.exe
(McAfee, Inc. -> McAfee, LLC) C:\Windows\System32\mfevtps.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\mcafee\csp\4.6.104.0\McCSPServiceHost.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\mcafee\mmsshost\MMSSHOST.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\mcafee\modulecore\ModuleCoreService.exe <3>
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\mcafee\modulecore\ProtectedModuleHost.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\mcafee\pef\CORE\PEFService.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\mcafee\VSCore_21_4\mcapexe.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\mcafee\MAT\McPvTray.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\mcafee\mfeav\MfeAVSvc.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\mcafee\MQS\QcShm.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <27>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe <2>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\ejbea\AppData\Local\Microsoft\OneDrive\21.170.0822.0002\FileCoAuth.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\ejbea\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2108.25001.0_x64__8wekyb3d8bbwe\Cortana.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20388.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20388.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12107.1001.15.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Rivet Networks LLC -> CloudBees, Inc.) C:\Program Files\Rivet Networks\SmartByte\RNDBWMService.exe
(Rivet Networks LLC -> DELL) C:\Program Files\Rivet Networks\SmartByte\SmartByteTelemetry.exe
(Rivet Networks LLC -> Rivet Networks LLC) C:\Program Files\Rivet Networks\SmartByte\RNDBWM.exe
(Rivet Networks LLC -> Rivet Networks) C:\Program Files\Rivet Networks\SmartByte\SmartByteNetworkService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [320568 2016-09-20] (Intel® Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9269328 2019-01-28] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506384 2019-01-28] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [3910656 2017-05-03] (Dell Inc.) [File not signed]
HKLM\...\Run: [DellMobileConnectWelcome] => C:\Program Files\Dell\DellMobileConnectDrivers\DellMobileConnectWStartup.exe [313064 2018-10-05] (SCREENOVATE TECHNOLOGIES LTD. -> Screenovate Technologies Ltd.)
HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [1213736 2018-11-04] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKU\S-1-5-21-3457983286-1419784188-334204780-1001\...\Run: [MicrosoftEdgeAutoLaunch_799699109B40F4658C53434E420CEEDF] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5
HKLM\...\Windows x64\Print Processors\Canon MX920 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDBL.DLL [30208 2012-09-20] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {3F2C0611-A707-4EE5-B1C2-510E1C9C381C} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1155480 2021-09-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {45C19C88-2540-4538-89E6-64CA0C4A968C} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent => {ABCECA3B-EA5A-496B-A021-5C6BAB365E5C} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [1032448 2021-08-02] (McAfee, LLC -> McAfee, LLC)
Task: {4F81D523-BD6A-42F8-989E-3956C016F759} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [113536 2021-09-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {5300D027-704A-42B3-87FB-53C63FB81C6A} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [4697736 2021-08-16] (McAfee, LLC -> McAfee, LLC)
Task: {565C569C-FB63-4DCF-9BBC-CBA946D4D301} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [21857672 2021-09-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {56A41862-AEDD-4602-A82D-4F6BE056D8C8} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [113536 2021-09-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {7D24E915-203B-46BB-BAA3-1B7076BC9B72} - System32\Tasks\McAfee\McAfee DAT Built in test => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.0.12.663\mcdatrep.exe [1889696 2021-01-07] (McAfee, Inc. -> McAfee, LLC.)
Task: {7EFFC206-E80C-4F97-B685-92BA29565D7F} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [21857672 2021-09-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {8B4DF5ED-846A-4856-850C-50ABD39BEDDE} - System32\Tasks\SmartByte Telemetry => C:\Program Files\Rivet Networks\SmartByte\SmartByteTelemetry.exe [32448 2018-12-04] (Rivet Networks LLC -> DELL)
Task: {D4273156-AC6B-4500-AAF9-7DBB5A0D1988} - System32\Tasks\McAfee\DAD.Execute.Updates => C:\Program Files\Common Files\McAfee\DynamicAppDownloader\DADUpdater.exe [4114288 2021-08-12] (McAfee, LLC -> McAfee, LLC)
"C:\Windows\System32\Tasks\McAfee\McAfee Idle Detection Task" was unlocked. <==== ATTENTION
Task: {D7294A9A-3352-49AB-B910-8E199838193E} - System32\Tasks\McAfee\McAfee Idle Detection Task => {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [1032448 2021-08-02] (McAfee, LLC -> McAfee, LLC)
Task: {DA5F1CB2-CBEE-4D4B-B0BA-A0654EFEDEF0} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [757944 2021-05-06] (McAfee, LLC -> McAfee, LLC)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.1
Tcpip\..\Interfaces\{589ec2c5-523f-4790-b90c-67d059a82bbe}: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{6daae701-dcd4-4585-aa71-409ea1fd00ff}: [DhcpNameServer] 192.168.0.1 192.168.0.1
 
Edge: 
=======
DownloadDir: C:\Users\ejbea\Downloads
Edge Notifications: HKU\S-1-5-21-3457983286-1419784188-334204780-1001 -> hxxps://comfywedgesandal.com; hxxps://shoppersurveys.co; hxxps://www.dailymail.co.uk; hxxps://www.bankrate.com; hxxps://www.truthfinder.com; hxxps://www.seniorsavingz.org; hxxps://www.orthofeet.com; hxxps://www.facebook.com
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\ejbea\AppData\Local\Microsoft\Edge\User Data\cId=128000000001363769&path= [2021-09-21] <==== ATTENTION
Edge Profile: C:\Users\ejbea\AppData\Local\Microsoft\Edge\User Data\Default [2021-09-21]
Edge Notifications: Default -> hxxps://us.shein.com; hxxps://webtronshop.com; hxxps://www.banggood.com; hxxps://www.facebook.com; hxxps://www.finecomb.com; hxxps://www.justfab.com
Edge Extension: (Home | BVSCU) - C:\Users\ejbea\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bdaipkelaldmidppbfaafolldkbdenfg [2020-11-13]
 
FireFox:
========
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Extension: (No Name) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2020-07-31] [not signed]
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\McAfee\MSKHKLM => not found
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\McAfee\MSK
FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2021-09-09] [Legacy] [not signed]
FF Plugin: @mcafee.com/MSC,version=10 -> C:\Program Files\McAfee\MSC\npMcSnFFPl64.dll [2021-08-22] (McAfee, LLC -> )
FF Plugin-x32: @mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\MSC\npMcSnFFPl.dll [2021-08-22] (McAfee, LLC -> )
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-05-28] (Microsoft Corporation -> Microsoft Corporation)
 
Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9179528 2021-09-10] (Microsoft Corporation -> Microsoft Corporation)
R2 Dell SupportAssist Remediation; C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe [293528 2018-10-20] (Dell Inc -> Dell Inc.)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [35976 2019-04-03] (Dell Inc -> )
S2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [949960 2020-08-07] () [File not signed]
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_21_4\McApExe.exe [789752 2021-08-22] (McAfee, LLC -> McAfee, LLC)
S3 McAWFwk; c:\Program Files\Common Files\mcafee\actwiz\McAWFwk.exe [455584 2018-07-16] (McAfee, Inc. -> McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\4.6.104.0\\McCSPServiceHost.exe [2825792 2021-08-13] (McAfee, LLC -> McAfee, LLC)
S3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [652232 2021-05-11] (McAfee, Inc. -> McAfee, LLC)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [652232 2021-05-11] (McAfee, Inc. -> McAfee, LLC)
R3 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [652232 2021-05-11] (McAfee, Inc. -> McAfee, LLC)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1671760 2021-08-10] (McAfee, LLC -> McAfee, LLC)
R2 PEFService; C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe [4288832 2021-08-13] (McAfee, LLC -> McAfee, LLC)
R2 RNDBWM; C:\Program Files\Rivet Networks\SmartByte\RNDBWMService.exe [64184 2018-12-04] (Rivet Networks LLC -> CloudBees, Inc.)
R2 SmartByte Network Service x64; C:\Program Files\Rivet Networks\SmartByte\SmartByteNetworkService.exe [2114248 2018-12-04] (Rivet Networks LLC -> Rivet Networks)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\NisSrv.exe [2772856 2021-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MsMpEng.exe [136640 2021-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [80400 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
S3 DDDriver; C:\WINDOWS\System32\drivers\dddriver64Dcsa.sys [35704 2019-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Dell Inc.)
R2 DpmLiteDrv; c:\Program Files\Dell\QuickSet\DpmLiteDrv64.sys [15080 2014-10-15] (Wistron Corporation -> Wistron Corp.)
R2 McPvDrv; C:\WINDOWS\system32\drivers\McPvDrv.sys [97696 2021-07-27] (McAfee, LLC -> McAfee, LLC)
R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [550944 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [390664 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [85952 2021-05-19] (Microsoft Windows Early Launch Anti-malware Publisher -> McAfee, LLC)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [527368 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [1037320 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [590032 2021-04-16] (McAfee, Inc. -> McAfee LLC.)
S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [120512 2021-04-16] (McAfee, Inc. -> McAfee LLC.)
R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [121352 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [257552 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R3 SmbCoSvc; C:\WINDOWS\system32\DRIVERS\SmbCo10X64.sys [120008 2018-12-04] (Rivet Networks LLC -> Rivet Networks, LLC.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2021-09-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [433384 2021-09-18] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86264 2021-09-18] (Microsoft Windows -> Microsoft Corporation)
S3 MpKslbdb8f141; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{11863E0B-8241-4CEF-8BF6-107FA524074A}\MpKslDrv.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2021-09-21 11:57 - 2021-09-21 15:30 - 000000000 ____D C:\FRST
2021-09-16 13:34 - 2021-09-16 13:34 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-09-16 13:32 - 2021-09-16 13:32 - 001313608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-09-16 13:32 - 2021-09-16 13:32 - 000672768 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2021-09-16 13:32 - 2021-09-16 13:32 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-09-16 13:32 - 2021-09-16 13:32 - 000122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx
2021-09-16 13:32 - 2021-09-16 13:32 - 000011355 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-09-16 13:30 - 2021-09-16 13:30 - 002111488 _____ (Digimarc) C:\WINDOWS\SysWOW64\DMRCDecoder.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2021-09-16 13:30 - 2021-09-16 13:30 - 001164288 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2021-09-16 13:30 - 2021-09-16 13:30 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2021-09-16 13:30 - 2021-09-16 13:30 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2021-09-16 13:30 - 2021-09-16 13:30 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx
2021-09-16 13:28 - 2021-09-16 13:28 - 001823304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-09-16 13:28 - 2021-09-16 13:28 - 001393480 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-09-16 13:27 - 2021-09-16 13:27 - 002295296 _____ (Digimarc) C:\WINDOWS\system32\DMRCDecoder.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2021-09-16 13:27 - 2021-09-16 13:27 - 000566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2021-09-16 13:27 - 2021-09-16 13:27 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe
2021-09-16 13:27 - 2021-09-16 13:27 - 000162816 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2021-09-16 13:27 - 2021-09-16 13:27 - 000098816 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-09-16 11:32 - 2021-09-16 11:32 - 000000000 ___HD C:\$WinREAgent
2021-08-24 08:54 - 2021-08-24 08:56 - 001485796 _____ C:\WINDOWS\Minidump\082421-46375-01.dmp
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2021-09-21 15:30 - 2019-12-07 04:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-09-21 15:08 - 2020-11-22 01:09 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-09-21 13:19 - 2019-12-07 04:13 - 000000000 ____D C:\WINDOWS\INF
2021-09-21 13:07 - 2019-06-18 17:24 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2021-09-21 11:53 - 2020-11-22 01:42 - 000000000 ____D C:\WINDOWS\system32\Tasks\McAfee
2021-09-21 11:31 - 2020-12-15 16:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2021-09-19 15:26 - 2019-04-03 16:04 - 000000000 ___RD C:\Users\ejbea\OneDrive
2021-09-19 15:20 - 2020-12-15 17:15 - 000000000 __RSD C:\Users\ejbea\OneDrive\Mobile uploads\Documents\McAfee Vaults
2021-09-19 15:19 - 2019-04-03 15:56 - 000000000 __SHD C:\Users\ejbea\IntelGraphicsProfiles
2021-09-19 15:17 - 2019-12-07 04:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2021-09-19 15:14 - 2020-11-22 01:42 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-09-19 15:14 - 2020-11-22 01:09 - 000008192 ___SH C:\DumpStack.log.tmp
2021-09-19 15:14 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ServiceState
2021-09-18 22:38 - 2019-12-07 04:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-09-18 22:38 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-09-18 22:35 - 2020-11-22 01:16 - 000000000 ____D C:\Users\ejbea
2021-09-18 22:34 - 2019-02-08 15:05 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-09-18 22:25 - 2019-03-30 01:58 - 000803176 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2021-09-17 19:05 - 2020-07-09 16:01 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-09-17 19:05 - 2020-07-09 16:01 - 000002278 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-09-16 15:13 - 2020-11-22 01:28 - 000797618 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-09-16 15:09 - 2020-11-22 01:09 - 000448408 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-09-16 15:06 - 2019-12-07 04:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2021-09-16 15:04 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2021-09-16 15:04 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-09-16 15:04 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-09-16 15:03 - 2019-12-07 04:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-09-16 15:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-09-16 15:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2021-09-16 15:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-09-16 15:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-09-16 15:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2021-09-16 15:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-09-16 15:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2021-09-16 15:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2021-09-16 15:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2021-09-16 15:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-09-16 15:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-09-16 15:03 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\servicing
2021-09-16 13:59 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-09-16 11:26 - 2019-04-03 18:07 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-09-16 11:19 - 2019-04-03 18:07 - 135637312 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-09-15 20:46 - 2020-11-22 01:42 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3457983286-1419784188-334204780-1001
2021-09-15 20:46 - 2020-11-22 01:16 - 000002381 _____ C:\Users\ejbea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-09-12 23:00 - 2019-04-03 15:56 - 000000000 ____D C:\Users\ejbea\AppData\Local\Packages
2021-09-12 13:01 - 2020-10-01 18:41 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-09-09 17:30 - 2019-02-08 15:35 - 000000000 ____D C:\Program Files\Common Files\mcafee
2021-09-09 17:27 - 2020-11-22 01:42 - 000003316 _____ C:\WINDOWS\system32\Tasks\McAfeeLogon
2021-09-08 16:58 - 2020-11-22 01:42 - 000003710 _____ C:\WINDOWS\system32\Tasks\McAfee Remediation (Prepare)
2021-09-04 19:05 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2021-09-04 09:49 - 2019-06-04 22:14 - 000000000 ____D C:\Users\ejbea\AppData\Local\D3DSCache
2021-08-24 08:57 - 2021-03-01 21:21 - 000000000 ____D C:\WINDOWS\Minidump
2021-08-24 08:54 - 2019-10-12 18:06 - 801071561 _____ C:\WINDOWS\MEMORY.DMP
 
==================== FLock ==============================
 
2020-11-22 01:11 C:\Recovery
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 

Addition

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-09-2021

Ran by ejbea (21-09-2021 15:34:07)
Running from C:\Users\ejbea\OneDrive\Desktop
Windows 10 Home Version 2004 19041.1237 (X64) (2020-11-22 06:44:39)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-3457983286-1419784188-334204780-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3457983286-1419784188-334204780-503 - Limited - Disabled)
ejbea (S-1-5-21-3457983286-1419784188-334204780-1001 - Administrator - Enabled) => C:\Users\ejbea
Guest (S-1-5-21-3457983286-1419784188-334204780-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-3457983286-1419784188-334204780-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee VirusScan (Enabled - Up to date) {9D4501E6-72F6-2877-C789-89AF6F535B2C}
AS: McAfee VirusScan (Enabled - Up to date) {4DE344F8-6897-65B4-CED0-82B3AF2591B4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall (Enabled) {A57E80C3-3899-292F-ECD6-209A91801C57}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Dell Mobile Connect Drivers (HKLM\...\{04DF02C6-E3D7-4D26-A44C-6F8A2E218D2C}) (Version: 1.3.6844 - Screenovate Technologies Ltd.)
Dell SupportAssist Remediation (HKLM\...\{03C35F56-A9AD-4B59-B061-B8CE41C4C22B}) (Version: 4.1.0.6830 - Dell Inc.) Hidden
Dell SupportAssist Remediation (HKLM-x32\...\{f4ee83d8-d901-4c1a-b5a2-288427598fe2}) (Version: 4.1.0.6830 - Dell Inc.)
Dell Touchpad (HKLM\...\SynTPDeinstKey) (Version: 19.2.17.70 - Synaptics Incorporated)
Dell Update - SupportAssist Update Plugin (HKLM\...\{9BEF4D9A-592C-4073-B202-30234347B3DA}) (Version: 4.1.0.6830 - Dell Inc.) Hidden
Dell Update - SupportAssist Update Plugin (HKLM-x32\...\{286db51f-336c-4d5e-b1e2-3fbc3becd693}) (Version: 4.1.0.6830 - Dell Inc.)
Dell Update for Windows 10 (HKLM\...\{70E9F8CC-A23E-4C25-B292-C86C1821587C}) (Version: 3.0.1 - Dell, Inc.)
Intel® Chipset Device Software (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel® Corporation) Hidden
Intel® Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.3.10207.5567 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1054 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 23.20.16.4973 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.2.0.1020 - Intel Corporation)
Intel® Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.866.0 - Intel Corporation) Hidden
Intel® Trusted Connect Services Client (HKLM-x32\...\{246c6cc0-9810-4728-9a29-28474de2eec5}) (Version: 1.47.866.0 - Intel Corporation) Hidden
Intel® Wireless Bluetooth® (HKLM-x32\...\{00000060-0200-1033-84C8-B8D95FA3C8C3}) (Version: 20.60.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{a914536c-bd41-479c-96aa-dee4a9639c22}) (Version: 21.10.1 - Intel Corporation)
Intel® Software Guard Extensions Platform Software (HKLM\...\{06F94C28-DE1D-485F-AD91-333ACEB3F52D}) (Version: 1.6.100.32677 - Intel Corporation)
Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.7.9669.4 - Waves Audio Ltd.) Hidden
McAfee LiveSafe (HKLM-x32\...\MSC) (Version: 16.0 R37 - McAfee, LLC)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.14326.20404 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 93.0.961.52 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 93.0.961.52 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3457983286-1419784188-334204780-1001\...\OneDriveSetup.exe) (Version: 21.170.0822.0002 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{7B981965-2FBC-433C-B4B3-E183EE97CD29}) (Version: 2.83.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.14326.20404 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.14326.20238 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.14326.20404 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
QuickSet64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 11.1.40 - Dell Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.31228 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8622 - Realtek Semiconductor Corp.)
SmartByte Drivers and Services (HKLM\...\{01F01829-4C5A-41B0-8198-0BDD02B34C47}) (Version: 2.0.643 - Rivet Networks)
TurboTax 2018 (HKLM-x32\...\TurboTax 2018) (Version: 2018.0 - Intuit, Inc)
TurboTax 2019 (HKLM-x32\...\TurboTax 2019) (Version: 2019.0 - Intuit, Inc)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-3) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WebAdvisor by McAfee (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.1.140 - McAfee, LLC)
Zoom (HKU\S-1-5-21-3457983286-1419784188-334204780-1001\...\ZoomUMX) (Version: 5.1 - Zoom Video Communications, Inc.)
 
Packages:
=========
Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_1.64.3.0_x86__kgqvnymyfvs32 [2021-09-16] (king.com)
Candy Crush Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.2110.1.0_x86__kgqvnymyfvs32 [2021-09-18] (king.com)
Cooking Fever -> C:\Program Files\WindowsApps\NORDCURRENT.COOKINGFEVER_13.0.10.0_x86__m9bz608c1b9ra [2021-07-27] (Nordcurrent)
Dell CinemaColor -> C:\Program Files\WindowsApps\PortraitDisplays.DellCinemaColor_2.3.57.0_x64__2dgmkzkw4h30c [2021-07-27] (Portrait Displays)
Dell Customer Connect -> C:\Program Files\WindowsApps\DellInc.DellCustomerConnect_5.3.0.0_x64__htrsf667h5kn2 [2021-08-08] (Dell Inc)
Dell Digital Delivery -> C:\Program Files\WindowsApps\DellInc.DellDigitalDelivery_4.0.92.0_x64__htrsf667h5kn2 [2021-08-10] (Dell Inc)
Dell Mobile Connect 3.3 -> C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.3.9803.0_x64__0vhbc3ng4wbp0 [2021-06-21] (Screenovate Technologies) [Startup Task]
Dell Update -> C:\Program Files\WindowsApps\DellInc.DellUpdate_3.0.160.0_x64__htrsf667h5kn2 [2019-02-08] (Dell Inc)
Dropbox promotion -> C:\Program Files\WindowsApps\C27EB4BA.DropboxOEM_20.4.3.0_x64__xbfy0k16fey96 [2020-01-16] (Dropbox Inc.)
Fitbit Coach -> C:\Program Files\WindowsApps\Fitbit.FitbitCoach_4.4.133.0_x64__6mqt6hf9g46tw [2019-04-03] (Fitbit)
LinkedIn -> C:\Program Files\WindowsApps\7EE7776C.LinkedInforWindows_2.1.7098.0_neutral__w1wdnht996qgy [2019-04-03] (LinkedIn)
McAfee® Personal Security -> C:\Program Files\WindowsApps\5A894077.McAfeeSecurity_2.1.67.0_x64__wafk5atnkzcwy [2021-09-18] (McAfee LLC.)
Media Suite Essentials for Dell -> C:\Program Files\WindowsApps\DB6EA5DB.MediaSuiteEssentialsforDell_2.6.4028.0_x86__mcezb6ze687jp [2020-03-29] (CYBERLINK CORPORATION.)
Messenger -> C:\Program Files\WindowsApps\FACEBOOK.317180B0BB486_1220.6.117.0_x64__8xx8rvfyw5nnt [2021-09-18] (Facebook Inc) [Startup Task]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-04-03] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-04-03] (Microsoft Corporation) [MS Ad]
Microsoft Mahjong -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMahjong_4.0.11030.0_x64__8wekyb3d8bbwe [2020-11-27] (Microsoft Studios) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.10.7290.0_x64__8wekyb3d8bbwe [2021-08-05] (Microsoft Studios) [MS Ad]
MPEG-2 Video Extension -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.42152.0_x64__8wekyb3d8bbwe [2021-08-27] (Microsoft Corporation)
My Dell -> C:\Program Files\WindowsApps\DellInc.MyDell_1.91.7.0_x64__htrsf667h5kn2 [2021-08-08] (Dell Inc)
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.97.752.0_x64__mcm4njqhnhss8 [2020-07-15] (Netflix, Inc.)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-11-21] (Microsoft Corporation)
Phototastic Collage -> C:\Program Files\WindowsApps\ThumbmunkeysLtd.PhototasticCollage_3.27.1.0_x64__nfy108tqq3p12 [2021-02-20] (Thumbmunkeys Ltd)
Plex -> C:\Program Files\WindowsApps\CAF9E577.Plex_3.2.20.0_x64__aam28m9va5cke [2019-04-03] (Plex)
Power Media Player for Dell -> C:\Program Files\WindowsApps\DB6EA5DB.PowerMediaPlayerforDell_14.2.3708.0_x86__mcezb6ze687jp [2021-07-14] (CYBERLINK CORPORATION.)
Power2Go for Dell -> C:\Program Files\WindowsApps\DB6EA5DB.Power2GoforDell_11.0.3920.0_x86__mcezb6ze687jp [2020-08-13] (CYBERLINK CORPORATION.) [Startup Task]
PowerDirector for Dell -> C:\Program Files\WindowsApps\DB6EA5DB.PowerDirectorforDell_15.0.4409.0_x64__mcezb6ze687jp [2019-04-03] (CYBERLINK CORPORATION.)
SmartByte -> C:\Program Files\WindowsApps\RivetNetworks.SmartByte_3.1.995.0_x64__rh07ty8m5nkag [2021-08-14] (Rivet Networks LLC)
Translator -> C:\Program Files\WindowsApps\Microsoft.BingTranslator_5.6.0.0_x64__8wekyb3d8bbwe [2019-08-03] (Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3457983286-1419784188-334204780-1001_Classes\CLSID\{a9872fee-5a55-4ecb-9b0f-b06fedcf14d1}\localserver32 -> C:\Program Files\Waves\MaxxAudio\MaxxAudioPro.exe (Waves Inc -> Waves Audio Ltd)
ContextMenuHandlers1: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => C:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2021-08-22] (McAfee, LLC -> McAfee, LLC)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\igfxDTCM.dll [2018-03-21] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => C:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2021-08-22] (McAfee, LLC -> McAfee, LLC)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\ejbea\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__bdaipkelaldmidppbfaafolldkbdenfg\Home _ BVSCU.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) ->  --profile-directory=Default --app-id=bdaipkelaldmidppbfaafolldkbdenfg --app-url=hxxps://www.bvscu.org/
 
==================== Loaded Modules (Whitelisted) =============
 
2017-05-03 20:20 - 2017-05-03 20:20 - 000086016 _____ (Dell Inc.) [File not signed] C:\Program Files\Dell\QuickSet\dadkeyb.dll
2018-12-04 12:10 - 2018-12-04 12:10 - 000100864 _____ (Rivet Networks) [File not signed] C:\Program Files\Rivet Networks\SmartByte\KillerNetworkServicePS.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
HKU\S-1-5-21-3457983286-1419784188-334204780-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=620947&OCID=AVRES000&pc=UE00
HKU\S-1-5-21-3457983286-1419784188-334204780-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2021-05-28] (Microsoft Corporation -> Microsoft Corporation)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2020-07-31] (McAfee, LLC -> McAfee, LLC)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2020-07-31] (McAfee, LLC -> McAfee, LLC)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-08-26] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-08-26] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-08-26] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-08-26] (Microsoft Corporation -> Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\McAfee\MSC\McSnIePl64.dll [2021-08-22] (McAfee, LLC -> McAfee, LLC)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2021-08-22] (McAfee, LLC -> McAfee, LLC)
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2018-09-15 02:31 - 2018-09-15 02:31 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\iCLS\;C:\Program Files\Intel\Intel® Management Engine Components\iCLS\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL;C:\Program Files\Intel\Intel® Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT;C:\Program Files\Intel\Intel® Management Engine Components\IPT;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\
HKU\S-1-5-21-3457983286-1419784188-334204780-1001\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{C909EBC9-72FD-4AE2-ABD9-AF6AD14CC7E5}] => (Allow) C:\Program Files (x86)\Common Files\McAfee\MMSSHost\MMSSHost.exe (McAfee, LLC -> McAfee, LLC)
FirewallRules: [{5063EBCB-ABE1-42AB-A083-80AF05CE1048}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe (McAfee, LLC -> McAfee, LLC)
FirewallRules: [{D83A36C9-79A1-40EB-B4B3-2B46FC066D0A}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe => No File
FirewallRules: [{B28F8059-CB4B-40B2-A9C3-27A56B1BDE3F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.11629.20214.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe => No File
FirewallRules: [{89201931-C0C7-4269-8D13-2D10CC494228}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation -> )
FirewallRules: [{EE179294-8BE1-48D2-829B-0D208A3ABC0D}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{008C2730-9A95-4A24-8F94-6D33FC90705E}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{D832794C-2804-4AC3-9A1C-6C4981BD8E14}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{0DF6AE09-D610-435A-B250-F62CFD17A521}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{76FB62CC-CE27-4E18-8A24-CCE2C1D8AB76}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{4B2F5D68-0069-4EB2-98FA-8A01A364A3DE}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{07BB402A-4180-4104-B415-65DACD47B472}] => (Allow) C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.3.9803.0_x64__0vhbc3ng4wbp0\app\DellMobileConnectClient.exe (SCREENOVATE TECHNOLOGIES LTD. -> Screenovate Technologies Ltd.)
FirewallRules: [{4A8033E9-B576-4E83-805B-A6496E14239E}] => (Allow) C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.3.9803.0_x64__0vhbc3ng4wbp0\app\DellMobileConnectClient.exe (SCREENOVATE TECHNOLOGIES LTD. -> Screenovate Technologies Ltd.)
FirewallRules: [{E1250F2B-4DAF-42E4-88D6-330A3F1F3A04}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{A224DBA5-4E7A-48C3-B08E-B9EFF5329157}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{EF17721C-F271-495B-8942-7BB9128D3DDB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{04B9B98A-720E-449C-B401-045C48635E1B}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{B665FCFF-FAF3-41B8-8D5D-A33E02972549}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6B79E6D0-1443-4BF0-9C14-2F8EAB59166E}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\93.0.961.52\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
 
==================== Restore Points =========================
 
16-09-2021 11:27:10 Windows Modules Installer
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (09/21/2021 03:08:36 PM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel® Dynamic Platform and Thermal Framework : ESIF(8.3.10207.5567) TYPE: ERROR MODULE: DPTF TIME 172537344 ms
 
DPTF Build Version:  8.3.10207.5567
DPTF Build Date:  Nov  2 2017 14:28:00
Source File:  ..\..\..\..\Sources\Policies\ConfigTdpPolicy\ConfigTdpPolicy.cpp @ line 155
Executing Function:  ConfigTdpPolicy::onBindDomain
Message:  ConfigTdp not supported.
Participant:  TCPU [0]
Domain:  PKG [0]
Policy:  ConfigTDP Policy [0]
 
Error: (09/21/2021 03:08:35 PM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel® Dynamic Platform and Thermal Framework : ESIF(8.3.10207.5567) TYPE: ERROR MODULE: DPTF TIME 172536125 ms
 
DPTF Build Version:  8.3.10207.5567
DPTF Build Date:  Nov  2 2017 14:28:00
Source File:  ..\..\..\..\Sources\Policies\ConfigTdpPolicy\ConfigTdpPolicy.cpp @ line 342
Executing Function:  ConfigTdpPolicy::synchronizeConfigTdpPlatformSettings
Message:  ConfigTdp not supported.
Policy:  ConfigTDP Policy [0]
 
Error: (09/21/2021 02:27:54 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: The storage optimizer couldn't complete retrim on OS (C:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)
 
Error: (09/21/2021 11:40:10 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program HxOutlook.exe version 16.0.14326.20384 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 2de4
 
Start Time: 01d7af073a28fe29
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20388.0_x64__8wekyb3d8bbwe\HxOutlook.exe
 
Report Id: e22af4fb-8b16-457c-abf8-f3f79752c7f1
 
Faulting package full name: microsoft.windowscommunicationsapps_16005.14326.20388.0_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: microsoft.windowslive.mail
 
Hang type: Quiesce
 
Error: (09/21/2021 10:55:52 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_MapsBroker, version: 10.0.19041.546, time stamp: 0x058e175a
Faulting module name: KERNELBASE.dll, version: 10.0.19041.1202, time stamp: 0xc9db1934
Exception code: 0x8400000e
Fault offset: 0x000000000010be3e
Faulting process id: 0x37b0
Faulting application start time: 0x01d7af010889f60e
Faulting application path: C:\WINDOWS\System32\svchost.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report Id: acf84680-bc1d-419f-98cf-d73e7171372c
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (09/21/2021 10:51:42 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program LockApp.exe version 10.0.19041.844 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 27b4
 
Start Time: 01d7aefa69758767
 
Termination Time: 4294967295
 
Application Path: C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
 
Report Id: 9c219e5e-e895-4f43-805f-d1a67c5fc285
 
Faulting package full name: Microsoft.LockApp_10.0.19041.1023_neutral__cw5n1h2txyewy
 
Faulting package-relative application ID: WindowsDefaultLockScreen
 
Hang type: Cross-process
 
Error: (09/21/2021 10:48:15 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (09/21/2021 10:33:58 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program explorer.exe version 10.0.19041.1202 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 1464
 
Start Time: 01d7ad93ada30389
 
Termination Time: 58
 
Application Path: C:\Windows\explorer.exe
 
Report Id: 300fdb0f-c6f4-495a-9dee-37d023c584d5
 
Faulting package full name: 
 
Faulting package-relative application ID: 
 
Hang type: Unknown
 
 
System errors:
=============
Error: (09/21/2021 01:08:59 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Search service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (09/21/2021 01:08:59 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
 
Error: (09/21/2021 10:59:20 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Rivet Dynamic Bandwidth Management service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (09/21/2021 10:59:20 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Rivet Dynamic Bandwidth Management service to connect.
 
Error: (09/21/2021 10:56:13 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-2KHI5DN)
Description: The server {209500FC-6B45-4693-8871-6296C4843751} did not register with DCOM within the required timeout.
 
Error: (09/21/2021 10:56:00 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Downloaded Maps Manager service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (09/19/2021 03:28:03 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Intel® Management and Security Application Local Management Service service hung on starting.
 
Error: (09/19/2021 03:25:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Intuit Update Service v4 service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
 
Windows Defender:
================
Date: 2021-05-25 20:50:33
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2021-05-24 14:28:58
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2021-05-24 10:18:48
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2021-05-24 10:11:23
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2021-05-24 09:36:35
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2021-05-27 20:35:04
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.339.1367.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.18100.6
Error code: 0x80070102
Error description: The wait operation timed out. 
 
Date: 2021-05-22 19:14:05
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.339.1227.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.18100.6
Error code: 0x80070102
Error description: The wait operation timed out. 
 
Date: 2021-05-18 20:26:23
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.339.981.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.18100.6
Error code: 0x80240009
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 
 
CodeIntegrity:
===============
Date: 2021-09-21 11:31:47
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Common Files\mcafee\modulecore\ProtectedModuleHost.exe) attempted to load \Device\HarddiskVolume3\Program Files\mcafee.com\agent\WSCLLCGlobalSign.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2021-09-21 11:31:47
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Common Files\mcafee\modulecore\ProtectedModuleHost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\mcafee\platform\core\vtploader.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
BIOS: Dell Inc. 2.9.0 01/17/2019
Motherboard: Dell Inc. 0KDGM1
Processor: Intel® Core™ i3-7020U CPU @ 2.30GHz
Percentage of memory in use: 83%
Total physical RAM: 3961.88 MB
Available physical RAM: 662.06 MB
Total Virtual: 5625.88 MB
Available Virtual: 716.23 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:916.28 GB) (Free:844.84 GB) (Protected) NTFS
Drive d: (ALANJACKSON) (CDROM) (Total:2.84 GB) (Free:0 GB) UDF
 
\\?\Volume{fd2d1fed-76f6-480c-b417-67c9ffa24b55}\ () (Fixed) (Total:0.97 GB) (Free:0.42 GB) NTFS
\\?\Volume{5cd94f67-f6f3-4212-a598-b033ff9c94e0}\ (Image) (Fixed) (Total:12.37 GB) (Free:0.18 GB) NTFS
\\?\Volume{47947bc6-a3e5-4503-8019-82fe861d2456}\ (DELLSUPPORT) (Fixed) (Total:1.14 GB) (Free:0.48 GB) NTFS
\\?\Volume{d2539f45-3d68-4475-9752-df5d993b6786}\ (ESP) (Fixed) (Total:0.63 GB) (Free:0.57 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 6CAC8AAD)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

  • 0

#4
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,096 posts

Hi, Mark.

 

There is no sign of an active infection in the computer. However, there are some things we can do to improve computer's functionality.
 
 
Before we begin, I just remind of you the procedure's guidelines:

 

1. Always ask before acting. Do not continue if you are not sure, or if something unexpected happens!

2. Do not run any tools unless instructed to do so. Also, do not uninstall or install any software during the procedure, unless I ask you to do so.

3. If your computer seems to start working normally, don't abandon the topic. Even if your system is behaving normally, there may still be some malware remnants left over. Additionally, malware can re-infect the computer if some remnants are left. Therefore, please complete all requested steps to make sure any malware is successfully eradicated from your PC.

4. You have to reply to my posts within 3 days. If you need some additional time, just let me know. Otherwise, I will leave the topic due to lack of feedback. If you are able, I would request you to check this thread at least once per day so that we can resolve your issues effectively and efficiently.

5. Logs from malware diagnostic or removal programs can take some time to get analyzed. Also, have in mind that all the experts here are volunteers and may not be available to assist when you post. Please, be patient, while I analyze your logs.
 
 
===========================
 
Let's begin.

 
1. McAfee Removal
 
You have McAfee LiveSafe and WebAdvisor by McAfee installed. Since you got the error message in green (from your post), I recommend you to uninstall McAfee. Besides, sometimes third-party antivirus cause issues in Windows 10. If that is not the case, and your friend wants McAfee, you can always re-install it, but please do that at the end of the procedure.
 
To uninstall McAfee products:

Use Method 2 in this link: McAfee KB - How to remove McAfee products from a PC that runs Windows (TS101331)

 
2. Uninstall programs
 
There are many programs that came pre-installed in the computer. Some of them may cause slowness.
 
To uninstall them:

  • Press the Windows Key + R.
  • Type appwiz.cpl in the Run box and click OK.
  • The Add/Remove Programs list will open. Locate the following programs in the list:
SmartByte Drivers and Services
Dell SupportAssist Remediation 
Dell Update - SupportAssist Update Plugin 
  • Select the above programs, one by one, and click Uninstall.
  • Restart the computer.

 
3. Remove apps

  • Click on the Start button and find the following apps. Right click on each one and select Uninstall.
    Dell CinemaColor 
    Dell Customer Connect
    Dell Digital Delivery 
    Dell Mobile Connect 3.3 
    Dell Update 
    My Dell 
    SmartByte 
    McAfee® Personal Security 
  • Restart.

 

4. Edge notifications
 
There are many many Edge notifications. Ask your friend if she intentionally enable notifications from these sites:

hxxps://us.shein.com; 
hxxps://webtronshop.com; 
hxxps://www.banggood.com; 
hxxps://www.finecomb.com; 
hxxps://www.justfab.com 
hxxps://comfywedgesandal.com; 
hxxps://shoppersurveys.co; 
hxxps://www.dailymail.co.uk; 
hxxps://www.bankrate.com; 
hxxps://www.truthfinder.com; 
hxxps://www.seniorsavingz.org; 
hxxps://www.orthofeet.com; 
hxxps://www.facebook.com
 
 

5. Fresh FRST logs
 
After the removals, please attach for me fresh FRST logs.

  • Double-click on the FRST icon to run it, as you did before. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
  • Please attach the content of these two logs in your next reply.

(To attach the files, click on the More Reply Options at the bottom right of the reply area, and then choose Attach File)


  • 0

#5
moondog830

moondog830

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 804 posts

1. Done

2. Done

3. Done

4. wrote them down so that I can ask her about them ... chances are it was just some clicking without thinking ... she is around 80

5. attached

 

 

Attached Files


  • 0

#6
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,096 posts

Hi, Mark.
 
I'm really surprised with what McAfee Removal tool does NOT do! It was supposed to delete everything regarding the product. Instead, almost everything is there! Services, drivers, remnants of any kind! That's why I recommend Microsoft Defender for computers with Windows 10 and nothing else. But of course, any user can make their choices. 
 
Let's continue.
 
1. FRST fix

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system

  • Please select the entire contents of the code box below, from the "Start::" line to "End::", including both lines. Right-click and select "Copy ". No need to paste anything to anywhere.
Start::
CreateRestorePoint:
CloseProcesses:
AS: McAfee VirusScan (Enabled - Up to date) {4DE344F8-6897-65B4-CED0-82B3AF2591B4}
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
FirewallRules: [{D83A36C9-79A1-40EB-B4B3-2B46FC066D0A}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe => No File
FirewallRules: [{B28F8059-CB4B-40B2-A9C3-27A56B1BDE3F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.11629.20214.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe => No File
Task: {45C19C88-2540-4538-89E6-64CA0C4A968C} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent => {ABCECA3B-EA5A-496B-A021-5C6BAB365E5C} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [1032448 2021-08-02] (McAfee, LLC -> McAfee, LLC)
Task: {5300D027-704A-42B3-87FB-53C63FB81C6A} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [4697736 2021-08-16] (McAfee, LLC -> McAfee, LLC)
Task: {7D24E915-203B-46BB-BAA3-1B7076BC9B72} - System32\Tasks\McAfee\McAfee DAT Built in test => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.0.12.663\mcdatrep.exe [1889696 2021-01-07] (McAfee, Inc. -> McAfee, LLC.)
Task: {8B4DF5ED-846A-4856-850C-50ABD39BEDDE} - System32\Tasks\SmartByte Telemetry => C:\Program Files\Rivet Networks\SmartByte\SmartByteTelemetry.exe [32448 2018-12-04] (Rivet Networks LLC -> DELL)
Task: {D4273156-AC6B-4500-AAF9-7DBB5A0D1988} - System32\Tasks\McAfee\DAD.Execute.Updates => C:\Program Files\Common Files\McAfee\DynamicAppDownloader\DADUpdater.exe [4114288 2021-08-12] (McAfee, LLC -> McAfee, LLC)
"C:\Windows\System32\Tasks\McAfee\McAfee Idle Detection Task" was unlocked. <==== ATTENTION
Task: {D7294A9A-3352-49AB-B910-8E199838193E} - System32\Tasks\McAfee\McAfee Idle Detection Task => {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [1032448 2021-08-02] (McAfee, LLC -> McAfee, LLC)
Task: {DA5F1CB2-CBEE-4D4B-B0BA-A0654EFEDEF0} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [757944 2021-05-06] (McAfee, LLC -> McAfee, LLC)
Edge Notifications: HKU\S-1-5-21-3457983286-1419784188-334204780-1001 -> hxxps://comfywedgesandal.com; hxxps://shoppersurveys.co; hxxps://www.dailymail.co.uk; hxxps://www.bankrate.com; hxxps://www.truthfinder.com; hxxps://www.seniorsavingz.org; hxxps://www.orthofeet.com; hxxps://www.facebook.com
Edge Notifications: Default -> hxxps://us.shein.com; hxxps://webtronshop.com; hxxps://www.banggood.com; hxxps://www.facebook.com; hxxps://www.finecomb.com; hxxps://www.justfab.com
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Extension: (No Name) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2020-07-31] [not signed]
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\McAfee\MSKHKLM => not found
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\McAfee\MSK
FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2021-09-09] [Legacy] [not signed]
FF Plugin: @mcafee.com/MSC,version=10 -> C:\Program Files\McAfee\MSC\npMcSnFFPl64.dll [2021-08-22] (McAfee, LLC -> )
FF Plugin-x32: @mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\MSC\npMcSnFFPl.dll [2021-08-22] (McAfee, LLC -> )
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
R2 Dell SupportAssist Remediation; C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe [293528 2018-10-20] (Dell Inc -> Dell Inc.)
S2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [949960 2020-08-07] () [File not signed]
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_21_4\McApExe.exe [789752 2021-08-22] (McAfee, LLC -> McAfee, LLC)
S3 McAWFwk; c:\Program Files\Common Files\mcafee\actwiz\McAWFwk.exe [455584 2018-07-16] (McAfee, Inc. -> McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\4.6.104.0\\McCSPServiceHost.exe [2825792 2021-08-13] (McAfee, LLC -> McAfee, LLC)
S3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [652232 2021-05-11] (McAfee, Inc. -> McAfee, LLC)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [652232 2021-05-11] (McAfee, Inc. -> McAfee, LLC)
R3 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [652232 2021-05-11] (McAfee, Inc. -> McAfee, LLC)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1671760 2021-08-10] (McAfee, LLC -> McAfee, LLC)
R2 PEFService; C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe [4288832 2021-08-13] (McAfee, LLC -> McAfee, LLC)
R2 SmartByte Network Service x64; C:\Program Files\Rivet Networks\SmartByte\SmartByteNetworkService.exe [2114248 2018-12-04] (Rivet Networks LLC -> Rivet Networks)
R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [80400 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R2 McPvDrv; C:\WINDOWS\system32\drivers\McPvDrv.sys [97696 2021-07-27] (McAfee, LLC -> McAfee, LLC)
R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [550944 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [390664 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [85952 2021-05-19] (Microsoft Windows Early Launch Anti-malware Publisher -> McAfee, LLC)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [527368 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [1037320 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [590032 2021-04-16] (McAfee, Inc. -> McAfee LLC.)
S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [120512 2021-04-16] (McAfee, Inc. -> McAfee LLC.)
R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [121352 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [257552 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R3 SmbCoSvc; C:\WINDOWS\system32\DRIVERS\SmbCo10X64.sys [120008 2018-12-04] (Rivet Networks LLC -> Rivet Networks, LLC.)
S3 MpKslbdb8f141; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{11863E0B-8241-4CEF-8BF6-107FA524074A}\MpKslDrv.sys [X]
C:\WINDOWS\system32\Tasks\McAfee
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
C:\Users\ejbea\OneDrive\Mobile uploads\Documents\McAfee Vaults
C:\WINDOWS\system32\Tasks\McAfeeLogon
C:\WINDOWS\system32\Tasks\McAfee Remediation (Prepare)
C:\Program Files\Dell\SARemediation
C:\Program Files\McAfee
C:\Program Files\Rivet Networks
C:\WINDOWS\System32\drivers\cfwids.sys 
C:\WINDOWS\system32\drivers\McPvDrv.sys
C:\WINDOWS\System32\drivers\mfeaack.sys 
RC:\WINDOWS\System32\drivers\mfeavfk.sys
C:\WINDOWS\System32\drivers\mfeelamk.sys 
C:\WINDOWS\System32\drivers\mfefirek.sys 
C:\WINDOWS\System32\drivers\mfehidk.sys 
C:\WINDOWS\System32\DRIVERS\mfencbdc.sys 
C:\WINDOWS\System32\DRIVERS\mfencrk.sys 
C:\WINDOWS\System32\drivers\mfeplk.sys 
C:\WINDOWS\System32\drivers\mfewfpk.sys 
C:\WINDOWS\system32\DRIVERS\SmbCo10X64.sys 
C:\Program Files\Common Files\McAfee
C:\Program Files\Common Files\AV\McAfee VirusScan
C:\Program Files\Rivet Networks
EmptyTemp:
End::
  • Please right-click on FRST64 on your Desktop, to run it as administrator. When the tool opens, click "yes" to the disclaimer.
  • Press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt on your Desktop.
  • Please post the log in your next reply.

 

2. Run AdwCleaner (Scan mode)

Download AdwCleaner and save it to your desktop.

  • Double click AdwCleaner.exe to run it.
  • Click Scan Now.
    • When the scan has finished, a Scan Results window will open.
    • Click Cancel (at this point do not attempt to Quarantine anything that is found)
  • Now click the Log Files tab.
    • Double click on the latest scan log (Scan logs have a [S0*] suffix, where * is replaced by a number. The latest scan will have the largest number)
    • A Notepad file will open containing the results of the scan.
    • Please post the contents of the file in your next reply.

 

3. Run Malwarebytes (Scan mode)

  • Download Malwarebytes and save it to your Desktop.
  • Once downloaded, close all programs and Windows on your computer.
  • Double-click on the icon on your desktop named MBSetup.exe. This will start the installation of MBAM onto your computer.
  • Follow the instructions to install the program.
  • When finished, double click the program's icon created on your Desktop.
  • Click the little gear on the top right (Settings) and when it opens, click the Security tab and make sure about the following:
    Under the title Scan Options, all the options are checked.
    Under the title Windows Security Center (Premium only) the option is NOT checked.
    Under the title Potentially unwanted items all options are set to Always.
  • Click on the little gear to return to the main menu and select Scan. The program will start scanning your computer. This may take about 10 minutes, but in some cases it may be take longer.
  • When finished, you will see the Threat Scan Summary window open.
  • If threats are not found, click View Report and proceed to the two last steps below.

    If threats are found, make sure that all threats are not selected, close the program and proceed to the next steps below.
    • Open Malwarebytes again, click on the Scanner, and then on the Reports tab.
    • Find the report with the most recent date and double click on it.
    • Click on Export and then Copy to Clipboard.
    • Paste its content here, in your next reply.

 

 

In your next reply please post:

  1. The fixlog.txt
  2. The AdwCleaner[S0*].txt
  3. The Malwarebytes report

  • 0

#7
moondog830

moondog830

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 804 posts

FixLog

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 20-09-2021
Ran by ejbea (22-09-2021 14:24:21) Run:1
Running from C:\Users\ejbea\OneDrive\Desktop
Loaded Profiles: ejbea
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
AS: McAfee VirusScan (Enabled - Up to date) {4DE344F8-6897-65B4-CED0-82B3AF2591B4}
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
FirewallRules: [{D83A36C9-79A1-40EB-B4B3-2B46FC066D0A}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe => No File
FirewallRules: [{B28F8059-CB4B-40B2-A9C3-27A56B1BDE3F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.11629.20214.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe => No File
Task: {45C19C88-2540-4538-89E6-64CA0C4A968C} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent => {ABCECA3B-EA5A-496B-A021-5C6BAB365E5C} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [1032448 2021-08-02] (McAfee, LLC -> McAfee, LLC)
Task: {5300D027-704A-42B3-87FB-53C63FB81C6A} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [4697736 2021-08-16] (McAfee, LLC -> McAfee, LLC)
Task: {7D24E915-203B-46BB-BAA3-1B7076BC9B72} - System32\Tasks\McAfee\McAfee DAT Built in test => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.0.12.663\mcdatrep.exe [1889696 2021-01-07] (McAfee, Inc. -> McAfee, LLC.)
Task: {8B4DF5ED-846A-4856-850C-50ABD39BEDDE} - System32\Tasks\SmartByte Telemetry => C:\Program Files\Rivet Networks\SmartByte\SmartByteTelemetry.exe [32448 2018-12-04] (Rivet Networks LLC -> DELL)
Task: {D4273156-AC6B-4500-AAF9-7DBB5A0D1988} - System32\Tasks\McAfee\DAD.Execute.Updates => C:\Program Files\Common Files\McAfee\DynamicAppDownloader\DADUpdater.exe [4114288 2021-08-12] (McAfee, LLC -> McAfee, LLC)
"C:\Windows\System32\Tasks\McAfee\McAfee Idle Detection Task" was unlocked. <==== ATTENTION
Task: {D7294A9A-3352-49AB-B910-8E199838193E} - System32\Tasks\McAfee\McAfee Idle Detection Task => {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [1032448 2021-08-02] (McAfee, LLC -> McAfee, LLC)
Task: {DA5F1CB2-CBEE-4D4B-B0BA-A0654EFEDEF0} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [757944 2021-05-06] (McAfee, LLC -> McAfee, LLC)
Edge Notifications: HKU\S-1-5-21-3457983286-1419784188-334204780-1001 -> hxxps://comfywedgesandal.com; hxxps://shoppersurveys.co; hxxps://www.dailymail.co.uk; hxxps://www.bankrate.com; hxxps://www.truthfinder.com; hxxps://www.seniorsavingz.org; hxxps://www.orthofeet.com; hxxps://www.facebook.com
Edge Notifications: Default -> hxxps://us.shein.com; hxxps://webtronshop.com; hxxps://www.banggood.com; hxxps://www.facebook.com; hxxps://www.finecomb.com; hxxps://www.justfab.com
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Extension: (No Name) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2020-07-31] [not signed]
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\McAfee\MSKHKLM => not found
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\McAfee\MSK
FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2021-09-09] [Legacy] [not signed]
FF Plugin: @mcafee.com/MSC,version=10 -> C:\Program Files\McAfee\MSC\npMcSnFFPl64.dll [2021-08-22] (McAfee, LLC -> )
FF Plugin-x32: @mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\MSC\npMcSnFFPl.dll [2021-08-22] (McAfee, LLC -> )
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
R2 Dell SupportAssist Remediation; C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe [293528 2018-10-20] (Dell Inc -> Dell Inc.)
S2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [949960 2020-08-07] () [File not signed]
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_21_4\McApExe.exe [789752 2021-08-22] (McAfee, LLC -> McAfee, LLC)
S3 McAWFwk; c:\Program Files\Common Files\mcafee\actwiz\McAWFwk.exe [455584 2018-07-16] (McAfee, Inc. -> McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\4.6.104.0\\McCSPServiceHost.exe [2825792 2021-08-13] (McAfee, LLC -> McAfee, LLC)
S3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [652232 2021-05-11] (McAfee, Inc. -> McAfee, LLC)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [652232 2021-05-11] (McAfee, Inc. -> McAfee, LLC)
R3 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [652232 2021-05-11] (McAfee, Inc. -> McAfee, LLC)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1671760 2021-08-10] (McAfee, LLC -> McAfee, LLC)
R2 PEFService; C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe [4288832 2021-08-13] (McAfee, LLC -> McAfee, LLC)
R2 SmartByte Network Service x64; C:\Program Files\Rivet Networks\SmartByte\SmartByteNetworkService.exe [2114248 2018-12-04] (Rivet Networks LLC -> Rivet Networks)
R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [80400 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R2 McPvDrv; C:\WINDOWS\system32\drivers\McPvDrv.sys [97696 2021-07-27] (McAfee, LLC -> McAfee, LLC)
R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [550944 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [390664 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [85952 2021-05-19] (Microsoft Windows Early Launch Anti-malware Publisher -> McAfee, LLC)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [527368 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [1037320 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [590032 2021-04-16] (McAfee, Inc. -> McAfee LLC.)
S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [120512 2021-04-16] (McAfee, Inc. -> McAfee LLC.)
R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [121352 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [257552 2021-05-19] (McAfee, Inc. -> McAfee, LLC)
R3 SmbCoSvc; C:\WINDOWS\system32\DRIVERS\SmbCo10X64.sys [120008 2018-12-04] (Rivet Networks LLC -> Rivet Networks, LLC.)
S3 MpKslbdb8f141; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{11863E0B-8241-4CEF-8BF6-107FA524074A}\MpKslDrv.sys [X]
C:\WINDOWS\system32\Tasks\McAfee
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
C:\Users\ejbea\OneDrive\Mobile uploads\Documents\McAfee Vaults
C:\WINDOWS\system32\Tasks\McAfeeLogon
C:\WINDOWS\system32\Tasks\McAfee Remediation (Prepare)
C:\Program Files\Dell\SARemediation
C:\Program Files\McAfee
C:\Program Files\Rivet Networks
C:\WINDOWS\System32\drivers\cfwids.sys 
C:\WINDOWS\system32\drivers\McPvDrv.sys
C:\WINDOWS\System32\drivers\mfeaack.sys 
RC:\WINDOWS\System32\drivers\mfeavfk.sys
C:\WINDOWS\System32\drivers\mfeelamk.sys 
C:\WINDOWS\System32\drivers\mfefirek.sys 
C:\WINDOWS\System32\drivers\mfehidk.sys 
C:\WINDOWS\System32\DRIVERS\mfencbdc.sys 
C:\WINDOWS\System32\DRIVERS\mfencrk.sys 
C:\WINDOWS\System32\drivers\mfeplk.sys 
C:\WINDOWS\System32\drivers\mfewfpk.sys 
C:\WINDOWS\system32\DRIVERS\SmbCo10X64.sys 
C:\Program Files\Common Files\McAfee
C:\Program Files\Common Files\AV\McAfee VirusScan
C:\Program Files\Rivet Networks
EmptyTemp:
 
*****************
 
Restore point was successfully created.
Processes closed successfully.
"AS: McAfee VirusScan (Enabled - Up to date) {4DE344F8-6897-65B4-CED0-82B3AF2591B4}" => removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D83A36C9-79A1-40EB-B4B3-2B46FC066D0A}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B28F8059-CB4B-40B2-A9C3-27A56B1BDE3F}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{45C19C88-2540-4538-89E6-64CA0C4A968C}" => not found
"C:\WINDOWS\System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\McAfee\McAfee Auto Maintenance Task Agent" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5300D027-704A-42B3-87FB-53C63FB81C6A}" => not found
"C:\WINDOWS\System32\Tasks\McAfee Remediation (Prepare)" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\McAfee Remediation (Prepare)" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7D24E915-203B-46BB-BAA3-1B7076BC9B72}" => not found
"C:\WINDOWS\System32\Tasks\McAfee\McAfee DAT Built in test" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\McAfee\McAfee DAT Built in test" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B4DF5ED-846A-4856-850C-50ABD39BEDDE}" => not found
"C:\WINDOWS\System32\Tasks\SmartByte Telemetry" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SmartByte Telemetry" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D4273156-AC6B-4500-AAF9-7DBB5A0D1988}" => not found
"C:\WINDOWS\System32\Tasks\McAfee\DAD.Execute.Updates" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\McAfee\DAD.Execute.Updates" => not found
"C:\Windows\System32\Tasks\McAfee\McAfee Idle Detection Task" was unlocked. <==== ATTENTION" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D7294A9A-3352-49AB-B910-8E199838193E}" => not found
"C:\WINDOWS\System32\Tasks\McAfee\McAfee Idle Detection Task" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\McAfee\McAfee Idle Detection Task" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA5F1CB2-CBEE-4D4B-B0BA-A0654EFEDEF0}" => not found
"C:\WINDOWS\System32\Tasks\McAfeeLogon" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\McAfeeLogon" => not found
"Edge Notifications:" => removed successfully
"Edge Notifications" => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => removed successfully
"HKLM\Software\Mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}" => not found
"C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi" => not found
"HKLM\Software\Mozilla\Thunderbird\Extensions\\[email protected]" => not found
"HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}" => not found
"HKLM\Software\Wow6432Node\Mozilla\Thunderbird\Extensions\\[email protected]" => not found
"C:\Program Files\McAfee\MSK" => not found
HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10 => not found
"C:\Program Files\McAfee\MSC\npMcSnFFPl64.dll" => not found
"HKLM\Software\Wow6432Node\MozillaPlugins\@mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\MSC\npMcSnFFPl.dll [2021-08-22] (McAfee, LLC" => not found
"C:\Program Files (x86)\McAfee\MSC\npMcSnFFPl.dll" => not found
HKLM\SOFTWARE\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho => not found
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho => not found
Dell SupportAssist Remediation => service not found.
McAfee WebAdvisor => service not found.
McAPExe => service not found.
McAWFwk => service not found.
mccspsvc => service not found.
mfefire => service not found.
mfemms => service not found.
mfevtp => service not found.
ModuleCoreService => service not found.
PEFService => service not found.
SmartByte Network Service x64 => service not found.
cfwids => service not found.
McPvDrv => service not found.
mfeaack => service not found.
mfeavfk => service not found.
mfeelamk => service not found.
mfefirek => service not found.
mfehidk => service not found.
mfencbdc => service not found.
mfencrk => service not found.
mfeplk => service not found.
mfewfpk => service not found.
SmbCoSvc => service not found.
MpKslbdb8f141 => service not found.
C:\WINDOWS\system32\Tasks\McAfee => moved successfully
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee" => not found
"C:\Users\ejbea\OneDrive\Mobile uploads\Documents\McAfee Vaults" => not found
"C:\WINDOWS\system32\Tasks\McAfeeLogon" => not found
"C:\WINDOWS\system32\Tasks\McAfee Remediation (Prepare)" => not found
"C:\Program Files\Dell\SARemediation" => not found
"C:\Program Files\McAfee" => not found
"C:\Program Files\Rivet Networks" => not found
"C:\WINDOWS\System32\drivers\cfwids.sys" => not found
"C:\WINDOWS\system32\drivers\McPvDrv.sys" => not found
"C:\WINDOWS\System32\drivers\mfeaack.sys" => not found
RC:\WINDOWS\System32\drivers\mfeavfk.sys => Error: No automatic fix found for this entry.
"C:\WINDOWS\System32\drivers\mfeelamk.sys" => not found
"C:\WINDOWS\System32\drivers\mfefirek.sys" => not found
"C:\WINDOWS\System32\drivers\mfehidk.sys" => not found
"C:\WINDOWS\System32\DRIVERS\mfencbdc.sys" => not found
"C:\WINDOWS\System32\DRIVERS\mfencrk.sys" => not found
"C:\WINDOWS\System32\drivers\mfeplk.sys" => not found
"C:\WINDOWS\System32\drivers\mfewfpk.sys" => not found
"C:\WINDOWS\system32\DRIVERS\SmbCo10X64.sys" => not found
"C:\Program Files\Common Files\McAfee" => not found
"C:\Program Files\Common Files\AV\McAfee VirusScan" => not found
"C:\Program Files\Rivet Networks" => not found
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 14966784 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 90077758 B
Java, Flash, Steam htmlcache => 735 B
Windows/system/drivers => 145840894 B
Edge => 29538150 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 6656 B
ProgramData => 6656 B
Public => 6656 B
systemprofile => 19003238 B
systemprofile32 => 19003238 B
LocalService => 20623636 B
NetworkService => 29717972 B
ejbea => 163829866 B
 
RecycleBin => 4196042 B
EmptyTemp: => 511.9 MB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 14:32:26 ====
 
AdwCleaner
 
# -------------------------------
# Malwarebytes AdwCleaner 8.3.0.0
# -------------------------------
# Build:    06-29-2021
# Database: 2021-09-09.1 (Cloud)
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    09-22-2021
# Duration: 00:00:24
# OS:       Windows 10 Home
# Scanned:  31990
# Detected: 21
 
 
***** [ Services ] *****
 
No malicious services found.
 
***** [ Folders ] *****
 
No malicious folders found.
 
***** [ Files ] *****
 
No malicious files found.
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
***** [ WMI ] *****
 
No malicious WMI found.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts found.
 
***** [ Tasks ] *****
 
No malicious tasks found.
 
***** [ Registry ] *****
 
PUP.Optional.Legacy             HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\dotomi.com
PUP.Optional.Legacy             HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\familywize.org
PUP.Optional.Legacy             HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\izito.com
PUP.Optional.Legacy             HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\dotomi.com
PUP.Optional.Legacy             HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\familywize.org
PUP.Optional.Legacy             HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\izito.com
PUP.Optional.TheBrightTag       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\s.thebrighttag.com
PUP.Optional.TheBrightTag       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\thebrighttag.com
PUP.Optional.TheBrightTag       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\s.thebrighttag.com
PUP.Optional.TheBrightTag       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\thebrighttag.com
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries found.
 
***** [ Chromium URLs ] *****
 
No malicious Chromium URLs found.
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries found.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs found.
 
***** [ Hosts File Entries ] *****
 
No malicious hosts file entries found.
 
***** [ Preinstalled Software ] *****
 
Preinstalled.DellQuickset   Folder   C:\Program Files\DELL\QUICKSET 
Preinstalled.DellQuickset   Folder   C:\ProgramData\DELL\QUICKSET 
Preinstalled.DellQuickset   Registry   HKLM\Software\Classes\CLSID\{518741A2-FEDB-4917-934D-28BE560D45BA} 
Preinstalled.DellQuickset   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Run|QuickSet 
Preinstalled.DellQuickset   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{87CF757E-C1F1-4D22-865C-00C6950B5258} 
Preinstalled.DellSupportAssistAgent   Folder   C:\ProgramData\DELL\SAREMEDIATION\AGENT 
Preinstalled.DellSupportAssistAgent   Folder   C:\ProgramData\DELL\SAREMEDIATION\PLUGIN 
Preinstalled.DellUpdateforWindows10   Folder   C:\Program Files (x86)\DELL\UPDATESERVICE 
Preinstalled.DellUpdateforWindows10   Folder   C:\Program Files\DELL\UPDATE 
Preinstalled.DellUpdateforWindows10   Folder   C:\ProgramData\DELL\UPDATESERVICE 
Preinstalled.DellUpdateforWindows10   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{70E9F8CC-A23E-4C25-B292-C86C1821587C} 
 
 
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
 
 
Malwarebytes
 
Malwarebytes

www.malwarebytes.com

 

-Log Details-

Scan Date: 9/22/21

Scan Time: 7:02 PM

Log File: 9574a248-1c01-11ec-84c1-6c2b5950f5eb.json

 

-Software Information-

Version: 4.4.6.132

Components Version: 1.0.1453

Update Package Version: 1.0.45240

License: Trial

 

-System Information-

OS: Windows 10 (Build 19041.1237)

CPU: x64

File System: NTFS

User: DESKTOP-2KHI5DN\ejbea

 

-Scan Summary-

Scan Type: Threat Scan

Scan Initiated By: Manual

Result: Completed

Objects Scanned: 305548

Threats Detected: 0

Threats Quarantined: 0

Time Elapsed: 4 min, 43 sec

 

-Scan Options-

Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Detect

PUM: Detect

 

-Scan Details-

Process: 0

(No malicious items detected)

 

Module: 0

(No malicious items detected)

 

Registry Key: 0

(No malicious items detected)

 

Registry Value: 0

(No malicious items detected)

 

Registry Data: 0

(No malicious items detected)

 

Data Stream: 0

(No malicious items detected)

 

Folder: 0

(No malicious items detected)

 

File: 0

(No malicious items detected)

 

Physical Sector: 0

(No malicious items detected)

 

WMI: 0

(No malicious items detected)

 

 

(end)


  • 0

#8
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,096 posts

Well, it seems that I commented on the McAfee Removal tool without noticing that you posted the previous FRST.txt log, created on the 21st of September.
 
Ran by ejbea (administrator) on DESKTOP-2KHI5DN (Dell Inc. Inspiron 15-3567) (21-09-2021 15:20:35)
 
That's why all the Not found warnings in the fixlog. 
 
Let's clean.

1. AdwCleaner (Clean mode)

  • Double click AdwCleaner.exe on your Desktop, to run it as you did before.
  • Click Scan Now.
  • When the scan has finished a Scan Results window will open.
  • Please check all the boxes and then click Quarantine.
  • Click Next.
    • If any pre-installed software was found on your machine, a prompt window will open. Click OK to close it.
    • Check any pre-installed software items to remove.
    • Click Quarantine.
  • A prompt to save your work will appear.
    • Click Continue when you're ready to proceed.
  • A prompt to restart your computer will appear.
    • Click Restart Now.
  • Once your computer has restarted:
    • If it doesn't open automatically, please start AdwCleaner.
    • Click the Log Files tab.
    • Double click on the latest Clean log (Clean logs have a [C0*] suffix, where * is replaced by a number, the latest scan will have the largest number)
    • A Notepad file will open containing the results of the removal.
    • Please post the contents of the file in your next reply.

 

2. ESET Online Scanner

Download ESET Online Scanner and save it to your desktop.

  • Right-click on esetonlinescanner_enu.exe and select Run as Administrator.
  • When the tool opens, click Get Started.
  • Read and accept the license agreement.
  • At the Welcome to ESET Online Scanner window, click Get Started.
  • Select whether you would like to send anonymous data to ESET.
  • Note: if you see the "Welcome Back to ESET Online Scanner" screen, click Computer Scan > Full Scan.
  • Click on the Full Scan option.
  • Select Enable ESET to detect and remove potentially unwanted applications, then click Start scan.
  • ESET will now begin scanning your computer. This may take some time.
  • When the scan is finished and if threats have been detected, select Save scan log. Save it to your desktop as eset.txt. Click on Continue.
  • ESET Online Scanner may ask if you'd like to turn on the Periodic Scan feature. Click on Continue.
  • On the next screen, you can leave feedback about the program if you wish. Check the box for Delete application data on closing. If you left feedback, click Submit and continue. If not, Close without feedback.
  • Open the scan log on your desktop (eset.txt) and copy and paste its contents into your next reply.

 

3. Check Services

  • Please download Farbar Service Scanner and save it on your Desktop. IMPORTANT.
  • Right click on the tool icon and run it as administrator.
  • Make sure all the options are checked.
  • Click on the Scan button.
  • It will create a log (FSS.txt) on your Desktop.
  • Copy and paste the log's content to your next reply.

 

In your next reply please post:

  1. The AdwCleaner[C0*].txt
  2. The eset.txt
  3. The FSS.txt

  • 0

#9
moondog830

moondog830

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 804 posts

Hey Dr. M,

    With my friend's computer moving slow I started by downloading on my computer and transferring to hers the programs etc... that you wanted me to run. However, with ESET it was a link and I tried to simply go to their site and download it on my own and run it ... wrong idea on my part. Now ESET's program is installed and asking me for purchase/license information ... and I'm not sure how to get rid of it. 

 

AdwCleaner C01

 

# -------------------------------

# Malwarebytes AdwCleaner 8.3.0.0
# -------------------------------
# Build:    06-29-2021
# Database: 2021-09-09.1 (Cloud)
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    09-23-2021
# Duration: 00:00:24
# OS:       Windows 10 Home
# Cleaned:  21
# Awaiting reboot:2
# Failed:   0
 
 
***** [ Services ] *****
 
No malicious services cleaned.
 
***** [ Folders ] *****
 
No malicious folders cleaned.
 
***** [ Files ] *****
 
No malicious files cleaned.
 
***** [ DLL ] *****
 
No malicious DLLs cleaned.
 
***** [ WMI ] *****
 
No malicious WMI cleaned.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts cleaned.
 
***** [ Tasks ] *****
 
No malicious tasks cleaned.
 
***** [ Registry ] *****
 
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\dotomi.com
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\familywize.org
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\izito.com
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\s.thebrighttag.com
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\thebrighttag.com
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\dotomi.com
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\familywize.org
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\izito.com
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\s.thebrighttag.com
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\thebrighttag.com
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries cleaned.
 
***** [ Chromium URLs ] *****
 
No malicious Chromium URLs cleaned.
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries cleaned.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs cleaned.
 
***** [ Hosts File Entries ] *****
 
No malicious hosts file entries cleaned.
 
***** [ Preinstalled Software ] *****
 
Deleted       Preinstalled.DellQuickset   Folder   C:\Program Files\DELL\QUICKSET
Deleted       Preinstalled.DellQuickset   Folder   C:\ProgramData\DELL\QUICKSET
Deleted       Preinstalled.DellQuickset   Registry   HKLM\Software\Classes\CLSID\{518741A2-FEDB-4917-934D-28BE560D45BA}
Deleted       Preinstalled.DellQuickset   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Run|QuickSet
Deleted       Preinstalled.DellQuickset   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{87CF757E-C1F1-4D22-865C-00C6950B5258}
Deleted       Preinstalled.DellSupportAssistAgent   Folder   C:\ProgramData\DELL\SAREMEDIATION\AGENT
Deleted       Preinstalled.DellSupportAssistAgent   Folder   C:\ProgramData\DELL\SAREMEDIATION\PLUGIN
Deleted       Preinstalled.DellUpdateforWindows10   Folder   C:\Program Files\DELL\UPDATE
Deleted       Preinstalled.DellUpdateforWindows10   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{70E9F8CC-A23E-4C25-B292-C86C1821587C}
Needs Reboot  Preinstalled.DellUpdateforWindows10   Folder   C:\Program Files (x86)\DELL\UPDATESERVICE
Needs Reboot  Preinstalled.DellUpdateforWindows10   Folder   C:\ProgramData\DELL\UPDATESERVICE
 
 
*************************
 
[+] Delete Tracing Keys
[+] Reset Winsock
 
*************************
 
***** Reboot Required to Complete *****
 
ESET Online Scan
 
9/23/2021 11:30:34 AM
Files scanned: 422985
Detected files: 0
Cleaned files: 0
Total scan time: 05:10:07
Scan status: Finished
 
FSS
 
Farbar Service Scanner Version: 23-12-2020
Ran by ejbea (administrator) on 23-09-2021 at 11:38:53
Running from "C:\Users\ejbea\OneDrive\Desktop"
Microsoft Windows 10 Home  (X64)
Boot Mode: Normal
****************************************************************
 
Internet Services:
============
 
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
 
 
Windows Firewall:
=============
 
Firewall Disabled Policy: 
==================
 
 
System Restore:
============
 
System Restore Policy: 
========================
 
 
Windows Security:
============
 
 
Windows Update:
============
 
Windows Autoupdate Disabled Policy: 
============================
 
 
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend: ""C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MsMpEng.exe"".
 
 
Windows Defender Disabled Policy: 
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
 
 
Other Services:
==============
 
 
File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\Drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\Drivers\afd.sys => File is digitally signed
C:\Windows\System32\Drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\Drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\SecurityHealthService.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
 
 
**** End of log ****

  • 0

#10
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,096 posts

Hi, Mark.

 

The Eset Online Scanner is free. You probably installed the antivirus? You can use the Eset removal tool to remove whatever you installed. 

 

Please use the problematic computer from now on. I'll wait for the scan result before giving you any further instructions.


  • 0

Advertisements


#11
moondog830

moondog830

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 804 posts

downloaded Eset removal tool and ran it ... it does not recognize any supported applications. I navigate to programs and features to attempt to uninstall 'ESET Security' but don't have an option to uninstall ... only an option to CHANGE.


  • 0

#12
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,096 posts

In the installed programs list what is the exact name of the Eset product you installed? 


  • 0

#13
moondog830

moondog830

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 804 posts

ESET Security

 

do you want a screenshot of it?

 

it also has a pop-up that asks me to purchase or set up my account

 

Also, you said to use the problematic pc ... it will not let me refresh the geeks page and it will not allow me to go to the Eset removal tool link. For both it get the message

This page isn't responding, lists the page and then asks if I want wait or cancel.


Edited by moondog830, 23 September 2021 - 01:46 PM.

  • 0

#14
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,096 posts

Hi, Mark.
 
Let's take things one by one.
 
For your computer
 
Try the actual Eset removal tool. There are detailed instructions here: %5BKB2289%5D Manually uninstall your ESET product using the ESET uninstaller tool
 
 
For the problematic computer
 

it will not let me refresh the geeks page and it will not allow me to go to the Eset removal tool link. For both it get the message
 
This page isn't responding, lists the page and then asks if I want wait or cancel.

 
This is something I didn't knew.
 
Question: 
 
What browser are you using? Is the connection problem occurs with other browsers too?
 

 

Let's use a different way.

Run Deployment Image Servicing and Management (DISM)

  • Click on the Start button and in the search box, type Command Prompt
  • When you see Command Prompt on the list, right-click on it and select Run as administrator
  • Enter the command below and press on Enter;
DISM /Online /Cleanup-Image /RestoreHealth
  • Let the scan run until the end (100%). Depending on your system, it can take some time.
  • Please post here the result you got (Screenshot)

 

When DISM finishes, you can then run SFC from the same command prompt window, but full instructions as if starting fresh:

  • Click on the Start button and in the search box, type Command Prompt
  • When you see Command Prompt on the list, right-click on it and select Run as administrator
  • Enter the command below and press on Enter
sfc /scannow
  • Let the scan finish.
  • You will normally get one of the following results:
    Windows Resource Protection did not find any integrity violations
    Windows Resource Protection found corrupt files and successfully repaired them
    Windows Resource Protection found corrupt files but was unable to fix some of them
    Windows Resource Protection could not perform the requested operation
    
    Please post the result you got (Screenshot).

  • 0

#15
moondog830

moondog830

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 804 posts

when I try to get to safe mode to run the ESET removal tool it takes me to a page asking for a restoration key for 'BitLocker' ... don't even know what that is. 

 

the thing with the browser was only yesterday, I can now get to the all pages in Edge (which is what she uses) and Brave ... 


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP