Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Ran Malwarebytes and Internet won't work
Message
<blockquote data-quote="Lacywilmerton" data-source="post: 793576" data-attributes="member: 77545"><p>As an update, if I restart the computer, the internet functions for awhile. But then it stops again. I'm scanning with frst right now and will provide the report asap.</p><p></p><p>Here's the FRST log</p><p>[code]</p><p>Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.01.2019</p><p>Ran by hp (administrator) on HP-PC (22-01-2019 14:46:33)</p><p>Running from C:\Users\hp\Downloads</p><p>Loaded Profiles: hp (Available Profiles: hp)</p><p>Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)</p><p>Internet Explorer Version 11 (Default browser: Chrome)</p><p>Boot Mode: Normal</p><p>Tutorial for Farbar Recovery Scan Tool: [URL="http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/"]FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials[/URL]</p><p></p><p>==================== Processes (Whitelisted) =================</p><p></p><p>(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)</p><p></p><p>(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\vsserv.exe</p><p>(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe</p><p>(Bitdefender) C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnService.exe</p><p>(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe</p><p>(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe</p><p>(Microsoft Corporation) C:\Windows\System32\wlanext.exe</p><p>(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe</p><p>(Intel Corporation) C:\Windows\System32\igfxtray.exe</p><p>(Intel Corporation) C:\Windows\System32\hkcmd.exe</p><p>(Intel Corporation) C:\Windows\System32\igfxpers.exe</p><p>(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe</p><p>(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe</p><p>(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe</p><p>(Bitdefender) C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnApp.exe</p><p>(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler64.exe</p><p>(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe</p><p>(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe</p><p>(Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe</p><p>(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe</p><p>(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe</p><p>(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe</p><p>(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe</p><p>(Bitdefender) C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe</p><p>(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe</p><p>(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Microsoft Corporation) C:\Windows\System32\dllhost.exe</p><p></p><p>==================== Registry (Whitelisted) ===========================</p><p></p><p>(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)</p><p></p><p>HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-10-24] (IDT, Inc.)</p><p>HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2833504 2017-08-26] (Synaptics Incorporated)</p><p>HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe [482024 2018-11-23] (Bitdefender)</p><p>HKLM\...\Run: [BdVpnApp] => C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnApp.exe [91384 2018-11-16] (Bitdefender)</p><p>HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)</p><p>HKLM-x32\...\Run: [NUSB3MON] => c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048 2011-09-16] (Renesas Electronics Corporation)</p><p>HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-26] (Intel Corporation)</p><p>HKU\S-1-5-21-4218809093-567755804-543443116-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [5583120 2015-02-27] (Disc Soft Ltd)</p><p>HKU\S-1-5-21-4218809093-567755804-543443116-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-20] (Microsoft Corporation)</p><p>HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601</p><p>HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\Installer\chrmstp.exe [2019-01-20] (Google Inc.)</p><p>Startup: C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2018-03-17]</p><p>ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)</p><p>CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION</p><p></p><p>==================== Internet (Whitelisted) ====================</p><p></p><p>(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)</p><p></p><p>Tcpip\Parameters: [DhcpNameServer] 192.168.1.1</p><p>Tcpip\Parameters: [NameServer] 8.8.8.8</p><p>Tcpip\..\Interfaces\{2428F2AD-69F4-4776-822B-F219A75AA330}: [NameServer] 8.8.8.8</p><p>Tcpip\..\Interfaces\{2428F2AD-69F4-4776-822B-F219A75AA330}: [DhcpNameServer] 192.168.1.1</p><p>Tcpip\..\Interfaces\{2495A7F8-9D33-48F2-B9FD-E42EBF9700F7}: [NameServer] 8.8.8.8</p><p>Tcpip\..\Interfaces\{53086195-A107-4AA9-8886-C663EE54DE95}: [NameServer] 8.8.8.8</p><p>Tcpip\..\Interfaces\{56142C7C-244D-4E03-AA1A-795AA0D28447}: [NameServer] 8.8.8.8</p><p>Tcpip\..\Interfaces\{BFF9657D-D5BA-4FA4-99FC-CA986724B041}: [DhcpNameServer] 192.168.1.1</p><p>Tcpip\..\Interfaces\{D770B206-273D-4D48-B604-BC4AC181B2D2}: [NameServer] 8.8.8.8</p><p>Tcpip\..\Interfaces\{D8E4B8E5-73F4-438C-8795-2857B9A14A08}: [NameServer] 8.8.8.8</p><p></p><p>Internet Explorer:</p><p>==================</p><p>BHO: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2018-12-04] (Bitdefender)</p><p>BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)</p><p>BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)</p><p>BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.)</p><p>BHO-x32: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2018-12-04] (Bitdefender)</p><p>BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)</p><p>BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2018-03-30] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)</p><p>BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)</p><p>BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)</p><p>Toolbar: HKLM - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2018-12-04] (Bitdefender)</p><p>Toolbar: HKLM-x32 - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2018-12-04] (Bitdefender)</p><p></p><p>FireFox:</p><p>========</p><p>FF DefaultProfile: 0pdmxapa.default</p><p>FF ProfilePath: C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\0pdmxapa.default [2019-01-21]</p><p>FF HKLM\...\Firefox\Extensions: [[email]bdwtwe@bitdefender.com[/email]] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi</p><p>FF Extension: (Bitdefender Wallet) - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi [2018-11-23]</p><p>FF HKLM\...\Thunderbird\Extensions: [[email]bdThunderbird@bitdefender.com[/email]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext</p><p>FF Extension: (Bitdefender Antispam Toolbar) - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext [2018-12-20] [Legacy] [not signed]</p><p>FF HKLM-x32\...\Firefox\Extensions: [[email]bdwtwe@bitdefender.com[/email]] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi</p><p>FF HKLM-x32\...\Thunderbird\Extensions: [[email]bdThunderbird@bitdefender.com[/email]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext</p><p>FF Plugin: @microsoft.com/GENUINE -> disabled [No File]</p><p>FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] ( Microsoft Corporation)</p><p>FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)</p><p>FF Plugin: @videolan.org/vlc,version=3.0.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN)</p><p>FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1231201.dll [2017-11-02] (Adobe Systems, Inc.)</p><p>FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]</p><p>FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]</p><p>FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]</p><p>FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] ( Microsoft Corporation)</p><p>FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)</p><p>FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)</p><p>FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc.)</p><p>FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc.)</p><p>FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-12-04] (Adobe Systems Inc.)</p><p></p><p>Chrome: </p><p>=======</p><p>CHR Session Restore: Default -> is enabled.</p><p>CHR Profile: C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default [2019-01-22]</p><p>CHR Extension: (Google Drive) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-03-17]</p><p>CHR Extension: (YouTube) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-03-17]</p><p>CHR Extension: (Chrome Web Store Payments) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]</p><p>CHR Extension: (Gmail) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-03-17]</p><p>CHR Extension: (Chrome Media Router) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-21]</p><p>CHR Profile: C:\Users\hp\AppData\Local\Google\Chrome\User Data\System Profile [2018-03-20]</p><p>CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx</p><p>CHR HKLM-x32\...\Chrome\Extension: [gannpgaobkkhmpomoijebaigcapoeebl] - hxxps://clients2.google.com/service/update2/crx</p><p></p><p>==================== Services (Whitelisted) ====================</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p>R2 AESTFilters; C:\Program Files\IDT\WDM\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation) [File not signed]</p><p>S3 AfVpnService; C:\Program Files\Bitdefender\Bitdefender VPN\vpnservice.exe [322432 2018-10-25] (AnchorFree Inc.)</p><p>S2 AmazonMeterService; C:\Program Files (x86)\ShopTracker\Scheduler\AmazonMeter.Scheduler.exe [32664 2018-08-07] (VL)</p><p>R2 BDAuxSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [779152 2018-11-23] (Bitdefender)</p><p>R2 bdredline; C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe [2195320 2018-03-22] (Bitdefender)</p><p>R2 BdVpnService; C:\Program Files\Bitdefender\Bitdefender VPN\bdvpnservice.exe [96568 2018-11-16] (Bitdefender)</p><p>R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272592 2015-02-27] (Disc Soft Ltd)</p><p>S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-03] (HP)</p><p>R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [347512 2018-12-06] (HP Inc.)</p><p>R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes)</p><p>R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1293936 2018-11-15] (Bitdefender)</p><p>R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2012-10-24] (IDT, Inc.) [File not signed]</p><p>R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe [112656 2018-11-23] (Bitdefender)</p><p>R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender Security\vsserv.exe [804656 2018-11-23] (Bitdefender)</p><p>S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)</p><p></p><p>===================== Drivers (Whitelisted) ======================</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p>R3 aftap0901; C:\Windows\System32\DRIVERS\aftap0901.sys [48624 2018-06-15] (The OpenVPN Project)</p><p>R1 atc; C:\Windows\System32\DRIVERS\atc.sys [1292296 2018-06-05] (BitDefender S.R.L. Bucharest, ROMANIA)</p><p>R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1725800 2018-02-02] (BitDefender)</p><p>R2 BdDci; C:\Windows\System32\DRIVERS\bddci.sys [156912 2018-10-18] (Bitdefender)</p><p>R0 bdprivmon; C:\Windows\System32\DRIVERS\bdprivmon.sys [45728 2018-09-17] (© Bitdefender SRL)</p><p>R1 BDVEDISK; C:\Windows\System32\DRIVERS\bdvedisk.sys [96448 2018-04-27] (BitDefender)</p><p>R3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [29184 2009-08-13] (CSR, plc)</p><p>R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30352 2018-07-16] (Disc Soft Ltd)</p><p>S3 edrsensor; C:\Windows\System32\DRIVERS\edrsensor.sys [248336 2017-11-15] (BitDefender S.R.L. Bucharest, ROMANIA)</p><p>R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [152688 2018-12-04] (Malwarebytes)</p><p>R1 Gemma; C:\Windows\System32\DRIVERS\Gemma.sys [359584 2018-10-04] (BitDefender S.R.L. Bucharest, ROMANIA)</p><p>R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [193184 2018-05-29] (BitDefender LLC)</p><p>R2 Ignis; C:\Windows\System32\DRIVERS\ignis.sys [196352 2018-10-26] (Bitdefender)</p><p>R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [198512 2019-01-21] (Malwarebytes)</p><p>R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [126624 2019-01-22] (Malwarebytes)</p><p>R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [72536 2019-01-22] (Malwarebytes)</p><p>R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [261032 2019-01-22] (Malwarebytes)</p><p>R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [103760 2019-01-22] (Malwarebytes)</p><p>R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [2621128 2015-07-15] (Sonix Tech. Co., Ltd.)</p><p>R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381608 2018-07-16] (Duplex Secure Ltd.)</p><p>R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [609576 2018-06-28] (Bitdefender)</p><p>S3 CLMirrorDriver; system32\DRIVERS\CLMirrorDriver.sys [X]</p><p>S3 clwvd8; system32\DRIVERS\clwvd8.sys [X]</p><p></p><p>==================== NetSvcs (Whitelisted) ===================</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p></p><p>==================== One month (created) ========</p><p></p><p>(If an entry is included in the fixlist, the file/folder will be moved.)</p><p></p><p>2019-01-22 14:46 - 2019-01-22 14:47 - 000018629 _____ C:\Users\hp\Downloads\FRST.txt</p><p>2019-01-22 14:46 - 2019-01-22 14:46 - 000000000 ____D C:\FRST</p><p>2019-01-22 14:45 - 2019-01-22 14:45 - 002428416 _____ (Farbar) C:\Users\hp\Downloads\FRST64.exe</p><p>2019-01-22 14:40 - 2019-01-22 14:40 - 000126624 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys</p><p>2019-01-22 14:40 - 2019-01-22 14:40 - 000072536 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys</p><p>2019-01-22 14:39 - 2019-01-22 14:48 - 000103760 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys</p><p>2019-01-22 14:39 - 2019-01-22 14:39 - 000261032 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys</p><p>2019-01-22 10:18 - 2019-01-22 10:18 - 000000000 ____D C:\ProgramData\HitmanPro</p><p>2019-01-22 08:16 - 2019-01-22 08:16 - 000001413 _____ C:\Users\hp\Desktop\Internet Explorer.lnk</p><p>2019-01-22 08:06 - 2019-01-22 08:06 - 000034894 _____ C:\ProgramData\dm.uninstall.1548173102.bdinstall.bin</p><p>2019-01-22 00:22 - 2019-01-22 14:34 - 000002015 _____ C:\bdlog.txt</p><p>2019-01-21 23:57 - 2019-01-21 23:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender VPN</p><p>2019-01-21 23:57 - 2019-01-21 23:57 - 000000000 ____D C:\ProgramData\Bitdefender VPN</p><p>2019-01-21 23:57 - 2019-01-21 23:57 - 000000000 _____ C:\ProgramData\vpn.1548143609.bdinstall.bin</p><p>2019-01-21 23:56 - 2018-06-15 09:26 - 000048624 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\aftap0901.sys</p><p>2019-01-21 23:52 - 2019-01-21 23:52 - 000043592 _____ C:\ProgramData\dm.update.1548143335.bdinstall.bin</p><p>2019-01-21 23:48 - 2019-01-21 23:48 - 000058739 _____ C:\ProgramData\dm.1548142798.bdinstall.bin</p><p>2019-01-21 23:47 - 2019-01-21 23:47 - 000000000 ____D C:\ProgramData\Bitdefender Device Management</p><p>2019-01-21 23:46 - 2019-01-22 14:38 - 000065536 _____ C:\Windows\system32\Ikeext.etl</p><p>2019-01-21 23:39 - 2019-01-21 23:39 - 000806224 _____ C:\ProgramData\cl.1548141579.bdinstall.v2.bin</p><p>2019-01-21 23:39 - 2019-01-21 23:39 - 000101492 _____ C:\ProgramData\cl.kit.1548141549.bdinstall.v2.bin</p><p>2019-01-21 23:37 - 2019-01-21 23:37 - 000000000 ____D C:\ProgramData\Gemma</p><p>2019-01-21 23:37 - 2019-01-21 23:37 - 000000000 ____D C:\ProgramData\Atc</p><p>2019-01-21 23:36 - 2019-01-21 23:57 - 000002078 _____ C:\Users\Public\Desktop\Bitdefender VPN.lnk</p><p>2019-01-21 23:36 - 2019-01-21 23:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender Security</p><p>2019-01-21 23:36 - 2019-01-21 23:36 - 000002230 _____ C:\Users\Public\Desktop\Bitdefender.lnk</p><p>2019-01-21 23:36 - 2019-01-21 23:36 - 000000000 ____D C:\Windows\system32\elambkup</p><p>2019-01-21 23:36 - 2019-01-21 23:36 - 000000000 ____D C:\ProgramData\BDLogging</p><p>2019-01-21 23:36 - 2018-04-19 07:37 - 000023032 _____ (Bitdefender) C:\Windows\system32\Drivers\bdelam.sys</p><p>2019-01-21 23:35 - 2018-10-04 22:40 - 000359584 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\Windows\system32\Drivers\Gemma.sys</p><p>2019-01-21 23:35 - 2018-04-27 07:45 - 000096448 _____ (BitDefender) C:\Windows\system32\Drivers\bdvedisk.sys</p><p>2019-01-21 23:35 - 2007-04-11 10:11 - 000511328 _____ (Microsoft Corporation) C:\Windows\capicom.dll</p><p>2019-01-21 23:34 - 2019-01-22 08:27 - 000000000 ____D C:\Program Files\Bitdefender</p><p>2019-01-21 23:34 - 2019-01-21 23:43 - 000000000 ____D C:\Users\hp\AppData\Roaming\Bitdefender</p><p>2019-01-21 23:34 - 2018-10-26 10:57 - 000196352 _____ (Bitdefender) C:\Windows\system32\Drivers\ignis.sys</p><p>2019-01-21 23:34 - 2018-10-18 17:12 - 000156912 _____ (Bitdefender) C:\Windows\system32\Drivers\bddci.sys</p><p>2019-01-21 23:34 - 2018-09-17 04:36 - 000045728 _____ (© Bitdefender SRL) C:\Windows\system32\Drivers\bdprivmon.sys</p><p>2019-01-21 23:34 - 2018-06-28 13:39 - 000609576 _____ (Bitdefender) C:\Windows\system32\Drivers\trufos.sys</p><p>2019-01-21 23:34 - 2018-06-05 03:32 - 001292296 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\Windows\system32\Drivers\atc.sys</p><p>2019-01-21 23:34 - 2018-05-29 04:04 - 000193184 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys</p><p>2019-01-21 23:19 - 2019-01-21 23:34 - 000000000 ____D C:\Program Files\Common Files\Bitdefender</p><p>2019-01-21 23:17 - 2019-01-22 14:40 - 000003648 _____ C:\Windows\System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864</p><p>2019-01-21 23:15 - 2019-01-21 23:48 - 000000000 ____D C:\Program Files\Bitdefender Agent</p><p>2019-01-21 23:15 - 2019-01-21 23:15 - 000105828 _____ C:\ProgramData\agent.1548141312.bdinstall.v2.bin</p><p>2019-01-21 23:09 - 2019-01-21 23:10 - 011334352 _____ C:\Users\hp\Downloads\bitdefender_isecurity.exe</p><p>2019-01-21 22:20 - 2019-01-22 09:56 - 000000000 ____D C:\Users\hp\AppData\Roaming\Fighters</p><p>2019-01-21 22:19 - 2019-01-22 09:56 - 000000000 ____D C:\ProgramData\Fighters</p><p>2019-01-21 17:53 - 2019-01-10 16:49 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys</p><p>2019-01-21 17:53 - 2019-01-10 16:49 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys</p><p>2019-01-21 17:53 - 2019-01-10 16:47 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll</p><p>2019-01-21 17:53 - 2019-01-10 16:47 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll</p><p>2019-01-21 17:53 - 2019-01-10 16:47 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll</p><p>2019-01-21 17:53 - 2019-01-10 16:46 - 001472512 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll</p><p>2019-01-21 17:53 - 2019-01-10 16:34 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll</p><p>2019-01-21 17:53 - 2019-01-10 16:34 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll</p><p>2019-01-21 17:53 - 2019-01-10 16:15 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe</p><p>2019-01-21 17:53 - 2018-12-28 11:59 - 002072576 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll</p><p>2019-01-21 17:53 - 2018-12-28 11:59 - 000876032 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll</p><p>2019-01-21 17:53 - 2018-12-28 11:59 - 000516608 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll</p><p>2019-01-21 17:53 - 2018-12-28 11:59 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll</p><p>2019-01-21 17:53 - 2018-12-28 11:59 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll</p><p>2019-01-21 17:53 - 2018-12-28 11:48 - 001425920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll</p><p>2019-01-21 17:53 - 2018-12-28 11:48 - 000582144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll</p><p>2019-01-21 17:53 - 2018-12-28 11:48 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll</p><p>2019-01-21 17:53 - 2018-12-28 11:32 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll</p><p>2019-01-21 17:53 - 2018-12-04 08:07 - 000194048 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll</p><p>2019-01-21 17:53 - 2018-12-04 08:07 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll</p><p>2019-01-21 17:53 - 2018-12-04 07:55 - 000158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itircl.dll</p><p>2019-01-21 17:53 - 2018-12-04 07:55 - 000142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll</p><p>2019-01-21 17:53 - 2018-12-02 08:06 - 000687616 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000998480 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000918408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000066000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000063936 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000021968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000020944 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000019408 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000018880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000017872 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000017856 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000017360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000017352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000016336 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000015824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000015808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000015296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000014312 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000014272 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000013768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000013760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000013760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000013264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000012752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000012736 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000012264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000012240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000012240 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000012240 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000012232 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000012224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000012224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000012024 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000011752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000011728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000011728 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000011512 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000011216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000011216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000011216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll</p><p>2019-01-21 17:53 - 2018-10-12 05:05 - 000011200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll</p><p>2019-01-21 02:18 - 2019-01-21 02:19 - 082430032 _____ (Malwarebytes ) C:\Users\hp\Downloads\mb3-setup-consumer-3.6.1.2711-1.0.519-1.0.8878 (1).exe</p><p>2019-01-21 00:47 - 2019-01-21 20:09 - 000198512 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys</p><p>2019-01-21 00:47 - 2019-01-21 00:47 - 000001827 _____ C:\Users\Public\Desktop\Malwarebytes.lnk</p><p>2019-01-21 00:47 - 2019-01-21 00:47 - 000000000 ____D C:\Users\hp\AppData\Local\mbamtray</p><p>2019-01-21 00:47 - 2019-01-21 00:47 - 000000000 ____D C:\Users\hp\AppData\Local\mbam</p><p>2019-01-21 00:47 - 2019-01-21 00:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes</p><p>2019-01-21 00:47 - 2019-01-21 00:47 - 000000000 ____D C:\ProgramData\Malwarebytes</p><p>2019-01-21 00:47 - 2019-01-21 00:47 - 000000000 ____D C:\Program Files\Malwarebytes</p><p>2019-01-21 00:47 - 2018-12-04 08:09 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys</p><p>2019-01-21 00:36 - 2019-01-21 00:44 - 082430032 _____ (Malwarebytes ) C:\Users\hp\Downloads\mb3-setup-consumer-3.6.1.2711-1.0.519-1.0.8878.exe</p><p>2019-01-20 23:47 - 2019-01-20 23:47 - 000002296 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk</p><p>2019-01-20 23:47 - 2019-01-20 23:47 - 000002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk</p><p>2019-01-15 23:33 - 2019-01-17 22:24 - 000000000 ____D C:\Users\hp\AppData\Roaming\obs-studio</p><p>2019-01-15 23:29 - 2019-01-15 23:29 - 000001003 _____ C:\Users\Public\Desktop\OBS Studio.lnk</p><p>2019-01-15 23:29 - 2019-01-15 23:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio</p><p>2019-01-15 23:29 - 2019-01-15 23:29 - 000000000 ____D C:\Program Files\obs-studio</p><p>2019-01-15 22:55 - 2019-01-15 22:55 - 069551216 _____ (obsproject.com) C:\Users\hp\Downloads\OBS-Studio-22.0.2-Full-Installer-x64.exe</p><p>2019-01-09 08:25 - 2018-12-28 15:42 - 000396888 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll</p><p>2019-01-09 08:25 - 2018-12-28 14:52 - 000348760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll</p><p>2019-01-09 08:25 - 2018-12-28 12:03 - 000631680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi</p><p>2019-01-09 08:25 - 2018-12-28 12:02 - 005552360 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe</p><p>2019-01-09 08:25 - 2018-12-28 12:02 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys</p><p>2019-01-09 08:25 - 2018-12-28 12:02 - 000708328 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi</p><p>2019-01-09 08:25 - 2018-12-28 12:02 - 000262376 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll</p><p>2019-01-09 08:25 - 2018-12-28 12:01 - 001664360 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 001211904 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000094208 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:51 - 004055272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe</p><p>2019-01-09 08:25 - 2018-12-28 11:51 - 003960552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe</p><p>2019-01-09 08:25 - 2018-12-28 11:50 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000275968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:34 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe</p><p>2019-01-09 08:25 - 2018-12-28 11:34 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe</p><p>2019-01-09 08:25 - 2018-12-28 11:34 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys</p><p>2019-01-09 08:25 - 2018-12-28 11:34 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe</p><p>2019-01-09 08:25 - 2018-12-28 11:31 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe</p><p>2019-01-09 08:25 - 2018-12-28 11:31 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe</p><p>2019-01-09 08:25 - 2018-12-28 11:31 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys</p><p>2019-01-09 08:25 - 2018-12-28 11:30 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe</p><p>2019-01-09 08:25 - 2018-12-28 11:28 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys</p><p>2019-01-09 08:25 - 2018-12-28 11:28 - 000161280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys</p><p>2019-01-09 08:25 - 2018-12-28 11:28 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys</p><p>2019-01-09 08:25 - 2018-12-28 11:27 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe</p><p>2019-01-09 08:25 - 2018-12-28 11:27 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys</p><p>2019-01-09 08:25 - 2018-12-28 11:27 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys</p><p>2019-01-09 08:25 - 2018-12-28 11:27 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys</p><p>2019-01-09 08:25 - 2018-12-28 11:27 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys</p><p>2019-01-09 08:25 - 2018-12-28 11:27 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe</p><p>2019-01-09 08:25 - 2018-12-28 11:27 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:27 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe</p><p>2019-01-09 08:25 - 2018-12-28 11:27 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe</p><p>2019-01-09 08:25 - 2018-12-28 11:26 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:26 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:26 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 11:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll</p><p>2019-01-09 08:25 - 2018-12-28 10:09 - 000419608 _____ C:\Windows\SysWOW64\locale.nls</p><p>2019-01-09 08:25 - 2018-12-28 10:09 - 000419608 _____ C:\Windows\system32\locale.nls</p><p>2019-01-09 08:25 - 2018-12-27 16:01 - 025738240 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:50 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb</p><p>2019-01-09 08:25 - 2018-12-27 15:50 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:38 - 002902016 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:37 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:36 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:36 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec</p><p>2019-01-09 08:25 - 2018-12-27 15:36 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:36 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:31 - 005778944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:29 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:28 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:26 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:25 - 020279808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:25 - 000790016 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:25 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe</p><p>2019-01-09 08:25 - 2018-12-27 15:25 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe</p><p>2019-01-09 08:25 - 2018-12-27 15:24 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:17 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb</p><p>2019-01-09 08:25 - 2018-12-27 15:17 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe</p><p>2019-01-09 08:25 - 2018-12-27 15:14 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:07 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx</p><p>2019-01-09 08:25 - 2018-12-27 15:07 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:06 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:05 - 000498176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:05 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:04 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec</p><p>2019-01-09 08:25 - 2018-12-27 15:04 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:03 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:03 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:03 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:02 - 002295808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll</p><p>2019-01-09 08:25 - 2018-12-27 15:01 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:59 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:59 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:58 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:56 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:55 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:55 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:55 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe</p><p>2019-01-09 08:25 - 2018-12-27 14:50 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:48 - 015284224 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:48 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:48 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe</p><p>2019-01-09 08:25 - 2018-12-27 14:47 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:46 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:45 - 002135552 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl</p><p>2019-01-09 08:25 - 2018-12-27 14:43 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:42 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:42 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx</p><p>2019-01-09 08:25 - 2018-12-27 14:39 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:39 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:37 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:36 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:33 - 004860416 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:33 - 004494848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:31 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:29 - 013680640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:29 - 002060288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl</p><p>2019-01-09 08:25 - 2018-12-27 14:29 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:28 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:22 - 001555968 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:11 - 004386816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:11 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:07 - 001329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll</p><p>2019-01-09 08:25 - 2018-12-27 14:06 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll</p><p>2019-01-09 08:25 - 2018-12-07 19:08 - 000095744 _____ (Microsoft Corporation) C:\Windows\system32\rascfg.dll</p><p>2019-01-09 08:25 - 2018-12-07 19:08 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll</p><p>2019-01-09 08:25 - 2018-12-07 19:08 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\ndptsp.tsp</p><p>2019-01-09 08:25 - 2018-12-07 19:08 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\kmddsp.tsp</p><p>2019-01-09 08:25 - 2018-12-07 19:08 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\rasmxs.dll</p><p>2019-01-09 08:25 - 2018-12-07 19:08 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\rasser.dll</p><p>2019-01-09 08:25 - 2018-12-07 18:56 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rascfg.dll</p><p>2019-01-09 08:25 - 2018-12-07 18:56 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdiag.dll</p><p>2019-01-09 08:25 - 2018-12-07 18:56 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ndptsp.tsp</p><p>2019-01-09 08:25 - 2018-12-07 18:47 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys</p><p>2019-01-09 08:25 - 2018-12-07 18:47 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys</p><p>2019-01-09 08:25 - 2018-12-07 18:47 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndistapi.sys</p><p>2019-01-09 08:25 - 2018-12-07 18:41 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kmddsp.tsp</p><p>2019-01-09 08:25 - 2018-12-07 18:41 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasmxs.dll</p><p>2019-01-09 08:25 - 2018-12-07 18:41 - 000022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasser.dll</p><p>2019-01-09 08:25 - 2018-12-07 07:33 - 000352768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll</p><p>2019-01-05 11:27 - 2019-01-05 11:27 - 000000000 ____D C:\ProgramData\Jetmedia</p><p>2019-01-05 11:25 - 2019-01-15 12:24 - 000000000 ____D C:\ProgramData\Gxjri</p><p>2019-01-05 11:25 - 2019-01-05 11:25 - 000000000 ____D C:\ProgramData\Gjmp</p><p>2019-01-02 20:32 - 2019-01-02 20:32 - 000238937 _____ C:\Users\hp\Downloads\The-Buried-Secrets-of-Peonies.pdf</p><p>2018-12-31 14:26 - 2018-12-31 14:26 - 000000000 ____D C:\Program Files\DIFX</p><p>2018-12-31 14:25 - 2018-12-31 14:28 - 000245568 _____ (KEYLOK) C:\Windows\system32\NWKL2_64.DLL</p><p>2018-12-31 14:25 - 2018-12-31 14:28 - 000236352 _____ (KEYLOK) C:\Windows\system32\KL2DLL64.DLL</p><p>2018-12-31 14:25 - 2018-12-31 14:28 - 000207168 _____ (KEYLOK) C:\Windows\SysWOW64\NWKL2_32.DLL</p><p>2018-12-31 14:25 - 2018-12-31 14:28 - 000198976 _____ (KEYLOK) C:\Windows\SysWOW64\KL2DLL32.DLL</p><p>2018-12-31 14:25 - 2018-12-31 14:28 - 000041984 _____ C:\Windows\system32\ppmon64.exe</p><p>2018-12-31 14:25 - 2018-12-31 14:28 - 000024136 _____ C:\Windows\SysWOW64\ppmon.exe</p><p>2018-12-31 14:25 - 2018-12-31 14:28 - 000012480 _____ C:\Windows\SysWOW64\KL2N.DLL</p><p>2018-12-31 14:25 - 2018-12-31 14:28 - 000007440 _____ C:\Windows\SysWOW64\ppmon.dll</p><p>2018-12-31 14:25 - 2018-12-31 14:28 - 000000000 ____D C:\Users\hp\AppData\Local\KEYLOK</p><p></p><p>==================== One month (modified) ========</p><p></p><p>(If an entry is included in the fixlist, the file/folder will be moved.)</p><p></p><p>2019-01-22 14:47 - 2009-07-13 20:45 - 000018752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0</p><p>2019-01-22 14:47 - 2009-07-13 20:45 - 000018752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0</p><p>2019-01-22 14:41 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\tracing</p><p>2019-01-22 14:37 - 2009-07-13 21:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT</p><p>2019-01-22 14:34 - 2018-06-22 12:50 - 000000000 ____D C:\Users\hp\AmazonMeter</p><p>2019-01-22 14:00 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\rescache</p><p>2019-01-22 10:18 - 2009-07-13 21:13 - 000781790 _____ C:\Windows\system32\PerfStringBackup.INI</p><p>2019-01-22 10:18 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\inf</p><p>2019-01-22 09:59 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\system32\NDF</p><p>2019-01-22 08:00 - 2018-04-03 15:06 - 000000000 ____D C:\Program Files\Recuva</p><p>2019-01-22 00:17 - 2018-07-16 20:53 - 000000000 ____D C:\Users\hp\AppData\Roaming\DAEMON Tools Lite</p><p>2019-01-21 23:34 - 2018-04-10 11:04 - 000000000 ____D C:\ProgramData\Bitdefender</p><p>2019-01-21 23:34 - 2018-03-18 09:19 - 000001945 _____ C:\Windows\epplauncher.mif</p><p>2019-01-21 23:29 - 2018-09-18 19:43 - 000003168 _____ C:\Windows\System32\Tasks\HPCeeScheduleForhp</p><p>2019-01-21 23:29 - 2018-09-18 19:43 - 000000320 _____ C:\Windows\Tasks\HPCeeScheduleForhp.job</p><p>2019-01-21 22:31 - 2018-03-05 06:54 - 000000000 ____D C:\Users\hp</p><p>2019-01-21 22:10 - 2018-04-09 17:59 - 000371954 _____ C:\Windows\ntbtlog.txt</p><p>2019-01-21 19:02 - 2018-03-28 09:54 - 000007610 _____ C:\Users\hp\AppData\Local\Resmon.ResmonCfg</p><p>2019-01-21 19:01 - 2018-06-22 12:50 - 000000000 ____D C:\Users\hp\AppData\Local\ShopTracker</p><p>2019-01-21 18:51 - 2018-11-09 20:08 - 000000000 ____D C:\ProgramData\install_clap</p><p>2019-01-21 18:51 - 2018-04-23 21:14 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information</p><p>2019-01-21 18:50 - 2018-11-13 23:21 - 000000000 ____D C:\Users\hp\AppData\Local\CyberLink</p><p>2019-01-21 18:50 - 2018-11-10 00:18 - 000000000 ____D C:\Users\Public\Documents\CyberLink</p><p>2019-01-21 17:57 - 2018-03-18 00:00 - 000774404 _____ C:\Windows\SysWOW64\PerfStringBackup.INI</p><p>2019-01-20 23:46 - 2018-03-05 08:56 - 000000000 ____D C:\Program Files (x86)\Google</p><p>2019-01-20 23:39 - 2018-03-05 08:53 - 000003902 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{F6E746E4-63AF-49FA-9A7B-94C1E28737FA}</p><p>2019-01-20 23:22 - 2009-07-13 19:20 - 000000000 ____D C:\PerfLogs</p><p>2019-01-20 22:46 - 2018-03-18 09:20 - 000000000 ____D C:\Program Files\Microsoft Silverlight</p><p>2019-01-20 22:46 - 2018-03-18 09:20 - 000000000 ____D C:\Program Files (x86)\Microsoft Silverlight</p><p>2019-01-18 10:54 - 2018-11-13 23:21 - 000000000 ____D C:\Users\hp\Documents\YouCam</p><p>2019-01-17 23:43 - 2018-03-05 09:02 - 000000000 ____D C:\Users\hp\AppData\Roaming\vlc</p><p>2019-01-16 09:35 - 2018-03-18 09:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight</p><p>2019-01-15 23:10 - 2018-11-09 20:29 - 000000000 ____D C:\ProgramData\Package Cache</p><p>2019-01-14 17:07 - 2018-05-02 14:23 - 000000000 ____D C:\Users\hp\AppData\Local\ElevatedDiagnostics</p><p>2019-01-11 08:52 - 2018-03-05 08:27 - 000000000 ____D C:\Windows\system32\MRT</p><p>2019-01-11 08:45 - 2018-03-05 08:27 - 132790320 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe</p><p>2019-01-05 11:27 - 2018-09-06 15:55 - 000000000 ____D C:\Users\hp\AppData\Roaming\Jetmedia</p><p>2019-01-05 10:42 - 2018-03-30 16:41 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk</p><p></p><p>==================== Files in the root of some directories =======</p><p></p><p>2018-03-28 09:54 - 2019-01-21 19:02 - 000007610 _____ () C:\Users\hp\AppData\Local\Resmon.ResmonCfg</p><p></p><p>Some files in TEMP:</p><p>====================</p><p>2019-01-21 23:57 - 2019-01-21 23:57 - 000290304 _____ (Microsoft Corporation) C:\Users\hp\AppData\Local\Temp\CakeTubeSdk.Windows.Service.subinacl.exe</p><p>2018-12-31 14:25 - 2018-12-31 14:28 - 000033792 ____N (Microsoft Corporation) C:\Users\hp\AppData\Local\Temp\regini.exe</p><p></p><p>==================== Bamital & volsnap ======================</p><p></p><p>(There is no automatic fix for files that do not pass verification.)</p><p></p><p>C:\Windows\system32\winlogon.exe => File is digitally signed</p><p>C:\Windows\system32\wininit.exe => File is digitally signed</p><p>C:\Windows\SysWOW64\wininit.exe => File is digitally signed</p><p>C:\Windows\explorer.exe => File is digitally signed</p><p>C:\Windows\SysWOW64\explorer.exe => File is digitally signed</p><p>C:\Windows\system32\svchost.exe => File is digitally signed</p><p>C:\Windows\SysWOW64\svchost.exe => File is digitally signed</p><p>C:\Windows\system32\services.exe => File is digitally signed</p><p>C:\Windows\system32\User32.dll => File is digitally signed</p><p>C:\Windows\SysWOW64\User32.dll => File is digitally signed</p><p>C:\Windows\system32\userinit.exe => File is digitally signed</p><p>C:\Windows\SysWOW64\userinit.exe => File is digitally signed</p><p>C:\Windows\system32\rpcss.dll => File is digitally signed</p><p>C:\Windows\system32\dnsapi.dll => File is digitally signed</p><p>C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed</p><p>C:\Windows\system32\dllhost.exe => File is digitally signed</p><p>C:\Windows\SysWOW64\dllhost.exe => File is digitally signed</p><p>C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed</p><p></p><p>LastRegBack: 2019-01-14 15:19</p><p></p><p>==================== End of FRST.txt ============================</p><p></p><p></p><p></p><p>And here's the Addition log:</p><p></p><p></p><p>Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.01.2019</p><p>Ran by hp (22-01-2019 14:48:50)</p><p>Running from C:\Users\hp\Downloads</p><p>Windows 7 Professional Service Pack 1 (X64) (2018-03-05 14:54:51)</p><p>Boot Mode: Normal</p><p>==========================================================</p><p></p><p></p><p>==================== Accounts: =============================</p><p></p><p>Administrator (S-1-5-21-4218809093-567755804-543443116-500 - Administrator - Disabled)</p><p>Guest (S-1-5-21-4218809093-567755804-543443116-501 - Limited - Enabled)</p><p>hp (S-1-5-21-4218809093-567755804-543443116-1000 - Administrator - Enabled) => C:\Users\hp</p><p>Taya (S-1-5-21-4218809093-567755804-543443116-1003 - Limited - Enabled)</p><p></p><p>==================== Security Center ========================</p><p></p><p>(If an entry is included in the fixlist, it will be removed.)</p><p></p><p>AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}</p><p>AV: Bitdefender Antivirus (Enabled - Up to date) {0E17DB7D-A20F-62CE-B95B-17DB0CDFE318}</p><p>AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}</p><p>AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}</p><p>AS: Bitdefender Antispyware (Enabled - Up to date) {B5763A99-8435-6D40-83EB-2CA97758A9A5}</p><p>FW: Bitdefender Firewall (Enabled) {362C5A58-E860-6396-9204-BEEEF20CA463}</p><p></p><p>==================== Installed Programs ======================</p><p></p><p>(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)</p><p></p><p>Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.010.20069 - Adobe Systems Incorporated)</p><p>Adobe Shockwave Player 12.3 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.3.1.201 - Adobe Systems, Inc.)</p><p>Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 23.0.8.132 - Bitdefender)</p><p>Bitdefender Internet Security (HKLM\...\Bitdefender) (Version: 23.0.16.72 - Bitdefender)</p><p>Bitdefender VPN (HKLM\...\Bitdefender VPN) (Version: 23.0.8.625 - Bitdefender)</p><p>DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 5.0.1.0406 - Disc Soft Ltd)</p><p>Evernote v. 6.11.2 (HKLM-x32\...\{FC67AAF6-3477-11E8-B094-005056951CAD}) (Version: 6.11.2.7027 - Evernote Corp.)</p><p>Google Chrome (HKLM-x32\...\Google Chrome) (Version: 71.0.3578.98 - Google Inc.)</p><p>Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden</p><p>HP ESU for Microsoft Windows 7 (HKLM-x32\...\{801EAD7A-7202-4BE4-84A1-299202AD17C0}) (Version: 2.0.7.1 - Hewlett-Packard Company)</p><p>HP Support Solutions Framework (HKLM-x32\...\{930B5F2B-8DB9-42F4-90E4-5D3DC30541C3}) (Version: 12.10.49.21 - HP Inc.)</p><p>IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6433.0 - IDT)</p><p>Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 20.1 - Intel)</p><p>Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation)</p><p>Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.2.1004 - Intel Corporation)</p><p>Malwarebytes version 3.6.1.2711 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes)</p><p>Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)</p><p>Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)</p><p>Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 (HKLM-x32\...\{95ac1cfa-f4fb-4d1b-8912-7f9d5fbb140d}) (Version: 14.15.26706.0 - Microsoft Corporation)</p><p>Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)</p><p>MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)</p><p>MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)</p><p>NativeDesktopMediaService (HKLM-x32\...\{FC44DE72-60F9-4BC1-B098-D2F6B5A06187}) (Version: 3.5.0 - Jetmedia) <==== ATTENTION</p><p>OBS Studio (HKLM-x32\...\OBS Studio) (Version: 22.0.2 - OBS Project)</p><p>Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.36.0 - Renesas Electronics Corporation) Hidden</p><p>Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.36.0 - Renesas Electronics Corporation)</p><p>Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)</p><p>ShopTracker 1.1.32 (HKLM-x32\...\AmazonMeter) (Version: 1.1.32 - Nielsen)</p><p>Skype version 8.33 (HKLM-x32\...\Skype_is1) (Version: 8.33 - Skype Technologies S.A.)</p><p>swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden</p><p>Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.18.25 - Synaptics Incorporated)</p><p>VLC media player (HKLM\...\VLC media player) (Version: 3.0.1 - VideoLAN)</p><p>Windows Driver Package - KEYLOK (usbkey) USB (06/10/2010 64.0.0.0) (HKLM\...\B048A6D4B0188E5A802ADFF30A7C78FA4AD99BE0) (Version: 06/10/2010 64.0.0.0 - KEYLOK)</p><p></p><p>==================== Custom CLSID (Whitelisted): ==========================</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p>ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)</p><p>ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2015-06-01] (Intel Corporation)</p><p>ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)</p><p></p><p>==================== Scheduled Tasks (Whitelisted) =============</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p>Task: {2F70818D-EECB-4C2D-8C18-D8CB211769DB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-13] (Adobe Systems Incorporated)</p><p>Task: {41322D55-C5AF-4689-AA68-DE65CD9D94A1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Opt-in For HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Utils.exe [2018-12-10] (HP Inc.)</p><p>Task: {43F40AD4-27CB-4F04-A673-F018A90D9537} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2018-11-08] (HP Inc.)</p><p>Task: {4808226E-2946-406B-8CD0-9B10A08DBCC0} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)</p><p>Task: {505C49A2-7605-44A3-BB9A-8F28811F51A7} - System32\Tasks\ApowerREC => C:\Program Files (x86)\Apowersoft\ApowerREC\ApowerREC.exe</p><p>Task: {50D935BD-9157-484A-948C-E4024F607798} - System32\Tasks\HPCeeScheduleForhp => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2016-06-24] (HP Inc.)</p><p>Task: {59E09B6C-AC84-4A3C-9917-831B0AFDB0EB} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2018-11-15] (Bitdefender)</p><p>Task: {5A44B482-7ED6-4DCF-8980-2D06063B3650} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-11-09] (HP Inc.)</p><p>Task: {6033258D-31A3-4BA6-9BB6-D02935163EA9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-03-05] (Google Inc.)</p><p>Task: {6F783847-CDC2-44B3-9BBD-8DA9A89C8ED1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2019-01-02] (HP Inc.)</p><p>Task: {7C2C5399-5BFA-4BD2-A19A-B937D60964D1} - System32\Tasks\Games\UpdateCheck_S-1-5-21-4218809093-567755804-543443116-1000</p><p>Task: {AAD573DB-3E59-479A-A342-9C4B96F9A0CF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-12-10] (HP Inc.)</p><p>Task: {DE8B9D39-02CF-44BB-A3C0-5FB381E203FD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-11-09] (HP Inc.)</p><p>Task: {EB50DE0F-035E-41B1-BC4D-DA76802B8E49} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-12-10] (HP Inc.)</p><p>Task: {F159CC70-12F7-411B-B347-44CB39AAA1BC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-11-21] (HP Inc.)</p><p>Task: {FFE32A28-EBAD-433F-A0E6-324B456BFB5C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-03-05] (Google Inc.)</p><p></p><p>(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)</p><p></p><p>Task: C:\Windows\Tasks\HPCeeScheduleForhp.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe</p><p></p><p>==================== Shortcuts & WMI ========================</p><p></p><p>(The entries could be listed to be restored or removed.)</p><p></p><p></p><p>==================== Loaded Modules (Whitelisted) ==============</p><p></p><p>2019-01-21 23:35 - 2018-11-14 20:36 - 000994752 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttpbr.mdl</p><p>2019-01-21 23:35 - 2018-11-14 20:36 - 000544880 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttpdsp.mdl</p><p>2019-01-21 23:35 - 2018-11-14 20:36 - 003240080 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttpph.mdl</p><p>2019-01-21 23:35 - 2018-11-14 20:36 - 001530368 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttprbl.mdl</p><p>2018-11-20 04:46 - 2018-11-20 04:46 - 004310296 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF</p><p>2010-10-20 14:23 - 2010-10-20 14:23 - 008801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll</p><p>2015-06-01 18:00 - 2015-06-01 18:00 - 000102912 _____ () C:\Windows\System32\IccLibDll_x64.dll</p><p>2019-01-21 00:47 - 2018-11-21 11:07 - 002842608 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll</p><p>2019-01-21 00:47 - 2018-11-15 11:01 - 002712432 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll</p><p>2019-01-20 23:47 - 2018-12-11 21:11 - 005237216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libglesv2.dll</p><p>2019-01-20 23:47 - 2018-12-11 21:11 - 000117216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libegl.dll</p><p>2018-03-30 17:34 - 2018-03-30 17:34 - 000668384 _____ () C:\Program Files (x86)\Evernote\Evernote\tidy.dll</p><p>2019-01-12 12:55 - 2019-01-12 12:55 - 000169984 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\6ce952d16a75232a68643938f3f36608\IsdiInterop.ni.dll</p><p>2018-11-18 23:14 - 2011-01-12 17:56 - 000058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll</p><p></p><p>==================== Alternate Data Streams (Whitelisted) =========</p><p></p><p>(If an entry is included in the fixlist, only the ADS will be removed.)</p><p></p><p></p><p>==================== Safe Mode (Whitelisted) ===================</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)</p><p></p><p>HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver"</p><p>HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"</p><p>HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver"</p><p>HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"</p><p></p><p>==================== Association (Whitelisted) ===============</p><p></p><p>(If an entry is included in the fixlist, the registry item will be restored to default or removed.)</p><p></p><p></p><p>==================== Internet Explorer trusted/restricted ===============</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry.)</p><p></p><p></p><p>==================== Hosts content: ===============================</p><p></p><p>(If needed Hosts: directive could be included in the fixlist to reset Hosts.)</p><p></p><p>2009-07-13 18:34 - 2019-01-22 14:37 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts</p><p></p><p></p><p>==================== Other Areas ============================</p><p></p><p>(Currently there is no automatic fix for this section.)</p><p></p><p>HKU\S-1-5-21-4218809093-567755804-543443116-1000\Control Panel\Desktop\\Wallpaper -> </p><p>DNS Servers: 192.168.1.1</p><p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)</p><p>Windows Firewall is enabled.</p><p></p><p>==================== MSCONFIG/TASK MANAGER disabled items ==</p><p></p><p>If an entry is included in the fixlist, it will be removed.</p><p></p><p></p><p>==================== FirewallRules (Whitelisted) ===============</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p>FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe (Microsoft Corporation)</p><p>FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe (Microsoft Corporation)</p><p>FirewallRules: [{34542273-AA73-424A-8BE8-DF8B61746018}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe No File</p><p>FirewallRules: [{92B5D6B8-AC28-4707-B46D-EA2A1017D6C8}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Technologies S.A.)</p><p>FirewallRules: [{9C771DE2-06DE-4AF7-8745-43CAC05B4CC6}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Technologies S.A.)</p><p>FirewallRules: [{F7787BBA-55E1-4380-B343-D931984681D0}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerREC\ApowerREC.exe No File</p><p>FirewallRules: [{74D2EF85-DC10-4053-B3F3-58DDD6D50414}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerREC\ApowerREC.exe No File</p><p>FirewallRules: [{67DDB1D0-08A8-437B-BB76-ED7F8D4D275E}] => (Allow) C:\ProgramData\Gxjri\desktop_media_service.exe No File</p><p>FirewallRules: [{354F4BAA-EBD5-4309-B8D9-666A34CE0165}] => (Allow) C:\Windows\SysWOW64\TCPSVCS.EXE (Microsoft Corporation)</p><p>FirewallRules: [{2D6ABAF4-650D-4A37-B4D9-4C23FC85533A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)</p><p></p><p>==================== Restore Points =========================</p><p></p><p>15-01-2019 23:09:44 Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706</p><p>15-01-2019 23:17:40 Windows Update</p><p>16-01-2019 09:14:38 Windows Update</p><p>19-01-2019 23:03:52 Windows Update</p><p>20-01-2019 22:43:24 Removed Windows 7 USB/DVD Download Tool</p><p>20-01-2019 23:42:45 Removed Google Chrome</p><p>21-01-2019 17:39:12 Windows Update</p><p>21-01-2019 17:53:33 Windows Update</p><p>21-01-2019 22:20:16 Installed SLOW-PCfighter.</p><p>21-01-2019 22:26:15 Fighters Backup</p><p></p><p>==================== Faulty Device Manager Devices =============</p><p></p><p>Name: LG K20 PLUS</p><p>Description: LG K20 PLUS</p><p>Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}</p><p>Manufacturer: LGE</p><p>Service: WUDFRd</p><p>Problem: : This device cannot start. (Code10)</p><p>Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.</p><p>On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.</p><p></p><p></p><p>==================== Event log errors: =========================</p><p></p><p>Application errors:</p><p>==================</p><p>Error: (01/22/2019 08:12:06 AM) (Source: Application Hang) (EventID: 1002) (User: )</p><p>Description: The program iexplore.exe version 11.0.9600.19236 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.</p><p></p><p>Process ID: 1e5c</p><p></p><p>Start Time: 01d4b26d2534c17a</p><p></p><p>Termination Time: 16</p><p></p><p>Application Path: C:\Program Files\Internet Explorer\iexplore.exe</p><p></p><p>Report Id: 71ecbed6-1e60-11e9-be53-001a7dda7114</p><p></p><p>Error: (01/22/2019 12:22:23 AM) (Source: Application Hang) (EventID: 1002) (User: )</p><p>Description: The program obs64.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.</p><p></p><p>Process ID: 1840</p><p></p><p>Start Time: 01d4b22b372f8c80</p><p></p><p>Termination Time: 9</p><p></p><p>Application Path: C:\Program Files\obs-studio\bin\64bit\obs64.exe</p><p></p><p>Report Id: d554d2c3-1e1e-11e9-9985-101f744b6eab</p><p></p><p>Error: (01/21/2019 10:26:16 PM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: Volume Shadow Copy Service error: Unexpected error calling routine ConvertStringSidToSid(S-1-5-21-4218809093-567755804-543443116-1000.bak). hr = 0x80070539, The security ID structure is invalid.</p><p>.</p><p></p><p></p><p>Operation:</p><p> OnIdentify event</p><p> Gathering Writer Data</p><p></p><p>Context:</p><p> Execution Context: Shadow Copy Optimization Writer</p><p> Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}</p><p> Writer Name: Shadow Copy Optimization Writer</p><p> Writer Instance ID: {a7838b74-aeb9-4d64-aaf0-ebd4769f8485}</p><p></p><p>Error: (01/21/2019 10:26:15 PM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: Volume Shadow Copy Service error: Unexpected error calling routine ConvertStringSidToSid(S-1-5-21-4218809093-567755804-543443116-1000.bak). hr = 0x80070539, The security ID structure is invalid.</p><p>.</p><p></p><p></p><p>Operation:</p><p> OnIdentify event</p><p> Gathering Writer Data</p><p></p><p>Context:</p><p> Execution Context: Shadow Copy Optimization Writer</p><p> Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}</p><p> Writer Name: Shadow Copy Optimization Writer</p><p> Writer Instance ID: {a7838b74-aeb9-4d64-aaf0-ebd4769f8485}</p><p></p><p>Error: (01/21/2019 10:20:16 PM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: Volume Shadow Copy Service error: Unexpected error calling routine ConvertStringSidToSid(S-1-5-21-4218809093-567755804-543443116-1000.bak). hr = 0x80070539, The security ID structure is invalid.</p><p>.</p><p></p><p></p><p>Operation:</p><p> OnIdentify event</p><p> Gathering Writer Data</p><p></p><p>Context:</p><p> Execution Context: Shadow Copy Optimization Writer</p><p> Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}</p><p> Writer Name: Shadow Copy Optimization Writer</p><p> Writer Instance ID: {fc00094d-9b7f-4c59-afe7-0d2e35bd3ac8}</p><p></p><p>Error: (01/21/2019 05:53:33 PM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: Volume Shadow Copy Service error: Unexpected error calling routine ConvertStringSidToSid(S-1-5-21-4218809093-567755804-543443116-1000.bak). hr = 0x80070539, The security ID structure is invalid.</p><p>.</p><p></p><p></p><p>Operation:</p><p> OnIdentify event</p><p> Gathering Writer Data</p><p></p><p>Context:</p><p> Execution Context: Shadow Copy Optimization Writer</p><p> Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}</p><p> Writer Name: Shadow Copy Optimization Writer</p><p> Writer Instance ID: {f8ab2b6a-ed99-4164-86a7-27a2d143bdef}</p><p></p><p>Error: (01/21/2019 05:39:12 PM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: Volume Shadow Copy Service error: Unexpected error calling routine ConvertStringSidToSid(S-1-5-21-4218809093-567755804-543443116-1000.bak). hr = 0x80070539, The security ID structure is invalid.</p><p>.</p><p></p><p></p><p>Operation:</p><p> OnIdentify event</p><p> Gathering Writer Data</p><p></p><p>Context:</p><p> Execution Context: Shadow Copy Optimization Writer</p><p> Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}</p><p> Writer Name: Shadow Copy Optimization Writer</p><p> Writer Instance ID: {cd6a5e15-4a1b-4b38-a569-6302682667b9}</p><p></p><p>Error: (01/20/2019 11:42:46 PM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: Volume Shadow Copy Service error: Unexpected error calling routine ConvertStringSidToSid(S-1-5-21-4218809093-567755804-543443116-1000.bak). hr = 0x80070539, The security ID structure is invalid.</p><p>.</p><p></p><p></p><p>Operation:</p><p> OnIdentify event</p><p> Gathering Writer Data</p><p></p><p>Context:</p><p> Execution Context: Shadow Copy Optimization Writer</p><p> Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}</p><p> Writer Name: Shadow Copy Optimization Writer</p><p> Writer Instance ID: {c8dd1a98-c2fe-49b1-8f7e-113b9a6d415b}</p><p></p><p></p><p>System errors:</p><p>=============</p><p>Error: (01/22/2019 02:39:07 PM) (Source: sptd) (EventID: 4) (User: )</p><p>Description: Driver detected an internal error in its data structures for .</p><p></p><p>Error: (01/22/2019 02:39:07 PM) (Source: sptd) (EventID: 4) (User: )</p><p>Description: Driver detected an internal error in its data structures for .</p><p></p><p>Error: (01/22/2019 02:39:05 PM) (Source: sptd) (EventID: 4) (User: )</p><p>Description: Driver detected an internal error in its data structures for .</p><p></p><p>Error: (01/22/2019 02:38:46 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)</p><p>Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID </p><p>{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}</p><p> and APPID </p><p>{344ED43D-D086-4961-86A6-1106F4ACAD9B}</p><p> to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.</p><p></p><p>Error: (01/22/2019 02:38:19 PM) (Source: Service Control Manager) (EventID: 7000) (User: )</p><p>Description: The Amazon Meter service failed to start due to the following error: </p><p>The service did not respond to the start or control request in a timely fashion.</p><p></p><p>Error: (01/22/2019 02:38:19 PM) (Source: Service Control Manager) (EventID: 7009) (User: )</p><p>Description: A timeout was reached (30000 milliseconds) while waiting for the Amazon Meter service to connect.</p><p></p><p>Error: (01/22/2019 02:38:07 PM) (Source: sptd) (EventID: 4) (User: )</p><p>Description: Driver detected an internal error in its data structures for .</p><p></p><p>Error: (01/22/2019 02:34:53 PM) (Source: Service Control Manager) (EventID: 7011) (User: )</p><p>Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the VSSERV service.</p><p></p><p></p><p>Windows Defender:</p><p>===================================</p><p>Date: 2018-07-06 09:38:11.787</p><p>Description: </p><p>Windows Defender has encountered an error trying to update signatures.</p><p>New Signature Version:1.271.442.0</p><p>Previous Signature Version:1.269.1075.0</p><p>Update Source:User</p><p>Signature Type:AntiSpyware</p><p>Update Type:Delta</p><p>Current Engine Version:1.1.15000.2</p><p>Previous Engine Version:1.1.14901.4</p><p>Error code:0x80070666</p><p>Error description:Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel. </p><p></p><p>Date: 2018-07-06 09:38:11.777</p><p>Description: </p><p>Windows Defender has encountered an error trying to update the engine.</p><p>New Engine Version:1.1.15000.2</p><p>Previous Engine Version:1.1.14901.4</p><p>Update Source:User</p><p>Error Code:0x80070666</p><p>Error description:Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel. </p><p></p><p>CodeIntegrity:</p><p>===================================</p><p></p><p>Date: 2019-01-22 14:46:17.553</p><p>Description: </p><p>Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.</p><p></p><p>Date: 2019-01-22 14:45:29.001</p><p>Description: </p><p>Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.</p><p></p><p>Date: 2019-01-22 14:39:54.853</p><p>Description: </p><p>Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.</p><p></p><p>Date: 2019-01-22 14:39:50.589</p><p>Description: </p><p>Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.</p><p></p><p>Date: 2019-01-22 14:34:14.958</p><p>Description: </p><p>Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.</p><p></p><p>Date: 2019-01-22 13:18:21.773</p><p>Description: </p><p>Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.</p><p></p><p>Date: 2019-01-22 13:18:14.617</p><p>Description: </p><p>Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.</p><p></p><p>Date: 2019-01-22 13:17:52.368</p><p>Description: </p><p>Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.</p><p></p><p>==================== Memory info =========================== </p><p></p><p>Processor: Intel(R) Core(TM) i5-2410M CPU @ 2.30GHz</p><p>Percentage of memory in use: 41%</p><p>Total physical RAM: 4030.36 MB</p><p>Available physical RAM: 2344.95 MB</p><p>Total Virtual: 8058.86 MB</p><p>Available Virtual: 5680.32 MB</p><p></p><p>==================== Drives ================================</p><p></p><p>Drive c: () (Fixed) (Total:297.99 GB) (Free:164.58 GB) NTFS</p><p></p><p>\\?\Volume{83cbe48b-209d-11e8-84ea-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS</p><p></p><p>==================== MBR & Partition Table ==================</p><p></p><p>========================================================</p><p>Disk: 0 (MBR Code: Windows 7/8/10) (Size: 298.1 GB) (Disk ID: 8E633DF9)</p><p>Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)</p><p>Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)</p><p></p><p>==================== End of Addition.txt ============================[/code]</p><p></p><p>Oh, and in case you couldn't tell, I'm a total newb, I know next to NOTHING about computers, but I can understand explanations and I'm good at following instructions, which is how I got as far as I am. Thanks for your time.</p><p></p><p>If no1 responds to help im just going to hard reset it in the hopes that that works im 99% sure i dont have anything i super need on it</p></blockquote><p></p>
[QUOTE="Lacywilmerton, post: 793576, member: 77545"] As an update, if I restart the computer, the internet functions for awhile. But then it stops again. I'm scanning with frst right now and will provide the report asap. Here's the FRST log [code] Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.01.2019 Ran by hp (administrator) on HP-PC (22-01-2019 14:46:33) Running from C:\Users\hp\Downloads Loaded Profiles: hp (Available Profiles: hp) Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: [URL="http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/"]FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials[/URL] ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\vsserv.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnService.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnApp.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler64.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Bitdefender) C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe (HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-10-24] (IDT, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2833504 2017-08-26] (Synaptics Incorporated) HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe [482024 2018-11-23] (Bitdefender) HKLM\...\Run: [BdVpnApp] => C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnApp.exe [91384 2018-11-16] (Bitdefender) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [NUSB3MON] => c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048 2011-09-16] (Renesas Electronics Corporation) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-26] (Intel Corporation) HKU\S-1-5-21-4218809093-567755804-543443116-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [5583120 2015-02-27] (Disc Soft Ltd) HKU\S-1-5-21-4218809093-567755804-543443116-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-20] (Microsoft Corporation) HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\Installer\chrmstp.exe [2019-01-20] (Google Inc.) Startup: C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2018-03-17] ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\Parameters: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{2428F2AD-69F4-4776-822B-F219A75AA330}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{2428F2AD-69F4-4776-822B-F219A75AA330}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{2495A7F8-9D33-48F2-B9FD-E42EBF9700F7}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{53086195-A107-4AA9-8886-C663EE54DE95}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{56142C7C-244D-4E03-AA1A-795AA0D28447}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{BFF9657D-D5BA-4FA4-99FC-CA986724B041}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{D770B206-273D-4D48-B604-BC4AC181B2D2}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{D8E4B8E5-73F4-438C-8795-2857B9A14A08}: [NameServer] 8.8.8.8 Internet Explorer: ================== BHO: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2018-12-04] (Bitdefender) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.) BHO-x32: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2018-12-04] (Bitdefender) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation) BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2018-03-30] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.) Toolbar: HKLM - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2018-12-04] (Bitdefender) Toolbar: HKLM-x32 - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2018-12-04] (Bitdefender) FireFox: ======== FF DefaultProfile: 0pdmxapa.default FF ProfilePath: C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\0pdmxapa.default [2019-01-21] FF HKLM\...\Firefox\Extensions: [[email]bdwtwe@bitdefender.com[/email]] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi FF Extension: (Bitdefender Wallet) - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi [2018-11-23] FF HKLM\...\Thunderbird\Extensions: [[email]bdThunderbird@bitdefender.com[/email]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext FF Extension: (Bitdefender Antispam Toolbar) - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext [2018-12-20] [Legacy] [not signed] FF HKLM-x32\...\Firefox\Extensions: [[email]bdwtwe@bitdefender.com[/email]] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi FF HKLM-x32\...\Thunderbird\Extensions: [[email]bdThunderbird@bitdefender.com[/email]] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN) FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1231201.dll [2017-11-02] (Adobe Systems, Inc.) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File] FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File] FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-12-04] (Adobe Systems Inc.) Chrome: ======= CHR Session Restore: Default -> is enabled. CHR Profile: C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default [2019-01-22] CHR Extension: (Google Drive) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-03-17] CHR Extension: (YouTube) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-03-17] CHR Extension: (Chrome Web Store Payments) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03] CHR Extension: (Gmail) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-03-17] CHR Extension: (Chrome Media Router) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-21] CHR Profile: C:\Users\hp\AppData\Local\Google\Chrome\User Data\System Profile [2018-03-20] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gannpgaobkkhmpomoijebaigcapoeebl] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AESTFilters; C:\Program Files\IDT\WDM\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation) [File not signed] S3 AfVpnService; C:\Program Files\Bitdefender\Bitdefender VPN\vpnservice.exe [322432 2018-10-25] (AnchorFree Inc.) S2 AmazonMeterService; C:\Program Files (x86)\ShopTracker\Scheduler\AmazonMeter.Scheduler.exe [32664 2018-08-07] (VL) R2 BDAuxSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [779152 2018-11-23] (Bitdefender) R2 bdredline; C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe [2195320 2018-03-22] (Bitdefender) R2 BdVpnService; C:\Program Files\Bitdefender\Bitdefender VPN\bdvpnservice.exe [96568 2018-11-16] (Bitdefender) R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272592 2015-02-27] (Disc Soft Ltd) S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-03] (HP) R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [347512 2018-12-06] (HP Inc.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes) R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1293936 2018-11-15] (Bitdefender) R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2012-10-24] (IDT, Inc.) [File not signed] R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe [112656 2018-11-23] (Bitdefender) R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender Security\vsserv.exe [804656 2018-11-23] (Bitdefender) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 aftap0901; C:\Windows\System32\DRIVERS\aftap0901.sys [48624 2018-06-15] (The OpenVPN Project) R1 atc; C:\Windows\System32\DRIVERS\atc.sys [1292296 2018-06-05] (BitDefender S.R.L. Bucharest, ROMANIA) R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1725800 2018-02-02] (BitDefender) R2 BdDci; C:\Windows\System32\DRIVERS\bddci.sys [156912 2018-10-18] (Bitdefender) R0 bdprivmon; C:\Windows\System32\DRIVERS\bdprivmon.sys [45728 2018-09-17] (© Bitdefender SRL) R1 BDVEDISK; C:\Windows\System32\DRIVERS\bdvedisk.sys [96448 2018-04-27] (BitDefender) R3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [29184 2009-08-13] (CSR, plc) R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30352 2018-07-16] (Disc Soft Ltd) S3 edrsensor; C:\Windows\System32\DRIVERS\edrsensor.sys [248336 2017-11-15] (BitDefender S.R.L. Bucharest, ROMANIA) R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [152688 2018-12-04] (Malwarebytes) R1 Gemma; C:\Windows\System32\DRIVERS\Gemma.sys [359584 2018-10-04] (BitDefender S.R.L. Bucharest, ROMANIA) R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [193184 2018-05-29] (BitDefender LLC) R2 Ignis; C:\Windows\System32\DRIVERS\ignis.sys [196352 2018-10-26] (Bitdefender) R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [198512 2019-01-21] (Malwarebytes) R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [126624 2019-01-22] (Malwarebytes) R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [72536 2019-01-22] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [261032 2019-01-22] (Malwarebytes) R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [103760 2019-01-22] (Malwarebytes) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [2621128 2015-07-15] (Sonix Tech. Co., Ltd.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381608 2018-07-16] (Duplex Secure Ltd.) R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [609576 2018-06-28] (Bitdefender) S3 CLMirrorDriver; system32\DRIVERS\CLMirrorDriver.sys [X] S3 clwvd8; system32\DRIVERS\clwvd8.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-01-22 14:46 - 2019-01-22 14:47 - 000018629 _____ C:\Users\hp\Downloads\FRST.txt 2019-01-22 14:46 - 2019-01-22 14:46 - 000000000 ____D C:\FRST 2019-01-22 14:45 - 2019-01-22 14:45 - 002428416 _____ (Farbar) C:\Users\hp\Downloads\FRST64.exe 2019-01-22 14:40 - 2019-01-22 14:40 - 000126624 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2019-01-22 14:40 - 2019-01-22 14:40 - 000072536 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2019-01-22 14:39 - 2019-01-22 14:48 - 000103760 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2019-01-22 14:39 - 2019-01-22 14:39 - 000261032 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2019-01-22 10:18 - 2019-01-22 10:18 - 000000000 ____D C:\ProgramData\HitmanPro 2019-01-22 08:16 - 2019-01-22 08:16 - 000001413 _____ C:\Users\hp\Desktop\Internet Explorer.lnk 2019-01-22 08:06 - 2019-01-22 08:06 - 000034894 _____ C:\ProgramData\dm.uninstall.1548173102.bdinstall.bin 2019-01-22 00:22 - 2019-01-22 14:34 - 000002015 _____ C:\bdlog.txt 2019-01-21 23:57 - 2019-01-21 23:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender VPN 2019-01-21 23:57 - 2019-01-21 23:57 - 000000000 ____D C:\ProgramData\Bitdefender VPN 2019-01-21 23:57 - 2019-01-21 23:57 - 000000000 _____ C:\ProgramData\vpn.1548143609.bdinstall.bin 2019-01-21 23:56 - 2018-06-15 09:26 - 000048624 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\aftap0901.sys 2019-01-21 23:52 - 2019-01-21 23:52 - 000043592 _____ C:\ProgramData\dm.update.1548143335.bdinstall.bin 2019-01-21 23:48 - 2019-01-21 23:48 - 000058739 _____ C:\ProgramData\dm.1548142798.bdinstall.bin 2019-01-21 23:47 - 2019-01-21 23:47 - 000000000 ____D C:\ProgramData\Bitdefender Device Management 2019-01-21 23:46 - 2019-01-22 14:38 - 000065536 _____ C:\Windows\system32\Ikeext.etl 2019-01-21 23:39 - 2019-01-21 23:39 - 000806224 _____ C:\ProgramData\cl.1548141579.bdinstall.v2.bin 2019-01-21 23:39 - 2019-01-21 23:39 - 000101492 _____ C:\ProgramData\cl.kit.1548141549.bdinstall.v2.bin 2019-01-21 23:37 - 2019-01-21 23:37 - 000000000 ____D C:\ProgramData\Gemma 2019-01-21 23:37 - 2019-01-21 23:37 - 000000000 ____D C:\ProgramData\Atc 2019-01-21 23:36 - 2019-01-21 23:57 - 000002078 _____ C:\Users\Public\Desktop\Bitdefender VPN.lnk 2019-01-21 23:36 - 2019-01-21 23:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender Security 2019-01-21 23:36 - 2019-01-21 23:36 - 000002230 _____ C:\Users\Public\Desktop\Bitdefender.lnk 2019-01-21 23:36 - 2019-01-21 23:36 - 000000000 ____D C:\Windows\system32\elambkup 2019-01-21 23:36 - 2019-01-21 23:36 - 000000000 ____D C:\ProgramData\BDLogging 2019-01-21 23:36 - 2018-04-19 07:37 - 000023032 _____ (Bitdefender) C:\Windows\system32\Drivers\bdelam.sys 2019-01-21 23:35 - 2018-10-04 22:40 - 000359584 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\Windows\system32\Drivers\Gemma.sys 2019-01-21 23:35 - 2018-04-27 07:45 - 000096448 _____ (BitDefender) C:\Windows\system32\Drivers\bdvedisk.sys 2019-01-21 23:35 - 2007-04-11 10:11 - 000511328 _____ (Microsoft Corporation) C:\Windows\capicom.dll 2019-01-21 23:34 - 2019-01-22 08:27 - 000000000 ____D C:\Program Files\Bitdefender 2019-01-21 23:34 - 2019-01-21 23:43 - 000000000 ____D C:\Users\hp\AppData\Roaming\Bitdefender 2019-01-21 23:34 - 2018-10-26 10:57 - 000196352 _____ (Bitdefender) C:\Windows\system32\Drivers\ignis.sys 2019-01-21 23:34 - 2018-10-18 17:12 - 000156912 _____ (Bitdefender) C:\Windows\system32\Drivers\bddci.sys 2019-01-21 23:34 - 2018-09-17 04:36 - 000045728 _____ (© Bitdefender SRL) C:\Windows\system32\Drivers\bdprivmon.sys 2019-01-21 23:34 - 2018-06-28 13:39 - 000609576 _____ (Bitdefender) C:\Windows\system32\Drivers\trufos.sys 2019-01-21 23:34 - 2018-06-05 03:32 - 001292296 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\Windows\system32\Drivers\atc.sys 2019-01-21 23:34 - 2018-05-29 04:04 - 000193184 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys 2019-01-21 23:19 - 2019-01-21 23:34 - 000000000 ____D C:\Program Files\Common Files\Bitdefender 2019-01-21 23:17 - 2019-01-22 14:40 - 000003648 _____ C:\Windows\System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 2019-01-21 23:15 - 2019-01-21 23:48 - 000000000 ____D C:\Program Files\Bitdefender Agent 2019-01-21 23:15 - 2019-01-21 23:15 - 000105828 _____ C:\ProgramData\agent.1548141312.bdinstall.v2.bin 2019-01-21 23:09 - 2019-01-21 23:10 - 011334352 _____ C:\Users\hp\Downloads\bitdefender_isecurity.exe 2019-01-21 22:20 - 2019-01-22 09:56 - 000000000 ____D C:\Users\hp\AppData\Roaming\Fighters 2019-01-21 22:19 - 2019-01-22 09:56 - 000000000 ____D C:\ProgramData\Fighters 2019-01-21 17:53 - 2019-01-10 16:49 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2019-01-21 17:53 - 2019-01-10 16:49 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2019-01-21 17:53 - 2019-01-10 16:47 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2019-01-21 17:53 - 2019-01-10 16:47 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2019-01-21 17:53 - 2019-01-10 16:47 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2019-01-21 17:53 - 2019-01-10 16:46 - 001472512 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2019-01-21 17:53 - 2019-01-10 16:34 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2019-01-21 17:53 - 2019-01-10 16:34 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2019-01-21 17:53 - 2019-01-10 16:15 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2019-01-21 17:53 - 2018-12-28 11:59 - 002072576 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2019-01-21 17:53 - 2018-12-28 11:59 - 000876032 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2019-01-21 17:53 - 2018-12-28 11:59 - 000516608 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2019-01-21 17:53 - 2018-12-28 11:59 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll 2019-01-21 17:53 - 2018-12-28 11:59 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll 2019-01-21 17:53 - 2018-12-28 11:48 - 001425920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2019-01-21 17:53 - 2018-12-28 11:48 - 000582144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2019-01-21 17:53 - 2018-12-28 11:48 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll 2019-01-21 17:53 - 2018-12-28 11:32 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll 2019-01-21 17:53 - 2018-12-04 08:07 - 000194048 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll 2019-01-21 17:53 - 2018-12-04 08:07 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll 2019-01-21 17:53 - 2018-12-04 07:55 - 000158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itircl.dll 2019-01-21 17:53 - 2018-12-04 07:55 - 000142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll 2019-01-21 17:53 - 2018-12-02 08:06 - 000687616 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000998480 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000918408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000066000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000063936 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000021968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000020944 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000019408 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000018880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000017872 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000017856 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000017360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000017352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000016336 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000015824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000015808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000015296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000014312 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000014272 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000013768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000013760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000013760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000013264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000012752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000012736 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000012264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000012240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000012240 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000012240 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000012232 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000012224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000012224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000012024 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000011752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000011728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000011728 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000011512 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000011216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000011216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000011216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2019-01-21 17:53 - 2018-10-12 05:05 - 000011200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2019-01-21 02:18 - 2019-01-21 02:19 - 082430032 _____ (Malwarebytes ) C:\Users\hp\Downloads\mb3-setup-consumer-3.6.1.2711-1.0.519-1.0.8878 (1).exe 2019-01-21 00:47 - 2019-01-21 20:09 - 000198512 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys 2019-01-21 00:47 - 2019-01-21 00:47 - 000001827 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2019-01-21 00:47 - 2019-01-21 00:47 - 000000000 ____D C:\Users\hp\AppData\Local\mbamtray 2019-01-21 00:47 - 2019-01-21 00:47 - 000000000 ____D C:\Users\hp\AppData\Local\mbam 2019-01-21 00:47 - 2019-01-21 00:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2019-01-21 00:47 - 2019-01-21 00:47 - 000000000 ____D C:\ProgramData\Malwarebytes 2019-01-21 00:47 - 2019-01-21 00:47 - 000000000 ____D C:\Program Files\Malwarebytes 2019-01-21 00:47 - 2018-12-04 08:09 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys 2019-01-21 00:36 - 2019-01-21 00:44 - 082430032 _____ (Malwarebytes ) C:\Users\hp\Downloads\mb3-setup-consumer-3.6.1.2711-1.0.519-1.0.8878.exe 2019-01-20 23:47 - 2019-01-20 23:47 - 000002296 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2019-01-20 23:47 - 2019-01-20 23:47 - 000002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2019-01-15 23:33 - 2019-01-17 22:24 - 000000000 ____D C:\Users\hp\AppData\Roaming\obs-studio 2019-01-15 23:29 - 2019-01-15 23:29 - 000001003 _____ C:\Users\Public\Desktop\OBS Studio.lnk 2019-01-15 23:29 - 2019-01-15 23:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio 2019-01-15 23:29 - 2019-01-15 23:29 - 000000000 ____D C:\Program Files\obs-studio 2019-01-15 22:55 - 2019-01-15 22:55 - 069551216 _____ (obsproject.com) C:\Users\hp\Downloads\OBS-Studio-22.0.2-Full-Installer-x64.exe 2019-01-09 08:25 - 2018-12-28 15:42 - 000396888 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2019-01-09 08:25 - 2018-12-28 14:52 - 000348760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2019-01-09 08:25 - 2018-12-28 12:03 - 000631680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2019-01-09 08:25 - 2018-12-28 12:02 - 005552360 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2019-01-09 08:25 - 2018-12-28 12:02 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2019-01-09 08:25 - 2018-12-28 12:02 - 000708328 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2019-01-09 08:25 - 2018-12-28 12:02 - 000262376 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll 2019-01-09 08:25 - 2018-12-28 12:01 - 001664360 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 001211904 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000094208 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:51 - 004055272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2019-01-09 08:25 - 2018-12-28 11:51 - 003960552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2019-01-09 08:25 - 2018-12-28 11:50 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000275968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:34 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2019-01-09 08:25 - 2018-12-28 11:34 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2019-01-09 08:25 - 2018-12-28 11:34 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2019-01-09 08:25 - 2018-12-28 11:34 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2019-01-09 08:25 - 2018-12-28 11:31 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2019-01-09 08:25 - 2018-12-28 11:31 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2019-01-09 08:25 - 2018-12-28 11:31 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys 2019-01-09 08:25 - 2018-12-28 11:30 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2019-01-09 08:25 - 2018-12-28 11:28 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2019-01-09 08:25 - 2018-12-28 11:28 - 000161280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2019-01-09 08:25 - 2018-12-28 11:28 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2019-01-09 08:25 - 2018-12-28 11:27 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2019-01-09 08:25 - 2018-12-28 11:27 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys 2019-01-09 08:25 - 2018-12-28 11:27 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys 2019-01-09 08:25 - 2018-12-28 11:27 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys 2019-01-09 08:25 - 2018-12-28 11:27 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys 2019-01-09 08:25 - 2018-12-28 11:27 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2019-01-09 08:25 - 2018-12-28 11:27 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2019-01-09 08:25 - 2018-12-28 11:27 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2019-01-09 08:25 - 2018-12-28 11:27 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2019-01-09 08:25 - 2018-12-28 11:26 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2019-01-09 08:25 - 2018-12-28 11:26 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:26 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 11:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2019-01-09 08:25 - 2018-12-28 10:09 - 000419608 _____ C:\Windows\SysWOW64\locale.nls 2019-01-09 08:25 - 2018-12-28 10:09 - 000419608 _____ C:\Windows\system32\locale.nls 2019-01-09 08:25 - 2018-12-27 16:01 - 025738240 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2019-01-09 08:25 - 2018-12-27 15:50 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2019-01-09 08:25 - 2018-12-27 15:50 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2019-01-09 08:25 - 2018-12-27 15:38 - 002902016 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2019-01-09 08:25 - 2018-12-27 15:37 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2019-01-09 08:25 - 2018-12-27 15:36 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2019-01-09 08:25 - 2018-12-27 15:36 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2019-01-09 08:25 - 2018-12-27 15:36 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2019-01-09 08:25 - 2018-12-27 15:36 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2019-01-09 08:25 - 2018-12-27 15:31 - 005778944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2019-01-09 08:25 - 2018-12-27 15:29 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2019-01-09 08:25 - 2018-12-27 15:28 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2019-01-09 08:25 - 2018-12-27 15:26 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2019-01-09 08:25 - 2018-12-27 15:25 - 020279808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2019-01-09 08:25 - 2018-12-27 15:25 - 000790016 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2019-01-09 08:25 - 2018-12-27 15:25 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2019-01-09 08:25 - 2018-12-27 15:25 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2019-01-09 08:25 - 2018-12-27 15:24 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2019-01-09 08:25 - 2018-12-27 15:17 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2019-01-09 08:25 - 2018-12-27 15:17 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2019-01-09 08:25 - 2018-12-27 15:14 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2019-01-09 08:25 - 2018-12-27 15:07 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2019-01-09 08:25 - 2018-12-27 15:07 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2019-01-09 08:25 - 2018-12-27 15:06 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2019-01-09 08:25 - 2018-12-27 15:05 - 000498176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2019-01-09 08:25 - 2018-12-27 15:05 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2019-01-09 08:25 - 2018-12-27 15:04 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2019-01-09 08:25 - 2018-12-27 15:04 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2019-01-09 08:25 - 2018-12-27 15:03 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2019-01-09 08:25 - 2018-12-27 15:03 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2019-01-09 08:25 - 2018-12-27 15:03 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2019-01-09 08:25 - 2018-12-27 15:02 - 002295808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2019-01-09 08:25 - 2018-12-27 15:01 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2019-01-09 08:25 - 2018-12-27 14:59 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2019-01-09 08:25 - 2018-12-27 14:59 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2019-01-09 08:25 - 2018-12-27 14:58 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2019-01-09 08:25 - 2018-12-27 14:56 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2019-01-09 08:25 - 2018-12-27 14:55 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2019-01-09 08:25 - 2018-12-27 14:55 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2019-01-09 08:25 - 2018-12-27 14:55 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2019-01-09 08:25 - 2018-12-27 14:50 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2019-01-09 08:25 - 2018-12-27 14:48 - 015284224 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2019-01-09 08:25 - 2018-12-27 14:48 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2019-01-09 08:25 - 2018-12-27 14:48 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2019-01-09 08:25 - 2018-12-27 14:47 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2019-01-09 08:25 - 2018-12-27 14:46 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2019-01-09 08:25 - 2018-12-27 14:45 - 002135552 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2019-01-09 08:25 - 2018-12-27 14:43 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2019-01-09 08:25 - 2018-12-27 14:42 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2019-01-09 08:25 - 2018-12-27 14:42 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2019-01-09 08:25 - 2018-12-27 14:39 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2019-01-09 08:25 - 2018-12-27 14:39 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2019-01-09 08:25 - 2018-12-27 14:37 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2019-01-09 08:25 - 2018-12-27 14:36 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2019-01-09 08:25 - 2018-12-27 14:33 - 004860416 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2019-01-09 08:25 - 2018-12-27 14:33 - 004494848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2019-01-09 08:25 - 2018-12-27 14:31 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2019-01-09 08:25 - 2018-12-27 14:29 - 013680640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2019-01-09 08:25 - 2018-12-27 14:29 - 002060288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2019-01-09 08:25 - 2018-12-27 14:29 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2019-01-09 08:25 - 2018-12-27 14:28 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2019-01-09 08:25 - 2018-12-27 14:22 - 001555968 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2019-01-09 08:25 - 2018-12-27 14:11 - 004386816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2019-01-09 08:25 - 2018-12-27 14:11 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2019-01-09 08:25 - 2018-12-27 14:07 - 001329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2019-01-09 08:25 - 2018-12-27 14:06 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2019-01-09 08:25 - 2018-12-07 19:08 - 000095744 _____ (Microsoft Corporation) C:\Windows\system32\rascfg.dll 2019-01-09 08:25 - 2018-12-07 19:08 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll 2019-01-09 08:25 - 2018-12-07 19:08 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\ndptsp.tsp 2019-01-09 08:25 - 2018-12-07 19:08 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\kmddsp.tsp 2019-01-09 08:25 - 2018-12-07 19:08 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\rasmxs.dll 2019-01-09 08:25 - 2018-12-07 19:08 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\rasser.dll 2019-01-09 08:25 - 2018-12-07 18:56 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rascfg.dll 2019-01-09 08:25 - 2018-12-07 18:56 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdiag.dll 2019-01-09 08:25 - 2018-12-07 18:56 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ndptsp.tsp 2019-01-09 08:25 - 2018-12-07 18:47 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys 2019-01-09 08:25 - 2018-12-07 18:47 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys 2019-01-09 08:25 - 2018-12-07 18:47 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndistapi.sys 2019-01-09 08:25 - 2018-12-07 18:41 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kmddsp.tsp 2019-01-09 08:25 - 2018-12-07 18:41 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasmxs.dll 2019-01-09 08:25 - 2018-12-07 18:41 - 000022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasser.dll 2019-01-09 08:25 - 2018-12-07 07:33 - 000352768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll 2019-01-05 11:27 - 2019-01-05 11:27 - 000000000 ____D C:\ProgramData\Jetmedia 2019-01-05 11:25 - 2019-01-15 12:24 - 000000000 ____D C:\ProgramData\Gxjri 2019-01-05 11:25 - 2019-01-05 11:25 - 000000000 ____D C:\ProgramData\Gjmp 2019-01-02 20:32 - 2019-01-02 20:32 - 000238937 _____ C:\Users\hp\Downloads\The-Buried-Secrets-of-Peonies.pdf 2018-12-31 14:26 - 2018-12-31 14:26 - 000000000 ____D C:\Program Files\DIFX 2018-12-31 14:25 - 2018-12-31 14:28 - 000245568 _____ (KEYLOK) C:\Windows\system32\NWKL2_64.DLL 2018-12-31 14:25 - 2018-12-31 14:28 - 000236352 _____ (KEYLOK) C:\Windows\system32\KL2DLL64.DLL 2018-12-31 14:25 - 2018-12-31 14:28 - 000207168 _____ (KEYLOK) C:\Windows\SysWOW64\NWKL2_32.DLL 2018-12-31 14:25 - 2018-12-31 14:28 - 000198976 _____ (KEYLOK) C:\Windows\SysWOW64\KL2DLL32.DLL 2018-12-31 14:25 - 2018-12-31 14:28 - 000041984 _____ C:\Windows\system32\ppmon64.exe 2018-12-31 14:25 - 2018-12-31 14:28 - 000024136 _____ C:\Windows\SysWOW64\ppmon.exe 2018-12-31 14:25 - 2018-12-31 14:28 - 000012480 _____ C:\Windows\SysWOW64\KL2N.DLL 2018-12-31 14:25 - 2018-12-31 14:28 - 000007440 _____ C:\Windows\SysWOW64\ppmon.dll 2018-12-31 14:25 - 2018-12-31 14:28 - 000000000 ____D C:\Users\hp\AppData\Local\KEYLOK ==================== One month (modified) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-01-22 14:47 - 2009-07-13 20:45 - 000018752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2019-01-22 14:47 - 2009-07-13 20:45 - 000018752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2019-01-22 14:41 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\tracing 2019-01-22 14:37 - 2009-07-13 21:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2019-01-22 14:34 - 2018-06-22 12:50 - 000000000 ____D C:\Users\hp\AmazonMeter 2019-01-22 14:00 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\rescache 2019-01-22 10:18 - 2009-07-13 21:13 - 000781790 _____ C:\Windows\system32\PerfStringBackup.INI 2019-01-22 10:18 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\inf 2019-01-22 09:59 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\system32\NDF 2019-01-22 08:00 - 2018-04-03 15:06 - 000000000 ____D C:\Program Files\Recuva 2019-01-22 00:17 - 2018-07-16 20:53 - 000000000 ____D C:\Users\hp\AppData\Roaming\DAEMON Tools Lite 2019-01-21 23:34 - 2018-04-10 11:04 - 000000000 ____D C:\ProgramData\Bitdefender 2019-01-21 23:34 - 2018-03-18 09:19 - 000001945 _____ C:\Windows\epplauncher.mif 2019-01-21 23:29 - 2018-09-18 19:43 - 000003168 _____ C:\Windows\System32\Tasks\HPCeeScheduleForhp 2019-01-21 23:29 - 2018-09-18 19:43 - 000000320 _____ C:\Windows\Tasks\HPCeeScheduleForhp.job 2019-01-21 22:31 - 2018-03-05 06:54 - 000000000 ____D C:\Users\hp 2019-01-21 22:10 - 2018-04-09 17:59 - 000371954 _____ C:\Windows\ntbtlog.txt 2019-01-21 19:02 - 2018-03-28 09:54 - 000007610 _____ C:\Users\hp\AppData\Local\Resmon.ResmonCfg 2019-01-21 19:01 - 2018-06-22 12:50 - 000000000 ____D C:\Users\hp\AppData\Local\ShopTracker 2019-01-21 18:51 - 2018-11-09 20:08 - 000000000 ____D C:\ProgramData\install_clap 2019-01-21 18:51 - 2018-04-23 21:14 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2019-01-21 18:50 - 2018-11-13 23:21 - 000000000 ____D C:\Users\hp\AppData\Local\CyberLink 2019-01-21 18:50 - 2018-11-10 00:18 - 000000000 ____D C:\Users\Public\Documents\CyberLink 2019-01-21 17:57 - 2018-03-18 00:00 - 000774404 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2019-01-20 23:46 - 2018-03-05 08:56 - 000000000 ____D C:\Program Files (x86)\Google 2019-01-20 23:39 - 2018-03-05 08:53 - 000003902 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{F6E746E4-63AF-49FA-9A7B-94C1E28737FA} 2019-01-20 23:22 - 2009-07-13 19:20 - 000000000 ____D C:\PerfLogs 2019-01-20 22:46 - 2018-03-18 09:20 - 000000000 ____D C:\Program Files\Microsoft Silverlight 2019-01-20 22:46 - 2018-03-18 09:20 - 000000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2019-01-18 10:54 - 2018-11-13 23:21 - 000000000 ____D C:\Users\hp\Documents\YouCam 2019-01-17 23:43 - 2018-03-05 09:02 - 000000000 ____D C:\Users\hp\AppData\Roaming\vlc 2019-01-16 09:35 - 2018-03-18 09:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2019-01-15 23:10 - 2018-11-09 20:29 - 000000000 ____D C:\ProgramData\Package Cache 2019-01-14 17:07 - 2018-05-02 14:23 - 000000000 ____D C:\Users\hp\AppData\Local\ElevatedDiagnostics 2019-01-11 08:52 - 2018-03-05 08:27 - 000000000 ____D C:\Windows\system32\MRT 2019-01-11 08:45 - 2018-03-05 08:27 - 132790320 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2019-01-05 11:27 - 2018-09-06 15:55 - 000000000 ____D C:\Users\hp\AppData\Roaming\Jetmedia 2019-01-05 10:42 - 2018-03-30 16:41 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk ==================== Files in the root of some directories ======= 2018-03-28 09:54 - 2019-01-21 19:02 - 000007610 _____ () C:\Users\hp\AppData\Local\Resmon.ResmonCfg Some files in TEMP: ==================== 2019-01-21 23:57 - 2019-01-21 23:57 - 000290304 _____ (Microsoft Corporation) C:\Users\hp\AppData\Local\Temp\CakeTubeSdk.Windows.Service.subinacl.exe 2018-12-31 14:25 - 2018-12-31 14:28 - 000033792 ____N (Microsoft Corporation) C:\Users\hp\AppData\Local\Temp\regini.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\dllhost.exe => File is digitally signed C:\Windows\SysWOW64\dllhost.exe => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2019-01-14 15:19 ==================== End of FRST.txt ============================ And here's the Addition log: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.01.2019 Ran by hp (22-01-2019 14:48:50) Running from C:\Users\hp\Downloads Windows 7 Professional Service Pack 1 (X64) (2018-03-05 14:54:51) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-4218809093-567755804-543443116-500 - Administrator - Disabled) Guest (S-1-5-21-4218809093-567755804-543443116-501 - Limited - Enabled) hp (S-1-5-21-4218809093-567755804-543443116-1000 - Administrator - Enabled) => C:\Users\hp Taya (S-1-5-21-4218809093-567755804-543443116-1003 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AV: Bitdefender Antivirus (Enabled - Up to date) {0E17DB7D-A20F-62CE-B95B-17DB0CDFE318} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Bitdefender Antispyware (Enabled - Up to date) {B5763A99-8435-6D40-83EB-2CA97758A9A5} FW: Bitdefender Firewall (Enabled) {362C5A58-E860-6396-9204-BEEEF20CA463} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.010.20069 - Adobe Systems Incorporated) Adobe Shockwave Player 12.3 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.3.1.201 - Adobe Systems, Inc.) Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 23.0.8.132 - Bitdefender) Bitdefender Internet Security (HKLM\...\Bitdefender) (Version: 23.0.16.72 - Bitdefender) Bitdefender VPN (HKLM\...\Bitdefender VPN) (Version: 23.0.8.625 - Bitdefender) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 5.0.1.0406 - Disc Soft Ltd) Evernote v. 6.11.2 (HKLM-x32\...\{FC67AAF6-3477-11E8-B094-005056951CAD}) (Version: 6.11.2.7027 - Evernote Corp.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 71.0.3578.98 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden HP ESU for Microsoft Windows 7 (HKLM-x32\...\{801EAD7A-7202-4BE4-84A1-299202AD17C0}) (Version: 2.0.7.1 - Hewlett-Packard Company) HP Support Solutions Framework (HKLM-x32\...\{930B5F2B-8DB9-42F4-90E4-5D3DC30541C3}) (Version: 12.10.49.21 - HP Inc.) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6433.0 - IDT) Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 20.1 - Intel) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.2.1004 - Intel Corporation) Malwarebytes version 3.6.1.2711 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes) Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 (HKLM-x32\...\{95ac1cfa-f4fb-4d1b-8912-7f9d5fbb140d}) (Version: 14.15.26706.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) NativeDesktopMediaService (HKLM-x32\...\{FC44DE72-60F9-4BC1-B098-D2F6B5A06187}) (Version: 3.5.0 - Jetmedia) <==== ATTENTION OBS Studio (HKLM-x32\...\OBS Studio) (Version: 22.0.2 - OBS Project) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.36.0 - Renesas Electronics Corporation) Hidden Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.36.0 - Renesas Electronics Corporation) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) ShopTracker 1.1.32 (HKLM-x32\...\AmazonMeter) (Version: 1.1.32 - Nielsen) Skype version 8.33 (HKLM-x32\...\Skype_is1) (Version: 8.33 - Skype Technologies S.A.) swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.18.25 - Synaptics Incorporated) VLC media player (HKLM\...\VLC media player) (Version: 3.0.1 - VideoLAN) Windows Driver Package - KEYLOK (usbkey) USB (06/10/2010 64.0.0.0) (HKLM\...\B048A6D4B0188E5A802ADFF30A7C78FA4AD99BE0) (Version: 06/10/2010 64.0.0.0 - KEYLOK) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2015-06-01] (Intel Corporation) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {2F70818D-EECB-4C2D-8C18-D8CB211769DB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-13] (Adobe Systems Incorporated) Task: {41322D55-C5AF-4689-AA68-DE65CD9D94A1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Opt-in For HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Utils.exe [2018-12-10] (HP Inc.) Task: {43F40AD4-27CB-4F04-A673-F018A90D9537} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2018-11-08] (HP Inc.) Task: {4808226E-2946-406B-8CD0-9B10A08DBCC0} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.) Task: {505C49A2-7605-44A3-BB9A-8F28811F51A7} - System32\Tasks\ApowerREC => C:\Program Files (x86)\Apowersoft\ApowerREC\ApowerREC.exe Task: {50D935BD-9157-484A-948C-E4024F607798} - System32\Tasks\HPCeeScheduleForhp => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2016-06-24] (HP Inc.) Task: {59E09B6C-AC84-4A3C-9917-831B0AFDB0EB} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2018-11-15] (Bitdefender) Task: {5A44B482-7ED6-4DCF-8980-2D06063B3650} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-11-09] (HP Inc.) Task: {6033258D-31A3-4BA6-9BB6-D02935163EA9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-03-05] (Google Inc.) Task: {6F783847-CDC2-44B3-9BBD-8DA9A89C8ED1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2019-01-02] (HP Inc.) Task: {7C2C5399-5BFA-4BD2-A19A-B937D60964D1} - System32\Tasks\Games\UpdateCheck_S-1-5-21-4218809093-567755804-543443116-1000 Task: {AAD573DB-3E59-479A-A342-9C4B96F9A0CF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-12-10] (HP Inc.) Task: {DE8B9D39-02CF-44BB-A3C0-5FB381E203FD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-11-09] (HP Inc.) Task: {EB50DE0F-035E-41B1-BC4D-DA76802B8E49} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-12-10] (HP Inc.) Task: {F159CC70-12F7-411B-B347-44CB39AAA1BC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-11-21] (HP Inc.) Task: {FFE32A28-EBAD-433F-A0E6-324B456BFB5C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-03-05] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\HPCeeScheduleForhp.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2019-01-21 23:35 - 2018-11-14 20:36 - 000994752 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttpbr.mdl 2019-01-21 23:35 - 2018-11-14 20:36 - 000544880 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttpdsp.mdl 2019-01-21 23:35 - 2018-11-14 20:36 - 003240080 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttpph.mdl 2019-01-21 23:35 - 2018-11-14 20:36 - 001530368 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttprbl.mdl 2018-11-20 04:46 - 2018-11-20 04:46 - 004310296 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-10-20 14:23 - 2010-10-20 14:23 - 008801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2015-06-01 18:00 - 2015-06-01 18:00 - 000102912 _____ () C:\Windows\System32\IccLibDll_x64.dll 2019-01-21 00:47 - 2018-11-21 11:07 - 002842608 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2019-01-21 00:47 - 2018-11-15 11:01 - 002712432 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll 2019-01-20 23:47 - 2018-12-11 21:11 - 005237216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libglesv2.dll 2019-01-20 23:47 - 2018-12-11 21:11 - 000117216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libegl.dll 2018-03-30 17:34 - 2018-03-30 17:34 - 000668384 _____ () C:\Program Files (x86)\Evernote\Evernote\tidy.dll 2019-01-12 12:55 - 2019-01-12 12:55 - 000169984 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\6ce952d16a75232a68643938f3f36608\IsdiInterop.ni.dll 2018-11-18 23:14 - 2011-01-12 17:56 - 000058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 18:34 - 2019-01-22 14:37 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-4218809093-567755804-543443116-1000\Control Panel\Desktop\\Wallpaper -> DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe (Microsoft Corporation) FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe (Microsoft Corporation) FirewallRules: [{34542273-AA73-424A-8BE8-DF8B61746018}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe No File FirewallRules: [{92B5D6B8-AC28-4707-B46D-EA2A1017D6C8}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Technologies S.A.) FirewallRules: [{9C771DE2-06DE-4AF7-8745-43CAC05B4CC6}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Technologies S.A.) FirewallRules: [{F7787BBA-55E1-4380-B343-D931984681D0}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerREC\ApowerREC.exe No File FirewallRules: [{74D2EF85-DC10-4053-B3F3-58DDD6D50414}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerREC\ApowerREC.exe No File FirewallRules: [{67DDB1D0-08A8-437B-BB76-ED7F8D4D275E}] => (Allow) C:\ProgramData\Gxjri\desktop_media_service.exe No File FirewallRules: [{354F4BAA-EBD5-4309-B8D9-666A34CE0165}] => (Allow) C:\Windows\SysWOW64\TCPSVCS.EXE (Microsoft Corporation) FirewallRules: [{2D6ABAF4-650D-4A37-B4D9-4C23FC85533A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ==================== Restore Points ========================= 15-01-2019 23:09:44 Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 15-01-2019 23:17:40 Windows Update 16-01-2019 09:14:38 Windows Update 19-01-2019 23:03:52 Windows Update 20-01-2019 22:43:24 Removed Windows 7 USB/DVD Download Tool 20-01-2019 23:42:45 Removed Google Chrome 21-01-2019 17:39:12 Windows Update 21-01-2019 17:53:33 Windows Update 21-01-2019 22:20:16 Installed SLOW-PCfighter. 21-01-2019 22:26:15 Fighters Backup ==================== Faulty Device Manager Devices ============= Name: LG K20 PLUS Description: LG K20 PLUS Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a} Manufacturer: LGE Service: WUDFRd Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (01/22/2019 08:12:06 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program iexplore.exe version 11.0.9600.19236 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 1e5c Start Time: 01d4b26d2534c17a Termination Time: 16 Application Path: C:\Program Files\Internet Explorer\iexplore.exe Report Id: 71ecbed6-1e60-11e9-be53-001a7dda7114 Error: (01/22/2019 12:22:23 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program obs64.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 1840 Start Time: 01d4b22b372f8c80 Termination Time: 9 Application Path: C:\Program Files\obs-studio\bin\64bit\obs64.exe Report Id: d554d2c3-1e1e-11e9-9985-101f744b6eab Error: (01/21/2019 10:26:16 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine ConvertStringSidToSid(S-1-5-21-4218809093-567755804-543443116-1000.bak). hr = 0x80070539, The security ID structure is invalid. . Operation: OnIdentify event Gathering Writer Data Context: Execution Context: Shadow Copy Optimization Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {a7838b74-aeb9-4d64-aaf0-ebd4769f8485} Error: (01/21/2019 10:26:15 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine ConvertStringSidToSid(S-1-5-21-4218809093-567755804-543443116-1000.bak). hr = 0x80070539, The security ID structure is invalid. . Operation: OnIdentify event Gathering Writer Data Context: Execution Context: Shadow Copy Optimization Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {a7838b74-aeb9-4d64-aaf0-ebd4769f8485} Error: (01/21/2019 10:20:16 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine ConvertStringSidToSid(S-1-5-21-4218809093-567755804-543443116-1000.bak). hr = 0x80070539, The security ID structure is invalid. . Operation: OnIdentify event Gathering Writer Data Context: Execution Context: Shadow Copy Optimization Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {fc00094d-9b7f-4c59-afe7-0d2e35bd3ac8} Error: (01/21/2019 05:53:33 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine ConvertStringSidToSid(S-1-5-21-4218809093-567755804-543443116-1000.bak). hr = 0x80070539, The security ID structure is invalid. . Operation: OnIdentify event Gathering Writer Data Context: Execution Context: Shadow Copy Optimization Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {f8ab2b6a-ed99-4164-86a7-27a2d143bdef} Error: (01/21/2019 05:39:12 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine ConvertStringSidToSid(S-1-5-21-4218809093-567755804-543443116-1000.bak). hr = 0x80070539, The security ID structure is invalid. . Operation: OnIdentify event Gathering Writer Data Context: Execution Context: Shadow Copy Optimization Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {cd6a5e15-4a1b-4b38-a569-6302682667b9} Error: (01/20/2019 11:42:46 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine ConvertStringSidToSid(S-1-5-21-4218809093-567755804-543443116-1000.bak). hr = 0x80070539, The security ID structure is invalid. . Operation: OnIdentify event Gathering Writer Data Context: Execution Context: Shadow Copy Optimization Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {c8dd1a98-c2fe-49b1-8f7e-113b9a6d415b} System errors: ============= Error: (01/22/2019 02:39:07 PM) (Source: sptd) (EventID: 4) (User: ) Description: Driver detected an internal error in its data structures for . Error: (01/22/2019 02:39:07 PM) (Source: sptd) (EventID: 4) (User: ) Description: Driver detected an internal error in its data structures for . Error: (01/22/2019 02:39:05 PM) (Source: sptd) (EventID: 4) (User: ) Description: Driver detected an internal error in its data structures for . Error: (01/22/2019 02:38:46 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. Error: (01/22/2019 02:38:19 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Amazon Meter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (01/22/2019 02:38:19 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Amazon Meter service to connect. Error: (01/22/2019 02:38:07 PM) (Source: sptd) (EventID: 4) (User: ) Description: Driver detected an internal error in its data structures for . Error: (01/22/2019 02:34:53 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the VSSERV service. Windows Defender: =================================== Date: 2018-07-06 09:38:11.787 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version:1.271.442.0 Previous Signature Version:1.269.1075.0 Update Source:User Signature Type:AntiSpyware Update Type:Delta Current Engine Version:1.1.15000.2 Previous Engine Version:1.1.14901.4 Error code:0x80070666 Error description:Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel. Date: 2018-07-06 09:38:11.777 Description: Windows Defender has encountered an error trying to update the engine. New Engine Version:1.1.15000.2 Previous Engine Version:1.1.14901.4 Update Source:User Error Code:0x80070666 Error description:Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel. CodeIntegrity: =================================== Date: 2019-01-22 14:46:17.553 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system. Date: 2019-01-22 14:45:29.001 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system. Date: 2019-01-22 14:39:54.853 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system. Date: 2019-01-22 14:39:50.589 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system. Date: 2019-01-22 14:34:14.958 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system. Date: 2019-01-22 13:18:21.773 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system. Date: 2019-01-22 13:18:14.617 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system. Date: 2019-01-22 13:17:52.368 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-2410M CPU @ 2.30GHz Percentage of memory in use: 41% Total physical RAM: 4030.36 MB Available physical RAM: 2344.95 MB Total Virtual: 8058.86 MB Available Virtual: 5680.32 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:297.99 GB) (Free:164.58 GB) NTFS \\?\Volume{83cbe48b-209d-11e8-84ea-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 298.1 GB) (Disk ID: 8E633DF9) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================[/code] Oh, and in case you couldn't tell, I'm a total newb, I know next to NOTHING about computers, but I can understand explanations and I'm good at following instructions, which is how I got as far as I am. Thanks for your time. If no1 responds to help im just going to hard reset it in the hopes that that works im 99% sure i dont have anything i super need on it [/QUOTE]
Insert quotes…
Verification
Post reply
Top