Jump to content

Help with pup.optional.yahoo!


Recommended Posts

Hi there! I couldn't quite figure out how to private message a moderator, so I'm posting up here again. 

This was the original thread: https://forums.malwarebytes.com/topic/217063-help-with-pupoptionalyahoo/

 

I tried what was suggested here, as per the Aura's advice (link https://forums.malwarebytes.com/topic/214325-chrome-secure-preferences-detection-always-comes-back/: ); however it did not solve my problem. How might I proceed?

 

Thank you for reading!

 

Link to post
Share on other sites

Alright. Follow the instructions below.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Scan mode
Follow the instructions below to download and execute a scan on your system with FRST, and provide the logs in your next reply.

  • Download the right version of FRST for your system:
    • FRST 32-bit
    • FRST 64-bit
      Note: Only the right version will run on your system, the other will throw an error message. So if you don't know what your system's version is, simply download both of them, and the one that works is the one you should be using.
  • Move the executable (FRST.exe or FRST64.exe) on your Desktop
  • Right-click on the executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the disclaimer by clicking on Yes, and FRST will then do a back-up of your Registry which should take a few seconds
  • Make sure the Addition.txt box is checked
  • Click on the Scan button
    KSJwAxg.png
  • On completion, two message box will open, saying that the results were saved to FRST.txt and Addition.txt, then open two Notepad files
  • Copy and paste the content of both FRST.txt and Addition.txt in your next reply


 
Link to post
Share on other sites

Aura,

Thank you again for your help. It is greatly appreciated.

 

 

ADDITION:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02.01.2018
Ran by Isaac Lee (04-01-2018 14:23:30)
Running from C:\Users\Isaac Lee\Desktop
Windows 10 Home Version 1703 15063.786 (X64) (2017-09-22 02:41:31)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2429715416-2568889488-3872324000-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2429715416-2568889488-3872324000-503 - Limited - Disabled)
Guest (S-1-5-21-2429715416-2568889488-3872324000-501 - Limited - Disabled)
Isaac Lee (S-1-5-21-2429715416-2568889488-3872324000-1001 - Administrator - Enabled) => C:\Users\Isaac Lee

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (HKLM\...\{0EBC740B-4363-489B-8C27-98CE0740BA19}) (Version: 18.2.4 - Hewlett-Packard) Hidden
7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov)
Adobe Flash Player 27 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 27.0.0.187 - Adobe Systems Incorporated)
AirDroid 3.5.4.0 (HKLM-x32\...\AirDroid) (Version: 3.5.4.0 - Sand Studio)
Alcor Micro USB Card Reader Driver (HKLM-x32\...\{9D569A6E-C9DF-490E-93E0-7AFD28D1F9BB}) (Version: 20.23.401.14519 - Alcor Micro Corp.) Hidden
Alcor Micro USB Card Reader Driver (HKLM-x32\...\InstallShield_{9D569A6E-C9DF-490E-93E0-7AFD28D1F9BB}) (Version: 20.23.401.14519 - Alcor Micro Corp.)
Anki (HKLM-x32\...\Anki) (Version:  - )
Apple Application Support (32-bit) (HKLM-x32\...\{BC7C46A4-D7A7-48EC-A98C-32A7762B5EFA}) (Version: 6.2.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{F0C4B709-8BF4-4A72-B527-12E7BF5482F8}) (Version: 6.2.1 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{19589375-5C58-4AFA-842F-8B34744CCEAD}) (Version: 2.5.0.1 - Apple Inc.)
ASUS FlipLock (HKLM\...\{7C7F8DAC-8ADA-4B86-BCB6-48B6FFB673DD}) (Version: 1.0.17 - ASUS)
ASUS PTP Driver (HKLM-x32\...\{7618E419-9124-4E6C-9AF4-487A6DDEC1C5}) (Version: 11.0.11 - ASUS)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0048 - ASUS)
AudioWizard (HKLM-x32\...\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}) (Version: 1.0.1.5 - ICEpower a/s)
Backup and Sync from Google (HKLM-x32\...\{908DB568-E5FA-40C7-A2AA-AB340190858B}) (Version: 3.38.7642.3857 - Google, Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.34 - Piriform)
dr.fone toolkit for Android (Version 8.3.3) (HKLM-x32\...\{7B08A1E1-3644-4237-B39D-762B5F5564D0}_is1) (Version: 8.3.3.64 - Wondershare Technology Co.,Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 63.0.3239.84 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
iCloud (HKLM\...\{99868C9C-C141-4DDE-A2C7-9DDF00F68F17}) (Version: 7.2.0.67 - Apple Inc.)
Intel(R) Chipset Device Software (HKLM-x32\...\{aaa7f0fb-02dc-4576-beef-7d24842c5fbe}) (Version: 10.1.1.32 - Intel(R) Corporation) Hidden
Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.2.11000.2996 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.5.0.1015 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 21.20.16.4550 - Intel Corporation)
Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.63.1620.3 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{4DA9DC19-4E1D-4B10-A726-A5F2A1BC7265}) (Version: 18.1.1546.2762 - Intel Corporation)
Intel® Integrated Sensor Solution (HKLM-x32\...\{b3c2a365-876b-4588-97ce-5ab104b07d57}) (Version: 3.0.30.1076 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{d5572863-793c-4ec8-872a-43cccc68b948}) (Version: 18.40.0 - Intel Corporation)
ISS_Drivers_x64 (HKLM\...\{7F65AED2-5B3C-40DD-996B-6F8820856F34}) (Version: 3.0.30.1076 - Intel Corporation) Hidden
KakaoTalk (HKLM-x32\...\KakaoTalk) (Version: 2.6.3.1672 - Kakao Corp.)
KB4023057 (HKLM\...\{264FDD69-C4DF-476F-B1B8-7DCEE4AF839B}) (Version: 2.4.0.0 - Microsoft Corporation)
K-Lite Codec Pack 13.5.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 13.5.0 - KLCP)
Malwarebytes version 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
MATLAB R2017a (HKLM\...\Matlab R2017a) (Version: 9.2 - MathWorks)
MediaMonkey 4.1 (HKLM-x32\...\MediaMonkey_is1) (Version: 4.1 - Ventis Media Inc.)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.8201.2213 - Microsoft Corporation)
Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.8201.2213 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\...\OneDriveSetup.exe) (Version: 17.3.6998.0830 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\...\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation)
Mozilla Firefox 55.0.3 (x64 en-US) (HKLM\...\Mozilla Firefox 55.0.3 (x64 en-US)) (Version: 55.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 55.0.3 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.8201.2213 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.8201.2213 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.8201.2075 - Microsoft Corporation) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.5.3 - pdfforge GmbH)
Pharos (HKLM-x32\...\Pharos) (Version:  - )
Pulse Secure (HKLM\...\{A6B07C9E-1D3D-4816-BC6C-679CC9B5E2F7}) (Version: 5.1.61491 - Pulse Secure, LLC) Hidden
Pulse Secure 5.1 (HKLM-x32\...\Pulse Secure 5.1) (Version: 5.1.61491 - Pulse Secure, LLC)
Pulse Secure Setup Client (HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\...\Juniper_Setup_Client) (Version: 8.1.6.61491 - Pulse Secure, LLC)
Pulse Secure Setup Client 64-bit Activex Control (HKLM\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Pulse Secure, LLC)
Pulse Secure Setup Client Activex Control (HKLM-x32\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Pulse Secure, LLC)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7848 - Realtek Semiconductor Corp.)
Samsung Kies3 (HKLM-x32\...\{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16084.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16084.2 - Samsung Electronics Co., Ltd.)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
SecureW2 Enterprise Client 3.5.14 (HKLM-x32\...\SecureW2 Enterprise Client) (Version:  - )
SumatraPDF (HKLM\...\SumatraPDF) (Version: 3.1.2 - Krzysztof Kowalczyk)
The Bat! v7.4.16 (64-bit) (HKLM\...\{BD704984-2F13-4EF3-90BD-38C949CE1D22}) (Version: 7.4.16 - Ritlabs, SRL)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.6 - VideoLAN)
WeChat (HKLM-x32\...\WeChat) (Version: 2.5.5.22 - 腾讯科技(深圳)有限公司)
Windows 10 Update and Privacy Settings (HKLM\...\{4DFCD818-036A-4229-A67D-CF17DC461D92}) (Version: 1.0.14.0 - Microsoft Corporation)
Windows Driver Package - ASUS (AsusPTPDrv) HIDClass  (06/03/2016 11.0.0.11) (HKLM\...\0B4533347E894EFA3F8DC5D4B35CF2D1B1BF756F) (Version: 06/03/2016 11.0.0.11 - ASUS)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-20] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-20] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-20] (Google)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\ShellExt.dll [2017-03-18] (Microsoft Corporation)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-11-20] (Google)
ContextMenuHandlers1: [PDFCreator.ShellContextMenu] -> {d9cea52e-100d-4159-89ea-76e845bc13e1} => C:\WINDOWS\system32\mscoree.dll [2017-03-18] (Microsoft Corporation)
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2017-12-08] (Apple Inc.)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\ShellExt.dll [2017-03-18] (Microsoft Corporation)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\ShellExt.dll [2017-03-18] (Microsoft Corporation)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-11-20] (Google)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_463164d40c3d26ce\igfxDTCM.dll [2016-11-30] (Intel Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0CE5CB8B-4962-4BB9-B534-CFC279E5FBFB} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-10-12] (Apple Inc.)
Task: {0EAB1253-71D5-48A5-8D74-BD5FFEC24B3B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2017-12-22] (Microsoft Corporation)
Task: {0EDFA46A-8EDA-49A5-9C56-8E6155E193D1} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2016-06-16] (Realtek Semiconductor)
Task: {3364F558-C6CB-44BC-859A-1288F3E0F7B5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-09-14] (Google Inc.)
Task: {4369D86C-25B4-4F18-8883-8A78C410FCDC} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_27_0_0_187_pepper.exe [2017-11-28] (Adobe Systems Incorporated)
Task: {43EE6994-3504-4CF5-B53E-BB9E5365AB9D} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-11-19] ()
Task: {4C58CC78-A15C-4AB1-8375-8B5D0A6740F5} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-11-19] ()
Task: {534065DA-4A30-47ED-8870-9D946B524C04} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2016-06-16] (Realtek Semiconductor)
Task: {53999AEE-5075-4A4C-A4AE-5FED89031F40} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-07] (Microsoft Corporation)
Task: {682D91F8-449D-47D8-8D36-BD1437B0CFF7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-09-07] (Piriform Ltd)
Task: {6B84DD80-6DB3-4EF6-84D3-FFD4EA76A2D9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-07] (Microsoft Corporation)
Task: {8F61BC54-E29C-4C67-A0C9-2787409BCAB2} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2015-09-22] (ASUSTek Computer Inc.)
Task: {93B9757E-84B2-4471-A47B-4574139674EA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-09-14] (Google Inc.)
Task: {A1889715-CBED-4583-A181-B884A76216C2} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-11-02] (Microsoft Corporation)
Task: {A78711CA-2F81-41EC-9D36-CDE1CA9969B2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-07] (Microsoft Corporation)
Task: {A86F3B0F-3003-4E07-95B0-57C895C741D5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-07] (Microsoft Corporation)
Task: {BBB50649-9423-4282-A1B9-707EA2DB8B11} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2017-12-22] (Microsoft Corporation)
Task: {BD4F92D1-7237-4D92-B27B-5E536CC04A47} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-12-22] (Microsoft Corporation)
Task: {D39E1995-9DB8-4D69-8909-55754A2E62A8} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-11-02] (Microsoft Corporation)
Task: {D6521E36-351E-47DC-9C76-BA8C3A029922} - System32\Tasks\MATLAB R2017a Startup Accelerator => C:\Program Files\MATLAB\R2017a\bin\win64\MATLABStartupAccelerator.exe [2017-01-19] ()
Task: {E1D0A4C9-7DA0-4847-A889-DFBFDFCCB1A0} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2017-09-01] ()
Task: {E51A6060-1F5C-4CD6-9426-DE1DB3843635} - System32\Tasks\SecureW2 Task => C:\Program Files (x86)\SecureW2\sw2_tray.exe [2015-06-03] (SecureW2 B.V.)
Task: {E9AF1D02-01FB-4CFF-B59E-B9239683B9DE} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [2016-02-19] (Intel(R) Corporation)
Task: {EA45D874-4AA9-4BA3-95DB-04DB6716E0EF} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2015-09-22] (ASUSTek Computer Inc.)
Task: {EF2CEEB5-EE5B-4ADB-A699-187C7E347826} - System32\Tasks\CheckFlipService => C:\Program Files\ASUS\ASUS FlipLock\CheckFlipService.exe [2016-07-28] ()
Task: {F356064B-D1AD-4FFF-8ACD-9E79283ECDC0} - System32\Tasks\ASUS Patch for Touch Panel => C:\ProgramData\AsTouchPanel\AsPatchTouchPanel64.exe [2016-03-07] (ASUSTek Computer INC.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\MATLAB R2017a Startup Accelerator.job => C:\Program Files\MATLAB\R2017a\bin\win64\MATLABStartupAccelerator.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2016-07-28 21:22 - 2016-07-28 21:22 - 000018872 _____ () C:\Program Files\ASUS\ASUS FlipLock\WifiPowerManager.exe
2016-07-28 21:22 - 2016-07-28 21:22 - 000016312 _____ () C:\Program Files\ASUS\ASUS FlipLock\FlipControlPTP.exe
2016-07-28 21:22 - 2016-07-28 21:22 - 000030648 _____ () C:\Program Files\ASUS\ASUS FlipLock\FlipController.exe
2017-03-18 15:58 - 2017-03-18 15:58 - 000138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2017-03-18 15:59 - 2017-03-18 21:31 - 001731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-01-03 16:13 - 2018-01-03 16:14 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2018-01-03 16:13 - 2018-01-03 16:14 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2018-01-03 16:13 - 2018-01-03 16:14 - 024670720 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2018-01-03 16:13 - 2018-01-03 16:14 - 002550272 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\skypert.dll
2017-11-20 15:27 - 2017-11-20 15:27 - 041061856 _____ () C:\Program Files (x86)\Google\Drive\googledrivesync.exe
2017-09-14 11:28 - 2017-11-29 09:11 - 002301384 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2017-12-05 17:47 - 2017-12-05 17:47 - 004698848 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11711.1001.5.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2017-12-14 12:46 - 2017-12-14 12:46 - 000477184 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2017-12-14 12:46 - 2017-12-14 12:46 - 058590720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2017-09-30 08:00 - 2017-09-30 08:01 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll
2017-11-10 11:59 - 2017-11-10 12:01 - 000164864 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\VideoPlugin.dll
2017-09-30 08:00 - 2017-09-30 08:01 - 000675328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\IPPNativePlugin.dll
2017-12-14 12:46 - 2017-12-14 12:46 - 003727360 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll
2017-12-14 12:46 - 2017-12-14 12:46 - 002270720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll
2017-12-14 12:46 - 2017-12-14 12:46 - 016395264 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll
2017-12-14 12:46 - 2017-12-14 12:46 - 003579904 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\MediaEngine.dll
2017-12-14 12:46 - 2017-12-14 12:46 - 003204096 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll
2017-09-21 22:15 - 2017-09-21 22:15 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2017-12-14 12:46 - 2017-12-14 12:46 - 000043520 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll
2017-12-14 12:46 - 2017-12-14 12:46 - 004038144 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.People.PeoplePicker.dll
2017-12-14 12:46 - 2017-12-14 12:46 - 001367040 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll
2017-12-14 12:46 - 2017-12-14 12:46 - 000214528 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\SKU.dll
2017-12-14 12:46 - 2017-12-14 12:46 - 000119808 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\ExploreModel.dll
2017-12-14 12:46 - 2017-12-14 12:46 - 000041472 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\ImageDecoding.dll
2017-10-26 07:51 - 2017-10-26 07:51 - 001921208 _____ () C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.8827.20991.0_x64__8wekyb3d8bbwe\Microsoft.Applications.Telemetry.Windows.dll
2017-12-30 18:47 - 2017-12-30 18:47 - 000140976 _____ () C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.8827.20991.0_x64__8wekyb3d8bbwe\textinputdriver.dll
2016-07-28 21:22 - 2016-07-28 21:22 - 000009216 _____ () C:\Program Files\ASUS\ASUS FlipLock\WMIProc.dll
2017-12-08 01:49 - 2017-12-08 01:49 - 001042232 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2017-12-08 01:48 - 2017-12-08 01:48 - 000189752 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
2017-12-08 01:49 - 2017-12-08 01:49 - 000076088 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2018-01-04 10:12 - 2018-01-04 10:12 - 000088064 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\_ctypes.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000919552 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\_hashlib.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000098816 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\win32api.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000110080 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\pywintypes27.dll
2018-01-04 10:12 - 2018-01-04 10:12 - 000364544 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\pythoncom27.dll
2018-01-04 10:12 - 2018-01-04 10:12 - 000686080 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\unicodedata.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000320512 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\win32com.shell.shell.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 001177088 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\wx._core_.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000806912 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\wx._gdi_.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000816640 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\wx._windows_.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 001067520 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\wx._controls_.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000733696 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\wx._misc_.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000736256 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\pysqlite2._sqlite.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000119808 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\win32file.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000108544 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\win32security.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000007168 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\hashobjs_ext.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000017920 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\thumbnails_ext.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000082432 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\usb_ext.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000013824 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\common.time34.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000018432 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\win32event.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000027648 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\windows.conditional.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000017408 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\windows.winwrap.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000089088 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\windows.volumes.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000167936 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\win32gui.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000046080 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\_socket.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 001311744 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\_ssl.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000129536 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\_elementtree.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000127488 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\pyexpat.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000038912 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\win32inet.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000077824 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\wx._html2.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000036864 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\_psutil_windows.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000524248 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\windows._lib_cacheinvalidation.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000011264 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\win32crypt.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000218624 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\PIL._imaging.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000027648 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\_multiprocessing.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000020480 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\_yappi.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000035840 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\win32process.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000024064 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\win32pipe.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000010240 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\select.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000025600 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\win32pdh.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000059392 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\windows.device_monitor.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000017408 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\win32profile.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000022528 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI93282\win32ts.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000088064 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\_ctypes.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000919552 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\_hashlib.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000098816 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\win32api.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000110080 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\pywintypes27.dll
2018-01-04 10:12 - 2018-01-04 10:12 - 000364544 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\pythoncom27.dll
2018-01-04 10:12 - 2018-01-04 10:12 - 000686080 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\unicodedata.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000320512 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\win32com.shell.shell.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 001177088 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\wx._core_.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000806912 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\wx._gdi_.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000816640 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\wx._windows_.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 001067520 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\wx._controls_.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000733696 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\wx._misc_.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000736256 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\pysqlite2._sqlite.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000119808 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\win32file.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000108544 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\win32security.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000007168 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\hashobjs_ext.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000017920 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\thumbnails_ext.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000082432 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\usb_ext.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000013824 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\common.time34.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000018432 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\win32event.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000027648 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\windows.conditional.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000017408 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\windows.winwrap.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000089088 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\windows.volumes.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000167936 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\win32gui.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000046080 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\_socket.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 001311744 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\_ssl.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000129536 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\_elementtree.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000127488 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\pyexpat.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000038912 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\win32inet.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000077824 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\wx._html2.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000036864 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\_psutil_windows.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000524248 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\windows._lib_cacheinvalidation.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000011264 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\win32crypt.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000218624 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\PIL._imaging.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000027648 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\_multiprocessing.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000020480 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\_yappi.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000035840 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\win32process.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000024064 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\win32pipe.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000010240 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\select.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000025600 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\win32pdh.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000059392 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\windows.device_monitor.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000017408 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\win32profile.pyd
2018-01-04 10:12 - 2018-01-04 10:12 - 000022528 _____ () C:\Users\Isaac Lee\AppData\Local\Temp\_MEI126082\win32ts.pyd

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-10-30 02:24 - 2017-12-16 21:07 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Signature\Signature01.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\...\StartupApproved\Run32: => "PulseSecure"
HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk"
HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\...\StartupApproved\Run: => "KakaoTalk"
HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\...\StartupApproved\Run: => "OneDrive"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{57BF59E3-9CE1-4042-920D-26EBD79B7148}] => (Allow) C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe
FirewallRules: [UDP Query User{5E194B9A-078C-4A5A-9637-AFD166EF3FEA}C:\program files\matlab\r2017a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\r2017a\bin\win64\matlab.exe
FirewallRules: [TCP Query User{EE6CDFC9-0230-47C2-AD77-E5E620995DFB}C:\program files\matlab\r2017a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\r2017a\bin\win64\matlab.exe
FirewallRules: [{B1C9C308-F431-4299-898B-C19B958ED160}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{A4120933-6EE0-4744-A67E-AB77C452AFE0}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [UDP Query User{105EEF27-C5C2-4E0B-A301-E08D41F759D5}D:\supplementary\sdi\sdi_x64_r1781.exe] => (Allow) D:\supplementary\sdi\sdi_x64_r1781.exe
FirewallRules: [TCP Query User{4C663848-92F9-4F0B-8B22-9F4466F991AF}D:\supplementary\sdi\sdi_x64_r1781.exe] => (Allow) D:\supplementary\sdi\sdi_x64_r1781.exe
FirewallRules: [{0C0A7D12-24A0-4139-A6C1-D83A1ADB36B2}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [TCP Query User{2F601F39-ACBC-4098-89C4-DD0AABE8E047}C:\program files (x86)\kakao\kakaotalk\kakaotalk.exe] => (Allow) C:\program files (x86)\kakao\kakaotalk\kakaotalk.exe
FirewallRules: [UDP Query User{DAED84AA-1BB1-458C-9D24-F5DFB11EC7C4}C:\program files (x86)\kakao\kakaotalk\kakaotalk.exe] => (Allow) C:\program files (x86)\kakao\kakaotalk\kakaotalk.exe
FirewallRules: [{7734856C-BBB5-49E3-939B-1217AA0D5011}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{03065967-1C72-4504-BE2F-ECB70DF3F177}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{ADF598BB-F8EF-46F7-9940-0C2BA944EA5F}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{EBC83954-E5DC-41FC-B425-040DABA0C205}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{60EDBD6A-29B6-4A8D-A24C-FD30F3A197DF}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{476D28B5-B0E0-4EF8-A41B-F91F44A23540}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6B746F16-2332-4A54-B715-C970A87A1043}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{FA235EDE-5EB4-4637-9BE7-A41A0A04D593}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{068CA815-BB94-4C28-BA1D-7CBB5DBB58E2}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{BBDA643A-2420-4DE0-BE72-30FCFFEF6F20}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{5DEEA4F8-F67E-4B95-BB3A-59EFDEA3D4EC}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe

==================== Restore Points =========================

11-12-2017 16:31:34 Scheduled Checkpoint
18-12-2017 20:38:49 Scheduled Checkpoint
29-12-2017 12:09:34 Scheduled Checkpoint
03-01-2018 21:54:10 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/04/2018 01:28:50 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3218

Error: (01/04/2018 01:28:50 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3218

Error: (01/04/2018 01:28:50 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/04/2018 01:14:52 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3234

Error: (01/04/2018 01:14:52 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3234

Error: (01/04/2018 01:14:52 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/03/2018 12:02:02 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3672

Error: (01/03/2018 12:02:02 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3672

Error: (01/03/2018 12:02:02 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/02/2018 08:57:08 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3625


System errors:
=============
Error: (01/04/2018 02:19:26 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/04/2018 01:28:13 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/04/2018 10:12:18 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/04/2018 10:12:18 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/04/2018 10:12:18 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/04/2018 10:12:18 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/04/2018 09:39:36 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The CldFlt service failed to start due to the following error: 
The request is not supported.

Error: (01/04/2018 09:35:37 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/04/2018 09:18:14 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/03/2018 09:30:19 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


CodeIntegrity:
===================================
  Date: 2018-01-04 14:22:02.506
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2018-01-04 14:22:02.503
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2018-01-04 10:18:20.809
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2018-01-04 10:18:20.805
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2018-01-03 21:34:04.840
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2018-01-03 21:34:04.838
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2018-01-02 12:50:49.836
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2018-01-02 12:50:49.833
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-12-30 18:57:10.751
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-12-30 18:57:10.748
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) m3-7Y30 CPU @ 1.00GHz
Percentage of memory in use: 40%
Total physical RAM: 8075.18 MB
Available physical RAM: 4767.79 MB
Total Virtual: 9355.18 MB
Available Virtual: 5590.62 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:237.37 GB) (Free:147.38 GB) NTFS ==>[system with boot components (obtained from drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: F4EA716C)

Partition: GPT.

==================== End of Addition.txt ============================

 

 

 

 

 

 

 

 

 

FRST:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02.01.2018
Ran by Isaac Lee (administrator) on LAPTOP-I1FRS6KV (04-01-2018 14:22:47)
Running from C:\Users\Isaac Lee\Desktop
Loaded Profiles: Isaac Lee (Available Profiles: Isaac Lee)
Platform: Windows 10 Home Version 1703 15063.786 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_463164d40c3d26ce\igfxCUIService.exe
(Pulse Secure, LLC) C:\Program Files (x86)\Common Files\Juniper Networks\JUNS\dsAccessService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files\ASUS\ASUS FlipLock\FlipService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_463164d40c3d26ce\IntelCpHDCPSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Pharos Systems International) C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe
(Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.227\WsAppService.exe
(Wondershare) C:\Program Files (x86)\Wondershare\dr.fone toolkit for Android\Library\DriverInstaller\DriverInstall.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_463164d40c3d26ce\IntelCpHeciSvc.exe
(Pulse Secure, LLC) C:\Program Files (x86)\Common Files\Juniper Networks\JUNS\dsAccessService.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\NisSrv.exe
() C:\Program Files\ASUS\ASUS FlipLock\WifiPowerManager.exe
() C:\Program Files\ASUS\ASUS FlipLock\FlipControlPTP.exe
() C:\Program Files\ASUS\ASUS FlipLock\FlipController.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
() C:\Program Files\ASUS\ASUS FlipLock\FlipController.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(ASUSTek Computer INC.) C:\ProgramData\AsTouchPanel\AsPatchTouchPanel64.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_463164d40c3d26ce\igfxEM.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Apple, Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
(Wondershare) C:\Program Files (x86)\Wondershare\dr.fone toolkit for Android\Addins\AndroidBackupRestore\BackupRemind.exe
(SecureW2 B.V.) C:\Program Files (x86)\SecureW2\sw2_tray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11711.1001.5.0_x64__8wekyb3d8bbwe\WinStore.App.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.8827.20991.0_x64__8wekyb3d8bbwe\onenoteim.exe
(Microsoft Corporation) C:\Windows\System32\wimserv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM-x32\...\Run: [SecureW2 Tray] => C:\Program Files (x86)\SecureW2\sw2_tray.exe [262464 2015-06-03] (SecureW2 B.V.)
HKLM-x32\...\Run: [PulseSecure] => C:\Program Files (x86)\Common Files\Juniper Networks\JamUI\Pulse.exe [2826584 2015-10-22] (Pulse Secure, LLC)
HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [41061856 2017-11-20] ()
HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9855192 2017-09-07] (Piriform Ltd)
HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\...\Run: [KakaoTalk] => C:\Program Files (x86)\Kakao\KakaoTalk\KakaoTalk.exe [8546112 2017-11-20] (Kakao Corp. )
HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2017-12-08] (Apple Inc.)
HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2017-12-08] (Apple Inc.)
HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [110392 2017-12-08] (Apple Inc.)
HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\...\Run: [iCloudPhotos] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [356664 2017-12-08] (Apple Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BackupRemind.lnk [2017-10-25]
ShortcutTarget: BackupRemind.lnk -> C:\Program Files (x86)\Wondershare\dr.fone toolkit for Android\Addins\AndroidBackupRestore\BackupRemind.exe (Wondershare)
Startup: C:\Users\Isaac Lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2017-09-22]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{2c94c9c7-c4c0-4995-b90f-c6d8c73e8fb8}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{62022f7a-afbf-450c-a8fb-8f2c798d061f}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6ceb2378-4142-40da-85e1-dc03de8889f7}: [NameServer] 128.6.1.1
Tcpip\..\Interfaces\{b3423fdc-10df-4b68-b026-bc0900fcb86f}: [DhcpNameServer] 172.17.128.24

Internet Explorer:
==================
HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus15.msn.com/?pc=ASTE
HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus15.msn.com/?pc=ASTE
SearchScopes: HKU\S-1-5-21-2429715416-2568889488-3872324000-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2429715416-2568889488-3872324000-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2017-12-05] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2017-11-19] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2017-12-22] (Microsoft Corporation)
DPF: HKLM {AA570693-00E2-4907-B6F1-60A1199B030C} hxxps://juniper.net/dana-cached/sc/JuniperSetupClient64.cab
DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-11-19] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-11-19] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-11-19] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-11-19] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-11-19] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-11-19] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-11-19] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-11-19] (Microsoft Corporation)

FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-11-19] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-11-19] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2017-11-19] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)

Chrome: 
=======
CHR HomePage: Default -> hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_fs_15_52&param1=1&param2=f%3D1%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0B0CyD0F0FyE0FzztDtC0C0EyCtByB0EtN0D0Tzu0StCyEyDyCtN1L2XzutAtFtCyCtFtCtFtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StBtD0FtDyDtAtCyBtGtCtCtC0FtGtBtA0F0DtGyBtB0EyEtG0DtB0AzztCzzyD0FyEtCyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szy0AtA0FyEzzyDyEtG0EzzyE0BtGyE0C0AtBtG0AtByBtBtGyBtAyCyEyCtCyDtCtAyE0Fzy2QtN0A0LzuyE%26cr%3D1864604354%26a%3Dwncy_fs_15_52%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro
CHR StartupUrls: Default -> "hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_fs_15_52&param1=1&param2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0B0CyD0F0FyE0FzztDtC0C0EyCtByB0EtN0D0Tzu0StCyEyDyCtN1L2XzutAtFtCyCtFtCtFtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StBtD0FtDyDtAtCyBtGtCtCtC0FtGtBtA0F0DtGyBtB0EyEtG0DtB0AzztCzzyD0FyEtCyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szy0AtA0FyEzzyDyEtG0EzzyE0BtGyE0C0AtBtG0AtByBtBtGyBtAyCyEyCtCyDtCtAyE0Fzy2QtN0A0LzuyE%26cr%3D1864604354%26a%3Dwncy_fs_15_52%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro"
CHR NewTab: Default ->  Active:"chrome-extension://jpfpebmajhhopeonhlcgidhclcccjcik/newtab.html"
CHR Profile: C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default [2018-01-04]
CHR Extension: (Slides) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-14]
CHR Extension: (Docs) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-14]
CHR Extension: (Google Drive) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-09-14]
CHR Extension: (YouTube) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-09-14]
CHR Extension: (Slinky Elegant) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmanlajnpdncmhfkiccmbgeocgbncfln [2017-09-14]
CHR Extension: (uBlock Origin) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-12-19]
CHR Extension: (Sheets) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-14]
CHR Extension: (Google Docs Offline) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-09-15]
CHR Extension: (Speed Dial 2 - New tab) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik [2017-09-14]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2017-09-21]
CHR Extension: (The Great Suspender) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbibkeccnjlkjkiokjodocebajanakg [2017-09-14]
CHR Extension: (StayFocusd) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2017-09-18]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2017-09-14]
CHR Extension: (Awesome Screenshot: Screen Video Recorder) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlipoenfbbikpbjkfpfillcgkoblgpmj [2017-12-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-14]
CHR Extension: (Gmail) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-09-14]
CHR Extension: (Chrome Media Router) - C:\Users\Isaac Lee\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-18]
CHR HKU\S-1-5-21-2429715416-2568889488-3872324000-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASUS Flip Service; C:\Program Files\ASUS\ASUS FlipLock\FlipService.exe [15288 2016-07-28] (ASUS)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8063656 2017-11-02] (Microsoft Corporation)
R2 esifsvc; C:\WINDOWS\system32\Intel\DPTF\esif_uf.exe [2215168 2016-08-22] (Intel Corporation)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [515232 2017-06-22] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [974632 2016-02-19] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [215328 2016-05-17] (Intel Corporation)
R2 JuniperAccessService; C:\Program Files (x86)\Common Files\Juniper Networks\JUNS\dsAccessService.exe [162136 2015-10-22] (Pulse Secure, LLC)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2016-02-08] ()
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2014-11-17] (Hewlett-Packard) [File not signed]
R2 Pharos Systems ComTaskMaster; C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe [1725952 2015-02-27] (Pharos Systems International) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2014-11-17] (Hewlett-Packard) [File not signed]
R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [741640 2014-06-16] (DEVGURU Co., LTD.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\NisSrv.exe [356176 2017-12-07] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe [105792 2017-12-07] (Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.227\WsAppService.exe [492768 2017-06-21] (Wondershare)
R2 WsDrvInst; C:\Program Files (x86)\Wondershare\dr.fone toolkit for Android\Library\DriverInstaller\DriverInstall.exe [118048 2017-06-22] (Wondershare)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3833248 2016-02-08] (Intel® Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 AsusPTPDrv; C:\WINDOWS\System32\drivers\AsusPTPFilter.sys [281592 2016-06-13] (ASUS Corporation)
S3 bcmfn; C:\WINDOWS\System32\drivers\bcmfn.sys [9728 2015-10-30] (Windows (R) Win 7 DDK provider) [File not signed]
R3 dptf_acpi; C:\WINDOWS\System32\drivers\dptf_acpi.sys [71232 2016-08-22] (Intel Corporation)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [66624 2016-08-22] (Intel Corporation)
R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [350272 2016-08-22] (Intel Corporation)
R3 HID_PCI; C:\WINDOWS\System32\drivers\HID_PCI.sys [30816 2016-05-24] (Intel)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [129008 2017-06-22] (Intel Corporation)
R3 ISH; C:\WINDOWS\System32\drivers\ISH.sys [140896 2016-06-05] (Intel)
R3 ISH_BusDriver; C:\WINDOWS\System32\drivers\ISH_BusDriver.sys [78432 2016-06-08] (Intel)
R1 jnprns; C:\WINDOWS\system32\DRIVERS\jnprns.sys [507192 2015-10-22] (Juniper Networks)
S4 jnprTdi_816_61491; C:\Windows\system32\Drivers\jnprTdi_816_61491.sys [108344 2015-10-22] (Pulse Secure, LLC)
S3 jnprva; C:\WINDOWS\System32\drivers\jnprva.sys [30072 2015-10-22] (Juniper Networks, Inc.)
R3 JnprVaMgr; C:\WINDOWS\System32\drivers\jnprvamgr.sys [45352 2015-10-22] (Juniper Networks, Inc.)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253880 2018-01-04] (Malwarebytes)
S3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [7135504 2016-02-27] (Intel Corporation)
R3 Netwtw06; C:\WINDOWS\System32\drivers\Netwtw06.sys [7553528 2017-07-11] (Intel Corporation)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 USBTINSP; C:\WINDOWS\System32\drivers\tinspusb.sys [142848 2010-03-29] (Texas Instruments)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46072 2017-12-07] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [288848 2017-12-07] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [129616 2017-12-07] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-04 14:22 - 2018-01-04 14:23 - 000021656 _____ C:\Users\Isaac Lee\Desktop\FRST.txt
2018-01-04 14:22 - 2018-01-04 14:22 - 000000000 ____D C:\FRST
2018-01-04 14:21 - 2018-01-04 14:22 - 002393088 _____ (Farbar) C:\Users\Isaac Lee\Desktop\FRST64.exe
2018-01-04 10:18 - 2018-01-04 10:18 - 000253880 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-01-04 10:18 - 2018-01-04 10:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-01-04 10:18 - 2018-01-04 10:18 - 000000000 ____D C:\ProgramData\MB3CoreBackup
2018-01-04 10:13 - 2018-01-04 12:23 - 098568633 _____ C:\Users\Isaac Lee\Downloads\[Daniel_V._Schroeder]_An_Introduction_to_Thermal_P(BookFi).pdf.crdownload
2018-01-04 09:39 - 2018-01-04 09:39 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-01-04 09:38 - 2018-01-04 09:38 - 000000000 ____D C:\WINDOWS\System32\Tasks\Apple
2018-01-04 09:38 - 2018-01-04 09:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2018-01-04 09:38 - 2018-01-04 09:38 - 000000000 ____D C:\Program Files (x86)\Apple Software Update
2018-01-04 09:26 - 2018-01-04 09:29 - 047880992 _____ C:\Users\Isaac Lee\Desktop\BIOMATERIALS-TEXTBOOK--3.pdf
2018-01-03 00:00 - 2018-01-03 00:01 - 000000116 _____ C:\Users\Isaac Lee\Desktop\breaking-fast.txt
2018-01-02 17:18 - 2018-01-02 17:20 - 000000000 ____D C:\AdwCleaner
2017-12-26 18:27 - 2017-12-26 18:56 - 000003737 _____ C:\Users\Isaac Lee\Desktop\awesome-in-this-place.txt
2017-12-17 22:14 - 2017-12-17 22:14 - 000000000 ___SD C:\WINDOWS\UpdateAssistantV2
2017-12-17 09:42 - 2017-12-17 09:42 - 000000000 ____D C:\Users\Isaac Lee\Documents\KakaoTalk Downloads
2017-12-14 14:21 - 2017-12-14 14:43 - 044098193 _____ C:\Users\Isaac Lee\Desktop\[Daniel_Coyle]_The_Talent_Code_Greatness_Isn't_Bo(BookFi).pdf
2017-12-14 14:21 - 2017-12-14 14:23 - 044098193 _____ C:\Users\Isaac Lee\Desktop\[Daniel_Coyle]_The_Talent_Code_Greatness_Isn't_Bo(b-ok.org).pdf
2017-12-12 20:45 - 2017-11-29 22:33 - 001144728 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-12-12 20:45 - 2017-11-29 22:33 - 001015704 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-12-12 20:45 - 2017-11-29 22:33 - 000038808 _____ (Microsoft Corporation) C:\WINDOWS\system32\OOBEUpdater.exe
2017-12-12 20:45 - 2017-11-29 22:29 - 008319384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-12-12 20:45 - 2017-11-29 22:26 - 002647216 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-12-12 20:45 - 2017-11-29 22:24 - 000870896 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2017-12-12 20:45 - 2017-11-29 22:23 - 007910960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-12-12 20:45 - 2017-11-29 22:23 - 001194248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2017-12-12 20:45 - 2017-11-29 22:00 - 002166808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-12-12 20:45 - 2017-11-29 21:59 - 023678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-12-12 20:45 - 2017-11-29 21:58 - 006763128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-12-12 20:45 - 2017-11-29 21:58 - 000702032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2017-12-12 20:45 - 2017-11-29 21:57 - 001123968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2017-12-12 20:45 - 2017-11-29 21:45 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-12-12 20:45 - 2017-11-29 21:45 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-12-12 20:45 - 2017-11-29 21:44 - 023679488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-12-12 20:45 - 2017-11-29 21:44 - 019334144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-12-12 20:45 - 2017-11-29 21:44 - 000171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2017-12-12 20:45 - 2017-11-29 21:44 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2017-12-12 20:45 - 2017-11-29 21:44 - 000042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
2017-12-12 20:45 - 2017-11-29 21:43 - 020511232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-12-12 20:45 - 2017-11-29 21:43 - 000164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
2017-12-12 20:45 - 2017-11-29 21:43 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-12-12 20:45 - 2017-11-29 21:43 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-12-12 20:45 - 2017-11-29 21:42 - 001878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-12-12 20:45 - 2017-11-29 21:42 - 000560640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2017-12-12 20:45 - 2017-11-29 21:42 - 000304640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2017-12-12 20:45 - 2017-11-29 21:42 - 000164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscript.exe
2017-12-12 20:45 - 2017-11-29 21:42 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2017-12-12 20:45 - 2017-11-29 21:42 - 000100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscript.ocx
2017-12-12 20:45 - 2017-11-29 21:42 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-12-12 20:45 - 2017-11-29 21:41 - 000527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-12-12 20:45 - 2017-11-29 21:41 - 000414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2017-12-12 20:45 - 2017-11-29 21:41 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-12-12 20:45 - 2017-11-29 21:41 - 000222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrobj.dll
2017-12-12 20:45 - 2017-11-29 21:41 - 000146944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscript.exe
2017-12-12 20:45 - 2017-11-29 21:40 - 012803072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-12-12 20:45 - 2017-11-29 21:40 - 000585216 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-12-12 20:45 - 2017-11-29 21:40 - 000528384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2017-12-12 20:45 - 2017-11-29 21:40 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrobj.dll
2017-12-12 20:45 - 2017-11-29 21:40 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscript.exe
2017-12-12 20:45 - 2017-11-29 21:39 - 011888640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-12-12 20:45 - 2017-11-29 21:39 - 003206656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
2017-12-12 20:45 - 2017-11-29 21:39 - 002809344 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-12-12 20:45 - 2017-11-29 21:39 - 000925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-12-12 20:45 - 2017-11-29 21:38 - 008195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-12-12 20:45 - 2017-11-29 21:38 - 001248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-12-12 20:45 - 2017-11-29 21:38 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-12-12 20:45 - 2017-11-29 21:38 - 000636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-12-12 20:45 - 2017-11-29 21:38 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-12-12 20:45 - 2017-11-29 21:37 - 006252544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-12-12 20:45 - 2017-11-29 21:37 - 003306496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-12-12 20:45 - 2017-11-29 21:37 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-12-12 20:45 - 2017-11-29 21:37 - 001293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-12-12 20:45 - 2017-11-29 21:36 - 005557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-12-12 20:45 - 2017-11-29 21:36 - 004726784 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-12-12 20:45 - 2017-11-29 21:36 - 003652096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-12-12 20:45 - 2017-11-29 21:36 - 001802240 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-12-12 20:45 - 2017-11-29 21:36 - 001398784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2017-12-12 20:45 - 2017-11-29 21:36 - 001019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-12-12 20:45 - 2017-11-29 21:36 - 000755200 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2017-12-12 20:45 - 2017-11-29 21:36 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2017-12-12 20:45 - 2017-11-29 21:35 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-12-12 20:45 - 2017-11-29 21:34 - 004559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-12-12 20:45 - 2017-11-17 04:46 - 002032536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2017-12-12 20:45 - 2017-11-17 04:46 - 001578904 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-12-12 20:45 - 2017-11-17 04:46 - 000821656 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2017-12-12 20:45 - 2017-11-17 04:46 - 000678808 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-12-12 20:45 - 2017-11-17 04:46 - 000613784 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-12-12 20:45 - 2017-11-17 04:46 - 000612248 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-12-12 20:45 - 2017-11-17 04:46 - 000484248 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-12-12 20:45 - 2017-11-17 04:46 - 000379288 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-12-12 20:45 - 2017-11-17 04:46 - 000259992 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-12-12 20:45 - 2017-11-17 04:46 - 000190360 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-12-12 20:45 - 2017-11-17 04:46 - 000136088 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-12-12 20:45 - 2017-11-17 04:46 - 000067992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2017-12-12 20:45 - 2017-11-17 04:46 - 000034712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-12-12 20:45 - 2017-11-17 04:41 - 000503704 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2017-12-12 20:45 - 2017-11-17 04:39 - 005477088 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-12-12 20:45 - 2017-11-17 04:39 - 000643200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-12-12 20:45 - 2017-11-17 04:37 - 021353200 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-12-12 20:45 - 2017-11-17 04:31 - 000223640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2017-12-12 20:45 - 2017-11-17 04:03 - 003668992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-12-12 20:45 - 2017-11-17 04:00 - 002953216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-12-12 20:45 - 2017-11-17 03:59 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-12-12 20:45 - 2017-11-17 03:56 - 000757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2017-12-05 10:43 - 2017-12-05 10:44 - 000000093 _____ C:\Users\Isaac Lee\Desktop\make_into_gif.txt

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-04 14:19 - 2017-03-18 15:51 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-01-04 13:28 - 2017-09-21 21:31 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-01-04 13:12 - 2017-09-20 16:00 - 000000000 ___DC C:\WINDOWS\Panther
2018-01-04 12:56 - 2017-09-21 21:40 - 000095253 _____ C:\WINDOWS\diagwrn.xml
2018-01-04 12:56 - 2017-09-21 21:40 - 000095253 _____ C:\WINDOWS\diagerr.xml
2018-01-04 11:34 - 2017-03-18 16:01 - 000000000 ____D C:\WINDOWS\INF
2018-01-04 11:27 - 2017-09-29 10:04 - 000000000 ___HD C:\$WINDOWS.~BT
2018-01-04 11:27 - 2017-03-18 16:03 - 000000000 ____D C:\WINDOWS\Registration
2018-01-04 10:19 - 2017-09-14 11:31 - 000000000 ____D C:\Users\Isaac Lee\Desktop\Always
2018-01-04 10:17 - 2017-10-28 09:34 - 001255730 _____ C:\WINDOWS\system32\perfh012.dat
2018-01-04 10:17 - 2017-10-28 09:34 - 000355376 _____ C:\WINDOWS\system32\perfc012.dat
2018-01-04 10:17 - 2016-04-11 20:57 - 004141940 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-01-04 10:15 - 2017-09-14 11:22 - 000000000 ____D C:\Users\Isaac Lee\Desktop\class_materials
2018-01-04 10:12 - 2017-11-28 08:52 - 000000000 ___RD C:\Users\Isaac Lee\iCloudDrive
2018-01-04 10:12 - 2017-09-14 12:11 - 000000000 ___RD C:\Users\Isaac Lee\Google Drive
2018-01-04 10:12 - 2016-11-16 20:25 - 000000000 __SHD C:\Users\Isaac Lee\IntelGraphicsProfiles
2018-01-04 09:39 - 2017-09-21 21:39 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-01-04 09:39 - 2017-09-21 21:34 - 000000000 ____D C:\Users\Isaac Lee
2018-01-04 09:39 - 2017-09-21 21:31 - 000420888 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-01-04 09:39 - 2017-03-18 06:40 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2018-01-04 09:38 - 2017-11-27 22:17 - 000002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2018-01-03 22:27 - 2017-03-18 06:40 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2018-01-03 16:14 - 2017-03-18 16:03 - 000000000 ___HD C:\Program Files\WindowsApps
2018-01-03 16:14 - 2017-03-18 16:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-12-31 10:16 - 2017-12-02 14:00 - 000000000 ____D C:\Users\Isaac Lee\Desktop\DEC-list
2017-12-30 18:10 - 2017-03-18 16:03 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-12-26 18:01 - 2017-09-28 07:47 - 000000000 ____D C:\Users\Isaac Lee\AppData\Roaming\vlc
2017-12-25 00:00 - 2016-11-16 20:04 - 000000000 ____D C:\Program Files\Microsoft Office
2017-12-24 09:09 - 2017-03-18 16:03 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-12-23 17:11 - 2016-11-16 20:25 - 000000000 ____D C:\Users\Isaac Lee\AppData\Local\Packages
2017-12-18 22:18 - 2017-03-18 16:03 - 000000000 ____D C:\WINDOWS\rescache
2017-12-17 22:15 - 2016-11-16 19:46 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-12-17 22:14 - 2017-03-18 16:03 - 000000000 ____D C:\WINDOWS\system32\oobe
2017-12-16 20:23 - 2017-03-18 16:03 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2017-12-14 12:43 - 2017-09-14 11:24 - 000002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-12-13 16:54 - 2017-09-15 15:00 - 000176215 _____ C:\notify_debug.txt
2017-12-12 22:37 - 2017-09-14 12:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2017-12-12 20:56 - 2017-09-16 12:29 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-12-12 20:46 - 2017-10-10 23:43 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2017-12-12 20:46 - 2017-09-16 12:29 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-12-09 17:51 - 2017-09-14 11:59 - 000000000 ____D C:\Users\Isaac Lee\Documents\MATLAB

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-12-26 18:22

==================== End of FRST.txt ============================

FRST.txt

Addition.txt

Link to post
Share on other sites

Alright follow the instructions below.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.

  • Download the attached fixlist.txt file, and save it on your Desktop (or wherever your FRST.exe/FRST64.exe executable is located)
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Fix button
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad
  • Copy and paste its content in your next reply

fixlist.txt

Link to post
Share on other sites

Ah I see! I thought it would affect all computers that synced with my Google Chrome account. It's a relief that they didn't.

My other computer did detect the pop.optional.yahoo :/

 

I went ahead and scanned my computer using the FRST and have included both the text of the Addition files and FRST as before to try and speed things along. Please let me know if I should have done something else!

 

 

Addition

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02.01.2018
Ran by redxx (05-01-2018 10:51:20)
Running from C:\Users\redxx\Desktop
Windows 10 Pro Version 1703 15063.786 (X64) (2017-08-03 11:13:07)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3734129659-697880071-3415915633-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3734129659-697880071-3415915633-503 - Limited - Disabled)
Guest (S-1-5-21-3734129659-697880071-3415915633-501 - Limited - Disabled)
redxx (S-1-5-21-3734129659-697880071-3415915633-1001 - Administrator - Enabled) => C:\Users\redxx

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\uTorrent) (Version: 3.5.0.43580 - BitTorrent Inc.)
µTorrent (HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\uTorrent) (Version: 3.5.0.43580 - BitTorrent Inc.)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated)
Anki (HKLM-x32\...\Anki) (Version:  - )
Apple Application Support (32-bit) (HKLM-x32\...\{D811A40A-9791-497C-B9DC-2D89C8E95EA1}) (Version: 6.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{8B47B514-F5D2-4E0D-B951-6E250618A7CD}) (Version: 6.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{31A0B634-BCF4-4D3F-8336-87FEACFEE142}) (Version: 11.0.1.2 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}) (Version: 2.4.8.1 - Apple Inc.)
AR8171 Driver Installation (HKLM-x32\...\{1E672F6A-B698-48A2-AE8C-427F97AF8F0E}) (Version: 1.0.0.32 - Rivet Networks)
AR8171 Drivers (HKLM\...\{C9CCB016-67E4-4872-AFD0-E3EE69B7CBFE}) (Version: 1.0.0.32 - Rivet Networks) Hidden
Audacity 2.1.1 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.1 - Audacity Team)
Backup and Sync from Google (HKLM-x32\...\{908DB568-E5FA-40C7-A2AA-AB340190858B}) (Version: 3.38.7642.3857 - Google, Inc.)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Bluebeam Vu x64 2015.5 (HKLM\...\{2915835C-B2F3-424E-9EE3-F3C95FF905E9}) (Version: 15.5.0 - Bluebeam Software, Inc.)
Blur Busters Strobe Util (HKLM-x32\...\{57BDAE81-2BE7-4ABA-8B03-1520FBF41AF9}) (Version: 1.0.0 - Blur Busters)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.38 - Piriform)
CEVO CS:GO Client Beta version 1.0 (HKLM-x32\...\CEVO CS:GO Client Beta_is1) (Version: 1.0 - )
Combined Community Codec Pack 2014-07-13 (HKLM-x32\...\Combined Community Codec Pack_is1) (Version: 2014.07.13.0 - CCCP Project)
CSGO Demos Manager version 2.3.2 (HKLM-x32\...\{2CC5723B-69A1-4B82-AA32-34968284F9C3}_is1) (Version: 2.3.2 - AkiVer)
CyberGhost 6 (HKLM\...\CyberGhost 6_is1) (Version:  - CyberGhost S.R.L.)
Discord (HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\Discord) (Version: 0.0.299 - Discord Inc.)
Discord (HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\Discord) (Version: 0.0.299 - Discord Inc.)
Dolphin (HKLM-x32\...\Dolphin) (Version: 4.0.2 - Dolphin Development Team)
Evernote v. 5.8.13 (HKLM-x32\...\{A229420E-204B-11E5-B844-0050569584E9}) (Version: 5.8.13.8152 - Evernote Corp.)
f.lux (HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\Flux) (Version:  - f.lux Software LLC)
f.lux (HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\Flux) (Version:  - f.lux Software LLC)
Focusrite Scarlett Family Audio Driver 3.1.10 (HKLM\...\Focusrite Scarlett Family Audio Driver_is1) (Version: 3.1.10 - Focusrite Audio Engineering Limited.)
FormatFactory 3.8.0.0 (HKLM-x32\...\FormatFactory) (Version: 3.8.0.0 - Free Time)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 63.0.3239.84 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
HandBrake 1.0.3 (HKLM-x32\...\HandBrake) (Version: 1.0.3 - )
iCloud (HKLM\...\{FF99A618-BCA5-4658-B9FF-CCF57C177610}) (Version: 7.1.0.34 - Apple Inc.)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4835 - Intel Corporation)
iTunes (HKLM\...\{F2517A28-8CB8-4206-B86C-5EDD4EA26682}) (Version: 12.7.1.14 - Apple Inc.)
Java 8 Update 151 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180151F0}) (Version: 8.0.1510.12 - Oracle Corporation)
KakaoTalk (HKLM-x32\...\KakaoTalk) (Version: 2.6.3.1672 - Kakao Corp.)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
League of Legends (HKLM-x32\...\{79BF4901-1EC4-4726-B3C2-A7859706C6E7}) (Version: 3.0.1 - Riot Games) Hidden
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
Logitech Gaming Software 8.88 (HKLM\...\Logitech Gaming Software) (Version: 8.88.30 - Logitech Inc.)
Macrium Reflect Free Edition (HKLM\...\{08B0BEF7-A098-4A77-B132-8702E9F43682}) (Version: 6.1.1225 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free Edition (HKLM\...\MacriumReflect) (Version: 6.1 - Paramount Software (UK) Ltd.)
Malwarebytes version 3.2.2.2018 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2018 - Malwarebytes)
Maple 18 (HKLM\...\Maple 18) (Version: 18 - Maplesoft)
MATLAB R2017b (HKLM\...\Matlab R2017b) (Version: 9.3 - MathWorks)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 57.0 (x64 en-US) (HKLM\...\Mozilla Firefox 57.0 (x64 en-US)) (Version: 57.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 57.0.0.6525 - Mozilla)
NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 388.13 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.10.0.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.10.0.95 - NVIDIA Corporation)
NVIDIA Graphics Driver 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 388.13 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.35.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.35.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.17.0329 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0329 - NVIDIA Corporation)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )
Oracle VM VirtualBox 5.1.22 (HKLM\...\{8D5E4D4D-5E0C-4448-B018-5DDEF1E208D9}) (Version: 5.1.22 - Oracle Corporation)
Overwatch (HKLM-x32\...\Overwatch) (Version:  - Blizzard Entertainment)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.1.2 - pdfforge)
Python 2.7.13 (HKLM-x32\...\{4A656C6C-D24A-473F-9747-3A8D00907A03}) (Version: 2.7.13150 - Python Software Foundation)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.21.28549 - Razer Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
REAPER (x64) (HKLM\...\REAPER) (Version:  - )
Resilio Sync (HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\Resilio Sync) (Version: 2.4.4 - Resilio, Inc.)
Resilio Sync (HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\Resilio Sync) (Version: 2.4.4 - Resilio, Inc.)
Samsung Kies3 (HKLM-x32\...\{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16011.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16011.2 - Samsung Electronics Co., Ltd.)
SecureW2 Enterprise Client 3.5.14 (HKLM-x32\...\SecureW2 Enterprise Client) (Version:  - )
Smart Switch (HKLM-x32\...\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.0.15064.11 - Samsung Electronics Co., Ltd.) Hidden
Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.0.15064.11 - Samsung Electronics Co., Ltd.)
StarCraft (HKLM-x32\...\StarCraft) (Version:  - Blizzard Entertainment)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SumatraPDF (HKLM\...\SumatraPDF) (Version: 3.1.2 - Krzysztof Kowalczyk)
SyncTrayzor (x64) version 1.1.18.0 (HKLM\...\{c004dcef-b848-46a5-9c30-4dbf736396fa}_is1) (Version: 1.1.18.0 - SyncTrayzor)
TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - )
TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.81460 - TeamViewer)
The Bat! v7.4.16 (64-bit) (HKLM\...\{BD704984-2F13-4EF3-90BD-38C949CE1D22}) (Version: 7.4.16 - Ritlabs, SRL)
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.5.0.0 - Elaborate Bytes)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
WeChat (HKLM-x32\...\WeChat) (Version: 2.4.1.79 - 腾讯科技(深圳)有限公司)
Windows Movie Maker 2.6 (HKLM-x32\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation)
WinImage (HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\WinImage) (Version:  - )
WinImage (HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\WinImage) (Version:  - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3734129659-697880071-3415915633-1001_Classes\CLSID\{3D3B1846-CC43-42AE-BFF9-D914083C2BA3}\InprocServer32 -> C:\Program Files\SumatraPDF\PdfPreview.dll ()
CustomCLSID: HKU\S-1-5-21-3734129659-697880071-3415915633-1001_Classes\CLSID\{55808EA8-81FE-43c6-AAE8-1D8149F941D3}\InprocServer32 -> C:\Program Files\SumatraPDF\PdfFilter.dll ()
CustomCLSID: HKU\S-1-5-21-3734129659-697880071-3415915633-1001_Classes\CLSID\{581FFA00-FC33-0004-0402-95003A5CDE89}\InprocServer32 -> C:\Users\redxx\AppData\Roaming\Resilio Sync\ShellExtensionPath64_2DC.dll ()
CustomCLSID: HKU\S-1-5-21-3734129659-697880071-3415915633-1001_Classes\CLSID\{581FFA01-FC33-0004-0402-95003A5CDE89}\InprocServer32 -> C:\Users\redxx\AppData\Roaming\Resilio Sync\ShellExtensionPath64_2DC.dll ()
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-20] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-20] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-20] (Google)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> No File
ShellIconOverlayIdentifiers: [!Resilio Sync 2.4.4Done] -> {581FFA04-FC33-0004-0402-95003A5CDE89} => C:\ProgramData\Resilio Sync\ShellExtensionOverlay64_2DC.dll [2017-03-09] ()
ShellIconOverlayIdentifiers: [!Resilio Sync 2.4.4RO] -> {581FFA03-FC33-0004-0402-95003A5CDE89} => C:\ProgramData\Resilio Sync\ShellExtensionOverlay64_2DC.dll [2017-03-09] ()
ShellIconOverlayIdentifiers: [!Resilio Sync 2.4.4RW] -> {581FFA02-FC33-0004-0402-95003A5CDE89} => C:\ProgramData\Resilio Sync\ShellExtensionOverlay64_2DC.dll [2017-03-09] ()
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> No File
ShellIconOverlayIdentifiers-x32: [!Resilio Sync 2.4.4Done] -> {581FFA04-FC33-0004-0402-95003A5CDE89} => C:\ProgramData\Resilio Sync\ShellExtensionOverlay64_2DC.dll [2017-03-09] ()
ShellIconOverlayIdentifiers-x32: [!Resilio Sync 2.4.4RO] -> {581FFA03-FC33-0004-0402-95003A5CDE89} => C:\ProgramData\Resilio Sync\ShellExtensionOverlay64_2DC.dll [2017-03-09] ()
ShellIconOverlayIdentifiers-x32: [!Resilio Sync 2.4.4RW] -> {581FFA02-FC33-0004-0402-95003A5CDE89} => C:\ProgramData\Resilio Sync\ShellExtensionOverlay64_2DC.dll [2017-03-09] ()
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\ShellExt.dll [2017-03-18] (Microsoft Corporation)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-11-20] (Google)
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2017-10-19] (Apple Inc.)
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2015-10-12] (Paramount Software UK Ltd)
ContextMenuHandlers1: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\ShellExt.dll [2017-03-18] (Microsoft Corporation)
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2015-10-12] (Paramount Software UK Ltd)
ContextMenuHandlers2: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-21] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\ShellExt.dll [2017-03-18] (Microsoft Corporation)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-11-20] (Google)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2017-10-20] (Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-10-27] (NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-21] (Malwarebytes)
ContextMenuHandlers1_S-1-5-21-3734129659-697880071-3415915633-1001: [Resilio Sync 2.4.4] -> {581FFA00-FC33-0004-0402-95003A5CDE89} => C:\Users\redxx\AppData\Roaming\Resilio Sync\ShellExtensionPath64_2DC.dll [2017-03-09] ()
ContextMenuHandlers4_S-1-5-21-3734129659-697880071-3415915633-1001: [Resilio Sync 2.4.4] -> {581FFA00-FC33-0004-0402-95003A5CDE89} => C:\Users\redxx\AppData\Roaming\Resilio Sync\ShellExtensionPath64_2DC.dll [2017-03-09] ()

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {01DF01A8-9745-4571-9120-94C38BFB021F} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-10-10] (NVIDIA Corporation)
Task: {175FCD56-FDC1-46C0-8C94-F19CA24992AA} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-07-24] (Apple Inc.)
Task: {3381C851-7676-4394-9F79-8992916D3709} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-10] (NVIDIA Corporation)
Task: {403EEDD7-B4CF-494A-9902-F8A88EB86FE2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-09] (Google Inc.)
Task: {4162F152-46C7-4402-BAF2-65469BB57D80} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-10-10] (NVIDIA Corporation)
Task: {43092082-32B2-4DA7-B12A-DD4CEC4C4B46} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-09] (Google Inc.)
Task: {4A4515DA-9655-43C2-8F49-B3310D2D3560} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-07] (Microsoft Corporation)
Task: {5D1ED2EC-9B20-4A01-9AC1-A67EA31400A2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-07] (Microsoft Corporation)
Task: {7290B464-13ED-41B8-AFDA-46CAD9B5AAC4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-07] (Microsoft Corporation)
Task: {7B5F2950-D049-4309-9E6E-EC46A14C31E2} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-10] (NVIDIA Corporation)
Task: {7DD19E29-55D6-4958-A777-6386CBD9C6D1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-07] (Microsoft Corporation)
Task: {8D079AC2-5A64-4851-84F7-BDD6A8634735} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2017-12-13] (Piriform Ltd)
Task: {A20FB470-E2F1-48EE-AFEC-87676AB60B87} - System32\Tasks\SecureW2 Task => C:\Program Files (x86)\SecureW2\sw2_tray.exe [2015-06-03] (SecureW2 B.V.)
Task: {A739EB68-5D70-441D-8979-2CE396CA7913} - System32\Tasks\MATLAB R2017b Startup Accelerator => E:\Windows\Program Files\MATLAB\bin\win64\MATLABStartupAccelerator.exe [2017-07-24] ()
Task: {B97B820A-5A7F-4AEB-966E-F794B071477F} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-10] (NVIDIA Corporation)
Task: {C84714C4-A420-4538-908D-D7C47DC893A6} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-12-13] (Piriform Ltd)
Task: {D6C7F691-29A3-4595-922F-3737C45D21C0} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-10] (NVIDIA Corporation)
Task: {F5A64C33-1582-404A-860D-165C8B61D567} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-10] (NVIDIA Corporation)
Task: {FE03B55B-30D7-4BAE-9321-C57870A87C0A} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-10-10] (NVIDIA Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\MATLAB R2017b Startup Accelerator.job => E:\Windows\Program Files\MATLAB\bin\win64\MATLABStartupAccelerator.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2017-06-16 23:54 - 2017-10-10 07:20 - 002289096 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2017-07-13 19:50 - 2017-07-13 19:50 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2017-10-18 22:51 - 2017-10-18 22:51 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2017-01-06 07:30 - 2017-10-10 20:05 - 001267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2015-11-04 19:11 - 2015-11-04 19:12 - 000188072 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
2017-08-03 01:27 - 2017-10-27 11:12 - 000133752 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-03-18 15:58 - 2017-03-18 15:58 - 000138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2017-10-20 16:42 - 2017-10-20 16:42 - 000393200 _____ () C:\WINDOWS\system32\igfxTray.exe
2017-03-09 02:17 - 2017-03-09 02:17 - 000529408 _____ () C:\ProgramData\Resilio Sync\ShellExtensionOverlay64_2DC.dll
2017-03-09 02:17 - 2017-03-09 02:17 - 001222656 _____ () C:\Users\redxx\AppData\Roaming\Resilio Sync\ShellExtensionPath64_2DC.dll
2017-03-18 15:59 - 2017-03-18 21:30 - 001731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-03-06 19:07 - 2015-03-06 19:07 - 000908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2016-09-29 16:13 - 2016-09-29 16:13 - 001096824 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2015-03-06 19:07 - 2015-03-06 19:07 - 000060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2016-09-29 16:13 - 2016-09-29 16:13 - 000241784 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2017-11-20 15:27 - 2017-11-20 15:27 - 041061856 _____ () C:\Program Files (x86)\Google\Drive\googledrivesync.exe
2017-12-26 09:41 - 2017-09-04 11:27 - 001139200 _____ () C:\Program Files\SyncTrayzor\SyncTrayzor.exe
2017-12-26 09:44 - 2017-12-26 09:44 - 015295008 _____ () C:\Users\redxx\AppData\Roaming\SyncTrayzor\syncthing.exe
2017-12-11 12:13 - 2017-12-05 23:24 - 004063064 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.84\libglesv2.dll
2017-12-11 12:13 - 2017-12-05 23:24 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.84\libegl.dll
2017-01-06 07:30 - 2017-10-10 20:05 - 001040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2018-01-05 10:35 - 2018-01-05 10:35 - 000088064 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\_ctypes.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000919552 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\_hashlib.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000098816 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\win32api.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000110080 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\pywintypes27.dll
2018-01-05 10:35 - 2018-01-05 10:35 - 000364544 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\pythoncom27.dll
2018-01-05 10:35 - 2018-01-05 10:35 - 000686080 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\unicodedata.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000320512 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\win32com.shell.shell.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 001177088 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\wx._core_.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000806912 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\wx._gdi_.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000816640 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\wx._windows_.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 001067520 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\wx._controls_.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000733696 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\wx._misc_.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000736256 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\pysqlite2._sqlite.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000119808 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\win32file.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000108544 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\win32security.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000007168 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\hashobjs_ext.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000017920 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\thumbnails_ext.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000082432 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\usb_ext.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000013824 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\common.time34.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000018432 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\win32event.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000027648 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\windows.conditional.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000017408 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\windows.winwrap.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000089088 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\windows.volumes.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000167936 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\win32gui.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000046080 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\_socket.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 001311744 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\_ssl.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000129536 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\_elementtree.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000127488 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\pyexpat.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000038912 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\win32inet.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000077824 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\wx._html2.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000036864 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\_psutil_windows.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000524248 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\windows._lib_cacheinvalidation.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000011264 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\win32crypt.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000218624 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\PIL._imaging.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000027648 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\_multiprocessing.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000020480 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\_yappi.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000035840 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\win32process.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000024064 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\win32pipe.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000010240 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\select.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000025600 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\win32pdh.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000059392 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\windows.device_monitor.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000017408 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\win32profile.pyd
2018-01-05 10:35 - 2018-01-05 10:35 - 000022528 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI90602\win32ts.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000088064 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\_ctypes.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000919552 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\_hashlib.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000098816 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\win32api.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000110080 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\pywintypes27.dll
2018-01-05 10:36 - 2018-01-05 10:36 - 000364544 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\pythoncom27.dll
2018-01-05 10:36 - 2018-01-05 10:36 - 000686080 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\unicodedata.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000320512 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\win32com.shell.shell.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 001177088 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\wx._core_.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000806912 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\wx._gdi_.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000816640 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\wx._windows_.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 001067520 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\wx._controls_.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000733696 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\wx._misc_.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000736256 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\pysqlite2._sqlite.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000119808 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\win32file.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000108544 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\win32security.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000007168 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\hashobjs_ext.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000017920 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\thumbnails_ext.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000082432 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\usb_ext.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000013824 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\common.time34.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000018432 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\win32event.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000027648 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\windows.conditional.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000017408 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\windows.winwrap.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000089088 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\windows.volumes.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000167936 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\win32gui.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000046080 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\_socket.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 001311744 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\_ssl.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000129536 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\_elementtree.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000127488 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\pyexpat.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000038912 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\win32inet.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000077824 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\wx._html2.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000036864 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\_psutil_windows.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000524248 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\windows._lib_cacheinvalidation.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000011264 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\win32crypt.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000218624 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\PIL._imaging.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000027648 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\_multiprocessing.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000020480 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\_yappi.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000035840 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\win32process.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000024064 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\win32pipe.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000010240 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\select.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000025600 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\win32pdh.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000059392 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\windows.device_monitor.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000017408 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\win32profile.pyd
2018-01-05 10:36 - 2018-01-05 10:36 - 000022528 _____ () C:\Users\redxx\AppData\Local\Temp\_MEI137802\win32ts.pyd
2017-01-06 07:30 - 2017-10-10 20:05 - 070805952 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-07-10 06:04 - 2015-07-10 06:02 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857060\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857076\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\redxx\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{beeca537-2b36-4dce-b501-2b998e615dcd}.jpg
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\Control Panel\Desktop\\Wallpaper -> C:\Users\redxx\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{beeca537-2b36-4dce-b501-2b998e615dcd}.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "Razer Synapse"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "VirtualCloneDrive"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\StartupApproved\Run: => "f.lux"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\StartupApproved\Run: => "CyberGhost"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\StartupApproved\Run: => "KakaoTalk"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\StartupApproved\Run: => "OneDriveSetup"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\StartupApproved\Run: => "iCloudPhotos"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\StartupApproved\Run: => "ApplePhotoStreams"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\StartupApproved\Run: => "iCloudDrive"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\StartupApproved\Run: => "iCloudServices"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\StartupApproved\Run: => "CyberGhost"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\StartupApproved\Run: => "KakaoTalk"
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\StartupApproved\Run: => "OneDriveSetup"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{D77D8B22-EEF0-4D32-9EAD-7C2B2FBC9FD9}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{107C1A6A-F776-449B-9A20-13E919D05DA1}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{37BF57AB-D884-45B0-8B1C-54A428AAA79A}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B402CD8B-A77E-4E20-AFAF-4498A30F717A}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5EC376F3-27F0-473B-935E-08B279FBF2A2}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{319DD7F7-2093-4F35-9B59-9B25DDC6A460}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DF9C250D-5CBE-4D47-A3B5-6F5AAF1F9DFB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{DFDDC4A0-DC92-40C4-9E12-71D786BFE3B9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{DF18BFF7-37DD-463C-861E-008760D47AB2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{4D252965-6DB6-403F-8A32-4318324EFAF4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{88806735-2F34-4A91-8488-466A1E17996B}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{52018EE0-BDAB-4E4F-9F97-4998D98D9897}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{005EED2B-14BD-4FA7-ABCA-84033BD68352}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D9DAAEC2-1547-4DD0-9183-6FA85251D622}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7027BFF8-4E19-46CB-8410-9287C5C1B9A2}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DEFA5C3A-C24B-49D1-BDEC-C24F2EEDF9A9}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C914311B-F170-4E33-81AA-84E44151235D}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DCD0E9FD-6233-4E13-9391-E8CC5211E1E0}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{65CACC7F-0FCA-4C1B-A903-09A6857D741D}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1B641808-E0D6-40BB-87CC-B8E66C19BA12}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A25F98A4-C63C-4269-A57C-057D4EF5C391}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{785278BD-D5A2-4DC0-94F9-8B0F3877191B}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EF97489C-F6E6-4FE8-91AD-20483A969858}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A5B818F6-5180-4406-A629-7D05FFB78B5A}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{394E71EB-F433-4AF4-B2C7-551AC4C948DE}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E7F4C448-6227-49C2-B7B4-A7A3CFD60D25}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{390B38D8-EA52-43B2-9889-5FF770A096D0}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6FAD9EB4-6183-44C9-8B6B-C1285FBE86DD}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8FFCF7CA-4ADE-4340-944B-C4E605D6D802}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7CBA51B6-96EC-40FA-B11B-04F8FC73C3A1}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{753715B6-0695-4DBB-9997-A8220684631B}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7A31931D-3997-48A1-8226-33F5626D46F3}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{93906CBF-B58E-469F-86B4-B675B57D136C}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7897E973-2644-4844-89E3-D85BDAFC761C}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5189005A-D91F-43F2-8CCB-501A4BC19CAB}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0710BAB7-AC70-44F1-980E-D154A0648FF4}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C1808890-1BC0-407B-A742-AD5DE3000FAF}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7E259424-F363-4B0E-BB03-BC7D800B1A17}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1807CE51-5B07-4CEA-874B-31DC96E576B3}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0390794E-5B4F-4626-81B3-869A6BC17317}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8160834B-ECC0-48ED-9F5D-58C7B87E7F2A}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A4D7AA09-FAEC-4620-A4A4-1EEC397BA7E8}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{580DAFD9-DE62-40EB-AFEB-DA9E13FE4062}] => (Allow) C:\Users\redxx\AppData\Roaming\Resilio Sync\Resilio Sync.exe
FirewallRules: [{482B0F59-9758-47EA-9E97-894711F14601}] => (Allow) C:\Users\redxx\AppData\Roaming\Resilio Sync\Resilio Sync.exe
FirewallRules: [{14B1661A-E7CC-4FDC-9E72-13AADA9E813D}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{02AA469F-3EEB-4461-A282-BB22C20C0CD1}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4B72888A-38D7-48A9-B40C-55F706C87D85}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{ACED5CEC-69E0-4586-83D2-13F920895D55}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1A540AD0-A3F0-4FE8-A297-45D03CAF72D5}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{97BDFA0A-F537-4150-935E-A11835A2BD50}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{D39CE274-605C-4B70-BC8D-C8370C00E4F9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{E2D1AA32-5897-44D7-AE23-D6C69D7DCCF1}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{B7669486-D5B5-4B16-8C20-1C5B97BF8A74}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AD6B13BF-64D9-428A-92C7-B58080D29254}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8153E473-553D-42A7-927B-56AA2B51BCB0}] => (Block) C:\program files\maple 18\jre\bin\maple.exe
FirewallRules: [{3BB02CAB-C561-4E98-BA92-FA68D3F937E3}] => (Block) C:\program files\maple 18\jre\bin\maple.exe
FirewallRules: [UDP Query User{ED4FC6A1-F6CE-4E9C-84AB-C494C8379C5D}C:\program files\maple 18\jre\bin\maple.exe] => (Allow) C:\program files\maple 18\jre\bin\maple.exe
FirewallRules: [TCP Query User{31D310D1-6F56-428D-9E09-92CA0D33094F}C:\program files\maple 18\jre\bin\maple.exe] => (Allow) C:\program files\maple 18\jre\bin\maple.exe
FirewallRules: [{02128929-DC9A-4710-856A-FC81F87AE58D}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{5EFD7E50-B655-4232-827E-58743DD3F867}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{ADB2ADD2-5D46-4539-BD0F-CA5262FDCDDF}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{9761931F-0C9A-4E7E-A429-FA4D3F7584BE}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{B71D4E6E-55F8-4561-8FD3-05A13BDA5B1A}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\chivalrymedievalwarfare\Binaries\Win32\CMW.exe
FirewallRules: [{A4CA978C-0666-4AFC-9FC3-F644AFEF58A9}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\chivalrymedievalwarfare\Binaries\Win32\CMW.exe
FirewallRules: [{E6E0C7BF-BD52-4EF3-8A94-E8B18500EE82}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\chivalrymedievalwarfare\Binaries\Win64\CMW.exe
FirewallRules: [{7600A21E-9BA4-4690-A29A-3662E878C846}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\chivalrymedievalwarfare\Binaries\Win64\CMW.exe
FirewallRules: [{509C17F4-8DA1-4497-818F-BFDA7A65B5C9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{E44EA476-1521-4F21-8A0C-D3B46A996E34}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{5A4281E7-FFA6-4C93-8626-7693EE1EFA75}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{8BBD8910-B22A-40EA-B052-E6200D758912}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{860729FD-7D98-4202-AA5C-ED8443F18513}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4CB27BDD-1699-4F3E-9A88-BAA7973720BB}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{E85E66ED-8286-45A7-A7D4-F13B8E4CCDB2}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{2BFB1D1E-0BEA-40B8-B858-CAF312C0C7F3}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{C698A63F-99C0-4073-982E-2DAA09ED96DC}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{CC6222BD-B469-40AC-A0CC-8161BACFE7B4}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{F6B2F5DD-620C-493E-907F-58FC799B0BCB}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{F6E435AC-71AD-4384-80BA-1F833C3B57F7}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{724AD46A-7738-4D06-BDD9-61F11E1692FB}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{3CCDE6E9-163C-4372-883F-E9AFEDB8F314}] => (Allow) C:\Program Files (x86)\FormatFactory\FormatFactory.exe
FirewallRules: [{748B7BF1-89B7-4D03-BC08-05331725BC8C}] => (Allow) C:\Program Files (x86)\FormatFactory\FFModules\Encoder\Doc\EBookCodec.exe
FirewallRules: [{1D72DC49-967B-4AB1-8F2F-47A537E81A19}] => (Allow) C:\Program Files (x86)\FormatFactory\FormatFactory.exe
FirewallRules: [{DC4C845D-CFA6-44A9-B50D-6B15035E3C79}] => (Allow) C:\Program Files (x86)\FormatFactory\FFModules\Encoder\Doc\EBookCodec.exe
FirewallRules: [{29BB091D-13A8-4E45-A561-8DDEF4CBC23D}] => (Allow) C:\Program Files (x86)\FormatFactory\FFModules\Package\PTInstOnline.exe
FirewallRules: [{A42C1509-FCE2-44C9-935D-2071D25AC6BC}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{FA82FD6B-3A94-4A37-8A11-B988E33E014F}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [TCP Query User{CC26D7C2-6102-4BA8-92AC-E65D82CC8203}E:\windows\program files\battlenet\overwatch\overwatch\overwatch.exe] => (Allow) E:\windows\program files\battlenet\overwatch\overwatch\overwatch.exe
FirewallRules: [UDP Query User{589192CD-A5EB-4956-BACE-59F6C1B5B658}E:\windows\program files\battlenet\overwatch\overwatch\overwatch.exe] => (Allow) E:\windows\program files\battlenet\overwatch\overwatch\overwatch.exe
FirewallRules: [{CE6702B9-0D99-4FD1-9E13-4E33C80558F9}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{7E6104F8-B84B-469E-8989-37CD7A43325D}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [TCP Query User{E9D5CDA8-B1A4-4AF5-82F5-64A14D54B6F9}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [UDP Query User{CD0D9FE1-DF01-44F4-8A49-0D41DB8FA11C}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [{720C80AC-EA95-4101-84E6-0765311E59E8}] => (Allow) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{BFA562CE-01BC-40FA-98CE-3D8EEF8F8A6D}] => (Allow) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{F83793A7-B279-4426-94E5-F39FF3714E6A}] => (Allow) C:\Users\redxx\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D3C70B23-6DBC-40FA-8D2E-6A11AEBBA772}] => (Allow) C:\Users\redxx\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{6962B991-5EE9-4994-BDE4-05C81C247753}] => (Allow) C:\Users\redxx\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{457D3C4D-BE9C-4EFD-8D68-0A86B197951D}] => (Allow) C:\Users\redxx\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{75D30C1F-9E0C-4319-B7AA-2F1D631C7B83}] => (Allow) C:\Users\redxx\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{56E96628-2317-46E8-89FA-4E9676A46B51}] => (Allow) C:\Users\redxx\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{9F35D0AC-5BC5-4A4E-B1D4-09432DFD3687}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{792DF268-8DAA-4322-B284-E26320EAF45E}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{27DE51A5-6947-415E-B9CA-203C3092AE1B}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A294C69F-A8B7-4E50-B798-B2B7BAC2BB42}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{92BFC483-1D1D-4D3B-9A48-1ABB61AE507D}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D798140E-25E7-4AD7-8B2A-BE6A776629F5}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BAB8BCED-034F-4EEC-9D17-71037C107C5D}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2271BC6B-3D18-46B0-9FD0-D1FDD544F869}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{D3D0F615-8FB3-4DC8-824A-296ECE28EBBD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{DD1DCE83-FEBF-472A-8F44-8EBCBF572880}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{86C4E3AF-E300-4D7E-A3B2-4B81C3A441D4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{48A8F597-17E5-49A6-9447-8EBC5578D769}C:\program files (x86)\kakao\kakaotalk\kakaotalk.exe] => (Allow) C:\program files (x86)\kakao\kakaotalk\kakaotalk.exe
FirewallRules: [UDP Query User{DD9DD1D0-919C-42AB-B7C6-ECA3FB8B8BD8}C:\program files (x86)\kakao\kakaotalk\kakaotalk.exe] => (Allow) C:\program files (x86)\kakao\kakaotalk\kakaotalk.exe
FirewallRules: [{30479F01-3A59-46FC-AF47-AFFC208D9834}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B5E8F6FA-FA15-4C48-A680-7B1ED81F0EAA}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{895E5DC7-102B-4A69-95B0-DCE15379CB5F}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4E03367C-619F-410E-B625-07C57F4EA8FE}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{76309CBB-8615-45BE-8064-912CAA480987}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6DD81A92-5915-478E-B6D9-625D7D2EAB19}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{28D24BC9-FDE2-4BD1-8E6E-0D6DA3991215}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E853C523-E92E-491F-95DB-91DD5E8A6DB1}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{939ADE98-EF08-4B62-B9A9-F4E9EBE90464}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9A413D3A-9A92-4B00-8996-F9C5C06EBC4A}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5075A878-90E6-4761-A563-E6609705F7EC}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E0CD15B9-753E-4003-AB31-C57DB6B2B7C9}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CFF6C281-D1FF-422E-93EC-D532A697889F}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7B154DDB-EC17-4B4D-AFA1-51C6B8061423}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A76C48D6-1B6F-494B-AC5F-E7EE2D4F86C6}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{37978FF3-E418-4100-9DB8-ECF3CA285737}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{09685CFC-C003-4C63-A855-96752F3DE2BF}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F9467327-56AE-47AD-AA5A-2C4CF4FB519B}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F254D5DA-2B69-411C-B1E5-C66E1FCEC44D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{C4CD416E-AD3A-413E-9BCD-2EA9473DCA1F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{C5A1EE07-D3CD-4B0A-AC62-96A2C9FD63E5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{C98630BD-7003-4E3E-BFE7-2C351BD10FAA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{84220E13-3B65-434E-ADEA-040C6914BB95}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{6B5641B3-3598-4574-B23D-D61FBD512B77}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B5622BD6-112B-4CC8-8927-92ADEF7D1BE2}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{721FF042-3940-4BE0-9493-F07A0D906FF8}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4D059713-5296-4DC1-8E2D-AFE7785D1C65}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F3BC7ACD-3EE5-499D-8310-AA8414E93574}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BAF34C5A-055F-4158-9A59-24129177D147}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{27F7D680-0EDE-435B-9113-46BBEF54D679}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{11399319-EC46-499E-A9CD-9B2AD8888469}] => (Allow) E:\Windows\Program Files\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{F2EA5D43-46B5-450B-9D6A-DED14C0F63C1}C:\users\redxx\appdata\roaming\synctrayzor\syncthing.exe] => (Allow) C:\users\redxx\appdata\roaming\synctrayzor\syncthing.exe
FirewallRules: [UDP Query User{803DD016-6736-43E4-A2FB-220F9CDEE6D0}C:\users\redxx\appdata\roaming\synctrayzor\syncthing.exe] => (Allow) C:\users\redxx\appdata\roaming\synctrayzor\syncthing.exe

==================== Restore Points =========================

05-12-2017 17:25:59 Scheduled Checkpoint
12-12-2017 20:40:47 Windows Update
22-12-2017 09:42:27 Scheduled Checkpoint

==================== Faulty Device Manager Devices =============

Name: TAP-Windows Adapter V9
Description: TAP-Windows Adapter V9
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: TAP-Windows Provider V9
Service: tap0901
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/05/2018 10:36:04 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ISAAC-MITX-DESK)
Description: Activation of app Microsoft.Getstarted_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (12/26/2017 10:07:22 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program CCleaner64.exe version 5.38.99.6357 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 1dc8

Start Time: 01d37e5aa6be2a48

Termination Time: 9

Application Path: C:\Program Files\CCleaner\CCleaner64.exe

Report Id: d7acba3d-cfa7-476a-a628-355e827f0e18

Faulting package full name: 

Faulting package-relative application ID:

Error: (12/26/2017 12:50:31 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ISAAC-MITX-DESK)
Description: Activation of app Microsoft.Getstarted_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (12/22/2017 09:21:54 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ISAAC-MITX-DESK)
Description: Activation of app Microsoft.Getstarted_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (12/20/2017 05:58:21 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ISAAC-MITX-DESK)
Description: Activation of app Microsoft.Getstarted_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (12/20/2017 05:56:59 PM) (Source: CyberGhost 6 Service) (EventID: 0) (User: )
Description: Failed to stop service. System.NullReferenceException: Object reference not set to an instance of an object.
   at CyberGhost.VPNServices.OpenVpn.DisconnectFromVpnServer(Boolean sendDisconnectEvent) in C:\TeamCity\buildAgent\work\5e751977071a47b0\Projects\CyberGhost\CyberGhost 6\CyberGhost.VPNServices\OpenVPN.cs:line 348
   at Service.ServiceController.OnStop() in C:\TeamCity\buildAgent\work\5e751977071a47b0\Projects\CyberGhost\CyberGhost 6\CyberGhost.Service\ServiceController.cs:line 170
   at System.ServiceProcess.ServiceBase.DeferredStop()

Error: (12/20/2017 01:35:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ISAAC-MITX-DESK)
Description: Activation of app Microsoft.Getstarted_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (12/20/2017 01:35:14 PM) (Source: CyberGhost 6 Service) (EventID: 0) (User: )
Description: Failed to stop service. System.NullReferenceException: Object reference not set to an instance of an object.
   at CyberGhost.VPNServices.OpenVpn.DisconnectFromVpnServer(Boolean sendDisconnectEvent) in C:\TeamCity\buildAgent\work\5e751977071a47b0\Projects\CyberGhost\CyberGhost 6\CyberGhost.VPNServices\OpenVPN.cs:line 348
   at Service.ServiceController.OnStop() in C:\TeamCity\buildAgent\work\5e751977071a47b0\Projects\CyberGhost\CyberGhost 6\CyberGhost.Service\ServiceController.cs:line 170
   at System.ServiceProcess.ServiceBase.DeferredStop()

Error: (12/20/2017 09:09:48 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ISAAC-MITX-DESK)
Description: Activation of app Microsoft.Getstarted_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (12/19/2017 03:18:38 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ISAAC-MITX-DESK)
Description: Activation of app Microsoft.Getstarted_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.


System errors:
=============
Error: (01/05/2018 10:41:12 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NBLGGH4R32N-Microsoft.WindowsFeedbackHub.

Error: (12/26/2017 11:04:35 AM) (Source: DCOM) (EventID: 10010) (User: ISAAC-MITX-DESK)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Error: (12/26/2017 11:04:35 AM) (Source: DCOM) (EventID: 10010) (User: ISAAC-MITX-DESK)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Error: (12/26/2017 11:04:35 AM) (Source: DCOM) (EventID: 10010) (User: ISAAC-MITX-DESK)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Error: (12/26/2017 11:04:35 AM) (Source: DCOM) (EventID: 10010) (User: ISAAC-MITX-DESK)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Error: (12/26/2017 11:04:35 AM) (Source: DCOM) (EventID: 10010) (User: ISAAC-MITX-DESK)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Error: (12/26/2017 11:04:35 AM) (Source: DCOM) (EventID: 10010) (User: ISAAC-MITX-DESK)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Error: (12/26/2017 11:04:35 AM) (Source: DCOM) (EventID: 10010) (User: ISAAC-MITX-DESK)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Error: (12/26/2017 11:04:34 AM) (Source: DCOM) (EventID: 10010) (User: ISAAC-MITX-DESK)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Error: (12/26/2017 11:04:34 AM) (Source: DCOM) (EventID: 10010) (User: ISAAC-MITX-DESK)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.


CodeIntegrity:
===================================
  Date: 2018-01-05 10:49:43.081
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2018-01-05 10:49:43.077
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2018-01-05 10:49:42.871
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2018-01-05 10:49:42.869
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2018-01-05 10:49:39.846
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2018-01-05 10:49:39.846
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2018-01-05 10:36:17.935
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2018-01-05 10:36:17.934
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-12-26 10:38:05.691
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-12-26 10:38:05.690
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz
Percentage of memory in use: 51%
Total physical RAM: 8057.67 MB
Available physical RAM: 3903.97 MB
Total Virtual: 9337.67 MB
Available Virtual: 4915.9 MB

==================== Drives ================================

Drive c: (SSD) (Fixed) (Total:221.83 GB) (Free:149.16 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: () (Fixed) (Total:911.44 GB) (Free:732.02 GB) NTFS
Drive f: (Linux_Mint) (Fixed) (Total:19.53 GB) (Free:12.69 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: 00000000)

Partition: GPT.

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 43527662)
Partition 1: (Active) - (Size=221.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=873 MB) - (Type=27)
Partition 3: (Not Active) - (Size=453 MB) - (Type=27)
Partition 4: (Not Active) - (Size=450 MB) - (Type=27)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 0468D39F)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=911.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=19.5 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=450 MB) - (Type=27)

==================== End of Addition.txt ============================

 

 

 

 

FRST

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02.01.2018
Ran by redxx (administrator) on ISAAC-MITX-DESK (05-01-2018 10:50:51)
Running from C:\Users\redxx\Desktop
Loaded Profiles: redxx &  (Available Profiles: redxx)
Platform: Windows 10 Pro Version 1703 15063.786 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Reflect\ReflectService.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(CyberGhost S.R.L) C:\Program Files\CyberGhost 6\CyberGhost.Service.exe
(Microsoft Corporation) C:\Windows\System32\Eap3Host.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\NisSrv.exe
(wyDay) C:\Program Files\CyberGhost 6\wyUpdate.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
() C:\Program Files\SyncTrayzor\SyncTrayzor.exe
() C:\Users\redxx\AppData\Roaming\SyncTrayzor\syncthing.exe
(SecureW2 B.V.) C:\Program Files (x86)\SecureW2\sw2_tray.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Apple Inc.) C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-08-09] (Realtek Semiconductor)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [16293496 2016-09-29] (Logitech Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297784 2017-10-20] (Apple Inc.)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [594240 2016-01-13] (Razer Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [SecureW2 Tray] => C:\Program Files (x86)\SecureW2\sw2_tray.exe [262464 2015-06-03] (SecureW2 B.V.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\Run: [Steam] => C:\Program Files\Steam\steam.exe [3111712 2017-12-15] (Valve Corporation)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\Run: [f.lux] => C:\Users\redxx\AppData\Local\FluxSoftware\Flux\flux.exe [1678840 2017-10-10] (f.lux Software LLC)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [41061856 2017-11-20] ()
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10249048 2017-12-13] (Piriform Ltd)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\Run: [KakaoTalk] => C:\Program Files (x86)\Kakao\KakaoTalk\KakaoTalk.exe [8546112 2017-11-20] (Kakao Corp. )
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2017-10-19] (Apple Inc.)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [110392 2017-10-19] (Apple Inc.)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2017-10-19] (Apple Inc.)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\Run: [iCloudPhotos] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [356664 2017-10-19] (Apple Inc.)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\Run: [Discord] => C:\Users\redxx\AppData\Local\Discord\app-0.0.299\Discord.exe [57954808 2017-12-11] (Discord Inc.)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001\...\Run: [SyncTrayzor] => C:\Program Files\SyncTrayzor\SyncTrayzor.exe [1139200 2017-09-04] ()
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\Run: [Steam] => C:\Program Files\Steam\steam.exe [3111712 2017-12-15] (Valve Corporation)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\Run: [f.lux] => C:\Users\redxx\AppData\Local\FluxSoftware\Flux\flux.exe [1678840 2017-10-10] (f.lux Software LLC)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [41061856 2017-11-20] ()
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10249048 2017-12-13] (Piriform Ltd)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\Run: [KakaoTalk] => C:\Program Files (x86)\Kakao\KakaoTalk\KakaoTalk.exe [8546112 2017-11-20] (Kakao Corp. )
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2017-10-19] (Apple Inc.)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [110392 2017-10-19] (Apple Inc.)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2017-10-19] (Apple Inc.)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\Run: [iCloudPhotos] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [356664 2017-10-19] (Apple Inc.)
HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\...\Run: [Discord] => C:\Users\redxx\AppData\Local\Discord\app-0.0.299\Discord.exe [57954808 2017-12-11] (Discord Inc.)
GroupPolicy: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{469836f9-a4fd-4aae-aabb-f2a479f0a73b}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{53453de2-e1c6-4311-a999-9f0f2ef18af8}: [NameServer] 208.67.222.222,208.67.220.220
Tcpip\..\Interfaces\{53453de2-e1c6-4311-a999-9f0f2ef18af8}: [DhcpNameServer] 128.6.1.1
Tcpip\..\Interfaces\{e60b4a6c-b64d-4b29-98a6-04c9c8c44108}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-10-19] (Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2015-07-01] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-19] (Oracle Corporation)

FireFox:
========
FF DefaultProfile: hyk8qrmy.default
FF ProfilePath: C:\Users\redxx\AppData\Roaming\Mozilla\Firefox\Profiles\hyk8qrmy.default [2017-12-26]
FF Homepage: Mozilla\Firefox\Profiles\hyk8qrmy.default -> hxxps://www.malwarebytes.org/restorebrowser/_fs_15_52&param1=1&param2=f%3D1%26b%3DFirefox%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0B0CyD0F0FyE0FzztDtC0C0EyCtByB0EtN0D0Tzu0StCyEyDyCtN1L2XzutAtFtCyCtFtCtFtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StBtD0FtDyDtAtCyBtGtCtCtC0FtGtBtA0F0DtGyBtB0EyEtG0DtB0AzztCzzyD0FyEtCyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szy0AtA0FyEzzyDyEtG0EzzyE0BtGyE0C0AtBtG0AtByBtBtGyBtAyCyEyCtCyDtCtAyE0Fzy2QtN0A0LzuyE%26cr%3D1864604354%26a%3Dwncy_fs_15_52%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro
FF Extension: (FlashGot) - C:\Users\redxx\AppData\Roaming\Mozilla\Firefox\Profiles\hyk8qrmy.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2016-12-08] [Legacy]
FF Extension: (uBlock) - C:\Users\redxx\AppData\Roaming\Mozilla\Firefox\Profiles\hyk8qrmy.default\Extensions\{2b10c1c8-a11f-4bad-fe9c-1c11e82cac42}.xpi [2015-12-07] [Legacy]
FF Extension: (NoScript) - C:\Users\redxx\AppData\Roaming\Mozilla\Firefox\Profiles\hyk8qrmy.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2017-12-19] [Legacy]
FF Extension: (Flash and Video Download) - C:\Users\redxx\AppData\Roaming\Mozilla\Firefox\Profiles\hyk8qrmy.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}.xpi [2017-12-26]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-18] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-18] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-10-19] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-10-19] (Oracle Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-10-27] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-10-27] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)

Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_fs_15_52&param1=1&param2=f%3D1%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0B0CyD0F0FyE0FzztDtC0C0EyCtByB0EtN0D0Tzu0StCyEyDyCtN1L2XzutAtFtCyCtFtCtFtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StBtD0FtDyDtAtCyBtGtCtCtC0FtGtBtA0F0DtGyBtB0EyEtG0DtB0AzztCzzyD0FyEtCyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szy0AtA0FyEzzyDyEtG0EzzyE0BtGyE0C0AtBtG0AtByBtBtGyBtAyCyEyCtCyDtCtAyE0Fzy2QtN0A0LzuyE%26cr%3D1864604354%26a%3Dwncy_fs_15_52%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro
CHR StartupUrls: Default -> "hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_fs_15_52&param1=1&param2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0B0CyD0F0FyE0FzztDtC0C0EyCtByB0EtN0D0Tzu0StCyEyDyCtN1L2XzutAtFtCyCtFtCtFtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StBtD0FtDyDtAtCyBtGtCtCtC0FtGtBtA0F0DtGyBtB0EyEtG0DtB0AzztCzzyD0FyEtCyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szy0AtA0FyEzzyDyEtG0EzzyE0BtGyE0C0AtBtG0AtByBtBtGyBtAyCyEyCtCyDtCtAyE0Fzy2QtN0A0LzuyE%26cr%3D1864604354%26a%3Dwncy_fs_15_52%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro"
CHR NewTab: Default ->  Active:"chrome-extension://jpfpebmajhhopeonhlcgidhclcccjcik/newtab.html"
CHR Profile: C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default [2018-01-05]
CHR Extension: (Slides) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Docs) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-20]
CHR Extension: (YouTube) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-20]
CHR Extension: (Slinky Elegant) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmanlajnpdncmhfkiccmbgeocgbncfln [2017-06-25]
CHR Extension: (uBlock Origin) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-12-19]
CHR Extension: (Google Search) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-20]
CHR Extension: (Sheets) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (Speed Dial 2) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik [2017-06-25]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2017-09-22]
CHR Extension: (The Great Suspender) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbibkeccnjlkjkiokjodocebajanakg [2017-06-16]
CHR Extension: (StayFocusd) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2017-09-17]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2015-11-20]
CHR Extension: (Awesome Screenshot: Screen Video Recorder) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlipoenfbbikpbjkfpfillcgkoblgpmj [2017-12-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Gmail) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-20]
CHR Extension: (Chrome Media Router) - C:\Users\redxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-13]
CHR Profile: C:\Users\redxx\AppData\Local\Google\Chrome\User Data\System Profile [2017-12-14]
CHR HKU\S-1-5-21-3734129659-697880071-3415915633-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3734129659-697880071-3415915633-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12222017091857091\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-10-11] (Apple Inc.)
S3 celavimushost; C:\Program Files (x86)\CEVO\CSGO Client Beta\CelavimusClientHelper.exe [124120 2015-08-15] (altPUG LLC)
R2 CG6Service; C:\Program Files\CyberGhost 6\CyberGhost.Service.exe [76848 2017-02-06] (CyberGhost S.R.L)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [365040 2017-10-20] (Intel Corporation)
R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193656 2016-09-29] (Logitech Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-21] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-10] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-10] (NVIDIA Corporation)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [188072 2015-11-04] ()
R2 ReflectService.exe; C:\Program Files\Macrium\Reflect\ReflectService.exe [3476432 2015-10-12] (Paramount Software UK Ltd)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-03-18] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10803440 2017-07-26] (TeamViewer GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\NisSrv.exe [356176 2017-12-07] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe [105792 2017-12-07] (Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AsrDrv101; C:\WINDOWS\SysWOW64\Drivers\AsrDrv101.sys [22280 2017-04-13] (ASRock Incorporation)
S3 i8042HDR; C:\WINDOWS\system32\DRIVERS\i8042HDR.sys [15920 2009-08-14] (Windows (R) Codename Longhorn DDK provider)
R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech)
R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2016-09-29] (Logitech Inc.)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [252232 2017-12-20] (Malwarebytes)
R1 MpKsleda8d5b5; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9778C618-9C7C-48CC-8756-0D8643D29FDB}\MpKsleda8d5b5.sys [58120 2018-01-05] (Microsoft Corporation)
R3 netr28ux; C:\WINDOWS\System32\drivers\netr28ux.sys [2224128 2017-03-18] (MediaTek Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_2e7fa54192fe16d0\nvlddmkm.sys [16936048 2017-11-09] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-10-10] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [50624 2017-10-10] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-10-10] (NVIDIA Corporation)
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-09-22] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [130880 2015-12-14] (Razer, Inc.)
S3 Scarlett_UAC2Audio; C:\WINDOWS\system32\DRIVERS\Scarlett_UAC2Audio.sys [93568 2014-10-02] (Focusrite Audio Engineering Limited.)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 USBTINSP; C:\WINDOWS\System32\drivers\tinspusb.sys [142848 2010-03-29] (Texas Instruments)
R1 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [131144 2017-04-28] (Oracle Corporation)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [205952 2017-04-28] (Oracle Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46072 2017-12-07] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [288848 2017-12-07] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [129616 2017-12-07] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-05 10:50 - 2018-01-05 10:51 - 000024438 _____ C:\Users\redxx\Desktop\FRST.txt
2018-01-05 10:50 - 2018-01-05 10:49 - 002393088 _____ (Farbar) C:\Users\redxx\Desktop\FRST64.exe
2017-12-26 09:44 - 2017-12-26 10:00 - 000000000 ____D C:\Users\redxx\AppData\Local\Syncthing
2017-12-26 09:44 - 2017-12-26 09:45 - 000000000 ____D C:\Users\redxx\Sync
2017-12-26 09:44 - 2017-12-26 09:44 - 000000000 ____D C:\Users\redxx\AppData\Local\SyncTrayzor
2017-12-26 09:41 - 2018-01-05 10:36 - 000000000 ____D C:\Users\redxx\AppData\Roaming\SyncTrayzor
2017-12-26 09:41 - 2017-12-26 09:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SyncTrayzor
2017-12-26 09:41 - 2017-12-26 09:41 - 000000000 ____D C:\Program Files\SyncTrayzor
2017-12-26 07:56 - 2017-12-26 07:56 - 000003938 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2017-12-21 00:55 - 2017-12-21 00:55 - 000000000 ____D C:\Users\redxx\AppData\Local\Discord
2017-12-20 20:21 - 2017-12-21 00:55 - 000000000 ____D C:\Users\redxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2017-12-20 20:21 - 2017-12-21 00:55 - 000000000 ____D C:\Users\redxx\AppData\Local\SquirrelTemp
2017-12-20 20:21 - 2017-12-20 22:12 - 000000000 ____D C:\Users\redxx\AppData\Roaming\discord
2017-12-20 17:56 - 2017-12-22 09:41 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2017-12-20 17:54 - 2017-12-20 17:56 - 000000000 ____D C:\AdwCleaner
2017-12-20 09:16 - 2018-01-05 10:50 - 000000000 ____D C:\FRST
2017-12-19 17:56 - 2017-12-20 17:56 - 092012544 _____ C:\WINDOWS\system32\config\SOFTWARE
2017-12-12 20:39 - 2017-11-29 22:00 - 002166808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-12-12 20:39 - 2017-11-29 21:58 - 006763128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-12-12 20:39 - 2017-11-29 21:58 - 000702032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2017-12-12 20:39 - 2017-11-29 21:57 - 001123968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2017-12-12 20:39 - 2017-11-29 21:44 - 019334144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-12-12 20:39 - 2017-11-29 21:43 - 020511232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-12-12 20:39 - 2017-11-29 21:43 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-12-12 20:39 - 2017-11-29 21:43 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-12-12 20:39 - 2017-11-29 21:42 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2017-12-12 20:39 - 2017-11-29 21:42 - 000100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscript.ocx
2017-12-12 20:39 - 2017-11-29 21:42 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-12-12 20:39 - 2017-11-29 21:41 - 000146944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscript.exe
2017-12-12 20:39 - 2017-11-29 21:40 - 000528384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2017-12-12 20:39 - 2017-11-29 21:40 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrobj.dll
2017-12-12 20:39 - 2017-11-29 21:40 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscript.exe
2017-12-12 20:39 - 2017-11-29 21:39 - 011888640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-12-12 20:39 - 2017-11-29 21:38 - 001248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-12-12 20:39 - 2017-11-29 21:38 - 000636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-12-12 20:39 - 2017-11-29 21:38 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-12-12 20:39 - 2017-11-29 21:37 - 006252544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-12-12 20:39 - 2017-11-29 21:37 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-12-12 20:39 - 2017-11-29 21:36 - 003652096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-12-12 20:39 - 2017-11-29 21:36 - 001019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-12-12 20:39 - 2017-11-29 21:36 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2017-12-12 20:39 - 2017-11-29 21:35 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-12-12 20:39 - 2017-11-29 21:34 - 004559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-12-12 20:39 - 2017-11-17 04:31 - 000223640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2017-12-12 20:39 - 2017-11-17 04:00 - 002953216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-12-12 20:35 - 2017-11-29 22:24 - 000870896 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2017-12-12 20:35 - 2017-11-29 22:23 - 007910960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-12-12 20:35 - 2017-11-29 21:45 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-12-12 20:35 - 2017-11-29 21:44 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2017-12-12 20:35 - 2017-11-29 21:44 - 000042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
2017-12-12 20:35 - 2017-11-29 21:43 - 000164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
2017-12-12 20:35 - 2017-11-29 21:42 - 001878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-12-12 20:35 - 2017-11-29 21:42 - 000164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscript.exe
2017-12-12 20:35 - 2017-11-29 21:41 - 000527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-12-12 20:35 - 2017-11-29 21:41 - 000222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrobj.dll
2017-12-12 20:35 - 2017-11-29 21:40 - 000585216 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-12-12 20:35 - 2017-11-29 21:38 - 008195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-12-12 20:35 - 2017-11-29 21:38 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-12-12 20:35 - 2017-11-29 21:37 - 001293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-12-12 20:35 - 2017-11-29 21:36 - 005557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-12-12 20:35 - 2017-11-29 21:36 - 004726784 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-12-12 20:35 - 2017-11-29 21:36 - 001398784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2017-12-12 20:35 - 2017-11-29 21:36 - 000755200 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2017-12-12 20:35 - 2017-11-17 04:37 - 021353200 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-12-12 20:35 - 2017-11-17 04:03 - 003668992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-12-12 20:35 - 2017-11-17 03:59 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-12-12 20:34 - 2017-11-29 22:33 - 000038808 _____ (Microsoft Corporation) C:\WINDOWS\system32\OOBEUpdater.exe
2017-12-12 20:34 - 2017-11-29 22:29 - 008319384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-12-12 20:34 - 2017-11-29 22:23 - 001194248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2017-12-12 20:34 - 2017-11-29 21:42 - 000560640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2017-12-12 20:34 - 2017-11-29 21:41 - 000414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2017-12-12 20:34 - 2017-11-29 21:39 - 000925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-12-12 20:34 - 2017-11-17 04:39 - 005477088 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-12-12 20:34 - 2017-11-17 04:39 - 000643200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-12-12 20:34 - 2017-11-17 03:56 - 000757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2017-12-12 20:33 - 2017-11-29 22:26 - 002647216 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-12-12 20:33 - 2017-11-29 21:59 - 023678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-12-12 20:33 - 2017-11-29 21:45 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-12-12 20:33 - 2017-11-29 21:44 - 023679488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-12-12 20:33 - 2017-11-29 21:44 - 000171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2017-12-12 20:33 - 2017-11-29 21:42 - 000304640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2017-12-12 20:33 - 2017-11-29 21:41 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-12-12 20:33 - 2017-11-29 21:40 - 012803072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-12-12 20:33 - 2017-11-29 21:39 - 002809344 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-12-12 20:33 - 2017-11-29 21:37 - 003306496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-12-12 20:33 - 2017-11-29 21:36 - 001802240 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-12-12 20:33 - 2017-11-17 04:46 - 002032536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2017-12-12 20:33 - 2017-11-17 04:46 - 001578904 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-12-12 20:33 - 2017-11-17 04:46 - 000678808 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-12-12 20:33 - 2017-11-17 04:46 - 000613784 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-12-12 20:33 - 2017-11-17 04:46 - 000612248 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-12-12 20:33 - 2017-11-17 04:46 - 000484248 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-12-12 20:33 - 2017-11-17 04:46 - 000379288 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-12-12 20:33 - 2017-11-17 04:46 - 000190360 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-12-12 20:33 - 2017-11-17 04:46 - 000136088 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-12-12 20:33 - 2017-11-17 04:46 - 000067992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2017-12-12 20:33 - 2017-11-17 04:46 - 000034712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-12-12 20:32 - 2017-11-29 22:33 - 001144728 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-12-12 20:32 - 2017-11-29 22:33 - 001015704 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-12-12 20:32 - 2017-11-29 21:39 - 003206656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
2017-12-12 20:32 - 2017-11-17 04:46 - 000821656 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2017-12-12 20:32 - 2017-11-17 04:46 - 000259992 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-12-12 20:32 - 2017-11-17 04:41 - 000503704 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-05 15:35 - 2017-08-03 01:27 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2018-01-05 15:35 - 2015-08-09 23:12 - 000000000 __SHD C:\Users\redxx\IntelGraphicsProfiles
2018-01-05 10:41 - 2017-03-18 16:03 - 000000000 ___HD C:\Program Files\WindowsApps
2018-01-05 10:41 - 2017-03-18 16:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-01-05 10:40 - 2017-08-03 01:31 - 000004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{E85BEA25-B1EA-4938-9366-896158D02C65}
2018-01-05 10:40 - 2017-08-03 01:27 - 000000000 ____D C:\ProgramData\NVIDIA
2018-01-05 10:37 - 2017-05-24 10:49 - 000000000 ___RD C:\Users\redxx\Google Drive
2017-12-26 10:21 - 2017-01-20 10:19 - 000000000 ____D C:\Users\redxx\AppData\LocalLow\Mozilla
2017-12-26 10:21 - 2015-08-12 22:30 - 000000000 ____D C:\Users\redxx\AppData\Roaming\Mozilla
2017-12-26 10:20 - 2017-04-04 15:04 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-12-26 10:20 - 2015-08-11 22:46 - 000000000 ____D C:\Users\redxx\Desktop\Usually Useless
2017-12-26 10:20 - 2015-08-09 23:16 - 000001231 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-12-26 10:20 - 2015-08-09 23:16 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-12-26 10:02 - 2017-03-09 02:17 - 000000000 ____D C:\Users\redxx\AppData\Roaming\Resilio Sync
2017-12-26 09:44 - 2017-08-03 01:28 - 000000000 ____D C:\Users\redxx
2017-12-26 09:27 - 2015-08-15 22:00 - 000000000 ____D C:\Users\redxx\AppData\Roaming\MPC-HC
2017-12-26 09:19 - 2017-03-18 16:01 - 000000000 ____D C:\WINDOWS\INF
2017-12-26 09:19 - 2015-08-09 23:15 - 000000000 ____D C:\Program Files\Steam
2017-12-26 08:01 - 2015-08-11 22:46 - 000000000 ____D C:\Users\redxx\Desktop\Always
2017-12-26 07:56 - 2017-07-19 06:27 - 000000000 ____D C:\Program Files\CCleaner
2017-12-22 09:41 - 2017-08-03 01:27 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-12-22 09:20 - 2017-11-01 22:00 - 000000000 ___RD C:\Users\redxx\iCloudDrive
2017-12-22 09:20 - 2017-08-18 08:30 - 001064938 _____ C:\WINDOWS\system32\perfh012.dat
2017-12-22 09:20 - 2017-08-18 08:30 - 000303634 _____ C:\WINDOWS\system32\perfc012.dat
2017-12-22 09:20 - 2017-08-03 01:33 - 003071844 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-12-20 17:56 - 2017-10-10 07:20 - 000252232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2017-12-20 17:56 - 2017-08-03 01:31 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-12-20 17:56 - 2017-03-18 06:40 - 001310720 _____ C:\WINDOWS\system32\config\BBI
2017-12-20 10:54 - 2016-12-29 20:48 - 000000000 ____D C:\Users\redxx\Desktop\reads____books
2017-12-19 17:54 - 2017-03-29 04:25 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
2017-12-19 15:07 - 2017-03-18 16:03 - 000000000 ____D C:\WINDOWS\rescache
2017-12-13 22:39 - 2015-08-09 23:12 - 000000000 ____D C:\Users\redxx\AppData\Local\Packages
2017-12-13 20:29 - 2017-02-27 00:17 - 000000000 ____D C:\Users\redxx\AppData\Roaming\TeamViewer
2017-12-13 20:29 - 2015-12-29 20:01 - 000000000 ____D C:\Users\redxx\AppData\Local\CrashDumps
2017-12-13 20:29 - 2015-12-24 16:14 - 000000000 ____D C:\Users\redxx\AppData\Roaming\uTorrent
2017-12-13 00:18 - 2016-11-20 13:54 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-12-13 00:11 - 2017-08-03 01:27 - 000491664 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-12-13 00:11 - 2017-08-03 01:27 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-12-13 00:10 - 2017-06-16 18:44 - 000000000 ___SD C:\WINDOWS\UpdateAssistantV2
2017-12-13 00:10 - 2017-03-18 16:03 - 000000000 ____D C:\WINDOWS\system32\oobe
2017-12-12 22:38 - 2017-08-03 01:31 - 000004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-12 22:38 - 2017-08-03 01:31 - 000004000 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-12 22:38 - 2017-08-03 01:31 - 000003940 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-12 22:38 - 2017-08-03 01:31 - 000003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-12 22:38 - 2017-08-03 01:31 - 000003866 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-12 22:38 - 2017-08-03 01:31 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-12 22:38 - 2017-08-03 01:31 - 000003696 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-12 22:38 - 2017-08-03 01:31 - 000003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-12 22:38 - 2017-08-03 01:27 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2017-12-12 22:38 - 2017-08-03 01:27 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2017-12-12 20:43 - 2017-08-03 01:27 - 000000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2017-12-12 20:43 - 2017-08-03 01:27 - 000000000 ____D C:\Program Files\Intel
2017-12-12 20:43 - 2017-03-18 15:51 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-12-12 20:42 - 2015-08-11 18:57 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-12-12 20:41 - 2017-10-11 11:11 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2017-12-12 20:41 - 2015-08-11 18:57 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-12-12 20:11 - 2017-11-20 08:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2017-12-11 12:14 - 2015-08-09 23:15 - 000002275 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-12-06 14:32 - 2015-08-10 23:22 - 000000000 ____D C:\Users\redxx\AppData\Local\NVIDIA

==================== Files in the root of some directories =======

2015-12-27 14:27 - 2015-12-27 14:27 - 000000041 _____ () C:\Users\redxx\AppData\Roaming\WB.CFG
2017-10-09 07:18 - 2017-10-09 07:18 - 000000000 _____ () C:\Users\redxx\AppData\Local\Driver_AR8171Present.flag
2016-01-29 13:02 - 2016-01-29 13:02 - 000001749 _____ () C:\Users\redxx\AppData\Local\recently-used.xbel
2016-01-02 13:08 - 2016-01-02 13:08 - 000007602 _____ () C:\Users\redxx\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-12-19 15:07

==================== End of FRST.txt ============================

 

 

Addition.txt

FRST.txt

Link to post
Share on other sites

Aura,

Everything is cleaned up now, except I still get one item that isn't being quarantined properly :/.

 

Fixlog attached.

 

Fixlog

Fix result of Farbar Recovery Scan Tool (x64) Version: 02.01.2018
Ran by redxx (06-01-2018 11:31:25) Run:1
Running from C:\Users\redxx\Desktop
Loaded Profiles: redxx &  (Available Profiles: redxx)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:

CHR HomePage: Default -> hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_fs_15_52&param1=1&param2=f%3D1%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0B0CyD0F0FyE0FzztDtC0C0EyCtByB0EtN0D0Tzu0StCyEyDyCtN1L2XzutAtFtCyCtFtCtFtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StBtD0FtDyDtAtCyBtGtCtCtC0FtGtBtA0F0DtGyBtB0EyEtG0DtB0AzztCzzyD0FyEtCyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szy0AtA0FyEzzyDyEtG0EzzyE0BtGyE0C0AtBtG0AtByBtBtGyBtAyCyEyCtCyDtCtAyE0Fzy2QtN0A0LzuyE%26cr%3D1864604354%26a%3Dwncy_fs_15_52%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro
CHR StartupUrls: Default -> "hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_fs_15_52&param1=1&param2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0B0CyD0F0FyE0FzztDtC0C0EyCtByB0EtN0D0Tzu0StCyEyDyCtN1L2XzutAtFtCyCtFtCtFtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StBtD0FtDyDtAtCyBtGtCtCtC0FtGtBtA0F0DtGyBtB0EyEtG0DtB0AzztCzzyD0FyEtCyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szy0AtA0FyEzzyDyEtG0EzzyE0BtGyE0C0AtBtG0AtByBtBtGyBtAyCyEyCtCyDtCtAyE0Fzy2QtN0A0LzuyE%26cr%3D1864604354%26a%3Dwncy_fs_15_52%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro"

EmptyTemp:
*****************

Processes closed successfully.
"Chrome HomePage" => removed successfully
"Chrome StartupUrls" => removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 9199616 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 94376082 B
Java, Flash, Steam htmlcache => 799845979 B
Windows/system/drivers => 108638 B
Edge => 1296 B
Chrome => 482254900 B
Firefox => 17636508 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 898 B
redxx => 252937454 B

RecycleBin => 119908 B
EmptyTemp: => 1.5 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 11:31:49 ====

Fixlog.txt

Edited by redxxfour
Link to post
Share on other sites

Due to the lack of feedback, this topic is closed to prevent others from posting here.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this topic. Other members who need assistance please start your own topic in a new thread.

Thanks

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.