Jump to content
Hmmmm

PUP.optional removal issues

Recommended Posts

Hi,

I am trying to save a friends laptop. 

Having run Trends micro online scan and Malwarebytes, that seems to have helped, there is also Avast antivirus on the laptop . The initial Malwarebytes scan could not deal with 3 files. I have since run Malwarebytes twice more in the last 24 hrs. It has picked up increasing amounts of issue (nowhere near as much as the first scan), always with a couple of files that cannot be removed. I guess there is a deeper issue that requires solving.

Any help would be appreciated

Thanks

Share this post


Link to post
Share on other sites

Hello, Welcome to Malwarebytes.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Download the Farbar Recovery Scan Tool (FRST).
Choose the 32 or 64 bit version for your system.
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file:
In the Reply section in the bottom of the topic Select Click the Choose a File.
Navigate to the location of the File.
Click the file. It will appear in section.
Click the Saving button.

Please post the logs for my review.

Wait for further instructions
====

p.s.
If this computer is synced with other devices let me know which browser is involved.

Share this post


Link to post
Share on other sites

Thanks,

FRST:
 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-10-2019
Ran by Welcome (administrator) on WELCOME-HP (Hewlett-Packard HP Pavilion g6 Notebook PC) (20-10-2019 16:22:56)
Running from C:\Users\Welcome\Desktop
Loaded Profiles: Welcome (Available Profiles: Welcome)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Alcatel-Lucent USA -> Alcatel-Lucent) C:\Program Files (x86)\Common Files\Motive\pcCMService.exe
(Alcatel-Lucent USA -> Alcatel-Lucent) C:\Program Files\Common Files\Motive\pcCMService.exe
(Alcatel-Lucent) [File not signed] C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\bin\MAHostService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.154.333\AvastBrowserCrashHandler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.154.333\AvastBrowserCrashHandler64.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(CyberLink -> CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(EasyBits Software AS -> EasyBits Software AS) [File not signed] C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Company -> Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
(Hewlett-Packard Company -> Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPConnectionManager.exe
(Hewlett-Packard Company -> Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Hewlett-Packard Company -> Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Hewlett-Packard Company -> Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Hewlett-Packard Company -> HP) C:\Windows\System32\HPSIsvc.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Huawei Technologies Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(Joyent, Inc) [File not signed] C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\bin\node.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVCM.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Piriform Software Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TunnelBear -> TunnelBear) C:\Program Files (x86)\TunnelBear\TunnelBear.Maintenance.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1424896 2011-12-01] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [268680 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-04-30] (Intel Corporation -> Intel Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [HPConnectionManager] => C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [103992 2011-09-13] (Hewlett-Packard Company -> Hewlett-Packard Development Company L.P.)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Company -> Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Company -> Hewlett-Packard Development Company, L.P.)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2010538318-109841488-92881702-1000\...\Run: [Google Update] => C:\Users\Welcome\AppData\Local\Google\Update\1.3.35.301\GoogleUpdateCore.exe [1107752 2019-10-17] (Google Inc -> Google LLC)
HKU\S-1-5-21-2010538318-109841488-92881702-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-2010538318-109841488-92881702-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-2010538318-109841488-92881702-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-2010538318-109841488-92881702-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2010538318-109841488-92881702-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-2010538318-109841488-92881702-1000\...\MountPoints2: {502d0a7d-74a7-11e9-9fa5-101f74baa827} - G:\HiSuiteDownLoader.exe
HKU\S-1-5-21-2010538318-109841488-92881702-1000\...\MountPoints2: {e613bd0e-907e-11e5-8968-101f74baa827} - G:\AutoRun.exe
HKU\S-1-5-21-2010538318-109841488-92881702-1000\...\MountPoints2: {e613bd24-907e-11e5-8968-101f74baa827} - G:\AutoRun.exe
HKU\S-1-5-21-2010538318-109841488-92881702-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-21] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2019-05-03] (Adobe Inc. -> Adobe Systems, Inc.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\77.0.1801.76\Installer\chrmstp.exe [2019-10-17] (AVAST Software s.r.o. -> AVAST Software)
HKLM\Software\...\Authentication\Credential Providers: [{4DA7114C-DE47-43BF-A644-62876DCC2A72}] -> C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDCREDPROV.DLL [2012-05-17] (Microsoft Corporation -> Microsoft Corp.)
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
AppInit_DLLs: C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\IEBHO.dll => C:\Program Files (x86)\SearchCore for Browsers\SearchCore for Browsers\x64\IEBHO.dll [1790872 2011-09-27] (Bandoo Media, Inc. -> Bandoo Media, inc)
AppInit_DLLs: DLL => No File
GroupPolicy\User: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {125C4797-EEB7-432C-9029-DE58E79DCBE6} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-17] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {14012C0F-9395-402C-B8E6-BA215BF9FA0F} - System32\Tasks\{293A7AA4-85AF-4E0B-A2B7-E06E589C866A} => "c:\users\welcome\appdata\local\google\chrome\application\chrome.exe" hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?page=tsProgressBar
Task: {25661166-C0F8-4885-A27C-058F714A9D00} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_270_Plugin.exe [1457720 2019-10-17] (Adobe Inc. -> Adobe)
Task: {2BB9E711-60D8-4FAD-BDA2-78310DC94DC2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-17] (Piriform Software Ltd -> Piriform Ltd)
Task: {4AEEEBF4-BDEB-4B4B-A273-9971AE1358C8} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2019-01-27] (AVAST Software s.r.o. -> AVAST Software)
Task: {5168796A-06B6-416E-A30B-C7D5885AA7FE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2010538318-109841488-92881702-1000Core => C:\Users\Welcome\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-09-01] (Google Inc -> Google Inc.)
Task: {657546E4-7413-4FCE-9485-CB3F184E3AB6} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1852624 2019-09-19] (AVAST Software s.r.o. -> AVAST Software)
Task: {686EE93D-6E66-460B-BC6F-36C28A33FCC8} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2011-03-22] (CyberLink -> CyberLink)
Task: {6B5D2924-5166-49C9-A02C-5D1802815435} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [561984 2011-06-01] (Apple Inc. -> Apple Inc.)
Task: {83979EC0-E0F9-4505-9559-902BCF951749} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2010538318-109841488-92881702-1000Core => C:\Users\Welcome\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-08-18] (Facebook, Inc. -> Facebook Inc.)
Task: {941C4740-A182-4245-8D9A-A80311764861} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [655736 2019-07-31] (HP Inc. -> HP Inc.)
Task: {945CDEBB-08C6-449B-92B6-B75E7F7D8AAA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [136056 2019-01-02] (HP Inc. -> HP Inc.)
Task: {9648D601-0D4B-461E-9DA0-5BE1349DB17D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc -> Google Inc.)
Task: {96A99A87-4591-4CF3-A201-B08B7F0BD87B} - System32\Tasks\Games\UpdateCheck_S-1-5-21-2010538318-109841488-92881702-1000 => {CA22F5B1-E06F-4A2B-94FC-21E87FE53781} C:\Windows\System32\gameux.dll [2746368 2012-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {B13B53B4-035C-4EA3-A78E-990B7E89BB74} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1240656 2019-09-10] (Adobe Inc. -> Adobe Systems)
Task: {B5520D01-6C07-464A-9E6D-75F229C23082} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {B62A9996-ED49-4595-AC31-59BF06817BF7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc -> Google Inc.)
Task: {CB5AFB97-E036-4280-85DF-04D58E821B55} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
Task: {D0F1239E-E2B6-445C-BCDF-2928D28A21F3} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2010538318-109841488-92881702-1000UA => C:\Users\Welcome\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-09-01] (Google Inc -> Google Inc.)
Task: {E4C70794-7A2F-4719-8FC8-09833A4AECCF} - System32\Tasks\{47C1EE03-DBDC-4F69-8684-8A725843FA1A} => C:\Windows\system32\pcalua.exe -a C:\Users\Welcome\Downloads\JWatcher+Video_V1.0JVM.exe -d C:\Users\Welcome\Downloads
Task: {E89BD3F7-41CF-4654-8E91-6C57E84CA97A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-10-17] (Adobe Inc. -> Adobe)
Task: {EAE0F588-4EE7-4BD9-B76B-E7DFD17D7F55} - System32\Tasks\{A41BF357-791A-42BB-BEA2-ADD1DBC0FCB7} => "c:\users\welcome\appdata\local\google\chrome\application\chrome.exe" hxxp://ui.skype.com/ui/0/5.1.0.104.161/en/go/help.faq.installer?LastError=1603
Task: {ED21B650-7C5E-4D83-B299-A7DA516CEA2C} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1852624 2019-09-19] (AVAST Software s.r.o. -> AVAST Software)
Task: {F76F476C-8026-48F9-8289-72391A183B14} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2010538318-109841488-92881702-1000UA => C:\Users\Welcome\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-08-18] (Facebook, Inc. -> Facebook Inc.)
Task: {FCE917A6-BF3D-42B2-9F0D-654C833459CF} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2019-01-27] (AVAST Software s.r.o. -> AVAST Software)
Task: {FD8C2181-CC81-4B8C-9204-B496000F4169} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1873288 2019-09-26] (AVAST Software s.r.o. -> AVAST Software)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2010538318-109841488-92881702-1000Core.job => C:\Users\Welcome\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2010538318-109841488-92881702-1000UA.job => C:\Users\Welcome\AppData\Local\Facebook\Update\FacebookUpdate.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{463A4814-E4CC-435D-87FA-F137CB6FA0A8}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{A641B911-487C-443F-B4FF-6CDE8A3D9C18}: [DhcpNameServer] 192.168.9.1 192.168.9.1
Tcpip\..\Interfaces\{D00198CA-4033-4CFB-9286-8C5256FCB8D6}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{D00198CA-4033-4CFB-9286-8C5256FCB8D6}: [DhcpNameServer] 192.168.1.254

Internet Explorer:
==================
HKU\S-1-5-21-2010538318-109841488-92881702-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/2
SearchScopes: HKLM -> DefaultScope {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {AFCC1A2E-D835-4FA6-B310-14D72BF837AF} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {AFCC1A2E-D835-4FA6-B310-14D72BF837AF} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-2010538318-109841488-92881702-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://mysearch.avg.com/search?cid={3CE8158B-FB5F-45C0-A03E-35A1F3D2181A}&mid=04d94a9cb0f847d298e5c156325e41d4-6bf6cc12e5c00251fc9290e050c22011984caa45&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-01-18 13:24:51&v=17.3.1.91&pid=safeguard&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2010538318-109841488-92881702-1000 -> {AFCC1A2E-D835-4FA6-B310-14D72BF837AF} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-2010538318-109841488-92881702-1000 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKU\S-1-5-21-2010538318-109841488-92881702-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
BHO: No Name -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\ssv.dll [2019-08-03] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17] (Skype Technologies SA -> Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\jp2ssv.dll [2019-08-03] (Oracle America, Inc. -> Oracle Corporation)
Toolbar: HKLM - No Name - !{3042df7a-e900-4389-9b94-923df0daa57e} -  No File
Toolbar: HKLM - No Name - !{98889811-442D-49dd-99D7-DC866BE87DBC} -  No File
Toolbar: HKLM - No Name - !{D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Toolbar: HKLM-x32 - No Name - !{3042df7a-e900-4389-9b94-923df0daa57e} -  No File
Toolbar: HKLM-x32 - No Name - !{98889811-442D-49dd-99D7-DC866BE87DBC} -  No File
Toolbar: HKLM-x32 - No Name - !{D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17] (Skype Technologies SA -> Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -  No File

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_270.dll [2019-10-17] (Adobe Inc. -> )
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_270.dll [2019-10-17] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1234204.dll [2018-06-06] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-10-01] (Apple Inc. -> )
FF Plugin-x32: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-08-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-08-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Motive.com/NpMotive,version=1.0 -> C:\Program Files (x86)\Common Files\Motive\npMotive.dll [2012-10-05] (Alcatel-Lucent) [File not signed]
FF Plugin-x32: @Motive.com/npMotiveRequest,version=1.0 -> C:\Program Files (x86)\Common Files\Motive\npMotiveRequest.dll [2011-12-06] (Alcatel-Lucent) [File not signed]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.301\npGoogleUpdate3.dll [2019-10-17] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.301\npGoogleUpdate3.dll [2019-10-17] (Google Inc -> Google LLC)
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-10-16] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2010538318-109841488-92881702-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Welcome\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Software Sarl -> Skype Limited)
FF Plugin HKU\S-1-5-21-2010538318-109841488-92881702-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Welcome\AppData\Local\Google\Update\1.3.35.301\npGoogleUpdate3.dll [2019-10-17] (Google Inc -> Google LLC)
FF Plugin HKU\S-1-5-21-2010538318-109841488-92881702-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Welcome\AppData\Local\Google\Update\1.3.35.301\npGoogleUpdate3.dll [2019-10-17] (Google Inc -> Google LLC)

Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://intranet.bangor.ac.uk/
CHR StartupUrls: Default -> "hxxps://www.ecosia.org/"
CHR NewTab: Default ->  Not-active:"chrome-extension://eedlgdlajadkbbjoobobefphmfkcchfk/newtab.html"
CHR Profile: C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Default [2019-10-20]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-03-16]
CHR Extension: (YouTube) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Ecosia Omnibar Redirect (Legacy)) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Default\Extensions\clellnciejhoedgepbdilbkdkaoecgpc [2017-05-18]
CHR Extension: (Google Search) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Ecosia Search) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Default\Extensions\eedlgdlajadkbbjoobobefphmfkcchfk [2019-10-18]
CHR Extension: (AdBlock) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2019-10-19]
CHR Extension: (Google Scholar Button) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldipcbpaocekfooobnbcddclnhejkcpn [2017-10-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-19]
CHR Extension: (Gmail) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-05-19]
CHR Extension: (Chrome Media Router) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-10-19]
CHR Profile: C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-10-19]
CHR Profile: C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1 [2019-10-19]
CHR Extension: (Google Slides) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-23]
CHR Extension: (Duolingo on the Web) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aiahmijlpehemcpleichkcokhegllfjl [2015-02-23]
CHR Extension: (Google Docs) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-23]
CHR Extension: (Google Drive) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-23]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-02-23]
CHR Extension: (YouTube) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-23]
CHR Extension: (Google Search) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-23]
CHR Extension: (Google Sheets) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-23]
CHR Extension: (AdBlock) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-02-23]
CHR Extension: (Skype Click to Call) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-02-23]
CHR Extension: (Google Wallet) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-23]
CHR Extension: (Gmail) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-23]
CHR Extension: (Ask Toolbar) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pljcgbedjplidkdjahbaalanadmjfgop [2015-02-23]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-01-17]
StartMenuInternet: Google Chrome - C:\Users\Welcome\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6085360 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2019-01-27] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [996880 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2019-01-27] (AVAST Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\77.0.1801.76\elevation_service.exe [984920 2019-09-19] (AVAST Software s.r.o. -> AVAST Software)
R2 BT Help Wizard; C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\bin\MAHostService.exe [321024 2014-04-09] (Alcatel-Lucent) [File not signed]
R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS -> EasyBits Software AS) [File not signed]
R2 HPSIService; C:\Windows\system32\HPSIsvc.exe [127800 2010-04-07] (Hewlett-Packard Company -> HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [358264 2019-08-07] (HP Inc. -> HP Inc.)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2018-10-22] (Huawei Technologies Co., Ltd. -> ) [File not signed]
S2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2425960 2012-04-19] (Realtek Semiconductor Corp -> Realsil Microelectronics Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
R2 msoidsvc; C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE [2079520 2012-05-17] (Microsoft Corporation -> Microsoft Corp.)
R2 pcCMService64; C:\Program Files\Common Files\Motive\pcCMService.exe [467256 2013-11-11] (Alcatel-Lucent USA -> Alcatel-Lucent)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [305152 2011-12-01] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
R2 TunnelBearMaintenance; C:\Program Files (x86)\TunnelBear\TunnelBear.Maintenance.exe [139896 2019-06-19] (TunnelBear -> TunnelBear)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [37616 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [204824 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [274456 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [209552 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [65120 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [276952 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [42736 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [171520 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110320 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [83792 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [854696 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [463584 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [236024 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [316528 2019-10-13] (AVAST Software s.r.o. -> AVAST Software)
R3 clwvd; C:\Windows\System32\DRIVERS\clwvd.sys [31088 2010-07-28] (CyberLink -> CyberLink Corporation)
S3 ew_usbccgpfilter; C:\Windows\System32\DRIVERS\ew_usbccgpfilter.sys [18944 2018-10-22] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2018-10-22] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [275232 2019-10-20] (Malwarebytes Corporation -> Malwarebytes)
S3 MREMP50; C:\Program Files (x86)\Common Files\Motive\MREMP50.sys [21248 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MREMP50a64; C:\Program Files\Common Files\Motive\MREMP50a64.SYS [43008 2010-02-02] (Motive Inc -> Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\Program Files (x86)\Common Files\Motive\MRESP50.sys [20096 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50a64; C:\Program Files\Common Files\Motive\MRESP50a64.SYS [40960 2010-02-02] (Motive Inc -> Printing Communications Assoc., Inc. (PCAUSA))
S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [20480 2012-12-24] (Microsoft Windows Hardware Compatibility Publisher -> Marvell Semiconductor, Inc.)
S3 SrvHsfHDA; C:\Windows\System32\DRIVERS\VSTAZL6.SYS [292864 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.)
S3 SrvHsfV92; C:\Windows\System32\DRIVERS\VSTDPV6.SYS [1485312 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.)
S3 SrvHsfWinac; C:\Windows\System32\DRIVERS\VSTCNXT6.SYS [740864 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.)
R3 STHDA; C:\Windows\System32\DRIVERS\stwrt64.sys [535040 2011-12-01] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
R3 tap-tb-0901; C:\Windows\System32\DRIVERS\tap-tb-0901.sys [38656 2019-06-19] (TunnelBear, Inc. -> The OpenVPN Project)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
S3 MREMPR5; \??\C:\PROGRA~2\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~2\COMMON~1\Motive\MRENDIS5.SYS [X]
S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-10-20 16:22 - 2019-10-20 16:26 - 000038307 _____ C:\Users\Welcome\Desktop\FRST.txt
2019-10-20 16:22 - 2019-10-20 16:22 - 000000000 ____D C:\Users\Welcome\Desktop\FRST-OlderVersion
2019-10-20 16:21 - 2019-10-20 16:25 - 000000000 ____D C:\FRST
2019-10-20 16:14 - 2019-10-20 16:14 - 000275232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-10-20 16:07 - 2013-10-02 03:22 - 000056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2019-10-20 16:07 - 2013-10-02 03:11 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2019-10-20 16:07 - 2013-10-02 03:08 - 000012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2019-10-20 16:07 - 2013-10-02 02:48 - 000056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2019-10-20 16:07 - 2013-10-02 02:48 - 000018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2019-10-20 16:07 - 2013-10-02 02:29 - 000062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2019-10-20 16:07 - 2013-10-02 02:10 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2019-10-20 16:07 - 2013-10-02 01:15 - 001057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2019-10-20 16:07 - 2013-10-02 01:14 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2019-10-20 16:07 - 2013-10-02 01:14 - 000017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2019-10-20 16:07 - 2013-10-02 01:08 - 000083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2019-10-20 16:07 - 2013-10-02 01:01 - 000420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2019-10-20 16:07 - 2013-10-02 00:58 - 000053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2019-10-20 16:07 - 2013-10-02 00:31 - 001147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2019-10-20 16:07 - 2013-10-02 00:08 - 000855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2019-10-20 16:07 - 2013-10-01 23:34 - 001068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2019-10-20 16:07 - 2013-10-01 21:57 - 006578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2019-10-20 16:07 - 2013-10-01 21:55 - 005698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2019-10-20 16:06 - 2012-08-23 15:13 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2019-10-20 16:06 - 2012-08-23 15:10 - 000019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2019-10-20 16:06 - 2012-08-23 15:08 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2019-10-20 16:06 - 2012-08-23 14:24 - 000015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2019-10-20 16:06 - 2012-08-23 12:12 - 000192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2019-10-20 16:06 - 2012-08-23 11:51 - 000228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2019-10-20 16:06 - 2012-08-23 10:51 - 003174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2019-10-20 16:02 - 2015-12-16 19:53 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll
2019-10-20 16:02 - 2015-12-16 19:53 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL
2019-10-20 16:02 - 2015-12-16 19:53 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL
2019-10-20 16:02 - 2015-12-16 19:48 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL
2019-10-20 16:02 - 2015-12-16 19:48 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll
2019-10-20 16:02 - 2015-12-16 19:48 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL
2019-10-20 15:53 - 2019-10-20 16:22 - 001617408 _____ (Farbar) C:\Users\Welcome\Desktop\FRST64.exe
2019-10-19 12:21 - 2019-10-19 12:22 - 000049200 _____ C:\Users\Welcome\Documents\cc_20191019_122138.reg
2019-10-18 21:37 - 2019-10-18 21:37 - 001286122 _____ C:\Users\Welcome\AppData\Local\census.cache
2019-10-18 21:36 - 2019-10-18 21:36 - 000237632 _____ C:\Users\Welcome\AppData\Local\ars.cache
2019-10-17 22:51 - 2019-10-07 07:49 - 000390752 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2019-10-17 22:51 - 2019-10-07 06:57 - 000341896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2019-10-17 22:51 - 2019-10-06 05:12 - 025753088 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-10-17 22:51 - 2019-10-06 05:00 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2019-10-17 22:51 - 2019-10-06 05:00 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2019-10-17 22:51 - 2019-10-06 04:49 - 002909184 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-10-17 22:51 - 2019-10-06 04:48 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2019-10-17 22:51 - 2019-10-06 04:47 - 000579584 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2019-10-17 22:51 - 2019-10-06 04:47 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2019-10-17 22:51 - 2019-10-06 04:47 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2019-10-17 22:51 - 2019-10-06 04:46 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2019-10-17 22:51 - 2019-10-06 04:41 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2019-10-17 22:51 - 2019-10-06 04:40 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2019-10-17 22:51 - 2019-10-06 04:38 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2019-10-17 22:51 - 2019-10-06 04:37 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2019-10-17 22:51 - 2019-10-06 04:37 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2019-10-17 22:51 - 2019-10-06 04:36 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2019-10-17 22:51 - 2019-10-06 04:36 - 000797696 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2019-10-17 22:51 - 2019-10-06 04:34 - 005500928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2019-10-17 22:51 - 2019-10-06 04:32 - 020290048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2019-10-17 22:51 - 2019-10-06 04:31 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2019-10-17 22:51 - 2019-10-06 04:28 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2019-10-17 22:51 - 2019-10-06 04:28 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2019-10-17 22:51 - 2019-10-06 04:23 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2019-10-17 22:51 - 2019-10-06 04:22 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2019-10-17 22:51 - 2019-10-06 04:22 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2019-10-17 22:51 - 2019-10-06 04:19 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2019-10-17 22:51 - 2019-10-06 04:19 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2019-10-17 22:51 - 2019-10-06 04:18 - 000496128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2019-10-17 22:51 - 2019-10-06 04:18 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2019-10-17 22:51 - 2019-10-06 04:17 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2019-10-17 22:51 - 2019-10-06 04:17 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2019-10-17 22:51 - 2019-10-06 04:16 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2019-10-17 22:51 - 2019-10-06 04:16 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2019-10-17 22:51 - 2019-10-06 04:15 - 002302464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2019-10-17 22:51 - 2019-10-06 04:12 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2019-10-17 22:51 - 2019-10-06 04:12 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2019-10-17 22:51 - 2019-10-06 04:11 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2019-10-17 22:51 - 2019-10-06 04:10 - 000663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2019-10-17 22:51 - 2019-10-06 04:10 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2019-10-17 22:51 - 2019-10-06 04:10 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2019-10-17 22:51 - 2019-10-06 04:07 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2019-10-17 22:51 - 2019-10-06 04:05 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2019-10-17 22:51 - 2019-10-06 04:05 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2019-10-17 22:51 - 2019-10-06 04:03 - 002132992 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2019-10-17 22:51 - 2019-10-06 04:03 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2019-10-17 22:51 - 2019-10-06 04:03 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2019-10-17 22:51 - 2019-10-06 04:00 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2019-10-17 22:51 - 2019-10-06 04:00 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2019-10-17 22:51 - 2019-10-06 03:59 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2019-10-17 22:51 - 2019-10-06 03:58 - 015413760 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-10-17 22:51 - 2019-10-06 03:57 - 004859904 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2019-10-17 22:51 - 2019-10-06 03:57 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2019-10-17 22:51 - 2019-10-06 03:56 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2019-10-17 22:51 - 2019-10-06 03:56 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2019-10-17 22:51 - 2019-10-06 03:55 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2019-10-17 22:51 - 2019-10-06 03:53 - 004112384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2019-10-17 22:51 - 2019-10-06 03:50 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2019-10-17 22:51 - 2019-10-06 03:49 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2019-10-17 22:51 - 2019-10-06 03:48 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2019-10-17 22:51 - 2019-10-06 03:48 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2019-10-17 22:51 - 2019-10-06 03:45 - 013808640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2019-10-17 22:51 - 2019-10-06 03:45 - 001566208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2019-10-17 22:51 - 2019-10-06 03:35 - 004387840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2019-10-17 22:51 - 2019-10-06 03:34 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2019-10-17 22:51 - 2019-10-06 03:32 - 001331712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2019-10-17 22:51 - 2019-10-06 03:30 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2019-10-17 22:51 - 2019-09-19 05:27 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\umpo.dll
2019-10-17 22:51 - 2019-09-12 04:53 - 000442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2019-10-17 22:51 - 2019-09-12 04:52 - 000373248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2019-10-17 22:51 - 2019-09-12 04:52 - 000195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2019-10-17 22:51 - 2019-09-12 04:44 - 000680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2019-10-17 22:51 - 2019-09-12 04:44 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2019-10-17 22:51 - 2019-09-12 04:44 - 000438784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2019-10-17 22:51 - 2019-09-12 04:44 - 000295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2019-10-17 22:51 - 2019-09-12 04:44 - 000284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2019-10-17 22:51 - 2019-09-10 03:24 - 001281536 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
2019-10-17 22:51 - 2019-09-10 02:54 - 003231744 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2019-10-17 22:50 - 2019-10-06 04:17 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2019-10-17 22:50 - 2019-09-17 03:32 - 004060896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2019-10-17 22:50 - 2019-09-17 03:32 - 003966688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2019-10-17 22:50 - 2019-09-17 03:32 - 000709856 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2019-10-17 22:50 - 2019-09-17 03:32 - 000627424 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2019-10-17 22:50 - 2019-09-17 03:31 - 005552864 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2019-10-17 22:50 - 2019-09-17 03:31 - 001319496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2019-10-17 22:50 - 2019-09-17 03:31 - 000263904 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2019-10-17 22:50 - 2019-09-17 03:31 - 000155360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2019-10-17 22:50 - 2019-09-17 03:31 - 000096992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2019-10-17 22:50 - 2019-09-17 03:30 - 001670784 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000834048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000555520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000275968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000261632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 001472512 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 001211392 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 001162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 001010176 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000733184 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000408576 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000236032 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000094208 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 03:04 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
2019-10-17 22:50 - 2019-09-17 03:03 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2019-10-17 22:50 - 2019-09-17 03:00 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2019-10-17 22:50 - 2019-09-17 03:00 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2019-10-17 22:50 - 2019-09-17 03:00 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2019-10-17 22:50 - 2019-09-17 02:59 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2019-10-17 22:50 - 2019-09-17 02:59 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2019-10-17 22:50 - 2019-09-17 02:59 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2019-10-17 22:50 - 2019-09-17 02:59 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2019-10-17 22:50 - 2019-09-17 02:59 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2019-10-17 22:50 - 2019-09-17 02:57 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2019-10-17 22:50 - 2019-09-17 02:57 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 02:57 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 02:57 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 02:57 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2019-10-17 22:50 - 2019-09-17 02:56 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2019-10-17 22:50 - 2019-09-17 02:56 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2019-10-17 22:50 - 2019-09-17 02:55 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2019-10-17 22:50 - 2019-09-17 02:53 - 000464384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2019-10-17 22:50 - 2019-09-17 02:53 - 000161280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2019-10-17 22:50 - 2019-09-17 02:52 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2019-10-17 22:50 - 2019-09-17 02:52 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2019-10-17 22:50 - 2019-09-17 02:52 - 000169984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2019-10-17 22:50 - 2019-09-17 02:52 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2019-10-17 22:50 - 2019-09-17 02:51 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2019-10-17 22:50 - 2019-09-17 02:51 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys
2019-10-17 22:50 - 2019-09-17 02:51 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys
2019-10-17 22:50 - 2019-09-17 02:51 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys
2019-10-17 22:50 - 2019-09-17 02:51 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys
2019-10-17 22:50 - 2019-09-17 02:51 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\npfs.sys
2019-10-17 22:50 - 2019-09-17 02:51 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2019-10-17 22:50 - 2019-09-17 01:13 - 000455392 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2019-10-17 22:50 - 2019-09-12 04:24 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2019-10-17 22:50 - 2019-09-11 05:56 - 000353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2019-10-17 22:50 - 2019-09-11 05:56 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll
2019-10-17 22:50 - 2019-09-10 03:27 - 000383488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2019-10-17 22:50 - 2019-09-10 03:27 - 000320512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
2019-10-17 22:50 - 2019-09-10 03:27 - 000160256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll
2019-10-17 22:50 - 2019-09-10 03:24 - 000486912 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2019-10-17 22:50 - 2019-09-10 03:24 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2019-10-17 22:50 - 2019-09-10 03:24 - 000174080 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll
2019-10-17 22:50 - 2019-09-10 03:24 - 000086016 _____ (Microsoft Corporation) C:\Windows\system32\wercplsupport.dll
2019-10-17 22:50 - 2019-09-10 03:24 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2019-10-17 22:50 - 2019-09-10 03:00 - 000361472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2019-10-17 22:50 - 2019-09-10 03:00 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWWIN.EXE
2019-10-17 22:50 - 2019-09-10 03:00 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2019-10-17 22:50 - 2019-09-10 03:00 - 000028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe
2019-10-17 22:50 - 2019-09-10 03:00 - 000028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
2019-10-17 22:50 - 2019-09-10 02:53 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2019-10-17 22:50 - 2019-09-10 02:53 - 000152576 _____ (Microsoft Corporation) C:\Windows\system32\DWWIN.EXE
2019-10-17 22:50 - 2019-09-10 02:53 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2019-10-17 22:50 - 2019-09-10 02:53 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
2019-10-17 22:50 - 2019-09-10 02:52 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\monitor.sys
2019-10-17 22:50 - 2019-09-10 02:49 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2019-10-17 20:24 - 2019-10-17 20:24 - 000000000 ____D C:\Users\Welcome\AppData\Local\mbamtray
2019-10-17 20:24 - 2019-10-17 20:24 - 000000000 ____D C:\Users\Welcome\AppData\Local\mbam
2019-10-17 20:23 - 2019-10-17 20:23 - 000000036 _____ C:\Users\Welcome\AppData\Local\housecall.guid.cache
2019-10-17 20:22 - 2019-10-17 20:22 - 002105760 _____ (Trend Micro Inc.) C:\Users\Welcome\Downloads\HousecallLauncher.exe
2019-10-17 20:21 - 2019-10-18 21:41 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2019-10-17 20:21 - 2019-10-17 20:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-10-17 20:21 - 2019-10-17 20:21 - 000000000 ____D C:\Program Files\Malwarebytes
2019-10-17 20:18 - 2019-10-17 20:20 - 066367928 _____ (Malwarebytes ) C:\Users\Welcome\Downloads\mb3-setup-37469.37469-3.8.3.2965-1.0.627-1.0.12633.exe
2019-10-13 19:32 - 2019-10-13 14:24 - 000355720 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2019-10-13 19:31 - 2019-10-13 14:24 - 000236024 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2019-10-13 19:31 - 2019-10-13 14:24 - 000171520 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2019-10-13 14:04 - 2019-10-13 14:04 - 009256960 _____ C:\Program Files (x86)\GUTEB49.tmp
2019-10-13 14:04 - 2019-10-13 14:04 - 000000000 ____D C:\Program Files (x86)\GUMEB48.tmp
2019-09-26 21:32 - 2019-08-16 02:02 - 000123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2019-09-26 21:32 - 2019-08-16 01:56 - 000142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2019-09-26 21:04 - 2019-08-29 03:52 - 000836608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2019-09-26 21:04 - 2019-08-29 03:50 - 001078784 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2019-09-26 21:04 - 2019-08-27 03:34 - 000350208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys
2019-09-26 21:04 - 2019-08-20 04:59 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ws2ifsl.sys
2019-09-26 21:04 - 2019-08-20 03:47 - 001251840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2019-09-26 21:04 - 2019-08-15 08:59 - 000878080 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2019-09-26 21:04 - 2019-08-15 08:59 - 000583680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2019-09-26 21:04 - 2019-08-14 18:54 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll
2019-09-26 21:04 - 2019-08-14 18:53 - 000253440 _____ (Microsoft) C:\Windows\SysWOW64\DShowRdpFilter.dll
2019-09-26 21:04 - 2019-08-14 06:22 - 000374496 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2019-09-26 21:04 - 2019-08-14 06:20 - 000300032 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
2019-09-26 21:04 - 2019-08-14 06:20 - 000282112 _____ (Microsoft) C:\Windows\system32\DShowRdpFilter.dll
2019-09-26 21:04 - 2019-08-14 05:52 - 000455680 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2019-09-26 21:04 - 2019-08-13 03:58 - 001312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2019-09-26 21:04 - 2019-08-13 01:56 - 001650176 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2019-09-26 21:03 - 2019-08-22 23:07 - 000628480 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2019-09-26 21:03 - 2019-08-21 02:59 - 000311008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2019-09-26 21:03 - 2019-08-21 02:56 - 000071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2019-09-26 21:03 - 2019-08-21 02:56 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2019-09-26 21:03 - 2019-08-21 02:56 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2019-09-26 21:03 - 2019-08-21 00:19 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2019-09-26 21:03 - 2019-08-20 05:24 - 000385248 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2019-09-26 21:03 - 2019-08-20 05:21 - 000101376 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2019-09-26 21:03 - 2019-08-20 05:21 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2019-09-26 21:03 - 2019-08-20 05:21 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2019-09-26 21:03 - 2019-08-20 05:21 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2019-09-26 21:03 - 2019-08-13 23:20 - 000162016 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2019-09-26 21:03 - 2019-08-13 23:19 - 000988384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2019-09-26 21:03 - 2019-08-13 23:19 - 000267488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2019-09-26 21:03 - 2019-08-13 23:16 - 000484864 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2019-09-26 21:03 - 2019-08-13 23:15 - 000732160 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2019-09-26 21:03 - 2019-08-13 23:15 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2019-09-26 21:03 - 2019-08-13 23:15 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2019-09-26 21:03 - 2019-08-13 23:13 - 000363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2019-09-26 21:03 - 2019-08-13 23:13 - 000313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2019-09-26 21:03 - 2019-08-13 03:58 - 000475648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxbde40.dll
2019-09-26 21:03 - 2019-08-13 03:58 - 000313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd2x40.dll
2019-09-26 21:03 - 2019-08-13 01:56 - 002863104 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2019-09-26 21:03 - 2019-08-13 01:56 - 001712640 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2019-09-26 21:03 - 2019-08-13 01:56 - 000802304 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2019-09-26 21:03 - 2019-08-13 01:56 - 000634368 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2019-09-26 21:03 - 2019-08-13 01:56 - 000501760 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2019-09-26 21:03 - 2019-08-13 01:56 - 000456192 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2019-09-26 21:03 - 2019-08-13 01:56 - 000315904 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2019-09-26 21:03 - 2019-08-13 01:56 - 000257024 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-10-20 16:22 - 2009-07-14 05:45 - 000032064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-10-20 16:22 - 2009-07-14 05:45 - 000032064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-10-20 16:16 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\tracing
2019-10-20 16:14 - 2019-09-09 19:34 - 000000000 ____D C:\Program Files (x86)\TunnelBear
2019-10-20 16:13 - 2011-12-20 13:46 - 000065536 _____ C:\Windows\system32\Ikeext.etl
2019-10-20 16:13 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-10-20 16:11 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\PolicyDefinitions
2019-10-20 16:11 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2019-10-20 12:27 - 2009-07-14 06:13 - 000782510 _____ C:\Windows\system32\PerfStringBackup.INI
2019-10-20 08:58 - 2012-08-18 02:53 - 000000936 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2010538318-109841488-92881702-1000UA.job
2019-10-20 08:08 - 2013-03-29 18:56 - 000000000 ____D C:\Users\Welcome\AppData\Local\ElevatedDiagnostics
2019-10-20 08:02 - 2011-09-21 16:30 - 000003942 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{7DB0D1B4-6528-49EB-AA32-650AED10C9F1}
2019-10-19 20:06 - 2019-08-28 21:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2019-10-19 12:26 - 2012-06-03 22:52 - 000000000 ____D C:\Users\Welcome\AppData\Roaming\uTorrent
2019-10-19 02:58 - 2012-08-18 02:53 - 000000914 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2010538318-109841488-92881702-1000Core.job
2019-10-18 19:14 - 2011-10-07 12:10 - 000002425 _____ C:\Users\Welcome\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-10-18 05:19 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\rescache
2019-10-18 04:17 - 2009-07-14 05:45 - 000412736 _____ C:\Windows\system32\FNTCACHE.DAT
2019-10-18 04:16 - 2014-01-16 22:15 - 000000000 ____D C:\Program Files\CCleaner
2019-10-18 03:44 - 2014-02-26 09:48 - 000766820 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2019-10-18 03:41 - 2013-09-09 03:01 - 000000000 ____D C:\Windows\system32\MRT
2019-10-18 03:17 - 2012-05-12 13:02 - 127230528 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-10-18 01:56 - 2019-04-12 20:34 - 000003732 _____ C:\Windows\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2019-10-18 01:56 - 2019-04-12 20:34 - 000003150 _____ C:\Windows\system32\Tasks\Avast Secure Browser Heartbeat Task (Logon)
2019-10-18 01:56 - 2019-01-27 19:09 - 000002389 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2019-10-18 00:06 - 2015-07-29 11:25 - 000004476 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task
2019-10-18 00:02 - 2019-03-24 21:25 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-10-17 23:48 - 2011-09-22 15:11 - 000000000 ____D C:\Users\Welcome\AppData\Local\Adobe
2019-10-17 21:56 - 2018-03-16 12:53 - 000004470 _____ C:\Windows\system32\Tasks\Adobe Flash Player NPAPI Notifier
2019-10-17 21:56 - 2014-03-14 19:14 - 000004312 _____ C:\Windows\system32\Tasks\Adobe Flash Player Updater
2019-10-17 21:56 - 2012-08-18 13:55 - 000842296 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerApp.exe
2019-10-17 21:56 - 2011-09-29 18:28 - 000175160 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2019-10-17 21:55 - 2011-12-17 17:24 - 000000000 ____D C:\Windows\system32\Macromed
2019-10-17 21:55 - 2011-05-14 20:53 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2019-10-17 21:24 - 2011-10-12 18:38 - 000000000 __HDC C:\ProgramData\{1B0B54CA-AA7D-41D3-A84A-29E7C9CB13A2}
2019-10-17 21:24 - 2011-10-12 18:38 - 000000000 ____D C:\Program Files (x86)\SearchCore for Browsers
2019-10-17 21:22 - 2014-04-11 16:20 - 000000000 ____D C:\ProgramData\APN
2019-10-17 21:22 - 2012-03-09 01:12 - 000000000 ____D C:\ProgramData\InstallMate
2019-10-17 20:25 - 2011-11-19 16:30 - 000003334 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2019-10-17 20:25 - 2011-11-19 16:30 - 000003206 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2019-10-17 20:25 - 2011-10-07 12:09 - 000003510 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-2010538318-109841488-92881702-1000UA
2019-10-17 20:25 - 2011-10-07 12:09 - 000003238 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-2010538318-109841488-92881702-1000Core
2019-10-17 20:21 - 2012-10-23 18:13 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-10-16 19:56 - 2019-01-27 22:45 - 000004128 _____ C:\Windows\system32\Tasks\CCleaner Update
2019-10-16 19:56 - 2015-06-15 18:27 - 000003134 _____ C:\Windows\system32\Tasks\{A41BF357-791A-42BB-BEA2-ADD1DBC0FCB7}
2019-10-16 19:56 - 2015-03-09 15:42 - 000003168 _____ C:\Windows\system32\Tasks\{47C1EE03-DBDC-4F69-8684-8A725843FA1A}
2019-10-16 19:56 - 2014-01-16 22:15 - 000002776 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC
2019-10-16 19:56 - 2014-01-16 21:12 - 000003230 _____ C:\Windows\system32\Tasks\SidebarExecute
2019-10-16 19:56 - 2013-10-03 16:07 - 000003120 _____ C:\Windows\system32\Tasks\{293A7AA4-85AF-4E0B-A2B7-E06E589C866A}
2019-10-16 19:56 - 2012-08-18 02:53 - 000003926 _____ C:\Windows\system32\Tasks\FacebookUpdateTaskUserS-1-5-21-2010538318-109841488-92881702-1000UA
2019-10-16 19:56 - 2012-08-18 02:53 - 000003558 _____ C:\Windows\system32\Tasks\FacebookUpdateTaskUserS-1-5-21-2010538318-109841488-92881702-1000Core
2019-10-16 19:56 - 2012-05-12 22:49 - 000000000 ____D C:\Users\Welcome\AppData\Roaming\vlc
2019-10-16 19:56 - 2011-07-18 09:48 - 000003148 _____ C:\Windows\system32\Tasks\MirageAgent
2019-10-16 19:34 - 2019-01-27 18:35 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
2019-10-13 14:24 - 2019-02-16 20:59 - 000276952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2019-10-13 14:24 - 2019-01-27 18:34 - 000463584 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2019-10-13 14:24 - 2019-01-27 18:34 - 000316528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2019-10-13 14:24 - 2019-01-27 18:34 - 000110320 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2019-10-13 14:24 - 2019-01-27 18:34 - 000083792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2019-10-13 14:24 - 2019-01-27 18:34 - 000042736 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2019-10-13 14:23 - 2019-01-27 18:34 - 000854696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2019-10-13 14:23 - 2019-01-27 18:34 - 000274456 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdriver.sys
2019-10-13 14:23 - 2019-01-27 18:34 - 000209552 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsh.sys
2019-10-13 14:23 - 2019-01-27 18:34 - 000204824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2019-10-13 14:23 - 2019-01-27 18:34 - 000065120 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniv.sys
2019-10-13 14:23 - 2019-01-27 18:34 - 000037616 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArDisk.sys
2019-10-13 14:04 - 2014-05-07 07:23 - 000000000 ___SD C:\Windows\system32\CompatTel
2019-10-13 14:04 - 2011-11-19 16:30 - 000000000 ____D C:\Program Files (x86)\Google

==================== Files in the root of some directories ================

2001-08-16 21:44 - 2014-10-03 12:08 - 000024466 _____ () C:\Program Files\threepir.txt
2005-03-22 14:07 - 2014-10-03 12:08 - 000000546 _____ () C:\Program Files\threepirgrp.txt
2019-10-13 14:04 - 2019-10-13 14:04 - 009256960 _____ () C:\Program Files (x86)\GUTEB49.tmp
2012-10-22 19:39 - 2012-10-22 19:39 - 000000272 _____ () C:\Users\Welcome\AppData\Roaming\.backup.dm
2012-05-10 16:28 - 2012-05-10 16:39 - 000001558 _____ () C:\Users\Welcome\AppData\Roaming\result.db
2011-10-02 20:53 - 2015-09-14 12:30 - 000000600 _____ () C:\Users\Welcome\AppData\Roaming\winscp.rnd
2018-04-14 09:37 - 2018-04-14 09:37 - 000000000 _____ () C:\Users\Welcome\AppData\Roaming\Microsoft\9456.tmp
2019-10-18 21:36 - 2019-10-18 21:36 - 000237632 _____ () C:\Users\Welcome\AppData\Local\ars.cache
2019-10-18 21:37 - 2019-10-18 21:37 - 001286122 _____ () C:\Users\Welcome\AppData\Local\census.cache
2019-10-17 20:23 - 2019-10-17 20:23 - 000000036 _____ () C:\Users\Welcome\AppData\Local\housecall.guid.cache
2019-02-03 17:43 - 2019-02-03 17:43 - 000000886 _____ () C:\Users\Welcome\AppData\Local\recently-used.xbel
2014-06-09 10:00 - 2015-12-04 21:06 - 000002722 _____ () C:\Users\Welcome\AppData\Local\tpsRelw.ini
2017-06-05 21:43 - 2017-06-05 21:43 - 000000000 _____ () C:\Users\Welcome\AppData\Local\{A5138005-6829-43E5-A41C-7BE821DBBB9A}
2019-01-14 22:13 - 2019-01-14 22:13 - 000000000 _____ () C:\Users\Welcome\AppData\Local\{BFC6BB21-BF5E-4A9E-A51A-29FB42705379}

==================== FCheck ================================

(If an entry is included in the fixlist, the file/folder will be moved.)

FCheck: C:\Windows\SysWOW64\nsprs.dll [2012-02-24] <==== ATTENTION (zero byte File/Folder)
FCheck: C:\Windows\SysWOW64\serauth1.dll [2012-02-24] <==== ATTENTION (zero byte File/Folder)
FCheck: C:\Windows\SysWOW64\serauth2.dll [2012-02-24] <==== ATTENTION (zero byte File/Folder)
FCheck: C:\Windows\SysWOW64\ssprs.dll [2012-02-24] <==== ATTENTION (zero byte File/Folder)

==================== SigCheck ===============================

(There is no automatic fix for files that do not pass verification.)


LastRegBack: 2019-10-20 09:15
==================== End of FRST.txt ============================

Addition.txt

Share this post


Link to post
Share on other sites

Hi,

Please download the attached Fixlist.txt file to  the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.

fixlist.txt

Share this post


Link to post
Share on other sites

Fixlog:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 21-10-2019
Ran by Welcome (21-10-2019 18:15:30) Run:1
Running from C:\Users\Welcome\Desktop
Loaded Profiles: Welcome (Available Profiles: Welcome)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
AppInit_DLLs: C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\IEBHO.dll => C:\Program Files (x86)\SearchCore for Browsers\SearchCore for Browsers\x64\IEBHO.dll [1790872 2011-09-27] (Bandoo Media, Inc. -> Bandoo Media, inc)
AppInit_DLLs: DLL => No File
GroupPolicy\User: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
Task: {14012C0F-9395-402C-B8E6-BA215BF9FA0F} - System32\Tasks\{293A7AA4-85AF-4E0B-A2B7-E06E589C866A} => "c:\users\welcome\appdata\local\google\chrome\application\chrome.exe" hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?page=tsProgressBar
Task: {EAE0F588-4EE7-4BD9-B76B-E7DFD17D7F55} - System32\Tasks\{A41BF357-791A-42BB-BEA2-ADD1DBC0FCB7} => "c:\users\welcome\appdata\local\google\chrome\application\chrome.exe" hxxp://ui.skype.com/ui/0/5.1.0.104.161/en/go/help.faq.installer?LastError=1603
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKU\S-1-5-21-2010538318-109841488-92881702-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://mysearch.avg.com/search?cid={3CE8158B-FB5F-45C0-A03E-35A1F3D2181A}&mid=04d94a9cb0f847d298e5c156325e41d4-6bf6cc12e5c00251fc9290e050c22011984caa45&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-01-18 13:24:51&v=17.3.1.91&pid=safeguard&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2010538318-109841488-92881702-1000 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
BHO: No Name -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> No File
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
Toolbar: HKLM - No Name - !{3042df7a-e900-4389-9b94-923df0daa57e} -  No File
Toolbar: HKLM - No Name - !{98889811-442D-49dd-99D7-DC866BE87DBC} -  No File
Toolbar: HKLM - No Name - !{D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Toolbar: HKLM-x32 - No Name - !{3042df7a-e900-4389-9b94-923df0daa57e} -  No File
Toolbar: HKLM-x32 - No Name - !{98889811-442D-49dd-99D7-DC866BE87DBC} -  No File
Toolbar: HKLM-x32 - No Name - !{D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -  No File
CHR Extension: (Ask Toolbar) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pljcgbedjplidkdjahbaalanadmjfgop [2015-02-23]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
S3 MREMPR5; \??\C:\PROGRA~2\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~2\COMMON~1\Motive\MRENDIS5.SYS [X]
S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [X]
CustomCLSID: HKU\S-1-5-21-2010538318-109841488-92881702-1000_Classes\CLSID\{A2C6CB58-C076-425C-ACB7-6D19D64428CD}\localserver32 -> C:\Users\Welcome\AppData\Local\Google\Chrome\Application\77.0.3865.120\notification_helper.exe (Google LLC -> Google LLC)
ContextMenuHandlers1: [AVG Shell Extension] -> {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} =>  -> No File
ContextMenuHandlers1: [_Movavivc11] -> {1C604495-4D32-476e-8D7E-FBF50F6C80BF} =>  -> No File
ContextMenuHandlers6: [AVG Shell Extension] -> {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} =>  -> No File
ContextMenuHandlers6: [_Movavivc11] -> {1C604495-4D32-476e-8D7E-FBF50F6C80BF} =>  -> No File
ContextMenuHandlers1_S-1-5-21-2010538318-109841488-92881702-1000: [DropboxExt] -> [CC]{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} =>  -> No File
ContextMenuHandlers4_S-1-5-21-2010538318-109841488-92881702-1000: [DropboxExt] -> [CC]{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} =>  -> No File
AlternateDataStreams: C:\ProgramData\Temp:054203E4 [130]
HKU\S-1-5-21-2010538318-109841488-92881702-1000\Software\Classes\exefile:  <==== ATTENTION
HKU\S-1-5-21-2010538318-109841488-92881702-1000\Software\Classes\.exe: exefile =>  <==== ATTENTION
C:\Program Files (x86)\SearchCore for Browsers
C:\Windows\SysWOW64\nsprs.dll
C:\Windows\SysWOW64\serauth1.dll
C:\Windows\SysWOW64\serauth2.dll
C:\Windows\SysWOW64\ssprs.dll

*****************

Restore point was successfully created.
Processes closed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\EnableShellExecuteHooks" => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully
"C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\IEBHO.dll" => Value data removed successfully
"DLL" => Value data removed successfully
C:\Windows\system32\GroupPolicy\User => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
HKLM\SOFTWARE\Policies\Google => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{14012C0F-9395-402C-B8E6-BA215BF9FA0F}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{14012C0F-9395-402C-B8E6-BA215BF9FA0F}" => removed successfully
C:\Windows\System32\Tasks\{293A7AA4-85AF-4E0B-A2B7-E06E589C866A} => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{293A7AA4-85AF-4E0B-A2B7-E06E589C866A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EAE0F588-4EE7-4BD9-B76B-E7DFD17D7F55}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EAE0F588-4EE7-4BD9-B76B-E7DFD17D7F55}" => removed successfully
C:\Windows\System32\Tasks\{A41BF357-791A-42BB-BEA2-ADD1DBC0FCB7} => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A41BF357-791A-42BB-BEA2-ADD1DBC0FCB7}" => removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully
HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => removed successfully
HKLM\Software\Classes\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => not found
HKU\S-1-5-21-2010538318-109841488-92881702-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} => removed successfully
HKLM\Software\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => not found
HKU\S-1-5-21-2010538318-109841488-92881702-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => removed successfully
HKLM\Software\Classes\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => not found
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => removed successfully
HKLM\Software\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => not found
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} => removed successfully
HKLM\Software\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => not found
"HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\!{3042df7a-e900-4389-9b94-923df0daa57e}" => removed successfully
HKLM\Software\Classes\CLSID\!{3042df7a-e900-4389-9b94-923df0daa57e} => not found
"HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\!{98889811-442D-49dd-99D7-DC866BE87DBC}" => removed successfully
HKLM\Software\Classes\CLSID\!{98889811-442D-49dd-99D7-DC866BE87DBC} => not found
"HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\!{D4027C7F-154A-4066-A1AD-4243D8127440}" => removed successfully
HKLM\Software\Classes\CLSID\!{D4027C7F-154A-4066-A1AD-4243D8127440} => not found
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\!{3042df7a-e900-4389-9b94-923df0daa57e}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\!{3042df7a-e900-4389-9b94-923df0daa57e} => not found
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\!{98889811-442D-49dd-99D7-DC866BE87DBC}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\!{98889811-442D-49dd-99D7-DC866BE87DBC} => not found
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\!{D4027C7F-154A-4066-A1AD-4243D8127440}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\!{D4027C7F-154A-4066-A1AD-4243D8127440} => not found
HKLM\Software\Classes\PROTOCOLS\Handler\skype4com => removed successfully
HKLM\Software\Classes\CLSID\{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} => not found
CHR Extension: (Ask Toolbar) - C:\Users\Welcome\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pljcgbedjplidkdjahbaalanadmjfgop [2015-02-23] => Error: No automatic fix found for this entry.
HKLM\System\CurrentControlSet\Services\hwdatacard => removed successfully
hwdatacard => service removed successfully
HKLM\System\CurrentControlSet\Services\hwusbdev => removed successfully
hwusbdev => service removed successfully
HKLM\System\CurrentControlSet\Services\MREMPR5 => removed successfully
MREMPR5 => service removed successfully
HKLM\System\CurrentControlSet\Services\MRENDIS5 => removed successfully
MRENDIS5 => service removed successfully
HKLM\System\CurrentControlSet\Services\SBRE => removed successfully
SBRE => service removed successfully
HKU\S-1-5-21-2010538318-109841488-92881702-1000_Classes\CLSID\{A2C6CB58-C076-425C-ACB7-6D19D64428CD} => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\AVG Shell Extension => removed successfully
HKLM\Software\Classes\CLSID\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\_Movavivc11 => removed successfully
HKLM\Software\Classes\CLSID\{1C604495-4D32-476e-8D7E-FBF50F6C80BF} => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\AVG Shell Extension => removed successfully
HKLM\Software\Classes\CLSID\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\_Movavivc11 => removed successfully
HKLM\Software\Classes\CLSID\{1C604495-4D32-476e-8D7E-FBF50F6C80BF} => not found
HKU\S-1-5-21-2010538318-109841488-92881702-1000\Software\Classes\*\ShellEx\ContextMenuHandlers\DropboxExt => removed successfully
HKU\S-1-5-21-2010538318-109841488-92881702-1000\SOFTWARE\Classes\CLSID\[CC]{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => not found
HKU\S-1-5-21-2010538318-109841488-92881702-1000\Software\Classes\Directory\ShellEx\ContextMenuHandlers\DropboxExt => removed successfully
HKU\S-1-5-21-2010538318-109841488-92881702-1000\SOFTWARE\Classes\CLSID\[CC]{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => not found
C:\ProgramData\Temp => ":054203E4" ADS removed successfully
HKU\S-1-5-21-2010538318-109841488-92881702-1000\Software\Classes\exefile => removed successfully
HKU\S-1-5-21-2010538318-109841488-92881702-1000\Software\Classes\.exe => removed successfully
C:\Program Files (x86)\SearchCore for Browsers => moved successfully
C:\Windows\SysWOW64\nsprs.dll => moved successfully
C:\Windows\SysWOW64\serauth1.dll => moved successfully
C:\Windows\SysWOW64\serauth2.dll => moved successfully
C:\Windows\SysWOW64\ssprs.dll => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 5561137 B
Java, Flash, Steam htmlcache => 548 B
Windows/system/drivers => 8144173 B
Edge => 0 B
Chrome => 26438183 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 127621 B
systemprofile32 => 32067863 B
LocalService => 33919669 B
NetworkService => 33919669 B
Welcome => 89110469 B

RecycleBin => 0 B
EmptyTemp: => 226.7 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 18:20:38 ====

Share this post


Link to post
Share on other sites

Another 13 PUP.Optional issues caught by Malwarebyes after fixlog created and scan ran again.
Possible PUP issues were from before Fixlog.

Thanks

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.