Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

CPU spikes and flagged by malwarebytes anti-rookit (mbar)


  • This topic is locked This topic is locked
17 replies to this topic

#1 dementedreality

dementedreality

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:07 PM

Posted 21 March 2018 - 03:13 PM

I was getting very peculiar spikes of CPU usage from the msmpeng.exe which is the Microsoft Security Essentials anti-virus and anti-spyware, but this would happen when I did not have an active scan running or scheduled. I scanned with malwarebytes anti-rookit(MBAR) and it flagged something. I also scanned with combo fix, regular malware bytes, malware bytes adwcleaner, rkill, hitman pro, roguekiller, and emisoft emergency kit. Combofix showed some abnormal behavior and gave a message. I'll attach the log for it. aside from MBAR nothing was flagged. After combofix ran I no longer saw the CPU Spikes, but I'm not sure whether the removal process was entirely completed nor what I was infected with. Here are my FRST logs:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018
Ran by Zed (administrator) on BOXBRAIN (21-03-2018 13:03:31)
Running from C:\Users\Zed\Desktop
Loaded Profiles: Zed (Available Profiles: Zed)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(f.lux Software LLC) C:\Users\Zed\AppData\Local\FluxSoftware\Flux\flux.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareTactXMacroController.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Sublime HQ Pty Ltd) C:\Program Files\Sublime Text 3\sublime_text.exe
() C:\Program Files\Sublime Text 3\plugin_host.exe
(The Pidgin developer community) C:\Program Files (x86)\Pidgin\pidgin.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [286192 2013-04-10] (Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7611608 2014-06-02] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1387376 2014-05-13] (Realtek Semiconductor)
HKLM\...\Run: [Command Center Controllers] => C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [14056 2014-10-30] (Alienware)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-25] (Logitech, Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-24] (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-3759363114-2796580450-4264558159-1000\...\Run: [f.lux] => C:\Users\Zed\AppData\Local\FluxSoftware\Flux\flux.exe [1682936 2018-01-17] (f.lux Software LLC)
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
GroupPolicy: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{49986D67-FD5F-475B-BD9D-EF4AA77FD211}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{4CD58847-17AB-4170-BDF0-FC3113FC231B}: [DhcpNameServer] 75.75.75.75 75.75.76.76

Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3759363114-2796580450-4264558159-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)

FireFox:
========
FF DefaultProfile: 93gavzue.default
FF ProfilePath: C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default [2018-03-21]
FF Session Restore: Mozilla\Firefox\Profiles\93gavzue.default -> is enabled.
FF NewTabOverride: Mozilla\Firefox\Profiles\93gavzue.default -> Enabled: CookieAutoDelete@kennydo.com
FF Extension: (Cookie AutoDelete) - C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default\Extensions\CookieAutoDelete@kennydo.com.xpi [2018-02-12]
FF Extension: (NoScript) - C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2018-03-16]
FF Extension: (Adblock Plus) - C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-02-07]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2018-02-22] [Legacy] [not signed]
FF HKU\S-1-5-21-3759363114-2796580450-4264558159-1000\...\Firefox\Extensions: [fdm_ffext@freedownloadmanager.org] - C:\ProgramData\Free Download Manager\Firefox\Extensions\2.1.13
FF Extension: (Free Download Manager extension) - C:\ProgramData\Free Download Manager\Firefox\Extensions\2.1.13 [2018-03-01] [Legacy]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-10-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-10-23] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-02-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-02-21] (Google Inc.)

Chrome:
=======
CHR Profile: C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default [2018-03-21]
CHR Extension: (Slides) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-02-21]
CHR Extension: (Docs) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-21]
CHR Extension: (Google Drive) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-21]
CHR Extension: (YouTube) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-21]
CHR Extension: (Sheets) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-21]
CHR Extension: (Google Docs Offline) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-02-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-02-21]
CHR Extension: (Gmail) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-02-21]
CHR Extension: (Chrome Media Router) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-02-21]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-10] (Intel Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-11] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel® Corporation)
S3 ioloEnergyBooster; C:\Program Files\Alienware\Command Center\ioloEnergyBooster.exe [6145872 2012-11-01] (iolo technologies, LLC)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6440736 2018-03-03] (Malwarebytes)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [521064 2018-01-10] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [521064 2018-01-10] (NVIDIA Corporation)
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [340480 2013-10-08] (Qualcomm Atheros) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-07] (Realtek Semiconductor)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [172760 2018-02-07] (Broadcom Corporation.)
R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [67888 2013-02-13] (Qualcomm Atheros, Inc.)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [27552 2018-02-07] (REALiX™)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-04-10] (Intel Corporation)
R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [154320 2013-03-20] (Qualcomm Atheros, Inc.)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-03-21] (Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [300320 2013-10-23] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [32104 2018-01-10] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [59240 2017-12-14] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [59752 2018-01-10] (NVIDIA Corporation)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [32496 2013-04-08] (Synaptics Incorporated)
R3 ST_ACCEL; C:\Windows\System32\DRIVERS\ST_Accel.sys [87776 2013-04-11] (STMicroelectronics)
U5 TrueSight; C:\Windows\System32\Drivers\TrueSight.sys [28272 2018-03-21] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-21 13:03 - 2018-03-21 13:03 - 000016043 _____ C:\Users\Zed\Desktop\FRST.txt
2018-03-21 13:02 - 2018-03-21 13:02 - 002403328 _____ (Farbar) C:\Users\Zed\Desktop\FRST64.exe
2018-03-21 12:22 - 2008-04-11 08:03 - 000562688 _____ (Microsoft Corporation) C:\Users\Zed\Desktop\Install.exe
2018-03-21 12:05 - 2018-03-21 12:05 - 000000000 ____D C:\ProgramData\Emsisoft
2018-03-21 12:04 - 2018-03-21 12:07 - 000000000 ____D C:\EEK
2018-03-21 12:01 - 2018-03-21 12:03 - 320381672 _____ C:\Users\Zed\Desktop\EmsisoftEmergencyKit.exe
2018-03-21 11:53 - 2018-03-21 12:03 - 000000000 ____D C:\ProgramData\RogueKiller
2018-03-21 11:53 - 2018-03-21 11:53 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-03-21 11:52 - 2018-03-21 11:52 - 000012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe
2018-03-21 11:47 - 2018-03-21 11:53 - 000000000 ____D C:\ProgramData\HitmanPro
2018-03-21 11:46 - 2018-03-21 11:46 - 000001587 _____ C:\Users\Zed\Desktop\mbam.exe - Shortcut.lnk
2018-03-21 11:45 - 2018-03-21 11:45 - 000025122 _____ C:\ComboFix.txt
2018-03-21 11:35 - 2011-06-25 23:45 - 000256000 _____ C:\Windows\PEV.exe
2018-03-21 11:35 - 2010-11-07 10:20 - 000208896 _____ C:\Windows\MBR.exe
2018-03-21 11:35 - 2009-04-19 21:56 - 000060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2018-03-21 11:35 - 2000-08-30 17:00 - 000518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2018-03-21 11:35 - 2000-08-30 17:00 - 000406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2018-03-21 11:35 - 2000-08-30 17:00 - 000098816 _____ C:\Windows\sed.exe
2018-03-21 11:35 - 2000-08-30 17:00 - 000080412 _____ C:\Windows\grep.exe
2018-03-21 11:35 - 2000-08-30 17:00 - 000068096 _____ C:\Windows\zip.exe
2018-03-21 11:34 - 2018-03-21 11:45 - 000000000 ____D C:\Qoobox
2018-03-21 11:34 - 2018-03-21 11:38 - 000000000 ____D C:\Windows\erdnt
2018-03-21 11:33 - 2018-03-21 11:34 - 027005512 _____ (Adlice Software) C:\Users\Zed\Desktop\RogueKiller_portable64.exe
2018-03-21 11:32 - 2018-03-21 11:33 - 011605440 _____ (SurfRight B.V.) C:\Users\Zed\Desktop\HitmanPro_x64.exe
2018-03-21 11:25 - 2018-03-21 11:25 - 000255928 _____ (Malwarebytes) C:\Windows\system32\Drivers\252733D6.sys
2018-03-21 11:24 - 2018-03-21 11:32 - 000000000 ____D C:\Users\Zed\Desktop\mbar
2018-03-21 11:24 - 2018-03-21 11:32 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2018-03-21 11:24 - 2018-03-21 11:24 - 000192952 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2018-03-21 10:55 - 2018-03-21 12:08 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-03-16 04:30 - 2018-03-16 04:31 - 008222496 _____ (Malwarebytes) C:\Users\Zed\Desktop\AdwCleaner.exe
2018-03-16 04:29 - 2018-03-16 04:29 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\Zed\Desktop\rkill.exe
2018-03-14 21:34 - 2018-03-14 21:34 - 000000000 ____D C:\ProgramData\Oracle
2018-03-14 11:51 - 2018-03-08 20:39 - 005580992 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-03-14 11:51 - 2018-03-08 20:39 - 000708288 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-03-14 11:51 - 2018-03-08 20:39 - 000262336 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-03-14 11:51 - 2018-03-08 20:39 - 000154816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-03-14 11:51 - 2018-03-08 20:39 - 000095424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-03-14 11:51 - 2018-03-08 20:18 - 000631640 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-03-14 11:51 - 2018-03-08 20:14 - 004044992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-03-14 11:51 - 2018-03-08 20:14 - 004025536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-03-14 11:51 - 2018-03-08 20:09 - 001665336 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 001461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000094720 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:47 - 001314064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:38 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-03-14 11:51 - 2018-03-08 19:38 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-03-14 11:51 - 2018-03-08 19:38 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-03-14 11:51 - 2018-03-08 19:37 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-03-14 11:51 - 2018-03-08 19:34 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-03-14 11:51 - 2018-03-08 19:34 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-03-14 11:51 - 2018-03-08 19:33 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-03-14 11:51 - 2018-03-08 19:31 - 000160256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-03-14 11:51 - 2018-03-08 19:30 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-03-14 11:51 - 2018-03-08 19:30 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-03-14 11:51 - 2018-03-08 19:29 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-03-14 11:51 - 2018-03-08 19:29 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-03-14 11:51 - 2018-03-08 19:26 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-03-14 11:51 - 2018-03-08 19:22 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-03-14 11:51 - 2018-03-08 19:22 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-03-14 11:51 - 2018-03-08 19:22 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-03-14 11:51 - 2018-03-08 19:22 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-03-14 11:51 - 2018-03-08 19:22 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-03-14 11:51 - 2018-03-08 19:21 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:21 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:21 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:21 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-03-14 11:51 - 2018-03-01 01:36 - 003226112 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-03-14 11:51 - 2018-02-21 20:28 - 000217600 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2018-03-14 11:51 - 2018-02-21 20:06 - 000134656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2018-03-14 11:51 - 2018-02-18 14:34 - 000634272 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-03-14 11:51 - 2018-02-16 21:27 - 000395928 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-03-14 11:51 - 2018-02-16 20:36 - 000340088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-03-14 11:51 - 2018-02-16 08:51 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-03-14 11:51 - 2018-02-16 08:51 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-03-14 11:51 - 2018-02-16 08:51 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-03-14 11:51 - 2018-02-16 08:45 - 025742848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-03-14 11:51 - 2018-02-16 08:44 - 013678080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-03-14 11:51 - 2018-02-16 08:24 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-03-14 11:51 - 2018-02-16 08:24 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-03-14 11:51 - 2018-02-16 08:24 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-03-14 11:51 - 2018-02-16 08:19 - 020286976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-03-14 11:51 - 2018-02-16 07:37 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-03-14 11:51 - 2018-02-16 07:37 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-03-14 11:51 - 2018-02-15 08:15 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-03-14 11:51 - 2018-02-15 07:57 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-03-14 11:51 - 2018-02-10 11:35 - 000367296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000334528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000185024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000122560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\NV_AGP.SYS
2018-03-14 11:51 - 2018-02-10 11:35 - 000068288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000064192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ULIAGPKX.SYS
2018-03-14 11:51 - 2018-02-10 11:35 - 000063168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000060608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\AGP440.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000036032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vdrvroot.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000031936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mssmbios.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000023744 _____ (Microsoft Corporation) C:\Windows\system32\streamci.dll
2018-03-14 11:51 - 2018-02-10 11:35 - 000020160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\isapnp.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000015040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msisadrv.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000012096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\swenum.sys
2018-03-14 11:51 - 2018-02-10 11:23 - 002292224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2018-03-14 11:51 - 2018-02-10 11:23 - 000330240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2018-03-14 11:51 - 2018-02-10 11:23 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\racpldlg.dll
2018-03-14 11:51 - 2018-02-10 11:11 - 003665920 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2018-03-14 11:51 - 2018-02-10 11:11 - 000369664 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2018-03-14 11:51 - 2018-02-10 11:11 - 000133120 _____ (Microsoft Corporation) C:\Windows\system32\msrahc.dll
2018-03-14 11:51 - 2018-02-10 11:11 - 000119296 _____ (Microsoft Corporation) C:\Windows\system32\racpldlg.dll
2018-03-14 11:51 - 2018-02-10 10:55 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-03-14 11:51 - 2018-02-10 10:55 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-03-14 11:51 - 2018-02-10 10:40 - 002901504 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-03-14 11:51 - 2018-02-10 10:40 - 000577536 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-03-14 11:51 - 2018-02-10 10:40 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-03-14 11:51 - 2018-02-10 10:40 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-03-14 11:51 - 2018-02-10 10:40 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-03-14 11:51 - 2018-02-10 10:37 - 005779968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-03-14 11:51 - 2018-02-10 10:36 - 000108032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msra.exe
2018-03-14 11:51 - 2018-02-10 10:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdchange.exe
2018-03-14 11:51 - 2018-02-10 10:36 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsraLegacy.tlb
2018-03-14 11:51 - 2018-02-10 10:32 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-03-14 11:51 - 2018-02-10 10:31 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-03-14 11:51 - 2018-02-10 10:29 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-03-14 11:51 - 2018-02-10 10:28 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-03-14 11:51 - 2018-02-10 10:28 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-03-14 11:51 - 2018-02-10 10:27 - 000817152 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-03-14 11:51 - 2018-02-10 10:27 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-03-14 11:51 - 2018-02-10 10:26 - 000653312 _____ (Microsoft Corporation) C:\Windows\system32\msra.exe
2018-03-14 11:51 - 2018-02-10 10:26 - 000051712 _____ (Microsoft Corporation) C:\Windows\system32\sdchange.exe
2018-03-14 11:51 - 2018-02-10 10:25 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wmiacpi.sys
2018-03-14 11:51 - 2018-02-10 10:25 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\errdev.sys
2018-03-14 11:51 - 2018-02-10 10:25 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\MsraLegacy.tlb
2018-03-14 11:51 - 2018-02-10 10:22 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-03-14 11:51 - 2018-02-10 10:20 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-03-14 11:51 - 2018-02-10 10:10 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-03-14 11:51 - 2018-02-10 10:10 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-03-14 11:51 - 2018-02-10 10:10 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-03-14 11:51 - 2018-02-10 10:09 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-03-14 11:51 - 2018-02-10 10:09 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-03-14 11:51 - 2018-02-10 10:09 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-03-14 11:51 - 2018-02-10 10:09 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-03-14 11:51 - 2018-02-10 10:06 - 002295296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-03-14 11:51 - 2018-02-10 10:06 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-03-14 11:51 - 2018-02-10 10:03 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-03-14 11:51 - 2018-02-10 10:03 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-03-14 11:51 - 2018-02-10 10:01 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-03-14 11:51 - 2018-02-10 10:01 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-03-14 11:51 - 2018-02-10 10:00 - 000661504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-03-14 11:51 - 2018-02-10 10:00 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-03-14 11:51 - 2018-02-10 10:00 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-03-14 11:51 - 2018-02-10 09:57 - 015281664 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-03-14 11:51 - 2018-02-10 09:52 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-03-14 11:51 - 2018-02-10 09:50 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-03-14 11:51 - 2018-02-10 09:50 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-03-14 11:51 - 2018-02-10 09:47 - 002134016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-03-14 11:51 - 2018-02-10 09:47 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-03-14 11:51 - 2018-02-10 09:47 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-03-14 11:51 - 2018-02-10 09:47 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-03-14 11:51 - 2018-02-10 09:46 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-03-14 11:51 - 2018-02-10 09:44 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-03-14 11:51 - 2018-02-10 09:41 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-03-14 11:51 - 2018-02-10 09:40 - 004496384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-03-14 11:51 - 2018-02-10 09:35 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-03-14 11:51 - 2018-02-10 09:34 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-03-14 11:51 - 2018-02-10 09:33 - 002058240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-03-14 11:51 - 2018-02-10 09:33 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-03-14 11:51 - 2018-02-10 09:23 - 001545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-03-14 11:51 - 2018-02-10 09:12 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-03-14 11:51 - 2018-02-10 09:11 - 001313792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-03-14 11:51 - 2018-02-10 09:09 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-03-14 11:51 - 2018-02-02 11:40 - 000114368 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2018-03-14 11:51 - 2018-02-02 11:29 - 002365952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2018-03-14 11:51 - 2018-02-02 11:29 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2018-03-14 11:51 - 2018-02-02 11:29 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2018-03-14 11:51 - 2018-02-02 11:28 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2018-03-14 11:51 - 2018-02-02 11:16 - 003246080 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2018-03-14 11:51 - 2018-02-02 11:16 - 000504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2018-03-14 11:51 - 2018-02-02 11:16 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2018-03-14 11:51 - 2018-02-02 11:14 - 001942016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2018-03-14 11:51 - 2018-02-02 11:14 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2018-03-14 11:51 - 2018-02-02 10:46 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2018-03-14 11:51 - 2018-02-02 10:36 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2018-03-14 11:51 - 2018-01-15 12:59 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-03-14 11:51 - 2018-01-15 12:40 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2018-03-14 11:51 - 2018-01-12 09:40 - 000407040 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2018-03-14 11:51 - 2018-01-12 09:26 - 000308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2018-03-14 11:50 - 2018-02-13 11:17 - 000136384 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-03-14 11:50 - 2018-02-13 11:10 - 000655872 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-03-14 11:50 - 2018-02-13 07:05 - 001994752 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-03-14 11:50 - 2018-02-13 07:05 - 001560064 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-03-14 11:50 - 2018-02-13 07:05 - 000740864 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-03-14 11:50 - 2018-02-13 07:05 - 000600576 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-03-14 11:50 - 2018-02-13 07:05 - 000451072 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-03-14 11:50 - 2018-02-13 07:05 - 000380928 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-03-14 11:50 - 2018-02-13 07:05 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-03-14 11:50 - 2018-02-13 07:05 - 000237568 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-03-12 05:25 - 2018-03-12 05:25 - 000000000 ____D C:\Users\Zed\AppData\LocalLow\Strange Loop Games
2018-03-12 04:25 - 2018-03-12 04:25 - 000000000 ____D C:\Users\Zed\AppData\LocalLow\Momoiro Software
2018-03-11 04:46 - 2018-03-21 11:25 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-03-11 04:46 - 2018-03-11 04:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-03-11 04:46 - 2018-01-18 08:03 - 000076200 _____ C:\Windows\system32\Drivers\mbae64.sys
2018-03-11 04:28 - 2018-03-16 04:33 - 000000000 ____D C:\AdwCleaner
2018-03-03 17:12 - 2018-03-03 17:12 - 000000000 ____D C:\Windows\pss
2018-03-02 21:43 - 2018-03-02 21:43 - 000000000 ____D C:\Users\Zed\AppData\LocalLow\Ankama
2018-03-02 21:33 - 2018-03-02 21:33 - 000000000 ____D C:\Users\Zed\AppData\Local\Ankama
2018-03-01 23:30 - 2018-03-21 06:39 - 000000000 ____D C:\Users\Zed\AppData\Roaming\twitch-electron
2018-03-01 21:13 - 2018-03-01 21:13 - 000002073 _____ C:\Users\Zed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\f.lux.lnk
2018-03-01 21:13 - 2018-03-01 21:13 - 000000000 ____D C:\Users\Zed\AppData\Local\FluxSoftware
2018-03-01 12:33 - 2018-03-01 12:33 - 000000000 ____D C:\Users\Zed\AppData\Roaming\FreeDownloadManager.ORG
2018-03-01 12:33 - 2018-03-01 12:33 - 000000000 ____D C:\ProgramData\FreeDownloadManager.ORG
2018-03-01 12:33 - 2018-03-01 12:33 - 000000000 ____D C:\ProgramData\Free Download Manager
2018-02-22 16:32 - 2018-03-03 22:12 - 000000000 ____D C:\Users\Zed\AppData\Local\Spotify
2018-02-22 16:32 - 2018-02-22 16:32 - 000001781 _____ C:\Users\Zed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2018-02-22 16:31 - 2018-03-03 19:49 - 000000000 ____D C:\Users\Zed\AppData\Roaming\Spotify
2018-02-22 12:31 - 2018-02-22 12:31 - 000000000 ____D C:\Users\Public\Documents\Logishrd
2018-02-22 12:31 - 2018-02-22 12:31 - 000000000 ____D C:\ProgramData\Logitech
2018-02-22 12:30 - 2018-02-22 12:31 - 000000000 ____D C:\ProgramData\Logishrd
2018-02-22 12:30 - 2018-02-22 12:30 - 000018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2018-02-22 12:30 - 2018-02-22 12:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2018-02-22 12:30 - 2018-02-22 12:30 - 000000000 ____D C:\Program Files\Logitech
2018-02-22 12:29 - 2018-02-22 12:31 - 000000000 ____D C:\Users\Zed\AppData\Roaming\Logitech
2018-02-22 12:29 - 2018-02-22 12:30 - 000000000 ____D C:\Program Files\Common Files\LogiShrd
2018-02-22 12:29 - 2018-02-22 12:29 - 000000000 ____D C:\Users\Zed\AppData\Roaming\Logishrd
2018-02-21 18:14 - 2018-02-28 10:46 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-02-21 18:10 - 2018-03-17 20:11 - 000003332 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-02-21 18:10 - 2018-03-17 20:11 - 000003204 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-02-21 18:10 - 2018-02-21 18:29 - 000000000 ____D C:\Users\Zed\AppData\Local\Google
2018-02-21 18:10 - 2018-02-21 18:13 - 000000000 ____D C:\Program Files (x86)\Google
2018-02-21 17:14 - 2018-02-21 18:41 - 000000000 ____D C:\ESD
2018-02-21 15:10 - 2018-02-21 15:10 - 000002167 _____ C:\Windows\diagwrn.xml
2018-02-21 15:10 - 2018-02-21 15:10 - 000001908 _____ C:\Windows\diagerr.xml
2018-02-21 14:01 - 2018-02-21 14:01 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2018-02-21 07:52 - 2018-02-21 07:52 - 000000039 _____ C:\Users\Zed\AppData\Local\kritadisplayrc
2018-02-21 07:51 - 2018-02-21 07:51 - 000000063 _____ C:\Users\Zed\AppData\Local\emaildefaults

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-21 13:03 - 2018-02-10 02:32 - 000000000 ____D C:\Users\Zed\Desktop\Vanilla - Origin
2018-03-21 13:03 - 2018-01-01 17:11 - 000000000 ____D C:\FRST
2018-03-21 12:51 - 2018-02-07 22:42 - 000000000 ____D C:\Users\Zed\AppData\Roaming\.purple
2018-03-21 12:18 - 2018-02-16 11:47 - 000007610 _____ C:\Users\Zed\AppData\Local\Resmon.ResmonCfg
2018-03-21 12:16 - 2009-07-13 21:45 - 000021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-03-21 12:16 - 2009-07-13 21:45 - 000021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-03-21 12:15 - 2009-07-13 22:13 - 000784286 _____ C:\Windows\system32\PerfStringBackup.INI
2018-03-21 12:15 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\inf
2018-03-21 12:10 - 2018-02-07 22:04 - 000000000 ____D C:\Users\Zed\AppData\LocalLow\Mozilla
2018-03-21 12:08 - 2018-02-07 22:57 - 000000000 ____D C:\ProgramData\NVIDIA
2018-03-21 12:08 - 2009-07-13 22:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-03-21 11:44 - 2009-07-13 19:34 - 000000215 _____ C:\Windows\system.ini
2018-03-21 07:27 - 2018-02-07 22:34 - 000000000 ____D C:\Users\Zed\AppData\Roaming\Twitch
2018-03-19 20:17 - 2009-07-13 22:08 - 000013356 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-03-17 20:03 - 2018-02-07 22:04 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-03-17 16:24 - 2018-02-07 22:04 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-03-16 04:17 - 2018-02-10 02:40 - 000000000 ____D C:\Users\Zed\AppData\Roaming\vlc
2018-03-15 06:55 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\rescache
2018-03-14 15:29 - 2009-07-13 21:45 - 000268448 _____ C:\Windows\system32\FNTCACHE.DAT
2018-03-14 15:28 - 2018-02-14 04:04 - 000000000 ____D C:\Windows\system32\appraiser
2018-03-14 12:07 - 2018-02-08 03:50 - 000000000 ____D C:\Windows\system32\MRT
2018-03-14 12:06 - 2018-02-08 03:50 - 130364688 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-03-14 12:06 - 2018-02-08 03:49 - 130364688 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-03-13 23:03 - 2018-02-11 07:21 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-03-13 23:03 - 2018-02-11 07:21 - 000000000 ____D C:\Windows\system32\Macromed
2018-03-12 05:17 - 2018-02-18 13:54 - 000000000 ____D C:\Users\Zed\AppData\Roaming\Free Download Manager
2018-03-11 05:08 - 2018-02-08 07:13 - 000000000 ____D C:\Program Files (x86)\Steam
2018-03-05 15:04 - 2018-02-09 00:27 - 000000000 ____D C:\Users\Zed\Documents\My Games
2018-03-01 21:15 - 2018-02-18 13:54 - 000000000 ____D C:\Program Files (x86)\Free Download Manager
2018-03-01 12:33 - 2018-02-18 13:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Download Manager
2018-02-24 13:49 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\system32\NDF
2018-02-21 18:41 - 2018-02-07 21:17 - 000000000 ____D C:\Windows\Panther
2018-02-21 16:45 - 2009-07-13 20:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2018-02-21 16:45 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy
2018-02-21 14:21 - 2009-07-13 20:20 - 000000000 __RHD C:\Users\Public\Libraries
2018-02-21 07:52 - 2018-02-14 06:41 - 000015311 _____ C:\Users\Zed\AppData\Local\kritarc

==================== Files in the root of some directories =======

2018-02-07 22:44 - 2018-02-07 22:44 - 000000000 _____ () C:\Users\Zed\AppData\Local\Driver_LOM_8161Present.flag
2018-02-21 07:51 - 2018-02-21 07:51 - 000000063 _____ () C:\Users\Zed\AppData\Local\emaildefaults
2018-02-21 07:52 - 2018-02-21 07:52 - 000000039 _____ () C:\Users\Zed\AppData\Local\kritadisplayrc
2018-02-14 06:41 - 2018-02-21 07:52 - 000015311 _____ () C:\Users\Zed\AppData\Local\kritarc
2018-02-16 11:47 - 2018-03-21 12:18 - 000007610 _____ () C:\Users\Zed\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
2018-03-21 11:53 - 2018-03-08 20:09 - 001665336 _____ (Microsoft Corporation) C:\Users\Zed\AppData\Local\Temp\dllnt_dump.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-03-19 00:53

==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14.03.2018
Ran by Zed (21-03-2018 13:03:54)
Running from C:\Users\Zed\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2018-02-08 04:23:20)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3759363114-2796580450-4264558159-500 - Administrator - Disabled)
Guest (S-1-5-21-3759363114-2796580450-4264558159-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3759363114-2796580450-4264558159-1003 - Limited - Enabled)
Zed (S-1-5-21-3759363114-2796580450-4264558159-1000 - Administrator - Enabled) => C:\Users\Zed

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 18.01 (x64) (HKLM\...\7-Zip) (Version: 18.01 - Igor Pavlov)
Alienware Command Center (HKLM\...\{5DBA5090-EAB9-4E1C-8F92-C71A1423F14C}) (Version: 3.6.4.0 - Alienware Corp.) Hidden
Alienware Command Center (HKLM-x32\...\InstallShield_{5DBA5090-EAB9-4E1C-8F92-C71A1423F14C}) (Version: 3.6.4.0 - Alienware Corp.)
AutoHotkey 1.1.27.07 (HKLM\...\AutoHotkey) (Version: 1.1.27.07 - Lexikos)
Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 6.30.223.215 - Broadcom Corporation)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Hidden
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Hidden
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) Hidden
EMSC (HKLM-x32\...\{FEF06E73-A519-4510-8CF3-B66041B91D8A}) (Version: 0.0.0.9C - Compal Electronics, Inc.) Hidden
f.lux (HKU\S-1-5-21-3759363114-2796580450-4264558159-1000\...\Flux) (Version:  - f.lux Software LLC)
Free Download Manager 3.9.7 (HKLM-x32\...\Free Download Manager_is1) (Version:  - FreeDownloadManager.ORG)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 64.0.3282.186 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
HWiNFO64 Version 5.72 (HKLM\...\HWiNFO64_is1) (Version: 5.72 - Martin Malík - REALiX)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1323 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.0.7.1002 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.0.0.102 - Intel Corporation)
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
Malwarebytes version 3.4.4.2398 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.4.4.2398 - Malwarebytes)
Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Mozilla Firefox 59.0.1 (x64 en-US) (HKLM\...\Mozilla Firefox 59.0.1 (x64 en-US)) (Version: 59.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 58.0.2 - Mozilla)
NVIDIA 3D Vision Driver 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 331.65 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.12.0.84 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.12.0.84 - NVIDIA Corporation)
NVIDIA Graphics Driver 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.0927 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0927 - NVIDIA Corporation)
Pidgin (HKLM-x32\...\Pidgin) (Version: 2.12.0 - )
Python 3.6.4 (32-bit) (HKU\S-1-5-21-3759363114-2796580450-4264558159-1000\...\{9218130b-5ad0-4cf7-82be-6993cfd6cb84}) (Version: 3.6.4150.0 - Python Software Foundation)
Python 3.6.4 Add to Path (32-bit) (HKLM-x32\...\{B7F6071F-CC88-469C-9AC6-BEBA83594819}) (Version: 3.6.4150.0 - Python Software Foundation) Hidden
Python 3.6.4 Core Interpreter (32-bit) (HKLM-x32\...\{D188614B-E656-4EF1-9F5A-23559EBE8F5A}) (Version: 3.6.4150.0 - Python Software Foundation) Hidden
Python 3.6.4 Development Libraries (32-bit) (HKLM-x32\...\{C3797E33-967D-4687-8F1A-9DE771A00125}) (Version: 3.6.4150.0 - Python Software Foundation) Hidden
Python 3.6.4 Documentation (32-bit) (HKLM-x32\...\{E09874D3-E898-4AB6-B043-EE24DF786088}) (Version: 3.6.4150.0 - Python Software Foundation) Hidden
Python 3.6.4 Executables (32-bit) (HKLM-x32\...\{47A75DB9-F3F5-4697-9261-DBA5162DBB9E}) (Version: 3.6.4150.0 - Python Software Foundation) Hidden
Python 3.6.4 pip Bootstrap (32-bit) (HKLM-x32\...\{54142B43-2FA5-4BBA-BF03-27C10EB50C1E}) (Version: 3.6.4150.0 - Python Software Foundation) Hidden
Python 3.6.4 Standard Library (32-bit) (HKLM-x32\...\{2832768E-9BCA-4421-950C-7186B3BDFC45}) (Version: 3.6.4150.0 - Python Software Foundation) Hidden
Python 3.6.4 Tcl/Tk Support (32-bit) (HKLM-x32\...\{20888FA1-8127-42E3-969F-9BF93245AC83}) (Version: 3.6.4150.0 - Python Software Foundation) Hidden
Python 3.6.4 Test Suite (32-bit) (HKLM-x32\...\{D14FB2FA-51B2-415C-93BF-5053102235EE}) (Version: 3.6.4150.0 - Python Software Foundation) Hidden
Python 3.6.4 Utility Scripts (32-bit) (HKLM-x32\...\{D0730E44-E519-4F39-B926-E2FC0449D67C}) (Version: 3.6.4150.0 - Python Software Foundation) Hidden
Python Launcher (HKLM-x32\...\{B42FF40A-60D4-4096-AC47-C86153D72797}) (Version: 3.6.6196.0 - Python Software Foundation)
Qualcomm Atheros Bandwidth Control Filter Driver (HKLM\...\{EEA2190D-D9F6-437B-BFF2-EC5DF619B83F}) (Version: 1.0.36.1067 - Qualcomm Atheros) Hidden
Qualcomm Atheros Killer E220x Drivers (HKLM\...\{D5583A0A-C100-43B9-B6FD-6D5970912A6E}) (Version: 1.0.36.1067 - Qualcomm Atheros) Hidden
Qualcomm Atheros Killer Network Manager Suite (HKLM-x32\...\{E70DB50B-10B4-46BC-9DE2-AB8B49E061EE}) (Version: 1.0.36.1067 - Qualcomm Atheros)
Qualcomm Atheros Network Manager (HKLM\...\{987ACE92-A585-45CF-AE43-0B038780B497}) (Version: 1.0.36.1067 - Qualcomm Atheros) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7260 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{0D61A55C-3ADC-409F-BF5B-A1766D1F5944}) (Version: 6.2.9200.28134 - Realtek Semiconductor Corp.)
Spotify (HKU\S-1-5-21-3759363114-2796580450-4264558159-1000\...\Spotify) (Version: 1.0.75.483.g7ff4a0dc - Spotify AB)
ST Microelectronics 3 Axis Digital Accelerometer Solution (HKLM-x32\...\{9C24F411-9CA7-4A8A-91F3-F08A4A38EB31}) (Version: 4.12.0040 - ST Microelectronics)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Sublime Text Build 3143 (HKLM\...\Sublime Text 3_is1) (Version:  - Sublime HQ Pty Ltd)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.3.8.62 - Synaptics Incorporated)
Twitch (HKU\S-1-5-21-3759363114-2796580450-4264558159-1000\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 7.0.0.0 - Twitch Interactive, Inc.)
WIDCOMM Bluetooth Software (HKLM\...\{A1439D4F-FD46-47F2-A1D3-FEE097C29A09}) (Version: 6.5.1.5100 - Broadcom Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3759363114-2796580450-4264558159-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-01-28] (Igor Pavlov)
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-03] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-01-28] (Igor Pavlov)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2014-03-07] (Intel Corporation)
ContextMenuHandlers5: [igfxOSP] -> {FA507C3F-30C6-4DCA-9EE5-2656072EEC14} => C:\Windows\system32\igfxOSP.dll [2014-03-07] (Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2013-10-23] (NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-01-28] (Igor Pavlov)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-03] (Malwarebytes)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {3C5D78E5-4083-4125-B0A1-A19A2362D59D} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-01-10] (NVIDIA Corporation)
Task: {3F638687-49F4-459C-B635-FE77460F9E3D} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2018-01-10] (NVIDIA Corporation)
Task: {40EC8FE0-3C9B-4A7A-8579-3FDD31DF661D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-02-21] (Google Inc.)
Task: {56B93278-1E8C-4F07-90C9-12BE5131E688} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2018-01-10] (NVIDIA Corporation)
Task: {5C49A9B4-776E-41CD-B7AA-DA71102ED149} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2018-01-10] (NVIDIA Corporation)
Task: {AC2453DA-5CF3-4503-A56F-E0FF187FBCB2} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-01-10] (NVIDIA Corporation)
Task: {C0712B9E-D137-42E1-96E4-D236E66BC9B8} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-05-13] (Realtek Semiconductor)
Task: {C548C471-1606-441E-B8D8-216FDC20BA58} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-01-10] (NVIDIA Corporation)
Task: {CC98245B-1C92-4963-9F8E-CF6291EC782F} - System32\Tasks\Start Alarm Software => C:\Users\Zed\Desktop\FreeAlarmClockPortable\FreeAlarmClock.exe [2016-01-19] (Comfort Software Group)
Task: {CF0E3FC4-82CE-4111-8270-F35ABEB675FD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-02-21] (Google Inc.)
Task: {CF25F80F-75D6-4041-9BE3-57A8554B8CC1} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-01-10] (NVIDIA Corporation)
Task: {D9F7A3BD-2D64-46DD-A841-5136EE7ABB8A} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-01-10] (NVIDIA Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2018-02-07 22:57 - 2013-10-23 01:20 - 000102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2018-02-08 21:48 - 2018-01-10 07:05 - 001269096 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2018-03-11 04:46 - 2018-02-05 14:44 - 002299168 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-02-07 22:33 - 2017-09-13 18:11 - 000742512 _____ () C:\Program Files\Sublime Text 3\plugin_host.exe
2017-03-09 19:11 - 2017-03-09 19:11 - 000036878 _____ () C:\Program Files (x86)\Pidgin\libssp-0.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000671031 _____ () C:\Program Files (x86)\Pidgin\exchndl.dll
2018-02-07 22:32 - 2018-02-07 22:32 - 000904525 _____ () C:\Program Files (x86)\Pidgin\Gtk\bin\libcairo-2.dll
2018-02-07 22:32 - 2018-02-07 22:32 - 000279059 _____ () C:\Program Files (x86)\Pidgin\Gtk\bin\libfontconfig-1.dll
2018-02-07 22:32 - 2018-02-07 22:32 - 000177586 _____ () C:\Program Files (x86)\Pidgin\Gtk\bin\libexpat-1.dll
2018-02-07 22:32 - 2018-02-07 22:32 - 000553382 _____ () C:\Program Files (x86)\Pidgin\Gtk\bin\freetype6.dll
2018-02-07 22:32 - 2018-02-07 22:32 - 000216992 _____ () C:\Program Files (x86)\Pidgin\Gtk\bin\libpng14-14.dll
2018-02-07 22:32 - 2018-02-07 22:32 - 000118272 _____ () C:\Program Files (x86)\Pidgin\Gtk\bin\zlib1.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 001136034 _____ () C:\Program Files (x86)\Pidgin\libxml2-2.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000475580 _____ () C:\Program Files (x86)\Pidgin\spellcheck\libgtkspell-0.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000020997 _____ () C:\Program Files (x86)\Pidgin\plugins\autoaccept.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000013253 _____ () C:\Program Files (x86)\Pidgin\plugins\buddynote.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000024924 _____ () C:\Program Files (x86)\Pidgin\plugins\convcolors.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000015702 _____ () C:\Program Files (x86)\Pidgin\plugins\extplacement.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000014147 _____ () C:\Program Files (x86)\Pidgin\plugins\gtkbuddynote.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000018882 _____ () C:\Program Files (x86)\Pidgin\plugins\history.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000012865 _____ () C:\Program Files (x86)\Pidgin\plugins\iconaway.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000019043 _____ () C:\Program Files (x86)\Pidgin\plugins\idle.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000018555 _____ () C:\Program Files (x86)\Pidgin\plugins\joinpart.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000015074 _____ () C:\Program Files (x86)\Pidgin\plugins\libaim.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000315843 _____ () C:\Program Files (x86)\Pidgin\liboscar.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000093066 _____ () C:\Program Files (x86)\Pidgin\plugins\libbonjour.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000332178 _____ () C:\Program Files (x86)\Pidgin\plugins\libgg.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000016005 _____ () C:\Program Files (x86)\Pidgin\plugins\libicq.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000108441 _____ () C:\Program Files (x86)\Pidgin\plugins\libirc.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000128694 _____ () C:\Program Files (x86)\Pidgin\libsasl2-3.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000123540 _____ () C:\Program Files (x86)\Pidgin\plugins\libnovell.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000116071 _____ () C:\Program Files (x86)\Pidgin\plugins\libsametime.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000152852 _____ () C:\Program Files (x86)\Pidgin\libmeanwhile-1.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000171123 _____ () C:\Program Files (x86)\Pidgin\plugins\libsilc.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000868705 _____ () C:\Program Files (x86)\Pidgin\libsilc-1-1-4.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000225616 _____ () C:\Program Files (x86)\Pidgin\libsilcclient-1-1-4.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000055880 _____ () C:\Program Files (x86)\Pidgin\plugins\libsimple.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000021337 _____ () C:\Program Files (x86)\Pidgin\plugins\libxmpp.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000416644 _____ () C:\Program Files (x86)\Pidgin\libjabber.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000047934 _____ () C:\Program Files (x86)\Pidgin\plugins\log_reader.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000021795 _____ () C:\Program Files (x86)\Pidgin\plugins\markerline.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000013456 _____ () C:\Program Files (x86)\Pidgin\plugins\newline.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000029737 _____ () C:\Program Files (x86)\Pidgin\plugins\notify.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000021075 _____ () C:\Program Files (x86)\Pidgin\plugins\nss-prefs.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000017023 _____ () C:\Program Files (x86)\Pidgin\plugins\offlinemsg.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000029256 _____ () C:\Program Files (x86)\Pidgin\plugins\pidginrc.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000015380 _____ () C:\Program Files (x86)\Pidgin\plugins\psychic.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000015429 _____ () C:\Program Files (x86)\Pidgin\plugins\relnot.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000015045 _____ () C:\Program Files (x86)\Pidgin\plugins\sendbutton.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000069625 _____ () C:\Program Files (x86)\Pidgin\plugins\spellchk.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000031993 _____ () C:\Program Files (x86)\Pidgin\plugins\ssl-nss.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000012004 _____ () C:\Program Files (x86)\Pidgin\plugins\ssl.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000015978 _____ () C:\Program Files (x86)\Pidgin\plugins\statenotify.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000030353 _____ () C:\Program Files (x86)\Pidgin\plugins\themeedit.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000032020 _____ () C:\Program Files (x86)\Pidgin\plugins\ticker.dll
2017-03-09 19:12 - 2017-03-09 19:12 - 000018399 _____ () C:\Program Files (x86)\Pidgin\plugins\timestamp.dll
2017-03-09 19:12 - 2017-03-09 19:12 - 000023851 _____ () C:\Program Files (x86)\Pidgin\plugins\timestamp_format.dll
2017-03-09 19:12 - 2017-03-09 19:12 - 000029791 _____ () C:\Program Files (x86)\Pidgin\plugins\win2ktrans.dll
2017-03-09 19:12 - 2017-03-09 19:12 - 000030771 _____ () C:\Program Files (x86)\Pidgin\plugins\winprefs.dll
2017-03-09 19:12 - 2017-03-09 19:12 - 000037191 _____ () C:\Program Files (x86)\Pidgin\plugins\xmppconsole.dll
2017-03-09 19:12 - 2017-03-09 19:12 - 000044494 _____ () C:\Program Files (x86)\Pidgin\plugins\xmppdisco.dll
2017-03-09 19:12 - 2017-03-09 19:12 - 000048402 _____ () C:\Program Files (x86)\Pidgin\sasl2\libanonymous-3.dll
2017-03-09 19:12 - 2017-03-09 19:12 - 000049962 _____ () C:\Program Files (x86)\Pidgin\sasl2\libcrammd5-3.dll
2017-03-09 19:12 - 2017-03-09 19:12 - 000079858 _____ () C:\Program Files (x86)\Pidgin\sasl2\libdigestmd5-3.dll
2017-03-09 19:12 - 2017-03-09 19:12 - 000048907 _____ () C:\Program Files (x86)\Pidgin\sasl2\libplain-3.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000554496 _____ () C:\Program Files (x86)\Pidgin\sqlite3.dll
2018-02-07 22:32 - 2018-02-07 22:32 - 000090496 _____ () C:\Program Files (x86)\Pidgin\Gtk\lib\gtk-2.0\2.10.0\engines\libwimp.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000509014 _____ () C:\Program Files (x86)\Pidgin\spellcheck\lib\enchant\libenchant_ispell.dll
2017-03-09 19:11 - 2017-03-09 19:11 - 000999501 _____ () C:\Program Files (x86)\Pidgin\spellcheck\lib\enchant\libenchant_myspell.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:34 - 2018-03-21 11:38 - 000000027 _____ C:\Windows\system32\Drivers\etc\hosts

127.0.0.1       localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3759363114-2796580450-4264558159-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Zed\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\Services: AERTFilters => 2
MSCONFIG\Services: btwdins => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: MBAMService => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\Windows\pss\Bluetooth.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Killer Network Manager.lnk => C:\Windows\pss\Killer Network Manager.lnk.CommonStartup
MSCONFIG\startupreg: Spotify => C:\Users\Zed\AppData\Roaming\Spotify\Spotify.exe --autostart --minimized
MSCONFIG\startupreg: Spotify Web Helper => C:\Users\Zed\AppData\Roaming\Spotify\SpotifyWebHelper.exe --autostart
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\steam.exe" -silent
MSCONFIG\startupreg: SynTPEnh => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{5B074ABD-75D0-47A0-8557-EAF366C7F9D8}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{C61AC3C7-7CD8-4915-A7BC-26AA33204256}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{DB75B153-3A32-4612-90E0-434F70FDB8F1}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{16413A9A-F570-4447-8869-C24941641D41}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{FB3B4EA3-042C-44F8-B62F-DC385C56634B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{243217B3-84C6-419C-865B-7260CB0857A0}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{0DDF1353-D152-49A5-8D56-6DBF74457D9A}C:\users\zed\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\zed\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{64645C8C-BBC0-4018-B36F-7C85642F8D39}C:\users\zed\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\zed\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{9A561BF6-21F7-478B-A39B-74F2A9370479}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{A9ACB954-9924-46F5-AF77-8592659D2A1B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{EA150B3C-85AB-43EA-AB40-38FBCBD40C4F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{DDB4A486-CBE0-492C-B691-8B459918712F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{E27FDD0C-F13A-4773-B1FB-A9A3970B25C2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{FC6E9F05-5831-4D24-B8DE-1A606E16E23E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{BAB03F8B-47E6-4FB1-AFB4-24C7063248ED}C:\users\zed\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\zed\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{78928721-8914-46B1-AF80-668332B7FBB7}C:\users\zed\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\zed\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{330C7FC1-3C2A-4B7C-AE3F-00A2273791D4}C:\users\zed\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\zed\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{7C688177-5345-4327-946E-EE32B543381F}C:\users\zed\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\zed\appdata\roaming\spotify\spotify.exe
FirewallRules: [{7FA029D7-D479-43FE-A451-BD4B17C00D6C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{EBEC033C-FABD-4042-A0B0-6168605A5417}C:\users\zed\desktop\eco.v0.7.2.2\eco_data\server\ecoserver.exe] => (Block) C:\users\zed\desktop\eco.v0.7.2.2\eco_data\server\ecoserver.exe
FirewallRules: [UDP Query User{52EAFC52-BB5C-4B4D-BC95-1CEDC583ECCD}C:\users\zed\desktop\eco.v0.7.2.2\eco_data\server\ecoserver.exe] => (Block) C:\users\zed\desktop\eco.v0.7.2.2\eco_data\server\ecoserver.exe

==================== Restore Points =========================

07-03-2018 22:30:03 Windows Update
11-03-2018 03:26:46 Windows Update
14-03-2018 11:51:33 Windows Update
14-03-2018 12:05:21 Windows Update
17-03-2018 16:34:30 Windows Update
20-03-2018 20:13:54 Windows Update
21-03-2018 11:49:40 Checkpoint by HitmanPro
21-03-2018 11:51:01 Removed Windows 7 USB/DVD Download Tool
21-03-2018 11:52:00 Checkpoint by HitmanPro
21-03-2018 11:52:38 Checkpoint by HitmanPro

==================== Faulty Device Manager Devices =============

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Synaptics SMBus TouchPad
Description: Synaptics SMBus TouchPad
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Synaptics
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/21/2018 12:08:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (03/21/2018 12:07:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: RAVBg64.exe, version: 1.0.0.193, time stamp: 0x53720efa
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x000000000211b900
Faulting process id: 0x52c
Faulting application start time: 0x01d3c13f407276e8
Faulting application path: C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
Faulting module path: unknown
Report Id: 152a570d-2d3b-11e8-97ec-240a646ec005

Error: (03/21/2018 11:52:46 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000031c,SYSTEM\CurrentControlSet\Services\VSS\Diag\VssvcPublisher,0,REG_BINARY,0000000001DDECB0.72).  hr = 0x80070005, Access is denied.
.

Error: (03/21/2018 11:52:46 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000002dc,(null),0,REG_BINARY,0000000001E3DED0.72).  hr = 0x80070005, Access is denied.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {7c8e8d29-b1d0-4e5a-86f2-64c59fe9842b}

Error: (03/21/2018 11:52:46 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001e4,SYSTEM\CurrentControlSet\Services\VSS\Diag\COM+ REGDB Writer,0,REG_BINARY,000000000300F000.72).  hr = 0x80070005, Access is denied.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {542da469-d3e1-473c-9f4f-7847f01fc64f}
   Writer Name: COM+ REGDB Writer
   Writer Instance ID: {761617f9-4a19-4a7a-96de-2b988ab80b4f}

Error: (03/21/2018 11:52:46 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000d90,(null),0,REG_BINARY,000000000A08E3A0.72).  hr = 0x80070005, Access is denied.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2}
   Writer Name: MSSearch Service Writer
   Writer Instance ID: {847bdde6-217c-484a-9ea5-b76b8b34d36f}

Error: (03/21/2018 11:52:46 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000604,(null),0,REG_BINARY,0000000000F0E340.72).  hr = 0x80070005, Access is denied.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {ae94f378-5f8d-4112-8110-5845aec44b5e}

Error: (03/21/2018 11:52:46 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000002dc,(null),0,REG_BINARY,0000000001E3DED0.72).  hr = 0x80070005, Access is denied.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {7c8e8d29-b1d0-4e5a-86f2-64c59fe9842b}


System errors:
=============
Error: (03/21/2018 12:08:10 PM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.

Reported by component: Processor Core
Error Source: 3
Error Type: 9
Processor ID: 0

The details view of this entry contains further information.

Error: (03/21/2018 12:08:10 PM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.

Reported by component: Processor Core
Error Source: 3
Error Type: 9
Processor ID: 0

The details view of this entry contains further information.

Error: (03/21/2018 12:05:11 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Type with the following error:
Access is denied.

Error: (03/21/2018 12:05:10 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Type with the following error:
Access is denied.

Error: (03/21/2018 11:44:37 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The PEVSystemStart service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.

Error: (03/21/2018 11:43:29 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The PEVSystemStart service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.

Error: (03/21/2018 11:38:13 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The PEVSystemStart service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.

Error: (03/21/2018 11:37:58 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.


CodeIntegrity:
===================================

Date: 2018-03-21 11:37:58.581
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-03-21 11:37:58.566
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

Processor: Intel® Core™ i7-4700MQ CPU @ 2.40GHz
Percentage of memory in use: 44%
Total physical RAM: 8077.11 MB
Available physical RAM: 4453.52 MB
Total Virtual: 16152.38 MB
Available Virtual: 12121.96 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:110.78 GB) (Free:61.94 GB) NTFS
Drive e: (MagneticDisk) (Fixed) (Total:698.6 GB) (Free:698.2 GB) NTFS
Drive f: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from drive)]

\\?\Volume{fab45f7d-0c86-11e8-9a47-806e6f6e6963}\ () (Fixed) (Total:0.91 GB) (Free:0.43 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 698.6 GB) (Disk ID: A7EB6FAE)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=698.6 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 111.8 GB) (Disk ID: A300234D)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=110.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=928 MB) - (Type=27)

==================== End of Addition.txt ============================

Attached Files



BC AdBot (Login to Remove)

 


#2 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,798 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:03:07 AM

Posted 22 March 2018 - 11:57 AM

dementedreality:

 
 
:welcome: to the Bleeping Computer Virus, Trojans, Spyware, and Malware Removal Logs Forum.  My name is Phil.  May I address you by your first name?
 
I will be assisting you with your computer issues.  I will endeavor to respond within a reasonable time.   Forum policy requires that I post within 48 hours after your last post, but I do endeavor to post within 24 hours of your last post.
 
I would ask that you please continue to copy and paste the contents of all requested log files directly into your replies.   Please do not use "code" or "quote" boxes.  Thank you for your anticipated cooperation.
 
I will need some time to review your FRST logs.  That could take a day or two, but I do hope to respond later today with an initial FRST "fixlist" script.
 
PLEASE DO NOT RUN ANY ADDITIONAL SCANS OR ANTI-MALWARE REMOVAL TOOLS UNTIL YOU HAVE RECEIVED A RESPONSE FROM ME.
Doing so would complicate the situation and it would cause further delays in resolving your issues.  It could also potentially result in harm to your computer because my "fix" will be based on the FRST scan logs you have already submitted.
 
Thank you and have a great day.
 
Regards,
-Phil

Graduate of the Bleeping Computer Malware Removal Study Hall


#3 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,798 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:03:07 AM

Posted 22 March 2018 - 12:57 PM

dementedreality:

Thank you for your patience while I analyzed your FRST logs.

Before we start dealing with the problems you are experiencing, I would ask that you to take note of the following points:

  • I am a Bleeping Computer volunteer, so I ask you to be patient. I know it is frustrating when your computer is not working properly, but malware removal takes time.
  • Please also remember that I can only dedicate a limited number of hours a day to helping people. We may live in different time zones, which may cause delays in responding.
  • If I have not responded to you within 48 hours, please send me a personal message. Likewise, I expect you to respond within 48 hours, and sooner is better because we can fix your computer faster.
  • If I have not heard from you in three days, I will "bump" your post. After five days of no response, I will consider that you no longer need my assistance and this thread will be closed.
  • Logs can take a while to research, so please be patient.
  • Some issues just cannot be solved so you must be prepared for this.
  • Please read and follow the instructions in the exact sequence that they are posted to avoid making a bad situation worse.
  • Please print or copy and save the instructions.
  • Back up all your data and important files on another (external) drive before starting to run malware removal tools. Malware removal can cause unpredictable and unintended issues. Also you should be aware that some of the tools and scripts that will be used, will remove malware detected, without notice.
  • You should try to limit your browsing with this computer until you are given the "All Clear." Some malware applications steal passwords.
  • Please do not install or uninstall any applications, unless directed. Don't run any scripts or tools on your own because unsupervised usage may cause more harm than good.
  • Please use only the tools you have been instructed to use.
  • If you are using CD/DVD emulation software, this should be uninstalled or disabled as it can interfere with the removal of some malware. It can be turned off with Defogger and then turned back on when you get the "All Clear."
  • Please copy and paste the requested log files inside your post(s), unless otherwise instructed. Please do not use code or quote boxes.
  • There are no silly questions. Ask for clarification, if you have any questions or concerns.
  • Bleeping Computer does not support any piracy. Evidence of illegal OS, software, cracks/keygens, etc., will be revealed by scan logs, and if found, further assistance may be suspended. Uninstall such software before proceeding!
  • Any P2P software such as uTorrent, BitTorrent, Kazaa, etc. must be uninstalled or completely disabled. P2P software is a major security risk to your computer and may have been the route the malware used to infect your computer.
  • Failure to follow these guidelines may result in assistance being withdrawn and your thread being closed.
  • I am volunteering my time to help you, and I will need you to help me. Together, we can, hopefully, disinfect your computer and get if functioning properly again. That is my only aim.

.

OK, let's get started ...

.

:step1: Please run a FRST fix for me.

NOTICE: This FRST "fixlist" script was written specifically for this user, for use on this individual computer. Running this on another computer may cause damage to your operating system.
 

Start::
CreateRestorePoint:
CloseProcesses:
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
Folder: C:\ComboFix
File: C:\Users\Zed\AppData\Local\kritarc
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
End::
  • Please highlight the entire contents of the code box above, from the "Start::" line to the "End::" line, including both of those lines, right click, and select "Copy", which will copy the "fix" script into the Windows clipboard.
  • Right click FRST64.exe, and select "Run as Administrator".
  • Press Fix button once and wait.
  • Please reboot the computer, if requested.
  • A log file called "fixlog.txt" will be saved in the same folder as the FRST program is located.
  • Please copy and paste the contents of the "fixlog.txt" file into your next reply.

.

Thank you and have a great day.

Regards,
-Phil

Uninstall ComboFix
 


Graduate of the Bleeping Computer Malware Removal Study Hall


#4 dementedreality

dementedreality
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:07 PM

Posted 22 March 2018 - 04:14 PM

My name is Alex.

Combofix uninstalled.

Fix result of Farbar Recovery Scan Tool (x64) Version: 14.03.2018
Ran by Zed (22-03-2018 14:11:30) Run:1
Running from C:\Users\Zed\Desktop
Loaded Profiles: Zed (Available Profiles: Zed)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
Folder: C:\ComboFix
File: C:\Users\Zed\AppData\Local\kritarc
ContextMenuHandlers5: [igfxcui] -&gt; {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =&gt; -&gt; No File

*****************

Restore point was successfully created.
Processes closed successfully.
"HKLM\System\CurrentControlSet\Services\catchme" =&gt; removed successfully
catchme =&gt; service removed successfully

========================= Folder: C:\ComboFix ========================

not found.

====== End of Folder: ======


========================= File: C:\Users\Zed\AppData\Local\kritarc ========================

C:\Users\Zed\AppData\Local\kritarc
File not signed
MD5: 52C0DE5493B36F95135EAD86C818B243
Creation and modification date: 2018-02-14 06:41 - 2018-02-21 07:52
Size: 000015311
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
VirusTotal: 0

====== End of File: ======

"HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui" =&gt; removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =&gt; not found


The system needed a reboot.

==== End of Fixlog 14:11:41 ====

Edited by dementedreality, 22 March 2018 - 04:21 PM.


#5 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,798 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:03:07 AM

Posted 23 March 2018 - 05:50 AM

Alex:

 

Thank you for your post, for permission to address you by your first name, for the update that ComboFix has been uninstalled, and for copying and pasting the contents of the FRST "fixlog.txt" file.

 

We strongly recommend that users do not run ComboFix, unless under supervision and only when directed to do so.  Please see this post for more information that explains the reasons for this position.  Personally, I would never run ComboFix on a computer, unless every other option available to me had failed to remediate a malware infection, and that has never happened.  Thankfully, the product is incompatible with Windows 8 and 10, since it is no longer being updated, thus sparing users of those versions of Windows from potentially damaging their computers by running it unsupervised.

 

How did you uninstall Combofix, exactly?  The reason that I ask is that, unless uninstalled correctly, it will leave remnants behind and I will want a fresh copy of the "FRST.txt" log only to check for those remnants and eliminate them, if present.

 

Thank you and have a great day.

 

Regards,

-Phil


Graduate of the Bleeping Computer Malware Removal Study Hall


#6 dementedreality

dementedreality
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:07 PM

Posted 23 March 2018 - 06:06 AM

I ran combofix /uninstall

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018
Ran by Zed (administrator) on BOXBRAIN (23-03-2018 04:04:51)
Running from C:\Users\Zed\Desktop
Loaded Profiles: Zed (Available Profiles: Zed)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(f.lux Software LLC) C:\Users\Zed\AppData\Local\FluxSoftware\Flux\flux.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareTactXMacroController.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [286192 2013-04-10] (Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7611608 2014-06-02] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1387376 2014-05-13] (Realtek Semiconductor)
HKLM\...\Run: [Command Center Controllers] => C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [14056 2014-10-30] (Alienware)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-25] (Logitech, Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-24] (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-3759363114-2796580450-4264558159-1000\...\Run: [f.lux] => C:\Users\Zed\AppData\Local\FluxSoftware\Flux\flux.exe [1682936 2018-01-17] (f.lux Software LLC)
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
GroupPolicy: Restriction {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)

FireFox:
========
FF DefaultProfile: 93gavzue.default
FF ProfilePath: C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default [2018-03-23]
FF Session Restore: Mozilla\Firefox\Profiles\93gavzue.default -> is enabled.
FF NewTabOverride: Mozilla\Firefox\Profiles\93gavzue.default -> Enabled: CookieAutoDelete@kennydo.com
FF NewTabOverride: Mozilla\Firefox\Profiles\93gavzue.default -> Enabled: jid1-MnnxcxisBPnSXQ-eff@jetpack
FF Extension: (Cookie AutoDelete) - C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default\Extensions\CookieAutoDelete@kennydo.com.xpi [2018-02-12]
FF Extension: (Name) - C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default\Extensions\firefox@ghostery.com.xpi [2018-03-21]
FF Extension: (Privacy Badger) - C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default\Extensions\jid1-MnnxcxisBPnSXQ-eff@jetpack.xpi [2018-03-21]
FF Extension: (NoScript) - C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2018-03-16]
FF Extension: (Adblock Plus) - C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-02-07]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2018-02-22] [Legacy] [not signed]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-10-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-10-23] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-02-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-02-21] (Google Inc.)

Chrome:
=======
CHR Profile: C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default [2018-03-21]
CHR Extension: (Slides) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-02-21]
CHR Extension: (Docs) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-21]
CHR Extension: (Google Drive) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-21]
CHR Extension: (YouTube) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-21]
CHR Extension: (Sheets) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-21]
CHR Extension: (Google Docs Offline) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-02-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-02-21]
CHR Extension: (Gmail) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-02-21]
CHR Extension: (Chrome Media Router) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-02-21]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-10] (Intel Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-11] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel® Corporation)
S3 ioloEnergyBooster; C:\Program Files\Alienware\Command Center\ioloEnergyBooster.exe [6145872 2012-11-01] (iolo technologies, LLC)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6440736 2018-03-03] (Malwarebytes)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [521064 2018-01-10] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [521064 2018-01-10] (NVIDIA Corporation)
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [340480 2013-10-08] (Qualcomm Atheros) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-07] (Realtek Semiconductor)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)

Edited by dementedreality, 23 March 2018 - 06:08 AM.


#7 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,798 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:03:07 AM

Posted 23 March 2018 - 07:37 AM

Alex:
 
Thank you for your post.  That is the correct way to uninstall ComboFix:thumbup2:  I would still like to see a fresh FRST scan log: only the "FRST.txt" scan.  I don't need the "Addition.txt" scan log file.  With ComboFix, I like to sure that it is entirely gone.
 
Your previous FRST scan log "FRST,txt" file was truncated at the "Drivers" section.  Can you try to run it again and past the complete log?  It should say, at the end:
 


==================== End of FRST.txt ============================

 
 
The "FRST.txt" log file for your computer should be about 600 lines long.
 
Thank you and have a great day.
 
Regards,
-Phil


Graduate of the Bleeping Computer Malware Removal Study Hall


#8 dementedreality

dementedreality
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:07 PM

Posted 23 March 2018 - 08:06 AM

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018
Ran by Zed (administrator) on BOXBRAIN (23-03-2018 06:05:24)
Running from C:\Users\Zed\Desktop
Loaded Profiles: Zed (Available Profiles: Zed)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(f.lux Software LLC) C:\Users\Zed\AppData\Local\FluxSoftware\Flux\flux.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareTactXMacroController.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [286192 2013-04-10] (Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7611608 2014-06-02] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1387376 2014-05-13] (Realtek Semiconductor)
HKLM\...\Run: [Command Center Controllers] => C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [14056 2014-10-30] (Alienware)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-25] (Logitech, Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-24] (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-3759363114-2796580450-4264558159-1000\...\Run: [f.lux] => C:\Users\Zed\AppData\Local\FluxSoftware\Flux\flux.exe [1682936 2018-01-17] (f.lux Software LLC)
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
GroupPolicy: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{49986D67-FD5F-475B-BD9D-EF4AA77FD211}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{4CD58847-17AB-4170-BDF0-FC3113FC231B}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{4CD58847-17AB-4170-BDF0-FC3113FC231B}: [DhcpNameServer] 75.75.75.75 75.75.76.76

Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3759363114-2796580450-4264558159-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)

FireFox:
========
FF DefaultProfile: 93gavzue.default
FF ProfilePath: C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default [2018-03-23]
FF Session Restore: Mozilla\Firefox\Profiles\93gavzue.default -> is enabled.
FF NewTabOverride: Mozilla\Firefox\Profiles\93gavzue.default -> Enabled: CookieAutoDelete@kennydo.com
FF NewTabOverride: Mozilla\Firefox\Profiles\93gavzue.default -> Enabled: jid1-MnnxcxisBPnSXQ-eff@jetpack
FF Extension: (Cookie AutoDelete) - C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default\Extensions\CookieAutoDelete@kennydo.com.xpi [2018-02-12]
FF Extension: (Name) - C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default\Extensions\firefox@ghostery.com.xpi [2018-03-21]
FF Extension: (Privacy Badger) - C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default\Extensions\jid1-MnnxcxisBPnSXQ-eff@jetpack.xpi [2018-03-21]
FF Extension: (NoScript) - C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2018-03-16]
FF Extension: (Adblock Plus) - C:\Users\Zed\AppData\Roaming\Mozilla\Firefox\Profiles\93gavzue.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-02-07]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2018-02-22] [Legacy] [not signed]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-10-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-10-23] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-02-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-02-21] (Google Inc.)

Chrome:
=======
CHR Profile: C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default [2018-03-21]
CHR Extension: (Slides) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-02-21]
CHR Extension: (Docs) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-21]
CHR Extension: (Google Drive) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-21]
CHR Extension: (YouTube) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-21]
CHR Extension: (Sheets) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-21]
CHR Extension: (Google Docs Offline) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-02-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-02-21]
CHR Extension: (Gmail) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-02-21]
CHR Extension: (Chrome Media Router) - C:\Users\Zed\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-02-21]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-10] (Intel Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-11] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel® Corporation)
S3 ioloEnergyBooster; C:\Program Files\Alienware\Command Center\ioloEnergyBooster.exe [6145872 2012-11-01] (iolo technologies, LLC)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6440736 2018-03-03] (Malwarebytes)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [521064 2018-01-10] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [521064 2018-01-10] (NVIDIA Corporation)
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [340480 2013-10-08] (Qualcomm Atheros) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-07] (Realtek Semiconductor)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [172760 2018-02-07] (Broadcom Corporation.)
R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [67888 2013-02-13] (Qualcomm Atheros, Inc.)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [27552 2018-02-07] (REALiX™)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-04-10] (Intel Corporation)
R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [154320 2013-03-20] (Qualcomm Atheros, Inc.)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-03-23] (Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [300320 2013-10-23] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [32104 2018-01-10] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [59240 2017-12-14] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [59752 2018-01-10] (NVIDIA Corporation)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [32496 2013-04-08] (Synaptics Incorporated)
R3 ST_ACCEL; C:\Windows\System32\DRIVERS\ST_Accel.sys [87776 2013-04-11] (STMicroelectronics)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-22 14:19 - 2018-03-22 14:19 - 000000000 ___SD C:\ComboFix
2018-03-22 14:11 - 2018-03-22 14:11 - 000001584 _____ C:\Users\Zed\Desktop\Fixlog.txt
2018-03-22 06:32 - 2018-03-22 06:32 - 000026060 _____ C:\ComboFix.txt
2018-03-22 06:04 - 2018-03-22 06:04 - 000001035 _____ C:\Users\Zed\Desktop\start emergency kit scanner.exe - Shortcut.lnk
2018-03-22 05:38 - 2018-03-22 05:38 - 000015198 _____ C:\Users\Zed\Desktop\Spirals Exercises
2018-03-22 05:37 - 2018-03-22 05:37 - 000016712 _____ C:\Users\Zed\Desktop\Quicksilver Exercises
2018-03-21 17:35 - 2018-03-21 17:35 - 000003100 _____ C:\Windows\System32\Tasks\{11698239-3C11-47BF-B7C2-B0A7BC02C3C1}
2018-03-21 17:32 - 2018-03-21 17:32 - 000037888 _____ (Soeperman Enterprises Ltd.) C:\Users\Zed\Desktop\ADSSpy.exe
2018-03-21 13:03 - 2018-03-23 06:05 - 000015896 _____ C:\Users\Zed\Desktop\FRST.txt
2018-03-21 13:03 - 2018-03-23 04:05 - 000032407 _____ C:\Users\Zed\Desktop\Addition.txt
2018-03-21 13:02 - 2018-03-21 13:02 - 002403328 _____ (Farbar) C:\Users\Zed\Desktop\FRST64.exe
2018-03-21 12:05 - 2018-03-21 12:05 - 000000000 ____D C:\ProgramData\Emsisoft
2018-03-21 12:04 - 2018-03-22 06:06 - 000000000 ____D C:\EEK
2018-03-21 11:53 - 2018-03-22 05:47 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-03-21 11:53 - 2018-03-21 12:03 - 000000000 ____D C:\ProgramData\RogueKiller
2018-03-21 11:52 - 2018-03-21 11:52 - 000012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe
2018-03-21 11:47 - 2018-03-21 11:53 - 000000000 ____D C:\ProgramData\HitmanPro
2018-03-21 11:46 - 2018-03-21 11:46 - 000001587 _____ C:\Users\Zed\Desktop\mbam.exe - Shortcut.lnk
2018-03-21 11:34 - 2018-03-22 14:19 - 000000000 ____D C:\Windows\erdnt
2018-03-21 11:34 - 2018-03-22 14:19 - 000000000 ____D C:\Qoobox
2018-03-21 11:33 - 2018-03-21 11:34 - 027005512 _____ (Adlice Software) C:\Users\Zed\Desktop\RogueKiller_portable64.exe
2018-03-21 11:32 - 2018-03-21 11:33 - 011605440 _____ (SurfRight B.V.) C:\Users\Zed\Desktop\HitmanPro_x64.exe
2018-03-21 11:25 - 2018-03-21 11:25 - 000255928 _____ (Malwarebytes) C:\Windows\system32\Drivers\252733D6.sys
2018-03-21 11:24 - 2018-03-21 11:32 - 000000000 ____D C:\Users\Zed\Desktop\mbar
2018-03-21 11:24 - 2018-03-21 11:32 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2018-03-21 11:24 - 2018-03-21 11:24 - 000192952 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2018-03-21 10:55 - 2018-03-23 04:04 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-03-16 04:30 - 2018-03-16 04:31 - 008222496 _____ (Malwarebytes) C:\Users\Zed\Desktop\AdwCleaner.exe
2018-03-16 04:29 - 2018-03-16 04:29 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\Zed\Desktop\rkill.exe
2018-03-14 21:34 - 2018-03-14 21:34 - 000000000 ____D C:\ProgramData\Oracle
2018-03-14 11:51 - 2018-03-08 20:39 - 005580992 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-03-14 11:51 - 2018-03-08 20:39 - 000708288 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-03-14 11:51 - 2018-03-08 20:39 - 000262336 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-03-14 11:51 - 2018-03-08 20:39 - 000154816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-03-14 11:51 - 2018-03-08 20:39 - 000095424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-03-14 11:51 - 2018-03-08 20:18 - 000631640 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-03-14 11:51 - 2018-03-08 20:14 - 004044992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-03-14 11:51 - 2018-03-08 20:14 - 004025536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-03-14 11:51 - 2018-03-08 20:09 - 001665336 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 001461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000094720 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 20:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:47 - 001314064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:38 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-03-14 11:51 - 2018-03-08 19:38 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-03-14 11:51 - 2018-03-08 19:38 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-03-14 11:51 - 2018-03-08 19:37 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-03-14 11:51 - 2018-03-08 19:34 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-03-14 11:51 - 2018-03-08 19:34 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-03-14 11:51 - 2018-03-08 19:33 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-03-14 11:51 - 2018-03-08 19:31 - 000160256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-03-14 11:51 - 2018-03-08 19:30 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-03-14 11:51 - 2018-03-08 19:30 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-03-14 11:51 - 2018-03-08 19:29 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-03-14 11:51 - 2018-03-08 19:29 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-03-14 11:51 - 2018-03-08 19:26 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-03-14 11:51 - 2018-03-08 19:22 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-03-14 11:51 - 2018-03-08 19:22 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-03-14 11:51 - 2018-03-08 19:22 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-03-14 11:51 - 2018-03-08 19:22 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-03-14 11:51 - 2018-03-08 19:22 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-03-14 11:51 - 2018-03-08 19:21 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:21 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:21 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-03-14 11:51 - 2018-03-08 19:21 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-03-14 11:51 - 2018-03-01 01:36 - 003226112 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-03-14 11:51 - 2018-02-21 20:28 - 000217600 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2018-03-14 11:51 - 2018-02-21 20:06 - 000134656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2018-03-14 11:51 - 2018-02-18 14:34 - 000634272 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-03-14 11:51 - 2018-02-16 21:27 - 000395928 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-03-14 11:51 - 2018-02-16 20:36 - 000340088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-03-14 11:51 - 2018-02-16 08:51 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-03-14 11:51 - 2018-02-16 08:51 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-03-14 11:51 - 2018-02-16 08:51 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-03-14 11:51 - 2018-02-16 08:45 - 025742848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-03-14 11:51 - 2018-02-16 08:44 - 013678080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-03-14 11:51 - 2018-02-16 08:24 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-03-14 11:51 - 2018-02-16 08:24 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-03-14 11:51 - 2018-02-16 08:24 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-03-14 11:51 - 2018-02-16 08:19 - 020286976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-03-14 11:51 - 2018-02-16 07:37 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-03-14 11:51 - 2018-02-16 07:37 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-03-14 11:51 - 2018-02-15 08:15 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-03-14 11:51 - 2018-02-15 07:57 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-03-14 11:51 - 2018-02-10 11:35 - 000367296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000334528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000185024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000122560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\NV_AGP.SYS
2018-03-14 11:51 - 2018-02-10 11:35 - 000068288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000064192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ULIAGPKX.SYS
2018-03-14 11:51 - 2018-02-10 11:35 - 000063168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000060608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\AGP440.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000036032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vdrvroot.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000031936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mssmbios.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000023744 _____ (Microsoft Corporation) C:\Windows\system32\streamci.dll
2018-03-14 11:51 - 2018-02-10 11:35 - 000020160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\isapnp.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000015040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msisadrv.sys
2018-03-14 11:51 - 2018-02-10 11:35 - 000012096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\swenum.sys
2018-03-14 11:51 - 2018-02-10 11:23 - 002292224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2018-03-14 11:51 - 2018-02-10 11:23 - 000330240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2018-03-14 11:51 - 2018-02-10 11:23 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\racpldlg.dll
2018-03-14 11:51 - 2018-02-10 11:11 - 003665920 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2018-03-14 11:51 - 2018-02-10 11:11 - 000369664 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2018-03-14 11:51 - 2018-02-10 11:11 - 000133120 _____ (Microsoft Corporation) C:\Windows\system32\msrahc.dll
2018-03-14 11:51 - 2018-02-10 11:11 - 000119296 _____ (Microsoft Corporation) C:\Windows\system32\racpldlg.dll
2018-03-14 11:51 - 2018-02-10 10:55 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-03-14 11:51 - 2018-02-10 10:55 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-03-14 11:51 - 2018-02-10 10:40 - 002901504 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-03-14 11:51 - 2018-02-10 10:40 - 000577536 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-03-14 11:51 - 2018-02-10 10:40 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-03-14 11:51 - 2018-02-10 10:40 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-03-14 11:51 - 2018-02-10 10:40 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-03-14 11:51 - 2018-02-10 10:37 - 005779968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-03-14 11:51 - 2018-02-10 10:36 - 000108032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msra.exe
2018-03-14 11:51 - 2018-02-10 10:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdchange.exe
2018-03-14 11:51 - 2018-02-10 10:36 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsraLegacy.tlb
2018-03-14 11:51 - 2018-02-10 10:32 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-03-14 11:51 - 2018-02-10 10:31 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-03-14 11:51 - 2018-02-10 10:29 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-03-14 11:51 - 2018-02-10 10:28 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-03-14 11:51 - 2018-02-10 10:28 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-03-14 11:51 - 2018-02-10 10:27 - 000817152 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-03-14 11:51 - 2018-02-10 10:27 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-03-14 11:51 - 2018-02-10 10:26 - 000653312 _____ (Microsoft Corporation) C:\Windows\system32\msra.exe
2018-03-14 11:51 - 2018-02-10 10:26 - 000051712 _____ (Microsoft Corporation) C:\Windows\system32\sdchange.exe
2018-03-14 11:51 - 2018-02-10 10:25 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wmiacpi.sys
2018-03-14 11:51 - 2018-02-10 10:25 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\errdev.sys
2018-03-14 11:51 - 2018-02-10 10:25 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\MsraLegacy.tlb
2018-03-14 11:51 - 2018-02-10 10:22 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-03-14 11:51 - 2018-02-10 10:20 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-03-14 11:51 - 2018-02-10 10:10 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-03-14 11:51 - 2018-02-10 10:10 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-03-14 11:51 - 2018-02-10 10:10 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-03-14 11:51 - 2018-02-10 10:09 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-03-14 11:51 - 2018-02-10 10:09 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-03-14 11:51 - 2018-02-10 10:09 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-03-14 11:51 - 2018-02-10 10:09 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-03-14 11:51 - 2018-02-10 10:06 - 002295296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-03-14 11:51 - 2018-02-10 10:06 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-03-14 11:51 - 2018-02-10 10:03 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-03-14 11:51 - 2018-02-10 10:03 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-03-14 11:51 - 2018-02-10 10:01 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-03-14 11:51 - 2018-02-10 10:01 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-03-14 11:51 - 2018-02-10 10:00 - 000661504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-03-14 11:51 - 2018-02-10 10:00 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-03-14 11:51 - 2018-02-10 10:00 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-03-14 11:51 - 2018-02-10 09:57 - 015281664 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-03-14 11:51 - 2018-02-10 09:52 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-03-14 11:51 - 2018-02-10 09:50 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-03-14 11:51 - 2018-02-10 09:50 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-03-14 11:51 - 2018-02-10 09:47 - 002134016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-03-14 11:51 - 2018-02-10 09:47 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-03-14 11:51 - 2018-02-10 09:47 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-03-14 11:51 - 2018-02-10 09:47 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-03-14 11:51 - 2018-02-10 09:46 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-03-14 11:51 - 2018-02-10 09:44 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-03-14 11:51 - 2018-02-10 09:41 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-03-14 11:51 - 2018-02-10 09:40 - 004496384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-03-14 11:51 - 2018-02-10 09:35 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-03-14 11:51 - 2018-02-10 09:34 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-03-14 11:51 - 2018-02-10 09:33 - 002058240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-03-14 11:51 - 2018-02-10 09:33 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-03-14 11:51 - 2018-02-10 09:23 - 001545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-03-14 11:51 - 2018-02-10 09:12 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-03-14 11:51 - 2018-02-10 09:11 - 001313792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-03-14 11:51 - 2018-02-10 09:09 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-03-14 11:51 - 2018-02-02 11:40 - 000114368 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2018-03-14 11:51 - 2018-02-02 11:29 - 002365952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2018-03-14 11:51 - 2018-02-02 11:29 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2018-03-14 11:51 - 2018-02-02 11:29 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2018-03-14 11:51 - 2018-02-02 11:28 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2018-03-14 11:51 - 2018-02-02 11:16 - 003246080 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2018-03-14 11:51 - 2018-02-02 11:16 - 000504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2018-03-14 11:51 - 2018-02-02 11:16 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2018-03-14 11:51 - 2018-02-02 11:14 - 001942016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2018-03-14 11:51 - 2018-02-02 11:14 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2018-03-14 11:51 - 2018-02-02 10:46 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2018-03-14 11:51 - 2018-02-02 10:36 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2018-03-14 11:51 - 2018-01-15 12:59 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-03-14 11:51 - 2018-01-15 12:40 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2018-03-14 11:51 - 2018-01-12 09:40 - 000407040 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2018-03-14 11:51 - 2018-01-12 09:26 - 000308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2018-03-14 11:50 - 2018-02-13 11:17 - 000136384 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-03-14 11:50 - 2018-02-13 11:10 - 000655872 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-03-14 11:50 - 2018-02-13 07:05 - 001994752 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-03-14 11:50 - 2018-02-13 07:05 - 001560064 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-03-14 11:50 - 2018-02-13 07:05 - 000740864 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-03-14 11:50 - 2018-02-13 07:05 - 000600576 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-03-14 11:50 - 2018-02-13 07:05 - 000451072 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-03-14 11:50 - 2018-02-13 07:05 - 000380928 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-03-14 11:50 - 2018-02-13 07:05 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-03-14 11:50 - 2018-02-13 07:05 - 000237568 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-03-12 05:25 - 2018-03-12 05:25 - 000000000 ____D C:\Users\Zed\AppData\LocalLow\Strange Loop Games
2018-03-12 04:25 - 2018-03-12 04:25 - 000000000 ____D C:\Users\Zed\AppData\LocalLow\Momoiro Software
2018-03-11 04:46 - 2018-03-21 11:25 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-03-11 04:46 - 2018-03-11 04:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-03-11 04:46 - 2018-01-18 08:03 - 000076200 _____ C:\Windows\system32\Drivers\mbae64.sys
2018-03-11 04:28 - 2018-03-16 04:33 - 000000000 ____D C:\AdwCleaner
2018-03-03 17:12 - 2018-03-03 17:12 - 000000000 ____D C:\Windows\pss
2018-03-02 21:43 - 2018-03-02 21:43 - 000000000 ____D C:\Users\Zed\AppData\LocalLow\Ankama
2018-03-02 21:33 - 2018-03-02 21:33 - 000000000 ____D C:\Users\Zed\AppData\Local\Ankama
2018-03-01 23:30 - 2018-03-22 19:31 - 000000000 ____D C:\Users\Zed\AppData\Roaming\twitch-electron
2018-03-01 21:13 - 2018-03-01 21:13 - 000002073 _____ C:\Users\Zed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\f.lux.lnk
2018-03-01 21:13 - 2018-03-01 21:13 - 000000000 ____D C:\Users\Zed\AppData\Local\FluxSoftware
2018-03-01 12:33 - 2018-03-01 12:33 - 000000000 ____D C:\Users\Zed\AppData\Roaming\FreeDownloadManager.ORG
2018-03-01 12:33 - 2018-03-01 12:33 - 000000000 ____D C:\ProgramData\FreeDownloadManager.ORG
2018-03-01 12:33 - 2018-03-01 12:33 - 000000000 ____D C:\ProgramData\Free Download Manager
2018-02-22 16:32 - 2018-03-03 22:12 - 000000000 ____D C:\Users\Zed\AppData\Local\Spotify
2018-02-22 16:32 - 2018-02-22 16:32 - 000001781 _____ C:\Users\Zed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2018-02-22 16:31 - 2018-03-03 19:49 - 000000000 ____D C:\Users\Zed\AppData\Roaming\Spotify
2018-02-22 12:31 - 2018-02-22 12:31 - 000000000 ____D C:\Users\Public\Documents\Logishrd
2018-02-22 12:31 - 2018-02-22 12:31 - 000000000 ____D C:\ProgramData\Logitech
2018-02-22 12:30 - 2018-02-22 12:31 - 000000000 ____D C:\ProgramData\Logishrd
2018-02-22 12:30 - 2018-02-22 12:30 - 000018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2018-02-22 12:30 - 2018-02-22 12:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2018-02-22 12:30 - 2018-02-22 12:30 - 000000000 ____D C:\Program Files\Logitech
2018-02-22 12:29 - 2018-02-22 12:31 - 000000000 ____D C:\Users\Zed\AppData\Roaming\Logitech
2018-02-22 12:29 - 2018-02-22 12:30 - 000000000 ____D C:\Program Files\Common Files\LogiShrd
2018-02-22 12:29 - 2018-02-22 12:29 - 000000000 ____D C:\Users\Zed\AppData\Roaming\Logishrd
2018-02-21 18:14 - 2018-02-28 10:46 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-02-21 18:10 - 2018-03-17 20:11 - 000003332 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-02-21 18:10 - 2018-03-17 20:11 - 000003204 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-02-21 18:10 - 2018-02-21 18:29 - 000000000 ____D C:\Users\Zed\AppData\Local\Google
2018-02-21 18:10 - 2018-02-21 18:13 - 000000000 ____D C:\Program Files (x86)\Google
2018-02-21 17:14 - 2018-02-21 18:41 - 000000000 ____D C:\ESD
2018-02-21 15:10 - 2018-02-21 15:10 - 000002167 _____ C:\Windows\diagwrn.xml
2018-02-21 15:10 - 2018-02-21 15:10 - 000001908 _____ C:\Windows\diagerr.xml
2018-02-21 14:01 - 2018-02-21 14:01 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2018-02-21 07:52 - 2018-02-21 07:52 - 000000039 _____ C:\Users\Zed\AppData\Local\kritadisplayrc
2018-02-21 07:51 - 2018-02-21 07:51 - 000000063 _____ C:\Users\Zed\AppData\Local\emaildefaults

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-23 06:05 - 2018-01-01 17:11 - 000000000 ____D C:\FRST
2018-03-23 04:17 - 2009-07-13 21:45 - 000021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-03-23 04:17 - 2009-07-13 21:45 - 000021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-03-23 04:11 - 2009-07-13 22:13 - 000784286 _____ C:\Windows\system32\PerfStringBackup.INI
2018-03-23 04:11 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\inf
2018-03-23 04:04 - 2018-02-07 22:57 - 000000000 ____D C:\ProgramData\NVIDIA
2018-03-23 04:04 - 2018-02-07 22:04 - 000000000 ____D C:\Users\Zed\AppData\LocalLow\Mozilla
2018-03-23 04:04 - 2009-07-13 22:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-03-22 19:48 - 2018-02-07 22:34 - 000000000 ____D C:\Users\Zed\AppData\Roaming\Twitch
2018-03-22 14:09 - 2018-02-07 22:42 - 000000000 ____D C:\Users\Zed\AppData\Roaming\.purple
2018-03-22 07:23 - 2018-02-16 11:47 - 000007610 _____ C:\Users\Zed\AppData\Local\Resmon.ResmonCfg
2018-03-22 06:31 - 2009-07-13 19:34 - 000000215 _____ C:\Windows\system.ini
2018-03-22 05:31 - 2018-02-08 07:13 - 000000000 ____D C:\Program Files (x86)\Steam
2018-03-21 13:03 - 2018-02-10 02:32 - 000000000 ____D C:\Users\Zed\Desktop\Vanilla - Origin
2018-03-21 11:38 - 2009-07-13 19:34 - 000000027 _____ C:\Windows\system32\Drivers\etc\HOSTS.MVP
2018-03-19 20:17 - 2009-07-13 22:08 - 000014106 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-03-17 20:03 - 2018-02-07 22:04 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-03-17 16:24 - 2018-02-07 22:04 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-03-16 04:17 - 2018-02-10 02:40 - 000000000 ____D C:\Users\Zed\AppData\Roaming\vlc
2018-03-15 06:55 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\rescache
2018-03-14 15:29 - 2009-07-13 21:45 - 000268448 _____ C:\Windows\system32\FNTCACHE.DAT
2018-03-14 15:28 - 2018-02-14 04:04 - 000000000 ____D C:\Windows\system32\appraiser
2018-03-14 12:07 - 2018-02-08 03:50 - 000000000 ____D C:\Windows\system32\MRT
2018-03-14 12:06 - 2018-02-08 03:50 - 130364688 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-03-14 12:06 - 2018-02-08 03:49 - 130364688 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-03-13 23:03 - 2018-02-11 07:21 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-03-13 23:03 - 2018-02-11 07:21 - 000000000 ____D C:\Windows\system32\Macromed
2018-03-05 15:04 - 2018-02-09 00:27 - 000000000 ____D C:\Users\Zed\Documents\My Games
2018-02-24 13:49 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\system32\NDF
2018-02-21 18:41 - 2018-02-07 21:17 - 000000000 ____D C:\Windows\Panther
2018-02-21 16:45 - 2009-07-13 20:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2018-02-21 16:45 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy
2018-02-21 14:21 - 2009-07-13 20:20 - 000000000 __RHD C:\Users\Public\Libraries
2018-02-21 07:52 - 2018-02-14 06:41 - 000015311 _____ C:\Users\Zed\AppData\Local\kritarc

==================== Files in the root of some directories =======

2018-02-07 22:44 - 2018-02-07 22:44 - 000000000 _____ () C:\Users\Zed\AppData\Local\Driver_LOM_8161Present.flag
2018-02-21 07:51 - 2018-02-21 07:51 - 000000063 _____ () C:\Users\Zed\AppData\Local\emaildefaults
2018-02-21 07:52 - 2018-02-21 07:52 - 000000039 _____ () C:\Users\Zed\AppData\Local\kritadisplayrc
2018-02-14 06:41 - 2018-02-21 07:52 - 000015311 _____ () C:\Users\Zed\AppData\Local\kritarc
2018-02-16 11:47 - 2018-03-22 07:23 - 000007610 _____ () C:\Users\Zed\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-03-19 00:53

==================== End of FRST.txt ============================



#9 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,798 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:03:07 AM

Posted 23 March 2018 - 08:53 AM

Alex:

Thank you for your post and for the fresh FRST scan log: "FRST.txt"

.

:step1: Please run a FRST fix for me.

NOTICE: This FRST "fixlist" script was written specifically for this user, for use on this individual computer. Running this on another computer may cause damage to your operating system.

Start::
CreateRestorePoint:
CloseProcesses:
GroupPolicy: Restriction <==== ATTENTION
2018-03-22 14:19 - 2018-03-22 14:19 - 000000000 ___SD C:\ComboFix
2018-03-22 06:32 - 2018-03-22 06:32 - 000026060 _____ C:\ComboFix.txt
2018-03-21 11:34 - 2018-03-22 14:19 - 000000000 ____D C:\Qoobox
End::
  • Please highlight the entire contents of the code box above, from the "Start::" line to the "End::" line, including both of those lines, right click, and select "Copy", which will copy the "fix" script into the Windows clipboard.
  • Right click FRST64.exe, and select "Run as Administrator".
  • Press Fix button once and wait.
  • Please reboot the computer, if requested.
  • A log file called "fixlog.txt" will be saved in the same folder as the FRST program is located.
  • Please copy and paste the contents of the "fixlog.txt" file into your next reply.

.

Thank you and have a great day.

Regards,
-Phil


Graduate of the Bleeping Computer Malware Removal Study Hall


#10 dementedreality

dementedreality
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:07 PM

Posted 23 March 2018 - 09:10 AM

Fix result of Farbar Recovery Scan Tool (x64) Version: 14.03.2018
Ran by Zed (23-03-2018 07:06:01) Run:2
Running from C:\Users\Zed\Desktop
Loaded Profiles: Zed (Available Profiles: Zed)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
GroupPolicy: Restriction &lt;==== ATTENTION
2018-03-22 14:19 - 2018-03-22 14:19 - 000000000 ___SD C:\ComboFix
2018-03-22 06:32 - 2018-03-22 06:32 - 000026060 _____ C:\ComboFix.txt
2018-03-21 11:34 - 2018-03-22 14:19 - 000000000 ____D C:\Qoobox

*****************

Restore point was successfully created.
Processes closed successfully.
C:\Windows\system32\GroupPolicy\Machine =&gt; moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini =&gt; moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini =&gt; moved successfully
C:\ComboFix =&gt; moved successfully
C:\ComboFix.txt =&gt; moved successfully
C:\Qoobox =&gt; moved successfully


The system needed a reboot.

==== End of Fixlog 07:06:08 ====

Edited by dementedreality, 23 March 2018 - 09:10 AM.


#11 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,798 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:03:07 AM

Posted 23 March 2018 - 09:21 AM

Alex:
 
Thank you for copying and pasting the contents of the FRST "fixlog.txt" file into your response and running that FRST "fixlist" script.  Now I am happy - ComboFix is no more! :)
 
Let's run some standard anti-malware scans to see if anything shows up.  It would not surprise me if the ESET finds the ComboFix quarantine, assuming that it did detect something and quarantine it.

.
 
:step1: ESET Online Scanner using Internet Explorer:

Note: You will need to disable your currently installed Anti-Virus, how to do so can be found here.

  • Download esetsmartinstaller_enu.exe and save it to your Desktop.
  • Double click the icon.
  • Check YES, I accept the Terms of Use.
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Then select: "Enable detection of potentially unwanted applications" - Yes.
  • Click Advanced settings.
  • Check the following items.

Enable detection of potentially unwanted applications
Remove found threats
Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology

  • Click Change next to Current scan targets:
  • Place a check mark in any additional drive you wish to scan then click OK.
  • Click Start.
  • ESET will then download updates and begin scanning your computer.
  • If no threats are found simply click Uninstall application on close and hit Finish.
  • If threats are found click List of found threats.
  • Click Export to text file.
  • Save the file on your Desktop as ESET.txt.
  • Click Back.
  • Check Uninstall application on close and Delete quarantined files.
  • Click Finish.
  • Close the ESET Online Scanner window.
  • Copy and paste the contents of ESET.txt into your reply, if any threats were detected. There will be no log, if no threats were detected.

Don't forget to re-enable your antivirus when finished!

.

:step2: I see that you have Malwarebytes installed. Please ensure that the settings are set as specified and follow the instructions listed below to run a scan and post the results.

  • Please go to "Settings", "Protection", and turn on "Scan for rootkits", if it is not "On."
  • Ensure that under "Potential Threat Protection", both switches are set to "Always Detect PUPs/PUMs (recommended).
  • Then scroll to the bottom of that page and ensure that "Automatic Quarantine" is turned "On."
  • Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu.
  • If an update of the definitions is available, it will be downloaded and installed before the scan commences.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.

The Scan log is available through Reports (double-click the appropriate scan log) or you can just double-click the "Last Scan" entry on the Dashboard. Click "Export"., and then select "Copy to Clipboard". Next, please paste the contents of the log into your next reply.

.

:step3: Please download AdwCleaner by Malwarebytes and save the file to your Desktop.

  • Vista/Windows 7/8/10 users right-click and select Run As Administrator
  • The tool will start to update the database, please wait for it to complete the update.
  • Click on I Agree button.
  • Click on the Scan button.
  • AdwCleaner will begin its scan ... please be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Logfile button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, then make sure that you uncheck it before running the "Clean" process.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
  • After the scan has finished ...
  • Uncheck any PUP and adware applications that you want to keep.


If you are unsure about one or more of the detected programs, then please copy and paste the scan log, with your questions, and I will provide you with advice about those files.
The Scan logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
Do not follow the remaining "Clean" instructions until directed to do so by me, if you have any questions about one or more of the detections.
If you have no questions about any of the detections, then please proceed to the "Clean" steps below.

  • Then click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
  • Please copy and paste the contents of that logfile into your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

.

I will be offline for the next few hours, until possibly tomorrow. Today is my weekly image backup day for my two computers. In this line of work, you see first-hand how easy it is to "lose" your computer, so I practice what I preach. :)

Thank you and have a great day.

Regards,
-Phil


Graduate of the Bleeping Computer Malware Removal Study Hall


#12 dementedreality

dementedreality
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:07 PM

Posted 23 March 2018 - 10:03 AM

Nothing on ESET


Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 3/23/18
Scan Time: 7:58 AM
Log File: b0656594-2eaa-11e8-a4b1-f01faf22b944.json
Administrator: Yes

-Software Information-
Version: 3.4.4.2398
Components Version: 1.0.322
Update Package Version: 1.0.4460
License: Free

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: BoxBrain\Zed

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 244668
Threats Detected: 0
(No malicious items detected)
Threats Quarantined: 0
(No malicious items detected)
Time Elapsed: 1 min, 33 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 0
(No malicious items detected)

Physical Sector: 0
(No malicious items detected)


(end)


# AdwCleaner 7.0.8.0 - Logfile created on Fri Mar 23 15:01:43 2018
# Updated on 2018/08/02 by Malwarebytes
# Database: 2018-03-22.1
# Running on Windows 7 Home Premium (X64)
# Mode: scan
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries.

*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [952 B] - [2018/3/11 11:29:39]
C:/AdwCleaner/AdwCleaner[S1].txt - [1019 B] - [2018/3/16 11:33:54]


########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt ##########

Edited by dementedreality, 23 March 2018 - 10:05 AM.


#13 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,798 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:03:07 AM

Posted 23 March 2018 - 10:56 AM

Alex:

 

Thank you for your post and for the scan logs.  That all looks great! :thumbup2:

 

How is your computer working now?  I am not seeing any malware.  If there are issues, please describe them in as much detail as possible, including any possible error codes/messages.

 

I am trying to get my weekly backups done today, so I might not be back until tomorrow.

 

If all is good with your computer, then we will clean up the tools we used, and I will provide you with some parting advice.

 

Have a great day.

 

Regards,

-Phil


Graduate of the Bleeping Computer Malware Removal Study Hall


#14 dementedreality

dementedreality
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:07 PM

Posted 25 March 2018 - 05:07 PM

I am not facing any issues presently, but I do not understand why Malwarebytes Anti-Rookit detected a rogue process that it needed to end before it could launch nor why running combofix resolved the CPU spike and abnormal behavior by MSMPENG.EXE, the security essentials process. Before I ran combofix I would get CPU loads of 100% for about 3 seconds every time i loaded a webpage as well as periodically even when the browser was closed. As I didn't get any flags from the scans except the MBAR on startup I do not know the nature or depth of infection. Is it possible that you might elucidate these sticking points? If I had spyware on my machine for example I will need to purge my passwords and secure financial processing accounts.

 



#15 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,798 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:03:07 AM

Posted 26 March 2018 - 12:30 PM

Alex:
 
Thank you for your post.  There is no evidence of a keylogger or backdoor Trojan on your computer.  The scans and anti-malware tools that we have run would have detected such a "beast," if it was inhabiting your computer.
 
As for what ComboFix did, or didn't, do, I can't address that.  Personally, I avoid that program like the plague.  You won't see many, if any, qualified malware removal specialists using that program these days.  The program is not Windows 8/10 compatible, and it has not been updated in years, so with the new Windows updates to XP, Vista, and 7, you can't have any confidence that using it, won't "break" something, even in OS versions, with which it was compatible.
 
.

:step1: Please provide me with a fresh set of FRST logs. I would like to make a final reconnaisance of your computer and I also want to identify the anti-malware scanners and cleaners that we used, so that we can delete them in the next post.

If there are any anti-malware tools that you want to keep, please let me know, although it is always advisable to download the latest versions of those tools, since they are updated so frequently.

If you have Malwarebytes installed, I would suggest that you keep it. If you don't want to keep Malwarebytes installed on your computer, please go to this link to download the latest version of MB-Clean.exe and run it to remove all traces of Malwarebytes. Please let me know if you did uninstall Malwarebytes. Once you have run the MB-Clean.exe tool successfully, you can manually delete that file as well.

.

Thank you and have a great day.

Regards,
-Phil


Graduate of the Bleeping Computer Malware Removal Study Hall





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users