Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

svchost.exe high memory usage, slowing down computer


  • This topic is locked This topic is locked
11 replies to this topic

#1 Bodum

Bodum

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:20 AM

Posted 14 April 2018 - 12:55 PM

Hello Malware Response Team!

 

I was told to post here after working with someone in the "Security / Am I Infected? What do I do?" forum. My Windows 7 computer was suddenly running slowly while doing very minimal tasks such as word processing. This is not normal and I found that svchost.exe was using up to 1,400,000 K of memory. I was wondering if this is due to a virus, and if so, what do I do?

 

I have run CCleaner, Malwarebytes - Clean Mode, and AdwCleaner. I use Bitdefender total security 2018 and it runs a daily scan and manages my firewall. Bitdefender hasn't found anything yet.

 

I followed the Prep Guide; here are my FRST logs. Thank you for your help!

 

FRST.txt

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018
Ran by admin (administrator) on MICHITA-PC (14-04-2018 12:03:35)
Running from C:\Users\Chris\Desktop
Loaded Profiles: Chris & admin (Available Profiles: Chris & Leslie & admin & Abby Lomax)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\vsserv.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnService.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Device Management\DevMgmtService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(The OpenVPN Project) C:\Program Files\OpenVPN\bin\openvpnserv.exe
(Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
() C:\Windows\System32\rpcnetp.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Bitdefender) C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnApp.exe
() C:\Program Files\OpenVPN\bin\openvpn-gui.exe
() C:\Program Files\Google\Drive\googledrivesync.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdwtxag.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
() C:\Program Files\Google\Drive\googledrivesync.exe
(Panda Security) C:\Program Files (x86)\Panda USB Vaccine\USBVaccine.exe
(The OpenVPN Project) C:\Program Files\OpenVPN\bin\openvpn.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdwtxcr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\odscanui.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe [444312 2018-02-22] (Bitdefender)
HKLM\...\Run: [BdVpnApp] => C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnApp.exe [88576 2018-03-20] (Bitdefender)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2679313766-3789782403-2851624562-1000\...\Run: [OPENVPN-GUI] => C:\Program Files\OpenVPN\bin\openvpn-gui.exe [665216 2018-03-01] ()
HKU\S-1-5-21-2679313766-3789782403-2851624562-1000\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [46139776 2018-03-15] ()
HKU\S-1-5-21-2679313766-3789782403-2851624562-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [17074688 2018-03-06] (Piriform Ltd)
HKU\S-1-5-21-2679313766-3789782403-2851624562-1000\...\Policies\system: [DisableChangePassword] 1
HKU\S-1-5-21-2679313766-3789782403-2851624562-1002\...\Run: [OPENVPN-GUI] => C:\Program Files\OpenVPN\bin\openvpn-gui.exe [665216 2018-03-01] ()
HKU\S-1-5-21-2679313766-3789782403-2851624562-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [17074688 2018-03-06] (Piriform Ltd)
HKU\S-1-5-21-2679313766-3789782403-2851624562-1002\...\MountPoints2: {241dab4f-060f-11e8-b1f8-047d7bf080aa} - V:\setup.EXE /AUTORUN
GroupPolicy: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 198.18.0.1 198.18.0.2
Tcpip\..\Interfaces\{7512BD34-23B5-479B-B8F2-6C231317FBB5}: [DhcpNameServer] 200.48.225.130 200.48.225.146
Tcpip\..\Interfaces\{7C3298EF-987F-442C-B686-0966568CCC33}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{7C3298EF-987F-442C-B686-0966568CCC33}: [DhcpNameServer] 200.48.225.146 200.48.225.130
Tcpip\..\Interfaces\{FC9E2511-B69F-4DD4-8732-E2C979C3B72C}: [DhcpNameServer] 198.18.0.1 198.18.0.2

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2679313766-3789782403-2851624562-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2679313766-3789782403-2851624562-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2679313766-3789782403-2851624562-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/es-pe/?ocid=iehp
BHO: Bitdefender Wallet  -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2018-02-22] (Bitdefender)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2018-02-13] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2018-01-30] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2018-02-13] (Microsoft Corporation)
BHO-x32: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2018-02-22] (Bitdefender)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2018-01-30] (Microsoft Corporation)
Toolbar: HKLM - Bitdefender Wallet  - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2018-02-22] (Bitdefender)
Toolbar: HKLM-x32 - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2018-02-22] (Bitdefender)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2018-01-30] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: 332pvgff.default
FF ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\332pvgff.default [2018-04-13]
FF Homepage: Mozilla\Firefox\Profiles\332pvgff.default -> hxxps://www.google.com/
FF Session Restore: Mozilla\Firefox\Profiles\332pvgff.default -> is enabled.
FF NewTabOverride: Mozilla\Firefox\Profiles\332pvgff.default -> Enabled: uBlock0@raymondhill.net
FF Extension: (Disconnect) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\332pvgff.default\Extensions\2.0@disconnect.me.xpi [2018-01-30]
FF Extension: (Blender) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\332pvgff.default\Extensions\blender@meh.paranoid.pk.xpi [2018-01-30] [Legacy]
FF Extension: (HTTPS Everywhere) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\332pvgff.default\Extensions\https-everywhere@eff.org.xpi [2018-04-09]
FF Extension: (Firefox Lightbeam) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\332pvgff.default\Extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi [2018-03-30]
FF Extension: (PDF Mage) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\332pvgff.default\Extensions\jid1-GeRCnsiDhZiTvA@jetpack.xpi [2018-01-30]
FF Extension: (RequestPolicy) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\332pvgff.default\Extensions\requestpolicy@requestpolicy.com.xpi [2018-01-30] [Legacy]
FF Extension: (uBlock Origin) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\332pvgff.default\Extensions\uBlock0@raymondhill.net.xpi [2018-04-09]
FF Extension: (EPUBReader) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\332pvgff.default\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}.xpi [2018-01-30]
FF Extension: (NoScript) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\332pvgff.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2018-03-30]
FF Extension: (Easy Youtube Video Downloader Express) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\332pvgff.default\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2018-03-30]
FF Extension: (Greasemonkey) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\332pvgff.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2018-03-30]
FF HKLM\...\Firefox\Extensions: [bdwtwe@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff
FF Extension: (Bitdefender Wallet) - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff [2018-01-25]
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext
FF Extension: (Bitdefender Antispam Toolbar) - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext [2018-01-25] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [bdwtwe@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2018-01-30] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-30] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-30] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-11-29] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-11] (Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default [2018-04-13]
CHR Extension: (Slides) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-02-12]
CHR Extension: (Docs) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-16]
CHR Extension: (Google Drive) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-16]
CHR Extension: (YouTube) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-16]
CHR Extension: (Sheets) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-12]
CHR Extension: (Bitdefender Wallet) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gannpgaobkkhmpomoijebaigcapoeebl [2018-02-12]
CHR Extension: (Google Docs Offline) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-02-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-02-12]
CHR Extension: (Gmail) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-02-16]
CHR Extension: (Chrome Media Router) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-25]
CHR HKU\S-1-5-21-2679313766-3789782403-2851624562-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gannpgaobkkhmpomoijebaigcapoeebl] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2319848 2018-01-05] (Adobe Systems, Incorporated)
R2 bdredline; C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe [2119184 2017-09-26] (Bitdefender)
R2 BdVpnService; C:\Program Files\Bitdefender\Bitdefender VPN\bdvpnservice.exe [106736 2018-03-20] (Bitdefender)
S3 BitdefenderVpnSvc; C:\Program Files\Bitdefender\Bitdefender VPN\vpnservice.exe [320896 2018-03-02] (AnchorFree Inc.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3058392 2017-12-12] (Microsoft Corporation)
R2 DevMgmtService; C:\Program Files\Bitdefender\Bitdefender Device Management\DevMgmtService.exe [103584 2018-01-15] (Bitdefender)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6479136 2018-03-27] (Malwarebytes)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv2.exe [15872 2018-03-01] ( ) [File not signed]
R2 OpenVPNServiceInteractive; C:\Program Files\OpenVPN\bin\openvpnserv.exe [75392 2018-03-01] (The OpenVPN Project)
S3 OpenVPNServiceLegacy; C:\Program Files\OpenVPN\bin\openvpnserv.exe [75392 2018-03-01] (The OpenVPN Project)
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1278584 2017-10-31] (Bitdefender)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe [114968 2018-02-22] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender Security\vsserv.exe [1236696 2018-02-22] (Bitdefender)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 aftap0901; C:\Windows\System32\DRIVERS\aftap0901.sys [48624 2017-11-29] (The OpenVPN Project)
R1 atc; C:\Windows\System32\DRIVERS\atc.sys [1177720 2018-02-22] (BitDefender S.R.L. Bucharest, ROMANIA)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1725800 2018-02-22] (BitDefender)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [124424 2017-05-31] (BitDefender LLC)
R0 bdprivmon; C:\Windows\System32\DRIVERS\bdprivmon.sys [47376 2017-10-09] (© Bitdefender SRL)
R1 BDVEDISK; C:\Windows\System32\DRIVERS\bdvedisk.sys [87912 2015-12-04] (BitDefender)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [76192 2018-03-19] ()
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [191784 2018-02-22] (BitDefender LLC)
R0 Ignis; C:\Windows\System32\DRIVERS\ignis.sys [190752 2018-02-22] (Bitdefender)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [193768 2018-04-13] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [112864 2018-04-14] (Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [44768 2018-04-14] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-04-14] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [93816 2018-04-14] (Malwarebytes)
R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [1514568 2013-05-02] (Realtek Semiconductor Corporation )
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-16] (Synaptics Incorporated)
S3 tapipvanish; C:\Windows\System32\DRIVERS\tapipvanish.sys [34520 2017-09-19] (The OpenVPN Project)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [439576 2018-03-06] (BitDefender S.R.L.)
R1 veracrypt; C:\Windows\System32\drivers\veracrypt.sys [631200 2018-01-30] (IDRIX)
S3 WDC_SAM; C:\Windows\System32\DRIVERS\wdcsam64_prewin8.sys [31920 2018-02-26] (Western Digital Technologies)
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-04-14 12:04 - 2018-04-14 12:04 - 000000000 ____D C:\Users\Chris\Desktop\Scans 2
2018-04-14 12:03 - 2018-04-14 12:06 - 000018658 _____ C:\Users\Chris\Desktop\FRST.txt
2018-04-14 12:03 - 2018-04-14 12:03 - 000000000 ____D C:\FRST
2018-04-14 12:01 - 2018-04-14 12:01 - 002403328 _____ (Farbar) C:\Users\Chris\Desktop\FRST64.exe
2018-04-13 16:04 - 2018-04-13 16:04 - 000003088 _____ C:\Windows\System32\Tasks\AdwCleaner_onReboot
2018-04-13 16:02 - 2018-04-13 16:03 - 000000000 ____D C:\AdwCleaner
2018-04-13 16:01 - 2018-04-13 16:01 - 007256272 _____ (Malwarebytes) C:\Users\Chris\Desktop\AdwCleaner.exe
2018-04-13 15:56 - 2018-04-13 17:13 - 000000000 ____D C:\Users\Chris\Desktop\Scans
2018-04-13 15:55 - 2018-04-13 15:55 - 000000000 ____D C:\Users\admin\Desktop\New folder (2)
2018-04-13 15:55 - 2018-04-13 15:55 - 000000000 ____D C:\Users\admin\Desktop\New folder
2018-04-13 15:46 - 2018-04-14 11:41 - 000093816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2018-04-13 15:46 - 2018-04-14 11:40 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-04-13 15:46 - 2018-04-14 11:40 - 000112864 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2018-04-13 15:46 - 2018-04-14 11:40 - 000044768 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2018-04-13 15:46 - 2018-04-13 15:46 - 000193768 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2018-04-13 15:46 - 2018-04-13 15:46 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-04-13 15:46 - 2018-04-13 15:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-04-13 15:46 - 2018-03-19 12:57 - 000076192 _____ C:\Windows\system32\Drivers\mbae64.sys
2018-04-13 15:45 - 2018-04-13 15:45 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-04-13 15:45 - 2018-04-13 15:45 - 000000000 ____D C:\Program Files\Malwarebytes
2018-04-13 15:32 - 2018-04-13 15:35 - 071942408 _____ (Malwarebytes ) C:\Users\Chris\Downloads\mb3-setup-1878.1878-3.4.5.2467.exe
2018-04-13 15:28 - 2018-04-13 15:28 - 000003870 _____ C:\Windows\System32\Tasks\CCleaner Update
2018-04-13 15:28 - 2018-04-13 15:28 - 000002794 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2018-04-13 15:28 - 2018-04-13 15:28 - 000000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-04-13 15:28 - 2018-04-13 15:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-04-13 15:28 - 2018-04-13 15:28 - 000000000 ____D C:\Program Files\CCleaner
2018-04-13 15:26 - 2018-04-13 15:26 - 015333512 _____ (Piriform Ltd) C:\Users\Chris\Downloads\ccsetup541.exe
2018-04-12 21:43 - 2018-04-12 21:43 - 000004360 _____ C:\Users\Chris\AppData\Local\recently-used.xbel
2018-04-10 20:45 - 2018-03-30 21:09 - 005583040 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-04-10 20:45 - 2018-03-30 21:09 - 000708288 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-04-10 20:45 - 2018-03-30 21:09 - 000262336 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-04-10 20:45 - 2018-03-30 21:09 - 000154816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-04-10 20:45 - 2018-03-30 21:09 - 000095424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-04-10 20:45 - 2018-03-30 20:45 - 000631640 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-04-10 20:45 - 2018-03-30 20:39 - 004046528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-04-10 20:45 - 2018-03-30 20:39 - 003958464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-04-10 20:45 - 2018-03-30 20:38 - 001665336 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 001461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000094720 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:12 - 001314064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 20:06 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-04-10 20:45 - 2018-03-30 20:06 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-04-10 20:45 - 2018-03-30 20:06 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-04-10 20:45 - 2018-03-30 20:06 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-04-10 20:45 - 2018-03-30 20:03 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-04-10 20:45 - 2018-03-30 20:02 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-04-10 20:45 - 2018-03-30 20:02 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-04-10 20:45 - 2018-03-30 19:59 - 000160256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-04-10 20:45 - 2018-03-30 19:58 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-04-10 20:45 - 2018-03-30 19:58 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-04-10 20:45 - 2018-03-30 19:58 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-04-10 20:45 - 2018-03-30 19:58 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-04-10 20:45 - 2018-03-30 19:51 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-04-10 20:45 - 2018-03-30 19:47 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-04-10 20:45 - 2018-03-30 19:47 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-04-10 20:45 - 2018-03-30 19:47 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-04-10 20:45 - 2018-03-30 19:47 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-04-10 20:45 - 2018-03-30 19:47 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 19:47 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 19:47 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 19:47 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-04-10 20:45 - 2018-03-30 19:47 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-04-10 20:45 - 2018-03-28 02:30 - 003225600 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-04-10 20:45 - 2018-03-23 13:50 - 000396952 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-04-10 20:45 - 2018-03-23 12:59 - 000348824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-04-10 20:45 - 2018-03-22 18:00 - 025742336 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-04-10 20:45 - 2018-03-22 16:32 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-04-10 20:45 - 2018-03-22 16:32 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-04-10 20:45 - 2018-03-22 16:26 - 020287488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-04-10 20:45 - 2018-03-22 16:19 - 002901504 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-04-10 20:45 - 2018-03-22 16:18 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-04-10 20:45 - 2018-03-22 16:17 - 000578048 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-04-10 20:45 - 2018-03-22 16:17 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-04-10 20:45 - 2018-03-22 16:17 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-04-10 20:45 - 2018-03-22 16:17 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-04-10 20:45 - 2018-03-22 16:15 - 005780480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-04-10 20:45 - 2018-03-22 16:10 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-04-10 20:45 - 2018-03-22 16:09 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-04-10 20:45 - 2018-03-22 16:07 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-04-10 20:45 - 2018-03-22 16:06 - 000794112 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-04-10 20:45 - 2018-03-22 16:06 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-04-10 20:45 - 2018-03-22 16:06 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-04-10 20:45 - 2018-03-22 16:05 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-04-10 20:45 - 2018-03-22 16:04 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-04-10 20:45 - 2018-03-22 15:58 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-04-10 20:45 - 2018-03-22 15:55 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-04-10 20:45 - 2018-03-22 15:52 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-04-10 20:45 - 2018-03-22 15:52 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-04-10 20:45 - 2018-03-22 15:51 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-04-10 20:45 - 2018-03-22 15:51 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-04-10 20:45 - 2018-03-22 15:50 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-04-10 20:45 - 2018-03-22 15:49 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-04-10 20:45 - 2018-03-22 15:48 - 002295296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-04-10 20:45 - 2018-03-22 15:48 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-04-10 20:45 - 2018-03-22 15:48 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-04-10 20:45 - 2018-03-22 15:45 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-04-10 20:45 - 2018-03-22 15:45 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-04-10 20:45 - 2018-03-22 15:45 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-04-10 20:45 - 2018-03-22 15:44 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-04-10 20:45 - 2018-03-22 15:43 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-04-10 20:45 - 2018-03-22 15:42 - 000661504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-04-10 20:45 - 2018-03-22 15:42 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-04-10 20:45 - 2018-03-22 15:42 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-04-10 20:45 - 2018-03-22 15:41 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-04-10 20:45 - 2018-03-22 15:40 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-04-10 20:45 - 2018-03-22 15:33 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-04-10 20:45 - 2018-03-22 15:31 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-04-10 20:45 - 2018-03-22 15:29 - 015282688 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-04-10 20:45 - 2018-03-22 15:29 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-04-10 20:45 - 2018-03-22 15:29 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-04-10 20:45 - 2018-03-22 15:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-04-10 20:45 - 2018-03-22 15:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-04-10 20:45 - 2018-03-22 15:28 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-04-10 20:45 - 2018-03-22 15:27 - 002135552 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-04-10 20:45 - 2018-03-22 15:27 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-04-10 20:45 - 2018-03-22 15:25 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-04-10 20:45 - 2018-03-22 15:25 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-04-10 20:45 - 2018-03-22 15:24 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-04-10 20:45 - 2018-03-22 15:22 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-04-10 20:45 - 2018-03-22 15:21 - 004496896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-04-10 20:45 - 2018-03-22 15:20 - 013680128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-04-10 20:45 - 2018-03-22 15:17 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-04-10 20:45 - 2018-03-22 15:15 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-04-10 20:45 - 2018-03-22 15:15 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-04-10 20:45 - 2018-03-22 15:14 - 002059776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-04-10 20:45 - 2018-03-22 15:14 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-04-10 20:45 - 2018-03-22 15:04 - 001545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-04-10 20:45 - 2018-03-22 14:55 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-04-10 20:45 - 2018-03-22 14:53 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-04-10 20:45 - 2018-03-22 14:52 - 001313792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-04-10 20:45 - 2018-03-22 14:51 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-04-10 20:45 - 2018-03-10 12:11 - 000340480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2018-04-10 20:45 - 2018-03-09 13:18 - 000309440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2018-04-10 20:45 - 2018-03-09 13:12 - 000383680 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-04-10 20:45 - 2018-03-09 13:12 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2018-04-10 20:45 - 2018-03-09 13:12 - 000071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2018-04-10 20:45 - 2018-03-09 13:12 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2018-04-10 20:45 - 2018-03-09 13:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2018-04-10 20:45 - 2018-03-09 13:07 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2018-04-10 20:45 - 2018-03-09 13:07 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-04-10 20:45 - 2018-03-09 13:07 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-04-10 20:45 - 2018-03-09 13:06 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-04-10 20:45 - 2018-03-09 13:06 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-04-10 20:45 - 2018-03-09 12:31 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2018-04-10 20:45 - 2018-03-06 13:13 - 000148160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\basecsp.dll
2018-04-10 20:45 - 2018-03-06 13:11 - 000184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scksp.dll
2018-04-10 20:45 - 2018-03-06 13:11 - 000052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsnmp32.dll
2018-04-10 20:45 - 2018-03-06 13:10 - 000170176 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2018-04-10 20:45 - 2018-03-06 13:07 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll
2018-04-10 20:45 - 2018-03-06 13:07 - 000067072 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000995272 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000063832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000020824 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000019800 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000016216 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000015704 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000013656 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000922944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000066392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000019800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000016216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000015704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000013656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2018-04-10 20:45 - 2018-01-25 09:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2018-04-10 20:42 - 2018-03-14 12:14 - 000135360 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-04-10 20:42 - 2018-03-14 12:09 - 000656384 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-04-10 20:42 - 2018-03-14 08:05 - 001993728 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-04-10 20:42 - 2018-03-14 08:05 - 001559552 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-04-10 20:42 - 2018-03-14 08:05 - 000739840 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-04-10 20:42 - 2018-03-14 08:05 - 000599552 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-04-10 20:42 - 2018-03-14 08:05 - 000450048 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-04-10 20:42 - 2018-03-14 08:05 - 000414720 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-04-10 20:42 - 2018-03-14 08:05 - 000291840 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-04-10 20:42 - 2018-03-14 08:05 - 000237056 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-04-09 23:10 - 2018-04-10 00:15 - 000000000 ____D C:\Users\Chris\AppData\Local\Screencast-O-Matic-v2
2018-04-09 23:10 - 2018-04-09 23:10 - 000000000 ____D C:\Users\Chris\Documents\Screencast-O-Matic
2018-04-09 23:10 - 2018-04-09 23:10 - 000000000 ____D C:\Users\Chris\AppData\Local\WebLaunchRecorder
2018-04-09 23:05 - 2018-04-09 23:05 - 000347584 _____ (Big Nerd Software, LLC) C:\Users\Chris\Downloads\WebLaunchRecorder.exe
2018-04-09 18:25 - 2018-04-09 18:25 - 000000000 ____D C:\Users\admin\OpenVPN
2018-04-09 17:57 - 2018-04-09 18:02 - 000000000 ____D C:\Users\Abby Lomax\AppData\Roaming\Bitdefender
2018-04-09 17:57 - 2018-04-09 17:57 - 000072128 _____ C:\Users\Abby Lomax\AppData\Local\GDIPFONTCACHEV1.DAT
2018-04-09 17:57 - 2018-04-09 17:57 - 000002259 _____ C:\Users\Abby Lomax\Desktop\Google Chrome.lnk
2018-04-09 17:57 - 2018-04-09 17:57 - 000001417 _____ C:\Users\Abby Lomax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2018-04-09 17:57 - 2018-04-09 17:57 - 000000000 ____D C:\Users\Abby Lomax\OpenVPN
2018-04-09 17:57 - 2018-04-09 17:57 - 000000000 ____D C:\Users\Abby Lomax\AppData\Roaming\Adobe
2018-04-09 17:57 - 2018-04-09 17:57 - 000000000 ____D C:\Users\Abby Lomax\AppData\Local\VirtualStore
2018-04-09 17:56 - 2018-04-09 17:57 - 000000000 ____D C:\Users\Abby Lomax\AppData\Local\Google
2018-04-09 17:56 - 2018-04-09 17:57 - 000000000 ____D C:\Users\Abby Lomax
2018-04-09 17:56 - 2018-04-09 17:56 - 000000020 ___SH C:\Users\Abby Lomax\ntuser.ini
2018-04-09 17:56 - 2018-01-30 19:23 - 000002104 _____ C:\Users\Abby Lomax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2018-04-09 17:56 - 2011-04-12 03:28 - 000000000 ____D C:\Users\Abby Lomax\AppData\Roaming\Media Center Programs
2018-04-09 16:04 - 2018-04-09 16:04 - 000001344 _____ C:\Users\Chris\Downloads\Week #12 Homework - JavaScript1&2.zip
2018-04-08 19:06 - 2018-04-08 19:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TAP-Windows
2018-04-08 19:06 - 2018-04-08 19:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN
2018-04-08 19:06 - 2018-04-08 19:06 - 000000000 ____D C:\Program Files\TAP-Windows
2018-04-08 19:06 - 2018-04-08 19:06 - 000000000 ____D C:\Program Files\OpenVPN
2018-04-08 18:04 - 2018-04-08 18:04 - 003850400 _____ C:\Users\Chris\Downloads\openvpn-install-2.4.5-I601.exe
2018-04-08 17:27 - 2018-04-08 17:27 - 001414794 _____ (Igor Pavlov) C:\Users\Chris\Downloads\7z1801-x64.exe
2018-04-05 13:02 - 2018-04-05 13:02 - 000016570 _____ C:\Users\Chris\Downloads\EndofChapter Six.pdf
2018-04-02 16:26 - 2018-04-08 17:35 - 000000000 ____D C:\Program Files (x86)\BlueStacks
2018-04-02 16:17 - 2018-04-02 16:22 - 298116824 _____ (BlueStack Systems Inc.) C:\Users\Chris\Downloads\BlueStacks-Installer_BS3_native_f702afd399ed60d9650d9b3aebe3ae30.exe
2018-04-02 16:02 - 2018-04-02 16:02 - 018573608 _____ C:\Users\Chris\Downloads\prey-windows-1.7.3-x64.exe
2018-04-02 16:01 - 2018-04-02 16:01 - 017662152 _____ C:\Users\Chris\Downloads\prey-windows-1.7.3-x86.exe
2018-03-30 16:49 - 2018-03-30 16:50 - 000000000 ____D C:\Users\admin\Documents\Instalation of Group Policy Manager (3rd party)
2018-03-30 16:29 - 2001-08-23 13:00 - 000034871 _____ C:\Windows\system32\gpedit.msc
2018-03-30 16:20 - 2018-03-30 16:20 - 000000000 ____D C:\Windows\SysWOW64\GPBAK
2018-03-30 16:20 - 2008-04-14 02:11 - 000295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appmgr.dll
2018-03-30 16:20 - 2001-08-23 13:00 - 000034871 _____ C:\Windows\SysWOW64\gpedit.msc
2018-03-30 16:19 - 2018-03-30 16:19 - 000875012 _____ C:\Users\admin\Downloads\add_gpedit_msc_by_jwils876-d3kh6vm.zip
2018-03-30 16:19 - 2018-03-30 16:19 - 000000000 ____D C:\Users\admin\Downloads\add_gpedit_msc_by_jwils876-d3kh6vm
2018-03-30 11:46 - 2018-04-13 15:30 - 000000000 ____D C:\Users\admin\AppData\Local\CrashDumps
2018-03-26 12:29 - 2018-03-26 12:31 - 000000000 ____D C:\Users\admin\AppData\Local\VMware
2018-03-26 11:45 - 2018-03-26 11:45 - 000000000 ____D C:\Program Files\Google
2018-03-26 11:44 - 2018-03-26 11:44 - 000000000 ____D C:\Users\Default\AppData\Local\Google
2018-03-26 11:44 - 2018-03-26 11:44 - 000000000 ____D C:\Users\Default User\AppData\Local\Google
2018-03-26 11:05 - 2018-03-31 09:11 - 000000008 __RSH C:\ProgramData\ntuser.pol
2018-03-26 10:23 - 2018-03-26 10:23 - 000000000 ____D C:\Users\Chris\OpenVPN
2018-03-26 10:08 - 2018-03-26 10:08 - 000072017 _____ C:\ProgramData\vpn.1522076663.bdinstall.bin
2018-03-26 10:07 - 2018-03-26 10:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender VPN
2018-03-26 10:05 - 2018-03-26 10:05 - 000038519 _____ C:\ProgramData\vpn.uninstall.1522076673.bdinstall.bin
2018-03-25 10:02 - 2018-04-09 18:46 - 000000000 ____D C:\Users\Public\Documents\Stuff to Share

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-04-14 11:57 - 2009-07-13 23:45 - 000021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-04-14 11:57 - 2009-07-13 23:45 - 000021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-04-14 11:45 - 2018-02-03 12:44 - 000000000 ___RD C:\Users\Chris\Google Drive
2018-04-14 11:45 - 2018-01-31 05:57 - 000000000 ____D C:\Users\Chris\AppData\LocalLow\Mozilla
2018-04-14 11:45 - 2018-01-30 11:49 - 000003648 _____ C:\Windows\System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
2018-04-14 11:39 - 2018-01-30 13:58 - 000017920 _____ C:\Windows\SysWOW64\rpcnetp.dll
2018-04-14 11:39 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-04-14 11:38 - 2018-01-30 13:58 - 000017920 _____ C:\Windows\SysWOW64\rpcnetp.exe
2018-04-14 11:38 - 2018-01-30 13:58 - 000017920 _____ C:\Windows\system32\rpcnetp.exe
2018-04-13 22:07 - 2018-01-30 17:03 - 000058856 _____ C:\bdlog.txt
2018-04-13 18:05 - 2018-01-30 13:17 - 000003120 _____ C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe
2018-04-13 18:05 - 2018-01-30 13:17 - 000003094 _____ C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe
2018-04-13 18:05 - 2018-01-30 13:17 - 000003092 _____ C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_itype_exe
2018-04-13 17:59 - 2018-02-09 12:14 - 000003466 _____ C:\Windows\System32\Tasks\AdobeGCInvoker-1.0-Michita-PC-Leslie
2018-04-13 17:59 - 2018-02-09 11:12 - 000004478 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2018-04-13 17:59 - 2018-01-31 06:03 - 000004480 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-04-13 17:56 - 2018-03-02 11:36 - 000002976 _____ C:\Windows\System32\Tasks\{EFB4458F-69BC-494D-93B7-9BC0B96901D6}
2018-04-13 17:56 - 2018-02-09 10:06 - 000003464 _____ C:\Windows\System32\Tasks\AdobeGCInvoker-1.0-Michita-PC-Chris
2018-04-13 17:55 - 2018-02-12 11:23 - 000003464 _____ C:\Windows\System32\Tasks\AdobeGCInvoker-1.0-Michita-PC-admin
2018-04-13 17:55 - 2018-01-31 06:03 - 000004326 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-04-13 17:18 - 2018-02-20 05:58 - 000000000 ____D C:\Users\Chris\AppData\Local\CrashDumps
2018-04-13 15:46 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2018-04-13 15:30 - 2018-01-30 13:57 - 000000000 ____D C:\Windows\Panther
2018-04-13 12:30 - 2018-02-10 09:30 - 000000000 ___HD C:\Users\Public\Documents\.tmp.drivedownload
2018-04-12 20:36 - 2018-02-15 18:49 - 000000000 ____D C:\Users\Chris\AppData\Local\Battle.net
2018-04-12 18:56 - 2018-02-15 19:45 - 000000000 ____D C:\Program Files (x86)\StarCraft II
2018-04-12 18:55 - 2018-02-15 18:45 - 000000000 ____D C:\Program Files (x86)\Battle.net
2018-04-12 11:25 - 2018-02-04 11:00 - 000000000 ____D C:\Users\Chris\Documents\Custom Office Templates
2018-04-12 11:25 - 2018-02-01 07:27 - 000000000 ____D C:\Users\Chris\AppData\Roaming\vlc
2018-04-11 16:19 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\rescache
2018-04-11 15:50 - 2018-02-26 11:30 - 000000000 ____D C:\Users\Chris\AppData\Local\Spotify
2018-04-11 15:41 - 2018-02-26 11:48 - 000000000 ____D C:\Users\Chris\AppData\Roaming\Spotify
2018-04-11 14:04 - 2018-02-06 09:39 - 000000000 ____D C:\Users\Chris\Documents\My Kindle Content
2018-04-11 09:12 - 2018-01-30 14:38 - 000000000 ____D C:\Users\admin
2018-04-10 21:19 - 2009-07-14 00:13 - 000781302 _____ C:\Windows\system32\PerfStringBackup.INI
2018-04-10 21:13 - 2009-07-13 23:45 - 000325104 _____ C:\Windows\system32\FNTCACHE.DAT
2018-04-10 21:11 - 2018-01-31 05:18 - 000000000 ____D C:\Windows\system32\appraiser
2018-04-10 20:51 - 2018-01-30 14:41 - 000000000 ____D C:\Windows\system32\MRT
2018-04-10 20:48 - 2018-01-30 14:40 - 136971704 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-04-10 20:48 - 2018-01-30 14:40 - 136971704 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-04-09 18:46 - 2018-01-30 11:43 - 000000000 ____D C:\Users\admin\AppData\LocalLow\Mozilla
2018-04-08 19:38 - 2018-02-17 16:06 - 000000000 ____D C:\Users\Chris\AppData\Roaming\deluge
2018-04-08 09:47 - 2018-01-30 09:15 - 000000000 ____D C:\Users\Chris\Documents\Google Drive Docs
2018-04-06 09:20 - 2009-07-14 00:08 - 000032614 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-04-05 21:15 - 2018-02-08 11:21 - 000000600 _____ C:\Users\Chris\AppData\Local\PUTTY.RND
2018-04-03 11:25 - 2018-01-30 09:37 - 000000000 ____D C:\Users\Leslie\Documents\100NIKON
2018-04-03 11:21 - 2018-01-30 14:02 - 000072128 _____ C:\Users\Leslie\AppData\Local\GDIPFONTCACHEV1.DAT
2018-03-30 16:34 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy
2018-03-30 16:29 - 2009-07-13 22:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2018-03-30 15:17 - 2018-01-30 19:08 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-03-30 15:16 - 2018-01-30 19:00 - 000000000 ____D C:\Program Files\Microsoft Office 15
2018-03-29 09:02 - 2018-01-30 11:43 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-03-27 11:11 - 2018-01-30 11:43 - 000000936 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-03-27 11:11 - 2018-01-30 11:43 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-03-27 11:05 - 2018-01-31 10:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2018-03-26 12:29 - 2018-02-23 11:06 - 000001024 _____ C:\.rnd
2018-03-26 11:45 - 2018-02-03 10:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2018-03-26 10:23 - 2018-01-30 14:09 - 000000000 ____D C:\Users\Chris
2018-03-26 10:05 - 2018-01-30 12:03 - 000000000 ____D C:\Program Files\Bitdefender
2018-03-25 10:04 - 2018-02-06 09:16 - 000000000 ____D C:\Users\admin\Desktop\Leslie's Computer's Drivers
2018-03-25 07:30 - 2018-01-31 06:02 - 000000000 ____D C:\Users\admin\AppData\Local\Adobe
2018-03-25 07:29 - 2018-01-31 06:03 - 000804352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-03-25 07:29 - 2018-01-31 06:03 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-03-25 07:29 - 2018-01-31 06:03 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-03-25 07:29 - 2018-01-31 06:03 - 000000000 ____D C:\Windows\system32\Macromed
2018-03-23 12:40 - 2018-01-30 20:58 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-03-23 12:29 - 2018-02-17 17:38 - 000000000 ____D C:\Users\Chris\Documents\StarCraft II

==================== Files in the root of some directories =======

2018-02-05 21:39 - 2018-02-05 21:39 - 000000600 _____ () C:\Users\admin\AppData\Local\PUTTY.RND
2018-02-11 10:53 - 2018-02-11 10:59 - 000007606 _____ () C:\Users\admin\AppData\Local\resmon.resmoncfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-04-08 15:33

==================== End of FRST.txt ============================

 



BC AdBot (Login to Remove)

 


#2 Bodum

Bodum
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:20 AM

Posted 14 April 2018 - 12:57 PM

Here is my Addition.txt. Earlier I tried to post them together and I kept getting an "Error 524" message in my browser. I'm glad it is working now!

 

Addition.txt

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14.03.2018
Ran by admin (14-04-2018 12:07:55)
Running from C:\Users\Chris\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2018-01-30 19:09:33)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Abby Lomax (S-1-5-21-2679313766-3789782403-2851624562-1009 - Limited - Enabled) => C:\Users\Abby Lomax
admin (S-1-5-21-2679313766-3789782403-2851624562-1002 - Administrator - Enabled) => C:\Users\admin
Administrator (S-1-5-21-2679313766-3789782403-2851624562-500 - Administrator - Disabled)
Chris (S-1-5-21-2679313766-3789782403-2851624562-1000 - Limited - Enabled) => C:\Users\Chris
Guest (S-1-5-21-2679313766-3789782403-2851624562-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2679313766-3789782403-2851624562-1007 - Limited - Enabled)
Leslie (S-1-5-21-2679313766-3789782403-2851624562-1001 - Limited - Enabled) => C:\Users\Leslie

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: Bitdefender Antivirus (Enabled - Up to date) {3FB17364-4FCC-0FA7-6BBF-973897395371}
AS: Bitdefender Antispyware (Enabled - Up to date) {84D09280-69F6-0029-510F-AC4AECBE19CC}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Enabled) {078AF241-05A3-0EFF-40E0-3E0D69EA140A}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated)
Adobe Flash Player 29 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 29.0.0.113 - Adobe Systems Incorporated)
Amazon Kindle (HKU\S-1-5-21-2679313766-3789782403-2851624562-1000\...\Amazon Kindle) (Version: 1.21.0.48017 - Amazon)
Backup and Sync from Google (HKLM\...\{4B7277C7-9CEE-45FC-B36B-19AD28281B9C}) (Version: 3.40.8921.5350 - Google, Inc.)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 22.0.10.67 - Bitdefender)
Bitdefender Device Management (HKLM\...\Bitdefender Device Management) (Version: 22.0.17.208 - Bitdefender)
Bitdefender Total Security (HKLM\...\Bitdefender) (Version: 22.0.18.224 - Bitdefender)
Bitdefender VPN (HKLM\...\Bitdefender VPN) (Version: 22.0.7.486 - Bitdefender)
CCleaner (HKLM\...\CCleaner) (Version: 5.41 - Piriform)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.51.2.63 - Conexant)
Deluge 1.3.15 (HKLM-x32\...\Deluge) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 65.0.3325.181 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
KeyTweak - Keyboard Remapper (remove only) (HKLM-x32\...\KeyTweak) (Version:  - )
Malwarebytes version 3.4.5.2467 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.4.5.2467 - Malwarebytes)
Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft Office Home and Student 2013 - en-us (HKLM\...\HomeStudentRetail - en-us) (Version: 15.0.5015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2679313766-3789782403-2851624562-1002\...\OneDriveSetup.exe) (Version: 17.3.4604.0120 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Core Components (x64) ENU  (HKLM\...\{8CCBEC22-D2DB-4DC9-A58A-E1A1F3A38C8A}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Provider Services (x64) ENU  (HKLM\...\{03AC245F-4C64-425C-89CF-7783C1D3AB2C}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Visio Professional 2013 (HKLM-x32\...\Office15.VISPROR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25810 (HKLM-x32\...\{56e11d69-7cc9-40a5-a4f9-8f6190c4d84d}) (Version: 14.12.25810.0 - Microsoft Corporation)
Mozilla Firefox 59.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 59.0.2 (x64 en-US)) (Version: 59.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 59.0.2 - Mozilla)
MusicBee 3.1 (HKLM-x32\...\MusicBee) (Version: 3.1 - Steven Mayall)
Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.5.6 - Notepad++ Team)
Office 15 Click-to-Run Extensibility Component (HKLM-x32\...\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.5015.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (HKLM\...\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.5015.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (HKLM-x32\...\{90150000-008C-0409-0000-0000000FF1CE}) (Version: 15.0.5015.1000 - Microsoft Corporation) Hidden
OpenVPN 2.4.5-I601  (HKLM\...\OpenVPN) (Version: 2.4.5-I601 - OpenVPN Technologies, Inc.)
Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM-x32\...\{90150000-001F-040C-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Panda USB Vaccine 1.0.1.16 (HKLM-x32\...\{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1) (Version:  - Panda Security)
Revo Uninstaller 2.0.5 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.5 - VS Revo Group, Ltd.)
Spotify (HKU\S-1-5-21-2679313766-3789782403-2851624562-1000\...\Spotify) (Version: 1.0.77.338.g758ebd78 - Spotify AB)
StarCraft II (HKLM-x32\...\StarCraft II) (Version:  - Blizzard Entertainment)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.5 - Synaptics Incorporated)
TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
VeraCrypt (HKLM-x32\...\VeraCrypt) (Version: 1.21 - IDRIX)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.8 - VideoLAN)
Web Launch Recorder (HKU\S-1-5-21-2679313766-3789782403-2851624562-1000\...\WebLaunchRecorder) (Version: 2.0 - )
WinCDEmu (HKLM-x32\...\WinCDEmu) (Version: 4.1 - Sysprogs)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2017-12-31] ()
ContextMenuHandlers1: [WinCDEmu] -> {D0E37FD2-F675-426F-B09A-2CF37BA46FD5} => C:\Program Files (x86)\WinCDEmu\x64\WinCDEmuContextMenu.dll [2015-09-28] (Sysprogs OU)
ContextMenuHandlers2: [WinCDEmu] -> {A9901FCD-B4DF-43A1-BD5D-6C9F88679497} => C:\Program Files (x86)\WinCDEmu\x64\WinCDEmuContextMenu.dll [2015-09-28] (Sysprogs OU)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2012-05-10] (Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers6: [WinCDEmu] -> {A9901FCD-B4DF-43A1-BD5D-6C9F88679497} => C:\Program Files (x86)\WinCDEmu\x64\WinCDEmuContextMenu.dll [2015-09-28] (Sysprogs OU)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0DECA859-F9FA-4369-A55D-000F9DAD6406} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_113_pepper.exe [2018-03-25] (Adobe Systems Incorporated)
Task: {10DBAC66-2AED-4EF4-A6DF-DFC8F6B6A3B9} - System32\Tasks\AdobeGCInvoker-1.0-Michita-PC-Chris => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-01-05] (Adobe Systems, Incorporated)
Task: {452F874B-8EE1-417B-BFF9-9C0C9250A48B} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe
Task: {5A34807B-A3C5-4D0B-A728-0A9422E54A8C} - System32\Tasks\AdwCleaner_onReboot => C:\Users\Chris\Downloads\AdwCleaner.exe
Task: {5CCFAE5B-AF54-44A4-925E-A95BCC329DF3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-03-25] (Adobe Systems Incorporated)
Task: {5E31ECED-E3EA-4EEC-B06D-B55EA4DB35C5} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {6D43841D-D1DE-464D-9D32-0471F1F4D190} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-01-30] (Google Inc.)
Task: {733954B6-DBE4-460E-9F18-2C148FDA1E69} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
Task: {79D6EF48-63A8-449A-836C-96CB286166DA} - System32\Tasks\{EFB4458F-69BC-494D-93B7-9BC0B96901D6} => C:\Program Files (x86)\StarCraft II\StarCraft II.exe [2018-02-15] (Blizzard Entertainment)
Task: {8C1B88AB-AD8A-4282-BE58-AC68C847D70D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)
Task: {8D2FDB44-525A-4092-8FAF-68F74D8B4189} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-03-06] (Piriform Ltd)
Task: {904B6DCD-55E0-4BF7-BE5F-63256D4B1C6C} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
Task: {9835F1D4-86CD-45A8-A509-2A6D006B7C45} - System32\Tasks\Synaptics TouchPad Enhancements => Program Files\Synaptics\SynTP\SynTPEnh.exe
Task: {A6600EB4-8B08-4781-ABD5-7CE46FD2C61D} - System32\Tasks\PandaUSBVaccine => C:\Program Files (x86)\Panda USB Vaccine\RunInteractiveWin.exe [2010-06-01] ()
Task: {AAC49296-209B-4538-A5FD-E71E91D1C480} - System32\Tasks\AdobeGCInvoker-1.0-Michita-PC-admin => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-01-05] (Adobe Systems, Incorporated)
Task: {AB870DB8-D8A2-4FDD-9A11-9C12FBDD61CF} - System32\Tasks\AdobeGCInvoker-1.0-Michita-PC-Leslie => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-01-05] (Adobe Systems, Incorporated)
Task: {B11FE323-38EE-4AA1-953E-D3B7D455F123} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-03-06] (Piriform Ltd)
Task: {BEE32288-88EC-4CD7-9236-1F5045B09EC0} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-12-12] (Microsoft Corporation)
Task: {C1885B05-3D3C-4053-99DD-8878099B897F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-01-30] (Google Inc.)
Task: {CBB29516-A573-45BA-96E2-8CCC820A0939} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2017-10-31] (Bitdefender)
Task: {DE38B930-F42B-4EFA-BA01-0DCED046121D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {E29A559C-7C9F-45DD-9A4D-A91398785CF9} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-12-12] (Microsoft Corporation)
Task: {E90A53F1-E844-4109-89EC-9F5855CACF8B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2018-01-30 12:05 - 2017-02-07 12:34 - 001008448 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttpbr.mdl
2018-01-30 12:05 - 2017-02-07 12:34 - 000541952 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttpdsp.mdl
2018-01-30 12:05 - 2017-02-07 12:34 - 003243920 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttpph.mdl
2018-01-30 12:05 - 2017-02-07 12:34 - 001544568 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttprbl.mdl
2018-01-30 19:00 - 2017-01-17 03:25 - 000117440 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2018-01-30 13:58 - 2018-04-14 11:38 - 000017920 _____ () C:\Windows\System32\rpcnetp.exe
2018-04-13 15:46 - 2018-03-12 15:09 - 002300192 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-04-13 15:46 - 2018-03-27 13:47 - 002492704 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2018-01-30 19:10 - 2018-01-30 19:10 - 008909512 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2017-12-31 20:07 - 2017-12-31 20:07 - 000230064 _____ () C:\Program Files\Notepad++\NppShell_06.dll
2018-01-30 10:06 - 2012-05-10 14:16 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2018-03-01 03:51 - 2018-03-01 03:51 - 000665216 _____ () C:\Program Files\OpenVPN\bin\openvpn-gui.exe
2018-03-15 11:31 - 2018-03-15 11:31 - 046139776 _____ () C:\Program Files\Google\Drive\googledrivesync.exe
2018-04-14 11:43 - 2018-04-14 11:43 - 000113152 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\_ctypes.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000080896 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\bz2.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 001585152 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\_hashlib.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000128512 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\win32api.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000137728 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\pywintypes27.dll
2018-04-14 11:43 - 2018-04-14 11:43 - 000548864 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\pythoncom27.dll
2018-04-14 11:43 - 2018-04-14 11:43 - 000689664 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\unicodedata.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000438784 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\win32com.shell.shell.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 001489408 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\wx._core_.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 001007104 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\wx._gdi_.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 001039872 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\wx._windows_.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 001325056 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\wx._controls_.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000916992 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\wx._misc_.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 001084416 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\pysqlite2._sqlite.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000149504 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\win32file.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000136192 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\win32security.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000007680 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\hashobjs_ext.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000020992 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\thumbnails_ext.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000118784 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\usb_ext.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000047616 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\_socket.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 002224128 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\_ssl.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000014848 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\common.time34.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000023040 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\win32event.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000033280 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\windows.conditional.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000019968 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\windows.winwrap.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000107520 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\windows.volumes.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000223232 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\win32gui.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000173568 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\_elementtree.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000169472 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\pyexpat.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000048128 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\win32inet.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000103424 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\wx._html2.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000046080 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\_psutil_windows.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000633240 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\windows._cacheinvalidation.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 005408256 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\cello.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000010752 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\select.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000011776 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\win32crypt.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000301568 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\PIL._imaging.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000032256 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\_multiprocessing.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000026112 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\_yappi.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000044032 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\win32process.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000027648 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\win32pipe.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000029696 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\win32pdh.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000038400 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\windows.connectivity.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000071168 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\windows.device_monitor.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000020480 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\win32profile.pyd
2018-04-14 11:43 - 2018-04-14 11:43 - 000026624 _____ () C:\Users\Chris\AppData\Local\Temp\_MEI49362\win32ts.pyd
2018-03-01 03:51 - 2018-03-01 03:51 - 000226208 _____ () C:\Program Files\OpenVPN\bin\liblzo2-2.dll
2018-03-01 03:51 - 2018-03-01 03:51 - 000127488 _____ () C:\Program Files\OpenVPN\bin\libpkcs11-helper-1.dll
2018-01-30 19:01 - 2018-01-30 19:01 - 000325824 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\AppVIsvStream32.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2018-04-14 11:39 - 000000000 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2679313766-3789782403-2851624562-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-2679313766-3789782403-2851624562-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\admin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 198.18.0.1 - 198.18.0.2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: AGSService => 2
MSCONFIG\Services: BdVpnService => 2
MSCONFIG\Services: BitdefenderVpnSvc => 3
MSCONFIG\Services: CxAudMsg => 2
MSCONFIG\Services: GlassWire => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: rpcnet => 2
MSCONFIG\startupreg: AdobeGCInvoker-1.0 => "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe"
MSCONFIG\startupreg: SmartAudio => C:\Program Files\CONEXANT\SAII\SACpl.exe /t

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{63C932E3-A989-4B22-82AB-7B2D26A0D159}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{4CBE834E-D530-45E9-810C-0D023E37FBFE}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{A388E9A6-20EA-4863-85CC-47A22D4A5E85}] => (Allow) C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
FirewallRules: [{9EFB2EFA-1AE9-43E9-87F4-87C05FA7D40B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{55B31162-4EDF-434C-8F22-3D43E18E9CF5}] => (Allow) C:\Program Files (x86)\BlueStacks\HD-Player.exe

==================== Restore Points =========================

08-04-2018 18:07:03 Revo Uninstaller's restore point - IPVanish
10-04-2018 20:46:00 Windows Update

==================== Faulty Device Manager Devices =============

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (04/14/2018 11:39:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (04/13/2018 04:06:51 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (04/13/2018 12:27:05 PM) (Source: openvpnserv) (EventID: 0) (User: )
Description: Event-ID 0

Error: (04/13/2018 12:19:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (04/12/2018 09:25:58 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (04/11/2018 10:56:13 AM) (Source: openvpnserv) (EventID: 0) (User: )
Description: Event-ID 0

Error: (04/11/2018 10:55:57 AM) (Source: openvpnserv) (EventID: 0) (User: )
Description: Event-ID 0

Error: (04/11/2018 10:55:09 AM) (Source: openvpnserv) (EventID: 0) (User: )
Description: Event-ID 0


System errors:
=============
Error: (04/14/2018 11:54:00 AM) (Source: BROWSER) (EventID: 8032) (User: )
Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{7C3298EF-987F-442C-B686-0966568CCC33}.
The backup browser is stopping.

Error: (04/14/2018 11:39:29 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\Windows\system32\Rtlihvs.dll
Error Code: 126

Error: (04/13/2018 10:07:30 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The TCP/IP NetBIOS Helper service failed to start due to the following error:
The service did not start due to a logon failure.

Error: (04/13/2018 10:07:30 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The lmhosts service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error:
The security account manager (SAM) or local security authority (LSA) server was in the wrong state to perform the security operation.


To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

Error: (04/13/2018 04:06:03 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\Windows\system32\Rtlihvs.dll
Error Code: 126

Error: (04/13/2018 04:04:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Media Player Network Sharing Service service failed to start due to the following error:
The service did not start due to a logon failure.

Error: (04/13/2018 04:04:31 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The WMPNetworkSvc service was unable to log on as NT AUTHORITY\NetworkService with the currently configured password due to the following error:
The request is not supported.


To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

Error: (04/13/2018 04:04:01 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Bitdefender Vpn Service service terminated unexpectedly.  It has done this 1 time(s).


CodeIntegrity:
===================================

Date: 2018-01-30 18:20:42.178
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\admin\Downloads\VCdRom.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-01-30 18:20:42.147
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\admin\Downloads\VCdRom.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-01-30 14:22:19.667
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-01-30 14:22:19.667
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

Processor: Intel® Pentium® CPU B950 @ 2.10GHz
Percentage of memory in use: 52%
Total physical RAM: 8092.36 MB
Available physical RAM: 3845.96 MB
Total Virtual: 16182.89 MB
Available Virtual: 11900.79 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:698.54 GB) (Free:461.73 GB) NTFS

\\?\Volume{7fd83ac3-05ef-11e8-80fc-806e6f6e6963}\ () (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 698.6 GB) (Disk ID: B27ACCC4)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=698.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================



#3 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,341 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:12:20 PM

Posted 15 April 2018 - 11:37 AM

Bodum:

:welcome: to the Bleeping Computer Virus, Trojans, Spyware, and Malware Removal Logs Forum. My name is Phil. May I address you by your first name?

I will be assisting you with your computer issues. I will endeavor to respond within a reasonable time. Forum policy requires that I post within 48 hours after your last post, but I do endeavor to post within 24 hours of your last post.

I would ask that you please continue to copy and paste the contents of all requested log files directly into your replies. Please do not use "code" or "quote" boxes. Thank you for your anticipated cooperation.

I will need some time to review your FRST logs. That could take a day or two, but I do hope to respond later today with an initial FRST "fixlist" script.

PLEASE DO NOT RUN ANY ADDITIONAL SCANS OR ANTI-MALWARE REMOVAL TOOLS UNTIL YOU HAVE RECEIVED A RESPONSE FROM ME.
Doing so would complicate the situation and it would cause further delays in resolving your issues. It could also potentially result in harm to your computer because my "fix" will be based on the FRST scan logs you have already submitted.

Thank you and have a great day.

Regards,
-Phil


Member of the Unified Network of Instructors and Trusted Eliminators


#4 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,341 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:12:20 PM

Posted 15 April 2018 - 12:52 PM

Bodum:

Thank you for your patience while I analyzed your FRST logs.

Before we start dealing with the problems you are experiencing, I would ask that you to take note of the following points:

  • I am a Bleeping Computer volunteer, so I ask you to be patient. I know it is frustrating when your computer is not working properly, but malware removal takes time.
  • Please also remember that I can only dedicate a limited number of hours a day to helping people. We may live in different time zones, which may cause delays in responding.
  • If I have not responded to you within 48 hours, please send me a personal message. Likewise, I expect you to respond within 48 hours, and sooner is better because we can fix your computer faster.
  • If I have not heard from you in three days, I will "bump" your post. After five days of no response, I will consider that you no longer need my assistance and this thread will be closed.
  • Logs can take a while to research, so please be patient.
  • Some issues just cannot be solved so you must be prepared for this.
  • Please read and follow the instructions in the exact sequence that they are posted to avoid making a bad situation worse.
  • Please print or copy and save the instructions.
  • Back up all your data and important files on another (external) drive before starting to run malware removal tools. Malware removal can cause unpredictable and unintended issues. Also you should be aware that some of the tools and scripts that will be used, will remove malware detected, without notice.
  • You should try to limit your browsing with this computer until you are given the "All Clear." Some malware applications steal passwords.
  • Please do not install or uninstall any applications, unless directed. Don't run any scripts or tools on your own because unsupervised usage may cause more harm than good.
  • Please use only the tools you have been instructed to use.
  • If you are using CD/DVD emulation software, this should be uninstalled or disabled as it can interfere with the removal of some malware. It can be turned off with Defogger and then turned back on when you get the "All Clear."
  • Please copy and paste the requested log files inside your post(s), unless otherwise instructed. Please do not use code or quote boxes.
  • There are no silly questions. Ask for clarification, if you have any questions or concerns.
  • Bleeping Computer does not support any piracy. Evidence of illegal OS, software, cracks/keygens, etc., will be revealed by scan logs, and if found, further assistance may be suspended. Uninstall such software before proceeding!
  • Any P2P software such as uTorrent, BitTorrent, Kazaa, etc. must be uninstalled or completely disabled. P2P software is a major security risk to your computer and may have been the route the malware used to infect your computer.
  • Failure to follow these guidelines may result in assistance being withdrawn and your thread being closed.
  • I am volunteering my time to help you, and I will need you to help me. Together, we can, hopefully, disinfect your computer and get if functioning properly again. That is my only aim.

.

OK, let's get started ...

.

:step1: Please run a FRST fix for me. I want to investigate some files.

I am not seeing, so far, any active malware on your computer. I am also a Bitdefender Total Security user, but I do not use their new Bitdefender VPN Premium (or Free) programs. I visit the Bitdefender Forums daily and there are issues with this "new" product that are being addressed. That said, I notice that you also have OpenVPN installed.

 

I am wondering if there could be a conflict between these two products that might explain the lagging performance. You could try uninstalling the OpenVPN program and see if it makes any difference in the performance on your computer. The reason that I suggest this is that both programs have open processes running that might be conflicting with each other.

NOTICE: This FRST "fixlist" script was written specifically for this user, for use on this individual computer. Running this on another computer may cause damage to your operating system.
 

Start::
CreateRestorePoint:
CloseProcesses:
File: C:\Windows\System32\rpcnetp.exe
VirusTotal: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gannpgaobkkhmpomoijebaigcapoeebl
File: C:\Windows\System32\DRIVERS\aftap0901.sys
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
File: C:\Windows\system32\gpedit.msc;C:\Windows\SysWOW64\gpedit.msc
End::
  • Please highlight the entire contents of the code box above, from the "Start::" line to the "End::" line, including both of those lines, right click, and select "Copy", which will copy the "fix" script into the Windows clipboard.
  • Right click FRST64.exe, and select "Run as Administrator".
  • Press Fix button once and wait.
  • Please reboot the computer, if requested.
  • A log file called "fixlog.txt" will be saved in the same folder as the FRST program is located.
  • Please copy and paste the contents of the "fixlog.txt" file into your next reply.

.

Thank you and have a great day.

Regards,
-Phil


Member of the Unified Network of Instructors and Trusted Eliminators


#5 Bodum

Bodum
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:20 AM

Posted 15 April 2018 - 01:24 PM

Hi Phil!

My name is Chris. I read through your message carefully. You ask me to remove all P2P software; I had Deluge installed and before running the FXRT scan, I removed it using RevoUninstaller, which also removed the registry key for Deluge. But I do have a question about this. You say P2P is a major security concern. Can you please explain this in more detail? What are the security concerns? Is there a way to use P2P safely? A lot of sites allow you to download legal products using P2P and it is typically much faster. Thank you for your help!

 

I ran FRST and here is my, here is my fixlog.txt:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 15.04.2018
Ran by admin (15-04-2018 13:07:03) Run:1
Running from C:\Users\Chris\Desktop
Loaded Profiles: Chris & admin (Available Profiles: Chris & Leslie & admin & Abby Lomax)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
File: C:\Windows\System32\rpcnetp.exe
VirusTotal: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gannpgaobkkhmpomoijebaigcapoeebl
File: C:\Windows\System32\DRIVERS\aftap0901.sys
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
File: C:\Windows\system32\gpedit.msc;C:\Windows\SysWOW64\gpedit.msc

*****************

Restore point was successfully created.
Processes closed successfully.

========================= File: C:\Windows\System32\rpcnetp.exe ========================

C:\Windows\System32\rpcnetp.exe
File is digitally signed
MD5: 0036FF1838951639C6B7EE13218C0A21
Creation and modification date: 2018-01-30 13:58 - 2018-04-14 11:38
Size: 000017920
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
VirusTotal: https://www.virustotal.com/file/7dfde0fd2a361438db85c7abf89e22e9d50ab3509815bc0b6ad1b7ad1060e301/analysis/1523195829/

====== End of File: ======

VirusTotal: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gannpgaobkkhmpomoijebaigcapoeebl => D41D8CD98F00B204E9800998ECF8427E (0-byte MD5)

========================= File: C:\Windows\System32\DRIVERS\aftap0901.sys ========================

C:\Windows\System32\DRIVERS\aftap0901.sys
File is digitally signed
MD5: CAC023BFA2B7D9ADB24B1779B3ABB091
Creation and modification date: 2018-02-24 06:03 - 2017-11-29 07:51
Size: 000048624
Attributes: ----A
Company Name: The OpenVPN Project
Internal Name: aftap0901.sys
Original Name: aftap0901.sys
Product: TAP-Windows Virtual Network Driver (NDIS 6.0)
Description: TAP-Windows Virtual Network Driver (NDIS 6.0)
File Version: 9.21.2 9/21
Product Version: 9.21.2 9/21
Copyright: OpenVPN Technologies, Inc.
VirusTotal: https://www.virustotal.com/file/fc8da96cb5dd7555b9b97b8241c51f4dca9beacf02da76e5a6a807dc3c3f0fe8/analysis/1520881217/

====== End of File: ======

"HKLM\System\CurrentControlSet\Services\VMnetAdapter" => removed successfully
VMnetAdapter => service removed successfully

========================= File: C:\Windows\system32\gpedit.msc;C:\Windows\SysWOW64\gpedit.msc ========================

C:\Windows\system32\gpedit.msc
File not signed
MD5: C9AD01520798DC5CD144C2DCE97657C3
Creation and modification date: 2018-03-30 16:29 - 2001-08-23 13:00
Size: 000034871
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
VirusTotal: https://www.virustotal.com/file/da7f0d319289ddbcd70d110f72778cec6246e342f65fef727219bd575405d89b/analysis/1521136258/

C:\Windows\SysWOW64\gpedit.msc
File not signed
MD5: C9AD01520798DC5CD144C2DCE97657C3
Creation and modification date: 2018-03-30 16:20 - 2001-08-23 13:00
Size: 000034871
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
VirusTotal: https://www.virustotal.com/file/da7f0d319289ddbcd70d110f72778cec6246e342f65fef727219bd575405d89b/analysis/1521136258/

====== End of File: ======



The system needed a reboot.

==== End of Fixlog 13:07:36 ====



#6 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,341 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:12:20 PM

Posted 15 April 2018 - 02:14 PM

Chris:

 

Thank you for your post and for permission to address you by your first name.  :thumbup2:  Also, thank you for running the FRST "fixlist" script.

 

All looks benign, although the file (and two other variants):

 

C:\Windows\System32\rpcnetp.exe

 

do not have a lot of file properties information.  From some sources, I determined that it apparently might be an Absolute Software Lojack file(s), used to trace and protect laptops.  The problem is that I don't see Lojack as an installed program (I don't see it on my own laptop either and I have Lojack installed on it).  I presume that is a security measure to avoid tipping off the thief that the computer can be traced and remotely locked down, as would the lack of file "properties" information for the three related files.

 

:step1: So the question is: do you have Lojack installed on the computer?

 

.

 

:step2: Have you run a Bitdefender Total Security "System Scan"?  The Quick Scan just checks files and folders where malware commonly resides.  I am guilty of overkill, I know, but I run full "System Scans" on both of my computers weekly.  I guess that being in this "business" has made me a super cautious.  I have seen so many lose so much, so quickly, and have no backups!

 

Ordinarily I would have you run a suite of standard free anti-malware scans, but you have Bitdefender Total SecurityMalwarebytes, and AdwCleaner on your computer, and I presume you have run all of the scans, with the exception possibly of a BD System Scan.

 

.

 

:step3: Personally, I would not go near P2P!  That is a major attack vector for malware and there is no way to use P2P safely.  I would recommend that you read this article by quietman7, one of the foremost computer security experts here at Bleeping Computer.  I am not accusing, or even suggesting, that you might use "cracks" or "keygens" (but many do), so please scroll down to :step2: in that article.  There are too many people who think that you can use P2P safely.  P2P is not a benign entity, and you open yourself, and your computer, to serious vulnerabilities that malware exploits.

 

.

 

Thank you and have a great day.

 

Regards,

-Phil


Member of the Unified Network of Instructors and Trusted Eliminators


#7 Bodum

Bodum
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:20 AM

Posted 15 April 2018 - 05:04 PM

Hi Phil,

 

No problem! And:

 

1) I do not think I have lojack, but I'm not sure. Is there a way I can check? BUT I did have prey for about a week. I recently uninstalled it. Also, I looked under Task Manager / Services and I saw the following services "rpcnet (stopped), rpcnetp (running, location Windows/System32)".

 

2) I have not yet run a System Scan, I will run one now! I run a weekly deep scan that is a "custom scan" in Bitdefender. It says it scans for rootkits and doesn't ignore any files (even old ones). I tried to set the highest settings for the scan. Are system scans different?   ... I ran the scan and it said the system is clean.

 

3) Thank you for the info! I will start reading!

 

4) Regarding OpenVPN. I am certainly willing to uninstall it and see how it works. However, I use it for my VPN so I have encrypted traffic. I would prefer to keep it rather than use the Program developed by my VPN provider. Should I remove Bitdefender VPN instead? I don't use it at all.

 

5) My computer was acting slow again. I checked Task manager as an admin, and Firefox was using about 1,200,000 K of Memory and my CPU usage was at 99 %. Is this normal for Firefox? I had three tabs open. One was streaming a non-HD video.

 

 

Best,

Chris


Edited by Bodum, 15 April 2018 - 05:06 PM.


#8 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,341 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:12:20 PM

Posted 16 April 2018 - 12:39 PM

Chris:
 
Thank you for your post.  I did some more research on rpcnet.exe (and associated files).  It appears that the computer manufacturer may have installed those files.  If you "google" rpcnet, you will find lots of hits, like this one.  I think that it is safe to leave it alone.
 
I do have Bitdefender 2018 Total Security, but I have never activated the new free VPN option that they offered a few months back.  Bitdefender VPN does not appear in my list of installed programs, so it might be safe to uninstall it or deactivate it.  Personally, I would either post over at the Bitdefender Forums, here; or, contact their Tech Support to see how to properly disable or uninstall the product.

 

By all means keep your OpenVPN.  I was just suggesting that there MIGHT BE a conflict between the two VPN products, but that is just a GUESS!
 
There are lots of complaints about the newer versions of Mozilla Firefox consuming excess CPU and memory.
 
Link 1
Link 2
Link 3
 
You can "google" Firefox hogging CPU and memory, and you will get lots of hits.  I don't use Firefox, so I can't tell you what is "normal" for it.  You might want to try some of the suggested fixes.  What we know, is that we can't find any evidence of active malware being responsible for this issue, based on the scans that we have run.
 
Thank you and have a great day.
 
Regards,
-Phil


Member of the Unified Network of Instructors and Trusted Eliminators


#9 Bodum

Bodum
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:20 AM

Posted 17 April 2018 - 10:34 AM

Hi Phil,

 

Thank you for your help! I will start reading about Firefox and I'll leave rpcnet.exe alone. Well, I'm glad to know there isn't any obvious malicious activity on my computer. I assume we've resolved this as much as we can.

 

However, I did have one other concern. Today another computer that connects to the same access point as the computer discussed in this forum suddenly couldn't resolve DNS or flush DNS. I created another post under the "What do I do? Am I infected forum?" You can find it here.

 

Do you think this could be related? Is it possible there is a worm on my network? Or is it more likely that this is a coincidence?

 

Best,

Chris



#10 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,341 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:12:20 PM

Posted 17 April 2018 - 11:13 AM

Chris:
 
Thank you for your post.  We normally only deal with one computer per topic, for obvious reasons.  It could get really confusing, really quickly.
 
Since you have posted in the Am I Infected? What Do I Do? (AII) Forum about the second computer, I think that we should let that run its course since duplicate topics also cause confusion and duplication of effort.  If the helpers in the AII Forum suspect a malware infestation that they cannot deal with in the AII Forum (because of AII Forum rules governing which anti-malware tools may be used in that Forum), they will instruct you to post FRST scan logs for that computer in this Forum.
 
The question that occurs to me, and that I am sure that it has occurred to you is: If you have an active "network" worm, why is only one computer on the network affected?  Network worms like to spread!  See this link.

Since we have ruled out malware issues on this computer, we should clean up a little.

.

:step1: Please manually delete the following files/folders:

  • C:\FRST
  • FRST/FRST64.exe.
  • C:\fixlog.txt.
  • All desktop shortcut icons related to the anti-malware scanners/cleaners that we used.

.

:step2: . . . Some Final Advice . . .

The most common cause of an infected machine is the Trojan Horse, or programs which appear to be legitimate but which contain malicious payloads, or which are simply malicious in and of themselves. No antivirus, firewall, host-based intrusion prevention system (HIPS), or other security software can fully protect you against this kind of attack. The best way to project yourself is not to run email attachments from untrusted sources, and avoid software downloaded from the internet wherever possible. Remember, when you run an application, you are giving that application permission to do to your machine anything you can do to the machine, including create, modify, or destroy files or other data. In the Windows (and most other systems' such as Unix) security model, applications don't have privileges, users do.

The second most common cause of infection is out of date software. Leaving your system unpatched leaves holes through which attackers can execute code on your behalf without your consent. This goes for far more than common targets such as Windows and Internet Explorer. Most recent threats target other third party software, such as Adobe's Adobe Reader, Shockwave Player, or Flash Player, or Oracle's Java browser plugins. You can check your system for out of date software manually, or by using automated software tools, such as Adlice Software UCheck. This goes doubly for security applications such as antivirus and other antimalware products based on definition lists, where out-of-date lists mean no detection of newer malware.

Finally, occasionally you will be forced to run some potentially infected binary, or attackers will use a hole which is unpatched by software vendors, so a last line of defense is needed. That means turning on a firewall (Windows Firewall included with Windows Vista or later is fine) and leaving it on, and using and keeping up-to-date an antivirus solution such as Bitdefender. Antiviral solutions don't even have to cost money; later versions of Windows Defender provide perfectly acceptable protection for free. If for some reason you don't like Windows Defender, there are other free products available as well or you can purchase a security product or products.

  • Avira (shows nag screen to purchase full product when updating, home use only)
  • Bitdefender Free (home use only)

Personally I use Bitdefender 2018 Total Security, along with Malwarebytes Premium. Another paid product worth considering is Emsisoft Anti-Malware, which combines the Bitdefender virus scanning engine with their own anti-malware engine, so that you essentially get two computer security products, totally integrated, for the price of one. Please consult this link for more information on choosing a computer security product.

If you want more information about the methods that malware uses to infect your computer, please consider browsing our How did I get infected? topic.

.

It has been a pleasure assisting you and I hope that you will avoid any further infections in the future. Your most important protection step is to ALWAYS HAVE MORE THAN ONE RECENT BACKUP OF YOUR ENTIRE SYSTEM on an external drive that is only connected to your computer long enough to backup or restore. I do system images weekly. With the free backup software out there (Easeus ToDo Backup Home, Macrium Reflect, etc.), and the very reasonable prices for external USB hard drives, there is no reason to not have a backup.

.

If you have no other questions about this computer, then I will conclude your topic. Please let me know. Thank you.

On behalf of the Bleeping Computer (BC) community, thank you for choosing BC to assist you with your computer issues, stay safe out there in cyberspace, and have a great day.

Regards,
-Phil


Member of the Unified Network of Instructors and Trusted Eliminators


#11 Bodum

Bodum
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:20 AM

Posted 17 April 2018 - 11:41 AM

Hi Phil,

 

Thank you for the info! I have no further questions.

 

Singing off,

 

Best,

Chris



#12 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,341 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:12:20 PM

Posted 17 April 2018 - 11:43 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

Member of the Unified Network of Instructors and Trusted Eliminators





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users