Need Help Removing Virus/Malware - Virus, Trojan, Spyware, And ...
Có thể bạn quan tâm
-
Sign In - Create Account
Search Advanced Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. Click here to Register a free account now! or read our Welcome Guide to learn how to use this site. Latest News: OpenAI's ChatGPT ads will allegedly prioritize sponsored content in answers
Featured Deal: A lifetime of ad-free documentaries without a recurring bill in this deal
Latest Buyer's Guide: Best VPNs in 2025
Need Help Removing Virus/Malware Started by DominoPunkyHeart , Jan 05 2022 05:19 PM - Page 1 of 2
- 1
- 2
- Next
#1
DominoPunkyHeart
DominoPunkyHeart -
- Members
- 10 posts
- OFFLINE
- Local time:01:59 PM
Posted 05 January 2022 - 05:19 PM
I'm brand new to this site, so I hope I'm posting this in the right section. I need some help removing a possible virus or malware on my computer that recently started infecting it. My browser keeps closing by itself and then reopening because of something that is using Windows Powershell to do this, and my Windows Defender recentlty detected something called Win32/Wacapew.C!ml and I don't know how to remove it. I've tried Malwarebytes but it didn't seem to find it and remove it for me. It's becoming very bothersome and I'm afraid it will access information that I don't want it to. I came across this website while searching for solutions and I downloaded the Farbar Recovery Scan Tool. I scanned my computer and it gave me two txt files showing my laptop's information. I haven't used the "fix" option yet and I don't know where to go from here. If anyone can help me with this, I would be greatly appreciated. I've included the txt files the Farbar gave me after scanning. Thank youAttached Files
Back to top
BC AdBot (Login to Remove)

- BleepingComputer.com
- Register to remove ads
#2
polskamachina
polskamachina -
- Malware Response Team
- 5,965 posts
- OFFLINE
- Gender:Male
- Location:California
- Local time:10:59 AM
Posted 05 January 2022 - 07:24 PM
Hi DominoPunkyHeart
My name is polskamachina and I would like to
you to the Malware Removal Forum. I will be helping you with your malware issues. What follows below are some ground rules for this forum. I will reply as soon as possible (typically within 24-48 hours). In turn, I ask that you please respond within 72 hours. If you know you will be away longer than that, please let me know. I am in California at GMT-8 hours (Pacific Standard Time). If I do not respond to you within 48 hours, feel free to send me a private message. Some points for you to keep in mind:
- Do NOT run any tools unless instructed to do so.
- We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine. Running any additional tools may detect false positives, interfere with our tools, cause unforeseen damage, or system instability.
- Do not attach logs or use code boxes, just copy and paste the text into your replies to me.
- I cannot see your computer. Periodically update me on the condition of your computer, and provide as much detail as you can in every post.
- Once things seem to be working again, please do not abandon the thread. I will give an "all-clean" message at the very end.
- NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planned. You can put them on a CD/DVD, external drive or a flash drive, anywhere except on the computer.
- NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. Please remember to copy the entire post so you do not miss any instructions.
Let me review your situation and I will get back to you soon with further instructions. polskamachina
If I have made your computing life easier, please consider making a contribution.
Back to top
#3
DominoPunkyHeart
DominoPunkyHeart - Topic Starter
-
- Members
- 10 posts
- OFFLINE
- Local time:01:59 PM
Posted 05 January 2022 - 07:38 PM
Thank you very much, polskamachina for considering to help me with this situation.
I will be going offline shortly for sleep, but I will be checking for your replies as soon as I wake again - and I will keep in touch until my problem is resolved. After reading your message, you can be sure that I won't try to remove the possible malware without your help. Again, thank you for assisstance with this issue, I greatly appreciate it!
Back to top
#4
polskamachina
polskamachina -
- Malware Response Team
- 5,965 posts
- OFFLINE
- Gender:Male
- Location:California
- Local time:10:59 AM
Posted 06 January 2022 - 12:23 PM
Hi DominoPunkyHeart
Going over your logs I noticed that you have μTorrent installed.
- Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
- They are a security risk which can make your computer susceptible to a wide variety of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.
- Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
- The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.
It is pretty much certain that if you continue to use P2P programs, you will get infected again. I would recommend that you uninstall μTorrent, however that choice is up to you. If you do not wish to remove it, then please DO NOT USE IT DURING OUR MALWARE REMOVAL PROCESS. Directions for removal are here. Next:
- Highlight the text below in its entirety and press Ctrl-C to copy it to your clipboard:
- Run FRST64
- Click on Fix
- When the fix completes, you will be asked to restart your computer. Please allow the restart.
- When your computer reboots back to your Desktop, the file Fixlog.txt will have been placed into your Downloads folder
- Copy and paste (do not attach) that file into your next reply to me
Next:
- Download AdwCleaner and save it to your Desktop
- Right-click on AdwCleaner.exe and select
Run as Administrator - Accept the EULA (I accept), then click on Scan Now
- Let the scan complete
- Once the scan completes, make sure that every item listed in the different tabs is checked and click on the Clean & Repair button
- Subsequently you may be asked to Run Basic Repair. This is optional. I would suggest holding off on this for now.
- Once the cleaning process is complete, AdwCleaner will ask you to restart your computer
- Close all other open windows and allow it to restart
- After the restart, Notepad will open with the AdwCleaner cleaning log
- Please copy and paste the contents of that log into your next reply to me
In summary I will need from you:
- Fixlog.txt
- AdwCleaner cleaning log
- How is your computer performing now?
Let me know if you have any questions.
polskamachina
If I have made your computing life easier, please consider making a contribution.
Back to top
#5
DominoPunkyHeart
DominoPunkyHeart - Topic Starter
-
- Members
- 10 posts
- OFFLINE
- Local time:01:59 PM
Posted 07 January 2022 - 05:49 AM
Hello polskamachina,
The other day when I booted up my laptop to check for your replies, I noticed my malware program Malwarebytes started running a scan so I let it do it on its own. When it finished, it caught several trojans that I believe were causing my problem. For the last few days I haven't noticed any problems with my laptop computer at all! Thankfully, I think Malwarebytes has saved it by removing those virus torjans. I thank you for your help with everything, but I may not actually need to use your fix now if my laptop is running okay again, unless you recommend I do something from here? Also, I don't believe utorrent had caused this because I haven't used it in a while. I may very well delete it since I haven't really been using it lately, but I was always careful about using it for only specific downloads. If you want, I can show you my logs again just to be sure everything is completely clear? Again, I thank you for your help and I will certainly come here again if I need any help in the future.
-DominoPunkyHeart
Back to top
#6
Maurice Naggar
Maurice Naggar -
- Malware Response Team
- 2,155 posts
- OFFLINE
Eradicator de malware
- Gender:Male
- Location:USA
- Local time:12:59 PM
Posted 07 January 2022 - 10:44 AM
Hello DominoPunkyHeart. Please do all that is outlined by Polskamachina. This pc has a serious Chrome hijacker "Chromeloader". ~Maurice Naggar MS-MVP (Oct 2002 - Sept 2010)
Back to top
#7
polskamachina
polskamachina -
- Malware Response Team
- 5,965 posts
- OFFLINE
- Gender:Male
- Location:California
- Local time:10:59 AM
Posted 07 January 2022 - 12:29 PM
Hi DominoPunkyHeart ![]()
If you want, I can show you my logs again just to be sure everything is completely clear?
Yes, please show me the Malwarebytes log. The procedure for exporting the report is as follows:
- Open Malwarebytes for Windows.
- Click the Scanner card.
- Click the Reports tab.
- At the top-right of the Scan reports, you can Hide reports with no detections by checking the box.
- Hover your cursor over the report you want to view (the one with the most recent date) and click the eye icon (
). - A Summary window displays to show the scan results and the date and time executed. For more details, click the Advanced tab in this window.
- To download the full report, click Export, and click Copy to Clipboard
- Paste your report into your next reply to me
Next:
- Run FRST64
- Click on Scan
- When the scan completes, copy and paste FRST.txt and Addition.txt into your next reply to me
In summary I will need the following logs from you:
- Latest Malwarebytes removal report
- FRST.txt
- Addition.txt
Let me know if you have any questions.
polskamachina
If I have made your computing life easier, please consider making a contribution.
Back to top
#8
DominoPunkyHeart
DominoPunkyHeart - Topic Starter
-
- Members
- 10 posts
- OFFLINE
- Local time:01:59 PM
Posted 07 January 2022 - 08:27 PM
Hello polskamachina, in my reply I have included all the logs you've asked for. Please let me know if any further attention is needed for my laptop and I will check for your reply. Hopefully everything is back to working order. -DominoPunkyHeart Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 1/6/22 Scan Time: 3:13 AM Log File: 90fa41a4-6ec8-11ec-89f2-c85b76ddc406.json -Software Information- Version: 4.5.0.152 Components Version: 1.0.1538 Update Package Version: 1.0.49486 License: Trial -System Information- OS: Windows 10 (Build 19042.1415) CPU: x64 File System: NTFS User: System -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Scheduler Result: Completed Objects Scanned: 321798 Threats Detected: 4 Threats Quarantined: 4 Time Elapsed: 6 min, 0 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 3 Trojan.Downloader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ChromeLoader, Quarantined, 525, 1013878, , , , , , Trojan.Downloader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5FC46DA9-B902-4534-BD56-314763BE61C1}, Quarantined, 525, 1013878, , , , , , Trojan.Downloader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{5FC46DA9-B902-4534-BD56-314763BE61C1}, Quarantined, 525, 1013878, , , , , , Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 0 (No malicious items detected) File: 1 Trojan.Downloader, C:\WINDOWS\SYSTEM32\TASKS\ChromeLoader, Quarantined, 525, 1013878, 1.0.49486, , ame, , 2B041E4905764C13DFE4E21F91A7F935, 3B1F10F160AF29DD6E2F2F366BD612017ABD3F57E01BDCB69F0B0D5BA1E0879C Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-12-2021 Ran by scott (administrator) on DOMINOPUNKYHEAR (LENOVO 80Q0) (07-01-2022 20:15:53) Running from C:\Users\scott\Downloads Loaded Profiles: scott Platform: Microsoft Windows 10 Home Version 20H2 19042.1415 (X64) Language: English (United States) Default browser: Chrome Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Adobe Systems Incorporated -> ) C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe (Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe (Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2Toast.exe (Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <13> (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxCUIService.exe (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxEM.exe (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxext.exe (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHDCPSvc.exe (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHeciSvc.exe (Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (LENOVO -> ) C:\Program Files\Lenovo\LenovoUtility\utility.exe (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.CompanionApp.exe <3> (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost86\Lenovo.Modern.ImController.PluginHost.Device.exe (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe (LENOVO -> Lenovo(beijing) Limited) C:\Program Files\Lenovo\Nerve Center\bin\x64\HotkeyMonitor.exe (LENOVO -> Lenovo(beijing) Limited) C:\Program Files\Lenovo\Nerve Center\bin\x64\LenovoNerveCenterTray.exe (LENOVO -> Lenovo(beijing) Limited) C:\Program Files\Lenovo\Nerve Center\bin\x64\LenovoNerveCenterUpdateAgent.exe (LENOVO -> Lenovo(beijing) Limited) C:\Program Files\Lenovo\Nerve Center\bin\x64\PluginLoaderSvc.exe (LENOVO -> Lenovo(beijing) Limited) C:\Program Files\Lenovo\Nerve Center\bin\x86\GameRecorderSVC.exe (LENOVO -> Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2110.13603.0_x64__8wekyb3d8bbwe\Cortana.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2110.13603.0_x64__8wekyb3d8bbwe\Win32Bridge.Server.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <3> (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (SweetLabs Inc. -> SweetLabs, Inc) C:\Users\scott\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corp. -> Valve Corporation) D:\Steam Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7> (Valve Corp. -> Valve Corporation) D:\Steam Games\Steam\steam.exe (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NerveCenterTray] => C:\Program Files\Lenovo\Nerve Center\bin\x64\LenovoNerveCenterTray.exe [245088 2017-04-28] (LENOVO -> Lenovo(beijing) Limited) HKLM\...\Run: [LenovoUtility] => C:\Program Files\Lenovo\LenovoUtility\utility.exe [791848 2017-03-09] (LENOVO -> ) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16779768 2016-12-22] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1478144 2016-12-22] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1478144 2016-12-22] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1478144 2016-12-22] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [323056 2015-11-04] (Intel® Rapid Storage Technology -> Intel Corporation) HKLM\...\Run: [DAX2_APP] => C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe [829632 2016-06-24] (Dolby Laboratories, Inc. -> ) HKLM-x32\...\Run: [Adobe Photo Downloader] => C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\apdproxy.exe [67488 2007-09-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM-x32\...\Run: [WDDiscovery] => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Discovery.exe [81379600 2021-12-27] (Western Digital Technologies, Inc. -> Western Digital Corporation) HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\Run: [Discord] => C:\Users\scott\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub) HKLM\...\Windows x64\Print Processors\BJ Print Processor4: C:\Windows\System32\spool\prtprocs\x64\CNBPP4.DLL [84992 2011-08-30] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\BJ Language Monitor4: C:\Windows\system32\CNBLM4.DLL [267776 2011-08-30] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\97.0.4692.71\Installer\chrmstp.exe [2022-01-06] (Google LLC -> Google LLC) ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0316DD02-0788-46A3-B31D-D268AA016796} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\c983d090-49d2-4d7b-b68c-da049919be80 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {03405A93-69CC-432A-819B-C994CD11EEA2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-26] (Google Inc -> Google Inc.) Task: {0FCD2477-D645-4A26-9C66-6FBB862E7E54} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\dd88ca7d-1204-4101-acf5-b5ae5e854747 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {39CDEF37-7D8A-4E7B-8964-CA932EBB9AE5} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [1542080 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) Task: {40DE693C-8CFD-4CAC-8980-2BB8B1532DE4} - System32\Tasks\App Explorer => C:\Users\scott\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [7744560 2021-01-19] (SweetLabs Inc. -> SweetLabs, Inc) <==== ATTENTION Task: {44EF4A33-40A1-4267-9A66-1E83E8656E33} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\ad28dbd8-94e7-4179-8ea6-2a16996351d8 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {4E01D4EE-C295-472D-8C91-FF25F9AF74C6} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [728000 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) Task: {4EA7A415-93B1-4D9C-8A29-1B1BECB0E909} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log Task: {58895498-3B9B-4802-9021-58372A7F37A8} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => "%windir%\system32\sc.exe" START ImControllerService Task: {66318254-D66D-4652-86E7-C0D94986EE08} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [960448 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) Task: {70FFF1DF-0DBA-4C94-99A9-C0DF052F99D1} - System32\Tasks\Microsoft\Windows\Setup\EOSNotify => C:\WINDOWS\system32\EOSNotify.exe (No File) Task: {75A437C2-FB70-4356-8EF3-B5A0C78539EF} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [108872 2021-12-18] (Microsoft Corporation -> Microsoft Corporation) Task: {77E1CB8F-8FE0-4C1A-B440-D52FAE80C047} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [436160 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) Task: {7D1B2B7E-FFB6-4893-9CA1-99F466036754} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32 Task: {7FABF0B7-BC09-49B6-9896-DE0A10ED887C} - System32\Tasks\Lenovo\BatteryGauge\BatteryGaugeMaintenance => C:\ProgramData\Lenovo\ImController\Plugins\LenovoBatteryGaugePackage\x64\BGHelper.exe [145480 2021-09-09] (Lenovo -> Lenovo Group Ltd.) Task: {867DE49F-DC09-4079-B91D-A1604FAD8131} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\b3e62256-cc6b-4b96-835d-821ec281b063 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {8CBB3840-CF5D-4699-A8F3-6DAF2B51BBAA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-26] (Google Inc -> Google Inc.) Task: {A5D5D761-F453-4A1D-A3F8-E215695D3C70} - System32\Tasks\Nvbackend_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (No File) Task: {B06EB3BB-EF4C-45D2-AF49-F40B58E4DCEA} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22797704 2021-12-10] (Microsoft Corporation -> Microsoft Corporation) Task: {B1E1D06C-AF40-4BE7-AEDA-CD7EB9FEFDFE} - System32\Tasks\NerveCenterUpdate => C:\Program Files\Lenovo\Nerve Center\bin\x64\LenovoNerveCenterUpdateAgent.exe [744800 2017-04-28] (LENOVO -> Lenovo(beijing) Limited) Task: {BD893A82-480B-423E-BE60-F42F446B7C8F} - System32\Tasks\WD Discovery Service Task scott => C:\Program Files (x86)\Western Digital\Discovery\Current\Service\WDDiscoveryService.exe [78608 2021-12-27] (Western Digital Technologies, Inc. -> ) Task: {BE905044-A82A-4869-8BE3-6696AB9F23EB} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [655296 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) Task: {CA29313F-D0F5-4F99-A316-6BFF7C27D621} - System32\Tasks\Lenovo\Lenovo Settings Power => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor Task: {CEF656B0-8B38-44E4-AAA3-FBFA364A2B5E} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [728000 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) Task: {D2E9298C-C0CA-4CE6-A76B-5DD5144BD5BB} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22797704 2021-12-10] (Microsoft Corporation -> Microsoft Corporation) Task: {DB06F123-BE8B-46B0-A1C2-A31839917A66} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe [63728 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {E256BDCD-E19B-435E-9297-D81244D62A3A} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\9d14f0f5-2fca-4e63-bf39-347fb1fd24b1 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {E3EB9A8C-38D3-4EE3-84DE-B5017822D94F} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [108872 2021-12-18] (Microsoft Corporation -> Microsoft Corporation) Task: {EB9E0C1E-23C5-4083-81B0-A7039C345E0B} - System32\Tasks\WD Device Agent Task scott => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Device Agent.exe [723728 2021-12-27] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) Task: {FC35D24A-2F66-4E75-9B09-570AA3EA9889} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [655296 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.63 Tcpip\..\Interfaces\{b675f143-5303-45d5-9d76-55b176ae069d}: [DhcpNameServer] 150.204.1.2 Tcpip\..\Interfaces\{cc2b293d-37dd-49a3-ba83-23d46f9c1139}: [DhcpNameServer] 209.18.47.61 209.18.47.63 Edge: ======= DownloadDir: C:\Users\scott\Downloads Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found] Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found] Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found] Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found] Edge Profile: C:\Users\scott\AppData\Local\Microsoft\Edge\User Data\Default [2022-01-05] FireFox: ======== FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-10-31] (Microsoft Corporation -> Microsoft Corporation) Chrome: ======= CHR Profile: C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default [2022-01-07] CHR StartupUrls: Default -> "hxxp://homepage-web.com/?s=toshibaupd&m=start" CHR NewTab: Default -> Active:"chrome-extension://nadklbnikchkjjnlmnomcbdppegnppkk/tab10.html" CHR Extension: (Slides) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-11-26] CHR Extension: (Docs) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-11-26] CHR Extension: (Google Drive) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-24] CHR Extension: (YouTube) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-11-26] CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2021-11-24] CHR Extension: (Tampermonkey) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2021-05-23] CHR Extension: (Gloss dark) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\edfjafcniegodjnlgfgacgkbbmjhgmfd [2022-01-05] CHR Extension: (Sheets) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-11-26] CHR Extension: (Night Mode Pro) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbilbeoogenjmnabenfjfoockmpfnjoh [2021-07-19] CHR Extension: (Google Docs Offline) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-11-30] CHR Extension: (Dabi Wallpaper HD Custom New Tab) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\nadklbnikchkjjnlmnomcbdppegnppkk [2022-01-05] CHR Extension: (Chrome Web Store Payments) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-28] CHR Extension: (Gmail) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22] CHR Extension: (Settings) - C:\Users\scott\AppData\Local [2022-01-07] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeActiveFileMonitor6.0; C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [124832 2007-09-11] (Adobe Systems Incorporated -> ) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12129128 2021-12-10] (Microsoft Corporation -> Microsoft Corporation) R2 DAX2API; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [163336 2016-09-19] (Dolby Laboratories, Inc. -> ) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811120 2020-03-15] (EasyAntiCheat Oy -> Epic Games, Inc) S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2018-11-27] (Macrovision Europe Ltd.) [File not signed] R2 GameRecorderSVC; C:\Program Files\Lenovo\Nerve Center\bin\x86\GameRecorderSVC.exe [392032 2017-04-28] (LENOVO -> Lenovo(beijing) Limited) R2 ImControllerService; C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7901368 2022-01-05] (Malwarebytes Inc -> Malwarebytes) R2 PluginLoaderSvc; C:\Program Files\Lenovo\Nerve Center\bin\x64\PluginLoaderSvc.exe [966496 2017-04-28] (LENOVO -> Lenovo(beijing) Limited) S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [2017072 2021-12-20] (Rockstar Games, Inc. -> Rockstar Games) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [528160 2018-06-04] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\NisSrv.exe [2876152 2021-12-15] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MsMpEng.exe [128360 2021-12-15] (Microsoft Windows Publisher -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 BHTPCRDR; C:\WINDOWS\System32\drivers\bhtpcrdr.sys [173432 2016-08-10] (BayHub Technology Inc. -> BayHubTech/O2Micro) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed] S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [160176 2022-01-05] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) R2 FBNetFilter; C:\Windows\system32\Drivers\FBNetFlt.sys [46576 2017-04-28] (Lenovo (Beijing) Co., Ltd. -> Lenovo(beijing) Limited) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [210352 2022-01-05] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2022-01-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [193448 2022-01-06] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [69040 2022-01-06] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2022-01-05] (Malwarebytes Inc -> Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [149424 2022-01-06] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2021-12-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [435432 2021-12-15] (Microsoft Windows -> Microsoft Corporation) R1 wdfsconnect2017; C:\WINDOWS\system32\drivers\wdfsconnect2017.sys [468112 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86248 2021-12-15] (Microsoft Windows -> Microsoft Corporation) R3 wdvpnpbus; C:\WINDOWS\System32\drivers\wdvpnpbus.sys [20624 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2022-01-07 20:15 - 2022-01-07 20:16 - 000027544 ____C C:\Users\scott\Downloads\FRST.txt 2022-01-07 19:04 - 2022-01-07 19:04 - 000000000 ___DC C:\Users\scott\AppData\LocalLow\IGDump 2022-01-06 11:05 - 2022-01-06 11:05 - 000193448 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2022-01-06 11:05 - 2022-01-06 11:05 - 000149424 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2022-01-06 11:05 - 2022-01-06 11:05 - 000069040 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2022-01-05 16:25 - 2022-01-07 20:16 - 000000000 ___DC C:\FRST 2022-01-05 16:19 - 2022-01-05 16:19 - 002311168 ____C (Farbar) C:\Users\scott\Downloads\FRST64.exe 2022-01-05 15:47 - 2022-01-05 15:47 - 000000000 ___DC C:\AdwCleaner 2022-01-05 11:07 - 2022-01-05 11:07 - 000265926 _____ C:\WINDOWS\ntbtlog.txt 2022-01-05 11:07 - 2022-01-05 11:07 - 000000214 ____C C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job 2022-01-05 09:25 - 2022-01-05 09:25 - 000000000 ____D C:\Users\scott\AppData\Local\mbam 2022-01-05 09:24 - 2022-01-05 11:11 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2022-01-05 09:24 - 2022-01-05 11:07 - 000210352 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys 2022-01-05 09:24 - 2022-01-05 09:24 - 000160176 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 2022-01-05 09:24 - 2022-01-05 09:24 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys 2022-01-05 09:24 - 2022-01-05 09:24 - 000002040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk 2022-01-05 09:24 - 2022-01-05 09:24 - 000002028 ____C C:\Users\Public\Desktop\Malwarebytes.lnk 2022-01-05 09:24 - 2022-01-05 09:24 - 000000000 ____D C:\ProgramData\Malwarebytes 2022-01-05 09:24 - 2022-01-05 09:24 - 000000000 ____D C:\Program Files\Malwarebytes 2022-01-05 07:31 - 2022-01-06 11:04 - 097517568 _____ C:\WINDOWS\system32\config\SOFTWARE 2022-01-05 07:27 - 2022-01-05 07:31 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware 2022-01-05 04:49 - 2022-01-05 04:49 - 000000000 ____D C:\Users\scott\AppData\Local\GUI 2022-01-05 04:49 - 2022-01-05 04:49 - 000000000 ____D C:\ProgramData\SecuritySuite 2022-01-04 13:31 - 2022-01-04 13:31 - 000000000 ____D C:\Users\scott\AppData\Local\Chess2 2022-01-04 13:29 - 2022-01-04 13:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Chess Ultra 2022-01-04 12:53 - 2022-01-04 12:53 - 000000000 ____D C:\Users\scott\AppData\Local\chrome 2021-12-27 19:36 - 2021-12-27 19:36 - 000003172 _____ C:\WINDOWS\system32\Tasks\WD Device Agent Task scott 2021-12-18 01:27 - 2021-12-18 01:27 - 000000000 ____D C:\WINDOWS\SystemTemp 2021-12-18 01:25 - 2021-12-18 01:25 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe 2021-12-18 01:25 - 2021-12-18 01:25 - 000011979 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2021-12-18 01:24 - 2021-12-18 01:24 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe 2021-12-18 01:24 - 2021-12-18 01:24 - 000162816 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe 2021-12-18 01:19 - 2021-12-18 01:19 - 000000000 __HDC C:\$WinREAgent ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2022-01-07 20:10 - 2018-11-26 16:18 - 000000000 ___DC C:\Users\scott\AppData\Local\Host App Service 2022-01-07 19:31 - 2018-11-26 16:58 - 000000000 ___DC C:\Program Files (x86)\Google 2022-01-07 19:18 - 2019-12-07 04:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2022-01-07 13:53 - 2021-03-14 18:25 - 000004168 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{441EDC59-0660-4121-9195-856D71242991} 2022-01-07 13:53 - 2017-03-09 09:49 - 000000000 ___DC C:\ProgramData\NVIDIA 2022-01-07 13:50 - 2018-11-26 16:35 - 000000000 _SHDC C:\Users\scott\IntelGraphicsProfiles 2022-01-07 11:37 - 2021-03-14 18:18 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2022-01-07 08:27 - 2018-11-26 19:07 - 000000000 ___DC C:\Users\scott\AppData\Roaming\vlc 2022-01-06 11:12 - 2021-03-14 19:23 - 000842414 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2022-01-06 11:12 - 2019-12-07 04:13 - 000000000 ____D C:\WINDOWS\INF 2022-01-06 11:05 - 2021-03-14 18:25 - 000000006 ___HC C:\WINDOWS\Tasks\SA.DAT 2022-01-06 11:05 - 2021-03-14 18:18 - 000008192 ___SH C:\DumpStack.log.tmp 2022-01-06 11:05 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ServiceState 2022-01-06 11:04 - 2019-12-07 04:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2022-01-06 06:30 - 2018-11-27 05:11 - 000000000 ___DC C:\Users\scott\AppData\Roaming\discord 2022-01-06 06:24 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2022-01-06 05:38 - 2018-11-27 05:11 - 000000000 ___DC C:\Users\scott\AppData\Local\Discord 2022-01-06 03:16 - 2018-11-26 16:58 - 000002308 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2022-01-05 13:51 - 2018-11-26 21:55 - 000000000 ___DC C:\Users\scott\AppData\Local\D3DSCache 2022-01-05 13:19 - 2019-12-07 04:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2022-01-05 12:49 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2022-01-05 10:05 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2022-01-05 09:25 - 2018-11-30 01:32 - 000000000 ___DC C:\Users\scott\AppData\Local\CrashDumps 2022-01-05 04:17 - 2019-12-07 04:14 - 000000000 ___HD C:\Program Files\WindowsApps 2022-01-05 04:08 - 2021-11-14 13:50 - 000000000 ___DC C:\Users\scott\AppData\LocalLow\uTorrent 2022-01-05 04:08 - 2019-04-13 02:55 - 000000000 ___DC C:\Users\scott\AppData\Local\BitTorrentHelper 2022-01-05 04:08 - 2018-11-27 00:58 - 000000000 ___DC C:\Users\scott\AppData\Roaming\uTorrent 2022-01-04 13:31 - 2019-01-05 23:35 - 000000000 ___DC C:\Users\scott\AppData\Local\UnrealEngine 2021-12-28 17:07 - 2018-11-29 15:38 - 000000000 ___DC C:\Users\scott\AppData\Roaming\WD Discovery 2021-12-28 17:07 - 2018-11-29 15:38 - 000000000 ___DC C:\Users\scott\.wdc 2021-12-27 23:05 - 2021-03-14 18:18 - 001338920 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2021-12-27 19:37 - 2018-11-29 15:39 - 000000000 ___DC C:\Program Files\WD Desktop App 2021-12-27 19:37 - 2017-03-09 09:48 - 000000000 ___DC C:\ProgramData\Package Cache 2021-12-27 19:36 - 2021-03-14 18:25 - 000003236 _____ C:\WINDOWS\system32\Tasks\WD Discovery Service Task scott 2021-12-27 19:36 - 2018-11-29 15:39 - 000000000 ___DC C:\Program Files (x86)\Western Digital 2021-12-27 19:36 - 2018-11-26 16:36 - 000000000 __RDC C:\Users\scott\OneDrive 2021-12-27 00:57 - 2021-03-14 09:50 - 000000000 ____D C:\Users\scott 2021-12-20 17:04 - 2019-08-30 05:36 - 000000000 ____D C:\Users\scott\AppData\Local\Rockstar Games 2021-12-20 17:01 - 2019-08-30 05:36 - 000000000 ____D C:\Program Files\Rockstar Games 2021-12-20 17:01 - 2019-08-30 05:36 - 000000000 ____D C:\Program Files (x86)\Rockstar Games 2021-12-20 10:09 - 2021-04-19 21:57 - 000000000 ____D C:\Users\scott\AppData\Local\T2GP Launcher 2021-12-19 04:14 - 2020-03-13 15:02 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2021-12-18 17:56 - 2017-03-09 08:27 - 000000000 ___DC C:\Program Files (x86)\Microsoft Office 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SystemResources 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\setup 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\et-EE 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\es-MX 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\Provisioning 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2021-12-16 16:44 - 2018-11-26 19:39 - 000000000 ___DC C:\WINDOWS\system32\MRT 2021-12-16 16:42 - 2018-11-26 19:39 - 137938848 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2021-12-15 19:49 - 2018-11-26 19:39 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2021-12-11 10:31 - 2021-03-24 19:52 - 000000000 ____D C:\WINDOWS\Minidump 2021-12-10 20:08 - 2021-04-26 03:47 - 000003386 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d719293b661bc7 2021-12-10 20:08 - 2021-03-14 18:25 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-12-2021 Ran by scott (07-01-2022 20:17:01) Running from C:\Users\scott\Downloads Microsoft Windows 10 Home Version 20H2 19042.1415 (X64) (2021-03-14 23:26:02) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= (If an entry is included in the fixlist, it will be removed.) Administrator (S-1-5-21-4096549371-2451222336-3956411163-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-4096549371-2451222336-3956411163-503 - Limited - Disabled) defaultuser0 (S-1-5-21-4096549371-2451222336-3956411163-1000 - Limited - Disabled) => C:\Users\defaultuser0 Guest (S-1-5-21-4096549371-2451222336-3956411163-501 - Limited - Disabled) scott (S-1-5-21-4096549371-2451222336-3956411163-1001 - Administrator - Enabled) => C:\Users\scott WDAGUtilityAccount (S-1-5-21-4096549371-2451222336-3956411163-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) [NarutoPlanet.ru] Bleach Heat The Soul 7 PC (HKLM-x32\...\[NarutoPlanet.ru] Bleach Heat The Soul 7 PC_is1) (Version: [NarutoPlanet.ru] Bleach Heat The Soul 7 PC - NarutoPlanet.ru) µTorrent (HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\uTorrent) (Version: 3.5.5.46096 - BitTorrent Inc.) 7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov) ACID Music Studio 10.0 (HKLM-x32\...\{0417C9E1-CBD4-11E3-A786-F04DA23A5C58}) (Version: 10.0.108 - Sony) Adobe Photoshop (HKLM-x32\...\Adobe Photoshop_is1) (Version: - www.g1wholesale.com) Adobe Photoshop Elements 6.0 (HKLM-x32\...\Adobe Photoshop Elements 6) (Version: 6.0 - Adobe Systems Inc.) BayHubTech Flash Memory Card Windows Driver (HKLM\...\{357682C3-2295-45C5-B7DD-8109E66656EC}) (Version: 3.4.00.30 - BayHub Technology LTD.) Hidden BayHubTech Flash Memory Card Windows Driver (HKLM-x32\...\InstallShield_{357682C3-2295-45C5-B7DD-8109E66656EC}) (Version: 3.4.00.30 - BayHub Technology LTD.) BCC 8 OFX 64Bit (HKLM\...\{6309B4F7-F571-44FB-A154-330BE4C57042}) (Version: 8.1.0301 - Boris FX, Inc.) CEP (Color Enable Package) v.9.2 (beta) (HKLM-x32\...\CEP - Colour Enable Packages_is1) (Version: 9.2 (beta) - Numenor, for ModTheSims2) Chess Ultra (HKLM-x32\...\Chess Ultra_is1) (Version: - ) Cities Skylines Campus (HKLM-x32\...\Cities Skylines Campus_is1) (Version: - ) Cities Skylines Modern City Center (HKLM-x32\...\Cities Skylines Modern City Center_is1) (Version: - ) Cities Skylines Sunset Harbor (HKLM-x32\...\Cities Skylines Sunset Harbor_is1) (Version: - ) Cities Skylines Train Stations (HKLM-x32\...\Cities Skylines Train Stations_is1) (Version: - ) Dead or Alive 6 (HKLM-x32\...\Dead or Alive 6_is1) (Version: - ) Discord (HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\Discord) (Version: 0.0.309 - Discord Inc.) Dolby Audio X2 Windows API SDK (HKLM\...\{AA950AA4-CD9B-4D81-B6C0-BFABB7A24261}) (Version: 0.7.5.65 - Dolby Laboratories, Inc.) Dolby Audio X2 Windows APP (HKLM\...\{D765CF7F-14F9-4C80-B06C-10E68F10EBCC}) (Version: 0.7.2.62 - Dolby Laboratories, Inc.) Dragon Ball FighterZ (HKLM-x32\...\Dragon Ball FighterZ_is1) (Version: - ) DVD Architect Studio 5.0 (HKLM-x32\...\{3822E74F-08F8-11E3-99EE-F04DA23A5C58}) (Version: 5.0.186 - Sony) EA Download Manager (HKLM-x32\...\EADM) (Version: 5.0.0.255 - Electronic Arts, Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 97.0.4692.71 - Google LLC) Intel® Chipset Device Software (HKLM-x32\...\{fb610cea-ba50-4d4b-a717-cf025419035c}) (Version: 10.1.1.13 - Intel® Corporation) Hidden Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1177 - Intel Corporation) Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 21.20.16.4526 - Intel Corporation) Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.0.1042 - Intel Corporation) Intel® Wireless Bluetooth® (HKLM-x32\...\{3920BCB0-23AA-4D0D-93E5-404692DAF9D2}) (Version: 19.00.1621.3340 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{bc883058-299e-461f-8e52-4f1dbb355f86}) (Version: 19.0.1 - Intel Corporation) iZotope Audio Enhancer (HKLM-x32\...\iZotope Audio Enhancer_is1) (Version: 1.00 - iZotope, Inc.) JUMP FORCE (HKLM-x32\...\JUMP FORCE_is1) (Version: - ) Jurassic World: Evolution (HKLM-x32\...\Jurassic World: Evolution_is1) (Version: - ) Just Cause 4 (HKLM-x32\...\{D1F33AFE-757B-4A27-9F96-D507177C3E40}_is1) (Version: - Avalanche Studios) Lenovo App Explorer (HKU\S-1-5-19\...\Host App Service) (Version: 0.271.1.400 - SweetLabs for Lenovo) <==== ATTENTION Lenovo App Explorer (HKU\S-1-5-20\...\Host App Service) (Version: 0.271.1.400 - SweetLabs for Lenovo) <==== ATTENTION Lenovo App Explorer (HKU\S-1-5-21-4096549371-2451222336-3956411163-1000\...\Host App Service) (Version: 0.273.2.941 - SweetLabs for Lenovo) <==== ATTENTION Lenovo App Explorer (HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\Host App Service) (Version: 0.273.4.227 - SweetLabs for Lenovo) <==== ATTENTION Lenovo Nerve Sense (HKLM\...\{DCB4DFB5-93CA-4BDD-9D08-CE880626B46E}_is1) (Version: 2.6.11.8 - Lenovo) Lenovo Settings - Power (HKLM-x32\...\{A6CFC34A-56EE-4AF5-8C49-995F59E6A160}) (Version: 2.00.000 - Lenovo) Lenovo System Interface Foundation Driver (HKLM\...\{C2E5CA37-C862-4A69-AC6D-24F450A20C16}) (Version: 1.1.17.1 - Lenovo) LenovoUtility (HKLM-x32\...\{6ADA7E88-8D16-4D0D-BC90-2B93AC5E56DA}) (Version: 3.0.0.4 - Lenovo) Hidden LenovoUtility (HKLM-x32\...\InstallShield_{6ADA7E88-8D16-4D0D-BC90-2B93AC5E56DA}) (Version: 3.0.0.4 - Lenovo) Malwarebytes version 4.5.0.152 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.0.152 - Malwarebytes) Malzbies Pinball Collection Ghouls (HKLM-x32\...\Malzbies Pinball Collection Ghouls_is1) (Version: - ) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 96.0.1054.62 - Microsoft Corporation) Microsoft Office Home and Student 2016 - en-us (HKLM\...\HomeStudentRetail - en-us) (Version: 16.0.14701.20262 - Microsoft Corporation) Microsoft Office Word 2007 (HKLM-x32\...\WORD) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{29B15818-E79F-4AB0-8938-9410C807AD76}) (Version: 2.84.0.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.28.29334 (HKLM-x32\...\{a9cfe9c7-e54f-46cd-9c5c-542ff8e3e8c4}) (Version: 14.28.29334.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29334 (HKLM-x32\...\{b2d0f752-adc5-496e-8f70-8669de01f746}) (Version: 14.28.29334.0 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Movie Studio Platinum 13.0 (64-bit) (HKLM\...\{402E168F-CC02-11E3-812F-F04DA23A5C58}) (Version: 13.0.932 - Sony) NARUTO SHIPPUDEN Ultimate Ninja STORM 4 Road to Boruto Next Generations (HKLM-x32\...\NARUTO SHIPPUDEN Ultimate Ninja STORM 4 Road to ~629813CA_is1) (Version: - ) NewBlue VideoFX for Sony Vegas MSPPS (HKLM\...\NewBlue VideoFX for Sony Vegas MSPPS) (Version: 2.0 - NewBlue) NewBlue VideoFX for Sony Vegas MSPPS (HKLM-x32\...\NewBlue VideoFX for Sony Vegas MSPPS) (Version: 2.0 - NewBlue) NVIDIA GeForce Experience 3.10.0.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.10.0.95 - NVIDIA Corporation) NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.14701.20262 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.14701.20248 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.14701.20262 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden OpenAL (HKLM-x32\...\OpenAL) (Version: - ) OpenIV (HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\OpenIV) (Version: 4.0.1.1452 - .black/OpenIV Team) PGA TOUR 2K21 (HKLM-x32\...\PGA TOUR 2K21_is1) (Version: - ) Pinball Arcade Season 1 to 7 Pro Packs (HKLM-x32\...\Pinball Arcade Season 1 to 7 Pro Packs_is1) (Version: - ) Pinball FX3 Williams Pinball Volume 5 (HKLM-x32\...\Pinball FX3 Williams Pinball Volume 5_is1) (Version: - ) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.9.422.2016 - Realtek) Revo Uninstaller 2.2.2 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.2.2 - VS Revo Group, Ltd.) Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.53.576 - Rockstar Games) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.0.9.3 - Rockstar Games) Saints Row - The Third (HKLM-x32\...\1430740694_is1) (Version: 2.0.0.4 - GOG.com) SanDisk Security (HKLM-x32\...\{189ff347-b978-4c66-88b6-30214ecb87a9}) (Version: 1.0.0.17 - Western Digital Technologies, Inc.) SanDisk Security (HKLM-x32\...\{3C6EE362-358C-41AB-8B54-0BBBE7DE837F}) (Version: 1.0.0.17 - Western Digital Technologies, Inc.) Hidden Sekiro Shadows Die Twice (HKLM-x32\...\Sekiro Shadows Die Twice_is1) (Version: - ) Sims 3 - Nude Censor Remover (HKLM-x32\...\xSIMS_Censor_Remover_TS3) (Version: - ) Sims 4 Studio (HKLM-x32\...\{870AA913-0774-4ED0-B144-BC2C0CBE4BA0}_is1) (Version: 3.1.3.3 - Sims 4 Studio) Sony Vocal Eraser (HKLM-x32\...\Sony Vocal Eraser_is1) (Version: 1.00 - iZotope, Inc.) Sound Forge Audio Studio 10.0 (HKLM-x32\...\{BC208D90-4643-11E3-987B-F04DA23A5C58}) (Version: 10.0.252 - Sony) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Street Fighter V Arcade Edition (HKLM-x32\...\Street Fighter V Arcade Edition_is1) (Version: - ) TEKKEN 7 Ultimate Edition (HKLM-x32\...\TEKKEN 7 Ultimate Edition_is1) (Version: - ) The Sims 4 v. 1.67.45.1020 (HKLM-x32\...\The Sims 4_is1) (Version: - ) The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts) The Sims™ 3 70s, 80s, & 90s Stuff (HKLM-x32\...\{E1868CAE-E3B9-4099-8C18-AA8944D336FD}) (Version: 17.0.77 - Electronic Arts) The Sims™ 3 Ambitions (HKLM-x32\...\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts) The Sims™ 3 Diesel Stuff (HKLM-x32\...\{1C9B6173-6DC9-4EEE-9EFC-6BA115CFBE43}) (Version: 14.0.48 - Electronic Arts) The Sims™ 3 Fast Lane Stuff (HKLM-x32\...\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}) (Version: 5.0.44 - Electronic Arts) The Sims™ 3 Generations (HKLM-x32\...\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts) The Sims™ 3 High-End Loft Stuff (HKLM-x32\...\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts) The Sims™ 3 Into the Future (HKLM-x32\...\{A0BBD6C7-B546-4048-B33A-F21F5C9F5B09}) (Version: 21.0.150 - Electronic Arts) The Sims™ 3 Island Paradise (HKLM-x32\...\{DB21639E-FE55-432C-BCA2-0C5249E3F79E}) (Version: 19.0.101 - Electronic Arts) The Sims™ 3 Katy Perry's Sweet Treats (HKLM-x32\...\{9B2506E3-9A3F-45B5-96BF-509CAD584650}) (Version: 13.0.62 - Electronic Arts) The Sims™ 3 Late Night (HKLM-x32\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts) The Sims™ 3 Master Suite Stuff (HKLM-x32\...\{08A25478-C5DD-4EA7-B168-3D687CA987FF}) (Version: 11.0.84 - Electronic Arts) The Sims™ 3 Movie Stuff (HKLM-x32\...\{D0087539-3C57-44E0-BEE7-D779D546CBE1}) (Version: 20.0.53 - Electronic Arts) The Sims™ 3 Outdoor Living Stuff (HKLM-x32\...\{117B6BF6-82C3-420C-B284-9247C8568E53}) (Version: 7.0.55 - Electronic Arts) The Sims™ 3 Pets (HKLM-x32\...\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts) The Sims™ 3 Seasons (HKLM-x32\...\{3DE92282-CB49-434F-81BF-94E5B380E889}) (Version: 16.0.136 - Electronic Arts) The Sims™ 3 Showtime (HKLM-x32\...\{3BBFD444-5FAB-49F6-98B1-A1954E831399}) (Version: 12.0.273 - Electronic Arts) The Sims™ 3 Supernatural (HKLM-x32\...\{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}) (Version: 15.0.135 - Electronic Arts) The Sims™ 3 Town Life Stuff (HKLM-x32\...\{7B11296A-F894-449C-8DF6-6AAAA7D4D118}) (Version: 9.0.73 - Electronic Arts) The Sims™ 3 University Life (HKLM-x32\...\{F26DE8EF-F2CF-40DC-8CDA-CC0D82D11B36}) (Version: 18.0.126 - Electronic Arts) The Sims™ 3 World Adventures (HKLM-x32\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts) Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{C99F4AFA-B32C-4063-865C-D7B5CC0A78FB}) (Version: 2.54.0.0 - Microsoft Corporation) UpdateAssistant (HKLM\...\{52C1DD03-104E-4AC6-9DC6-21D585721ED1}) (Version: 1.19.0.0 - Microsoft Corporation) Hidden Vegas Movie Studio HD 9.0 (HKLM-x32\...\{655CD886-3B90-4E4D-B314-92BDA9B08C86}) (Version: 9.0.30 - Sony) VLC media player (HKLM\...\VLC media player) (Version: 3.0.12 - VideoLAN) Vulkan Run Time Libraries 1.0.11.1 (HKLM\...\VulkanRT1.0.11.1) (Version: 1.0.11.1 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-3) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-4) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-5) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Watch Dogs Complete Edition MULTi19 - ElAmigos version 1.06.329 (HKLM-x32\...\{EC053F56-69AC-44BF-A227-F6CB1E35272D}_is1) (Version: 1.06.329 - UBISoft) Watch_Dogs 2 (HKLM-x32\...\Watch_Dogs 2_is1) (Version: - ) WD Desktop App 2.1.0.322 (HKLM-x32\...\{9478cae3-730b-4ffe-b22b-ae8b7787f5d5}) (Version: 2.1.0.322 - Western Digital Corporation) Hidden WD Desktop App 2.1.0.322 (x64) (HKLM\...\{CA7F7232-526E-41BD-971A-47BE28C18516}) (Version: 2.1.0.322 - Western Digital Corporation) Hidden WD Discovery (HKLM-x32\...\WDDiscovery) (Version: 4.3.336 - Western Digital Technologies, Inc.) WD SES Driver Setup (HKLM-x32\...\{924A274D-38B6-4930-8859-F3F51CFA8DDD}) (Version: 1.1.0.25 - Western Digital) Hidden WeMod (HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\WeMod) (Version: 7.1.16 - WeMod) Windows PC Health Check (HKLM\...\{B1E7D0FD-7CFE-4E0C-A5DA-0F676499DB91}) (Version: 3.2.2110.14001 - Microsoft Corporation) Packages: ========= BreeZip -> C:\Program Files\WindowsApps\3138AweZip.AweZip_1.4.8.0_x86__ffd303wmbhcjt [2021-08-17] (BreeZip) [MS Ad] Lenovo Settings -> C:\Program Files\WindowsApps\LenovoCorporation.LenovoSettings_3.177.0.0_x86__4642shxvsv8s2 [2021-11-16] (LENOVO INCORPORATED.) Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2112.10.0_x64__k1h2ywk1493x8 [2021-12-29] (LENOVO INC.) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-03-14] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-03-14] (Microsoft Corporation) [MS Ad] Microsoft Mahjong -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMahjong_4.1.11220.0_x64__8wekyb3d8bbwe [2021-12-07] (Microsoft Studios) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.11.12030.0_x64__8wekyb3d8bbwe [2021-12-11] (Microsoft Studios) [MS Ad] Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-08-08] (Microsoft Corporation) Real Chess Online -> C:\Program Files\WindowsApps\52833Alienforce.ChessFusionFree_3.25.0.0_x64__np5hvx4gj677g [2021-11-16] (Alienforce) Trio Office -> C:\Program Files\WindowsApps\64343GTDocStudio.OfficeDocOpener_3.2.24.0_x86__3h5nez1g3qt2c [2021-08-17] (GT Office PDF Studio) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-4096549371-2451222336-3956411163-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\scott\AppData\Local\Microsoft\OneDrive\18.192.0920.0015\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-4096549371-2451222336-3956411163-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\scott\AppData\Local\Microsoft\OneDrive\18.192.0920.0015\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-4096549371-2451222336-3956411163-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\scott\AppData\Local\Microsoft\OneDrive\18.192.0920.0015\amd64\FileSyncShell64.dll => No File SSODL: WDFSMountNotificator-wdfsconnect2017 - {F91D11A8-8E29-408A-A9ED-D1B4CE29ECDF} - C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed] SSODL-x32: WDFSMountNotificator-wdfsconnect2017 - {F91D11A8-8E29-408A-A9ED-D1B4CE29ECDF} - C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed] ShellServiceObjects: Virtual Storage Mount Notification -> {F91D11A8-8E29-408A-A9ED-D1B4CE29ECDF} => C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed] ShellServiceObjects-x32: Virtual Storage Mount Notification -> {F91D11A8-8E29-408A-A9ED-D1B4CE29ECDF} => C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed] ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay01] -> {4F8A325E-9DAF-44B8-A825-1A14DFA0FA78} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay02] -> {0176BDDE-B59A-4A1E-808B-CAD461415CCA} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay03] -> {B65909D1-57AF-41F5-AB94-BEB733F62B35} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay04] -> {C6C2397D-8238-4332-8935-86C39C7C165F} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay05] -> {E7B3BCF9-0386-4B5F-AE6A-91B9F1423973} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay06] -> {564EA121-D9DA-485D-82C2-C2ED7BFCCEAD} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers1: [WDDesktopContextMenu] -> {f351d8c9-ff13-3519-92fa-763cce46b27b} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-01-05] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers4: [WDDesktopContextMenu] -> {f351d8c9-ff13-3519-92fa-763cce46b27b} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxDTCM.dll [2018-05-07] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-01-15] (NVIDIA Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-01-05] (Malwarebytes Corporation -> Malwarebytes) ==================== Codecs (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Drivers32: [vidc.VP60] => C:\WINDOWS\SysWOW64\vp6vfw.dll [447752 2014-09-16] (Electronic Arts -> On2.com) HKLM\...\Drivers32: [vidc.VP61] => C:\WINDOWS\SysWOW64\vp6vfw.dll [447752 2014-09-16] (Electronic Arts -> On2.com) ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= 2021-11-20 05:34 - 2021-10-05 20:30 - 126961152 _____ () [File not signed] D:\Steam Games\Steam\bin\cef\cef.win7x64\libcef.dll 2021-11-20 05:34 - 2021-10-05 20:30 - 000384000 _____ () [File not signed] D:\Steam Games\Steam\bin\cef\cef.win7x64\libegl.dll 2021-11-20 05:34 - 2021-10-05 20:30 - 008006656 _____ () [File not signed] D:\Steam Games\Steam\bin\cef\cef.win7x64\libglesv2.dll 2020-01-19 07:47 - 2019-02-21 11:00 - 000078336 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll 2020-04-17 12:19 - 2020-04-17 12:19 - 000000000 ___CL (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\AppVIsvSubsystems32.dll 2020-04-17 12:19 - 2020-04-17 12:19 - 000000000 ___CL (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\c2r32.dll 2021-11-20 05:34 - 2021-10-05 20:30 - 000983552 _____ (The Chromium Authors) [File not signed] D:\Steam Games\Steam\bin\cef\cef.win7x64\chrome_elf.dll 2018-11-29 15:39 - 2017-11-10 12:51 - 000180224 _____ (Western Digital Technologies, Inc.) [File not signed] C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ========== HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17swin10.msn.com/?pc=LSJE HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.toshiba.com SearchScopes: HKU\S-1-5-21-4096549371-2451222336-3956411163-1001 -> DefaultScope {BBBC899D-85F0-447B-89ED-F68FBA315D38} URL = SearchScopes: HKU\S-1-5-21-4096549371-2451222336-3956411163-1001 -> {BBBC899D-85F0-447B-89ED-F68FBA315D38} URL = BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2021-10-31] (Microsoft Corporation -> Microsoft Corporation) BHO: No Name -> {F91D11A8-8E29-408A-A9ED-D1B4CE29ECDF}' -> No File BHO-x32: No Name -> {F91D11A8-8E29-408A-A9ED-D1B4CE29ECDF}' -> No File Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-31] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-31] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-31] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-31] (Microsoft Corporation -> Microsoft Corporation) ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2016-07-16 06:47 - 2022-01-05 13:19 - 000000824 ____C C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-4096549371-2451222336-3956411163-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\Control Panel\Desktop\\Wallpaper -> E:\Anime and Yaoi\dabi (26).jpeg DNS Servers: 209.18.47.61 - 209.18.47.63 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) HKLM\...\StartupApproved\Run: => "WinZip PreLoader" HKLM\...\StartupApproved\Run32: => "Adobe Photo Downloader" HKLM\...\StartupApproved\Run32: => "WDDiscovery" HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\StartupApproved\Run: => "OneDriveSetup" HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\StartupApproved\Run: => "uTorrent" HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\StartupApproved\Run: => "Discord" HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\StartupApproved\Run: => "ShutterflyStudio" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [UDP Query User{4B0469CC-C1DB-4073-AE30-18D56FD2983B}E:\simcasino.v15.02.2021\simcasino\simcasino.exe] => (Allow) E:\simcasino.v15.02.2021\simcasino\simcasino.exe => No File FirewallRules: [TCP Query User{8D26ABB6-5C87-4273-9362-13F86D515553}E:\simcasino.v15.02.2021\simcasino\simcasino.exe] => (Allow) E:\simcasino.v15.02.2021\simcasino\simcasino.exe => No File FirewallRules: [{2BA8F4F5-08F8-4AA0-AF22-95DF989BBFCB}] => (Allow) E:\Pinball Games\Pinball.Parlor\PP.exe => No File FirewallRules: [{95002BEA-BA72-4726-90CC-6502BF6225D2}] => (Allow) E:\Pinball Games\Pinball.Parlor\PP.exe => No File FirewallRules: [{ED631F4E-09FC-4225-BC45-144386BCC66A}] => (Allow) E:\Pinball Games\Pinball.Parlor\PP.exe => No File FirewallRules: [{35094D17-58A1-432B-AF94-47034D9175E3}] => (Allow) E:\Pinball Games\Pinball.Parlor\PP.exe => No File FirewallRules: [{578CED8D-A937-4408-85B1-057D819CDDE9}] => (Allow) D:\Steam Games\Steam\steamapps\common\Zaccaria Pinball\ZaccariaPinball.exe () [File not signed] FirewallRules: [{6291D1CC-6C69-4971-80F3-D6F51869054B}] => (Allow) D:\Steam Games\Steam\steamapps\common\Zaccaria Pinball\ZaccariaPinball.exe () [File not signed] FirewallRules: [UDP Query User{02A6B425-F016-4A10-9DD3-EBD3447F85D8}E:\games\the sims 4\game\bin_le\ts4.exe] => (Block) E:\games\the sims 4\game\bin_le\ts4.exe (Electronic Arts Inc.) [File not signed] FirewallRules: [TCP Query User{604C14CD-E578-4F53-A635-3F9369D476E2}E:\games\the sims 4\game\bin_le\ts4.exe] => (Block) E:\games\the sims 4\game\bin_le\ts4.exe (Electronic Arts Inc.) [File not signed] FirewallRules: [{6B831CFE-226F-4BC0-8799-C6960ED033BA}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe => No File FirewallRules: [{B4135EB5-8A74-4C8A-9E8C-2D88FEA394C8}] => (Allow) D:\Steam Games\Steam\steamapps\common\L.A.Noire\LANLauncher.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{8CC87BE0-A341-498A-99DC-1005713C94CD}] => (Allow) D:\Steam Games\Steam\steamapps\common\L.A.Noire\LANLauncher.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{0D49990D-62BD-4859-A700-3469F2224838}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia II Definitive Edition\pc\Mafia2Launcher\Launcher.exe (2K Games) [File not signed] FirewallRules: [{0037A64F-6418-4B28-99AA-4CEC6632E396}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia II Definitive Edition\pc\Mafia2Launcher\Launcher.exe (2K Games) [File not signed] FirewallRules: [{52177A74-62B9-4CD0-8860-620E281BB1CA}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia Definitive Edition\launcher.exe (2K Games) [File not signed] FirewallRules: [{EAB8B3F6-5224-4110-B901-8BAE79D593DF}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia Definitive Edition\launcher.exe (2K Games) [File not signed] FirewallRules: [UDP Query User{9DBA000A-E130-4AFE-820E-97F92B406617}E:\games\the sims 4\game\bin\ts4_x64.exe] => (Allow) E:\games\the sims 4\game\bin\ts4_x64.exe (Electronic Arts Inc.) [File not signed] FirewallRules: [TCP Query User{2093F737-F84F-4B39-BF95-D6BDCEDAEFBC}E:\games\the sims 4\game\bin\ts4_x64.exe] => (Allow) E:\games\the sims 4\game\bin\ts4_x64.exe (Electronic Arts Inc.) [File not signed] FirewallRules: [{6D355FBE-AE23-4E76-9BE1-415F370A40AF}] => (Allow) D:\Steam Games\Steam\steamapps\common\My Hero Ones Justice 2\HeroGame\Binaries\Win64\MHOJ2.exe (BNEI) [File not signed] FirewallRules: [{05A799FE-E82A-42F7-B1CD-C27EB1F737EB}] => (Allow) D:\Steam Games\Steam\steamapps\common\My Hero Ones Justice 2\HeroGame\Binaries\Win64\MHOJ2.exe (BNEI) [File not signed] FirewallRules: [UDP Query User{23F24458-48C5-4E43-9A3A-5EB7AA8A6CB2}E:\games\the sims 4 eco lifestyle\game\bin\ts4_x64.exe] => (Allow) E:\games\the sims 4 eco lifestyle\game\bin\ts4_x64.exe => No File FirewallRules: [TCP Query User{407E0FBD-26EC-4C2D-910E-9D2676EAC39A}E:\games\the sims 4 eco lifestyle\game\bin\ts4_x64.exe] => (Allow) E:\games\the sims 4 eco lifestyle\game\bin\ts4_x64.exe => No File FirewallRules: [UDP Query User{76093F34-BB7F-4D4F-9C8D-978A39E22122}E:\saints row 3 - game\saints row 3\saintsrowthethird_dx11.exe] => (Allow) E:\saints row 3 - game\saints row 3\saintsrowthethird_dx11.exe => No File FirewallRules: [TCP Query User{573B1A30-35C8-4FB9-A7C5-15E296CD908E}E:\saints row 3 - game\saints row 3\saintsrowthethird_dx11.exe] => (Allow) E:\saints row 3 - game\saints row 3\saintsrowthethird_dx11.exe => No File FirewallRules: [UDP Query User{E36F3718-5ABA-4F09-9A84-622B97661E9A}E:\saints row 2 - game\saints row 2\sr2_pc.exe] => (Allow) E:\saints row 2 - game\saints row 2\sr2_pc.exe => No File FirewallRules: [TCP Query User{492D992A-B834-49D1-A22F-B047C113916F}E:\saints row 2 - game\saints row 2\sr2_pc.exe] => (Allow) E:\saints row 2 - game\saints row 2\sr2_pc.exe => No File FirewallRules: [{FA3B11CD-BDE4-474D-8BBC-A864BDF57DC6}] => (Allow) D:\Steam Games\Steam\steamapps\common\ONE PUNCH MAN A HERO NOBODY KNOWS\ONE PUNCH MAN A HERO NOBODY KNOWS.exe (EasyAntiCheat Oy -> Epic Games, Inc) FirewallRules: [{770ABD07-908B-4038-9E2B-43AA5247C36A}] => (Allow) D:\Steam Games\Steam\steamapps\common\ONE PUNCH MAN A HERO NOBODY KNOWS\ONE PUNCH MAN A HERO NOBODY KNOWS.exe (EasyAntiCheat Oy -> Epic Games, Inc) FirewallRules: [UDP Query User{075CE593-D950-425E-83C3-C80B941C0542}E:\jump force\jump force\jump_force\binaries\win64\jump_force-win64-shipping.exe] => (Allow) E:\jump force\jump force\jump_force\binaries\win64\jump_force-win64-shipping.exe => No File FirewallRules: [TCP Query User{65119092-D215-4C52-A477-96859EE6834B}E:\jump force\jump force\jump_force\binaries\win64\jump_force-win64-shipping.exe] => (Allow) E:\jump force\jump force\jump_force\binaries\win64\jump_force-win64-shipping.exe => No File FirewallRules: [UDP Query User{225B6674-4EF9-452A-A013-DB1632F8FF70}E:\games\the sims 4 discover university\game\bin\ts4_x64.exe] => (Allow) E:\games\the sims 4 discover university\game\bin\ts4_x64.exe => No File FirewallRules: [TCP Query User{5AEA2B36-DBE7-4F8B-BCAB-FE6119D1A79D}E:\games\the sims 4 discover university\game\bin\ts4_x64.exe] => (Allow) E:\games\the sims 4 discover university\game\bin\ts4_x64.exe => No File FirewallRules: [UDP Query User{26A3908F-600E-4728-B212-033DFFE88CC4}E:\the sims 4 island living\game\bin\ts4_x64.exe] => (Allow) E:\the sims 4 island living\game\bin\ts4_x64.exe => No File FirewallRules: [TCP Query User{24BAE737-62B0-4D31-9DFB-F2D08C329463}E:\the sims 4 island living\game\bin\ts4_x64.exe] => (Allow) E:\the sims 4 island living\game\bin\ts4_x64.exe => No File FirewallRules: [{54D3C906-730A-4545-BE80-5D37F4EF3442}] => (Allow) D:\Steam Games\Steam\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{DE8E5125-E4FF-4B84-A9C7-57694D8C872B}] => (Allow) D:\Steam Games\Steam\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [UDP Query User{406E7D4C-5313-4DC8-9788-8C5326B8574A}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN) FirewallRules: [TCP Query User{BE965456-0BA7-49A3-AF32-CA675905D022}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN) FirewallRules: [{8C765058-EBDC-49C7-AFB3-9A9553C97CB0}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia III\launcher.exe (2K Games) [File not signed] FirewallRules: [{4F6ECDF4-A6A3-4A45-83C0-D18FE400D7C7}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia III\launcher.exe (2K Games) [File not signed] FirewallRules: [UDP Query User{92AB6788-F44B-43E7-A6D7-6A207EE5E7F2}D:\steam games\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam games\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [TCP Query User{78BEB908-31AD-40B8-B653-C42436652223}D:\steam games\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam games\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{886BA011-EE86-44DF-8738-8D6AC580EB09}] => (Allow) D:\Steam Games\Steam\steamapps\common\Planet Coaster\PlanetCoaster.exe (Frontier Developments) [File not signed] FirewallRules: [{F516BCD2-EF46-48D4-A27C-D0C977AE8E21}] => (Allow) D:\Steam Games\Steam\steamapps\common\Planet Coaster\PlanetCoaster.exe (Frontier Developments) [File not signed] FirewallRules: [{781E1F98-B0F2-4D7F-8A3D-051798C394C8}] => (Allow) D:\Steam Games\Steam\steamapps\common\Yu-Gi-Oh! Duel Links\dlpc.exe () [File not signed] FirewallRules: [{2BB30453-D433-4B87-9B94-3B7456347913}] => (Allow) D:\Steam Games\Steam\steamapps\common\Yu-Gi-Oh! Duel Links\dlpc.exe () [File not signed] FirewallRules: [{AE29D15C-8257-4C4E-9774-2BF93DCBBA28}] => (Allow) D:\Steam Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{6BAE6C46-018F-42DB-A00E-48672377063D}] => (Allow) D:\Steam Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{573DFEFD-8D8C-4804-9C5C-D44AAE79007C}] => (Allow) D:\Steam Games\Steam\Steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{29C7D96E-AA89-4034-A699-7405B485E321}] => (Allow) D:\Steam Games\Steam\Steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{FF4E265D-9BED-41E5-A98B-616CAC76BB72}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File FirewallRules: [{0A6916B6-01F8-450D-BB7A-B5F7E7E34ABA}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File FirewallRules: [UDP Query User{9837C1F5-F109-4F33-888C-1E4CFEC2F604}C:\program files (x86)\electronic arts\eadm\core.exe] => (Allow) C:\program files (x86)\electronic arts\eadm\core.exe (Electronic Arts) [File not signed] FirewallRules: [TCP Query User{F966D549-DC83-452A-85EA-DCA2C8C9812D}C:\program files (x86)\electronic arts\eadm\core.exe] => (Allow) C:\program files (x86)\electronic arts\eadm\core.exe (Electronic Arts) [File not signed] FirewallRules: [{AE8C34BC-ACB4-4A43-A2D0-82C09EDC7509}] => (Allow) C:\Users\scott\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{B9428937-3308-43EB-9441-118E34FAB86F}] => (Allow) C:\Users\scott\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{DCE649F0-ECD9-4B28-A0A9-2E9D6451C8A6}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe => No File FirewallRules: [{57DC1CE6-9422-4664-A900-60824715780C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe => No File FirewallRules: [{3A7CE6AA-F28D-41D0-819A-4506962FE6E2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe => No File FirewallRules: [{9535E231-B162-4767-981B-F90D5B094171}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe => No File FirewallRules: [{0CE0CD08-704E-41D1-A721-C8E922776127}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe => No File FirewallRules: [{D6F58F83-5AD4-4378-8891-1F4973B6C7B7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{641BCB6F-2207-45E6-B0F1-9B3D9ABF9572}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{7D6BC653-B637-4D69-95CB-29F6A129AAE8}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation-Wireless Connectivity Solutions -> ) FirewallRules: [{7D1E8511-C6C1-43E5-A8C4-A297ECAD4FB1}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File FirewallRules: [{64C15539-1AFB-493A-9AFD-6B05B945A4E7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File FirewallRules: [{D0BB3EC2-1E52-4745-A8CB-8F37783CFA27}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File FirewallRules: [{5FCFC011-1ACC-4063-B31A-D65F2CADC780}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File FirewallRules: [{35D66A13-CE26-4559-A502-BEFAB94B81A6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Yu-Gi-Oh! Duel Links\dlpc.exe => No File FirewallRules: [{FD01972E-0CC5-407F-8BB2-519B023DF505}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Yu-Gi-Oh! Duel Links\dlpc.exe => No File FirewallRules: [{953B4BB5-ADAD-45B8-9417-0386DDD6AB06}] => (Allow) D:\Steam Games\Steam\steamapps\common\Nioh\nioh_launcher.exe (KOEI TECMO GAMES CO., LTD. -> KOEI TECMO GAMES CO., LTD.) FirewallRules: [{4859D924-6225-4BDB-A0FA-B9E39FC3BA07}] => (Allow) D:\Steam Games\Steam\steamapps\common\Nioh\nioh_launcher.exe (KOEI TECMO GAMES CO., LTD. -> KOEI TECMO GAMES CO., LTD.) FirewallRules: [{2BB97784-7268-46DD-BD51-690864A2618B}] => (Allow) D:\Steam Games\Steam\steamapps\common\Nioh\nioh.exe (KOEI TECMO GAMES CO., LTD. -> KOEI TECMO GAMES CO., LTD.) FirewallRules: [{D0C6C47C-91B5-48F3-AE47-704B8B1B0EC3}] => (Allow) D:\Steam Games\Steam\steamapps\common\Nioh\nioh.exe (KOEI TECMO GAMES CO., LTD. -> KOEI TECMO GAMES CO., LTD.) FirewallRules: [{3F982B6F-B0DA-4B18-9B5C-EF6315C042A5}] => (Allow) D:\Steam Games\Steam\steamapps\common\SleepingDogsDefinitiveEdition\sdhdship.exe (SQUARE ENIX LIMITED) [File not signed] FirewallRules: [{66E15689-61A5-46C1-BA9D-29FD324CB7B6}] => (Allow) D:\Steam Games\Steam\steamapps\common\SleepingDogsDefinitiveEdition\sdhdship.exe (SQUARE ENIX LIMITED) [File not signed] FirewallRules: [{FA3A1A9E-DB6D-4D5F-8FD9-9855C4F295B0}] => (Allow) D:\Steam Games\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{93CCCBFC-269A-40DD-B434-2A00A9B40F61}] => (Allow) D:\Steam Games\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{F02AE2B9-D9BA-40F2-BD17-5431AC894E0D}] => (Allow) D:\Steam Games\Steam\steamapps\common\Planet Zoo\PlanetZoo.exe (Frontier Developments) [File not signed] FirewallRules: [{D70E4A50-4A25-4201-AF64-C2536B42B121}] => (Allow) D:\Steam Games\Steam\steamapps\common\Planet Zoo\PlanetZoo.exe (Frontier Developments) [File not signed] FirewallRules: [{86AC83B3-384B-4CD3-8ABB-1F26D629C7F9}] => (Allow) D:\Steam Games\Steam\steamapps\common\L.A.Noire\PlayLAN.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{82220C68-D0B3-4F79-952F-D29F762EAE34}] => (Allow) D:\Steam Games\Steam\steamapps\common\L.A.Noire\PlayLAN.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [TCP Query User{926015D9-E9F3-4E44-A911-C2735AE11664}E:\samurai shodown\samuraishodown\samuraishodown\binaries\win64\samuraishodown-win64-shipping.exe] => (Allow) E:\samurai shodown\samuraishodown\samuraishodown\binaries\win64\samuraishodown-win64-shipping.exe => No File FirewallRules: [UDP Query User{D67483AB-D877-4026-BCEC-DF697099F3CA}E:\samurai shodown\samuraishodown\samuraishodown\binaries\win64\samuraishodown-win64-shipping.exe] => (Allow) E:\samurai shodown\samuraishodown\samuraishodown\binaries\win64\samuraishodown-win64-shipping.exe => No File FirewallRules: [{29971094-37B5-4F40-A64B-52D746E081E4}] => (Allow) D:\zmodeler3\ZModeler3.exe => No File FirewallRules: [{28B544F8-E35A-4F03-A038-CF6E0D8EED8D}] => (Allow) D:\zmodeler3\ZModeler3.exe => No File FirewallRules: [{EFBD647B-1FD7-4E19-A19A-1A411FCC3411}] => (Allow) D:\zmodeler3\ZModeler3.exe => No File FirewallRules: [{BFF68BE2-D729-40F6-9A9F-1CF752D53A44}] => (Allow) D:\zmodeler3\ZModeler3.exe => No File FirewallRules: [{579E5E5A-5694-4144-B6D4-E867C0324EDF}] => (Allow) D:\Steam Games\Steam\steamapps\common\Star Wars - The Old Republic\launcher.exe (Electronic Arts, Inc. -> BioWare) FirewallRules: [{1B3D4663-8D48-48C1-85AE-09059E824526}] => (Allow) D:\Steam Games\Steam\steamapps\common\Star Wars - The Old Republic\launcher.exe (Electronic Arts, Inc. -> BioWare) FirewallRules: [TCP Query User{AB585D3A-4EED-4A8D-A58F-08AF49CBD498}C:\windows\system32\sihost.exe] => (Block) C:\windows\system32\sihost.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [UDP Query User{CFDA8192-A06C-489B-A133-72673C347932}C:\windows\system32\sihost.exe] => (Block) C:\windows\system32\sihost.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{C73E5409-6D65-4BF7-AEB8-0C81987349D9}] => (Allow) D:\Steam Games\Steam\steamapps\common\SoulcaliburVI\SoulcaliburVI\Binaries\Win64\SoulcaliburVI.exe () [File not signed] FirewallRules: [{0EAC40C6-0777-4281-8776-23DBCF7805A4}] => (Allow) D:\Steam Games\Steam\steamapps\common\SoulcaliburVI\SoulcaliburVI\Binaries\Win64\SoulcaliburVI.exe () [File not signed] FirewallRules: [{E2BBE992-93F2-4595-B06E-A3704F657A73}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia Definitive Edition\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{EC0E51E5-C765-4D4C-BE1F-558CFB6C6687}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia Definitive Edition\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{7D417A1F-DA81-45C3-879B-D4F9EB6D9C3A}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia II Definitive Edition\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{6734A3D0-7BFD-4312-91CF-0F2F88428F02}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia II Definitive Edition\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{1CC14F77-1E7E-4773-A2DD-8E6982DBB59B}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia III\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{C0329008-F391-4EC3-86A9-B3E93735AE5F}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia III\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{17BB9C1B-5E37-4864-BD3A-BC92F3CF852C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{986D468F-8400-4C47-80F3-6885F54E10F3}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{043E91F9-2F63-47EE-ADD1-65B5309AAEBB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{7C3900C1-2E0F-4803-A235-C056EED61DFA}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{424F5783-378D-4B77-84B1-9965513DB332}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) ==================== Restore Points ========================= ATTENTION: System Restore is disabled (Total:118 GB) (Free:24.86 GB) (21%) ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (01/05/2022 01:19:33 PM) (Source: SecurityCenter) (EventID: 17) (User: ) Description: Security Center failed to validate caller with error %1. Error: (01/05/2022 01:19:33 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Error while updating status to SECURITY_PRODUCT_STATE_OFF. Error: (01/05/2022 01:19:33 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Error while updating status to SECURITY_PRODUCT_STATE_OFF. Error: (01/05/2022 01:19:33 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Error while updating status to SECURITY_PRODUCT_STATE_OFF. Error: (01/05/2022 01:19:33 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Error while updating status to SECURITY_PRODUCT_STATE_OFF. Error: (01/05/2022 01:19:33 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Error while updating status to SECURITY_PRODUCT_STATE_OFF. Error: (01/05/2022 01:19:32 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Error while updating status to SECURITY_PRODUCT_STATE_OFF. Error: (01/05/2022 01:19:32 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Error while updating status to SECURITY_PRODUCT_STATE_OFF. System errors: ============= Error: (01/06/2022 08:40:30 PM) (Source: Netwtw06) (EventID: 5005) (User: ) Description: Intel® Dual Band Wireless-AC 8260 : Has encountered an internal error and has failed. 5005 - Driver internal error Error: (01/06/2022 08:40:30 PM) (Source: Netwtw06) (EventID: 5035) (User: ) Description: 5035 - Driver OSC Pending OID watchdog Error: (01/06/2022 11:05:06 AM) (Source: Application Popup) (EventID: 56) (User: ) Description: ACPI5 Error: (01/06/2022 09:30:26 AM) (Source: Netwtw06) (EventID: 5005) (User: ) Description: Intel® Dual Band Wireless-AC 8260 : Has encountered an internal error and has failed. 5005 - Driver internal error Error: (01/06/2022 09:30:26 AM) (Source: Netwtw06) (EventID: 5035) (User: ) Description: 5035 - Driver OSC Pending OID watchdog Error: (01/06/2022 09:30:26 AM) (Source: Netwtw06) (EventID: 5002) (User: ) Description: Intel® Dual Band Wireless-AC 8260 : Has determined that the network adapter is not functioning properly. 5002 - uCode SW error (SysAssert, NMI) Error: (01/05/2022 07:02:42 PM) (Source: Netwtw06) (EventID: 5005) (User: ) Description: Intel® Dual Band Wireless-AC 8260 : Has encountered an internal error and has failed. 5005 - Driver internal error Error: (01/05/2022 07:02:42 PM) (Source: Netwtw06) (EventID: 5035) (User: ) Description: 5035 - Driver OSC Pending OID watchdog Windows Defender: ================ Date: 2022-01-05 09:19:37 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2022-01-05 04:27:00 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Custom Scan Date: 2022-01-05 04:27:00 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Full Scan Date: 2022-01-04 02:19:34 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2021-12-31 21:34:02 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Event[0]: Date: 2022-01-05 11:07:33 Description: Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x8007043c Error description: This service cannot be started in Safe Mode Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem. Date: 2021-12-25 03:49:41 Description: Microsoft Defender Antivirus has encountered an error trying to update security intelligence. New security intelligence Version: Previous security intelligence Version: 1.355.800.0 Update Source: Microsoft Update Server Security intelligence Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.18800.4 Error code: 0x8024402f Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. ==================== Memory info =========================== BIOS: LENOVO CDCN53WW 09/19/2016 Motherboard: LENOVO Allsparks 7A Processor: Intel® Core i7-6700HQ CPU @ 2.60GHz Percentage of memory in use: 18% Total physical RAM: 32595.78 MB Available physical RAM: 26708.81 MB Total Virtual: 37459.78 MB Available Virtual: 31256.9 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:118 GB) (Free:24.86 GB) NTFS Drive d: () (Fixed) (Total:931.39 GB) (Free:174.28 GB) NTFS Drive e: (My Passport) (Fixed) (Total:1862.98 GB) (Free:613.73 GB) NTFS Drive f: (Extreme SSD) (Fixed) (Total:3725.97 GB) (Free:3098.37 GB) exFAT \\?\Volume{6928a397-e5f4-4365-8811-35087e280745}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.47 GB) NTFS \\?\Volume{04942020-540b-4f93-8db9-06578ad813d0}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32 ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (Size: 119.2 GB) (Disk ID: 3ADB3DF5) Partition: GPT. ========================================================== Disk: 1 (Size: 931.5 GB) (Disk ID: 61994A64) Partition: GPT. ========================================================== Disk: 2 (Size: 3726 GB) (Disk ID: 16F2A91F) Partition: GPT. ========================================================== Disk: 3 (Size: 1863 GB) (Disk ID: 16F2A91F) Partition: GPT. ==================== End of Addition.txt =======================
Back to top
#9
polskamachina
polskamachina -
- Malware Response Team
- 5,965 posts
- OFFLINE
- Gender:Male
- Location:California
- Local time:10:59 AM
Posted 08 January 2022 - 02:50 PM
Hi DominoPunkyHeart
Good job posting the logs. I forgot to ask you to complete the tasks I asked you to do at the beginning. I will repost it here with some slight modifications to the code based on your previous Malwarebytes scan.results. Next:
- Highlight the text below in its entirety and press Ctrl-C to copy it to your clipboard:
- Run FRST64
- Click on Fix
- When the fix completes, you will be asked to restart your computer. Please allow the restart.
- When your computer reboots back to your Desktop, the file Fixlog.txt will have been placed into your Downloads folder
- Copy and paste (do not attach) that file into your next reply to me
Next:
- Download AdwCleaner and save it to your Desktop
- Right-click on AdwCleaner.exe and select
Run as Administrator - Accept the EULA (I accept), then click on Scan Now
- Let the scan complete
- Once the scan completes, make sure that every item listed in the different tabs is checked and click on the Clean & Repair button
- Subsequently you may be asked to Run Basic Repair. This is optional. I would suggest holding off on this for now.
- Once the cleaning process is complete, AdwCleaner will ask you to restart your computer
- Close all other open windows and allow it to restart
- After the restart, Notepad will open with the AdwCleaner cleaning log
- Please copy and paste the contents of that log into your next reply to me
In summary I will need from you:
- Fixlog.txt
- AdwCleaner cleaning log
- How is your computer performing now?
Let me know if you have any questions. polskamachina
Edited by polskamachina, 09 January 2022 - 12:35 AM.
If I have made your computing life easier, please consider making a contribution.
Back to top
#10
DominoPunkyHeart
DominoPunkyHeart - Topic Starter
-
- Members
- 10 posts
- OFFLINE
- Local time:01:59 PM
Posted 09 January 2022 - 12:30 AM
Hi polskamachina, here are the logs from both the fixlog and also the AdwareCleaner as you requested. Hopefully everything is clean and clear for my laptop.
Currently my laptop seems to be running okay, and I hope it is fixed.
Fix result of Farbar Recovery Scan Tool (x64) Version: 27-12-2021 Ran by scott (09-01-2022 00:16:20) Run:1 Running from C:\Users\scott\Downloads Loaded Profiles: defaultuser0 & scott Boot Mode: Normal ============================================== fixlist content: ***************** SystemRestore: On CreateRestorePoint: CloseProcesses: Task: {40DE693C-8CFD-4CAC-8980-2BB8B1532DE4} - System32\Tasks\App Explorer => C:\Users\scott\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [7744560 2021-01-19] (SweetLabs Inc. -> SweetLabs, Inc) <==== ATTENTION Task: {70FFF1DF-0DBA-4C94-99A9-C0DF052F99D1} - System32\Tasks\Microsoft\Windows\Setup\EOSNotify => C:\WINDOWS\system32\EOSNotify.exe (No File) Task: {A5D5D761-F453-4A1D-A3F8-E215695D3C70} - System32\Tasks\Nvbackend_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (No File) CustomCLSID: HKU\S-1-5-21-4096549371-2451222336-3956411163-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\scott\AppData\Local\Microsoft\OneDrive\18.192.0920.0015\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-4096549371-2451222336-3956411163-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\scott\AppData\Local\Microsoft\OneDrive\18.192.0920.0015\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-4096549371-2451222336-3956411163-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\scott\AppData\Local\Microsoft\OneDrive\18.192.0920.0015\amd64\FileSyncShell64.dll => No File ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File BHO: No Name -> {F91D11A8-8E29-408A-A9ED-D1B4CE29ECDF}' -> No File BHO-x32: No Name -> {F91D11A8-8E29-408A-A9ED-D1B4CE29ECDF}' -> No File FirewallRules: [UDP Query User{4B0469CC-C1DB-4073-AE30-18D56FD2983B}E:\simcasino.v15.02.2021\simcasino\simcasino.exe] => (Allow) E:\simcasino.v15.02.2021\simcasino\simcasino.exe => No File FirewallRules: [TCP Query User{8D26ABB6-5C87-4273-9362-13F86D515553}E:\simcasino.v15.02.2021\simcasino\simcasino.exe] => (Allow) E:\simcasino.v15.02.2021\simcasino\simcasino.exe => No File FirewallRules: [{2BA8F4F5-08F8-4AA0-AF22-95DF989BBFCB}] => (Allow) E:\Pinball Games\Pinball.Parlor\PP.exe => No File FirewallRules: [{95002BEA-BA72-4726-90CC-6502BF6225D2}] => (Allow) E:\Pinball Games\Pinball.Parlor\PP.exe => No File FirewallRules: [{ED631F4E-09FC-4225-BC45-144386BCC66A}] => (Allow) E:\Pinball Games\Pinball.Parlor\PP.exe => No File FirewallRules: [{35094D17-58A1-432B-AF94-47034D9175E3}] => (Allow) E:\Pinball Games\Pinball.Parlor\PP.exe => No File FirewallRules: [{6B831CFE-226F-4BC0-8799-C6960ED033BA}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe => No File FirewallRules: [UDP Query User{23F24458-48C5-4E43-9A3A-5EB7AA8A6CB2}E:\games\the sims 4 eco lifestyle\game\bin\ts4_x64.exe] => (Allow) E:\games\the sims 4 eco lifestyle\game\bin\ts4_x64.exe => No File FirewallRules: [TCP Query User{407E0FBD-26EC-4C2D-910E-9D2676EAC39A}E:\games\the sims 4 eco lifestyle\game\bin\ts4_x64.exe] => (Allow) E:\games\the sims 4 eco lifestyle\game\bin\ts4_x64.exe => No File FirewallRules: [UDP Query User{76093F34-BB7F-4D4F-9C8D-978A39E22122}E:\saints row 3 - game\saints row 3\saintsrowthethird_dx11.exe] => (Allow) E:\saints row 3 - game\saints row 3\saintsrowthethird_dx11.exe => No File FirewallRules: [TCP Query User{573B1A30-35C8-4FB9-A7C5-15E296CD908E}E:\saints row 3 - game\saints row 3\saintsrowthethird_dx11.exe] => (Allow) E:\saints row 3 - game\saints row 3\saintsrowthethird_dx11.exe => No File FirewallRules: [UDP Query User{E36F3718-5ABA-4F09-9A84-622B97661E9A}E:\saints row 2 - game\saints row 2\sr2_pc.exe] => (Allow) E:\saints row 2 - game\saints row 2\sr2_pc.exe => No File FirewallRules: [TCP Query User{492D992A-B834-49D1-A22F-B047C113916F}E:\saints row 2 - game\saints row 2\sr2_pc.exe] => (Allow) E:\saints row 2 - game\saints row 2\sr2_pc.exe => No File FirewallRules: [UDP Query User{075CE593-D950-425E-83C3-C80B941C0542}E:\jump force\jump force\jump_force\binaries\win64\jump_force-win64-shipping.exe] => (Allow) E:\jump force\jump force\jump_force\binaries\win64\jump_force-win64-shipping.exe => No File FirewallRules: [TCP Query User{65119092-D215-4C52-A477-96859EE6834B}E:\jump force\jump force\jump_force\binaries\win64\jump_force-win64-shipping.exe] => (Allow) E:\jump force\jump force\jump_force\binaries\win64\jump_force-win64-shipping.exe => No File FirewallRules: [UDP Query User{225B6674-4EF9-452A-A013-DB1632F8FF70}E:\games\the sims 4 discover university\game\bin\ts4_x64.exe] => (Allow) E:\games\the sims 4 discover university\game\bin\ts4_x64.exe => No File FirewallRules: [TCP Query User{5AEA2B36-DBE7-4F8B-BCAB-FE6119D1A79D}E:\games\the sims 4 discover university\game\bin\ts4_x64.exe] => (Allow) E:\games\the sims 4 discover university\game\bin\ts4_x64.exe => No File FirewallRules: [UDP Query User{26A3908F-600E-4728-B212-033DFFE88CC4}E:\the sims 4 island living\game\bin\ts4_x64.exe] => (Allow) E:\the sims 4 island living\game\bin\ts4_x64.exe => No File FirewallRules: [TCP Query User{24BAE737-62B0-4D31-9DFB-F2D08C329463}E:\the sims 4 island living\game\bin\ts4_x64.exe] => (Allow) E:\the sims 4 island living\game\bin\ts4_x64.exe => No File FirewallRules: [{FF4E265D-9BED-41E5-A98B-616CAC76BB72}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File FirewallRules: [{0A6916B6-01F8-450D-BB7A-B5F7E7E34ABA}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File FirewallRules: [{DCE649F0-ECD9-4B28-A0A9-2E9D6451C8A6}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe => No File FirewallRules: [{57DC1CE6-9422-4664-A900-60824715780C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe => No File FirewallRules: [{3A7CE6AA-F28D-41D0-819A-4506962FE6E2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe => No File FirewallRules: [{9535E231-B162-4767-981B-F90D5B094171}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe => No File FirewallRules: [{0CE0CD08-704E-41D1-A721-C8E922776127}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe => No File FirewallRules: [{7D1E8511-C6C1-43E5-A8C4-A297ECAD4FB1}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File FirewallRules: [{64C15539-1AFB-493A-9AFD-6B05B945A4E7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File FirewallRules: [{D0BB3EC2-1E52-4745-A8CB-8F37783CFA27}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File FirewallRules: [{5FCFC011-1ACC-4063-B31A-D65F2CADC780}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File FirewallRules: [{35D66A13-CE26-4559-A502-BEFAB94B81A6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Yu-Gi-Oh! Duel Links\dlpc.exe => No File FirewallRules: [{FD01972E-0CC5-407F-8BB2-519B023DF505}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Yu-Gi-Oh! Duel Links\dlpc.exe => No File FirewallRules: [TCP Query User{926015D9-E9F3-4E44-A911-C2735AE11664}E:\samurai shodown\samuraishodown\samuraishodown\binaries\win64\samuraishodown-win64-shipping.exe] => (Allow) E:\samurai shodown\samuraishodown\samuraishodown\binaries\win64\samuraishodown-win64-shipping.exe => No File FirewallRules: [UDP Query User{D67483AB-D877-4026-BCEC-DF697099F3CA}E:\samurai shodown\samuraishodown\samuraishodown\binaries\win64\samuraishodown-win64-shipping.exe] => (Allow) E:\samurai shodown\samuraishodown\samuraishodown\binaries\win64\samuraishodown-win64-shipping.exe => No File FirewallRules: [{29971094-37B5-4F40-A64B-52D746E081E4}] => (Allow) D:\zmodeler3\ZModeler3.exe => No File FirewallRules: [{28B544F8-E35A-4F03-A038-CF6E0D8EED8D}] => (Allow) D:\zmodeler3\ZModeler3.exe => No File FirewallRules: [{EFBD647B-1FD7-4E19-A19A-1A411FCC3411}] => (Allow) D:\zmodeler3\ZModeler3.exe => No File FirewallRules: [{BFF68BE2-D729-40F6-9A9F-1CF752D53A44}] => (Allow) D:\zmodeler3\ZModeler3.exe => No File ***************** SystemRestore: On => completed Restore point was successfully created. Processes closed successfully. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{40DE693C-8CFD-4CAC-8980-2BB8B1532DE4}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40DE693C-8CFD-4CAC-8980-2BB8B1532DE4}" => removed successfully C:\WINDOWS\System32\Tasks\App Explorer => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\App Explorer" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{70FFF1DF-0DBA-4C94-99A9-C0DF052F99D1}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70FFF1DF-0DBA-4C94-99A9-C0DF052F99D1}" => removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Setup\EOSNotify => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\EOSNotify" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A5D5D761-F453-4A1D-A3F8-E215695D3C70}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A5D5D761-F453-4A1D-A3F8-E215695D3C70}" => removed successfully C:\WINDOWS\System32\Tasks\Nvbackend_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Nvbackend_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" => removed successfully HKU\S-1-5-21-4096549371-2451222336-3956411163-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E} => removed successfully HKU\S-1-5-21-4096549371-2451222336-3956411163-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C} => removed successfully HKU\S-1-5-21-4096549371-2451222336-3956411163-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E} => removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => removed successfully HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => removed successfully HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => removed successfully HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => removed successfully HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => removed successfully HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => removed successfully HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F91D11A8-8E29-408A-A9ED-D1B4CE29ECDF}' => removed successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F91D11A8-8E29-408A-A9ED-D1B4CE29ECDF}' => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{4B0469CC-C1DB-4073-AE30-18D56FD2983B}E:\simcasino.v15.02.2021\simcasino\simcasino.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{8D26ABB6-5C87-4273-9362-13F86D515553}E:\simcasino.v15.02.2021\simcasino\simcasino.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2BA8F4F5-08F8-4AA0-AF22-95DF989BBFCB}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{95002BEA-BA72-4726-90CC-6502BF6225D2}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{ED631F4E-09FC-4225-BC45-144386BCC66A}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{35094D17-58A1-432B-AF94-47034D9175E3}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6B831CFE-226F-4BC0-8799-C6960ED033BA}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{23F24458-48C5-4E43-9A3A-5EB7AA8A6CB2}E:\games\the sims 4 eco lifestyle\game\bin\ts4_x64.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{407E0FBD-26EC-4C2D-910E-9D2676EAC39A}E:\games\the sims 4 eco lifestyle\game\bin\ts4_x64.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{76093F34-BB7F-4D4F-9C8D-978A39E22122}E:\saints row 3 - game\saints row 3\saintsrowthethird_dx11.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{573B1A30-35C8-4FB9-A7C5-15E296CD908E}E:\saints row 3 - game\saints row 3\saintsrowthethird_dx11.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{E36F3718-5ABA-4F09-9A84-622B97661E9A}E:\saints row 2 - game\saints row 2\sr2_pc.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{492D992A-B834-49D1-A22F-B047C113916F}E:\saints row 2 - game\saints row 2\sr2_pc.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{075CE593-D950-425E-83C3-C80B941C0542}E:\jump force\jump force\jump_force\binaries\win64\jump_force-win64-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{65119092-D215-4C52-A477-96859EE6834B}E:\jump force\jump force\jump_force\binaries\win64\jump_force-win64-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{225B6674-4EF9-452A-A013-DB1632F8FF70}E:\games\the sims 4 discover university\game\bin\ts4_x64.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{5AEA2B36-DBE7-4F8B-BCAB-FE6119D1A79D}E:\games\the sims 4 discover university\game\bin\ts4_x64.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{26A3908F-600E-4728-B212-033DFFE88CC4}E:\the sims 4 island living\game\bin\ts4_x64.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{24BAE737-62B0-4D31-9DFB-F2D08C329463}E:\the sims 4 island living\game\bin\ts4_x64.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FF4E265D-9BED-41E5-A98B-616CAC76BB72}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0A6916B6-01F8-450D-BB7A-B5F7E7E34ABA}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DCE649F0-ECD9-4B28-A0A9-2E9D6451C8A6}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{57DC1CE6-9422-4664-A900-60824715780C}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3A7CE6AA-F28D-41D0-819A-4506962FE6E2}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9535E231-B162-4767-981B-F90D5B094171}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0CE0CD08-704E-41D1-A721-C8E922776127}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7D1E8511-C6C1-43E5-A8C4-A297ECAD4FB1}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{64C15539-1AFB-493A-9AFD-6B05B945A4E7}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D0BB3EC2-1E52-4745-A8CB-8F37783CFA27}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5FCFC011-1ACC-4063-B31A-D65F2CADC780}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{35D66A13-CE26-4559-A502-BEFAB94B81A6}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FD01972E-0CC5-407F-8BB2-519B023DF505}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{926015D9-E9F3-4E44-A911-C2735AE11664}E:\samurai shodown\samuraishodown\samuraishodown\binaries\win64\samuraishodown-win64-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D67483AB-D877-4026-BCEC-DF697099F3CA}E:\samurai shodown\samuraishodown\samuraishodown\binaries\win64\samuraishodown-win64-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{29971094-37B5-4F40-A64B-52D746E081E4}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{28B544F8-E35A-4F03-A038-CF6E0D8EED8D}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{EFBD647B-1FD7-4E19-A19A-1A411FCC3411}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BFF68BE2-D729-40F6-9A9F-1CF752D53A44}" => removed successfully The system needed a reboot. ==== End of Fixlog 00:16:33 ==== # ------------------------------- # Malwarebytes AdwCleaner 8.3.1.0 # ------------------------------- # Build: 11-18-2021 # Database: 2021-12-02.1 (Cloud) # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Clean # ------------------------------- # Start: 01-09-2022 # Duration: 00:00:03 # OS: Windows 10 Home # Cleaned: 24 # Failed: 0 ***** [ Services ] ***** No malicious services cleaned. ***** [ Folders ] ***** Deleted C:\ProgramData\Host App Service Deleted C:\ProgramData\SecuritySuite Deleted C:\Users\Default\AppData\Local\Host App Service Deleted C:\Users\defaultuser0\AppData\Local\Host App Service Deleted C:\Users\scott\AppData\Local\Host App Service Deleted C:\Windows\ServiceProfiles\LocalService\AppData\Local\Host App Service Deleted C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Host App Service Deleted C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\TotalAV ***** [ Files ] ***** Deleted C:\Windows\System32\Tasks_Migrated\App Explorer ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks cleaned. ***** [ Registry ] ***** Deleted HKCU\Software\App Host Service Deleted HKCU\Software\Host App Service Deleted HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\thebrighttag.com Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service Deleted HKCU\Software\SSProtect Deleted HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.totalav.passwordvaultassistant Deleted HKLM\SOFTWARE\Microsoft\Edge\NativeMessagingHosts\com.totalav.passwordvaultassistant Deleted HKLM\SOFTWARE\Mozilla\NativeMessagingHosts\com.totalav.passwordvaultassistant Deleted HKLM\Software\Classes\totalav Deleted HKLM\System\CurrentControlSet\Services\EventLog\Application\SecurityService Deleted HKU\S-1-5-19\Software\Host App Service Deleted HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service Deleted HKU\S-1-5-20\Software\Host App Service Deleted HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries cleaned. ***** [ Chromium URLs ] ***** Deleted http://homepage-web.com/?s=toshibaupd&m=start ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries cleaned. ***** [ Firefox URLs ] ***** No malicious Firefox URLs cleaned. ***** [ Hosts File Entries ] ***** No malicious hosts file entries cleaned. ***** [ Preinstalled Software ] ***** No Preinstalled Software cleaned. ************************* [+] Delete Tracing Keys [+] Reset Winsock ************************* AdwCleaner[S00].txt - [5063 octets] - [05/01/2022 15:47:30] AdwCleaner[S01].txt - [4811 octets] - [09/01/2022 00:20:27] ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########
Back to top
#11
polskamachina
polskamachina -
- Malware Response Team
- 5,965 posts
- OFFLINE
- Gender:Male
- Location:California
- Local time:10:59 AM
Posted 09 January 2022 - 01:07 PM
Hi DominoPunkyHeart, We're almost at the finish line.
ESET Online Scanner:
- Download ESET Online Scanner from the ESET website by clicking the ONE-TIME-SCAN button on that webpage
- Double-click the esetonlinescanner.exe file you downloaded to run the application
- Select product language
- Click Get started and confirm the User access control dialog of Windows
- In the Terms of use screen, click Accept if you agree to the Terms of use. After accepting the terms of use, the shortcut for ESET Online Scanner is created on your Desktop
- Click Get started in the welcome screen
- Select whether or not you want to join the Customer Experience Improvement Program, and whether or not to enable the feedback system, then click Continue
- Select the Full Scan type
- Select the choice to enable detections of potentially unwanted applications (PUA)
- After the detection module updates are downloaded, the scan starts. Scan progress is shown via the progress bar along with the path and title of file being scanned. You can pause or cancel the scan at any time
- Note: The scan make take several hours depending on how many files are on your computer..When the scan has finished and if threats have been detected, click Save scan log and save the text file with a unique name such as, ESET results.txt thenclick Continue.
- Copy and paste the contents of this ESET results report into your next reply to me (If no threats were detected, you do not need to save the results)
- The following steps are optional and are not required
- If there has been no ESET security product detected on your machine, and your user account has administrator privileges, ESET Online Scanner will offer you to turn on Periodic scan. This choice is up to you
- In the Thank you for using ESET Online Scanner screen you can rate the application and leave feedback. In addition, to delete all detection modules and settings of ESET Online Scanner configured in previous steps, select Delete application's data on closing
- Click Submit and close if you rated the application and/or left a feedback, or click Close without feedback
- Click Finish to exit ESET Online Scanner
Next:
- Run FRST64
- Click on Scan
- When the scan completes, please copy and paste FRST.txt and Addition.txt into your next reply to me
In summary I will need from you:
- ESET scan log (if threats were found)
- FRST.txt
- Addition.txt
Let me know if you have any questions. polskamachina
If I have made your computing life easier, please consider making a contribution.
Back to top
#12
DominoPunkyHeart
DominoPunkyHeart - Topic Starter
-
- Members
- 10 posts
- OFFLINE
- Local time:01:59 PM
Posted 09 January 2022 - 06:09 PM
Hey polskamachina, here are the logs you've asked for after I've done the scans.
Please let me know how everything looks for my laptop, and thank you for all the help you've been giving me!
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-12-2021 Ran by scott (administrator) on DOMINOPUNKYHEAR (LENOVO 80Q0) (09-01-2022 17:51:38) Running from C:\Users\scott\Downloads Loaded Profiles: scott Platform: Microsoft Windows 10 Home Version 20H2 19042.1415 (X64) Language: English (United States) Default browser: Chrome Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Adobe Systems Incorporated -> ) C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe (Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe (Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <13> (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxCUIService.exe (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxEM.exe (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxext.exe (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHDCPSvc.exe (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHeciSvc.exe (Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (LENOVO -> ) C:\Program Files\Lenovo\LenovoUtility\utility.exe (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.CompanionApp.exe <3> (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost86\Lenovo.Modern.ImController.PluginHost.Device.exe (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe (LENOVO -> Lenovo(beijing) Limited) C:\Program Files\Lenovo\Nerve Center\bin\x64\HotkeyMonitor.exe (LENOVO -> Lenovo(beijing) Limited) C:\Program Files\Lenovo\Nerve Center\bin\x64\LenovoNerveCenterTray.exe (LENOVO -> Lenovo(beijing) Limited) C:\Program Files\Lenovo\Nerve Center\bin\x64\LenovoNerveCenterUpdateAgent.exe (LENOVO -> Lenovo(beijing) Limited) C:\Program Files\Lenovo\Nerve Center\bin\x64\PluginLoaderSvc.exe (LENOVO -> Lenovo(beijing) Limited) C:\Program Files\Lenovo\Nerve Center\bin\x86\GameRecorderSVC.exe (LENOVO -> Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2110.13603.0_x64__8wekyb3d8bbwe\Cortana.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2110.13603.0_x64__8wekyb3d8bbwe\Win32Bridge.Server.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <3> (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NerveCenterTray] => C:\Program Files\Lenovo\Nerve Center\bin\x64\LenovoNerveCenterTray.exe [245088 2017-04-28] (LENOVO -> Lenovo(beijing) Limited) HKLM\...\Run: [LenovoUtility] => C:\Program Files\Lenovo\LenovoUtility\utility.exe [791848 2017-03-09] (LENOVO -> ) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16779768 2016-12-22] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1478144 2016-12-22] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1478144 2016-12-22] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1478144 2016-12-22] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [323056 2015-11-04] (Intel® Rapid Storage Technology -> Intel Corporation) HKLM\...\Run: [DAX2_APP] => C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe [829632 2016-06-24] (Dolby Laboratories, Inc. -> ) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [167496 2021-12-08] (ESET, spol. s r.o. -> ESET) HKLM-x32\...\Run: [Adobe Photo Downloader] => C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\apdproxy.exe [67488 2007-09-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM-x32\...\Run: [WDDiscovery] => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Discovery.exe [81379600 2021-12-27] (Western Digital Technologies, Inc. -> Western Digital Corporation) HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\Run: [Discord] => C:\Users\scott\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub) HKLM\...\Windows x64\Print Processors\BJ Print Processor4: C:\Windows\System32\spool\prtprocs\x64\CNBPP4.DLL [84992 2011-08-30] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\BJ Language Monitor4: C:\Windows\system32\CNBLM4.DLL [267776 2011-08-30] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\97.0.4692.71\Installer\chrmstp.exe [2022-01-06] (Google LLC -> Google LLC) ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0316DD02-0788-46A3-B31D-D268AA016796} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\c983d090-49d2-4d7b-b68c-da049919be80 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {03405A93-69CC-432A-819B-C994CD11EEA2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-26] (Google Inc -> Google Inc.) Task: {0FCD2477-D645-4A26-9C66-6FBB862E7E54} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\dd88ca7d-1204-4101-acf5-b5ae5e854747 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {39CDEF37-7D8A-4E7B-8964-CA932EBB9AE5} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [1542080 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) Task: {44EF4A33-40A1-4267-9A66-1E83E8656E33} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\ad28dbd8-94e7-4179-8ea6-2a16996351d8 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {4E01D4EE-C295-472D-8C91-FF25F9AF74C6} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [728000 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) Task: {4EA7A415-93B1-4D9C-8A29-1B1BECB0E909} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log Task: {58895498-3B9B-4802-9021-58372A7F37A8} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => "%windir%\system32\sc.exe" START ImControllerService Task: {66318254-D66D-4652-86E7-C0D94986EE08} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [960448 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) Task: {75A437C2-FB70-4356-8EF3-B5A0C78539EF} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [108872 2021-12-18] (Microsoft Corporation -> Microsoft Corporation) Task: {77E1CB8F-8FE0-4C1A-B440-D52FAE80C047} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [436160 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) Task: {7D1B2B7E-FFB6-4893-9CA1-99F466036754} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32 Task: {7FABF0B7-BC09-49B6-9896-DE0A10ED887C} - System32\Tasks\Lenovo\BatteryGauge\BatteryGaugeMaintenance => C:\ProgramData\Lenovo\ImController\Plugins\LenovoBatteryGaugePackage\x64\BGHelper.exe [145480 2021-09-09] (Lenovo -> Lenovo Group Ltd.) Task: {867DE49F-DC09-4079-B91D-A1604FAD8131} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\b3e62256-cc6b-4b96-835d-821ec281b063 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {8CBB3840-CF5D-4699-A8F3-6DAF2B51BBAA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-26] (Google Inc -> Google Inc.) Task: {B06EB3BB-EF4C-45D2-AF49-F40B58E4DCEA} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22797704 2021-12-10] (Microsoft Corporation -> Microsoft Corporation) Task: {B1E1D06C-AF40-4BE7-AEDA-CD7EB9FEFDFE} - System32\Tasks\NerveCenterUpdate => C:\Program Files\Lenovo\Nerve Center\bin\x64\LenovoNerveCenterUpdateAgent.exe [744800 2017-04-28] (LENOVO -> Lenovo(beijing) Limited) Task: {BD893A82-480B-423E-BE60-F42F446B7C8F} - System32\Tasks\WD Discovery Service Task scott => C:\Program Files (x86)\Western Digital\Discovery\Current\Service\WDDiscoveryService.exe [78608 2021-12-27] (Western Digital Technologies, Inc. -> ) Task: {BE905044-A82A-4869-8BE3-6696AB9F23EB} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [655296 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) Task: {CA29313F-D0F5-4F99-A316-6BFF7C27D621} - System32\Tasks\Lenovo\Lenovo Settings Power => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor Task: {CEF656B0-8B38-44E4-AAA3-FBFA364A2B5E} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [728000 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) Task: {D2E9298C-C0CA-4CE6-A76B-5DD5144BD5BB} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22797704 2021-12-10] (Microsoft Corporation -> Microsoft Corporation) Task: {DB06F123-BE8B-46B0-A1C2-A31839917A66} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe [63728 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {E256BDCD-E19B-435E-9297-D81244D62A3A} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\9d14f0f5-2fca-4e63-bf39-347fb1fd24b1 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {E3EB9A8C-38D3-4EE3-84DE-B5017822D94F} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [108872 2021-12-18] (Microsoft Corporation -> Microsoft Corporation) Task: {EB9E0C1E-23C5-4083-81B0-A7039C345E0B} - System32\Tasks\WD Device Agent Task scott => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Device Agent.exe [723728 2021-12-27] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) Task: {FC35D24A-2F66-4E75-9B09-570AA3EA9889} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [655296 2017-10-10] (NVIDIA Corporation -> NVIDIA Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.63 Tcpip\..\Interfaces\{b675f143-5303-45d5-9d76-55b176ae069d}: [DhcpNameServer] 150.204.1.2 Tcpip\..\Interfaces\{cc2b293d-37dd-49a3-ba83-23d46f9c1139}: [DhcpNameServer] 209.18.47.61 209.18.47.63 Edge: ======= DownloadDir: C:\Users\scott\Downloads Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found] Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found] Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found] Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found] Edge Profile: C:\Users\scott\AppData\Local\Microsoft\Edge\User Data\Default [2022-01-05] FireFox: ======== FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-10-31] (Microsoft Corporation -> Microsoft Corporation) Chrome: ======= CHR Profile: C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default [2022-01-09] CHR StartupUrls: Default -> "hxxp://homepage-web.com/?s=toshibaupd&m=start","hxxps://www.google.com/" CHR NewTab: Default -> Active:"chrome-extension://nadklbnikchkjjnlmnomcbdppegnppkk/tab10.html" CHR Extension: (Slides) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-11-26] CHR Extension: (Docs) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-11-26] CHR Extension: (Google Drive) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-24] CHR Extension: (YouTube) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-11-26] CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2021-11-24] CHR Extension: (Tampermonkey) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2021-05-23] CHR Extension: (Gloss dark) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\edfjafcniegodjnlgfgacgkbbmjhgmfd [2022-01-05] CHR Extension: (Sheets) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-11-26] CHR Extension: (Night Mode Pro) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbilbeoogenjmnabenfjfoockmpfnjoh [2021-07-19] CHR Extension: (Google Docs Offline) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-11-30] CHR Extension: (Dabi Wallpaper HD Custom New Tab) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\nadklbnikchkjjnlmnomcbdppegnppkk [2022-01-05] CHR Extension: (Chrome Web Store Payments) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-28] CHR Extension: (Gmail) - C:\Users\scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22] CHR Extension: (Settings) - C:\Users\scott\AppData\Local [2022-01-09] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeActiveFileMonitor6.0; C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [124832 2007-09-11] (Adobe Systems Incorporated -> ) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12129128 2021-12-10] (Microsoft Corporation -> Microsoft Corporation) R2 DAX2API; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [163336 2016-09-19] (Dolby Laboratories, Inc. -> ) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811120 2020-03-15] (EasyAntiCheat Oy -> Epic Games, Inc) R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [3141480 2021-12-08] (ESET, spol. s r.o. -> ESET) R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [3141480 2021-12-08] (ESET, spol. s r.o. -> ESET) S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2018-11-27] (Macrovision Europe Ltd.) [File not signed] R2 GameRecorderSVC; C:\Program Files\Lenovo\Nerve Center\bin\x86\GameRecorderSVC.exe [392032 2017-04-28] (LENOVO -> Lenovo(beijing) Limited) R2 ImControllerService; C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7901368 2022-01-05] (Malwarebytes Inc -> Malwarebytes) R2 PluginLoaderSvc; C:\Program Files\Lenovo\Nerve Center\bin\x64\PluginLoaderSvc.exe [966496 2017-04-28] (LENOVO -> Lenovo(beijing) Limited) S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [2017072 2021-12-20] (Rockstar Games, Inc. -> Rockstar Games) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [528160 2018-06-04] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\NisSrv.exe [2876152 2021-12-15] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MsMpEng.exe [128360 2021-12-15] (Microsoft Windows Publisher -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 BHTPCRDR; C:\WINDOWS\System32\drivers\bhtpcrdr.sys [173432 2016-08-10] (BayHub Technology Inc. -> BayHubTech/O2Micro) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed] S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [183408 2021-12-08] (ESET, spol. s r.o. -> ESET) R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [124496 2021-12-08] (ESET, spol. s r.o. -> ESET) S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15824 2021-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET) R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [201984 2021-12-08] (ESET, spol. s r.o. -> ESET) S2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [43920 2021-12-08] (ESET, spol. s r.o. -> ESET) R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [69736 2021-12-08] (ESET, spol. s r.o. -> ESET) R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [107456 2021-12-08] (ESET, spol. s r.o. -> ESET) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [160176 2022-01-05] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) R2 FBNetFilter; C:\Windows\system32\Drivers\FBNetFlt.sys [46576 2017-04-28] (Lenovo (Beijing) Co., Ltd. -> Lenovo(beijing) Limited) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [210352 2022-01-05] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2022-01-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [193448 2022-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [69040 2022-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2022-01-05] (Malwarebytes Inc -> Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [149424 2022-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2021-12-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [435432 2021-12-15] (Microsoft Windows -> Microsoft Corporation) R1 wdfsconnect2017; C:\WINDOWS\system32\drivers\wdfsconnect2017.sys [468112 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86248 2021-12-15] (Microsoft Windows -> Microsoft Corporation) R3 wdvpnpbus; C:\WINDOWS\System32\drivers\wdvpnpbus.sys [20624 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2022-01-09 17:51 - 2022-01-09 17:52 - 000027841 ____C C:\Users\scott\Downloads\FRST.txt 2022-01-09 16:21 - 2022-01-09 16:21 - 000002023 ____C C:\Users\Public\Desktop\ESET Banking & Payment protection.lnk 2022-01-09 15:41 - 2022-01-09 15:41 - 000000000 ___DC C:\Users\scott\AppData\LocalLow\IGDump 2022-01-09 15:24 - 2022-01-09 15:24 - 000000000 ____D C:\Users\scott\AppData\Local\ESET 2022-01-09 15:24 - 2022-01-09 15:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET 2022-01-09 15:24 - 2022-01-09 15:24 - 000000000 ____D C:\ProgramData\ESET 2022-01-09 15:24 - 2022-01-09 15:24 - 000000000 ____D C:\Program Files\ESET 2022-01-09 15:10 - 2022-01-09 15:10 - 008398952 ____C (ESET) C:\Users\scott\Downloads\eset_internet_security_live_installer.exe 2022-01-09 00:26 - 2022-01-09 00:26 - 000069040 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2022-01-09 00:25 - 2022-01-09 00:25 - 000193448 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2022-01-09 00:25 - 2022-01-09 00:25 - 000149424 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2022-01-09 00:15 - 2022-01-09 00:15 - 008540344 ____C (Malwarebytes) C:\Users\scott\Downloads\adwcleaner_8.3.1.exe 2022-01-05 16:25 - 2022-01-09 17:51 - 000000000 ___DC C:\FRST 2022-01-05 16:19 - 2022-01-05 16:19 - 002311168 ____C (Farbar) C:\Users\scott\Downloads\FRST64.exe 2022-01-05 15:47 - 2022-01-09 00:22 - 000000000 ___DC C:\AdwCleaner 2022-01-05 11:07 - 2022-01-05 11:07 - 000265926 _____ C:\WINDOWS\ntbtlog.txt 2022-01-05 11:07 - 2022-01-05 11:07 - 000000214 ____C C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job 2022-01-05 09:25 - 2022-01-05 09:25 - 000000000 ____D C:\Users\scott\AppData\Local\mbam 2022-01-05 09:24 - 2022-01-05 11:11 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2022-01-05 09:24 - 2022-01-05 11:07 - 000210352 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys 2022-01-05 09:24 - 2022-01-05 09:24 - 000160176 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 2022-01-05 09:24 - 2022-01-05 09:24 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys 2022-01-05 09:24 - 2022-01-05 09:24 - 000002040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk 2022-01-05 09:24 - 2022-01-05 09:24 - 000002028 ____C C:\Users\Public\Desktop\Malwarebytes.lnk 2022-01-05 09:24 - 2022-01-05 09:24 - 000000000 ____D C:\ProgramData\Malwarebytes 2022-01-05 09:24 - 2022-01-05 09:24 - 000000000 ____D C:\Program Files\Malwarebytes 2022-01-05 07:31 - 2022-01-09 00:25 - 097779712 _____ C:\WINDOWS\system32\config\SOFTWARE 2022-01-05 07:27 - 2022-01-05 07:31 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware 2022-01-05 04:49 - 2022-01-05 04:49 - 000000000 ____D C:\Users\scott\AppData\Local\GUI 2022-01-04 13:31 - 2022-01-04 13:31 - 000000000 ____D C:\Users\scott\AppData\Local\Chess2 2022-01-04 13:29 - 2022-01-04 13:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Chess Ultra 2022-01-04 12:53 - 2022-01-04 12:53 - 000000000 ____D C:\Users\scott\AppData\Local\chrome 2021-12-27 19:36 - 2021-12-27 19:36 - 000003172 _____ C:\WINDOWS\system32\Tasks\WD Device Agent Task scott 2021-12-18 01:27 - 2021-12-18 01:27 - 000000000 ____D C:\WINDOWS\SystemTemp 2021-12-18 01:25 - 2021-12-18 01:25 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe 2021-12-18 01:25 - 2021-12-18 01:25 - 000011979 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2021-12-18 01:24 - 2021-12-18 01:24 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe 2021-12-18 01:24 - 2021-12-18 01:24 - 000162816 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe 2021-12-18 01:19 - 2021-12-18 01:19 - 000000000 __HDC C:\$WinREAgent ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2022-01-09 17:39 - 2018-11-27 00:58 - 000000000 ___DC C:\Users\scott\AppData\Roaming\uTorrent 2022-01-09 17:31 - 2018-11-26 16:58 - 000000000 ___DC C:\Program Files (x86)\Google 2022-01-09 17:30 - 2021-03-14 18:18 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2022-01-09 15:24 - 2019-12-07 04:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2022-01-09 15:24 - 2019-12-07 04:13 - 000000000 ____D C:\WINDOWS\INF 2022-01-09 15:13 - 2021-03-14 18:25 - 000004168 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{441EDC59-0660-4121-9195-856D71242991} 2022-01-09 15:13 - 2019-12-07 04:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2022-01-09 12:25 - 2017-03-09 09:49 - 000000000 ___DC C:\ProgramData\NVIDIA 2022-01-09 12:22 - 2018-11-26 16:35 - 000000000 _SHDC C:\Users\scott\IntelGraphicsProfiles 2022-01-09 11:25 - 2018-11-26 19:07 - 000000000 ___DC C:\Users\scott\AppData\Roaming\vlc 2022-01-09 09:58 - 2018-11-27 05:11 - 000000000 ___DC C:\Users\scott\AppData\Roaming\discord 2022-01-09 09:58 - 2018-11-27 05:11 - 000000000 ___DC C:\Users\scott\AppData\Local\Discord 2022-01-09 00:33 - 2021-03-14 19:23 - 000842414 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2022-01-09 00:25 - 2021-03-14 18:25 - 000000006 ___HC C:\WINDOWS\Tasks\SA.DAT 2022-01-09 00:25 - 2021-03-14 18:18 - 000008192 ___SH C:\DumpStack.log.tmp 2022-01-09 00:25 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ServiceState 2022-01-09 00:25 - 2019-12-07 04:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2022-01-09 00:22 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated 2022-01-08 23:46 - 2018-11-26 21:55 - 000000000 ___DC C:\Users\scott\AppData\Local\D3DSCache 2022-01-08 07:03 - 2020-03-13 15:02 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2022-01-08 07:03 - 2019-12-07 04:14 - 000000000 ___HD C:\Program Files\WindowsApps 2022-01-08 07:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2022-01-06 03:16 - 2018-11-26 16:58 - 000002308 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2022-01-05 12:49 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2022-01-05 10:05 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2022-01-05 09:25 - 2018-11-30 01:32 - 000000000 ___DC C:\Users\scott\AppData\Local\CrashDumps 2022-01-05 04:08 - 2021-11-14 13:50 - 000000000 ___DC C:\Users\scott\AppData\LocalLow\uTorrent 2022-01-05 04:08 - 2019-04-13 02:55 - 000000000 ___DC C:\Users\scott\AppData\Local\BitTorrentHelper 2022-01-04 13:31 - 2019-01-05 23:35 - 000000000 ___DC C:\Users\scott\AppData\Local\UnrealEngine 2021-12-28 17:07 - 2018-11-29 15:38 - 000000000 ___DC C:\Users\scott\AppData\Roaming\WD Discovery 2021-12-28 17:07 - 2018-11-29 15:38 - 000000000 ___DC C:\Users\scott\.wdc 2021-12-27 23:05 - 2021-03-14 18:18 - 001338920 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2021-12-27 19:37 - 2018-11-29 15:39 - 000000000 ___DC C:\Program Files\WD Desktop App 2021-12-27 19:37 - 2017-03-09 09:48 - 000000000 ___DC C:\ProgramData\Package Cache 2021-12-27 19:36 - 2021-03-14 18:25 - 000003236 _____ C:\WINDOWS\system32\Tasks\WD Discovery Service Task scott 2021-12-27 19:36 - 2018-11-29 15:39 - 000000000 ___DC C:\Program Files (x86)\Western Digital 2021-12-27 19:36 - 2018-11-26 16:36 - 000000000 __RDC C:\Users\scott\OneDrive 2021-12-27 00:57 - 2021-03-14 09:50 - 000000000 ____D C:\Users\scott 2021-12-20 17:04 - 2019-08-30 05:36 - 000000000 ____D C:\Users\scott\AppData\Local\Rockstar Games 2021-12-20 17:01 - 2019-08-30 05:36 - 000000000 ____D C:\Program Files\Rockstar Games 2021-12-20 17:01 - 2019-08-30 05:36 - 000000000 ____D C:\Program Files (x86)\Rockstar Games 2021-12-20 10:09 - 2021-04-19 21:57 - 000000000 ____D C:\Users\scott\AppData\Local\T2GP Launcher 2021-12-18 17:56 - 2017-03-09 08:27 - 000000000 ___DC C:\Program Files (x86)\Microsoft Office 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SystemResources 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\setup 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\et-EE 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\es-MX 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\Provisioning 2021-12-18 01:27 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2021-12-16 16:44 - 2018-11-26 19:39 - 000000000 ___DC C:\WINDOWS\system32\MRT 2021-12-16 16:42 - 2018-11-26 19:39 - 137938848 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2021-12-15 19:49 - 2018-11-26 19:39 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2021-12-11 10:31 - 2021-03-24 19:52 - 000000000 ____D C:\WINDOWS\Minidump 2021-12-10 20:08 - 2021-04-26 03:47 - 000003386 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d719293b661bc7 2021-12-10 20:08 - 2021-03-14 18:25 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ======================== Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-12-2021 Ran by scott (09-01-2022 17:52:52) Running from C:\Users\scott\Downloads Microsoft Windows 10 Home Version 20H2 19042.1415 (X64) (2021-03-14 23:26:02) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= (If an entry is included in the fixlist, it will be removed.) Administrator (S-1-5-21-4096549371-2451222336-3956411163-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-4096549371-2451222336-3956411163-503 - Limited - Disabled) defaultuser0 (S-1-5-21-4096549371-2451222336-3956411163-1000 - Limited - Disabled) => C:\Users\defaultuser0 Guest (S-1-5-21-4096549371-2451222336-3956411163-501 - Limited - Disabled) scott (S-1-5-21-4096549371-2451222336-3956411163-1001 - Administrator - Enabled) => C:\Users\scott WDAGUtilityAccount (S-1-5-21-4096549371-2451222336-3956411163-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: ESET Security (Enabled - Up to date) {89B55CC4-3881-78B2-11E2-479AE0371896} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: ESET Firewall (Enabled) {B18EDDE1-72EE-79EA-3ABD-EEAF1EE45FED} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) [NarutoPlanet.ru] Bleach Heat The Soul 7 PC (HKLM-x32\...\[NarutoPlanet.ru] Bleach Heat The Soul 7 PC_is1) (Version: [NarutoPlanet.ru] Bleach Heat The Soul 7 PC - NarutoPlanet.ru) µTorrent (HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\uTorrent) (Version: 3.5.5.46096 - BitTorrent Inc.) 7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov) ACID Music Studio 10.0 (HKLM-x32\...\{0417C9E1-CBD4-11E3-A786-F04DA23A5C58}) (Version: 10.0.108 - Sony) Adobe Photoshop (HKLM-x32\...\Adobe Photoshop_is1) (Version: - www.g1wholesale.com) Adobe Photoshop Elements 6.0 (HKLM-x32\...\Adobe Photoshop Elements 6) (Version: 6.0 - Adobe Systems Inc.) BayHubTech Flash Memory Card Windows Driver (HKLM\...\{357682C3-2295-45C5-B7DD-8109E66656EC}) (Version: 3.4.00.30 - BayHub Technology LTD.) Hidden BayHubTech Flash Memory Card Windows Driver (HKLM-x32\...\InstallShield_{357682C3-2295-45C5-B7DD-8109E66656EC}) (Version: 3.4.00.30 - BayHub Technology LTD.) BCC 8 OFX 64Bit (HKLM\...\{6309B4F7-F571-44FB-A154-330BE4C57042}) (Version: 8.1.0301 - Boris FX, Inc.) CEP (Color Enable Package) v.9.2 (beta) (HKLM-x32\...\CEP - Colour Enable Packages_is1) (Version: 9.2 (beta) - Numenor, for ModTheSims2) Chess Ultra (HKLM-x32\...\Chess Ultra_is1) (Version: - ) Cities Skylines Campus (HKLM-x32\...\Cities Skylines Campus_is1) (Version: - ) Cities Skylines Modern City Center (HKLM-x32\...\Cities Skylines Modern City Center_is1) (Version: - ) Cities Skylines Sunset Harbor (HKLM-x32\...\Cities Skylines Sunset Harbor_is1) (Version: - ) Cities Skylines Train Stations (HKLM-x32\...\Cities Skylines Train Stations_is1) (Version: - ) Dead or Alive 6 (HKLM-x32\...\Dead or Alive 6_is1) (Version: - ) Discord (HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\Discord) (Version: 0.0.309 - Discord Inc.) Dolby Audio X2 Windows API SDK (HKLM\...\{AA950AA4-CD9B-4D81-B6C0-BFABB7A24261}) (Version: 0.7.5.65 - Dolby Laboratories, Inc.) Dolby Audio X2 Windows APP (HKLM\...\{D765CF7F-14F9-4C80-B06C-10E68F10EBCC}) (Version: 0.7.2.62 - Dolby Laboratories, Inc.) Dragon Ball FighterZ (HKLM-x32\...\Dragon Ball FighterZ_is1) (Version: - ) DVD Architect Studio 5.0 (HKLM-x32\...\{3822E74F-08F8-11E3-99EE-F04DA23A5C58}) (Version: 5.0.186 - Sony) EA Download Manager (HKLM-x32\...\EADM) (Version: 5.0.0.255 - Electronic Arts, Inc.) ESET Security (HKLM\...\{AE2CE1E7-D216-4BB2-B66B-E268F033A61A}) (Version: 15.0.21.0 - ESET, spol. s r.o.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 97.0.4692.71 - Google LLC) Intel® Chipset Device Software (HKLM-x32\...\{fb610cea-ba50-4d4b-a717-cf025419035c}) (Version: 10.1.1.13 - Intel® Corporation) Hidden Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1177 - Intel Corporation) Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 21.20.16.4526 - Intel Corporation) Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.0.1042 - Intel Corporation) Intel® Wireless Bluetooth® (HKLM-x32\...\{3920BCB0-23AA-4D0D-93E5-404692DAF9D2}) (Version: 19.00.1621.3340 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{bc883058-299e-461f-8e52-4f1dbb355f86}) (Version: 19.0.1 - Intel Corporation) iZotope Audio Enhancer (HKLM-x32\...\iZotope Audio Enhancer_is1) (Version: 1.00 - iZotope, Inc.) JUMP FORCE (HKLM-x32\...\JUMP FORCE_is1) (Version: - ) Jurassic World: Evolution (HKLM-x32\...\Jurassic World: Evolution_is1) (Version: - ) Just Cause 4 (HKLM-x32\...\{D1F33AFE-757B-4A27-9F96-D507177C3E40}_is1) (Version: - Avalanche Studios) Lenovo App Explorer (HKU\S-1-5-21-4096549371-2451222336-3956411163-1000\...\Host App Service) (Version: 0.273.2.941 - SweetLabs for Lenovo) <==== ATTENTION Lenovo Nerve Sense (HKLM\...\{DCB4DFB5-93CA-4BDD-9D08-CE880626B46E}_is1) (Version: 2.6.11.8 - Lenovo) Lenovo Settings - Power (HKLM-x32\...\{A6CFC34A-56EE-4AF5-8C49-995F59E6A160}) (Version: 2.00.000 - Lenovo) Lenovo System Interface Foundation Driver (HKLM\...\{C2E5CA37-C862-4A69-AC6D-24F450A20C16}) (Version: 1.1.17.1 - Lenovo) LenovoUtility (HKLM-x32\...\{6ADA7E88-8D16-4D0D-BC90-2B93AC5E56DA}) (Version: 3.0.0.4 - Lenovo) Hidden LenovoUtility (HKLM-x32\...\InstallShield_{6ADA7E88-8D16-4D0D-BC90-2B93AC5E56DA}) (Version: 3.0.0.4 - Lenovo) Malwarebytes version 4.5.0.152 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.0.152 - Malwarebytes) Malzbies Pinball Collection Ghouls (HKLM-x32\...\Malzbies Pinball Collection Ghouls_is1) (Version: - ) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 97.0.1072.55 - Microsoft Corporation) Microsoft Office Home and Student 2016 - en-us (HKLM\...\HomeStudentRetail - en-us) (Version: 16.0.14701.20262 - Microsoft Corporation) Microsoft Office Word 2007 (HKLM-x32\...\WORD) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{29B15818-E79F-4AB0-8938-9410C807AD76}) (Version: 2.84.0.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.28.29334 (HKLM-x32\...\{a9cfe9c7-e54f-46cd-9c5c-542ff8e3e8c4}) (Version: 14.28.29334.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29334 (HKLM-x32\...\{b2d0f752-adc5-496e-8f70-8669de01f746}) (Version: 14.28.29334.0 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Movie Studio Platinum 13.0 (64-bit) (HKLM\...\{402E168F-CC02-11E3-812F-F04DA23A5C58}) (Version: 13.0.932 - Sony) NARUTO SHIPPUDEN Ultimate Ninja STORM 4 Road to Boruto Next Generations (HKLM-x32\...\NARUTO SHIPPUDEN Ultimate Ninja STORM 4 Road to ~629813CA_is1) (Version: - ) NewBlue VideoFX for Sony Vegas MSPPS (HKLM\...\NewBlue VideoFX for Sony Vegas MSPPS) (Version: 2.0 - NewBlue) NewBlue VideoFX for Sony Vegas MSPPS (HKLM-x32\...\NewBlue VideoFX for Sony Vegas MSPPS) (Version: 2.0 - NewBlue) NVIDIA GeForce Experience 3.10.0.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.10.0.95 - NVIDIA Corporation) NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.14701.20262 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.14701.20248 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.14701.20262 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden OpenAL (HKLM-x32\...\OpenAL) (Version: - ) OpenIV (HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\OpenIV) (Version: 4.0.1.1452 - .black/OpenIV Team) PGA TOUR 2K21 (HKLM-x32\...\PGA TOUR 2K21_is1) (Version: - ) Pinball Arcade Season 1 to 7 Pro Packs (HKLM-x32\...\Pinball Arcade Season 1 to 7 Pro Packs_is1) (Version: - ) Pinball FX3 Williams Pinball Volume 5 (HKLM-x32\...\Pinball FX3 Williams Pinball Volume 5_is1) (Version: - ) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.9.422.2016 - Realtek) Revo Uninstaller 2.2.2 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.2.2 - VS Revo Group, Ltd.) Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.53.576 - Rockstar Games) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.0.9.3 - Rockstar Games) Saints Row - The Third (HKLM-x32\...\1430740694_is1) (Version: 2.0.0.4 - GOG.com) SanDisk Security (HKLM-x32\...\{189ff347-b978-4c66-88b6-30214ecb87a9}) (Version: 1.0.0.17 - Western Digital Technologies, Inc.) SanDisk Security (HKLM-x32\...\{3C6EE362-358C-41AB-8B54-0BBBE7DE837F}) (Version: 1.0.0.17 - Western Digital Technologies, Inc.) Hidden Sekiro Shadows Die Twice (HKLM-x32\...\Sekiro Shadows Die Twice_is1) (Version: - ) Sims 3 - Nude Censor Remover (HKLM-x32\...\xSIMS_Censor_Remover_TS3) (Version: - ) Sims 4 Studio (HKLM-x32\...\{870AA913-0774-4ED0-B144-BC2C0CBE4BA0}_is1) (Version: 3.1.3.3 - Sims 4 Studio) Sony Vocal Eraser (HKLM-x32\...\Sony Vocal Eraser_is1) (Version: 1.00 - iZotope, Inc.) Sound Forge Audio Studio 10.0 (HKLM-x32\...\{BC208D90-4643-11E3-987B-F04DA23A5C58}) (Version: 10.0.252 - Sony) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Street Fighter V Arcade Edition (HKLM-x32\...\Street Fighter V Arcade Edition_is1) (Version: - ) TEKKEN 7 Ultimate Edition (HKLM-x32\...\TEKKEN 7 Ultimate Edition_is1) (Version: - ) The Sims 4 v. 1.67.45.1020 (HKLM-x32\...\The Sims 4_is1) (Version: - ) The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts) The Sims™ 3 70s, 80s, & 90s Stuff (HKLM-x32\...\{E1868CAE-E3B9-4099-8C18-AA8944D336FD}) (Version: 17.0.77 - Electronic Arts) The Sims™ 3 Ambitions (HKLM-x32\...\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts) The Sims™ 3 Diesel Stuff (HKLM-x32\...\{1C9B6173-6DC9-4EEE-9EFC-6BA115CFBE43}) (Version: 14.0.48 - Electronic Arts) The Sims™ 3 Fast Lane Stuff (HKLM-x32\...\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}) (Version: 5.0.44 - Electronic Arts) The Sims™ 3 Generations (HKLM-x32\...\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts) The Sims™ 3 High-End Loft Stuff (HKLM-x32\...\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts) The Sims™ 3 Into the Future (HKLM-x32\...\{A0BBD6C7-B546-4048-B33A-F21F5C9F5B09}) (Version: 21.0.150 - Electronic Arts) The Sims™ 3 Island Paradise (HKLM-x32\...\{DB21639E-FE55-432C-BCA2-0C5249E3F79E}) (Version: 19.0.101 - Electronic Arts) The Sims™ 3 Katy Perry's Sweet Treats (HKLM-x32\...\{9B2506E3-9A3F-45B5-96BF-509CAD584650}) (Version: 13.0.62 - Electronic Arts) The Sims™ 3 Late Night (HKLM-x32\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts) The Sims™ 3 Master Suite Stuff (HKLM-x32\...\{08A25478-C5DD-4EA7-B168-3D687CA987FF}) (Version: 11.0.84 - Electronic Arts) The Sims™ 3 Movie Stuff (HKLM-x32\...\{D0087539-3C57-44E0-BEE7-D779D546CBE1}) (Version: 20.0.53 - Electronic Arts) The Sims™ 3 Outdoor Living Stuff (HKLM-x32\...\{117B6BF6-82C3-420C-B284-9247C8568E53}) (Version: 7.0.55 - Electronic Arts) The Sims™ 3 Pets (HKLM-x32\...\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts) The Sims™ 3 Seasons (HKLM-x32\...\{3DE92282-CB49-434F-81BF-94E5B380E889}) (Version: 16.0.136 - Electronic Arts) The Sims™ 3 Showtime (HKLM-x32\...\{3BBFD444-5FAB-49F6-98B1-A1954E831399}) (Version: 12.0.273 - Electronic Arts) The Sims™ 3 Supernatural (HKLM-x32\...\{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}) (Version: 15.0.135 - Electronic Arts) The Sims™ 3 Town Life Stuff (HKLM-x32\...\{7B11296A-F894-449C-8DF6-6AAAA7D4D118}) (Version: 9.0.73 - Electronic Arts) The Sims™ 3 University Life (HKLM-x32\...\{F26DE8EF-F2CF-40DC-8CDA-CC0D82D11B36}) (Version: 18.0.126 - Electronic Arts) The Sims™ 3 World Adventures (HKLM-x32\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts) Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{C99F4AFA-B32C-4063-865C-D7B5CC0A78FB}) (Version: 2.54.0.0 - Microsoft Corporation) UpdateAssistant (HKLM\...\{52C1DD03-104E-4AC6-9DC6-21D585721ED1}) (Version: 1.19.0.0 - Microsoft Corporation) Hidden Vegas Movie Studio HD 9.0 (HKLM-x32\...\{655CD886-3B90-4E4D-B314-92BDA9B08C86}) (Version: 9.0.30 - Sony) VLC media player (HKLM\...\VLC media player) (Version: 3.0.12 - VideoLAN) Vulkan Run Time Libraries 1.0.11.1 (HKLM\...\VulkanRT1.0.11.1) (Version: 1.0.11.1 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-3) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-4) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-5) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Watch Dogs Complete Edition MULTi19 - ElAmigos version 1.06.329 (HKLM-x32\...\{EC053F56-69AC-44BF-A227-F6CB1E35272D}_is1) (Version: 1.06.329 - UBISoft) Watch_Dogs 2 (HKLM-x32\...\Watch_Dogs 2_is1) (Version: - ) WD Desktop App 2.1.0.322 (HKLM-x32\...\{9478cae3-730b-4ffe-b22b-ae8b7787f5d5}) (Version: 2.1.0.322 - Western Digital Corporation) Hidden WD Desktop App 2.1.0.322 (x64) (HKLM\...\{CA7F7232-526E-41BD-971A-47BE28C18516}) (Version: 2.1.0.322 - Western Digital Corporation) Hidden WD Discovery (HKLM-x32\...\WDDiscovery) (Version: 4.3.336 - Western Digital Technologies, Inc.) WD SES Driver Setup (HKLM-x32\...\{924A274D-38B6-4930-8859-F3F51CFA8DDD}) (Version: 1.1.0.25 - Western Digital) Hidden WeMod (HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\WeMod) (Version: 7.1.16 - WeMod) Windows PC Health Check (HKLM\...\{B1E7D0FD-7CFE-4E0C-A5DA-0F676499DB91}) (Version: 3.2.2110.14001 - Microsoft Corporation) Packages: ========= BreeZip -> C:\Program Files\WindowsApps\3138AweZip.AweZip_1.4.8.0_x86__ffd303wmbhcjt [2021-08-17] (BreeZip) [MS Ad] Lenovo Settings -> C:\Program Files\WindowsApps\LenovoCorporation.LenovoSettings_3.177.0.0_x86__4642shxvsv8s2 [2021-11-16] (LENOVO INCORPORATED.) Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2112.10.0_x64__k1h2ywk1493x8 [2021-12-29] (LENOVO INC.) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-03-14] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-03-14] (Microsoft Corporation) [MS Ad] Microsoft Mahjong -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMahjong_4.1.11220.0_x64__8wekyb3d8bbwe [2021-12-07] (Microsoft Studios) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.11.12030.0_x64__8wekyb3d8bbwe [2021-12-11] (Microsoft Studios) [MS Ad] Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-08-08] (Microsoft Corporation) Real Chess Online -> C:\Program Files\WindowsApps\52833Alienforce.ChessFusionFree_3.25.0.0_x64__np5hvx4gj677g [2021-11-16] (Alienforce) Trio Office -> C:\Program Files\WindowsApps\64343GTDocStudio.OfficeDocOpener_3.2.24.0_x86__3h5nez1g3qt2c [2021-08-17] (GT Office PDF Studio) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) SSODL: WDFSMountNotificator-wdfsconnect2017 - {F91D11A8-8E29-408A-A9ED-D1B4CE29ECDF} - C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed] SSODL-x32: WDFSMountNotificator-wdfsconnect2017 - {F91D11A8-8E29-408A-A9ED-D1B4CE29ECDF} - C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed] ShellServiceObjects: Virtual Storage Mount Notification -> {F91D11A8-8E29-408A-A9ED-D1B4CE29ECDF} => C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed] ShellServiceObjects-x32: Virtual Storage Mount Notification -> {F91D11A8-8E29-408A-A9ED-D1B4CE29ECDF} => C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed] ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay01] -> {4F8A325E-9DAF-44B8-A825-1A14DFA0FA78} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay02] -> {0176BDDE-B59A-4A1E-808B-CAD461415CCA} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay03] -> {B65909D1-57AF-41F5-AB94-BEB733F62B35} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay04] -> {C6C2397D-8238-4332-8935-86C39C7C165F} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay05] -> {E7B3BCF9-0386-4B5F-AE6A-91B9F1423973} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay06] -> {564EA121-D9DA-485D-82C2-C2ED7BFCCEAD} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2021-12-08] (ESET, spol. s r.o. -> ESET) ContextMenuHandlers1: [WDDesktopContextMenu] -> {f351d8c9-ff13-3519-92fa-763cce46b27b} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2021-12-08] (ESET, spol. s r.o. -> ESET) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-01-05] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers4: [WDDesktopContextMenu] -> {f351d8c9-ff13-3519-92fa-763cce46b27b} => C:\Program Files\WD Desktop App\kda.DLL [2021-07-26] (Western Digital Technologies, Inc. -> Western Digital Corporation) ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxDTCM.dll [2018-05-07] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-01-15] (NVIDIA Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2021-12-08] (ESET, spol. s r.o. -> ESET) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-01-05] (Malwarebytes Corporation -> Malwarebytes) ==================== Codecs (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Drivers32: [vidc.VP60] => C:\WINDOWS\SysWOW64\vp6vfw.dll [447752 2014-09-16] (Electronic Arts -> On2.com) HKLM\...\Drivers32: [vidc.VP61] => C:\WINDOWS\SysWOW64\vp6vfw.dll [447752 2014-09-16] (Electronic Arts -> On2.com) ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= 2020-01-19 07:47 - 2019-02-21 11:00 - 000078336 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll 2020-04-17 12:19 - 2020-04-17 12:19 - 000000000 ___CL (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\AppVIsvSubsystems32.dll 2020-04-17 12:19 - 2020-04-17 12:19 - 000000000 ___CL (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\c2r32.dll ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ========== HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17swin10.msn.com/?pc=LSJE HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.toshiba.com SearchScopes: HKU\S-1-5-21-4096549371-2451222336-3956411163-1001 -> DefaultScope {BBBC899D-85F0-447B-89ED-F68FBA315D38} URL = SearchScopes: HKU\S-1-5-21-4096549371-2451222336-3956411163-1001 -> {BBBC899D-85F0-447B-89ED-F68FBA315D38} URL = BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2021-10-31] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-31] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-31] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-31] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-31] (Microsoft Corporation -> Microsoft Corporation) ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2016-07-16 06:47 - 2022-01-05 13:19 - 000000824 ____C C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-4096549371-2451222336-3956411163-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\Control Panel\Desktop\\Wallpaper -> E:\Anime and Yaoi\dabi (26).jpeg DNS Servers: 209.18.47.61 - 209.18.47.63 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) HKLM\...\StartupApproved\Run: => "WinZip PreLoader" HKLM\...\StartupApproved\Run32: => "Adobe Photo Downloader" HKLM\...\StartupApproved\Run32: => "WDDiscovery" HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\StartupApproved\Run: => "OneDriveSetup" HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\StartupApproved\Run: => "uTorrent" HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\StartupApproved\Run: => "Discord" HKU\S-1-5-21-4096549371-2451222336-3956411163-1001\...\StartupApproved\Run: => "ShutterflyStudio" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{578CED8D-A937-4408-85B1-057D819CDDE9}] => (Allow) D:\Steam Games\Steam\steamapps\common\Zaccaria Pinball\ZaccariaPinball.exe () [File not signed] FirewallRules: [{6291D1CC-6C69-4971-80F3-D6F51869054B}] => (Allow) D:\Steam Games\Steam\steamapps\common\Zaccaria Pinball\ZaccariaPinball.exe () [File not signed] FirewallRules: [UDP Query User{02A6B425-F016-4A10-9DD3-EBD3447F85D8}E:\games\the sims 4\game\bin_le\ts4.exe] => (Block) E:\games\the sims 4\game\bin_le\ts4.exe (Electronic Arts Inc.) [File not signed] FirewallRules: [TCP Query User{604C14CD-E578-4F53-A635-3F9369D476E2}E:\games\the sims 4\game\bin_le\ts4.exe] => (Block) E:\games\the sims 4\game\bin_le\ts4.exe (Electronic Arts Inc.) [File not signed] FirewallRules: [{B4135EB5-8A74-4C8A-9E8C-2D88FEA394C8}] => (Allow) D:\Steam Games\Steam\steamapps\common\L.A.Noire\LANLauncher.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{8CC87BE0-A341-498A-99DC-1005713C94CD}] => (Allow) D:\Steam Games\Steam\steamapps\common\L.A.Noire\LANLauncher.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{0D49990D-62BD-4859-A700-3469F2224838}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia II Definitive Edition\pc\Mafia2Launcher\Launcher.exe (2K Games) [File not signed] FirewallRules: [{0037A64F-6418-4B28-99AA-4CEC6632E396}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia II Definitive Edition\pc\Mafia2Launcher\Launcher.exe (2K Games) [File not signed] FirewallRules: [{52177A74-62B9-4CD0-8860-620E281BB1CA}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia Definitive Edition\launcher.exe (2K Games) [File not signed] FirewallRules: [{EAB8B3F6-5224-4110-B901-8BAE79D593DF}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia Definitive Edition\launcher.exe (2K Games) [File not signed] FirewallRules: [UDP Query User{9DBA000A-E130-4AFE-820E-97F92B406617}E:\games\the sims 4\game\bin\ts4_x64.exe] => (Allow) E:\games\the sims 4\game\bin\ts4_x64.exe (Electronic Arts Inc.) [File not signed] FirewallRules: [TCP Query User{2093F737-F84F-4B39-BF95-D6BDCEDAEFBC}E:\games\the sims 4\game\bin\ts4_x64.exe] => (Allow) E:\games\the sims 4\game\bin\ts4_x64.exe (Electronic Arts Inc.) [File not signed] FirewallRules: [{6D355FBE-AE23-4E76-9BE1-415F370A40AF}] => (Allow) D:\Steam Games\Steam\steamapps\common\My Hero Ones Justice 2\HeroGame\Binaries\Win64\MHOJ2.exe (BNEI) [File not signed] FirewallRules: [{05A799FE-E82A-42F7-B1CD-C27EB1F737EB}] => (Allow) D:\Steam Games\Steam\steamapps\common\My Hero Ones Justice 2\HeroGame\Binaries\Win64\MHOJ2.exe (BNEI) [File not signed] FirewallRules: [{FA3B11CD-BDE4-474D-8BBC-A864BDF57DC6}] => (Allow) D:\Steam Games\Steam\steamapps\common\ONE PUNCH MAN A HERO NOBODY KNOWS\ONE PUNCH MAN A HERO NOBODY KNOWS.exe (EasyAntiCheat Oy -> Epic Games, Inc) FirewallRules: [{770ABD07-908B-4038-9E2B-43AA5247C36A}] => (Allow) D:\Steam Games\Steam\steamapps\common\ONE PUNCH MAN A HERO NOBODY KNOWS\ONE PUNCH MAN A HERO NOBODY KNOWS.exe (EasyAntiCheat Oy -> Epic Games, Inc) FirewallRules: [{54D3C906-730A-4545-BE80-5D37F4EF3442}] => (Allow) D:\Steam Games\Steam\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{DE8E5125-E4FF-4B84-A9C7-57694D8C872B}] => (Allow) D:\Steam Games\Steam\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [UDP Query User{406E7D4C-5313-4DC8-9788-8C5326B8574A}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN) FirewallRules: [TCP Query User{BE965456-0BA7-49A3-AF32-CA675905D022}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN) FirewallRules: [{8C765058-EBDC-49C7-AFB3-9A9553C97CB0}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia III\launcher.exe (2K Games) [File not signed] FirewallRules: [{4F6ECDF4-A6A3-4A45-83C0-D18FE400D7C7}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia III\launcher.exe (2K Games) [File not signed] FirewallRules: [UDP Query User{92AB6788-F44B-43E7-A6D7-6A207EE5E7F2}D:\steam games\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam games\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [TCP Query User{78BEB908-31AD-40B8-B653-C42436652223}D:\steam games\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam games\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{886BA011-EE86-44DF-8738-8D6AC580EB09}] => (Allow) D:\Steam Games\Steam\steamapps\common\Planet Coaster\PlanetCoaster.exe (Frontier Developments) [File not signed] FirewallRules: [{F516BCD2-EF46-48D4-A27C-D0C977AE8E21}] => (Allow) D:\Steam Games\Steam\steamapps\common\Planet Coaster\PlanetCoaster.exe (Frontier Developments) [File not signed] FirewallRules: [{781E1F98-B0F2-4D7F-8A3D-051798C394C8}] => (Allow) D:\Steam Games\Steam\steamapps\common\Yu-Gi-Oh! Duel Links\dlpc.exe () [File not signed] FirewallRules: [{2BB30453-D433-4B87-9B94-3B7456347913}] => (Allow) D:\Steam Games\Steam\steamapps\common\Yu-Gi-Oh! Duel Links\dlpc.exe () [File not signed] FirewallRules: [{AE29D15C-8257-4C4E-9774-2BF93DCBBA28}] => (Allow) D:\Steam Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{6BAE6C46-018F-42DB-A00E-48672377063D}] => (Allow) D:\Steam Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{573DFEFD-8D8C-4804-9C5C-D44AAE79007C}] => (Allow) D:\Steam Games\Steam\Steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{29C7D96E-AA89-4034-A699-7405B485E321}] => (Allow) D:\Steam Games\Steam\Steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [UDP Query User{9837C1F5-F109-4F33-888C-1E4CFEC2F604}C:\program files (x86)\electronic arts\eadm\core.exe] => (Allow) C:\program files (x86)\electronic arts\eadm\core.exe (Electronic Arts) [File not signed] FirewallRules: [TCP Query User{F966D549-DC83-452A-85EA-DCA2C8C9812D}C:\program files (x86)\electronic arts\eadm\core.exe] => (Allow) C:\program files (x86)\electronic arts\eadm\core.exe (Electronic Arts) [File not signed] FirewallRules: [{AE8C34BC-ACB4-4A43-A2D0-82C09EDC7509}] => (Allow) C:\Users\scott\AppData\Roaming\uTorrent\uTorrent.exe => No File FirewallRules: [{B9428937-3308-43EB-9441-118E34FAB86F}] => (Allow) C:\Users\scott\AppData\Roaming\uTorrent\uTorrent.exe => No File FirewallRules: [{D6F58F83-5AD4-4378-8891-1F4973B6C7B7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{641BCB6F-2207-45E6-B0F1-9B3D9ABF9572}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{7D6BC653-B637-4D69-95CB-29F6A129AAE8}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation-Wireless Connectivity Solutions -> ) FirewallRules: [{953B4BB5-ADAD-45B8-9417-0386DDD6AB06}] => (Allow) D:\Steam Games\Steam\steamapps\common\Nioh\nioh_launcher.exe (KOEI TECMO GAMES CO., LTD. -> KOEI TECMO GAMES CO., LTD.) FirewallRules: [{4859D924-6225-4BDB-A0FA-B9E39FC3BA07}] => (Allow) D:\Steam Games\Steam\steamapps\common\Nioh\nioh_launcher.exe (KOEI TECMO GAMES CO., LTD. -> KOEI TECMO GAMES CO., LTD.) FirewallRules: [{2BB97784-7268-46DD-BD51-690864A2618B}] => (Allow) D:\Steam Games\Steam\steamapps\common\Nioh\nioh.exe (KOEI TECMO GAMES CO., LTD. -> KOEI TECMO GAMES CO., LTD.) FirewallRules: [{D0C6C47C-91B5-48F3-AE47-704B8B1B0EC3}] => (Allow) D:\Steam Games\Steam\steamapps\common\Nioh\nioh.exe (KOEI TECMO GAMES CO., LTD. -> KOEI TECMO GAMES CO., LTD.) FirewallRules: [{3F982B6F-B0DA-4B18-9B5C-EF6315C042A5}] => (Allow) D:\Steam Games\Steam\steamapps\common\SleepingDogsDefinitiveEdition\sdhdship.exe (SQUARE ENIX LIMITED) [File not signed] FirewallRules: [{66E15689-61A5-46C1-BA9D-29FD324CB7B6}] => (Allow) D:\Steam Games\Steam\steamapps\common\SleepingDogsDefinitiveEdition\sdhdship.exe (SQUARE ENIX LIMITED) [File not signed] FirewallRules: [{FA3A1A9E-DB6D-4D5F-8FD9-9855C4F295B0}] => (Allow) D:\Steam Games\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{93CCCBFC-269A-40DD-B434-2A00A9B40F61}] => (Allow) D:\Steam Games\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{F02AE2B9-D9BA-40F2-BD17-5431AC894E0D}] => (Allow) D:\Steam Games\Steam\steamapps\common\Planet Zoo\PlanetZoo.exe (Frontier Developments) [File not signed] FirewallRules: [{D70E4A50-4A25-4201-AF64-C2536B42B121}] => (Allow) D:\Steam Games\Steam\steamapps\common\Planet Zoo\PlanetZoo.exe (Frontier Developments) [File not signed] FirewallRules: [{86AC83B3-384B-4CD3-8ABB-1F26D629C7F9}] => (Allow) D:\Steam Games\Steam\steamapps\common\L.A.Noire\PlayLAN.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{82220C68-D0B3-4F79-952F-D29F762EAE34}] => (Allow) D:\Steam Games\Steam\steamapps\common\L.A.Noire\PlayLAN.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{579E5E5A-5694-4144-B6D4-E867C0324EDF}] => (Allow) D:\Steam Games\Steam\steamapps\common\Star Wars - The Old Republic\launcher.exe (Electronic Arts, Inc. -> BioWare) FirewallRules: [{1B3D4663-8D48-48C1-85AE-09059E824526}] => (Allow) D:\Steam Games\Steam\steamapps\common\Star Wars - The Old Republic\launcher.exe (Electronic Arts, Inc. -> BioWare) FirewallRules: [TCP Query User{AB585D3A-4EED-4A8D-A58F-08AF49CBD498}C:\windows\system32\sihost.exe] => (Block) C:\windows\system32\sihost.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [UDP Query User{CFDA8192-A06C-489B-A133-72673C347932}C:\windows\system32\sihost.exe] => (Block) C:\windows\system32\sihost.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{C73E5409-6D65-4BF7-AEB8-0C81987349D9}] => (Allow) D:\Steam Games\Steam\steamapps\common\SoulcaliburVI\SoulcaliburVI\Binaries\Win64\SoulcaliburVI.exe () [File not signed] FirewallRules: [{0EAC40C6-0777-4281-8776-23DBCF7805A4}] => (Allow) D:\Steam Games\Steam\steamapps\common\SoulcaliburVI\SoulcaliburVI\Binaries\Win64\SoulcaliburVI.exe () [File not signed] FirewallRules: [{E2BBE992-93F2-4595-B06E-A3704F657A73}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia Definitive Edition\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{EC0E51E5-C765-4D4C-BE1F-558CFB6C6687}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia Definitive Edition\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{7D417A1F-DA81-45C3-879B-D4F9EB6D9C3A}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia II Definitive Edition\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{6734A3D0-7BFD-4312-91CF-0F2F88428F02}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia II Definitive Edition\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{1CC14F77-1E7E-4773-A2DD-8E6982DBB59B}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia III\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{C0329008-F391-4EC3-86A9-B3E93735AE5F}] => (Allow) D:\Steam Games\Steam\steamapps\common\Mafia III\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{17BB9C1B-5E37-4864-BD3A-BC92F3CF852C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{986D468F-8400-4C47-80F3-6885F54E10F3}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{043E91F9-2F63-47EE-ADD1-65B5309AAEBB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{7C3900C1-2E0F-4803-A235-C056EED61DFA}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{424F5783-378D-4B77-84B1-9965513DB332}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) ==================== Restore Points ========================= ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (01/09/2022 04:39:57 PM) (Source: Microsoft Security Client) (EventID: 3002) (User: ) Description: Event-ID 3002 Error: (01/09/2022 04:39:57 PM) (Source: Microsoft Security Client) (EventID: 2002) (User: ) Description: Event-ID 2002 Error: (01/09/2022 04:39:57 PM) (Source: Microsoft Security Client) (EventID: 2003) (User: ) Description: Event-ID 2003 Error: (01/09/2022 04:23:27 PM) (Source: Microsoft Security Client) (EventID: 3002) (User: ) Description: Event-ID 3002 Error: (01/09/2022 04:23:27 PM) (Source: Microsoft Security Client) (EventID: 2002) (User: ) Description: Event-ID 2002 Error: (01/09/2022 04:23:27 PM) (Source: Microsoft Security Client) (EventID: 2003) (User: ) Description: Event-ID 2003 Error: (01/09/2022 12:16:20 AM) (Source: VSS) (EventID: 8194) (User: ) Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied. . This is often caused by incorrect security settings in either the writer or requestor process. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {a6689664-af35-4900-a771-c6d90662b486} Error: (01/05/2022 01:19:33 PM) (Source: SecurityCenter) (EventID: 17) (User: ) Description: Security Center failed to validate caller with error %1. System errors: ============= Error: (01/09/2022 04:51:45 PM) (Source: volsnap) (EventID: 36) (User: ) Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. Error: (01/09/2022 08:38:41 AM) (Source: Netwtw06) (EventID: 5005) (User: ) Description: Intel® Dual Band Wireless-AC 8260 : Has encountered an internal error and has failed. 5005 - Driver internal error Error: (01/09/2022 08:38:41 AM) (Source: Netwtw06) (EventID: 5035) (User: ) Description: 5035 - Driver OSC Pending OID watchdog Error: (01/09/2022 08:38:41 AM) (Source: Netwtw06) (EventID: 5002) (User: ) Description: Intel® Dual Band Wireless-AC 8260 : Has determined that the network adapter is not functioning properly. 5002 - uCode SW error (SysAssert, NMI) Error: (01/09/2022 12:25:30 AM) (Source: Application Popup) (EventID: 56) (User: ) Description: ACPI5 Error: (01/09/2022 12:25:12 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Microsoft Defender Antivirus Network Inspection Service service failed to start due to the following error: The service did not start due to a logon failure. Error: (01/09/2022 12:25:12 AM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: The WdNisSvc service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The request is not supported. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC). Error: (01/09/2022 12:25:10 AM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16392) (User: NT AUTHORITY) Description: The BITS service failed to start. Error 2147500053. Windows Defender: ================Event[0]: Date: 2022-01-09 00:25:12 Description: Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed. Feature: Network Inspection System Error Code: 0x8007042d Error description: The service did not start due to a logon failure. Reason: The system is missing updates that are required for running Network Inspection System. Install the required updates and restart the device. CodeIntegrity: =============== Date: 2022-01-09 17:26:38 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2022-01-09 17:26:38 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\drivers\iaStorA.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== BIOS: LENOVO CDCN53WW 09/19/2016 Motherboard: LENOVO Allsparks 7A Processor: Intel® Core i7-6700HQ CPU @ 2.60GHz Percentage of memory in use: 27% Total physical RAM: 32595.78 MB Available physical RAM: 23732.12 MB Total Virtual: 37459.78 MB Available Virtual: 27371.61 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:118 GB) (Free:24.04 GB) NTFS Drive d: () (Fixed) (Total:931.39 GB) (Free:174.19 GB) NTFS Drive e: (My Passport) (Fixed) (Total:1862.98 GB) (Free:613.23 GB) NTFS Drive f: (Extreme SSD) (Fixed) (Total:3725.97 GB) (Free:3098.37 GB) exFAT \\?\Volume{6928a397-e5f4-4365-8811-35087e280745}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.47 GB) NTFS \\?\Volume{04942020-540b-4f93-8db9-06578ad813d0}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32 ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (Size: 119.2 GB) (Disk ID: 3ADB3DF5) Partition: GPT. ========================================================== Disk: 1 (Size: 931.5 GB) (Disk ID: 61994A64) Partition: GPT. ========================================================== Disk: 2 (Size: 3726 GB) (Disk ID: 16F2A91F) Partition: GPT. ========================================================== Disk: 3 (Size: 1863 GB) (Disk ID: 16F2A91F) Partition: GPT. ==================== End of Addition.txt =======================
Back to top
#13
polskamachina
polskamachina -
- Malware Response Team
- 5,965 posts
- OFFLINE
- Gender:Male
- Location:California
- Local time:10:59 AM
Posted 09 January 2022 - 11:28 PM
Hi DominoPunkyHeart
Did your ESET scan report any detections? If not, we can proceed to the finishing steps.
polskamachina
If I have made your computing life easier, please consider making a contribution.
Back to top
#14
DominoPunkyHeart
DominoPunkyHeart - Topic Starter
-
- Members
- 10 posts
- OFFLINE
- Local time:01:59 PM
Posted 09 January 2022 - 11:54 PM
Hi polskamachina ![]()
No the ESET scan didn't report anything. I did however, have a problem with Malwarebytes being installed on my computer and it recognized the quarantine items in Malwarebytes previous scan logs back when it cleared them off my computer. It didn't seem to find any new problems and the scan was clean.
-DominoPunkyHeart
Back to top
#15
polskamachina
polskamachina -
- Malware Response Team
- 5,965 posts
- OFFLINE
- Gender:Male
- Location:California
- Local time:10:59 AM
Posted 10 January 2022 - 04:21 PM
Hi DominoPunkyHeart
I noticed that both Malwarebytes and ESET antivirus programs are both enabled. In theory, they're supposed to behave nicely together but if it were my machine, I would choose one and stick with that. Next:
It didn't seem to find any new problems and the scan was clean.
That's good news. Glad to hear you're back up to speed now. Your computer appears to be all clean.
Please continue with the following steps that will remove all the diagnostic tools you used to scan and clean your system.
- Download KpRm by Kernel-Panik and save it to your desktop
- Right-click kprm_2.9.3.exe and select Run as Administrator
- Read and accept the disclaimer
- When the tool opens, ensure all boxes under Actions are checked
- Under Delete quarantines select Delete now, then click Run
- Once complete, click OK.
- A log will open in Notepad named kprm-(date).txt.
- Please copy and paste the contents of that file into your next reply to me
Let me know if you have any questions. polskamachina
If I have made your computing life easier, please consider making a contribution.
Back to top
- Page 1 of 2
- 1
- 2
- Next
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users
Reply to quoted posts Clear
-
- Help
| Advertise | About Us | Terms of Use | Privacy Policy | Sitemap | Chat | RSS Feeds | Contact Us |
| Tech Support Forums | Virus Removal Guides | Downloads | Tutorials | The Computer Glossary | Uninstall List | Startups |
Community Forum Software by IP.Board
Sign In
Use Twitter
- Need an account? Register now!
- Username
- Forum Password I've forgotten my password
- Remember me This is not recommended for shared computers
- Sign in anonymously Don't add me to the active users list
- Privacy Policy
Từ khóa » Google Chrome.lnk Là Gì
-
Cách Diệt Virus Shortcut - Giúp Máy Tính Hoạt động Trở Lại Bình Thường
-
Win32/Wacapew.C!ml Cannot Remove - Virus, Trojan, Spyware, And ...
-
Folder Keeps Reappearing After Delete - Virus, Trojan, Spyware, And ...
-
Simone Biles Out Of Tokyo Olympics Gymnastics Team Final Due To ...
-
Jason Derulo 'worried' He'd Lose Sex Symbol Status After Becoming A ...
-
Serial Inventor Offers Tips & Discounts For InventorSpot Readers
This topic is locked
Addition.txt
Back to top





