Quantcast
Channel: Spybot Forums
Viewing all 7590 articles
Browse latest View live

Spybot located virus Gen:Variant.Jaik.16274.

$
0
0
After I have spybot delete the file I rescanned and it was back. This is the location: C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.1.3842.0_x64__rz1tebttyb220\Assets\RadarHost

Here is FRST: FRST.txt

The "Addition.txt file was 1kb too large for the attachements manager so I copied and pasted it below.
Got error from aswmbr virtualization technology question after clicking yes and computer was restarted twice, so I then clicked no.
Then got error and computer restart after clicking scan twice, Stop code: DRIVER_IRQL_NOT_LESS_OR_EQUAL aswMBR.sys, so I have no log file to post for that program.

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-12-2019
Ran by Alexa (30-12-2019 20:21:16)
Running from C:\Users\Alexa\Desktop
Windows 10 Home Version 1903 18362.535 (X64) (2019-07-27 23:16:41)
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-3759400987-4214920439-3437108526-500 - Administrator - Disabled)
Alexa (S-1-5-21-3759400987-4214920439-3437108526-1003 - Administrator - Enabled) => C:\Users\Alexa
Brandon (S-1-5-21-3759400987-4214920439-3437108526-1004 - Administrator - Enabled) => C:\Users\Brandon
DefaultAccount (S-1-5-21-3759400987-4214920439-3437108526-503 - Limited - Disabled)
Guest (S-1-5-21-3759400987-4214920439-3437108526-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-3759400987-4214920439-3437108526-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Spybot - Search and Destroy (Enabled - Up to date) {F77C7796-45C4-531E-0DAE-B4A8229B11C8}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {4C1D9672-63FE-5C90-371E-8FDA591C5B75}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.021.20061 - Adobe Systems Incorporated)
Apple Application Support (32-bit) (HKLM-x32\...\{C3A282C9-4C8B-4A63-B449-3A064FB378D7}) (Version: 8.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{CC046FB9-E84E-4092-B924-DBE33DA2BE75}) (Version: 8.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{6CECF0FB-EE71-4FE5-8AE0-FA007408934A}) (Version: 13.0.0.38 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A3985C05-7386-411F-A4BF-32A73F37EB44}) (Version: 2.6.3.1 - Apple Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CPUID CPU-Z 1.86 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.86 - CPUID, Inc.)
Diablo II (HKLM-x32\...\Diablo II) (Version: - )
Documentation Manager (HKLM\...\{3EF18AD4-8F08-42FE-B2A4-F2DDB1DFB5D0}) (Version: 21.50.1.1 - Intel Corporation) Hidden
Intel Driver && Support Assistant (HKLM-x32\...\{3EAAD5EA-1D87-442D-8426-FD4FCE62119D}) (Version: 19.12.50.5 - Intel) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel(R) Corporation) Hidden
Intel(R) Computing Improvement Program (HKLM\...\{D40D4164-EEDB-4F0F-85C6-2058A9E34CC7}) (Version: 2.4.04370 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1036 - Intel Corporation)
Intel(R) Online Connect Software Asset Manager (HKLM-x32\...\{AE956AB9-CD98-4F1E-8B9E-C3C66E290D64}) (Version: 3.4.2072 - Intel Corporation) Hidden
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000050-0210-1033-84C8-B8D95FA3C8C3}) (Version: 21.50.0.1 - Intel Corporation)
Intel® Driver & Support Assistant (HKLM-x32\...\{8d174f37-ea1a-4e4d-be82-c10521a3c687}) (Version: 19.12.50.5 - Intel)
Intel® PROSet/Wireless Software (HKLM-x32\...\{6aa2484c-1a35-428e-a857-8ee0a874d2d1}) (Version: 20.110.0 - Intel Corporation)
Intel® Software Guard Extensions Platform Software (HKLM\...\{2DF17C75-9627-4213-8612-17955E92F782}) (Version: 1.6.101.32869 - Intel Corporation)
Intel® Software Installer (HKLM-x32\...\{e2b4037f-6ffc-4200-8b24-fdc8512f0dc9}) (Version: 21.50.1.1 - Intel Corporation) Hidden
iTunes (HKLM\...\{9C96D8AC-EE43-4B47-877C-D11595511C8E}) (Version: 12.10.3.1 - Apple Inc.)
LibreOffice 5.4.2.2 (HKLM\...\{71F5B603-BA9F-41E1-BC94-9839DFE5A83E}) (Version: 5.4.2.2 - The Document Foundation)
Microsoft Office Home and Student 2016 - en-us (HKLM\...\HomeStudentRetail - en-us) (Version: 16.0.12228.20364 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.11.25325 (HKLM-x32\...\{6c6356fe-cbfa-4944-9bed-a9e99f45cb7a}) (Version: 14.11.25325.0 - Microsoft Corporation)
Mozilla Firefox 71.0 (x64 en-US) (HKLM\...\Mozilla Firefox 71.0 (x64 en-US)) (Version: 71.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 55.0.3 - Mozilla)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.19 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 3.20.1.57 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.20.1.57 - NVIDIA Corporation)
NVIDIA Graphics Driver 441.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 441.41 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.38.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.21 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.12228.20364 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.12228.20364 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.12228.20364 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.10.714.2016 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8010 - Realtek Semiconductor Corp.)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.7.64.0 - Safer-Networking Ltd.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 3.5.3 - Tweaking.com)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22243 - Microsoft Corporation)
WinRAR 5.50 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)

Packages:
=========
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-07] (Autodesk Inc.)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.1.3842.0_x64__rz1tebttyb220 [2019-12-18] (Dolby Laboratories)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_105.1.623.0_x64__v10z8vjag6ke6 [2019-11-15] (HP Inc.)
March of Empires: War of Lords -> C:\Program Files\WindowsApps\A278AB0D.MarchofEmpires_4.5.1.3_x86__h6adky7gbf63m [2019-12-18] (Gameloft.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-13] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-13] (Microsoft Corporation) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.34.13393.0_x64__8wekyb3d8bbwe [2019-12-18] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.5.12061.0_x64__8wekyb3d8bbwe [2019-12-11] (Microsoft Studios) [MS Ad]
Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.14.105.0_x64__8wekyb3d8bbwe [2019-12-22] (Microsoft Studios)
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.34.13393.0_x64__8wekyb3d8bbwe [2019-12-18] (Microsoft Corporation) [MS Ad]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003_Classes\CLSID\{233525e0-5434-46ef-b464-fd7e45e2e145}\localserver32 -> C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe (IDSA Production signing key -> Intel)
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2019-11-20] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2016-09-14 12:51 - 2016-09-14 12:51 - 000000000 ____L (Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\AppVIsvSubsystems64.dll
2016-09-14 12:51 - 2016-09-14 12:51 - 000000000 ____L (Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\c2r64.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

There are 7943 more sites.

IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\123simsen.com -> www.123simsen.com

There are 7946 more sites.


==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2016-07-16 06:47 - 2019-09-10 19:47 - 000455006 ____R C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com

There are 15616 more lines.

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\Alexa\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 209.18.47.61 - 209.18.47.62
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Intel(R) Technology Access Filter Driver -> nt_ndisrd (enabled)
Wi-Fi: Intel(R) Technology Access Filter Driver -> nt_ndisrd (enabled)

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKU\S-1-5-21-3759400987-4214920439-3437108526-1003\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{F859A27E-5B42-43FC-8254-B74485E98E86}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\RESIDENT EVIL 2 BIOHAZARD RE2\re2.exe (CAPCOM CO., LTD. -> )
FirewallRules: [{FF41A1A5-7710-4190-AA62-BA4392ABFE48}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\RESIDENT EVIL 2 BIOHAZARD RE2\re2.exe (CAPCOM CO., LTD. -> )
FirewallRules: [{A9141E70-0AF7-4B28-98E9-DF012F0D761E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Frostpunk\Frostpunk.exe (Marek Ziemak -> 11 bit studios S.A.)
FirewallRules: [{DDE52180-00FF-4DCF-A584-9C3C9D3FB55A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Frostpunk\Frostpunk.exe (Marek Ziemak -> 11 bit studios S.A.)
FirewallRules: [{01E02995-A6DD-45DB-BC09-77F733EAE0DB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Talos Principle\Bin\x64\Talos_Unrestricted.exe (GHI Media LLC -> Croteam)
FirewallRules: [{4FC02FE4-A1F1-47A0-B7B4-21080EAFBEF1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Talos Principle\Bin\x64\Talos_Unrestricted.exe (GHI Media LLC -> Croteam)
FirewallRules: [{3388E838-C71D-4F18-A095-93C890CE0F0B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Talos Principle\Bin\x64\Talos.exe (GHI Media LLC -> Croteam)
FirewallRules: [{C523494F-F21E-462E-BC6E-6C8409BDAD11}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Talos Principle\Bin\x64\Talos.exe (GHI Media LLC -> Croteam)
FirewallRules: [{0A6123E5-01ED-4897-8B5A-C0041D3F57D9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Pathologic\Pathologic.exe () [File not signed]
FirewallRules: [{8DD6DFDB-827F-42A9-9B43-1EA738E7E6AB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Pathologic\Pathologic.exe () [File not signed]
FirewallRules: [{C74A7378-3DCF-448D-B642-C51621E69B52}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grimoire_Heralds_of_the_Winged_Exemplar\Grimoire.exe () [File not signed]
FirewallRules: [{E9870213-CED6-4AB0-887F-0FF094CD2A02}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grimoire_Heralds_of_the_Winged_Exemplar\Grimoire.exe () [File not signed]
FirewallRules: [{C097F00F-B588-48E9-9330-B2B2121FDC93}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ObraDinn\ObraDinn.exe () [File not signed]
FirewallRules: [{80CB594D-067F-480D-BA4C-D4AB7EC00FB9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ObraDinn\ObraDinn.exe () [File not signed]
FirewallRules: [{46E78626-78AD-48C3-A4A3-4B92944CBC8A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Talos Principle\Bin\Talos_Unrestricted.exe No File
FirewallRules: [{C0AEE527-2C6A-441E-9F71-D545ED7457F6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Talos Principle\Bin\Talos_Unrestricted.exe No File
FirewallRules: [{ACAFA4F6-E7CF-4C0E-9C9D-659DFC665859}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Talos Principle\Bin\Talos.exe No File
FirewallRules: [{FFEB8FA8-CA7F-4DC4-964C-EECC7A62EF5E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Talos Principle\Bin\Talos.exe No File
FirewallRules: [{47986002-6662-4BAA-B5F7-A805F25B1351}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Path of Exile\PathOfExileSteam.exe (Grinding Gear Games Limited -> )
FirewallRules: [{A786B2A0-040C-4788-A316-59D2278B2EF3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Path of Exile\PathOfExileSteam.exe (Grinding Gear Games Limited -> )
FirewallRules: [{95A24584-F7AB-4C47-B96F-ECEA35A7D835}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Undertale\UNDERTALE.exe (Toby Fox ) [File not signed]
FirewallRules: [{1F27FB1F-4CBF-458F-82B2-215C574ADAA6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Undertale\UNDERTALE.exe (Toby Fox ) [File not signed]
FirewallRules: [UDP Query User{D81C456C-B69A-4484-AB02-A50A63D42CC0}C:\program files (x86)\steam\steamapps\common\phantomdoctrine\iwtb\binaries\win64\iwtb-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\phantomdoctrine\iwtb\binaries\win64\iwtb-win64-shipping.exe (CreativeForge Games) [File not signed]
FirewallRules: [TCP Query User{038FBC86-6F78-4DEF-992C-6B036E1A0376}C:\program files (x86)\steam\steamapps\common\phantomdoctrine\iwtb\binaries\win64\iwtb-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\phantomdoctrine\iwtb\binaries\win64\iwtb-win64-shipping.exe (CreativeForge Games) [File not signed]
FirewallRules: [{C728DA6B-5DFD-4A56-B85D-4DE76AF4BF49}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PhantomDoctrine\IWTB.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{07ADB0EB-F66F-42C9-8092-3BD2A9BFE3D6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PhantomDoctrine\IWTB.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{F4D42DF3-298D-4C8B-A566-B9F52FBC2530}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Banished\Application-steam-x64.exe () [File not signed]
FirewallRules: [{9A04BE8F-116E-4EF2-BF71-6F80685C756D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Banished\Application-steam-x64.exe () [File not signed]
FirewallRules: [{271F50AD-7613-4A78-9709-AFC7C836A593}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DRAGON QUEST XI\Game\Binaries\Win64\OverwriteSettings.exe () [File not signed]
FirewallRules: [{CCEDBCDE-FFB4-4A52-B68F-1ABDAB0D4D57}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DRAGON QUEST XI\Game\Binaries\Win64\OverwriteSettings.exe () [File not signed]
FirewallRules: [{32BE9CB5-00CF-4D93-BBE3-5F6D52BD5A29}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DRAGON QUEST XI\Game\Binaries\Win64\DRAGON QUEST XI.exe (SQUARE ENIX CO., LTD. -> SQUARE ENIX CO., LTD.)
FirewallRules: [{3F6A357F-9435-4502-84DE-964EA2BBE097}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DRAGON QUEST XI\Game\Binaries\Win64\DRAGON QUEST XI.exe (SQUARE ENIX CO., LTD. -> SQUARE ENIX CO., LTD.)
FirewallRules: [{05B9E27F-6186-4E43-BD79-9CB35CAD56F6}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation -> )
FirewallRules: [{F1B26A92-14FD-40EC-8561-14E67FE1240F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Subnautica\Subnautica.exe () [File not signed]
FirewallRules: [{93035125-2B34-4F3B-8763-AC1CFB4E192A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Subnautica\Subnautica.exe () [File not signed]
FirewallRules: [{F1BB5D98-3838-4636-828B-4CD92D60C560}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe () [File not signed]
FirewallRules: [{56B7DE1B-0D1F-4690-B3A7-5386A5FE1BC4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe () [File not signed]
FirewallRules: [{B80DD964-B9D4-4D3F-A274-1B4566840388}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\INSIDE\INSIDE.exe () [File not signed]
FirewallRules: [{FA18EEEF-9351-4A6C-B5F1-3FD5124745F7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\INSIDE\INSIDE.exe () [File not signed]
FirewallRules: [{827015EA-7DD6-49C0-A294-D29BB77DC87A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\HELLGATE_London\Hellgate.exe (Hanbitsoft, inc.) [File not signed]
FirewallRules: [{B989D61D-EB73-4BFD-A281-34D9472B884B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\HELLGATE_London\Hellgate.exe (Hanbitsoft, inc.) [File not signed]
FirewallRules: [{064BED59-F339-4D84-9426-33D54F134959}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crest\Crest.exe No File
FirewallRules: [{315EE0EF-AE07-4702-8ECF-85FA4BED2745}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crest\Crest.exe No File
FirewallRules: [{56F5E796-E82D-4C15-814F-E2FBFB66D833}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Balrum\Balrum.exe () [File not signed]
FirewallRules: [{10950EF1-8DDB-4C47-82A0-7C936CF0BF99}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Balrum\Balrum.exe () [File not signed]
FirewallRules: [{6990B182-93B0-4745-803F-73DBCC8D4EA6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\One Hour One Life\steamGateClient.exe () [File not signed]
FirewallRules: [{DFBF751A-9A96-4D0E-9ACB-E1795E68B5FE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\One Hour One Life\steamGateClient.exe () [File not signed]
FirewallRules: [{361CDD12-1BAE-42A3-8E0D-A7A71E212BEE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Final Fantasy 6\FF6_Launcher.exe () [File not signed]
FirewallRules: [{01900879-4934-43B0-B36B-FDCA9685C412}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Final Fantasy 6\FF6_Launcher.exe () [File not signed]
FirewallRules: [{CE0606F3-0918-429D-8952-29119D0AE3F0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Final Fantasy 6\FF6.exe () [File not signed]
FirewallRules: [{B6AB938B-49D9-46C1-9EEC-1B1401287B8D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Final Fantasy 6\FF6.exe () [File not signed]
FirewallRules: [{8E2A35E0-D0A9-4AD8-8CA5-4A81DF3A1547}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\One Way Heroics\Game.exe (SilverSecond) [File not signed]
FirewallRules: [{6FBF6DA6-1A4F-471E-803C-98C107428EF9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\One Way Heroics\Game.exe (SilverSecond) [File not signed]
FirewallRules: [{7F4B49FF-BE18-476F-97F8-C6F5DB4D0CF7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TheCatLady\TheCatLady.exe ( ) [File not signed]
FirewallRules: [{9BF17E51-DDAC-46B4-BFA4-9672B260D739}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TheCatLady\TheCatLady.exe ( ) [File not signed]
FirewallRules: [UDP Query User{CD0C1701-EA95-4851-9121-DD901725020E}C:\users\alexa\desktop\downloader_diablo2_enus.exe] => (Allow) C:\users\alexa\desktop\downloader_diablo2_enus.exe No File
FirewallRules: [TCP Query User{B24442E6-05C9-4FD5-B23B-0450AF847AA8}C:\users\alexa\desktop\downloader_diablo2_enus.exe] => (Allow) C:\users\alexa\desktop\downloader_diablo2_enus.exe No File
FirewallRules: [UDP Query User{B09E8273-263C-4FE4-AF5A-AE519D3627DC}C:\users\alexa\desktop\msiproductreghelper.exe] => (Allow) C:\users\alexa\desktop\msiproductreghelper.exe No File
FirewallRules: [TCP Query User{048CF24A-CBF5-432C-854E-B4C186F9AD57}C:\users\alexa\desktop\msiproductreghelper.exe] => (Allow) C:\users\alexa\desktop\msiproductreghelper.exe No File
FirewallRules: [{C4B573F1-8002-44F4-A4C2-02E73F47A7A8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7dLauncher.exe () [File not signed]
FirewallRules: [{64178229-6A07-4498-A77B-223A428A3918}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7dLauncher.exe () [File not signed]
FirewallRules: [{B51DFDAF-E31A-449B-9DED-A6870BCBD816}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\OneShot\steamshim.exe () [File not signed]
FirewallRules: [{CE43EBF5-C42C-4145-BEF4-BCD3A958B377}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\OneShot\steamshim.exe () [File not signed]
FirewallRules: [{8D981B4F-A1EC-4EF4-8005-CDDCAD7DF33F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Echo of the Wilds\Echo of the Wilds.exe ( ) [File not signed]
FirewallRules: [{E3AE976D-0BC6-42AF-A8F9-F63A1D1A707C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Echo of the Wilds\Echo of the Wilds.exe ( ) [File not signed]
FirewallRules: [{A6A23493-5F76-49DC-9596-F9E7FA567B99}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Prison Architect\Prison Architect64.exe () [File not signed]
FirewallRules: [{1C12618B-2826-499A-9AC4-95409C5C71F4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Prison Architect\Prison Architect64.exe () [File not signed]
FirewallRules: [{0B218D72-20AF-47FC-88C6-907444C8D728}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Prison Architect\Prison Architect.exe () [File not signed]
FirewallRules: [{9272163B-B608-44AF-A5F6-414609A404C0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Prison Architect\Prison Architect.exe () [File not signed]
FirewallRules: [{5F943F94-8139-4A65-8917-C1C3D7975B26}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\RimWorld\RimWorldWin64.exe () [File not signed]
FirewallRules: [{0D304D49-D526-495B-94FB-8E1D7ECE6578}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\RimWorld\RimWorldWin64.exe () [File not signed]
FirewallRules: [{FDB35216-4BA6-4B39-9FA3-1664D539D7C4}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{12CE2698-34D3-494F-9281-A5A27C25E4CB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{2BFC3141-04B3-466F-B492-4C8CBB4DE244}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cultist Simulator\cultistsimulator.exe () [File not signed]
FirewallRules: [{AFF77D57-FCCD-482C-94C2-556DCEC4F938}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cultist Simulator\cultistsimulator.exe () [File not signed]
FirewallRules: [{9E9C448B-E1BF-4B5D-BB05-13E17B3C6C14}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{03521296-B129-477C-AA1E-88D09D2917F2}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{A3D72F14-0129-45A6-80F6-17A34776A717}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kenshi\kenshi_x64.exe () [File not signed]
FirewallRules: [{C9A0D68D-AB83-4547-B821-8DC8E13EFF0A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kenshi\kenshi_x64.exe () [File not signed]
FirewallRules: [{D92923B0-6A58-4405-808D-3530E7E009F2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kenshi\forgotten construction set.exe (LoFi Games) [File not signed]
FirewallRules: [{732790E0-D2D1-4091-B64B-0DBBE41FEB55}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kenshi\forgotten construction set.exe (LoFi Games) [File not signed]
FirewallRules: [{64259F30-2432-4F09-8D69-000E89BA4EC5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Founders Fortune\Founders Fortune.exe () [File not signed]
FirewallRules: [{A2173B30-B427-4BD3-9663-019C452D5BCA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Founders Fortune\Founders Fortune.exe () [File not signed]
FirewallRules: [{3FE67233-F1ED-4F72-8764-7D3797097C41}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{B4FAF54E-7D16-42E8-99EA-AF810ED96ABB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Wayward\wayward.exe (Unlok) [File not signed]
FirewallRules: [{E6CA50D5-02AA-4CDA-B25A-8B1DA680BB5C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Wayward\wayward.exe (Unlok) [File not signed]
FirewallRules: [{1DDC6C08-6567-447E-8459-8C703F0054AE}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{31BF8E66-B1F9-4C4E-BD48-23E0800C0EDE}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{3AB9654C-763E-4D67-8A8F-9F9F82770D0C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Conan Exiles\ConanSandbox\Binaries\Win64\ConanSandbox_BE.exe No File
FirewallRules: [{BD7C84ED-07BA-4A96-9F41-146ABE6AB48A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Conan Exiles\ConanSandbox\Binaries\Win64\ConanSandbox_BE.exe No File
FirewallRules: [{C2571D72-3378-472E-994B-B341AA32F43E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Conan Exiles\ConanSandbox\Binaries\Win64\ConanSandbox.exe No File
FirewallRules: [{F5B1E028-4807-42DA-A793-5C066C7F3A90}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Conan Exiles\ConanSandbox\Binaries\Win64\ConanSandbox.exe No File
FirewallRules: [{21665B92-FA55-4FB0-9FDF-7865BDF3E2DF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe () [File not signed]
FirewallRules: [{58D7C3B4-8E53-43AC-95CB-9852FC0C2FA1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe () [File not signed]
FirewallRules: [{EFC842D1-D32C-4752-A14E-7669036F74CD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForestVR.exe () [File not signed]
FirewallRules: [{DD5E13F5-7554-4C44-AFC2-20CEDAC90B9E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForestVR.exe () [File not signed]
FirewallRules: [{B92A0525-3AF8-4CAC-9983-B8CC482AAF66}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Prison Architect\Launcher\dowser.exe (Paradox Interactive Ab (Publ) -> )
FirewallRules: [{AA6784A1-158A-433D-8CF5-0D867BA64CAA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Prison Architect\Launcher\dowser.exe (Paradox Interactive Ab (Publ) -> )
FirewallRules: [{FBA37510-7C75-4456-A5E3-1235E08DC51A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{C8CF39E5-55AE-4BE9-AD81-069647957ADD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [TCP Query User{CD0F2B92-B549-4A9D-B75D-4CA9FEB53AF7}C:\program files (x86)\steam\steamapps\common\7 days to die\7daystodie.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\7 days to die\7daystodie.exe () [File not signed]
FirewallRules: [UDP Query User{48E3ED49-6E07-45BF-8581-F516F6EACE31}C:\program files (x86)\steam\steamapps\common\7 days to die\7daystodie.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\7 days to die\7daystodie.exe () [File not signed]
FirewallRules: [{8E1679EE-A758-4D83-B461-FC19F9F62DC1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hero-U Rogue to Redemption\Hero-U.exe () [File not signed]
FirewallRules: [{9F909402-A1B9-4C04-A823-F0A105FBC626}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hero-U Rogue to Redemption\Hero-U.exe () [File not signed]
FirewallRules: [TCP Query User{8053B81D-D9D8-4BFC-9F44-2E1DD1DB5635}C:\program files (x86)\steam\steamapps\common\avorion\bin\avorionserver.exe] => (Block) C:\program files (x86)\steam\steamapps\common\avorion\bin\avorionserver.exe () [File not signed]
FirewallRules: [UDP Query User{CF708CFD-D91D-46A4-AAAF-612F5C19B683}C:\program files (x86)\steam\steamapps\common\avorion\bin\avorionserver.exe] => (Block) C:\program files (x86)\steam\steamapps\common\avorion\bin\avorionserver.exe () [File not signed]
FirewallRules: [{8AAE54E0-6E57-45F0-9217-B3E2607A071B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{F3792AE3-0329-4630-81E2-D73EB4991EE2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{99DDF2A7-CE57-4B76-AF96-711250FFE813}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{05349130-B373-426C-84E9-A812EF46BE61}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{CBA36077-F6D5-4D21-AAFC-A6BA1BE48051}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Disco Elysium\disco.exe () [File not signed]
FirewallRules: [{D5D44493-8ED2-4FAE-9850-F9A81E6BFEFF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Disco Elysium\disco.exe () [File not signed]
FirewallRules: [{88DD5521-DF62-4A79-8275-724A74ADD0D1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Automation Empire\AutomationEmpire.exe () [File not signed]
FirewallRules: [{AC9BE2C4-B31A-405D-8ABC-7D16179138CE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Automation Empire\AutomationEmpire.exe () [File not signed]
FirewallRules: [{B8A843B9-0277-4CF1-8722-4D5D5521F293}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TPH\TPH.exe () [File not signed]
FirewallRules: [{6CD17394-96CC-4B19-87C4-6EEF33DB36D1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TPH\TPH.exe () [File not signed]
FirewallRules: [{990F5A47-47CD-49BE-A667-0D9B3250CC85}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Visage\Visage.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{2F7F395F-B98E-48B1-BD63-6A6E2DBB8227}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Visage\Visage.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [TCP Query User{35B55829-2A91-446E-94D2-F5E137FB3EF2}C:\program files (x86)\steam\steamapps\common\visage\visage\binaries\win64\visage-win64-shipping.exe] => (Block) C:\program files (x86)\steam\steamapps\common\visage\visage\binaries\win64\visage-win64-shipping.exe (CN=SadSquare Studio) [File not signed]
FirewallRules: [UDP Query User{7D45A4D2-123A-4573-A88B-F519915CA6E4}C:\program files (x86)\steam\steamapps\common\visage\visage\binaries\win64\visage-win64-shipping.exe] => (Block) C:\program files (x86)\steam\steamapps\common\visage\visage\binaries\win64\visage-win64-shipping.exe (CN=SadSquare Studio) [File not signed]
FirewallRules: [{F08C75BA-59DC-4FED-9385-B1C2A2B00A07}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{074B5567-88A9-4BE7-9AB1-54E7C2E32769}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Avorion\bin\Avorion.exe () [File not signed]
FirewallRules: [{B044971C-2892-4C12-9661-CD9CB357B31B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Avorion\bin\Avorion.exe () [File not signed]
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

==================== Restore Points =========================

11-12-2019 01:56:16 Windows Update
17-12-2019 19:36:33 Intel® Driver & Support Assistant

==================== Faulty Device Manager Devices ============

Name: Intel(R) Wireless Bluetooth(R)
Description: Intel(R) Wireless Bluetooth(R)
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Intel Corporation
Service: BTHUSB
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: ========================

Application errors:
==================
Error: (12/30/2019 08:18:49 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (185936,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (12/30/2019 07:56:49 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (174232,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (12/29/2019 04:16:13 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (171616,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (12/28/2019 09:03:12 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9812

Error: (12/28/2019 09:03:12 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9812

Error: (12/28/2019 09:03:12 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (12/28/2019 09:03:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8250

Error: (12/28/2019 09:03:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8250


System errors:
=============
Error: (12/17/2019 12:06:33 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Steam Client Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

Error: (12/17/2019 12:06:33 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.

Error: (12/16/2019 02:24:37 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-JTDGVR7)
Description: The server {F9717507-6651-4EDB-BFF7-AE615179BCCF} did not register with DCOM within the required timeout.

Error: (12/11/2019 11:14:44 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 2:43:22 AM on ‎12/‎11/‎2019 was unexpected.

Error: (12/11/2019 11:09:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Steam Client Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

Error: (12/11/2019 11:09:22 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.

Error: (12/11/2019 02:42:55 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: The Delivery Optimization service did not shut down properly after receiving a preshutdown control.

Error: (12/11/2019 02:42:34 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {338B40F9-9D68-4B53-A793-6B9AA0C5F63B} did not register with DCOM within the required timeout.


CodeIntegrity:
===================================

Date: 2019-12-30 20:07:28.194
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll that did not meet the Windows signing level requirements.

Date: 2019-12-30 20:05:14.352
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll that did not meet the Windows signing level requirements.

Date: 2019-12-30 19:52:31.795
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll that did not meet the Windows signing level requirements.

Date: 2019-12-30 19:37:28.202
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll that did not meet the Windows signing level requirements.

Date: 2019-12-30 19:32:43.863
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\dllhost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll that did not meet the Microsoft signing level requirements.

Date: 2019-12-30 19:32:43.490
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\dllhost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll that did not meet the Microsoft signing level requirements.

Date: 2019-12-30 19:32:08.604
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll that did not meet the Store signing level requirements.

Date: 2019-12-30 19:32:08.354
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\MicrosoftEdgeSH.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll that did not meet the Store signing level requirements.

==================== Memory info ===========================

BIOS: American Megatrends Inc. 1.20 04/07/2017
Motherboard: MSI Z270-A PRO (MS-7A71)
Processor: Intel(R) Core(TM) i7-7700K CPU @ 4.20GHz
Percentage of memory in use: 22%
Total physical RAM: 32735.85 MB
Available physical RAM: 25381.27 MB
Total Virtual: 37599.85 MB
Available Virtual: 25218.65 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:464.37 GB) (Free:72.39 GB) NTFS
Drive e: (New Volume) (Fixed) (Total:2794.39 GB) (Free:2794.13 GB) NTFS

\\?\Volume{c8dd3706-3566-4fdc-ab25-2a213fcf9e84}\ (Recovery) (Fixed) (Total:0.44 GB) (Free:0.42 GB) NTFS
\\?\Volume{04015f3a-347f-4031-83e9-5d7fc7e4f793}\ () (Fixed) (Total:0.83 GB) (Free:0.41 GB) NTFS
\\?\Volume{8e6a62d9-4499-4e0e-9465-ac658f3d7553}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 6437ED14)

Partition: GPT.

==========================================================
Disk: 1 (Protective MBR) (Size: 2794.5 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================
Attached Files

Does Ignore on scan result entries work?

$
0
0
I am running Spybot Portable Version 2.7.64.0/Malware Scanner 2.7.64.191

If there is current information about how to use Spybot 2.x I would appreciate being advised because I have found no information at https://www.safer-networking.org/support/spybot-2-faq/ to help me on how to Ignore or Whitelist or....

I have been relying on tutorials written for older versions, and am finding the content either misleading or invalid.

At https://www.safer-networking.org/tutorials/ is given the advice of "Maybe you don’t want your list of most recently used Word documents removed? At this point you have three options....if you want to just keep all tracks from a specific product, just right-click a product in the results list and choose the corresponding option."

This has been used to retain 'Recent file...' and 'Browser: History' but nothing changes. Every time I do a scan the Ignored entries appear all over again in the list and I have to untick them. It is very wearing to do a scan and have to repeat the exercise of unticking the entries I do not want to have removed.

The alternative to "open the File sets page on the Settings section of the program, and disable the Usage tracks entries." works, but that is like using a shotgun when all I need is a rifle.

I have checked the directory, and it shows only zero-length files.

dir "C:\ProgramData\Spybot - Search & Destroy\Ignore"
0 Filesets.sbe
0 Products.sbe
0 Results.sbe

To be specific, this is what I do every time:

Scan
Right click 'Recent file..' entries, and choose 'Ignore selected item in the future'
Choose Fix selected
Close Spybot

If I open Spybot immediately and re-scan, all of the entries which I had marked to Ignore appear in the list.

Is Ignore yet another function that supposedly exists in Spybot but doesn't?

That was my experience with whitelisting which says at https://www.safer-networking.org/faq...tem-whitelist/ that I "have the option to create a whitelist. This is a list of programs that are known to be safe. This will speed up the scanning process as these files will not be scanned in the future unless they have been altered in some way." It goes on to say that this is done by running SDPrepPos.exe, which prompts me to create a whitelist BUT it only gives me the choice of whitelisting a drive.

Whitelisting drives is useless to someone who wants to whitelist only trusted programs.

Similarly, advice from 2014 at https://forums.spybot.info/showthrea...ghlight=ignore says "Open Spybot Start Center,place a checkmark in Advanced User Mode,click Settings(if you are using Windows Vista or Windows 7,say yes to the prompt from User Account Control.),click the Ignore List tab,click the Add...button,and in the space at the top,type in Cookie,then select Cookie below,press Ok,and after you see Cookie added to the Ignore List,press Apply and Ok."

And again, advice from 2013 at https://forums.spybot.info/showthrea...ghlight=ignore tells me how to remove items from the Ignore list by opening "Spybot-S&D Start Center, checkmark Advanced User Mode, click Settings(say Yes to the prompt from UAC, if applicable), go to the Ignore Lists tab. Anything you've rightclicked to be ignored is probably under the Items tab, though you can look at the Programs tab, too, to be sure. Click your mouse on anything you'd like not to be ignored anymore, hit the Remove button. When you're done removing everything you don't want in there, click Apply and then Ok"

There is no Advanced User Mode on my Start Center.

Am I encountering the above issues because I am using the Portable version of Spybot or are they issues because Spybot 2.7 no longer has these capabilities?

Thanks

http://validate.perfdrive.com/captcha?...

$
0
0
I am getting redirected to this page which will not load every time I try to go to my checking account. Is this a virus? It is not detected by Norton or this program. What is it, and can I eliminate it?

License Purchase Today

$
0
0
I have been a user of home edition for many years. Today I purchased/renewed my license. I was really over due. My start center no longer works. How do I get this thing going again?
thank you

My Computer is infected, please help

$
0
0
Half a year ago (start of august) both of my emails and my paypal got hacked, and i just barely got them back through my phone and my Laptop.

Because i only use my PC for those things i expected a virus on there, and after i informed myself for a good anti-malware, i installed spybot and it found around 3 Trojans on there and successfully removed them.

Since then my Computer acted strangely from time to time and malwarebytes showed me that my browser tried to open malicious websites on its own, particular when i opened games.

December i finally decided to get rid of everything on my PC to be safe. So i prepared a USB with Windows Creation Tool, changed the boot order to open up the USB first, formatted my main drive and ended the setup.
Should have been the end of it, but my PC acted strangely again and after i ran Spybot a couple of times it found 2 Trojans again.

I then remembered that there was an option to delete everything in the windows setup and i did everything again, a few days ago. Did not help a bit and Malwarebytes still showed me that Firefox tried to open malicious websites.

Please help me.

P.S. I do have a Home License for Spybot but it didn't show me anything, also i ran adwarecleaner and RogueKiller with no success.

P.S.S. i tried running aswMBR, but i always get a blue screen with the error something about Drivers not equal less, so I'm just going to post the FRST log.

P.S.S.S. I'm from Germany so the FRST log is automaticity in German and i tried everything to make it completely into English, but some parts are still German. I'm very sorry about that.

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 08-01-2020
durchgeführt von Leonard (Administrator) auf DESKTOP-A41L3FV (Gigabyte Technology Co., Ltd. Z370 AORUS ULTRA GAMING WIFI) (11-01-2020 22:35:19)
Gestartet von C:\Users\Leonard\Desktop
Geladene Profile: Leonard (Verfügbare Profile: Leonard)
Platform: Windows 10 Home Version 1909 18363.535 (X64) Sprache: German (Germany)
Standard-Browser: FF
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Adlice -> ) C:\Program Files\RogueKiller\RogueKiller64.exe
(Adlice -> ) C:\Program Files\RogueKiller\RogueKillerSvc.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Leonard\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11912.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.471_none_5f12f35059003107\TiWorker.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\Display.NvContainer\NVDisplay.Container.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Spotify AB -> Spotify Ltd) C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe
(Spotify AB -> Spotify Ltd) C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe
(Spotify AB -> Spotify Ltd) C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe
(Spotify AB -> Spotify Ltd) C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe
(Spotify AB -> Spotify Ltd) C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe

==================== Registry (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9235936 2017-11-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [6788032 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3288016 2019-12-16] (Valve -> Valve Corporation)
HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\Run: [Spotify] => C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe [22151072 2020-01-09] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3288016 2019-12-16] (Valve -> Valve Corporation)
HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\Run: [Spotify] => C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe [22151072 2020-01-09] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\RunOnce: [Application Restart #0] => C:\Program Files\Mozilla Firefox\firefox.exe -os-restarted
HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3288016 2019-12-16] (Valve -> Valve Corporation)
HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\Run: [Spotify] => C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe [22151072 2020-01-09] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\RunOnce: [Application Restart #0] => C:\Program Files\Mozilla Firefox\firefox.exe -os-restarted
HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3288016 2019-12-16] (Valve -> Valve Corporation)
HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\Run: [Spotify] => C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe [22151072 2020-01-09] (Spotify AB -> Spotify Ltd)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {7B797784-141A-45C7-84AA-27104DDDABB8} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [7192192 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {E3FFD7DE-EB75-4A43-9D27-18E0D1E20619} - System32\Tasks\Microsoft\Windows\RetailDemo\CleanupOfflineContent => {61f77d5e-afe9-400b-a5e6-e9e80fc8e601} C:\Windows\System32\RDXTaskFactory.dll [415744 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
Task: {F6387FE8-CCF3-41C0-B7C9-C09C027F71E4} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [7651984 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {F72A9D58-D115-4C5C-AA7C-9377E51013A7} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [6944304 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)


==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.101.1
Tcpip\..\Interfaces\{fc0a4e6f-4f37-4e9c-90c6-a6aa9a923641}: [DhcpNameServer] 192.168.101.1

Internet Explorer:
==================

FireFox:
========
FF DefaultProfile: 2w5lohba.default
FF ProfilePath: C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\2w5lohba.default [2020-01-09]
FF ProfilePath: C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\j4jjxgiw.default-release [2020-01-11]
FF Session Restore: Mozilla\Firefox\Profiles\j4jjxgiw.default-release -> ist aktiviert.
FF Extension: (Ghostery – Privacy Ad Blocker) - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\j4jjxgiw.default-release\Extensions\firefox@ghostery.com.xpi [2020-01-09]
FF Extension: (English (GB) Language Pack) - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\j4jjxgiw.default-release\Extensions\langpack-en-GB@firefox.mozilla.org.xpi [2020-01-10]
FF Extension: (British English Dictionary (Marco Pinto)) - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\j4jjxgiw.default-release\Extensions\marcoagpinto@mail.telepac.pt.xpi [2020-01-10]

==================== Dienste (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [805488 2020-01-09] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 ibtsiva; C:\Windows\system32\ibtsiva.exe [530208 2019-09-12] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6960640 2020-01-09] (Malwarebytes Inc -> Malwarebytes)
R2 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [16576568 2020-01-06] (Adlice -> )
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3892256 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [3943664 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [233712 2018-02-06] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4098056 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [113992 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Treiber (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R3 e1dexpress; C:\Windows\System32\DriverStore\FileRepository\e1d68x64.inf_amd64_b44028fc7fdf4fca\e1d68x64.sys [599920 2019-09-13] (Intel(R) INTELND1820 -> Intel Corporation)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153312 2020-01-09] (Malwarebytes Corporation -> Malwarebytes)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [731424 2019-09-12] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [218288 2020-01-09] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [20936 2020-01-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [226448 2020-01-11] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73584 2020-01-11] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248968 2020-01-11] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [105112 2020-01-11] (Malwarebytes Inc -> Malwarebytes)
R3 MEIx64; C:\Windows\System32\DriverStore\FileRepository\heci.inf_amd64_85021432489d6a1c\x64\TeeDriverW8x64.sys [266128 2019-04-17] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R3 Netwtw06; C:\Windows\System32\drivers\Netwtw06.sys [8723968 2019-03-19] (Microsoft Windows -> Intel Corporation)
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\nvlddmkm.sys [22094936 2019-10-04] (NVIDIA Corporation -> NVIDIA Corporation)
R3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [8206848 2019-03-19] (Microsoft Windows -> Realtek Semiconductor Corporation )
U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [28272 2020-01-11] (Adlice -> )
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46472 2019-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [333784 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [62432 2019-03-19] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat (erstellte) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2020-01-11 22:35 - 2020-01-11 22:35 - 000015506 _____ C:\Users\Leonard\Desktop\FRST.txt
2020-01-11 22:34 - 2020-01-11 22:34 - 002573312 _____ (Farbar) C:\Users\Leonard\Desktop\FRST64.exe
2020-01-11 21:55 - 2020-01-11 21:55 - 000248968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2020-01-11 21:55 - 2020-01-11 21:55 - 000226448 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2020-01-11 21:55 - 2020-01-11 21:55 - 000105112 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2020-01-11 21:55 - 2020-01-11 21:55 - 000073584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2020-01-11 21:32 - 2020-01-11 21:32 - 000772596 _____ C:\Windows\Minidump\011120-6953-01.dmp
2020-01-11 21:30 - 2020-01-11 21:32 - 936522033 _____ C:\Windows\MEMORY.DMP
2020-01-11 21:30 - 2020-01-11 21:30 - 000772724 _____ C:\Windows\Minidump\011120-6968-01.dmp
2020-01-11 21:29 - 2020-01-11 21:29 - 005198336 _____ (AVAST Software) C:\Users\Leonard\Desktop\aswMBR.exe
2020-01-11 17:51 - 2020-01-11 17:52 - 088060112 _____ (TeamSpeak Systems GmbH) C:\Users\Leonard\Downloads\TeamSpeak3-Client-win64-3.3.2.exe
2020-01-10 21:17 - 2019-03-18 14:20 - 005739008 _____ (Microsoft Corporation) C:\Windows\system32\prm0009.dll
2020-01-10 21:17 - 2019-03-18 14:19 - 002629120 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons0009.dll
2020-01-10 21:17 - 2019-03-18 14:07 - 006359552 _____ (Microsoft Corporation) C:\Windows\system32\NlsData0009.dll
2020-01-10 21:17 - 2019-03-18 14:01 - 005496832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NlsData0009.dll
2020-01-10 20:57 - 2020-01-10 20:57 - 000017999 _____ C:\Windows\Tweaking.com - Registry Backup Setup Log.txt
2020-01-10 20:57 - 2020-01-10 20:57 - 000002304 _____ C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
2020-01-10 20:57 - 2020-01-10 20:57 - 000002304 _____ C:\ProgramData\Desktop\Tweaking.com - Registry Backup.lnk
2020-01-10 20:57 - 2020-01-10 20:57 - 000000207 _____ C:\Windows\tweaking.com-regbackup-DESKTOP-A41L3FV-Windows-10-Home-(64-bit).dat
2020-01-10 20:57 - 2020-01-10 20:57 - 000000000 ____D C:\RegBackup
2020-01-10 20:57 - 2020-01-10 20:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2020-01-10 20:57 - 2020-01-10 20:57 - 000000000 ____D C:\Program Files (x86)\Tweaking.com
2020-01-10 20:55 - 2020-01-10 20:56 - 005766144 _____ (Tweaking.com) C:\Users\Leonard\Downloads\tweaking.com_registry_backup_setup.exe
2020-01-10 20:06 - 2020-01-11 22:35 - 000000000 ____D C:\FRST
2020-01-10 19:32 - 2020-01-10 19:33 - 000000000 ____D C:\Windows\system32\MRT
2020-01-10 19:32 - 2020-01-10 19:32 - 129221664 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 025901056 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 025443840 _____ (Microsoft Corporation) C:\Windows\system32\Hydrogen.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 022627840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 019849216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 018020352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 017787904 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 014816256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 009927992 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 009711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 008011264 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 007905000 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 007849424 _____ (Microsoft Corporation) C:\Windows\system32\OneCoreUAPCommonProxyStub.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 007754240 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 007600448 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 007278592 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 007263992 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 007195648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 007015936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 006516648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 006435840 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 006232576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 006227104 _____ (Microsoft Corporation) C:\Windows\system32\StartTileData.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 006166016 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 006083832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 005943296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 005914112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 005890048 _____ (Microsoft Corporation) C:\Windows\system32\Windows.AI.MachineLearning.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 005764664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 005501952 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 005112320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 004615616 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 004578816 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 004307968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdp.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 004150272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.AI.MachineLearning.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 004140544 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsThresholdAdminFlowUI.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 004129416 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 004047360 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 004005888 _____ (Microsoft Corporation) C:\Windows\system32\EdgeContent.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 003967920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 003791360 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 003752960 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 003742544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 003729408 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 003703296 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 003591208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 003487232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 003387392 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 003371928 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 003263488 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 003105792 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 003084800 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002988344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 002956472 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002871848 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 002870784 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002800640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 002772272 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002762296 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002716672 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 002703872 _____ (Microsoft Corporation) C:\Windows\system32\WebRuntimeManager.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002698768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 002586816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002562048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002494432 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002399232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AcGenral.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002305536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002284544 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002258848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002147328 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002126112 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002120704 _____ (Microsoft Corporation) C:\Windows\system32\WpcDesktopMonSvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002114048 _____ (Microsoft Corporation) C:\Windows\system32\Windows.CloudStore.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 002082208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001974824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\refs.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 001942528 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001920512 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001916984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001866272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001856512 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001757304 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2020-01-10 19:29 - 2020-01-10 19:29 - 001748480 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001743888 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001726480 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001697280 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001691648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001687040 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001664904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001656600 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001647072 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001610752 _____ (Microsoft Corporation) C:\Windows\system32\HologramCompositor.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001539584 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001512528 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 001458688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001451520 _____ (Microsoft Corporation) C:\Windows\system32\usocoreworker.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 001428992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 001413912 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001413840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001399312 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 001394168 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001366128 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2020-01-10 19:29 - 2020-01-10 19:29 - 001348096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001327064 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001283072 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001261464 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001259416 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 001257472 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001189376 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001182448 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 001171704 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001154656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001149712 _____ (Microsoft Corporation) C:\Windows\system32\ApplyTrustOffline.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 001098928 _____ (Microsoft Corporation) C:\Windows\system32\DolbyDecMFT.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001094656 _____ (Microsoft Corporation) C:\Windows\system32\WpcRefreshTask.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001072952 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 001070080 _____ (Microsoft Corporation) C:\Windows\system32\BTAGService.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001069064 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001066496 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001062912 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001059840 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 001054864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001027000 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001017680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001007616 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 001006904 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostCommon.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000986936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\refsv1.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000982840 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000975872 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000921600 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000913920 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000911824 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000892696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000878080 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Service.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000874936 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000874536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000864256 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000849920 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000844800 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000842752 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000842552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudExperienceHostCommon.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000832000 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000826368 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelinesvc.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000822416 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000822072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000811536 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000797112 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000774456 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000768528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000768488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000765440 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000750080 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000747320 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000735744 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000708096 _____ (Microsoft Corporation) C:\Windows\system32\agentactivationruntimewindows.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000704000 _____ (Microsoft Corporation) C:\Windows\system32\agentactivationruntime.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Mirage.Internal.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000700416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BTAGService.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000689664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000679152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000674280 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000673456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000669696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000669352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000657424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000649728 _____ (Microsoft Corporation) C:\Windows\system32\DevicesFlowBroker.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\cdpsvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000642560 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000638264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000632320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000618496 _____ (Microsoft Corporation) C:\Windows\system32\CredProvDataModel.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000606720 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000604984 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000599552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActivationManager.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000598528 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000598016 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000595968 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000593128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000589592 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000586768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000578560 _____ (Microsoft Corporation) C:\Windows\system32\SppExtComObj.Exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000563712 _____ (Microsoft Corporation) C:\Windows\system32\wpnprv.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000552448 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000551736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Vid.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000550400 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000534528 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Bluetooth.UserService.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000532480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000530944 _____ (Microsoft Corporation) C:\Windows\system32\usosvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000524800 _____ (Microsoft Corporation) C:\Windows\system32\cdpusersvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000524264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Enumeration.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000522176 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000517432 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000516544 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000514576 _____ (Microsoft Corporation) C:\Windows\system32\dcntel.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000513536 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000513336 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000511000 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000496640 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000492032 _____ (Microsoft Corporation) C:\Windows\system32\Narrator.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000487424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.FileExplorer.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000477712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2020-01-10 19:29 - 2020-01-10 19:29 - 000477184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000469504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000466928 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000465208 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000461320 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000457216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cldflt.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000456192 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.ConversationalAgent.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000455168 _____ (Microsoft Corporation) C:\Windows\system32\upnphost.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000453632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredProvDataModel.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000452920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000446464 _____ (Microsoft Corporation) C:\Windows\system32\Magnify.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000443904 _____ (Microsoft Corporation) C:\Windows\system32\edgeIso.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000441144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000435200 _____ (Microsoft Corporation) C:\Windows\system32\wincorlib.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000431616 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BioFeedback.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000430080 _____ (Microsoft Corporation) C:\Windows\system32\fhcfg.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000429568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000422712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000416016 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000415544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aepic.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000406480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Enumeration.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000404904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000404480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000401920 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000401408 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000392192 _____ (Microsoft Corporation) C:\Windows\system32\Search.ProtocolHandler.MAPI2.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000382976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000381952 _____ (Microsoft Corporation) C:\Windows\system32\AppLockerCSP.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000380944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000380928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AcLayers.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000375720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000372752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000368128 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000359424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\MbbCx.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000358400 _____ (Microsoft Corporation) C:\Windows\system32\AcGenral.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Magnify.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000350720 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_SpeechPrivacy.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000342528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000332288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000327680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnphost.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000327680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgeIso.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000324624 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32k.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000322504 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\AcLayers.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000308736 _____ (Microsoft Corporation) C:\Windows\system32\msIso.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000307712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincorlib.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000299520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000292664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000291256 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000283648 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000283136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000280064 _____ (Microsoft Corporation) C:\Windows\system32\cmd.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000278016 _____ (Microsoft Corporation) C:\Windows\system32\WpcTok.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000277504 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_CapabilityAccess.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000265216 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000256000 _____ (Microsoft Corporation) C:\Windows\system32\UpdateDeploymentProvider.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000251904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msIso.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000251512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winnat.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000249856 _____ (Gracenote, Inc.) C:\Windows\SysWOW64\gnsdk_fp.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000247856 _____ (Microsoft Corporation) C:\Windows\system32\weretw.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000241152 _____ (Microsoft Corporation) C:\Windows\system32\policymanagerprecheck.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000240640 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000239104 _____ (Microsoft Corporation) C:\Windows\system32\vdsbas.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000237056 _____ (Microsoft Corporation) C:\Windows\system32\accessibilitycpl.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000236032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000236032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000235008 _____ (Microsoft Corporation) C:\Windows\system32\fwpolicyiomgr.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000227840 _____ (Microsoft Corporation) C:\Windows\system32\IndexedDbLegacy.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000225280 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000224768 _____ (Microsoft Corporation) C:\Windows\system32\DWWIN.EXE
2020-01-10 19:29 - 2020-01-10 19:29 - 000220472 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000219136 _____ (Microsoft Corporation) C:\Windows\system32\wscinterop.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000214528 _____ (Microsoft Corporation) C:\Windows\system32\DiagSvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000211968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000210744 _____ (Microsoft Corporation) C:\Windows\system32\tcbloader.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000206336 _____ (Microsoft Corporation) C:\Windows\system32\wincredui.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000204816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spacedump.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000204800 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000202552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000201728 _____ (Microsoft Corporation) C:\Windows\system32\AppXApplicabilityBlob.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\accessibilitycpl.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000199480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000197632 _____ (Microsoft Corporation) C:\Windows\system32\Win32CompatibilityAppraiserCSP.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000193800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\weretw.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000189440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwpolicyiomgr.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWWIN.EXE
2020-01-10 19:29 - 2020-01-10 19:29 - 000184832 _____ (Microsoft Corporation) C:\Windows\system32\AarSvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000179712 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IndexedDbLegacy.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000175616 _____ (Microsoft Corporation) C:\Windows\system32\dmvdsitf.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000169472 _____ (Microsoft Corporation) C:\Windows\system32\SpatialAudioLicenseSrv.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscinterop.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000164776 _____ (Microsoft Corporation) C:\Windows\system32\omadmapi.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000164368 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000162816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredui.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000162304 _____ (Microsoft Corporation) C:\Windows\system32\fwbase.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000159232 _____ (Microsoft Corporation) C:\Windows\system32\srpapi.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000157184 _____ (Microsoft Corporation) C:\Windows\system32\RMapi.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000155136 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000154112 _____ (Microsoft Corporation) C:\Windows\system32\dssvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000147456 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SpatialAudioLicenseSrv.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000139776 _____ (Microsoft Corporation) C:\Windows\system32\Chakrathunk.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000136536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\omadmapi.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000132608 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwbase.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000129024 _____ (Microsoft Corporation) C:\Windows\system32\UtcDecoderHost.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000127272 _____ (Microsoft Corporation) C:\Windows\system32\win32u.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000126464 _____ (Microsoft Corporation) C:\Windows\system32\WinHvPlatform.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\ApplicationControlCSP.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000122880 _____ (Microsoft Corporation) C:\Windows\system32\wercplsupport.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000118784 _____ (Microsoft Corporation) C:\Windows\system32\Utilman.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000118272 _____ (Microsoft Corporation) C:\Windows\system32\EaseOfAccessDialog.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthenum.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000113160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000113152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000111104 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000108032 _____ (Microsoft Corporation) C:\Windows\system32\TpmTasks.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000105984 _____ (Microsoft Corporation) C:\Windows\system32\utcutil.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000105488 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000105472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakrathunk.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000100352 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000100352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cdfs.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000099328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS
2020-01-10 19:29 - 2020-01-10 19:29 - 000097080 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000094720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Utilman.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EaseOfAccessDialog.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000093496 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000090624 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000089536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32u.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000088568 _____ (Microsoft Corporation) C:\Windows\system32\remoteaudioendpoint.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\ApiSetHost.AppExecutionAlias.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AcXtrnal.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000086016 _____ (Microsoft Corporation) C:\Windows\system32\AtBroker.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000084488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winhvr.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000084488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvservice.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000083456 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl
2020-01-10 19:29 - 2020-01-10 19:29 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dtdump.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sethc.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000079360 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000077824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\CustomInstallExec.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\autopilot.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000074240 _____ (Microsoft Corporation) C:\Windows\system32\reg.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000073024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\remoteaudioendpoint.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000071480 _____ (Microsoft Corporation) C:\Windows\system32\win32appinventorycsp.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000068096 _____ (Microsoft Corporation) C:\Windows\system32\udhisapi.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000068096 _____ (Microsoft Corporation) C:\Windows\system32\fdProxy.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscui.cpl
2020-01-10 19:29 - 2020-01-10 19:29 - 000067112 _____ (Microsoft Corporation) C:\Windows\system32\WindowsManagementServiceWinRt.ProxyStub.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AtBroker.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\iemigplugin.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ApiSetHost.AppExecutionAlias.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iemigplugin.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\vss_ps.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000061240 _____ (Microsoft Corporation) C:\Windows\system32\hvhostsvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\AxInstUI.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\reg.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\udhisapi.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000057856 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000057344 _____ (Microsoft Corporation) C:\Windows\system32\audioresourceregistrar.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000051200 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000048128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000047616 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000047208 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000046592 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelineprxy.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\LaunchWinApp.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\upnpcont.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000039936 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthMini.SYS
2020-01-10 19:29 - 2020-01-10 19:29 - 000036368 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnpcont.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\DevQueryBroker.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LaunchWinApp.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000033280 _____ (Microsoft Corporation) C:\Windows\system32\posetup.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000032056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000028344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winnsi.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000027648 _____ (Microsoft Corporation) C:\Windows\system32\wscisvif.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\autopilotdiag.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\appidtel.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000024792 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000021304 _____ (Microsoft Corporation) C:\Windows\system32\kdhvcom.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000020352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nsi.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000018944 _____ (Microsoft Corporation) C:\Windows\system32\wscproxystub.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000018432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\applockerfltr.sys
2020-01-10 19:29 - 2020-01-10 19:29 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\iscsilog.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000015360 _____ (Microsoft Corporation) C:\Windows\system32\AcXtrnal.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDJPN.DLL
2020-01-10 19:29 - 2020-01-10 19:29 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\dstokenclean.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000012800 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\pacjsworker.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000010752 _____ (Microsoft Corporation) C:\Windows\system32\DMAlertListener.ProxyStub.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000009216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000009216 _____ (Microsoft Corporation) C:\Windows\system32\wscadminui.exe
2020-01-10 19:29 - 2020-01-10 19:29 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbd106.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DMAlertListener.ProxyStub.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000005632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2020-01-10 19:29 - 2020-01-10 19:29 - 000005632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000003072 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2020-01-10 19:29 - 2020-01-10 19:29 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2020-01-10 19:29 - 2020-01-10 19:29 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\tier2punctuations.dll
2020-01-10 19:26 - 2020-01-11 21:48 - 000001483 _____ C:\Users\Leonard\Desktop\4.txt
2020-01-10 19:25 - 2019-10-17 06:17 - 000492544 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2020-01-10 19:25 - 2019-10-17 06:01 - 000390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2020-01-10 18:06 - 2020-01-11 21:55 - 000000000 ____D C:\Users\Leonard\AppData\Local\CrashDumps
2020-01-10 16:24 - 2019-03-19 04:49 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts.20200110-172418.backup
2020-01-10 16:19 - 2020-01-11 21:55 - 000028272 _____ C:\Windows\system32\Drivers\truesight.sys
2020-01-10 16:19 - 2020-01-10 16:19 - 000000899 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2020-01-10 16:19 - 2020-01-10 16:19 - 000000899 _____ C:\ProgramData\Desktop\RogueKiller.lnk
2020-01-10 16:19 - 2020-01-10 16:19 - 000000000 ____D C:\ProgramData\RogueKiller
2020-01-10 16:19 - 2020-01-10 16:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2020-01-10 16:19 - 2020-01-10 16:19 - 000000000 ____D C:\Program Files\RogueKiller
2020-01-09 17:18 - 2020-01-09 17:18 - 000000000 ____D C:\AdwCleaner
2020-01-09 17:17 - 2020-01-09 17:18 - 008237744 _____ (Malwarebytes) C:\Users\Leonard\Desktop\adwcleaner_8.0.1.exe
2020-01-09 15:28 - 2020-01-09 15:28 - 000000000 ____D C:\Users\Leonard\AppData\Roaming\EasyAntiCheat
2020-01-09 15:27 - 2020-01-09 15:28 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat
2020-01-09 15:27 - 2010-06-02 03:55 - 000527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2020-01-09 15:27 - 2010-06-02 03:55 - 000518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2020-01-09 15:27 - 2010-06-02 03:55 - 000239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2020-01-09 15:27 - 2010-06-02 03:55 - 000176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2020-01-09 15:27 - 2010-06-02 03:55 - 000077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2020-01-09 15:27 - 2010-06-02 03:55 - 000074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2020-01-09 15:27 - 2010-05-26 10:41 - 002526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2020-01-09 15:27 - 2010-05-26 10:41 - 002401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2020-01-09 15:27 - 2010-05-26 10:41 - 002106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2020-01-09 15:27 - 2010-05-26 10:41 - 001998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2020-01-09 15:27 - 2010-05-26 10:41 - 001907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2020-01-09 15:27 - 2010-05-26 10:41 - 001868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2020-01-09 15:27 - 2010-05-26 10:41 - 000511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2020-01-09 15:27 - 2010-05-26 10:41 - 000470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2020-01-09 15:27 - 2010-05-26 10:41 - 000276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2020-01-09 15:27 - 2010-05-26 10:41 - 000248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2020-01-09 15:27 - 2010-02-04 09:01 - 000530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2020-01-09 15:27 - 2010-02-04 09:01 - 000528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2020-01-09 15:27 - 2010-02-04 09:01 - 000238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2020-01-09 15:27 - 2010-02-04 09:01 - 000176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2020-01-09 15:27 - 2010-02-04 09:01 - 000078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2020-01-09 15:27 - 2010-02-04 09:01 - 000074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2020-01-09 15:27 - 2010-02-04 09:01 - 000024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2020-01-09 15:27 - 2010-02-04 09:01 - 000022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2020-01-09 15:27 - 2009-09-04 16:44 - 000517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2020-01-09 15:27 - 2009-09-04 16:44 - 000515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2020-01-09 15:27 - 2009-09-04 16:44 - 000238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2020-01-09 15:27 - 2009-09-04 16:44 - 000176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2020-01-09 15:27 - 2009-09-04 16:44 - 000073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2020-01-09 15:27 - 2009-09-04 16:44 - 000069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2020-01-09 15:27 - 2009-09-04 16:29 - 005554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2020-01-09 15:27 - 2009-09-04 16:29 - 005501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2020-01-09 15:27 - 2009-09-04 16:29 - 002582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2020-01-09 15:27 - 2009-09-04 16:29 - 002475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2020-01-09 15:27 - 2009-09-04 16:29 - 001974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2020-01-09 15:27 - 2009-09-04 16:29 - 001892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2020-01-09 15:27 - 2009-09-04 16:29 - 000523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2020-01-09 15:27 - 2009-09-04 16:29 - 000453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2020-01-09 15:27 - 2009-09-04 16:29 - 000285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2020-01-09 15:27 - 2009-09-04 16:29 - 000235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2020-01-09 15:27 - 2009-03-16 13:18 - 000521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2020-01-09 15:27 - 2009-03-16 13:18 - 000517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2020-01-09 15:27 - 2009-03-16 13:18 - 000235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2020-01-09 15:27 - 2009-03-16 13:18 - 000174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2020-01-09 15:27 - 2009-03-16 13:18 - 000024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2020-01-09 15:27 - 2009-03-16 13:18 - 000022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2020-01-09 15:27 - 2009-03-09 14:27 - 005425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2020-01-09 15:27 - 2009-03-09 14:27 - 004178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2020-01-09 15:27 - 2009-03-09 14:27 - 002430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2020-01-09 15:27 - 2009-03-09 14:27 - 001846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2020-01-09 15:27 - 2009-03-09 14:27 - 000520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2020-01-09 15:27 - 2009-03-09 14:27 - 000453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2020-01-09 15:27 - 2008-10-27 09:04 - 000518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2020-01-09 15:27 - 2008-10-27 09:04 - 000514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2020-01-09 15:27 - 2008-10-27 09:04 - 000235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2020-01-09 15:27 - 2008-10-27 09:04 - 000175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2020-01-09 15:27 - 2008-10-27 09:04 - 000074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2020-01-09 15:27 - 2008-10-27 09:04 - 000070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2020-01-09 15:27 - 2008-10-27 09:04 - 000025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2020-01-09 15:27 - 2008-10-27 09:04 - 000023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2020-01-09 15:27 - 2008-10-15 05:22 - 005631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2020-01-09 15:27 - 2008-10-15 05:22 - 004379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2020-01-09 15:27 - 2008-10-15 05:22 - 002605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2020-01-09 15:27 - 2008-10-15 05:22 - 002036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2020-01-09 15:27 - 2008-10-15 05:22 - 000519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2020-01-09 15:27 - 2008-10-15 05:22 - 000452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2020-01-09 15:27 - 2008-07-31 09:41 - 000238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2020-01-09 15:27 - 2008-07-31 09:41 - 000177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2020-01-09 15:27 - 2008-07-31 09:41 - 000072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2020-01-09 15:27 - 2008-07-31 09:41 - 000068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2020-01-09 15:27 - 2008-07-31 09:40 - 000513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2020-01-09 15:27 - 2008-07-31 09:40 - 000509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2020-01-09 15:27 - 2008-07-10 10:01 - 000467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2020-01-09 15:27 - 2008-07-10 10:00 - 004992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2020-01-09 15:27 - 2008-07-10 10:00 - 003851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2020-01-09 15:27 - 2008-07-10 10:00 - 001942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2020-01-09 15:27 - 2008-07-10 10:00 - 001493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2020-01-09 15:27 - 2008-07-10 10:00 - 000540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2020-01-09 15:27 - 2008-05-30 13:19 - 000511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2020-01-09 15:27 - 2008-05-30 13:19 - 000507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2020-01-09 15:27 - 2008-05-30 13:18 - 000238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2020-01-09 15:27 - 2008-05-30 13:18 - 000177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2020-01-09 15:27 - 2008-05-30 13:17 - 000068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2020-01-09 15:27 - 2008-05-30 13:17 - 000065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2020-01-09 15:27 - 2008-05-30 13:17 - 000025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2020-01-09 15:27 - 2008-05-30 13:16 - 000028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2020-01-09 15:27 - 2008-05-30 13:11 - 004991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2020-01-09 15:27 - 2008-05-30 13:11 - 003850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2020-01-09 15:27 - 2008-05-30 13:11 - 001941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2020-01-09 15:27 - 2008-05-30 13:11 - 001491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2020-01-09 15:27 - 2008-05-30 13:11 - 000540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2020-01-09 15:27 - 2008-05-30 13:11 - 000467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2020-01-09 15:27 - 2008-03-05 15:04 - 000489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2020-01-09 15:27 - 2008-03-05 15:03 - 000479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2020-01-09 15:27 - 2008-03-05 15:03 - 000238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2020-01-09 15:27 - 2008-03-05 15:03 - 000177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2020-01-09 15:27 - 2008-03-05 15:00 - 000028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2020-01-09 15:27 - 2008-03-05 15:00 - 000025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2020-01-09 15:27 - 2008-03-05 14:56 - 004910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2020-01-09 15:27 - 2008-03-05 14:56 - 003786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2020-01-09 15:27 - 2008-03-05 14:56 - 001860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2020-01-09 15:27 - 2008-03-05 14:56 - 001420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2020-01-09 15:27 - 2008-02-05 22:07 - 000529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2020-01-09 15:27 - 2008-02-05 22:07 - 000462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2020-01-09 15:27 - 2007-10-22 02:40 - 000411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2020-01-09 15:27 - 2007-10-22 02:39 - 000267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2020-01-09 15:27 - 2007-10-22 02:37 - 000021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2020-01-09 15:27 - 2007-10-22 02:37 - 000017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2020-01-09 15:27 - 2007-10-12 14:14 - 005081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2020-01-09 15:27 - 2007-10-12 14:14 - 003734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2020-01-09 15:27 - 2007-10-12 14:14 - 002006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2020-01-09 15:27 - 2007-10-12 14:14 - 001374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2020-01-09 15:27 - 2007-10-02 08:56 - 000508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2020-01-09 15:27 - 2007-10-02 08:56 - 000444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2020-01-09 15:27 - 2007-07-19 23:57 - 000411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2020-01-09 15:27 - 2007-07-19 23:57 - 000267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2020-01-09 15:27 - 2007-07-19 17:14 - 005073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2020-01-09 15:27 - 2007-07-19 17:14 - 003727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2020-01-09 15:27 - 2007-07-19 17:14 - 001985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2020-01-09 15:27 - 2007-07-19 17:14 - 001358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2020-01-09 15:27 - 2007-07-19 17:14 - 000508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2020-01-09 15:27 - 2007-07-19 17:14 - 000444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2020-01-09 15:27 - 2007-06-20 19:49 - 000409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2020-01-09 15:27 - 2007-06-20 19:46 - 000266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2020-01-09 15:27 - 2007-05-16 15:45 - 004496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2020-01-09 15:27 - 2007-05-16 15:45 - 003497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2020-01-09 15:27 - 2007-05-16 15:45 - 001401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2020-01-09 15:27 - 2007-05-16 15:45 - 001124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2020-01-09 15:27 - 2007-05-16 15:45 - 000506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2020-01-09 15:27 - 2007-05-16 15:45 - 000443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2020-01-09 15:27 - 2007-04-04 17:55 - 000403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2020-01-09 15:27 - 2007-04-04 17:55 - 000261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2020-01-09 15:27 - 2007-04-04 17:54 - 000107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2020-01-09 15:27 - 2007-04-04 17:53 - 000081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2020-01-09 15:27 - 2007-03-15 15:57 - 000506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2020-01-09 15:27 - 2007-03-15 15:57 - 000443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2020-01-09 15:27 - 2007-03-12 15:42 - 004494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2020-01-09 15:27 - 2007-03-12 15:42 - 003495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2020-01-09 15:27 - 2007-03-12 15:42 - 001400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2020-01-09 15:27 - 2007-03-12 15:42 - 001123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2020-01-09 15:27 - 2007-03-05 11:42 - 000017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2020-01-09 15:27 - 2007-03-05 11:42 - 000015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2020-01-09 15:27 - 2007-01-24 14:27 - 000393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2020-01-09 15:27 - 2007-01-24 14:27 - 000255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2020-01-09 15:27 - 2006-12-08 11:02 - 000251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2020-01-09 15:27 - 2006-12-08 11:00 - 000390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2020-01-09 15:27 - 2006-11-29 12:06 - 004398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2020-01-09 15:27 - 2006-11-29 12:06 - 003426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2020-01-09 15:27 - 2006-11-29 12:06 - 000469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2020-01-09 15:27 - 2006-11-29 12:06 - 000440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2020-01-09 15:27 - 2006-09-28 15:05 - 003977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2020-01-09 15:27 - 2006-09-28 15:05 - 002414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2020-01-09 15:27 - 2006-09-28 15:05 - 000237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2020-01-09 15:27 - 2006-09-28 15:04 - 000364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2020-01-09 15:27 - 2006-07-28 08:31 - 000083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2020-01-09 15:27 - 2006-07-28 08:30 - 000363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2020-01-09 15:27 - 2006-07-28 08:30 - 000236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2020-01-09 15:27 - 2006-07-28 08:30 - 000062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2020-01-09 15:27 - 2006-05-31 06:24 - 000230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2020-01-09 15:27 - 2006-05-31 06:22 - 000354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2020-01-09 15:27 - 2006-03-31 11:41 - 003927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2020-01-09 15:27 - 2006-03-31 11:40 - 002388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2020-01-09 15:27 - 2006-03-31 11:40 - 000352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2020-01-09 15:27 - 2006-03-31 11:39 - 000229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2020-01-09 15:27 - 2006-03-31 11:39 - 000083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2020-01-09 15:27 - 2006-03-31 11:39 - 000062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2020-01-09 15:27 - 2006-02-03 07:43 - 003830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2020-01-09 15:27 - 2006-02-03 07:43 - 002332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2020-01-09 15:27 - 2006-02-03 07:42 - 000355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2020-01-09 15:27 - 2006-02-03 07:42 - 000230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2020-01-09 15:27 - 2006-02-03 07:41 - 000016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2020-01-09 15:27 - 2006-02-03 07:41 - 000014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2020-01-09 15:27 - 2005-12-05 17:09 - 003815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2020-01-09 15:27 - 2005-12-05 17:09 - 002323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2020-01-09 15:27 - 2005-07-22 18:59 - 003807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2020-01-09 15:27 - 2005-07-22 18:59 - 002319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2020-01-09 15:27 - 2005-05-26 14:34 - 003767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2020-01-09 15:27 - 2005-05-26 14:34 - 002297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2020-01-09 15:27 - 2005-03-18 16:19 - 003823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2020-01-09 15:27 - 2005-03-18 16:19 - 002337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2020-01-09 15:27 - 2005-02-05 18:45 - 003544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2020-01-09 15:27 - 2005-02-05 18:45 - 002222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2020-01-09 15:03 - 2020-01-09 14:59 - 000748816 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2020-01-09 13:59 - 2020-01-09 15:27 - 000000000 ____D C:\ProgramData\Package Cache
2020-01-09 13:59 - 2020-01-09 13:59 - 000000000 ____D C:\Users\Leonard\AppData\LocalLow\Hopoo Games, LLC
2020-01-09 13:38 - 2020-01-11 21:55 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2020-01-09 13:38 - 2020-01-10 16:18 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2020-01-09 13:38 - 2020-01-09 13:38 - 000001456 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2020-01-09 13:38 - 2020-01-09 13:38 - 000001444 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2020-01-09 13:38 - 2020-01-09 13:38 - 000001444 _____ C:\ProgramData\Desktop\Spybot-S&D Start Center.lnk
2020-01-09 13:38 - 2020-01-09 13:38 - 000000000 ____D C:\Windows\system32\Tasks\Safer-Networking
2020-01-09 13:38 - 2020-01-09 13:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2020-01-09 13:38 - 2018-02-06 18:04 - 000032168 _____ (Safer-Networking Ltd.) C:\Windows\system32\sdnclean64.exe
2020-01-09 13:37 - 2020-01-09 13:37 - 069910960 _____ (Safer-Networking Ltd. ) C:\Users\Leonard\Downloads\spybotsd-2.7.64.0.exe
2020-01-09 13:36 - 2020-01-09 13:36 - 002473688 _____ (Opera Software) C:\Users\Leonard\Downloads\OperaSetup.exe
2020-01-09 13:31 - 2020-01-11 21:54 - 000006604 _____ C:\ProgramData\DisplaySessionContainer1.log_backup1
2020-01-09 13:27 - 2020-01-09 13:27 - 000000000 ____D C:\Users\Leonard\AppData\Local\D3DSCache
2020-01-09 13:27 - 2020-01-09 13:27 - 000000000 ____D C:\ProgramData\NVIDIA
2020-01-09 13:25 - 2020-01-11 21:54 - 000020896 _____ C:\ProgramData\NVDisplayContainerWatchdog.log_backup1
2020-01-09 13:25 - 2020-01-11 21:54 - 000012964 _____ C:\ProgramData\NVDisplay.ContainerLocalSystem.log_backup1
2020-01-09 13:25 - 2020-01-10 21:29 - 000006608 _____ C:\ProgramData\DisplaySessionContainer2.log_backup1
2020-01-09 13:24 - 2020-01-09 15:31 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2020-01-09 13:24 - 2020-01-09 13:25 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2020-01-09 13:24 - 2020-01-09 13:24 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
2020-01-09 13:23 - 2020-01-09 13:23 - 000000000 ____D C:\Users\Leonard\AppData\Local\Steam
2020-01-09 13:23 - 2020-01-09 13:23 - 000000000 ____D C:\Users\Leonard\AppData\Local\CEF
2020-01-09 13:23 - 2019-10-04 15:15 - 001006800 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2020-01-09 13:23 - 2019-10-04 15:15 - 001006800 _____ C:\Windows\system32\vulkan-1.dll
2020-01-09 13:23 - 2019-10-04 15:15 - 000870096 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2020-01-09 13:23 - 2019-10-04 15:15 - 000870096 _____ C:\Windows\SysWOW64\vulkan-1.dll
2020-01-09 13:23 - 2019-10-04 15:15 - 000552328 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2020-01-09 13:23 - 2019-10-04 15:15 - 000456640 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2020-01-09 13:23 - 2019-10-04 15:15 - 000286416 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2020-01-09 13:23 - 2019-10-04 15:15 - 000286416 _____ C:\Windows\system32\vulkaninfo.exe
2020-01-09 13:23 - 2019-10-04 15:15 - 000260304 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2020-01-09 13:23 - 2019-10-04 15:15 - 000260304 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2020-01-09 13:23 - 2019-10-04 15:14 - 011059400 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2020-01-09 13:23 - 2019-10-04 15:14 - 009492680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2020-01-09 13:23 - 2019-10-04 15:14 - 000676608 _____ C:\Windows\system32\nvofapi64.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 020194504 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 017471368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 005443976 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 005425600 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 004767952 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 002041784 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 001543424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 001472408 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 001164168 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 001136024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 001004936 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 000914120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 000822016 _____ (NVIDIA Corporation) C:\Windows\system32\nvmcumd.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 000810240 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 000656128 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 000633936 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 000572376 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
2020-01-09 13:23 - 2019-10-04 15:13 - 000543952 _____ C:\Windows\SysWOW64\nvofapi.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 000523728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2020-01-09 13:23 - 2019-10-04 15:13 - 000449736 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
2020-01-09 13:23 - 2019-10-04 15:13 - 000237424 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2020-01-09 13:23 - 2019-10-04 15:13 - 000055664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhdap64.dll
2020-01-09 13:23 - 2019-10-04 15:12 - 040412552 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2020-01-09 13:23 - 2019-10-04 15:12 - 035269840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2020-01-09 13:23 - 2019-10-04 15:12 - 005087232 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2020-01-09 13:23 - 2019-10-04 15:12 - 004342736 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2020-01-09 13:23 - 2019-10-04 15:12 - 000858504 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
2020-01-09 13:23 - 2019-10-04 14:53 - 000104564 _____ C:\Windows\system32\nvidia-smi.1.pdf
2020-01-09 13:23 - 2019-10-04 14:53 - 000057400 _____ C:\Windows\system32\nvinfo.pb
2020-01-09 13:19 - 2020-01-10 21:30 - 000000000 ____D C:\Users\Leonard\AppData\Local\Spotify
2020-01-09 13:19 - 2020-01-09 13:19 - 000001860 _____ C:\Users\Leonard\Desktop\Spotify.lnk
2020-01-09 13:19 - 2020-01-09 13:19 - 000001846 _____ C:\Users\Leonard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2020-01-09 13:18 - 2020-01-09 13:18 - 000000000 ____H C:\ProgramData\DP45977C.lfl
2020-01-09 13:18 - 2020-01-09 13:18 - 000000000 ____D C:\Windows\SysWOW64\RTCOM
2020-01-09 13:18 - 2020-01-09 13:18 - 000000000 ____D C:\Program Files\Realtek
2020-01-09 13:17 - 2017-11-16 00:45 - 072520704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2020-01-09 13:17 - 2017-11-16 00:45 - 006038440 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2020-01-09 13:17 - 2017-11-16 00:45 - 003677152 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2020-01-09 13:17 - 2017-11-16 00:45 - 003205600 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2020-01-09 13:17 - 2017-11-16 00:45 - 002922976 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2020-01-09 13:17 - 2017-11-16 00:45 - 000023688 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2020-01-09 13:17 - 2017-11-16 00:44 - 007172904 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
2020-01-09 13:17 - 2017-11-16 00:44 - 007096184 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll
2020-01-09 13:17 - 2017-11-16 00:43 - 000118584 _____ C:\Windows\system32\AcpiServiceVnA64.dll
2020-01-09 13:17 - 2017-11-16 00:43 - 000105304 _____ C:\Windows\system32\audioLibVc.dll
2020-01-09 13:17 - 2017-11-16 00:41 - 003509192 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2020-01-09 13:17 - 2017-11-16 00:41 - 000343704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2020-01-09 13:17 - 2017-11-16 00:41 - 000192976 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2020-01-09 13:17 - 2017-11-16 00:40 - 003562432 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2020-01-09 13:17 - 2017-11-16 00:40 - 001351232 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2020-01-09 13:17 - 2017-11-16 00:40 - 000691672 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2020-01-09 13:17 - 2017-11-16 00:40 - 000151784 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
2020-01-09 13:17 - 2017-11-16 00:40 - 000084608 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
2020-01-09 13:17 - 2017-11-16 00:39 - 001780608 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
2020-01-09 13:17 - 2017-11-16 00:39 - 001591056 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2020-01-09 13:17 - 2017-11-16 00:39 - 000727432 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
2020-01-09 13:17 - 2017-11-16 00:39 - 000708304 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
2020-01-09 13:17 - 2017-11-16 00:39 - 000447712 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
2020-01-09 13:17 - 2017-11-16 00:39 - 000134192 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
2020-01-09 13:17 - 2017-11-16 00:38 - 001965808 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll
2020-01-09 13:17 - 2017-11-16 00:38 - 001508928 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
2020-01-09 13:17 - 2017-11-16 00:38 - 000743960 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
2020-01-09 13:17 - 2017-11-16 00:38 - 000504296 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
2020-01-09 13:17 - 2017-11-16 00:38 - 000445392 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
2020-01-09 13:17 - 2017-11-16 00:38 - 000441264 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
2020-01-09 13:17 - 2017-11-16 00:38 - 000327448 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll
2020-01-09 13:17 - 2017-11-16 00:38 - 000272712 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll
2020-01-09 13:17 - 2017-11-16 00:38 - 000253896 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
2020-01-09 13:17 - 2017-11-16 00:38 - 000253856 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
2020-01-09 13:17 - 2017-11-16 00:38 - 000252872 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
2020-01-09 13:17 - 2017-11-16 00:09 - 014964257 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
2020-01-09 13:14 - 2020-01-11 22:01 - 000000000 ____D C:\Users\Leonard\AppData\Roaming\Spotify
2020-01-09 13:13 - 2020-01-11 21:55 - 000000000 ____D C:\Program Files (x86)\Steam
2020-01-09 13:13 - 2020-01-10 21:42 - 000000000 ____D C:\ProgramData\Packages
2020-01-09 13:13 - 2020-01-09 13:14 - 000896512 _____ (Spotify Ltd) C:\Users\Leonard\Downloads\SpotifySetup.exe
2020-01-09 13:13 - 2020-01-09 13:13 - 001573568 _____ C:\Users\Leonard\Downloads\SteamSetup.exe
2020-01-09 13:13 - 2020-01-09 13:13 - 000001028 _____ C:\Users\Public\Desktop\Steam.lnk
2020-01-09 13:13 - 2020-01-09 13:13 - 000001028 _____ C:\ProgramData\Desktop\Steam.lnk
2020-01-09 13:13 - 2020-01-09 13:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2020-01-09 13:12 - 2020-01-09 13:12 - 000000000 ____D C:\Users\Leonard\AppData\Local\Comms
2020-01-09 13:09 - 2020-01-11 21:55 - 000000000 ____D C:\Users\Leonard\AppData\LocalLow\Mozilla
2020-01-09 13:09 - 2020-01-09 13:09 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-01-09 13:09 - 2020-01-09 13:09 - 000000993 _____ C:\Users\Public\Desktop\Firefox.lnk
2020-01-09 13:09 - 2020-01-09 13:09 - 000000993 _____ C:\ProgramData\Desktop\Firefox.lnk
2020-01-09 13:09 - 2020-01-09 13:09 - 000000000 ____D C:\Users\Leonard\AppData\Roaming\Mozilla
2020-01-09 13:09 - 2020-01-09 13:09 - 000000000 ____D C:\Users\Leonard\AppData\Local\Mozilla
2020-01-09 13:09 - 2020-01-09 13:09 - 000000000 ____D C:\ProgramData\Mozilla
2020-01-09 13:09 - 2020-01-09 13:09 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-01-09 13:09 - 2020-01-09 13:09 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-01-09 13:07 - 2020-01-09 13:07 - 000218288 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2020-01-09 13:07 - 2020-01-09 13:07 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2020-01-09 13:07 - 2020-01-09 13:07 - 000020936 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys
2020-01-09 13:07 - 2020-01-09 13:07 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-01-09 13:07 - 2020-01-09 13:07 - 000002021 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-01-09 13:07 - 2020-01-09 13:07 - 000000000 ____D C:\Users\Leonard\AppData\Local\mbamtray
2020-01-09 13:07 - 2020-01-09 13:07 - 000000000 ____D C:\Users\Leonard\AppData\Local\mbam
2020-01-09 13:07 - 2020-01-09 13:07 - 000000000 ____D C:\Users\Leonard\AppData\Local\cache
2020-01-09 13:07 - 2020-01-09 13:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2020-01-09 13:07 - 2020-01-09 13:07 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-01-09 13:06 - 2020-01-09 13:06 - 000000000 ___HD C:\Users\Leonard\MicrosoftEdgeBackups
2020-01-09 13:06 - 2020-01-09 13:06 - 000000000 ____D C:\Program Files\Malwarebytes
2020-01-09 13:05 - 2020-01-10 21:18 - 000000000 ____D C:\Users\Leonard\AppData\Local\PlaceholderTileLogoFolder
2020-01-09 13:01 - 2020-01-09 13:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-Link
2020-01-09 12:59 - 2020-01-09 12:59 - 000000000 ____D C:\Program Files (x86)\TP-Link
2020-01-09 12:58 - 2020-01-09 12:59 - 000000000 ____D C:\Users\Leonard\AppData\Local\TP-Link
2020-01-09 12:58 - 2020-01-09 12:58 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2020-01-09 12:58 - 2020-01-09 12:58 - 000000000 ____D C:\ProgramData\TP-Link
2020-01-09 12:58 - 2017-12-20 03:25 - 004776168 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\rtwlanu.sys
2020-01-09 12:58 - 2017-12-20 03:25 - 000018548 _____ C:\Windows\system32\netrtwlanu.cat
2020-01-09 12:58 - 2017-12-20 03:18 - 000004453 _____ C:\Windows\system32\LIM_TLWN821N_5_UN.txt
2020-01-09 12:58 - 2017-12-20 03:18 - 000004453 _____ C:\Windows\system32\Drivers\LIM_TLWN821N_5_UN.txt
2020-01-09 12:58 - 2017-12-20 03:18 - 000002703 _____ C:\Windows\system32\PBR_TLWN821N_5_UN.txt
2020-01-09 12:58 - 2017-12-20 03:18 - 000002703 _____ C:\Windows\system32\Drivers\PBR_TLWN821N_5_UN.txt
2020-01-09 12:57 - 2020-01-09 13:32 - 000003378 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-68706545-277898625-3769142786-1001
2020-01-09 12:57 - 2020-01-09 13:32 - 000000000 ___RD C:\Users\Leonard\OneDrive
2020-01-09 12:57 - 2020-01-09 13:05 - 000000000 ____D C:\Users\Leonard\AppData\Local\MicrosoftEdge
2020-01-09 12:57 - 2020-01-09 12:57 - 000001450 _____ C:\Users\Leonard\Desktop\Microsoft Edge.lnk
2020-01-09 12:57 - 2020-01-09 12:57 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2020-01-09 12:56 - 2020-01-09 13:27 - 000000000 ____D C:\Users\Leonard\AppData\Local\Publishers
2020-01-09 12:55 - 2020-01-11 21:54 - 000000000 ____D C:\Users\Leonard
2020-01-09 12:55 - 2020-01-10 21:26 - 000000000 ____D C:\Users\Leonard\AppData\Local\Packages
2020-01-09 12:55 - 2020-01-10 19:36 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-01-09 12:55 - 2020-01-10 19:36 - 000000000 ___RD C:\Users\Leonard\3D Objects
2020-01-09 12:55 - 2020-01-09 13:32 - 000002381 _____ C:\Users\Leonard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-01-09 12:55 - 2020-01-09 12:56 - 000000000 ____D C:\Users\Leonard\AppData\Local\ConnectedDevicesPlatform
2020-01-09 12:55 - 2020-01-09 12:55 - 000000020 ___SH C:\Users\Leonard\ntuser.ini
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Vorlagen
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Startmenü
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Netzwerkumgebung
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Lokale Einstellungen
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Eigene Dateien
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Druckumgebung
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Documents\Eigene Videos
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Documents\Eigene Musik
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Documents\Eigene Bilder
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\AppData\Local\Verlauf
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\AppData\Local\Anwendungsdaten
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Anwendungsdaten
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 ____D C:\Users\Leonard\AppData\Roaming\Adobe
2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 ____D C:\Users\Leonard\AppData\Local\VirtualStore
2020-01-09 12:54 - 2020-01-11 22:01 - 001632524 _____ C:\Windows\system32\PerfStringBackup.INI
2020-01-09 12:52 - 2019-10-07 02:55 - 002874368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2020-01-09 12:50 - 2020-01-11 21:32 - 000000000 ____D C:\Windows\minidump
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Videos
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Musik
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Bilder
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Vorlagen
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Startmenü
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Netzwerkumgebung
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Lokale Einstellungen
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Eigene Dateien
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Druckumgebung
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Videos
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Anwendungsdaten
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Vorlagen
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Startmenü
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Netzwerkumgebung
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Lokale Einstellungen
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Eigene Dateien
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Druckumgebung
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Documents\Eigene Videos
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Anwendungsdaten
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Programme
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\ProgramData\Vorlagen
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\ProgramData\Startmenü
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\ProgramData\Dokumente
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\ProgramData\Anwendungsdaten
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Program Files\Gemeinsame Dateien
2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Dokumente und Einstellungen
2020-01-09 12:48 - 2020-01-11 21:55 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-01-09 12:48 - 2020-01-11 21:32 - 000000000 ____D C:\Windows\system32\SleepStudy
2020-01-09 12:48 - 2020-01-11 17:37 - 000000000 ____D C:\Windows\Panther
2020-01-09 12:48 - 2020-01-10 19:34 - 000257920 _____ C:\Windows\system32\FNTCACHE.DAT
2020-01-09 12:48 - 2020-01-09 12:48 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2020-01-09 12:48 - 2020-01-09 12:48 - 000000000 ____D C:\Windows\system32\Drivers\wd
2020-01-09 12:48 - 2020-01-09 12:48 - 000000000 ____D C:\Windows\ServiceProfiles

==================== Ein Monat (geänderte) ==================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2020-01-11 22:25 - 2019-03-19 04:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-01-11 22:15 - 2019-03-19 04:37 - 000000000 ____D C:\Windows\CbsTemp
2020-01-11 22:10 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\AppReadiness
2020-01-11 22:01 - 2019-03-19 12:16 - 000704076 _____ C:\Windows\system32\perfh007.dat
2020-01-11 22:01 - 2019-03-19 12:16 - 000142100 _____ C:\Windows\system32\perfc007.dat
2020-01-11 22:01 - 2019-03-19 04:50 - 000000000 ____D C:\Windows\INF
2020-01-11 21:54 - 2019-03-19 04:37 - 000524288 _____ C:\Windows\system32\config\BBI
2020-01-10 23:39 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\NDF
2020-01-10 21:42 - 2019-03-19 04:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-01-10 21:20 - 2019-03-19 12:18 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2020-01-10 21:20 - 2019-03-19 12:18 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\SysWOW64\winrm
2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\SysWOW64\WCN
2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\SysWOW64\slmgr
2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\system32\winrm
2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\system32\WCN
2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\system32\slmgr
2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\system32\Printing_Admin_Scripts
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ___SD C:\Windows\SysWOW64\F12
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ___SD C:\Windows\SysWOW64\DiagSvcs
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ___SD C:\Windows\system32\F12
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ___SD C:\Windows\system32\dsc
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ___SD C:\Windows\system32\DiagSvcs
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\SysWOW64\oobe
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\SystemResetPlatform
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\oobe
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\migwiz
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\PolicyDefinitions
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\IME
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files\Windows Defender
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files\Common Files\System
2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2020-01-10 21:20 - 2019-03-19 04:37 - 000000000 ____D C:\Windows\servicing
2020-01-10 21:17 - 2019-03-19 12:17 - 000000000 ____D C:\Windows\OCR
2020-01-10 19:34 - 2019-03-19 04:52 - 000000000 ___RD C:\Windows\PrintDialog
2020-01-10 19:34 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\SystemResources
2020-01-10 19:34 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\appraiser
2020-01-10 19:34 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\ShellExperiences
2020-01-10 19:34 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\ShellComponents
2020-01-10 19:34 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\DiagTrack
2020-01-10 19:34 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\bcastdvr
2020-01-10 18:54 - 2019-03-19 04:37 - 000032768 _____ C:\Windows\system32\config\ELAM
2020-01-10 11:31 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\appcompat
2020-01-09 15:27 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-01-09 13:14 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\ServiceState
2020-01-09 13:07 - 2019-03-19 04:52 - 000000000 ___HD C:\Windows\ELAMBKUP
2020-01-09 12:57 - 2019-03-19 04:52 - 000000000 ____D C:\ProgramData\USOPrivate
2020-01-09 12:52 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\spool
2020-01-09 12:52 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\FxsTmp
2020-01-09 12:51 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2020-01-09 12:51 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\LiveKernelReports
2020-01-09 12:50 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files\Windows NT
2020-01-09 12:48 - 2019-03-19 04:49 - 000028672 _____ C:\Windows\system32\config\BCD-Template

==================== SigCheck ============================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

==================== Ende von FRST.txt ========================

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 08-01-2020
durchgeführt von Leonard (11-01-2020 22:35:59)
Gestartet von C:\Users\Leonard\Desktop
Windows 10 Home Version 1909 18363.535 (X64) (2020-01-09 12:50:52)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-68706545-277898625-3769142786-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-68706545-277898625-3769142786-503 - Limited - Disabled)
Gast (S-1-5-21-68706545-277898625-3769142786-501 - Limited - Disabled)
Leonard (S-1-5-21-68706545-277898625-3769142786-1001 - Administrator - Enabled) => C:\Users\Leonard
WDAGUtilityAccount (S-1-5-21-68706545-277898625-3769142786-504 - Limited - Disabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Malwarebytes version 4.0.4.49 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.0.4.49 - Malwarebytes)
Microsoft OneDrive (HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Mozilla Firefox 72.0.1 (x64 de) (HKLM\...\Mozilla Firefox 72.0.1 (x64 de)) (Version: 72.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 72.0.1 - Mozilla)
NVIDIA Grafiktreiber 432.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 432.00 - NVIDIA Corporation)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8302 - Realtek Semiconductor Corp.)
RogueKiller Version 14.0.4.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 14.0.4.0 - Adlice Software)
Spotify (HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\Spotify) (Version: 1.1.22.633.g1bab253a - Spotify AB)
Spotify (HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\Spotify) (Version: 1.1.22.633.g1bab253a - Spotify AB)
Spotify (HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\Spotify) (Version: 1.1.22.633.g1bab253a - Spotify AB)
Spotify (HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\Spotify) (Version: 1.1.22.633.g1bab253a - Spotify AB)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.7.64.0 - Safer-Networking Ltd.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TP-Link TL-WN821N (HKLM-x32\...\{03468BE2-4451-416D-B045-60F2101122D4}) (Version: 2.1.0 - TP-Link)
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 3.5.3 - Tweaking.com)

Packages:
=========
Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_1.28.8.0_x86__kgqvnymyfvs32 [2020-01-09] (king.com)
Farm Heroes Saga -> C:\Program Files\WindowsApps\king.com.FarmHeroesSaga_5.30.9.0_x86__kgqvnymyfvs32 [2020-01-10] (king.com)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-01-10] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-01-10] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.5.12061.0_x64__8wekyb3d8bbwe [2020-01-10] (Microsoft Studios) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.34.13393.0_x64__8wekyb3d8bbwe [2020-01-10] (Microsoft Corporation) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.956.0_x64__56jybvy8sckqj [2020-01-09] (NVIDIA Corp.)
XING -> C:\Program Files\WindowsApps\XINGAG.XING_3.145.2.0_x86__xpfg3f7e9an52 [2020-01-09] (New Work SE)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-01-09] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\nvshext.dll [2019-10-04] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-01-09] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)

==================== Codecs (Nicht auf der Ausnahmeliste) ====================

==================== Verknüpfungen & WMI ========================

==================== Geladene Module (Nicht auf der Ausnahmeliste) =============


==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ==================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =================

==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ==========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

Da befinden sich 7942 mehr Seiten.

IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\123simsen.com -> www.123simsen.com

Da befinden sich 7942 mehr Seiten.

IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\123simsen.com -> www.123simsen.com

Da befinden sich 7942 mehr Seiten.

IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\123simsen.com -> www.123simsen.com

Da befinden sich 7942 mehr Seiten.

IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\123simsen.com -> www.123simsen.com

Da befinden sich 7942 mehr Seiten.


==================== Hosts Inhalt: =========================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2019-03-19 04:49 - 2020-01-10 16:24 - 000454708 ____R C:\Windows\system32\drivers\etc\hosts
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com

Da befinden sich 15607 zusätzliche Einträge.


==================== Andere Bereiche ===========================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513148\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514148\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944339\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513257\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514273\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944395\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-68706545-277898625-3769142786-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
DNS Servers: 192.168.101.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [{C23099A0-9BAD-4206-8840-EC1C604E2A32}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{8E199E48-1B9E-4E42-BFF9-D1ED9FAC4E1E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{74C3C881-3292-4459-A09D-1E6F5CE9A5C8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{8B15969A-97D3-4D47-B8BD-EA8FB88A9F83}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{9FD1E7DC-5779-46D3-9CB1-3CEC99C18D4F}C:\users\leonard\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\leonard\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{DC157001-0CBB-47BE-8E2E-41A60745C83D}C:\users\leonard\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\leonard\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{C5E30BD3-0E5B-4E44-B99F-3BEA775E2C86}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{AC87B4B7-B15C-4F80-BB71-F5227DFC35CF}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{11166E47-97D9-4C5E-9E74-C6993320BAFD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Risk of Rain 2\Risk of Rain 2.exe () [Datei ist nicht signiert]
FirewallRules: [{2323BF67-6459-48B3-A6CD-6371570E3B2F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Risk of Rain 2\Risk of Rain 2.exe () [Datei ist nicht signiert]
FirewallRules: [{4C546CB5-5FDE-4803-8B7E-D2D644D8321F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kingdom Under Fire 2\KUF2SteamLauncher.exe (Gameforge 4D GmbH -> )
FirewallRules: [{F6E7B600-0373-469F-AE2F-9A5F34922EFE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kingdom Under Fire 2\KUF2SteamLauncher.exe (Gameforge 4D GmbH -> )
FirewallRules: [{A8A32258-88A0-4617-BF31-CF8E5F8E5590}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AoE2DE\AoE2DE_s.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{2815C75A-6FE5-4897-8C0B-991FE84DC792}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AoE2DE\AoE2DE_s.exe (Microsoft Corporation -> Microsoft Corporation)
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

==================== Wiederherstellungspunkte =========================

ACHTUNG: Systemwiederherstellung ist deaktiviert (Total:111.22 GB) (Free:35.03 GB) (31%)

==================== Fehlerhafte Geräte im Gerätemanager ============


==================== Fehlereinträge in der Ereignisanzeige: ========================

Applikationsfehler:
==================
Error: (01/11/2020 09:55:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
Exception code: 0xe06d7363
Fault offset: 0x000000000003a839
Faulting process ID: 0x26c
Faulting application start time: 0x01d5c8c9e6709ec6
Faulting application path: C:\Windows\system32\ctfmon.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report ID: be451b2b-a212-439d-8a16-89642ac820b7
Faulting package full name:
Faulting package-relative application ID:

Error: (01/11/2020 09:55:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
Exception code: 0xe06d7363
Fault offset: 0x000000000003a839
Faulting process ID: 0x1ffc
Faulting application start time: 0x01d5c8c9e3718069
Faulting application path: C:\Windows\system32\ctfmon.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report ID: a6564c4d-95e2-4ca7-829d-9ef10a254baf
Faulting package full name:
Faulting package-relative application ID:

Error: (01/11/2020 09:55:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
Exception code: 0xe06d7363
Fault offset: 0x000000000003a839
Faulting process ID: 0x2a30
Faulting application start time: 0x01d5c8c9e072a0f1
Faulting application path: C:\Windows\system32\ctfmon.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report ID: 2e6ef05e-a0aa-45e8-9bbe-1b76b9f666e5
Faulting package full name:
Faulting package-relative application ID:

Error: (01/11/2020 09:55:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
Exception code: 0xe06d7363
Fault offset: 0x000000000003a839
Faulting process ID: 0x2b60
Faulting application start time: 0x01d5c8c9dd75078a
Faulting application path: C:\Windows\system32\ctfmon.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report ID: dc328812-db4e-429c-afa6-af639dce0139
Faulting package full name:
Faulting package-relative application ID:

Error: (01/11/2020 09:55:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
Exception code: 0xe06d7363
Fault offset: 0x000000000003a839
Faulting process ID: 0x293c
Faulting application start time: 0x01d5c8c9da76c0e8
Faulting application path: C:\Windows\system32\ctfmon.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report ID: b15dc70f-ca3d-4991-920e-a1e76aa57d37
Faulting package full name:
Faulting package-relative application ID:

Error: (01/11/2020 09:55:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
Exception code: 0xe06d7363
Fault offset: 0x000000000003a839
Faulting process ID: 0x1fa8
Faulting application start time: 0x01d5c8c9d7791fb3
Faulting application path: C:\Windows\system32\ctfmon.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report ID: 363b22b9-e56d-459c-91a0-08d336e09c32
Faulting package full name:
Faulting package-relative application ID:

Error: (01/11/2020 09:55:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
Exception code: 0xe06d7363
Fault offset: 0x000000000003a839
Faulting process ID: 0x21fc
Faulting application start time: 0x01d5c8c9d479b3d9
Faulting application path: C:\Windows\system32\ctfmon.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report ID: 6a5dbc23-8a88-41bd-b526-347b9174b307
Faulting package full name:
Faulting package-relative application ID:

Error: (01/11/2020 09:55:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
Exception code: 0xe06d7363
Fault offset: 0x000000000003a839
Faulting process ID: 0x2178
Faulting application start time: 0x01d5c8c9d09e9b2a
Faulting application path: C:\Windows\system32\ctfmon.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report ID: 222da474-4953-4c77-80ea-e32bd90da535
Faulting package full name:
Faulting package-relative application ID:


Systemfehler:
=============
Error: (01/11/2020 09:55:09 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\Windows\system32\Rtlihvs.dll
Error Code: 126

Error: (01/11/2020 09:32:59 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1 (0xfffff8051cc5b010, 0x00000000000000ff, 0x0000000000000000, 0xfffff8051ddd95ae). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 8f06bf1e-541f-4817-bbec-03352736ad88.

Error: (01/11/2020 09:32:56 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\Windows\system32\Rtlihvs.dll
Error Code: 126

Error: (01/11/2020 09:32:55 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 22:30:25 on ‎11.‎01.‎2020 was unexpected.

Error: (01/11/2020 09:30:30 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff6fb7dbedde0, 0x0000000000000000, 0xfffff8056a0e78be, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: bea19e77-5c5b-4d98-97ec-fe8b94df829e.

Error: (01/11/2020 09:30:26 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\Windows\system32\Rtlihvs.dll
Error Code: 126

Error: (01/11/2020 09:30:25 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 22:23:09 on ‎11.‎01.‎2020 was unexpected.

Error: (01/10/2020 09:29:51 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\Windows\system32\Rtlihvs.dll
Error Code: 126


Windows Defender:
===================================
Date: 2020-01-10 18:54:11.855
Description:
Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: Behavior Monitoring
Error Code: 0x80508023
Error description: Auf dem Gerät wurde keine Schadsoftware oder andere potenziell unerwünschte Software gefunden.
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

Date: 2020-01-10 16:22:24.686
Description:
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.307.2007.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16600.7
Error code: 0x8024402f
Error description: Unerwartetes Problem bei der Überprüfung auf Updates. Informationen zum Installieren von Updates oder zur Problembehandlung finden Sie unter "Hilfe und Support".

Date: 2020-01-09 20:10:39.614
Description:
Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: Behavior Monitoring
Error Code: 0x80508023
Error description: Auf dem Gerät wurde keine Schadsoftware oder andere potenziell unerwünschte Software gefunden.
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

CodeIntegrity:
===================================

Date: 2020-01-11 21:55:10.691
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-01-11 21:55:10.651
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-01-11 21:34:36.616
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2020-01-11 21:32:58.184
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-01-11 21:32:58.155
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-01-11 21:30:28.345
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-01-11 21:30:28.323
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-01-11 13:03:39.789
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

==================== Speicherinformationen ===========================

BIOS: American Megatrends Inc. F10 09/18/2018
Hauptplatine: Gigabyte Technology Co., Ltd. Z370 AORUS ULTRA GAMING WIFI-CF
Prozessor: Intel(R) Core(TM) i7-8700K CPU @ 3.70GHz
Prozentuale Nutzung des RAM: 37%
Installierter physikalischer RAM: 16326.27 MB
Verfügbarer physikalischer RAM: 10134.73 MB
Summe virtueller Speicher: 19270.27 MB
Verfügbarer virtueller Speicher: 10656.82 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:111.22 GB) (Free:35.03 GB) NTFS
Drive d: () (Fixed) (Total:931.39 GB) (Free:931.18 GB) NTFS

\\?\Volume{a16fb195-0000-0000-0000-100000000000}\ (System-reserviert) (Fixed) (Total:0.57 GB) (Free:0.11 GB) NTFS

==================== MBR & Partitionstabelle ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 111.8 GB) (Disk ID: A16FB195)
Partition 1: (Active) - (Size=579 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.2 GB) - (Type=07 NTFS)

==========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: 2AAA9BAC)

Partition: GPT.

==================== Ende von Addition.txt =======================

One Updater. No AV site has adressed it. What files are associated?

$
0
0
It seems to work like antivirus 2007. Knowing what files were involved, I got rid of av2007 and used that computer for years. Does anyone know what trojans and files are involved with one updater?

Manual Removal Guide for PU.Mindspark.DailyProductivityTools

$
0
0
The following instructions have been created to help you to get rid of "PU.Mindspark.DailyProductivityTools" manually.
Use this guide at your own risk; software should usually be better suited to remove malware, since it is able to look deeper.

If this guide was helpful to you, please consider donating towards this site.

Threat Details:

Categories:
  • pups

Description:
PU.Mindspark.DailyProductivityTools installs a toolbar by Mindspark Interactive Network.
Removal Instructions:

Files:

Important: There are more files that cannot be safely described in simple words. Please use Spybot-S&D to remove them.

Folders:

Please use Windows Explorer or another file manager of your choice to locate and delete these folders.
  • The directory at "<$LOCALAPPDATA>\Google\Chrome\User Data\Default\Extensions\difcnlhbpohkmlhkpkimihocbagbijii".
  • The directory at "<$LOCALAPPDATA>\Google\Chrome\User Data\Default\Local Extension Settings\difcnlhbpohkmlhkpkimihocbagbijii".
Make sure you set your file manager to display hidden and system files. If PU.Mindspark.DailyProductivityTools uses rootkit technologies, use our RootAlyzer or our Total Commander anti-rootkit plugins.
You will have to use a global search for files without a name specified. Be extra careful, because just the name might not be enough to identify folders!

Final Words:

If neither Spybot-S&D nor self help did resolve the issue or you would prefer one on one help,
  1. Please read these instructions before requesting assistance,
  2. Then start your own thread in the Malware Removal Forum where a volunteer analyst will advise you as soon as available.


There are more files or system entries belonging to this product that <$SPYBOTSD> can remove, but that cannot be easily described in text. Please use <$SPYBOTSD> to make sure <$PRODUCTNAME> gets completely removed.

Closing Windows 7 and removing Spybot professional

$
0
0
Hi, I will be closing down my old Windows 7 computer and will be removing the Spybot Professional that will expire in Mar. I have no problem with any time left on it. I got my money's worth. :) I have since purchase a new Windows 10 and have already put in Spybot Professional in it. (Would not have a computer without it). My question is this. I want to make sure that I am not on the auto-renewal program. I have my receipts, but am not sure where to find out if I agreed to an auto-renewal. Can you point me in the right direction? I do not want to accidentally cancel my new subscription and will be renewing it when it comes due.

Paid for two computers, now what?

$
0
0
I took a chance and paid for Home protection licensing for two computers. On my desktop I downloaded SpyBot and updated the one year contract that had expired.

I fired up my laptop and tried to update the expired SpyBot license on it as well. I am asked to buy another license. I have no idea how to proceed.

Thanks.

An error (different error) occured during antivirus updates

$
0
0
Update Log


[i] 20-01-17 12:30:52 THttpUpdateDaemon HTTP daemon on port 21321 closed.
[+] 20-01-17 12:34:42 THttpUpdateDaemon Background Updating Service got started...
[i] 20-01-17 12:34:42 THttpUpdateDaemon Listening on port 21321
[i] 20-01-17 12:34:42 THttpUpdateDaemon Successfully started listening on port 21321.
[i] 20-01-17 13:48:20 THttpUpdateDaemon HTTP daemon on port 21321 closed.
[+] 20-01-17 13:59:37 THttpUpdateDaemon Background Updating Service got started...
[i] 20-01-17 13:59:37 THttpUpdateDaemon Listening on port 21321
[i] 20-01-17 13:59:37 THttpUpdateDaemon Successfully started listening on port 21321.
SDUpdSvc.exe [2020-01-17 14:21:13] [+] Updating Service is active.
SDUpdSvc.exe [2020-01-17 14:21:13] [.] Trying to retrieve update info file from http://updates1.safer-networking.org/spybotsd2.uid...
SDUpdSvc.exe [2020-01-17 14:21:14] [+] Retrieved update info file.
SDUpdSvc.exe [2020-01-17 14:21:14] [.] Info file part done.
SDUpdSvc.exe [2020-01-17 14:21:15] [.] Testing which updates apply to this version...
SDUpdSvc.exe [2020-01-17 14:21:15] [+] No updates required.
SDUpdSvc.exe [2020-01-17 14:21:15] +++
SDUpdSvc.exe [2020-01-17 14:26:02] [+] Updating Service is active.
SDUpdSvc.exe [2020-01-17 14:26:02] [.] Trying to retrieve update info file from http://updates3.safer-networking.org/spybotsd2.uid...
SDUpdSvc.exe [2020-01-17 14:26:03] [+] Retrieved update info file.
SDUpdSvc.exe [2020-01-17 14:26:03] [.] Info file part done.
SDUpdSvc.exe [2020-01-17 14:26:03] [.] Testing which updates apply to this version...
SDUpdSvc.exe [2020-01-17 14:26:03] [+] No updates required.
SDUpdSvc.exe [2020-01-17 14:26:03] +++
SDUpdSvc.exe [2020-01-19 09:06:36] [+] Updating Service is active.
SDUpdSvc.exe [2020-01-19 09:06:36] [.] Trying to retrieve update info file from http://updates2.safer-networking.org/spybotsd2.uid...
SDUpdSvc.exe [2020-01-19 09:06:38] [+] Retrieved update info file.
SDUpdSvc.exe [2020-01-19 09:06:38] [.] Info file part done.
SDUpdSvc.exe [2020-01-19 09:06:38] [.] Testing which updates apply to this version...
SDUpdSvc.exe [2020-01-19 09:06:38] [+] No updates required.
SDUpdSvc.exe [2020-01-19 09:06:38] +++
SDUpdSvc.exe [2020-01-20 09:45:31] [+] Updating Service is active.
SDUpdSvc.exe [2020-01-20 09:45:36] [.] Trying to retrieve update info file from http://updates3.safer-networking.org/spybotsd2.uid...
SDUpdSvc.exe [2020-01-20 09:45:36] [+] Retrieved update info file.
SDUpdSvc.exe [2020-01-20 09:45:37] [.] Info file part done.
SDUpdSvc.exe [2020-01-20 09:45:37] [.] Testing which updates apply to this version...
SDUpdSvc.exe [2020-01-20 09:45:37] [+] No updates required.
SDUpdSvc.exe [2020-01-20 09:45:37] +++
SDUpdSvc.exe [2020-01-20 09:47:26] [+] Updating Service is active.
SDUpdSvc.exe [2020-01-20 09:47:26] [.] Trying to retrieve update info file from http://updates2.safer-networking.org/spybotsd2.uid...
SDUpdSvc.exe [2020-01-20 09:47:27] [+] Retrieved update info file.
SDUpdSvc.exe [2020-01-20 09:47:27] [.] Info file part done.
SDUpdSvc.exe [2020-01-20 09:47:27] [.] Testing which updates apply to this version...
SDUpdSvc.exe [2020-01-20 09:47:27] [+] No updates required.
SDUpdSvc.exe [2020-01-20 09:47:27] +++
SDUpdSvc.exe [2020-01-20 10:00:39] [+] Updating Service is active.
SDUpdSvc.exe [2020-01-20 10:00:39] [.] Trying to retrieve update info file from http://updates2.safer-networking.org/spybotsd2.uid...
SDUpdSvc.exe [2020-01-20 10:00:40] [+] Retrieved update info file.
SDUpdSvc.exe [2020-01-20 10:00:40] [.] Info file part done.
SDUpdSvc.exe [2020-01-20 10:00:40] [.] Testing which updates apply to this version...
SDUpdSvc.exe [2020-01-20 10:00:40] [+] No updates required.
SDUpdSvc.exe [2020-01-20 10:00:40] +++


This just started last week.
Attached Images

Both Computers Crushed Under 100% CPU and 80%+ Memory Usage

$
0
0
I apologize if this duplicates any thread or if it is in the incorrect location, it has taken over an hour to get online, registered, and starting this post as both of my computers (laptop and desktop) have exploded with Live Protection dialog processes (apparently responding to the waterfall of Windows Problem Reporting (32 bit) processes that I see in Task Manager). I think that my first dial-up was faster.

I will check back tomorrow when I have some patience restored. I am wondering if there is a known issue that has shown up in the past 24-72 hours. Did Microsoft or Spybot push out a recent update that isn't playing well with the other?

I have rebooted both computers with no improvement (takes forever to start up as Live Protection scans all tray apps) and both are running Win10 and Spybot +AV v2.7

I will happily provide more information. I will also check my registered eMail address tomorrow when I can hopefully stomach the lag between keystrokes and the appearance of the characters on screen.

Thank you in advance.

Can't create boot cd image

$
0
0
I've seen two other posts with the same problems and no answers to fix the issue. I'm just wondering why.

In my case,

Quote:

Image file is 797876224 bytes
ERROR: Image is 115892224 bytes too large (681984000)
(use -m to override or try -o to optimize storage)

Check the above for error messages, we could not create a valid ISO file.
which I don't understand because I have no control over allocating space for or specifying an image size. Only spybot2 was chosen to be added.

Earlier in the log,

Quote:

Could not copy C:\WINDOWS\winhlp32.exe to C:\SpybotBootCD\Mount\Windows\System32!
Could not copy C:\WINDOWS\system32\winver.exe to C:\SpybotBootCD\Mount\Windows\System32!
Could not copy C:\WINDOWS\system32\notepad.exe to C:\SpybotBootCD\Mount\Windows\System32!
Could not copy C:\WINDOWS\system32\xchm.exe to C:\SpybotBootCD\Mount\Windows\System32!
File operation failed (error 0x02)!
this leaves me confused because if it couldn't copy some files, that would lead me to think the image would be undersized as opposed to over.

Just what needs to happen here?

Spybot Anti-Beacon | disables windows location

Can't use Windows Defender Real-time Protection: can't stop Security Center Service

$
0
0
I have Spybot Search & Destroy + AV 2.7.64.0 Professional (Settings 2.7.64.139) on a PC with Windows 10 Pro.

I would like to use Windows Defender Real-time Protection. However, I can't because Windows says "You're using other antivirus providers". The only other antivirus Windows shows is Spybot.

In the Spybot Start Center, I checked "Advanced User Mode", then clicked "Settings" & selected "System Services". I tried to stop the Spybot Security Center Service, but the Stop button is greyed out and inoperative.

What can I do? The only thing I've found that works is to uninstall Spybot. I don't want to do that because I will have wasted my money buying the Professional version.

Fix selected freezes

$
0
0
Hey All. After running my scan, I check the "Fix Selected" box. But within about 5 seconds, I get the "not responding" message. It has happened the last 3 times. Running program under "Run as admin" Any advice?
Thanks in advance
Carl

Checksum errors

$
0
0
I have tried to update Spybot detection rules for 2 days now and keep getting BAD CHECKSUM errors from ALL servers. How do I fix this ?

Thanks,

fab

Scheduler not working

$
0
0
Hi,
Thank you for accepting me to the forum.

I have been using Spybot version 1.62? (I think) free version for many years but due to the fact I have decided to keep using Win7 for a while, I decided to upgrade my security and have purchase a licence for v2.7 ( I did purchase a licence once before but didn't like the interface so never used it. The interface on this version is much more user friendly).

None of my scheduled tasks are running on the schedule. I have adjusted and readjusted the settings (running as administrator), ticked whether logged on or not; wake computer if asleep etc.etc on a number of occasions but to no avail.
Do you have any suggestions of what may be the problem?

I am disappointed as the old, free version worked perfectly and scanned on whatever schedule I set it to.

Thank you for any assistance.

Malwarbytes is missing...

$
0
0
i just noticed. gone, paid version i had for awhile now and it's just an empty folder now. plus this laptop thoughnot the fastest does seem to be running terribly slow so i thought i'd check in here and see if there was a real problem. i realize i'll need to contact malwarebytes about their program, but i thought if something got it then maybe this should be my first step. the aswMBR as the last time i attempted to run crashedmy pc. thanks!

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-02-2020 02
Ran by ronny (administrator) on LAPTOP-4HPCQJEC (LENOVO 81DE) (02-02-2020 20:34:56)
Running from C:\Users\ronny\Desktop
Loaded Profiles: ronny (Available Profiles: ronny)
Platform: Windows 10 Home Version 1809 17763.678 (X64) Language: English (United States)
Default browser: "C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe" "%1"
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(A.V.M. SOFTWARE, INC. -> AVM Software) C:\Program Files (x86)\Paltalk\update\pt_update_service.exe
(Acrox) [File not signed] C:\Blackweb Gaming AP\Blackweb Gaming AP.exe
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(DEVGURU Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler64.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_0a3294d3216a4a83\jhi_service.exe
(Intel(R) pGFX -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_a7428663aca90897\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_a7428663aca90897\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_c59c7d36072c06c5\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_c59c7d36072c06c5\IntelCpHeciSvc.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\VantageService\LenovoVantageService.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Microsoft Corporation -> Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.mspaint_6.1907.18017.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.19081.22010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1910.0.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12430.20136.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12430.20136.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19122.138.0_x64__8wekyb3d8bbwe\YourPhoneServer\YourPhoneServer.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.20011.10711.0_x64__8wekyb3d8bbwe\Music.UI.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.20011.10711.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17763.649_none_220d598194935132\TiWorker.exe
(Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) C:\WINDOWS\System32\drivers\AdminService.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\NisSrv.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Qualcomm Atheros -> Qualcomm Technologies Inc.) C:\WINDOWS\System32\drivers\QcomWlanSrvx64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\WINDOWS\System32\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\WINDOWS\System32\SynTPEnhService.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18390912 2019-05-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506176 2019-05-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506176 2019-05-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [Blackweb Gaming AP] => C:\Blackweb Gaming AP\Blackweb Gaming AP.exe [4572160 2018-12-03] (Acrox) [File not signed]
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-12] (Logitech, Inc. -> Logitech Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [646160 2019-12-11] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [Paltalk] => C:\Program Files (x86)\Paltalk\Paltalk.exe [27530616 2020-01-07] (A.V.M. SOFTWARE, INC. -> AVM Software)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.130\Installer\chrmstp.exe [2020-01-22] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\79.1.2.43\Installer\chrmstp.exe [2020-01-17] (Brave Software, Inc.) [File not signed]
Startup: C:\Users\ronny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk [2019-10-06]
ShortcutTarget: Logitech . Product Registration.lnk -> C:\Program Files (x86)\Logitech\Ereg\eReg.exe (Logitech -> Leader Technologies/Logitech)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {03DECDDE-F4B1-44F3-9409-39BF17651149} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0ADF630D-EDBE-4DCC-A006-37EA17B9829E} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506176 2019-05-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {0C25F01C-2626-4E63-9C4A-C1B0D1A0F5A7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0DC837F4-B0A7-4D92-BBC2-208778FABD04} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1240656 2019-09-11] (Adobe Inc. -> Adobe Systems)
Task: {112CBE13-520D-4DCF-993C-30FAF813B393} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [157320 2019-12-19] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {2FD0F9A8-C83D-4FCC-BD4C-839960DC14AA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {31FD8A2F-9D5E-4525-AFCF-2D4B03D890EF} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\Explorer.exe /NOUACCHECK
Task: {32A0F6A1-AC7F-44BD-AA4E-E35787A61D78} - System32\Tasks\Maxthon5 Update => C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe [170784 2019-08-30] (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
Task: {38FAD77F-6D48-4035-BF92-011D322C5647} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-01-25] (Adobe Inc. -> Adobe)
Task: {3BEB2327-EE69-4E8B-B89A-DB4ECDABEE48} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4981CF69-42E6-4140-B62A-D15905D49575} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_321_pepper.exe [1453624 2020-01-25] (Adobe Inc. -> Adobe)
Task: {4CC26219-5974-4334-A597-B6CAE981AA23} - System32\Tasks\Lenovo\LenovoWelcomeTask => C:\ProgramData\Lenovo\ImController\Plugins\LenovoFirstRunExperiencePackage\x86\LenovoWelcomeTask.exe
Task: {8ED2C411-7510-43C9-A180-9D84045CF0DC} - System32\Tasks\RtHDVBg_LENOVO_DOLBYDRAGON => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506176 2019-05-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {913DEC7B-6404-4696-8410-CBAD196D382C} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [157320 2019-12-19] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {D8C30AAD-88BE-464B-9998-1CAD53EE81F5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-08-30] (Google Inc -> Google LLC)
Task: {E08247A7-2E4E-46DE-BA0B-ED3A2B7B3D52} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-08-30] (Google Inc -> Google LLC)
Task: {F81F0636-106C-44EF-B47C-C0716C4AA000} - System32\Tasks\Microsoft\Windows\RetailDemo\CleanupOfflineContent => {61f77d5e-afe9-400b-a5e6-e9e80fc8e601} C:\Windows\System32\RDXTaskFactory.dll [411136 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
Task: {FA6D3E51-BDBD-490F-B0FD-8CECC50F7079} - System32\Tasks\RtHDVBg_Dolby => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506176 2019-05-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{0bcac531-5d49-47cd-83a9-fde31a860b63}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{3c4cf5c5-956d-414c-aa7f-b1f6f0c46421}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{40819c4a-134a-456a-863f-af0c92d95b2b}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{4127e473-dfe3-4b25-bc2c-0156f88a971e}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{8def4e12-00e5-41e9-8a5a-38726c85de90}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{911b4540-8355-45a8-a572-9d59dc506868}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{9160b299-4de8-46a3-89d4-bf9551ab42a3}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{95b16433-0be1-43d3-a9ce-053d12f5f22c}: [DhcpNameServer] 150.208.1.2

Internet Explorer:
==================
HKU\S-1-5-21-4109447768-91167649-2371174200-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP
HKU\S-1-5-21-4109447768-91167649-2371174200-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-4109447768-91167649-2371174200-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
SearchScopes: HKU\S-1-5-21-4109447768-91167649-2371174200-1001 -> DefaultScope {1DE58705-3063-4F2A-835E-EB8A8011C103} URL =
SearchScopes: HKU\S-1-5-21-4109447768-91167649-2371174200-1001 -> {1DE58705-3063-4F2A-835E-EB8A8011C103} URL =
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_241\bin\ssv.dll [2020-01-15] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_241\bin\jp2ssv.dll [2020-01-15] (Oracle America, Inc. -> Oracle Corporation)

Edge:
======
DownloadDir: C:\Users\ronny\Downloads
Edge Notifications: HKU\S-1-5-21-4109447768-91167649-2371174200-1001 -> hxxps://www.facebook.com
Edge Extension: (uBlock Origin) -> EdgeExtension_37833NikRollsuBlockOrigin_f8jsg5mm64m62 => C:\Program Files\WindowsApps\37833NikRolls.uBlockOrigin_1.15.24.0_neutral__f8jsg5mm64m62 [2019-10-08]
Edge Extension: (Autofill for Microsoft Edge by Fillr) -> EdgeExtension_FillrFillrAutofillforEdge_wmnk5xzcp70cp => C:\Program Files\WindowsApps\Fillr.FillrAutofillforEdge_0.2.13.0_neutral__wmnk5xzcp70cp [2019-10-08]

FireFox:
========
FF DefaultProfile: fningdqf.default
FF DefaultProfile: maib197h.default
FF ProfilePath: C:\Users\ronny\AppData\Roaming\Mozilla\SeaMonkey\Profiles\fningdqf.default [2019-10-07]
FF Extension: (DOM Inspector) - C:\Users\ronny\AppData\Roaming\Mozilla\SeaMonkey\Profiles\fningdqf.default\Extensions\inspector@mozilla.org.xpi [2019-10-02] [Legacy] [not signed]
FF Extension: (ChatZilla) - C:\Users\ronny\AppData\Roaming\Mozilla\SeaMonkey\Profiles\fningdqf.default\Extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}.xpi [2019-10-02] [Legacy] [not signed]
FF Extension: (Lightning) - C:\Users\ronny\AppData\Roaming\Mozilla\SeaMonkey\Profiles\fningdqf.default\Extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103} [2019-10-02] [Legacy] [not signed]
FF ProfilePath: C:\Users\ronny\AppData\Roaming\Mozilla\Firefox\Profiles\maib197h.default [2019-08-26]
FF ProfilePath: C:\Users\ronny\AppData\Roaming\Mozilla\Firefox\Profiles\g2q5qzsk.default-release [2020-02-01]
FF Notifications: Mozilla\Firefox\Profiles\g2q5qzsk.default-release -> hxxps://www.facebook.com
FF Extension: (uBlock Origin) - C:\Users\ronny\AppData\Roaming\Mozilla\Firefox\Profiles\g2q5qzsk.default-release\Extensions\uBlock0@raymondhill.net.xpi [2020-01-28]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt => not found
FF Plugin-x32: @flyordie.com/GamesPlugin -> C:\Program Files (x86)\Flyordie Plugin\npfod.dll [2020-01-15] (Solware IT Ltd -> Solware)
FF Plugin-x32: @java.com/DTPlugin,version=11.241.2 -> C:\Program Files (x86)\Java\jre1.8.0_241\bin\dtplugin\npDeployJava1.dll [2020-01-15] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.241.2 -> C:\Program Files (x86)\Java\jre1.8.0_241\bin\plugin2\npjp2.dll [2020-01-15] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @tools.brave.com/BraveSoftware Update;version=3 -> C:\Program Files (x86)\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2019-12-19] (Brave Software, Inc. -> BraveSoftware Inc.)
FF Plugin-x32: @tools.brave.com/BraveSoftware Update;version=9 -> C:\Program Files (x86)\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2019-12-19] (Brave Software, Inc. -> BraveSoftware Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2019-12-13] (Google LLC -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2019-12-13] (Google LLC -> Google LLC)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-12-02] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4109447768-91167649-2371174200-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\ronny\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2017-05-18] (Unity Technologies SF -> Unity Technologies ApS)

Chrome:
=======
CHR Profile: C:\Users\ronny\AppData\Local\Google\Chrome\User Data\Default [2020-01-23]
CHR HomePage: Default -> hxxp://www.msn.com/
CHR StartupUrls: Default -> "hxxp://search.conduit.com/?ctid=CT3324319&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPCB0F839A-04A4-4A4D-ADAD-AD1A6A976444&SSPV=","hxxps://www.google.com/"
CHR Extension: (Slides) - C:\Users\ronny\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-08-30]
CHR Extension: (Docs) - C:\Users\ronny\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-08-30]
CHR Extension: (Google Drive) - C:\Users\ronny\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-08-30]
CHR Extension: (YouTube) - C:\Users\ronny\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-08-30]
CHR Extension: (File Converter Extension) - C:\Users\ronny\AppData\Local\Google\Chrome\User Data\Default\Extensions\blppeofoijnlbofllclklacdlfckbkok [2020-01-23]
CHR Extension: (Adobe Acrobat) - C:\Users\ronny\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-12-29]
CHR Extension: (Sheets) - C:\Users\ronny\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-08-30]
CHR Extension: (Google Docs Offline) - C:\Users\ronny\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-01-17]
CHR Extension: (Glossy Blue) - C:\Users\ronny\AppData\Local\Google\Chrome\User Data\Default\Extensions\nheaocaplknjkpcnbadlgfpdfjaabiml [2019-08-30]
CHR Extension: (Chrome Web Store Payments) - C:\Users\ronny\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-11-13]
CHR Extension: (Gmail) - C:\Users\ronny\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-08-30]
CHR Extension: (Chrome Media Router) - C:\Users\ronny\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-01-17]
CHR Profile: C:\Users\ronny\AppData\Local\Google\Chrome\User Data\System Profile [2020-01-17]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AtherosSvc; C:\WINDOWS\System32\drivers\AdminService.exe [420472 2019-04-11] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S2 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [157320 2019-12-19] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [157320 2019-12-19] (Brave Software, Inc. -> BraveSoftware Inc.)
R2 Dolby DAX2 API Service; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [189464 2019-01-21] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\WINDOWS\System32\Intel\iCLS Client\lib\SocketHeciServer.exe [780600 2018-10-02] (Intel(R) Trust Services -> Intel(R) Corporation)
S2 Intel(R) TPM Provisioning Service; C:\WINDOWS\System32\Intel\iCLS Client\lib\TPMProvisioningService.exe [718656 2018-10-02] (Intel(R) Trust Services -> Intel(R) Corporation)
S2 IntelAudioService; C:\WINDOWS\system32\cAVS\Intel(R) Audio Service\IntelAudioService.exe [195536 2018-01-12] (Microsoft Windows Hardware Compatibility Publisher -> Intel)
R2 jhi_service; C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_0a3294d3216a4a83\jhi_service.exe [578752 2018-11-13] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R2 LenovoVantageService; C:\Program Files (x86)\Lenovo\VantageService\LenovoVantageService.exe [18200 2019-07-24] (Lenovo -> Lenovo Group Ltd.)
S2 MxService; C:\Program Files (x86)\Maxthon5\Bin\MxService.exe [178976 2019-08-30] (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
R2 paltalk_update_service; C:\Program Files (x86)\Paltalk\update\pt_update_service.exe [1229688 2019-08-22] (A.V.M. SOFTWARE, INC. -> AVM Software)
R2 QcomWlanSrv; C:\WINDOWS\System32\drivers\QcomWlanSrvx64.exe [191976 2019-03-07] (Qualcomm Atheros -> Qualcomm Technologies Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [267552 2019-05-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2019-09-23] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [780328 2019-09-23] (DEVGURU Co., Ltd. -> DEVGURU Co., LTD.)
R2 SynTPEnhService; C:\WINDOWS\System32\SynTPEnhService.exe [353320 2018-10-29] (Synaptics Incorporated -> Synaptics Incorporated)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [79120 2016-03-03] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 ApkbfiltrService; C:\WINDOWS\System32\drivers\Apkbfiltr.sys [31016 2015-07-23] (Alps Electric Co., LTD. -> Alps Electric Co., Ltd.)
R3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [136040 2019-09-23] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R0 iaStorAC; C:\WINDOWS\System32\drivers\iaStorAC.sys [1017200 2019-03-25] (Intel(R) Rapid Storage Technology -> Intel Corporation)
R3 JmUsbCcgp; C:\WINDOWS\System32\drivers\jmccgp.sys [17136 2009-07-28] (JMicron Technology Corp. -> JMicron Technology Corp.)
R3 necbatt; C:\WINDOWS\System32\drivers\necbatt.sys [34880 2018-05-09] (NEC Personal Computers, Ltd. -> NEC Personal Computers, Ltd.)
R3 Qcamain10x64; C:\WINDOWS\System32\drivers\Qcamain10x64.sys [2372072 2019-03-07] (Qualcomm Atheros -> Qualcomm Atheros, Inc.)
S3 rdacpi; C:\WINDOWS\System32\drivers\rdacpi.sys [41784 2017-07-13] (EA Excelsior Hang Tong Computer Technology Limited -> )
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [605696 2018-09-15] (Microsoft Windows -> Realtek )
S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [421312 2017-10-18] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [48992 2019-01-23] (Synaptics Incorporated -> Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [48992 2019-01-23] (Synaptics Incorporated -> Synaptics Incorporated)
S3 ssudcdf; C:\WINDOWS\System32\drivers\ssudcdf.sys [36608 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr))
R3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166760 2019-09-23] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 stdriver; C:\WINDOWS\system32\DRIVERS\stdriverx64.sys [54664 2019-08-24] (NCH Software Pty Ltd -> )
R3 SynRMIHID; C:\WINDOWS\System32\drivers\SynRMIHID.sys [61480 2018-10-29] (Synaptics Incorporated -> Synaptics Incorporated)
U3 TrueSight; C:\WINDOWS\System32\drivers\truesight.sys [28272 2019-10-07] (Adlice -> )
R3 usbrndis6; C:\WINDOWS\System32\drivers\usb80236.sys [24576 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [45664 2019-12-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [355760 2019-12-08] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2019-12-08] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-02-02 20:34 - 2020-02-02 20:37 - 000028621 _____ C:\Users\ronny\Desktop\FRST.txt
2020-02-02 20:33 - 2020-02-02 20:36 - 000000000 ____D C:\FRST
2020-02-02 20:32 - 2020-02-02 20:32 - 002279424 _____ (Farbar) C:\Users\ronny\Desktop\FRST64.exe
2020-02-02 20:30 - 2020-02-02 20:30 - 000002315 _____ C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
2020-02-02 20:30 - 2020-02-02 20:30 - 000002315 _____ C:\ProgramData\Desktop\Tweaking.com - Registry Backup.lnk
2020-02-02 20:28 - 2020-02-02 20:28 - 005766144 _____ (Tweaking.com) C:\Users\ronny\Desktop\tweaking.com_registry_backup_setup(1).exe
2020-02-01 02:06 - 2020-02-01 02:06 - 001483907 _____ C:\Users\ronny\Desktop\MCC9043_IB.PDF
2020-01-29 14:02 - 2020-01-29 14:07 - 000000000 ____D C:\Blackweb Gaming AP
2020-01-29 14:02 - 2020-01-29 14:02 - 000000770 _____ C:\Users\ronny\Desktop\Blackweb Gaming AP.lnk
2020-01-29 14:02 - 2020-01-29 14:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blackweb Gaming AP
2020-01-29 05:44 - 2020-01-29 05:44 - 033108558 _____ C:\Users\ronny\Desktop\. I Wish My Baby Was Born.wav
2020-01-28 23:50 - 2020-01-28 23:50 - 046524077 _____ C:\Users\ronny\Desktop\output%2F442374760742842%2Fmoises--allfiles.zip
2020-01-25 20:57 - 2020-01-25 20:57 - 000004548 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2020-01-25 20:57 - 2020-01-25 20:57 - 000004370 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player Updater
2020-01-24 19:37 - 2020-01-24 19:37 - 028721742 _____ C:\Users\ronny\Desktop\Closer To The Bone.wav
2020-01-23 02:17 - 2020-01-28 23:48 - 000000000 ____D C:\Users\ronny\Desktop\converts
2020-01-23 02:07 - 2020-01-23 02:07 - 000001366 _____ C:\Users\Public\Desktop\NCH Suite.lnk
2020-01-23 02:07 - 2020-01-23 02:07 - 000001366 _____ C:\ProgramData\Desktop\NCH Suite.lnk
2020-01-23 02:07 - 2020-01-23 02:07 - 000001226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoPad Image Editor.lnk
2020-01-23 02:07 - 2020-01-23 02:07 - 000001214 _____ C:\Users\Public\Desktop\PhotoPad Image Editor.lnk
2020-01-23 02:07 - 2020-01-23 02:07 - 000001214 _____ C:\ProgramData\Desktop\PhotoPad Image Editor.lnk
2020-01-23 02:07 - 2020-01-23 02:07 - 000000000 ____D C:\Users\ronny\NCH Software Suite
2020-01-23 02:06 - 2020-01-23 02:06 - 001847864 _____ (NCH Software) C:\Users\ronny\Desktop\PhotoPadPhotoEditingSoftware.exe
2020-01-23 01:54 - 2020-01-23 01:54 - 000000000 ____D C:\Users\ronny\AppData\Roaming\FastStone
2020-01-23 01:53 - 2020-01-23 01:53 - 000001199 _____ C:\Users\Public\Desktop\FastStone Image Viewer.lnk
2020-01-23 01:53 - 2020-01-23 01:53 - 000001199 _____ C:\ProgramData\Desktop\FastStone Image Viewer.lnk
2020-01-23 01:53 - 2020-01-23 01:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Image Viewer
2020-01-23 01:53 - 2020-01-23 01:53 - 000000000 ____D C:\Program Files (x86)\FastStone Image Viewer
2020-01-23 01:52 - 2020-01-23 01:52 - 007059871 _____ (FastStone Soft) C:\Users\ronny\Desktop\FSViewerSetup74.exe
2020-01-20 00:46 - 2020-01-20 00:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2020-01-18 17:38 - 2020-01-18 17:39 - 000004608 _____ C:\Users\ronny\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2020-01-16 22:53 - 2020-01-16 22:53 - 000000000 ____D C:\ProgramData\mb3migration
2020-01-16 22:50 - 2020-01-16 22:50 - 002573312 _____ (Farbar) C:\Users\ronny\Downloads\FRSTEnglish.exe
2020-01-15 10:37 - 2020-01-15 10:37 - 000000000 ____D C:\Program Files (x86)\Flyordie Plugin
2020-01-15 10:28 - 2020-01-15 10:28 - 000000000 ____D C:\Users\ronny\AppData\Roaming\Sun
2020-01-15 10:27 - 2020-01-15 10:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2020-01-15 10:27 - 2020-01-15 10:27 - 000114232 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2020-01-15 10:26 - 2020-01-15 10:39 - 000000000 ____D C:\Program Files (x86)\Java
2020-01-12 02:16 - 2020-01-12 02:16 - 000001039 _____ C:\Users\ronny\Downloads\Galaxy Note9 - Shortcut.lnk
2020-01-11 22:12 - 2020-01-24 14:02 - 000000000 ____D C:\Users\ronny\Desktop\Moises Remakes
2020-01-07 09:57 - 2020-01-31 16:11 - 000000000 ____D C:\Users\ronny\Desktop\Karaoke
2020-01-06 20:24 - 2020-01-06 20:24 - 000002320 _____ C:\Users\ronny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Suite.lnk
2020-01-06 20:24 - 2020-01-06 20:24 - 000002112 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Suite.lnk
2020-01-06 20:24 - 2020-01-06 20:24 - 000001210 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Sound Editor.lnk
2020-01-06 20:24 - 2020-01-06 20:24 - 000001198 _____ C:\Users\Public\Desktop\WavePad Sound Editor.lnk
2020-01-06 20:24 - 2020-01-06 20:24 - 000001198 _____ C:\ProgramData\Desktop\WavePad Sound Editor.lnk
2020-01-06 20:22 - 2020-01-06 20:22 - 000001242 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RecordPad Sound Recorder.lnk
2020-01-06 20:22 - 2020-01-06 20:22 - 000000000 ____D C:\Users\ronny\AppData\Roaming\Recordpad

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-02-02 20:30 - 2019-10-06 21:02 - 000034355 _____ C:\WINDOWS\Tweaking.com - Registry Backup Setup Log.txt
2020-02-02 20:25 - 2019-08-23 15:08 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-02-02 18:04 - 2019-08-23 19:38 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-02-02 14:53 - 2019-09-28 01:49 - 000004164 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{253E348A-5B90-498C-8E33-9D9478C11A9F}
2020-02-02 14:53 - 2019-08-23 18:10 - 000840848 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-02-02 14:53 - 2019-08-23 15:06 - 000000000 ____D C:\WINDOWS\INF
2020-02-02 14:52 - 2019-08-23 15:08 - 000000000 ____D C:\WINDOWS\system32\NDF
2020-02-01 05:07 - 2019-08-26 15:20 - 000000000 ____D C:\Users\ronny\AppData\LocalLow\Mozilla
2020-01-31 18:28 - 2019-08-23 15:08 - 000000000 ___HD C:\Program Files\WindowsApps
2020-01-31 18:28 - 2019-08-23 15:08 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-01-31 04:16 - 2019-11-18 08:55 - 000000000 ____D C:\ProgramData\Paltalk Update
2020-01-30 14:08 - 2019-08-23 18:27 - 000000000 ____D C:\Users\ronny\AppData\Local\PlaceholderTileLogoFolder
2020-01-30 02:07 - 2019-08-24 14:37 - 000000000 ____D C:\WINDOWS\system32\Tasks\NCH Software
2020-01-29 16:52 - 2019-10-06 21:24 - 000000000 ____D C:\WINDOWS\Minidump
2020-01-29 14:06 - 2019-08-23 18:21 - 000000000 __SHD C:\Users\ronny\IntelGraphicsProfiles
2020-01-29 14:04 - 2019-08-23 20:06 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-01-29 14:03 - 2019-08-23 14:35 - 001310720 _____ C:\WINDOWS\system32\config\BBI
2020-01-29 14:02 - 2019-08-23 18:14 - 000000000 ____D C:\Users\ronny
2020-01-29 04:47 - 2019-08-23 15:08 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-01-29 04:44 - 2020-01-01 16:40 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-01-29 04:44 - 2019-08-26 15:20 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-01-28 23:10 - 2019-10-07 23:23 - 000000000 ____D C:\Users\ronny\AppData\Local\CrashDumps
2020-01-28 05:20 - 2019-08-26 15:20 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-01-25 20:58 - 2019-11-28 23:09 - 000000000 ____D C:\Users\ronny\AppData\Local\Adobe
2020-01-25 20:56 - 2019-08-23 15:08 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-01-25 20:56 - 2019-08-23 15:08 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-01-24 14:04 - 2019-11-14 10:55 - 000000000 ____D C:\Users\ronny\Desktop\Recordings
2020-01-23 02:07 - 2019-08-24 14:37 - 000000000 ____D C:\Users\ronny\AppData\Roaming\NCH Software
2020-01-23 02:07 - 2019-08-24 14:37 - 000000000 ____D C:\ProgramData\NCH Software
2020-01-23 02:07 - 2019-08-24 14:37 - 000000000 ____D C:\Program Files (x86)\NCH Software
2020-01-22 13:24 - 2019-08-30 01:04 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-01-19 01:08 - 2018-10-09 08:54 - 000000000 ____D C:\ProgramData\Package Cache
2020-01-18 21:14 - 2019-08-23 18:28 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4109447768-91167649-2371174200-1001
2020-01-18 21:14 - 2019-08-23 18:28 - 000000000 ___RD C:\Users\ronny\OneDrive
2020-01-18 21:14 - 2019-08-23 18:14 - 000002370 _____ C:\Users\ronny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-01-17 19:19 - 2019-12-19 15:14 - 000002425 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brave.lnk
2020-01-17 01:58 - 2019-11-18 08:55 - 000000000 ____D C:\Program Files (x86)\Paltalk
2020-01-16 23:04 - 2019-09-01 15:26 - 000000000 ____D C:\Program Files\Malwarebytes
2020-01-16 22:55 - 2019-08-23 15:08 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-01-15 01:27 - 2019-08-23 20:00 - 000000000 ____D C:\ProgramData\Oracle
2020-01-14 22:06 - 2019-08-23 20:49 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-01-14 22:00 - 2019-08-23 20:49 - 120202352 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-01-14 15:10 - 2019-08-23 18:21 - 000000000 ____D C:\Users\ronny\AppData\Local\Packages
2020-01-11 08:42 - 2019-09-07 01:06 - 000000000 ____D C:\Users\ronny\AppData\Local\ElevatedDiagnostics
2020-01-08 13:35 - 2019-08-24 15:08 - 000000000 ____D C:\Program Files\Common Files\logishrd
2020-01-08 13:34 - 2019-10-04 20:44 - 000000000 ____D C:\ProgramData\LogiShrd
2020-01-08 13:32 - 2019-10-16 18:00 - 000000000 ____D C:\Users\ronny\AppData\Roaming\Logishrd
2020-01-08 13:23 - 2019-08-23 15:08 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-01-08 10:55 - 2019-09-19 11:34 - 000018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys
2020-01-07 22:56 - 2020-01-02 04:49 - 000000000 ____D C:\Users\Public\Logi
2020-01-06 19:49 - 2019-09-08 06:29 - 000000000 ____D C:\Users\ronny\Desktop\Email attachments
2020-01-03 23:12 - 2020-01-02 03:01 - 000000000 ____D C:\ProgramData\boost_interprocess

==================== Files in the root of some directories ========

2019-09-26 20:23 - 2019-09-26 20:23 - 000000287 _____ () C:\ProgramData\fontcacheev1.dat
2020-01-18 17:38 - 2020-01-18 17:39 - 000004608 _____ () C:\Users\ronny\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2019-12-21 10:11 - 2019-12-21 10:11 - 000007606 _____ () C:\Users\ronny\AppData\Local\Resmon.ResmonCfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-02-2020 02
Ran by ronny (02-02-2020 20:39:35)
Running from C:\Users\ronny\Desktop
Windows 10 Home Version 1809 17763.678 (X64) (2019-08-24 00:08:39)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-4109447768-91167649-2371174200-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4109447768-91167649-2371174200-503 - Limited - Disabled)
Guest (S-1-5-21-4109447768-91167649-2371174200-501 - Limited - Disabled)
ronny (S-1-5-21-4109447768-91167649-2371174200-1001 - Administrator - Enabled) => C:\Users\ronny
WDAGUtilityAccount (S-1-5-21-4109447768-91167649-2371174200-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.021.20061 - Adobe Systems Incorporated)
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.321 - Adobe)
Blackweb Gaming AP version 1.0.9.9 (HKLM\...\Blackweb Gaming AP_is1) (Version: 1.0.9.9 - )
Brave (HKLM-x32\...\BraveSoftware Brave-Browser) (Version: 79.1.2.43 - Brave Software Inc)
CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden
Dolby Audio X2 Windows API SDK (HKLM\...\{F290F786-5F69-48D4-B20B-D21C7DE56EF0}) (Version: 0.8.8.88 - Dolby Laboratories, Inc.) Hidden
Dolby Audio X2 Windows APP (HKLM\...\{4A02DCED-C2B0-4DD3-87BD-7D8E68D6AF3C}) (Version: 0.8.6.75 - Dolby Laboratories, Inc.) Hidden
Dwyco CDC-X version 2.20 (HKU\S-1-5-21-4109447768-91167649-2371174200-1001\...\Dwyco CDC-X_is1) (Version: 2.20 - Dwyco, Inc.)
Easy Thumbnails (Remove only) (HKLM-x32\...\Easy Thumbnails_is1) (Version: 3.0 - Fookes Software)
erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden
FastStone Image Viewer 7.4 (HKLM-x32\...\FastStone Image Viewer) (Version: 7.4 - FastStone Soft)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 79.0.3945.130 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.421 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.99.0 - Google Inc.) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{44ded3eb-1686-46a6-9770-fd79096c29f7}) (Version: 10.1.1.45 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1052 - Intel Corporation)
Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.715.0 - Intel Corporation) Hidden
Intel(R) Trusted Connect Services Client (HKLM-x32\...\{2b32b7d0-4f9f-47c8-adb7-807e6cb2fb75}) (Version: 1.47.715.0 - Intel Corporation) Hidden
Java 8 Update 231 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180231F0}) (Version: 8.0.2310.11 - Oracle Corporation)
Java 8 Update 241 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180241F0}) (Version: 8.0.2410.7 - Oracle Corporation)
KaraFun Player 2 (HKLM-x32\...\KaraFun Player 2_is1) (Version: 2.6.1.1 - Recisio)
Lenovo Vantage Service (HKLM-x32\...\VantageSRV_is1) (Version: 2.0.7.0 - Lenovo Group Ltd.)
Logitech Unifying Software 2.50 (HKLM\...\Logitech Unifying) (Version: 2.50.25 - Logitech)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.)
Microsoft OneDrive (HKU\S-1-5-21-4109447768-91167649-2371174200-1001\...\OneDriveSetup.exe) (Version: 19.222.1110.0006 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 71.0 (x64 en-US) (HKLM\...\Mozilla Firefox 71.0 (x64 en-US)) (Version: 71.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 68.0.2 - Mozilla)
MX5 (HKLM-x32\...\Maxthon5) (Version: 5.2.7.5000 - Maxthon International Limited)
Paltalk (HKLM-x32\...\Paltalk) (Version: - )
PhotoPad Image Editor (HKLM-x32\...\PhotoPad) (Version: 5.50 - NCH Software)
RecordPad Sound Recorder (HKLM-x32\...\Recordpad) (Version: 8.01 - NCH Software)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.7.17.0 - Samsung Electronics Co., Ltd.)
SeaMonkey 2.49.5 (x86 en-US) (HKLM-x32\...\SeaMonkey 2.49.5 (x86 en-US)) (Version: 2.49.5 - Mozilla)
SoundTap Streaming Audio Recorder (HKLM-x32\...\SoundTap) (Version: 6.03 - NCH Software)
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 3.5.3 - Tweaking.com)
Unity Web Player (HKU\S-1-5-21-4109447768-91167649-2371174200-1001\...\UnityWebPlayer) (Version: 5.3.8f2 - Unity Technologies ApS)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WavePad Sound Editor (HKLM-x32\...\WavePad) (Version: 9.79 - NCH Software)
Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22899 - Microsoft Corporation)

Packages:
=========
Autofill for Microsoft Edge by Fillr -> C:\Program Files\WindowsApps\Fillr.FillrAutofillforEdge_0.2.13.0_neutral__wmnk5xzcp70cp [2019-10-08] (Fillr)
Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_1.29.4.0_x86__kgqvnymyfvs32 [2020-01-25] (king.com)
Candy Crush Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.1690.1.0_x86__kgqvnymyfvs32 [2020-01-29] (king.com)
Cloud Drive! -> C:\Program Files\WindowsApps\5913DefineStudio.CloudDrive_4.9.0.0_x64__jj4r3mnwe2ey2 [2020-01-01] (Define Studio) [MS Ad]
Geek app-Wish -> C:\Program Files\WindowsApps\25912WinPhoneTotalApps.Geekapp-Wish_1.0.0.1_neutral__rdnsa2fnwy8xy [2020-01-12] (Wonderful World Apps (WWA))
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa [2020-01-29] (Apple Inc.) [Startup Task]
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.1910.41.0_x64__k1h2ywk1493x8 [2019-12-30] (LENOVO INC.)
LenovoUtility -> C:\Program Files\WindowsApps\E0469640.LenovoUtility_3.1.4.0_x64__5grkq8ppsgwt4 [2020-01-03] (LENOVO INC) [Startup Task]
Microsoft Access -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Access_16051.12325.20344.0_x86__8wekyb3d8bbwe [2020-01-27] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\microsoft.advertising.xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-10-08] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\microsoft.advertising.xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-10-08] (Microsoft Corporation) [MS Ad]
Microsoft Excel -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Excel_16051.12325.20344.0_x86__8wekyb3d8bbwe [2020-01-27] (Microsoft Corporation)
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.34.20074.0_x64__8wekyb3d8bbwe [2020-01-13] (Microsoft Corporation) [MS Ad]
Microsoft Office Desktop Apps -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop_16051.12325.20344.0_x86__8wekyb3d8bbwe [2020-01-27] (Microsoft Corporation)
Microsoft Outlook -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.12325.20344.0_x86__8wekyb3d8bbwe [2020-01-27] (Microsoft Corporation)
Microsoft PowerPoint -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.PowerPoint_16051.12325.20344.0_x86__8wekyb3d8bbwe [2020-01-27] (Microsoft Corporation)
Microsoft Publisher -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Publisher_16051.12325.20344.0_x86__8wekyb3d8bbwe [2020-01-27] (Microsoft Corporation)
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.5.12061.0_x64__8wekyb3d8bbwe [2019-12-12] (Microsoft Studios) [MS Ad]
Microsoft Word -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Word_16051.12325.20344.0_x86__8wekyb3d8bbwe [2020-01-27] (Microsoft Corporation)
Movie Maker : Video Editor With Photo Slideshow -> C:\Program Files\WindowsApps\13941FunAppsMaker.MovieMakerVideoEditorWithPhotoSl_1.0.16.0_x64__yg31wsae9kk16 [2020-01-16] (FunAppsMaker) [MS Ad]
MPEG-2 Video Extension -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.22661.0_x64__8wekyb3d8bbwe [2019-10-08] (Microsoft Corporation)
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.34.13393.0_x64__8wekyb3d8bbwe [2019-12-17] (Microsoft Corporation) [MS Ad]
MultiRec -> C:\Program Files\WindowsApps\davidtanzer.net.MultiRec_1.0.2.0_x64__8k66xfnpkzez6 [2019-10-14] (David Tanzer)
OneDrive -> C:\Program Files\WindowsApps\microsoft.microsoftskydrive_19.22.5.0_x64__8wekyb3d8bbwe [2019-11-20] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-10-08] (Microsoft Corporation)
Sketchpads -> C:\Program Files\WindowsApps\48791Untoldlies.Sketchpads_1.1.0.1_neutral__8yj6wf32v5cte [2019-12-29] (LiKZ)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.125.559.0_x86__zpdnekdrzrea0 [2020-01-30] (Spotify AB) [Startup Task]
uBlock Origin -> C:\Program Files\WindowsApps\37833NikRolls.uBlockOrigin_1.15.24.0_neutral__f8jsg5mm64m62 [2019-10-08] (Nik Rolls)
Ultra Paint -> C:\Program Files\WindowsApps\D5BE6627.UltraPaint_2.0.2.0_x86__9pm2v9747qaaa [2019-11-07] (CompuClever Systems Inc.)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [vidc.i420] => C:\WINDOWS\system32\lvcod64.dll [175392 2012-10-26] (Logitech, Inc. -> Logitech Inc.)
HKLM\...\Drivers32: [vidc.i420] => C:\Windows\SysWOW64\lvcodec2.dll [305000 2012-10-26] (Logitech, Inc. -> Logitech Inc.)

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\ronny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Paltalk\Remove settings.lnk -> C:\Program Files (x86)\Paltalk\ng_clean_settings.bat ()

==================== Loaded Modules (Whitelisted) =============


==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\ronny\OneDrive:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.SyncRootIdentity [130]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2018-04-11 17:38 - 2018-04-11 17:36 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

2019-10-23 21:31 - 2019-10-23 21:36 - 000000445 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT
HKU\S-1-5-21-4109447768-91167649-2371174200-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ronny\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\20180524_101516.gif
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\...\StartupApproved\Run: => "EvtMgr6"
HKLM\...\StartupApproved\Run32: => "LWS"
HKU\S-1-5-21-4109447768-91167649-2371174200-1001\...\StartupApproved\StartupFolder: => "Logitech . Product Registration.lnk"
HKU\S-1-5-21-4109447768-91167649-2371174200-1001\...\StartupApproved\Run: => "OneDrive"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{BAFE3480-AEB5-4800-9E2D-8E61E183CD3D}C:\users\ronny\documents\dwyco\cdc-x\cdcx.exe] => (Allow) C:\users\ronny\documents\dwyco\cdc-x\cdcx.exe (Dwyco, Inc. -> )
FirewallRules: [UDP Query User{C0ADCAA4-DF8A-4292-9D89-A7D6ACEB34A5}C:\users\ronny\documents\dwyco\cdc-x\cdcx.exe] => (Allow) C:\users\ronny\documents\dwyco\cdc-x\cdcx.exe (Dwyco, Inc. -> )
FirewallRules: [{18993CBE-DAD3-4CA6-B611-E6C9F2C517C9}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{9E6AC93C-08F1-4BF8-AC63-8068E9CC5EA2}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{128B5960-7AFA-41F4-B56B-ADAC6413F6C2}] => (Allow) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
FirewallRules: [{6DBA228B-5816-4BB6-8B69-28D3B15980B0}] => (Allow) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
FirewallRules: [{E955BADC-DF2B-47FB-BE7D-EDD81425FC1F}] => (Allow) %systemroot%\system32\alg.exe No File
FirewallRules: [{F850B365-54C0-4904-BFE8-3BFA9131EF8C}] => (Allow) %systemroot%\system32\alg.exe No File
FirewallRules: [{504637E0-AA81-4A4E-B46F-C0E05C5F2A3A}] => (Allow) C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.)
FirewallRules: [{34AE96D9-E476-415C-991A-2BE79EF9283E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{F2F739EC-FE16-4AAB-AE9E-93754A25E2BD}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.12325.20344.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AA0C68E5-8F3D-4F7A-A2CA-74D5875ECA92}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{8D290D7F-B51E-440A-9C69-C43F5AFFFB1E}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{A5EBA336-D986-4597-95D2-1FD9ACA8E84E}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{AF73B399-A155-4B55-A474-8616E9F030E8}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{218F3333-5012-4BA0-836E-6A9F51C39D4D}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{5F087B9C-F52A-46F2-888C-987D66701220}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{53F7BA74-C0B0-4649-85B9-CE5753F7F3EA}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{8C2F5129-16B2-4DBA-A8E0-AC574DBB8C85}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{1B951595-69B9-44CD-B944-FF7131C1C9A1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.125.559.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{74555956-CF20-43E4-AF0C-0D033D244B12}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.125.559.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{9672B3FE-5EA7-42F5-B24D-3A812DAC9977}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.125.559.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{D19C51B7-FFD9-49E8-A6DC-AC8779C29B2C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.125.559.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{65ADEC78-7014-45A1-ABAA-134CB2615634}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.125.559.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{8AC0834B-1BB3-4082-AEA9-F54AD6B432F3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.125.559.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{A2E686FD-EAFD-4E93-8147-7D359B4EB541}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.125.559.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{D6F2EADC-CC10-400A-8457-B98B4BD7CF10}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.125.559.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)

==================== Restore Points =========================

15-01-2020 09:54:16 Removed Java 8 Update 241
24-01-2020 03:54:21 Windows Update

==================== Faulty Device Manager Devices ============

Name: Unknown USB Device (Port Reset Failed)
Description: Unknown USB Device (Port Reset Failed)
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: (Standard USB Host Controller)
Service:
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation.


==================== Event log errors: ========================

Application errors:
==================
Error: (02/02/2020 02:27:57 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Maxthon.exe version 5.2.7.5000 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 4c8

Start Time: 01d5d8e71589d96a

Termination Time: 629

Application Path: C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe

Report Id: 96a1c812-a212-4b5d-a0f3-7f76fb48aa26

Faulting package full name:

Faulting package-relative application ID:

Hang type: Unknown

Error: (01/30/2020 03:02:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_smphost, version: 10.0.17763.1, time stamp: 0xb900eeff
Faulting module name: ntdll.dll, version: 10.0.17763.592, time stamp: 0x0f1b8afd
Exception code: 0xc0000005
Fault offset: 0x000000000004df23
Faulting process id: 0x2fb8
Faulting application start time: 0x01d5d74c0f7b33be
Faulting application path: C:\WINDOWS\System32\svchost.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 6c1fc899-d5c0-4ec3-b189-e4e22fea7be7
Faulting package full name:
Faulting package-relative application ID:

Error: (01/28/2020 11:10:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GfxDownloadWrapper.exe, version: 8.15.100.6577, time stamp: 0x5c5c547b
Faulting module name: KERNELBASE.dll, version: 10.0.17763.652, time stamp: 0x598c4711
Exception code: 0xe0434352
Fault offset: 0x0000000000039129
Faulting process id: 0x2ec0
Faulting application start time: 0x01d5d6626c80b832
Faulting application path: C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_a7428663aca90897\GfxDownloadWrapper.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report Id: b3b3f6ea-73fd-4c62-9091-b67030303a24
Faulting package full name:
Faulting package-relative application ID:

Error: (01/28/2020 11:10:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GfxDownloadWrapper.exe, version: 8.15.100.6577, time stamp: 0x5c5c547b
Faulting module name: KERNELBASE.dll, version: 10.0.17763.652, time stamp: 0x598c4711
Exception code: 0xe0434352
Fault offset: 0x0000000000039129
Faulting process id: 0x35e4
Faulting application start time: 0x01d5d6626d0a525f
Faulting application path: C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_a7428663aca90897\GfxDownloadWrapper.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report Id: 3d29dc5f-b75c-4b78-800a-1cc956d61038
Faulting package full name:
Faulting package-relative application ID:

Error: (01/28/2020 11:10:34 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: GfxDownloadWrapper.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.IO.IOException
at System.IO.__Error.WinIOError(Int32, System.String)
at System.IO.FileStream.Init(System.String, System.IO.FileMode, System.IO.FileAccess, Int32, Boolean, System.IO.FileShare, Int32, System.IO.FileOptions, SECURITY_ATTRIBUTES, System.String, Boolean, Boolean, Boolean)
at System.IO.FileStream..ctor(System.String, System.IO.FileMode, System.IO.FileAccess, System.IO.FileShare, Int32, System.IO.FileOptions, System.String, Boolean, Boolean, Boolean)
at System.IO.StreamWriter.CreateFile(System.String, Boolean, Boolean)
at System.IO.StreamWriter..ctor(System.String, Boolean, System.Text.Encoding, Int32, Boolean)
at System.IO.StreamWriter..ctor(System.String, Boolean, System.Text.Encoding)
at GfxGameSettingsDownload.Program.Main(System.String[])

Error: (01/28/2020 11:10:34 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: GfxDownloadWrapper.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.IO.IOException
at System.IO.__Error.WinIOError(Int32, System.String)
at System.IO.FileStream.Init(System.String, System.IO.FileMode, System.IO.FileAccess, Int32, Boolean, System.IO.FileShare, Int32, System.IO.FileOptions, SECURITY_ATTRIBUTES, System.String, Boolean, Boolean, Boolean)
at System.IO.FileStream..ctor(System.String, System.IO.FileMode, System.IO.FileAccess, System.IO.FileShare, Int32, System.IO.FileOptions, System.String, Boolean, Boolean, Boolean)
at System.IO.StreamWriter.CreateFile(System.String, Boolean, Boolean)
at System.IO.StreamWriter..ctor(System.String, Boolean, System.Text.Encoding, Int32, Boolean)
at System.IO.StreamWriter..ctor(System.String, Boolean, System.Text.Encoding)
at GfxGameSettingsDownload.Program.Main(System.String[])

Error: (01/26/2020 11:09:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GfxDownloadWrapper.exe, version: 8.15.100.6577, time stamp: 0x5c5c547b
Faulting module name: KERNELBASE.dll, version: 10.0.17763.652, time stamp: 0x598c4711
Exception code: 0xe0434352
Fault offset: 0x0000000000039129
Faulting process id: 0x3a18
Faulting application start time: 0x01d5d4d0037545ed
Faulting application path: C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_a7428663aca90897\GfxDownloadWrapper.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report Id: 835abf9c-b264-4f6c-b04a-d4b2d93b1e85
Faulting package full name:
Faulting package-relative application ID:

Error: (01/26/2020 11:09:55 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: GfxDownloadWrapper.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.IO.DirectoryNotFoundException
at System.IO.__Error.WinIOError(Int32, System.String)
at System.IO.FileStream.Init(System.String, System.IO.FileMode, System.IO.FileAccess, Int32, Boolean, System.IO.FileShare, Int32, System.IO.FileOptions, SECURITY_ATTRIBUTES, System.String, Boolean, Boolean, Boolean)
at System.IO.FileStream..ctor(System.String, System.IO.FileMode, System.IO.FileAccess, System.IO.FileShare, Int32, System.IO.FileOptions, System.String, Boolean, Boolean, Boolean)
at System.IO.StreamWriter.CreateFile(System.String, Boolean, Boolean)
at System.IO.StreamWriter..ctor(System.String, Boolean, System.Text.Encoding, Int32, Boolean)
at System.IO.StreamWriter..ctor(System.String, Boolean, System.Text.Encoding)
at GfxGameSettingsDownload.Program.Main(System.String[])


System errors:
=============
Error: (02/02/2020 05:00:54 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: NT AUTHORITY)
Description: Miniport Remote NDIS based Internet Sharing Device #3, {9160b299-4de8-46a3-89d4-bf9551ab42a3}, had event 74

Error: (02/01/2020 03:19:30 AM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-4HPCQJEC)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user LAPTOP-4HPCQJEC\ronny SID (S-1-5-21-4109447768-91167649-2371174200-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (02/01/2020 03:19:30 AM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-4HPCQJEC)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user LAPTOP-4HPCQJEC\ronny SID (S-1-5-21-4109447768-91167649-2371174200-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (02/01/2020 03:14:33 AM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-4HPCQJEC)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user LAPTOP-4HPCQJEC\ronny SID (S-1-5-21-4109447768-91167649-2371174200-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (02/01/2020 03:14:32 AM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-4HPCQJEC)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user LAPTOP-4HPCQJEC\ronny SID (S-1-5-21-4109447768-91167649-2371174200-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (02/01/2020 02:46:41 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk2\DR52.

Error: (02/01/2020 02:46:41 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk2\DR52.

Error: (02/01/2020 02:46:39 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk2\DR52.


Windows Defender:
===================================
Date: 2020-01-29 12:10:15.282
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {396DB32F-329D-4CA1-B855-88898DACEE7D}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2020-01-29 12:00:20.346
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {1432EAAB-C3BC-4099-BFB2-4BF8C948F140}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2020-01-26 01:20:29.453
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {1D46E386-20CC-4C51-9A04-6479414C8A63}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2020-01-17 01:22:26.603
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {BE924E9C-C209-4E3A-A140-1F77F13EEA40}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2020-01-11 12:14:21.755
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {705343EE-9386-47F2-9305-DD4037B960A3}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2020-01-29 14:14:28.932
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.307.3203.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16600.7
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Date: 2020-01-29 04:55:13.481
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.307.3203.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16600.7
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Date: 2020-01-28 19:40:01.886
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.307.3203.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16600.7
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Date: 2020-01-21 20:36:52.957
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.307.2762.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16600.7
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Date: 2020-01-19 03:20:39.734
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.307.2608.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16600.7
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

CodeIntegrity:
===================================

Date: 2020-01-11 08:51:46.998
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\WINDOWS\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2020-01-11 01:19:02.236
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\WINDOWS\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2020-01-11 01:08:31.850
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\WINDOWS\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2020-01-11 01:08:21.492
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\WINDOWS\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2020-01-11 01:08:11.555
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\WINDOWS\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2020-01-11 01:07:57.109
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\WINDOWS\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2020-01-11 01:06:26.727
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\WINDOWS\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2020-01-08 22:29:47.492
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\WINDOWS\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

==================== Memory info ===========================

BIOS: LENOVO 8TCN53WW 05/17/2019
Motherboard: LENOVO LNVNB161216
Processor: Intel(R) Core(TM) i3-8130U CPU @ 2.20GHz
Percentage of memory in use: 83%
Total physical RAM: 4005.22 MB
Available physical RAM: 654.88 MB
Total Virtual: 10262.96 MB
Available Virtual: 3155.1 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:930.27 GB) (Free:869.69 GB) NTFS

\\?\Volume{eae77724-da1d-47c7-8a1a-90516e452771}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.5 GB) NTFS
\\?\Volume{58b722d2-9514-4e02-a23f-e06dd61b5c39}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 346005D8)

Partition: GPT.

==================== End of Addition.txt =======================

Cookie settings help needed

$
0
0
Update: I think I found it so please ignore this post.

Hi,
I have some websites that I like to remain logged into but everytime I go to the I find Spybot has logged me out. This obviously has something to do with removal of cookies but I can't find where the seetings are that I need to adjust to stop this from happening. I have been through every tab in the 'Tasks' window and am probably just being thick but can't find the right one to change the necessary settings in.

I did do a search on here and found this: https://forums.spybot.info/showthrea...g+out+of+sites but it is from 2013 and I suspect that updated versions have the settings elsewhere as I am unable to find them where recommended on this thread.

Please help.
Thank you.

License Purchase Today

$
0
0
I have been a user of home edition for many years. Today I purchased/renewed my license. I was really over due. My start center no longer works. How do I get this thing going again?
thank you
Viewing all 7590 articles
Browse latest View live