Go Back   Cyber Tech Help Support Forums > Software > Malware Removal

Notices

Reply
 
Topic Tools
  #1  
Old December 16th, 2019, 06:26 PM
sportsfan7702 sportsfan7702 is offline
Senior Member
 
Join Date: Sep 2008
Posts: 306
Doing my yearly check for malware

I really should do this twice a year but in the last 3 months with work I have not had a chance. I'm running FRST an hope everyone has been well.

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation -> ) C:\Windows\System32\igfxTray.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\Pres entationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wek yb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1 910.0.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9270208 2018-11-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKU\S-1-5-21-3107326716-814032089-3740455390-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105904865\...\RunOnce: [Application Restart #0] => C:\Program Files\Mozilla Firefox\firefox.exe [566984 2019-12-05] (Mozilla Corporation -> Mozilla Corporation)
HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105904865\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105907102\...\RunOnce: [Application Restart #0] => C:\Program Files\Mozilla Firefox\firefox.exe [566984 2019-12-05] (Mozilla Corporation -> Mozilla Corporation)
HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105907102\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {2FB111B2-4601-4545-8FA8-70CD9F810B29} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_ 0_0_303_Plugin.exe [1457720 2019-12-10] (Adobe Inc. -> Adobe)
Task: {48211D53-740F-4C4F-8F6C-3E39617E98D2} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe [335416 2019-12-10] (Adobe Inc. -> Adobe)
Task: {8EFF3ADE-B677-490B-A0A6-A64F40DE12FD} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_ 0_0_303_pepper.exe [1453112 2019-12-10] (Adobe Inc. -> Adobe)
Task: {C9AEBBAE-CDD4-497D-8700-2607B72A139B} - System32\Tasks\Opera scheduled Autoupdate 1574190292 => C:\Users\MattS\AppData\Local\Programs\Opera\launch er.exe [1528344 2019-12-12] (Opera Software AS -> Opera Software)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask .job => C:\WINDOWS\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{d09ea5d8-05ca-4dce-a6a2-7912228ab1f1}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{d7fd4481-caf7-4e4b-801a-8d29c88b4e10}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================

Edge:
======
DownloadDir: C:\Users\MattS\Downloads
Edge Notifications: HKU\S-1-5-21-3107326716-814032089-3740455390-1001 -> hxxps://www.eroprofile.com

FireFox:
========
FF DefaultProfile: y5zdsbob.default
FF ProfilePath: C:\Users\MattS\AppData\Roaming\Mozilla\Firefox\Pro files\y5zdsbob.default [2019-10-18]
FF ProfilePath: C:\Users\MattS\AppData\Roaming\Mozilla\Firefox\Pro files\4t6if1oe.default-release [2019-12-16]
FF Extension: (NoSquint Plus) - C:\Users\MattS\AppData\Roaming\Mozilla\Firefox\Pro files\4t6if1oe.default-release\Extensions\zoomlevelplus@zoomlevelplus.net .xpi [2019-08-12]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_ 303.dll [2019-12-10] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_ 303.dll [2019-12-10] (Adobe Inc. -> )

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [370560 2018-10-12] (Intel Corporation -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6960640 2019-12-16] (Malwarebytes Inc -> Malwarebytes)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [324544 2018-11-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [278616 2017-08-18] (Synaptics Incorporated -> Synaptics Incorporated)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2019-12-03] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2019-12-03] (Microsoft Windows Publisher -> Microsoft Corporation)
Reply With Quote


  #2  
Old December 16th, 2019, 06:27 PM
sportsfan7702 sportsfan7702 is offline
Senior Member
 
Join Date: Sep 2008
Posts: 306
===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 Accelerometer; C:\WINDOWS\System32\drivers\Accelerometer.sys [53904 2019-07-22] (HP Inc. -> HP)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2019-12-16] (Malwarebytes Corporation -> Malwarebytes)
R0 hpdskflt; C:\WINDOWS\System32\drivers\hpdskflt.sys [41104 2019-07-22] (HP Inc. -> HP)
R3 HpqKbFiltr; C:\WINDOWS\System32\drivers\HpqKbFiltr64.sys [37112 2015-06-17] (Hewlett-Packard Company -> Hewlett-Packard Company)
R3 ISCT; C:\WINDOWS\System32\drivers\ISCTD64.sys [46568 2013-08-13] (Intel(R) Smart Connect software -> )
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [216544 2019-12-16] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-12-16] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [224408 2019-12-16] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73584 2019-12-16] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [278344 2019-12-16] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [116832 2019-12-16] (Malwarebytes Corporation -> Malwarebytes)
R3 pelmouse; C:\WINDOWS\system32\DRIVERS\pelmouse.sys [26880 2016-07-11] (WDKTestCert idd,131110062695071623 -> TPMX Electronics Ltd.)
R3 pelusblf; C:\WINDOWS\system32\DRIVERS\pelusblf.sys [33048 2016-07-11] (WDKTestCert idd,131110062695071623 -> )
S3 phidmice; C:\WINDOWS\System32\drivers\phidmice.sys [33048 2016-07-11] (WDKTestCert idd,131110062695071623 -> )
S3 pmouself; C:\WINDOWS\System32\drivers\pmouself.sys [26880 2016-07-11] (WDKTestCert idd,131110062695071623 -> TPMX Electronics Ltd.)
S3 pvendrlf; C:\WINDOWS\System32\drivers\pvendrlf.sys [15032 2016-07-11] (WDKTestCert idd,131110062695071623 -> TPMX Electronics Ltd.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1010656 2017-11-27] (Realtek Semiconductor Corp. -> Realtek )
R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [8206848 2019-03-18] (Microsoft Windows -> Realtek Semiconductor Corporation )
R3 RTWlanE; C:\WINDOWS\System32\drivers\rtwlane.sys [7904088 2018-04-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation )
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [53848 2017-08-18] (Synaptics Incorporated -> Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [55384 2017-08-18] (Synaptics Incorporated -> Synaptics Incorporated)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64912 2017-05-18] (Samsung Electronics Co., Ltd. -> QUALCOMM Incorporated)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45664 2019-12-03] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [355760 2019-12-03] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [151184 2016-07-15] (NGO -> MBB)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2019-12-03] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64 .sys [34944 2018-05-11] (HP Inc. -> HP)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-12-16 11:20 - 2019-12-16 11:22 - 000012482 _____ C:\Users\MattS\Downloads\FRST.txt
2019-12-16 11:19 - 2019-12-16 11:19 - 002264064 _____ (Farbar) C:\Users\MattS\Downloads\FRST64.exe
2019-12-16 11:14 - 2019-12-16 11:14 - 000224408 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2019-12-16 11:14 - 2019-12-16 11:14 - 000116832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2019-12-16 11:14 - 2019-12-16 11:14 - 000073584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2019-12-16 11:12 - 2019-12-16 11:12 - 000000000 ____D C:\Users\MattS\AppData\LocalLow\IGDump
2019-12-16 11:05 - 2019-12-16 11:05 - 000278344 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2019-12-16 11:05 - 2019-12-16 11:05 - 000216544 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2019-12-16 11:02 - 2019-12-16 11:03 - 161071328 _____ (Malwarebytes) C:\Users\MattS\Downloads\MBSetup-122164.122164.exe
2019-12-16 10:59 - 2019-12-16 10:59 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2019-12-13 09:52 - 2019-12-13 09:52 - 000004206 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1574190292
2019-12-13 09:52 - 2019-12-13 09:52 - 000001399 _____ C:\Users\MattS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Opera Browser.lnk
2019-12-10 23:56 - 2019-12-10 23:56 - 025443840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 018020352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 009927992 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 007905000 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 007754240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 007600448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayR eady.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 007278592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 006516648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayR eady.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 006083832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 005943296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 005914112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 005764664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 004129416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 003729408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-12-10 23:56 - 2019-12-10 23:56 - 003703296 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 002800640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-12-10 23:56 - 2019-12-10 23:56 - 002762296 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 002716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-12-10 23:56 - 2019-12-10 23:56 - 002698768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2019-12-10 23:56 - 2019-12-10 23:56 - 002494432 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 002284544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.oneco re.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 002147328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 002082208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001757304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-12-10 23:56 - 2019-12-10 23:56 - 001748480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.deskt op.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001743888 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001697280 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001664904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001656600 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001647072 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001610752 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001539584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001512528 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001451520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 001413840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001399312 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-12-10 23:56 - 2019-12-10 23:56 - 001261464 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001182448 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 001098928 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001072952 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 001066496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001054864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 001006904 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000986936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2019-12-10 23:56 - 2019-12-10 23:56 - 000921600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dl l
2019-12-10 23:56 - 2019-12-10 23:56 - 000878080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000842552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000826368 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelinesvc.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 000822416 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 000797112 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000774456 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000674280 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 000673456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 000646144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dl l
2019-12-10 23:56 - 2019-12-10 23:56 - 000598016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000593128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2019-12-10 23:56 - 2019-12-10 23:56 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2019-12-10 23:56 - 2019-12-10 23:56 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000530944 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000524264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dl l
2019-12-10 23:56 - 2019-12-10 23:56 - 000513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 000511000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2019-12-10 23:56 - 2019-12-10 23:56 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000422712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2019-12-10 23:56 - 2019-12-10 23:56 - 000406480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dl l
2019-12-10 23:56 - 2019-12-10 23:56 - 000404480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\exfat.sys
2019-12-10 23:56 - 2019-12-10 23:56 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys
2019-12-10 23:56 - 2019-12-10 23:56 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2019-12-10 23:56 - 2019-12-10 23:56 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000127272 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cdfs.sys
2019-12-10 23:56 - 2019-12-10 23:56 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000097080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000089536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2019-12-10 23:56 - 2019-12-10 23:56 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentS tatusTracking.ConfigProvider.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000067112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsManagementServiceWinRt. ProxyStub.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelineprxy.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevQueryBroker.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000032056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys
2019-12-10 23:56 - 2019-12-10 23:56 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2019-12-10 23:56 - 2019-12-10 23:56 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2019-12-05 21:01 - 2019-12-13 02:15 - 000000000 ____D C:\Program Files\Mozilla Firefox
2019-12-05 15:20 - 2019-12-05 15:20 - 000000000 ____D C:\Users\MattS\AppData\Local\cache
2019-12-05 15:19 - 2019-12-16 11:05 - 000002029 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-12-05 15:19 - 2019-12-16 11:05 - 000002029 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2019-12-05 15:19 - 2019-12-16 11:04 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2019-12-05 15:19 - 2019-12-16 11:04 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2019-12-05 15:19 - 2019-12-05 15:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-11-24 20:12 - 2019-11-24 20:12 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3107326716-814032089-3740455390-1001
2019-11-24 20:11 - 2019-11-24 20:11 - 000002363 _____ C:\Users\MattS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\OneDrive.lnk
2019-11-20 09:51 - 2019-11-20 09:51 - 172961592 _____ C:\Users\MattS\Downloads\Aradeth_Volvo_VNL670_v1.5 .3.1_ETS2.scs
2019-11-19 15:32 - 2019-11-19 15:38 - 102733747 _____ C:\Users\MattS\Downloads\Volvo_Vnl_2019_v2.17.zip
2019-11-19 15:31 - 2019-11-19 15:42 - 211735887 _____ C:\Users\MattS\Downloads\volvo.7z
2019-11-19 14:45 - 2019-11-19 14:46 - 015303760 _____ (Auslogi˜cs ) C:\Users\MattS\Downloads\registry-cleaner-setup.exe
2019-11-19 13:38 - 2019-11-19 13:39 - 003770512 _____ (Opera Software) C:\Users\MattS\Downloads\OperaGXSetup (1).exe
2019-11-19 10:17 - 2019-11-19 10:18 - 248290819 _____ C:\Users\MattS\Downloads\Volvo_vnl_truckstop_v1.5. zip
Reply With Quote
  #3  
Old December 16th, 2019, 06:28 PM
sportsfan7702 sportsfan7702 is offline
Senior Member
 
Join Date: Sep 2008
Posts: 306
==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-12-16 11:21 - 2019-01-10 10:07 - 000000000 ____D C:\FRST
2019-12-16 11:16 - 2019-03-18 22:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-12-16 11:11 - 2018-07-05 20:11 - 000000000 ____D C:\Users\MattS\AppData\LocalLow\Mozilla
2019-12-16 11:05 - 2019-08-13 21:47 - 000840852 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-12-16 11:05 - 2019-03-18 22:50 - 000000000 ____D C:\WINDOWS\INF
2019-12-16 10:59 - 2018-02-25 22:09 - 000000000 __SHD C:\Users\MattS\IntelGraphicsProfiles
2019-12-16 10:58 - 2019-08-13 21:55 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-12-16 10:57 - 2019-03-18 22:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2019-12-16 09:23 - 2019-08-13 21:30 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-12-15 11:30 - 2018-02-25 22:14 - 000000000 ____D C:\Users\MattS\OneDrive\Documents\American Truck Simulator
2019-12-15 10:47 - 2019-02-10 14:38 - 000000000 ____D C:\Program Files (x86)\Steam
2019-12-15 00:26 - 2019-08-29 23:08 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-12-13 23:36 - 2019-03-18 22:52 - 000000000 ___HD C:\Program Files\WindowsApps
2019-12-13 02:17 - 2018-02-25 22:09 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-12-13 02:17 - 2018-02-25 22:09 - 000000000 ___RD C:\Users\MattS\3D Objects
2019-12-13 02:15 - 2019-10-15 19:57 - 000257824 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-12-13 02:15 - 2019-08-12 09:58 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-12-13 02:12 - 2019-03-18 22:52 - 000000000 ____D C:\WINDOWS\SystemResources
2019-12-13 02:12 - 2019-03-18 22:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-12-13 02:12 - 2019-03-18 22:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-12-11 00:06 - 2019-02-09 20:13 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-12-11 00:04 - 2019-09-10 23:10 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-12-11 00:04 - 2019-02-09 20:12 - 129221664 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-12-10 10:40 - 2018-02-25 22:14 - 000000000 ____D C:\Users\MattS\OneDrive\Documents\Euro Truck Simulator 2
2019-12-10 09:11 - 2019-11-12 09:07 - 000004558 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2019-12-10 09:11 - 2019-03-18 22:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-12-10 09:11 - 2019-03-18 22:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-12-10 08:11 - 2019-09-10 09:11 - 000004546 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player NPAPI Notifier
2019-12-07 19:54 - 2019-08-12 09:58 - 000001011 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-12-05 15:19 - 2019-03-18 22:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2019-12-05 15:18 - 2019-05-28 09:43 - 000000000 ____D C:\Program Files\Malwarebytes
2019-12-05 15:18 - 2019-03-27 10:30 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-12-03 09:45 - 2019-02-09 18:02 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-11-24 20:12 - 2018-02-25 22:12 - 000000000 ___RD C:\Users\MattS\OneDrive
2019-11-19 09:05 - 2019-08-13 21:37 - 000000000 ____D C:\Users\MattS

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
Reply With Quote
  #4  
Old December 16th, 2019, 06:28 PM
sportsfan7702 sportsfan7702 is offline
Senior Member
 
Join Date: Sep 2008
Posts: 306
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-12-2019
Ran by MattS (16-12-2019 11:23:27)
Running from C:\Users\MattS\Downloads
Windows 10 Home Version 1903 18362.535 (X64) (2019-08-14 03:57:42)
Boot Mode: Normal
================================================== ========


==================== Accounts: =============================

Administrator (S-1-5-21-3107326716-814032089-3740455390-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3107326716-814032089-3740455390-503 - Limited - Disabled)
Guest (S-1-5-21-3107326716-814032089-3740455390-501 - Limited - Disabled)
MattS (S-1-5-21-3107326716-814032089-3740455390-1001 - Administrator - Enabled) => C:\Users\MattS
WDAGUtilityAccount (S-1-5-21-3107326716-814032089-3740455390-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 18.06 (x64) (HKLM\...\7-Zip) (Version: 18.06 - Igor Pavlov)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.303 - Adobe)
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.303 - Adobe)
Malwarebytes version 4.0.4.49 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.0.4.49 - Malwarebytes)
Microsoft OneDrive (HKU\S-1-5-21-3107326716-814032089-3740455390-1001\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105904865\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105907102\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation)
Mozilla Firefox 71.0 (x64 en-US) (HKLM\...\Mozilla Firefox 71.0 (x64 en-US)) (Version: 71.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 68.0.1 - Mozilla)
Opera Stable 65.0.3467.72 (HKU\S-1-5-21-3107326716-814032089-3740455390-1001\...\Opera 65.0.3467.72) (Version: 65.0.3467.72 - Opera Software)
Opera Stable 65.0.3467.72 (HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105904865\...\Opera 65.0.3467.72) (Version: 65.0.3467.72 - Opera Software)
Opera Stable 65.0.3467.72 (HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105907102\...\Opera 65.0.3467.72) (Version: 65.0.3467.72 - Opera Software)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8416 - Realtek Semiconductor Corp.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Steep (HKLM-x32\...\Uplay Install 3279) (Version: - Ubisoft)
Synaptics ClickPad Driver (HKLM\...\SynTPDeinstKey) (Version: 19.3.31.31 - Synaptics Incorporated)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{16AD6161-2E47-4BF1-AA77-0946EFE93E08}) (Version: 2.61.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 88.0 - Ubisoft)

Packages:
=========
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.18 11.1.0_x64__8wekyb3d8bbwe [2019-02-09] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.18 11.1.0_x86__8wekyb3d8bbwe [2019-02-09] (Microsoft Corporation) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.33.13094.0_ x64__8wekyb3d8bbwe [2019-11-13] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireColl ection_4.5.12061.0_x64__8wekyb3d8bbwe [2019-12-11] (Microsoft Studios) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.33.13253 .0_x64__8wekyb3d8bbwe [2019-11-24] (Microsoft Corporation) [MS Ad]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3107326716-814032089-3740455390-1001_Classes\CLSID\{C591CFEA-E432-495d-A0BE-58E4CCD87B17}\Shell\Open\Command -> C:\Program Files\Synaptics\SynTP\SynTPCpl.dll (Synaptics Incorporated -> Synaptics Incorporated)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-12-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-12-05] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-12-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2018-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-12-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-12-05] (Malwarebytes Corporation -> Malwarebytes)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Min imal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Net work\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-02-09 19:26 - 2019-02-09 19:21 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
Reply With Quote
  #5  
Old December 16th, 2019, 06:32 PM
sportsfan7702 sportsfan7702 is offline
Senior Member
 
Join Date: Sep 2008
Posts: 306
==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-02-09 19:26 - 2019-02-09 19:21 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105904412\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105906662\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105904615\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105906896\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-3107326716-814032089-3740455390-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\MattS\AppData\Local\Microsoft\Windows\The mes\RoamedThemeFiles\DesktopBackground\facebook_15 11574001546.jpg
HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105904865\Control Panel\Desktop\\Wallpaper -> C:\Users\MattS\AppData\Local\Microsoft\Windows\The mes\RoamedThemeFiles\DesktopBackground\facebook_15 11574001546.jpg
HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105907102\Control Panel\Desktop\\Wallpaper -> C:\Users\MattS\AppData\Local\Microsoft\Windows\The mes\RoamedThemeFiles\DesktopBackground\facebook_15 11574001546.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Pol icies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer => (SmartScreenEnabled: Warn)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{0B4E4B78-359E-4BC9-8907-C612FF352809}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{68A417FD-E58B-4850-A451-2FCC16134762}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{5961CBC4-0D6D-4FAE-89A8-BD4D874C5FD0}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{B7A200C1-5DE6-4DCE-8BB7-4C8705AFA373}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{6332BB97-2AD8-480F-B7A0-986E950FC8C6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software) [File not signed]
FirewallRules: [{2A3BDE2E-3ED5-4BE3-ACB8-76254EE074F4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software) [File not signed]
FirewallRules: [{D6DD0BB4-D6A9-41E2-AA5A-E2860DD7FF31}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software) [File not signed]
FirewallRules: [{B5155654-605C-4EB2-BF32-1D5F337F031E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software) [File not signed]
FirewallRules: [{F6F9F423-A8C8-4E10-B777-6917457573F9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{2A08183A-8A5F-432E-B2E6-F44B0372575F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{079E1C55-604D-4B14-8E06-E5D5435BE50A}C:\users\matts\appdata\local\programs \opera\65.0.3467.42\opera.exe] => (Allow) C:\users\matts\appdata\local\programs\opera\65.0.3 467.42\opera.exe No File
FirewallRules: [UDP Query User{CFBC3079-16A6-4A52-AD0A-30373F37E917}C:\users\matts\appdata\local\programs \opera\65.0.3467.42\opera.exe] => (Allow) C:\users\matts\appdata\local\programs\opera\65.0.3 467.42\opera.exe No File
FirewallRules: [{98F13058-B8F3-4863-A97A-423CC43F3CDC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{7104A4A0-3684-4C2A-AD73-F59909707FEE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{035D7BF8-64E7-40EA-940F-F6228EC55B01}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software) [File not signed]
FirewallRules: [{487792BE-3D79-4A93-8CF3-5DE3F4A31E58}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software) [File not signed]
FirewallRules: [{445770C3-3ADE-416A-8284-323C7F39AF7A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software) [File not signed]
FirewallRules: [{36F3F637-E38B-4AC4-981F-0AA7EFB20D6E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software) [File not signed]

==================== Restore Points =========================

08-12-2019 17:25:37 Scheduled Checkpoint

==================== Faulty Device Manager Devices ============
Reply With Quote
  #6  
Old December 16th, 2019, 06:32 PM
sportsfan7702 sportsfan7702 is offline
Senior Member
 
Join Date: Sep 2008
Posts: 306
==================== Event log errors: ========================

Application errors:
==================
Error: (12/16/2019 11:17:53 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4920,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\TileDataLayer\Database\EDB.log.

Error: (12/16/2019 11:06:19 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SearchUI.exe version 10.0.18362.418 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 1c1c

Start Time: 01d5b43231aad61d

Termination Time: 4294967295

Application Path: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\SearchUI.exe

Report Id: 78599cae-f5dc-4d48-a651-b5e22a67c520

Faulting package full name: Microsoft.Windows.Cortana_1.13.0.18362_neutral_neu tral_cw5n1h2txyewy

Faulting package-relative application ID: CortanaUI

Hang type: Quiesce

Error: (12/16/2019 10:47:01 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (9320,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\TileDataLayer\Database\EDB.log.

Error: (12/16/2019 09:29:15 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (10508,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\TileDataLayer\Database\EDB.log.

Error: (12/16/2019 08:58:17 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (12368,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\TileDataLayer\Database\EDB.log.

Error: (12/16/2019 08:47:21 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4680,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\TileDataLayer\Database\EDB.log.

Error: (12/16/2019 05:00:15 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (11980,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\TileDataLayer\Database\EDB.log.

Error: (12/15/2019 10:23:41 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (9544,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\TileDataLayer\Database\EDB.log.
Reply With Quote
  #7  
Old December 16th, 2019, 06:33 PM
sportsfan7702 sportsfan7702 is offline
Senior Member
 
Join Date: Sep 2008
Posts: 306
System errors:
=============
Error: (12/16/2019 10:59:22 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

Error: (12/16/2019 10:59:22 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Presentation Foundation Font Cache 3.0.0.0 service to connect.

Error: (12/15/2019 12:26:53 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NZKPSTSNW4P-Microsoft.XboxGamingOverlay.

Error: (12/13/2019 11:34:46 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NZKPSTSNW4P-Microsoft.XboxGamingOverlay.

Error: (12/13/2019 09:17:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Steam Client Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

Error: (12/13/2019 09:17:15 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.

Error: (11/25/2019 11:54:20 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Steam Client Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

Error: (11/25/2019 11:54:20 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.


Windows Defender:
===================================
Date: 2019-12-13 04:21:12.793
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {C0AE569D-A09A-4EF0-952D-43EB5E405345}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-12-13 04:18:13.242
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {268C8D9F-FE40-4B43-A02B-3986F343CC4C}
Scan Type: Antimalware
Scan Parameters: Quick Scan

==================== Memory info ===========================

BIOS: Insyde F.34 12/19/2014
Motherboard: Hewlett-Packard 227F
Processor: Intel(R) Core(TM) i5-4210U CPU @ 1.70GHz
Percentage of memory in use: 65%
Total physical RAM: 6074.15 MB
Available physical RAM: 2073.62 MB
Total Virtual: 7098.15 MB
Available Virtual: 2823.96 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:671.44 GB) (Free:573.94 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:23.53 GB) (Free:2.5 GB) NTFS ==>[system with boot components (obtained from drive)]

\\?\Volume{67899f6a-63a2-467d-9814-d6b89580224b}\ (WINRE) (Fixed) (Total:0.63 GB) (Free:0.33 GB) NTFS
\\?\Volume{34479b69-3f08-4eec-a65e-94afaa7f4487}\ () (Fixed) (Total:0.96 GB) (Free:0.41 GB) NTFS
\\?\Volume{96761440-6b60-46fa-8d5e-9ebc07d780e3}\ () (Fixed) (Total:0.84 GB) (Free:0.78 GB) NTFS
\\?\Volume{db0fd788-f90d-4d26-bd8a-23cc33437550}\ () (Fixed) (Total:0.84 GB) (Free:0.77 GB) NTFS
\\?\Volume{ac955b8f-d529-45d2-aca4-57c6610bea79}\ () (Fixed) (Total:0.25 GB) (Free:0.15 GB) FAT32
Reply With Quote
  #8  
Old December 16th, 2019, 06:33 PM
sportsfan7702 sportsfan7702 is offline
Senior Member
 
Join Date: Sep 2008
Posts: 306
==================== MBR & Partition Table ====================

================================================== ========
Disk: 0 (Size: 698.6 GB) (Disk ID: 715CA9C3)

Partition: GPT.

==================== End of Addition.txt =======================
Reply With Quote
  #9  
Old December 17th, 2019, 08:21 PM
Jintan's Avatar
Jintan Jintan is offline
Cyber Tech Help Moderator
 
Join Date: Dec 2004
Posts: 51,964
Howdy sportsfan7702

Everything looks okay. Are you having any problems at all?
Reply With Quote
  #10  
Old December 18th, 2019, 04:42 PM
sportsfan7702 sportsfan7702 is offline
Senior Member
 
Join Date: Sep 2008
Posts: 306
The occasional buffering on webpages sometimes but nothing major.
Reply With Quote
  #11  
Old December 18th, 2019, 07:16 PM
sportsfan7702 sportsfan7702 is offline
Senior Member
 
Join Date: Sep 2008
Posts: 306
Do have one question though. It may be moved to the appropriate forum if need be. These days, would you run Opera or Firefox? I'm not a big fan of Chrome or Edge.
Reply With Quote
  #12  
Old December 18th, 2019, 07:19 PM
Jintan's Avatar
Jintan Jintan is offline
Cyber Tech Help Moderator
 
Join Date: Dec 2004
Posts: 51,964
I'm just one person, so can only offer one person's opinion. But I always use Firefox. I never really cottoned to Opera, and I agree with you about Chrome and Edge.
Reply With Quote
Reply

Bookmarks

Topic Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump




All times are GMT +1. The time now is 03:56 PM.