|
Malware Removal Discussion about Trojans, viruses, hoaxes, firewalls, spyware, and general Security issues. If you suspect your PC is infected with a virus, trojan or spyware app please include any supporting documentation or logs |
|
Topic Tools |
#1
|
|||
|
|||
Doing my yearly check for malware
I really should do this twice a year but in the last 3 months with work I have not had a chance. I'm running FRST an hope everyone has been well.
==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel Corporation -> ) C:\Windows\System32\igfxTray.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxHK.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\Pres entationFontCache.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wek yb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1 910.0.0_x64__8wekyb3d8bbwe\Calculator.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9270208 2018-11-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKU\S-1-5-21-3107326716-814032089-3740455390-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105904865\...\RunOnce: [Application Restart #0] => C:\Program Files\Mozilla Firefox\firefox.exe [566984 2019-12-05] (Mozilla Corporation -> Mozilla Corporation) HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105904865\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105907102\...\RunOnce: [Application Restart #0] => C:\Program Files\Mozilla Firefox\firefox.exe [566984 2019-12-05] (Mozilla Corporation -> Mozilla Corporation) HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105907102\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {2FB111B2-4601-4545-8FA8-70CD9F810B29} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_ 0_0_303_Plugin.exe [1457720 2019-12-10] (Adobe Inc. -> Adobe) Task: {48211D53-740F-4C4F-8F6C-3E39617E98D2} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe [335416 2019-12-10] (Adobe Inc. -> Adobe) Task: {8EFF3ADE-B677-490B-A0A6-A64F40DE12FD} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_ 0_0_303_pepper.exe [1453112 2019-12-10] (Adobe Inc. -> Adobe) Task: {C9AEBBAE-CDD4-497D-8700-2607B72A139B} - System32\Tasks\Opera scheduled Autoupdate 1574190292 => C:\Users\MattS\AppData\Local\Programs\Opera\launch er.exe [1528344 2019-12-12] (Opera Software AS -> Opera Software) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask .job => C:\WINDOWS\explorer.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{d09ea5d8-05ca-4dce-a6a2-7912228ab1f1}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{d7fd4481-caf7-4e4b-801a-8d29c88b4e10}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== Edge: ====== DownloadDir: C:\Users\MattS\Downloads Edge Notifications: HKU\S-1-5-21-3107326716-814032089-3740455390-1001 -> hxxps://www.eroprofile.com FireFox: ======== FF DefaultProfile: y5zdsbob.default FF ProfilePath: C:\Users\MattS\AppData\Roaming\Mozilla\Firefox\Pro files\y5zdsbob.default [2019-10-18] FF ProfilePath: C:\Users\MattS\AppData\Roaming\Mozilla\Firefox\Pro files\4t6if1oe.default-release [2019-12-16] FF Extension: (NoSquint Plus) - C:\Users\MattS\AppData\Roaming\Mozilla\Firefox\Pro files\4t6if1oe.default-release\Extensions\zoomlevelplus@zoomlevelplus.net .xpi [2019-08-12] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_ 303.dll [2019-12-10] (Adobe Inc. -> ) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_ 303.dll [2019-12-10] (Adobe Inc. -> ) ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [370560 2018-10-12] (Intel Corporation -> Intel Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6960640 2019-12-16] (Malwarebytes Inc -> Malwarebytes) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [324544 2018-11-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [278616 2017-08-18] (Synaptics Incorporated -> Synaptics Incorporated) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2019-12-03] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2019-12-03] (Microsoft Windows Publisher -> Microsoft Corporation) |
#2
|
|||
|
|||
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 Accelerometer; C:\WINDOWS\System32\drivers\Accelerometer.sys [53904 2019-07-22] (HP Inc. -> HP) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.) S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2019-12-16] (Malwarebytes Corporation -> Malwarebytes) R0 hpdskflt; C:\WINDOWS\System32\drivers\hpdskflt.sys [41104 2019-07-22] (HP Inc. -> HP) R3 HpqKbFiltr; C:\WINDOWS\System32\drivers\HpqKbFiltr64.sys [37112 2015-06-17] (Hewlett-Packard Company -> Hewlett-Packard Company) R3 ISCT; C:\WINDOWS\System32\drivers\ISCTD64.sys [46568 2013-08-13] (Intel(R) Smart Connect software -> ) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [216544 2019-12-16] (Malwarebytes Inc -> Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-12-16] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [224408 2019-12-16] (Malwarebytes Corporation -> Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73584 2019-12-16] (Malwarebytes Corporation -> Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [278344 2019-12-16] (Malwarebytes Inc -> Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [116832 2019-12-16] (Malwarebytes Corporation -> Malwarebytes) R3 pelmouse; C:\WINDOWS\system32\DRIVERS\pelmouse.sys [26880 2016-07-11] (WDKTestCert idd,131110062695071623 -> TPMX Electronics Ltd.) R3 pelusblf; C:\WINDOWS\system32\DRIVERS\pelusblf.sys [33048 2016-07-11] (WDKTestCert idd,131110062695071623 -> ) S3 phidmice; C:\WINDOWS\System32\drivers\phidmice.sys [33048 2016-07-11] (WDKTestCert idd,131110062695071623 -> ) S3 pmouself; C:\WINDOWS\System32\drivers\pmouself.sys [26880 2016-07-11] (WDKTestCert idd,131110062695071623 -> TPMX Electronics Ltd.) S3 pvendrlf; C:\WINDOWS\System32\drivers\pvendrlf.sys [15032 2016-07-11] (WDKTestCert idd,131110062695071623 -> TPMX Electronics Ltd.) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1010656 2017-11-27] (Realtek Semiconductor Corp. -> Realtek ) R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [8206848 2019-03-18] (Microsoft Windows -> Realtek Semiconductor Corporation ) R3 RTWlanE; C:\WINDOWS\System32\drivers\rtwlane.sys [7904088 2018-04-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation ) S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [53848 2017-08-18] (Synaptics Incorporated -> Synaptics Incorporated) R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [55384 2017-08-18] (Synaptics Incorporated -> Synaptics Incorporated) S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64912 2017-05-18] (Samsung Electronics Co., Ltd. -> QUALCOMM Incorporated) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45664 2019-12-03] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [355760 2019-12-03] (Microsoft Windows -> Microsoft Corporation) S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [151184 2016-07-15] (NGO -> MBB) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2019-12-03] (Microsoft Windows -> Microsoft Corporation) R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64 .sys [34944 2018-05-11] (HP Inc. -> HP) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) =================== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-12-16 11:20 - 2019-12-16 11:22 - 000012482 _____ C:\Users\MattS\Downloads\FRST.txt 2019-12-16 11:19 - 2019-12-16 11:19 - 002264064 _____ (Farbar) C:\Users\MattS\Downloads\FRST64.exe 2019-12-16 11:14 - 2019-12-16 11:14 - 000224408 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2019-12-16 11:14 - 2019-12-16 11:14 - 000116832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2019-12-16 11:14 - 2019-12-16 11:14 - 000073584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2019-12-16 11:12 - 2019-12-16 11:12 - 000000000 ____D C:\Users\MattS\AppData\LocalLow\IGDump 2019-12-16 11:05 - 2019-12-16 11:05 - 000278344 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2019-12-16 11:05 - 2019-12-16 11:05 - 000216544 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys 2019-12-16 11:02 - 2019-12-16 11:03 - 161071328 _____ (Malwarebytes) C:\Users\MattS\Downloads\MBSetup-122164.122164.exe 2019-12-16 10:59 - 2019-12-16 10:59 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2019-12-13 09:52 - 2019-12-13 09:52 - 000004206 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1574190292 2019-12-13 09:52 - 2019-12-13 09:52 - 000001399 _____ C:\Users\MattS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Opera Browser.lnk 2019-12-10 23:56 - 2019-12-10 23:56 - 025443840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 018020352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 009927992 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 007905000 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 007754240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 007600448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayR eady.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 007278592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 006516648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayR eady.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 006083832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 005943296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 005914112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 005764664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 004129416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 003729408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2019-12-10 23:56 - 2019-12-10 23:56 - 003703296 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 002800640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2019-12-10 23:56 - 2019-12-10 23:56 - 002762296 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 002716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2019-12-10 23:56 - 2019-12-10 23:56 - 002698768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2019-12-10 23:56 - 2019-12-10 23:56 - 002494432 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 002284544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.oneco re.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 002147328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 002082208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001757304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2019-12-10 23:56 - 2019-12-10 23:56 - 001748480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.deskt op.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001743888 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001697280 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001664904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001656600 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001647072 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001610752 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001539584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001512528 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001451520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 001413840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001399312 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2019-12-10 23:56 - 2019-12-10 23:56 - 001261464 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001182448 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 001098928 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001072952 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 001066496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001054864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 001006904 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000986936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys 2019-12-10 23:56 - 2019-12-10 23:56 - 000921600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dl l 2019-12-10 23:56 - 2019-12-10 23:56 - 000878080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000842552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000826368 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelinesvc.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 000822416 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 000797112 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000774456 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000674280 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 000673456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 000646144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dl l 2019-12-10 23:56 - 2019-12-10 23:56 - 000598016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000593128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe 2019-12-10 23:56 - 2019-12-10 23:56 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2019-12-10 23:56 - 2019-12-10 23:56 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000530944 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000524264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dl l 2019-12-10 23:56 - 2019-12-10 23:56 - 000513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 000511000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys 2019-12-10 23:56 - 2019-12-10 23:56 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000422712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2019-12-10 23:56 - 2019-12-10 23:56 - 000406480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dl l 2019-12-10 23:56 - 2019-12-10 23:56 - 000404480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\exfat.sys 2019-12-10 23:56 - 2019-12-10 23:56 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys 2019-12-10 23:56 - 2019-12-10 23:56 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2019-12-10 23:56 - 2019-12-10 23:56 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000127272 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cdfs.sys 2019-12-10 23:56 - 2019-12-10 23:56 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000097080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000089536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe 2019-12-10 23:56 - 2019-12-10 23:56 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentS tatusTracking.ConfigProvider.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000067112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsManagementServiceWinRt. ProxyStub.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelineprxy.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevQueryBroker.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000032056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys 2019-12-10 23:56 - 2019-12-10 23:56 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll 2019-12-10 23:56 - 2019-12-10 23:56 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll 2019-12-05 21:01 - 2019-12-13 02:15 - 000000000 ____D C:\Program Files\Mozilla Firefox 2019-12-05 15:20 - 2019-12-05 15:20 - 000000000 ____D C:\Users\MattS\AppData\Local\cache 2019-12-05 15:19 - 2019-12-16 11:05 - 000002029 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2019-12-05 15:19 - 2019-12-16 11:05 - 000002029 _____ C:\ProgramData\Desktop\Malwarebytes.lnk 2019-12-05 15:19 - 2019-12-16 11:04 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 2019-12-05 15:19 - 2019-12-16 11:04 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys 2019-12-05 15:19 - 2019-12-05 15:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2019-11-24 20:12 - 2019-11-24 20:12 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3107326716-814032089-3740455390-1001 2019-11-24 20:11 - 2019-11-24 20:11 - 000002363 _____ C:\Users\MattS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\OneDrive.lnk 2019-11-20 09:51 - 2019-11-20 09:51 - 172961592 _____ C:\Users\MattS\Downloads\Aradeth_Volvo_VNL670_v1.5 .3.1_ETS2.scs 2019-11-19 15:32 - 2019-11-19 15:38 - 102733747 _____ C:\Users\MattS\Downloads\Volvo_Vnl_2019_v2.17.zip 2019-11-19 15:31 - 2019-11-19 15:42 - 211735887 _____ C:\Users\MattS\Downloads\volvo.7z 2019-11-19 14:45 - 2019-11-19 14:46 - 015303760 _____ (Auslogics ) C:\Users\MattS\Downloads\registry-cleaner-setup.exe 2019-11-19 13:38 - 2019-11-19 13:39 - 003770512 _____ (Opera Software) C:\Users\MattS\Downloads\OperaGXSetup (1).exe 2019-11-19 10:17 - 2019-11-19 10:18 - 248290819 _____ C:\Users\MattS\Downloads\Volvo_vnl_truckstop_v1.5. zip |
#3
|
|||
|
|||
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.) 2019-12-16 11:21 - 2019-01-10 10:07 - 000000000 ____D C:\FRST 2019-12-16 11:16 - 2019-03-18 22:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-12-16 11:11 - 2018-07-05 20:11 - 000000000 ____D C:\Users\MattS\AppData\LocalLow\Mozilla 2019-12-16 11:05 - 2019-08-13 21:47 - 000840852 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2019-12-16 11:05 - 2019-03-18 22:50 - 000000000 ____D C:\WINDOWS\INF 2019-12-16 10:59 - 2018-02-25 22:09 - 000000000 __SHD C:\Users\MattS\IntelGraphicsProfiles 2019-12-16 10:58 - 2019-08-13 21:55 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2019-12-16 10:57 - 2019-03-18 22:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2019-12-16 09:23 - 2019-08-13 21:30 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2019-12-15 11:30 - 2018-02-25 22:14 - 000000000 ____D C:\Users\MattS\OneDrive\Documents\American Truck Simulator 2019-12-15 10:47 - 2019-02-10 14:38 - 000000000 ____D C:\Program Files (x86)\Steam 2019-12-15 00:26 - 2019-08-29 23:08 - 000000000 ____D C:\WINDOWS\AppReadiness 2019-12-13 23:36 - 2019-03-18 22:52 - 000000000 ___HD C:\Program Files\WindowsApps 2019-12-13 02:17 - 2018-02-25 22:09 - 000000000 __RHD C:\Users\Public\AccountPictures 2019-12-13 02:17 - 2018-02-25 22:09 - 000000000 ___RD C:\Users\MattS\3D Objects 2019-12-13 02:15 - 2019-10-15 19:57 - 000257824 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2019-12-13 02:15 - 2019-08-12 09:58 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2019-12-13 02:12 - 2019-03-18 22:52 - 000000000 ____D C:\WINDOWS\SystemResources 2019-12-13 02:12 - 2019-03-18 22:52 - 000000000 ____D C:\WINDOWS\ShellExperiences 2019-12-13 02:12 - 2019-03-18 22:52 - 000000000 ____D C:\WINDOWS\bcastdvr 2019-12-11 00:06 - 2019-02-09 20:13 - 000000000 ____D C:\WINDOWS\system32\MRT 2019-12-11 00:04 - 2019-09-10 23:10 - 000000000 ____D C:\WINDOWS\CbsTemp 2019-12-11 00:04 - 2019-02-09 20:12 - 129221664 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2019-12-10 10:40 - 2018-02-25 22:14 - 000000000 ____D C:\Users\MattS\OneDrive\Documents\Euro Truck Simulator 2 2019-12-10 09:11 - 2019-11-12 09:07 - 000004558 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier 2019-12-10 09:11 - 2019-03-18 22:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2019-12-10 09:11 - 2019-03-18 22:52 - 000000000 ____D C:\WINDOWS\system32\Macromed 2019-12-10 08:11 - 2019-09-10 09:11 - 000004546 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player NPAPI Notifier 2019-12-07 19:54 - 2019-08-12 09:58 - 000001011 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2019-12-05 15:19 - 2019-03-18 22:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2019-12-05 15:18 - 2019-05-28 09:43 - 000000000 ____D C:\Program Files\Malwarebytes 2019-12-05 15:18 - 2019-03-27 10:30 - 000000000 ____D C:\ProgramData\Malwarebytes 2019-12-03 09:45 - 2019-02-09 18:02 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2019-11-24 20:12 - 2018-02-25 22:12 - 000000000 ___RD C:\Users\MattS\OneDrive 2019-11-19 09:05 - 2019-08-13 21:37 - 000000000 ____D C:\Users\MattS ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ======================== |
#4
|
|||
|
|||
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-12-2019
Ran by MattS (16-12-2019 11:23:27) Running from C:\Users\MattS\Downloads Windows 10 Home Version 1903 18362.535 (X64) (2019-08-14 03:57:42) Boot Mode: Normal ================================================== ======== ==================== Accounts: ============================= Administrator (S-1-5-21-3107326716-814032089-3740455390-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3107326716-814032089-3740455390-503 - Limited - Disabled) Guest (S-1-5-21-3107326716-814032089-3740455390-501 - Limited - Disabled) MattS (S-1-5-21-3107326716-814032089-3740455390-1001 - Administrator - Enabled) => C:\Users\MattS WDAGUtilityAccount (S-1-5-21-3107326716-814032089-3740455390-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 18.06 (x64) (HKLM\...\7-Zip) (Version: 18.06 - Igor Pavlov) Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.303 - Adobe) Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.303 - Adobe) Malwarebytes version 4.0.4.49 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.0.4.49 - Malwarebytes) Microsoft OneDrive (HKU\S-1-5-21-3107326716-814032089-3740455390-1001\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105904865\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105907102\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation) Mozilla Firefox 71.0 (x64 en-US) (HKLM\...\Mozilla Firefox 71.0 (x64 en-US)) (Version: 71.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 68.0.1 - Mozilla) Opera Stable 65.0.3467.72 (HKU\S-1-5-21-3107326716-814032089-3740455390-1001\...\Opera 65.0.3467.72) (Version: 65.0.3467.72 - Opera Software) Opera Stable 65.0.3467.72 (HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105904865\...\Opera 65.0.3467.72) (Version: 65.0.3467.72 - Opera Software) Opera Stable 65.0.3467.72 (HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105907102\...\Opera 65.0.3467.72) (Version: 65.0.3467.72 - Opera Software) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8416 - Realtek Semiconductor Corp.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Steep (HKLM-x32\...\Uplay Install 3279) (Version: - Ubisoft) Synaptics ClickPad Driver (HKLM\...\SynTPDeinstKey) (Version: 19.3.31.31 - Synaptics Incorporated) Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{16AD6161-2E47-4BF1-AA77-0946EFE93E08}) (Version: 2.61.0.0 - Microsoft Corporation) Uplay (HKLM-x32\...\Uplay) (Version: 88.0 - Ubisoft) Packages: ========= Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.18 11.1.0_x64__8wekyb3d8bbwe [2019-02-09] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.18 11.1.0_x86__8wekyb3d8bbwe [2019-02-09] (Microsoft Corporation) [MS Ad] Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.33.13094.0_ x64__8wekyb3d8bbwe [2019-11-13] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireColl ection_4.5.12061.0_x64__8wekyb3d8bbwe [2019-12-11] (Microsoft Studios) [MS Ad] MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.33.13253 .0_x64__8wekyb3d8bbwe [2019-11-24] (Microsoft Corporation) [MS Ad] ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3107326716-814032089-3740455390-1001_Classes\CLSID\{C591CFEA-E432-495d-A0BE-58E4CCD87B17}\Shell\Open\Command -> C:\Program Files\Synaptics\SynTP\SynTPCpl.dll (Synaptics Incorporated -> Synaptics Incorporated) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-12-30] (Igor Pavlov) [File not signed] ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-12-05] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-12-30] (Igor Pavlov) [File not signed] ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2018-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-12-30] (Igor Pavlov) [File not signed] ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-12-05] (Malwarebytes Corporation -> Malwarebytes) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Min imal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Net work\MBAMService => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer trusted/restricted ========== ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2019-02-09 19:26 - 2019-02-09 19:21 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts |
#5
|
|||
|
|||
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2019-02-09 19:26 - 2019-02-09 19:21 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105904412\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105906662\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105904615\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105906896\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg HKU\S-1-5-21-3107326716-814032089-3740455390-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\MattS\AppData\Local\Microsoft\Windows\The mes\RoamedThemeFiles\DesktopBackground\facebook_15 11574001546.jpg HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105904865\Control Panel\Desktop\\Wallpaper -> C:\Users\MattS\AppData\Local\Microsoft\Windows\The mes\RoamedThemeFiles\DesktopBackground\facebook_15 11574001546.jpg HKU\S-1-5-21-3107326716-814032089-3740455390-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019105907102\Control Panel\Desktop\\Wallpaper -> C:\Users\MattS\AppData\Local\Microsoft\Windows\The mes\RoamedThemeFiles\DesktopBackground\facebook_15 11574001546.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Pol icies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer => (SmartScreenEnabled: Warn) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{0B4E4B78-359E-4BC9-8907-C612FF352809}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{68A417FD-E58B-4850-A451-2FCC16134762}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{5961CBC4-0D6D-4FAE-89A8-BD4D874C5FD0}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{B7A200C1-5DE6-4DCE-8BB7-4C8705AFA373}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{6332BB97-2AD8-480F-B7A0-986E950FC8C6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software) [File not signed] FirewallRules: [{2A3BDE2E-3ED5-4BE3-ACB8-76254EE074F4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software) [File not signed] FirewallRules: [{D6DD0BB4-D6A9-41E2-AA5A-E2860DD7FF31}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software) [File not signed] FirewallRules: [{B5155654-605C-4EB2-BF32-1D5F337F031E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software) [File not signed] FirewallRules: [{F6F9F423-A8C8-4E10-B777-6917457573F9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{2A08183A-8A5F-432E-B2E6-F44B0372575F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [TCP Query User{079E1C55-604D-4B14-8E06-E5D5435BE50A}C:\users\matts\appdata\local\programs \opera\65.0.3467.42\opera.exe] => (Allow) C:\users\matts\appdata\local\programs\opera\65.0.3 467.42\opera.exe No File FirewallRules: [UDP Query User{CFBC3079-16A6-4A52-AD0A-30373F37E917}C:\users\matts\appdata\local\programs \opera\65.0.3467.42\opera.exe] => (Allow) C:\users\matts\appdata\local\programs\opera\65.0.3 467.42\opera.exe No File FirewallRules: [{98F13058-B8F3-4863-A97A-423CC43F3CDC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software) FirewallRules: [{7104A4A0-3684-4C2A-AD73-F59909707FEE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software) FirewallRules: [{035D7BF8-64E7-40EA-940F-F6228EC55B01}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software) [File not signed] FirewallRules: [{487792BE-3D79-4A93-8CF3-5DE3F4A31E58}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software) [File not signed] FirewallRules: [{445770C3-3ADE-416A-8284-323C7F39AF7A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software) [File not signed] FirewallRules: [{36F3F637-E38B-4AC4-981F-0AA7EFB20D6E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software) [File not signed] ==================== Restore Points ========================= 08-12-2019 17:25:37 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============ |
#6
|
|||
|
|||
==================== Event log errors: ========================
Application errors: ================== Error: (12/16/2019 11:17:53 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (4920,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\TileDataLayer\Database\EDB.log. Error: (12/16/2019 11:06:19 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program SearchUI.exe version 10.0.18362.418 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 1c1c Start Time: 01d5b43231aad61d Termination Time: 4294967295 Application Path: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\SearchUI.exe Report Id: 78599cae-f5dc-4d48-a651-b5e22a67c520 Faulting package full name: Microsoft.Windows.Cortana_1.13.0.18362_neutral_neu tral_cw5n1h2txyewy Faulting package-relative application ID: CortanaUI Hang type: Quiesce Error: (12/16/2019 10:47:01 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (9320,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\TileDataLayer\Database\EDB.log. Error: (12/16/2019 09:29:15 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (10508,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\TileDataLayer\Database\EDB.log. Error: (12/16/2019 08:58:17 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (12368,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\TileDataLayer\Database\EDB.log. Error: (12/16/2019 08:47:21 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (4680,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\TileDataLayer\Database\EDB.log. Error: (12/16/2019 05:00:15 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (11980,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\TileDataLayer\Database\EDB.log. Error: (12/15/2019 10:23:41 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (9544,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\TileDataLayer\Database\EDB.log. |
#7
|
|||
|
|||
System errors:
============= Error: (12/16/2019 10:59:22 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (12/16/2019 10:59:22 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Presentation Foundation Font Cache 3.0.0.0 service to connect. Error: (12/15/2019 12:26:53 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NZKPSTSNW4P-Microsoft.XboxGamingOverlay. Error: (12/13/2019 11:34:46 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NZKPSTSNW4P-Microsoft.XboxGamingOverlay. Error: (12/13/2019 09:17:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (12/13/2019 09:17:15 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect. Error: (11/25/2019 11:54:20 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (11/25/2019 11:54:20 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect. Windows Defender: =================================== Date: 2019-12-13 04:21:12.793 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {C0AE569D-A09A-4EF0-952D-43EB5E405345} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-12-13 04:18:13.242 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {268C8D9F-FE40-4B43-A02B-3986F343CC4C} Scan Type: Antimalware Scan Parameters: Quick Scan ==================== Memory info =========================== BIOS: Insyde F.34 12/19/2014 Motherboard: Hewlett-Packard 227F Processor: Intel(R) Core(TM) i5-4210U CPU @ 1.70GHz Percentage of memory in use: 65% Total physical RAM: 6074.15 MB Available physical RAM: 2073.62 MB Total Virtual: 7098.15 MB Available Virtual: 2823.96 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:671.44 GB) (Free:573.94 GB) NTFS Drive d: (RECOVERY) (Fixed) (Total:23.53 GB) (Free:2.5 GB) NTFS ==>[system with boot components (obtained from drive)] \\?\Volume{67899f6a-63a2-467d-9814-d6b89580224b}\ (WINRE) (Fixed) (Total:0.63 GB) (Free:0.33 GB) NTFS \\?\Volume{34479b69-3f08-4eec-a65e-94afaa7f4487}\ () (Fixed) (Total:0.96 GB) (Free:0.41 GB) NTFS \\?\Volume{96761440-6b60-46fa-8d5e-9ebc07d780e3}\ () (Fixed) (Total:0.84 GB) (Free:0.78 GB) NTFS \\?\Volume{db0fd788-f90d-4d26-bd8a-23cc33437550}\ () (Fixed) (Total:0.84 GB) (Free:0.77 GB) NTFS \\?\Volume{ac955b8f-d529-45d2-aca4-57c6610bea79}\ () (Fixed) (Total:0.25 GB) (Free:0.15 GB) FAT32 |
#8
|
|||
|
|||
==================== MBR & Partition Table ====================
================================================== ======== Disk: 0 (Size: 698.6 GB) (Disk ID: 715CA9C3) Partition: GPT. ==================== End of Addition.txt ======================= |
#9
|
||||
|
||||
Howdy sportsfan7702
Everything looks okay. Are you having any problems at all? |
#10
|
|||
|
|||
The occasional buffering on webpages sometimes but nothing major.
|
#11
|
|||
|
|||
Do have one question though. It may be moved to the appropriate forum if need be. These days, would you run Opera or Firefox? I'm not a big fan of Chrome or Edge.
|
#12
|
||||
|
||||
I'm just one person, so can only offer one person's opinion. But I always use Firefox. I never really cottoned to Opera, and I agree with you about Chrome and Edge.
|
Bookmarks |
«
Previous Topic
|
Next Topic
»
|
|
Similar Topics | ||||
Topic | Topic Starter | Forum | Replies | Last Post |
I want to check for malware | Ernest123 | Malware Removal | 2 | July 17th, 2009 02:33 AM |
Yearly virus? | Zulu196 | Malware Removal | 3 | May 31st, 2007 09:23 AM |
check for malware? | lethal dosage | Malware Removal | 11 | January 8th, 2006 08:42 PM |
Yearly Physical | hypnotizeminds | Jokes Forum | 1 | April 22nd, 2005 10:59 PM |
yearly physical | renegade600 | Jokes Forum | 1 | October 13th, 2004 11:55 AM |
All times are GMT +1. The time now is 07:16 PM.