Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-08-2017 Ran by [removed] (administrator) on BRANDON-PC (28-08-2017 11:16:00) Running from C:\Users\[removed]\Downloads [removed] Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe () C:\Program Files (x86)\AnyDesk\AnyDesk.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe (McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe (McAfee, Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe (Bitdefender) C:\Program Files\Bitdefender Antivirus Free\updatesrv.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe (Bitdefender) C:\Program Files\Bitdefender Antivirus Free\vsserv.exe (Bitdefender) C:\Program Files\Bitdefender Antivirus Free\vsservppl.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (VMware, Inc.) C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Bitdefender) C:\Program Files\Bitdefender Antivirus Free\bdagent.exe (Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Greenshot) C:\Program Files\Greenshot\Greenshot.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Spotify Ltd) C:\Users\Brandon\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Discord Inc.) C:\Users\Brandon\AppData\Local\Discord\app-0.0.298\Discord.exe (Franz) C:\Users\Brandon\AppData\Local\Franz\app-4.0.4\Franz.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Program Files (x86)\AnyDesk\AnyDesk.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Mega Limited) C:\Users\Brandon\AppData\Local\MEGAsync\MEGAsync.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Security) C:\Program Files\Intel Security\True Key\application\truekey.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Franz) C:\Users\Brandon\AppData\Local\Franz\app-4.0.4\Franz.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Franz) C:\Users\Brandon\AppData\Local\Franz\app-4.0.4\Franz.exe (Microsoft Corporation) C:\Windows\System32\cmd.exe (Intel Security) C:\Program Files\Intel Security\True Key\application\native_proxy.exe (Discord Inc.) C:\Users\Brandon\AppData\Local\Discord\app-0.0.298\Discord.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Intel Security) C:\Program Files\Intel Security\True Key\application\truekey.exe (Franz) C:\Users\Brandon\AppData\Local\Franz\app-4.0.4\Franz.exe (Franz) C:\Users\Brandon\AppData\Local\Franz\app-4.0.4\Franz.exe (Franz) C:\Users\Brandon\AppData\Local\Franz\app-4.0.4\Franz.exe (Franz) C:\Users\Brandon\AppData\Local\Franz\app-4.0.4\Franz.exe (Franz) C:\Users\Brandon\AppData\Local\Franz\app-4.0.4\Franz.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Franz) C:\Users\Brandon\AppData\Local\Franz\app-4.0.4\Franz.exe (Franz) C:\Users\Brandon\AppData\Local\Franz\app-4.0.4\Franz.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Discord Inc.) C:\Users\Brandon\AppData\Local\Discord\app-0.0.298\Discord.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\MSOSYNC.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Security) C:\Program Files\Intel Security\True Key\application\truekey.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8843520 2016-01-28] (Realtek Semiconductor) HKLM\...\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [527792 2017-01-28] (Greenshot) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-03-22] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3487032 2017-08-22] (Dropbox, Inc.) HKU\S-1-5-21-2700185069-337209265-1189023076-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3062560 2017-07-17] (Valve Corporation) HKU\S-1-5-21-2700185069-337209265-1189023076-1000\...\Run: [Spotify Web Helper] => C:\Users\Brandon\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1446000 2017-04-15] (Spotify Ltd) HKU\S-1-5-21-2700185069-337209265-1189023076-1000\...\Run: [Discord] => C:\Users\Brandon\AppData\Local\Discord\app-0.0.298\Discord.exe [57477112 2017-08-08] (Discord Inc.) HKU\S-1-5-21-2700185069-337209265-1189023076-1000\...\Run: [Franz] => C:\Users\Brandon\AppData\Local\Franz\app-4.0.4\Franz.exe [86039832 2016-09-06] (Franz) HKU\S-1-5-21-2700185069-337209265-1189023076-1000\...\Run: [GoogleChromeAutoLaunch_E39CDFEA4A38A6B3C5F413D26810AFC3] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1301848 2017-08-11] (Google Inc.) Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2017-04-15] ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe () Startup: C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2017-04-14] ShortcutTarget: MEGAsync.lnk -> C:\Users\Brandon\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) AutoConfigURL: [S-1-5-21-2700185069-337209265-1189023076-1000] => hxxp://web-fast-access.com/wpad.dat?3118156cbce7d2a4ab6f648a4935390234516216 Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{0C7448BC-E1DC-46CD-B398-FDC3864EF444}: [DhcpNameServer] 192.168.212.1 Tcpip\..\Interfaces\{3026E971-E11B-473C-8AF7-59CD541EBD45}: [DhcpNameServer] 192.168.116.2 Tcpip\..\Interfaces\{3184DF4E-A4FD-40B0-874B-AA2104940999}: [DhcpNameServer] 192.168.1.1 ManualProxies: 0hxxp://web-fast-access.com/wpad.dat?3118156cbce7d2a4ab6f648a4935390234516216 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-2700185069-337209265-1189023076-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-2700185069-337209265-1189023076-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-06-26] (Intel Security) BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-04-11] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-04-15] (Oracle Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2017-04-17] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-04-17] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-04-15] (Oracle Corporation) BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-06-26] (Intel Security) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-04-15] (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2017-04-17] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-04-15] (Oracle Corporation) Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-06-26] (Intel Security) Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-06-26] (Intel Security) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2017-04-17] (Microsoft Corporation) FireFox: ======== FF Plugin: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-04-15] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-04-15] (Oracle Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-04-15] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-04-15] (Oracle Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2017-04-17] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.) FF Plugin HKU\S-1-5-21-2700185069-337209265-1189023076-1000: @zoom.us/ZoomVideoPlugin -> C:\Users\Brandon\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2017-04-18] (Zoom Video Communications, Inc.) Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxp://www.google.com/ CHR StartupUrls: Default -> "hxxps://mail.google.com/mail/u/0/#inbox","hxxps://www.evernote.com/Home.action","hxxps://calendar.sunrise.am/","hxxps://mail.google.com/tasks/canvas?pli=1" CHR NewTab: Default -> Active:"chrome-extension://cfmnkhhioonhiehehedmnjibmampjiab/newtab.html" CHR Session Restore: Default -> is enabled. CHR Profile: C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default [2017-08-28] CHR Extension: (Google Slides) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-04-15] CHR Extension: (Entanglement Web App) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd [2017-04-15] CHR Extension: (BIODIGITAL HUMAN) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\agoenciogemlojlhccbcpcfflicgnaak [2017-04-15] CHR Extension: (3DTin) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\algoakekcdmbbikdjgjdahbfihboglmi [2017-04-15] CHR Extension: (Google Docs) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-04-15] CHR Extension: (Google Drive) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-15] CHR Extension: (Shortcuts for Google™) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\baohinapilmkigilbbbcccncoljkdpnd [2017-08-18] CHR Extension: (Web Developer) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbameneiokkgbdmiekhjnmfkcnldhhm [2017-08-08] CHR Extension: (Desmos Graphing Calculator) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhdheahnajobgndecdbggfmcojekgdko [2017-04-15] CHR Extension: (ColorZilla) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhlhnicpbhignbdhedgjhgdocnmhomnp [2017-04-15] CHR Extension: (YouTube) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-15] CHR Extension: (Math Mahjong) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbcfbhpnngegochhbdlanodnmijfplal [2017-04-15] CHR Extension: (New tab page by start.me) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfmnkhhioonhiehehedmnjibmampjiab [2017-06-11] CHR Extension: (uBlock Origin) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-07-21] CHR Extension: (Better Google Tasks) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\denjcdefjebbmlihdoojnebochnkgcin [2017-08-09] CHR Extension: (Tampermonkey) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2017-05-12] CHR Extension: (Chameleon) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmpojjilddefgnhiicjcmhbkjgbbclob [2017-08-07] CHR Extension: (Dropbox for Gmail) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpdmhfocilnekecfjgimjdeckachfbec [2017-04-15] CHR Extension: (Chinese Tutor Flashcards) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\egbbefchlgcnhjoncjebmkffamidfhae [2017-04-15] CHR Extension: (Razor Robotics - Learn about Robots!) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\egkgahnohapkoinbbljfnihggdleofpg [2017-04-15] CHR Extension: (Black Menu for Google™) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\eignhdfgaldabilaaegmdfbajngjmoke [2017-08-17] CHR Extension: (Google Sheets) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-04-15] CHR Extension: (Favicon Badges) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnaohmeicdkcipkhddeaibfhmbobbfm [2017-04-15] CHR Extension: (IQTELL) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmdccnpaoemhnnmekglmjlpeeochillh [2017-04-23] CHR Extension: (GoToMeeting Pro Screensharing) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcgikpombjkodabhbdalkcdhmllafipp [2017-04-18] CHR Extension: (Chuck Anderson) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\gegkoiakifeoejnjkbnnojkkdoegeofp [2017-08-13] CHR Extension: (Google Docs Offline) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-04-15] CHR Extension: (Planetarium) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\gheikhdfflhlbemfmhcfpeblehemeklp [2017-04-15] CHR Extension: (Best Education Apps) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\hglmfdgjlbhgpmadafhlekoafbodhfna [2017-04-15] CHR Extension: (StudentBook) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\hiimjijildjkajollpjecaocbbjfobed [2017-04-15] CHR Extension: (Vector Paint) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnbpdiengicdefcjecjbnjnoifekhgdo [2017-04-15] CHR Extension: (Dropbox) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2017-04-15] CHR Extension: (Cisco WebEx Extension) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2017-07-14] CHR Extension: (Reddit Enhancement Suite) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2017-08-07] CHR Extension: (Google Hangouts) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\knipolnnllmklapflnccelgolnpehhpl [2017-05-04] CHR Extension: (Evernote Web) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2017-04-15] CHR Extension: (Poppit!) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi [2017-04-15] CHR Extension: (3D Solar System Web) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdaaepplopehigjgkolniddiadbbkphd [2017-04-15] CHR Extension: (Boomerang for Gmail) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdanidgdpmkimeiiojknlnekblgmpdll [2017-05-16] CHR Extension: (Guitar Chords) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\megglpjmadjmghjegnallnhiknjnnjhh [2017-04-15] CHR Extension: (Pocket) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2017-04-15] CHR Extension: (ChemReference: Periodic Table) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjpnebljmdbglkmlnijcaplhfhkhdnib [2017-04-15] CHR Extension: (True Key™ by Intel Security) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbeldjopgciegccabfohnefghfpinncn [2017-08-07] CHR Extension: (Video Speed Controller) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffaoalbilbmmfgbnbgppjihopabppdk [2017-08-28] CHR Extension: (Save to Pocket) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj [2017-07-21] CHR Extension: (Chrome Web Store Payments) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22] CHR Extension: (Scientific Calculator) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\npoipmeppdioagbkigdlnpmjphnolaog [2017-07-06] CHR Extension: (Evernote Web Clipper) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2017-05-31] CHR Extension: (Gmail) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-04-15] CHR Extension: (Chrome Media Router) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-11] CHR Profile: C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-07-07] CHR Profile: C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-08-28] CHR Extension: (Google Slides) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-06-21] CHR Extension: (Google Docs) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2017-06-21] CHR Extension: (Google Drive) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-06-21] CHR Extension: (YouTube) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-06-21] CHR Extension: (uBlock Origin) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-08-07] CHR Extension: (Chameleon) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dmpojjilddefgnhiicjcmhbkjgbbclob [2017-08-07] CHR Extension: (Google Sheets) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-06-21] CHR Extension: (Google Docs Offline) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-06-22] CHR Extension: (Chrome Web Store Payments) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22] CHR Extension: (Gmail) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-06-21] CHR Extension: (Chrome Media Router) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-10] CHR Profile: C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 2 [2017-08-21] CHR Extension: (Google Slides) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-06-21] CHR Extension: (Google Docs) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2017-06-21] CHR Extension: (Google Drive) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-06-21] CHR Extension: (YouTube) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-06-21] CHR Extension: (Google Sheets) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-06-21] CHR Extension: (Google Docs Offline) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-06-22] CHR Extension: (Chrome Web Store Payments) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-06-21] CHR Extension: (Gmail) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-06-21] CHR Extension: (Chrome Media Router) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-19] CHR Profile: C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 3 [2017-07-15] CHR Extension: (Google Slides) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-06-21] CHR Extension: (Google Docs) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2017-06-21] CHR Extension: (Google Drive) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-06-21] CHR Extension: (YouTube) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-06-21] CHR Extension: (Google Sheets) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-06-21] CHR Extension: (Google Docs Offline) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-06-22] CHR Extension: (Chrome Web Store Payments) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-06-21] CHR Extension: (Gmail) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-06-21] CHR Extension: (Chrome Media Router) - C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-14] CHR Profile: C:\Users\Brandon\AppData\Local\Google\Chrome\User Data\System Profile [2017-06-22] ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [1738952 2017-04-15] () R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-03-17] (Apple Inc.) R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3042544 2017-03-14] (Microsoft Corporation) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-04-15] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-04-15] (Dropbox, Inc.) R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [49992 2017-08-22] (Dropbox, Inc.) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [383016 2017-07-14] (EasyAntiCheat Ltd) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [974632 2016-02-19] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [209184 2016-03-16] (Intel Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes) R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1269824 2017-06-21] (Bitdefender) R2 Themes; C:\Windows\system32\themeservice.dll [44544 2017-04-15] (Microsoft Corporation) [File not signed] R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [1001920 2017-06-26] (McAfee, Inc.) R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [16928 2017-06-26] (McAfee, Inc.) S3 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [87760 2017-06-26] (McAfee, Inc.) R2 updatesrv; C:\Program Files\Bitdefender Antivirus Free\updatesrv.exe [100392 2017-05-04] (Bitdefender) R2 vsserv; C:\Program Files\Bitdefender Antivirus Free\vsserv.exe [100392 2017-05-04] (Bitdefender) R2 vsservppl; C:\Program Files\Bitdefender Antivirus Free\vsservppl.exe [100392 2017-05-04] (Bitdefender) S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [128232 2017-02-08] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R0 atc; C:\Windows\System32\DRIVERS\atc.sys [950160 2017-06-07] (BitDefender S.R.L. Bucharest, ROMANIA) R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1612648 2017-04-19] (BitDefender) R1 bdfwfpf; C:\Program Files\Bitdefender Antivirus Free\bdfwfpf.sys [127312 2016-02-22] (BitDefender LLC) R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [147528 2016-01-24] (Rivet Networks, LLC.) R3 edrsensor; C:\Windows\System32\DRIVERS\edrsensor.sys [259880 2017-06-23] (BitDefender S.R.L. Bucharest, ROMANIA) R0 gzflt; C:\Windows\System32\drivers\gzflt.sys [187688 2017-05-11] (BitDefender LLC) R3 KillerEth; C:\Windows\System32\DRIVERS\e24w7x64.sys [125488 2015-04-01] (Qualcomm Atheros, Inc.) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [253856 2017-08-28] (Malwarebytes) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [180264 2016-02-04] (Intel Corporation) R2 trufos; C:\Windows\System32\drivers\trufos.sys [520032 2016-06-22] (BitDefender S.R.L.) R1 vmkbd3; C:\Windows\System32\DRIVERS\vmkbd.sys [52288 2017-06-19] (VMware, Inc.) R2 vmparport; C:\Windows\System32\DRIVERS\vmparport.sys [49216 2017-06-19] (VMware, Inc.) R0 vsock; C:\Windows\System32\DRIVERS\vsock.sys [93248 2016-09-30] (VMware, Inc.) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-08-28 11:13 - 2017-08-28 11:13 - 000000000 ___HD C:\OneDriveTemp 2017-08-23 13:06 - 2017-08-23 13:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-08-22 09:55 - 2017-08-22 09:55 - 000049992 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe 2017-08-22 09:55 - 2017-08-22 09:55 - 000045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys 2017-08-22 09:55 - 2017-08-22 09:55 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys 2017-08-22 09:55 - 2017-08-22 09:55 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys 2017-08-21 19:45 - 2017-08-21 19:45 - 000066683 _____ C:\Users\Brandon\Downloads\Addition.txt 2017-08-21 19:44 - 2017-08-28 11:16 - 000032860 _____ C:\Users\Brandon\Downloads\FRST.txt 2017-08-21 19:44 - 2017-08-28 11:16 - 000000000 ____D C:\FRST 2017-08-21 19:43 - 2017-08-21 19:43 - 002395648 _____ (Farbar) C:\Users\Brandon\Downloads\FRST64.exe 2017-08-21 15:31 - 2017-08-21 15:31 - 008927124 _____ C:\Users\Brandon\Downloads\crazyclientv9.7_mpgh.net.zip 2017-08-21 15:31 - 2017-08-21 15:31 - 000000000 ____D C:\Users\Brandon\Downloads\crazyclientv9.7_mpgh.net 2017-08-19 22:35 - 2017-08-19 22:35 - 000890144 _____ C:\Users\Brandon\Downloads\Recording_2017-08-19_22_32_43.m4a 2017-08-18 11:14 - 2017-08-18 11:14 - 037255040 _____ (The Git Development Community ) C:\Users\Brandon\Downloads\Git-2.14.1-64-bit (1).exe 2017-08-17 11:34 - 2017-08-17 11:34 - 000000153 _____ C:\Users\Brandon\.bash_history 2017-08-17 11:30 - 2017-08-17 11:31 - 000000000 ____D C:\Program Files\Git 2017-08-17 11:30 - 2017-08-17 11:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Git 2017-08-17 11:30 - 2017-08-17 11:30 - 000000000 ____D C:\ProgramData\Git 2017-08-17 11:26 - 2017-08-17 11:27 - 037255040 _____ (The Git Development Community ) C:\Users\Brandon\Downloads\Git-2.14.1-64-bit.exe 2017-08-17 00:10 - 2017-08-17 00:10 - 000000000 ____D C:\Users\Brandon\AppData\Local\Fusetools 2017-08-17 00:10 - 2017-08-17 00:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fuse 2017-08-17 00:10 - 2017-08-17 00:10 - 000000000 ____D C:\ProgramData\Dependencies 2017-08-17 00:10 - 2017-08-17 00:10 - 000000000 ____D C:\Program Files (x86)\Fuse 2017-08-17 00:09 - 2017-08-17 00:09 - 000000007 _____ C:\Users\Brandon\Downloads\VcRedistLog.txt 2017-08-17 00:08 - 2017-08-17 00:09 - 090254160 _____ (Fusetools) C:\Users\Brandon\Downloads\fuse_win_1_2_1_13974.exe 2017-08-15 19:06 - 2017-08-15 19:06 - 000010728 _____ C:\Users\Brandon\Downloads\meeting (15).collab 2017-08-13 23:42 - 2017-01-07 16:49 - 000000000 ____D C:\Users\Brandon\Downloads\flatoon-master 2017-08-13 23:41 - 2017-08-13 23:41 - 000001182 _____ C:\Users\Brandon\Downloads\flatoon-master.zip 2017-08-11 18:01 - 2017-08-11 18:02 - 026828247 _____ C:\Users\Brandon\Downloads\Phoenix3.ipa 2017-08-11 17:51 - 2017-08-11 17:51 - 000046224 _____ C:\Users\Brandon\Downloads\com.kanesbetas.microplayer_0.0.1-165+debug_iphoneos-arm.zip 2017-08-11 17:51 - 2017-08-11 17:51 - 000046224 _____ C:\Users\Brandon\Downloads\com.kanesbetas.microplayer_0.0.1-165+debug_iphoneos-arm (1).zip 2017-08-10 20:30 - 2017-08-10 20:30 - 000001138 _____ C:\Users\Public\Desktop\Bitdefender Antivirus Free.lnk 2017-08-10 20:30 - 2017-08-10 20:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender Antivirus Free 2017-08-10 20:30 - 2017-08-10 20:30 - 000000000 ____D C:\ProgramData\Bitdefender 2017-08-10 20:30 - 2017-06-23 03:51 - 000259880 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\Windows\system32\Drivers\edrsensor.sys 2017-08-10 20:30 - 2017-06-07 05:04 - 000950160 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\Windows\system32\Drivers\atc.sys 2017-08-10 20:30 - 2017-05-11 05:37 - 000187688 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys 2017-08-10 20:30 - 2017-04-19 07:19 - 001612648 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys 2017-08-10 20:29 - 2017-08-10 20:29 - 000000000 ____D C:\Users\Brandon\AppData\Roaming\QuickScan 2017-08-10 20:29 - 2016-06-22 15:40 - 000520032 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys 2017-08-10 20:28 - 2017-08-28 11:15 - 000000000 ____D C:\Program Files\Bitdefender Antivirus Free 2017-08-10 20:26 - 2017-08-28 11:15 - 000003648 _____ C:\Windows\System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 2017-08-10 20:24 - 2017-08-28 11:13 - 000000000 ____D C:\Program Files\Bitdefender Agent 2017-08-10 20:24 - 2017-08-10 20:24 - 000048446 _____ C:\ProgramData\agent.1502421891.bdinstall.bin 2017-08-10 20:24 - 2017-08-10 20:24 - 000000000 ____D C:\ProgramData\Bitdefender Agent 2017-08-10 20:11 - 2017-08-10 20:11 - 009932672 _____ C:\Users\Brandon\Downloads\bitdefender_online.exe 2017-08-08 19:07 - 2017-08-08 19:07 - 000010728 _____ C:\Users\Brandon\Downloads\meeting (14).collab 2017-08-08 16:17 - 2017-08-08 16:17 - 000000000 ____D C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc 2017-08-07 13:15 - 2017-08-07 13:15 - 005093855 _____ C:\Users\Brandon\Downloads\video (8).mov 2017-08-07 12:47 - 2017-08-07 12:47 - 004307358 _____ C:\Users\Brandon\Downloads\crazyclientv9.6.2_mpgh.net.zip 2017-08-07 10:42 - 2017-08-07 10:42 - 000003180 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2700185069-337209265-1189023076-1000 ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-08-28 11:13 - 2017-06-18 20:08 - 000000000 ____D C:\Users\Brandon\AppData\Roaming\Franz 2017-08-28 11:13 - 2017-04-17 22:39 - 000000000 ___RD C:\Users\Brandon\OneDrive 2017-08-28 11:13 - 2017-04-15 04:41 - 000000000 ____D C:\Program Files (x86)\Steam 2017-08-28 11:12 - 2017-04-15 04:45 - 000000906 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2017-08-28 11:03 - 2009-07-13 21:45 - 000026544 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-08-28 11:03 - 2009-07-13 21:45 - 000026544 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-08-28 11:01 - 2009-07-13 22:13 - 000785814 _____ C:\Windows\system32\PerfStringBackup.INI 2017-08-28 11:01 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\inf 2017-08-28 10:56 - 2017-07-06 21:06 - 000000000 ____D C:\ProgramData\VMware 2017-08-28 10:56 - 2017-04-15 04:47 - 000253856 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-08-28 10:56 - 2009-07-13 22:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2017-08-24 12:33 - 2017-04-15 04:28 - 000065536 _____ C:\Windows\system32\spu_storage.bin 2017-08-24 11:50 - 2017-04-15 04:45 - 000000910 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2017-08-23 13:06 - 2017-04-15 04:45 - 000000000 ____D C:\Program Files (x86)\Dropbox 2017-08-23 12:46 - 2017-04-18 17:47 - 000000000 ____D C:\Users\Brandon\AppData\Roaming\.minecraft 2017-08-23 10:13 - 2017-04-14 22:18 - 000000000 ____D C:\Program Files (x86)\McAfee 2017-08-22 13:26 - 2017-04-14 22:18 - 000003312 _____ C:\Windows\System32\Tasks\McAfee Remediation (Prepare) 2017-08-22 13:26 - 2017-04-14 22:18 - 000000000 ____D C:\ProgramData\McAfee 2017-08-22 12:26 - 2017-04-14 22:18 - 000000000 ____D C:\Program Files\Common Files\AV 2017-08-21 19:50 - 2017-04-15 04:40 - 000001123 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk 2017-08-21 19:50 - 2017-04-15 04:40 - 000001111 _____ C:\Users\Public\Desktop\Opera Browser.lnk 2017-08-21 19:50 - 2017-04-15 04:16 - 000002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-08-21 19:50 - 2017-04-15 04:16 - 000002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-08-21 19:50 - 2017-04-15 03:44 - 000001413 _____ C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2017-08-21 19:37 - 2017-04-14 22:18 - 000000000 ____D C:\Users\Brandon\AppData\Local\tkdata 2017-08-19 17:51 - 2017-04-15 04:43 - 000000000 ____D C:\Users\Brandon\AppData\Local\Spotify 2017-08-19 16:24 - 2017-04-15 04:43 - 000000000 ____D C:\Users\Brandon\AppData\Roaming\Spotify 2017-08-17 19:27 - 2017-04-14 22:25 - 000000000 ___RD C:\Users\Brandon\Documents\MEGA 2017-08-17 11:34 - 2017-04-15 03:44 - 000000000 ____D C:\Users\Brandon 2017-08-17 11:24 - 2017-04-14 22:30 - 000000000 ____D C:\Users\Brandon\AppData\Local\clink 2017-08-17 10:57 - 2017-04-15 04:40 - 000000000 ____D C:\Program Files (x86)\Opera 2017-08-17 00:10 - 2017-04-15 04:03 - 000000000 ____D C:\ProgramData\Package Cache 2017-08-16 10:54 - 2017-04-15 04:40 - 000003850 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1492256439 2017-08-13 13:10 - 2017-06-21 12:21 - 000002339 _____ C:\Users\Brandon\Desktop\Arimyth Alt - Chrome.lnk 2017-08-13 13:10 - 2017-06-21 12:20 - 000002339 _____ C:\Users\Brandon\Desktop\Sylexserver - Chrome.lnk 2017-08-13 13:10 - 2017-06-21 12:13 - 000002339 _____ C:\Users\Brandon\Desktop\EDM Central - Chrome.lnk 2017-08-13 13:10 - 2017-06-21 12:13 - 000002299 _____ C:\Users\Brandon\Desktop\Brandon - Chrome.lnk 2017-08-13 13:06 - 2017-04-15 04:16 - 000000000 ____D C:\Users\Brandon\AppData\Local\Google 2017-08-11 18:03 - 2017-04-15 01:05 - 000000000 ____D C:\Program Files\Impactor_0.9.41 2017-08-09 10:28 - 2017-04-15 01:30 - 000000000 ____D C:\Users\Brandon\AppData\Roaming\discord 2017-08-08 19:10 - 2017-04-15 04:47 - 000077376 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-08-08 19:07 - 2017-04-15 04:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-08-08 16:17 - 2017-04-15 01:30 - 000002132 _____ C:\Users\Brandon\Desktop\Discord.lnk 2017-08-08 16:17 - 2017-04-15 01:30 - 000000000 ____D C:\Users\Brandon\AppData\Local\Discord 2017-08-07 12:49 - 2017-06-21 11:28 - 000000000 ____D C:\Users\Brandon\Downloads\crazyclientv9.4_mpgh.net 2017-08-07 10:42 - 2017-04-17 22:39 - 000002124 _____ C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk ==================== Files in the root of some directories ======= 2017-07-19 14:25 - 2017-07-19 14:25 - 000003159 _____ () C:\Users\Brandon\AppData\Local\recently-used.xbel 2017-08-10 20:24 - 2017-08-10 20:24 - 000048446 _____ () C:\ProgramData\agent.1502421891.bdinstall.bin 2017-04-15 04:06 - 2017-04-15 04:06 - 000000000 ____H () C:\ProgramData\DP45977C.lfl Some files in TEMP: ==================== 2017-05-01 15:10 - 2017-05-01 15:10 - 000288088 _____ (Microsoft Corporation) C:\Users\Brandon\AppData\Local\Temp\dxwebsetup.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-08-21 09:53 ==================== End of FRST.txt ============================