Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15.09.2018 Ran by [removed] (administrator) on TAM-HP (22-09-2018 21:01:56) Running from C:\Users\[removed]\Desktop\Antiviruses [removed] Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Windows\System32\nvwmi64.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe (Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe (NVIDIA Corporation) C:\Windows\System32\nvwmi64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (DigitalPersona, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe () C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro X476dw MFP\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP Officejet Pro 8610\Bin\ScanToPCActivationApp.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe (ShareX Team) C:\Program Files\ShareX\ShareX.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (NCR Corporation) C:\Program Files (x86)\NCR\Passport Web Edition\pwecsrvc.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe (Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpAgent.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPConnectionManager.exe (Infineon Technologies AG) C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IFXSPMGT.exe (Infineon Technologies AG) C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IFXTCS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe () C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe (PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe (Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Infineon Technologies AG) C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Infineon Technologies AG) C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\PSDrt.exe (ArcSoft, Inc.) C:\Windows\SysWOW64\ArcVCapRender\uArcCapture.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe (Portrait Displays, Inc) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro X476dw MFP\Bin\HPNetworkCommunicatorCom.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP Officejet Pro 8610\Bin\HPNetworkCommunicatorCom.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [HPPowerAssistant] => C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2941496 2011-03-17] (Hewlett-Packard Company) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2710824 2011-03-29] (Synaptics Incorporated) HKLM\...\Run: [MfeEpePcMonitor] => C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe [200704 2011-03-29] () HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-08-30] (AVAST Software) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-03-04] (IDT, Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [316392 2018-05-11] (Adobe Systems, Incorporated) HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [312376 2011-03-21] (Hewlett-Packard Company) HKLM-x32\...\Run: [File Sanitizer] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [12277760 2011-03-10] (Hewlett-Packard) HKLM-x32\...\Run: [NUSB3MON] => c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [112152 2011-01-17] (Intel Corporation) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-26] (Intel Corporation) HKLM-x32\...\Run: [HPConnectionManager] => c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [94264 2011-04-05] (Hewlett-Packard Development Company L.P.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [HPQuickWebProxy] => c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [76344 2011-03-30] (Hewlett-Packard Company) HKLM-x32\...\Run: [IFXSPMGTx] => c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [1125728 2011-01-19] (Infineon Technologies AG) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [Passport Web Edition Client] => C:\Program Files (x86)\NCR\Passport Web Edition\pwecsrvc.exe [24675 2013-04-24] (NCR Corporation) HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [1194048 2018-02-01] (PDF Complete Inc) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle Corporation) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2409944 2018-06-22] (Adobe Systems Incorporated) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe, Winlogon\Notify\DeviceNP: C:\Windows\SysWOW64\DeviceNP.dll [2011-03-07] (Hewlett-Packard Company) HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [SPReview] => "C:\windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 HKU\S-1-5-21-2257169433-888997055-2771706037-1001\...\Run: [HP Officejet Pro X476dw MFP (NET)] => C:\Program Files\HP\HP Officejet Pro X476dw MFP\Bin\ScanToPCActivationApp.exe [3487240 2014-03-06] (Hewlett-Packard Co.) HKU\S-1-5-21-2257169433-888997055-2771706037-1001\...\Run: [HP Officejet Pro 8610 (NET)] => C:\Program Files\HP\HP Officejet Pro 8610\Bin\ScanToPCActivationApp.exe [3487240 2014-07-21] (Hewlett-Packard Development Company, LP) HKU\S-1-5-21-2257169433-888997055-2771706037-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation) HKU\S-1-5-21-2257169433-888997055-2771706037-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [32993168 2018-09-12] (Epic Games, Inc.) HKU\S-1-5-21-2257169433-888997055-2771706037-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [HP Officejet Pro X476dw MFP (NET)] => C:\Program Files\HP\HP Officejet Pro X476dw MFP\Bin\ScanToPCActivationApp.exe [3487240 2014-03-06] (Hewlett-Packard Co.) HKU\S-1-5-21-2257169433-888997055-2771706037-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [HP Officejet Pro 8610 (NET)] => C:\Program Files\HP\HP Officejet Pro 8610\Bin\ScanToPCActivationApp.exe [3487240 2014-07-21] (Hewlett-Packard Development Company, LP) HKU\S-1-5-21-2257169433-888997055-2771706037-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation) HKU\S-1-5-21-2257169433-888997055-2771706037-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [32993168 2018-09-12] (Epic Games, Inc.) HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 Lsa: [Notification Packages] EpePcNp64 DPPassFilter scecli Startup: C:\Users\Tam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ShareX.lnk [2018-06-26] ShortcutTarget: ShareX.lnk -> C:\Program Files\ShareX\ShareX.exe (ShareX Team) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{F401344E-7C27-47D3-8034-E27465C3058D}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{FADA2F14-0E44-4874-828E-FF293601D6AE}: [DhcpNameServer] [removed] [removed] Internet Explorer: ================== HKU\S-1-5-21-2257169433-888997055-2771706037-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM/1 HKU\S-1-5-21-2257169433-888997055-2771706037-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp HKU\S-1-5-21-2257169433-888997055-2771706037-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM/1 HKU\S-1-5-21-2257169433-888997055-2771706037-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp SearchScopes: HKLM -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKLM -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2257169433-888997055-2771706037-1001 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2257169433-888997055-2771706037-1001 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKU\S-1-5-21-2257169433-888997055-2771706037-1001 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2257169433-888997055-2771706037-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2257169433-888997055-2771706037-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKU\S-1-5-21-2257169433-888997055-2771706037-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_171\bin\ssv.dll [2018-04-29] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-04-29] (Oracle Corporation) BHO-x32: File Sanitizer for HP ProtectTools -> {3134413B-49B4-425C-98A5-893C1F195601} -> C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2011-03-10] (Hewlett-Packard) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) FireFox: ======== FF HKLM-x32\...\Firefox\Extensions: [[removed]] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt FF Extension: (DigitalPersona Extension) - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2011-05-06] [Legacy] [not signed] FF HKU\S-1-5-21-2257169433-888997055-2771706037-1001\...\SeaMonkey\Extensions: [[removed]] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found FF HKU\S-1-5-21-2257169433-888997055-2771706037-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SeaMonkey\Extensions: [[removed]] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found FF Plugin: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-04-29] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-04-29] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2018-06-22] (Adobe Systems) FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom) FF Plugin-x32: @DVR/npmedia,version=3.1.0.4 -> C:\Program Files (x86)\webrec\WEB30\WebPlugin\npmedia.dll [2015-03-09] () FF Plugin-x32: @DVR/npTimeGrid,version=3.1.0.4 -> C:\Program Files (x86)\webrec\WEB30\WebPlugin\npTimeGrid.dll [2015-03-09] (Unauthorized copy) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-08-14] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-08-14] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.) FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2018-06-22] (Adobe Systems) FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom) FF Plugin ProgramFiles/Appdata: C:\Users\Tam\AppData\Roaming\mozilla\plugins\npatgpc.dll [2015-05-04] (Cisco WebEx LLC) Chrome: ======= CHR DefaultProfile: Profile 1 CHR Profile: C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-11-03] CHR Profile: C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-09-22] CHR Extension: (Slides) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12] CHR Extension: (Docs) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12] CHR Extension: (Google Drive) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-08-02] CHR Extension: (YouTube) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-02] CHR Extension: (Avast Passwords) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2018-08-17] CHR Extension: (Avast SafePrice | Comparison, deals, coupons) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2018-09-20] CHR Extension: (Sheets) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12] CHR Extension: (Google Docs Offline) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-24] CHR Extension: (AdBlock) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-09-18] CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2018-09-14] CHR Extension: (Avast Online Security) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2018-04-22] CHR Extension: (Chrome Web Store Payments) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-11] CHR Extension: (Material Dark) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\npadhaijchjemiifipabpmeebeelbmpd [2017-08-02] CHR Extension: (Gmail) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-02] CHR Extension: (Chrome Media Router) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-09-14] CHR Profile: C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 2 [2017-11-03] CHR Profile: C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3 [2018-09-21] CHR Extension: (Slides) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-11-04] CHR Extension: (DocHub - Edit and Sign PDF Documents) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\adgncicbhbjfpijkdmbijninnhnmiblj [2018-04-11] CHR Extension: (Share to Classroom) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\adokjfanaflbkibffcbhihgihpgijcei [2018-08-28] CHR Extension: (Docs) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-04] CHR Extension: (Google Drive) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-11-04] CHR Extension: (YouTube) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-12-04] CHR Extension: (Chromium License) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\egebdhfpiokhoiflhfpfcafldnljfjhi [2018-09-14] [UpdateUrl: hxxp://goguardian.com/licenses/update.php] <==== ATTENTION CHR Extension: (Duolingo) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ekajaiihjemkjldcienbdonodmbiklnb [2017-12-04] CHR Extension: (Sheets) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-12-04] CHR Extension: (Google Docs Offline) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-28] CHR Extension: (Avast Online Security) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\gomekmidlodglbbmalcneegieacbdmki [2018-08-29] CHR Extension: (Chromium M) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\haldlgldplgnggkjaafhelgiaglafanh [2018-09-21] [UpdateUrl: hxxps://ext.goguardian.com/stable.xml] <==== ATTENTION CHR Extension: (Dictionary) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\hpgblgbmcleigbahedfgempmpnlkhhpk [2018-08-28] CHR Extension: (Cloud Browser) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\kmomimblkpkjeilfbkinoonalgiejlcl [2018-08-28] CHR Extension: (Google Dictionary (by Google)) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2018-08-28] CHR Extension: (Minecraft Temple) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nfejgbpkichfijkfakkalfhlcngamele [2018-08-28] CHR Extension: (Chrome Web Store Payments) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-12] CHR Extension: (WeVideo - Video Editor and Maker) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\okgjbfikepgflmlelgfgecmgjnmnmnnb [2018-04-11] CHR Extension: (Gmail) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-11-04] CHR Extension: (Chrome Media Router) - C:\Users\Tam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-09-20] CHR Profile: C:\Users\Tam\AppData\Local\Google\Chrome\User Data\System Profile [2017-11-03] CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [818128 2018-06-22] (Adobe Systems Incorporated) R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2321384 2018-05-11] (Adobe Systems, Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2128872 2018-05-11] (Adobe Systems, Incorporated) R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7994520 2018-08-30] (AVAST Software) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [322464 2018-08-30] (AVAST Software) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [5745672 2018-04-26] () R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [485712 2011-04-01] (DigitalPersona, Inc.) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [529056 2018-07-19] (EasyAntiCheat Ltd) S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [464512 2011-03-07] (Hewlett-Packard Company) S3 HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [30776 2011-04-04] (Hewlett-Packard Development Company, L.P) R2 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [133688 2011-01-28] (Hewlett-Packard Company) R2 HPFSService; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [320512 2011-03-10] (Hewlett-Packard) [File not signed] R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [293944 2011-03-21] (Hewlett-Packard Company) R2 IFXSpMgtSrv; c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [1125728 2011-01-19] (Infineon Technologies AG) R2 IFXTCS; c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe [980320 2011-01-19] (Infineon Technologies AG) R2 McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [1318912 2011-03-29] () [File not signed] S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268704 2017-04-10] () R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [50688 2013-05-16] (Hewlett-Packard) [File not signed] R2 NVWMI; C:\windows\system32\nvwmi64.exe [4165568 2017-08-14] (NVIDIA Corporation) R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1793600 2018-02-01] (PDF Complete Inc) R2 PersonalSecureDriveService; c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe [203104 2011-01-19] (Infineon Technologies AG) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [66048 2013-05-16] (Hewlett-Packard) [File not signed] R2 uArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [502464 2010-11-11] (ArcSoft, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation) R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [656664 2014-08-19] (Wacom Technology, Corp.) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3750304 2017-04-10] (Intel® Corporation) S2 HP Health Check Service; "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe" [X] R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 ARCVCAM; C:\windows\System32\DRIVERS\ArcSoftVCapture.sys [32192 2010-11-11] (ArcSoft, Inc.) R1 aswArPot; C:\windows\System32\drivers\aswArPot.sys [199712 2018-08-30] (AVAST Software) R1 aswbidsdriver; C:\windows\System32\drivers\aswbidsdrivera.sys [229384 2018-08-30] (AVAST Software) R0 aswbidsh; C:\windows\System32\drivers\aswbidsha.sys [201320 2018-08-30] (AVAST Software) R0 aswblog; C:\windows\System32\drivers\aswbloga.sys [346664 2018-08-30] (AVAST Software) R0 aswbuniv; C:\windows\System32\drivers\aswbuniva.sys [59568 2018-08-30] (AVAST Software) R1 aswHdsKe; C:\windows\System32\drivers\aswHdsKe.sys [249016 2018-08-30] (AVAST Software) S3 aswHwid; C:\windows\System32\drivers\aswHwid.sys [46968 2018-08-30] (AVAST Software) R2 aswMonFlt; C:\windows\System32\drivers\aswMonFlt.sys [163392 2018-09-12] (AVAST Software) R1 aswRdr; C:\windows\System32\drivers\aswRdr2.sys [111864 2018-08-30] (AVAST Software) R0 aswRvrt; C:\windows\System32\drivers\aswRvrt.sys [87904 2018-08-30] (AVAST Software) R1 aswSnx; C:\windows\System32\drivers\aswSnx.sys [1027720 2018-08-30] (AVAST Software) R1 aswSP; C:\windows\System32\drivers\aswSP.sys [467320 2018-09-04] (AVAST Software) R2 aswStm; C:\windows\System32\drivers\aswStm.sys [215920 2018-09-12] (AVAST Software) R0 aswVmm; C:\windows\System32\drivers\aswVmm.sys [381560 2018-08-30] (AVAST Software) S3 DAMDrv; C:\windows\System32\DRIVERS\DAMDrv64.sys [63336 2011-03-03] (Hewlett-Packard Company) R3 johci; C:\windows\System32\DRIVERS\johci.sys [26712 2011-02-09] (JMicron Technology Corp.) R3 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [140672 2018-09-22] (Malwarebytes) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [192216 2018-09-22] (Malwarebytes) R0 MfeEpePc; C:\Windows\System32\Drivers\MfeEpePc.sys [168008 2011-03-29] (McAfee, Inc.) R3 NETwNs64; C:\windows\System32\DRIVERS\NETwsw01.sys [11534096 2015-05-04] (Intel Corporation) R1 PersonalSecureDrive; C:\windows\System32\drivers\psd.sys [44576 2010-01-25] (Infineon Technologies AG) R3 SNP2UVC; C:\windows\System32\DRIVERS\snp2uvc.sys [1826048 2010-12-21] () S3 SWDUMon; C:\windows\System32\DRIVERS\SWDUMon.sys [25608 2018-08-05] (SlimWare Utilities, Inc.) S3 TsUsb2; C:\windows\System32\Drivers\TSUSB2.sys [53760 2007-05-25] (HTL) S3 USBAAPL64; C:\windows\System32\Drivers\usbaapl64.sys [54784 2015-11-05] (Apple, Inc.) [File not signed] U1 aswbdisk; no ImagePath S3 btwampfl; system32\drivers\btwampfl.sys [X] S3 btwaudio; system32\drivers\btwaudio.sys [X] S3 btwavdt; system32\DRIVERS\btwavdt.sys [X] S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [X] S3 btwrchid; system32\DRIVERS\btwrchid.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-09-22 20:40 - 2018-09-22 20:40 - 000000000 ____D C:\ProgramData\MB2Migration 2018-09-22 20:22 - 2018-09-22 20:27 - 000140672 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys 2018-09-22 20:22 - 2018-09-22 20:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2018-09-22 20:22 - 2018-09-22 20:22 - 000000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2018-09-22 20:22 - 2016-03-10 14:09 - 000064896 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2018-09-22 20:22 - 2016-03-10 14:08 - 000027008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys 2018-09-22 20:21 - 2018-09-22 20:21 - 000000000 ____D C:\Users\Tam\AppData\Local\mbam 2018-09-16 14:57 - 2018-09-18 20:45 - 000715284 _____ C:\Users\Tam\Documents\Float Diagram.blend 2018-09-16 14:57 - 2018-09-18 20:44 - 000715284 _____ C:\Users\Tam\Documents\Float Diagram.blend1 2018-09-15 22:01 - 2018-09-16 15:03 - 000526868 _____ C:\Users\Tam\Documents\Panther Float Head.blend 2018-09-15 22:01 - 2018-09-15 22:01 - 000577164 _____ C:\Users\Tam\Documents\Panther Float Head.blend1 2018-09-08 16:59 - 2018-09-22 20:42 - 000192216 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamswissarmy.sys 2018-08-30 17:20 - 2018-08-30 17:20 - 000379608 _____ (AVAST Software) C:\windows\system32\aswBoot.exe ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-09-22 21:01 - 2018-08-03 17:33 - 000000000 ____D C:\Program Files (x86)\Adobe Photoshop CS6 2018-09-22 21:01 - 2017-08-03 11:11 - 000000000 ____D C:\FRST 2018-09-22 21:01 - 2017-08-02 19:38 - 000000000 ____D C:\Users\Tam\Desktop\Antiviruses 2018-09-22 20:46 - 2009-07-13 21:45 - 000020944 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2018-09-22 20:46 - 2009-07-13 21:45 - 000020944 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2018-09-22 20:38 - 2011-05-06 21:49 - 000000000 ____D C:\ProgramData\PDFC 2018-09-22 20:35 - 2014-11-20 09:53 - 000000000 ____D C:\ProgramData\NVIDIA 2018-09-22 20:35 - 2009-07-13 22:08 - 000000006 ____H C:\windows\Tasks\SA.DAT 2018-09-22 20:22 - 2017-08-02 19:41 - 000000000 ____D C:\ProgramData\Malwarebytes 2018-09-22 20:21 - 2017-08-02 20:05 - 000000000 ____D C:\Program Files (x86)\Steam 2018-09-22 20:19 - 2017-08-02 20:05 - 000000000 ____D C:\Users\Tam\AppData\Roaming\Spotify 2018-09-22 11:55 - 2018-07-31 21:14 - 000003494 _____ C:\windows\System32\Tasks\AdobeAAMUpdater-1.0-Tam-HP-Tam 2018-09-22 11:55 - 2018-07-31 21:14 - 000003450 _____ C:\windows\System32\Tasks\AdobeGCInvoker-1.0-Tam-HP-Tam 2018-09-22 11:55 - 2018-06-04 10:33 - 000003198 _____ C:\windows\System32\Tasks\Get Yeeted on Boi 2018-09-22 11:55 - 2017-11-17 17:02 - 000000000 ____D C:\windows\System32\Tasks\AVAST Software 2018-09-22 11:55 - 2014-11-20 09:58 - 000003332 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2018-09-22 11:55 - 2014-11-20 09:58 - 000003204 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2018-09-22 11:53 - 2018-05-12 21:35 - 000000000 ____D C:\Users\Tam\BrawlhallaReplays 2018-09-22 11:47 - 2017-09-23 19:21 - 000000000 ____D C:\Users\Tam\AppData\Local\AVAST Software 2018-09-22 11:34 - 2017-11-18 15:10 - 000000000 ____D C:\Users\Tam\AppData\Local\Warframe 2018-09-21 21:01 - 2017-08-04 09:56 - 000001344 _____ C:\Users\Tam\Desktop\Roblox Player.lnk 2018-09-21 21:01 - 2017-08-04 09:54 - 000001163 _____ C:\Users\Tam\Desktop\Roblox Studio.lnk 2018-09-21 21:01 - 2017-08-04 09:54 - 000000000 ____D C:\Users\Tam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox 2018-09-21 20:11 - 2018-04-27 21:39 - 000001272 _____ C:\Users\Tam\Desktop\nativelog.txt 2018-09-21 20:11 - 2018-04-27 21:30 - 000000000 ____D C:\Users\Tam\AppData\Roaming\.minecraft 2018-09-21 19:45 - 2017-11-03 22:25 - 000000000 ____D C:\Users\Tam\Documents\ShareX 2018-09-21 19:12 - 2017-08-02 20:14 - 000000000 ____D C:\Users\Tam\AppData\Local\Spotify 2018-09-18 20:25 - 2017-08-03 11:14 - 000000000 ____D C:\Program Files\paint.net 2018-09-18 19:35 - 2018-03-19 20:06 - 000000000 ____D C:\tmp 2018-09-17 18:19 - 2014-11-20 09:59 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2018-09-16 18:16 - 2009-07-13 22:08 - 000032594 _____ C:\windows\Tasks\SCHEDLGU.TXT 2018-09-16 14:49 - 2017-11-15 16:40 - 000004168 _____ C:\windows\System32\Tasks\Avast Emergency Update 2018-09-12 15:46 - 2017-11-15 16:39 - 000215920 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys 2018-09-12 15:46 - 2017-11-15 16:39 - 000163392 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys 2018-09-12 15:46 - 2014-11-20 09:57 - 000000000 ____D C:\Users\Tam\AppData\Roaming\Adobe 2018-09-10 16:07 - 2018-07-31 20:34 - 000000000 ____D C:\ProgramData\Adobe 2018-09-09 20:57 - 2018-02-19 09:52 - 000000000 ____D C:\Users\Tam\Desktop\AutoM8 2018-09-09 19:48 - 2018-08-03 17:09 - 000000000 ____D C:\Users\Tam\AppData\LocalLow\Adobe 2018-09-09 19:48 - 2018-07-31 20:28 - 000000000 ____D C:\Users\Tam\AppData\Local\Adobe 2018-09-09 17:28 - 2018-07-31 21:16 - 000000000 ___RD C:\Users\Tam\Creative Cloud Files 2018-09-08 16:58 - 2018-06-09 09:22 - 000152688 _____ (Malwarebytes) C:\windows\system32\Drivers\mbae64.sys 2018-09-04 16:42 - 2017-11-15 16:39 - 000467320 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys 2018-08-30 17:22 - 2017-11-15 16:39 - 000087904 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys 2018-08-30 17:20 - 2017-11-15 16:39 - 000381560 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys 2018-08-30 17:20 - 2017-11-15 16:39 - 000199712 _____ (AVAST Software) C:\windows\system32\Drivers\aswArPot.sys 2018-08-30 17:20 - 2017-11-15 16:39 - 000111864 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys 2018-08-30 17:20 - 2017-11-15 16:39 - 000046968 _____ (AVAST Software) C:\windows\system32\Drivers\aswHwid.sys 2018-08-30 17:19 - 2017-12-21 12:09 - 000249016 _____ (AVAST Software) C:\windows\system32\Drivers\aswHdsKe.sys 2018-08-30 17:19 - 2017-11-15 16:39 - 001027720 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys 2018-08-30 17:19 - 2017-11-15 16:39 - 000346664 _____ (AVAST Software) C:\windows\system32\Drivers\aswbloga.sys 2018-08-30 17:19 - 2017-11-15 16:39 - 000229384 _____ (AVAST Software) C:\windows\system32\Drivers\aswbidsdrivera.sys 2018-08-30 17:19 - 2017-11-15 16:39 - 000201320 _____ (AVAST Software) C:\windows\system32\Drivers\aswbidsha.sys 2018-08-30 17:19 - 2017-11-15 16:39 - 000059568 _____ (AVAST Software) C:\windows\system32\Drivers\aswbuniva.sys 2018-08-28 16:25 - 2018-03-17 11:14 - 000000000 ____D C:\Users\Tam\Documents\ROBLOX ==================== Files in the root of some directories ======= 2011-02-24 00:10 - 2011-02-24 00:10 - 000020432 _____ (Intel Corporation) C:\Users\Tam\AppData\Roaming\JomCap.dll 2014-11-20 09:06 - 2014-11-20 09:07 - 000050964 _____ () C:\Users\Tam\AppData\Roaming\QWInstall.log 2016-06-06 15:00 - 2016-06-06 15:00 - 000000000 _____ () C:\Users\Tam\AppData\Local\{887018FD-C5E6-4B09-9158-D77877341818} Some files in TEMP: ==================== 2014-11-20 08:55 - 2014-11-20 08:55 - 000426044 _____ (Hewlett-Packard Company) C:\Users\Tam\AppData\Local\Temp\CpqMC.dll 2016-03-09 15:20 - 2016-03-09 15:20 - 000000000 _____ () C:\Users\Tam\AppData\Local\Temp\etethdio.dll 2011-01-14 22:14 - 2011-01-14 22:14 - 003330232 _____ (Hewlett-Packard Company) C:\Users\Tam\AppData\Local\Temp\HPSWF.EXE 2018-07-13 10:30 - 2018-07-13 10:30 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-1010997884759045236.dll 2018-06-30 17:35 - 2018-06-30 17:35 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-114281658366092378.dll 2018-07-04 17:11 - 2018-07-04 17:11 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-1182409032652409725.dll 2018-07-03 10:57 - 2018-07-03 10:57 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-1247301502591679042.dll 2018-07-11 09:42 - 2018-07-11 09:42 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-1303097495445590414.dll 2018-07-06 13:33 - 2018-07-06 13:33 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-1603202929396162931.dll 2018-07-06 09:10 - 2018-07-06 09:10 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-1761239583132306730.dll 2018-06-27 20:37 - 2018-06-27 20:37 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-2047772158787543379.dll 2018-07-11 19:22 - 2018-07-11 19:22 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-2253401857238783313.dll 2018-07-09 17:27 - 2018-07-09 17:27 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-2337436248905988063.dll 2018-06-29 19:35 - 2018-06-29 19:35 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-2372963674945945934.dll 2018-07-08 19:34 - 2018-07-08 19:34 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-2521842757455238398.dll 2018-08-24 20:13 - 2018-08-24 20:13 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-2680262587391514660.dll 2018-08-11 10:25 - 2018-08-11 10:25 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-2707917457910123223.dll 2018-07-02 11:43 - 2018-07-02 11:43 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-2810650118798143401.dll 2018-07-03 10:27 - 2018-07-03 10:27 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-2870714046650673636.dll 2018-06-27 20:41 - 2018-06-27 20:41 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-3071523032528695610.dll 2018-07-11 14:25 - 2018-07-11 14:25 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-3385157986456784627.dll 2018-07-10 10:42 - 2018-07-10 10:42 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-3434624398456282948.dll 2018-07-01 14:23 - 2018-07-01 14:23 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-346477479070217186.dll 2018-07-04 09:29 - 2018-07-04 09:29 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-3631325410899275016.dll 2018-07-11 14:23 - 2018-07-11 14:23 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-373937473051150468.dll 2018-08-10 20:34 - 2018-08-10 20:34 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-3797971451813094983.dll 2018-07-12 18:28 - 2018-07-12 18:28 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-3926862313536065590.dll 2018-07-10 19:52 - 2018-07-10 19:52 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-4063391945295942949.dll 2018-07-08 10:06 - 2018-07-08 10:06 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-4066721505298895358.dll 2018-07-10 18:30 - 2018-07-10 18:30 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-4132040846415239579.dll 2018-07-12 11:35 - 2018-07-12 11:35 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-4144250482012100336.dll 2018-07-15 19:00 - 2018-07-15 19:00 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-437531092008481158.dll 2018-07-02 19:14 - 2018-07-02 19:14 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-4394814674473502463.dll 2018-07-08 19:31 - 2018-07-08 19:31 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-4600155326625628712.dll 2018-08-25 10:12 - 2018-08-25 10:12 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-4602828893507657241.dll 2018-07-06 13:19 - 2018-07-06 13:19 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-4905352235190754591.dll 2018-06-30 09:05 - 2018-06-30 09:05 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-5169747604384495880.dll 2018-07-06 13:32 - 2018-07-06 13:32 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-534242042647039370.dll 2018-07-13 18:31 - 2018-07-13 18:31 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-564741236961404434.dll 2018-07-11 11:59 - 2018-07-11 11:59 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-5669251281504923559.dll 2018-07-05 18:20 - 2018-07-05 18:20 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-5834296964424461125.dll 2018-07-02 19:11 - 2018-07-02 19:11 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-5948494479327703099.dll 2018-09-21 20:01 - 2018-09-21 20:01 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-6158942759581855103.dll 2018-07-05 20:55 - 2018-07-05 20:55 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-6403095216103572520.dll 2018-07-01 15:47 - 2018-07-01 15:47 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-6482936984306456604.dll 2018-07-06 11:22 - 2018-07-06 11:22 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-6502465683142607067.dll 2018-07-03 19:19 - 2018-07-03 19:19 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-6602546209477100510.dll 2018-07-08 12:14 - 2018-07-08 12:14 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-661082329947620103.dll 2018-06-28 10:14 - 2018-06-28 10:14 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-6989482188008190806.dll 2018-06-27 21:10 - 2018-06-27 21:10 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-7041843333542640632.dll 2018-06-30 09:29 - 2018-06-30 09:29 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-7108392836448466782.dll 2018-07-09 10:40 - 2018-07-09 10:40 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-7111294482199110590.dll 2018-07-06 11:06 - 2018-07-06 11:06 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-7275546105858303092.dll 2018-07-02 19:53 - 2018-07-02 19:53 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-7529871326098192204.dll 2018-06-29 14:17 - 2018-06-29 14:17 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-7546508394981004453.dll 2018-06-28 20:01 - 2018-06-28 20:01 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-7676497325359457392.dll 2018-07-30 18:39 - 2018-07-30 18:39 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-7697523056367623835.dll 2018-07-19 12:43 - 2018-07-19 12:43 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-7710967688979411009.dll 2018-07-08 19:35 - 2018-07-08 19:35 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-7731973479955226278.dll 2018-06-28 13:59 - 2018-06-28 13:59 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-8094715428981414831.dll 2018-07-05 10:33 - 2018-07-05 10:33 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-8151255613658643985.dll 2018-07-07 19:48 - 2018-07-07 19:48 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-8167974497104031064.dll 2018-06-29 09:39 - 2018-06-29 09:39 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-8284759178324540238.dll 2018-07-06 19:07 - 2018-07-06 19:07 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-8521551276089244759.dll 2018-07-02 21:16 - 2018-07-02 21:16 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-8645719817980766821.dll 2018-07-02 11:30 - 2018-07-02 11:30 - 000019968 ____N (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-8704415041380251485.dll 2018-07-11 11:55 - 2018-07-11 11:55 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-904380684433355865.dll 2018-08-26 20:45 - 2018-08-26 20:45 - 000019968 _____ (Red Hat®, Inc.) C:\Users\Tam\AppData\Local\Temp\jansi-64-9102354454545170408.dll 2017-08-02 16:54 - 2010-08-13 18:19 - 000468232 _____ (Microsoft Corporation) C:\Users\Tam\AppData\Local\Temp\MSN59C5.exe 2011-02-16 14:17 - 2011-02-16 14:17 - 000103792 _____ () C:\Users\Tam\AppData\Local\Temp\SWHelperQueryW.dll ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\windows\system32\winlogon.exe => File is digitally signed C:\windows\system32\wininit.exe => File is digitally signed C:\windows\SysWOW64\wininit.exe => File is digitally signed C:\windows\explorer.exe => File is digitally signed C:\windows\SysWOW64\explorer.exe => File is digitally signed C:\windows\system32\svchost.exe => File is digitally signed C:\windows\SysWOW64\svchost.exe => File is digitally signed C:\windows\system32\services.exe => File is digitally signed C:\windows\system32\User32.dll => File is digitally signed C:\windows\SysWOW64\User32.dll => File is digitally signed C:\windows\system32\userinit.exe => File is digitally signed C:\windows\SysWOW64\userinit.exe => File is digitally signed C:\windows\system32\rpcss.dll => File is digitally signed C:\windows\system32\dnsapi.dll => File is digitally signed C:\windows\SysWOW64\dnsapi.dll => File is digitally signed C:\windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2018-09-19 18:09 ==================== End of FRST.txt ============================