Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17.03.2019 Ran by [removed] (administrator) on WINDOWS8X64 (28-03-2019 00:34:40) Running from C:\Users\[removed]\Downloads [removed] Platform: Windows 8.1 Enterprise (X64) Language: English (United States) Default browser: Chrome Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Invincea, Inc. -> Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (Arcai.com) [File not signed] C:\Program Files (x86)\netcut\services\aips.exe (Intel(R) Software -> Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe (Intel(R) Software -> Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe () [File not signed] C:\Program Files\dbbmn10\bin\mysqld.exe (Nitro Software, Inc. -> Nitro Software, Inc.) C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe (Nitro Software, Inc. -> ) C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe (Nitro Software, Inc. -> Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Microsoft SQL Server\MSSQL\Binn\sqlagent.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Smadsoft) [File not signed] C:\Program Files (x86)\SMADAV\SMΔRTP.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel(R) Software -> Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\spool\drivers\x64\3\E_YATIUPE.EXE (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Zainuddin Nafarin -> Smadav Software) C:\Program Files (x86)\SMADAV\SmadavProtect64.exe (ESET, spol. s r.o. -> ESET spol. s r.o.) C:\Users\Personal\Downloads\esetonlinescanner_enu.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\Windows\system32\DptfPolicyLpmServiceHelper.exe [109312 2015-03-31] (Intel(R) Software -> Intel Corporation) HKLM-x32\...\Run: [SMΔRT-Protection] => C:\Program Files (x86)\Smadav\SMΔRTP.exe [1846384 2017-06-16] (Smadsoft) [File not signed] HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle America, Inc. -> Oracle Corporation) HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [3682968 2018-07-10] (Invincea, Inc. -> Sandboxie Holdings, LLC) HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\Run: [EPLTarget\P0000000000000003] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIN0E.EXE [298560 2014-03-20] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\Run: [EPLTarget\P0000000000000002] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIUPE.EXE [416896 2017-09-22] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\Policies\Explorer: [DisallowRun] 1 HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\Policies\Explorer\DisallowRun: [1] Mshta.exe HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\Policies\Explorer\DisallowRun: [2] powershell.exe HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\Policies\Explorer\DisallowRun: [3] bitsadmin.exe HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {006ce48b-b323-11e7-826b-f832e4d9686b} - "F:\Lenovo_Suite.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {04bd90b1-b1e6-11e8-82d5-f832e4d9686b} - "F:\Setup.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {0bfeca56-2c54-11e8-82b9-f832e4d9686b} - "F:\AutoRun.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {0ee791ea-978c-11e7-826a-f832e4d9686b} - "F:\Setup.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {14c19719-14ad-11e8-82b0-f832e4d9686b} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {2e16678e-c597-11e6-825d-f832e4d9686b} - "F:\Setup.exe" /s HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {3239ab32-4f22-11e8-82c3-e44f9c7eacfb} - "F:\Setup.exe" /s HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {3503351b-88db-11e7-826a-f832e4d9686b} - "F:\AutoRun.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {393497e1-ee0a-11e7-8297-b1997b972107} - "F:\Setup.exe" /s HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {41bf1132-2378-11e7-8266-f832e4d9686b} - "F:\AutoRun.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {41bf11f2-2378-11e7-8266-f832e4d9686b} - "F:\AutoRun.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {4944fec6-e802-11e7-8295-f832e4d9686b} - "F:\Setup.exe" /s HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {4cdc15e9-6a16-11e7-8267-f832e4d9686b} - "F:\Lenovo_Suite.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {58b527d9-596b-11e7-8266-f832e4d9686b} - "F:\Setup.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {5dfb6499-a6b8-11e7-826a-f832e4d9686b} - "F:\AutoRun.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {6b1b89a3-c8ae-11e7-8272-f832e4d9686b} - "F:\AutoRun.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {78fde44f-fc64-11e7-82a4-f832e4d9686b} - "F:\AutoRun.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {7a3a78d2-2dc7-11e9-830c-f832e4d9686b} - "F:\AutoRun.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {7a3a7939-2dc7-11e9-830c-f832e4d9686b} - "F:\AutoRun.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {8b574723-a19b-11e7-826a-f832e4d9686b} - "F:\Lenovo_Suite.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {b10e8f9b-2da9-11e7-8266-f832e4d9686b} - "F:\AutoRun.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {b10e90f5-2da9-11e7-8266-f832e4d9686b} - "F:\AutoRun.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {bda73b15-4b10-11e9-8316-f832e4d9686b} - "F:\Setup.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {c154c647-f214-11e7-829b-f832e4d9686b} - "F:\Setup.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {c1cc2a39-c5a0-11e7-8271-28c2ddcb34b5} - "F:\Setup.exe" /s HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {c1cc2b87-c5a0-11e7-8271-f832e4d9686b} - "F:\Setup.exe" /s HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {d6cbdd77-17ab-11e9-8304-f832e4d9686b} - "F:\Lenovo_Suite.exe" HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {e8b0ff8f-f482-11e7-829c-f832e4d9686b} - "F:\Setup.exe" /s HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {f002bb10-ca71-11e7-8273-f832e4d9686b} - "F:\Setup.exe" /s HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {f12226d3-18ee-11e7-8265-f832e4d9686b} - "F:\Setup.exe" /s HKU\S-1-5-21-2205616561-3770222130-115500733-1001\...\MountPoints2: {fb3806eb-275f-11e8-82b8-f832e4d9686b} - "F:\AutoRun.exe" HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\system32\lagarith.dll [148992 2011-12-08] ( ) [File not signed] HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\system32\x264vfw64.dll [3502080 2014-07-23] (x264vfw project) [File not signed] HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\system32\ac3acm.acm [180736 2012-07-21] (fccHandler) [File not signed] HKLM\...\Drivers32: [msacm.l3codecp] => C:\Windows\system32\l3codecp.acm [175616 2013-08-22] (Microsoft Windows -> Fraunhofer Institut Integrierte Schaltungen IIS) HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\SysWOW64\lagarith.dll [216064 2011-12-08] ( ) [File not signed] HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\SysWOW64\x264vfw.dll [3510784 2014-07-23] (x264vfw project) [File not signed] HKLM\...\Drivers32: [VIDC.FFDS] => C:\Windows\SysWOW64\ff_vfw.dll [112640 2014-11-15] () [File not signed] HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\SysWOW64\ac3acm.acm [122880 2012-07-21] (fccHandler) [File not signed] HKLM\...\Drivers32: [msacm.l3codecp] => C:\Windows\SysWOW64\l3codecp.acm [183808 2013-08-22] (Microsoft Windows -> Fraunhofer Institut Integrierte Schaltungen IIS) HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\73.0.3683.86\Installer\chrmstp.exe [2019-03-26] (Google LLC -> Google Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Service Manager.lnk [2017-04-05] ShortcutTarget: Service Manager.lnk -> C:\Program Files (x86)\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Microsoft Corporation) [File not signed] GroupPolicy: Restriction ? <==== ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.100.1 Tcpip\..\Interfaces\{6AA302F0-8680-40D5-9FB7-70EDFF734824}: [DhcpNameServer] 192.168.100.1 Tcpip\..\Interfaces\{A30F507B-BA2D-40E2-8D1E-3DDBE85FC97E}: [NameServer] 192.168.101.28 0.0.0.0 Internet Explorer: ================== HKU\S-1-5-21-2205616561-3770222130-115500733-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://id.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=bgy_nrssi_18_37_18¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Did%26pa%3Dwingy%26cd%3D2XzuyEtN2Y1L1Qzu0FzztAtB0EyE0DzyyCzzyC0BtA0EtB0CtN0D0Tzu0StByEyDtDtN1L2XzuyEtFtByCtFtDtFtCtAyDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyBtAtB0C0C0C0EtBtGyDzytBtDtG0D0CtCyBtGyDyByDyCtGtAyCtCyEtDyDtA0EtByEyC0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD1R1R1OtA1Q1OzztG1RyD1OtCtGyEzytDzytGzyyC1TtDtGzytByB1OtCtBtCtA1P1T1Pzz2QtN0A0LzutDtN1B2Z1V1T1S1NzutCzytBtAtDtN1Q2Z1B1P1RzutCyDtAyBtDzzzyzztCtD%26cr%3D223715752%26a%3Dbgy_nrssi_18_37_18%26os_ver%3D6.3%26os%3DWindows%2B8.1%2BEnterprise HKU\S-1-5-21-2205616561-3770222130-115500733-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/id-id/?ocid=iehp SearchScopes: HKU\S-1-5-21-2205616561-3770222130-115500733-1001 -> DefaultScope {518b33ae-375d-712d-6742-d1fe0400268d} URL = hxxps://id.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=bgy_nrssi_18_37_18¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Did%26pa%3Dwingy%26cd%3D2XzuyEtN2Y1L1Qzu0FzztAtB0EyE0DzyyCzzyC0BtA0EtB0CtN0D0Tzu0StByEyDtDtN1L2XzuyEtFtByCtFtDtFtCtAyDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyBtAtB0C0C0C0EtBtGyDzytBtDtG0D0CtCyBtGyDyByDyCtGtAyCtCyEtDyDtA0EtByEyC0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD1R1R1OtA1Q1OzztG1RyD1OtCtGyEzytDzytGzyyC1TtDtGzytByB1OtCtBtCtA1P1T1Pzz2QtN0A0LzutDtN1B2Z1V1T1S1NzutCzytBtAtDtN1Q2Z1B1P1RzutCyDtAyBtDzzzyzztCtD%26cr%3D223715752%26a%3Dbgy_nrssi_18_37_18%26os_ver%3D6.3%26os%3DWindows%2B8.1%2BEnterprise&p={searchTerms} SearchScopes: HKU\S-1-5-21-2205616561-3770222130-115500733-1001 -> {518b33ae-375d-712d-6742-d1fe0400268d} URL = hxxps://id.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=bgy_nrssi_18_37_18¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Did%26pa%3Dwingy%26cd%3D2XzuyEtN2Y1L1Qzu0FzztAtB0EyE0DzyyCzzyC0BtA0EtB0CtN0D0Tzu0StByEyDtDtN1L2XzuyEtFtByCtFtDtFtCtAyDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyBtAtB0C0C0C0EtBtGyDzytBtDtG0D0CtCyBtGyDyByDyCtGtAyCtCyEtDyDtA0EtByEyC0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD1R1R1OtA1Q1OzztG1RyD1OtCtGyEzytDzytGzyyC1TtDtGzytByB1OtCtBtCtA1P1T1Pzz2QtN0A0LzutDtN1B2Z1V1T1S1NzutCzytBtAtDtN1Q2Z1B1P1RzutCyDtAyBtDzzzyzztCtD%26cr%3D223715752%26a%3Dbgy_nrssi_18_37_18%26os_ver%3D6.3%26os%3DWindows%2B8.1%2BEnterprise&p={searchTerms} BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation -> Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\ssv.dll [2018-09-16] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\jp2ssv.dll [2018-09-16] (Oracle America, Inc. -> Oracle Corporation) Toolbar: HKU\S-1-5-21-2205616561-3770222130-115500733-1001 -> No Name - {C500C267-63BF-451F-8797-4D720C9A2ED9} - No File FireFox: ======== FF DefaultProfile: r2ewsoif.default FF ProfilePath: C:\Users\Personal\AppData\Roaming\Mozilla\Firefox\Profiles\r2ewsoif.default [2019-03-27] FF Homepage: Mozilla\Firefox\Profiles\r2ewsoif.default -> hxxp://hp.myway.com/easypdfcombine/ttab02/index.html?coId=undefined&subId=undefined&ln=en&n&ptb&st&p2&si FF Extension: (No Name) - C:\Users\Personal\AppData\Roaming\Mozilla\Firefox\Profiles\r2ewsoif.default\Extensions\[removed] [2019-03-27] [not signed] FF SearchPlugin: C:\Users\Personal\AppData\Roaming\Mozilla\Firefox\Profiles\r2ewsoif.default\searchplugins\yahoo! powered search.xml [2018-09-16] FF HKLM-x32\...\Thunderbird\Extensions: [[removed]] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_108.dll [2018-09-16] (Adobe Systems Incorporated -> ) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-08-10] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-08-10] (VideoLAN -> VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_108.dll [2018-09-16] (Adobe Systems Incorporated -> ) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-09-03] (Intel(R) Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-09-03] (Intel(R) Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2018-09-16] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-09-16] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-05-25] (Yahoo! Inc. -> Yahoo! Inc.) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 10\npnitromozilla.dll [2016-07-22] (Nitro Software, Inc. -> Nitro PDF) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-20] (Google Inc -> Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-20] (Google Inc -> Google Inc.) Chrome: ======= CHR DefaultProfile: Profile 2 CHR StartupUrls: Profile 2 -> "about:blank" CHR Profile: C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Guest Profile [2018-08-10] CHR Profile: C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2 [2019-03-28] CHR Extension: (Slides) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-16] CHR Extension: (Scatter) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ammjpmhgckkpcamddpolhchgomcojkle [2019-02-02] CHR Extension: (Docs) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-16] CHR Extension: (Google Drive) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-05-08] CHR Extension: (YouTube) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-05-08] CHR Extension: (Sheets) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-16] CHR Extension: (NasExtWallet) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gehjkhmhclgnkkhpfamakecfgakkfkco [2018-11-02] CHR Extension: (Google Docs Offline) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-24] CHR Extension: (BrowserStack Local) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mfiddfehmfdojjfdpfngagldgaaafcfo [2018-12-16] CHR Extension: (Search Manager) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce [2019-02-27] CHR Extension: (MetaMask) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nkbihfbeogaeaoehlefnkodbefgpgknn [2019-03-15] CHR Extension: (Chrome Web Store Payments) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04] CHR Extension: (Gmail) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-05-08] CHR Extension: (Chrome Media Router) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-03-28] CHR Profile: C:\Users\Personal\AppData\Local\Google\Chrome\User Data\System Profile [2018-08-10] CHR HKLM\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2017-10-06] CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-2205616561-3770222130-115500733-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-2205616561-3770222130-115500733-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AIPS; C:\Program Files (x86)\netcut\services\AIPS.exe [262144 2011-07-28] (Arcai.com) [File not signed] S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed] S4 camfrog_update_service; C:\Program Files (x86)\Camfrog\Camfrog Video Chat\update\cf_update_service.exe [1063968 2016-03-15] (Camshare Inc. -> Camshare Inc.) R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [115192 2015-03-31] (Intel(R) Software -> Intel Corporation) R2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [122624 2015-03-31] (Intel(R) Software -> Intel Corporation) R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [145224 2018-01-29] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [344168 2015-10-02] (Intel Corporation - pGFX -> Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887256 2014-05-13] (Intel® Trusted Connect Service -> Intel(R) Corporation) R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [21304 2017-09-28] (Microsoft Corporation -> Microsoft Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-09-03] (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) R2 MSSQLSERVER; C:\Program Files (x86)\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe [9150464 2005-05-04] (Microsoft Corporation) [File not signed] S3 MSSQLServerADHelper; C:\Program Files (x86)\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [73728 2005-05-03] (Microsoft Corporation) [File not signed] R2 mysqlbmn10; C:\Program Files\dbbmn10\bin\mysqld.exe [5730304 2007-07-07] () [File not signed] R2 NitroDriverReadSpool10; C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe [327320 2016-07-22] (Nitro Software, Inc. -> Nitro Software, Inc.) R2 NitroUpdateService; C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe [417944 2016-07-22] (Nitro Software, Inc. -> ) R2 nlsX86cc; C:\Windows\SysWOW64\NLSSRV32.EXE [71832 2016-07-22] (Nitro Software, Inc. -> Nalpeiron Ltd.) S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG -> Nero AG) S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [328344 2018-07-10] (Invincea, Inc. -> Sandboxie Holdings, LLC) R2 SQLSERVERAGENT; C:\Program Files (x86)\Microsoft SQL Server\MSSQL\binn\sqlagent.exe [323584 2005-05-03] (Microsoft Corporation) [File not signed] S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed] S3 Te.Service; C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe [187904 2017-09-28] (Microsoft Corporation) [File not signed] S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11644656 2018-08-13] (TeamViewer GmbH -> TeamViewer GmbH) S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [142440 2017-12-14] (Microsoft Corporation -> Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation -> Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation -> Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [13209088 2014-07-21] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) S3 amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [626688 2014-07-21] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices, Inc. -> Advanced Micro Devices) R3 athr; C:\Windows\system32\DRIVERS\athw8x.sys [3680256 2013-06-18] (Microsoft Windows -> Qualcomm Atheros Communications, Inc.) S3 ATP; C:\Windows\System32\drivers\AsusTP.sys [73512 2015-06-30] (ASUSTeK Computer Inc. -> ASUS Corporation) S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [116552 2015-03-31] (Intel(R) Software -> Intel Corporation) R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [490064 2015-03-31] (Intel(R) Software -> Intel Corporation) R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [43512 2015-06-26] (Intel(R) Software -> Intel Corporation) R3 dptf_pch; C:\Windows\System32\drivers\dptf_pch.sys [38208 2014-09-19] (Intel(R) Software -> Intel Corporation) S3 ewusbmbb; C:\Windows\system32\DRIVERS\ewusbwwan.sys [421376 2017-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.) S3 ew_hwusbdev; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [117248 2017-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.) R3 huawei_enumerator; C:\Windows\System32\drivers\ew_jubusenum.sys [86016 2017-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.) S3 hwdatacard; C:\Windows\system32\DRIVERS\ewusbmdm.sys [221312 2017-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.) R0 IntelHSWPcc; C:\Windows\System32\drivers\IntelPcc.sys [79528 2014-09-05] (Intel(R) Software -> Intel Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [126976 2014-09-03] (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.) S3 qcfilter; C:\Windows\System32\drivers\qcusbfilter.sys [49208 2017-03-15] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated) S3 qcusbser; C:\Windows\system32\DRIVERS\qcusbser.sys [397312 2014-05-23] (USBHostDriver(Test003) -> QUALCOMM Incorporated) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [228176 2018-07-10] (Invincea, Inc. -> Sandboxie Holdings, LLC) S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R3 tap0901; C:\Windows\system32\DRIVERS\tap0901.sys [40664 2013-08-22] (OpenVPN Technologies, Inc. -> The OpenVPN Project) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [35856 2014-03-24] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WDC_SAM; C:\Windows\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [257880 2014-03-24] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Windows -> Microsoft Corporation) R1 YSDrv; C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [310536 2018-05-12] (Beijing Duodian Online Science and Technology Co.,Ltd -> BigNox Corporation) U4 nxfs; no ImagePath U4 nxpcap; no ImagePath U4 nxsshd; no ImagePath U4 nxusbd; no ImagePath U4 nxusbh; no ImagePath U4 nxusbs; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-03-28 00:21 - 2019-03-28 00:22 - 002434048 _____ (Farbar) C:\Users\Personal\Downloads\FRST64 (1).exe 2019-03-28 00:08 - 2019-03-28 00:08 - 000000000 ____D C:\Users\Personal\AppData\Roaming\EPSON 2019-03-27 19:28 - 2019-03-27 19:30 - 007657592 _____ (ESET spol. s r.o.) C:\Users\Personal\Downloads\esetonlinescanner_enu.exe 2019-03-25 20:38 - 2019-03-25 20:38 - 000015411 _____ C:\Users\Personal\Downloads\FKTP BPKP 2019.xlsx 2019-03-24 10:51 - 2019-03-24 10:51 - 000000000 ____D C:\Users\Personal\Documents\inventaris 2017 2019-03-24 10:51 - 2019-03-24 10:51 - 000000000 ____D C:\Users\Personal\Documents\IBU LUDIAH 2019-03-24 10:50 - 2019-03-24 10:51 - 000000000 ____D C:\Users\Personal\Documents\IBU ANNE 2019-03-24 10:50 - 2019-03-24 10:50 - 000000000 ____D C:\Users\Personal\Documents\UKM akreditasi 2017 2019-03-24 10:50 - 2019-03-24 10:50 - 000000000 ____D C:\Users\Personal\Documents\surveior pra akreditasi 2019-03-24 10:50 - 2019-03-24 10:50 - 000000000 ____D C:\Users\Personal\Documents\SOP barang 2019-03-24 10:50 - 2019-03-24 10:50 - 000000000 ____D C:\Users\Personal\Documents\SK 2019-03-24 10:50 - 2019-03-24 10:50 - 000000000 ____D C:\Users\Personal\Documents\REVISI AKREDITASI 2017 2019-03-24 10:50 - 2019-03-24 10:50 - 000000000 ____D C:\Users\Personal\Documents\Kesling 2019-03-24 10:50 - 2019-03-24 10:50 - 000000000 ____D C:\Users\Personal\Documents\KA DRG 2019-03-24 10:50 - 2019-03-24 10:50 - 000000000 ____D C:\Users\Personal\Documents\inventaris baru 2017 2019-03-24 10:50 - 2018-03-08 16:55 - 000014311 _____ C:\Users\Personal\Documents\BA obat 1 - Copy.xlsx 2019-03-24 10:50 - 2018-03-07 09:00 - 000009886 _____ C:\Users\Personal\Documents\Obat pustu horas.xlsx 2019-03-24 10:50 - 2018-03-06 09:33 - 000168765 _____ C:\Users\Personal\Documents\FORMAT KESWA TERBARU.xlsx 2019-03-24 10:50 - 2018-02-13 15:35 - 000010818 _____ C:\Users\Personal\Documents\Pemakai kendaraan dinas Roda dua.xlsx 2019-03-24 10:50 - 2018-02-07 12:41 - 000013467 _____ C:\Users\Personal\Documents\KS Raya.xlsx 2019-03-24 10:50 - 2017-11-28 08:30 - 000000000 ____D C:\Users\Personal\Documents\Skypee 2019-03-24 10:50 - 2017-11-22 09:42 - 000011561 _____ C:\Users\Personal\Documents\identifikasi peran lintas sektor.xlsx 2019-03-24 10:50 - 2017-11-20 16:16 - 000014732 _____ C:\Users\Personal\Documents\Hasil analisis iden. Umpan balik.xlsx 2019-03-24 10:50 - 2017-11-20 14:06 - 000013897 _____ C:\Users\Personal\Documents\hasil umpan balik.xlsx 2019-03-24 10:50 - 2017-11-18 17:00 - 000025320 _____ C:\Users\Personal\Documents\ANJAB KAPUS- Copy.xlsx 2019-03-24 10:50 - 2017-10-18 18:32 - 000023634 _____ C:\Users\Personal\Documents\RTL UKM 2017.xlsx 2019-03-24 10:50 - 2017-10-16 11:34 - 000016872 _____ C:\Users\Personal\Documents\tabel kesehatan gigi balita.xlsx 2019-03-24 10:50 - 2017-09-25 13:25 - 000010920 _____ C:\Users\Personal\Documents\Copy of Form Rekap Pasung.xlsx 2019-03-24 10:50 - 2017-09-12 22:48 - 000011940 _____ C:\Users\Personal\Documents\IDENTIFIKASI DAN ANALISIS RESIKO.xlsx 2019-03-22 15:25 - 2019-03-22 15:26 - 000329855 _____ C:\Users\Personal\Downloads\1 (1).pdf 2019-03-22 14:52 - 2019-03-22 14:52 - 000993800 _____ C:\Users\Personal\Downloads\1-converted.pdf 2019-03-22 14:52 - 2019-03-22 14:52 - 000000864 _____ C:\Users\Personal\Downloads\Music - Shortcut.lnk 2019-03-22 14:50 - 2019-03-22 14:50 - 001050029 _____ C:\Users\Personal\Downloads\1.pdf 2019-03-22 10:06 - 2019-03-22 10:06 - 000039200 _____ C:\Users\Personal\Downloads\Peraturan-Pemerintah-tahun-2002-027-02 (1).pdf 2019-03-22 09:56 - 2019-03-22 09:56 - 000039200 _____ C:\Users\Personal\Downloads\Peraturan-Pemerintah-tahun-2002-027-02.pdf 2019-03-20 21:12 - 2019-03-20 21:12 - 000074663 _____ C:\Users\Personal\Downloads\1272052511980001_kartu_akun.pdf 2019-03-20 13:59 - 2019-03-20 14:05 - 000025240 _____ C:\Users\Personal\Documents\jasa Desember 2018.xlsx 2019-03-16 10:14 - 2019-03-16 10:14 - 002496125 _____ C:\Users\Personal\Downloads\5ab_6192939182625652847.pdf 2019-03-16 10:12 - 2019-03-16 10:12 - 002611625 _____ C:\Users\Personal\Downloads\5a_6192939182625652847.pdf 2019-03-16 10:09 - 2019-03-16 10:09 - 000001315 _____ C:\Users\Public\Desktop\SlimPDF Reader.lnk 2019-03-16 10:09 - 2019-03-16 10:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimPDF Reader 2019-03-16 10:09 - 2019-03-16 10:09 - 000000000 ____D C:\Program Files (x86)\Investintech.com Inc 2019-03-16 10:07 - 2019-03-16 10:08 - 001502120 _____ (Investintech.com Inc. ) C:\Users\Personal\Downloads\InstallSlimPDFReader.exe 2019-03-16 09:46 - 2019-03-16 09:46 - 001599578 _____ C:\Users\Personal\Downloads\Nitro_Pro_Enterprise_10_5_9.rar 2019-03-16 09:39 - 2019-03-16 09:39 - 000084994 _____ C:\Users\Personal\Downloads\Keymaker-CORE.rar 2019-03-16 09:32 - 2019-03-16 09:33 - 027600391 _____ C:\Users\Personal\Downloads\5_6192939182625652847.pdf 2019-03-16 09:21 - 2019-03-16 09:21 - 001021814 _____ C:\Users\Personal\Documents\5_6300544412791341146(2).pdf 2019-03-16 09:18 - 2019-03-16 09:18 - 005408730 _____ C:\Users\Personal\Downloads\5_6300544412791341146(2).pdf 2019-03-15 10:36 - 2019-03-18 12:17 - 000094753 _____ C:\Users\Personal\Documents\Form Self Assesment Peer Review 2019.xlsx 2019-03-15 10:03 - 2019-03-15 10:03 - 005408730 _____ C:\Users\Personal\Downloads\5_6300544412791341146(1).pdf 2019-03-15 09:45 - 2019-03-15 09:45 - 005408730 _____ C:\Users\Personal\Downloads\5_6300544412791341146.pdf 2019-03-15 09:16 - 2019-03-15 09:16 - 001509247 _____ C:\Users\Personal\Downloads\5_6300544412791341145(1).pdf 2019-03-15 09:14 - 2019-03-15 09:14 - 001509247 _____ C:\Users\Personal\Downloads\5_6300544412791341145.pdf 2019-03-09 18:19 - 2019-03-09 18:19 - 000121295 _____ C:\Users\Personal\Downloads\kuesioner_survei (4).pdf 2019-02-28 12:13 - 2019-02-28 12:13 - 000000946 _____ C:\Users\Personal\Desktop\BMD 2018 Unaudited.lnk 2019-02-28 11:35 - 2019-03-20 20:05 - 000000000 ____D C:\temp 2019-02-28 11:34 - 2019-02-28 11:34 - 000000585 _____ C:\Users\Personal\Desktop\psedia15.exe - Shortcut.lnk 2019-02-28 11:34 - 2019-02-28 11:34 - 000000190 _____ C:\Windows\ODBCINST.INI 2019-02-26 12:43 - 2019-03-27 19:43 - 000000943 _____ C:\Windows\Tasks\EPSON L360 Series Update {B0E1B48D-61C0-463A-8B55-4F6E4E69B93E}.job 2019-02-26 12:43 - 2019-02-26 12:43 - 000003974 _____ C:\Windows\System32\Tasks\EPSON L360 Series Update {B0E1B48D-61C0-463A-8B55-4F6E4E69B93E} 2019-02-26 12:07 - 2019-02-26 12:07 - 003540910 _____ C:\Users\Personal\Downloads\Kota ehat 1.pdf 2019-02-26 12:02 - 2019-02-26 12:03 - 000281962 _____ C:\Users\Personal\Downloads\Dok baru 2019-02-26 10.45.16.pdf ==================== One month (modified) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-03-28 00:37 - 2018-12-07 13:37 - 000000943 _____ C:\Windows\Tasks\EPSON L360 Series Update {313381FA-41B8-4ADA-A30C-FAEAE9B938E8}.job 2019-03-28 00:37 - 2018-09-15 14:53 - 000031519 _____ C:\Users\Personal\Downloads\FRST.txt 2019-03-28 00:34 - 2018-09-15 14:56 - 000058289 _____ C:\Users\Personal\Downloads\Addition.txt 2019-03-28 00:34 - 2018-08-11 20:30 - 000000000 ____D C:\FRST 2019-03-28 00:30 - 2015-05-02 01:36 - 000003950 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{430A11C4-6745-4BAC-8E8F-9C2DDC8746AE} 2019-03-28 00:27 - 2018-12-13 10:27 - 000000943 _____ C:\Windows\Tasks\EPSON L3110 Series Update {2E2656F3-76E3-4F00-A7E3-FBC95CF3E168}.job 2019-03-28 00:13 - 2015-05-02 00:30 - 000003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2205616561-3770222130-115500733-1001 2019-03-28 00:07 - 2016-09-05 10:26 - 000000000 __SHD C:\Users\Personal\IntelGraphicsProfiles 2019-03-27 21:29 - 2017-04-04 11:36 - 000000000 ____D C:\Users\Personal\Downloads\patch 2019-03-27 20:22 - 2018-11-20 16:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\arcai.com 2019-03-27 20:22 - 2018-11-20 16:03 - 000000000 ____D C:\Program Files (x86)\netcut 2019-03-27 20:10 - 2017-04-04 11:39 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager 2019-03-27 20:02 - 2018-12-13 12:02 - 000000943 _____ C:\Windows\Tasks\EPSON L3110 Series Update {B28D2220-919F-4BB0-BD8E-C71621D33D0A}.job 2019-03-27 19:30 - 2016-09-06 21:14 - 000000000 ____D C:\Users\Personal\AppData\Local\ESET 2019-03-26 23:37 - 2016-03-17 16:35 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Nitro 2019-03-26 23:18 - 2017-10-18 20:42 - 000000000 ____D C:\Users\Personal\Documents\foto ukm part 2 2019-03-26 23:09 - 2017-04-04 13:04 - 000000000 ____D C:\Users\Personal\Downloads\Telegram Desktop 2019-03-26 22:51 - 2017-04-04 12:51 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Telegram Desktop 2019-03-26 20:56 - 2014-03-18 17:16 - 000011642 _____ C:\Windows\system32\PerfStringBackup.INI 2019-03-26 20:56 - 2013-08-22 20:36 - 000000000 ____D C:\Windows\Inf 2019-03-26 20:46 - 2016-03-17 16:29 - 000002215 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2019-03-26 20:46 - 2016-03-17 16:29 - 000002174 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2019-03-26 20:33 - 2018-01-14 22:44 - 000001063 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk 2019-03-26 20:33 - 2016-03-17 16:30 - 000003852 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1458207001 2019-03-26 20:33 - 2016-03-17 16:29 - 000000000 ____D C:\Program Files (x86)\Opera 2019-03-25 20:25 - 2018-08-16 12:20 - 000000000 ____D C:\Users\Personal\AppData\Local\CrashDumps 2019-03-24 10:51 - 2017-10-20 14:14 - 000000000 ____D C:\Users\Personal\Documents\IBU MEGA 2019-03-24 10:50 - 2017-08-24 14:21 - 000000000 ____D C:\Users\Personal\Documents\SOP UKM 2019-03-22 20:16 - 2018-07-04 20:32 - 000000000 ___RD C:\Users\Personal\Documents\Scanned Documents 2019-03-20 20:05 - 2013-08-22 21:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2019-03-18 11:40 - 2018-09-17 23:39 - 000004128 _____ C:\Windows\System32\Tasks\CCleaner Update 2019-03-16 10:14 - 2018-11-11 22:37 - 000000000 ____D C:\Users\Personal\AppData\Local\NitroSpoolDir 2019-03-16 00:54 - 2018-11-14 19:56 - 000007600 _____ C:\Users\Personal\AppData\Local\resmon.resmoncfg 2019-03-12 11:16 - 2015-05-02 00:24 - 000000000 ____D C:\Users\Personal 2019-02-27 20:03 - 2019-01-24 11:25 - 000020407 _____ C:\Users\Personal\Documents\Laporan barang atk.xlsx ==================== Files in the root of some directories ======= 2019-02-11 02:04 - 2019-02-11 02:04 - 000001189 _____ () C:\Users\Personal\AppData\Roaming\D3D5D3C0-0F3D-40c1-9973-CEB7C072AE32.ini 2018-11-14 19:56 - 2019-03-16 00:54 - 000007600 _____ () C:\Users\Personal\AppData\Local\resmon.resmoncfg Some files in TEMP: ==================== 2018-08-11 18:39 - 2014-03-18 17:28 - 001727760 _____ (Microsoft Corporation) C:\Users\Personal\AppData\Local\Temp\dllnt_dump.dll 2018-11-20 16:00 - 2008-10-01 12:40 - 000453720 _____ (Macrovision Corporation) C:\Users\Personal\AppData\Local\Temp\_is740.exe 2018-12-13 09:31 - 2006-05-25 00:10 - 000455600 ____R (Macrovision Corporation) C:\Users\Personal\AppData\Local\Temp\_isAF96.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\dllhost.exe => File is digitally signed C:\Windows\SysWOW64\dllhost.exe => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed