Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-12-2019 Ran by [removed] (administrator) on DESKTOP-813561A (Dell Inc. Inspiron 15-3567) (04-01-2020 09:24:05) Running from C:\Users\[removed]\Downloads [removed] Platform: Windows 10 Home Version 1703 15063.1387 (X64) Language: English (United States) Default browser: Opera Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) () [File not signed] C:\ProgramData\Abelssoft\AntiRansomware\Program\AntiRansomware.exe (BitTorrent Inc -> BitTorrent Inc.) C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent Web\utweb.exe (BitTorrent Inc -> BitTorrent Inc.) C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent\helper\helper.exe (BitTorrent Inc -> BitTorrent Inc.) C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent\updates\3.5.5_45503\utorrentie.exe (BitTorrent Inc -> BitTorrent Inc.) C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent\updates\3.5.5_45503\utorrentie.exe (BitTorrent Inc -> BitTorrent Inc.) C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent\uTorrent.exe (Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe (Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe (Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe (Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe (Dell Inc -> Dell Inc.) C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe (Dell Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe (Dell Inc.) [File not signed] C:\Program Files\Dell\QuickSet\quickset.exe (EnigmaSoft Limited -> EnigmaSoft Limited) C:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exe (EnigmaSoft Limited -> EnigmaSoft Limited) C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe (EnigmaSoft Limited -> EnigmaSoft Limited) C:\Program Files\EnigmaSoft\SpyHunter\SpyHunter5.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler64.exe (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe (Intel(R) Corporation -> Intel Corporation) C:\Program Files\Intel\IntelSGXPSW\bin\x64\Release\aesm_service.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\igfxCUIService.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\igfxEM.exe (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFCore.exe (IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 20.0\avp.exe (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 20.0\avpui.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files (x86)\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Windows -> Microsoft Corporation) C:\Program Files\rempl\sedlauncher.exe (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe (Opera Software AS -> Opera Software) C:\Program Files\Opera\assistant\browser_assistant.exe (Opera Software AS -> Opera Software) C:\Program Files\Opera\assistant\browser_assistant.exe (PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\DSAPI.exe (Qualcomm Atheros -> Qualcomm Technologies Inc.) C:\Windows\System32\drivers\QcomWlanSrvx64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Rivet Networks LLC -> CloudBees, Inc.) C:\Program Files\Rivet Networks\SmartByte\RNDBWMService.exe (Rivet Networks LLC -> DELL) C:\Program Files\Rivet Networks\SmartByte\SmartByteTelemetry.exe (Rivet Networks LLC -> Rivet Networks LLC) C:\Program Files\Rivet Networks\SmartByte\RNDBWM.exe (Rivet Networks LLC -> Rivet Networks) C:\Program Files\Rivet Networks\SmartByte\SmartByteNetworkService.exe (Rosetta Stone Ltd -> Rosetta Stone Ltd.) C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe (Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.1000_x64__kzf8qxf38zg5c\SkypeHost.exe (SurfRight B.V. -> SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-19] (Microsoft Windows -> Microsoft Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9269352 2019-09-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506384 2019-09-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [320568 2016-09-20] (Intel(R) Rapid Storage Technology -> Intel Corporation) HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [3910656 2017-05-04] (Dell Inc.) [File not signed] HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [1220416 2018-03-06] (Waves Inc -> Waves Audio Ltd.) HKLM-x32\...\Run: [Opera Browser Assistant] => C:\Program Files\Opera\assistant\browser_assistant.exe [2774040 2019-12-19] (Opera Software AS -> Opera Software) HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5276944 2019-11-27] (IObit Information Technology -> IObit) HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Run: [utweb] => C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent Web\utweb.exe [5216440 2018-04-24] (BitTorrent Inc -> BitTorrent Inc.) HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Run: [GoogleChromeAutoLaunch_6BCEFFED5377C18D30C2056EF5045257] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Run: [uTorrent] => C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent\uTorrent.exe [2088680 2020-01-02] (BitTorrent Inc -> BitTorrent Inc.) HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1 HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Policies\Explorer: [DisallowRun] 1 HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Policies\Explorer\DisallowRun: [1] Mshta.exe HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Policies\Explorer\DisallowRun: [2] powershell.exe HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Policies\Explorer\DisallowRun: [3] bitsadmin.exe HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\MountPoints2: {f58070ba-1f81-11e8-af19-e89eb444c350} - "E:\.\StartModem.exe" HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.88\Installer\chrmstp.exe [2020-01-03] (Google LLC -> Google LLC) BootExecute: autocheck autochk * bootdelete FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {191D314E-BD96-4234-9F58-69DF34A04873} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [1642672 2012-10-01] (Microsoft Corporation -> Microsoft Corporation) Task: {1A7A1124-9653-4A38-82C1-9D25566B66B1} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation) Task: {2FC2EE25-2377-41D1-88F6-F581AC68A9C8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-03-04] (Google Inc -> Google Inc.) Task: {4CB5FB8B-12CA-4F51-A0DB-6247A72F1AC2} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation) Task: {5A6A5BD1-2F35-4458-9E58-A795060719AE} - System32\Tasks\SmartByte Telemetry => C:\Program Files\Rivet Networks\SmartByte\SmartByteTelemetry.exe [32448 2018-12-04] (Rivet Networks LLC -> DELL) Task: {5DB11C3C-54B7-403D-85DE-004E8A337E03} - System32\Tasks\AMHelper => C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe [659520 2019-11-04] (Zemana D.O.O. Sarajevo -> Zemana Ltd.) Task: {6C7739AD-F12B-4628-99B3-63C79FC80EF3} - System32\Tasks\Abelssoft\AntiRansomware => C:\Program Files (x86)\AntiRansomware\AbLauncher.exe [18312 2019-12-10] (Ascora GmbH -> ) Task: {738FBFF5-2B65-424D-AA54-D19DFF231B9B} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [791232 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) Task: {75758A59-CCF9-40BE-9265-155778996344} - System32\Tasks\Opera scheduled Autoupdate 1525338304 => C:\Program Files\Opera\launcher.exe [1528344 2019-12-19] (Opera Software AS -> Opera Software) Task: {77F84055-57D4-492E-8447-DBF62D36ACDD} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [909112 2016-07-27] (Intel(R) Trusted Connect Service -> Intel(R) Corporation) Task: {82646C8A-0338-4CA0-AF55-8AA820C08388} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [726488 2019-09-10] (Dell Inc. -> Dell Inc.) Task: {8F248A92-559A-4BBA-966F-4978CFA1320E} - System32\Tasks\IMF_SkipUAC_Kafi&Kafi => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5276944 2019-11-27] (IObit Information Technology -> IObit) Task: {980D64A7-DCBF-420E-B3BC-3F27F571C4EB} - System32\Tasks\Opera scheduled assistant Autoupdate 1548868564 => C:\Program Files\Opera\launcher.exe [1528344 2019-12-19] (Opera Software AS -> Opera Software) Task: {BC319665-F0C8-44A3-B0D9-E124B2C47EE5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-03-04] (Google Inc -> Google Inc.) Task: {FF0F119A-BA25-47AD-843F-776FE503F14D} - System32\Tasks\Reg Organizer Applications Updates Check => C:\Program Files (x86)\Reg Organizer\RegOrganizer.exe -SilentUpdatesCheck (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{14aee701-a839-4709-b600-ffab162621c1}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{cd6ef802-6821-4ba0-9383-09fdfa037b4c}: [NameServer] 188.135.0.23 Tcpip\..\Interfaces\{d97eea9b-ccad-4230-b29e-da0296760329}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1786950783-2709316424-3276483186-1001 -> DefaultScope {3C8E8372-E18E-4348-BA21-C30536C6CED3} URL = BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) BHO: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - No File FireFox: ======== FF HKLM\...\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 20.0\FFExt\light_plugin_firefox\addon.xpi FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 20.0\FFExt\light_plugin_firefox\addon.xpi [2020-01-03] FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 20.0\FFExt\light_plugin_firefox\addon.xpi FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2020-01-02] (Google LLC -> Google LLC) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2020-01-02] (Google LLC -> Google LLC) Chrome: ======= CHR NewTab: Default -> Not-active:"chrome-extension://picpadgnaiehfpanhlnlejeelgohjpid/ntp1.html", Not-active:"chrome-extension://odcommfbpjnempjflnjmgmnfpgcadboo/ntp1.html" CHR Notifications: Default -> hxxps://web.whatsapp.com; hxxps://www.hindilinks4u.to CHR Profile: C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default [2020-01-04] CHR Extension: (Slides) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-03-04] CHR Extension: (Docs) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-03-04] CHR Extension: (Google Drive) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-03-04] CHR Extension: (YouTube) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-03-04] CHR Extension: (Kaspersky Protection) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\elhpdacimkjpccooodognopfhbdgnpbk [2020-01-03] CHR Extension: (Sheets) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-03-04] CHR Extension: (Google Docs Offline) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-09-17] CHR Extension: (Notifier for WhatsApp Web) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kaoholkoedbpjiangnchpfchhmageifp [2019-09-09] CHR Extension: (Google Hangouts) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2019-06-05] CHR Extension: (Chrome Web Store Payments) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-01-02] CHR Extension: (Gmail) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-05-13] CHR Extension: (Chrome Media Router) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-01-04] CHR HKLM\...\Chrome\Extension: [elhpdacimkjpccooodognopfhbdgnpbk] - hxxps://chrome.google.com/webstore/detail/elhpdacimkjpccooodognopfhbdgnpbk CHR HKLM-x32\...\Chrome\Extension: [elhpdacimkjpccooodognopfhbdgnpbk] - hxxps://chrome.google.com/webstore/detail/elhpdacimkjpccooodognopfhbdgnpbk CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AESMService; c:\Program Files\Intel\IntelSGXPSW\bin\x64\Release\aesm_service.exe [3723400 2016-04-14] (Intel(R) Corporation -> Intel Corporation) R2 AtherosSvc; C:\Windows\system32\DRIVERS\AdminService.exe [414696 2019-09-09] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) R2 AVP20.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 20.0\avp.exe [357416 2019-03-21] (Kaspersky Lab -> AO Kaspersky Lab) R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [209448 2019-05-21] (Dell Inc -> Dell Inc.) R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3373600 2019-05-21] (Dell Inc -> Dell Inc.) R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [218144 2019-05-21] (Dell Inc -> Dell Inc.) R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\DSAPI.exe [1050952 2019-09-22] (PC-Doctor, Inc. -> PC-Doctor, Inc.) R2 Dell SupportAssist Remediation; C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe [293528 2018-10-20] (Dell Inc -> Dell Inc.) R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [35976 2019-04-03] (Dell Inc -> ) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [802432 2018-11-15] (EasyAntiCheat Oy -> EasyAntiCheat Ltd) R2 EsgShKernel; C:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exe [11780320 2020-01-04] (EnigmaSoft Limited -> EnigmaSoft Limited) R2 esifsvc; C:\Windows\System32\Intel\DPTF\esif_uf.exe [1855976 2019-09-09] (Intel Corporation -> Intel Corporation) R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [162392 2020-01-04] (SurfRight B.V. -> SurfRight B.V.) R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2377488 2019-11-20] (IObit Information Technology -> IObit) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [987432 2016-07-27] (Intel(R) Trusted Connect Service -> Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [177440 2016-08-30] (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) S3 klvssbridge64_20.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 20.0\x64\vssbridge64.exe [438928 2019-03-21] (Kaspersky Lab -> AO Kaspersky Lab) R2 MBAMService; C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbamservice.exe [6960640 2020-01-04] (Malwarebytes Inc -> Malwarebytes) R2 QcomWlanSrv; C:\Windows\System32\drivers\QcomWlanSrvx64.exe [227728 2019-09-09] (Qualcomm Atheros -> Qualcomm Technologies Inc.) R2 RNDBWM; C:\Program Files\Rivet Networks\SmartByte\RNDBWMService.exe [64184 2018-12-04] (Rivet Networks LLC -> CloudBees, Inc.) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [268368 2019-09-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor) R2 ShMonitor; C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe [519904 2020-01-04] (EnigmaSoft Limited -> EnigmaSoft Limited) S3 ShutdownService; C:\ProgramData\Abelssoft\AntiRansomware\Program\ShutdownService.exe [13192 2019-12-10] (Ascora GmbH -> ) R2 SmartByte Network Service x64; C:\Program Files\Rivet Networks\SmartByte\SmartByteNetworkService.exe [2114248 2018-12-04] (Rivet Networks LLC -> Rivet Networks) R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [48600 2019-09-10] (Dell Inc. -> Dell Inc.) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [265640 2018-09-26] (Synaptics Incorporated -> Synaptics Incorporated) S3 uSHAREitSvc; C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.Service.exe [33224 2017-09-11] (SHAREit Technologies Co.Ltd -> SHAREit Technologies Co.Ltd) R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [882496 2018-03-06] (Waves Inc -> Waves Audio Ltd.) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\NisSrv.exe [3630832 2019-09-20] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\MsMpEng.exe [103168 2019-09-20] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 amsdk; C:\Windows\system32\drivers\amsdk.sys [232792 2020-01-03] (Zemana D.O.O. Sarajevo -> Copyright 2018.) R2 aow_drv; C:\Program Files\TxGameAssistant\UI\2.0.7373.123\aow_drv_x64_ev.sys [859456 2018-12-22] (Tencent Technology(Shenzhen) Company Limited -> Tencent) R3 BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [65952 2019-09-09] (WDKTestCert aswbldsv,131431045756648395 -> Qualcomm) R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [246912 2019-02-16] (Kaspersky Lab -> AO Kaspersky Lab) R3 DDDriver; C:\Windows\system32\drivers\DDDriver64Dcsa.sys [36728 2019-05-21] (Microsoft Windows Hardware Compatibility Publisher -> Dell Inc.) S3 DellProf; C:\Windows\system32\drivers\DellProf.sys [41208 2018-02-10] (Techporch Incorporated -> Dell Computer Corporation) R2 DpmLiteDrv; c:\Program Files\Dell\QuickSet\DpmLiteDrv64.sys [15080 2014-10-16] (Wistron Corporation -> Wistron Corp.) R3 dptf_acpi; C:\Windows\System32\drivers\dptf_acpi.sys [78680 2019-09-09] (Intel Corporation -> Intel Corporation) R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [71000 2019-09-09] (Intel Corporation -> Intel Corporation) R3 EnigmaFileMonDriver; C:\Windows\System32\drivers\EnigmaFileMonDriver.sys [68424 2020-01-04] (EnigmaSoft Limited -> EnigmaSoft Limited) R3 esif_lf; C:\Windows\system32\DRIVERS\esif_lf.sys [402264 2019-09-09] (Intel Corporation -> Intel Corporation) R3 HidEventFilter; C:\Windows\System32\drivers\HidEventFilter.sys [84008 2019-09-09] (Intel(R) Software -> Intel Corporation) R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2018-03-10] (Martin Malik - REALiX -> REALiX(tm)) R3 iaLPSS2_GPIO2; C:\Windows\System32\drivers\iaLPSS2_GPIO2.sys [98760 2019-09-09] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) R0 iaStorAC; C:\Windows\System32\drivers\iaStorAC.sys [909152 2019-09-14] (Intel Corporation -> Intel Corporation) R3 IMFDownProtect; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win10_amd64\IMFDownProtect.sys [40016 2018-12-06] (IObit Information Technology -> IObit) R3 IMFForceDelete; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win10_amd64\IMFForceDelete.sys [34192 2019-06-11] (IObit Information Technology -> IObit) R3 ImfObCallback; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win10_amd64\ImfObCallback.sys [37328 2018-12-06] (IObit Information Technology -> IObit) R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [76624 2019-03-19] (Kaspersky Lab -> AO Kaspersky Lab) R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [129152 2019-08-02] (Kaspersky Lab -> AO Kaspersky Lab) R1 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [93312 2019-03-12] (Kaspersky Lab -> AO Kaspersky Lab) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [37816 2019-01-24] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab) R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [251512 2020-01-04] (Kaspersky Lab -> AO Kaspersky Lab) R1 klgse; C:\Windows\System32\DRIVERS\klgse.sys [516216 2019-09-17] (Kaspersky Lab -> AO Kaspersky Lab) R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [1123664 2019-10-17] (Kaspersky Lab -> AO Kaspersky Lab) R3 klids; C:\ProgramData\Kaspersky Lab\AVP20.0\Bases\klids.sys [201280 2020-01-04] (Kaspersky Lab -> AO Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [998016 2020-01-04] (Kaspersky Lab -> AO Kaspersky Lab) R1 klim6; C:\Windows\system32\DRIVERS\klim6.sys [58192 2019-03-19] (Kaspersky Lab -> AO Kaspersky Lab) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [79184 2019-03-18] (Kaspersky Lab -> AO Kaspersky Lab) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [59512 2019-03-18] (Kaspersky Lab -> AO Kaspersky Lab) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [51328 2019-03-13] (Kaspersky Lab -> AO Kaspersky Lab) S3 klpnpflt; C:\Windows\system32\DRIVERS\klpnpflt.sys [45904 2019-03-10] (Kaspersky Lab -> AO Kaspersky Lab) R0 klupd_klif_arkmon; C:\Windows\System32\Drivers\klupd_klif_arkmon.sys [251256 2020-01-04] (Kaspersky Lab -> AO Kaspersky Lab) R3 klupd_klif_kimul; C:\Windows\System32\Drivers\klupd_klif_kimul.sys [99152 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) R3 klupd_klif_klark; C:\Windows\System32\Drivers\klupd_klif_klark.sys [306248 2020-01-04] (Kaspersky Lab -> AO Kaspersky Lab) R0 klupd_klif_klbg; C:\Windows\System32\Drivers\klupd_klif_klbg.sys [119744 2020-01-04] (Kaspersky Lab -> AO Kaspersky Lab) R3 klupd_klif_mark; C:\Windows\System32\Drivers\klupd_klif_mark.sys [204520 2020-01-04] (Kaspersky Lab -> AO Kaspersky Lab) S4 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [105600 2019-03-05] (Kaspersky Lab -> AO Kaspersky Lab) R1 klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [210280 2019-03-13] (Kaspersky Lab -> AO Kaspersky Lab) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [232272 2019-03-19] (Kaspersky Lab -> AO Kaspersky Lab) R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [216544 2020-01-04] (Malwarebytes Inc -> Malwarebytes) S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [20936 2020-01-04] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [278344 2020-01-04] (Malwarebytes Inc -> Malwarebytes) S3 mtkmbim; C:\Windows\System32\drivers\mtkmbim7_x64.sys [209920 2016-07-29] (Microsoft Windows Hardware Compatibility Publisher -> MBB) R3 Qcamain10x64; C:\Windows\System32\drivers\Qcamain10x64.sys [2335632 2019-09-09] (Qualcomm Atheros -> Qualcomm Atheros, Inc.) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [1158944 2019-09-14] (Realtek Semiconductor Corp. -> Realtek ) R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [450152 2019-09-09] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation) S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [31128 2017-03-19] (Microsoft Windows -> ) R3 SmbCoSvc; C:\Windows\system32\DRIVERS\SmbCo10X64.sys [120008 2018-12-04] (Rivet Networks LLC -> Rivet Networks, LLC.) R3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [56840 2019-09-09] (Synaptics Incorporated -> Synaptics Incorporated) R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [65960 2018-09-26] (Synaptics Incorporated -> Synaptics Incorporated) S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [46472 2019-09-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [346336 2019-09-20] (Microsoft Windows -> Microsoft Corporation) S3 wdf_usb; C:\Windows\system32\DRIVERS\usb2ser.sys [82944 2016-07-29] (Microsoft Windows Hardware Compatibility Publisher -> MBB) S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [53984 2019-09-20] (Microsoft Windows -> Microsoft Corporation) U1 aswbdisk; no ImagePath U0 aswblog; no ImagePath S3 cpuz145; \??\C:\Windows\temp\cpuz145\cpuz145_x64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) =================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-01-04 09:24 - 2020-01-04 09:26 - 000033343 _____ C:\Users\Kafi&Kafi\Downloads\FRST.txt 2020-01-04 09:23 - 2020-01-04 09:25 - 000000000 ____D C:\FRST 2020-01-04 09:21 - 2020-01-04 09:21 - 002272256 _____ (Farbar) C:\Users\Kafi&Kafi\Downloads\FRST64.exe 2020-01-04 09:05 - 2020-01-04 09:05 - 000278344 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2020-01-04 09:05 - 2020-01-04 09:05 - 000216544 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys 2020-01-04 09:03 - 2020-01-04 09:27 - 000093809 _____ C:\Windows\ZAM.krnl.trace 2020-01-04 07:59 - 2020-01-04 09:05 - 000068424 _____ (EnigmaSoft Limited) C:\Windows\system32\Drivers\EnigmaFileMonDriver.sys 2020-01-04 07:59 - 2020-01-04 07:59 - 000001061 _____ C:\Users\Public\Desktop\SpyHunter5.lnk 2020-01-04 07:59 - 2020-01-04 07:59 - 000001061 _____ C:\ProgramData\Desktop\SpyHunter5.lnk 2020-01-04 07:59 - 2020-01-04 07:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EnigmaSoft 2020-01-04 07:59 - 2020-01-04 07:59 - 000000000 ____D C:\ProgramData\EnigmaSoft Limited 2020-01-04 07:58 - 2020-01-04 07:59 - 000000000 ____D C:\sh5ldr 2020-01-04 07:48 - 2020-01-04 07:48 - 000001085 _____ C:\Users\Public\Desktop\Trojan Killer.lnk 2020-01-04 07:48 - 2020-01-04 07:48 - 000001085 _____ C:\ProgramData\Desktop\Trojan Killer.lnk 2020-01-04 07:48 - 2020-01-04 07:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GridinSoft Trojan Killer 2020-01-04 07:46 - 2020-01-04 07:46 - 000000000 ____D C:\Program Files\EnigmaSoft 2020-01-04 07:45 - 2020-01-04 07:47 - 000590136 _____ (Reimage) C:\Users\Kafi&Kafi\Downloads\ReimageRepair.exe 2020-01-04 07:44 - 2020-01-04 07:45 - 006946736 _____ (EnigmaSoft Limited) C:\Users\Kafi&Kafi\Downloads\SpyHunter-Installer.exe 2020-01-04 07:38 - 2020-01-04 07:47 - 019255000 _____ (Microsoft Corporation) C:\Users\Kafi&Kafi\Downloads\MediaCreationTool1909.exe 2020-01-04 07:38 - 2020-01-04 07:38 - 000000000 ___HD C:\$WINDOWS.~BT 2020-01-04 07:38 - 2020-01-04 07:38 - 000000000 ____D C:\Windows.old 2020-01-04 07:27 - 2020-01-04 07:27 - 000306248 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_klark.sys 2020-01-04 07:26 - 2020-01-04 07:27 - 000204520 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_mark.sys 2020-01-04 07:26 - 2020-01-04 07:26 - 000251256 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_arkmon.sys 2020-01-04 07:26 - 2020-01-04 07:26 - 000119744 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_klbg.sys 2020-01-04 07:26 - 2020-01-04 07:25 - 000251512 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klflt.sys 2020-01-04 07:26 - 2020-01-04 07:19 - 000998016 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klif.sys 2020-01-04 07:25 - 2020-01-04 07:25 - 000000000 ___HD C:\$SysReset 2020-01-04 07:18 - 2020-01-04 07:19 - 000000000 ____D C:\EEK 2020-01-04 07:02 - 2020-01-04 07:02 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\cache 2020-01-04 06:43 - 2020-01-04 06:43 - 000002101 _____ C:\Users\Public\Desktop\Heilig Defense MinerOff.lnk 2020-01-04 06:43 - 2020-01-04 06:43 - 000002101 _____ C:\ProgramData\Desktop\Heilig Defense MinerOff.lnk 2020-01-04 06:43 - 2020-01-04 06:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Heilig Defense 2020-01-04 06:43 - 2020-01-04 06:43 - 000000000 ____D C:\Program Files\Heilig Defense 2020-01-04 06:43 - 2018-03-14 18:15 - 000033224 _____ (Heilig Defense, LLC) C:\Windows\system32\Drivers\HDProcMon2.sys 2020-01-04 06:42 - 2020-01-04 06:42 - 002482600 _____ (Heilig Defense) C:\Users\Kafi&Kafi\Downloads\HDMinerOff.1.2018.246.722.x64.exe 2020-01-04 06:38 - 2020-01-04 06:38 - 000099868 _____ C:\Windows\system32\bootdelete.lst 2020-01-04 06:38 - 2020-01-04 06:38 - 000012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe 2020-01-04 06:21 - 2020-01-04 06:46 - 356231498 _____ C:\Users\Kafi&Kafi\Downloads\EmsisoftEmergencyKit.exe 2020-01-04 06:16 - 2020-01-04 06:16 - 000001968 _____ C:\Users\Public\Desktop\HitmanPro.lnk 2020-01-04 06:16 - 2020-01-04 06:16 - 000001968 _____ C:\ProgramData\Desktop\HitmanPro.lnk 2020-01-04 06:16 - 2020-01-04 06:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro 2020-01-04 06:16 - 2020-01-04 06:16 - 000000000 ____D C:\Program Files\HitmanPro 2020-01-03 23:32 - 2020-01-03 23:32 - 000232792 _____ (Copyright 2018.) C:\Windows\system32\Drivers\amsdk.sys 2020-01-03 23:32 - 2020-01-03 23:32 - 000003574 _____ C:\Windows\system32\Tasks\AMHelper 2020-01-03 23:32 - 2020-01-03 23:32 - 000001339 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk 2020-01-03 23:32 - 2020-01-03 23:32 - 000001339 _____ C:\ProgramData\Desktop\Zemana AntiMalware.lnk 2020-01-03 23:32 - 2020-01-03 23:32 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\Zemana 2020-01-03 23:32 - 2020-01-03 23:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware 2020-01-03 23:32 - 2020-01-03 23:32 - 000000000 ____D C:\Program Files (x86)\Zemana 2020-01-03 23:31 - 2020-01-03 23:32 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\AMSDK 2020-01-03 23:27 - 2020-01-03 23:29 - 012741568 _____ (Zemana Ltd. ) C:\Users\Kafi&Kafi\Downloads\AntiMalware_Setup.exe 2020-01-03 23:24 - 2020-01-03 23:57 - 011575104 _____ (SurfRight B.V.) C:\Users\Kafi&Kafi\Downloads\HitmanPro_x64.exe 2020-01-03 23:21 - 2020-01-04 06:41 - 000000000 ____D C:\ProgramData\HitmanPro 2020-01-03 23:13 - 2020-01-03 23:20 - 010925800 _____ (SurfRight B.V.) C:\Users\Kafi&Kafi\Downloads\HitmanPro.exe 2020-01-03 23:01 - 2020-01-03 23:03 - 016655521 ____R C:\Users\Kafi&Kafi\Downloads\IObit.Uninstaller.Pro-9.2.0.16.zip 2020-01-03 22:57 - 2020-01-03 22:57 - 000000000 ____D C:\Windows\pss 2020-01-03 22:54 - 2020-01-03 22:54 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job 2020-01-03 22:29 - 2020-01-03 22:30 - 001883976 _____ (Malwarebytes) C:\Users\Kafi&Kafi\Downloads\MBSetup.exe 2020-01-03 22:27 - 2020-01-03 22:27 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\mbam 2020-01-03 22:03 - 2020-01-04 07:45 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\CrashDumps 2020-01-03 21:41 - 2020-01-04 07:23 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\ElevatedDiagnostics 2020-01-03 16:27 - 2020-01-03 16:27 - 000000000 ___HD C:\Users\Kafi&Kafi\AppData\Roaming\ zAnti Ransomeware Honeypot 2020-01-03 16:27 - 2020-01-03 16:27 - 000000000 ___HD C:\Users\Kafi&Kafi\AppData\Roaming\ ! Anti Ransomeware Honeypot 2020-01-03 16:27 - 2020-01-03 16:27 - 000000000 ___HD C:\Users\Kafi&Kafi\AppData\Local\ ! Anti Ransomeware Honeypot 2020-01-03 15:35 - 2020-01-03 22:58 - 000000000 ____D C:\Program Files (x86)\FileASSASSIN 2020-01-03 15:35 - 2020-01-03 15:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileASSASSIN 2020-01-03 14:54 - 2020-01-03 14:54 - 000000100 _____ C:\Windows\infpub.dat 2020-01-03 14:54 - 2020-01-03 14:54 - 000000100 _____ C:\Windows\cscc.dat 2020-01-03 14:54 - 2020-01-03 14:54 - 000000000 ____D C:\Windows\system32\Tasks\Abelssoft 2020-01-03 14:50 - 2020-01-03 14:54 - 000000000 ___HD C:\Users\Kafi&Kafi\ zAnti Ransomeware Honeypot 2020-01-03 14:50 - 2020-01-03 14:54 - 000000000 ___HD C:\Users\Kafi&Kafi\AppData\Local\ zAnti Ransomeware Honeypot 2020-01-03 14:50 - 2020-01-03 14:54 - 000000000 ___HD C:\Users\Kafi&Kafi\ ! Anti Ransomeware Honeypot 2020-01-03 14:50 - 2020-01-03 14:50 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\Abelssoft 2020-01-03 14:43 - 2020-01-03 14:43 - 000002064 _____ C:\Users\Public\Desktop\AntiRansomware.lnk 2020-01-03 14:43 - 2020-01-03 14:43 - 000002064 _____ C:\ProgramData\Desktop\AntiRansomware.lnk 2020-01-03 14:43 - 2020-01-03 14:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntiRansomware 2020-01-03 14:43 - 2020-01-03 14:43 - 000000000 ____D C:\ProgramData\Abelssoft 2020-01-03 14:43 - 2020-01-03 14:43 - 000000000 ____D C:\Program Files (x86)\AntiRansomware 2020-01-03 14:14 - 2020-01-03 14:14 - 000002956 _____ C:\Windows\system32\Tasks\IMF_SkipUAC_Kafi&Kafi 2020-01-03 14:06 - 2020-01-03 14:06 - 000001264 _____ C:\Users\Public\Desktop\IObit Malware Fighter.lnk 2020-01-03 14:06 - 2020-01-03 14:06 - 000001264 _____ C:\ProgramData\Desktop\IObit Malware Fighter.lnk 2020-01-03 14:06 - 2020-01-03 14:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter 2020-01-03 13:53 - 2020-01-03 13:58 - 062477152 _____ C:\Users\Kafi&Kafi\Desktop\IObitMalwareFighterPro7.4.0.5820.zip 2020-01-03 13:47 - 2020-01-03 13:47 - 000003392 _____ C:\Windows\system32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} 2020-01-03 13:46 - 2020-01-03 13:47 - 000000000 ____D C:\Program Files\Common Files\AV 2020-01-03 13:45 - 2020-01-03 13:45 - 000099152 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_kimul.sys 2020-01-03 13:44 - 2020-01-03 13:44 - 000002286 _____ C:\Users\Public\Desktop\Kaspersky Passwords.lnk 2020-01-03 13:44 - 2020-01-03 13:44 - 000002286 _____ C:\ProgramData\Desktop\Kaspersky Passwords.lnk 2020-01-03 13:42 - 2020-01-03 13:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus 2020-01-03 13:42 - 2020-01-03 13:41 - 000002160 _____ C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2020-01-03 13:42 - 2020-01-03 13:41 - 000002160 _____ C:\ProgramData\Desktop\Kaspersky Anti-Virus.lnk 2020-01-03 13:41 - 2013-05-06 08:13 - 000110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll 2020-01-03 13:40 - 2020-01-04 09:28 - 000000000 ____D C:\ProgramData\Kaspersky Lab 2020-01-03 13:40 - 2020-01-03 13:40 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab 2020-01-03 13:32 - 2020-01-04 07:01 - 000002085 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2020-01-03 13:32 - 2020-01-04 07:01 - 000002085 _____ C:\ProgramData\Desktop\Malwarebytes.lnk 2020-01-03 13:32 - 2020-01-04 06:58 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys 2020-01-03 13:32 - 2020-01-04 06:57 - 000020936 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys 2020-01-03 13:32 - 2020-01-03 13:32 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\mbamtray 2020-01-03 13:32 - 2020-01-03 13:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2020-01-03 13:31 - 2020-01-03 13:31 - 000000000 ____D C:\Windows\system32\Drivers\etc\BACKUP 2020-01-03 13:31 - 2020-01-03 13:31 - 000000000 ____D C:\ProgramData\Malwarebytes 2020-01-03 13:31 - 2020-01-03 13:31 - 000000000 ____D C:\Program Files (x86)\Malwarebytes 2020-01-03 13:30 - 2020-01-03 13:30 - 000000000 ____D C:\Users\Kafi&Kafi\Documents\Malwarebytes Anti-Malware Premium 3.8.3.2965 Repack 2020-01-03 13:22 - 2020-01-03 13:28 - 066201013 _____ C:\Users\Kafi&Kafi\Documents\Malwarebytes Anti-Malware Premium 3.8.3.2965 Repack.7z 2020-01-03 13:12 - 2020-01-03 13:22 - 130331038 _____ C:\Users\Kafi&Kafi\Documents\Kaspersky.AntiVirus.2020.c20.0.14.1085.(abc).7z.crdownload 2020-01-03 13:11 - 2020-01-03 13:11 - 000052140 _____ C:\Users\Kafi&Kafi\Desktop\Applications.html 2020-01-03 12:55 - 2020-01-03 12:55 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Roaming\ChemTable Software 2020-01-03 12:53 - 2020-01-03 13:12 - 192015653 _____ C:\Users\Kafi&Kafi\Documents\Kaspersky.AntiVirus.2020.c20.0.14.1085.(abc).7z 2020-01-03 12:52 - 2020-01-03 12:52 - 000001253 _____ C:\Users\Public\Desktop\Reg Organizer.lnk 2020-01-03 12:52 - 2020-01-03 12:52 - 000001253 _____ C:\ProgramData\Desktop\Reg Organizer.lnk 2020-01-03 12:52 - 2020-01-03 12:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reg Organizer 2020-01-03 12:52 - 2020-01-03 12:52 - 000000000 ____D C:\ProgramData\Chemtable Software 2020-01-03 10:33 - 2020-01-03 16:26 - 000458248 _____ C:\Windows\system32\FNTCACHE.DAT 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\SysWOW64\taskshostservices.exe 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\SysWOW64\Drivers\WinmonProcessMonitor.sys 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\SysWOW64\Drivers\winmonfs.sys 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\SysWOW64\Drivers\winmon.sys 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\system32\taskshostservices.exe 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\system32\Drivers\WinmonProcessMonitor.sys 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\system32\Drivers\winmonfs.sys 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\system32\Drivers\winmon.sys 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\mssecsvc.exe 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 ____D C:\Windows\SysWOW64\SecureBootThemes 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 ____D C:\Windows\system32\SecureBootThemes 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 ____D C:\Windows\SpeechsTracing 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 ____D C:\Windows\rss 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 ____D C:\Windows\AppDiagnostics 2020-01-03 03:40 - 2020-01-03 12:45 - 000000000 ____D C:\Program Files (x86)\SMADAV 2020-01-03 03:40 - 2020-01-03 10:43 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Roaming\Smadav 2020-01-03 03:40 - 2020-01-03 10:30 - 000000000 __SHD C:\[Smad-Cage] 2020-01-03 03:05 - 2020-01-03 03:31 - 000000000 ____D C:\Users\Kafi&Kafi\Desktop\Setup 2020-01-03 03:04 - 2019-12-28 08:20 - 045212988 _____ C:\Users\Kafi&Kafi\Desktop\Setup.rar 2020-01-03 02:50 - 2020-01-04 07:48 - 000000000 ____D C:\Program Files (x86)\Trojan Killer 2020-01-03 02:37 - 2020-01-03 02:37 - 000004288 _____ C:\Windows\system32\Tasks\Reg Organizer Applications Updates Check 2020-01-03 02:00 - 2020-01-03 12:55 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\ChemTable Software 2020-01-03 02:00 - 2020-01-03 12:53 - 000000000 ____D C:\Program Files (x86)\Reg Organizer 2020-01-03 01:50 - 2020-01-03 01:50 - 096206848 _____ C:\Windows\system32\config\software.iobit 2020-01-03 01:50 - 2020-01-03 01:50 - 007671808 _____ C:\Windows\system32\config\drivers.iobit 2020-01-03 01:50 - 2020-01-03 01:50 - 000868352 _____ C:\Windows\system32\config\default.iobit 2020-01-03 01:50 - 2020-01-03 01:50 - 000040960 _____ C:\Windows\system32\config\sam.iobit 2020-01-03 01:50 - 2020-01-03 01:50 - 000032768 _____ C:\Windows\system32\config\security.iobit 2020-01-03 01:37 - 2020-01-03 01:37 - 000003958 _____ C:\Windows\system32\Tasks\Opera scheduled Autoupdate 1525338304 2020-01-03 01:37 - 2020-01-03 01:37 - 000001109 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk 2020-01-03 01:33 - 2020-01-03 02:02 - 068581891 ____R C:\Users\Kafi&Kafi\Downloads\Trojan_Killer_2.1.6 Preactivated.zip 2020-01-03 01:33 - 2020-01-03 01:49 - 021179033 ____R C:\Users\Kafi&Kafi\Downloads\Reg_Organizer_8.41.zip 2020-01-03 01:15 - 2020-01-03 01:15 - 069726208 _____ C:\Windows\system32\config\components.iobit 2020-01-03 01:08 - 2020-01-03 03:08 - 000000000 ____D C:\ProgramData\{F86B0233-9A85-4589-8AAF-524CC4F8211B} 2020-01-03 00:58 - 2020-01-03 01:00 - 054201472 ____R C:\Users\Kafi&Kafi\Downloads\Advanced.SystemCare.13.1.0.188.rar 2020-01-03 00:57 - 2020-01-03 04:13 - 000000000 ____D C:\Program Files\Process Hacker 2 2020-01-03 00:54 - 2020-01-03 00:56 - 000000000 ____D C:\Users\Kafi&Kafi\Downloads\SHAREit 2020-01-03 00:54 - 2020-01-03 00:54 - 000001285 _____ C:\Users\Public\Desktop\SHAREit.lnk 2020-01-03 00:54 - 2020-01-03 00:54 - 000001285 _____ C:\ProgramData\Desktop\SHAREit.lnk 2020-01-03 00:54 - 2020-01-03 00:54 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\SHAREit Technologies 2020-01-03 00:54 - 2020-01-03 00:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SHAREit 2020-01-03 00:54 - 2020-01-03 00:54 - 000000000 ____D C:\Program Files (x86)\SHAREit Technologies 2020-01-03 00:52 - 2020-01-03 00:52 - 006449464 _____ (SHAREit Technologies Co.Ltd ) C:\Users\Kafi&Kafi\Downloads\SHAREit-KCWEB.exe 2020-01-03 00:51 - 2020-01-03 02:48 - 005436872 _____ C:\Users\Kafi&Kafi\Downloads\shareit-connect-and-transfer - FilePlanet.apk 2020-01-02 23:36 - 2020-01-03 02:48 - 000000000 ____D C:\Windows\Minidump ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-01-04 09:28 - 2018-05-03 17:23 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent 2020-01-04 09:11 - 2017-03-19 01:03 - 000000000 ____D C:\Windows\registration 2020-01-04 09:08 - 2019-09-09 14:31 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\LocalLow\uTorrent 2020-01-04 09:08 - 2019-03-21 21:37 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\BitTorrentHelper 2020-01-04 09:05 - 2018-02-19 15:40 - 000000000 __SHD C:\Users\Kafi&Kafi\IntelGraphicsProfiles 2020-01-04 09:05 - 2017-03-19 01:03 - 000000000 ____D C:\Windows\AppReadiness 2020-01-04 09:03 - 2017-08-24 23:40 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2020-01-04 08:23 - 2018-02-19 15:39 - 000000000 ____D C:\Users\Kafi&Kafi 2020-01-04 08:23 - 2017-03-18 15:40 - 000786432 _____ C:\Windows\system32\config\BBI 2020-01-04 07:50 - 2018-03-09 18:07 - 000000000 ____D C:\Windows\system32\MRT 2020-01-04 07:48 - 2017-03-19 01:03 - 000000000 ___HD C:\Program Files\WindowsApps 2020-01-04 07:40 - 2018-03-09 18:02 - 129221664 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2020-01-04 07:14 - 2018-05-02 23:35 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent Web 2020-01-04 06:53 - 2018-11-30 15:26 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager 2020-01-04 06:32 - 2017-03-19 01:01 - 000000000 ____D C:\Windows\INF 2020-01-04 06:14 - 2018-09-17 19:30 - 000004184 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{4D0547B5-98FF-4F54-86AB-46F07D04C5B3} 2020-01-04 06:14 - 2018-05-02 23:35 - 000000000 ____D C:\Program Files\Opera 2020-01-04 03:46 - 2017-08-24 23:40 - 000000000 ____D C:\Windows\system32\SleepStudy 2020-01-03 23:26 - 2018-11-30 15:27 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Roaming\IDM 2020-01-03 23:13 - 2018-03-04 22:31 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2020-01-03 23:13 - 2018-03-04 22:31 - 000002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2020-01-03 23:13 - 2018-03-04 22:31 - 000002262 _____ C:\ProgramData\Desktop\Google Chrome.lnk 2020-01-03 14:47 - 2017-08-25 00:02 - 000000000 ____D C:\ProgramData\Package Cache 2020-01-03 14:14 - 2018-03-10 17:26 - 000000000 ____D C:\ProgramData\ProductData 2020-01-03 14:14 - 2018-03-10 17:25 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Roaming\IObit 2020-01-03 14:07 - 2018-03-10 17:25 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\LocalLow\IObit 2020-01-03 14:06 - 2018-03-10 17:25 - 000000000 ____D C:\Program Files (x86)\IObit 2020-01-03 14:05 - 2018-03-10 17:25 - 000000000 ____D C:\ProgramData\IObit 2020-01-03 13:41 - 2017-03-18 15:40 - 000032768 _____ C:\Windows\system32\config\ELAM 2020-01-03 13:40 - 2017-03-19 01:03 - 000000000 ___HD C:\Windows\ELAMBKUP 2020-01-03 10:33 - 2018-05-02 23:41 - 000000000 ____D C:\ProgramData\AVAST Software 2020-01-03 10:33 - 2017-08-25 00:19 - 000000000 ____D C:\ProgramData\McAfee 2020-01-03 03:07 - 2017-03-19 01:03 - 000000000 ____D C:\Windows\Help 2020-01-03 02:54 - 2017-03-19 01:03 - 000000000 ___SD C:\Windows\Downloaded Program Files 2020-01-03 02:54 - 2017-03-19 01:03 - 000000000 ____D C:\Windows\LiveKernelReports 2020-01-03 02:48 - 2018-11-30 14:56 - 000164489 _____ C:\Users\Kafi&Kafi\Downloads\pdf_download-3.0.0.2-fx.xpi 2020-01-03 02:48 - 2018-11-28 17:05 - 000394571 _____ C:\Users\Kafi&Kafi\Downloads\arabi ms p4 2018.pdf 2020-01-03 02:48 - 2018-11-28 17:05 - 000394571 _____ C:\Users\Kafi&Kafi\Downloads\0544_s18_ms_42 (3).pdf 2020-01-03 02:48 - 2018-11-28 17:05 - 000394571 _____ C:\Users\Kafi&Kafi\Downloads\0544_s18_ms_42 (2).pdf 2020-01-03 02:48 - 2018-09-16 21:22 - 138489784 _____ (WhatsApp) C:\Users\Kafi&Kafi\Downloads\WhatsAppSetup (1).exe 2020-01-03 02:31 - 2017-03-19 01:03 - 000000000 ____D C:\Windows\system32\MsDtc 2020-01-03 01:56 - 2017-08-24 23:22 - 000000000 ____D C:\Windows\Panther 2020-01-03 01:54 - 2018-09-23 22:33 - 000000036 _____ C:\Windows\progress.ini 2020-01-03 01:54 - 2017-08-25 00:55 - 000001890 _____ C:\Windows\diagwrn.xml 2020-01-03 01:54 - 2017-08-25 00:55 - 000001890 _____ C:\Windows\diagerr.xml 2020-01-03 01:44 - 2018-03-11 22:30 - 000000000 ___HD C:\$GetCurrent 2020-01-03 01:44 - 2018-03-11 22:30 - 000000000 ____D C:\Windows10Upgrade 2020-01-03 01:36 - 2017-03-19 00:51 - 000000000 ____D C:\Windows\CbsTemp 2020-01-03 00:03 - 2018-02-19 15:40 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\Packages 2020-01-03 00:02 - 2017-08-25 00:20 - 000000000 ____D C:\Windows\system32\Tasks\McAfee 2020-01-02 23:51 - 2019-09-09 15:36 - 000748816 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2020-01-02 22:00 - 2018-03-04 22:25 - 000003420 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA 2020-01-02 22:00 - 2018-03-04 22:25 - 000003296 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore 2020-01-02 21:54 - 2018-03-04 22:25 - 000000000 ____D C:\Program Files (x86)\Google 2020-01-02 21:45 - 2019-09-26 21:40 - 000004170 _____ C:\Windows\system32\Tasks\Opera scheduled assistant Autoupdate 1548868564 ==================== Files in the root of some directories ======== 2018-09-17 18:21 - 2004-05-16 00:57 - 000452217 _____ () C:\Users\Kafi&Kafi\irunin.dat 2018-09-17 18:21 - 2004-05-16 01:29 - 000000253 _____ () C:\Users\Kafi&Kafi\keys.dat 2018-09-17 18:21 - 2002-11-27 17:33 - 000338432 ____R () C:\Users\Kafi&Kafi\Mss32.dll 2019-09-10 15:40 - 2019-09-10 15:40 - 000000000 _____ () C:\Users\Kafi&Kafi\AppData\Local\{BD7B1ABB-05E3-4D99-BFBE-85D006971391} ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) LastRegBack: 2019-09-20 21:28 ==================== End of FRST.txt ========================