Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-12-2019 Ran by [removed] (04-01-2020 09:28:48) Running from C:\Users\[removed]\Downloads Windows 10 Home Version 1703 15063.1387 (X64) (2018-02-19 11:34:19) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1786950783-2709316424-3276483186-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1786950783-2709316424-3276483186-503 - Limited - Disabled) Guest (S-1-5-21-1786950783-2709316424-3276483186-501 - Limited - Disabled) Kafi&Kafi (S-1-5-21-1786950783-2709316424-3276483186-1001 - Administrator - Enabled) => C:\Users\Kafi&Kafi ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Kaspersky Anti-Virus (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8} AS: Kaspersky Anti-Virus (Enabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\uTorrent) (Version: 3.5.5.45359 - BitTorrent Inc.) AntiRansomware 2020 (HKLM-x32\...\AbAppId-82_is1) (Version: 20.01 - Abelssoft) Dell Digital Delivery (HKLM-x32\...\{7294961D-6EC1-4418-9017-0180A0C78A91}) (Version: 3.2.1006.0 - Dell Products, LP) Dell SupportAssist (HKLM\...\{95BD6E30-2B18-4FB0-B5AE-8250E5584831}) (Version: 3.3.3.13 - Dell Inc.) Dell SupportAssist Remediation (HKLM\...\{5832D99C-C9C6-437F-861C-43ED6333956F}) (Version: 4.1.0.6828 - Dell Inc.) Hidden Dell SupportAssist Remediation (HKLM-x32\...\{48253a97-70d4-4166-9a2b-80b3bb2fcc75}) (Version: 4.1.0.6828 - Dell Inc.) Dell Touchpad (HKLM\...\SynTPDeinstKey) (Version: 19.2.17.70 - Synaptics Incorporated) Dell Update - SupportAssist Update Plugin (HKLM\...\{6DE68941-66DE-48DE-9C80-FE60C9DE0AD4}) (Version: 4.0.1.5857 - Dell Inc.) Hidden Dell Update - SupportAssist Update Plugin (HKLM-x32\...\{1dbe752f-b00e-4567-9276-141812b20d28}) (Version: 4.0.1.5857 - Dell Inc.) Dell Update (HKLM-x32\...\{5EBBC1DA-975F-44A0-B438-F325BCD45577}) (Version: 3.0.1 - Dell Inc.) D-Link Connection Manager v3.0.0MES (HKLM-x32\...\Broad Mobi HSPA Modem Normal Version_is1) (Version: - ) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden FileASSASSIN (HKLM-x32\...\FileASSASSIN) (Version: 1.06 - Malwarebytes) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 79.0.3945.88 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.421 - Google LLC) Hidden GridinSoft Trojan Killer (HKLM-x32\...\{EC8BB70B-7943-4FDD-83F8-DBDAD425845D}_is1) (Version: 2.1.6 - GridinSoft LLC) Heilig Defense MinerOff (HKLM\...\HeiligDefenseMinerOff) (Version: 1.2018.7.11 - Heilig Defense) HitmanPro 3.8 (HKLM\...\HitmanPro38) (Version: 3.8.16.310 - SurfRight B.V.) Intel(R) Chipset Device Software (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel(R) Corporation) Hidden Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.2.11000.2996 - Intel Corporation) Intel(R) HID Event Filter (HKLM-x32\...\3FB06EEC-013D-4366-9918-71B97DFB84EB) (Version: 1.1.0.317 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1025 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 21.20.16.4627 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.2.0.1020 - Intel Corporation) Intel® Software Guard Extensions Platform Software (HKLM\...\{06F94C28-DE1D-485F-AD91-333ACEB3F52D}) (Version: 1.6.100.32677 - Intel Corporation) IObit Malware Fighter 7 (HKLM-x32\...\IObit Malware Fighter_is1) (Version: 7.4.0.5820 - IObit) Kaspersky Anti-Virus (HKLM-x32\...\{D891550B-ACFE-4797-B368-BCFC434BBEB1}) (Version: 20.0.14.1085 - Kaspersky) Hidden Kaspersky Anti-Virus (HKLM-x32\...\InstallWIX_{D891550B-ACFE-4797-B368-BCFC434BBEB1}) (Version: 20.0.14.1085 - Kaspersky) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Malwarebytes version 4.0.4.49 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.0.4.49 - Malwarebytes) Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.7.9434.5 - Waves Audio Ltd.) Hidden Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\OneDriveSetup.exe) (Version: 19.152.0927.0012 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61135 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61135 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61135 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61135 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM-x32\...\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation) Microsoft Visual C++ 2017 x64 Additional Runtime - 14.12.25711 (HKLM\...\{7D02C46E-2953-3EB1-A5D5-7943C9D7684F}) (Version: 14.12.25711 - Microsoft Corporation) Microsoft Visual C++ 2017 x64 Minimum Runtime - 14.12.25711 (HKLM\...\{043D5787-5988-3DE2-928D-3B6A75E2126E}) (Version: 14.12.25711 - Microsoft Corporation) Microsoft Visual C++ 2017 x86 Additional Runtime - 14.12.25711 (HKLM-x32\...\{8FDCF95F-4756-34F4-9DA2-D708E7FAC504}) (Version: 14.12.25711 - Microsoft Corporation) Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.12.25711 (HKLM-x32\...\{6E894015-A182-3C1E-A7D2-3032CB2E1D43}) (Version: 14.12.25711 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{FD9D64F4-CAF5-3D23-845A-B843C78CC1A5}) (Version: 10.0.60830 - Microsoft Corporation) Opera Stable 65.0.3467.78 (HKLM-x32\...\Opera 65.0.3467.78) (Version: 65.0.3467.78 - Opera Software) Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Qualcomm 11ac Wireless LAN&Bluetooth Installer (HKLM-x32\...\{E7086B15-806E-4519-A876-DBA9FDDE9A13}) (Version: 11.0.0.10426 - Qualcomm) QuickSet64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 11.1.40 - Dell Inc.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.31228 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8581 - Realtek Semiconductor Corp.) Reg Organizer version 8.41 (HKLM-x32\...\Reg Organizer_is1) (Version: 8.41 - ChemTable Software) Rosetta Stone Language Training (HKLM-x32\...\{00384623-4937-4D7D-BDD9-23513D1C50AB}) (Version: 5.0.37.0 - Rosetta Stone, Ltd) Rosetta Stone Ltd Services (HKLM-x32\...\{3165E4A6-D5DE-46B0-8597-D55E2B826B84}) (Version: 3.2.21 - Rosetta Stone Ltd.) SHAREit (HKLM-x32\...\www.ushareit.com_is1) (Version: 4.0.6.177 - SHAREit Technologies Co.Ltd) SmartByte Drivers and Services (HKLM\...\{01F01829-4C5A-41B0-8198-0BDD02B34C47}) (Version: 2.0.643 - Rivet Networks) SpyHunter 5 (HKLM-x32\...\SpyHunter5) (Version: 5.7.24.155 - EnigmaSoft Limited) Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden UpdateAssistant (HKLM\...\{EC4F72E8-52FE-454E-B70F-DBE5C0FA44C5}) (Version: 1.20.0.0 - Microsoft Corporation) Hidden uTorrent Web (HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\utweb) (Version: 0.16.0 - BitTorrent, Inc.) Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0) (Version: 1.0.33.0 - LunarG, Inc.) WhatsApp (HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\WhatsApp) (Version: 0.2.8361 - WhatsApp) Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22617 - Microsoft Corporation) Windows Setup Remediations (x64) (KB4023057) (HKLM\...\{5534e02f-0f5d-40dd-ba92-bea38d22384d}.sdb) (Version: - ) WinRAR 5.71 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH) Zemana AntiMalware version 3.1.495 (HKLM-x32\...\{4E1F3677-C72E-4F7D-B66E-85467B1A289E}_is1) (Version: 3.1.495 - Zemana) Packages: ========= Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2020-01-03] (Autodesk Inc.) Benji Bananas Adventures -> C:\Program Files\WindowsApps\BenjiBananas.BenjiBananasAdventures_1.6.0.0_x86__jk5exrty1qj4c [2018-03-06] (Benji Bananas) Dell Customer Connect -> C:\Program Files\WindowsApps\DellInc.DellCustomerConnect_5.2.13.0_x64__htrsf667h5kn2 [2018-03-12] (Dell Inc) Dell Product Registration -> C:\Program Files\WindowsApps\DellInc.DellProductRegistration_3.4.6.0_x64__htrsf667h5kn2 [2018-09-17] (Dell Inc) Dell SupportAssist for PCs -> C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs_1.2.0.0_x64__htrsf667h5kn2 [2018-09-18] (Dell Inc) Disney Magic Kingdoms -> C:\Program Files\WindowsApps\A278AB0D.DisneyMagicKingdoms_4.3.0.7_x86__h6adky7gbf63m [2019-09-10] (Gameloft.) Dropbox promotion -> C:\Program Files\WindowsApps\C27EB4BA.DropboxOEM_20.4.2.0_x64__xbfy0k16fey96 [2020-01-03] (Dropbox Inc.) English Urdu dictionary free -> C:\Program Files\WindowsApps\10668Dict.land.UrduEnglishdictionary_1.12.0.0_x64__pht0r4cb04wa0 [2019-03-21] (Dict.land) [MS Ad] Hidden City: Hidden Object Adventure -> C:\Program Files\WindowsApps\828B5831.HiddenCityMysteryofShadows_1.32.3201.0_x86__ytsefhwckbdv6 [2020-01-04] (G5 Entertainment AB) Hotspot Shield Free VPN -> C:\Program Files\WindowsApps\6F71D7A7.HotspotShieldFreeVPN_1.6.3.0_x64__nsbqstbb9qxb6 [2018-03-14] (AnchorFree Inc.) imo desktop free video calls and chat -> C:\Program Files\WindowsApps\imoim.imodesktopfreevideocallsandchat_1.6.60.0_x86__y6z4cjm7ph9q0 [2019-03-21] (IMO.IM) Jetpack Joyride -> C:\Program Files\WindowsApps\HalfbrickStudiosPtyLtd.JetpackJoyride_1.0.3.68_x86__w77bc8x1h5kya [2018-03-06] (Halfbrick Studios Pty Ltd) Kick the Buddy 3D -> C:\Program Files\WindowsApps\29419NewFreeGoodGames.KicktheBuddy3D_2.1.0.0_x86__f2csh8nw1151c [2019-09-09] (New Free Good Games) [MS Ad] March of Empires: Sultans War -> C:\Program Files\WindowsApps\A278AB0D.MarchofEmpires_4.5.1.3_x86__h6adky7gbf63m [2020-01-03] (Gameloft.) Media Suite Essentials for Dell -> C:\Program Files\WindowsApps\DB6EA5DB.MediaSuiteEssentialsforDell_2.4.2725.0_x86__mcezb6ze687jp [2018-09-17] (CYBERLINK CORPORATION.) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-03-21] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-03-21] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.6132.0_x64__8wekyb3d8bbwe [2019-09-09] (Microsoft Studios) [MS Ad] Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.12.101.0_x64__8wekyb3d8bbwe [2019-09-09] (Microsoft Studios) One Calendar -> C:\Program Files\WindowsApps\64885BlueEdge.OneCalendar_2019.210.3.0_x64__8kea50m9krsh2 [2019-06-05] (Code Spark) Power Media Player for Dell -> C:\Program Files\WindowsApps\DB6EA5DB.PowerMediaPlayerforDell_14.1.9506.0_x86__mcezb6ze687jp [2018-11-24] (CYBERLINK CORPORATION.) Power2Go for Dell -> C:\Program Files\WindowsApps\DB6EA5DB.Power2GoforDell_8.0.8908.0_x86__mcezb6ze687jp [2018-09-17] (CYBERLINK CORPORATION.) [Startup Task] PowerDirector for Dell -> C:\Program Files\WindowsApps\DB6EA5DB.PowerDirectorforDell_15.0.4409.0_x64__mcezb6ze687jp [2018-09-17] (CYBERLINK CORPORATION.) Royal Revolt 2 -> C:\Program Files\WindowsApps\flaregamesGmbH.RoyalRevolt2_5.3.0.0_x86__g0q0z3kw54rap [2020-01-04] (flaregames GmbH) SmartByte -> C:\Program Files\WindowsApps\RivetNetworks.SmartByte_2.5.713.0_x64__rh07ty8m5nkag [2019-06-05] (Rivet Networks LLC) Translator -> C:\Program Files\WindowsApps\Microsoft.BingTranslator_5.5.14.0_x64__8wekyb3d8bbwe [2019-09-09] (Microsoft Corporation) الأخبار من Microsoft -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.31.12124.0_x64__8wekyb3d8bbwe [2019-09-09] (Microsoft Corporation) [MS Ad] البريد والتقويم -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11001.20116.0_x64__8wekyb3d8bbwe [2018-12-15] (Microsoft Corporation) [MS Ad] الطقس من MSN -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.31.11905.0_x64__8wekyb3d8bbwe [2019-09-09] (Microsoft Corporation) [MS Ad] ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1786950783-2709316424-3276483186-1001_Classes\CLSID\{a9872fee-5a55-4ecb-9b0f-b06fedcf14d1}\localserver32 -> C:\Program Files\Waves\MaxxAudio\MaxxAudioPro.exe (Waves Inc -> Waves Audio Ltd) ShellIconOverlayIdentifiers: [ IMFSafeBox] -> {0BB81440-5F42-4480-A5F7-770A6F439FC8} => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFShellExt.dll [2019-07-30] (IObit Information Technology -> IObit) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers1: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana\AntiMalware\AM_ShellExt64.dll [2019-11-04] (Zemana D.O.O. Sarajevo -> Advanced Malware Protection. Copyright 2019.) ContextMenuHandlers1: [IObit Malware Fighter] -> {0BB81440-5F42-4480-A5F7-770A6F439FC8} => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFShellExt.dll [2019-07-30] (IObit Information Technology -> IObit) ContextMenuHandlers1: [Kaspersky Anti-Virus 20.0] -> {6E1B4453-548D-4C43-A4AB-DE8D1D3DE17B} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 20.0\x64\ShellEx.dll [2020-01-04] (Kaspersky Lab -> AO Kaspersky Lab) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-28] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-28] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers2: [Kaspersky Anti-Virus 20.0] -> {6E1B4453-548D-4C43-A4AB-DE8D1D3DE17B} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 20.0\x64\ShellEx.dll [2020-01-04] (Kaspersky Lab -> AO Kaspersky Lab) ContextMenuHandlers3-x32: [FAExt] -> {05672D66-9736-42F5-8BEB-FA1DD3CA51C4} => C:\Program Files (x86)\FileASSASSIN\FileASSASSINExt.dll [2007-03-31] (Malwarebytes) [File not signed] ContextMenuHandlers4: [IObit Malware Fighter] -> {0BB81440-5F42-4480-A5F7-770A6F439FC8} => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFShellExt.dll [2019-07-30] (IObit Information Technology -> IObit) ContextMenuHandlers4: [Kaspersky Anti-Virus 20.0] -> {6E1B4453-548D-4C43-A4AB-DE8D1D3DE17B} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 20.0\x64\ShellEx.dll [2020-01-04] (Kaspersky Lab -> AO Kaspersky Lab) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\igfxDTCM.dll [2018-03-21] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers6: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana\AntiMalware\AM_ShellExt64.dll [2019-11-04] (Zemana D.O.O. Sarajevo -> Advanced Malware Protection. Copyright 2019.) ContextMenuHandlers6: [IObit Malware Fighter] -> {0BB81440-5F42-4480-A5F7-770A6F439FC8} => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFShellExt.dll [2019-07-30] (IObit Information Technology -> IObit) ContextMenuHandlers6: [Kaspersky Anti-Virus 20.0] -> {6E1B4453-548D-4C43-A4AB-DE8D1D3DE17B} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 20.0\x64\ShellEx.dll [2020-01-04] (Kaspersky Lab -> AO Kaspersky Lab) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-28] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-28] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Kafi&Kafi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\facebook.lnk -> C:\Program Files\Opera\launcher.exe (Opera Software) -> www.facebook.com ShortcutWithArgument: C:\Users\Kafi&Kafi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\a3a1d6b8109861c5\Google Hangouts.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=nckgahadagoaajjgafhacjanaoiihapd ==================== Loaded Modules (Whitelisted) ============= 2020-01-03 14:43 - 2019-10-08 12:41 - 000289280 _____ () [File not signed] C:\ProgramData\Abelssoft\AntiRansomware\Program\x64\Bootstrapper.dll 2020-01-03 14:43 - 2019-10-08 12:41 - 000207872 _____ () [File not signed] C:\ProgramData\Abelssoft\AntiRansomware\Program\x64\InjectionHelper.dll 2018-04-24 03:33 - 2018-04-24 03:33 - 001221120 _____ () [File not signed] C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent Web\avcodec-57.dll 2018-04-24 03:33 - 2018-04-24 03:33 - 000796160 _____ () [File not signed] C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent Web\avformat-57.dll 2018-04-24 03:33 - 2018-04-24 03:33 - 000446976 _____ () [File not signed] C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent Web\avutil-55.dll 2018-04-24 03:33 - 2018-04-24 03:33 - 000146944 _____ () [File not signed] C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent Web\swresample-2.dll 2017-05-04 04:20 - 2017-05-04 04:20 - 000086016 _____ (Dell Inc.) [File not signed] C:\Program Files\Dell\QuickSet\dadkeyb.dll 2018-12-04 12:10 - 2018-12-04 12:10 - 000100864 _____ (Rivet Networks) [File not signed] C:\Program Files\Rivet Networks\SmartByte\KillerNetworkServicePS.dll 2018-04-24 03:33 - 2018-04-24 03:33 - 001272320 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent Web\LIBEAY32.dll 2018-04-24 03:33 - 2018-04-24 03:33 - 000278528 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent Web\SSLEAY32.dll ==================== Alternate Data Streams (Whitelisted) ======== (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [472] ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer trusted/restricted ========== ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2017-03-19 01:03 - 2020-01-03 13:31 - 000001079 _____ C:\Windows\system32\drivers\etc\hosts 127.0.0.1 16.217.0.0 127.0.0.1 rosettastone.com 127.0.0.1 launch.rosettastone.com 127.0.0.1 amp.rosettastone.com 127.0.0.1 resources.rosettastone.com 127.0.0.1 updates.rosettastone.com 0.0.0.0 serius.mwbsys.com 0.0.0.0 keystone.mwbsys.com ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\StartupApproved\Run: => "OneDrive" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{BD4ADEFD-310D-479E-BA74-3F18699B7B39}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{C38EA9BA-9932-42B4-A9D4-F3661CCF60A8}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{7CE442D6-E181-4994-B75D-6374FB4761EA}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{EDA4A2B3-268D-4509-B076-E84C41208C05}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{9C56B0AC-D1A5-410F-8142-955AF42241BC}] => (Allow) C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneLtdServices.exe (Rosetta Stone Ltd -> Rosetta Stone Ltd.) FirewallRules: [{1A59CD4D-2EF2-46EF-8EDF-71DEF6F9DAFF}] => (Allow) C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneLtdServices.exe (Rosetta Stone Ltd -> Rosetta Stone Ltd.) FirewallRules: [{46EF5C40-18D6-416C-B820-F39D4BAB2F67}] => (Allow) C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe (Rosetta Stone Ltd -> Rosetta Stone Ltd.) FirewallRules: [{3D03DF4A-0129-49F3-B277-DE432E085D7D}] => (Allow) C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe (Rosetta Stone Ltd -> Rosetta Stone Ltd.) FirewallRules: [{564D6E10-C18F-4261-90E8-6DC56CED2E5C}] => (Allow) C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent Web\utweb.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{C324D99B-1775-4684-AB52-53D73F6ED1AF}] => (Allow) C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent Web\utweb.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{A68760CB-CADD-4076-A2D4-35396F319583}] => (Allow) C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{0EE71408-9206-44D6-8385-0D8BDDD2E1C5}] => (Allow) C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{F0E8CFCE-FDB8-4B65-A515-2EAC46AF6B21}] => (Allow) C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{4352A5F8-AFD6-40C1-94E8-40B4675CC9C7}] => (Allow) C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{437DA0CB-FB15-4642-BF62-DF30B32B6E65}] => (Allow) C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{1FBE1028-83BD-4647-A521-BA2DF6ECCBE1}] => (Allow) C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{9B581CF3-00CF-43F2-B63E-2714729755F1}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{1B01231B-0773-4828-92F0-BE830B159605}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\TInst.exe (Tencent Technology(Shenzhen) Company Limited -> ) FirewallRules: [{6618D9E9-DEF4-41A0-8872-2E0B6069380F}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\bugreport.exe (Tencent Technology(Shenzhen) Company Limited -> 腾讯公司) FirewallRules: [{E44B7679-7A23-4624-9CDE-9581453CE54A}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\QQExternal.exe (Tencent Technology(Shenzhen) Company Limited -> ) FirewallRules: [{88CA1A99-511C-4C52-A448-52B05FCF35A6}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\GameDownload.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{6AD7BA9C-6FCF-4EAF-98D0-08FEB5C110F3}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\GF186\TUpdate.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{0E9E53DF-4F91-4874-B8D2-B6442DB3305F}] => (Allow) C:\Program Files\TxGameAssistant\UI\AndroidEmulator.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{33C5F59D-5D70-4772-9D3F-BD3E505DD8DB}] => (Allow) C:\Program Files\TxGameAssistant\UI\adb.exe () [File not signed] FirewallRules: [{B1C6EC94-A862-4B71-825F-287A63252A4C}] => (Allow) C:\Program Files\TxGameAssistant\UI\TInst.exe (Tencent Technology(Shenzhen) Company Limited -> ) FirewallRules: [{9F2A91EE-10B8-4928-8C41-AE18D520E711}] => (Allow) C:\Program Files\TxGameAssistant\UI\bugreport.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{31012D38-20A6-4CC5-B1DC-8D6653147602}] => (Allow) C:\Program Files\TxGameAssistant\UI\TxGaDcc.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [TCP Query User{77033C5A-5992-4C7C-9EFE-C79DBF3FF304}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe No File FirewallRules: [UDP Query User{79715BE9-947B-48FA-A586-E0118540E233}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe No File FirewallRules: [TCP Query User{A0053C54-AB3E-4E21-BCFC-F9EBAECD1A7B}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe No File FirewallRules: [UDP Query User{AA311C4C-4BED-45D9-A136-82D57C94CB31}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe No File FirewallRules: [{8BDB3D96-1745-4EE7-97D3-FFB5C0531B04}] => (Allow) C:\Program Files\TxGameAssistant\UI\AndroidEmulator.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{0F3BC432-49FF-4296-B5DE-0E1A173C0F16}] => (Allow) C:\Program Files\TxGameAssistant\UI\adb.exe () [File not signed] FirewallRules: [{71B27770-6295-4D56-835F-A2AEC212890A}] => (Allow) C:\Program Files\TxGameAssistant\UI\TInst.exe (Tencent Technology(Shenzhen) Company Limited -> ) FirewallRules: [{F6243F87-187E-4722-94B1-B9CAF0CD8B15}] => (Allow) C:\Program Files\TxGameAssistant\UI\bugreport.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{F493A4FE-2B10-46A9-93D6-5DB2CBC7BE0A}] => (Allow) C:\Program Files\TxGameAssistant\UI\TxGaDcc.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{705E39A6-CFB3-4BB9-A6F1-CF3BE0E0E43C}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{5F9A8F1C-27F1-45F6-9811-4A692E903A4C}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\TInst.exe (Tencent Technology(Shenzhen) Company Limited -> ) FirewallRules: [{C340BE61-4355-4539-BAA4-F56CE21D458B}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\bugreport.exe (Tencent Technology(Shenzhen) Company Limited -> 腾讯公司) FirewallRules: [{84F53562-1500-479B-A2BE-5FBBA125E831}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\QQExternal.exe (Tencent Technology(Shenzhen) Company Limited -> ) FirewallRules: [{FED0EE0D-3C04-45EB-B027-A66783A74A5D}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\GameDownload.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{72F834BF-B3B9-43ED-98D6-C35D13A4D736}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\GF186\TUpdate.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{3472B6EB-59C8-43C9-97FF-0840A56B564C}] => (Allow) C:\Program Files\Opera\63.0.3368.107\opera.exe (Opera Software AS -> Opera Software) FirewallRules: [{A5E104BE-7A64-4DDE-A6AB-30EC74ED07FE}] => (Allow) C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe (SHAREit Technologies Co.Ltd -> SHAREit Technologies Co.Ltd) FirewallRules: [{6D2BE52B-10D5-46CA-9644-7B52DF5CC980}] => (Allow) C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe (SHAREit Technologies Co.Ltd -> SHAREit Technologies Co.Ltd) FirewallRules: [{7CD85107-5A7F-4324-96A2-E1B32A2148CC}] => (Allow) C:\Program Files\Opera\65.0.3467.78_0\opera.exe (Opera Software AS -> Opera Software) FirewallRules: [{A3BCFE28-1E03-4922-B847-157E335663FC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) ==================== Restore Points ========================= 04-01-2020 07:39:21 Windows Update ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (01/04/2020 09:04:59 AM) (Source: DPTF) (EventID: 17) (User: NT AUTHORITY) Description: ESIF(8.4.11000.6436) TYPE: ERROR MODULE: DPTF TIME 103256 ms DPTF Build Version: 8.4.11000.6436 DPTF Build Date: Apr 27 2018 16:54:10 Source File: ..\..\..\..\Sources\Policies\ConfigTdpPolicy\ConfigTdpPolicy.cpp @ line 167 Executing Function: ConfigTdpPolicy::onBindDomain Message: ConfigTdp not supported. Participant: TCPU [0] Domain: PKG [0] Policy: ConfigTDP Policy [0] Error: (01/04/2020 09:04:59 AM) (Source: DPTF) (EventID: 17) (User: NT AUTHORITY) Description: ESIF(8.4.11000.6436) TYPE: ERROR MODULE: DPTF TIME 103234 ms DPTF Build Version: 8.4.11000.6436 DPTF Build Date: Apr 27 2018 16:54:10 Source File: ..\..\..\..\Sources\Policies\ConfigTdpPolicy\ConfigTdpPolicy.cpp @ line 357 Executing Function: ConfigTdpPolicy::synchronizeConfigTdpPlatformSettings Message: ConfigTdp not supported. Policy: ConfigTDP Policy [0] Error: (01/04/2020 08:03:05 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program opera.exe version 65.0.3467.78 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 1750 Start Time: 01d5c2aed593ace0 Termination Time: 75 Application Path: C:\Program Files\Opera\65.0.3467.78_0\opera.exe Report Id: ae4b0703-37fd-4655-acda-80fd04f7528f Faulting package full name: Faulting package-relative application ID: Error: (01/04/2020 08:00:39 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program chrome.exe version 79.0.3945.88 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 2580 Start Time: 01d5c2ac0f03d4d4 Termination Time: 176 Application Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Report Id: d2b0b540-cd64-4c3b-bc30-e418f1fb8eaf Faulting package full name: Faulting package-relative application ID: Error: (01/04/2020 07:45:31 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: CHXSmartScreen.exe, version: 10.0.15063.0, time stamp: 0x58ccbe5f Faulting module name: edgehtml.dll, version: 11.0.15063.1387, time stamp: 0x7c1b93d1 Exception code: 0xc0000005 Fault offset: 0x00000000000a1cf6 Faulting process id: 0x2c04 Faulting application start time: 0x01d5c2b167732b79 Faulting application path: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe Faulting module path: C:\Windows\SYSTEM32\edgehtml.dll Report Id: fd2519ec-cc74-4d64-8381-9f2ea5b15188 Faulting package full name: Microsoft.Windows.Apprep.ChxApp_1000.15063.0.0_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: App Error: (01/04/2020 07:25:55 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program opera.exe version 65.0.3467.78 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 32c0 Start Time: 01d5c2ad1cfb4c66 Termination Time: 22 Application Path: C:\Program Files\Opera\65.0.3467.78_0\opera.exe Report Id: 8d75716e-e30e-4139-8d6f-5560a32501f2 Faulting package full name: Faulting package-relative application ID: Error: (01/04/2020 07:07:06 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program chrome.exe version 79.0.3945.88 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 1b50 Start Time: 01d5c2aa77c521c5 Termination Time: 33 Application Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Report Id: 4fe9e657-8b33-4c62-ba6b-cf96619194a0 Faulting package full name: Faulting package-relative application ID: Error: (01/04/2020 07:00:01 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HDMinerOff.exe, version: 1.2018.246.420, time stamp: 0x5b8cb6a0 Faulting module name: KERNELBASE.dll, version: 10.0.15063.1266, time stamp: 0x293cc0a1 Exception code: 0xe0434352 Fault offset: 0x00000000000656b8 Faulting process id: 0x255c Faulting application start time: 0x01d5c2aaf4238b62 Faulting application path: C:\Program Files\Heilig Defense\MinerOff\HDMinerOff.exe Faulting module path: C:\Windows\System32\KERNELBASE.dll Report Id: c187a8cd-7a84-4ce3-ae96-3dcb643571fd Faulting package full name: Faulting package-relative application ID: System errors: ============= Error: (01/04/2020 09:05:12 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (01/04/2020 09:05:12 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (01/04/2020 09:04:10 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The CldFlt service failed to start due to the following error: The request is not supported. Error: (01/04/2020 08:23:27 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (60000 milliseconds) was reached while waiting for a transaction response from the EsgShKernel service. Error: (01/04/2020 07:00:51 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Downloaded Maps Manager service terminated unexpectedly. It has done this 1 time(s). Error: (01/04/2020 06:59:28 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Dell Hardware Support service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (01/04/2020 06:59:28 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (60000 milliseconds) while waiting for the Dell Hardware Support service to connect. Error: (01/04/2020 06:58:44 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {B91D5831-B1BD-4608-8198-D72E155020F7} did not register with DCOM within the required timeout. Windows Defender: =================================== Date: 2020-01-03 03:10:24.534 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:VBS/Miner&threatid=2147742178&enterprise=0 Name: Trojan:VBS/Miner ID: 2147742178 Severity: Severe Category: Trojan Path: file:_C:\Users\Kafi&Kafi\AppData\Roaming\libraries\vcruntime140dd.dll Detection Origin: Local machine Detection Type: Concrete Detection Source: Real-Time Protection Process Name: C:\Program Files (x86)\Trojan Killer\tk64.exe Signature Version: AV: 1.301.1812.0, AS: 1.301.1812.0, NIS: 1.301.1812.0 Engine Version: AM: 1.1.16600.7, NIS: 1.1.16600.7 Date: 2019-09-20 21:34:59.027 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {72A4EFDB-CAD2-4860-A6F8-07EF46CFF584} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2020-01-03 12:08:33.677 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.301.1812.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16600.7 Error code: 0x80072ee7 Error description: The server name or address could not be resolved Date: 2020-01-03 12:08:33.676 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.301.1812.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiSpyware Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16600.7 Error code: 0x80072ee7 Error description: The server name or address could not be resolved Date: 2020-01-03 12:08:33.676 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.301.1812.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16600.7 Error code: 0x80072ee7 Error description: The server name or address could not be resolved Date: 2020-01-03 12:08:33.655 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.301.1812.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16600.7 Error code: 0x80072ee7 Error description: The server name or address could not be resolved Date: 2020-01-03 12:08:33.654 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.301.1812.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiSpyware Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16600.7 Error code: 0x80072ee7 Error description: The server name or address could not be resolved CodeIntegrity: =================================== Date: 2020-01-04 00:09:49.853 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Opera\65.0.3467.78_0\opera.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements. Date: 2020-01-04 00:09:49.839 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements. Date: 2020-01-03 23:45:44.018 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Opera\65.0.3467.78_0\opera.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements. Date: 2020-01-03 23:44:57.186 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Opera\65.0.3467.78_0\opera.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements. Date: 2020-01-03 15:30:42.118 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\$WINDOWS.~BT\NewOS\Windows\WinSxS\wow64_windows-devices-perception_31bf3856ad364e35_10.0.17134.1_none_b54ad0cf31a6e2c9\Windows.Devices.Perception.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2020-01-03 15:30:42.039 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\$WINDOWS.~BT\NewOS\Windows\WinSxS\wow64_windows-devices-perception_31bf3856ad364e35_10.0.17134.1_none_b54ad0cf31a6e2c9\Windows.Devices.Perception.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2020-01-03 15:30:33.630 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\$WINDOWS.~BT\NewOS\Windows\WinSxS\wow64_microsoft-xbox-gameoverlay_31bf3856ad364e35_10.0.17134.1_none_2e8b005bc4dbb92d\GamePanel.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2020-01-03 15:30:33.609 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\$WINDOWS.~BT\NewOS\Windows\WinSxS\wow64_microsoft-xbox-gameoverlay_31bf3856ad364e35_10.0.17134.1_none_2e8b005bc4dbb92d\GamePanel.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== BIOS: Dell Inc. 2.9.0 01/17/2019 Motherboard: Dell Inc. 0FGN4M Processor: Intel(R) Core(TM) i3-6006U CPU @ 2.00GHz Percentage of memory in use: 82% Total physical RAM: 3965.61 MB Available physical RAM: 701.91 MB Total Virtual: 6525.61 MB Available Virtual: 1869.32 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:915.98 GB) (Free:845.52 GB) NTFS \\?\Volume{b5be7212-489a-467e-a4f7-a8cbedc43811}\ (WINRETOOLS) (Fixed) (Total:0.49 GB) (Free:0.1 GB) NTFS \\?\Volume{c9266022-b63a-4c10-a562-fab82b859d17}\ (Image) (Fixed) (Total:13.31 GB) (Free:0.11 GB) NTFS \\?\Volume{88aa5568-a05f-4cd8-a0f5-6288a000d058}\ (DELLSUPPORT) (Fixed) (Total:1.12 GB) (Free:0.47 GB) NTFS ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 2CB0ADA8) Partition: GPT. ==================== End of Addition.txt =======================