Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-12-2019 Ran by [removed] (administrator) on DESKTOP-813561A (Dell Inc. Inspiron 15-3567) (04-01-2020 21:46:50) Running from C:\Users\[removed]\Downloads [removed] Platform: Windows 10 Home Version 1703 15063.1387 (X64) Language: English (United States) Default browser: Opera Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe (Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe (Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe (Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe (Dell Inc -> Dell Inc.) C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe (Dell Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe (Dell Inc.) [File not signed] C:\Program Files\Dell\QuickSet\quickset.exe (EnigmaSoft Limited -> EnigmaSoft Limited) C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler64.exe (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe (Intel(R) Corporation -> Intel Corporation) C:\Program Files\Intel\IntelSGXPSW\bin\x64\Release\aesm_service.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\igfxCUIService.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k127153.inf_amd64_3f3936d8dec668b8\igfxEM.exe (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe (Microsoft Corporation -> Microsoft Corporation) C:\Users\Kafi&Kafi\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Windows -> Microsoft Corporation) C:\Program Files\rempl\sedlauncher.exe (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\InstallAgent.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\MpCmdRun.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\MpCmdRun.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\NisSrv.exe (Opera Software AS -> Opera Software) C:\Program Files\Opera\assistant\browser_assistant.exe (Opera Software AS -> Opera Software) C:\Program Files\Opera\assistant\browser_assistant.exe (PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\DSAPI.exe (Qualcomm Atheros -> Qualcomm Technologies Inc.) C:\Windows\System32\drivers\QcomWlanSrvx64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Rivet Networks LLC -> CloudBees, Inc.) C:\Program Files\Rivet Networks\SmartByte\RNDBWMService.exe (Rivet Networks LLC -> Rivet Networks LLC) C:\Program Files\Rivet Networks\SmartByte\RNDBWM.exe (Rivet Networks LLC -> Rivet Networks) C:\Program Files\Rivet Networks\SmartByte\SmartByteNetworkService.exe (Rosetta Stone Ltd -> Rosetta Stone Ltd.) C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe (Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.1000_x64__kzf8qxf38zg5c\SkypeHost.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-19] (Microsoft Windows -> Microsoft Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9269352 2019-09-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506384 2019-09-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [320568 2016-09-20] (Intel(R) Rapid Storage Technology -> Intel Corporation) HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [3910656 2017-05-04] (Dell Inc.) [File not signed] HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [1220416 2018-03-06] (Waves Inc -> Waves Audio Ltd.) HKLM-x32\...\Run: [Opera Browser Assistant] => C:\Program Files\Opera\assistant\browser_assistant.exe [2774040 2019-12-19] (Opera Software AS -> Opera Software) HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5276944 2019-11-27] (IObit Information Technology -> IObit) HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Run: [utweb] => "C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent Web\utweb.exe" /MINIMIZED HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Run: [GoogleChromeAutoLaunch_6BCEFFED5377C18D30C2056EF5045257] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\Kafi&Kafi\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\Kafi&Kafi\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\RunOnce: [Uninstall 19.152.0927.0012\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Kafi&Kafi\AppData\Local\Microsoft\OneDrive\19.152.0927.0012\amd64" HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\RunOnce: [Uninstall 19.152.0927.0012] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Kafi&Kafi\AppData\Local\Microsoft\OneDrive\19.152.0927.0012" HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1 HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Policies\Explorer: [DisallowRun] 1 HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Policies\Explorer\DisallowRun: [1] Mshta.exe HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Policies\Explorer\DisallowRun: [2] powershell.exe HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\Policies\Explorer\DisallowRun: [3] bitsadmin.exe HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\...\MountPoints2: {f58070ba-1f81-11e8-af19-e89eb444c350} - "E:\.\StartModem.exe" HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.88\Installer\chrmstp.exe [2020-01-03] (Google LLC -> Google LLC) BootExecute: autocheck autochk * bootdelete FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {191D314E-BD96-4234-9F58-69DF34A04873} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [1642672 2012-10-01] (Microsoft Corporation -> Microsoft Corporation) Task: {1A7A1124-9653-4A38-82C1-9D25566B66B1} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation) Task: {2A387C3B-7DF3-43E5-8E0E-59FFBA1E3E57} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\MpCmdRun.exe [467880 2019-09-20] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {2FC2EE25-2377-41D1-88F6-F581AC68A9C8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-03-04] (Google Inc -> Google Inc.) Task: {4CB5FB8B-12CA-4F51-A0DB-6247A72F1AC2} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation) Task: {5A6A5BD1-2F35-4458-9E58-A795060719AE} - System32\Tasks\SmartByte Telemetry => C:\Program Files\Rivet Networks\SmartByte\SmartByteTelemetry.exe [32448 2018-12-04] (Rivet Networks LLC -> DELL) Task: {5DB11C3C-54B7-403D-85DE-004E8A337E03} - System32\Tasks\AMHelper => C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe [659520 2019-11-04] (Zemana D.O.O. Sarajevo -> Zemana Ltd.) Task: {738FBFF5-2B65-424D-AA54-D19DFF231B9B} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [791232 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) Task: {75758A59-CCF9-40BE-9265-155778996344} - System32\Tasks\Opera scheduled Autoupdate 1525338304 => C:\Program Files\Opera\launcher.exe [1528344 2019-12-19] (Opera Software AS -> Opera Software) Task: {77F84055-57D4-492E-8447-DBF62D36ACDD} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [909112 2016-07-27] (Intel(R) Trusted Connect Service -> Intel(R) Corporation) Task: {82646C8A-0338-4CA0-AF55-8AA820C08388} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [726488 2019-09-10] (Dell Inc. -> Dell Inc.) Task: {8F248A92-559A-4BBA-966F-4978CFA1320E} - System32\Tasks\IMF_SkipUAC_Kafi&Kafi => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5276944 2019-11-27] (IObit Information Technology -> IObit) Task: {980D64A7-DCBF-420E-B3BC-3F27F571C4EB} - System32\Tasks\Opera scheduled assistant Autoupdate 1548868564 => C:\Program Files\Opera\launcher.exe [1528344 2019-12-19] (Opera Software AS -> Opera Software) Task: {9EEE4150-6D33-4CFD-AFEA-5E1CF11B0352} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\MpCmdRun.exe [467880 2019-09-20] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {BC319665-F0C8-44A3-B0D9-E124B2C47EE5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-03-04] (Google Inc -> Google Inc.) Task: {D10BD2D4-034E-4E00-9D54-53DE4DDCB07E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\MpCmdRun.exe [467880 2019-09-20] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {F362D871-BBFC-43BD-B9B0-17BDDDA3778F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\MpCmdRun.exe [467880 2019-09-20] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {FF0F119A-BA25-47AD-843F-776FE503F14D} - System32\Tasks\Reg Organizer Applications Updates Check => C:\Program Files (x86)\Reg Organizer\RegOrganizer.exe -SilentUpdatesCheck (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{14aee701-a839-4709-b600-ffab162621c1}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{cd6ef802-6821-4ba0-9383-09fdfa037b4c}: [NameServer] 188.135.0.23 Tcpip\..\Interfaces\{d97eea9b-ccad-4230-b29e-da0296760329}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1786950783-2709316424-3276483186-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1786950783-2709316424-3276483186-1001 -> DefaultScope {3C8E8372-E18E-4348-BA21-C30536C6CED3} URL = BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) BHO: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - No File FireFox: ======== FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2020-01-02] (Google LLC -> Google LLC) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2020-01-02] (Google LLC -> Google LLC) Chrome: ======= CHR NewTab: Default -> Not-active:"chrome-extension://picpadgnaiehfpanhlnlejeelgohjpid/ntp1.html", Not-active:"chrome-extension://odcommfbpjnempjflnjmgmnfpgcadboo/ntp1.html" CHR Notifications: Default -> hxxps://web.whatsapp.com; hxxps://www.hindilinks4u.to CHR Profile: C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default [2020-01-04] CHR Extension: (Slides) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-03-04] CHR Extension: (Docs) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-03-04] CHR Extension: (Google Drive) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-03-04] CHR Extension: (YouTube) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-03-04] CHR Extension: (Sheets) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-03-04] CHR Extension: (Google Docs Offline) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-09-17] CHR Extension: (Notifier for WhatsApp Web) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kaoholkoedbpjiangnchpfchhmageifp [2019-09-09] CHR Extension: (Google Hangouts) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2019-06-05] CHR Extension: (Chrome Web Store Payments) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-01-02] CHR Extension: (Gmail) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-05-13] CHR Extension: (Chrome Media Router) - C:\Users\Kafi&Kafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-01-04] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AESMService; c:\Program Files\Intel\IntelSGXPSW\bin\x64\Release\aesm_service.exe [3723400 2016-04-14] (Intel(R) Corporation -> Intel Corporation) R2 AtherosSvc; C:\Windows\system32\DRIVERS\AdminService.exe [414696 2019-09-09] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [209448 2019-05-21] (Dell Inc -> Dell Inc.) R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3373600 2019-05-21] (Dell Inc -> Dell Inc.) R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [218144 2019-05-21] (Dell Inc -> Dell Inc.) R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\DSAPI.exe [1050952 2019-09-22] (PC-Doctor, Inc. -> PC-Doctor, Inc.) R2 Dell SupportAssist Remediation; C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe [293528 2018-10-20] (Dell Inc -> Dell Inc.) R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [35976 2019-04-03] (Dell Inc -> ) S2 EsgShKernel; C:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exe [11780320 2020-01-04] (EnigmaSoft Limited -> EnigmaSoft Limited) R2 esifsvc; C:\Windows\System32\Intel\DPTF\esif_uf.exe [1855976 2019-09-09] (Intel Corporation -> Intel Corporation) R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2377488 2019-11-20] (IObit Information Technology -> IObit) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [987432 2016-07-27] (Intel(R) Trusted Connect Service -> Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [177440 2016-08-30] (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) R2 QcomWlanSrv; C:\Windows\System32\drivers\QcomWlanSrvx64.exe [227728 2019-09-09] (Qualcomm Atheros -> Qualcomm Technologies Inc.) R2 RNDBWM; C:\Program Files\Rivet Networks\SmartByte\RNDBWMService.exe [64184 2018-12-04] (Rivet Networks LLC -> CloudBees, Inc.) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [268368 2019-09-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor) R2 ShMonitor; C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe [519904 2020-01-04] (EnigmaSoft Limited -> EnigmaSoft Limited) R2 SmartByte Network Service x64; C:\Program Files\Rivet Networks\SmartByte\SmartByteNetworkService.exe [2114248 2018-12-04] (Rivet Networks LLC -> Rivet Networks) R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [48600 2019-09-10] (Dell Inc. -> Dell Inc.) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [265640 2018-09-26] (Synaptics Incorporated -> Synaptics Incorporated) S3 uSHAREitSvc; C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.Service.exe [33224 2017-09-11] (SHAREit Technologies Co.Ltd -> SHAREit Technologies Co.Ltd) R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [882496 2018-03-06] (Waves Inc -> Waves Audio Ltd.) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\NisSrv.exe [3630832 2019-09-20] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\MsMpEng.exe [103168 2019-09-20] (Microsoft Windows Publisher -> Microsoft Corporation) S3 EasyAntiCheat; "C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe" [X] ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 amsdk; C:\Windows\system32\drivers\amsdk.sys [232792 2020-01-03] (Zemana D.O.O. Sarajevo -> Copyright 2018.) R2 aow_drv; C:\Program Files\TxGameAssistant\UI\2.0.7373.123\aow_drv_x64_ev.sys [859456 2018-12-22] (Tencent Technology(Shenzhen) Company Limited -> Tencent) R3 BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [65952 2019-09-09] (WDKTestCert aswbldsv,131431045756648395 -> Qualcomm) R3 DDDriver; C:\Windows\system32\drivers\DDDriver64Dcsa.sys [36728 2019-05-21] (Microsoft Windows Hardware Compatibility Publisher -> Dell Inc.) S3 DellProf; C:\Windows\system32\drivers\DellProf.sys [41208 2018-02-10] (Techporch Incorporated -> Dell Computer Corporation) R2 DpmLiteDrv; c:\Program Files\Dell\QuickSet\DpmLiteDrv64.sys [15080 2014-10-16] (Wistron Corporation -> Wistron Corp.) R3 dptf_acpi; C:\Windows\System32\drivers\dptf_acpi.sys [78680 2019-09-09] (Intel Corporation -> Intel Corporation) R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [71000 2019-09-09] (Intel Corporation -> Intel Corporation) R3 esif_lf; C:\Windows\system32\DRIVERS\esif_lf.sys [402264 2019-09-09] (Intel Corporation -> Intel Corporation) R3 HidEventFilter; C:\Windows\System32\drivers\HidEventFilter.sys [84008 2019-09-09] (Intel(R) Software -> Intel Corporation) R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2018-03-10] (Martin Malik - REALiX -> REALiX(tm)) R3 iaLPSS2_GPIO2; C:\Windows\System32\drivers\iaLPSS2_GPIO2.sys [98760 2019-09-09] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) R0 iaStorAC; C:\Windows\System32\drivers\iaStorAC.sys [909152 2019-09-14] (Intel Corporation -> Intel Corporation) R3 IMFDownProtect; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win10_amd64\IMFDownProtect.sys [40016 2018-12-06] (IObit Information Technology -> IObit) R3 IMFForceDelete; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win10_amd64\IMFForceDelete.sys [34192 2019-06-11] (IObit Information Technology -> IObit) R3 ImfObCallback; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win10_amd64\ImfObCallback.sys [37328 2018-12-06] (IObit Information Technology -> IObit) R4 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [93312 2019-03-12] (Kaspersky Lab -> AO Kaspersky Lab) R4 klflt; C:\Windows\system32\DRIVERS\klflt.sys [251512 2020-01-04] (Kaspersky Lab -> AO Kaspersky Lab) R4 klgse; C:\Windows\System32\DRIVERS\klgse.sys [516216 2019-09-17] (Kaspersky Lab -> AO Kaspersky Lab) R4 klhk; C:\Windows\system32\DRIVERS\klhk.sys [1123664 2019-10-17] (Kaspersky Lab -> AO Kaspersky Lab) R4 KLIF; C:\Windows\System32\DRIVERS\klif.sys [998016 2020-01-04] (Kaspersky Lab -> AO Kaspersky Lab) R4 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [79184 2019-03-18] (Kaspersky Lab -> AO Kaspersky Lab) R4 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [59512 2019-03-18] (Kaspersky Lab -> AO Kaspersky Lab) R4 klpd; C:\Windows\System32\DRIVERS\klpd.sys [51328 2019-03-13] (Kaspersky Lab -> AO Kaspersky Lab) R4 kneps; C:\Windows\system32\DRIVERS\kneps.sys [232272 2019-03-19] (Kaspersky Lab -> AO Kaspersky Lab) S3 mtkmbim; C:\Windows\System32\drivers\mtkmbim7_x64.sys [209920 2016-07-29] (Microsoft Windows Hardware Compatibility Publisher -> MBB) R3 Qcamain10x64; C:\Windows\System32\drivers\Qcamain10x64.sys [2335632 2019-09-09] (Qualcomm Atheros -> Qualcomm Atheros, Inc.) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [1158944 2019-09-14] (Realtek Semiconductor Corp. -> Realtek ) R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [450152 2019-09-09] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation) S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [31128 2017-03-19] (Microsoft Windows -> ) R3 SmbCoSvc; C:\Windows\system32\DRIVERS\SmbCo10X64.sys [120008 2018-12-04] (Rivet Networks LLC -> Rivet Networks, LLC.) R3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [56840 2019-09-09] (Synaptics Incorporated -> Synaptics Incorporated) R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [65960 2018-09-26] (Synaptics Incorporated -> Synaptics Incorporated) S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [46472 2019-09-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [346336 2019-09-20] (Microsoft Windows -> Microsoft Corporation) S3 wdf_usb; C:\Windows\system32\DRIVERS\usb2ser.sys [82944 2016-07-29] (Microsoft Windows Hardware Compatibility Publisher -> MBB) R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [53984 2019-09-20] (Microsoft Windows -> Microsoft Corporation) U1 aswbdisk; no ImagePath U0 aswblog; no ImagePath R4 cm_km; \SystemRoot\system32\DRIVERS\cm_km.sys [X] S3 cpuz145; \??\C:\Windows\temp\cpuz145\cpuz145_x64.sys [X] R4 klbackupdisk; \SystemRoot\system32\DRIVERS\klbackupdisk.sys [X] R4 klbackupflt; system32\DRIVERS\klbackupflt.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) =================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-01-04 21:46 - 2020-01-04 21:48 - 000030077 _____ C:\Users\Kafi&Kafi\Downloads\FRST.txt 2020-01-04 20:59 - 2020-01-04 20:59 - 000003396 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1786950783-2709316424-3276483186-1001 2020-01-04 20:59 - 2020-01-04 20:59 - 000002381 _____ C:\Users\Kafi&Kafi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2020-01-04 09:38 - 2020-01-04 09:39 - 000000000 ___HD C:\$WINDOWS.~BT 2020-01-04 09:23 - 2020-01-04 21:47 - 000000000 ____D C:\FRST 2020-01-04 09:21 - 2020-01-04 09:21 - 002272256 _____ (Farbar) C:\Users\Kafi&Kafi\Downloads\FRST64.exe 2020-01-04 09:03 - 2020-01-04 21:48 - 000191685 _____ C:\Windows\ZAM.krnl.trace 2020-01-04 07:59 - 2020-01-04 07:59 - 000001061 _____ C:\Users\Public\Desktop\SpyHunter5.lnk 2020-01-04 07:59 - 2020-01-04 07:59 - 000001061 _____ C:\ProgramData\Desktop\SpyHunter5.lnk 2020-01-04 07:59 - 2020-01-04 07:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EnigmaSoft 2020-01-04 07:58 - 2020-01-04 07:59 - 000000000 ____D C:\sh5ldr 2020-01-04 07:46 - 2020-01-04 07:46 - 000000000 ____D C:\Program Files\EnigmaSoft 2020-01-04 07:45 - 2020-01-04 07:47 - 000590136 _____ (Reimage) C:\Users\Kafi&Kafi\Downloads\ReimageRepair.exe 2020-01-04 07:44 - 2020-01-04 07:45 - 006946736 _____ (EnigmaSoft Limited) C:\Users\Kafi&Kafi\Downloads\SpyHunter-Installer.exe 2020-01-04 07:38 - 2020-01-04 07:47 - 019255000 _____ (Microsoft Corporation) C:\Users\Kafi&Kafi\Downloads\MediaCreationTool1909.exe 2020-01-04 07:38 - 2020-01-04 07:38 - 000000000 ____D C:\Windows.old 2020-01-04 07:27 - 2020-01-04 07:27 - 000306248 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_klark.sys 2020-01-04 07:26 - 2020-01-04 07:27 - 000204520 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_mark.sys 2020-01-04 07:26 - 2020-01-04 07:26 - 000251256 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_arkmon.sys 2020-01-04 07:26 - 2020-01-04 07:26 - 000119744 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_klbg.sys 2020-01-04 07:26 - 2020-01-04 07:25 - 000251512 ____N (AO Kaspersky Lab) C:\Windows\system32\Drivers\klflt.sys 2020-01-04 07:26 - 2020-01-04 07:19 - 000998016 ____N (AO Kaspersky Lab) C:\Windows\system32\Drivers\klif.sys 2020-01-04 07:25 - 2020-01-04 07:25 - 000000000 ___HD C:\$SysReset 2020-01-04 07:18 - 2020-01-04 07:19 - 000000000 ____D C:\EEK 2020-01-04 07:02 - 2020-01-04 07:02 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\cache 2020-01-04 06:43 - 2020-01-04 06:43 - 000002101 _____ C:\Users\Public\Desktop\Heilig Defense MinerOff.lnk 2020-01-04 06:43 - 2020-01-04 06:43 - 000002101 _____ C:\ProgramData\Desktop\Heilig Defense MinerOff.lnk 2020-01-04 06:43 - 2020-01-04 06:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Heilig Defense 2020-01-04 06:43 - 2018-03-14 18:15 - 000033224 _____ (Heilig Defense, LLC) C:\Windows\system32\Drivers\HDProcMon2.sys 2020-01-04 06:38 - 2020-01-04 06:38 - 000099868 _____ C:\Windows\system32\bootdelete.lst 2020-01-04 06:38 - 2020-01-04 06:38 - 000012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe 2020-01-04 06:21 - 2020-01-04 06:46 - 356231498 _____ C:\Users\Kafi&Kafi\Downloads\EmsisoftEmergencyKit.exe 2020-01-03 23:32 - 2020-01-03 23:32 - 000232792 _____ (Copyright 2018.) C:\Windows\system32\Drivers\amsdk.sys 2020-01-03 23:32 - 2020-01-03 23:32 - 000003574 _____ C:\Windows\system32\Tasks\AMHelper 2020-01-03 23:32 - 2020-01-03 23:32 - 000001339 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk 2020-01-03 23:32 - 2020-01-03 23:32 - 000001339 _____ C:\ProgramData\Desktop\Zemana AntiMalware.lnk 2020-01-03 23:32 - 2020-01-03 23:32 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\Zemana 2020-01-03 23:32 - 2020-01-03 23:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware 2020-01-03 23:32 - 2020-01-03 23:32 - 000000000 ____D C:\Program Files (x86)\Zemana 2020-01-03 23:31 - 2020-01-03 23:32 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\AMSDK 2020-01-03 22:57 - 2020-01-03 22:57 - 000000000 ____D C:\Windows\pss 2020-01-03 22:54 - 2020-01-03 22:54 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job 2020-01-03 22:27 - 2020-01-03 22:27 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\mbam 2020-01-03 22:03 - 2020-01-04 07:45 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\CrashDumps 2020-01-03 21:41 - 2020-01-04 07:23 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\ElevatedDiagnostics 2020-01-03 14:54 - 2020-01-04 20:33 - 000000000 ____D C:\Windows\system32\Tasks\Abelssoft 2020-01-03 14:54 - 2020-01-03 14:54 - 000000100 _____ C:\Windows\infpub.dat 2020-01-03 14:54 - 2020-01-03 14:54 - 000000100 _____ C:\Windows\cscc.dat 2020-01-03 14:50 - 2020-01-03 14:50 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\Abelssoft 2020-01-03 14:43 - 2020-01-03 14:43 - 000000000 ____D C:\ProgramData\Abelssoft 2020-01-03 14:14 - 2020-01-03 14:14 - 000002956 _____ C:\Windows\system32\Tasks\IMF_SkipUAC_Kafi&Kafi 2020-01-03 14:06 - 2020-01-04 21:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter 2020-01-03 13:47 - 2020-01-03 13:47 - 000003392 _____ C:\Windows\system32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} 2020-01-03 13:46 - 2020-01-04 20:39 - 000000000 ____D C:\Program Files\Common Files\AV 2020-01-03 13:45 - 2020-01-03 13:45 - 000099152 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_kimul.sys 2020-01-03 13:32 - 2020-01-03 13:32 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\mbamtray 2020-01-03 13:31 - 2020-01-03 13:31 - 000000000 ____D C:\Windows\system32\Drivers\etc\BACKUP 2020-01-03 13:31 - 2020-01-03 13:31 - 000000000 ____D C:\Program Files (x86)\Malwarebytes 2020-01-03 13:11 - 2020-01-03 13:11 - 000052140 _____ C:\Users\Kafi&Kafi\Desktop\Applications.html 2020-01-03 10:33 - 2020-01-03 16:26 - 000458248 _____ C:\Windows\system32\FNTCACHE.DAT 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\SysWOW64\taskshostservices.exe 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\SysWOW64\Drivers\WinmonProcessMonitor.sys 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\SysWOW64\Drivers\winmonfs.sys 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\SysWOW64\Drivers\winmon.sys 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\system32\taskshostservices.exe 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\system32\Drivers\WinmonProcessMonitor.sys 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\system32\Drivers\winmonfs.sys 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\system32\Drivers\winmon.sys 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 _RSHD C:\Windows\mssecsvc.exe 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 ____D C:\Windows\SysWOW64\SecureBootThemes 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 ____D C:\Windows\system32\SecureBootThemes 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 ____D C:\Windows\SpeechsTracing 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 ____D C:\Windows\rss 2020-01-03 03:42 - 2020-01-03 03:42 - 000000000 ____D C:\Windows\AppDiagnostics 2020-01-03 03:40 - 2020-01-03 10:43 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Roaming\Smadav 2020-01-03 03:40 - 2020-01-03 10:30 - 000000000 __SHD C:\[Smad-Cage] 2020-01-03 02:50 - 2020-01-04 21:23 - 000000000 ____D C:\Program Files (x86)\Trojan Killer 2020-01-03 02:37 - 2020-01-03 02:37 - 000004288 _____ C:\Windows\system32\Tasks\Reg Organizer Applications Updates Check 2020-01-03 02:00 - 2020-01-04 20:38 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\ChemTable Software 2020-01-03 01:50 - 2020-01-03 01:50 - 096206848 _____ C:\Windows\system32\config\software.iobit 2020-01-03 01:50 - 2020-01-03 01:50 - 007671808 _____ C:\Windows\system32\config\drivers.iobit 2020-01-03 01:50 - 2020-01-03 01:50 - 000868352 _____ C:\Windows\system32\config\default.iobit 2020-01-03 01:50 - 2020-01-03 01:50 - 000040960 _____ C:\Windows\system32\config\sam.iobit 2020-01-03 01:50 - 2020-01-03 01:50 - 000032768 _____ C:\Windows\system32\config\security.iobit 2020-01-03 01:37 - 2020-01-03 01:37 - 000003958 _____ C:\Windows\system32\Tasks\Opera scheduled Autoupdate 1525338304 2020-01-03 01:37 - 2020-01-03 01:37 - 000001109 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk 2020-01-03 01:33 - 2020-01-03 02:02 - 068581891 ____R C:\Users\Kafi&Kafi\Downloads\Trojan_Killer_2.1.6 Preactivated.zip 2020-01-03 01:15 - 2020-01-03 01:15 - 069726208 _____ C:\Windows\system32\config\components.iobit 2020-01-03 01:08 - 2020-01-03 03:08 - 000000000 ____D C:\ProgramData\{F86B0233-9A85-4589-8AAF-524CC4F8211B} 2020-01-03 00:54 - 2020-01-03 00:56 - 000000000 ____D C:\Users\Kafi&Kafi\Downloads\SHAREit 2020-01-03 00:54 - 2020-01-03 00:54 - 000001285 _____ C:\Users\Public\Desktop\SHAREit.lnk 2020-01-03 00:54 - 2020-01-03 00:54 - 000001285 _____ C:\ProgramData\Desktop\SHAREit.lnk 2020-01-03 00:54 - 2020-01-03 00:54 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\SHAREit Technologies 2020-01-03 00:54 - 2020-01-03 00:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SHAREit 2020-01-03 00:54 - 2020-01-03 00:54 - 000000000 ____D C:\Program Files (x86)\SHAREit Technologies 2020-01-03 00:52 - 2020-01-03 00:52 - 006449464 _____ (SHAREit Technologies Co.Ltd ) C:\Users\Kafi&Kafi\Downloads\SHAREit-KCWEB.exe 2020-01-02 23:36 - 2020-01-03 02:48 - 000000000 ____D C:\Windows\Minidump ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-01-04 21:25 - 2017-03-19 01:03 - 000000000 ___HD C:\Windows\ELAMBKUP 2020-01-04 21:08 - 2018-02-19 15:39 - 000000000 ____D C:\Users\Kafi&Kafi 2020-01-04 20:59 - 2018-02-19 15:49 - 000000000 ___RD C:\Users\Kafi&Kafi\OneDrive 2020-01-04 20:59 - 2017-03-19 01:03 - 000000000 ___HD C:\Program Files\WindowsApps 2020-01-04 20:59 - 2017-03-19 01:03 - 000000000 ____D C:\Windows\AppReadiness 2020-01-04 20:43 - 2017-08-25 00:11 - 000000000 ____D C:\Program Files (x86)\VulkanRT 2020-01-04 20:40 - 2017-03-19 01:01 - 000000000 ____D C:\Windows\INF 2020-01-04 20:40 - 2017-03-18 15:40 - 000032768 _____ C:\Windows\system32\config\ELAM 2020-01-04 20:39 - 2019-09-28 23:14 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\WhatsApp 2020-01-04 20:38 - 2018-02-19 15:40 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\Packages 2020-01-04 20:33 - 2019-09-09 14:31 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\LocalLow\uTorrent 2020-01-04 20:33 - 2018-05-03 17:23 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Roaming\uTorrent 2020-01-04 20:29 - 2018-09-17 19:30 - 000004184 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{4D0547B5-98FF-4F54-86AB-46F07D04C5B3} 2020-01-04 20:26 - 2017-08-24 23:40 - 000000000 ____D C:\Windows\system32\SleepStudy 2020-01-04 09:44 - 2017-08-24 23:22 - 000000000 ____D C:\Windows\Panther 2020-01-04 09:11 - 2017-03-19 01:03 - 000000000 ____D C:\Windows\registration 2020-01-04 09:08 - 2019-03-21 21:37 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Local\BitTorrentHelper 2020-01-04 09:05 - 2018-02-19 15:40 - 000000000 __SHD C:\Users\Kafi&Kafi\IntelGraphicsProfiles 2020-01-04 09:03 - 2017-08-24 23:40 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2020-01-04 08:23 - 2017-03-18 15:40 - 000786432 _____ C:\Windows\system32\config\BBI 2020-01-04 07:50 - 2018-03-09 18:07 - 000000000 ____D C:\Windows\system32\MRT 2020-01-04 07:40 - 2018-03-09 18:02 - 129221664 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2020-01-04 06:14 - 2018-05-02 23:35 - 000000000 ____D C:\Program Files\Opera 2020-01-03 23:26 - 2018-11-30 15:27 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Roaming\IDM 2020-01-03 23:13 - 2018-03-04 22:31 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2020-01-03 23:13 - 2018-03-04 22:31 - 000002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2020-01-03 23:13 - 2018-03-04 22:31 - 000002262 _____ C:\ProgramData\Desktop\Google Chrome.lnk 2020-01-03 14:47 - 2017-08-25 00:02 - 000000000 ____D C:\ProgramData\Package Cache 2020-01-03 14:14 - 2018-03-10 17:26 - 000000000 ____D C:\ProgramData\ProductData 2020-01-03 14:14 - 2018-03-10 17:25 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\Roaming\IObit 2020-01-03 14:07 - 2018-03-10 17:25 - 000000000 ____D C:\Users\Kafi&Kafi\AppData\LocalLow\IObit 2020-01-03 14:06 - 2018-03-10 17:25 - 000000000 ____D C:\Program Files (x86)\IObit 2020-01-03 14:05 - 2018-03-10 17:25 - 000000000 ____D C:\ProgramData\IObit 2020-01-03 10:33 - 2018-05-02 23:41 - 000000000 ____D C:\ProgramData\AVAST Software 2020-01-03 03:07 - 2017-03-19 01:03 - 000000000 ____D C:\Windows\Help 2020-01-03 02:54 - 2017-03-19 01:03 - 000000000 ___SD C:\Windows\Downloaded Program Files 2020-01-03 02:54 - 2017-03-19 01:03 - 000000000 ____D C:\Windows\LiveKernelReports 2020-01-03 02:48 - 2018-11-30 14:56 - 000164489 _____ C:\Users\Kafi&Kafi\Downloads\pdf_download-3.0.0.2-fx.xpi 2020-01-03 02:48 - 2018-11-28 17:05 - 000394571 _____ C:\Users\Kafi&Kafi\Downloads\0544_s18_ms_42 (3).pdf 2020-01-03 02:48 - 2018-11-28 17:05 - 000394571 _____ C:\Users\Kafi&Kafi\Downloads\0544_s18_ms_42 (2).pdf 2020-01-03 02:31 - 2017-03-19 01:03 - 000000000 ____D C:\Windows\system32\MsDtc 2020-01-03 01:54 - 2018-09-23 22:33 - 000000036 _____ C:\Windows\progress.ini 2020-01-03 01:54 - 2017-08-25 00:55 - 000001890 _____ C:\Windows\diagwrn.xml 2020-01-03 01:54 - 2017-08-25 00:55 - 000001890 _____ C:\Windows\diagerr.xml 2020-01-03 01:44 - 2018-03-11 22:30 - 000000000 ___HD C:\$GetCurrent 2020-01-03 01:44 - 2018-03-11 22:30 - 000000000 ____D C:\Windows10Upgrade 2020-01-03 01:36 - 2017-03-19 00:51 - 000000000 ____D C:\Windows\CbsTemp 2020-01-03 00:02 - 2017-08-25 00:20 - 000000000 ____D C:\Windows\system32\Tasks\McAfee 2020-01-02 23:51 - 2019-09-09 15:36 - 000748816 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2020-01-02 22:00 - 2018-03-04 22:25 - 000003420 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA 2020-01-02 22:00 - 2018-03-04 22:25 - 000003296 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore 2020-01-02 21:54 - 2018-03-04 22:25 - 000000000 ____D C:\Program Files (x86)\Google 2020-01-02 21:45 - 2019-09-26 21:40 - 000004170 _____ C:\Windows\system32\Tasks\Opera scheduled assistant Autoupdate 1548868564 ==================== Files in the root of some directories ======== 2019-09-10 15:40 - 2019-09-10 15:40 - 000000000 _____ () C:\Users\Kafi&Kafi\AppData\Local\{BD7B1ABB-05E3-4D99-BFBE-85D006971391} ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) LastRegBack: 2019-09-20 21:28 ==================== End of FRST.txt ========================