Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-06-2021 Ran by [removed] (administrator) on CRAIGPC (LENOVO 10104) (25-06-2021 10:05:26) Running from C:\Users\[removed]\Downloads [removed] Platform: Windows 8.1 Single Language (Update) (X64) Language: English (United States) Default browser: Chrome Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (CyberLink -> CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (CyberLink -> CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (Dolby Laboratories, Inc. -> Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Google LLC -> ) C:\Program Files\Google\Drive File Stream\48.0.13.0\crashpad_handler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <18> (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2> (Primax Electronics Ltd.) [File not signed] C:\Program Files\Lenovo\Lenovo Black Silk USB Keyboard\Pelico.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe <6> (SurfRight B.V. -> SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12937872 2012-07-27] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-07-10] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [Lenovo Black Silk Input Device Main Program] => C:\Program Files\Lenovo\Lenovo Black Silk USB Keyboard\Pelico.exe [118272 2011-04-19] (Primax Electronics Ltd.) [File not signed] HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe" HKLM\...\Run: [WinZip UN] => C:\Program Files\WinZip\WZUpdateNotifier.exe [2859928 2020-09-25] (Corel Corporation -> Corel Corporation) HKLM\...\Run: [WinZip FAH] => C:\Program Files\WinZip\FAHConsole.exe [436704 2020-09-25] (Corel Corporation -> WinZip Computing, S.L.) HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508656 2012-07-26] (Dolby Laboratories, Inc. -> Dolby Laboratories Inc.) HKLM-x32\...\Run: [TNIOSDVolumeSync(x64)] => C:\Program Files (x86)\TNIOSDVolumeSync\TNIExec.exe [9728 2012-08-30] (TPV-INVENTA TECHNOLOGY CO., LTD.) [File not signed] HKLM-x32\...\Run: [TNIOSDVolumeSync(x86)] => C:\Program Files\TNIOSDVolumeSync\TNIExec.exe HKLM-x32\...\Run: [Lenovo Eye Distance System] => C:\Program Files\Lenovo\Lenovo Eye Distance System\Lenovo Eye Distance System.exe [270680 2012-07-19] (Lenovo -> Lenovo) HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink -> CyberLink) HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink -> CyberLink Corp.) HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [103720 2009-12-05] (CyberLink -> CyberLink) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-07] (CyberLink -> CyberLink Corp.) HKLM-x32\...\Run: [Lenovo Dynamic Brightness System] => C:\Program Files\Lenovo\Lenovo Brightness System\RunLDBS.exe [1752408 2012-07-10] (Lenovo -> TODO: <公司名>) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink -> CyberLink Corp.) HKLM-x32\...\Run: [LVT] => C:\Program Files\Lenovo\LVT\LJYZ.exe [886112 2011-11-24] (Lenovo (Beijing) Limited -> Lenovo) HKLM-x32\...\Run: [CitrixReceiver] => "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk" HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [407904 2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [153952 2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [8167200 2021-06-19] (Dropbox, Inc -> Dropbox, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-12-19] (Oracle America, Inc. -> Oracle Corporation) HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\48.0.13.0\GoogleDriveFS.exe [58172896 2021-05-24] (Google LLC -> Google, Inc.) HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\48.0.13.0\GoogleDriveFS.exe [58172896 2021-05-24] (Google LLC -> Google, Inc.) HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248176 2014-06-05] (TomTom International BV -> TomTom) HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\Run: [Google Update] => C:\Users\Craig\AppData\Local\Google\Update\1.3.36.82\GoogleUpdateCore.exe [217432 2021-04-20] (Google LLC -> Google LLC) HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\Run: [RGSC] => C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe [305064 2008-11-14] (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\Run: [com.squirrel.Teams.Teams] => C:\Users\Craig\AppData\Local\Microsoft\Teams\Update.exe [2342544 2020-04-01] (Microsoft 3rd Party Application Component -> Microsoft Corporation) HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\48.0.13.0\GoogleDriveFS.exe [58172896 2021-05-24] (Google LLC -> Google, Inc.) HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\48.0.13.0\GoogleDriveFS.exe [58172896 2021-05-24] (Google LLC -> Google, Inc.) HKLM\...\Windows x64\Print Processors\hpzpplhn: C:\Windows\System32\spool\prtprocs\x64\hpzpplhn.dll [100352 2007-05-23] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation) HKLM\...\Print\Monitors\Nitro PDF Port Monitor: c:\windows\system32\nitrolocalmon2.dll [29704 2012-12-14] (Nitro PDF Software -> Nitro PDF Software) HKLM\...\Print\Monitors\PCL hpz3llhn: c:\windows\system32\hpz3llhn.dll [36352 2007-05-23] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Company) HKLM\Software\...\AppCompatFlags\Custom\DKII.EXE: [{b6462b67-caf5-4a74-99df-cc2811bd1957}.sdb] -> GOG.com Dungeon Keeper 2 HKLM\Software\...\AppCompatFlags\InstalledSDB\{b6462b67-caf5-4a74-99df-cc2811bd1957}: [DatabasePath] -> C:\WINDOWS\AppPatch\Custom\{b6462b67-caf5-4a74-99df-cc2811bd1957}.sdb [2012-11-06] HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\91.0.4472.114\Installer\chrmstp.exe [2021-06-17] (Google LLC -> Google LLC) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2021-06-18] ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (Corel Corporation -> WinZip Computing) ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {09330573-95C5-48B5-BEFF-F26DB1199733} - System32\Tasks\Lenovo\Lenovo-19237 => C:\ProgramData\Lenovo-19237.vbs [198 2013-06-05] () [File not signed] <==== ATTENTION Task: {094CD275-5C71-4753-B57E-5566CA859498} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316} Task: {0F6DBBD1-1FA5-490B-A482-1F43FCC689E6} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969} Task: {174476BF-8AA9-4A13-B737-FB28D2BD173B} - System32\Tasks\ProtonVPN Update => C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.UpdateService.exe [61760 2020-10-23] (ProtonVPN AG -> ) Task: {2DDD57F3-D8F2-4378-8A42-589519B8CADE} - System32\Tasks\WinZip Update Notifier 1 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2859928 2020-09-25] (Corel Corporation -> Corel Corporation) Task: {3824CF4D-6BF5-4FEB-BF01-EE3A459DDB5E} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink -> CyberLink) Task: {3D85728E-F1B4-44A2-A4EC-B422AF6BDA14} - System32\Tasks\WinZip Update Notifier 3 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2859928 2020-09-25] (Corel Corporation -> Corel Corporation) Task: {3F8B48FB-CE76-4DE8-80F3-CD671615A82C} - System32\Tasks\Lenovo\Lenovo-19172 => C:\ProgramData\Lenovo-19172.vbs [198 2013-06-05] () [File not signed] <==== ATTENTION Task: {403155BB-9141-4E8A-89CB-76EFBE1A9887} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-22] (Microsoft Corporation -> Microsoft Corporation) Task: {4FFCE92E-B292-43BE-9FDA-DE59F898DA27} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-07-10] (Google Inc -> Google Inc.) Task: {59BEAF25-A964-4490-A251-B1A904872AD4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3289921415-534489958-369683985-1002UA => C:\Users\Craig\AppData\Local\Google\Update\GoogleUpdate.exe [153168 2018-07-10] (Google Inc -> Google Inc.) Task: {7AF5E293-0552-4A05-AB22-E979D48A729E} - System32\Tasks\WinZip Update Notifier 2 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2859928 2020-09-25] (Corel Corporation -> Corel Corporation) Task: {83643AA1-C079-40DF-891C-89DED994B5E1} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe Task: {84DEFF48-13D8-4756-A297-D7C594B88A05} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3289921415-534489958-369683985-1002Core => C:\Users\Craig\AppData\Local\Google\Update\GoogleUpdate.exe [153168 2018-07-10] (Google Inc -> Google Inc.) Task: {8B6759EE-1C08-4B8F-955C-774AB5A6544E} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDfE067B1} Task: {93DB65B0-9EB9-41F7-B372-DCD3465827B3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-22] (Microsoft Corporation -> Microsoft Corporation) Task: {9B91F9A4-7118-40EA-B239-40ED575D5352} - System32\Tasks\{F20D7C68-8AEC-4261-A1C4-9CD22DF73B8D} => C:\windows\system32\pcalua.exe -a "C:\Program Files\McAfee\MSC\mcuihost.exe" -c /body:misp://MSCJsRes.dll::uninstall.html /id:uninstall Task: {B42CF91F-9C04-47C2-8400-8534580DE4E4} - System32\Tasks\StartMenu8_Start => C:\program files (x86)\iobit\Classic Start\Start_Active.exe [22816 2016-11-15] (IObit Information Technology -> ) Task: {B779B792-15AE-47F0-B4C3-5FCA3BBF79E7} - System32\Tasks\G2MUpdateTask-S-1-5-21-3289921415-534489958-369683985-1002 => C:\Users\Craig\AppData\Local\GoToMeeting\19709\g2mupdate.exe [31320 2021-05-29] (LogMeIn, Inc. -> LogMeIn, Inc.) Task: {B88F6182-1FCC-424A-A91A-E7DB847380C2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-07-10] (Google Inc -> Google Inc.) Task: {BB7217D4-AE61-4084-B852-DC311369D667} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-02-22] (Dropbox, Inc -> Dropbox, Inc.) Task: {BCBD0623-8120-462F-815E-892D50A95B47} - System32\Tasks\G2MUploadTask-S-1-5-21-3289921415-534489958-369683985-1002 => C:\Users\Craig\AppData\Local\GoToMeeting\19709\g2mupload.exe [31320 2021-05-29] (LogMeIn, Inc. -> LogMeIn, Inc.) Task: {C9DCF59E-6B97-4C0C-8641-B8261089C8CA} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43da-BFD7-FBEEA2180A1E} Task: {DA36F2BD-2F20-48D9-897F-E8B7C60511EC} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.) Task: {DB21EF32-6BA9-4118-BBC1-BC4FF48961E5} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4f47-879B-29A80C355D61} Task: {EC6D9E91-C149-4122-8356-0181A3292293} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-02-22] (Dropbox, Inc -> Dropbox, Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-3289921415-534489958-369683985-1002.job => C:\Users\Craig\AppData\Local\GoToMeeting\19709\g2mupdate.exe Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-3289921415-534489958-369683985-1002.job => C:\Users\Craig\AppData\Local\GoToMeeting\19709\g2mupload.exe Task: C:\WINDOWS\Tasks\StartMenu8_Start.job => C:\program files (x86)\iobit\Classic Start\Start_Active.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local: [ActivePolicy] SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local\ipsecPolicy{1bec036e-5b21-4769-9542-d35d23a035f5} <==== ATTENTION (Restriction - IP) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{804FE210-C7CE-4409-BDF2-18981B42CD7A}: [DhcpNameServer] 192.168.0.1 Edge: ======= Edge Profile: C:\Users\Craig\AppData\Local\Microsoft\Edge\User Data\Default [2021-06-19] Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee] FireFox: ======== FF ProfilePath: C:\Users\Craig\AppData\Roaming\TomTom\HOME\Profiles\hs4ek8s4.default [2014-12-28] FF Extension: (Map status indicator) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\[removed] [2014-12-28] [Legacy] [not signed] FF HKLM-x32\...\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK => not found FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel® Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel® Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2018-03-29] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2018-03-29] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-02-15] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 8\npnitromozilla.dll [2012-12-14] (Nitro PDF Software -> Nitro PDF) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-05-28] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3289921415-534489958-369683985-1002: intel.com/AppUp -> C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp.dll [No File] FF Plugin HKU\S-1-5-21-3289921415-534489958-369683985-1002: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2021-04-27] (Ubisoft Entertainment Sweden AB -> ) FF Plugin HKU\S-1-5-21-3289921415-534489958-369683985-500: intel.com/AppUp -> C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp.dll [No File] Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\Craig\AppData\Local\Google\Chrome\User Data\Default [2021-06-25] CHR Notifications: Default -> hxxps://web.skype.com CHR Extension: (Google Drive) - C:\Users\Craig\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-20] CHR Extension: (YouTube) - C:\Users\Craig\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-10] CHR Extension: (Chrome Web Store Payments) - C:\Users\Craig\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29] CHR Extension: (Gmail) - C:\Users\Craig\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22] CHR Extension: (Chrome Media Router) - C:\Users\Craig\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-06-08] CHR HKU\S-1-5-21-3289921415-534489958-369683985-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.) S2 Dashboard Service; C:\Program Files (x86)\Lenovo\Lenovo Dashboard\DdMgr.exe [24880 2013-01-15] (Beijing Heegle Technology Co., Ltd. -> Microsoft) [File not signed] S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-02-22] (Dropbox, Inc -> Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-02-22] (Dropbox, Inc -> Dropbox, Inc.) R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [44328 2021-06-19] (Dropbox, Inc -> Dropbox, Inc.) S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [382504 2018-09-07] (EasyAntiCheat Oy -> EasyAntiCheat Ltd) R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [151496 2021-06-23] (SurfRight B.V. -> SurfRight B.V.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [7391408 2021-06-18] (Malwarebytes Inc -> Malwarebytes) S4 NitroDriverReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [230408 2012-12-14] (Nitro PDF Software -> Nitro PDF Software) S4 nlsX86cc; C:\windows\SysWOW64\NLSSRV32.EXE [70152 2012-12-14] (Nitro PDF Software -> Nalpeiron Ltd.) S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2522424 2020-11-20] (Electronic Arts, Inc. -> Electronic Arts) S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3476800 2020-11-20] (Electronic Arts, Inc. -> Electronic Arts) S3 ProtonVPN Service; C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPNService.exe [99136 2020-10-23] (ProtonVPN AG -> ) S3 ProtonVPN Update Service; C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.UpdateService.exe [61760 2020-10-23] (ProtonVPN AG -> ) S4 SMService; C:\program files (x86)\iobit\Classic Start\SMService.exe [1077536 2017-01-16] (IObit Information Technology -> IObit) S4 TNISrvc; C:\Program Files (x86)\TNIOSDVolumeSync\TNISrvc.exe [53760 2012-08-30] (TPV-INVENTA TECHNOLOGY CO., LTD.) [File not signed] R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation -> Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation -> Microsoft Corporation) S2 Ms14B10DA0App; C:\WINDOWS\System32\Ms14B10DA0App.dll [X] ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) U5 amsdk; C:\Windows\System32\Drivers\amsdk.sys [232792 2021-06-23] (Zemana D.O.O. Sarajevo -> Copyright 2018.) R2 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv_bgp.sys [315976 2020-10-05] (Bluestack Systems, Inc -> Bluestack System Inc.) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [199128 2021-06-18] (Malwarebytes Inc -> Malwarebytes) R1 googledrivefs3301; C:\WINDOWS\System32\DRIVERS\googledrivefs3301.sys [123176 2020-11-17] (Google LLC -> Google, Inc.) R1 googledrivefs3460; C:\WINDOWS\System32\DRIVERS\googledrivefs3460.sys [380328 2021-05-24] (Google LLC -> Google, Inc.) S3 LEMo602D; C:\WINDOWS\system32\DRIVERS\LEMo602D.sys [24064 2011-04-19] (Microsoft Windows Hardware Compatibility Publisher -> Primax Electronics Ltd.) S3 LEub602D; C:\WINDOWS\system32\DRIVERS\LEub602D.sys [18944 2011-05-17] (Microsoft Windows Hardware Compatibility Publisher -> Primax Electronics Ltd.) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220752 2021-06-21] (Malwarebytes Inc -> Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [77496 2021-06-25] (Malwarebytes Inc -> Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-06-24] (Malwarebytes Inc -> Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [156880 2021-06-25] (Malwarebytes Inc -> Malwarebytes) S3 MpKsl30f2f58e; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{97CA743B-42CF-4493-9669-9FEF1682CD7E}\MpKslDrv.sys [47328 2021-06-20] (Microsoft Windows -> Microsoft Corporation) S3 MpKslab085dca; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{97CA743B-42CF-4493-9669-9FEF1682CD7E}\MpKslDrv.sys [47328 2021-06-20] (Microsoft Windows -> Microsoft Corporation) S3 MpKslc7305a20; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{97CA743B-42CF-4493-9669-9FEF1682CD7E}\MpKslDrv.sys [47328 2021-06-20] (Microsoft Windows -> Microsoft Corporation) S3 nlwt; C:\WINDOWS\system32\DRIVERS\nlwt.sys [29888 2020-11-10] (TEFINCOM S.A. -> WireGuard LLC) S3 ProtonVPNSplitTunnel; C:\Program Files (x86)\Proton Technologies\ProtonVPN\x64\Win7\ProtonVPN.SplitTunnelDriver.sys [22456 2020-08-19] (ProtonVPN AG -> Proton Technologies AG) R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [266896 2012-06-13] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.) S3 tapnordvpn; C:\WINDOWS\system32\DRIVERS\tapnordvpn.sys [35592 2020-06-09] (TEFINCOM S.A. -> The OpenVPN Project) R3 tapprotonvpn; C:\WINDOWS\system32\DRIVERS\tapprotonvpn.sys [39864 2020-08-19] (ProtonVPN AG -> The OpenVPN Project) R3 VMC412; C:\WINDOWS\System32\Drivers\VMC412.sys [232576 2012-08-22] (Microsoft Windows Hardware Compatibility Publisher -> Vimicro Corporation) R3 vmuacflt; C:\WINDOWS\System32\Drivers\vmuacflt.sys [13696 2012-05-02] (Microsoft Windows Hardware Compatibility Publisher -> Vimicro Corporation) S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Windows -> Microsoft Corporation) R0 WinI2C-DDC; C:\WINDOWS\System32\drivers\DDCDrv.sys [20832 2008-04-08] (PC Micro Systems Inc. -> Nicomsoft Ltd.) R0 WinI2C-DDC; C:\Windows\SysWOW64\drivers\DDCDrv.sys [15712 2010-03-23] (Lenovo (Beijing) Limited -> Nicomsoft Ltd.) S3 wsvd; C:\WINDOWS\system32\DRIVERS\wsvd.sys [102376 2012-06-14] (CyberLink -> "CyberLink) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) NETSVC: Ms14B10DA0App -> C:\WINDOWS\System32\Ms14B10DA0App.dll ==> No File ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2021-06-25 07:05 - 2021-06-25 08:05 - 000001082 _____ C:\Users\Craig\Downloads\Fixlog.txt 2021-06-25 07:04 - 2021-06-25 07:05 - 000000078 _____ C:\Users\Craig\Downloads\mqykrylffojpw.txt 2021-06-25 06:55 - 2021-06-25 06:55 - 000156880 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2021-06-25 06:55 - 2021-06-25 06:55 - 000077496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2021-06-24 18:22 - 2021-06-24 18:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2021-06-23 14:48 - 2021-06-23 14:52 - 000232792 _____ (Copyright 2018.) C:\WINDOWS\system32\Drivers\amsdk.sys 2021-06-23 14:48 - 2021-06-23 14:52 - 000000000 ____D C:\Users\Craig\AppData\Local\AMSDK 2021-06-23 14:43 - 2021-06-23 14:44 - 013922376 _____ (Zemana Ltd. ) C:\Users\Craig\Downloads\AntiMalware_Setup.exe 2021-06-23 14:40 - 2021-06-23 14:40 - 000012872 _____ (SurfRight B.V.) C:\WINDOWS\system32\bootdelete.exe 2021-06-23 14:16 - 2021-06-23 14:41 - 000000000 ____D C:\ProgramData\HitmanPro 2021-06-23 14:16 - 2021-06-23 14:16 - 000001876 _____ C:\Users\Public\Desktop\HitmanPro.lnk 2021-06-23 14:16 - 2021-06-23 14:16 - 000001876 _____ C:\ProgramData\Desktop\HitmanPro.lnk 2021-06-23 14:16 - 2021-06-23 14:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro 2021-06-23 14:16 - 2021-06-23 14:16 - 000000000 ____D C:\Program Files\HitmanPro 2021-06-23 14:15 - 2021-06-23 14:15 - 011332032 _____ (SurfRight B.V.) C:\Users\Craig\Downloads\hitmanpro_x64.exe 2021-06-23 13:24 - 2021-06-23 13:31 - 000002192 _____ C:\Users\Craig\Desktop\Rkill.txt 2021-06-23 13:24 - 2021-06-23 13:24 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\Craig\Downloads\rkill.exe 2021-06-23 13:22 - 2021-06-23 13:22 - 000000022 _____ C:\Users\Craig\Downloads\ESETPoweliksCleaner.exe_20210623.132259.2812.zip 2021-06-22 02:37 - 2021-06-22 02:37 - 000411752 _____ C:\WINDOWS\Minidump\062221-47765-01.dmp 2021-06-21 17:01 - 2021-06-21 17:01 - 000036629 _____ C:\Users\Craig\Downloads\FRST (1).txt 2021-06-21 16:57 - 2021-06-21 16:57 - 000095313 _____ C:\Users\Craig\Downloads\Addition (1).txt 2021-06-21 16:39 - 2021-06-21 16:44 - 000095313 _____ C:\Users\Craig\Downloads\Addition.txt 2021-06-21 16:35 - 2021-06-25 10:06 - 000026366 _____ C:\Users\Craig\Downloads\FRST.txt 2021-06-21 16:34 - 2021-06-25 10:06 - 000000000 ____D C:\FRST 2021-06-21 16:32 - 2021-06-21 16:32 - 002300416 _____ (Farbar) C:\Users\Craig\Downloads\FRST64.exe 2021-06-21 13:27 - 2021-06-21 13:28 - 000363240 _____ C:\WINDOWS\Minidump\062121-27500-01.dmp 2021-06-21 13:26 - 2021-06-21 13:26 - 000000000 _____ C:\WINDOWS\Minidump\062121-32890-01.dmp 2021-06-21 05:43 - 2021-06-21 05:43 - 000000000 ___HD C:\$SysReset 2021-06-20 19:56 - 2021-06-20 19:56 - 000564320 _____ (ESET) C:\Users\Craig\Downloads\ESETPoweliksCleaner.exe 2021-06-20 19:56 - 2021-06-20 19:56 - 000000022 _____ C:\Users\Craig\Downloads\ESETPoweliksCleaner.exe_20210620.195659.5016.zip 2021-06-19 16:57 - 2019-08-30 01:45 - 000835480 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2021-06-19 16:57 - 2019-08-30 01:45 - 000179816 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2021-06-19 16:46 - 2021-06-19 16:46 - 000003380 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2021-06-19 16:46 - 2021-06-19 16:46 - 000003252 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2021-06-19 16:46 - 2021-06-19 16:46 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2021-06-19 16:46 - 2021-06-19 16:46 - 000002213 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2021-06-19 16:46 - 2021-06-19 16:46 - 000002213 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk 2021-06-19 15:55 - 2021-06-19 15:55 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys 2021-06-19 15:55 - 2021-06-19 15:55 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys 2021-06-19 15:55 - 2021-06-19 15:55 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys 2021-06-19 15:55 - 2021-06-19 15:55 - 000044328 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe 2021-06-19 03:06 - 2021-06-25 08:15 - 000000000 ____D C:\Users\Craig\AppData\LocalLow\IGDump 2021-06-18 22:25 - 2021-06-21 10:50 - 000220752 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys 2021-06-18 22:25 - 2021-06-18 22:25 - 000001947 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk 2021-06-18 22:24 - 2021-06-24 07:08 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2021-06-18 20:16 - 2021-06-21 05:25 - 000220872 _____ C:\WINDOWS\ntbtlog.txt 2021-06-18 18:33 - 2021-06-18 18:33 - 002646176 _____ C:\Users\Craig\Downloads\ProcessExplorer (1).zip 2021-06-18 18:27 - 2021-06-18 18:31 - 000000000 ____D C:\Users\Craig\AppData\Local\WinZip 2021-06-18 18:27 - 2021-06-18 18:27 - 000003530 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 2 2021-06-18 18:27 - 2021-06-18 18:27 - 000003528 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 3 2021-06-18 18:27 - 2021-06-18 18:27 - 000003528 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 1 2021-06-18 18:27 - 2021-06-18 18:27 - 000002001 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip.lnk 2021-06-18 18:27 - 2021-06-18 18:27 - 000001901 _____ C:\Users\Public\Desktop\WinZip.lnk 2021-06-18 18:27 - 2021-06-18 18:27 - 000001901 _____ C:\ProgramData\Desktop\WinZip.lnk 2021-06-18 18:27 - 2021-06-18 18:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 2021-06-18 18:26 - 2021-06-18 18:27 - 000000000 ____D C:\Program Files\WinZip 2021-06-18 18:19 - 2021-06-18 18:19 - 002646176 _____ C:\Users\Craig\Downloads\ProcessExplorer.zip 2021-06-18 18:19 - 2021-06-18 18:19 - 000977344 _____ (WinZip Computing) C:\Users\Craig\Downloads\winzip25-p003.exe 2021-06-18 16:57 - 2021-06-18 16:57 - 000000000 ____D C:\Users\Craig\AppData\Local\mbamtray 2021-06-18 16:57 - 2021-06-18 16:57 - 000000000 ____D C:\Users\Craig\AppData\Local\mbam 2021-06-18 16:56 - 2021-06-18 22:25 - 000001935 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2021-06-18 16:56 - 2021-06-18 22:25 - 000001935 _____ C:\ProgramData\Desktop\Malwarebytes.lnk 2021-06-18 16:56 - 2021-06-18 22:23 - 000199128 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 2021-06-18 16:56 - 2021-06-18 16:56 - 000000000 ____D C:\Program Files\Malwarebytes 2021-06-18 16:55 - 2021-06-18 16:55 - 000000000 ____D C:\ProgramData\MB2Migration 2021-06-18 01:48 - 2021-06-18 01:48 - 000411712 _____ C:\WINDOWS\Minidump\061821-51171-01.dmp 2021-06-18 01:45 - 2021-06-18 01:45 - 000000000 ____D C:\Program Files (x86)\CTH3VNU8KZHDXY6YYCF9YV8OXGPW3P2APZPL ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2021-06-25 09:49 - 2017-09-27 12:27 - 000000000 ____D C:\Users\Craig\Documents\Outlook Files 2021-06-25 09:37 - 2017-08-31 19:01 - 000000554 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-3289921415-534489958-369683985-1002.job 2021-06-25 09:08 - 2018-02-22 11:07 - 000000922 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job 2021-06-25 08:18 - 2017-08-31 19:01 - 000000650 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-3289921415-534489958-369683985-1002.job 2021-06-25 08:15 - 2016-04-26 14:02 - 000000000 ____D C:\Users\Craig\AppData\Local\CrashDumps 2021-06-25 07:57 - 2012-07-26 09:59 - 000000000 ____D C:\WINDOWS\CbsTemp 2021-06-25 07:04 - 2014-11-05 12:48 - 000000000 ___DO C:\Users\Craig\OneDrive 2021-06-25 07:00 - 2018-02-22 11:07 - 000000918 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job 2021-06-25 06:59 - 2014-09-24 09:20 - 000908172 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2021-06-25 06:59 - 2013-08-22 15:36 - 000000000 ____D C:\WINDOWS\Inf 2021-06-25 06:55 - 2018-03-29 10:30 - 000000000 ____D C:\ProgramData\NVIDIA 2021-06-25 06:55 - 2013-08-22 16:45 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2021-06-25 02:29 - 2013-08-22 15:25 - 000262144 ___SH C:\WINDOWS\system32\config\BBI 2021-06-25 00:51 - 2014-10-02 17:03 - 000000000 ____D C:\Program Files (x86)\Steam 2021-06-24 19:12 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\system32\NDF 2021-06-24 18:52 - 2014-11-05 13:00 - 000003596 _____ C:\WINDOWS\system32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3289921415-534489958-369683985-1002 2021-06-24 18:22 - 2018-02-22 11:07 - 000000000 ____D C:\Program Files (x86)\Dropbox 2021-06-24 18:03 - 2018-02-22 11:07 - 000003894 _____ C:\WINDOWS\system32\Tasks\DropboxUpdateTaskMachineUA 2021-06-24 18:03 - 2018-02-22 11:07 - 000003658 _____ C:\WINDOWS\system32\Tasks\DropboxUpdateTaskMachineCore 2021-06-24 07:19 - 2014-01-09 13:26 - 000000000 ____D C:\Users\Craig\AppData\Local\Packages 2021-06-22 02:37 - 2015-05-29 12:02 - 000000000 ____D C:\WINDOWS\Minidump 2021-06-22 02:36 - 2015-05-29 12:02 - 530907073 _____ C:\WINDOWS\MEMORY.DMP 2021-06-20 23:51 - 2014-12-30 13:54 - 000000000 ____D C:\Users\Craig\AppData\Local\ElevatedDiagnostics 2021-06-20 20:20 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\rescache 2021-06-19 16:56 - 2013-08-22 16:44 - 000481832 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2021-06-19 16:49 - 2015-04-15 01:39 - 000000000 ____D C:\WINDOWS\system32\appraiser 2021-06-19 16:49 - 2014-09-24 11:58 - 000000000 ___SD C:\WINDOWS\system32\CompatTel 2021-06-19 16:49 - 2013-08-22 17:36 - 000000000 ___RD C:\WINDOWS\ToastData 2021-06-19 16:49 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2021-06-19 16:49 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\system32\setup 2021-06-19 16:49 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\system32\inetsrv 2021-06-19 16:49 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2021-06-19 16:49 - 2013-08-22 17:36 - 000000000 ____D C:\Program Files\Windows Defender 2021-06-19 16:49 - 2013-08-22 17:36 - 000000000 ____D C:\Program Files\Common Files\System 2021-06-19 16:49 - 2013-08-22 15:36 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2021-06-19 16:49 - 2013-08-22 15:36 - 000000000 ____D C:\WINDOWS\system32\oobe 2021-06-19 16:49 - 2013-08-22 15:36 - 000000000 ____D C:\WINDOWS\system32\Dism 2021-06-19 16:36 - 2017-09-27 12:04 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2021-06-19 16:25 - 2014-10-03 11:11 - 000000000 ____D C:\WINDOWS\system32\MRT 2021-06-19 16:20 - 2014-10-03 11:11 - 132447432 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2021-06-19 16:18 - 2012-07-26 07:26 - 000000199 _____ C:\WINDOWS\win.ini 2021-06-18 23:09 - 2017-09-05 12:56 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IIS 2021-06-18 18:28 - 2017-07-12 20:42 - 000000000 ____D C:\ProgramData\WinZip 2021-06-18 16:56 - 2016-04-04 22:36 - 000000000 ____D C:\ProgramData\Malwarebytes 2021-06-18 16:56 - 2016-04-04 22:36 - 000000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2021-06-18 01:49 - 2014-11-05 12:30 - 000000000 ____D C:\Users\Craig 2021-06-18 01:48 - 2015-03-11 21:22 - 000073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\sens.dll 2021-06-17 22:09 - 2018-07-10 19:20 - 000002255 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2021-06-15 10:45 - 2014-10-02 15:47 - 000000000 ____D C:\Users\Craig\AppData\Roaming\Nitro PDF 2021-06-15 10:03 - 2018-08-29 13:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2021-06-11 12:27 - 2017-09-04 11:54 - 000002090 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2021-06-04 19:20 - 2018-11-21 16:58 - 000000000 ____D C:\Users\Craig\Desktop\Recipes 2021-05-31 22:49 - 2015-11-17 01:35 - 000000000 ____D C:\Users\Craig\AppData\Local\Ubisoft Game Launcher 2021-05-31 22:48 - 2015-11-17 01:09 - 000000000 ____D C:\Users\Craig\AppData\Roaming\Might & Magic Heroes VI 2021-05-29 18:40 - 2017-08-31 19:01 - 000003648 _____ C:\WINDOWS\system32\Tasks\G2MUploadTask-S-1-5-21-3289921415-534489958-369683985-1002 2021-05-29 18:40 - 2017-08-31 19:01 - 000003552 _____ C:\WINDOWS\system32\Tasks\G2MUpdateTask-S-1-5-21-3289921415-534489958-369683985-1002 2021-05-29 18:40 - 2017-08-31 19:01 - 000000000 ____D C:\Users\Craig\AppData\Local\GoToMeeting ==================== Files in the root of some directories ======== 2015-04-02 15:35 - 2018-03-13 21:20 - 000007600 _____ () C:\Users\Craig\AppData\Local\resmon.resmoncfg ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) LastRegBack: 2021-06-25 08:40 ==================== End of FRST.txt ========================