Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all articles
Browse latest Browse all 2798

Lost Admin control in normal boot

$
0
0
When I hit control+alt+delete then click task manager nothing shows up. I just updated skype and it said I had a ShellExecuteEX failed; code 5. Access denied.
A lot of control panel functions don't work such as creating a new user.

This also appears when i try to uninstall anything.

https://cdn.discordapp.com/attachmen...39/unknown.png
https://cdn.discordapp.com/attachmen...41/unknown.png

What have I tried thus far:
1. Running in Safe mode (installing and uninstalling is fine) but I still cant create a new user.
2. In safe mode I tried deleting homegroupuser $ it got deleted then I set my account to admin nothing.
3. Through CMD i tried to give my self admin by
net localgroup administrators [username] /add It said the account was already admin.
4.Thought it was a SSD issue but Samsung Magician shows the my ssd is healthy.


So currently im stumped on what to do and i just want to be able to install stuff normally and hit control alt delete.
I also contemplated about playing with my registry but i have no idea what im doing.

This is my FRST Text

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-11-2019
Ran by Ruroka (administrator) on RUROKA-PC (MSI MS-7816) (14-11-2019 18:23:34)
Running from C:\Users\Ruroka\Desktop
Loaded Profiles: Ruroka (Available Profiles: Ruroka)
Platform: Windows 10 Pro Version 1809 17763.864 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Safe Mode (minimal)
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1910.4-0\MsMpEng.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [17406072 2017-01-23] (Logitech Inc -> Logitech Inc.)
HKLM-x32\...\Run: [USB3MON] => "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [1047536 2013-11-12] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) [File not signed]
HKLM-x32\...\Run: [Sound Blaster Z-Series Control Panel] => C:\Program Files (x86)\Creative\Sound Blaster Z-Series\Sound Blaster Z-Series Control Panel\SBZ.exe [877056 2014-11-24] (Creative Technology Ltd) [File not signed]
HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\Live Update.exe [3476432 2014-09-18] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star International)
HKLM-x32\...\Run: [Corsair laver] => C:\Program Files (x86)\Corsair\K90 Keyboard\K90Hid.exe [1780736 2013-06-05] (Corsair Components Inc) [File not signed]
HKLM-x32\...\Run: [Command Center] => C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe [797648 2014-09-02] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-523977749-2779465332-2768229729-1000\...\Run: [DisplayFusion] => C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [10531216 2019-05-22] (Binary Fortress Software Ltd. -> Binary Fortress Software)
HKU\S-1-5-21-523977749-2779465332-2768229729-1000\...\Run: [Discord] => C:\Users\Ruroka\AppData\Local\Discord\app-0.0.305\Discord.exe [81780056 2019-03-07] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-523977749-2779465332-2768229729-1000\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [83524968 2019-11-12] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-523977749-2779465332-2768229729-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [25624208 2017-11-10] (Google Inc -> Google)
HKU\S-1-5-21-523977749-2779465332-2768229729-1000\...\Run: [SideSync] => C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe [12476064 2019-01-11] (Samsung Electronics CO., LTD. -> )
HKU\S-1-5-21-523977749-2779465332-2768229729-1000\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe [577568 2019-11-01] (Mozilla Corporation -> Mozilla Corporation)
HKU\S-1-5-21-523977749-2779465332-2768229729-1000\...\RunOnce: [Application Restart #1] => C:\Users\Ruroka\AppData\Roaming\BitTorrent Sync\BTSync.exe [8957432 2016-06-11] (BitTorrent Inc -> BitTorrent, Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2014-09-20]
ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{A003678C-C125-49A0-90D0-99AE485F6F92}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Qualcomm Atheros, Inc. -> Flexera Software LLC)
Startup: C:\Users\Ruroka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2016-04-03]
ShortcutTarget: MEGAsync.lnk -> C:\Users\Ruroka\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited -> Mega Limited)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {00EE5BCF-2954-47CE-99DD-46FCEE2F55D2} - System32\Tasks\{357B38DB-93A0-439B-9E6B-664F7BCDD421} => C:\Users\Ruroka\AppData\Local\Google\Chrome SxS\Application\chrome.exe
Task: {085DCD39-40AE-4132-918C-7745400FD388} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-523977749-2779465332-2768229729-1000 => C:\Users\Ruroka\AppData\Local\MEGAsync\MEGAupdater.exe [615160 2019-09-16] (Mega Limited -> Mega Limited)
Task: {0B2830DA-77CE-4701-B075-496820F9D13A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-523977749-2779465332-2768229729-1000UA1d4e98351ffb88f => C:\Users\Ruroka\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {0F9EBBE9-ECF4-462C-8F88-487C44D19249} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4f47-879B-29A80C355D61}
Task: {11697F07-BFCB-4B9C-A6D7-3E1A3794569A} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {1248D05A-D126-4C26-B441-19B3D99E9A74} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {1697D9A9-4DB3-46C9-9972-F29CE24C4724} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {175D7E0E-0523-4680-81BD-9E7F349C0496} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [913448 2019-09-05] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {17B40C1E-D431-4C56-81DA-2571F861192C} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {181CDB50-F085-4DAD-98D2-FE2F2B5D0730} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-523977749-2779465332-2768229729-1000Core => C:\Users\Ruroka\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {21CA6B4E-0734-4A34-8329-9EC0E5AF3822} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {27FF32A9-40D4-43D5-B595-C9B3DD29E3F9} - System32\Tasks\{0B1433D4-52E2-4B87-9646-10A86A95B04D} => C:\Windows\system32\pcalua.exe -a "F:\OtherDriver\Intel SCT\Setup.exe" -d "F:\OtherDriver\Intel SCT" -c -s
Task: {28CC40EC-A364-4F45-B1F6-E919C18E13B6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-28] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {32228845-642A-42ED-9651-4FFAC4D3295B} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43da-BFD7-FBEEA2180A1E}
Task: {3260707E-D6E1-44DF-A7DF-259FF1CE0408} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_293_Plugin.exe [1457720 2019-11-13] (Adobe Inc. -> Adobe)
Task: {3C9A1CB9-EF05-496F-94B8-DE5144DE7B55} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [860016 2019-08-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {3E95D310-F90B-4B3F-AECD-96A1440C5467} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe
Task: {4308D76F-681C-4A44-A093-6201DF04A96F} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47c2-B62A-B7C4CED925CB}
Task: {48D54752-8763-46CF-871A-7037A9713DB5} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {4FD3E128-B3CB-4768-9CA3-3407D15B7B45} - System32\Tasks\{A7ECDD8E-163B-4080-8013-74C5B930B5C8} => E:\Pictures\New folder\107GRJ518\AR107518\’´š’s—ƒƒCƒhI\’´š’s—ƒƒCƒhI.exe
Task: {54608EC6-227C-44A1-8D64-486DEB215C44} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133608 2019-09-05] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {55472654-3F97-4D9C-BF53-ECB8ADB868D6} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A}
Task: {5B9FB43B-C9B8-4B00-8F64-877544D60542} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-28] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {5C97205E-D548-4E1F-B4BF-7122FC00887D} - System32\Tasks\{4D457424-9597-417F-BFC5-964A92584C52} => E:\Pictures\New folder\107GRJ518\AR107518\’´š’s—ƒƒCƒhI\’´š’s—ƒƒCƒhI.exe
Task: {5DAD3E10-D7FF-4D35-B47C-B38FD4DD1F1B} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {5E2884C6-2F08-48DD-9EE2-858CF1C4CAEC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-11-14] (Adobe Inc. -> Adobe)
Task: {601EACC1-C817-4D96-8895-2B2417A32EFC} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_293_pepper.exe [1453112 2019-11-14] (Adobe Inc. -> Adobe)
Task: {61130889-A8EE-48EE-8211-FDBC789EBB05} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6954D200-EF23-449C-B22A-4994A57455A8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {6ED36A8E-6223-45EA-86E0-ADFFCAFA3E57} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {70C18FE4-56EF-4287-9252-4A3276F7CEA0} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [653864 2019-09-05] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {710E2045-D781-4EE2-9A00-A433D4741946} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-28] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {716FA15C-C98D-4F10-9A49-09203D7C2543} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133608 2019-09-05] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {751E0B50-2FCB-484B-BE8F-338FC0E747E9} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {7CD73CCE-2BFD-4D66-8DFA-5AFBA4A28F3D} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133608 2019-09-05] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8141FDD3-A2D3-4653-99D5-7171CCE0755A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {829472A6-AEFA-4419-9131-74932A3FDFFD} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133608 2019-09-05] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {82EB0C70-1076-4782-A6E2-6D651CD76CFF} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8546CDCD-914D-48C1-986E-8136EBD3F9B4} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3310688 2019-09-05] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8BB54FBC-AD81-4E4D-8B96-3B7A60098F9E} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8DD6ABA4-000C-4C4C-8BCC-51F012E39ADE} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8F7B2DFB-4A38-4547-9CD4-5B6A341DB3F0} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [860016 2019-08-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8F935865-5E98-41EF-AE17-25C642820861} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung Magician\SamsungMagician.exe [1112576 2017-05-19] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co. Ltd.)
Task: {9ED66EB6-4864-4909-A89E-76F324855657} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [913448 2019-09-05] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A2B37E01-1D7B-4718-BEAF-36F090654506} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-523977749-2779465332-2768229729-1000UA => C:\Users\Ruroka\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {A7B521C3-D8A0-45F7-9114-FCA7B78E830C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-523977749-2779465332-2768229729-1000Core1d2bfa4af82c662 => C:\Users\Ruroka\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {A7F1DA23-8EFF-47B3-83B8-7E4C86E566A7} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {AB6816BA-BA7D-4B2E-A3A1-247BA7A23E1E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-28] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40b4-8963-D3C761B18371}
Task: {B4534181-D4FA-4972-BC4E-8F2B9525872A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {CAF0C645-90CD-4B83-9B50-F9CCA7C814A1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-523977749-2779465332-2768229729-1000UA1d2bfa4af88b9e9 => C:\Users\Ruroka\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {CCD0523A-7F87-43E5-B9DD-9EEA812C3AA1} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {CDB36BA8-2BFA-48B3-BE45-21F906B0A658} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDfE067B1}
Task: {CF2D052B-277E-41B8-B35D-44A39D0D6D3C} - System32\Tasks\GPU Tweak II => C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe [6528464 2016-09-01] (ASUSTeK Computer Inc. -> TODO: <Company name>)
Task: {D0B327F0-4576-42BA-A809-CF4D6CEF9F0C} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {D54539D2-8A68-47E2-A833-287D09522E33} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {DBA55EB1-1638-4500-AA73-6AF58730B868} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {E19A8845-D654-49CB-A4DC-D52F782B9299} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E3F5009F-EF9D-4114-8C14-000FD03EB847} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-523977749-2779465332-2768229729-1000Core1d4e98351fbe860 => C:\Users\Ruroka\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {E985C37E-6855-473F-B938-73FFE00821B3} - System32\Tasks\Start Sync on startup => C:\Users\Ruroka\AppData\Roaming\BitTorrent Sync\BTSync.exe [8957432 2016-06-11] (BitTorrent Inc -> BitTorrent, Inc.)
Task: {EF18DEDD-3F5C-418E-B0C1-D32EC99F31EF} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {F0BC4C3D-F35E-4129-A406-3A8BC62AD8C0} - System32\Tasks\BlueStacksHelper => T:\BlueStacks\Client\Helper\BlueStacksHelper.exe [745480 2019-04-16] (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
Task: {F28B1D7E-EFD5-4A89-9D04-799C756BBA1C} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{A8049358-7C1D-48B4-B0D0-941A5B516735}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\ssv.dll [2018-05-11] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-05-11] (Oracle America, Inc. -> Oracle Corporation)
DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} hxxp://files.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - No File
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll No File

FireFox:
========
FF DefaultProfile: ft2tkp33.default-1434340142524-1506826299583
FF ProfilePath: C:\Users\Ruroka\AppData\Roaming\Mozilla\Firefox\Profiles\ft2tkp33.default-1434340142524-1506826299583 [2019-11-14]
FF DownloadDir: C:\Users\Ruroka\Desktop
FF Session Restore: Mozilla\Firefox\Profiles\ft2tkp33.default-1434340142524-1506826299583 -> is enabled.
FF Extension: (Firefox Lockwise) - C:\Users\Ruroka\AppData\Roaming\Mozilla\Firefox\Profiles\ft2tkp33.default-1434340142524-1506826299583\Extensions\lockbox@mozilla.com.xpi [2019-08-12] [UpdateUrl:hxxps://lockwise.firefox.com/addon/updates.json]
FF Extension: (Create a new script) - C:\Users\Ruroka\AppData\Roaming\Mozilla\Firefox\Profiles\ft2tkp33.default-1434340142524-1506826299583\Extensions\{aecec67f-0d10-4fa7-b7c7-609a2db280cf}.xpi [2019-11-07]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\Ruroka\AppData\Roaming\Mozilla\Firefox\Profiles\ft2tkp33.default-1434340142524-1506826299583\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-10-23]
FF Plugin: @Adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_293.dll [2019-11-13] (Adobe Inc. -> )
FF Plugin-x32: @Adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_293.dll [2019-11-13] (Adobe Inc. -> )
FF Plugin-x32: @Intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @Intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @Java.com/DTPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-05-11] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @Java.com/JavaPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-05-11] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [No File]

Chrome:
=======
CHR DefaultProfile: Profile 1
CHR Session Restore: Profile 1 -> is enabled.
CHR Profile: C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default [2019-04-02]
CHR Extension: (BetterTTV) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2018-08-15]
CHR Extension: (Docs) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-22]
CHR Extension: (Google Drive) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-22]
CHR Extension: (YouTube) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-22]
CHR Extension: (uBlock Origin) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2019-03-31]
CHR Extension: (Granblue Faggotry) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\dofpehnfogbkhlllbkiiokkgahoaakla [2018-01-24]
CHR Extension: (グランブルーファンタジー[ChromeApps版]) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\eablgejicbklomgaiclcolfilbkckngf [2018-08-15]
CHR Extension: (Sheets) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-22]
CHR Extension: (Viramate) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgpokpknehglcioijejfeebigdnbnokj [2019-03-27]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2018-08-15]
CHR Extension: (Granblue Fantasy1) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfaedihknneehpabpeooalmfneonjncf [2018-01-22]
CHR Extension: (LINE) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\menkifleemblimdogmoihpfopnplikde [2018-03-08]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Granblue UI Mod) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\oldabbgalcibkledioddbmgekdolimhh [2018-04-19]
CHR Extension: (Gmail) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-22]
CHR Extension: (Chrome Media Router) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-08-15]
CHR Profile: C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Guest Profile [2018-09-03]
CHR Profile: C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 1 [2019-10-29]
CHR Extension: (Slides) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-24]
CHR Extension: (Docs) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-24]
CHR Extension: (Google Drive) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-24]
CHR Extension: (YouTube) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-24]
CHR Extension: (Sheets) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-24]
CHR Extension: (Viramate) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fgpokpknehglcioijejfeebigdnbnokj [2019-03-26]
CHR Extension: (VideoCast (VLC/Chromecast)) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gclhodkofgoighinmongpkpncdpalejb [2018-10-13]
CHR Extension: (Google Docs Offline) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Gmail) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-29]
CHR Extension: (Chrome Media Router) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-09-23]
CHR Profile: C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 2 [2018-09-03]
CHR Extension: (Slides) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-24]
CHR Extension: (Docs) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-24]
CHR Extension: (Google Drive) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-24]
CHR Extension: (YouTube) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-24]
CHR Extension: (Sheets) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-24]
CHR Extension: (Viramate) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\fgpokpknehglcioijejfeebigdnbnokj [2018-04-06]
CHR Extension: (Google Docs Offline) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-06]
CHR Extension: (Gmail) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-24]
CHR Extension: (Chrome Media Router) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-06]
CHR Profile: C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 3 [2018-09-03]
CHR Extension: (Slides) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-24]
CHR Extension: (Docs) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-24]
CHR Extension: (Google Drive) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-24]
CHR Extension: (YouTube) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-24]
CHR Extension: (Sheets) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-24]
CHR Extension: (Viramate) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\fgpokpknehglcioijejfeebigdnbnokj [2018-04-06]
CHR Extension: (Google Docs Offline) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-06]
CHR Extension: (Gmail) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-24]
CHR Extension: (Chrome Media Router) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-06]
CHR Profile: C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 4 [2018-09-03]
CHR Extension: (Slides) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-30]
CHR Extension: (Docs) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-30]
CHR Extension: (Google Drive) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-30]
CHR Extension: (YouTube) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-30]
CHR Extension: (Sheets) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-30]
CHR Extension: (Google Docs Offline) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-02-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-26]
CHR Extension: (Gmail) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-30]
CHR Extension: (Chrome Media Router) - C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-30]
CHR Profile: C:\Users\Ruroka\AppData\Local\Google\Chrome\User Data\System Profile [2018-09-03]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8404720 2019-10-22] (BattlEye Innovations e.K. -> )
S2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe [71512 2017-11-02] (Google Inc -> Google Inc.)
S3 Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [79360 2018-04-02] (Creative Labs) [File not signed]
S2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [423424 2012-10-08] (Creative Technology Ltd) [File not signed]
S2 CtHdaSvc; C:\WINDOWS\sysWow64\CtHdaSvc.exe [122880 2017-01-18] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd)
S2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [7037344 2019-05-22] (Binary Fortress Software Ltd. -> Binary Fortress Software)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [781440 2018-12-09] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel® Trusted Connect Service -> Intel(R) Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation)
S2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [225400 2017-01-23] (Logitech Inc -> Logitech Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
S3 MSIBIOSData_CC; C:\Program Files (x86)\MSI\Command Center\BIOSData\MSIBIOSDataService.exe [2100736 2014-06-04] (MSI) [File not signed]
S3 MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe [4026368 2014-06-06] (MSI) [File not signed]
S3 MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\MSICommService.exe [2118144 2014-07-28] () [File not signed]
S3 MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe [4156928 2014-08-27] () [File not signed]
S2 MSICTL_CC; C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe [1992192 2014-08-19] () [File not signed]
S3 MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe [2242560 2014-09-01] () [File not signed]
S3 MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe [2063360 2014-07-28] () [File not signed]
S3 MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe [550400 2014-08-13] () [File not signed]
S2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [1723856 2014-09-18] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star International)
S2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [161776 2013-09-09] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [30240 2013-09-26] (MICRO-STAR INTERNATIONAL CO., LTD. -> MICRO-STAR INTERNATIONAL CO., LTD.)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3916368 2016-01-09] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
S2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [860016 2019-08-27] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [860016 2019-08-27] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Origin Client Service; O:\New folder\New folder\Origin\OriginClientService.exe [2425136 2019-11-12] (Electronic Arts, Inc. -> Electronic Arts)
S2 Origin Web Helper Service; O:\New folder\New folder\Origin\OriginWebHelperService.exe [3303736 2019-11-12] (Electronic Arts, Inc. -> Electronic Arts)
S3 PAExec; C:\Windows\PAExec.exe [189112 2017-01-27] (Power Admin LLC -> Power Admin LLC)
S2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [340480 2013-09-11] (Qualcomm Atheros) [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5378320 2019-10-03] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2017-01-16] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
S2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12054872 2019-10-10] (TeamViewer GmbH -> TeamViewer GmbH)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\NisSrv.exe [3201616 2019-10-28] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MsMpEng.exe [103168 2019-10-28] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-11-08] (AVG Technologies -> AVG Technologies)
S1 BfLwf; C:\WINDOWS\system32\DRIVERS\bflwfx64.sys [67888 2013-02-13] (Qualcomm Atheros, Inc. -> Qualcomm Atheros, Inc.)
S2 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv.sys [313112 2019-10-16] (Bluestack Systems, Inc. -> Bluestack System Inc. )
R3 CORSGKB; C:\WINDOWS\system32\drivers\CORSGKB.sys [25600 2012-03-27] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 cthda; C:\WINDOWS\system32\drivers\cthda.sys [1074984 2017-01-18] (Creative Technology Ltd -> Creative Technology Ltd)
S3 cthdb; C:\WINDOWS\system32\DRIVERS\cthdb.sys [42792 2017-01-18] (Creative Technology Ltd -> Creative Technology Ltd)
S3 EvolveVirtualAdapter; C:\WINDOWS\System32\DRIVERS\evolve.sys [21656 2015-02-11] (Echobit, LLC -> Echobit, LLC)
S3 ipadtst; C:\Program Files (x86)\MSI\Super-Charger\ipadtst_64.sys [20464 2013-11-11] (MICRO-STAR INTERNATIONAL CO., LTD. -> Windows (R) Win 7 DDK provider)
R3 ISCT; C:\WINDOWS\System32\drivers\ISCTD64.sys [47008 2016-07-26] (Intel(R) Smart Connect software -> )
S3 KillerEth; C:\WINDOWS\System32\drivers\e2xw10x64.sys [145920 2018-09-15] (Microsoft Windows -> Qualcomm Atheros, Inc.)
S2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech -> Logitech)
R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2017-01-23] (Logitech Inc -> Logitech Inc.)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-06-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [275232 2019-11-14] (Malwarebytes Corporation -> Malwarebytes)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation)
S3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [14136 2010-10-22] (Micro-Star Int'l Co. Ltd. -> MSI)
S3 NTIOLib_MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\NTIOLib_X64.sys [13368 2012-11-20] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 NTIOLib_MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\NTIOLib_X64.sys [13368 2012-11-19] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 NTIOLib_MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\NTIOLib_X64.sys [13368 2012-11-20] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 NTIOLib_MSIFrequency_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\CPU_Frequency\NTIOLib_X64.sys [13368 2012-11-20] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 NTIOLib_MSIRatio_CC; C:\Program Files (x86)\MSI\Command Center\CPU\CPU_Ratio\NTIOLib_X64.sys [13368 2012-11-20] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\NTIOLib_X64.sys [13368 2012-11-19] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 NTIOLib_MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\NTIOLib_X64.sys [13368 2012-11-19] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_830a0263f2ee97ce\nvlddmkm.sys [22370696 2019-09-06] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30336 2019-07-23] (NVIDIA Corporation -> NVIDIA Corporation)
S3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [69840 2019-04-17] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [75600 2019-09-05] (NVIDIA Corporation -> NVIDIA Corporation)
R3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
S3 VBAudioVMAUXVAIOMME; C:\WINDOWS\system32\DRIVERS\vbaudio_vmauxvaio64_win7.sys [41192 2017-09-01] (Vincent Burel -> Windows (R) Win 7 DDK provider)
S3 VBAudioVMVAIOMME; C:\WINDOWS\system32\DRIVERS\vbaudio_vmvaio64_win7.sys [41192 2017-09-01] (Vincent Burel -> Windows (R) Win 7 DDK provider)
S1 VBoxUSBMon; C:\WINDOWS\System32\DRIVERS\VBoxUSBMon.sys [127432 2015-09-16] (Duodian Online Technology Co. Ltd. -> BigNox Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46472 2019-10-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [351968 2019-10-28] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [53984 2019-10-28] (Microsoft Windows -> Microsoft Corporation)
R3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [63840 2015-06-06] (Intel(R) Software -> Intel Corporation)
S1 YSDrv; C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [310536 2019-10-17] (Beijing Duodian Online Science and Technology Co.,Ltd -> BigNox Corporation)
S3 GPUZ; \??\C:\Users\Ruroka\AppData\Local\Temp\GPUZ.sys [X] <==== ATTENTION
U3 idsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-11-14 18:20 - 2019-11-14 18:21 - 000132305 _____ C:\Users\Ruroka\Desktop\Addition.txt
2019-11-14 18:19 - 2019-11-14 18:23 - 000042663 _____ C:\Users\Ruroka\Desktop\FRST.txt
2019-11-14 18:19 - 2019-11-14 18:23 - 000000000 ____D C:\FRST
2019-11-14 18:18 - 2019-11-14 18:18 - 000275232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2019-11-14 18:14 - 2019-11-14 18:14 - 002260480 _____ (Farbar) C:\Users\Ruroka\Desktop\FRST64.exe
2019-11-14 18:09 - 2019-11-14 18:09 - 000000218 _____ C:\Users\Ruroka\AppData\Local\recently-used.xbel
2019-11-14 17:25 - 2019-11-14 17:25 - 000000000 ____D C:\Users\Ruroka\AppData\Local\ElevatedDiagnostics
2019-11-14 16:51 - 2019-11-14 16:51 - 000000000 ____D C:\Users\Ruroka\Desktop\New folder
2019-11-14 16:47 - 2019-11-14 18:18 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2019-11-14 16:47 - 2019-11-14 16:49 - 000000024 _____ C:\Users\Ruroka\Desktop\DiskInfo.ini
2019-11-14 16:41 - 2019-11-14 18:20 - 000910044 _____ C:\WINDOWS\ntbtlog.txt
2019-11-14 10:50 - 2019-11-12 19:20 - 005419576 _____ (Crystal Dew World) C:\Users\Ruroka\Desktop\DiskInfo64K.exe
2019-11-14 10:49 - 2019-11-14 10:49 - 048732624 _____ C:\Users\Ruroka\Desktop\CrystalDiskInfo8_3_2KureiKei.zip
2019-11-13 22:51 - 2019-11-14 08:54 - 004986936 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2019-11-12 17:54 - 2019-11-12 17:54 - 000000000 ____D C:\ProgramData\Ubisoft
2019-11-12 13:39 - 2019-11-12 13:39 - 023455232 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 022137120 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 019014144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 012960256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 012258816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 011724288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 009941504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 009667896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 007872000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 007700696 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 007656072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 007645392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 006934016 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 006547896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 006318328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 006065152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 005770240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 005608336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 005575168 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 005573232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 005436696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 004873216 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 004866560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AI.MachineLearning.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 004661760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 004413936 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 004303872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 004049920 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 003906560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 003872336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 003703296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 003656792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 003637760 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 003624448 _____ (Microsoft Corporation) C:\WINDOWS\system32\tellib.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 003576832 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 003550384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 003496448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AI.MachineLearning.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 003387392 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 003363640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 003333632 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 003082752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 002918200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 002871824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 002848768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 002765312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 002707968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 002699976 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 002698752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 002645504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 002628112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 002421248 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 002393600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 002348544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 002192384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 002109960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 002072176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 002050560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001994976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001966096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 001933408 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001929728 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001918792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001904128 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001751432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001726480 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001702600 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-11-12 13:39 - 2019-11-12 13:39 - 001677808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001674480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001668784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001668752 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001666440 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001644544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001608192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001538560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 001486472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001473296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 001465472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001346216 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-11-12 13:39 - 2019-11-12 13:39 - 001331536 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001294792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001291264 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001267240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2019-11-12 13:39 - 2019-11-12 13:39 - 001262592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001258512 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 001200920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001183504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 001180248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001098136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001054712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 001054224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 001050112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 001049608 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 001024712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 001022464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000948224 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\assignedaccessmanagersvc.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000927232 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000888560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000877568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000869888 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000862008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000856424 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000811536 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000808960 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000808272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000807424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000801792 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000782968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000775768 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000774144 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000773208 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000750592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000747536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000741688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000687104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000680184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000661264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000652088 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000642560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000638480 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000629248 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessManager.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000604344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000591160 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000590336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000588816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\csc.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000575488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000553784 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000548864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000547328 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000542320 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000536320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000535080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000520704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000514600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000509968 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000505640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000486400 _____ C:\WINDOWS\system32\AssignedAccessCsp.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000481280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000474936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2019-11-12 13:39 - 2019-11-12 13:39 - 000473832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000465416 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000462352 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000450632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000445752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000435512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000428032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000427832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000415760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000389408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000385848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000383288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000367104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000360960 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000350208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000324624 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000321024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComposableShellProxyStub.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000303104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000263360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000262152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000249856 _____ (Gracenote, Inc.) C:\WINDOWS\SysWOW64\gnsdk_fp.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2019-11-12 13:39 - 2019-11-12 13:39 - 000214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000213304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000201528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000193336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000180736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2019-11-12 13:39 - 2019-11-12 13:39 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\prntvpt.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\spacebridge.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000166400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spacebridge.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000164368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000160272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pacer.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AppExecutionAlias.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000152896 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComposableShellProxyStub.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_BackgroundApps.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000141736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prntvpt.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000138112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000132608 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tunnel.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000120352 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000118480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000112168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstSv.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinHvPlatform.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000105832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellExtFramework.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000090632 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000087080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhvr.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApiSetHost.AppExecutionAlias.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000086840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\npfs.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000086744 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskhostw.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000080400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2019-11-12 13:39 - 2019-11-12 13:39 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usp10.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usp10.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000071696 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CapabilityAccessManagerClient.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ApiSetHost.AppExecutionAlias.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000061480 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvhostsvc.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessRuntime.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwm.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000047616 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AssignedAccessRuntime.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\compact.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\compact.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000036368 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2019-11-12 13:39 - 2019-11-12 13:39 - 000023768 _____ (Microsoft Corporation) C:\WINDOWS\system32\nsi.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000020144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nsi.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2019-11-12 13:39 - 2019-11-12 13:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2019-11-12 13:39 - 2019-11-12 13:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2019-11-12 13:39 - 2019-11-12 13:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2019-11-12 13:39 - 2019-11-12 13:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2019-11-12 13:39 - 2019-11-12 13:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2019-11-12 13:39 - 2019-11-12 13:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2019-11-12 13:39 - 2019-11-12 13:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2019-11-12 13:39 - 2019-11-12 13:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2019-11-12 13:38 - 2019-11-12 13:38 - 000667664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2019-11-12 13:38 - 2019-11-12 13:38 - 000520208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys
2019-11-12 13:38 - 2019-11-12 13:38 - 000198968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spacedump.sys
2019-11-06 12:59 - 2019-11-06 12:59 - 000001010 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 14.lnk
2019-11-05 16:56 - 2019-11-07 21:35 - 000016586 _____ C:\Users\Ruroka\Desktop\KM coverletter.odt
2019-10-27 16:54 - 2019-10-27 16:54 - 001115213 _____ C:\Users\Ruroka\Downloads\410128_20191028_064520_226496212.mp4
2019-10-26 10:28 - 2019-10-26 10:32 - 000000000 ____D C:\ProgramData\HitmanPro
2019-10-26 10:28 - 2019-10-26 10:28 - 011539456 _____ (SurfRight B.V.) C:\Users\Ruroka\Downloads\HitmanPro_x64.exe
2019-10-26 10:25 - 2019-10-26 10:25 - 007622344 _____ (Malwarebytes) C:\Users\Ruroka\Downloads\AdwCleaner.exe
2019-10-26 10:11 - 2019-10-26 10:11 - 000000000 ____D C:\Users\Ruroka\AppData\Local\mbam
2019-10-26 10:10 - 2019-10-31 17:54 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2019-10-26 10:10 - 2019-10-26 10:10 - 000000000 ____D C:\Users\Ruroka\AppData\Local\mbamtray
2019-10-26 10:10 - 2019-10-26 10:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-10-26 10:10 - 2019-10-26 10:10 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-10-26 10:10 - 2019-10-26 10:10 - 000000000 ____D C:\Program Files\Malwarebytes
2019-10-26 10:10 - 2019-06-26 12:00 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2019-10-26 10:08 - 2019-10-26 10:08 - 064333800 _____ (Malwarebytes ) C:\Users\Ruroka\Downloads\mb3-setup-1878.1878-3.8.3.2965.exe
2019-10-26 10:07 - 2019-10-26 10:07 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\Ruroka\Downloads\rkill.exe
2019-10-24 10:43 - 2019-10-25 10:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MTG Arena
2019-10-17 18:54 - 2019-10-17 18:54 - 000003912 _____ C:\WINDOWS\system32\Tasks\BlueStacksHelper
2019-10-17 18:51 - 2019-10-17 18:51 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks.lnk
2019-10-17 18:51 - 2019-10-17 18:51 - 000001261 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks Multi-Instance Manager.lnk
2019-10-17 18:50 - 2019-10-17 18:50 - 000000000 ____D C:\Program Files\BlueStacks
2019-10-17 18:46 - 2019-10-17 18:50 - 000000000 ____D C:\Users\Ruroka\AppData\Local\BlueStacksSetup
2019-10-17 18:46 - 2019-10-17 18:50 - 000000000 ____D C:\Users\Public\BlueStacks
2019-10-17 18:45 - 2019-10-17 18:45 - 000938632 _____ (BlueStack Systems Inc.) C:\Users\Ruroka\Downloads\BlueStacksInstaller_4.140.11.1002_native_9a81f6a0e754ce0badb38ad1b4d11bf9.exe
2019-10-17 17:50 - 2019-11-04 12:12 - 000000000 ____D C:\Users\Ruroka\AppData\Local\NoxSrv
2019-10-17 17:50 - 2019-10-17 17:50 - 000000041 _____ C:\Users\Ruroka\inst.ini
2019-10-17 17:50 - 2019-10-17 17:50 - 000000000 ____D C:\Program Files (x86)\Bignox
2019-10-17 17:41 - 2019-10-17 17:41 - 000000000 ____D C:\WINDOWS\SysWOW64\ax0b.CIS
2019-10-17 17:41 - 2019-10-17 17:41 - 000000000 ____D C:\Users\Ruroka\AppData\Local\NoxInsPackFileder
2019-10-16 11:06 - 2019-10-16 11:06 - 063390528 _____ (Electronic Arts) C:\Users\Ruroka\Downloads\OriginThinSetup.exe

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-11-14 18:22 - 2019-02-15 09:49 - 000935300 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-11-14 18:22 - 2018-09-15 02:31 - 000000000 ____D C:\WINDOWS\INF
2019-11-14 18:17 - 2019-02-15 09:53 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-11-14 18:17 - 2018-09-15 01:09 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2019-11-14 18:17 - 2016-06-05 22:21 - 000000000 ____D C:\Users\Ruroka\AppData\Roaming\BitTorrent Sync
2019-11-14 18:09 - 2019-05-27 19:32 - 000000000 ____D C:\Users\Ruroka\AppData\Roaming\deluge
2019-11-14 17:43 - 2018-09-15 02:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-11-14 17:36 - 2017-01-01 01:57 - 000000000 ____D C:\Users\Ruroka\AppData\LocalLow\Mozilla
2019-11-14 17:35 - 2017-01-27 21:20 - 000000000 ____D C:\ProgramData\NVIDIA
2019-11-14 17:34 - 2019-02-15 09:53 - 000003248 _____ C:\WINDOWS\system32\Tasks\GPU Tweak II
2019-11-14 17:33 - 2014-09-21 01:11 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2019-11-14 16:49 - 2017-12-06 14:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2019-11-14 16:40 - 2019-02-15 09:50 - 000000000 ____D C:\Users\Ruroka
2019-11-14 16:21 - 2018-05-16 15:06 - 000000000 ____D C:\Users\Ruroka\AppData\Local\Ubisoft Game Launcher
2019-11-14 16:18 - 2014-09-21 07:10 - 000000000 ____D C:\Program Files (x86)\Samsung Magician
2019-11-14 16:05 - 2019-02-15 09:47 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-11-14 08:54 - 2019-02-15 09:53 - 000004530 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2019-11-14 08:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-11-14 08:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-11-13 22:51 - 2019-02-15 09:53 - 000004578 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player NPAPI Notifier
2019-11-13 21:52 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-11-13 19:54 - 2018-09-15 02:33 - 000000000 ___HD C:\Program Files\WindowsApps
2019-11-13 19:47 - 2019-02-16 00:58 - 000000000 ____D C:\Users\Ruroka\AppData\Roaming\Discord
2019-11-13 10:14 - 2014-09-20 21:06 - 000748816 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2019-11-13 10:04 - 2019-02-15 09:53 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-11-13 10:04 - 2019-02-15 09:53 - 000000000 ___RD C:\Users\Ruroka\3D Objects
2019-11-13 10:04 - 2018-05-01 18:05 - 000000000 ___RD C:\Users\Ruroka\Virtual Machines
2019-11-13 10:03 - 2019-02-15 09:47 - 000431464 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-11-12 23:44 - 2018-09-15 02:33 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2019-11-12 23:44 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2019-11-12 23:44 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-11-12 23:44 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-11-12 23:44 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-11-12 23:44 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2019-11-12 23:44 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-11-12 23:44 - 2018-09-15 01:09 - 000000000 ____D C:\WINDOWS\system32\Dism
2019-11-12 13:46 - 2014-09-21 00:33 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-11-12 13:40 - 2018-09-15 02:23 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-11-12 13:40 - 2014-09-21 00:33 - 128443096 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-11-10 22:42 - 2019-02-06 23:09 - 000000000 ____D C:\ProgramData\Origin
2019-11-10 18:21 - 2018-12-24 12:27 - 000000109 _____ C:\Users\Ruroka\Desktop\listen.pls
2019-11-10 18:19 - 2019-02-11 00:15 - 000000000 ____D C:\Users\Ruroka\AppData\Roaming\Origin
2019-11-06 13:53 - 2019-02-15 10:01 - 000000000 ____D C:\Users\Ruroka\AppData\Local\Comms
2019-11-06 13:52 - 2019-02-15 09:53 - 000000000 ____D C:\Users\Ruroka\AppData\Local\Packages
2019-11-06 12:59 - 2018-01-30 23:44 - 000000000 ____D C:\Users\Ruroka\AppData\Local\TeamViewer
2019-11-05 14:19 - 2019-04-02 13:38 - 000003712 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-523977749-2779465332-2768229729-1000UA1d4e98351ffb88f
2019-11-05 14:19 - 2019-04-02 13:38 - 000003444 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-523977749-2779465332-2768229729-1000Core1d4e98351fbe860
2019-11-04 12:15 - 2016-07-13 22:32 - 000000000 ____D C:\Users\Ruroka\AppData\Local\Nox
2019-11-04 12:12 - 2019-09-24 15:44 - 000000300 _____ C:\Users\Ruroka\d4ac4633ebd6440fa397b84f1bc94a3c.7z
2019-11-04 12:12 - 2019-06-07 16:06 - 000000000 ____D C:\Users\Ruroka\.BigNox
2019-11-04 12:12 - 2018-12-06 13:01 - 000000000 ____D C:\Users\Ruroka\vmlogs
2019-11-04 12:12 - 2016-08-19 09:01 - 000000000 ____D C:\Users\Ruroka\.android
2019-11-03 12:27 - 2014-12-26 18:19 - 000000000 ____D C:\Users\Ruroka\AppData\Local\DisplayFusion
2019-11-02 10:30 - 2017-12-02 21:55 - 000000000 ____D C:\Users\Ruroka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2019-11-02 09:55 - 2015-01-09 03:34 - 000000000 ____D C:\Users\Ruroka\AppData\Local\CrashDumps
2019-11-01 16:42 - 2019-02-15 10:10 - 000000000 ____D C:\ProgramData\Packages
2019-11-01 09:45 - 2017-08-08 07:34 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-11-01 09:45 - 2014-09-21 00:05 - 000001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-10-30 12:49 - 2019-07-18 12:13 - 000044042 _____ C:\Users\Ruroka\Desktop\Resume.pdf
2019-10-29 19:38 - 2014-09-20 11:33 - 000000000 ____D C:\Program Files (x86)\Google
2019-10-28 19:22 - 2019-02-15 09:53 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-10-27 09:01 - 2019-02-15 10:22 - 000000000 ____D C:\Users\Ruroka\AppData\Local\D3DSCache
2019-10-26 10:23 - 2014-11-08 01:39 - 000000258 __RSH C:\ProgramData\ntuser.pol
2019-10-26 10:10 - 2018-09-15 02:33 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2019-10-24 19:50 - 2017-06-05 17:19 - 000000000 ____D C:\Users\Ruroka\AppData\Roaming\discordptb
2019-10-24 11:28 - 2019-08-27 15:37 - 000039525 _____ C:\Users\Ruroka\Desktop\Cover Letter.pdf
2019-10-17 18:50 - 2016-04-21 21:42 - 000000000 ____D C:\Users\Ruroka\AppData\Local\BlueStacks
2019-10-17 17:50 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\Registration
2019-10-17 17:41 - 2019-03-10 13:36 - 000000070 _____ C:\Users\Ruroka\AppData\Local\update_progress.txt

==================== Files in the root of some directories ========

2016-03-31 21:46 - 2016-04-24 22:29 - 000001411 _____ () C:\Users\Ruroka\AppData\Roaming\.syncplay.log
2018-07-26 09:44 - 2018-09-28 23:12 - 000000134 _____ () C:\Users\Ruroka\AppData\Roaming\licecap.ini
2017-09-17 12:49 - 2017-09-17 12:56 - 000033882 _____ () C:\Users\Ruroka\AppData\Roaming\VoiceMeeterDefault.xml
2015-11-16 02:14 - 2015-11-16 02:14 - 001065984 _____ () C:\Users\Ruroka\AppData\Local\file__0.localstorage
2019-11-14 18:09 - 2019-11-14 18:09 - 000000218 _____ () C:\Users\Ruroka\AppData\Local\recently-used.xbel
2017-05-01 14:32 - 2017-05-01 14:32 - 000000017 _____ () C:\Users\Ruroka\AppData\Local\resmon.resmoncfg
2019-03-10 13:36 - 2019-10-17 17:41 - 000000070 _____ () C:\Users\Ruroka\AppData\Local\update_progress.txt

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Viewing all articles
Browse latest Browse all 2798

Trending Articles