Noticed my cursor jump around and restart the computer once yesterday. Also though I spotted some access to gmail from my computer while I was asleep from my computer. Not certain there is an issue.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-10-2017
Ran by frank (administrator) on LAPTOP-IQSLKOFV (07-10-2017 21:17:40)
Running from C:\Users\frank\Downloads
Loaded Profiles: frank (Available Profiles: frank)
Platform: Windows 10 Home Version 1703 (X64) Language: English (United Kingdom)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\igfxCUIService.exe
(HP) C:\Windows\System32\hpservice.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\IntelCpHDCPSvc.exe
(Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\IntelCpHeciSvc.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Trend Micro Inc.) C:\Program Files (x86)\Trend Micro\DRScanner\DRScanner.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\igfxEM.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\syswow64\wbem\WmiPrvSE.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11701.1001.87.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8900104 2016-09-09] (Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [253344 2017-10-07] (AVAST Software)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 192.168.1.254
Tcpip\..\Interfaces\{67c6456b-c7f8-4eb3-b087-c5123e077200}: [DhcpNameServer] 192.168.1.254 192.168.1.254
Internet Explorer:
==================
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-07] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-07] (Google Inc.)
Chrome:
=======
CHR Profile: C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default [2017-10-07]
CHR Extension: (Google Slides) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-07]
CHR Extension: (Google Docs) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-07]
CHR Extension: (Google Drive) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-10-07]
CHR Extension: (YouTube) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-10-07]
CHR Extension: (Google Sheets) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-07]
CHR Extension: (Google Docs Offline) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-10-07]
CHR Extension: (The Camelizer) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghnomdcacenbmilgjigehppbamfndblo [2017-10-07]
CHR Extension: (AdBlock) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-10-07]
CHR Extension: (History Eraser App) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjolhjmdgbhebcdnfjhngobjggghoipa [2017-10-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-10-07]
CHR Extension: (Click&Clean App) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2017-10-07]
CHR Extension: (Gmail) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-10-07]
CHR Extension: (Chrome Media Router) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-07]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7446024 2017-10-07] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [281416 2017-10-07] (AVAST Software)
R2 esifsvc; C:\WINDOWS\system32\Intel\DPTF\esif_uf.exe [2208888 2016-09-19] (Intel Corporation)
R2 hpsrv; C:\WINDOWS\system32\Hpservice.exe [38728 2016-10-12] (HP)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [317952 2016-09-09] (Realtek Semiconductor)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [278616 2017-08-18] (Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation)
R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 Accelerometer; C:\WINDOWS\System32\drivers\Accelerometer.sys [56128 2016-10-12] (HP)
R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [321032 2017-10-07] (AVAST Software s.r.o.)
R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [198976 2017-10-07] (AVAST Software s.r.o.)
R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [343288 2017-10-07] (AVAST Software s.r.o.)
R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [57736 2017-10-07] (AVAST Software s.r.o.)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [47008 2017-10-07] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [147776 2017-10-07] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [110376 2017-10-07] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [84416 2017-10-07] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1020536 2017-10-07] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [587168 2017-10-07] (AVAST Software)
R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [201352 2017-10-07] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [363440 2017-10-07] (AVAST Software)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [66624 2016-09-19] (Intel Corporation)
R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [350272 2016-09-19] (Intel Corporation)
R0 hpdskflt; C:\WINDOWS\System32\drivers\hpdskflt.sys [42312 2016-10-12] (HP)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [174600 2017-04-13] (Intel Corporation)
R1 klhk; C:\WINDOWS\System32\drivers\klhk.sys [522736 2017-10-07] (AO Kaspersky Lab)
R3 Netwtw04; C:\WINDOWS\system32\DRIVERS\Netwtw04.sys [7643648 2017-07-13] (Intel Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [943112 2016-08-05] (Realtek )
S3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [779232 2016-08-22] (Realsil Semiconductor Corporation)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [53848 2017-08-18] (Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [55384 2017-08-18] (Synaptics Incorporated)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [30368 2017-06-21] (HP)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-10-07 21:17 - 2017-10-07 21:17 - 002400768 _____ (Farbar) C:\Users\frank\Downloads\FRST64.exe
2017-10-07 21:17 - 2017-10-07 21:17 - 000011550 _____ C:\Users\frank\Downloads\FRST.txt
2017-10-07 21:17 - 2017-10-07 21:17 - 000000000 ____D C:\Users\frank\Downloads\FRST-OlderVersion
2017-10-07 21:17 - 2017-10-07 21:17 - 000000000 ____D C:\FRST
2017-10-07 12:25 - 2017-10-07 18:25 - 000004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{B26E548C-5E35-48EE-8005-7067AFE7970D}
2017-10-07 12:13 - 2017-10-07 12:21 - 000000010 _____ C:\Users\frank\AppData\Local\sponge.last.runtime.cache
2017-10-07 12:11 - 2017-10-07 12:24 - 000614685 _____ C:\Users\frank\AppData\Local\census.cache
2017-10-07 12:11 - 2017-10-07 12:24 - 000248588 _____ C:\Users\frank\AppData\Local\ars.cache
2017-10-07 12:06 - 2017-10-07 12:06 - 000000000 ____D C:\WINDOWS\Trend Micro
2017-10-07 12:01 - 2017-10-07 12:01 - 000000036 _____ C:\Users\frank\AppData\Local\housecall.guid.cache
2017-10-07 12:01 - 2016-08-22 20:20 - 000332512 _____ (Trend Micro Inc.) C:\WINDOWS\system32\Drivers\tmcomm.sys
2017-10-07 11:58 - 2017-10-07 11:58 - 002527376 _____ (Trend Micro Inc.) C:\Users\frank\Downloads\HousecallLauncher64 (1).exe
2017-10-07 11:58 - 2017-10-07 11:58 - 000003198 _____ C:\WINDOWS\System32\Tasks\DRScanner Startup
2017-10-07 11:58 - 2017-10-07 11:58 - 000002118 _____ C:\Users\Public\Desktop\HouseCall for Home IoT Devices.lnk
2017-10-07 11:58 - 2017-10-07 11:58 - 000000000 ____D C:\Users\frank\AppData\Local\Trend Micro
2017-10-07 11:58 - 2017-10-07 11:58 - 000000000 ____D C:\Program Files (x86)\Trend Micro
2017-10-07 11:57 - 2017-10-07 11:51 - 000544424 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-10-07 11:53 - 2017-10-07 11:54 - 002527376 _____ (Trend Micro Inc.) C:\Users\frank\Downloads\HousecallLauncher64.exe
2017-10-07 11:53 - 2017-10-07 11:53 - 000523344 _____ (Trend Micro Inc.) C:\Users\frank\Downloads\HouseCallforHomeNetworks.exe
2017-10-07 06:48 - 2017-10-07 06:48 - 000000000 ____D C:\Users\frank\AppData\Roaming\Skype
2017-10-07 03:57 - 2017-10-07 03:57 - 000000000 ____D C:\WINDOWS\InfusedApps
2017-10-07 03:56 - 2017-10-07 03:57 - 000000000 ____D C:\Windows.old
2017-10-07 03:56 - 2017-10-07 03:56 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2017-10-07 03:56 - 2017-10-07 02:57 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2017-10-07 03:54 - 2017-10-07 03:54 - 000000000 ____D C:\Program Files\Synaptics
2017-10-07 03:53 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\Setup
2017-10-07 03:52 - 2017-10-07 03:52 - 000000000 ____D C:\WINDOWS\OCR
2017-10-07 03:52 - 2017-10-07 03:52 - 000000000 ____D C:\Program Files\Reference Assemblies
2017-10-07 03:52 - 2017-10-07 03:52 - 000000000 ____D C:\Program Files\MSBuild
2017-10-07 03:52 - 2017-10-07 03:52 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-10-07 03:52 - 2017-10-07 03:52 - 000000000 ____D C:\Program Files (x86)\MSBuild
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\sysprep
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\0409
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\winrm
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\WCN
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\slmgr
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\0409
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\DigitalLocker
2017-10-07 03:50 - 2017-09-02 16:15 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-10-07 03:50 - 2017-09-02 16:15 - 000177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-10-07 03:48 - 2017-10-07 11:58 - 000000000 ___RD C:\Program Files (x86)
2017-10-07 03:48 - 2017-10-07 05:44 - 000000000 ___HD C:\Program Files\WindowsApps
2017-10-07 03:48 - 2017-10-07 04:36 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-10-07 03:48 - 2017-10-07 03:57 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ___SD C:\WINDOWS\system32\F12
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\system32\setup
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\system32\oobe
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\system32\migwiz
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\system32\Dism
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\system32\appraiser
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\ShellExperiences
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\Provisioning
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\Program Files\Windows Defender
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2017-10-07 03:48 - 2017-10-07 03:52 - 000000000 ____D C:\WINDOWS\SystemApps
2017-10-07 03:48 - 2017-10-07 03:52 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ___SD C:\WINDOWS\system32\dsc
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\MUI
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\Com
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\IME
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\Help
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\Program Files\Common Files\System
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 __SHD C:\Program Files\Windows Sidebar
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 __RSD C:\WINDOWS\Media
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ___SD C:\WINDOWS\SysWOW64\Nui
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ___SD C:\WINDOWS\system32\Nui
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ___SD C:\WINDOWS\system32\Configuration
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ___RD C:\WINDOWS\Offline Web Pages
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Web
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Vss
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\tracing
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\TAPI
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\SMI
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\ras
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\NDF
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\MsDtc
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\icsxml
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SystemResources
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\winevt
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\ras
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\ProximityToast
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\PointOfService
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\Ipmi
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\IME
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\icsxml
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\ias
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\Hydrogen
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\GroupPolicy
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\downlevel
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\DDFs
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\config\systemprofile
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\config\Journal
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\Bthprops
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\AppLocker
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\System
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SKB
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\security
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\schemas
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SchCache
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Resources
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Registration
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\PLA
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Performance
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\ModemLogs
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\L2Schemas
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\InputMethod
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Globalization
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\GameBarPresenceWriter
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Cursors
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Branding
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\bcastdvr
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\appcompat
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\addins
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files\Windows Security
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files\Windows Portable Devices
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files\Windows NT
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files\Common Files\Services
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files (x86)\Windows NT
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2017-10-07 03:48 - 2017-10-07 03:47 - 000230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2017-10-07 03:48 - 2017-10-07 03:47 - 000215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2017-10-07 03:48 - 2017-10-07 03:47 - 000215943 _____ C:\WINDOWS\system32\dssec.dat
2017-10-07 03:48 - 2017-10-07 03:47 - 000207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2017-10-07 03:48 - 2017-10-07 03:47 - 000017635 _____ C:\WINDOWS\system32\Drivers\etc\services
2017-10-07 03:48 - 2017-10-07 03:47 - 000015940 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2017-10-07 03:48 - 2017-10-07 03:47 - 000004096 _____ C:\WINDOWS\system32\config\VSMIDK
2017-10-07 03:48 - 2017-10-07 03:47 - 000003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2017-10-07 03:48 - 2017-10-07 03:47 - 000001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
2017-10-07 03:48 - 2017-10-07 03:47 - 000000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2017-10-07 03:48 - 2017-10-07 03:47 - 000000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2017-10-07 03:48 - 2017-10-07 03:47 - 000000741 _____ C:\WINDOWS\system32\NOISE.DAT
2017-10-07 03:48 - 2017-10-07 03:47 - 000000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
2017-10-07 03:48 - 2017-10-07 03:47 - 000000219 _____ C:\WINDOWS\system.ini
2017-10-07 03:48 - 2017-10-07 03:47 - 000000092 _____ C:\WINDOWS\win.ini
2017-10-07 03:48 - 2017-10-07 03:04 - 000000000 ____D C:\WINDOWS\system32\spool
2017-10-07 03:48 - 2017-10-07 03:04 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2017-10-07 03:48 - 2017-10-07 03:04 - 000000000 ____D C:\WINDOWS\rescache
2017-10-07 03:48 - 2017-10-07 03:02 - 000000000 __RHD C:\Users\Public\Libraries
2017-10-07 03:48 - 2017-10-07 03:02 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-10-07 03:48 - 2017-10-07 03:00 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2017-10-07 03:48 - 2017-10-07 02:59 - 000000000 ___RD C:\WINDOWS\PrintDialog
2017-10-07 03:48 - 2017-10-07 02:59 - 000000000 ___RD C:\WINDOWS\MiracastView
2017-10-07 03:48 - 2017-10-07 02:59 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-10-07 03:48 - 2017-10-07 02:59 - 000000000 ____D C:\WINDOWS\HoloShell
2017-10-07 03:48 - 2017-10-07 02:57 - 000000000 ____D C:\WINDOWS\system32\config\TxR
2017-10-07 03:48 - 2017-10-07 02:57 - 000000000 ____D C:\WINDOWS\system32\config\RegBack
2017-10-07 03:47 - 2017-10-07 04:12 - 000000000 ____D C:\WINDOWS\INF
2017-10-07 03:44 - 2017-10-07 20:54 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-10-07 03:43 - 2017-10-07 11:40 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2017-10-07 03:43 - 2017-10-07 03:56 - 000024576 _____ C:\WINDOWS\system32\config\SAM
2017-10-07 03:43 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\servicing
2017-10-07 03:43 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\SMI
2017-10-07 03:43 - 2017-10-07 03:04 - 000000000 ____D C:\WINDOWS\Panther
2017-10-07 03:43 - 2017-10-07 03:01 - 147062784 _____ C:\WINDOWS\system32\config\SYSTEM
2017-10-07 03:43 - 2017-10-07 03:01 - 070516736 _____ C:\WINDOWS\system32\config\SOFTWARE
2017-10-07 03:43 - 2017-10-07 03:01 - 001572864 _____ C:\WINDOWS\system32\config\BBI
2017-10-07 03:43 - 2017-10-07 03:01 - 000262144 _____ C:\WINDOWS\system32\config\DEFAULT
2017-10-07 03:43 - 2017-10-07 03:01 - 000057344 _____ C:\WINDOWS\system32\config\SECURITY
2017-10-07 03:20 - 2017-10-07 03:20 - 000000000 ____D C:\Users\frank\AppData\Roaming\AVAST Software
2017-10-07 03:20 - 2017-10-07 03:20 - 000000000 ____D C:\Users\frank\AppData\Local\Comms
2017-10-07 03:20 - 2017-10-07 03:20 - 000000000 ____D C:\Users\frank\AppData\Local\CEF
2017-10-07 03:19 - 2017-10-07 03:19 - 000061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys
2017-10-07 03:19 - 2017-10-07 03:19 - 000001974 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2017-10-07 03:18 - 2017-10-07 03:18 - 000003994 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2017-10-07 03:18 - 2017-10-07 03:17 - 001020536 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000587168 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000363440 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000343288 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000321032 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000201352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000198976 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000147776 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000110376 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000084416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000057736 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000047008 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2017-10-07 03:17 - 2017-10-07 03:17 - 000401488 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2017-10-07 03:13 - 2017-10-07 03:28 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-10-07 03:10 - 2017-10-07 03:10 - 000000000 ____D C:\Program Files\AVAST Software
2017-10-07 03:09 - 2017-10-07 21:00 - 000911014 _____
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-10-2017
Ran by frank (administrator) on LAPTOP-IQSLKOFV (07-10-2017 21:17:40)
Running from C:\Users\frank\Downloads
Loaded Profiles: frank (Available Profiles: frank)
Platform: Windows 10 Home Version 1703 (X64) Language: English (United Kingdom)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\igfxCUIService.exe
(HP) C:\Windows\System32\hpservice.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\IntelCpHDCPSvc.exe
(Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\IntelCpHeciSvc.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Trend Micro Inc.) C:\Program Files (x86)\Trend Micro\DRScanner\DRScanner.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\igfxEM.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\syswow64\wbem\WmiPrvSE.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11701.1001.87.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8900104 2016-09-09] (Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [253344 2017-10-07] (AVAST Software)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 192.168.1.254
Tcpip\..\Interfaces\{67c6456b-c7f8-4eb3-b087-c5123e077200}: [DhcpNameServer] 192.168.1.254 192.168.1.254
Internet Explorer:
==================
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-07] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-07] (Google Inc.)
Chrome:
=======
CHR Profile: C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default [2017-10-07]
CHR Extension: (Google Slides) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-07]
CHR Extension: (Google Docs) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-07]
CHR Extension: (Google Drive) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-10-07]
CHR Extension: (YouTube) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-10-07]
CHR Extension: (Google Sheets) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-07]
CHR Extension: (Google Docs Offline) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-10-07]
CHR Extension: (The Camelizer) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghnomdcacenbmilgjigehppbamfndblo [2017-10-07]
CHR Extension: (AdBlock) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-10-07]
CHR Extension: (History Eraser App) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjolhjmdgbhebcdnfjhngobjggghoipa [2017-10-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-10-07]
CHR Extension: (Click&Clean App) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2017-10-07]
CHR Extension: (Gmail) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-10-07]
CHR Extension: (Chrome Media Router) - C:\Users\frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-07]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7446024 2017-10-07] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [281416 2017-10-07] (AVAST Software)
R2 esifsvc; C:\WINDOWS\system32\Intel\DPTF\esif_uf.exe [2208888 2016-09-19] (Intel Corporation)
R2 hpsrv; C:\WINDOWS\system32\Hpservice.exe [38728 2016-10-12] (HP)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [317952 2016-09-09] (Realtek Semiconductor)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [278616 2017-08-18] (Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation)
R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 Accelerometer; C:\WINDOWS\System32\drivers\Accelerometer.sys [56128 2016-10-12] (HP)
R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [321032 2017-10-07] (AVAST Software s.r.o.)
R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [198976 2017-10-07] (AVAST Software s.r.o.)
R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [343288 2017-10-07] (AVAST Software s.r.o.)
R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [57736 2017-10-07] (AVAST Software s.r.o.)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [47008 2017-10-07] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [147776 2017-10-07] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [110376 2017-10-07] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [84416 2017-10-07] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1020536 2017-10-07] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [587168 2017-10-07] (AVAST Software)
R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [201352 2017-10-07] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [363440 2017-10-07] (AVAST Software)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [66624 2016-09-19] (Intel Corporation)
R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [350272 2016-09-19] (Intel Corporation)
R0 hpdskflt; C:\WINDOWS\System32\drivers\hpdskflt.sys [42312 2016-10-12] (HP)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [174600 2017-04-13] (Intel Corporation)
R1 klhk; C:\WINDOWS\System32\drivers\klhk.sys [522736 2017-10-07] (AO Kaspersky Lab)
R3 Netwtw04; C:\WINDOWS\system32\DRIVERS\Netwtw04.sys [7643648 2017-07-13] (Intel Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [943112 2016-08-05] (Realtek )
S3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [779232 2016-08-22] (Realsil Semiconductor Corporation)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [53848 2017-08-18] (Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [55384 2017-08-18] (Synaptics Incorporated)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [30368 2017-06-21] (HP)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-10-07 21:17 - 2017-10-07 21:17 - 002400768 _____ (Farbar) C:\Users\frank\Downloads\FRST64.exe
2017-10-07 21:17 - 2017-10-07 21:17 - 000011550 _____ C:\Users\frank\Downloads\FRST.txt
2017-10-07 21:17 - 2017-10-07 21:17 - 000000000 ____D C:\Users\frank\Downloads\FRST-OlderVersion
2017-10-07 21:17 - 2017-10-07 21:17 - 000000000 ____D C:\FRST
2017-10-07 12:25 - 2017-10-07 18:25 - 000004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{B26E548C-5E35-48EE-8005-7067AFE7970D}
2017-10-07 12:13 - 2017-10-07 12:21 - 000000010 _____ C:\Users\frank\AppData\Local\sponge.last.runtime.cache
2017-10-07 12:11 - 2017-10-07 12:24 - 000614685 _____ C:\Users\frank\AppData\Local\census.cache
2017-10-07 12:11 - 2017-10-07 12:24 - 000248588 _____ C:\Users\frank\AppData\Local\ars.cache
2017-10-07 12:06 - 2017-10-07 12:06 - 000000000 ____D C:\WINDOWS\Trend Micro
2017-10-07 12:01 - 2017-10-07 12:01 - 000000036 _____ C:\Users\frank\AppData\Local\housecall.guid.cache
2017-10-07 12:01 - 2016-08-22 20:20 - 000332512 _____ (Trend Micro Inc.) C:\WINDOWS\system32\Drivers\tmcomm.sys
2017-10-07 11:58 - 2017-10-07 11:58 - 002527376 _____ (Trend Micro Inc.) C:\Users\frank\Downloads\HousecallLauncher64 (1).exe
2017-10-07 11:58 - 2017-10-07 11:58 - 000003198 _____ C:\WINDOWS\System32\Tasks\DRScanner Startup
2017-10-07 11:58 - 2017-10-07 11:58 - 000002118 _____ C:\Users\Public\Desktop\HouseCall for Home IoT Devices.lnk
2017-10-07 11:58 - 2017-10-07 11:58 - 000000000 ____D C:\Users\frank\AppData\Local\Trend Micro
2017-10-07 11:58 - 2017-10-07 11:58 - 000000000 ____D C:\Program Files (x86)\Trend Micro
2017-10-07 11:57 - 2017-10-07 11:51 - 000544424 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-10-07 11:53 - 2017-10-07 11:54 - 002527376 _____ (Trend Micro Inc.) C:\Users\frank\Downloads\HousecallLauncher64.exe
2017-10-07 11:53 - 2017-10-07 11:53 - 000523344 _____ (Trend Micro Inc.) C:\Users\frank\Downloads\HouseCallforHomeNetworks.exe
2017-10-07 06:48 - 2017-10-07 06:48 - 000000000 ____D C:\Users\frank\AppData\Roaming\Skype
2017-10-07 03:57 - 2017-10-07 03:57 - 000000000 ____D C:\WINDOWS\InfusedApps
2017-10-07 03:56 - 2017-10-07 03:57 - 000000000 ____D C:\Windows.old
2017-10-07 03:56 - 2017-10-07 03:56 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2017-10-07 03:56 - 2017-10-07 02:57 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2017-10-07 03:54 - 2017-10-07 03:54 - 000000000 ____D C:\Program Files\Synaptics
2017-10-07 03:53 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\Setup
2017-10-07 03:52 - 2017-10-07 03:52 - 000000000 ____D C:\WINDOWS\OCR
2017-10-07 03:52 - 2017-10-07 03:52 - 000000000 ____D C:\Program Files\Reference Assemblies
2017-10-07 03:52 - 2017-10-07 03:52 - 000000000 ____D C:\Program Files\MSBuild
2017-10-07 03:52 - 2017-10-07 03:52 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-10-07 03:52 - 2017-10-07 03:52 - 000000000 ____D C:\Program Files (x86)\MSBuild
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\sysprep
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\0409
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\winrm
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\WCN
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\slmgr
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\0409
2017-10-07 03:51 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\DigitalLocker
2017-10-07 03:50 - 2017-09-02 16:15 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-10-07 03:50 - 2017-09-02 16:15 - 000177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-10-07 03:48 - 2017-10-07 11:58 - 000000000 ___RD C:\Program Files (x86)
2017-10-07 03:48 - 2017-10-07 05:44 - 000000000 ___HD C:\Program Files\WindowsApps
2017-10-07 03:48 - 2017-10-07 04:36 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-10-07 03:48 - 2017-10-07 03:57 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ___SD C:\WINDOWS\system32\F12
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\system32\setup
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\system32\oobe
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\system32\migwiz
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\system32\Dism
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\system32\appraiser
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\ShellExperiences
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\WINDOWS\Provisioning
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\Program Files\Windows Defender
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-10-07 03:48 - 2017-10-07 03:53 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2017-10-07 03:48 - 2017-10-07 03:52 - 000000000 ____D C:\WINDOWS\SystemApps
2017-10-07 03:48 - 2017-10-07 03:52 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ___SD C:\WINDOWS\system32\dsc
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\MUI
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\system32\Com
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\IME
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\Help
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\Program Files\Common Files\System
2017-10-07 03:48 - 2017-10-07 03:51 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 __SHD C:\Program Files\Windows Sidebar
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 __RSD C:\WINDOWS\Media
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ___SD C:\WINDOWS\SysWOW64\Nui
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ___SD C:\WINDOWS\system32\Nui
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ___SD C:\WINDOWS\system32\Configuration
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ___RD C:\WINDOWS\Offline Web Pages
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Web
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Vss
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\tracing
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\TAPI
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\SMI
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\ras
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\NDF
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\MsDtc
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\icsxml
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SystemResources
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\winevt
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\ras
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\ProximityToast
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\PointOfService
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\Ipmi
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\IME
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\icsxml
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\ias
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\Hydrogen
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\GroupPolicy
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\downlevel
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\DDFs
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\config\systemprofile
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\config\Journal
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\Bthprops
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\AppLocker
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\System
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SKB
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\security
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\schemas
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\SchCache
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Resources
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Registration
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\PLA
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Performance
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\ModemLogs
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\L2Schemas
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\InputMethod
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Globalization
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\GameBarPresenceWriter
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Cursors
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\Branding
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\bcastdvr
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\appcompat
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\addins
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files\Windows Security
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files\Windows Portable Devices
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files\Windows NT
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files\Common Files\Services
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files (x86)\Windows NT
2017-10-07 03:48 - 2017-10-07 03:48 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2017-10-07 03:48 - 2017-10-07 03:47 - 000230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2017-10-07 03:48 - 2017-10-07 03:47 - 000215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2017-10-07 03:48 - 2017-10-07 03:47 - 000215943 _____ C:\WINDOWS\system32\dssec.dat
2017-10-07 03:48 - 2017-10-07 03:47 - 000207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2017-10-07 03:48 - 2017-10-07 03:47 - 000017635 _____ C:\WINDOWS\system32\Drivers\etc\services
2017-10-07 03:48 - 2017-10-07 03:47 - 000015940 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2017-10-07 03:48 - 2017-10-07 03:47 - 000004096 _____ C:\WINDOWS\system32\config\VSMIDK
2017-10-07 03:48 - 2017-10-07 03:47 - 000003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2017-10-07 03:48 - 2017-10-07 03:47 - 000001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
2017-10-07 03:48 - 2017-10-07 03:47 - 000000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2017-10-07 03:48 - 2017-10-07 03:47 - 000000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2017-10-07 03:48 - 2017-10-07 03:47 - 000000741 _____ C:\WINDOWS\system32\NOISE.DAT
2017-10-07 03:48 - 2017-10-07 03:47 - 000000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
2017-10-07 03:48 - 2017-10-07 03:47 - 000000219 _____ C:\WINDOWS\system.ini
2017-10-07 03:48 - 2017-10-07 03:47 - 000000092 _____ C:\WINDOWS\win.ini
2017-10-07 03:48 - 2017-10-07 03:04 - 000000000 ____D C:\WINDOWS\system32\spool
2017-10-07 03:48 - 2017-10-07 03:04 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2017-10-07 03:48 - 2017-10-07 03:04 - 000000000 ____D C:\WINDOWS\rescache
2017-10-07 03:48 - 2017-10-07 03:02 - 000000000 __RHD C:\Users\Public\Libraries
2017-10-07 03:48 - 2017-10-07 03:02 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-10-07 03:48 - 2017-10-07 03:00 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2017-10-07 03:48 - 2017-10-07 02:59 - 000000000 ___RD C:\WINDOWS\PrintDialog
2017-10-07 03:48 - 2017-10-07 02:59 - 000000000 ___RD C:\WINDOWS\MiracastView
2017-10-07 03:48 - 2017-10-07 02:59 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-10-07 03:48 - 2017-10-07 02:59 - 000000000 ____D C:\WINDOWS\HoloShell
2017-10-07 03:48 - 2017-10-07 02:57 - 000000000 ____D C:\WINDOWS\system32\config\TxR
2017-10-07 03:48 - 2017-10-07 02:57 - 000000000 ____D C:\WINDOWS\system32\config\RegBack
2017-10-07 03:47 - 2017-10-07 04:12 - 000000000 ____D C:\WINDOWS\INF
2017-10-07 03:44 - 2017-10-07 20:54 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-10-07 03:43 - 2017-10-07 11:40 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2017-10-07 03:43 - 2017-10-07 03:56 - 000024576 _____ C:\WINDOWS\system32\config\SAM
2017-10-07 03:43 - 2017-10-07 03:51 - 000000000 ____D C:\WINDOWS\servicing
2017-10-07 03:43 - 2017-10-07 03:48 - 000000000 ____D C:\WINDOWS\system32\SMI
2017-10-07 03:43 - 2017-10-07 03:04 - 000000000 ____D C:\WINDOWS\Panther
2017-10-07 03:43 - 2017-10-07 03:01 - 147062784 _____ C:\WINDOWS\system32\config\SYSTEM
2017-10-07 03:43 - 2017-10-07 03:01 - 070516736 _____ C:\WINDOWS\system32\config\SOFTWARE
2017-10-07 03:43 - 2017-10-07 03:01 - 001572864 _____ C:\WINDOWS\system32\config\BBI
2017-10-07 03:43 - 2017-10-07 03:01 - 000262144 _____ C:\WINDOWS\system32\config\DEFAULT
2017-10-07 03:43 - 2017-10-07 03:01 - 000057344 _____ C:\WINDOWS\system32\config\SECURITY
2017-10-07 03:20 - 2017-10-07 03:20 - 000000000 ____D C:\Users\frank\AppData\Roaming\AVAST Software
2017-10-07 03:20 - 2017-10-07 03:20 - 000000000 ____D C:\Users\frank\AppData\Local\Comms
2017-10-07 03:20 - 2017-10-07 03:20 - 000000000 ____D C:\Users\frank\AppData\Local\CEF
2017-10-07 03:19 - 2017-10-07 03:19 - 000061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys
2017-10-07 03:19 - 2017-10-07 03:19 - 000001974 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2017-10-07 03:18 - 2017-10-07 03:18 - 000003994 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2017-10-07 03:18 - 2017-10-07 03:17 - 001020536 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000587168 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000363440 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000343288 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000321032 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000201352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000198976 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000147776 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000110376 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000084416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000057736 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2017-10-07 03:18 - 2017-10-07 03:17 - 000047008 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2017-10-07 03:17 - 2017-10-07 03:17 - 000401488 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2017-10-07 03:13 - 2017-10-07 03:28 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-10-07 03:10 - 2017-10-07 03:10 - 000000000 ____D C:\Program Files\AVAST Software
2017-10-07 03:09 - 2017-10-07 21:00 - 000911014 _____