Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22.04.2018 01
Ran by Frost (administrator) on FROST (12-09-2018 06:26:07)
Running from C:\Users\Frost\Downloads\Programs
Loaded Profiles: Frost (Available Profiles: Frost)
Platform: Windows 10 Pro Version 1803 17134.228 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
Failed to access process -> Registry
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(eVenture Limited) C:\Program Files (x86)\hide.me VPN\hidemesvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Discord Inc.) C:\Users\Frost\AppData\Local\Discord\app-0.0.301\Discord.exe
(Discord Inc.) C:\Users\Frost\AppData\Local\Discord\app-0.0.301\Discord.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
(Discord Inc.) C:\Users\Frost\AppData\Local\Discord\app-0.0.301\Discord.exe
(Microsoft Corporation) C:\Windows\System32\SgrmBroker.exe
() C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_1.16.1007.0_x64__8wekyb3d8bbwe\GameBar.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() E:\League of Legends\RADS\projects\league_client\releases\0.0.0.161\deploy\LeagueClient.exe
() E:\League of Legends\RADS\projects\league_client\releases\0.0.0.161\deploy\LeagueClientUx.exe
() E:\League of Legends\RADS\projects\league_client\releases\0.0.0.161\deploy\LeagueClientUxRender.exe
() E:\League of Legends\RADS\projects\league_client\releases\0.0.0.161\deploy\LeagueClientUxRender.exe
(Microsoft Corporation) C:\Windows\System32\GameBarPresenceWriter.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
HKLM\...\Run: [MRT] => C:\Windows\system32\MRT.exe [137343192 2018-08-14] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18389440 2018-07-10] (Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle Corporation)
HKU\S-1-5-21-160697542-1886492661-2065992700-1001\...\Run: [Discord] => C:\Users\Frost\AppData\Local\Discord\app-0.0.301\Discord.exe [57816920 2018-05-01] (Discord Inc.)
HKU\S-1-5-21-160697542-1886492661-2065992700-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3207968 2018-09-08] (Valve Corporation)
HKU\S-1-5-21-160697542-1886492661-2065992700-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [4031600 2018-07-09] (Tonec Inc.)
HKU\S-1-5-21-160697542-1886492661-2065992700-1001\...\Run: [Spotify Web Helper] => C:\Users\Frost\AppData\Roaming\Spotify\SpotifyWebHelper.exe [855440 2018-07-12] (Spotify Ltd)
HKU\S-1-5-21-160697542-1886492661-2065992700-1001\...\Run: [Spotify] => C:\Users\Frost\AppData\Roaming\Spotify\Spotify.exe [24398736 2018-07-12] (Spotify Ltd)
HKU\S-1-5-21-160697542-1886492661-2065992700-1001\...\MountPoints2: D - "D:\Autorun.exe"
IFEO\CNC3.exe: [Debugger]
IFEO\CNC3EP1.exe: [Debugger]
IFEO\generals.exe: [Debugger]
IFEO\RA3.exe: [Debugger] C:\Program Files (x86)\Revora\CNCOnline\cnconline.exe
Startup: C:\Users\Frost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DK.bat [2018-08-14] ()
Startup: C:\Users\Frost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hide.me VPN.lnk [2018-09-08]
ShortcutTarget: hide.me VPN.lnk -> C:\Program Files (x86)\hide.me VPN\Hide.me.exe (eVenture Limited)
Startup: C:\Users\Frost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2018-09-03]
ShortcutTarget: MEGAsync.lnk -> C:\Users\Frost\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited)
Startup: C:\Users\Frost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ZenMate.bat [2018-09-08] ()
AlternateShell:
GroupPolicy: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{468cbd28-47dc-46bc-b88f-29d80e019b7b}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{468cbd28-47dc-46bc-b88f-29d80e019b7b}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2018-06-20] (Internet Download Manager, Tonec Inc.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_181\bin\ssv.dll [2018-08-18] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_181\bin\jp2ssv.dll [2018-08-18] (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2018-06-20] (Internet Download Manager, Tonec Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\ssv.dll [2018-08-18] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\jp2ssv.dll [2018-08-18] (Oracle Corporation)
FireFox:
========
FF HKU\S-1-5-21-160697542-1886492661-2065992700-1001\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Frost\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Frost\AppData\Roaming\IDM\idmmzcc5 [2018-07-10] [Legacy] [not signed]
FF HKU\S-1-5-21-160697542-1886492661-2065992700-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-12-20] [Legacy]
FF Plugin: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2018-08-18] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-08-18] (Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2018-08-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-08-18] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-07-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-07-10] (Google Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxps://
www.google.com/
CHR StartupUrls: Default -> "hxxps://
www.google.com/"
CHR NewTab: Default -> Active:"chrome-extension://eamgcmbligmdanhboepgecjolijbeamg/start/index.html"
CHR Profile: C:\Users\Frost\AppData\Local\Google\Chrome\User Data\Default [2018-09-12]
CHR Extension: (Google Drive) - C:\Users\Frost\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-07-10]
CHR Extension: (Razer) - C:\Users\Frost\AppData\Local\Google\Chrome\User Data\Default\Extensions\blbcjclholhnenkngiajifpenjnklokk [2018-07-10]
CHR Extension: (Youtube) - C:\Users\Frost\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-10]
CHR Extension: (Overwatch Wallpapers HD New Tab Themes) - C:\Users\Frost\AppData\Local\Google\Chrome\User Data\Default\Extensions\eamgcmbligmdanhboepgecjolijbeamg [2018-07-10]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\Frost\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2018-07-10]
CHR Extension: (آدبلوك بلس) - C:\Users\Frost\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-07-25]
CHR Extension: (No Coin - Block miners on the web!) - C:\Users\Frost\AppData\Local\Google\Chrome\User Data\Default\Extensions\gojamcfopckidlocpkbelmpjcgmbgjcl [2018-08-24]
CHR Extension: (IDM Integration Module) - C:\Users\Frost\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2018-07-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Frost\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-07-10]
CHR Extension: (Gmail) - C:\Users\Frost\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-07-10]
CHR Extension: (Chrome Media Router) - C:\Users\Frost\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-07-25]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-07-10]
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-07-10]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BcastDVRUserService; C:\WINDOWS\System32\BcastDVRUserService.dll [1364992 2018-08-03] (Microsoft Corporation)
R3 BcastDVRUserService_4d612; C:\WINDOWS\system32\svchost.exe [51288 2018-04-12] (Microsoft Corporation)
R3 BcastDVRUserService_4d612; C:\WINDOWS\SysWOW64\svchost.exe [44520 2018-04-12] (Microsoft Corporation)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [7211968 2018-07-30] ()
S3 BluetoothUserService; C:\WINDOWS\System32\Microsoft.Bluetooth.UserService.dll [464384 2018-04-12] (Microsoft Corporation)
S3 BluetoothUserService_4d612; C:\WINDOWS\system32\svchost.exe [51288 2018-04-12] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S3 BluetoothUserService_4d612; C:\WINDOWS\SysWOW64\svchost.exe [44520 2018-04-12] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S3 BTAGService; C:\WINDOWS\System32\BTAGService.dll [514048 2018-04-12] (Microsoft Corporation)
S3 BthAvctpSvc; C:\WINDOWS\System32\BthAvctpSvc.dll [395264 2018-04-12] (Microsoft Corporation)
S3 CaptureService; C:\WINDOWS\System32\CaptureService.dll [125952 2018-04-12] (Microsoft Corporation)
S3 CaptureService_4d612; C:\WINDOWS\system32\svchost.exe [51288 2018-04-12] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S3 CaptureService_4d612; C:\WINDOWS\SysWOW64\svchost.exe [44520 2018-04-12] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S3 DevicePickerUserSvc; C:\WINDOWS\System32\Windows.Devices.Picker.dll [400896 2018-04-12] (Microsoft Corporation)
S3 DevicePickerUserSvc; C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll [312832 2018-04-12] (Microsoft Corporation)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [780928 2018-05-12] (EasyAntiCheat Ltd)
R2 hmevpnsvc; C:\Program Files (x86)\hide.me VPN\hidemesvc.exe [139424 2018-07-17] (eVenture Limited)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [353768 2018-07-10] (Intel Corporation)
S3 LxpSvc; C:\WINDOWS\System32\LanguageOverlayServer.dll [199680 2018-04-12] (Microsoft Corporation)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
R2 osrss; C:\WINDOWS\system32\osrss.dll [131288 2018-06-27] (Microsoft Corporation)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
S4 sedsvc; C:\Program Files\rempl\sedsvc.exe [296336 2018-08-10] (Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-08-22] (Microsoft Corporation)
R2 SgrmBroker; C:\WINDOWS\system32\SgrmBroker.exe [163336 2018-04-12] (Microsoft Corporation)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
S4 tzautoupdate; C:\WINDOWS\SysWOW64\tzautoupdate.dll [72192 2018-04-12] (Microsoft Corporation)
S3 VacSvc; C:\WINDOWS\System32\vac.dll [411256 2018-04-12] (Microsoft Corporation)
S3 WaaSMedicSvc; C:\WINDOWS\System32\WaaSMedicSvc.dll [392704 2018-04-12] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4451616 2018-04-12] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [106904 2018-08-03] (Microsoft Corporation)
S3 wisvc; C:\WINDOWS\SysWOW64\flightsettings.dll [729088 2018-08-22] (Microsoft Corporation)
S3 WpcMonSvc; C:\WINDOWS\System32\WpcDesktopMonSvc.dll [1456640 2018-08-22] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 afunix; C:\WINDOWS\system32\drivers\afunix.sys [39424 2018-04-12] (Microsoft Corporation)
R1 afunix; C:\Windows\SysWOW64\drivers\afunix.sys [29696 2018-04-12] (Microsoft Corporation)
S3 bindflt; C:\WINDOWS\system32\drivers\bindflt.sys [92056 2018-04-12] (Microsoft Corporation)
R3 ETDSMBus; C:\WINDOWS\System32\drivers\ETDSMBus.sys [31816 2018-07-10] (ELAN Microelectronic Corp.)
S4 hvcrash; C:\WINDOWS\System32\drivers\hvcrash.sys [33184 2018-04-12] (Microsoft Corporation)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2018-07-10] (REALiX(tm))
S0 iaStorAVC; C:\WINDOWS\System32\drivers\iaStorAVC.sys [885144 2018-04-12] (Intel Corporation)
S0 ItSas35i; C:\WINDOWS\System32\drivers\ItSas35i.sys [145816 2018-04-12] (Avago Technologies)
S0 megasas35i; C:\WINDOWS\System32\drivers\megasas35i.sys [82328 2018-04-12] (Avago Technologies)
S3 NPF; C:\WINDOWS\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S3 nvdimm; C:\WINDOWS\System32\drivers\nvdimm.sys [104448 2018-04-12] (Microsoft Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1139424 2018-08-03] (Realtek )
R0 SgrmAgent; C:\WINDOWS\System32\drivers\SgrmAgent.sys [63896 2018-04-12] (Microsoft Corporation)
S3 smbdirect; C:\WINDOWS\System32\DRIVERS\smbdirect.sys [152064 2018-04-12] (Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44616 2018-04-12] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [331680 2018-04-12] (Microsoft Corporation)
S3 WdmCompanionFilter; C:\WINDOWS\System32\drivers\WdmCompanionFilter.sys [21408 2018-04-12] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [44032 2018-04-12] (Microsoft Corporation)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [55704 2018-09-11] (Wellbia.com Co., Ltd.)
R3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [62856 2018-08-22] (Intel Corporation)
R1 YSDrv; C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [270608 2018-07-10] (BigNox Corporation)
S3 X6va066; \??\C:\Windows\SysWOW64\Drivers\X6va066 [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
NETSVC: LxpSvc -> C:\Windows\System32\LanguageOverlayServer.dll (Microsoft Corporation)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-09-12 04:30 - 2018-09-12 04:31 - 000000000 ____D C:\AdwCleaner
2018-09-12 04:29 - 2018-09-12 04:30 - 007567568 _____ (Malwarebytes) C:\Users\Frost\Downloads\AdwCleaner.exe
2018-09-12 04:29 - 2018-09-12 04:29 - 000103140 _____ C:\dtgtg.pif
2018-09-12 03:20 - 2018-09-12 03:20 - 000028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2018-09-12 03:18 - 2018-09-12 03:59 - 000000000 ____D C:\ProgramData\RogueKiller
2018-09-12 03:18 - 2018-09-12 03:18 - 000000899 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2018-09-12 03:18 - 2018-09-12 03:18 - 000000899 _____ C:\ProgramData\Desktop\RogueKiller.lnk
2018-09-12 03:18 - 2018-09-12 03:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-09-12 03:18 - 2018-09-12 03:18 - 000000000 ____D C:\Program Files\RogueKiller
2018-09-12 02:39 - 2018-09-12 02:40 - 000057197 _____ C:\Users\Frost\Downloads\Addition.txt
2018-09-12 02:37 - 2018-09-12 02:40 - 000152472 _____ C:\Users\Frost\Downloads\FRST.txt
2018-09-12 02:36 - 2018-09-12 06:26 - 000000000 ____D C:\FRST
2018-09-11 04:24 - 2018-09-11 04:24 - 000000222 _____ C:\Users\Frost\Desktop\Rust.url
2018-09-10 19:23 - 2018-09-10 19:23 - 000000000 ____D C:\Users\Frost\AppData\Roaming\CrystalIdea Software
2018-09-10 19:23 - 2018-08-31 22:28 - 001509936 _____ (SpeedyFox) C:\Users\Frost\Desktop\speedyfox.exe
2018-09-09 22:32 - 2018-09-09 22:45 - 000000000 ____D C:\Users\Frost\Documents\Cross Fire
2018-09-09 22:32 - 2018-09-09 22:45 - 000000000 ____D C:\CFLog
2018-09-09 22:31 - 2018-09-11 21:37 - 000055704 _____ (Wellbia.com Co., Ltd.) C:\WINDOWS\xhunter1.sys
2018-09-09 22:30 - 2018-09-09 22:30 - 000001025 _____ C:\Users\Frost\Desktop\CrossFire.lnk
2018-09-09 22:30 - 2018-09-09 22:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Z8Games
2018-09-09 19:20 - 2018-09-09 22:18 - 000000000 ____D C:\ProgramData\Solid State Networks
2018-09-09 18:30 - 2018-09-09 18:30 - 000029000 _____ C:\WINDOWS\SysWOW64\Drivers\X6va066
2018-09-08 21:30 - 2018-09-08 21:30 - 000003074 _____ C:\WINDOWS\System32\Tasks\UAC_X-VPN
2018-09-08 21:30 - 2018-09-08 21:30 - 000001910 _____ C:\Users\Public\Desktop\X-VPN.lnk
2018-09-08 21:30 - 2018-09-08 21:30 - 000001910 _____ C:\ProgramData\Desktop\X-VPN.lnk
2018-09-08 21:30 - 2018-09-08 21:30 - 000000000 ____D C:\Users\Frost\AppData\Roaming\kmg
2018-09-08 21:30 - 2018-09-08 21:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\X-VPN
2018-09-08 21:30 - 2018-09-08 21:30 - 000000000 ____D C:\Program Files (x86)\X-VPN
2018-09-08 21:18 - 2018-09-08 21:19 - 000000000 ____D C:\Program Files (x86)\hide.me VPN
2018-09-08 21:18 - 2018-09-08 21:18 - 000001094 _____ C:\Users\Public\Desktop\hide.me VPN.lnk
2018-09-08 21:18 - 2018-09-08 21:18 - 000001094 _____ C:\ProgramData\Desktop\hide.me VPN.lnk
2018-09-08 21:18 - 2018-09-08 21:18 - 000000000 ____D C:\Users\Frost\AppData\Roaming\Hide.me
2018-09-08 21:18 - 2018-09-08 21:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hide.me VPN
2018-09-08 21:08 - 2018-09-08 21:20 - 000000000 ____D C:\Users\Frost\AppData\Local\ZenMate
2018-09-08 20:35 - 2018-09-08 20:35 - 000000000 ____D C:\Users\Frost\AppData\Roaming\Hard Disk Sentinel
2018-09-03 07:21 - 2018-09-03 07:21 - 000000000 ____D C:\Users\Frost\Documents\Red Alert 3
2018-09-03 06:55 - 2018-09-03 06:55 - 000001701 _____ C:\Users\Public\Desktop\Command & Conquer™ Red Alert™ 3.lnk
2018-09-03 06:55 - 2018-09-03 06:55 - 000001701 _____ C:\ProgramData\Desktop\Command & Conquer™ Red Alert™ 3.lnk
2018-09-03 06:47 - 2018-09-03 06:47 - 000000000 ____D C:\WINDOWS\system32\appmgmt
2018-09-03 06:35 - 2018-09-03 06:35 - 000178800 _____ (Sony DADC Austria AG.) C:\WINDOWS\SysWOW64\CmdLineExt_x64.dll
2018-09-03 06:04 - 2018-09-03 06:04 - 000000853 _____ C:\Users\Public\Desktop\PowerISO.lnk
2018-09-03 06:04 - 2018-09-03 06:04 - 000000853 _____ C:\ProgramData\Desktop\PowerISO.lnk
2018-09-03 06:04 - 2018-09-03 06:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO
2018-09-03 06:04 - 2018-09-03 06:04 - 000000000 ____D C:\Program Files\PowerISO
2018-09-03 06:04 - 2017-06-07 02:36 - 000138296 _____ (Power Software Ltd) C:\WINDOWS\system32\Drivers\scdemu.sys
2018-09-03 05:34 - 2018-09-08 21:20 - 000000000 ____D C:\Users\Frost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ZenGuard GmbH
2018-09-03 05:34 - 2018-09-03 05:34 - 000000000 ____D C:\Users\Frost\AppData\Roaming\ZenMate
2018-09-03 05:34 - 2018-09-03 05:34 - 000000000 ____D C:\Users\Frost\AppData\Local\IsolatedStorage
2018-09-03 04:34 - 2018-05-13 12:33 - 000027136 _____ (The OpenVPN Project) C:\WINDOWS\system32\Drivers\tap0901.sys
2018-09-03 03:47 - 2018-09-03 03:47 - 000001125 _____ C:\Users\Frost\Desktop\MEGAsync.lnk
2018-09-03 03:47 - 2018-09-03 03:47 - 000000000 ____D C:\WINDOWS\System32\Tasks\MEGA
2018-09-03 03:47 - 2018-09-03 03:47 - 000000000 ____D C:\Users\Frost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MEGAsync
2018-09-03 03:47 - 2018-09-03 03:47 - 000000000 ____D C:\Users\Frost\AppData\Local\MEGAsync
2018-09-03 03:47 - 2018-09-03 03:47 - 000000000 ____D C:\Users\Frost\AppData\Local\Mega Limited
2018-09-01 20:29 - 2018-09-11 03:39 - 000000000 ____D C:\Users\Frost\AppData\Local\Razer
2018-09-01 20:27 - 2018-09-11 03:40 - 000000000 ____D C:\ProgramData\Razer
2018-08-31 03:15 - 2011-05-03 13:40 - 000000000 ____D C:\Users\Frost\Desktop\Unpark-CPU-App
2018-08-30 20:56 - 2018-08-30 20:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
2018-08-30 20:56 - 2018-08-30 20:56 - 000000000 ____D C:\Program Files (x86)\WinPcap
2018-08-30 06:49 - 2018-08-30 06:49 - 000000000 ____D C:\Users\Frost\AppData\LocalLow\Facepunch Studios LTD
2018-08-29 08:17 - 2018-09-03 17:52 - 000000000 ____D C:\Users\Frost\AppData\Local\DK Deploy Service
2018-08-29 08:17 - 2018-08-29 08:17 - 000001074 _____ C:\Users\Frost\Desktop\RagnoTech™ Low Specs Experience.lnk
2018-08-29 08:17 - 2018-08-29 08:17 - 000001069 _____ C:\Users\Frost\Desktop\RagnoTech™ ReSwitch.lnk
2018-08-29 08:17 - 2018-08-29 08:17 - 000000000 ____D C:\RagnoTech(TM) Software Solutions
2018-08-29 08:16 - 2018-08-29 08:18 - 000000000 ____D C:\Users\Frost\Downloads\56
2018-08-29 08:13 - 2018-08-29 08:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2018-08-29 07:55 - 2018-08-29 07:55 - 000000609 _____ C:\Users\Public\Desktop\Fraps.lnk
2018-08-29 07:55 - 2018-08-29 07:55 - 000000609 _____ C:\ProgramData\Desktop\Fraps.lnk
2018-08-29 07:55 - 2018-08-29 07:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2018-08-29 07:54 - 2018-08-29 07:59 - 000000000 ____D C:\Users\Frost\AppData\Roaming\DarkSoulsIII
2018-08-29 05:06 - 2018-08-29 06:33 - 000000899 _____ C:\Users\Public\Desktop\Dark Souls 3.lnk
2018-08-29 05:06 - 2018-08-29 06:33 - 000000899 _____ C:\ProgramData\Desktop\Dark Souls 3.lnk
2018-08-28 23:35 - 2018-08-28 23:35 - 000029000 _____ C:\WINDOWS\SysWOW64\Drivers\X6va066_2018.08.29.00.17.04
2018-08-28 06:30 - 2018-08-03 05:39 - 007519992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-08-28 06:30 - 2018-08-03 05:25 - 006568784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-08-28 06:30 - 2018-08-03 05:23 - 025846784 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-08-28 06:30 - 2018-08-03 05:18 - 022714880 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-08-28 06:29 - 2018-08-03 10:39 - 021389368 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-08-28 06:29 - 2018-08-03 10:39 - 000790304 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2018-08-28 06:29 - 2018-08-03 10:25 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2018-08-28 06:29 - 2018-08-03 10:24 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2018-08-28 06:29 - 2018-08-03 10:22 - 001127936 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2018-08-28 06:29 - 2018-08-03 10:21 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2018-08-28 06:29 - 2018-08-03 10:21 - 001121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2018-08-28 06:29 - 2018-08-03 10:21 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2018-08-28 06:29 - 2018-08-03 10:21 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-08-28 06:29 - 2018-08-03 10:20 - 004049408 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2018-08-28 06:29 - 2018-08-03 10:20 - 003652608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-08-28 06:29 - 2018-08-03 10:20 - 000134144 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2018-08-28 06:29 - 2018-08-03 10:19 - 001661440 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2018-08-28 06:29 - 2018-08-03 09:45 - 000663128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2018-08-28 06:29 - 2018-08-03 09:43 - 020383720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-08-28 06:29 - 2018-08-03 09:32 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
2018-08-28 06:29 - 2018-08-03 09:30 - 000099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2018-08-28 06:29 - 2018-08-03 09:29 - 000621568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2018-08-28 06:29 - 2018-08-03 09:29 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-08-28 06:29 - 2018-08-03 09:28 - 002895360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-08-28 06:29 - 2018-08-03 09:27 - 004050432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2018-08-28 06:29 - 2018-08-03 09:27 - 001469952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2018-08-28 06:29 - 2018-08-03 07:41 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2018-08-28 06:29 - 2018-08-03 06:49 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2018-08-28 06:29 - 2018-08-03 05:47 - 001034624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2018-08-28 06:29 - 2018-08-03 05:47 - 000128920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scmbus.sys
2018-08-28 06:29 - 2018-08-03 05:46 - 000272296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-08-28 06:29 - 2018-08-03 05:46 - 000269248 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-08-28 06:29 - 2018-08-03 05:41 - 000568600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2018-08-28 06:29 - 2018-08-03 05:41 - 000077608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2018-08-28 06:29 - 2018-08-03 05:41 - 000061736 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvhostsvc.dll
2018-08-28 06:29 - 2018-08-03 05:40 - 001221048 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-08-28 06:29 - 2018-08-03 05:40 - 001064744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-08-28 06:29 - 2018-08-03 05:40 - 001030952 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-08-28 06:29 - 2018-08-03 05:40 - 000566568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2018-08-28 06:29 - 2018-08-03 05:40 - 000228136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ucx01000.sys
2018-08-28 06:29 - 2018-08-03 05:40 - 000136488 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-08-28 06:29 - 2018-08-03 05:40 - 000072800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2018-08-28 06:29 - 2018-08-03 05:39 - 009091480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-08-28 06:29 - 2018-08-03 05:39 - 007436120 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-08-28 06:29 - 2018-08-03 05:39 - 002829216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-08-28 06:29 - 2018-08-03 05:39 - 001457136 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi