Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-03-2020
Ran by TimeMachine (administrator) on DESKJ (03-04-2020 19:59:23)
Running from C:\Users\TimeMachine\Desktop
Loaded Profiles: TimeMachine (Available Profiles: TimeMachine)
Platform: Windows 10 Home Version 1909 18363.720 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0353065.inf_amd64_2af28622e162cc90\B353014\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0353065.inf_amd64_2af28622e162cc90\B353014\atiesrxx.exe
(ALCPU -> ALCPU) C:\Program Files\Core Temp\Core Temp.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswEngSrv.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswidsagent.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGSvc.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGUI.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGUI.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\wsc_proxy.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(London Trust Media Incorporated -> ) C:\Program Files\Private Internet Access\pia-service.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_1.39.6001.0_x64__8wekyb3d8bbwe\GamingServices.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_1.39.6001.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11911.1001.9.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(Realtek Semiconductor Corp. -> Realtek) C:\Program Files\Realtek\WifiAutoInstall\WifiAutoInstallSrv.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [881440 2019-06-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [325704 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [601784 2019-07-17] (Razer USA Ltd. -> Razer Inc.)
HKU\S-1-5-21-1951528218-1203366226-1675654026-1001\...\Run: [Private Internet Access] => C:\Program Files\Private Internet Access\pia-client.exe [3839456 2020-02-06] (London Trust Media Incorporated -> Private Internet Access Incorporated)
HKU\S-1-5-21-1951528218-1203366226-1675654026-1001\...\Run: [Opera Browser Assistant] => C:\Users\TimeMachine\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3024920 2020-03-27] (Opera Software AS -> Opera Software)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.149\Installer\chrmstp.exe [2020-03-19] (Google LLC -> Google LLC)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {1021821E-A5C1-4D25-8071-02E841F335D6} - System32\Tasks\Opera scheduled assistant Autoupdate 1585360499 => C:\Users\TimeMachine\AppData\Local\Programs\Opera\launcher.exe [1538584 2020-03-27] (Opera Software AS -> Opera Software)
Task: {1FE028E7-A90D-45CD-8621-B3567B79934B} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-02-28] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {33220020-6395-4755-B537-040E534E35CC} - System32\Tasks\COMODO\COMODO Maintenance {947247B5-026A-4437-9371-770782BE839D} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [5701072 2019-10-17] (Comodo Security Solutions -> COMODO)
Task: {33F0E068-ABAC-4C38-8158-CE328BF030F4} - System32\Tasks\COMODO\COMODO Telemetry {18AD3DFA-30C0-4B5F-84F7-F1870B1A4921} => C:\Program Files\COMODO\COMODO Internet Security\cis.exe [13059536 2019-10-17] (Comodo Security Solutions -> COMODO)
Task: {5C49FD98-024A-42EB-9B5C-FDFC76D80B03} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [61624 2020-03-17] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {6FC9FEDD-7466-4B8B-8F37-EDB6CC77A68A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-10-30] (Google Inc -> Google LLC)
Task: {7FCAB8A9-0510-4F56-AAC0-F786ABCAE72E} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [5701072 2019-10-17] (Comodo Security Solutions -> COMODO)
Task: {825944D1-CA7B-4DB8-BB27-6DCE83ECABCD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18233016 2020-02-28] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {849ED783-65AE-441F-81AF-02D17540E60F} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [5701072 2019-10-17] (Comodo Security Solutions -> COMODO)
Task: {871F8FC5-9C71-484F-92E7-56C2D193DB07} - System32\Tasks\StartCNBM => C:\Program Files\AMD\CNext\CNext\cncmd.exe [61624 2020-03-17] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {962F55F6-06F7-4DBB-AF9D-3BB0D78FFA70} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1628160 2020-03-17] (Advanced Micro Devices, Inc.) [File not signed]
Task: {AADEBB09-6677-4811-B86D-602B0652E914} - System32\Tasks\AMDAutoUpdate => C:\Program Files\AMD\AutoUpdate\AMDAutoUpdate.exe [665848 2019-06-27] (Advanced Micro Devices INC. -> )
Task: {BA8CDA2E-6247-47B8-9BF9-51FBE058E73B} - System32\Tasks\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [5701072 2019-10-17] (Comodo Security Solutions -> COMODO)
Task: {C1853D54-7676-475B-B9EE-F77A6B621190} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-10-30] (Google Inc -> Google LLC)
Task: {C1C35D0B-FFF3-436A-9C9F-0A43B367BE31} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [3942704 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
Task: {CCAA4CFC-A777-4B32-BB46-717E49FCDA5E} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cis.exe [13059536 2019-10-17] (Comodo Security Solutions -> COMODO)
Task: {D479298B-F618-4353-953B-5E7F15008A1D} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\BIN64\InstallManagerApp.exe [1628160 2020-03-17] (Advanced Micro Devices, Inc.) [File not signed]
Task: {DCDD16D8-7D0A-4D59-BF93-8A002F672592} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [69304 2020-03-17] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {E060328C-A9F0-4592-8C04-93C05EDCB92C} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [1692296 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {E63AA187-A36A-4B1A-94DE-192EA6F315D8} - System32\Tasks\Opera scheduled Autoupdate 1585360495 => C:\Users\TimeMachine\AppData\Local\Programs\Opera\launcher.exe [1538584 2020-03-27] (Opera Software AS -> Opera Software)
Task: {E76AD7D3-4723-4381-A2CE-EF9314E07DCA} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1628160 2020-03-17] (Advanced Micro Devices, Inc.) [File not signed]
Task: {EFDA71DF-1A92-476F-ACD0-B2A4EB165172} - System32\Tasks\Core Temp Autostart TimeMachine => C:\Program Files\Core Temp\Core Temp.exe [1011592 2019-08-30] (ALCPU -> ALCPU)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\..\Interfaces\{04db5fc8-2861-4bda-8254-3cc631c85d62}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{ca8b32c1-656e-410d-87b1-9b5d06eb5072}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Internet Explorer:
==================
Edge:
======
DownloadDir: C:\Users\TimeMachine\Downloads
FireFox:
========
FF DefaultProfile: j9raw7xq.default
FF ProfilePath: C:\Users\TimeMachine\AppData\Roaming\Mozilla\Firefox\Profiles\j9raw7xq.default [2019-10-13]
FF ProfilePath: C:\Users\TimeMachine\AppData\Roaming\Mozilla\Firefox\Profiles\8qd4far1.default-release [2020-04-03]
FF Homepage: Mozilla\Firefox\Profiles\8qd4far1.default-release -> hxxps://www.google.com/
FF Session Restore: Mozilla\Firefox\Profiles\8qd4far1.default-release -> is enabled.
FF Extension: (Simple Translate) - C:\Users\TimeMachine\AppData\Roaming\Mozilla\Firefox\Profiles\8qd4far1.default-release\Extensions\
simple-translate@sienori.xpi [2019-10-21]
FF Extension: (SoundFixer) - C:\Users\TimeMachine\AppData\Roaming\Mozilla\Firefox\Profiles\8qd4far1.default-release\Extensions\
soundfixer@unrelenting.technology.xpi [2019-10-13]
FF Extension: (Netflix 1080p) - C:\Users\TimeMachine\AppData\Roaming\Mozilla\Firefox\Profiles\8qd4far1.default-release\Extensions\{05c186b0-5b6b-4371-b731-83c4f9868af2}.xpi [2019-12-28]
FF Extension: (YouTube Converter Button) - C:\Users\TimeMachine\AppData\Roaming\Mozilla\Firefox\Profiles\8qd4far1.default-release\Extensions\{8f4bbf79-5514-4d04-a901-d5fabfe91d73}.xpi [2019-10-13]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\TimeMachine\AppData\Roaming\Mozilla\Firefox\Profiles\8qd4far1.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2020-03-31]
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
Chrome:
=======
CHR Profile: C:\Users\TimeMachine\AppData\Local\Google\Chrome\User Data\Default [2020-03-23]
CHR Extension: (Slides) - C:\Users\TimeMachine\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-10-30]
CHR Extension: (Docs) - C:\Users\TimeMachine\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-10-30]
CHR Extension: (Google Drive) - C:\Users\TimeMachine\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-10-30]
CHR Extension: (YouTube) - C:\Users\TimeMachine\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-10-30]
CHR Extension: (Avast SafePrice | Comparison, deals, coupons) - C:\Users\TimeMachine\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2020-02-16]
CHR Extension: (Sheets) - C:\Users\TimeMachine\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-10-30]
CHR Extension: (Google Docs Offline) - C:\Users\TimeMachine\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-02-16]
CHR Extension: (Avast Online Security) - C:\Users\TimeMachine\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2020-02-16]
CHR Extension: (AVG SafePrice | Comparison, deals, coupons) - C:\Users\TimeMachine\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2020-02-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\TimeMachine\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-30]
CHR Extension: (Gmail) - C:\Users\TimeMachine\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-10-30]
CHR Extension: (Chrome Media Router) - C:\Users\TimeMachine\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-02-16]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn]
Opera:
=======
OPR Extension: (Adblock Plus - free ad blocker) - C:\Users\TimeMachine\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2020-03-31]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD External Events Utility; C:\WINDOWS\System32\DriverStore\FileRepository\u0353065.inf_amd64_2af28622e162cc90\B353014\atiesrxx.exe [524712 2020-03-18] (Advanced Micro Devices, Inc. -> AMD)
S2 AUEPLauncher; C:\Program Files\AMD\CIM\..\Performance Profile Client\AUEPLauncher.exe [60600 2020-03-17] (Advanced Micro Devices, Inc. -> AMD)
R2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [413544 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [6094272 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 AvgWscReporter; C:\Program Files\AVG\Antivirus\wsc_proxy.exe [110608 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8567960 2020-03-30] (BattlEye Innovations e.K. -> )
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [802432 2019-09-28] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [342456 2020-01-15] (FUTUREMARK INC -> Futuremark)
R2 GamingServices; C:\Program Files\WindowsApps\Microsoft.GamingServices_1.39.6001.0_x64__8wekyb3d8bbwe\GamingServices.exe [21640 2020-03-15] (Microsoft Corporation -> Microsoft Corporation)
R2 GamingServicesNet; C:\Program Files\WindowsApps\Microsoft.GamingServices_1.39.6001.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe [21640 2020-03-15] (Microsoft Corporation -> Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6933272 2020-03-10] (Malwarebytes Inc -> Malwarebytes)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2495280 2020-03-16] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3445560 2020-03-16] (Electronic Arts, Inc. -> Electronic Arts)
R2 PrivateInternetAccessService; C:\Program Files\Private Internet Access\pia-service.exe [1571840 2020-02-06] (London Trust Media Incorporated -> )
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [474256 2019-12-08] (Rockstar Games, Inc. -> Rockstar Games)
R2 RtkAudioUniversalService; C:\WINDOWS\System32\RtkAudUService64.exe [881440 2019-06-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.6-0\NisSrv.exe [3294680 2020-03-19] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WifiAutoInstallSrv; C:\Program Files\Realtek\WifiAutoInstall\WifiAutoInstallSrv.exe [138176 2017-11-17] (Realtek Semiconductor Corp. -> Realtek)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.6-0\MsMpEng.exe [103168 2020-03-19] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ALSysIO; C:\Users\TimeMachine\AppData\Local\Temp\ALSysIO64.sys [47240 2020-03-26] (ALCPU (Arthur Liberman) -> Arthur Liberman) <==== ATTENTION
R3 amdgpio2; C:\WINDOWS\System32\drivers\amdgpio2.sys [45832 2019-10-01] (Advanced Micro Devices INC. -> Advanced Micro Devices, Inc)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [24528 2019-04-18] (AMD PMP-PE CB Code Signer v20160415 -> Advanced Micro Devices, Inc)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\u0353065.inf_amd64_2af28622e162cc90\B353014\atikmdag.sys [65752488 2020-03-18] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\u0353065.inf_amd64_2af28622e162cc90\B353014\atikmpag.sys [592296 2020-03-18] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 AMDPCIDev; C:\WINDOWS\System32\drivers\AMDPCIDev.sys [32760 2019-05-30] (Advanced Micro Devices INC. -> Advanced Micro Devices)
R0 amdpsp; C:\WINDOWS\System32\drivers\amdpsp.sys [138544 2019-05-23] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc. )
R2 AMDRyzenMasterDriver; C:\Program Files\AMD\Performance Profile Client\RyzenMaster\AMDRyzenMasterDriver.sys [70304 2017-11-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R2 AMDRyzenMasterDriverV14; C:\Program Files\AMD\RyzenMaster\bin\AMDRyzenMasterDriver.sys [70432 2019-08-29] (Advanced Micro Devices INC. -> Advanced Micro Devices)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [108152 2019-11-17] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
R0 avgArDisk; C:\WINDOWS\System32\drivers\avgArDisk.sys [37928 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [206160 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdriver.sys [271704 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsh.sys [207192 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniv.sys [64344 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgElam; C:\WINDOWS\System32\drivers\avgElam.sys [16520 2020-03-23] (Microsoft Windows Early Launch Anti-malware Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgKbd; C:\WINDOWS\System32\drivers\avgKbd.sys [43560 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [175472 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [111144 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [84096 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [849256 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [459192 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [235280 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [316840 2020-03-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus.sys [135520 2019-07-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 gameflt; C:\WINDOWS\System32\DriverStore\FileRepository\gameflt.inf_amd64_1b1c9965dc1c6f0f\gameflt.sys [71000 2019-12-12] (Microsoft Windows -> Microsoft Corporation)
R2 inpoutx64; C:\WINDOWS\System32\Drivers\inpoutx64.sys [15008 2019-11-18] (Red Fox UK Limited -> Highresolution Enterprises [
www.highrez.co.uk])
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [214496 2020-03-25] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-03-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-03-26] (Malwarebytes Inc -> Malwarebytes)
R3 Neo_VPN; C:\WINDOWS\System32\drivers\Neo6_x64_VPN.sys [37824 2019-08-15] (SoftEther Corporation -> SoftEther Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1154336 2019-05-21] (Realtek Semiconductor Corp. -> Realtek )
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [24000 2019-09-25] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [7937904 2017-11-28] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation )
R1 SeLow; C:\WINDOWS\system32\DRIVERS\SeLow_x64.sys [50624 2019-10-14] (SoftEther Corporation -> SoftEther Corporation)
R2 SSGDIO; C:\WINDOWS\SysWOW64\DRIVERS\ssgdio64.sys [14608 2019-11-20] (ATI Technologies, Inc -> ATI Technologies Inc.)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166752 2019-07-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64864 2019-07-09] (Samsung Electronics Co., Ltd. -> QUALCOMM Incorporated)
R3 tap-pia-0901; C:\WINDOWS\System32\drivers\tap-pia-0901.sys [39944 2020-01-27] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45960 2020-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [391392 2020-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [2719256 2020-03-09] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
R3 Xvdd; C:\WINDOWS\System32\DriverStore\FileRepository\xvdd.inf_amd64_5ef00c58b02692b7\xvdd.sys [492376 2020-02-21] (Microsoft Windows -> Microsoft Corporation)
U4 CmdAgent; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-03 19:59 - 2020-04-03 19:59 - 000026764 _____ C:\Users\TimeMachine\Desktop\FRST.txt
2020-04-03 19:58 - 2020-04-03 19:59 - 000000000 ____D C:\FRST
2020-04-03 19:58 - 2020-04-03 19:58 - 002280448 _____ (Farbar) C:\Users\TimeMachine\Desktop\FRST64.exe
2020-04-03 19:58 - 2020-04-03 19:58 - 000000000 ____D C:\Users\TimeMachine\Desktop\FRST-OlderVersion
2020-03-31 23:55 - 2020-03-31 23:55 - 000413540 _____ C:\Users\TimeMachine\Desktop\john oliver.htm
2020-03-31 23:55 - 2020-03-31 23:55 - 000000000 ____D C:\Users\TimeMachine\Desktop\john oliver_files
2020-03-31 22:21 - 2020-04-02 19:03 - 000000000 ____D C:\Users\TimeMachine\AppData\LocalLow\IGDump
2020-03-30 21:06 - 2020-03-30 21:00 - 259911935 _____ C:\Users\TimeMachine\Desktop\20200330_205814.mp4
2020-03-30 20:28 - 2020-03-30 20:23 - 080881718 _____ C:\Users\TimeMachine\Desktop\20200330_202231.mp4
2020-03-30 19:07 - 2020-03-30 19:07 - 000000000 ____D C:\Users\TimeMachine\AppData\Local\BattlEye
2020-03-30 14:08 - 2020-03-30 14:08 - 000000000 ____D C:\ProgramData\Mount and Blade II Bannerlord
2020-03-30 14:07 - 2020-03-30 14:39 - 000000000 ____D C:\Users\TimeMachine\Documents\Mount and Blade II Bannerlord
2020-03-30 13:20 - 2020-03-30 13:20 - 000000222 _____ C:\Users\TimeMachine\Desktop\Mount & Blade II Bannerlord.url
2020-03-29 23:26 - 2020-03-29 23:26 - 000010150 _____ C:\Users\TimeMachine\Desktop\Wet City.jfif
2020-03-29 01:56 - 2020-03-29 01:59 - 000000000 ____D C:\Users\TimeMachine\Documents\Call of Duty Modern Warfare
2020-03-29 00:42 - 2020-03-29 00:42 - 000000693 _____ C:\Users\Public\Desktop\World of Warcraft.lnk
2020-03-29 00:42 - 2020-03-29 00:42 - 000000693 _____ C:\ProgramData\Desktop\World of Warcraft.lnk
2020-03-28 22:18 - 2020-04-03 18:55 - 000000000 ____D C:\Users\TimeMachine\Downloads\opera autoupdate
2020-03-27 18:55 - 2020-03-27 18:55 - 000000000 ____D C:\Users\TimeMachine\AppData\Local\Opera Software
2020-03-27 18:54 - 2020-04-01 00:51 - 000003776 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1585360499
2020-03-27 18:54 - 2020-04-01 00:51 - 000003510 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1585360495
2020-03-27 18:54 - 2020-03-27 18:54 - 002478664 _____ (Opera Software) C:\Users\TimeMachine\Downloads\OperaSetup(1).exe
2020-03-27 18:54 - 2020-03-27 18:54 - 000001490 _____ C:\Users\TimeMachine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
2020-03-27 18:54 - 2020-03-27 18:54 - 000001436 _____ C:\Users\TimeMachine\Desktop\Opera Browser.lnk
2020-03-27 18:54 - 2020-03-27 18:54 - 000000000 ____D C:\Users\TimeMachine\AppData\Roaming\Opera Software
2020-03-26 00:31 - 2020-03-26 00:31 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-03-23 23:16 - 2020-04-01 00:51 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2020-03-23 16:15 - 2020-03-23 16:15 - 000002004 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG AntiVirus FREE.lnk
2020-03-23 16:15 - 2020-03-23 16:15 - 000001992 _____ C:\Users\Public\Desktop\AVG AntiVirus FREE.lnk
2020-03-23 16:15 - 2020-03-23 16:15 - 000001992 _____ C:\ProgramData\Desktop\AVG AntiVirus FREE.lnk
2020-03-23 16:15 - 2020-03-23 16:15 - 000000000 ____D C:\Users\TimeMachine\AppData\Roaming\AVG
2020-03-23 16:13 - 2020-04-01 20:13 - 000004266 _____ C:\WINDOWS\system32\Tasks\Antivirus Emergency Update
2020-03-23 16:13 - 2020-03-23 16:13 - 000849256 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSnx.sys
2020-03-23 16:13 - 2020-03-23 16:13 - 000459192 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSP.sys
2020-03-23 16:13 - 2020-03-23 16:13 - 000368088 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgBoot.exe
2020-03-23 16:13 - 2020-03-23 16:13 - 000316840 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgVmm.sys
2020-03-23 16:13 - 2020-03-23 16:13 - 000271704 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsdriver.sys
2020-03-23 16:13 - 2020-03-23 16:13 - 000235280 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgStm.sys
2020-03-23 16:13 - 2020-03-23 16:13 - 000207192 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsh.sys
2020-03-23 16:13 - 2020-03-23 16:13 - 000206160 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArPot.sys
2020-03-23 16:13 - 2020-03-23 16:13 - 000175472 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgMonFlt.sys
2020-03-23 16:13 - 2020-03-23 16:13 - 000111144 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRdr2.sys
2020-03-23 16:13 - 2020-03-23 16:13 - 000084096 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRvrt.sys
2020-03-23 16:13 - 2020-03-23 16:13 - 000064344 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbuniv.sys
2020-03-23 16:13 - 2020-03-23 16:13 - 000043560 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgKbd.sys
2020-03-23 16:13 - 2020-03-23 16:13 - 000037928 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArDisk.sys
2020-03-23 16:13 - 2020-03-23 16:13 - 000016520 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgElam.sys
2020-03-23 16:13 - 2020-03-23 16:13 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVG
2020-03-23 16:13 - 2020-03-23 16:13 - 000000000 ____D C:\Program Files\Common Files\AVG
2020-03-23 16:10 - 2020-03-23 16:10 - 000000000 ____D C:\Program Files\AVG
2020-03-23 16:01 - 2020-03-23 16:02 - 022195736 _____ (Piriform Software Ltd) C:\Users\TimeMachine\Downloads\ccsetup564.exe
2020-03-20 21:44 - 2020-04-01 00:51 - 000002374 _____ C:\WINDOWS\system32\Tasks\StartCNBM
2020-03-20 21:44 - 2020-03-20 21:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Software
2020-03-20 21:26 - 2020-03-18 12:16 - 062867880 _____ C:\WINDOWS\system32\amd_comgr.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 052403624 _____ C:\WINDOWS\SysWOW64\amd_comgr32.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 004585920 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 004095400 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 001784744 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2020-03-20 21:26 - 2020-03-18 12:16 - 001784744 _____ C:\WINDOWS\system32\vulkaninfo.exe
2020-03-20 21:26 - 2020-03-18 12:16 - 001375144 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2020-03-20 21:26 - 2020-03-18 12:16 - 001375144 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2020-03-20 21:26 - 2020-03-18 12:16 - 001243560 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 001243560 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 001086184 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 001086184 _____ C:\WINDOWS\system32\vulkan-1.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000945032 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000945032 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000761256 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2020-03-20 21:26 - 2020-03-18 12:16 - 000574888 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Rapidfire64.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000493992 _____ C:\WINDOWS\system32\dgtrayicon.exe
2020-03-20 21:26 - 2020-03-18 12:16 - 000491944 _____ C:\WINDOWS\system32\GameManager64.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000485800 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\Rapidfire.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000469416 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000452008 _____ C:\WINDOWS\system32\atieah64.exe
2020-03-20 21:26 - 2020-03-18 12:16 - 000428992 _____ C:\WINDOWS\system32\EEURestart.exe
2020-03-20 21:26 - 2020-03-18 12:16 - 000374696 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000346024 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2020-03-20 21:26 - 2020-03-18 12:16 - 000345000 _____ C:\WINDOWS\system32\clinfo.exe
2020-03-20 21:26 - 2020-03-18 12:16 - 000242088 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000209320 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000184744 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000179080 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000163240 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000159680 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000158432 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000153512 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000138664 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000136616 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000136616 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000135592 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000124840 _____ C:\WINDOWS\system32\atidxx64.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000121768 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000121256 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdxc64.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000107432 _____ C:\WINDOWS\SysWOW64\atidxx32.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000106408 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdxc32.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000091560 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mcl64.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000076200 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mcl32.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000071104 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ati2erec.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000047528 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\RapidFireServer64.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000044456 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\RapidFireServer.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000020632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
2020-03-20 21:26 - 2020-03-18 12:16 - 000020608 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 078651304 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdhip64.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 001686840 _____ (AMD) C:\WINDOWS\system32\amf-mft-mjpeg-decoder64.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 001366192 _____ (AMD) C:\WINDOWS\SysWOW64\amf-mft-mjpeg-decoder32.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 000941992 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 000769448 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 000554408 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmcl64.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 000546568 _____ C:\WINDOWS\system32\amdmiracast.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 000484776 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 000467368 _____ C:\WINDOWS\system32\amdlogum.exe
2020-03-20 21:26 - 2020-03-18 12:15 - 000384424 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmcl32.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 000374184 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 000135160 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 000128976 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 000128952 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 000120064 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 000108056 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2020-03-20 21:26 - 2020-03-18 12:15 - 000108048 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2020-03-20 21:26 - 2020-03-17 14:03 - 003471376 _____ C:\WINDOWS\SysWOW64\atiumdva.cap
2020-03-20 21:26 - 2020-03-17 14:03 - 003437632 _____ C:\WINDOWS\system32\atiumd6a.cap
2020-03-20 21:26 - 2020-03-17 13:59 - 000543136 _____ C:\WINDOWS\SysWOW64\atiapfxx.blb
2020-03-20 21:26 - 2020-03-17 13:59 - 000543136 _____ C:\WINDOWS\system32\atiapfxx.blb
2020-03-18 21:15 - 2020-03-18 21:15 - 000000000 _____ C:\Users\TimeMachine\Desktop\602-832-6604.txt
2020-03-18 14:21 - 2020-03-18 14:21 - 000000000 _____ C:\Users\TimeMachine\Desktop\Moby ****.txt
2020-03-17 23:42 - 2020-03-17 23:42 - 000000222 _____ C:\Users\TimeMachine\Desktop\Chivalry Medieval Warfare.url
2020-03-16 17:36 - 2020-03-16 17:36 - 000000000 _____ C:\Users\TimeMachine\Desktop\Wet City.txt
2020-03-16 17:07 - 2020-03-16 17:07 - 000000000 _____ C:\Users\TimeMachine\Desktop\Dead Kennedys.txt
2020-03-16 02:20 - 2020-03-16 02:20 - 000000000 ____D C:\Users\TimeMachine\AppData\Roaming\EasyAntiCheat
2020-03-16 02:17 - 2020-03-16 02:20 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat
2020-03-16 01:57 - 2020-03-16 01:57 - 000918216 _____ (gamigo AG) C:\Users\TimeMachine\Downloads\WolfteamReloadedDownloader_US.exe
2020-03-16 01:17 - 2020-03-16 01:17 - 000000000 ____D C:\Users\TimeMachine\AppData\LocalLow\Creaky Corpse Ltd
2020-03-16 01:13 - 2020-03-16 01:13 - 000000000 ____D C:\Users\TimeMachine\AppData\Local\ZMR
2020-03-15 23:14 - 2020-03-15 23:16 - 000000000 ____D C:\Users\TimeMachine\AppData\Local\Trend Micro
2020-03-15 23:14 - 2018-01-30 20:16 - 000036600 _____ (Riverbed Technology, Inc.) C:\WINDOWS\system32\Drivers\npf.sys
2020-03-15 23:13 - 2020-03-16 01:22 - 000000000 ____D C:\Program Files (x86)\Trend Micro
2020-03-15 23:13 - 2020-03-15 23:13 - 000942452 _____ C:\Users\TimeMachine\AppData\Local\census.cache
2020-03-15 23:13 - 2020-03-15 23:13 - 000359933 _____ C:\Users\TimeMachine\AppData\Local\ars.cache
2020-03-15 23:02 - 2020-03-15 23:02 - 000000010 _____ C:\Users\TimeMachine\AppData\Local\sponge.last.runtime.cache
2020-03-15 22:58 - 2020-03-15 23:16 - 000000000 ____D C:\ProgramData\Trend Micro
2020-03-15 22:58 - 2020-03-15 22:58 - 000000000 ____D C:\WINDOWS\Trend Micro
2020-03-15 22:57 - 2020-03-15 22:57 - 002660528 _____ (Trend Micro Inc.) C:\Users\TimeMachine\Downloads\HousecallLauncher64.exe
2020-03-15 22:57 - 2020-03-15 22:57 - 000000036 _____ C:\Users\TimeMachine\AppData\Local\housecall.guid.cache
2020-03-15 22:54 - 2020-03-15 22:55 - 000000000 ____D C:\AdwCleaner
2020-03-15 22:54 - 2020-03-15 22:54 - 008199856 _____ (Malwarebytes) C:\Users\TimeMachine\Downloads\adwcleaner_8.0.3.exe
2020-03-15 22:34 - 2020-04-03 19:54 - 000000000 ____D C:\Users\TimeMachine\AppData\LocalLow\uTorrent
2020-03-15 21:57 - 2020-03-15 21:58 - 000000000 ____D C:\Program Files\Defraggler
2020-03-15 21:57 - 2020-03-15 21:57 - 006404096 _____ (Piriform Ltd) C:\Users\TimeMachine\Downloads\dfsetup222.exe
2020-03-15 19:44 - 2020-03-25 02:23 - 000214496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-03-15 10:54 - 2020-03-15 10:54 - 007094928 _____ (techPowerUp (
www.techpowerup.com)) C:\Users\TimeMachine\Downloads\GPU-Z.2.30.0.exe
2020-03-15 10:00 - 2020-03-29 04:21 - 000000000 ____D C:\Users\TimeMachine\AppData\Roaming\FAHClient
2020-03-15 10:00 - 2020-03-15 10:44 - 000002153 _____ C:\Users\TimeMachine\Desktop\
Folding@home.lnk
2020-03-15 10:00 - 2020-03-15 10:00 - 000000000 ____D C:\Users\TimeMachine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FAHClient
2020-03-15 10:00 - 2020-03-15 10:00 - 000000000 ____D C:\Program Files (x86)\FAHClient
2020-03-15 09:58 - 2020-03-15 09:58 - 031120224 _____ C:\Users\TimeMachine\Downloads\fah-installer_7.5.1_x86.exe
2020-03-14 02:54 - 2020-03-14 02:54 - 000001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Private Internet Access.lnk
2020-03-14 00:39 - 2020-03-14 00:39 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-03-14 00:39 - 2020-03-14 00:39 - 009930552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-03-14 00:39 - 2020-03-14 00:39 - 007604584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-03-14 00:39 - 2020-03-14 00:39 - 006520776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-03-14 00:39 - 2020-03-14 00:39 - 004563416 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-03-14 00:39 - 2020-03-14 00:39 - 001610240 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-03-14 00:39 - 2020-03-14 00:39 - 001398584 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-03-14 00:39 - 2020-03-14 00:39 - 001077048 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-03-14 00:39 - 2020-03-14 00:39 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2020-03-14 00:39 - 2020-03-14 00:39 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2020-03-14 00:39 - 2020-03-14 00:39 - 000561464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-03-14 00:07 - 2020-03-14 00:08 - 000000000 ____D C:\Users\TimeMachine\AppData\Local\BraveSoftware
2020-03-14 00:07 - 2020-03-14 00:07 - 001298328 _____ (BraveSoftware Inc.) C:\Users\TimeMachine\Downloads\BraveBrowserSetup.exe
2020-03-11 21:07 - 2020-03-11 21:07 - 000000000 ____D C:\Users\TimeMachine\Documents\Mount&Blade With Fire and Sword
2020-03-11 21:07 - 2020-03-11 21:07 - 000000000 ____D C:\Users\TimeMachine\AppData\Roaming\Mount&Blade With Fire and Sword
2020-03-11 00:39 - 2020-03-11 00:39 - 025900544 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 022635008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 019850240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 019812352 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 018027008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 011607552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 009711616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 007905784 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 007755776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 007259648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 006436352 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 006285312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 006168064 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 006084344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 005911040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 005764664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 005112832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 005040640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 004898144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpltfm.dll
2020-03-11 00:39 - 2020-03-11 00:39 - 004855808 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll